Decryption data leakage prevention method and control system based on data security semantic classification
By using the RASP probe as an in-process awareness extension of the data security semantic gateway and leveraging a security semantic knowledge base to drive a five-layer leakage prevention mechanism, the problem of insufficient automatic generation strategies for data semantic hierarchy in existing technologies is solved, achieving configuration-free minimal decryption and in-process semantic awareness data protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHANGHAI CUSTLE INFORMATION TECH CO LTD
- Filing Date
- 2026-04-17
- Publication Date
- 2026-07-14
AI Technical Summary
Existing data leakage prevention technologies cannot automatically generate leakage prevention strategies based on data semantic classification. After decryption, the data loses control within the application process and cannot form a complete semantic loop.
The RASP probe is positioned as an in-process awareness extension of the data security semantic gateway. It drives a five-layer leakage prevention mechanism through a security semantic knowledge base, realizing full lifecycle semantic control from pre-decryption to use.
It implements a leak prevention strategy that requires no manual configuration, ensures minimal decryption exposure, and provides in-process semantic awareness and traceable, non-repudiable data protection.
Smart Images

Figure FT_1 
Figure FT_2 
Figure FT_3
Abstract
Description
Technical Field
[0001] This invention belongs to the intersection of data security and runtime application protection technologies, specifically involving decryption data leakage prevention technology based on data security semantic classification, and semantic-driven runtime application self-protection and data security gateway linkage technology. Background Technology
[0002] Data is typically encrypted during transmission and storage, but when it is decrypted and processed in memory by legitimate applications, uncontrollable security risks arise. Existing data loss prevention technologies face the following fundamental limitations: Data Loss Prevention (DLP) products rely on content feature recognition (regular expressions, keywords, AI models) to determine data sensitivity. The recognition is based on the physical characteristics of the data, not its business semantics. The sensitivity of the same field varies across different business scenarios, which physical feature-based recognition mechanisms cannot differentiate. Furthermore, existing DLP products lose control after data enters memory and cannot track the flow of decrypted data within the application process. Runtime Application Self-Protection (RASP) technology: Existing RASP products are independent security components whose alarm rules are based on behavioral statistical patterns and do not understand the business semantic meaning of data. There is no real-time linkage mechanism between RASP products and data security management systems. After RASP detects abnormal behavior, it can only handle it locally and cannot trigger a coordinated response at the data security level (such as revoking decryption credentials).
[0003] The common limitations of the two types of technologies are: the leakage prevention strategy is based on rule configuration and cannot be automatically generated according to the semantic classification of data; there is a gap between the monitoring after data decryption and the data access control, and a complete semantic closed loop cannot be formed. Summary of the Invention
[0004] The purpose of this invention is to provide a decryption data leakage prevention method and control system based on data security semantic classification. The system uses a data security semantic gateway as a unified control center and automatically drives the collaborative operation of five layers of leakage prevention mechanisms through semantic classification of the security semantic knowledge base, so as to realize semantic management of the entire life cycle of decrypted data from before decryption to during use to the expiration of credentials.
[0005] The core technical concept of this invention is to position the RASP probe as an in-process awareness extension of the data security semantic gateway, rather than an independent security component. The behavioral data monitored by the probe is subject to compliance judgment by the gateway's semantic inference engine, and the judgment result drives real-time action. This enables the behavioral monitoring of decrypted data to be based on semantic compliance inference, rather than simple behavioral rule matching, achieving a fundamental improvement from "detecting abnormal behavior" to "judging semantic obligation violations."
[0006] The main technical effects of this invention are as follows: Zero-configuration anti-leakage strategy: Based on the semantic classification of the security semantic knowledge base, all anti-leakage parameters are automatically determined without manual configuration of each field. After a new field is classified into a semantic class, the corresponding strategy is automatically obtained. Minimal exposure surface: Minimizing field granularity in decryption ensures that only necessary fields are exposed in a single access, and combined with credential expiration control, the exposure time window of decrypted data is compressed to the minimum; In-process semantic awareness: As an extension of the gateway, the RASP probe extends the gateway's semantic awareness capabilities into the application process, filling the traditional blind spot of data security products within the application process. Traceable and non-repudiable: Semantic-aware watermarks carry complete semantic annotation information, which, combined with digital signatures, allows any copy held by the data recipient to be traced back to the original access request and semantic processing record. Attached Figure Description
[0007] Figure 1 This is a flowchart of the overall process of the present invention, showing the complete processing sequence of the five-layer linkage leakage prevention mechanism and the data flow between each layer. Illustrated content
[0008] This figure illustrates the five-layer linkage architecture of the data decryption and data leakage prevention method based on data security semantic classification as described in claim 1, showing the core responsibilities of each layer and the serial processing relationship between them, as well as the core technical value of each layer. Five-layer processing sequence
[0009] Step S1 (Semantic Hierarchy Query and Automatic Determination of Anti-Leakage Strategy): First row of the left column of the figure, dark blue. After receiving the decryption data access request, the data security semantic gateway queries the security semantic knowledge base to obtain the semantic hierarchy and applicable obligation set of the target data, and automatically determines four anti-leakage parameters based on the semantic hierarchy: (1a) Minimum field set - determines the minimum field range required for this decryption according to the obligation set and access purpose; (1b) Watermark strength and semantic annotation content - determines the watermark strength based on the semantic hierarchy; (1c) RASP monitoring strategy parameters - determines the monitoring range and threshold of the in-process probe; (1d) Credential validity period - the higher the semantic hierarchy, the shorter the validity period. Corresponding annotation in the right column of the figure: Semantic-driven · Zero configuration - the anti-leakage strategy does not require manual configuration and is automatically derived from the knowledge base.
[0010] Step S2 (Minimize Decryption Execution): Second row of the left column of the diagram, blue-green. Decryption is performed according to the minimum field set determined in S1, generating a temporary decryption credential. The validity period of the credential is bound to the semantic hierarchy. It is preferable to perform the decryption operation within a TEE trusted execution environment. The corresponding label in the right column of the diagram: Minimum Exposure Surface—Field-granular decryption compresses the data exposure surface of a single access to a minimum.
[0011] Step S3 (Semantic Aware Watermark Embedding): Third row of the left column of the diagram, dark green. A watermark carrying complete semantic annotation information (including the obligation set identifier and the recipient identifier) is embedded into the decrypted data, and a digital signature is added, making any copy traceable to the original access request. The corresponding label in the right column of the diagram is: Traceable and Non-repudiable.
[0012] Step S4 (RASP Probe Monitoring): Fourth row of the left column of the diagram, dark purple. A runtime application self-protection probe is deployed within the application process receiving decrypted data. The probe acts as an extension of the gateway's in-process awareness, monitoring data operation behavior in real time and reporting semantic audit events to the gateway. The corresponding label in the right column of the diagram is: In-process semantic awareness—filling the traditional blind spot of data security products within the application process.
[0013] Step S5 (Gateway Semantic Reasoning and Handling): Fifth row of the left column of the diagram, dark brown. The gateway determines whether the behavior reported by RASP violates the obligations and constraints based on the knowledge base reasoning rules, and performs tiered handling (minor violation alarm, medium violation restriction, serious violation revocation of certificate), and the certificate automatically expires upon expiration. The corresponding label in the right column of the diagram: Semantic compliance closed loop. Bottom Summary
[0014] The bottom of the diagram indicates that the five-layer mechanism is uniformly driven by a secure semantic knowledge base, collaboratively forming a data leakage prevention and protection system throughout the entire lifecycle of decrypted data. The unified driver of this five-layer mechanism is the secure semantic knowledge base, rather than the independent rule configurations of each layer; this is the fundamental difference from existing DLP+RASP solutions.
[0015] Figure 2 This diagram illustrates the RASP probe and gateway linkage architecture, showing the complete mechanism for probe deployment locations, bidirectional communication channels, semantic audit event reporting, and the issuance of handling instructions. Illustrated content
[0016] This figure illustrates the linkage architecture between the RASP probe described in step S4 of claim 1 and claim 3 and the data security semantic gateway, reflecting the core positioning of the probe as an intra-process perception extension of the gateway, as well as the design of the bidirectional communication channel. Left side: Data security semantic gateway (control center)
[0017] The gateway comprises five functional modules: a semantic reasoning engine (based on a knowledge base, performing compliance checks on probe-reported events); decryption credential management (responsible for credential issuance, verification, and revocation); a probe management module (responsible for probe deployment, status monitoring, and communication maintenance); a semantic audit log (recording violation events and attaching digital signatures); and a handling execution module (executing tiered response actions). The gateway is the decision-making center of the entire system; all compliance checks are performed by the semantic reasoning engine on the gateway side, rather than by the probes themselves. Middle: Encrypted two-way communication channel
[0018] The communication channel uses an encryption protocol (preferably the national cryptographic standard TLS, i.e. TLCP, but not limited to this), supporting data flow in two directions: Upward direction—the probe reports the monitored data operation behavior to the gateway in real time in the form of semantic audit events. The event content includes a semantic description of the operation behavior (data type, operation type, operation target, timestamp), but does not include the original data content to protect privacy; Downward direction—the gateway pushes the handling instructions to the probe in real time. The instruction types include restricting the operation type, forcing re-authentication, triggering credential revocation, etc. Right side: Target application process and RASP probe
[0019] RASP probes are deployed within the target application process and are responsible for monitoring seven types of operations: data read operations, file write operations, network transmission operations, clipboard operations, behavior serialization into semantic events, receiving and executing handling instructions, and probe integrity self-protection. The purple label at the bottom right of the diagram highlights the core positioning of the RASP probe: as an in-process awareness extension of the data security semantic gateway, rather than an independent security component—this is the fundamental difference between this invention and existing RASP technologies. The probe does not make autonomous security judgments but instead reports behavioral data to a gateway with semantic reasoning capabilities for evaluation. Integrity protection mechanism
[0020] The bottom of the diagram indicates the gateway integrity verification mechanism: The gateway periodically verifies the probe status, and automatically revokes the corresponding decryption credentials when the probe is tampered with or communication is interrupted, thereby preventing attackers from evading monitoring by destroying the probe.
[0021] Figure 3 This is a specification diagram of semantically aware watermark content, showing the semantic annotation elements carried by the watermark and the digital signature verification path. Illustrated content
[0022] This figure illustrates the five-element content specifications of the semantically aware watermark described in step S3 of claim 1 and claim 4, as well as the watermark digital signature protection mechanism and two independent verification paths (data recipient path and third-party auditor path). Left side: Specifications of the five elements of a watermark
[0023] The watermark content consists of five elements, embodying the core feature of "semantic awareness": ① Data semantic type reference—a unique identifier corresponding to the data entity class in the security semantic knowledge base. Example: Left side: Watermark five-element specification ontology: / / medical / DiagnosisRecord, enabling the verifier to confirm the semantic type of the data without re-performing content recognition; ② List of applicable obligation set identifiers—a list of obligation types that should be performed in this processing. Example: [Masking, kAnonymity(k=5), AuditLog], allowing the verifier to confirm whether the data has been processed according to the agreed security obligations; ③ Unique identifier of access request—associated with the semantic audit log entry of this access, used to trace the original access record backward from the watermark, realizing a complete traceability chain from any data copy to the original access event; ④ Semantic identity identifier of the recipient—a reference to the recipient's role class in the knowledge base. Example: ontology: / / role / ResearchInstitution, clearly defining the semantic identity of the legitimate data recipient; ⑤ Trusted timestamp—provided by an authoritative TSA service, independent of the system time of the recipient or sender, providing authoritative proof of the data delivery time. Digital signature protection
[0024] The watermark content is protected by a digital signature (preferably using the SM2 algorithm, but not limited to this). The signature object is a combination of the five elements mentioned above. The digital signature ensures the authenticity and integrity of the watermark content itself, preventing attackers from forging the watermark content. Right side: Two independent verification paths
[0025] Data receiver verification path (green): The receiver obtains the sender's digital certificate (from a trusted CA) → verifies the validity of the digital signature (proving the source is authentic and the content is complete) → restores the semantic type reference from the watermark to confirm the data classification → verifies the obligation set identifier to confirm that the security processing is performed as agreed. The entire process requires no requests for information from the sender and is completed independently.
[0026] The third-party auditor's verification path (in red) is as follows: Extract the access request identifier from the watermark → Query the semantic audit log library to locate the original access record → Verify the consistency of semantic type, obligation execution, and timestamp → Output non-repudiable data processing compliance proof. The auditor also independently completes the tracing and verification process without relying on the sender's cooperation.
[0027] Figure 4 This diagram illustrates the binding of voucher validity and semantic classification, showing the validity parameters corresponding to different semantic classifications and the strict rules for multi-field scenarios. Illustrated content
[0028] This diagram illustrates the rule system for binding the validity period of the decryption certificate with the data semantic classification as described in steps S1 / S2 of claim 1 and claim 6, as well as the strict rules for multi-field scenarios and the dynamic failure mechanism triggered by semantic classification changes. Left side: Four-level time constraint system
[0029] The security semantic knowledge base defines four semantic levels corresponding to credential validity constraints, with higher levels having stricter constraints: Level 1 (general data, such as visit_date, BusinessIdentifier) – maximum validity period of 365 days, single-user authorization; Level 2 (generally sensitive, such as patient_name, EmailAddress) – maximum validity period of 90 days, single-user authorization; Level 3 (highly sensitive, such as DiagnosisRecord, LabResult) – maximum validity period of 24 hours, dual-user authorization; Level 4 (highest protection level, such as GeneticInformation) – maximum validity period of 4 hours, multiple users plus approval, default is denied access. These validity parameters are formally defined in the security semantic knowledge base, not fixed values hard-coded in the code, and can be adjusted through knowledge base updates. Top right: Strict rules for multiple fields; Bottom right: Dynamic invalidation triggered by semantic level changes.
[0030] When this decryption involves multiple fields with different semantic levels, the validity period of the credential is determined by the most stringent (shortest) time constraint among all fields. The upper right of the diagram shows a specific example: the field set for this access is [visit_date(L1), diagnosis(L3), lab_result(L3)], with corresponding validity periods of 365 days, 24 hours, and 24 hours respectively. The most stringent field is L3 (24 hours) of both diagnosis and lab_result; therefore, the validity period of this credential is 24 hours. The most stringent field is highlighted in red in the diagram, and the final value is indicated in the green conclusion line. Bottom right: Semantic classification change triggers dynamic failure
[0031] The dynamic invalidation mechanism described in claim 6: When the semantic level of a field in the security semantic knowledge base changes (e.g., a field is upgraded from Level 2 to Level 3), the system automatically identifies all issued credentials marked with the semantic type of that field. During the next credential verification, the access permission for the corresponding field automatically expires, without waiting for the entire credential to expire; the level change takes effect immediately without manual intervention. The five arrows in the diagram illustrate this triggering chain: trigger event → identify affected credentials → automatic invalidation during the next verification → no need to wait for the entire credential to expire → knowledge base change automatically propagates to the credential layer. Detailed Implementation Example 1: Complete Implementation of Medical Research Data Scenarios
[0032] This embodiment describes the complete implementation of the present invention in a medical research data access scenario, illustrating the five steps and the synergistic operation of each claim.
[0033] Scenario Setting: An external research institution (ResearchInstitution role) requests access to clinical data in a hospital's patient database for research analysis (ResearchAccess purpose). The target table contains the following fields: patient_id (UniqueIdentifier L3), diagnosis (DiagnosisRecord L3), genetic_marker (GeneticInformation L4), and visit_date (EventDate L1).
[0034] Implementation of step S1 (claim 1 S1, claim 5): The data security semantic gateway receives access requests and queries the security semantic knowledge base: `genetic_marker` belongs to the `GeneticInformation` class (Level 4, default rejection, not included in decryption scope without specific authorization); `diagnosis` and `patient_id` belong to Level 3; `visit_date` belongs to Level 1. Based on this, the following is determined: Minimum field set = [visit_date, diagnosis] (`patient_id` is excluded due to the lack of a minimum obligation corresponding to the access purpose, and `genetic_marker` is excluded due to the default rejection at Level 4); Watermark strength = High (highest field driven by Level 3); RASP policy = Monitor all file write operations and network transmission operations; Credential validity period = 90 minutes (Level 3 corresponding to time constraints).
[0035] Implementation of step S2 (claim 1 S2, claim 2): The system only decrypts the `visit_date` and `diagnosis` fields (preferably within the TEE, but not limited to this), generating a temporary decryption certificate valid for 90 minutes. The certificate contains the set of allowed access fields: [visit_date, diagnosis]. The encryption status of `patient_id` and `genetic_marker` remains unchanged; even if a query returns these two columns, they will be returned as ciphertext or null values.
[0036] Implementation of step S3 (claim 1 S3, claim 4): The decrypted data undergoes semantically aware watermark embedding. The watermark content includes: a semantic type reference (a knowledge base identifier of the DiagnosisRecord class), an obligation set identifier ([Masking, kAnonymity(k=5)]), an access request identifier (a unique ID for this request), a recipient identifier (a semantic identity identifier for ResearchInstitution), and a trusted timestamp. The watermark is accompanied by an SM2 digital signature, which can be independently verified by the recipient and a third-party auditing institution.
[0037] Implementation of step S4 (claim 1 S4, claim 3): Deploy a RASP probe (either as an SDK injection or Java Agent, but not limited to) within the data processing application process of the research institution. The probe establishes an encrypted two-way communication channel with the gateway (preferably using the national standard TLS, but not limited to). The probe begins monitoring operations on decrypted data within the application process: the application reads the diagnosis field for statistical analysis—a normal operation, recording a semantic audit event; the application attempts to write the original value of the diagnosis field to a local file—the probe detects the file write operation, generates a semantic audit event, and reports it to the gateway.
[0038] Implementation of step S5 (claim 1 S5, claim 7): The gateway receives a semantic audit event for file writing and queries the security semantic knowledge base to infer that the DiagnosisRecord field, under the ResearchAccess purpose, has an obligation set containing kAnonymity (k=5), disallowing the persistence of raw values. The file writing behavior violates this obligation constraint. The gateway determines this as a moderate violation and executes the following actions: sends a file writing restriction command to the probe (the probe intercepts this operation); records the semantic violation audit log (with a digital signature); and sends an alert event to the security operations center. After 90 minutes, the credentials automatically expire, and the application process's access to the decrypted data automatically terminates without manual intervention. Example 2: Core Differences from Existing DLP and RASP Technologies
[0039] This embodiment illustrates the essential differences between the present invention and the prior art through comparison.
[0040] Comparison Dimension Existing DLP Products Existing RASP Products This Invention Strategy Determination Based on rule configuration, set field by field manually Based on behavior baseline statistics Automatically deduced based on semantic knowledge base, zero configuration Decryption Scope Control No field granularity control None Field granularity minimized decryption, automatically determined according to semantic obligations In-process perception None (out of control after data enters memory) Yes, but the rules do not understand semantics Yes, the probe extends as a semantic gateway for semantic compliance reasoning Watermarking Capability Some products have it, but without semantic annotation None Semantic-aware watermark, carrying complete semantic annotation + digital signature Credential Validity None None Driven by semantic grading, the higher the grading, the shorter the validity period Violation Judgment Content feature rule matching Behavior deviation from baseline detection Semantic obligation compliance reasoning, explainable Disposal Linkage Intercept or alarm Local disposal, no cross-layer linkage Probe + gateway real-time linkage, hierarchical disposal Non-repudiation Proof Some products have logs Some have Watermark + signature + timestamp, independently verifiable by third parties Implementation
[0041] The method described in this invention does not rely on any specific security semantic knowledge base. Any semantic knowledge system that can provide hierarchical query of data fields and derivation of obligation sets can be used in conjunction with this invention.
[0042] The RASP probe described in this invention does not depend on any specific deployment method. Any in-process sensing mechanism that can monitor data operation behavior within the application process and maintain real-time communication with the external control center can implement this invention.
[0043] The minimal decryption mechanism described in this invention does not depend on any specific cryptographic system. Any key management and encryption system that supports field-level decryption control can be used in conjunction with this invention. Preferably, existing national cryptographic hardware cryptographic devices (HSM / encryption machine) are used to perform the decryption operation.
[0044] The voucher validity control mechanism described in this invention does not depend on any specific voucher format. Any voucher mechanism that supports field access range constraints and validity binding can implement this invention.
[0045] Any substitutions made by those skilled in the art based on the technical solutions of this invention using the equivalent technical means described above are all within the protection scope of the claims of this invention.
Claims
1. A method for preventing data leakage through decryption based on data security semantic classification, characterized in that, Using a data security semantic gateway as the unified control center, the following steps are included: Step S1: Semantic hierarchical query and automatic determination of anti-leakage strategy - When a decryption data access request arrives, the semantic knowledge base is queried to obtain the semantic hierarchy and applicable obligation set of the target data. Based on the semantic hierarchy, the following anti-leakage strategy combination is automatically determined: (1a) Minimize the decryption scope: Based on the obligation set and access purpose of this access, the minimum field set required for this decryption is determined. Highly sensitive fields not within the obligation set are not included in this decryption; (1b) Semantic-aware watermark parameters: Based on the semantic hierarchy, the watermark strength is determined. The watermark content includes data semantic type reference, applicable obligation set identifier, access request identifier, and receiver identifier; (1c) RASP probe deployment instructions: Based on the semantic hierarchy, the monitoring strategy of the in-process monitoring probe is determined, including the range of monitored data operation types, abnormal behavior judgment threshold, and reporting frequency; (1d) Decryption certificate validity parameters: Based on the semantic hierarchy, the upper limit of the validity period of this decryption certificate is determined. The higher the semantic hierarchy, the shorter the validity period; Step S2: Minimum Decryption execution—Execute the decryption operation according to the minimum field set determined in step S1, generate a temporary decryption certificate for this access, the validity period of the certificate is bound to the timeliness parameter determined in step S1, and the certificate contains a set of allowed access field semantic types; Step S3: Semantic-aware watermark embedding—Perform watermark embedding on the data decrypted in step S2, the embedded watermark carries the semantic annotation information determined in step S1, so that the data receiver and third-party auditor can restore the semantic classification and processing obligation record of the data from the watermark; Step S4: RASP probe monitoring—Deploy a runtime application self-protection probe in the application process that receives the decrypted data, the probe performs the following functions as an in-process awareness extension of the data security semantic gateway: (4a) Monitor the operation behavior of the decrypted data in the application process, including data reading, copying, transmission, writing to external storage, etc.; (4b) Report the monitored data operation behavior to the data security semantic gateway in real time in the form of semantic audit events; (4c) Receive real-time processing instructions issued by the gateway, including restricting specific operation types, forcing re-authentication, triggering credential revocation, etc.; Step S5: Gateway semantic reasoning and processing - The data security semantic gateway receives semantic audit events reported by the RASP probe and judges whether the monitored behavior violates applicable obligation constraints based on the reasoning rule set of the security semantic knowledge base: (5a) If it is judged to be normal behavior, record the semantic audit log and continue monitoring; (5b) If it is judged to be a violation, trigger processing actions, including: revoking the current decryption credential, issuing restriction instructions to the application process, writing semantic violation alarm logs, and notifying the data security semantic gateway to terminate the session when necessary; (5c) When the credential expires, it will automatically become invalid regardless of whether a violation is found, and the application process's access to the decrypted data will be terminated accordingly.
2. The method according to claim 1, characterized in that, The decryption operation described in step S2 is preferably performed within a Trusted Execution Environment (TEE), but is not limited thereto. Any confidential computing mechanism that can provide hardware-level isolation protection can implement the present invention. The Trusted Execution Environment ensures that the decryption process and the decrypted data are not accessed by the host operating system or other processes in memory, thereby further reducing the exposure of the decrypted data during the computing process while minimizing the scope of decryption. The processing results within the TEE are output to the application process in encrypted form or in a processed form, and are not stored outside the TEE in plaintext form.
3. The method according to claim 1, characterized in that, The communication mechanism between the RASP probe and the data security semantic gateway in step S4 includes the following features: an encrypted, persistent, bidirectional communication channel is established between the probe and the gateway (preferably based on national cryptographic algorithms, but not limited to this); the semantic audit events reported by the probe include a semantic description of the operation behavior (data semantic type, operation type, operation target, timestamp) rather than the original data content, thus protecting data privacy; the processing instructions issued by the gateway are pushed to the probe in real time through the communication channel, and the response time of the probe to execute the instructions does not exceed a preset threshold; the integrity of the probe itself is verified by the gateway periodically, and the gateway automatically revokes the corresponding decryption certificate when the probe is tampered with or communication is interrupted.
4. The method according to claim 1, characterized in that, The semantically aware watermark content specification described in step S3 includes the following elements: data semantic type reference (a unique identifier corresponding to the data entity class in the security semantic knowledge base); list of applicable obligation set identifiers (the types of obligations that should be performed in this process); unique access request identifier (used to associate with the semantic audit log of this data access); and recipient semantic identity identifier (a reference to the recipient's role class in the security semantic knowledge base). A trusted timestamp (marking the data delivery time, provided by an authoritative timestamp service); the watermark content is protected by a digital signature (preferably SM2 algorithm, but not limited to this), enabling the data recipient or third-party auditor to independently verify the authenticity and integrity of the watermark, and to trace the complete chain of data processing obligations through the watermark content.
5. The method according to claim 1, characterized in that, The rule for determining the minimum field set in step S1 (1a) is as follows: The system queries the access scope definition of the data entity class corresponding to the current access purpose class in the security semantic knowledge base, and only includes fields within the access scope definition and compliant after the obligation is executed into the current decryption scope; specifically, fields with the highest semantic protection level (such as genetic information) are not included in the decryption scope under any access purpose, unless the accessing subject holds a special authorization certificate for that field type; the minimum field set is dynamically adjusted with the change of access purpose, and the same subject may obtain different minimum field sets under different access purposes.
6. The method according to claim 1, characterized in that, The rules for determining the validity period of the decryption certificate in step S1 (1d) are driven by the time constraint definitions corresponding to each security level in the security semantic knowledge base, rather than a preset fixed time parameter; when the current decryption involves multiple fields of different security levels, the validity period of the certificate takes the most stringent (shortest) time constraint among all fields; when the security level of the decrypted field changes in the knowledge base, the access permissions of the corresponding field in the issued certificate will automatically expire during the next certificate verification, without waiting for the certificate to expire as a whole.
7. The method according to claim 1, characterized in that, The violation handling mechanism described in step S5 includes a tiered response capability: based on the semantic severity assessment of the violation in the security semantic knowledge base, corresponding level of handling actions are executed; minor violations (such as accessing data within the scope of the obligation set but not the minimum field set) trigger alarm recording and restrict subsequent similar operations; moderate violations (such as attempting to write decrypted data to external storage) trigger session restrictions and real-time alarms; severe violations (such as attempting to bypass the RASP probe or tamper with the watermark) trigger immediate credential revocation, termination of the application process's access to decrypted data, and generation of a non-repudiable violation proof record; the violation proof record is attached with a digital signature and a trusted timestamp, which can be independently verified by a third party.
8. The method according to claim 1, characterized in that, The method described in this invention can be used in conjunction with any key management system, any application runtime environment, and any authentication mechanism. The introduction of the above-mentioned external systems does not change the five core technical mechanisms protected by this invention: automatic determination of semantic hierarchical driving strategy, minimization decryption, semantic awareness watermarking, semantic awareness extension in RASP process, and gateway semantic reasoning processing. The method of this invention is independently established at the level of the above-mentioned technical mechanisms.
9. A decryption data leakage prevention control system for implementing the method of claim 1, characterized in that, The system includes the following functional modules: Semantic Policy Determination Module: Receives decryption data access requests, queries the security semantic knowledge base, and automatically determines the minimum decryption scope, watermark parameters, RASP policy, and credential validity parameters; Minimum Decryption Module: Performs field-level decryption operations according to the semantic policy, generates temporary decryption credentials with field access scope constraints, and preferentially supports decryption within a trusted execution environment; Semantic Aware Watermark Module: Embeds semantic watermarks into decrypted data, outputs data carrying complete semantic annotation information, and adds digital signature protection to the watermark; RASP Probe Management Module: Deploys and manages runtime application self-protection probes to target application processes, maintains encrypted bidirectional communication channels with probes, receives semantic audit events reported by probes, and issues handling instructions to probes; Gateway Semantic Reasoning and Handling Module: Performs semantic compliance reasoning on RASP-reported behavioral events based on the security semantic knowledge base, executes tiered violation handling actions, and records semantic violation audit logs.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 8.