A data transmission method, apparatus, device and medium
By configuring a target data gateway and a distributed architecture in the data platform, and using data audit rules to automatically filter and transmit data, the universality and efficiency issues of cross-border data legality detection are solved, and real-time secure transmission of cross-border data is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TRANSWARP TECHNOLOGY (SHANGHAI) CO LTD
- Filing Date
- 2022-12-29
- Publication Date
- 2026-05-05
AI Technical Summary
Existing technologies for data legality detection lack universality, are difficult to apply to the compliance requirements of different countries, and have low data processing efficiency, making them unable to process big data and streaming data in real time.
By configuring a target data gateway in the data platform, data auditing rules are used to automatically audit the data to be transmitted, filter out the target data that meets the requirements, and deploy multiple instance nodes in a distributed architecture to achieve real-time data processing and secure transmission.
It enables automatic real-time auditing of cross-border data, applicable to any data platform, ensuring the universality and efficiency of data auditing, and guaranteeing data security and compliance.
Smart Images

Figure CN116015925B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to a data transmission method, apparatus, device, and medium. Background Technology
[0002] With the enactment of regulations regarding cross-border data transfers by various countries, it has become increasingly difficult to detect whether cross-border data contains sensitive information that is prohibited from being transferred due to differing compliance requirements across countries. Current compliance detection solutions mostly rely on manual or batch processing to check for confidential information. For big data and streaming data, where efficiency and time are critical for data review, current solutions are insufficient. Summary of the Invention
[0003] This invention provides a data transmission method, apparatus, device, and medium to solve the technical problems of data legality detection lacking universality and low data processing efficiency in the prior art.
[0004] According to one aspect of the present invention, a data transmission method is provided, applied to a first data platform, comprising:
[0005] In response to a data request sent by the second data platform, acquire the data to be transmitted that matches the data request;
[0006] The data audit rules corresponding to the first data platform are retrieved from the target data gateway; the target data gateway is configured in the data sandbox provided by the first data platform to the second data platform.
[0007] The data to be transmitted is audited according to the data auditing rules to obtain the corresponding target transmission data; wherein, the target transmission data is a subset of the data to be transmitted.
[0008] The target transmission data is sent to the second data platform.
[0009] According to another aspect of the present invention, a data transmission apparatus is provided, characterized in that it is applied to a first data platform and includes:
[0010] The first acquisition module is used to acquire data to be transmitted that matches the data request sent by the second data platform in response to the data request.
[0011] The lookup module is used to search for the data audit rules corresponding to the first data platform from the target data gateway; the target data gateway is configured in the data sandbox provided by the first data platform to the second data platform.
[0012] An auditing module is used to audit the data to be transmitted according to the data auditing rules to obtain the corresponding target transmission data; wherein the target transmission data is a subset of the data to be transmitted.
[0013] The transmission module is used to send the target transmission data to the second data platform.
[0014] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0015] At least one processor; and
[0016] A memory communicatively connected to the at least one processor; wherein,
[0017] The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the data transmission method described in any embodiment of the present invention.
[0018] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the data transmission method described in any embodiment of the present invention.
[0019] The technical solution of this invention, upon receiving a data request from a second data platform, acquires the data to be transmitted that matches the data request, searches for the data audit rules corresponding to the first data platform from the target data gateway, and automatically audits the data to be transmitted according to the data audit rules to obtain the target transmission data that meets the requirements, and then sends the target transmission data to the second data platform. This solves the technical problems of the lack of universality in data legality detection and low data processing efficiency in the prior art, realizes automatic real-time auditing of data that needs to cross borders, and processes the data to be transmitted according to different data audit rules corresponding to the first data platform, thus making it applicable to any data platform and ensuring the universality of data auditing.
[0020] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0022] Figure 1 This is a flowchart of a data transmission method provided in an embodiment of the present invention;
[0023] Figure 2 This is a flowchart of another data transmission method provided in an embodiment of the present invention;
[0024] Figure 3 This is a flowchart of another data transmission method provided in an embodiment of the present invention;
[0025] Figure 4 This is a flowchart of another data transmission method provided in an embodiment of the present invention;
[0026] Figure 5 This is an interactive schematic diagram of data transmission provided by an embodiment of the present invention;
[0027] Figure 6 This is a schematic diagram of the architecture of a data gateway provided in an embodiment of the present invention;
[0028] Figure 7 This is a schematic diagram of a data processing flow provided in an embodiment of the present invention;
[0029] Figure 8 This is a schematic diagram of the structure of a data transmission device provided in an embodiment of the present invention;
[0030] Figure 9 This is a structural block diagram of an electronic device provided in an embodiment of the present invention. Detailed Implementation
[0031] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0032] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0033] Among the existing cross-border data transmission solutions, there are two approaches:
[0034] First, a compliance factor library is generated based on the legal and regulatory requirements for cross-border or outbound transfer of personal privacy data, as well as relevant standards or specifications issued by the industry to which the organization or enterprise belongs; relevant cross-border documents are obtained; cross-border transmission data and corresponding interface information are obtained; the relevant cross-border documents and each compliance factor in the compliance factor library are compared to determine whether the relevant cross-border documents contain any non-compliance items; if the relevant cross-border documents contain non-compliance items, an alarm message for non-compliance items is output; the type of the interface is determined based on the transmission target IP address in the interface information to determine whether the interface is a cross-border transmission interface; if the interface is a cross-border transmission interface, the cross-border transmission data is identified for personal privacy data to obtain an identification result; it is determined whether the identification result contains personal privacy data; if the identification result contains personal privacy data, the cross-border transmission data is blocked in conjunction with the non-compliance items; if the relevant cross-border documents do not contain any non-compliance items, the cross-border transmission data is encrypted.
[0035] Secondly, it receives analysis requests from users; based on the analysis requests, it determines the outbound data network traffic to be analyzed, determines the search keywords based on the analysis requests, traverses the outbound data network traffic to be analyzed, and searches for sensitive outbound data that matches the search keywords.
[0036] However, the solution is only applicable to domestic data export detection and is not universally applicable; it cannot process export data in real time and change rules in real time, and the manual operation process is relatively inefficient; the compliance factor comparison process is carried out on a single node, which requires a long execution time when the data volume is large, resulting in low performance and inability to guarantee real-time processing; the review and transmission process of export data does not take security into consideration and is vulnerable to man-in-the-middle attacks. Attackers can modify the rules or data, which can lead to the leakage of confidential data or data unavailability.
[0037] Option 2 does not employ a distributed architecture. Instead, it performs a single-point traversal of outbound data, checking for specified keywords in the outbound traffic to determine if the data is sensitive. Therefore, performance cannot be guaranteed, and keyword matching itself has low accuracy, making it prone to false positives and false negatives. Furthermore, when data monitoring rules change, keywords need to be manually reset, resulting in low efficiency.
[0038] In view of this, embodiments of the present invention provide a data transmission method that automatically audits the data to be transmitted according to the data audit rules of a first data platform, thereby improving data processing efficiency while ensuring the universality of the solution.
[0039] In one embodiment, Figure 1 This is a flowchart illustrating a data transmission method provided in an embodiment of the present invention. This embodiment is applicable to data transmission between two cross-border data platforms. The method can be executed by a data transmission device, which can be implemented in hardware and / or software and can be configured in an electronic device. For example, the electronic device can be a computer, laptop, or other terminal with data transmission capabilities. Figure 1 As shown, the method includes:
[0040] S110. In response to a data request sent by the second data platform, obtain the data to be transmitted that matches the data request.
[0041] The second data platform and the first data platform belong to different regions. This can be understood as data transmission between the first and second data platforms constituting cross-border data transfer. In practice, the first and second data platforms can belong to different companies within different regions, and these companies may have business dealings. For example, the first and second data platforms can be any data platform, such as a financial platform. In this embodiment, data requests may include, but are not limited to, data access requests and data acquisition requests.
[0042] In this embodiment, when the first data platform receives a data request from the second data platform, the first data platform searches its own database for matching data based on the data request, which is then used as the corresponding data to be transmitted. Of course, to more accurately locate the data to be transmitted, the data required by the second data platform can be directly included in the data request.
[0043] S120. Locate the data audit rules corresponding to the first data platform from the target data gateway.
[0044] The target data gateway is configured within the data sandbox provided by the first data platform to the second data platform. The data sandbox is a closed data development environment provided by the data provider (the first data platform) to the data requester (the second data platform). It meets the needs of internal and inter-enterprise sharing scenarios, comprehensively ensuring data accessibility and controllable data exit through database security, data content security, and infrastructure security, enabling secure and open data sharing under compliant and legal conditions. In this embodiment, the target data gateway serves as the data interaction interface between the first and second data platforms. For example, the target data gateway can be an SQL gateway or an API gateway; there is no limitation on either. The SQL gateway is middleware, acting as an interface for drivers accessing SQL databases, providing functions including but not limited to load balancing, SQL rule routing, intelligent routing, web operations and maintenance, and security, according to the configuration file. The API gateway is used for request routing, API combination, and protocol conversion. All API requests from external clients are first routed to the API gateway, which then routes some requests to the corresponding services.
[0045] In this embodiment, data audit rules are used to audit whether the data processing of the data to be transmitted is compliant, whether the data policy is correctly executed, and whether the shared content is compliant. It should be noted that the target data gateway may contain data audit rules corresponding to different data platforms, so during data auditing, the data audit rules corresponding to the data platform can be directly retrieved from the target data gateway.
[0046] S130. Audit the data to be transmitted according to the data audit rules to obtain the corresponding target transmission data.
[0047] In this embodiment, the target data to be transmitted is a subset of the data to be transmitted. Specifically, if all the data to be transmitted conforms to the data audit rules corresponding to the first data platform, then the target data to be transmitted is the data to be transmitted; if only a portion of the data to be transmitted conforms to the data audit rules corresponding to the first data platform, then the target data to be transmitted is a subset of the data to be transmitted.
[0048] In this embodiment, corresponding data audit rules can be generated according to different data security policies, and audits can be conducted based on the data audit rules to determine whether the data processing of the data to be transmitted is compliant, whether the data policy is correctly executed, and whether the shared content is compliant, so as to obtain the corresponding target transmitted data.
[0049] S140, Send the target transmission data to the second data platform.
[0050] In this embodiment, the first data platform transmits target data that conforms to data audit rules to the second data platform through the target data gateway. This ensures data processing performance while preventing data security issues related to non-compliant data during cross-border transmission. Simultaneously, data that does not conform to data audit rules is stored in a data sandbox. To ensure effective utilization of the storage space in the data sandbox, a data expiration period can be set for non-compliant data. Once the expiration period is reached, the non-compliant data is automatically destroyed.
[0051] The technical solution of this embodiment solves the technical problems of data legality detection lacking universality and low data processing efficiency in the prior art by obtaining the data to be transmitted matching the data request when a data request is received from the second data platform, searching for the data audit rules corresponding to the first data platform from the target data gateway, and automatically auditing the data to be transmitted according to the data audit rules to obtain the target transmission data that meets the requirements, and sending the target transmission data to the second data platform. It realizes automatic real-time auditing of data that needs to cross borders, and processes the data to be transmitted according to the different data audit rules corresponding to the first data platform, so it can be applied to any data platform and ensures the universality of data auditing.
[0052] In one embodiment, Figure 2 This is a flowchart of another data transmission method provided by an embodiment of the present invention. This embodiment describes the process of determining the target instance node based on the above embodiments. Figure 2 As shown, the method includes:
[0053] S210. In response to the data request sent by the second data platform, obtain the current running status of each instance node in the target data gateway.
[0054] The current running state is used to characterize the current running state of the instance node. For example, the current running state may include, but is not limited to, a working state and an idle state. The working state refers to the instance node being in the process of processing data; the idle state refers to the instance node being in a state of inactivity.
[0055] In this embodiment, multiple instance nodes can be configured in the target data gateway, and each instance node has the same function, that is, it can all process data requests.
[0056] S220. Based on the load balancing principle and the current running status of each instance node, determine the target instance node corresponding to the data request, so as to process the data request through the target instance node.
[0057] The target instance node refers to the instance node that processes the currently received data request. In practice, each instance node can only process one data request at a time.
[0058] In this embodiment, a load balancing service is implemented in the target data gateway. Upon receiving a data request from the second data platform, the data request is allocated to the corresponding instance node, i.e., the target instance node, based on load balancing principles. However, in actual operation, if each instance node in the target data gateway is active (processing other data requests) when a data request from the second data platform is received, the data request from the second data platform is queued, waiting for one of the instance nodes to complete its data processing before being processed. If each instance node in the target data gateway is idle when a data request from the second data platform is received, the data request from the second data platform can be randomly allocated to an instance node, which will serve as the target instance node.
[0059] S230: Obtain the data to be transmitted that matches the data request.
[0060] S240. Locate the data audit rules corresponding to the first data platform from the target data gateway.
[0061] The target data gateway is configured in the data sandbox provided by the first data platform to the second data platform.
[0062] S250. Audit the data to be transmitted according to the data auditing rules to obtain the corresponding target data to be transmitted. The target data to be transmitted is a subset of the data to be transmitted.
[0063] In one embodiment, S250 includes S2501-S2502:
[0064] S2501. Filter out sensitive data from the data to be transmitted.
[0065] Sensitive data refers to data that, if leaked, may cause serious harm to society or individuals. For example, sensitive data may include personal privacy data or data that is unsuitable for publication by the company. In this embodiment, the data to be transmitted is traversed and identified to extract personal privacy data and / or data unsuitable for publication by the company, which are then designated as the corresponding sensitive data.
[0066] In this embodiment, it is determined whether the sensitive data has been classified and graded. If the data has been classified and graded, it is determined whether to perform de-identification. If it has been de-identified, it can be transmitted. If it has been classified and graded but has not undergone static de-identification, it needs to be dynamically de-identified in the target data gateway.
[0067] S2502. Perform truncation and / or desensitization operations on sensitive data in accordance with data auditing rules to obtain the corresponding target transmission data.
[0068] In this embodiment, after the data security policy is applied to the target data gateway, the target data gateway automatically creates corresponding data audit rules according to the data security policy. When the data to be transmitted needs to be transmitted to a cross-border second data platform, the target data gateway detects all data passing through the gateway according to the data audit rules.
[0069] Data is intercepted in the following situations: data that is not classified or graded; top-secret data; and confidential data that has not been anonymized. In this embodiment, after the data to be intercepted is truncated, the other data in the data to be transmitted can be used as the target data for transmission.
[0070] S260, Send the target transmission data to the second data platform.
[0071] The technical solution of this embodiment, based on the above embodiments, deploys multiple instance nodes in a distributed architecture in the target data gateway, and the multiple instance nodes can process data requests simultaneously, ensuring real-time data processing performance in big data scenarios, reducing congestion during cross-border data transmission, and ensuring real-time data processing; and desensitizes and / or truncates sensitive data in the data to be transmitted, ensuring the security of non-compliant data during cross-border transmission.
[0072] In one embodiment, Figure 3 This is a flowchart illustrating another data transmission method provided by an embodiment of the present invention. This embodiment, based on the above embodiments, describes the updating process of data security policies and data audit rules. The data audit rules and the data security policies are presented as plugins in the instance nodes. Figure 3 As shown, the method includes:
[0073] S310. Obtain the data security policy corresponding to the first data platform from the data supervision platform associated with the first data platform.
[0074] The data security policy is used to classify data according to different levels of importance and formulate different security policies for different levels of data. These policies include methods such as direct access, data anonymization, and access prohibition. In this embodiment, the data supervision platform is used to supervise the data transmission of each data platform and to configure the corresponding data security policy for each data platform. It can be understood that the data security policy for each data platform originates from the data supervision platform.
[0075] S320. Store the data security policy in the target database of the target data gateway, so that each instance node in the target data gateway can obtain the data security policy from the target database and update the data audit rules according to the data security policy.
[0076] The target database refers to a pre-configured storage space within the target data gateway. In this embodiment, different instance nodes within the target data gateway can share the same target database. When a new data security policy is issued by the data supervision platform, the data security policy is stored in the target database of the target data gateway. Different instance nodes can read the data security policy from this target database and update the corresponding data audit rules accordingly.
[0077] Of course, the target data gateway in the data sandbox can also proactively obtain data security policies from the data supervision platform. This can be understood as follows: when receiving a data request from a second data platform, if the target data gateway cannot find the corresponding data audit rules for the first data platform, it can proactively access the data supervision platform to obtain the data security policies for the first data platform and update the corresponding data audit rules based on those policies, thus obtaining the data audit rules for the first data platform.
[0078] S330, in response to the update instruction of the data security policy corresponding to the first data platform in the data supervision platform, update the data security policy corresponding to the first data platform on the blockchain.
[0079] The data security policy update instruction can be understood as an instruction from the data supervision platform to reconfigure the data security policy corresponding to the first data platform. In this embodiment, after the data supervision platform reconfigures the data security policy corresponding to the first data platform, it distributes the reconfigured data security policy to the target data gateway. A special protocol (e.g., blockchain) can be used during the distribution of the data security policy. When the data supervision platform specifies a new data security policy for the first data platform, it can update the policy on the blockchain.
[0080] S340: Based on the updated data security policy on the blockchain, the corresponding data security policy plugin in the target database of the target data gateway is updated in real time.
[0081] In this embodiment, the target data gateway reads the updated data security policy from the blockchain and updates the corresponding data security policy in its target database based on the new data security policy. Each instance node in the target data gateway updates the plugin for the corresponding data security policy based on the new data security policy.
[0082] S350: In response to a data request sent by the second data platform, obtain the data to be transmitted that matches the data request.
[0083] S360. Locate the data audit rules corresponding to the first data platform from the target data gateway.
[0084] The target data gateway is configured in the data sandbox provided by the first data platform to the second data platform.
[0085] S370. Audit the data to be transmitted according to the data audit rules to obtain the corresponding target data.
[0086] The target data to be transmitted is a subset of the data to be transmitted.
[0087] S380, Send the target transmission data to the second data platform.
[0088] The technical solution of this embodiment, based on the above embodiments, uses blockchain to update the corresponding data security policy in the target data gateway when the data supervision platform issues a new data security policy, to prevent man-in-the-middle tampering, thereby ensuring the trustworthiness and traceability of operations between multiple data platforms.
[0089] It should be noted that the update steps for data security policies and data audit rules can be performed at any stage of the data transmission process. This means that steps S310-S340 can be performed before or after S350; there is no limitation on this, as long as the data audit rules corresponding to the first data platform are stored in the target database of the target data gateway before searching for them.
[0090] In one embodiment, Figure 4 This is a flowchart of another data transmission method provided by an embodiment of the present invention. This embodiment describes the data audit result transmission process based on the above embodiments. Figure 4 As shown, the method includes:
[0091] S410, In response to a data request sent by the second data platform, obtain the data to be transmitted that matches the data request.
[0092] S420. Locate the data audit rules corresponding to the first data platform from the target data gateway.
[0093] The target data gateway is configured in the data sandbox provided by the first data platform to the second data platform.
[0094] S430. Audit the data to be transmitted in accordance with the data audit rules to obtain the corresponding target transmitted data and data audit results.
[0095] The target data to be transmitted is a subset of the data to be transmitted. The data audit results are used to ensure that data processing is compliant, data security policies are correctly implemented, and the shared content is compliant. In this embodiment, the data audit results may include ordinary access records as well as alerts indicating attempted access that violates data security policies.
[0096] S440: Send the target transmission data to the second data platform.
[0097] S450. Feedback the data audit results to the data supervision platform associated with the first data platform, so that the data supervision platform can adjust the corresponding data security strategy in real time based on the data audit results.
[0098] In this embodiment, data audit results are fed back to the data supervision platform in real time, enabling the platform to promptly assess whether cross-border data flows meet certain industry standards. The data supervision platform can adjust data security policies in real time based on the audit results (e.g., dynamically updating access blacklists) and distribute these policies to target data gateways within the data sandbox.
[0099] In one embodiment, feeding back the data audit results to the data supervision platform associated with the first data platform includes: updating the data audit results to the corresponding blockchain; and feeding back the data audit results to the data supervision platform via the blockchain.
[0100] In this embodiment, the target data gateway associated with the first data platform can update the data audit results to the corresponding blockchain and transmit the data audit results to the corresponding data supervision platform via the blockchain. Due to the characteristics of blockchain, each data audit result can be recorded, preventing tampering by a middleman, thereby ensuring the trustworthiness and traceability of operations between various data platforms.
[0101] In this embodiment, the execution order between S440 and S450 is not limited, as long as both S440 and S450 are executed after S430.
[0102] In one embodiment, Figure 5This is an interactive diagram illustrating data transmission according to an embodiment of the present invention. Assume the access link is A <-> B, and A and B belong to different countries with different regulations regarding data export. In this embodiment, the new access paths are A -> data gateway in country A -> B (i.e., A to the data gateway in country A, then to country B), and B -> data gateway in country B -> A (B to the data gateway in country B, then to country A). Here, A represents the first data platform, and B represents the second data platform. Both data gateways have built-in data security policies and data audit rules based on the different data export requirements of each country, and perform real-time online data review and truncation according to these policies. Since real-time data review and truncation have high performance requirements, the gateways must be implemented using a distributed architecture. Each SQL / API gateway (i.e., the target data gateway mentioned above) has multiple instance nodes, and each instance node can receive and process data requests from the target end, ensuring real-time data processing. A front-end load balancing service is used to send data that conforms to the rules to the target end and truncate data that does not conform to the rules.
[0103] like Figure 5 As shown, taking Company A sharing data with Company B, and data gateway A including 3 instance nodes as an example, when receiving a data request from Company B, the data request is assigned to the corresponding instance node for processing according to the load balancing principle. Then, the data to be transmitted in A that matches the data request is transmitted to data gateway A. One of the instance nodes in data gateway A audits the data to be transmitted to obtain the corresponding data audit rules and target transmission data. The target transmission data that meets the data audit rules is sent to Company B, and the data that does not meet the data audit rules (i.e., other data in the data to be transmitted besides the target transmission data) is truncated.
[0104] In one embodiment, Figure 6 This is a schematic diagram of a data gateway architecture provided by an embodiment of the present invention. Taking an SQL gateway / API gateway as an example, as shown... Figure 6 As shown, to ensure no third party can snoop on the data, the data gateway is built within a data sandbox provided by a third-party hosting platform. Taking A as an example, only data that complies with the data security policy and undergoes auditing according to the audit rules can be sent to B. All other data is stored in the sandbox (a data expiration period can be set, and expired data will be destroyed). However, its data audit rules and data security policies come from the data supervision platform. The detection results of the data security policy and the data audit results are transmitted to the data supervision platform in real time. The data audit results include ordinary access records and alerts for attempted access that violates the security policy.
[0105] Real-time data policy protection and auditing are implemented based on a unified SQL gateway or API gateway. These gateways contain multiple instance nodes, each with the same function, capable of handling data requests. The instance nodes are implemented using a plug-in approach, enabling real-time parsing and updating of relevant data security policies and data audit rules. Based on these rules, compliance checks are performed during data flow, and data management is carried out after the checks are completed.
[0106] The gateway processes two types of data: 1. Data that has been categorized and graded, and has undergone anonymization according to different grading levels; 2. Data that has been categorized and graded but has not undergone static anonymization, but requires dynamic anonymization at the gateway. When the data security policy is applied to the SQL gateway / API gateway, audit rules are automatically created in the gateway. When data requests to leave the country, the gateway checks all data passing through it according to the audit rules. Data is intercepted in the following situations, and the processing results are fed back to the data supervision platform: data that is not categorized or graded; top-secret data; confidential data that has not undergone anonymization.
[0107] Taking the A->B link as an example, data that complies with the data security policy is sent to B, and a log is recorded. The processing result is then fed back to the data supervision platform of the country where A is located.
[0108] In one embodiment, Figure 7 This is a schematic diagram of a data processing flow provided by an embodiment of the present invention. Figure 7 As shown, the data gateway in the data sandbox can obtain data security policies from the data supervision platform. Different instance nodes of the data gateway can share the same data storage (e.g., database, NFS, etc.). When the data supervision platform issues a new data security policy, it stores the policy in the data storage. Different instance nodes read the database and uniformly update the data audit rules. Within the data sandbox, the data gateway completes data audit analysis tasks in real time as required and feeds back the data audit results to the data supervision platform. Therefore, the data supervision platform can promptly grasp whether cross-border data flows in the data link meet certain industry standards. The data supervision platform can adjust the data security policy in real time based on the data audit results (e.g., dynamically update the access blacklist, etc.) and distribute the data security policy to the data gateway in the sandbox. Non-compliant data in the data to be transmitted corresponding to A that does not meet the data security policy and / or data audit rules is saved in the data sandbox and destroyed after the data validity period expires. Target transmission data in the data to be transmitted corresponding to A that meets the data security policy and data audit rules is transmitted to B.
[0109] The issuance of data security policies and data audit rules, as well as the retrieval of data audit results, can employ special protocols (such as blockchain). Whenever the data supervision platform designates a new policy, it updates the blockchain. The data gateway then reads these data security policies and processes the data within its data sandbox. The analysis results from the data gateway are also transmitted to the data supervision platform via the blockchain. Due to the characteristics of blockchain, each new policy and each analysis result is recorded, preventing man-in-the-middle tampering and ensuring the trustworthiness and traceability of operations among all parties.
[0110] In one embodiment, Figure 8 This is a schematic diagram of the structure of a data transmission device provided in an embodiment of the present invention. Figure 8 As shown, the device includes: a first acquisition module 810, a search module 820, an audit module 830, and a transmission module 840.
[0111] The first acquisition module 810 is used to acquire the data to be transmitted that matches the data request in response to the data request sent by the second data platform.
[0112] The lookup module 820 is used to look up the data audit rules corresponding to the first data platform from the target data gateway; the target data gateway is configured in the data sandbox provided by the first data platform to the second data platform.
[0113] The audit module 830 is used to audit the data to be transmitted according to the data audit rules to obtain the corresponding target data to be transmitted; wherein, the target data to be transmitted is a subset of the data to be transmitted.
[0114] The transmission module 840 is used to send the target transmission data to the second data platform.
[0115] In one embodiment, the data transmission device further includes:
[0116] The second acquisition module is used to acquire the data security policy corresponding to the first data platform from the data supervision platform associated with the first data platform;
[0117] The storage module is used to store data security policies in the target database of the target data gateway, so that each instance node in the target data gateway can retrieve the data security policies from the target database and update the data audit rules according to the data security policies.
[0118] In one embodiment, after responding to a data request sent by the second data platform, the data transmission device further includes:
[0119] The third acquisition module is used to acquire the current running status of each instance node in the target data gateway;
[0120] The determination module is used to determine the target instance node corresponding to the data request based on the load balancing principle and the current running status of each instance node, so that the data request can be processed through the target instance node.
[0121] In one embodiment, the data transmission device further includes:
[0122] The audit module 830 is also used to audit the data to be transmitted according to the data audit rules and obtain the corresponding data audit results;
[0123] The feedback module is used to send the data audit results back to the data supervision platform associated with the first data platform, so that the data supervision platform can adjust the corresponding data security strategy in real time based on the data audit results.
[0124] In one embodiment, the data audit results are fed back to the regulatory platform associated with the first data platform, specifically for: updating the data audit results to the corresponding blockchain; and feeding back the data audit results to the data regulatory platform via the blockchain.
[0125] In one embodiment, the audit module includes:
[0126] The filtering unit is used to filter out sensitive data from the data to be transmitted.
[0127] The processing unit is used to perform truncation and / or desensitization operations on sensitive data according to data auditing rules to obtain the corresponding target transmission data.
[0128] In one embodiment, data auditing rules and data security policies are presented as plug-ins in the instance node; the data transmission device further includes:
[0129] The first update module is used to respond to the update command of the data security policy corresponding to the first data platform in the data supervision platform and update the data security policy corresponding to the first data platform on the blockchain.
[0130] The second update module is used to update the corresponding data security policy plugins in the target database of the target data gateway in real time based on the updated data security policies on the blockchain.
[0131] The data transmission device provided in the embodiments of the present invention can execute the data transmission method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the method.
[0132] In one embodiment, Figure 9 This is a structural block diagram of an electronic device provided in an embodiment of the present invention. For example... Figure 9The diagram illustrates a schematic representation of an electronic device 10 that can be used to implement embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0133] like Figure 9 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0134] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0135] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as data transfer methods.
[0136] In some embodiments, the data transfer method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the data transfer method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the data transfer method by any other suitable means (e.g., by means of firmware).
[0137] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0138] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0139] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0140] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0141] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0142] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0143] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0144] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A data transmission method, characterized in that, Applied to the first data platform, including: In response to a data request sent by a second data platform, acquire the data to be transmitted that matches the data request; wherein the second data platform and the first data platform belong to different regions; The data audit rules corresponding to the first data platform are retrieved from the target data gateway; the target data gateway is configured in the data sandbox provided by the first data platform to the second data platform. The data to be transmitted is audited according to the data audit rules to obtain the corresponding target transmission data; wherein, the target transmission data is a subset of the data to be transmitted, and only contains data that conforms to the data audit rules; The target transmission data that conforms to the data audit rules is sent to the second data platform. Data that does not conform to the data audit rules is stored in the data sandbox and a data validity period is set. After the data that does not conform to the data audit rules reaches the data validity period, the data that does not conform to the data audit rules is automatically destroyed. The step of auditing the data to be transmitted according to the data auditing rules to obtain the corresponding target transmission data includes: Sensitive data was obtained from the data to be transmitted; According to the data auditing rules, the sensitive data is truncated and / or desensitized to obtain the corresponding target transmission data.
2. The method according to claim 1, characterized in that, Also includes: Obtain the data security policy corresponding to the first data platform from the data supervision platform associated with the first data platform; The data security policy is stored in the target database of the target data gateway, so that each instance node in the target data gateway can obtain the data security policy from the target database and update the data audit rules according to the data security policy.
3. The method according to claim 1, characterized in that, Following the response to the data request sent by the second data platform, the method further includes: Obtain the current running status of each instance node in the target data gateway; Based on the load balancing principle and the current running status of each instance node, the target instance node corresponding to the data request is determined so that the data request can be processed through the target instance node.
4. The method according to claim 1, characterized in that, Also includes: The data to be transmitted is audited according to the data audit rules to obtain the corresponding data audit results; The data audit results are fed back to the data supervision platform associated with the first data platform, so that the data supervision platform can adjust the corresponding data security strategy in real time based on the data audit results.
5. The method according to claim 4, characterized in that, The step of feeding back the data audit results to the regulatory platform associated with the first data platform includes: Update the data audit results to the corresponding blockchain; The data audit results are fed back to the data supervision platform via the blockchain.
6. The method according to claim 1, characterized in that, The data auditing rules and data security policies are presented as plugins in the instance nodes; the method also includes: In response to the update instruction of the data security policy corresponding to the first data platform in the data supervision platform, the data security policy corresponding to the first data platform on the blockchain is updated; Based on the updated data security policy on the blockchain, the corresponding data security policy plugin in the target database of the target data gateway is updated in real time.
7. A data transmission device, characterized in that, Applied to the first data platform, including: The first acquisition module is used to acquire data to be transmitted that matches the data request sent by the second data platform in response to the data request; wherein the second data platform and the first data platform belong to different regions; The lookup module is used to search for the data audit rules corresponding to the first data platform from the target data gateway; the target data gateway is configured in the data sandbox provided by the first data platform to the second data platform. An auditing module is used to audit the data to be transmitted according to the data auditing rules to obtain the corresponding target transmission data; wherein, the target transmission data is a subset of the data to be transmitted, containing only data that conforms to the data auditing rules; The transmission module is used to send target transmission data that conforms to the data audit rules to the second data platform, store data that does not conform to the data audit rules in the data sandbox, set the data validity period, and automatically destroy the data that does not conform to the data audit rules after the data validity period expires. The audit module includes: A filtering unit is used to filter out sensitive data from the data to be transmitted. The processing unit is used to perform truncation and / or desensitization operations on the sensitive data according to the data audit rules to obtain the corresponding target transmission data.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the data transmission method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that are used to cause a processor to execute the data transmission method according to any one of claims 1-6.
Citation Information
Patent Citations
Data uploading method and device
CN112015747A
Data transmission method and device, electronic equipment and storage medium
CN114285616A
Data cross-border compliance management and control method and device, computer equipment and storage medium
CN114760149A
Multi-task distributed scheduling load balancing method for heterogeneous computing platform
CN115292039A