Driving data processing method and device and storage medium

By establishing secure access conditions and compliance testing methods for obtaining driving data, sensitive information is identified and transformed to generate de-identified data. This solves the problems of hierarchical control and security in driving data transmission and reduces the risk of data leakage.

CN116070253BActive Publication Date: 2026-08-25TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111275851.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-29
Publication Date
2026-08-25
Estimated Expiration
2041-10-29

AI Technical Summary

Technical Problem

Existing technologies cannot effectively classify and manage driving data, posing a risk of data leakage, especially for highly secure confidential data, which is difficult to guarantee security during transmission.

Method used

By obtaining security access conditions for target driving data, compliance testing is performed based on preset compliance testing methods to identify sensitive information and perform data transformation processing to generate de-identified data, ensuring data security during transmission.

Benefits of technology

It enables comprehensive permission verification and compliance testing of driving data, reducing the risk of data leakage and improving the security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116070253B_ABST
    Figure CN116070253B_ABST
Patent Text Reader

Abstract

The application provides a driving data processing method and device and a storage medium, relates to the technical field of Internet, can be applied to various scenes such as cloud technology, artificial intelligence, intelligent transportation and auxiliary driving, and comprises the following steps: in response to a driving data access request sent by a terminal and carrying target object information and access point information, obtaining a target security permission condition matched with target driving data corresponding to the driving data access request; in the case where the target object information and the access point information satisfy the target security permission condition, performing compliance detection on the target driving data based on a preset compliance detection method to obtain a compliance detection result; if the compliance detection result is that sensitive information exists in the target driving data, performing data conversion processing on the sensitive information to obtain target desensitization data corresponding to the target driving data; and sending the target desensitization data to the terminal to enable the terminal to display the target desensitization data. The application can effectively reduce the risk of driving data leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of Internet technology, and in particular to a driving data processing method, apparatus and storage medium. Background Technology

[0002] With technological advancements, autonomous driving is becoming the mainstream trend in future transportation. During the research and development phase of autonomous driving, a large amount of driving data is generated, including roadside data, driving test data, vehicle driving data, operation and maintenance data, and information reports. This data is essential for relevant personnel in research, testing, and operation and maintenance. Therefore, corresponding platforms need to provide file upload and download capabilities for data analysis, report download, application deployment, maintenance, and upgrades. Typically, driving data contains a large amount of highly confidential information. Current technologies generally use secure transmission protocols for data transmission; however, this method cannot provide hierarchical data control and still carries the risk of data leakage. Therefore, an improved driving data processing solution is needed to enhance the security of driving data. Summary of the Invention

[0003] This application provides a driving data processing method, apparatus, and storage medium, which can effectively improve the security of driving data access and reduce the risk of data leakage.

[0004] On one hand, this application provides a driving data processing method, the method comprising: In response to a driving data access request sent by a terminal, which carries target object information and access point information, obtain the target security permission conditions corresponding to the target driving data to be accessed; If the target object information and the access point information meet the target security permission conditions, the target driving data is subjected to compliance detection based on a preset compliance detection method to obtain a compliance detection result. If the compliance test result indicates that there is sensitive information in the target driving data, the sensitive information is processed by data conversion to obtain the target desensitized data corresponding to the target driving data; The target de-identified data is sent to the terminal so that the terminal can display the target de-identified data.

[0005] On the other hand, a driving data processing device is provided, the device comprising: Information acquisition module: In response to the driving data access request sent by the terminal, which carries target object information and access point information, the module acquires the target security permission conditions corresponding to the target driving data to be accessed. Compliance detection module: used to perform compliance detection on the target driving data based on a preset compliance detection method, and obtain compliance detection results, when the target object information and the access point information meet the target security permission conditions; Data processing module: If the compliance detection result indicates that there is sensitive information in the target driving data, it performs data conversion processing on the sensitive information to obtain the target desensitized data corresponding to the target driving data; Data sending module: used to send the target de-identified data to the terminal so that the terminal can display the target de-identified data.

[0006] On the other hand, a computer device is provided, the device including a processor and a memory, the memory storing at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the driving data processing method as described above.

[0007] On the other hand, a computer-readable storage medium is provided, wherein at least one instruction or at least one program is stored therein, the at least one instruction or the at least one program being loaded and executed by a processor to implement the driving data processing method as described above.

[0008] On the other hand, a terminal is provided, the terminal including a processor and a memory, the device including a processor and a memory, the memory storing at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the driving data processing method as described above.

[0009] On the other hand, a server is provided, the server including a processor and a memory, the device including a processor and a memory, the memory storing at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the driving data processing method as described above.

[0010] On the other hand, a computer program product or computer program is provided, which includes computer instructions that, when executed by a processor, implement the driving data processing method described above.

[0011] The driving data processing method, apparatus, equipment, storage medium, terminal, server, and computer program product provided in this application have the following technical effects: This application responds to a driving data access request sent by a terminal, carrying target object information and access point information. It obtains the target security permission conditions matching the target driving data corresponding to the access request. If the target object information and access point information meet the target security permission conditions, it performs compliance testing on the target driving data based on a preset compliance detection method, obtaining a compliance detection result. If the compliance detection result indicates the presence of sensitive information in the target driving data, it performs data transformation processing on the sensitive information to obtain target de-identified data corresponding to the target driving data. The target de-identified data is then sent to the terminal for display. This approach enables comprehensive permission verification of driving data access requests based on object information and access information. After successful verification, it performs compliance testing and corresponding sensitive information processing on the driving data to be accessed based on a preset compliance detection method. Through multi-level prevention and control, it effectively improves the security of driving data and reduces the risk of driving data leakage. Attached Figure Description

[0012] To more clearly illustrate the technical solutions and advantages in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 This is a schematic diagram of an application environment provided in an embodiment of this application; Figure 2 This is a flowchart illustrating a driving data processing method provided in an embodiment of this application; Figure 3 This is a schematic diagram of the login interface of a human-computer interaction interface provided in an embodiment of this application; Figure 4 This is a schematic diagram of the framework of a driving data processing system provided in an embodiment of this application; Figure 5 This is a flowchart illustrating another driving data processing method provided in an embodiment of this application; Figure 6 This paper illustrates a structural framework diagram of a driving data service platform provided in an embodiment of this application. Figure 7 This is a schematic diagram of the structure of a driving data processing device provided in an embodiment of this application; Figure 8 This is a hardware structure block diagram of an electronic device for a driving data processing method provided in an embodiment of this application; Figure 9 This is a schematic diagram of the structure of a blockchain system provided in an embodiment of this application. Detailed Implementation

[0014] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0015] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or server that comprises a series of steps or sub-modules is not necessarily limited to those steps or sub-modules explicitly listed, but may include other steps or sub-modules not explicitly listed or inherent to such processes, methods, products, or devices.

[0016] Before providing a further detailed description of the embodiments of this application, the nouns and terms involved in the embodiments of this application will be explained, and the nouns and terms involved in the embodiments of this application shall be interpreted as follows.

[0017] Access point: refers to the device that allows wireless local area network (WLAN) user terminals to access the network.

[0018] DMZ: An abbreviation for "demilitarized zone," also known as an isolation zone. It's a buffer zone established between secure and insecure systems to address the issue of external network users being unable to access internal network servers after a firewall is installed. Its function is to isolate and deploy servers that are allowed external access, such as FTP servers and email servers, in this zone. This ensures the entire internal network is connected to the trusted zone, preventing direct access from any external network, thus separating the internal and external networks and meeting user security needs.

[0019] SFTP (SSH File Transfer Protocol): In the computer field, SSH file transfer protocol, also known as Secret File Transfer Protocol or Secure FTP, is a data stream connection that provides file access, transfer, and management functions.

[0020] LDAP (Lightweight Directory Access Protocol) is an open, neutral, industry-standard application protocol that provides access control and maintains distributed directory information via the IP protocol.

[0021] OpenLDAP is a free and open-source implementation of LDAP, released under its OpenLDAP license, and has been included in many popular Linux distributions.

[0022] nslcd: Its formal name is Daemon for NSS and PAM lookups using LDAP (nss-pam-ldapd). It was originally developed by Luke Howard of PADL Software as a fork of nss_ldap called the nss-ldapd suite.

[0023] NFS (Network File System) is a UNIX presentation layer protocol developed by Sun Microsystems that allows users to access files on a network as if they were using their own computer.

[0024] SMB (Server Messages Block) is a communication protocol for sharing files and printers on a local area network (LAN). It provides file and printer sharing services between different computers within the LAN. SMB is a client / server protocol, allowing clients to access shared file systems, printers, and other resources on a server.

[0025] Samba is a free software that implements the SMB protocol on Linux and UNIX systems, consisting of server and client programs. By configuring "NetBIOS over TCP / IP," Samba enables resource sharing not only with hosts on a local area network but also with computers worldwide.

[0026] Please see Figure 1 , Figure 1 This is a schematic diagram of an application environment provided in an embodiment of this application, such as... Figure 1 As shown, the application environment may include at least server 01 and terminal 02. In practical applications, terminal 01, server 01, and terminal 02 can be directly or indirectly connected via wired or wireless communication, and this application does not impose any restrictions on this.

[0027] In this embodiment, server 01 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.

[0028] Specifically, cloud technology refers to a managed technology that unifies hardware, software, and network resources within a wide area network (WAN) or local area network (LAN) to achieve data computation, storage, processing, and sharing. It distributes computing tasks across a resource pool composed of numerous computers, enabling various application systems to access computing power, storage space, and information services as needed. The network providing these resources is called the "cloud." Artificial intelligence cloud services are generally also known as AIaaS (AI as a Service). This is currently a mainstream service model for artificial intelligence platforms. Specifically, AIaaS platforms break down several common AI services and provide them as independent or packaged services in the cloud. This service model is similar to opening an AI-themed marketplace: all developers can access and use one or more AI services provided by the platform through API interfaces. Some experienced developers can also use the AI ​​framework and AI infrastructure provided by the platform to deploy and maintain their own dedicated cloud AI services.

[0029] Specifically, the servers mentioned above may include physical devices, such as network communication submodules, processors, and memory, as well as software running on the physical devices, such as applications.

[0030] In this embodiment, terminal 02 may include physical devices such as smartphones, desktop computers, tablets, laptops, digital assistants, augmented reality (AR) / virtual reality (VR) devices, smart voice interaction devices, smart home appliances, smart wearable devices, and in-vehicle terminal devices, and may also include software running on the physical device, such as applications.

[0031] In this embodiment, server 01 can respond to a driving data access request carrying target object information, perform permission verification on the corresponding target object information and access point information according to security permission conditions, and if the verification is successful (i.e., the target object information and access point information meet the security permission conditions), perform sensitive information detection on the target driving data to be accessed, and perform data conversion on the sensitive information; it can also respond to a data upload request, store the uplink driving data in a data isolation area, and further store the data; and after detecting incremental data, perform compliance processing on the incremental driving data to obtain compliant data, and then store the compliant data in a preset compliant data storage area. Terminal 02 can send driving data access requests, driving data download requests, or data upload requests to server 01, and can receive driving data fed back by the server and display or store it, and can also send uplink driving data to server 01.

[0032] Furthermore, it is understandable that Figure 1 The illustration only shows one application environment for a driving data processing method. This environment may include more or fewer nodes, and this application does not impose any limitations. For example, the data isolation zone can be set up on a separate server to form a separate node.

[0033] The application environment involved in this application embodiment, or the server 01 and terminal 02 in the application environment, can be a distributed system formed by connecting clients and multiple nodes (any form of computing device in the network, such as servers and user terminals) through network communication. The distributed system can be a blockchain system, which can provide driving data processing services, and can also provide data storage functions for the above services, such as storing driving data, compliant data obtained after compliant processing of driving data, and non-sensitive data.

[0034] See Figure 9 , Figure 9 This is an optional structural diagram of the distributed system 100 provided in this embodiment of the invention applied to a blockchain system. It consists of multiple nodes (any form of computing device in the network, such as servers or user terminals) and clients, forming a peer-to-peer (P2P) network. The P2P protocol is an application layer protocol running on top of the Transmission Control Protocol (TCP). In the distributed system, any machine, such as a server or terminal, can join and become a node. A node includes a hardware layer, a middleware layer, an operating system layer, and an application layer.

[0035] Blockchain, an emerging application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms, is essentially a decentralized database. It consists of a chain of data blocks linked using cryptographic methods, each containing information about a batch of network transactions used to verify the validity of the information (anti-counterfeiting) and generate the next block. A blockchain can include a blockchain underlying platform, a platform product service layer, and an application service layer. The blockchain underlying platform can include modules for user management, basic services, smart contracts, and operational monitoring. The user management module is responsible for managing the identity information of all blockchain participants, including maintaining public and private key generation (account management), key management, and maintaining the correspondence between user real identities and blockchain addresses (access management). Under authorization, it manages and audits transactions of certain real identities and provides risk control rule configuration (risk control audit). The basic service module is deployed on all blockchain node devices to verify the validity of business requests. After consensus is reached on valid requests, they are recorded in storage. For a new business request, the basic service first performs interface adaptation parsing and authentication (interface adaptation), and then encrypts the business information using a consensus algorithm (consensus management). The blockchain process involves several key steps: First, encryption and secure transmission of data to the shared ledger (network communication) for recording and storage. Second, the smart contract module handles contract registration, issuance, triggering, and execution. Developers can define contract logic using a programming language and publish it to the blockchain (contract registration). Execution is triggered by calling keys or other events based on the contract terms, completing the contract logic. The module also provides contract upgrade and cancellation functionality. Third, the operation and monitoring module handles deployment, configuration modification, contract settings, cloud adaptation, and real-time visualization of the product's operational status, including alerts, network status monitoring, and node device health monitoring. The platform's product service layer provides basic capabilities and implementation frameworks for typical applications. Developers can leverage these capabilities and add business characteristics to implement business logic on the blockchain. Finally, the application service layer provides blockchain-based application services to business stakeholders.

[0036] The following describes a driving data processing method based on the aforementioned application environment. This method is applied to a server-side application, and its embodiments can be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, smart transportation, and assisted driving. Please refer to... Figure 2 , Figure 2This is a flowchart illustrating a driving data processing method provided in an embodiment of this application. This specification provides method operation steps as shown in the embodiments or flowcharts, but based on conventional or non-inventive labor, more or fewer operation steps may be included. The order of steps listed in the embodiments is merely one possible execution order among many and does not represent the only possible execution order. In actual system or server product execution, the method can be executed sequentially according to the embodiments or drawings, or in parallel (e.g., in a parallel processor or multi-threaded processing environment).

[0037] In driving data processing scenarios, developers need to access and download driving data such as roadside data and application reports, while operations and maintenance personnel need to deploy, maintain, and upgrade platform applications. This necessitates the platform providing data uplink and downlink capabilities. Furthermore, from a security perspective, it's crucial to prevent uploaded files from containing malware, viruses, or other security risks; from a compliance perspective, it's essential to prevent the unauthorized downloading of driving data that poses a risk of information leakage. The technical solution presented in this application satisfies both the uplink and downlink requirements of driving data while ensuring security and compliance. Specifically, for example... Figure 2 As shown, the method may include the following steps.

[0038] S201: In response to a driving data access request sent by the terminal, which carries target object information and access point information, obtain the target security permission conditions corresponding to the target driving data to be accessed.

[0039] In this embodiment, driving data may include, but is not limited to, road sampling data, driving test data, vehicle driving data, and related operation and maintenance data and information reports. Driving data is assigned different data levels, which characterize the security level of the driving data. In some cases, data levels may include non-sensitive data, sensitive data, and confidential data. The original driving data may be classified as confidential data; compliant data obtained after compliance processing of the original driving data is classified as sensitive data; and operation and maintenance data and information reports are classified as non-sensitive data. Specifically, security permission conditions may include data download permission conditions and data access permission conditions depending on the request type. Depending on the verification object, data download permission conditions may include corresponding object permission verification conditions and access point verification conditions, and data access permission conditions may include corresponding object permission verification conditions and access point verification conditions. Different data levels of driving data correspond to different security permission conditions. Specifically, the target object may be the initiator of driving data access, download, and upload, such as the account of an operation and maintenance personnel. Target object information includes the object type and object level of the target object. Understandably, target objects can be set according to actual needs. For example, based on the work content of relevant personnel, they can be set as program maintenance objects and R&D objects, etc. Specifically, access point information refers to the device information of the terminal initiating the relevant request accessing the network in the wireless local area network (WLAN), such as thin client information, leased line client information, and area authentication client information. Among them, a thin client refers to a client that accesses and authenticates through a specified device; a leased line client refers to a client that accesses through a specified network leased line, where the specified network leased line is a physically and communicationally isolated independent local area network; an area authentication client refers to a client whose access location is located within a preset area. In this way, by setting different clients, data security can be improved while meeting data uplink and downlink requirements.

[0040] In practical applications, the terminal can provide a human-machine interface to receive login operation information, information setting operation information, driving data access operation information, download operation information, or upload operation information submitted by the target object, thereby triggering and generating corresponding login requests, information setting requests, driving data access requests, driving data download requests, and data upload requests. Please refer to [reference needed]. Figure 3 , Figure 3 A schematic diagram of a login interface for a human-computer interaction is shown. The target object can submit object information and settings information through this login interface, and submit the corresponding operation information by triggering the "Login" control on the interface, thereby triggering the corresponding request.

[0041] In practical applications, driving data of different data levels can be partitioned and stored to achieve hierarchical data control. Accordingly, obtaining the target security permission conditions corresponding to the target driving data to be accessed in S201 may include the following steps.

[0042] S2011: Obtain the data path information for the target driving data.

[0043] Specifically, the driving data access request also carries the data path information of the driving data to be accessed, or the data identifier information of the driving data to be accessed. The data path information can be obtained by parsing the driving data access request, or the corresponding data path information can be determined based on the parsed data identifier information.

[0044] Specifically, data path information can characterize the storage path of driving data. Different data levels of driving data are stored in different storage areas, corresponding to different storage paths. For example, confidential data such as raw driving data can be stored in the confidential data area, sensitive data such as compliance data can be stored in the compliance data area, and non-sensitive data such as operation and maintenance data and information reports can be stored in the non-sensitive data area.

[0045] S2013: Based on the preset correspondence between data path information and security permission conditions, the security permission conditions corresponding to the data path information of the target driving data are determined as the target security permission conditions.

[0046] Specifically, the mapping between data path information and security permission conditions can be pre-stored. After obtaining the data path information of the target driving data, the full security permission condition corresponding to that data path is determined as the target security permission condition. In some cases, after obtaining the data path information, the data level of the target driving data to be accessed can be determined through the mapping between the data path information and data levels. Then, based on the mapping between data levels and security permission conditions, the security permission conditions corresponding to the data level of the target driving data are determined as the target security permission conditions.

[0047] S203: If the target object information and access point information meet the target security permission conditions, perform compliance detection on the target driving data based on the preset compliance detection method.

[0048] In this embodiment, after determining the target security permission conditions, permission verification is performed on the target object information and access point information based on the target security permission conditions to obtain permission verification results. If the permission verification results indicate that the target object information and access point information meet the target security permission conditions, a preset compliance detection method is used to perform compliance detection on the target driving data.

[0049] In practical applications, driving data at different data levels can be subject to hierarchical control, with different data levels corresponding to different security permission conditions. Accordingly, the method may also include: obtaining the data level of the target driving data; if the data level of the target driving data is non-sensitive, and the target object information meets the target security permission conditions, the target driving data is sent to the terminal. For non-sensitive data, the corresponding security permission conditions include object permission verification conditions. Based on these object permission verification conditions, the target object information is verified for permissions; if the target object information meets the object permission verification conditions, then the target security permission conditions are met. The data level of the target driving data can be determined based on data path information, and the specific method is similar to the aforementioned method, so it will not be elaborated here.

[0050] In practical applications, if the target driving data is not classified as non-sensitive data, such as classified as confidential or sensitive data, then step S203 is triggered. Correspondingly, the security permission conditions include object permission verification conditions and access point verification conditions. Based on the object permission verification conditions, permission verification is performed on the target object information; based on the access point verification conditions, permission verification is performed on the access point information. If the target object information meets both the object permission verification conditions and the access point information meets the access point verification conditions, then the target security permission conditions are satisfied, and a preset compliance detection method is invoked for compliance detection.

[0051] Specifically, object whitelists can be set in advance, such as setting object whitelists corresponding to driving data access permissions and driving data download permissions respectively; accordingly, permission verification of target object information based on object permission verification conditions can include: determining whether the target object is included in the object whitelist corresponding to driving data access permissions based on the target object information, and if so, determining that the target object information meets the object permission verification conditions.

[0052] Specifically, different data access and data download permissions can be set for different access points. Correspondingly, permission verification of access point information based on access point verification conditions can include: determining whether the access point corresponding to the driving data access request is the preset access access point corresponding to the target driving data based on the access point information. If so, the access point information is determined to meet the access point verification conditions; otherwise, it is not.

[0053] In some cases, data can be classified as sensitive or confidential. For example, raw driving data and processed compliant data are classified as sensitive data. Correspondingly, if the target object is included in the whitelist corresponding to driving data access permissions, and the access point is a preset access point corresponding to sensitive or confidential data, then the target security permission conditions are met, and the user has access to the target driving data. In one embodiment, the preset access point corresponding to sensitive data may include thin clients and dedicated line clients, while the preset access point corresponding to confidential data includes dedicated line clients.

[0054] In some cases, after passing the above permission verification, if the target driving data is classified as confidential data and the access point is the preset access point corresponding to confidential data, the target driving data will be fed back to the terminal; if the target driving data is classified as confidential data and the access point is the preset access point corresponding to sensitive data, the target driving data classified as confidential data will be subject to compliance detection based on the preset compliance detection method.

[0055] In some cases, after passing the above permission verification, that is, the target object is in the whitelist and the access point is the preset access point corresponding to sensitive data or confidential data, if the target driving data is classified as sensitive data, then the target driving data classified as sensitive data will be subject to compliance detection based on the preset compliance detection method.

[0056] In practical applications, the preset compliance detection method includes a sensitive information detection method. Accordingly, compliance detection includes sensitive information detection. When the target driving data includes text data, compliance detection is performed on the target driving data based on the preset compliance detection method to obtain the compliance detection result, which may include the following steps.

[0057] S301: Perform text segmentation on the text data in the target driving data to obtain the corresponding text segments.

[0058] S303: Use compliant words from the preset compliant word library to perform word segmentation matching on the text data corresponding to the word segmentation.

[0059] S305: Determine sensitive information from text segmentation that does not match compliant words.

[0060] Specifically, the platform pre-stores a compliant terminology library, which contains compliant terms that are considered non-sensitive information. During the sensitive information detection process, each text data in the target driving data is segmented into words. This segmentation process can be the same as existing technologies, and this application does not impose any restrictions on it. After obtaining the text segment corresponding to each text data, it is matched with the compliant terms in the pre-stored compliant terminology library to determine whether there are compliant terms in the pre-stored compliant terminology library that match each text segment. If there are, the text segment is considered non-sensitive information. In some cases, if there are no compliant terms that match the text segment, it indicates that the text segment is unreadable, and the text segment is considered sensitive information, thus triggering step S205. Specifically, the matching method for the above-mentioned compliant terms can be field matching, such as string matching.

[0061] In other cases, prior to S305, the method further includes: if no compliant word matches the text segmentation, indicating that the text segmentation is unreadable, obtaining the character information of the text segmentation that does not match a compliant word for encrypted string risk control; specifically, matching the preset risk character information with this character information; if a match is found, determining that the corresponding text segmentation is sensitive information; if no match is found, determining that the corresponding text segmentation is non-sensitive information. Specifically, the character information may include character encoding format and character length, etc. Correspondingly, matching the preset risk character information with this character information may include: matching the character encoding format and character length with the preset risk character encoding format and risk character length. In one embodiment, if the character encoding format of the text segmentation conforms to an encrypted encoding format, such as base64 encoding, or the character length is greater than a preset length (the preset length can be 16, etc.), it indicates that the string may be an encrypted string, and determining that the corresponding text segmentation is sensitive information.

[0062] In practical applications, driving data also involves sensitive information such as location data. Accordingly, the following steps can be included to perform compliance checks on the target driving data based on the preset compliance check method to obtain the compliance check results.

[0063] S401: Detect the coordinate information of the target driving data based on preset coordinate information.

[0064] S403: If coordinate information is detected in the target driving data, the coordinate information is identified as sensitive information.

[0065] Specifically, the preset coordinate information may include at least one of the following: a preset coordinate value format (such as a two-axis coordinate format or a three-axis coordinate format), a coordinate value range (such as a latitude and longitude range), and coordinate attribute information. The coordinate value format may be, for example, a two-axis coordinate format or a three-axis coordinate format; the coordinate value range may be, for example, a latitude and longitude range; and the coordinate attribute information represents the attributes of the geographic coordinates, such as height, width, slope, distance, curvature, and diameter.

[0066] In some cases, coordinate information is identified for each data point in the target driving data based on preset coordinate information. If the coordinate information is identified, it is determined to be sensitive information.

[0067] In other cases, S401 may include: identifying coordinate information of each driving data in the target driving data based on coordinate attribute information, including coordinate value format identification, coordinate value range identification, and coordinate attribute information identification, thereby obtaining the coordinate quantity information, coordinate value range information, and coordinate attribute information corresponding to each driving data. Correspondingly, before determining the coordinate information as sensitive information, the method may further include: if the number of coordinates in the driving data is greater than a preset number of coordinates based on the coordinate quantity information, then the corresponding driving data is determined to be risky data; if the number of coordinates in the driving data is less than or equal to a preset number of coordinates based on the coordinate quantity information, and coordinate attribute information exists in the driving data, then the corresponding driving data is determined to be risky data, or each identified coordinate information is determined to be sensitive information; if the number of coordinates in the driving data is less than or equal to a preset number of coordinates based on the coordinate quantity information, and coordinate attribute information does not exist in the driving data, then each identified coordinate information is determined to be sensitive information.

[0068] Specifically, if the obtained coordinate values ​​are outside the preset coordinate range, the corresponding coordinate information can be ignored, that is, not included in the number of coordinates.

[0069] In practical applications, the preset compliance detection method may also include a risk data detection method. Accordingly, the compliance detection of the target driving data based on the preset compliance detection method to obtain the compliance detection result may also include the following steps.

[0070] S501: Obtain the content format information of each driving data in the target driving data.

[0071] S503: Match the content format information of each driving data with the preset risk format information.

[0072] S505: If there is content format information that matches the preset risk format information, the driving data corresponding to the matching content format information shall be determined as risk data.

[0073] In some cases, content format matching can be performed on each driving data in the target driving data to identify the matched data as risk data. In other cases, prior to S501, the type of each driving data in the target driving data can be filtered to obtain the data type of each driving data. If the data type is a text file or the content type is text, the content format information of the driving data is obtained for content format matching. Specifically, different text types can correspond to different preset risk format information. The text type can include, but is not limited to, txt, MF4, or doc text types. The content format information of the driving data is matched with the preset risk format information corresponding to its text type. If they match, the driving data is considered risk data; if they do not match, it is considered non-risk data.

[0074] Specifically, content format information can be information representing the format specifications of text content. Correspondingly, the types of preset risk format information can include, but are not limited to, text field names, field types, data length, numerical limits, and whether fields are required. For example, preset risk format information can be preset schema information.

[0075] In practical applications, the following steps may also be included when performing compliance checks on target driving data based on a preset compliance check method to obtain compliance check results.

[0076] S601: Perform data type detection on each driving data in the target driving data based on a preset data type.

[0077] S603: If driving data of a preset data type is detected, obtain the data attribute value from the data header of the driving data of the preset data type.

[0078] S605: Match the data attribute value with the preset security attribute value.

[0079] S607: If no safety attribute value is matched, driving data of the preset data type will be identified as risk data.

[0080] Specifically, the data type of each piece of driving data in the target driving data can be obtained. If the data type of the driving data is a preset data type, the data attribute values ​​in its data header are obtained and matched with preset safety attribute values. Based on the matching result, it is determined whether the driving data of the preset data type is risky or non-risky data. Specifically, different data types can correspond to different preset safety attribute values. In one embodiment, the preset data type can be MF4 text type. The file attribute values ​​in the file header are obtained and matched with preset safety attribute values. If the file attribute values ​​do not match any of the preset safety attribute values, then the MF4 file is risky data.

[0081] In some cases, after determining that driving data is risky data, the risky data can be re-detected for sensitive information based on the aforementioned sensitive information detection method. If sensitive information is detected, step S205 is executed to perform data conversion processing on the sensitive information to obtain the target desensitized data corresponding to the target driving data. In other cases, after determining that driving data is risky data, sensitive information detection is performed on the driving data other than the risky data in the target driving data to obtain the corresponding target desensitized data, and data feedback is provided.

[0082] S205: If the compliance test results indicate that there is sensitive information in the target driving data, perform data conversion processing on the sensitive information to obtain the target desensitized data corresponding to the target driving data.

[0083] In this embodiment, data transformation processing of sensitive information may include, but is not limited to, data replacement, data blurring, or data deflection. Specifically, data replacement involves replacing sensitive information with preset security information, such as replacing sensitive text with "*"; data blurring may involve masking sensitive information; and data deflection may involve deflecting numerical or coordinate information, such as coordinate deflection.

[0084] S207: Send the target de-identified data to the terminal so that the terminal can display the target de-identified data.

[0085] In this embodiment, after obtaining the target de-identified data, it is fed back to the terminal for display. In some cases, the target de-identified data can be sent to a data isolation zone first, and then fed back to the terminal from the data isolation zone. Alternatively, the target de-identified data can be sent to a data buffer first, then synchronized to the data isolation zone, and then fed back to the terminal from the data isolation zone. By deploying a data isolation zone, direct access to the core area of ​​the data center can be avoided, thereby improving data security.

[0086] Based on some or all of the above implementation methods, there is still a need for data uplink. In the embodiments of this application, please refer to... Figure 4The method may also include the following steps.

[0087] S701: In response to a data upload request sent by the terminal, which carries target path information and uplink driving data, store the uplink driving data in the data isolation area.

[0088] S703: Uses a data upload script to synchronize uplink driving data in the data isolation zone to the data buffer.

[0089] In this embodiment, the server deploys a data isolation zone, a data buffer, and a data storage zone. The data isolation zone is located on a separate server and is physically isolated from other servers. In both internal and external network environments, the internal network can access the external network and the data isolation zone, while the external network cannot access the internal network but can access the data isolation zone. The data isolation zone cannot access the external network. Source address translation is required when the internal network accesses the external network or vice versa. Specifically, the data isolation zone is located between the internal and external networks, while the data buffer and data storage zone are located within the internal network environment.

[0090] In practical applications, the target path information is the path information in the data storage area. After the target object triggers a data upload request, the platform stores the uplink driving data in the data isolation area based on the data upload request. Then, the data upload script periodically checks whether there is any incremental uplink driving data in the data isolation area, and then synchronizes it to the data buffer. In some cases, before step S703, the method further includes: calling a security scanning tool to perform a security scan on the uplink driving data; if the security scan result shows no security risk, then step S703 is executed. Security scanning can effectively reduce the risk of data contamination.

[0091] In some embodiments, a preset size of cache space can be allocated for different target objects in the data isolation area, data buffer, or data storage area to limit uploads and storage. For example, 200GB of space can be allocated to each target object. The data buffer can limit the directory space of the target object, recording the directory usage. If the space limit is exceeded (e.g., 200GB), data will no longer be synchronized from the data isolation area to the file buffer. During data synchronization, the directory usage can be reported to the management backend, such as the Web Portal backend. The size of data synchronized in a single instance can also be limited. For example, the size of each upload to the data buffer can be limited to approximately 900MB, with batch uploads and breakpoint resumption. If a file is larger than 900MB, it is uploaded in multiple batches. After the first batch is uploaded, the data in the data isolation area is not deleted; it is deleted only after all uploads are complete. If the upload is completed all at once, the data in the data isolation area is deleted directly. Specifically, uploaded data can be overwritten. If the filename, attributes, and group of the data are the same, data overwriting can be performed. Data in the data buffer can be retained for a preset time, such as seven days. Target objects can submit data operation commands through the terminal, such as data deletion or directory deletion.

[0092] In one embodiment, the data isolation zone can be built on a DMZ, and the terminal can access the required driving data via SFTP. Specifically, a DMZ server is deployed on the server side and integrated with LDAP, i.e., OpenLDAP and NSLCD integrated with the DMZ, etc., and NFS and Samba are deployed on the DMZ server, and SFTP is configured, etc.

[0093] S705: Use the upload service thread to store the uplink driving data in the data buffer to the storage location corresponding to the target path information.

[0094] In this embodiment, in response to a data upload request, a data upload task corresponding to the data upload request can be created. The data upload task may include target path information, target IP address, file ownership object name, or file ownership group, etc. Specifically, the data upload task can be stored in a task list, which can be a circular linked list. Based on a pre-created upload service thread, data upload tasks are periodically retrieved from the platform's background service; that is, data upload tasks are read from the task list, task consumption is performed, and the tasks are stored in the corresponding storage location. Specifically, the upload service thread can be pre-created by the data uplink service. Specifically, uplink driving data in the data cache can be uploaded to the storage location corresponding to the target path information in the data storage area via an SSH channel, and the execution structure is sent to the platform's background service.

[0095] In practical applications, before step S705, the method further includes: calling a safety scanning tool to perform a safety scan on the uplink driving data; if the safety scan result shows that there is no safety risk, then step S705 is executed.

[0096] In practical applications, after S705, please refer to... Figure 5 The method may also include the following steps.

[0097] S707: Sensitive information identification for uphill driving data.

[0098] S709: When coordinate information or vehicle identification information is detected in the uplink driving data, coordinate information is subjected to coordinate deflection processing, or vehicle identification information is subjected to data fuzzing processing, to obtain the compliant data corresponding to the uplink driving data.

[0099] S711: Store compliant data to the corresponding data storage location based on the preset compliant data path.

[0100] In this embodiment, a pre-created data compliance processing thread can periodically detect whether incremental uplink driving data exists in the data storage area. If incremental uplink driving data exists, sensitive information is identified. Similar to the previous steps, the method for sensitive information identification is similar to steps S401-S403 and S501-S505, and will not be repeated here. Specifically, the compliance processing thread can be pre-created through a compliance processing service. Specifically, when sensitive information is detected, data transformation processing is performed on the sensitive information, including but not limited to data replacement, data blurring, or data deflection. Specifically, when coordinate information is identified, coordinate deflection processing, such as nonlinear deflection, is performed on the coordinate information. When vehicle identification information is identified, data blurring processing, such as image masking, is performed on the vehicle identification information, thereby masking the sensitive information in the uplink driving data, obtaining compliant data, and storing it.

[0101] As mentioned earlier, driving data can be categorized into sensitive, non-sensitive, and confidential data based on data levels. Uplink driving data, i.e., raw driving data, is confidential; compliant data obtained after compliance processing is sensitive; and application statistics such as maintenance and reporting data, as well as simulation training results, are non-sensitive. Accordingly, driving data can be stored hierarchically based on data levels. Specifically, different storage areas and corresponding data paths can be allocated to driving data of different data levels. For example, raw driving data corresponds to the raw data path, compliant data to the compliant data path, and non-sensitive data to the non-sensitive data path. This allows for hierarchical management of driving data of different data levels based on different data paths.

[0102] Based on some or all of the above embodiments, the method in this application embodiment may further include the following steps.

[0103] S801: Receives a driving data download request sent by the terminal. The driving data download request carries target object information, access point information, and data path information of the driving data to be downloaded.

[0104] S803: Determine the data level information of the driving data to be downloaded based on the data path information of the driving data to be downloaded.

[0105] Specifically, driving data of different data levels is stored in corresponding preset areas, that is, it has preset data paths. Based on the correspondence between preset data path information and data level information, the data level information corresponding to the data path information of the driving data to be downloaded can be determined.

[0106] S805: Based on the preset correspondence between data level information and download permission conditions, determine the target download permission conditions corresponding to the data level information of the driving data to be downloaded.

[0107] In practical applications, different data levels of driving data correspond to different download permission conditions. This correspondence is stored as a mapping between data level information and download permission conditions.

[0108] S807: If the target object information and access point information meet the target download permission conditions, the driving data to be downloaded will be fed back to the terminal.

[0109] Specifically, the permission verification method for target object information is similar to that described above and will not be repeated here. Specifically, different access points can be set up based on actual needs. In one example, access points include leased line clients, thin clients, and regional authentication clients. These access points have different physical environments, security measures, and management processes, and can be connected to different download permission conditions. Among them, the leased line client can be a physically isolated client with an encrypted leased line connection, possessing the highest data permissions, and correspondingly, download and access permissions for sensitive, non-sensitive, and confidential data. The thin client can be a client accessed through a customized device, whose storage exchange interface can be disabled. It has access / download permissions for non-sensitive data and access permissions for sensitive data. In some cases, it may also have download permissions for sensitive data or access permissions for confidential data, but not download permissions for confidential data. The regional authentication client can be a client accessed within a pre-defined local region, requiring authentication access. It has access and download permissions for non-sensitive data, but not access / download permissions for sensitive and confidential data.

[0110] If the access point information or target object information does not meet the corresponding target download permission conditions, no download task will be generated. Specifically, before sensitive or confidential data is fed back to the thin client or leased line client, compliance testing, sensitive information processing, and risk data processing must be performed. The resulting de-identified target data is then fed back to the corresponding client to prevent the leakage of sensitive information.

[0111] Specifically, this can be achieved through a data downlink service, such as by creating a data download thread to periodically retrieve download tasks. Each download task includes the source data path, source IP address, and target object information. After retrieving the download task, the data to be downloaded can be read from the source data path and sent to a data buffer. The data to be downloaded in the data buffer is then synchronized to the data isolation area and finally sent to the terminal. Alternatively, data can be pulled from the cluster edge nodes on the server side to the data buffer using a data synchronization tool, and then the data downlink script can be used to synchronize the data in the data buffer to the data isolation area. After successful transmission, a notification message, such as a relevant email notification, can be sent to the target object.

[0112] In practical applications, the above technical solution is implemented based on a driving data service platform. Please refer to [the relevant documentation / reference]. Figure 6 , Figure 6 The diagram illustrates the structural framework of a driving data service platform provided in this application embodiment. A data isolation zone is set between the intranet environment and the extranet environment, and a data transmission channel is established between it and the data buffer. The data buffer and the data storage zone also establish a data transmission channel to meet the uplink and downlink requirements of driving data. The data buffer also communicates with the platform backend service to obtain task information from the platform backend service or send data such as log information to the platform backend service.

[0113] Specifically, during the data uplink process, the data upload script can periodically detect incremental uplink driving data in the data isolation area and synchronize it to the data buffer, thereby triggering the compliance processing service to process the incremental uplink driving data for compliance and obtain compliant data. The data uplink service periodically pulls data uplink tasks from the platform's backend service to store the incremental uplink driving data in the original data storage area of ​​the data storage area and store the compliant data in the compliant data storage area.

[0114] Specifically, during the data downlink process, the data downlink service periodically retrieves data downlink tasks from the platform's backend service and pulls corresponding downlink driving data from the data storage area to the data buffer. When compliance checks are required, the compliance processing service is triggered to perform compliance checks, sensitive information processing, and risk data processing on the downlink driving data, resulting in de-identified data. The data downlink script periodically checks incremental downlink driving data in the data isolation area and sends it there. Furthermore, a push streaming service is used to send log data and other information generated during the data flow process to the platform's backend service.

[0115] In one embodiment, the data isolation zone, data buffer, and data storage zone are located on different servers. The data isolation zone is deployed on a data isolation server, which can be an SFTP server, etc., and the data isolation server allows passwordless login to the root account. The data buffer is deployed on a data synchronization server, and the data buffer can utilize clients to access the data transmission channel of the data isolation server, such as using an rsync client to access the SSH channel of the SFTP server for data retrieval and push. The data storage zone can be deployed on a backend resource node server, and the data synchronization server can utilize passwordless login to the root account of the backend resource node server, and use clients to utilize the data transmission channel for data retrieval, push, and data authorization. Here, the client can also be an rsync client, and the data transmission channel can also be an SSH channel. Furthermore, the data synchronization server can also remotely log in to the backend resource node server via SSH to configure data permissions.

[0116] The technical solution of this application employs hierarchical processing and partitioned storage of driving data, which facilitates hierarchical control during data uplink and downlink processes. Upon receiving raw driving data, it undergoes compliance processing to obtain compliant data, thereby improving data utilization while reducing the risk of information leakage. Furthermore, upon receiving downlink data requests such as access and download, comprehensive permission verification is performed based on object and access information. After successful verification, the driving data to be accessed or downloaded undergoes further compliance checks and corresponding sensitive information processing based on a preset compliance detection method. This prevents the leakage of sensitive information or risky data missed during compliance processing. Through multi-level prevention and control, the security of driving data is effectively improved, and the risk of driving data leakage is reduced.

[0117] This application also provides a driving data processing device 800, such as... Figure 7 As shown, Figure 7 A schematic diagram of a driving data processing device provided in an embodiment of this application is shown. The device may include the following modules.

[0118] Information acquisition module 10: In response to a driving data access request sent by the terminal, which carries target object information and access point information, the module acquires the target security permission conditions and target object information corresponding to the target driving data to be accessed.

[0119] Compliance detection module 20: Used to perform compliance detection on target driving data based on a preset compliance detection method, provided that the target object information and access point information meet the target security permission conditions.

[0120] Data processing module 30: If the compliance test result indicates that there is sensitive information in the target driving data, it performs data conversion processing on the sensitive information to obtain the target desensitized data corresponding to the target driving data; Data sending module 40: Used to send the target de-identified data to the terminal so that the terminal can display the target de-identified data.

[0121] In some embodiments, the target driving data includes text data, and the compliance detection module 20 may include the following units.

[0122] Word segmentation unit: Used to perform text segmentation on the text data in the target driving data to obtain the corresponding text words.

[0123] Word segmentation matching unit: Used to perform word segmentation matching on the text data corresponding to the compliant words in the preset compliant word library.

[0124] The first sensitive information determination unit is used to identify sensitive information in text segmentation where no compliant words are matched.

[0125] In some embodiments, the compliance detection module 20 may include the following units.

[0126] Coordinate information detection unit: used to detect the coordinate information of the target driving data based on preset coordinate information.

[0127] The second sensitive information determination unit is used to determine the coordinate information as sensitive information when the coordinate information is detected in the target driving data.

[0128] In some embodiments, the compliance detection module 20 may include the following units.

[0129] Format information acquisition unit: used to acquire the content format information of each driving data in the target driving data.

[0130] Format information matching unit: used to match the content format information of each driving data with the preset risk format information.

[0131] First risk data determination unit: If there is content format information that matches the preset risk format information, the driving data corresponding to the matching content format information is determined as risk data.

[0132] In some embodiments, the compliance detection module 20 may include the following units.

[0133] Data type detection unit: used to perform data type detection on each driving data in the target driving data based on a preset data type.

[0134] Data attribute value acquisition unit: used to acquire data attribute values ​​from the data header of driving data of the preset data type if driving data of the preset data type is detected.

[0135] Attribute value matching unit: Used to match attribute values ​​with preset security attribute values.

[0136] The second risk data determination unit is used to determine driving data of a preset data type as risk data when no safety attribute value is matched.

[0137] In some embodiments, the information acquisition module 10 may include the following units.

[0138] Path information acquisition unit: Used to acquire data path information of target driving data.

[0139] Security permission condition determination unit: used to determine the security permission condition corresponding to the data path information of the target driving data as the target security permission condition based on the preset correspondence between data path information and security permission conditions.

[0140] In some embodiments, the apparatus may further include the following modules.

[0141] First storage module: Used to respond to data upload requests sent by the terminal, which carry target path information and uplink driving data, and store the uplink driving data in the data isolation area.

[0142] Data synchronization module: Used to synchronize uplink driving data in the data isolation area to the data buffer using a data upload script.

[0143] The second storage module is used to store the uplink driving data in the data buffer to the storage location corresponding to the target path information using the upload service thread.

[0144] In some embodiments, the apparatus may further include the following modules.

[0145] Sensitive Information Identification Module: This module is used to identify sensitive information in the uplink driving data after the data buffer is stored in the data buffer and the target path information is stored in the storage location corresponding to the uplink driving data using the upload service thread.

[0146] Compliance data generation module: When coordinate information or vehicle identification information is detected in the uplink driving data, the module performs coordinate deflection processing on the coordinate information or data fuzzing processing on the vehicle identification information to obtain the compliance data corresponding to the uplink driving data.

[0147] The third storage module is used to store compliant data to the corresponding data storage location based on a preset compliant data path.

[0148] It should be noted that the above-described device embodiments and method embodiments are based on the same implementation methods.

[0149] This application provides a driving data processing device, which can be a terminal or a server. The driving data processing device includes a processor and a memory. The memory stores at least one instruction or at least one program. The at least one instruction or at least one program is loaded and executed by the processor to implement the driving data processing method provided in the above method embodiments.

[0150] Memory can be used to store software programs and modules. The processor executes various functional applications and performs driving data processing by running the software programs and modules stored in the memory. Memory can primarily include a program storage area and a data storage area. The program storage area can store the operating system, application programs required for functions, etc.; the data storage area can store data created based on device usage, etc. Furthermore, memory can include high-speed random access memory, and can also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, memory can also include a memory controller to provide the processor with access to the memory.

[0151] The methods and embodiments provided in this application can be executed in electronic devices such as mobile terminals, computer terminals, servers, or similar computing devices. Figure 8 This is a hardware structure block diagram of an electronic device for a driving data processing method provided in an embodiment of this application. For example... Figure 8As shown, the electronic device 900 can vary significantly due to differences in configuration or performance. It may include one or more central processing units (CPUs) 910 (CPUs 910 may include, but are not limited to, microprocessors such as MCUs or programmable logic devices such as FPGAs), a memory 930 for storing data, and one or more storage media 920 (e.g., one or more mass storage devices) for storing application programs 923 or data 922. The memory 930 and storage media 920 may be temporary or persistent storage. The program stored in the storage media 920 may include one or more modules, each module may include a series of instruction operations on the electronic device. Furthermore, the CPU 910 may be configured to communicate with the storage media 920 and execute the series of instruction operations in the storage media 920 on the electronic device 900. Electronic device 900 may also include one or more power supplies 960, one or more wired or wireless network interfaces 950, one or more input / output interfaces 940, and / or one or more operating systems 921, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.

[0152] The input / output interface 940 can be used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the electronic device 900. In one example, the input / output interface 940 includes a network interface controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the input / output interface 940 may be a radio frequency (RF) module used for wireless communication with the Internet.

[0153] Those skilled in the art will understand that Figure 8 The structure shown is for illustrative purposes only and does not limit the structure of the electronic device described above. For example, the electronic device 900 may also include... Figure 8 The more or fewer components shown, or having the same Figure 8 The different configurations shown.

[0154] Embodiments of this application also provide a computer-readable storage medium, which can be disposed in an electronic device to store at least one instruction or at least one program related to implementing a driving data processing method in the method embodiment. The at least one instruction or the at least one program is loaded and executed by the processor to implement the driving data processing method provided in the above method embodiment.

[0155] Optionally, in this embodiment, the storage medium may be located at at least one of the multiple network servers in a computer network. Optionally, in this embodiment, the storage medium may include, but is not limited to, various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0156] According to one aspect of this application, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the methods provided in the various alternative implementations described above.

[0157] As can be seen from the embodiments of the driving data processing method, apparatus, device, server, terminal storage medium, and program product provided in this application, in response to a driving data access request sent by a terminal carrying target object information and access point information, this application obtains the target security permission conditions matching the target driving data corresponding to the driving data access request; if the target object information and access point information meet the target security permission conditions, it performs compliance detection on the target driving data based on a preset compliance detection method to obtain a compliance detection result; if the compliance detection result indicates that there is sensitive information in the target driving data, it performs data conversion processing on the sensitive information to obtain target desensitized data corresponding to the target driving data; and it sends the target desensitized data to the terminal so that the terminal can display the target desensitized data. This allows for comprehensive permission verification of driving data access requests based on object information and access information, and after successful verification, it performs compliance detection and corresponding sensitive information processing on the driving data to be accessed based on a preset compliance detection method. Through multi-level prevention and control, it effectively improves the security of driving data and reduces the risk of driving data leakage.

[0158] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are also possible or may be advantageous.

[0159] The various embodiments in this application are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the device, equipment, and storage medium embodiments are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0160] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware, or by a program instructing the relevant hardware to implement them. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

[0161] The above are merely preferred embodiments of this application and are not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

Claims

1. A driving data processing method, characterized in that, The method includes: Sensitive information identification is performed on the uplink driving data, which is data that is stored in the data isolation area in response to the data upload request, and then synchronized from the data isolation area to the data buffer and stored in the storage location corresponding to the target path information; If coordinate information or vehicle identification information is detected in the uplink driving data, coordinate deflection processing is performed on the coordinate information, or data fuzzing processing is performed on the vehicle identification information, to obtain the compliant data corresponding to the uplink driving data. Based on the preset compliance data path, the compliance data is stored in the corresponding data storage location; in response to the driving data access request sent by the terminal carrying target object information and access point information, the target security permission conditions corresponding to the target driving data to be accessed are obtained; If the target object information and the access point information meet the target security permission conditions, and if the target driving data is not non-sensitive data, a compliance detection is performed on the target driving data based on a preset compliance detection method to obtain a compliance detection result. The preset compliance detection method includes a sensitive information detection method and a risk data detection method. The detection method includes: identifying the coordinate information of each driving data in the target driving data based on coordinate attribute information to obtain the coordinate quantity information, coordinate value range information, and coordinate attribute information corresponding to each driving data. If the coordinate quantity information determines that the number of coordinates in the driving data is less than or equal to a preset number of coordinates, and the driving data contains... If no coordinate attribute information is found, the identified coordinate information is identified as sensitive information. If, based on the coordinate quantity information, the number of coordinates in the driving data is greater than a preset number of coordinates, or the number of coordinates is less than or equal to a preset number of coordinates and coordinate attribute information exists in the driving data, the corresponding driving data is identified as risk data. The risk data detection method includes: obtaining the content format information of each driving data in the target driving data; matching the content format information of each driving data with preset risk format information; if there is content format information that matches the preset risk format information, the driving data corresponding to the matched content format information is identified as risk data. If the compliance test result indicates that there is sensitive information in the target driving data, the sensitive information is processed by data conversion to obtain the target desensitized data corresponding to the target driving data; The target de-identified data is sent to the data buffer, and the target de-identified data in the data buffer is synchronized to the data isolation area. The target de-identified data in the data isolation area is sent to the terminal so that the terminal can display the target de-identified data. The data isolation area and the data buffer are located on different servers, and the data isolation area is physically isolated from other servers.

2. The method according to claim 1, characterized in that, The target driving data includes text data, and the compliance detection of the target driving data based on a preset compliance detection method, to obtain the compliance detection result, includes: The text data in the target driving data is processed by text segmentation to obtain the text segments corresponding to the text data. The text data is segmented and matched using compliant words from a preset compliant word library. Text segments that do not match compliant words are identified as sensitive information.

3. The method according to claim 1, characterized in that, The compliance detection of the target driving data based on the preset compliance detection method yields the following compliance detection results: Based on a preset data type, the data type of each driving data in the target driving data is detected. If driving data of a preset data type is detected, the data attribute value is obtained from the data header of the driving data of the preset data type; The data attribute values ​​are matched with preset security attribute values; If no safety attribute value is matched, the driving data of the preset data type will be identified as risk data.

4. The method according to claim 1, characterized in that, The target security permission conditions for obtaining the target driving data requested to be downloaded by the driving data access request include: Obtain the data path information of the target driving data; Based on the preset correspondence between data path information and security permission conditions, the security permission conditions corresponding to the data path information of the target driving data are determined as the target security permission conditions.

5. The method according to claim 1, characterized in that, The method further includes: In response to a data upload request sent by the terminal, which carries target path information and uplink driving data, the uplink driving data is stored in the data isolation area; The uplink driving data in the data isolation zone is synchronized to the data buffer using a data upload script. The upload service thread is used to store the uplink driving data in the data buffer to the storage location corresponding to the target path information.

6. A driving data processing device, characterized in that, The device includes: Sensitive information identification module: used to identify sensitive information in uplink driving data, which is data that is stored in the data isolation area in response to a data upload request, and then synchronized from the data isolation area to the data buffer and stored in the storage location corresponding to the target path information; Compliance data generation module: When the coordinate information or vehicle identification information is detected in the uplink driving data, the module performs coordinate deflection processing on the coordinate information or data fuzzing processing on the vehicle identification information to obtain the compliance data corresponding to the uplink driving data. The third storage module is used to store the compliant data to the corresponding data storage location based on a preset compliant data path. Information acquisition module: used to respond to driving data access requests sent by the terminal that carry target object information and access point information, and to obtain the target security permission conditions corresponding to the target driving data to be accessed; Compliance detection module: When the target object information and the access point information meet the target security permission conditions, if the target driving data is not non-sensitive data, it performs compliance detection on the target driving data based on a preset compliance detection method to obtain a compliance detection result. Data processing module: If the compliance detection result indicates the presence of sensitive information in the target driving data, perform data conversion processing on the sensitive information to obtain the target desensitized data corresponding to the target driving data; the preset compliance detection method includes a sensitive information detection method and a risk data detection method; the detection method includes: identifying the coordinate information of each driving data in the target driving data based on coordinate attribute information to obtain the coordinate quantity information, coordinate value range information, and coordinate attribute information corresponding to each driving data; if, based on the coordinate quantity information, it is determined that the number of coordinates in the driving data is less than or equal to a preset number of coordinates, and the driving data does not contain coordinate attribute information... If the identified coordinate information is determined to be sensitive information, and if the number of coordinates in the driving data is greater than a preset number of coordinates, or the number of coordinates is less than or equal to a preset number of coordinates and the driving data contains coordinate attribute information, then the corresponding driving data is determined to be risk data. The risk data detection method includes: obtaining the content format information of each driving data in the target driving data; matching the content format information of each driving data with preset risk format information; if there is content format information that matches the preset risk format information, the driving data corresponding to the matched content format information is determined to be risk data. Data sending module: used to send the target de-identified data to the data buffer, synchronize the target de-identified data in the data buffer to the data isolation area, and send the target de-identified data in the data isolation area to the terminal so that the terminal can display the target de-identified data. The data isolation area and the data buffer are located on different servers, and the data isolation area is physically isolated from other servers.

7. The apparatus according to claim 6, characterized in that, The target driving data includes text data, and the compliance detection module includes: Word segmentation processing unit: used to perform text segmentation processing on the text data in the target driving data to obtain the text segments corresponding to the text data; Word segmentation and matching unit: used to perform word segmentation and matching on the text data corresponding to the text segmentation using compliant words in a preset compliant word library; The first sensitive information determination unit is used to identify sensitive information in text segmentation where no compliant words are matched.

8. The apparatus according to claim 6, characterized in that, The compliance detection module includes: Data type detection unit: used to perform data type detection on each driving data in the target driving data based on a preset data type; Data attribute value acquisition unit: used to acquire data attribute values ​​from the data header of the driving data of the preset data type if the existence of driving data of the preset data type is detected; Attribute value matching unit: used to match the data attribute value with a preset security attribute value; The second risk data determination unit is used to determine the driving data of the preset data type as risk data when no safety attribute value is matched.

9. The apparatus according to claim 6, characterized in that, The information acquisition module includes: Path information acquisition unit: used to acquire the data path information of the target driving data; Security permission condition determination unit: used to determine the security permission condition corresponding to the data path information of the target driving data as the target security permission condition based on the preset correspondence between data path information and security permission conditions.

10. The apparatus according to claim 6, characterized in that, The device further includes: First storage module: used to respond to a data upload request sent by the terminal, which carries target path information and uplink driving data, and store the uplink driving data in the data isolation area; Data synchronization module: used to synchronize the uplink driving data in the data isolation area to the data buffer using the data upload script; The second storage module is used to store the uplink driving data in the data buffer to the storage location corresponding to the target path information using the upload service thread.

11. A computer-readable storage medium, characterized in that, The storage medium stores at least one instruction or at least one program segment, which is loaded and executed by a processor to implement the driving data processing method as described in any one of claims 1-5.

12. A computer device, characterized in that, The device includes a processor and a memory, wherein the memory stores at least one instruction or at least one program, the at least one instruction or the at least one program being loaded and executed by the processor to implement the driving data processing method as described in any one of claims 1-5.

13. A computer program product, characterized in that, The computer program product includes computer instructions that, when executed by a processor, implement the driving data processing method as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Intelligent data query method and device, electronic equipment and storage medium

    CN113434901A

  • Data processing method and device, computer readable medium and electronic equipment

    CN113468511A