A personal information risk warning method and device

Automatically evaluate the data processing type of personal information through AI models, calculate the impact and degree of protection of rights, solve the problem of incomplete assessment caused by manual review, and achieve efficient risk warning.

CN114780988BActive Publication Date: 2025-08-26SHU ANXIN (BEIJING) TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202210328008.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-03-29
Publication Date
2025-08-26
Estimated Expiration
2042-03-29

AI Technical Summary

Technical Problem

In the prior art, personal information protection mainly relies on manual review, resulting in imperfect assessment and a large amount of manpower and material resources, making it difficult to achieve comprehensive protection.

Method used

AI model is used to automatically evaluate the data processing type of personal information, calculate the degree of impact of personal rights and security protection, determine the risk level and issue early warning information.

Benefits of technology

It improves the accuracy and efficiency of personal information protection assessment and realizes automated risk warning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114780988B_ABST
    Figure CN114780988B_ABST
Patent Text Reader

Abstract

This application provides a personal information risk warning method and device, which includes: obtaining a user's personal information data and the data processing type corresponding to the personal information data; calling a first AI model and a second AI model and inputting the personal information data and the data processing type to respectively obtain the degree of personal rights and interests impact corresponding to the personal information data and the security level corresponding to the degree of personal rights and interests impact; calling a third AI model and inputting the data on the degree of personal rights and interests impact and the security level to determine the risk level of the personal information, and issuing a risk warning message based on the risk level. By setting the personal information type, rights and interests impact, and security level, this application can automatically perform personal information protection assessments, improving the accuracy and efficiency of personal information protection assessments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application seeks to protect an information risk warning technology, and in particular, relates to a personal information risk warning method. This application also relates to a personal information risk warning device. Background Art

[0002] Personal information risk refers to whether the processing of personal information will violate laws and regulations during the use of information data, and the judgment or description of whether the protection of personal information is complete.

[0003] In existing technologies, the protection of personal information is mainly based on manual review methods to predict risks and then protect them. This method makes it difficult to fully protect personal information and still cannot achieve fundamental improvements despite consuming a lot of manpower and material resources. Summary of the Invention

[0004] In order to solve the problem of imperfect personal information protection assessment, this application provides a personal information risk warning method. This application also relates to a personal information risk warning device.

[0005] This application provides a personal information risk warning method, including:

[0006] Obtaining the user's personal information data and the data processing type corresponding to the personal information data;

[0007] Calling the first AI model and the second AI model and inputting the personal information data and the data processing type, respectively obtaining the degree of impact on personal rights and interests corresponding to the personal information data and the degree of security protection corresponding to the degree of impact on personal rights and interests;

[0008] The third AI model is called, and the data on the degree of impact on personal rights and interests and the degree of security protection are input to determine the risk level of the personal information, and risk warning information is issued according to the risk level.

[0009] Optionally, the degree of impact on personal rights and interests is set to different preset levels according to the data processing type, wherein the data processing type includes: acquisition, use and dissemination of data.

[0010] Optionally, the preset level is three levels, including: no risk found, risk or serious risk.

[0011] Optionally, the risk level is determined based on the highest risk item among the personal rights and interests impact level or the security protection level.

[0012] Optionally, the warning information includes: a pop-up window, prohibited operation, and a light signal or sound signal.

[0013] This application also provides a personal information risk warning device, including:

[0014] A receiving module, configured to obtain the user's personal information data and the data processing type corresponding to the personal information data;

[0015] a determination module, configured to call the first AI model and the second AI model and input the personal information data and the data processing type, to respectively determine the degree of impact on personal rights and interests corresponding to the personal information data and the degree of security protection corresponding to the degree of impact on personal rights and interests;

[0016] The judgment module is used to call the third AI model and input the data on the degree of impact on personal rights and interests and the degree of security protection, determine the risk level of personal information, and issue risk warning information based on the risk level.

[0017] Optionally, the degree of impact on personal rights and interests is set to different preset levels according to the data processing type, wherein the data processing type includes: acquisition, use and dissemination of data.

[0018] Optionally, the preset level is three levels, including: no risk found, risk or serious risk.

[0019] Optionally, the risk level is determined based on the highest risk item among the personal rights and interests impact level or the security protection level.

[0020] Optionally, the warning information includes: a pop-up window, prohibited operation, and a light signal or sound signal.

[0021] The advantages of this application over the prior art are:

[0022] This application provides a personal information risk warning method, comprising: obtaining a user's personal information data and the data processing type corresponding to the personal information data; invoking a first AI model and a second AI model and inputting the personal information data and the data processing type to obtain the degree of impact on the personal rights and interests corresponding to the personal information data, and the security level corresponding to the degree of impact on the personal rights and interests; invoking a third AI model and inputting the data on the degree of impact on the personal rights and interests and the security level to determine the risk level of the personal information, and issuing a risk warning message based on the risk level. By setting the personal information type, rights impact, and security level, this application can automatically perform personal information protection assessments, improving the accuracy and efficiency of personal information protection assessments. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 This is the personal information risk warning flow chart in this application.

[0024] Figure 2This is a flow chart for determining the degree of impact on rights and interests of personal information data processing in this application.

[0025] Figure 3 This is a schematic diagram of the personal information risk warning device in this application. DETAILED DESCRIPTION

[0026] The following contents are all examples of specific implementation processes provided for detailed description of the technical solutions to be protected by this application. However, this application can also be implemented in other ways different from the descriptions here. Those skilled in the art can adopt different technical means to implement this application under the guidance of the concept of this application. Therefore, this application is not limited to the specific embodiments below.

[0027] This application provides a personal information risk warning method, comprising: obtaining a user's personal information data and the data processing type corresponding to the personal information data; invoking a first AI model and a second AI model and inputting the personal information data and the data processing type to obtain the degree of impact on the personal rights and interests corresponding to the personal information data, and the security level corresponding to the degree of impact on the personal rights and interests; invoking a third AI model and inputting the data on the degree of impact on the personal rights and interests and the security level to determine the risk level of the personal information, and issuing a risk warning message based on the risk level. By setting the personal information type, rights impact, and security level, this application can automatically perform personal information protection assessments, improving the accuracy and efficiency of personal information protection assessments.

[0028] Figure 1 This is the personal information risk warning flow chart in this application.

[0029] Please refer to Figure 1 As shown, S101 obtains the user's personal information data and the data processing type corresponding to the personal information data.

[0030] The personal information data shown is the personal information provided by users when using a certain product. The personal information has multiple categories, including identity information, occupation information, address information, relationship diagram information, etc. The categories can be further divided into multiple subcategories. For example, identity information can include age information, gender information, educational information, etc.; occupation information can include occupation category information, work experience information, salary information, etc.; address information can include residential address information, household registration information, etc.

[0031] Different categories of personal information may be processed differently, with each type of processing having a different impact on individual rights and interests. Data processing types include: acquisition, use, and dissemination of data.

[0032] In this application, each type of personal information has a mapping relationship with the information processing type. Therefore, when the personal information data is obtained, the data processing type of the personal information data can be determined based on the mapping relationship. The personal information data can be used for various applications such as user profiling, demand analysis, and interest analysis, and each application corresponds to a different data processing type.

[0033] Therefore, the data processing type of the personal information data described in this application can be set specifically according to the type of data and the application of the data, and will not be repeated here.

[0034] Please refer to Figure 1 As shown, S102 calls the AI ​​model and inputs the personal information data and data processing type to obtain the degree of impact on personal rights and interests corresponding to the personal information data, and the degree of security protection corresponding to the degree of impact on personal rights and interests.

[0035] The degree of impact on rights and interests is determined according to the data processing type. Therefore, after determining the data processing type, the degree of impact on rights and interests and the degree of security assurance of the data processing type can be determined.

[0036] Specifically, this application uses an AI model to calculate the degree of impact on personal rights and interests corresponding to personal information data, calculates the degree of impact on personal rights and interests through a first AI model, and calculates the degree of security protection through a second AI model.

[0037] The AI ​​model is a pre-trained convolutional neural network model used to calculate the degree of impact on human rights and interests and the degree of security protection corresponding to human information data and data processing types.

[0038] Specifically, the training method includes:

[0039] Acquire multiple data samples, where the data samples are multiple personal information data, and delete personal sensitive information in the data samples, where the sensitive information includes information such as gender, age, and residence.

[0040] Multiple sample data are divided into training data sets and test data sets, and the sample data in the training data sets are input into the convolutional neural network in turn, and the parameters are adjusted according to the calculation results.

[0041] After completion, input the test data set. If the calculation result of the test data set meets the result requirements, the AI ​​model training is completed. Otherwise, re-set the sample and repeat the training.

[0042] Call the pre-trained AI model that has been trained, input the personal information data and data processing type to obtain the degree of impact on personal rights and interests corresponding to the personal information data, and the degree of security protection corresponding to the degree of impact on personal rights and interests.

[0043] In this application, the sample data of the different AI models are the same. The key lies in the extraction of features by the convolutional neural network and the setting of parameters so that the final calculation results conform to the corresponding results.

[0044] Please refer to Figure 1 As shown, S103 calls the third AI model and inputs the data of the impact degree of personal rights and interests and the security protection degree, determines the risk level of personal information, and issues risk warning information according to the risk level.

[0045] Once the user's data processing type is determined, the rights and interests impact analysis can be performed based on the specific operations of the data processing.

[0046] Specifically, the processing of personal information data first determines whether the processing of personal information data complies with laws and regulations. If not, it can be determined that the processing of personal information seriously affects the rights and interests of individuals. If so, the next step is carried out.

[0047] Figure 2 This is a flow chart for determining the degree of impact on rights and interests of personal information data processing in this application.

[0048] Please refer to Figure 2 As shown, S201 determines the equity impact category of the data processing type.

[0049] The processing of any personal information data may have the following results: rights and interests are not affected, rights and interests are affected, and rights and interests are seriously affected.

[0050] After obtaining the equity impact categories, equity impact results are determined for each equity impact category, and these results have a one-to-one correspondence with the equity impact categories.

[0051] S201 determines the degree of equity impact.

[0052] Specifically, first determine the number of equity impact categories; based on the number of equity responses, determine whether there is an equity impact type that is the result of equity being affected or seriously affecting equity; otherwise, determine it as equity impact; if so, determine the degree of equity impact.

[0053] For example:

[0054] For a piece of personal information data S, the corresponding data processing type is A, then it can be determined that the number of rights and interests affected by A is n.

[0055] Assume that the degree of equity influence is D, then D can be expressed by the following formula:

[0056] DF n(a1*a2*a3*...*a n )

[0057] Where F is a parameter determined based on the equity impact results. The corresponding F for each data processing type A can be the same or different. a is the pre-set cardinality of each equity impact category, and n is the number of equity impact categories. Preferably, n < 4.

[0058] The risk level is determined based on the parameters of the individual rights impact level and the security level. Each rights impact category corresponds to a corresponding rights security level, and the rights security level is preset.

[0059] For each of the rights and interests impact categories, if the rights and interests protection level does not exist, the parameter is 1, and if it exists, it is 0. Let the parameter of the rights and interests protection be K, then:

[0060] D=K n F n (a i *a2*a3*...*a n )

[0061] It should be noted that K and F are different for each equity response type, so each a in the above formula should be multiplied by its corresponding K and F and then multiplied again. n KF=0, then the a n The KF value is 1 and participates in the calculation.

[0062] Once D is determined, a preset level can be determined based on the position of D in the risk range table, and a risk warning message can be issued based on the preset level. Preferably, the preset level is three levels, including: no risk found, risk, or serious risk. The warning message includes: pop-up window, prohibited operation, and light signal or sound signal.

[0063] Specifically, the risk level is determined based on the degree of impact on the equity, and is calculated by calling a third AI model.

[0064] Specifically, the third AI model is called, the D data is input, and the risk level is obtained.

[0065] The third AI model is trained by a convolutional neural network with three convolutional layers. The training method is:

[0066] Divide the D data set into a training set and a test set;

[0067] First, the training set data is input into the first convolutional layer. According to the first output result of the first convolutional layer, the parameters of the second convolutional layer are adjusted, and the first output data is input.

[0068] The third convolution layer is adjusted according to the second output data output by the second convolution layer, and the third output data is output.

[0069] The parameters of the first convolutional layer are adjusted based on the third output data to complete the training of the convolutional neural network. The test set data is input to determine whether the results meet the expectations. If so, the training is completed. If not, the training is restarted until the test set results meet the expectations.

[0070] The present application also provides a personal information risk warning device, including: a receiving module 301, a determining module 302 and a judging module 303.

[0071] Figure 3 This is a schematic diagram of the personal information risk warning device in this application.

[0072] Please refer to Figure 3 As shown, the receiving module 301 is used to obtain the user's personal information data and the data processing type corresponding to the personal information data.

[0073] The personal information data shown is the personal information provided by users when using a certain product. The personal information has multiple categories, including identity information, occupation information, address information, relationship diagram information, etc. The categories can be further divided into multiple subcategories. For example, identity information can include age information, gender information, educational information, etc.; occupation information can include occupation category information, work experience information, salary information, etc.; address information can include residential address information, household registration information, etc.

[0074] Different categories of personal information may be processed differently, with each type of processing having a different impact on individual rights and interests. Data processing types include: acquisition, use, and dissemination of data.

[0075] In this application, each type of personal information has a mapping relationship with the information processing type. Therefore, when the personal information data is obtained, the data processing type of the personal information data can be determined based on the mapping relationship. The personal information data can be used for various applications such as user profiling, demand analysis, and interest analysis, and each application corresponds to a different data processing type.

[0076] Therefore, the data processing type of the personal information data described in this application can be set specifically according to the type of data and the application of the data, and will not be repeated here.

[0077] Please refer to Figure 3 As shown, the determination module 302 is used to determine the degree of impact on personal rights and interests corresponding to the personal information data and the degree of security protection corresponding to the degree of impact on personal rights and interests according to the data processing type.

[0078] The degree of impact on rights and interests is determined according to the data processing type. Therefore, after determining the data processing type, the degree of impact on rights and interests and the degree of security assurance of the data processing type can be determined.

[0079] Please refer to Figure 3 As shown, the judgment module 303 is used to determine the risk level of personal information according to the impact degree of personal rights and interests and the security level, and issue risk warning information according to the risk level.

[0080] Once the user's data processing type is determined, the rights and interests impact analysis can be performed based on the specific operations of the data processing.

[0081] Specifically, the processing of personal information data first determines whether the processing of personal information data complies with laws and regulations. If not, it can be determined that the processing of personal information seriously affects the rights and interests of individuals. If so, the next step is carried out.

[0082] Please refer to Figure 2 As shown, S201 determines the equity impact category of the data processing type.

[0083] The processing of any personal information data may have the following results: rights and interests are not affected, rights and interests are affected, and rights and interests are seriously affected.

[0084] After obtaining the equity impact categories, equity impact results are determined for each equity impact category, and these results have a one-to-one correspondence with the equity impact categories.

[0085] S201 determines the degree of equity impact.

[0086] Specifically, first determine the number of equity impact categories; based on the number of equity responses, determine whether there is an equity impact type that is the result of equity being affected or seriously affecting equity; otherwise, determine it as equity impact; if so, determine the degree of equity impact.

[0087] For example:

[0088] For a piece of personal information data S, the corresponding data processing type is A, then it can be determined that the number of rights and interests affected by A is n.

[0089] Assume that the degree of equity influence is D, then D can be expressed by the following formula:

[0090] D=Fn (a1*a2*a3*...*a n )

[0091] Where F is a parameter determined based on the equity impact results. The corresponding F for each data processing type A can be the same or different. a is the pre-set cardinality of each equity impact category, and n is the number of equity impact categories. Preferably, n < 4.

[0092] The risk level is determined based on the parameters of the individual rights impact level and the security level. Each rights impact category corresponds to a corresponding rights security level, and the rights security level is preset.

[0093] For each of the rights and interests impact categories, if the rights and interests protection level does not exist, the parameter is 1, and if it exists, it is 0. Let the parameter of the rights and interests protection be K, then:

[0094] D=K n F n (a1*a2*a3*...a n )

[0095] It should be noted that K and F are different for each equity response type, so each a in the above formula should be multiplied by its corresponding K and F and then multiplied again. n KF=0, then the a n The KF value is 1 and participates in the calculation.

[0096] Once D is determined, a preset level can be determined based on the position of D in the risk range table, and a risk warning message can be issued based on the preset level. Preferably, the preset level is three levels, including: no risk found, risk, or serious risk. The warning message includes: pop-up window, prohibited operation, and light signal or sound signal.

Claims

1. A personal information risk early warning method, characterized in that: include: Obtaining the user's personal information data and the data processing type corresponding to the personal information data; The first and second AI models are called and input with the personal information data and data processing type, respectively obtaining the degree of impact on personal rights and interests corresponding to the personal information data and the degree of security protection corresponding to the degree of impact on personal rights and interests. The first and second AI models are pre-trained convolutional neural network models. During training, multiple data samples are first obtained and personal sensitive information in the data samples is deleted. The multiple sample data are then divided into training data sets and test data sets. The training data sets are used to adjust parameters and the test data sets are input for verification. If the results meet the requirements, the model training is completed; otherwise, the samples are reset and the training is repeated. Calling a third AI model and inputting data on the degree of impact on the personal rights and interests and the degree of security protection, determining the risk level of the personal information, and issuing risk warning information based on the risk level; The third AI model is based on a convolutional neural network and contains three convolutional layers. During training, the data set is divided into a training set and a test set. The parameters of subsequent convolutional layers and the first layer are adjusted in turn according to the output of each convolutional layer to complete the training of the convolutional neural network; the test set is input to determine whether the result meets the expectations. If so, the training is completed. If not, the training is restarted until the test set result meets the expectations.

2. The personal information risk warning method according to claim 1, characterized in that: The degree of impact on personal rights and interests is set to different preset levels according to the data processing type, wherein the data processing type includes: acquisition, use and dissemination of data.

3. The personal information risk warning method according to claim 2, characterized in that: The preset level is three levels, including: no risk found, risk or serious risk.

4. The personal information risk warning method according to claim 1, characterized in that: The risk level is determined based on parameters of the degree of impact on personal rights and interests and the degree of security protection.

5. The personal information risk warning method according to claim 1, characterized in that: The warning information includes: pop-up windows, prohibited operations, and light signals or sound signals.

6. A personal information risk warning device, characterized in that: include: A receiving module, configured to obtain the user's personal information data and the data processing type corresponding to the personal information data; A determination module is configured to invoke a first AI model and a second AI model and input the personal information data and data processing type to respectively determine the degree of impact on personal rights and interests corresponding to the personal information data and the degree of security protection corresponding to the degree of impact on personal rights and interests. The first and second AI models are pre-trained convolutional neural network models. During training, multiple data samples are first obtained and personal sensitive information in the data samples is deleted. The multiple sample data are then divided into a training data set and a test data set. The training data set is used to adjust parameters and the test data set is input for verification. If the results meet the requirements, model training is completed; otherwise, the samples are reset and training is repeated. a judgment module, configured to call a third AI model and input data on the degree of impact on personal rights and interests and the degree of security protection, determine the risk level of the personal information, and issue risk warning information based on the risk level; The third AI model is based on a convolutional neural network and contains three convolutional layers. During training, the data set is divided into a training set and a test set. The parameters of subsequent convolutional layers and the first layer are adjusted in turn according to the output of each convolutional layer to complete the training of the convolutional neural network; the test set is input to determine whether the result meets the expectations. If so, the training is completed. If not, the training is restarted until the test set result meets the expectations.

7. The personal information risk warning device according to claim 6, characterized in that: The degree of impact on personal rights and interests is set to different preset levels according to the data processing type, wherein the data processing type includes: acquisition, use and dissemination of data.

8. The personal information risk warning device according to claim 7, characterized in that: The preset level is three levels, including: no risk found, risk or serious risk.

9. The personal information risk warning device according to claim 6, characterized in that: The risk level is determined based on the highest risk item among the degree of impact on personal rights and interests or the degree of security protection.

10. The personal information risk warning device according to claim 6, characterized in that: The warning information includes: pop-up windows, prohibited operations, and light signals or sound signals.

Citation Information

Patent Citations

  • Mobile terminal authority control method based on information protection

    CN113158237A