A compliance analysis method and device, electronic equipment and storage medium are applied
By providing interactive pages and privacy-preserving computing technology on the server side, and deploying compliance and violation analysis models to the terminal, the accuracy and confidentiality issues of data compliance detection in business systems are resolved, enabling the assessment and simplification of enterprise data compliance processes without leaking trade secrets.
Patent Information
- Application Number
- CN202210579329.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-25
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2042-05-25
AI Technical Summary
In business systems, technical personnel lacking legal and regulatory knowledge struggle to accurately perform data compliance checks, and legal advice is often difficult to understand, leading to risks in data management. Existing technologies are insufficient to achieve comprehensive and accurate application compliance checks and confidentiality processing.
By employing privacy-preserving computing technology, the application type information is determined through an interactive page provided by the server. Pre-trained compliance and violation analysis models are deployed to the terminal for application analysis and compliance testing. Sandbox simulation of data rules and homomorphic encryption are used for matching analysis to ensure that trade secrets are not leaked.
It enables comprehensive and accurate application compliance testing without disclosing trade secrets, simplifies workflows, reduces costs, and ensures data security and the accuracy of compliance assessments.
Smart Images

Figure CN114996130B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the field of data security, and in particular to an application compliance analysis method and device, electronic equipment and storage medium. BACKGROUND
[0002] In many business system scenarios, a large amount of data needs to be processed, and these data need to be legally protected according to different national requirements and laws and regulations. The data processing process needs to be managed. The above process usually involves problems in different fields. Business technical personnel lack relevant legal and regulatory knowledge, and relevant regulations are often scattered, not systematic, subject to multi-party supervision, and described from a legal perspective, which can easily lead to inadequate understanding and execution by business technical personnel, and there is a certain risk in the execution of the entire system task. Legal personnel often lack technical knowledge, and the opinions and suggestions they give are often stereotyped and difficult to understand. For example, the Data Management Maturity Model (DCMM) helps enterprises to establish and evaluate their data management capabilities using advanced data management concepts and methods, continuously improve data management organizations, procedures and systems, and fully leverage data in promoting enterprise development towards informationization, digitization and intelligence. Relevant data security regulations and relevant local government digital regulations.
[0003] Therefore, how to comprehensively and accurately detect the compliance of an application and perform privacy protection during the detection process has become a problem to be solved. SUMMARY
[0004] Based on the above situation of the prior art, the purpose of embodiments of the present application is to provide an application compliance analysis method and device, electronic equipment and storage medium, which can detect the compliance of an application without leaking commercial secrets by using privacy protection computing technology.
[0005] To achieve the above purpose, according to one aspect of the present application, an application compliance analysis method is provided, applied to a server, comprising:
[0006] providing an interactive page, determining application type information of an application to be analyzed based on the interactive page, the application type information including scene information and location area information;
[0007] determining a trained application analysis model according to the application type information;
[0008] deploying the trained application analysis model to a terminal, so that the terminal analyzes the application to be analyzed by using the application analysis model to obtain an application analysis result;
[0009] receiving the application analysis result sent by the terminal to return feedback information.
[0010] Further, the trained application analysis model comprises a trained compliance analysis model and a trained violation analysis model.
[0011] The trained application analysis model is deployed to the terminal, so that the terminal uses the application analysis model to analyze the application to be analyzed, and obtains an application analysis result, comprising:
[0012] The trained compliance analysis model is sent to the terminal, so that the terminal uses the compliance analysis model to analyze the application to be analyzed, and obtains a compliance analysis result;
[0013] The trained violation analysis model is sent to the terminal, so that the terminal uses the violation analysis model to analyze the application to be analyzed, and obtains a violation analysis result;
[0014] The compliance analysis result and the violation analysis result are determined according to the compliance analysis result and the violation analysis result.
[0015] Further, it further comprises:
[0016] The trained compliance analysis model is split to obtain a plurality of compliance analysis sub-models, and type information of each compliance analysis sub-model is added to distinguish different compliance analysis sub-models;
[0017] The plurality of compliance analysis sub-models are sent to the terminal, so that the terminal uses the plurality of compliance analysis sub-models to analyze the application to be analyzed, and obtains a plurality of compliance sub-analysis results;
[0018] The plurality of compliance sub-analysis results sent by the terminal are received, and the compliance analysis result is determined according to the plurality of compliance sub-analysis results.
[0019] Further, it further comprises:
[0020] The trained violation analysis model is split to obtain a plurality of violation analysis sub-models, and type information of each violation analysis sub-model is added to distinguish different violation analysis sub-models;
[0021] The plurality of violation analysis sub-models are sent to the terminal, so that the terminal uses the plurality of violation analysis sub-models to analyze the application to be analyzed, and obtains a plurality of violation sub-analysis results;
[0022] The plurality of violation sub-analysis results sent by the terminal are received, and the violation analysis result is determined according to the plurality of violation sub-analysis results.
[0023] Further, the splitting comprises splitting the analysis model into a first sub-model corresponding to a data input link, a second sub-model corresponding to a data storage link, and a third sub-model corresponding to a data output link according to the detection content;
[0024] The analysis model comprises a compliance analysis model and a violation analysis model.
[0025] Further, the method further comprises:
[0026] The terminal deploys a sandbox to simulate data-related rules of the application to be analyzed in the sandbox, to determine input data of the application to be analyzed, and to input the input data into the compliance analysis model or the violation analysis model in the sandbox to determine an analysis result.
[0027] Further, the method further comprises:
[0028] The terminal deploys a preset standard application to the terminal to perform matching analysis on the application to be analyzed by using the preset standard application, to obtain a matching analysis result.
[0029] The data processing rule of the preset standard application is encrypted by using a homomorphic encryption method, to perform matching analysis on the terminal.
[0030] Further, the method further comprises:
[0031] The preset standard application is divided into multiple parts, and each part of the preset standard application is matched with a corresponding part of the application to be analyzed to determine whether each part of the application to be analyzed is consistent with the corresponding part of the preset standard application.
[0032] According to a second aspect of the present application, an application compliance analysis method is provided, which is applied to a terminal and comprises:
[0033] The terminal receives a compliance analysis model sent by a server, and performs compliance analysis on an application to be analyzed by using the compliance analysis model to obtain a compliance analysis result.
[0034] The terminal receives a violation analysis model sent by a server, and performs violation analysis on an application to be analyzed by using the violation analysis model to obtain a violation analysis result.
[0035] The terminal uploads the compliance analysis result and the violation analysis result to the server, to enable the server to obtain an application compliance comprehensive analysis result according to the compliance analysis result and the violation analysis result.
[0036] Further, the method further comprises:
[0037] The terminal receives one of multiple compliance analysis sub-models and one of multiple violation analysis sub-models sent by the server.
[0038] The terminal determines detection content according to type information of the compliance analysis sub-model, and performs analysis on the detection content of the application to be analyzed by using the compliance analysis sub-model to obtain a compliance sub-analysis result.
[0039] According to the type information of the violation analysis sub-model, the detection content is determined, the detection content of the application to be analyzed is analyzed by using the violation analysis sub-model, and a violation sub-analysis result is obtained;
[0040] The above steps are repeatedly performed until the plurality of compliance analysis sub-models and the plurality of violation analysis sub-models sent by the server are received and analyzed, and a plurality of compliance sub-analysis results and a plurality of violation sub-analysis results are obtained;
[0041] The plurality of compliance sub-analysis results and the plurality of violation sub-analysis results are uploaded to the server, so that the server determines a compliance analysis result according to the plurality of compliance sub-analysis results, and determines a violation analysis result according to the plurality of violation sub-analysis results.
[0042] According to a third aspect of the present application, an application compliance analysis device is provided, which is applied to a server and comprises:
[0043] An application type information determination module is configured to provide an interactive page, determine application type information of an application to be analyzed based on the interactive page, and the application type information comprises scene information and location area information;
[0044] An application analysis model determination module is configured to determine a trained application analysis model according to the application type information;
[0045] An application analysis model deployment module is configured to deploy the trained application analysis model to a terminal, so that the terminal analyzes the application to be analyzed by using the application analysis model, and obtains an application analysis result;
[0046] An application analysis result acquisition module is configured to receive the application analysis result sent by the terminal, and return feedback information.
[0047] According to a fourth aspect of the present application, an electronic device is provided, which comprises a memory, a processor, and executable instructions stored in the memory and executable on the processor, wherein the processor executes the program to realize the application compliance analysis method according to the first aspect of the present application, or the application compliance analysis method according to the second aspect of the present application.
[0048] According to a fifth aspect of the present application, a computer readable storage medium is provided, which stores computer executable instructions, wherein the executable instructions are executed by a processor to realize the application compliance analysis method according to the first aspect of the present application, or the application compliance analysis method according to the second aspect of the present application.
[0049] In summary, the embodiment of the present application provides an application compliance analysis method, device, electronic equipment and storage medium, the method comprises: providing an interactive page, determining the application type information of the application to be analyzed based on the interactive page; determining the trained application analysis model according to the application type information; deploying the trained application analysis model to the terminal; receiving the application analysis result sent by the terminal. The technical scheme of the embodiment of the present application provides the model of compliance analysis on the server side, and sends the model to the terminal with the application to be analyzed. The terminal obtains the compliance analysis model, the violation analysis model and the corresponding database template trained in the cloud (server side), and performs compliance analysis locally, so that the application to be detected does not need to be uploaded, the security of the application to be detected is ensured, the enterprise is helped to develop data management specifications without leaking the business secrets of the enterprise, and the data compliance process of the enterprise can also be evaluated without leaking the business secrets of the enterprise, thereby greatly simplifying the related work and reducing the cost. BRIEF DESCRIPTION OF DRAWINGS
[0050] Figure 1 is a flowchart of an application compliance analysis method provided by the embodiment of the present application;
[0051] Figure 2 is a block diagram of an application compliance analysis device provided by another embodiment of the present application;
[0052] Figure 3 is a block diagram of an application compliance analysis device provided by the embodiment of the present application;
[0053] Figure 4 is a block diagram of a server provided by the embodiment of the present application;
[0054] Figure 5 is a block diagram of an application compliance analysis device provided by another embodiment of the present application;
[0055] Figure 6 is a block diagram of a terminal provided by the embodiment of the present application;
[0056] Figure 7 is a structural schematic diagram of an application compliance analysis system provided by the embodiment of the present application;
[0057] Figure 8 is a structural schematic diagram of an electronic equipment provided by the embodiment of the present application. DETAILED DESCRIPTION
[0058] In order to make the objects, technical solutions and advantages of the present application clearer, the present application will be described in further detail below with reference to the embodiments and drawings. It should be understood that the description is only exemplary and is not intended to limit the scope of the present application. In addition, in the following description, the description of well-known structures and techniques is omitted to avoid unnecessary confusion of the concept of the present application.
[0059] It should be noted that, unless otherwise defined, technical terms or scientific terms used in one or more embodiments of the present application should be understood as their ordinary meaning to those skilled in the art to which the present disclosure belongs. The terms "first", "second" and similar terms used in one or more embodiments of the present application do not represent any order, number or importance, but are only used to distinguish different components. The terms "include" or "contain" and similar terms mean that the elements or objects before the terms cover the elements or objects listed after the terms and their equivalents, and do not exclude other elements or objects. The terms "connect" or "connected" and similar terms are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. The terms "up", "down", "left", "right" and the like are only used to represent relative positional relationships, and when the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0060] Based on the above background art, in order to facilitate the evaluation of the policy of the business system, the purpose of the embodiments of the present application is to establish a fair and reliable third-party agency that does not disclose information, which analyzes and calculates the application compliance. The agency sets up a server for providing a compliance analysis model, and sends the model to a terminal with an application to be analyzed. The terminal obtains the compliance analysis model, the violation analysis model and the corresponding database template trained in the cloud (server), and performs compliance analysis locally, so as to ensure the security of the application to be detected without uploading the application to be analyzed. The present application helps enterprises to develop data management specifications without leaking the business secrets of the enterprise, and thus can also evaluate the data compliance process of the enterprise without leaking the business secrets of the enterprise, thereby greatly simplifying the related work and reducing the cost.
[0061] The technical solutions of the present application will be described in detail below with reference to the drawings. In the embodiments of the present application, an application compliance analysis method is provided, which can be applied to a server, Figure 1 The flowchart of the application compliance analysis method is shown in FIG. 1, and the application compliance analysis method 100 includes the following steps:
[0062] S102, provide an interaction page, determine application type information of the application to be analyzed based on the interaction page, the application type information includes scene information and location area information. The interaction page is provided to a user who needs to perform compliance analysis on the application to be analyzed, for example, the user can provide the application to be analyzed through an input control on the interaction page or other input methods. The application type information of the application to be analyzed is determined based on the interaction page. The type information can be determined according to the related information of the application to be analyzed, and can include industry application scene information (such as medical treatment, transportation, finance, e-commerce, logistics, and education, etc.) related to the application and location area information (such as location area information of each province and each country, etc.), so that the application analysis model adopted can be selected according to the application type information.
[0063] S104, determine the trained application analysis model according to the application type information. The trained application analysis model includes a trained compliance analysis model and a trained violation analysis model. The compliance analysis model can be obtained through the following training steps:
[0064] S1041, obtain compliance related data. The compliance related data can be obtained by collecting case data of compliance applications, and performing semantic recognition on the compliance related data, such as natural language processing (Natural Language Processing, hereinafter referred to as "NLP") conversion, to determine application compliance rules, the compliance related data includes at least one of policy related data, regulation related data and compliance application case data, and the application compliance rules include at least one of data flow specification, privacy declaration specification and permission obtaining rule. In this step, by collecting data such as policies, laws and regulations, and compliance application cases, and through NLP conversion, combined with manual review, positive sample data in the template library is formed. The positive sample data can be understood as the rules of application compliance, wherein the rules can include data flow specification, privacy declaration specification, permission obtaining rule, etc. The NLP conversion learns and trains the templates in the basic template library and the collected library information in an artificial intelligence manner, and combines artificial judgment to establish a relationship between whether the field and corresponding technology of each template application comply with laws and regulations.
[0065] S1042, split the application compliance rules to obtain first input data and first annotation results.
[0066] S1043, input the first input data into the compliance analysis model to determine a first analysis result.
[0067] S1044, adjust the compliance analysis model according to the first analysis result and the first annotation result to determine the trained compliance analysis model.
[0068] In each of the above training steps, compliance-related data is obtained by collecting application case data to which compliance rules are applied, and the compliance analysis model is trained using the compliance-related data and in combination with the application compliance rules. As a result of the training, an automated judgment model between the template and the compliance of the laws and regulations is established, and the results of the model judgment can be intervened and / or adjusted by humans. On this basis, artificial intelligence can also be further used for processing to obtain an improved model. When the rules change or new cases appear, re-learning training can be started. The violation analysis model can be obtained through the following training steps:
[0069] S1045, obtain violation-related data, and perform semantic recognition on the violation-related data to determine the application of violation rules, wherein the violation-related data includes violation application case data, and the application of violation rules includes at least one of data flow violation information, privacy statement violation information, and permission request violation rules. In this step, the case data of the application of the violation is collected, the data is converted by NLP, and negative sample data is generated by combining human review.
[0070] S1046, split the application of violation rules to obtain second input data and second annotation results.
[0071] S1047, input the second input data into the violation analysis model to determine a second analysis result.
[0072] S1048, adjust the violation analysis model according to the second analysis result and the second annotation result to determine a trained violation analysis model.
[0073] The training steps of the violation analysis model are similar to the training steps of the compliance analysis model described above, except that the data obtained is violation-related data. The application of violation rules is determined by collecting violation application case data and performing semantic recognition on the compliance-related data, such as NLP conversion, to reflect application cases that may violate rules. In this step, negative sample data in the template library is formed by collecting data such as violation of policies and laws and regulations, and violation application cases, and by NLP conversion combined with human review. Negative sample data can be understood as a situation of application violation. The same parts as the training steps of the compliance analysis model are not described again.
[0074] S106, deploy the trained application analysis model to the terminal to enable the terminal to analyze the application to be analyzed using the application analysis model to obtain an application analysis result. This step can be specifically:
[0075] S1061, send the trained compliance analysis model to the terminal to enable the terminal to perform compliance analysis on the application to be analyzed using the compliance analysis model to obtain a compliance analysis result.
[0076] S1062. Send the trained violation analysis model to the terminal so that the terminal can use the violation analysis model to perform violation analysis on the application to be analyzed and obtain the violation analysis results.
[0077] S1063. Determine the application analysis results based on the compliance analysis results and the violation analysis results.
[0078] S108. Receive application analysis results sent by the receiving terminal and return feedback information. This feedback information may include modification suggestions for non-compliance, policy information related to non-compliant content, or compliance certification information for compliant content.
[0079] According to certain optional embodiments, the trained compliance analysis model can be further split into multiple compliance analysis sub-models, and type information of each compliance analysis sub-model can be added to distinguish different compliance analysis sub-models. These multiple compliance analysis sub-models are then sent to a terminal, allowing the terminal to analyze the application under analysis using these sub-models and obtain multiple compliance sub-analysis results. The terminal receives these multiple compliance sub-analysis results and determines the compliance analysis result based on them. Alternatively, the trained violation analysis model can be split into multiple violation analysis sub-models, and type information of each violation analysis sub-model can be added to distinguish different violation analysis sub-models. These multiple violation analysis sub-models are then sent to a terminal, allowing the terminal to analyze the application under analysis using these sub-models and obtain multiple violation sub-analysis results. The terminal receives these multiple violation sub-analysis results and determines the violation analysis result based on them. In this embodiment of the invention, the analysis model can also be split according to the detection content. For example, the analysis model can be split into a first sub-model corresponding to the data input stage, a second sub-model corresponding to the data storage stage, a third sub-model corresponding to the data output stage, and so on. Other splitting methods can also be adopted, such as splitting according to the type of detection data. By splitting the compliance analysis model and the violation analysis model into multiple sub-models, the security of the model can be improved, and one sub-model can be used for calculation at a time, reducing the computational burden on the terminal device.
[0080] This embodiment of the invention can also deploy a sandbox on the terminal, so that the terminal can simulate the data-related rules of the application to be analyzed in the sandbox, thereby determining the input data of the application to be analyzed, and inputting the input data into the compliance analysis model or violation analysis model in the sandbox to determine the analysis results.
[0081] According to some optional embodiments, the method can further include deploying a preset standard application to the terminal, so that the terminal performs matching analysis on the application to be analyzed by using the preset standard application, to obtain a matching analysis result; and a data processing rule of the preset standard application is encrypted by using a homomorphic encryption manner, so that the terminal performs the matching analysis. The preset standard application can be a compliance application that has been verified (or an application that has not been verified, a non-compliance application, etc.), and the matching analysis on the application to be analyzed is performed by using the preset standard application. If the two are consistent, the application to be analyzed can be considered as a compliance application. If the two are inconsistent, further verification analysis can be performed on the application to be analyzed by using other manners. In this embodiment, the preset standard application can be divided into multiple parts, so that the terminal performs matching analysis on each part of the preset standard application and a corresponding part of the application to be analyzed, to determine whether the parts of the application to be analyzed are consistent with the corresponding parts of the preset standard application. The multiple parts can be divided according to the processing process of the application, for example, the preset standard application is divided into a data acquisition related part, a data storage related part, and a data output related part. When performing the matching analysis, the data acquisition related part, the data storage related part, and the data output related part of the application to be analyzed are matched with the corresponding parts of the preset standard application, respectively, to determine whether each part is consistent. If some parts are inconsistent, further analysis can be performed on the inconsistent parts, thereby improving the efficiency of the application compliance analysis.
[0082] Embodiments of the application also provide an application compliance analysis method, which can be applied to a terminal, Figure 2 A flowchart of the application compliance analysis method is shown in the terminal, and the application compliance analysis method 200 includes the following steps:
[0083] S202, receiving a compliance analysis model sent by a server, and performing compliance analysis on an application to be analyzed by using the compliance analysis model to obtain a compliance analysis result.
[0084] S204, receiving a violation analysis model sent by a server, and performing violation analysis on an application to be analyzed by using the violation analysis model to obtain a violation analysis result.
[0085] S206, uploading the compliance analysis result and the violation analysis result to the server, so that the server obtains an application compliance comprehensive analysis result according to the compliance analysis result and the violation analysis result.
[0086] According to some optional embodiments, the method further comprises: receiving one of the plurality of compliance analysis sub-models and one of the plurality of violation analysis sub-models sent by the server; determining the detection content according to the type information of the compliance analysis sub-model, and using the compliance analysis sub-model to analyze the detection content of the application to be analyzed to obtain a compliance sub-analysis result; determining the detection content according to the type information of the violation analysis sub-model, and using the violation analysis sub-model to analyze the detection content of the application to be analyzed to obtain a violation sub-analysis result; repeating the above steps until the plurality of compliance analysis sub-models and the plurality of violation analysis sub-models sent by the server are received and analyzed, and a plurality of compliance sub-analysis results and a plurality of violation sub-analysis results are obtained; uploading the plurality of compliance sub-analysis results and the plurality of violation sub-analysis results to the server, so that the server determines a compliance analysis result according to the plurality of compliance sub-analysis results and determines a violation analysis result according to the plurality of violation sub-analysis results. The type information of the sub-model can be determined according to the application-related information, which can include application-related industry domain information (such as medical, transportation, financial, e-commerce, logistics, and education industry domain information) and location area information (such as provincial and national location area information). According to the type information added in the sub-model, the detection content corresponding to the compliance analysis sub-model or the violation analysis sub-model is determined, and the corresponding detection content is detected.
[0087] Embodiments of the application also provide an application compliance analysis device, which can be applied to a server, Figure 3 The application compliance analysis device is shown in the block diagram of the application compliance analysis device 300, which comprises:
[0088] The application type information determination module 301 is configured to provide an interactive page, determine the application type information of the application to be analyzed based on the interactive page, and the application type information comprises scene information and location area information.
[0089] The application analysis model determination module 302 is configured to determine the trained application analysis model according to the application type information.
[0090] The application analysis model deployment module 303 is configured to deploy the trained application analysis model to the terminal, so that the terminal uses the application analysis model to analyze the application to be analyzed to obtain an application analysis result.
[0091] The application analysis result acquisition module 304 is configured to receive the application analysis result sent by the terminal to return feedback information.
[0092] The server can also be provided with the following modules as the basis for the application compliance analysis of the application compliance analysis device 300, Figure 4 The block diagram of the server is shown in the block diagram of the server:
[0093] The template library module can include a large number of basic process regulation templates suitable for different fields, different industries, different businesses, different countries, different regions and localities, and these templates are the basis of other work.
[0094] The information collection module can collect relevant policy and regulation cases, technical scheme cases and the like through a special interface, manual input and the like, and save them into the corresponding template library.
[0095] The artificial intelligence natural language processing module (hereinafter referred to as "AI NLP module") has an artificial decision interface, and the result of AI analysis needs to be revised by personnel. The AI NLP module establishes the association between the templates in the template library and the relevant information through NLP + artificial analysis, including but not limited to: specific templates corresponding to policies, regulations, cases and technologies, and processes in specific regions that conform to the regulations and processes that do not conform to the regulations.
[0096] The security fusion computing center module is used to realize joint calculation of the server and the local terminal.
[0097] The embodiments of the application also provide an application compliance analysis device which can be applied to a terminal, Figure 5 The constituent block diagram of the application compliance analysis device is shown in the figure, and the device 500 includes:
[0098] The compliance analysis module 501 is used to receive a compliance analysis model sent by a server, and perform compliance analysis on an application to be analyzed by using the compliance analysis model to obtain a compliance analysis result.
[0099] The violation analysis module 502 receives a violation analysis model sent by a server, and performs violation analysis on an application to be analyzed by using the violation analysis model to obtain a violation analysis result.
[0100] The analysis result uploading module 503 is used to upload the compliance analysis result and the violation analysis result to the server, so that the server obtains an application compliance comprehensive analysis result according to the compliance analysis result and the violation analysis result.
[0101] The terminal can also be provided with the following modules to serve as the basis of the application compliance analysis device 500 for performing application compliance analysis, Figure 6 The constituent block diagram of the terminal is shown in the figure:
[0102] The artificial input module sets an input interface on the client terminal, and is used to input relevant information of data flow processing, such as information required by data flow rules, including company name, field, industry, region and country.
[0103] The virtual operation module can use an automatic access script or a real account of the client system to simulate the whole business process and obtain information related to data flow in the business.
[0104] The management module sets a management interface of the client, and is used to start relevant operations, review the collected data, determine whether the data are accurate, whether missing information needs to be supplemented, whether the client participates in the evaluation, and the like.
[0105] The secure fusion local computing unit module is jointly calculated with the secure fusion computing center module of the server under the management of the management module, obtains the services provided by the server for the client by using the data information of the server without leaking the commercial secrets of the client, and generates the basic specification by using the information input by the human and the information collected by the virtual operation module.
[0106] The generated basic specification often has problems, and the client terminal can also modify and adjust the specification according to the situation of the client terminal. The adjusted specification can be analyzed for compliance degree and risk factors by the method provided in the embodiments of the application. In addition, the data obtained by the virtual operation module and the specification modified by the client can be used for further evaluation.
[0107] The specific functions and operations of each module in the application compliance analysis device 300 and the application compliance analysis device 500 have been described in detail in the application compliance analysis method of the above embodiments, and therefore, the repeated description will be omitted here.
[0108] The embodiments of the application also provide an application compliance analysis system, Figure 7 The structure of the application compliance analysis system 700 is shown in a schematic diagram, and the system includes:
[0109] The server 701 and the at least one terminal 702. The server 701 and the at least one terminal 702, and each terminal 702 can be connected to each other through a network. The server 701 and the at least one terminal 702 can be the server and the terminal in the above embodiments. The server 701 sends a compliance analysis model and a violation analysis model, or multiple compliance analysis sub-models and violation analysis sub-models to the at least one terminal 702, and the terminal 702 uploads a compliance analysis result and a violation analysis result, or multiple compliance analysis sub-results and violation analysis sub-results to the server 701. Through the interaction between the server 701 and the at least one terminal 702, the application compliance analysis method in the above embodiments of the application is realized.
[0110] In the embodiments of the application, an electronic device is also provided, which includes a memory, a processor, and executable instructions stored in the memory and executable on the processor. When the processor executes the program, the application compliance analysis method described in the above embodiments of the application is realized. Figure 8A structural diagram of an electronic device 800 provided by this embodiment of the present application is shown. As shown in the figure Figure 8 As shown, the electronic device 800 includes one or more processors 801 and a memory 802, and computer-executable instructions stored in the memory 802, which, when executed by the processor 801, cause the processor 801 to perform the application compliance analysis method of the above embodiment. The processor 801 can be a central processing unit (CPU) or other form of processing unit having data processing and / or instruction executing capabilities, and can control other components in the electronic device to perform desired functions. The memory 802 can include one or more computer program products, which can include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM), cache, and / or the like. The non-volatile memory may, for example, include read-only memory (ROM), hard disk, flash memory, and / or the like. One or more computer program instructions can be stored on the computer-readable storage medium, and the processor 801 can execute the program instructions to implement the steps in the application compliance analysis method of the above embodiment of the present application and / or other desired functions.
[0111] The embodiments of the present application also provide a computer readable storage medium, which stores computer executable instructions, and the executable instructions are executed by a processor to implement the application compliance analysis method according to the above embodiments. The computer readable storage medium can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium may, for example, include but is not limited to an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination thereof. More specific examples (non-exhaustive list) of the readable storage medium include an electrical connection having one or more wires, a portable disc, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. It should be understood that the processor in the embodiments of the present application can be a central processing unit (CPU), and the processor can also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.
[0112] To sum up, the present application relates to an application compliance analysis method, device, electronic equipment and storage medium, the method comprising: providing an interactive page, determining application type information of an application to be analyzed based on the interactive page; determining a trained application analysis model according to the application type information; deploying the trained application analysis model to a terminal; and receiving an application analysis result sent by the terminal. The technical scheme of the embodiments of the present application provides a model for compliance analysis on the server side, and sends the model to a terminal with an application to be analyzed. The terminal performs compliance analysis locally by obtaining a compliance analysis model, a violation analysis model and a corresponding database template trained on the cloud (server side), thereby ensuring the security of the application to be detected without uploading the application to be analyzed, helping enterprises to develop data management specifications without leaking the commercial secrets of the enterprise, and further enabling the evaluation of the data compliance process of the enterprise without leaking the commercial secrets of the enterprise, thereby greatly simplifying the related work and reducing the cost.
[0113] It should be understood that all the above-described embodiments are merely exemplary and are not intended to limit the scope of the present application (including claims) to these examples; the technical features among the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other changes of different aspects of one or more embodiments of the present application as described above, which are not provided in details for the sake of simplicity. The above detailed description of the present application merely serves to illustrate or explain the principles of the present application, and does not constitute a limitation on the present application. Therefore, any modification, equivalent replacement, improvement, etc. made without departing from the spirit and scope of the present application shall be included in the protection scope of the present application. In addition, the claims of the present application are intended to cover all changes and modifications falling within the scope and boundary of the appended claims, or the equivalent forms of such scope and boundary.
Claims
1. A method for application compliance analysis, the method comprising: Applied to a server, comprising: Providing an interactive page, determining application type information of an application to be analyzed based on the interactive page, the application type information including scene information and location area information; Determine the trained application analysis model according to the application type information; Deploy the trained application analysis model to the terminal, so that the terminal adopts the application analysis model to analyze the application to be analyzed, and obtains the application analysis result; the trained application analysis model includes a trained compliance analysis model and a trained violation analysis model; the compliance analysis model obtains compliance data by collecting case data of compliant applications, and is trained and obtained by combining application compliance rules; the violation analysis model obtains violation data by collecting case data of violation applications, and is trained and obtained by combining application violation rules; Receive the application analysis result sent by the terminal to return feedback information; further comprising: Split the trained compliance analysis model to obtain multiple compliance analysis sub-models, and add type information of each compliance analysis sub-model to distinguish different compliance analysis sub-models; split the trained violation analysis model to obtain multiple violation analysis sub-models, and add type information of each violation analysis sub-model to distinguish different violation analysis sub-models; The splitting includes splitting the analysis model into a first sub-model corresponding to a data input link, a second sub-model corresponding to a data storage link, and a third sub-model corresponding to a data output link according to the detection content; the analysis model includes a compliance analysis model and a violation analysis model.
2. The method of claim 1, wherein, The trained application analysis model is deployed to the terminal to make the terminal adopt the application analysis model to analyze the application to be analyzed, and obtain the application analysis result, comprising: Send the trained compliance analysis model to the terminal to make the terminal adopt the compliance analysis model to analyze the compliance of the application to be analyzed, and obtain the compliance analysis result; Send the trained violation analysis model to the terminal to make the terminal adopt the violation analysis model to analyze the violation of the application to be analyzed, and obtain the violation analysis result; Determine the application analysis result according to the compliance analysis result and the violation analysis result.
3. The method of claim 1, wherein, Further comprising: Send multiple compliance analysis sub-models to the terminal to make the terminal adopt multiple compliance analysis sub-models to analyze the application to be analyzed, and obtain multiple compliance sub-analysis results; Receive the multiple compliance sub-analysis results sent by the terminal, and determine the compliance analysis result according to the multiple compliance sub-analysis results.
4. The method of claim 1, wherein, Further comprising: Send multiple violation analysis sub-models to the terminal to make the terminal adopt multiple violation analysis sub-models to analyze the application to be analyzed, and obtain multiple violation sub-analysis results; Receive the multiple violation sub-analysis results sent by the terminal, and determine the violation analysis result according to the multiple violation sub-analysis results.
5. The method of claim 1, wherein, Further comprising: Deploy a sandbox in the terminal to make the terminal simulate data-related rules of the application to be analyzed in the sandbox, and then determine the input data of the application to be analyzed, and input the input data into the compliance analysis model or the violation analysis model in the sandbox to determine the analysis result.
6. The method of claim 1, wherein, Further comprising: The preset standard application is deployed to the terminal, so that the terminal uses the preset standard application to perform matching analysis on the application to be analyzed, and obtains a matching analysis result; The data processing rule of the preset standard application is encrypted by a homomorphic encryption method, so as to perform matching analysis on the terminal.
7. The method of claim 6, wherein, Further comprising: The preset standard application is divided into multiple parts, so that the terminal uses each part of the preset standard application to perform matching analysis on the corresponding part of the application to be analyzed, to determine whether each part of the application to be analyzed is consistent with the corresponding part of the preset standard application.
8. A method for application compliance analysis, the method comprising: Applied to the terminal, comprising: Receiving the compliance analysis model sent by the server, using the compliance analysis model to perform compliance analysis on the application to be analyzed, and obtaining a compliance analysis result; Receiving the violation analysis model sent by the server, using the violation analysis model to perform violation analysis on the application to be analyzed, and obtaining a violation analysis result; The compliance analysis model is obtained by collecting case data of compliance applications, training with compliance data, and combining application compliance rules; the violation analysis model is obtained by collecting case data of violation applications, training with violation data, and combining application violation rules; Uploading the compliance analysis result and the violation analysis result to the server, so that the server obtains an application compliance comprehensive analysis result according to the compliance analysis result and the violation analysis result; further comprising: Receiving one of the multiple compliance analysis sub-models and one of the multiple violation analysis sub-models sent by the server; According to the type information of the compliance analysis sub-model, the detection content is determined, and the compliance analysis sub-model is used to analyze the detection content of the application to be analyzed, to obtain a compliance sub-analysis result; According to the type information of the violation analysis sub-model, the detection content is determined, and the violation analysis sub-model is used to analyze the detection content of the application to be analyzed, to obtain a violation sub-analysis result; Repeat the above steps until the multiple compliance analysis sub-models and the multiple violation analysis sub-models sent by the server are received and analyzed, to obtain multiple compliance sub-analysis results and multiple violation sub-analysis results.
9. The method of claim 8, wherein, Further comprising: Uploading the multiple compliance sub-analysis results and the multiple violation sub-analysis results to the server, so that the server determines the compliance analysis result according to the multiple compliance sub-analysis results, and determines the violation analysis result according to the multiple violation sub-analysis results.
10. An application compliance analysis apparatus characterized by comprising: Applied to the server, comprising: An application type information determination module for providing an interactive page, determining the application type information of the application to be analyzed based on the interactive page, the application type information including scene information and location area information; An application analysis model determination module for determining a trained application analysis model according to the application type information; The application analysis model deployment module is configured to deploy the trained application analysis model to the terminal, so that the terminal uses the application analysis model to analyze the application to be analyzed to obtain an application analysis result; the trained application analysis model includes a trained compliance analysis model and a trained violation analysis model; the compliance analysis model is obtained by collecting case data of compliant applications to obtain compliance data, and is trained using the compliance data and combined with application compliance rules; the violation analysis model is obtained by collecting case data of non-compliant applications to obtain violation data, and is trained using the violation data and combined with application violation rules; and the application compliance analysis method further includes: The trained compliance analysis model is split to obtain a plurality of compliance analysis sub-models, and type information of each compliance analysis sub-model is added to distinguish different compliance analysis sub-models; the trained violation analysis model is split to obtain a plurality of violation analysis sub-models, and type information of each violation analysis sub-model is added to distinguish different violation analysis sub-models; the splitting includes splitting the analysis model into a first sub-model corresponding to a data input link, a second sub-model corresponding to a data storage link, and a third sub-model corresponding to a data output link according to the detection content; and the analysis model includes the compliance analysis model and the violation analysis model; The application analysis result acquisition module is configured to receive the application analysis result sent by the terminal to return feedback information.
11. An electronic device comprising a memory, a processor, and executable instructions stored on the memory and executable on the processor, wherein: The processor executes the executable instructions to implement the application compliance analysis method of any one of claims 1-7, or the application compliance analysis method of any one of claims 8-9.
12. A computer-readable storage medium having stored thereon computer- executable instructions, wherein, The executable instructions are executed by the processor to implement the application compliance analysis method of any one of claims 1-7, or the application compliance analysis method of any one of claims 8-9.
Citation Information
Patent Citations
Website security detection method and device and storage medium
CN111314291A
Business processing method, device and apparatus
CN113435585A
Method, system and device for determining illegal application program and readable storage medium
CN113691492A