A self-checking method for cross-border data transmission
By introducing a self-test device in the data cross-border transmission, compliance review and credit assessment of received data is solved, and the problem of inability to effectively supervise and govern data use in traditional data cross-border transmission is improved, and the compliance and security of data use are improved.
Patent Information
- Application Number
- CN202310103499.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-13
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2043-02-13
AI Technical Summary
In traditional cross-border transmission of data, data recipients are unable to effectively supervise and govern the use of data, resulting in the leakage of personal privacy and important information, and may use data in violation of regulations, facing the risks of fines and sanctions.
The data cross-border self-test method is adopted to conduct compliance review of the received data through the self-test device, including downloading the basic self-test data, scanning local file data, generating self-test results and uploading them to the data platform, and conducting violation records and credit ratings.
It realizes effective supervision and governance of cross-border data transmission, improves the compliance and security of data use, reduces the risk of violations, and improves the security of data transmission through credit assessment.
Smart Images

Figure CN116132428B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data security use, and in particular relates to a self-checking method for cross-border data transmission. Background Art
[0002] With the rapid development of the digital economy and the booming of high-tech, the world has officially entered the era of big data, and data has played an increasingly important role in social development and people's lives. However, while big data has provided convenience to people's lives, a series of data security incidents caused by it have also attracted the attention of governments and society around the world.
[0003] The game and conflict between data security and compliance, economic and technological development are increasingly being placed at the forefront of public opinion. In recent years, my country has successively formulated the "Cybersecurity Law", "Data Security Law" and "Personal Information Protection Law" to determine the basic framework at the legal level, and relevant supporting regulations and implementation rules are also being formulated and improved. In the past, when Internet users used traditional cross-border data transmission, they did not have a strong concept of personal data protection, which may have serious consequences. From the perspective of the data sender, if you do not pay attention to the inspection of the data, it will cause the leakage of your personal privacy information and important information of your work unit (or even the country). From the perspective of the data receiver, if you do not pay attention to the inspection of the received data, you may use some expired or unauthorized data in violation of regulations, and there is a risk of facing huge fines or even national sanctions. Especially in traditional cross-border data transmission, the data receiver cannot effectively supervise and manage the use of the data after obtaining the data, and the historical use of the data by the data receiver cannot have a positive effect on the improvement of the security of future cross-border data transmission; therefore, it is very necessary to use a self-inspection device to self-inspect the data you send and receive. The present invention proposes a method and device for performing data self-check after data cross-border transmission, which can effectively improve the drawbacks of the above-mentioned traditional cross-border data transmission. Summary of the invention
[0004] The purpose of the present invention is to provide a method for cross-border data self-inspection; the cross-border data transmission is that the data publisher sends the data to the data receiver in some way, which can be transmitted directly or downloaded directly through the data platform for transmission; the data receiver uses the data after receiving the data; however, there may be some sensitive data in the data or the data itself has an authorized period for use, and these data should be subject to certain security processing after use; it is characterized in that the special processing is completed by a self-inspection device: after the data uploaded to the data platform is received, the use of the data is tracked. The receiver uses the self-inspection device to perform a data self-inspection on the received data, and the self-inspection device downloads the self-inspection basic data from the data platform, combines the received local file data scanned by the self-inspection device for compliance review, and uploads the data self-inspection results to the data platform;
[0005] The self-checking device comprises a data platform and a data self-checking module. The data platform comprises data uploading, data publishing, data review, data storage and data receiving in series, data receiving and subject consent are connected to self-checking data generation; violation records are respectively connected to self-checking report generation and user credit rating, and user credit rating is then connected to data publishing; the data platform is respectively connected to data acquisition and data uploading of the data self-checking module through self-checking data generation and violation records; the data platform provides the basic data required for self-checking operation for the data self-checking device, and the data self-checking module will upload and feed back the data of this self-checking to the data platform after performing a self-checking;
[0006] The data self-inspection module consists of data acquisition, compliance suggestions, result generation, violation record generation, violation upload, data scanning, subject consent policy configuration, and validity period check policy configuration; among which data scanning, subject consent policy configuration, and validity period check policy configuration constitute the data compliance review sub-module; violation record generation and violation upload are combined into a report generation sub-module.
[0007] The basic data transmission process of the data platform is: data upload -> data release -> data review -> data reception; when a new user is added to the data platform, the recorded user device information includes IPv6 address and Mac address; in data release, the risk level of this release is determined in combination with the user credit rating module to determine whether the review of this release requires manual intervention; if the risk of this release is judged to be high, manual review is required, otherwise it is automatically reviewed; the evaluation data of the user credit rating module is the data returned from the data self-check module;
[0008] The user credit rating module of the data platform can use the illegal project data to evaluate the user's credit level, which will have a positive impact on the security of future data releases. The self-check report module of the data platform can also use the illegal project data to generate a user's self-check report, and the user can improve his or her deficiencies in data compliance based on the content of the self-check report.
[0009] The data receiving module supports users to download data from the data platform. The data receiving module of the data platform records the user's download history. The self-check data generation module of the data platform generates data self-check results through the user's download history and the expiration time of the data, and performs the file expiration list required for the expired file check: it contains a list of files that the current user has downloaded on the cross-border data platform and have expired; in addition, the self-check data generation module obtains the subject consent task through the subject consent module of the data platform, and the subject consent task includes the user's claim for the right to use his or her personal information, such as reviewing, copying, correcting, supplementing, deleting, restricting use and withdrawing use; the data self-check module scans the subject consent information in the downloaded data according to the subject consent task and determines the information that needs to be corrected, supplemented, deleted or modified.
[0010] The self-checking process of the data self-checking device is as follows:
[0011] Step 1. The data acquisition module of the data self-check module obtains the IPv6 address of the running environment and obtains a local file list including all local files that need to be checked;
[0012] Step 2. The data acquisition module of the data self-checking module sends the IPv6 address to the data platform;
[0013] Step 3. The self-check data generation module of the data platform determines the user information of this self-check according to the received IPv6 address, and obtains the basic data of this self-check from the data receiving and subject consent module of the data platform according to the user information: file expiration list, subject consent task, and returns the data to the data acquisition module of the data self-check module;
[0014] Step 4. The data acquisition module transmits the file expiration list and subject consent tasks to the data compliance review module;
[0015] Step 5. The data compliance review module loads the subject consent policy configuration module and the expired file check module, uses the local file list obtained in step 1 and the file expiration list transmitted in step 4, and the subject consent task to start calling the data scanning module, and generates a file list containing files that have expired but have not been deleted by the user through the scanning operation; a file list that needs to be added, deleted, modified, and withdrawn for the subject information in the file, but the user has not performed the corresponding operation;
[0016] Step 6. The compliance suggestion module of the data self-checking module receives the scan results, performs compliance suggestion matching, and generates corresponding rectification suggestion data for each result data in the scan results;
[0017] Step 7. The result generation module of the data self-check module generates the original data of violations by combining the scanning results and the rectification suggestion data;
[0018] Step 8. The report generation module of the data self-inspection module receives the original violation data, which can be a list type data, including four columns: violation type, violation description, violation file list and rectification suggestion; wherein the violation type includes "file expiration", "file outbound", "change of outbound purpose", "file re-transfer", "handling rights request and complaint / appeal" and "illegal use of data subject information"; wherein the violation description is a supplementary description of the violation type; the violation file list is a path list of specific violation files; the rectification suggestion is a rectification suggestion for a violation type, wherein the rectification suggestion for "file expiration" is to provide a one-click deletion function; the violation record generation module is used to generate violation project data that meets the needs of the data platform, and the data includes the encapsulation of the original violation data, and adds some additional information, such as the self-inspection start time, self-inspection end time, and user id data; and the violation data upload module is used to transmit the violation data back to the violation record module of the data platform.
[0019] The present invention has the beneficial effect that, through the method, it is possible to timely and efficiently discover whether there are any violations in the cross-border data that has been received, and the protection of the appropriateness of cross-border data is strengthened.
[0020] In the process of self-checking data, data recipients can be provided with efficient rectification suggestions for the data that needs to be processed, thereby improving the compliance and legality of cross-border data use. At the same time, the self-checking data generated can also be used by the cross-border data platform to conduct credit assessments on cross-border data recipients and reduce the risks of cross-border data transmission in the later stage. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 This is a comparison diagram of data transmission processes, where a is the traditional process; b is the current process;
[0022] Figure 2 This is a schematic diagram of the self-test device. DETAILED DESCRIPTION
[0023] The purpose of the present invention is to provide a self-checking method for cross-border data transmission; the present invention is further explained below in conjunction with the accompanying drawings.
[0024] like Figure 1The data transmission process comparison diagram shown in the figure, where a is the traditional process; b is the current process; the cross-border data transmission process is that the data publisher sends the data to the data receiver in some way, which can be transmitted directly or downloaded directly through the data platform for transmission; after receiving the data, the data receiver uses the data (such as Figure 1 However, there may be some sensitive data in the data or the data itself has an authorized period. After use, these data should be subject to certain special processing; the special processing is completed by the self-checking device: after the data uploaded to the data platform is received, the use of the data is tracked. The recipient uses the self-checking device to perform a data self-check on the received data. The self-checking device downloads the basic self-checking data from the data platform, and performs a compliance review on the received local file data scanned by the self-checking device, and uploads the data self-checking results to the data platform. (As shown in a Figure 1 (as shown in b);
[0025] like Figure 2 The self-checking device shown includes a data platform and a data self-checking module. The data platform includes data uploading, data publishing, data review, data storage, and data receiving in series. Data receiving and subject consent are connected to self-checking data generation; violation records are respectively connected to self-checking report generation and user credit rating, and user credit rating is then connected to data publishing; the data platform is connected to data acquisition and data uploading of the data self-checking module through self-checking data generation and violation records respectively; the data platform provides the basic data required for self-checking operation for the data self-checking device, and the data self-checking module will upload and feed back the data of this self-checking to the data platform after performing a self-checking;
[0026] The data self-inspection module consists of data acquisition, compliance suggestions, result generation, violation record generation, violation upload, data scanning, subject consent policy configuration, and validity period check policy configuration; among which data scanning, subject consent policy configuration, and validity period check policy configuration constitute the data compliance review sub-module; violation record generation and violation upload are combined into a report generation sub-module.
[0027] The basic data transmission process of the data platform is: data upload -> data release -> data review -> data reception; when a new user is added to the data platform, the recorded user device information includes IPv6 address and Mac address; in data release, the risk level of this release is determined in combination with the user credit rating module to determine whether the review of this release requires manual intervention; if the risk of this release is judged to be high, manual review is required, otherwise it is automatically reviewed; the evaluation data of the user credit rating module is the data returned from the data self-check module;
[0028] The user credit rating module of the data platform can use the illegal project data to evaluate the user's credit level, which will have a positive impact on the security of future data releases. The self-check report module of the data platform can also use the illegal project data to generate a user's self-check report, and the user can improve his or her deficiencies in data compliance based on the content of the self-check report.
[0029] The data receiving module supports users to download data from the data platform. The data receiving module of the data platform records the user's download history. The self-check data generation module of the data platform generates data self-check results through the user's download history and the expiration time of the data, and performs the file expiration list required for the expired file check: it contains a list of files that the current user has downloaded on the cross-border data platform and have expired; in addition, the self-check data generation module obtains the subject consent task through the subject consent module of the data platform, and the subject consent task includes the user's claim for the right to use his or her personal information, such as reviewing, copying, correcting, supplementing, deleting, restricting use and withdrawing use; the data self-check module scans the subject consent information in the downloaded data according to the subject consent task and determines the information that needs to be corrected, supplemented, deleted or modified.
[0030] The self-checking process of the data self-checking device is as follows:
[0031] Step 1. The data acquisition module of the data self-check module obtains the IPv6 address of the running environment and obtains a local file list including all local files that need to be checked;
[0032] Step 2. The data acquisition module of the data self-checking module sends the IPv6 address to the data platform;
[0033] Step 3. The self-check data generation module of the data platform determines the user information of this self-check according to the received IPv6 address, and obtains the basic data of this self-check from the data receiving and subject consent module of the data platform according to the user information: file expiration list, subject consent task, and returns the data to the data acquisition module of the data self-check module;
[0034] Step 4. The data acquisition module transmits the file expiration list and subject consent tasks to the data compliance review module;
[0035] Step 5. The data compliance review module loads the subject consent policy configuration module and the expired file check module, uses the local file list obtained in step 1 and the file expiration list transmitted in step 4, and the subject consent task to start calling the data scanning module, and generates a file list containing files that have expired but have not been deleted by the user through the scanning operation; a file list that needs to add, delete, modify, and withdraw the subject information in the file, but the user has not performed the corresponding operation;
[0036] Step 6. The compliance suggestion module of the data self-checking module receives the scan results, performs compliance suggestion matching, and generates corresponding rectification suggestion data for each result data in the scan results;
[0037] Step 7. The result generation module of the data self-check module generates the original data of violations by combining the scanning results and the rectification suggestion data;
[0038] Step 8. The report generation module of the data self-inspection module receives the original violation data, which can be a list type data, including four columns: violation type, violation description, violation file list and rectification suggestion; wherein the violation type includes "file expiration", "file outbound", "change of outbound purpose", "file re-transfer", "handling rights request and complaint / appeal" and "illegal use of data subject information"; wherein the violation description is a supplementary description of the violation type; the violation file list is a path list of specific violation files; the rectification suggestion is a rectification suggestion for a violation type, wherein the rectification suggestion for "file expiration" is to provide a one-click deletion function; the violation record generation module is used to generate violation project data that meets the needs of the data platform, and the data includes the encapsulation of the original violation data, and adds some additional information, such as the self-inspection start time, self-inspection end time, and user id data; and the violation data upload module is used to transmit the violation data back to the violation record module of the data platform.
[0039] Example
[0040] The data acquisition module in step 4 also has the function of acquiring the self-check basic data and the local file list data; specifically including:
[0041] Step 41. Utilize the data scanning module and generate a local path for the user to input for self-checking through scanning operation. When the user inputs "c:\Users\mxzhang\Desktop\123" and there is an expired file "Supplementary Material 24.txt" under the path;
[0042] Step 42. After the user has filled in the local self-check path in step 41, click the Download Self-check List button. The click event of this button integrates the data acquisition module function and starts scanning the path entered by the user. If the path is a real path, all files under the path will be scanned, including files in all subfolders, as a local file list, and after recording, jump to step 44, otherwise end.
[0043] Step 43. Read all IPv6 addresses and poll the data platform for data until the data platform returns the file expiration list and the subject agrees to the task (if there is no data, it can be empty), then jump to step 45, otherwise it ends directly.
[0044] Step 44. Jump to the self-check list;
[0045] The "self-check list" of step 44 is implemented as follows:
[0046] Step 441. The file expiration list is displayed by a file expiration table and a subject consent expiration table respectively; subject consent task, there is an expired file "Supplementary Material 24.txt" in the file expiration list that needs to be checked.
[0047] Step 442. Call the data compliance review module. Based on the file expiration list and subject consent task (which can be left blank if there is no data) obtained in step 441, the data compliance review module loads the subject consent policy configuration module and the expired file inspection module, performs data scanning, and generates scanning results (including a list of files that have expired but have not been deleted by the user, and a list of files in which the subject information needs to be added, deleted, modified, or withdrawn but the user has not performed the corresponding operations).
[0048] Step 443. Call the compliance suggestion module to receive the scan results, perform compliance suggestion matching, and generate corresponding rectification suggestion data for each result data in the scan results.
[0049] Step 444. Call the result generation module to generate the original violation data based on the scanning results and rectification suggestion data.
[0050] Step 445. Jump to the self-test report.
[0051] The self-check report in step 445 is divided into two situations: no violation and violation, which are integrated into a report generation module. The specific implementation method is as follows:
[0052] Step 4451. The violation record generation module receives the original violation data transmitted from the self-check list and converts it into violation record data; if there is no violation record, a self-check report without violation is generated and the process goes to step 4453; otherwise, a self-check report with violation is generated and the process goes to step 4452.
[0053] Step 4452. Generate an expired and undeleted table and a subject consent invalidation table in the self-check report with violations, and display the type of violation, violation description, file list, and modification suggestions after the data self-check in the table. If it is a suggestion that can be automatically executed, generate a one-click execution button; if the file "Supplementary Material 24.txt" is an expired but not deleted file, give a violation description of the expired file and a one-click delete button for rectification, which can directly delete the expired file. Otherwise, give rectification suggestions for the user to modify manually. Jump to step 4453.
[0054] Step 4453. The user clicks the upload report button to call the violation upload and transmit the data to the violation record module of the data platform. If there is no violation, jump to step 4455, otherwise jump to step 4454.
[0055] Step 4454. The user makes corrections according to the correction suggestions. After the corrections are completed, the process jumps to step 441 to start self-checking.
[0056] Step 4455. Self-test ends.
[0057] The violation data uploaded by the data self-checking device of the present invention can be used by the data platform to generate a downloadable report file in PDF format, which users can download to understand their own data usage violation in each data self-check, bringing positive effects for future data compliance use. When the data management platform releases data, the risk level of the data released once can also be evaluated to improve the security of data transmission.
Claims
1. A self-checking method for cross-border data transmission; characterized in that: The self-check process for cross-border data transmission is as follows: Step 1. The data acquisition module of the data self-check module obtains the IPv6 address of the operating environment and obtains a list of all local files that need to be checked; Step 2. The data acquisition module sends the IPv6 address to the data platform; Step 3. The self-check data generation module of the data platform determines the user information of this self-check according to the received IPv6 address, and obtains the basic data of this self-check from the data receiving module and the subject consent module of the data platform according to the user information. The basic data includes: file expiration list, subject consent task, and returns the data to the data self-check module; Step 4. The data acquisition module transmits the file expiration list and subject consent tasks to the data compliance review module; Step 5. The data compliance review module loads the subject consent policy configuration module and the expired file check module, uses the local file list and file expiration list, and the subject consent task to start calling the data scanning module, and generates a file list containing files that have expired but have not been deleted by the user, and a file list that needs to add, delete, modify, and withdraw the subject information in the file, but the user has not performed the corresponding operation; Step 6. The compliance suggestion module of the data self-checking module receives the scan results, performs compliance suggestion matching, and generates corresponding rectification suggestion data for each result data in the scan results; Step 7. The result generation module of the data self-check module generates the original data of violations by combining the scanning results and the rectification suggestion data; Step 8. The report generation module of the data self-check module receives the original violation data, which is list type data, including four columns: violation type, violation description, violation file list and rectification suggestion; wherein, the violation description is a supplementary description of the violation type; the violation file list is a path list of violation files; the rectification suggestion is a rectification suggestion for a violation type, and the violation record generation module is used to generate violation project data, the violation project data includes the original violation data, self-check start time, self-check end time, and user id data; and the violation project data upload module is used to send the violation data back to the violation record module of the data platform.
2. The self-checking method for cross-border data transmission according to claim 1 is characterized in that: The data transmission process of the data platform is: data upload, data release, data review, and data reception in sequence; when a new user is added to the data platform, the recorded user device information includes the IPv6 address and the Mac address; during data release, the user credit rating module is combined to determine the risk level of this release, and decide whether the review of this release requires manual intervention; if the risk of this release is judged to be high, manual review is required, otherwise it is automatically reviewed.
3. The self-checking method for cross-border data transmission according to claim 1 is characterized in that: The user credit rating module of the data platform uses the illegal project data to evaluate the user's credit level, while the self-inspection report module of the data platform uses the illegal project data to generate a self-inspection report for the user.
4. The self-checking method for cross-border data transmission according to claim 1, characterized in that: The data receiving module supports users to download data from the data platform. The data receiving module of the data platform records the user's download records. The self-check data generation module of the data platform generates data self-check basic data through the user's download records and the expiration time of the data. The basic data includes an expiration list of files that the current user has downloaded from the data platform and have expired. In addition, the self-check data generation module obtains the subject consent task through the subject consent module of the data platform. The subject consent task includes the user's claim for the right to use his or her personal information. The data self-check module scans the subject consent information in the downloaded data according to the subject consent task and determines the information that needs to be corrected, supplemented, or deleted.
Citation Information
Patent Citations
Data cross-border compliance management and control method and device, computer equipment and storage medium
CN114760149A
Dynamic data-use restrictions
US20190018985A1