Method for generating privacy protocol family for application, client device and server
Through the collaborative work of client devices and servers, the application's privacy protocol family is automatically generated, solving the problems of long time, high cost and low accuracy caused by manual writing, and achieving fast and accurate privacy protocol family generation and version difference processing.
Patent Information
- Application Number
- CN202111223312.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-20
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2041-10-20
AI Technical Summary
The privacy protocol family that generates applications in the prior art requires manual writing, resulting in long time, high cost and low accuracy.
Through the collaborative work of the client device, the first server and the second server, the privacy behavior of the target application using personal data during operation is automatically captured, and the target privacy protocol family is generated, including data traffic analysis, data retention monitoring and SDK detection, etc., to ensure accuracy and efficiency.
The rapid generation of the target privacy protocol family is achieved, reducing generation costs, improving accuracy, and supporting the differential analysis and correction of new and old versions, avoiding tedious manual processes.
Smart Images

Figure CN115994379B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of privacy technology, and in particular to a method for generating a privacy protocol family for an application, a client device, and a server. Background Art
[0002] As users attach increasing importance to their privacy rights, numerous laws and regulations require that apps display their privacy protocols to users, effectively protecting their privacy rights when using various apps. This protocol provides the app with a textual explanation of the user's privacy rights and interests. This protocol may include a privacy statement, user agreement, and privacy requirements.
[0003] Currently, developers often manually write privacy protocols for their applications. Figure 1 , Figure 1 FIG. 1 shows a flow chart of a privacy protocol family for generating an application in a related art. Figure 1 As shown, in related technologies, R&D personnel need to intervene in the early stages of application development. The specific process of writing and generating the privacy protocol family for the application includes:
[0004] During the application design phase, developers can differentiate user scenarios and obtain corresponding user data definitions. Based on the user data definitions and in conjunction with relevant legal and regulatory requirements, a privacy policy is drafted by a professional privacy representative within the R&D team, and then confirmed by a professional privacy legal representative within the R&D team. This creates the application's privacy protocol family. Ultimately, developers can integrate the application's privacy protocol family into the application's installation package (or release package), and during the application's online release phase, the application's privacy protocol family will be available to users as the application's version is released.
[0005] However, the solutions of related technologies run through the entire development stage of the application and require privacy analysis by professionals, resulting in a long time, high investment cost and low accuracy in generating privacy protocol families. Summary of the Invention
[0006] The present application provides a privacy protocol family generation method, client device and server for an application, which can automatically generate a target privacy protocol family, and can solve the problems of long time, high cost and poor accuracy caused by manually writing privacy protocol families.
[0007] In a first aspect, the present application provides a method for generating a privacy protocol family for an application, which is applied to a client device.
[0008] The method includes:
[0009] After the client device runs the target application, the first personal data of the target application in the client device is obtained;
[0010] After determining that the first privacy behavior uses the first personal data, the client device sends first information to the second server, where the first information is used to describe the privacy situation in which the first privacy behavior uses the first personal data. The first privacy behavior includes all behaviors of all applications on the client device that require the use of personal data.
[0011] The client device sends the first personal data to the first server, so that the first server determines the second personal data of the target application in the first server based on the first personal data, and after determining that the second privacy behavior uses the second personal data, sends second information to the second server, where the second information is used to describe the privacy situation of the second privacy behavior using the second personal data. The second privacy behavior includes all behaviors of all applications in the first server that require the use of personal data.
[0012] The client device receives a target privacy protocol family from the second server, where the target privacy protocol family is generated by the second server based on the first information and the second information;
[0013] The client device stores the target privacy protocol family in the installation package of the target application, so that the target application can display the target privacy protocol family to the user after being started.
[0014] Through the privacy protocol family generation method of the application provided in the first aspect, based on the mutual cooperation between the client device, the first server and the second server, the client device and the first server adopt methods such as data flow analysis, data retention monitoring, SDK detection and data cross-border detection, etc., to capture all privacy behaviors that use personal data during the operation of the target application. The client device and the first server transmit the information corresponding to the aforementioned privacy situation to the second server, so that the second server can accurately and quickly generate the target privacy protocol family based on the user's privacy rights and interests in the target application represented by the aforementioned information. Thus, the automatic generation of the target privacy protocol family is achieved, avoiding the tedious process of the development stage of the associated application and the development and online stage of the bound application, shortening the time cost of generating the target privacy protocol family, reducing the investment cost of generating the target privacy protocol family, and improving the accuracy of generating the target privacy protocol family.
[0015] In one possible design, the client device runs a target application, including:
[0016] The client device receives the installation package of the target application;
[0017] When the client device determines that the installation package of the target application is not a new version, it runs the installation package of the target application.
[0018] In one possible design, the method further includes:
[0019] When the client device determines that the installation package of the target application is a new version, the client device sends the installation package of the target application to the second server;
[0020] The client device receives a target privacy protocol family corresponding to the new version from the second server. The target privacy protocol family corresponding to the new version is obtained by the second server determining the differences between the new and old versions based on the installation package of the target application, and updating the target privacy protocol family corresponding to the old version based on the differences.
[0021] The client device updates the target privacy protocol family corresponding to the old version in the installation package of the target application to the target privacy protocol family corresponding to the new version, so that the client device displays the target privacy protocol family corresponding to the new version after the target application is started.
[0022] In one possible design, the method further includes:
[0023] The client device displays the entire content of the target privacy protocol family;
[0024] The client device receives the revised content of the target privacy protocol family;
[0025] The client device updates the target privacy protocol family in the installation package of the target application based on the revised content to obtain the revised target privacy protocol family, so that the target application can display the revised target privacy protocol family to the user after startup;
[0026] The client device sends the revised target privacy protocol family to the second server, so that the second server updates the target privacy protocol family to the revised target privacy protocol family.
[0027] In one possible design, when the first privacy behavior includes: a sensitive behavior and a control operation, after determining that the first privacy behavior uses the first personal data, the client device sends first information to the second server, including:
[0028] After determining that the sensitive behavior uses the first personal data, the client device determines that the first information includes an identifier of the sensitive behavior and the content and identifier of the first personal data used in the sensitive behavior, and sends the identifier of the sensitive behavior and the content and identifier of the first personal data used in the sensitive behavior to the second server;
[0029] And / or, after determining that the control operation uses the first personal data, the client device determines that the first information includes the identifier of the control operation and the content and identifier of the first personal data used by the control operation, and sends the identifier of the control operation and the content and identifier of the first personal data used by the control operation to the second server.
[0030] In one possible design, when the first privacy behavior includes a disclosure behavior, after determining that the first privacy behavior uses the first personal data, the client device sends first information to the second server, including:
[0031] The client device determines data disclosure status of the target application in the client device based on the content and identifier of the first personal data;
[0032] After determining, based on the data disclosure status of the target application in the client device, that the disclosure behavior uses the first personal data, the client device determines that the first information includes an identifier of the disclosure behavior and the content and identifier of the first personal data used in the disclosure behavior;
[0033] The client device sends an identifier of the disclosure behavior and the content and identifier of the first personal data used in the disclosure behavior to the second server.
[0034] In one possible design, when the first privacy behavior includes a cross-border behavior, after determining that the first privacy behavior uses the first personal data, the client device sends first information to the second server, including:
[0035] The client device determines the cross-border status of data of the target application in the client device based on the content and identifier of the first personal data;
[0036] After the client device determines that the cross-border behavior uses the first personal data based on the cross-border data situation of the target application in the client device, the client device determines that the first information includes an identifier of the cross-border behavior and the content and identifier of the first personal data used in the cross-border behavior;
[0037] The client device sends the identifier of the cross-border behavior and the content and identifier of the first personal data used for the cross-border behavior to the second server.
[0038] In one possible design, when the second privacy behavior includes: a rights behavior and a retention behavior, the second information includes: an identifier of the rights behavior and the content and identifier of the second personal data used in the rights behavior, and / or an identifier of the retention behavior and the content and identifier of the second personal data used in the retention behavior;
[0039] Among them, the identification of the right behavior and the content and identification of the second personal data used by the right behavior are sent by the first server after the first server determines that the right behavior uses the second personal data based on the data retention status of the target application in the first server. The identification of the retention behavior and the content and identification of the second personal data used by the retention behavior are sent by the first server after the first server determines that the retention behavior uses the second personal data based on the data retention status of the target application in the first server. The data retention status of the target application in the first server is determined by the first server based on the content and identification of the second personal data.
[0040] In a possible design, when the second privacy behavior includes: a disclosure behavior, the method further includes:
[0041] The client device receives, from the first server, an identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior, included in the second information. The identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior are sent by the first server after determining, based on data disclosure status of the target application in the first server, that the disclosure behavior uses the second personal data. The data disclosure status of the target application in the first server is determined by the first server based on the content and identifier of the second personal data.
[0042] The client device sends an identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior to the second server.
[0043] In a possible design, when the second privacy behavior includes: cross-border behavior, the method further includes:
[0044] The client device receives, from the first server, an identifier of the cross-border behavior and the content and identifier of the second personal data used in the cross-border behavior, included in the second information. The identifier of the cross-border behavior and the content and identifier of the second personal data used in the cross-border behavior are sent by the first server after determining, based on the cross-border status of data of the target application in the first server, that the cross-border behavior uses the second personal data. The cross-border status of data of the target application in the first server is determined by the first server based on the content and identifier of the second personal data.
[0045] The client device sends the identifier of the cross-border behavior and the content and identifier of the second personal data used for the cross-border behavior to the second server.
[0046] In a second aspect, the present application provides a method for generating a privacy protocol family for an application, which is applied to a first server.
[0047] The method includes:
[0048] The first server receives, from the client device, first personal data of the target application in the client device, where the first personal data is obtained by the client device after running the target application;
[0049] The first server determines, based on the first personal data, second personal data of the target application in the first server;
[0050] After determining that the second privacy behavior uses the second personal data, the first server sends second information to the second server. The second information is used to describe the privacy situation of the second privacy behavior using the second personal data. The second privacy behavior includes all behaviors of all applications in the first server that need to use personal data, so that the second server generates a target privacy protocol family based on the first information and the second information, and sends the target privacy protocol family to the client device. The target privacy protocol family is used by the client device to store in the installation package of the target application, so that the target application can display the target privacy protocol family to the user after startup. The first information is sent to the second server by the client device after determining that the first privacy behavior uses the first personal data. The first information is used to describe the privacy situation of the first privacy behavior using the first personal data. The first privacy behavior includes all behaviors of all applications in the client device that need to use personal data.
[0051] In one possible design, when the second privacy behavior includes: a rights behavior and a retention behavior, after determining that the second privacy behavior uses the second personal data, the first server sends second information to the second server, including:
[0052] The first server determines data retention status of the target application in the first server based on the content and identifier of the second personal data;
[0053] After determining, based on the data retention situation, that the right action uses the second personal data, the first server determines that the second information includes an identifier of the right action and the content and identifier of the second personal data used in the right action, and sends the identifier of the right action and the content and identifier of the second personal data used in the right action to the second server;
[0054] And / or, after the first server determines that the retention behavior uses the second personal data based on the data retention situation, it determines that the second information includes the identifier of the retention behavior and the content and identifier of the second personal data used by the retention behavior, and sends the identifier of the retention behavior and the content and identifier of the second personal data used by the retention behavior to the second server.
[0055] In one possible design, when the second privacy behavior includes a disclosure behavior, after determining that the second privacy behavior uses the second personal data, the first server sends second information to the second server, including:
[0056] The first server determines data disclosure status of the target application in the first server based on the content and identifier of the second personal data;
[0057] After the first server determines, based on the data disclosure status of the target application in the first server, that the disclosure behavior uses the second personal data, the first server determines that the second information includes an identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior;
[0058] The first server sends an identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior to the second server;
[0059] Alternatively, the first server sends the identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior to the second server through the client device.
[0060] In one possible design, when the second privacy behavior includes a cross-border behavior, after determining that the second privacy behavior uses the second personal data, the first server sends second information to the second server, including:
[0061] The first server determines, based on the content and identifier of the second personal data, a cross-border data situation of the target application in the first server;
[0062] After determining, based on the cross-border data situation of the target application in the first server, that the cross-border behavior uses the second personal data, the first server determines that the second information includes an identifier of the cross-border behavior and the content and identifier of the second personal data used in the cross-border behavior;
[0063] The first server sends the identifier of the cross-border behavior and the content and identifier of the second personal data used in the cross-border behavior to the second server;
[0064] Alternatively, the first server sends the identifier of the cross-border behavior and the content and identifier of the second personal data used for the cross-border behavior to the second server through the client device.
[0065] The beneficial effects of the privacy protocol family generation method provided in the above-mentioned second aspect and the various possible designs of the above-mentioned second aspect can be referred to the beneficial effects brought about by the above-mentioned first aspect and the various possible implementation methods of the first aspect, and will not be repeated here.
[0066] In a third aspect, the present application provides a method for generating a privacy protocol family for an application, which is applied to a second server.
[0067] The method includes:
[0068] The second server receives first information from the client device, the first information being sent by the client device after determining that the first privacy behavior uses the first personal data. The first information is used to describe the privacy situation in which the first privacy behavior uses the first personal data of the target application on the client device. The first privacy behavior includes all behaviors of all applications on the client device that require the use of personal data. The first personal data is obtained by the client device after running the target application.
[0069] The second server receives second information from the first server. The second information is sent by the first server after the first server determines that the second privacy behavior uses the second personal data of the target application in the first server. The second information is used to describe the privacy situation of the second privacy behavior using the second personal data. The second privacy behavior includes all behaviors of all applications in the first server that require the use of personal data. The second personal data is determined by the first server based on the first personal data.
[0070] The second server generates a target privacy protocol family based on the first information and the second information;
[0071] The second server sends the target protocol family to the client device, and the target privacy protocol family is used by the client device to store in the installation package of the target application, so that the target application can display the target protocol family to the user after startup.
[0072] In one possible design, the method further includes:
[0073] The second server receives an installation package of a target application from the client device, where the installation package of the target application is sent by the client device when the client device determines that the installation package of the target application is a new version;
[0074] The second server determines the differences between the new and old versions based on the installation package of the target application;
[0075] The second server updates the target privacy protocol family corresponding to the old version based on the difference part to obtain the new version of the target privacy protocol family;
[0076] The second server sends the target privacy protocol family corresponding to the new version to the client device. The target privacy protocol family corresponding to the new version is used by the client device to update the target privacy protocol family corresponding to the old version in the installation package of the target application to the target privacy protocol family corresponding to the new version, so that the target application can display the target privacy protocol family corresponding to the new version to the user after startup.
[0077] In one possible design, the method further includes:
[0078] The second server receives a revised target privacy protocol family from the client device, where the revised target privacy protocol family is obtained by the client device updating the target privacy protocol family in the installation package of the target application based on the received revised content of the target privacy protocol family, where the revised content is received by the client device after displaying all contents of the target privacy protocol family;
[0079] The second server updates the target privacy protocol family to the revised target privacy protocol family.
[0080] In one possible design, when the first privacy behavior includes: a sensitive behavior and a control operation, the second server receives first information from the client device, including:
[0081] The second server receives, from the client device, an identifier of the sensitive behavior and the content and identifier of the first personal data used in the sensitive behavior, included in the first information. The identifier of the sensitive behavior and the content and identifier of the first personal data used in the sensitive behavior are sent by the client device after determining that the sensitive behavior uses the first personal data.
[0082] And / or, the second server receives the identifier of the control operation included in the first information and the content and identifier of the first personal data used by the control operation from the client device, and the identifier of the control operation and the content and identifier of the first personal data used by the control operation are sent by the client device after determining that the control operation uses the first personal data.
[0083] In one possible design, when the first privacy behavior includes: a disclosure behavior, the second server receives first information from the client device, including:
[0084] The second server receives the identifier of the disclosure behavior and the content and identifier of the first personal data used in the disclosure behavior included in the first information from the client device. The identifier of the disclosure behavior and the content and identifier of the first personal data used in the disclosure behavior are sent by the client device after determining that the disclosure behavior uses the first personal data based on the data disclosure status of the target application in the client device. The data disclosure status of the target application in the client device is determined by the client device based on the content and identifier of the first personal data.
[0085] In one possible design, when the first privacy behavior includes a cross-border behavior, the second server receives first information from the client device, including:
[0086] The second server receives the identifier of the cross-border behavior and the content and identifier of the first personal data used for the cross-border behavior included in the first information from the client device. The identifier of the cross-border behavior and the content and identifier of the first personal data used for the cross-border behavior are sent by the client device after determining that the cross-border behavior uses the first personal data based on the cross-border data situation of the target application in the client device. The cross-border data situation of the target application in the client device is determined by the client device based on the content and identifier of the first personal data.
[0087] In one possible design, when the second privacy behavior includes: a rights behavior and a retention behavior, the second server receives second information from the first server, including:
[0088] The second server receives, from the first server, an identifier of the rights act and the content and identifier of the second personal data used in the rights act, included in the second information. The identifier of the rights act and the content and identifier of the second personal data used in the rights act are sent by the first server after determining, based on the data retention situation, that the rights act uses the second personal data.
[0089] And / or, the second server receives, from the first server, an identifier of the retention behavior and the content and identifier of the second personal data used in the retention behavior, included in the second information, where the identifier of the retention behavior and the content and identifier of the second personal data used in the retention behavior are sent by the first server after determining, based on the data retention situation, that the retention behavior uses the second personal data;
[0090] The data retention status of the target application in the first server is determined by the first server based on the content and identifier of the second personal data.
[0091] In one possible design, when the second privacy behavior includes: a disclosure behavior, the second server receives second information from the first server, including:
[0092] The second server receives, from the first server, an identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior, included in the second information;
[0093] Alternatively, the second server receives, from the first server via the client device, an identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior included in the second information;
[0094] Among them, the identification of the disclosure behavior and the content and identification of the second personal data used in the disclosure behavior are sent by the first server after determining that the disclosure behavior uses the second personal data based on the data disclosure status of the target application in the first server. The data disclosure status of the target application in the first server is determined by the first server based on the content and identification of the second personal data.
[0095] In one possible design, when the second privacy behavior includes a cross-border behavior, the second server receives second information from the first server, including:
[0096] The second server receives, from the first server, an identifier of the cross-border behavior and the content and identifier of the second personal data used for the cross-border behavior included in the second information;
[0097] Alternatively, the second server receives, from the first server through the client device, the identifier of the cross-border behavior and the content and identifier of the second personal data used for the cross-border behavior included in the second information;
[0098] Among them, the identification of the cross-border behavior and the content and identification of the second personal data used in the cross-border behavior are sent by the first server after determining that the cross-border behavior uses the second personal data based on the cross-border data situation of the target application in the first server. The cross-border data situation of the target application in the first server is determined by the first server based on the content and identification of the second personal data.
[0099] The beneficial effects of the privacy protocol family generation method provided in the third aspect and the various possible designs of the third aspect can be referred to the beneficial effects brought about by the first aspect and the various possible implementation methods of the first aspect, and will not be repeated here.
[0100] In a fourth aspect, the present application provides a client device comprising: a memory and a processor; the memory is used to store program instructions; the processor is used to call the program instructions in the memory so that the client device executes the privacy protocol family generation method of the application in the first aspect and any possible design of the first aspect.
[0101] In a fifth aspect, the present application provides a server comprising: a memory and a processor; the memory is used to store program instructions; the processor is used to call the program instructions in the memory so that the server executes the second aspect and the privacy protocol family generation method for any possible design application of the second aspect, and / or the processor is used to call the program instructions in the memory so that the server executes the third aspect and the privacy protocol family generation method for any possible design application of the third aspect.
[0102] In a sixth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor on a client device, implements a method for generating a privacy protocol family for an application in the first aspect and any possible design of the first aspect.
[0103] In the seventh aspect, the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor on a server, it implements the second aspect and the method for generating a privacy protocol family for application in any possible design of the second aspect, and / or implements the third aspect and the method for generating a privacy protocol family for application in any possible design of the third aspect.
[0104] In an eighth aspect, the present application provides a computer program product, comprising: execution instructions, the execution instructions being stored in a readable storage medium, at least one processor of a client device being able to read the execution instructions from the readable storage medium, and at least one processor executing the execution instructions so that the client device implements the privacy protocol family generation method for the application in the first aspect and any possible design of the first aspect.
[0105] In the ninth aspect, the present application provides a computer program product, comprising: execution instructions, the execution instructions are stored in a readable storage medium, at least one processor of the server can read the execution instructions from the readable storage medium, and at least one processor executes the execution instructions so that the server implements the second aspect and the privacy protocol family generation method for application in any possible design of the second aspect, and / or implements the third aspect and the privacy protocol family generation method for application in any possible design of the third aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0106] Figure 1 A flowchart of a privacy protocol family for generating an application in a related technology;
[0107] Figure 2 A schematic diagram of the system architecture of a method for generating a privacy protocol family for an application provided in one embodiment of the present application;
[0108] Figure 3 A software structure block diagram of a client device, an application server, and a hosting server provided in one embodiment of the present application;
[0109] Figure 4 A software structure diagram of an application entity, an application sandbox, a service plug-in set, and a hosting service provided in an embodiment of the present application;
[0110] Figure 5 A signaling interaction diagram of a privacy protocol family generation method for an application provided in one embodiment of the present application;
[0111] Figure 6 A flowchart of a method for generating a privacy protocol family for an application provided in one embodiment of the present application;
[0112] Figure 7 A flowchart of a method for generating a privacy protocol family for an application provided in one embodiment of the present application;
[0113] Figure 8 A signaling interaction diagram of a privacy protocol family generation method for an application provided in one embodiment of the present application;
[0114] Figure 9 A signaling interaction diagram of a privacy protocol family generation method for an application provided in one embodiment of the present application;
[0115] Figure 10 A signaling interaction diagram of a privacy protocol family generation method for an application provided in one embodiment of the present application. DETAILED DESCRIPTION
[0116] In this application, "at least one" refers to one or more, and "plurality" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the objects associated before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a alone, b alone, or c alone can represent: a alone, b alone, c alone, a and b in combination, a and c in combination, b and c in combination, or a, b, and c in combination, where a, b, and c can be single or multiple. In addition, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as indicating or implying relative importance.
[0117] The present application provides a method for generating a privacy protocol family for an application, a client device, a server, a chip system, a computer-readable storage medium, and a computer program product. Based on the privacy status of personal data used in all privacy behaviors during the operation of the application, the privacy protocol family for the application can be automatically generated, avoiding the tedious process of the development stage of the associated application and the release and online stage of the bound application, shortening the time cost of generating the privacy protocol family for the application, reducing the investment cost of generating the privacy protocol family for the application, and ensuring the accuracy of the generated privacy protocol family for the application.
[0118] In addition, a channel for R&D personnel to conduct secondary confirmation and manual correction of the privacy protocol family of the application can be provided, so that the accuracy of the privacy protocol family of the application can be improved through secondary confirmation and manual correction of the privacy protocol family of the application by R&D personnel.
[0119] In addition, differentiated privacy analysis can be performed on the new and old versions of the application, and the privacy protocol family of the application corresponding to the new version can be quickly and accurately generated. This does not require a large amount of manpower to conduct privacy analysis, and does not need to be tied to the version release of the application. This solves the pain points of slow version release of the application and inaccurate privacy protocol family of the application due to frequent version iterations.
[0120] Below, some terms in this application are explained to facilitate understanding by those skilled in the art.
[0121] 1. Personal Data
[0122] Personal data refers to data related to the user's privacy rights and interests.
[0123] Personal data may include attribute parameters such as content and type. The data content of personal data refers to the specific data of the personal data. The identifier of personal data is used to indicate the specific type of personal data.
[0124] In some embodiments, the types of personal data may include user data and device information. User data may include, but is not limited to, name, identity information (such as ID number or photo), location data (such as latitude and longitude or room number), psychological state, genetic information, and social identity. Device information may include, but is not limited to, network identifier, device model, and physical address (MAC).
[0125] 2. Privacy Behavior
[0126] Privacy behavior refers to all behaviors that require the use of personal data by an application, which may fully involve the data lifecycle of the client device 0 analyzing the user's privacy rights and interests and the data lifecycle of the application server 2 analyzing the user's privacy rights and interests.
[0127] In addition, the identifier of the private behavior can indicate the type of the private behavior, wherein the identifier of the private behavior can be expressed in letters, numbers, binary, characters, etc.
[0128] In some embodiments, the types of privacy behaviors may include: sensitive behaviors (such as command execution, file upload, audio and video download, information storage, location information acquisition, etc.), control operations (such as user selection to agree to control operations, etc.), rights behaviors (i.e., user-initiated behaviors such as access, deletion, retention, etc.), retention behaviors (i.e., target applications actively perform behaviors such as access, deletion, retention, etc.), disclosure behaviors (such as data transmission to other applications / public accounts / web pages), and cross-border behaviors (such as data transmission to servers in other countries), etc.
[0129] See also Figure 2 , Figure 2 A schematic diagram of the system architecture of a privacy protocol family generation method for an application provided in this application is shown.
[0130] like Figure 2 As shown, the system architecture of the privacy protocol family generation method of the application of the present application may include: client device 0, application server 2 and hosting server 3.
[0131] The client device 0 is respectively connected to the application server 2 and the hosting server 3, and the application server 2 is also connected to the hosting server 3. The communication connection mentioned in this application may include a wireless connection and / or a wired connection, which is not limited in this application.
[0132] The target application's installation package can be installed and run on both client device 0 and application server 2. Accordingly, client device 0 is provided with application client 1 for the target application, and application server 2 can be application server 2 for the target application, so that client device 0 and application server 2 can cooperate with each other to implement all services of the target application. Hosting server 3 can be a server that generates the target privacy protocol family.
[0133] The target application mentioned in this application is an application (APP). This application does not limit the parameters of the target application, such as type, function, user interface, display location, etc. The target privacy protocol family mentioned in this application is the privacy protocol family of the target application. The target privacy protocol family provides the target application with a user's privacy rights and interests instruction text. The target privacy protocol family may include content such as a privacy statement, user agreement, and privacy requirements.
[0134] The client device 0 may be a terminal device, a server, or both a terminal device and a server, and this application does not limit this. For example, the terminal device may be a mobile phone (such as a foldable screen mobile phone, a large screen mobile phone, a smart phone, etc.), a tablet computer, a laptop computer, a wearable device, an in-vehicle device, an augmented reality (AR) / virtual reality (VR) device, an ultra-mobile personal computer (UMPC), a netbook, a personal digital assistant (PDA), a smart TV, a smart screen, a high-definition TV, a 4K TV, a smart speaker, a smart projector, etc.
[0135] The present application does not limit parameters such as type, quantity, etc. of the application server 2. For example, the application server 2 may be a cloud server.
[0136] The present application does not limit parameters such as type, quantity, etc. of the hosting server 3. In some embodiments, the hosting server 3 may be the application server 2 or a server different from the application server 2.
[0137] Based on the above description, a detailed Figure 2 The respective functions of the client device 0, application server 2 and hosting server 3 are realized.
[0138] For ease of explanation, the personal data 1 mentioned in this application refers to the personal data of the target application on client device 0, and the personal data 2 refers to the personal data of the target application on application server 2. Furthermore, the personal data 1 and the personal data 2 may be of the same content and type, or of different content and types, and this application does not impose any restrictions on this.
[0139] For ease of explanation, the privacy behavior 1 mentioned in this application may include all behaviors of all applications that require the use of personal data on client device 0, such as sensitive behaviors, control operations, disclosure behaviors, and cross-border behaviors. The privacy behavior 2 mentioned in this application may include all behaviors of all applications that require the use of personal data on application server 2, such as rights behaviors, retention behaviors, disclosure behaviors, and cross-border behaviors.
[0140] In this application, the application client 1 in the client device 0 is used to provide an installation package that carries the target application, runs the installation package of the target application, identifies personal data 1, triggers the application server 2 to identify personal data 2, analyzes whether the privacy behavior 1 uses personal data 1, pushes the privacy status of the privacy behavior 1 using personal data 1, and stores the target privacy protocol family.
[0141] In addition, the client device 0 is also used to provide capabilities such as displaying the target privacy protocol family, modifying the target privacy protocol family, determining whether the installation package of the target application is a new version, and updating the target privacy protocol family corresponding to the old version.
[0142] Application server 2 is used to provide the installation package for carrying the target application, run the installation package of the target application, identify personal data 2, analyze whether the privacy behavior 2 uses personal data 2, and push the privacy status of the privacy behavior 2 using personal data 2.
[0143] The hosting server 3 is used to provide the capabilities of receiving the privacy situation of privacy behavior 1 using personal data 1, receiving the privacy situation of privacy behavior 2 using personal data 2, analyzing the aforementioned various privacy situations, and generating a target privacy protocol family.
[0144] In addition, the hosting server 3 is also used to provide capabilities such as storing the target privacy protocol family, analyzing the differences between the new and old versions of the target application, and updating the target privacy protocol family.
[0145] Based on the above description, combined with Figure 3 , respectively introduce Figure 2 The specific implementation methods of the client device 0, application server 2 and hosting server 3 in each of them.
[0146] See also Figure 3 , Figure 3 The software structure block diagrams of the client device 0, application server 2 and hosting server 3 provided by the present application are shown.
[0147] like Figure 3 As shown, the application client 1 in the client device 0 of the present application may include: an application body 11 and an application sandbox 12. The application server 2 of the present application may include: a service plug-in set 20. The hosting server 3 of the present application may include: a hosting service 30.
[0148] The application body 11 is respectively connected to the application sandbox 12 and the hosting service 30 , the application sandbox 12 is respectively connected to the service plug-in set 20 and the hosting service 30 , and the service plug-in set 20 is also connected to the hosting service 30 .
[0149] The application entity 11 can be regarded as a container, which is used to provide the ability to carry the installation package of the target application and store the target privacy protocol family.
[0150] In addition, the application body 11 is also used to provide capabilities such as displaying the target privacy protocol family.
[0151] The application sandbox 12 is used to provide an installation package for running the target application, identify personal data 1, trigger the application server 2 to identify personal data 2, analyze whether the privacy behavior 1 uses personal data 1, and push the privacy situation of the privacy behavior 1 using personal data 1.
[0152] In addition, the application sandbox 12 is also used to provide capabilities such as correcting the target privacy protocol family, determining whether the installation package of the target application is a new version, and updating the target privacy protocol family corresponding to the old version.
[0153] The service plug-in set 20 is used to provide the capabilities of running the installation package of the target application, identifying personal data 2, analyzing whether the privacy behavior 2 uses personal data 2, and pushing the privacy situation of the privacy behavior 2 using personal data 2.
[0154] The hosting service 30 is used to provide the capabilities of receiving the privacy situation of privacy behavior 1 using personal data 1, receiving the privacy situation of privacy behavior 2 using personal data 2, analyzing the aforementioned various privacy situations, generating a target privacy protocol family, and storing the target privacy protocol family.
[0155] In addition, the hosting service 30 is also used to provide capabilities such as analyzing the differences between the new and old versions of the target application and updating the target privacy protocol family.
[0156] Based on the description of each software module above, combined with Figure 4 , respectively introduce Figure 3 The specific implementation methods of the application body 11, application sandbox 12, service plug-in set 20 and hosting service 30 are respectively described.
[0157] See also Figure 4 , Figure 4 The software structure diagrams of an application entity 11, an application sandbox 12, a service plug-in set 20 and a hosting service 30 provided by the present application are respectively shown.
[0158] like Figure 4 As shown, the application entity 11 may include a privacy agreement SDK (software development kit) 105. The application sandbox 12 may include a data identification module 101, a behavior detection module 102, an SDK detection module 103, and a data cross-border module 104. The service plug-in set 20 may include a data identification post 201, a data processing post 202, and an SDK detection post 203. The hosting service 30 may include a privacy statement / agreement generation service 301, a semantic analysis service 302, a version difference service 303, and an associated application service 304.
[0159] Privacy protocol SDK 105 is used to provide capabilities such as storing the target privacy protocol family and displaying the target privacy protocol family. It can integrate the target privacy protocol family into the installation package of the target application and can also display the target privacy protocol family.
[0160] The data identification module 101 is used to provide capabilities such as identifying personal data 1 and synchronizing personal data 1. It can identify the personal data 1 of the target application in the client device 0 and synchronize the personal data 1 to the application server 2.
[0161] The behavior detection module 102 is used to provide the ability to monitor the sensitive behavior of the target application in the client device 0, analyze whether the sensitive behavior uses personal data 1, and push the privacy situation of the sensitive behavior using personal data 1. It can realize real-time monitoring of sensitive behavior and push the privacy situation of the sensitive behavior using personal data 1.
[0162] The behavior detection module 102 is also used to provide the ability to monitor the control operations of the target application in the client device 0, such as the underlying details of the control, binding events, operation types, etc., analyze whether the control operation uses personal data 1, and push the privacy situation of the control operation using personal data 1. It can realize real-time monitoring of the control operation and can also realize the push of the privacy situation of the control operation using personal data 1.
[0163] The SDK detection module 103 is used to provide the ability to monitor the disclosure behavior of the target application in the client device 0, analyze whether the disclosure behavior uses personal data 1, and push the privacy situation of the disclosure behavior using personal data 1 by detecting whether the client device 0 is integrated with an SDK that communicates with other applications, other web pages or other servers. It can determine whether the target application performs disclosure behavior in the client device 0, and can also push the privacy situation of the disclosure behavior using personal data 1.
[0164] The cross-border data module 104 is used to provide the ability to monitor the cross-border behavior of the target application in the client device 0, such as data or traffic, analyze whether the cross-border behavior uses personal data 1, and push the privacy situation of the cross-border behavior using personal data 1. It can determine whether the target application performs cross-border behavior in the client device 0, and can also push the privacy situation of the cross-border behavior using personal data 1.
[0165] The data identification stub 201 is used to provide capabilities such as identifying personal data 2 and synchronizing personal data 2 by cooperating with the data identification module 101, so as to realize the identification of personal data of the target application in the application server 2.
[0166] The data processing pile 202 is used to provide the ability to monitor the retention behavior of the target application in the application server 2, analyze whether the retention behavior uses personal data 2, and push the privacy situation of the retention behavior using personal data 2 by cooperating with the data identification pile 201. It can realize real-time monitoring of the retention behavior and push the privacy situation of the retention behavior using personal data 2.
[0167] The data processing pile 202 is also used to provide the ability to monitor the cross-border behavior of the target application in the application server 2, such as data or traffic, analyze whether the cross-border behavior uses personal data 2, and push the privacy situation of the cross-border behavior using personal data 2, by coordinating with the data identification pile 201. It can realize real-time monitoring of cross-border behavior and push the privacy situation of the cross-border behavior using personal data 2.
[0168] The SDK detection pile 203 is used to cooperate with the SDK detection module 103 to provide the ability to detect whether an SDK is integrated in the application server 2, determine which SDKs are integrated in the application server 2, monitor the disclosure behavior of the target application in the application server 2, analyze whether the disclosure behavior uses personal data 2, and push the privacy situation of the disclosure behavior using personal data 2. It can determine whether the target application performs disclosure behavior in the application server 2, and can also push the privacy situation of the disclosure behavior using personal data 2.
[0169] The hosting service 30 is used to analyze the privacy situations of privacy behavior 1 using personal data 1 and privacy behavior 2 using personal data 2 through the privacy statement / protocol generation service 301, semantic analysis service 302, version difference service 303 and associated application service 304, generate a target privacy protocol family, and provide the target privacy protocol family and other capabilities to the application entity 11.
[0170] In addition, the hosting service 30 is also used to provide capabilities such as storing the target privacy protocol family, analyzing the differences between the new and old versions of the target application, and updating the target privacy protocol family.
[0171] Based on the mutual cooperation of the above software modules, the target privacy protocol family can be automatically generated, solving the pain points of high cost and poor accuracy caused by tedious version iteration and large amount of manpower investment.
[0172] Next, combine Figure 5 ,introduce Figure 4 The detailed process of generating the target privacy protocol family from each software module in .
[0173] See also Figure 5 , Figure 5 The signaling interaction diagrams of the privacy protocol family generation method provided by this application are shown respectively. For the convenience of explanation, Figure 5 In the example, application 1 is used as an example to illustrate the target application.
[0174] like Figure 5 As shown, the privacy protocol family generation method of the application of this application may include the following steps:
[0175] S0. The R&D personnel provide the installation package of application 1 to the application entity 11. Thus, the application entity 11 can determine whether the installation package of application 1 is a new version.
[0176] When it is determined that the installation package of application 1 is not a new version, application entity 11 can determine that application 1 is not undergoing a version update and that application entity 11 can determine that application 1 needs to generate a new privacy protocol family for application 1, and then execute S1. When it is determined that the installation package of application 1 is a new version, application entity 11 can determine that application 1 is undergoing a version update and that application entity 11 can determine that application 1 needs to generate a privacy protocol family for the new version, and then execute S30.
[0177] S1. When application entity 11 determines that the installation package of application 1 is not a new version, application entity 11 may send instruction 1 to data identification module 101 and instruction 2 to behavior detection module 102. After instructions 1 and 2 are transmitted, application entity 11 may run the installation package of application 1 to complete the service implementation of application 1.
[0178] Instruction 1 is used to instruct data identification module 101 to identify personal data 1, and instruction 2 is used to instruct behavior detection module 102 to monitor sensitive behaviors and control operations. Instruction 1 or instruction 2 can be represented in alphabetical, binary, or character formats. In addition, this application does not limit the time sequence in which application subject 11 transmits instruction 1 and instruction 2; they can be executed simultaneously or sequentially.
[0179] S2. After the application main body 11 runs the installation package of the application 1, the data identification module 101 responds to the instruction 1 and can identify the personal data 1 of the application 1 in the client device 0.
[0180] S3. After the application main body 11 runs the installation package of application 1, the behavior detection module 102 responds to instruction 2 and can monitor the sensitive behaviors and control operations of application 1.
[0181] After the data identification module 101 identifies the personal data 1, the data identification module 101 may execute S4, S6, S11, and S17 respectively to achieve data synchronization between the application client 1 in the client device 0 and the application server 2. The present application does not limit the temporal order of S4, S6, S11, and S17, and they may be executed simultaneously or sequentially.
[0182] S4. The data identification module 101 may send the content and identification of the personal data 1 to the behavior detection module 102.
[0183] S5. After receiving the personal data 1, the behavior detection module 102 can determine whether the sensitive behavior and control operation use the personal data 1 based on the content and identification of the personal data 1.
[0184] After determining that the sensitive behavior uses personal data 1, the behavior detection module 102 may send the identifier of the sensitive behavior and the content and identifier of the personal data 1 used by the sensitive behavior to the hosting service 30.
[0185] And / or, after determining that the control operation uses the personal data 1 , the behavior detection module 102 may send the identifier of the control operation and the content and identifier of the personal data 1 used by the control operation to the hosting service 30 .
[0186] Based on the description of S4-S5, after running the installation package of application 1, application client 1 in client device 0 can capture the privacy of personal data 1 in sensitive behaviors and control operations by analyzing the business implementation of application 1.
[0187] S6. The data identification module 101 may send the content and identification of the personal data 1 to the data identification post 201 to achieve data synchronization between the data identification module 101 and the data identification post 201.
[0188] S7. The data identification post 201 can identify the personal data 2 of the application 1 in the application server 2 based on the content and identification of the personal data 1.
[0189] After the data identification post 201 identifies the personal data 2, the data identification post 201 can execute S8 and S13 respectively. The present application does not limit the order of S8 and S13 in terms of time sequence, and they can be executed simultaneously or sequentially.
[0190] S8. The data identification post 201 may send the content and identification of the personal data 2 to the data processing post 202.
[0191] S9. After receiving the personal data 2, the data processing post 202 may determine the data retention status of the personal data 2 in the application server 2 based on the content and identification of the personal data 2.
[0192] S10. The data processing post 202 can determine whether the rights behavior and retention behavior use personal data 2 based on the data retention situation.
[0193] After determining that the rights behavior uses the personal data 2 , the data processing post 202 may send the identifier of the rights behavior and the content and identifier of the personal data 2 used by the rights behavior to the hosting service 30 .
[0194] And / or, after determining that the retention behavior uses the personal data 2, the data processing post 202 may send the identification of the retention behavior and the content and identification of the personal data 2 used by the retention behavior to the hosting service 30.
[0195] Based on the description of S6-S10, after running the installation package of application 1, application client 1 and application server 2 in client device 0 can capture the privacy of personal data 2 in rights behavior and retention behavior by analyzing the business implementation of application 1.
[0196] S11 , the data identification module 101 may send the content and identification of the personal data 1 to the SDK detection module 103 .
[0197] S12 , after receiving the personal data 1 , the SDK detection module 103 may determine the data disclosure status 1 of the personal data 1 in the client device 0 based on the content and identification of the personal data 1 .
[0198] S13. The data identification post 201 may send the content and identification of the personal data 2 to the SDK detection post 203.
[0199] S14 , after receiving the personal data 2 , the SDK detection post 203 can determine the data disclosure status 2 of the personal data 2 in the application server 2 based on the content and identification of the personal data 2 .
[0200] S15 . The SDK detection post 203 sends the data disclosure status 2 to the SDK detection module 103 , thereby achieving data synchronization between the SDK detection module 103 and the SDK detection post 203 .
[0201] S16. The SDK detection module 103 may determine whether the disclosure behavior uses personal data 1 and / or personal data 2 based on data disclosure situation 1 and data disclosure situation 2.
[0202] After determining that the disclosure behavior uses personal data 1 and / or personal data 2, the SDK detection module 103 may send an identifier of the disclosure behavior and the content and identifier of the personal data 1 and / or personal data 2 used in the disclosure behavior to the hosting service 30.
[0203] It should be noted that, in addition to the implementation of S15-S16, the SDK detection module 103 and the SDK detection post 203 can respectively perform the following steps:
[0204] SDK detection module 103 can determine whether the disclosure behavior uses personal data 1 based on data disclosure situation 1. After determining that the disclosure behavior uses personal data 1, SDK detection module 103 can send an identifier of the disclosure behavior and the content and identifier of the personal data 1 used in the disclosure behavior to the hosting service 30.
[0205] Furthermore, the SDK detection post 203 can determine whether the disclosure behavior uses personal data 2 based on the data disclosure situation 2. After determining that the disclosure behavior uses personal data 2, the SDK detection post 203 can send the identification of the disclosure behavior and the content and identification of the personal data 2 used in the disclosure behavior to the hosting service 30.
[0206] Based on the description of S11-S16, after running the installation package of application 1, application client 1 and application server 2 in client device 0 can capture the privacy situation of using personal data 1 and / or personal data 2 by analyzing the business implementation of application 1.
[0207] S17. The data identification module 101 can send the content and identification of the personal data 1 to the cross-border data module 104.
[0208] S18. After receiving the personal data 1, the data cross-border module 104 can determine the data cross-border situation 1 of the personal data 1 in the client device 0 based on the content and identification of the personal data 1.
[0209] S19. After receiving the personal data 2, the data processing post 202 can determine the cross-border data situation 2 of the personal data 2 in the application server 2 based on the content and identification of the personal data 2.
[0210] The present application does not limit the timing sequence of S9 and S19; they may be executed simultaneously or sequentially.
[0211] S20. The data processing post 202 can send the data cross-border situation 2 to the data cross-border module 104.
[0212] S21. The cross-border data module 104 can determine whether the cross-border behavior uses personal data 1 and / or personal data 2 based on the cross-border data situation 1 and the cross-border data situation 2.
[0213] After determining that the cross-border behavior uses personal data 1 and / or personal data 2, the data cross-border module 104 may send the identification of the cross-border behavior and the content and identification of the personal data 1 and / or personal data 2 used in the cross-border behavior to the hosting service 30.
[0214] It should be noted that, in addition to the implementation of S20-S21, the cross-border data module 104 and the data processing post 202 can respectively perform the following steps:
[0215] Based on the cross-border data situation 1, the cross-border data module 104 can determine whether the cross-border behavior uses personal data 1. After determining that the cross-border behavior uses personal data 1, the cross-border data module 104 can send the identifier of the cross-border behavior and the content and identifier of the personal data 1 used in the cross-border behavior to the hosting service 30.
[0216] Furthermore, based on the cross-border data situation 2, the data processing unit 202 can determine whether the cross-border behavior uses personal data 2. After determining that the cross-border behavior uses personal data 2, the cross-border data module 104 can send the cross-border behavior identifier and the content and identifier of the personal data 2 used in the cross-border behavior to the hosting service 30.
[0217] Based on the description of S17-S21, after running the installation package of application 1, application client 1 and application server 2 in client device 0 can capture the privacy situation of cross-border behavior using personal data 1 and / or personal data 2 by analyzing the business implementation of application 1.
[0218] It should be noted that sensitive behaviors and control operations, rights behaviors and retention behaviors, disclosure behaviors, and cross-border behaviors, respectively, and whether they use various privacy situations corresponding to personal data, can be executed simultaneously or successively, and this application does not impose any restrictions on this.
[0219] S22: Based on the aforementioned various privacy situations, the hosting service 30 can obtain corresponding privacy protocol information. Thus, based on the aforementioned privacy protocol information, the hosting service 30 can generate a privacy protocol family for application 1. Furthermore, the hosting service 30 can also store the privacy protocol family for application 1.
[0220] S23 . The hosting service 30 may send the privacy protocol family of the application 1 to the application entity 11 .
[0221] S24. After receiving the privacy protocol family of application 1, application entity 11 may store the privacy protocol family of application 1 in privacy protocol SDK 105, so that application 1 may call privacy protocol SDK 105 to display the privacy protocol family of application 1 after startup.
[0222] Based on the description of S22-S24, the hosting server 3 can automatically generate a privacy protocol family for the application 1 through the cooperation of the application client 1 and the application server 2 in the client device 0.
[0223] S25. The application entity 11 can use the privacy protocol SDK 105 to display the privacy protocol family of the application 1, so that the R&D personnel can clearly understand the privacy protocol family of the application 1.
[0224] S26. Based on the actual situation of application 1, the R&D personnel may modify the privacy protocol family of application 1 and provide the modified content of the privacy protocol family of application 1 to the application entity 11.
[0225] S27. Based on the revised content, the application entity 11 may update the privacy protocol family of the application 1 in the privacy protocol SDK 105 to obtain the revised privacy protocol family of the application 1.
[0226] S28 . The application entity 11 may send the modified privacy protocol family of the application 1 to the hosting service 30 .
[0227] S29: The hosting service 30 may update the stored privacy protocol family of application 1 based on the revised privacy protocol family of application 1. In addition, the hosting service 30 may also store the revised privacy protocol family of application 1.
[0228] It should be noted that S25-S29 are optional steps.
[0229] Based on the description of S25-S29, the application client 1 in the client device 0 can provide R&D personnel with a channel to manually correct the privacy protocol family of application 1 by displaying the privacy protocol family of application 1, thereby making timely and accurate corrections to the privacy protocol family of application 1 and improving the accuracy of generating the privacy protocol family of application 1.
[0230] S30 . When the installation package of application 1 is a new version, the application entity 11 may send the installation package of application 1 to the hosting service 30 .
[0231] S31: Hosting service 30 may perform a privacy analysis on the differences between the new and old versions of the installation package of application 1, and obtain the differences between the new and old versions of application 1. The differences refer to the different software codes in the installation package and the software codes that implement the necessary services of application 1 (e.g., the software codes corresponding to the user interface displayed after application 1 is started).
[0232] S32: Hosting service 30 uses static and / or dynamic analysis to generate a privacy protocol family for application 1 corresponding to the new version based on the differences and the privacy protocol family for application 1 corresponding to the old version. Hosting service 30 may also store the privacy protocol family for application 1 corresponding to the new version.
[0233] Among them, the static analysis method refers to the hosting service 30 analyzing the privacy situation of the use of personal data in the application client 1 and the application server 2 through the software code of the difference part, and determining whether there is deletion and / or new privacy protocol information in the privacy protocol family of the application 1 corresponding to the old version.
[0234] Among them, the dynamic analysis method refers to the hosting service 30 using the application body 11 and the application sandbox 12 to run the different parts of the software code to determine whether there is deleted and / or newly added privacy protocol information in the privacy protocol family of the application 1 corresponding to the old version.
[0235] After the hosting service 30 generates the privacy protocol family of application 1 corresponding to the new version, the hosting service 30 can execute S23 to transmit the privacy protocol family of application 1 corresponding to the new version to the application entity 11. The specific implementation process can be found in the description of S23 and will not be repeated here.
[0236] Based on the description of S30-S32, the hosting service 30 can quickly and accurately generate the privacy protocol family of application 1 corresponding to the new version by comparing and analyzing the differences between the old and new versions of application 1, combined with the privacy protocol family of application 1 corresponding to the old version, thereby solving the problem of needing to update the privacy protocol family of application 1 due to version iteration of application 1.
[0237] It should be noted that when application entity 11 determines that the installation package of application 1 is a new version, in addition to executing S30-S32 and S23-S24 to generate the privacy protocol family of application 1, the present application can also execute S1-S24 to generate the privacy protocol family of application 1, without the need for application entity 11 to determine whether the installation package of application 1 is a new version. Therefore, the step corresponding to application entity 11 determining whether the installation package of application 1 is a new version is optional.
[0238] In a specific embodiment, combining Figure 6 and Figure 7 , introduce in detail the use of Figure 2-Figure 5 The specific implementation of the privacy protocol family of each software module in the generation application 1. For the convenience of explanation, Figure 6 and Figure 7 In the example, application 1 is illustrated using the XX map APP.
[0239] exist Figure 2-Figure 4 Based on the software structure diagram shown, please refer to Figure 6 and Figure 7 , Figure 6 and Figure 7 The flowcharts of the privacy protocol family generation method for an application provided by the present application are respectively shown.
[0240] like Figure 6 As shown, the privacy protocol family generation method of the application of the present application may include: steps 0 to 25.
[0241] Step 0: The R&D personnel sends the installation package of the XX map APP to the application entity 11. The application entity 11 determines that the installation package of the XX map APP is not a new version, and the application entity 11 runs the installation package of the XX map APP.
[0242] Step 1: The data identification module 101 may identify personal data 1 including: International Mobile Equipment Identity (IMEI) and location information.
[0243] Step 2: The behavior detection module 102 may monitor the privacy behavior 1 including the sensitive behavior of uploading IMEI and location information to the network.
[0244] In step 3, based on the personal data 1 and privacy behavior 1 in steps 1 and 2, behavior detection module 102 can determine the privacy of the IMEI and location information used in the sensitive behavior of uploading IMEI and location information over the network. Therefore, behavior detection module 102 can push the aforementioned relevant information to hosting service 30, causing hosting service 30 to generate privacy agreement information for "collecting and uploading IMEI and location information."
[0245] Step 4: The data identification module 101 may transmit the personal data 1 including IMEI and location information to the data identification post 201 .
[0246] Step 5: The data identification post 201 can identify that the personal data 2 includes: IMEI.
[0247] Step 6: The data identification post 201 may transmit the personal data 2 including IMEI to the data processing post 202.
[0248] Step 7: The data processing post 202 may detect that the IMEI is deleted after t months. Thus, the data processing post 202 may determine that the data retention condition includes: the retention period of the IMEI is t months.
[0249] In step 8, the data processing server 202 can obtain the privacy information of the IMEI in the data retention behavior based on the data retention information in step 7. Therefore, the data processing server 202 can push the aforementioned relevant information to the hosting service 30, so that the hosting service 30 generates the privacy agreement information of "IMEI storage for t months".
[0250] Step 9: The data identification module 101 may transmit the personal data 1 including IMEI and location information to the SDK detection module 103 .
[0251] Step 10: SDK detection module 103 can identify that the SDK identified as aaa is integrated into the XX Map APP, and the IMEI is synchronously disclosed to the YY Mall APP through the SDK identified as aaa. Thus, SDK detection module 103 can obtain data disclosure situation 1.
[0252] Step 11: The data identification post 201 may transmit personal data 2 including IMEI to the SDK detection post 203.
[0253] Step 12: SDK detection post 203 can identify that the YY Mall App SDK is integrated into the XX Map App and that the IMEI is synchronously disclosed to the YY Mall App via the YY Mall App SDK. Thus, SDK detection post 203 can determine data disclosure status 2 and send data disclosure status 2 to SDK detection module 103.
[0254] In step 13, SDK detection module 103 can determine, based on data disclosure 1 and data disclosure 2 in steps 10 and 12, that the disclosure behavior uses the privacy information of personal data 1 and personal data 2. Therefore, SDK detection module 103 can push the aforementioned privacy information to hosting service 30, causing hosting service 30 to generate privacy agreement information for "disclosing IMEI to YY Mall App."
[0255] Step 14: The data identification module 101 may transmit personal data 1 including IMEI and location information to the cross-border data module 104.
[0256] Step 15: The cross-border data module 104 may identify that cross-border data situation 1 includes: transmitting location information to country m.
[0257] Step 16: The data processing post 202 can detect that the IMEI does not perform cross-border data transmission, and obtain cross-border data situation 2.
[0258] Step 17: The data processing post 202 may transmit the data cross-border situation 2 to the data cross-border module 104 .
[0259] In step 18, based on data cross-border situation 1 and data cross-border situation 2 in steps 15 and 17, the cross-border data module 104 can determine the privacy situation of the cross-border behavior using personal data 1. Therefore, the cross-border data module 104 can push the aforementioned privacy situation to the hosting service 30, causing the hosting service 30 to generate privacy agreement information for "transmitting location information to country m."
[0260] In step 19, the hosting service 30 can generate a privacy protocol family for the XX Map APP based on the privacy protocol information in steps 3, 8, 13, and 18, which may specifically include: 1. Collecting and uploading IMEI and location information; 2. Storing IMEI for t months; 3. Disclosing IMEI to the YY Mall APP; 4. Transmitting location information to country m.
[0261] Thus, the hosting service 30 can apply the privacy protocol family sent by the application entity 11 to the XX map APP.
[0262] Step 20: The application entity 11 may store the privacy protocol family of the XX map APP in the privacy protocol SDK 105, so that the privacy protocol family of the XX map APP may be displayed after the XX map APP is started.
[0263] Step 21: The application entity 11 can display the privacy protocol family of the XX map APP through the privacy protocol SDK 105.
[0264] Step 22: The developer manually updates and modifies the privacy protocol suite of the XX Map APP based on the actual situation of the XX Map APP. Thus, the application 11 can transmit the modified privacy protocol suite of the XX Map APP to the hosting service 30.
[0265] exist Figure 6 Based on the embodiment shown, Figure 7 As shown, the privacy protocol family generation method of the application of this application may include the following steps:
[0266] Step 23: The R&D personnel provide the application entity 11 with the installation package of the XX map APP, and the installation package of the XX map APP is a new version.
[0267] Step 24 : The application entity 11 sends the installation package of the XX map APP to the hosting service 30 .
[0268] Step 25: The hosting service 30 may perform a privacy analysis on the differences between the new and old versions of the installation package based on the installation package of the XX map APP, and obtain the differences between the new and old versions of the XX map APP.
[0269] Thus, the hosting service 30 can generate a privacy protocol family for application 1 corresponding to the new version based on the difference part and the privacy protocol family for application 1 corresponding to the old version, which may specifically include: 1. Collecting and uploading IMEI, location information and bank card number; 2. Storing IMEI for t months and storing bank card number for r months; 3. Disclosing IMEI to YY Mall APP; 4. Transmitting location information to country m.
[0270] In addition, if Figure 7 As shown, based on the privacy protocol family of application 1 corresponding to the new version, it can be seen that:
[0271] The data identification module 101 can identify that the personal data 1 includes: IMEI, location information and bank card number.
[0272] The behavior detection module 102 can monitor privacy behavior 1 including sensitive behaviors such as uploading IMEI, location information, and bank card number to the network.
[0273] The data identification post 201 can identify personal data 2 including: IMEI and bank card number.
[0274] The data processing post 202 can detect that the IME is deleted after It months, and the bank card number is deleted after r months.
[0275] It should be noted that the specific implementation process of each software module can be found in Figure 6 The description in is not repeated here.
[0276] Based on some of the aforementioned embodiments, the following introduces a method for generating a privacy protocol family for an application provided by this application.
[0277] Exemplarily, the present application provides a method for generating a privacy protocol family for an application.
[0278] See also Figure 8 , Figure 8 This is a signaling interaction diagram of a privacy protocol family generation method for an application provided in an embodiment of the present application. Figure 8 As shown, the privacy protocol family generation method of the application of the present application may include: S101-S108.
[0279] S101. After running a target application, the client device obtains the first personal data of the target application in the client device.
[0280] The specific implementation of the target application can refer to the description of application 1 mentioned above, the client device can refer to the description of client device 0 and application client 1 in client device 0 mentioned above, the first personal data can refer to the description of personal data 1 mentioned above, and the specific implementation of S101 can refer to Figure 5 The description of the application main body 11 running the installation package of the application 1 in S0 and the data identification module 101 identifying the personal data 1 in S2 is not repeated here.
[0281] S102. After determining that the first privacy behavior uses the first personal data, the client device sends first information to the second server. The first information is used to describe the privacy situation of the first privacy behavior using the first personal data. The first privacy behavior includes all behaviors of all applications in the client device that need to use personal data.
[0282] Among them, the specific implementation method of the first privacy behavior can refer to the description of the privacy behavior 1 mentioned above, the second server can refer to the description of the hosting server 3 mentioned above, the privacy situation of the first personal data used by the first privacy behavior can refer to the description of the privacy situation of whether the sensitive behavior, control operation, disclosure behavior and cross-border behavior use personal data 1 mentioned above, the first information can refer to the identification of sensitive behavior and the content and identification of personal data 1 used by sensitive behavior, the identification of control operation and the content and identification of personal data 1 used by control operation, the identification of disclosure behavior and the content and identification of personal data 1 used by disclosure behavior, as well as the identification of cross-border behavior and the description of the content and identification of personal data 1 used by cross-border behavior, the specific implementation method of S102 can refer to Figure 5 The sensitive behaviors, control operations, disclosure behaviors, and cross-border behaviors involved in S5, S16, and S21 shown use the description of personal data 1 and are not repeated here.
[0283] S103: The client device sends the first personal data to the first server.
[0284] The first server can refer to the description of the application server 2 mentioned above, and the specific implementation of S103 can refer to Figure 5 The data identification module 101 in S6 sends the content and identification description of the personal data 1 to the data identification post 201, which will not be described in detail here.
[0285] S104: The first server determines second personal data of the target application in the first server based on the first personal data.
[0286] The second personal data can refer to the description of personal data 2 mentioned above, and the specific implementation of S104 can refer to Figure 5 The data identification pile 201 in S7 shown determines the description of the personal data 2, which will not be described in detail here.
[0287] S105. After determining that the second privacy behavior uses the second personal data, the first server sends second information to the second server. The second information is used to describe the privacy situation of the second privacy behavior using the second personal data. The second privacy behavior includes all behaviors of all applications in the first server that need to use personal data.
[0288] Among them, the specific implementation method of the second privacy behavior can refer to the description of the privacy behavior 2 mentioned above. The privacy situation of the second privacy behavior using the second personal data can refer to the description of various privacy situations corresponding to whether the rights behavior, retention behavior, disclosure behavior and cross-border behavior mentioned above use personal data 2. The second information can refer to the identifier of the rights behavior mentioned above and the content and identifier of personal data 2 used by the rights behavior, the identifier of the retention behavior and the content and identifier of personal data 2 used by the retention behavior, the identifier of the disclosure behavior and the content and identifier of personal data 2 used by the disclosure behavior, as well as the identifier of the cross-border behavior and the description of the content and identifier of personal data 2 used by the cross-border behavior. The specific implementation method of S105 can refer to Figure 5 The rights, retention, disclosure and cross-border behaviors involved in S10, S16 and S21 shown use the description of personal data 2 and are not repeated here.
[0289] S106. The second server generates a target privacy protocol family based on the first information and the second information.
[0290] The target privacy protocol family can refer to the description of the privacy protocol family of application 1 mentioned above, and the specific implementation of S106 can refer to Figure 5 The hosting service 30 in S22 shown generates a description of the privacy protocol family of application 1, which will not be repeated here.
[0291] S107: The second server sends the target protocol suite to the client device.
[0292] The specific implementation of S107 can be found in Figure 5 The description of S23 shown is not repeated here.
[0293] S108: The client device stores the target privacy protocol family in the installation package of the target application, so that the target application can display the target privacy protocol family to the user after being started.
[0294] The specific implementation of S108 can be found in Figure 5 The description of S24 shown is not repeated here.
[0295] Compared to Figure 1 The related technology shown in the figure shows that the privacy protocol family generation method of the application of this application can automatically generate the target privacy protocol family. There is no need for professionals to write the target privacy protocol family, no need to associate the development stage of the application, and no need to bind the version of the application to be released online. The target privacy protocol family is generated in a short time, with low investment cost and high accuracy.
[0296] The privacy protocol family generation method for the application provided in this application, through the mutual cooperation between the client device, the first server and the second server, the client device and the first server adopt methods such as data flow analysis, data retention monitoring, SDK detection and data cross-border detection, etc., to capture all privacy behaviors that use personal data during the operation of the target application. The client device and the first server transmit the information corresponding to the aforementioned privacy situation to the second server, so that the second server can accurately and quickly generate the target privacy protocol family based on the privacy rights and interests of the user in the target application represented by the aforementioned information. Thus, the automatic generation of the target privacy protocol family is achieved, avoiding the tedious process of the development stage of the associated application and the development and online stage of the bound application, shortening the time cost of generating the target privacy protocol family, reducing the investment cost of generating the target privacy protocol family, and improving the accuracy of generating the target privacy protocol family.
[0297] Based on the description of the above embodiment, the second server has the ability to analyze the privacy differences between the new and old versions of the application during version iteration. Therefore, this application can also use version difference comparison to analyze privacy behavior in the entire process of business implementation of the target application, and can quickly and accurately generate the target privacy protocol family corresponding to the new version, solving the pain points of slow version release of the target application and poor accuracy of the target privacy protocol family due to frequent version iterations.
[0298] See also Figure 9 , Figure 9This is a signaling interaction diagram of a privacy protocol family generation method for an application provided in an embodiment of the present application. Figure 9 As shown, the privacy protocol family generation method of the application of the present application may include: S201-S208.
[0299] S201: The client device receives an installation package of a target application.
[0300] The specific implementation of S201 can be found in Figure 5 The developer in S0 provides the application entity 11 with a description of the installation package of the application 1, which will not be described in detail here.
[0301] S202: The client device determines whether the installation package of the target application is a new version.
[0302] When it is determined that the installation package of the target application is not a new version, the client device may execute S203 ; when it is determined that the installation package of the target application is a new version, the client device may execute S204 .
[0303] The specific implementation of S202 can be found in Figure 5 The description of the application main body 11 in S0 determining whether the installation package of application 1 is a new version is not repeated here.
[0304] S203, the client device runs the installation package of the target application. After S203 is executed, this application can continue to execute Figure 8 S101-S108( Figure 9 S101-S108 are not shown in the figure).
[0305] The specific implementation of S203 can be found in Figure 5 The description of the application main body 11 in S0 running the installation package of application 1 is not repeated here.
[0306] S204: The client device sends the installation package of the target application to the second server.
[0307] The specific implementation of S204 can be found in Figure 5 The description of S30 shown is not repeated here.
[0308] S205: The second server determines the difference between the new version and the old version based on the installation package of the target application.
[0309] The specific implementation of S205 can be found in Figure 5 The description of S31 shown is not repeated here.
[0310] S206. The second server updates the target privacy protocol family corresponding to the old version based on the difference portion to obtain a new version of the target privacy protocol family.
[0311] The specific implementation of S206 can be found in Figure 5 The description of S32 shown is not repeated here.
[0312] S207: The second server sends the target privacy protocol family corresponding to the new version to the client device.
[0313] The specific implementation of S207 can be found in Figure 5 The description of S23 shown is not repeated here.
[0314] S208. The client device updates the target privacy protocol family corresponding to the old version in the installation package of the target application to the target privacy protocol family corresponding to the new version, so that the client device displays the target privacy protocol family corresponding to the new version after the target application is started.
[0315] The specific implementation of S208 can be found in Figure 5 The description of S24 shown is not repeated here.
[0316] Based on the description of the above embodiments, the generated target privacy protocol family does not need to be written by professionals. This application can also provide R&D personnel with a channel for secondary confirmation and manual correction of the target privacy protocol family, which is conducive to improving the accuracy of the target privacy protocol family. It also enables the generation of the target privacy protocol family to take into account both automatic writing and manual correction.
[0317] See also Figure 10 , Figure 10 This is a signaling interaction diagram of a privacy protocol family generation method for an application provided in an embodiment of the present application. Figure 10 As shown, the privacy protocol family generation method of the application of the present application may include: S301-S305.
[0318] S301. The client device displays all contents of the target privacy protocol family.
[0319] The specific implementation of S301 can be found in Figure 5 The description of S25 shown is not repeated here.
[0320] S302: The client device receives the revised content of the target privacy protocol family.
[0321] The specific implementation of the modified content can refer to the description of the modified content of the privacy protocol family of application 1 mentioned above, and the specific implementation of S302 can refer to Figure 5 The description of S26 shown is not repeated here.
[0322] S303: The client device updates the target privacy protocol family in the installation package of the target application based on the revised content to obtain a revised target privacy protocol family, so that the target application can display the revised target privacy protocol family to the user after startup.
[0323] The specific implementation of the modified target privacy protocol family can be found in the description of the modified privacy protocol family of application 1 mentioned above, and the specific implementation of S303 can be found in Figure 5 The description of S27 shown is not repeated here.
[0324] S304: The client device sends the revised target privacy protocol family to the second server.
[0325] The specific implementation of S304 can be found in Figure 5 The description of S28 shown is not repeated here.
[0326] S305: The second server updates the target privacy protocol family to the revised target privacy protocol family.
[0327] The specific implementation of S305 can be found in Figure 5 The description of S29 shown is not repeated here.
[0328] In S102 , since the target application has many types of privacy behaviors in the client device, the client device determines first information corresponding to each privacy behavior based on each privacy behavior in the first privacy behavior.
[0329] In some embodiments, when the first privacy behavior includes: sensitive behavior and control operation, the client device can determine whether the sensitive behavior and control operation use the first personal data.
[0330] After determining that the sensitive behavior uses the first personal data, the client device can determine that the first information includes the identification of the sensitive behavior and the content and identification of the first personal data used by the sensitive behavior, and send the identification of the sensitive behavior and the content and identification of the first personal data used by the sensitive behavior to the second server.
[0331] And / or, after determining that the control operation uses the first personal data, the client device can determine that the first information includes the identifier of the control operation and the content and identifier of the first personal data used by the control operation, and send the identifier of the control operation and the content and identifier of the first personal data used by the control operation to the second server.
[0332] The specific implementation of the above process can be found in Figure 5 The description of S4-S5 shown is not repeated here.
[0333] In some embodiments, when the first privacy behavior includes a disclosure behavior, the client device may determine data disclosure status of the target application on the client device based on the content and identifier of the first personal data. The client device may determine whether the disclosure behavior uses the first personal data based on the data disclosure status of the target application on the client device.
[0334] Thus, after determining that the disclosure behavior uses the first personal data, the client device can determine that the first information includes the identification of the disclosure behavior and the content and identification of the first personal data used in the disclosure behavior, and send the identification of the disclosure behavior and the content and identification of the first personal data used in the disclosure behavior to the second server.
[0335] The specific implementation of the above process can be found in Figure 5 The disclosures in S11-S16 shown use the description of personal data 1 and are not repeated here.
[0336] In some embodiments, when the first privacy behavior includes a cross-border behavior, the client device may determine the cross-border data status of the target application on the client device based on the content and identifier of the first personal data. The client device may determine whether the cross-border behavior uses the first personal data based on the cross-border data status of the target application on the client device.
[0337] Thus, after determining that the cross-border behavior uses the first personal data, the client device can determine that the first information includes the identifier of the cross-border behavior and the content and identifier of the first personal data used for the cross-border behavior, and send the identifier of the cross-border behavior and the content and identifier of the first personal data used for the cross-border behavior to the second server.
[0338] The specific implementation of the above process can be found in Figure 5 The cross-border activities in S17-S21 shown use the description of personal data 1 and are not repeated here.
[0339] In S105 , since the target application in the first server has many types of privacy behaviors, the client device determines the second information corresponding to each privacy behavior based on each privacy behavior in the second privacy behavior.
[0340] In some embodiments, when the second privacy behavior includes a rights behavior and a retention behavior, the first server may determine the data retention status of the target application on the first server based on the content and identifier of the second personal data. Based on the data retention status, the first server may determine whether the rights behavior and the retention behavior use the second personal data.
[0341] Thus, after determining that the right behavior uses the second personal data, the first server can determine that the second information includes the identification of the right behavior and the content and identification of the second personal data used by the right behavior, and send the identification of the right behavior and the content and identification of the second personal data used by the right behavior to the second server.
[0342] And / or, after determining that the retention behavior uses the second personal data, the first server may determine that the second information includes an identifier of the retention behavior and the content and identifier of the second personal data used by the retention behavior, and send the identifier of the retention behavior and the content and identifier of the second personal data used by the retention behavior to the second server.
[0343] The specific implementation of the above process can be found in Figure 5 The description of S6-S10 shown is not repeated here.
[0344] In some embodiments, when the second privacy behavior includes a disclosure behavior, the first server may determine data disclosure status of the target application on the first server based on the content and identifier of the second personal data. The first server may determine whether the disclosure behavior uses the second personal data based on the data disclosure status of the target application on the first server.
[0345] Thus, after determining that the disclosure behavior uses the second personal data, the first server can determine that the second information includes the identification of the disclosure behavior and the content and identification of the second personal data used in the disclosure behavior, and send the identification of the disclosure behavior and the content and identification of the second personal data used in the disclosure behavior to the second server.
[0346] Alternatively, the first server may send an identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior to the second server through the client device.
[0347] The specific implementation of the above process can be found in Figure 5 The disclosure actions shown in S11-S16 use the description of personal data 2 and are not repeated here.
[0348] In some embodiments, when the second privacy behavior includes a cross-border behavior, the first server may determine the cross-border status of the target application's data on the first server based on the content and identifier of the second personal data. The first server may determine whether the cross-border behavior uses the second personal data based on the cross-border status of the target application's data on the first server.
[0349] Thus, after determining that the cross-border behavior uses the second personal data, the first server can determine that the second information includes the identifier of the cross-border behavior and the content and identifier of the second personal data used in the cross-border behavior, and send the identifier of the cross-border behavior and the content and identifier of the second personal data used in the cross-border behavior to the second server.
[0350] Alternatively, the first server may send the identifier of the cross-border behavior and the content and identifier of the second personal data used for the cross-border behavior to the second server through the client device.
[0351] The specific implementation of the above process can be found in Figure 5 The cross-border activities in S17-S21 shown use the description of personal data 2 and are not repeated here.
[0352] Based on the description of the above embodiments, the target privacy protocol family can be displayed to the user in a variety of ways.
[0353] In some embodiments, after receiving the first operation, the electronic device may start the target application and display a first user interface of the target application, where the first user interface includes all contents of the target privacy protocol family.
[0354] The first operation may include but is not limited to: click, double-click or long press, etc. This application does not limit the parameters of the first user interface such as size, shape, color or position.
[0355] For example, after receiving a first operation such as a click by a user on an icon of a target application, the electronic device may display the first user interface in a pop-up window suspended on the main page of the target application, thereby enabling the user to promptly browse the user's privacy rights and interests in the target application.
[0356] In other embodiments, after receiving the second operation, the electronic device may display a second user interface of the target application, wherein the second user interface includes adjustable content of the target privacy protocol family, thereby enabling the user to adjust the user's privacy rights in the target application according to their own wishes.
[0357] The second operation may include but is not limited to: click, double-click or long press, etc. This application does not limit the parameters of the second user interface such as size, shape, color or position.
[0358] For example, after receiving a second operation such as a click performed by the user on a control on the main page of the target application, the electronic device switches from displaying the main page of the target application to the second user interface, and the electronic device can use an option / switch button to display the adjustable content of the target privacy protocol family in the second user interface.
[0359] It should be noted that the electronic device mentioned above may be the client device 0 mentioned above, or may be other terminal devices, and this application does not limit this.
[0360] Exemplarily, the present application provides a client device comprising: a memory and a processor; the memory is used to store program instructions; the processor is used to call the program instructions in the memory so that the client device executes the privacy protocol family generation method of the application in the above embodiment.
[0361] Exemplarily, the present application provides a server comprising: a memory and a processor; the memory is used to store program instructions; the processor is used to call the program instructions in the memory so that the server executes the privacy protocol family generation method of the application in the above embodiment.
[0362] Exemplarily, the present application provides a chip system, which is applied to an electronic device including a memory, a display screen, and a sensor; the chip system includes: a processor; when the processor executes computer instructions stored in the memory, the client device or server executes the privacy protocol family generation method applied in the previous embodiment.
[0363] Exemplarily, the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor on a client device or a server, the method for generating a privacy protocol family for the application in the foregoing embodiment is implemented.
[0364] Exemplarily, the present application provides a computer program product, comprising: execution instructions, the execution instructions are stored in a readable storage medium, at least one processor of a client device or a server can read the execution instructions from the readable storage medium, and at least one processor executes the execution instructions so that the client device or the server implements the privacy protocol family generation method of the application in the foregoing embodiment.
[0365] In the above embodiments, all or part of the functions can be implemented by software, hardware, or a combination of software and hardware. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in this application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk (SSD)), etc.
[0366] Those skilled in the art will appreciate that all or part of the process steps in the above-described method embodiments can be implemented by a computer program instructing the relevant hardware. The program can be stored in a computer-readable storage medium, and when executed, the program can include the process steps in the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.
Claims
1. A method for generating a privacy protocol family for an application, characterized in that: Applied to a client device; the method comprises: After the target application is run, the client device obtains first personal data of the target application in the client device; After determining that a first privacy behavior uses the first personal data, the client device sends first information to the second server, where the first information is used to describe the privacy situation in which the first privacy behavior uses the first personal data. The first privacy behavior includes all behaviors applied in the client device that require the use of personal data. The client device sends the first personal data to the first server, so that the first server determines second personal data of the target application in the first server based on the first personal data, and after determining that a second privacy behavior uses the second personal data, sends second information to the second server, where the second information is used to describe a privacy situation in which the second privacy behavior uses the second personal data. The second privacy behavior includes all behaviors of all applications in the first server that require the use of personal data. The client device receives a target privacy protocol family from the second server, where the target privacy protocol family is generated by the second server based on the first information and the second information; The client device stores the target privacy protocol family in the installation package of the target application, so that the target application can display the target privacy protocol family to the user after being started.
2. The method according to claim 1, characterized in that The client device runs a target application, including: The client device receives the installation package of the target application; When the client device determines that the installation package of the target application is not a new version, it runs the installation package of the target application.
3. The method according to claim 2, characterized in that The method further comprises: When the client device determines that the installation package of the target application is a new version, the client device sends the installation package of the target application to the second server; The client device receives the target privacy protocol family corresponding to the new version from the second server, where the target privacy protocol family corresponding to the new version is obtained by the second server determining differences between the new and old versions based on the installation package of the target application, and updating the target privacy protocol family corresponding to the old version based on the differences; The client device updates the target privacy protocol family corresponding to the old version in the installation package of the target application to the target privacy protocol family corresponding to the new version, so that the client device displays the target privacy protocol family corresponding to the new version after the target application is started.
4. The method according to any one of claims 1 to 3, characterized in that The method further comprises: The client device displays the entire content of the target privacy protocol family; The client device receives the revised content of the target privacy protocol family; The client device updates the target privacy protocol family in the installation package of the target application based on the revised content to obtain the revised target privacy protocol family, so that the target application can display the revised target privacy protocol family to the user after startup; The client device sends the revised target privacy protocol family to the second server, so that the second server updates the target privacy protocol family to the revised target privacy protocol family.
5. The method according to any one of claims 1 to 3, characterized in that When the first privacy behavior includes: a sensitive behavior and a control operation, after determining that the first privacy behavior uses the first personal data, the client device sends first information to the second server, including: After determining that the sensitive behavior uses the first personal data, the client device determines that the first information includes an identifier of the sensitive behavior and the content and identifier of the first personal data used by the sensitive behavior, and sends the identifier of the sensitive behavior and the content and identifier of the first personal data used by the sensitive behavior to the second server; And / or, after determining that the control operation uses the first personal data, the client device determines that the first information includes the identifier of the control operation and the content and identifier of the first personal data used by the control operation, and sends the identifier of the control operation and the content and identifier of the first personal data used by the control operation to the second server.
6. The method according to any one of claims 1 to 3, characterized in that When the first privacy behavior includes disclosure, after determining that the first privacy behavior uses the first personal data, the client device sends first information to the second server, including: The client device determines, based on the content and identifier of the first personal data, data disclosure status of the target application in the client device; After determining, based on the data disclosure status of the target application in the client device, that the disclosure behavior uses the first personal data, the client device determines that the first information includes an identifier of the disclosure behavior and the content and identifier of the first personal data used in the disclosure behavior; The client device sends an identifier of the disclosure behavior and the content and identifier of the first personal data used in the disclosure behavior to the second server.
7. The method according to any one of claims 1 to 3, characterized in that When the first privacy behavior includes a cross-border behavior, after determining that the first privacy behavior uses the first personal data, the client device sends first information to the second server, including: The client device determines, based on the content and identifier of the first personal data, a cross-border data situation of the target application in the client device; After determining, based on the cross-border data situation of the target application in the client device, that the cross-border behavior uses the first personal data, the client device determines that the first information includes an identifier of the cross-border behavior and the content and identifier of the first personal data used in the cross-border behavior; The client device sends the identifier of the cross-border behavior and the content and identifier of the first personal data used for the cross-border behavior to the second server.
8. The method according to any one of claims 1 to 3, characterized in that When the second privacy behavior includes: a rights behavior and a retention behavior, the second information includes: an identifier of the rights behavior and the content and identifier of the second personal data used in the rights behavior, and / or an identifier of the retention behavior and the content and identifier of the second personal data used in the retention behavior; Among them, the identifier of the right behavior and the content and identifier of the second personal data used by the right behavior are sent by the first server after determining that the right behavior uses the second personal data based on the data retention status of the target application in the first server. The identifier of the retention behavior and the content and identifier of the second personal data used by the retention behavior are sent by the first server after determining that the retention behavior uses the second personal data based on the data retention status of the target application in the first server. The data retention status of the target application in the first server is determined by the first server based on the content and identifier of the second personal data.
9. The method according to any one of claims 1 to 3, characterized in that When the second privacy behavior includes disclosure, the method further includes: The client device receives, from the first server, an identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior, included in the second information. The identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior are sent by the first server after determining, based on data disclosure status of the target application in the first server, that the disclosure behavior uses the second personal data. The data disclosure status of the target application in the first server is determined by the first server based on the content and identifier of the second personal data. The client device sends the identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior to the second server.
10. The method according to any one of claims 1 to 3, characterized in that When the second privacy behavior includes: a cross-border behavior, the method further includes: The client device receives, from the first server, an identifier of the cross-border behavior and the content and identifier of the second personal data used for the cross-border behavior, included in the second information. The identifier of the cross-border behavior and the content and identifier of the second personal data used for the cross-border behavior are sent by the first server after determining, based on the cross-border data status of the target application in the first server, that the cross-border behavior uses the second personal data. The cross-border data status of the target application in the first server is determined by the first server based on the content and identifier of the second personal data. The client device sends the identifier of the cross-border behavior and the content and identifier of the second personal data used for the cross-border behavior to the second server.
11. A method for generating a privacy protocol family for an application, characterized in that: Applied to a first server; the method includes: The first server receives, from a client device, first personal data of a target application in the client device, where the first personal data is acquired by the client device after running the target application; The first server determines, based on the first personal data, second personal data of the target application in the first server; After determining that the second privacy behavior uses the second personal data, the first server sends second information to the second server, where the second information is used to describe the privacy situation of the second privacy behavior using the second personal data. The second privacy behavior includes all behaviors of all applications in the first server that need to use personal data, so that the second server generates a target privacy protocol family based on the first information and the second information, and sends the target privacy protocol family to the client device. The target privacy protocol family is used by the client device to store in the installation package of the target application so that the target application can display the target privacy protocol family to the user after startup. The first information is sent to the second server by the client device after determining that the first privacy behavior uses the first personal data. The first information is used to describe the privacy situation of the first privacy behavior using the first personal data. The first privacy behavior includes all behaviors of all applications in the client device that need to use personal data.
12. The method according to claim 11, characterized in that When the second privacy behavior includes: a rights behavior and a retention behavior, after determining that the second privacy behavior uses the second personal data, the first server sends second information to the second server, including: The first server determines, based on the content and identifier of the second personal data, data retention status of the target application in the first server; After determining, based on the data retention situation, that the right action uses the second personal data, the first server determines that the second information includes an identifier of the right action and the content and identifier of the second personal data used in the right action, and sends the identifier of the right action and the content and identifier of the second personal data used in the right action to the second server; And / or, after determining that the retention behavior uses the second personal data based on the data retention situation, the first server determines that the second information includes the identifier of the retention behavior and the content and identifier of the second personal data used by the retention behavior, and sends the identifier of the retention behavior and the content and identifier of the second personal data used by the retention behavior to the second server.
13. The method according to claim 11 or 12, characterized in that When the second privacy behavior includes disclosure, after determining that the second privacy behavior uses the second personal data, the first server sends second information to the second server, including: The first server determines, based on the content and identifier of the second personal data, data disclosure status of the target application in the first server; After determining, based on the data disclosure status of the target application on the first server, that the disclosure behavior uses the second personal data, the first server determines that the second information includes an identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior; The first server sends, to the second server, an identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior; Alternatively, the first server sends the identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior to the second server through the client device.
14. The method according to claim 11 or 12, characterized in that When the second privacy behavior includes a cross-border behavior, after determining that the second privacy behavior uses the second personal data, the first server sends second information to the second server, including: The first server determines, based on the content and identifier of the second personal data, a cross-border data situation of the target application in the first server; After determining, based on the cross-border data situation of the target application in the first server, that the cross-border behavior uses the second personal data, the first server determines that the second information includes an identifier of the cross-border behavior and the content and identifier of the second personal data used in the cross-border behavior; The first server sends the identifier of the cross-border behavior and the content and identifier of the second personal data used for the cross-border behavior to the second server; Alternatively, the first server sends the identifier of the cross-border behavior and the content and identifier of the second personal data used for the cross-border behavior to the second server through the client device.
15. A method for generating a privacy protocol family for an application, characterized in that: Applied to the second server; the method includes: The second server receives first information from a client device, the first information being sent by the client device after determining that a first privacy behavior uses first personal data, the first information being used to describe a privacy situation in which the first privacy behavior uses the first personal data of a target application in the client device, the first privacy behavior including all behaviors of all applications in the client device that require use of personal data, and the first personal data being obtained by the client device after running the target application; The second server receives second information from the first server, the second information being sent by the first server after determining that a second privacy behavior uses second personal data of the target application in the first server, the second information being used to describe a privacy situation in which the second privacy behavior uses the second personal data, the second privacy behavior including all behaviors of all applications in the first server that require use of personal data, and the second personal data being determined by the first server based on the first personal data; The second server generates a target privacy protocol family based on the first information and the second information; The second server sends the target privacy protocol family to the client device, and the target privacy protocol family is used by the client device to store in the installation package of the target application, so that the target application can display the target privacy protocol family to the user after startup.
16. The method according to claim 15, characterized in that The method further comprises: The second server receives the installation package of the target application from the client device, where the installation package of the target application is sent by the client device when the client device determines that the installation package of the target application is a new version; The second server determines the difference between the new version and the old version based on the installation package of the target application; The second server updates the target privacy protocol family corresponding to the old version based on the difference to obtain a new version of the target privacy protocol family; The second server sends the target privacy protocol family corresponding to the new version to the client device. The target privacy protocol family corresponding to the new version is used by the client device to update the target privacy protocol family corresponding to the old version in the installation package of the target application to the target privacy protocol family corresponding to the new version, so that the target application can display the target privacy protocol family corresponding to the new version to the user after startup.
17. The method according to claim 15 or 16, characterized in that The method further comprises: The second server receives the revised target privacy protocol family from the client device, where the revised target privacy protocol family is obtained by the client device updating the target privacy protocol family in the installation package of the target application based on the received revised content of the target privacy protocol family, and the revised content is received by the client device after displaying all content of the target privacy protocol family; The second server updates the target privacy protocol family to the revised target privacy protocol family.
18. The method according to claim 15 or 16, characterized in that When the first privacy behavior includes: a sensitive behavior and a control operation, the second server receives first information from the client device, including: The second server receives, from the client device, an identifier of the sensitive behavior and the content and identifier of the first personal data used by the sensitive behavior, included in the first information, where the identifier of the sensitive behavior and the content and identifier of the first personal data used by the sensitive behavior are sent by the client device after determining that the sensitive behavior uses the first personal data; And / or, the second server receives the identifier of the control operation and the content and identifier of the first personal data used by the control operation included in the first information from the client device, and the identifier of the control operation and the content and identifier of the first personal data used by the control operation are sent by the client device after determining that the control operation uses the first personal data.
19. The method according to claim 15 or 16, characterized in that When the first privacy behavior includes disclosure, the second server receives first information from the client device, including: The second server receives from the client device an identifier of the disclosure behavior and the content and identifier of the first personal data used in the disclosure behavior included in the first information. The identifier of the disclosure behavior and the content and identifier of the first personal data used in the disclosure behavior are sent by the client device after determining that the disclosure behavior uses the first personal data based on the data disclosure status of the target application in the client device. The data disclosure status of the target application in the client device is determined by the client device based on the content and identifier of the first personal data.
20. The method according to claim 15 or 16, characterized in that When the first privacy behavior includes a cross-border behavior, the second server receives first information from the client device, including: The second server receives the identifier of the cross-border behavior and the content and identifier of the first personal data used for the cross-border behavior included in the first information from the client device. The identifier of the cross-border behavior and the content and identifier of the first personal data used for the cross-border behavior are sent by the client device after determining that the cross-border behavior uses the first personal data based on the cross-border data situation of the target application in the client device. The cross-border data situation of the target application in the client device is determined by the client device based on the content and identifier of the first personal data.
21. The method according to claim 15 or 16, characterized in that When the second privacy behavior includes: a rights behavior and a retention behavior, the second server receives second information from the first server, including: The second server receives, from the first server, the identifier of the rights act and the content and identifier of the second personal data used in the rights act, included in the second information. The identifier of the rights act and the content and identifier of the second personal data used in the rights act are sent by the first server after determining, based on data retention, that the rights act uses the second personal data. and / or, the second server receives, from the first server, an identifier of the retention behavior and the content and identifier of the second personal data used in the retention behavior, included in the second information, wherein the identifier of the retention behavior and the content and identifier of the second personal data used in the retention behavior are sent by the first server after determining, based on the data retention situation, that the retention behavior uses the second personal data; The data retention status of the target application in the first server is determined by the first server based on the content and identifier of the second personal data.
22. The method according to claim 15 or 16, characterized in that When the second privacy behavior includes: a disclosure behavior, the second server receives second information from the first server, including: The second server receives, from the first server, an identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior, included in the second information; Alternatively, the second server receives, from the first server through the client device, the identifier of the disclosure behavior and the content and identifier of the second personal data used in the disclosure behavior, included in the second information; Among them, the identifier of the disclosure behavior and the content and identifier of the second personal data used by the disclosure behavior are sent by the first server after determining that the disclosure behavior uses the second personal data based on the data disclosure status of the target application in the first server. The data disclosure status of the target application in the first server is determined by the first server based on the content and identifier of the second personal data.
23. The method according to claim 15 or 16, characterized in that When the second privacy behavior includes a cross-border behavior, the second server receives second information from the first server, including: The second server receives, from the first server, the identifier of the cross-border behavior and the content and identifier of the second personal data used for the cross-border behavior included in the second information; Alternatively, the second server receives, from the first server through the client device, the identifier of the cross-border behavior and the content and identifier of the second personal data used for the cross-border behavior included in the second information; Among them, the identification of the cross-border behavior and the content and identification of the second personal data used by the cross-border behavior are sent by the first server after determining that the cross-border behavior uses the second personal data based on the cross-border data situation of the target application in the first server. The cross-border data situation of the target application in the first server is determined by the first server based on the content and identification of the second personal data.
24. A client device, characterized in that include: memory and processor; The memory is used to store program instructions; The processor is used to call the program instructions in the memory so that the client device executes the privacy protocol family generation method for the application described in any one of claims 1-10.
25. A server, characterized in that: include: memory and processor; The memory is used to store program instructions; The processor is used to call the program instructions in the memory so that the server executes the privacy protocol family generation method for the application described in any one of claims 11-14 and / or any one of claims 15-23.
26. A computer-readable storage medium, characterized in that The method comprises computer instructions, which, when executed on a client device, cause the client device to execute the method for generating a privacy protocol family for an application as described in any one of claims 1 to 10, or, when executed on a server, cause the server to execute the method for generating a privacy protocol family for an application as described in any one of claims 11 to 14 and / or any one of claims 15 to 23.
27. A computer program product, characterized in that When the computer program product runs on a computer, the computer executes the method for generating a privacy protocol family for an application as described in any one of claims 1 to 10, or the computer executes the method for generating a privacy protocol family for an application as described in any one of claims 11 to 14 and / or 15 to 23.
Citation Information
Patent Citations
Content sharing method and electronic equipment
CN110378145A
Data processing method and device
CN111773730A