A data leakage processing method, device and equipment for multi-scene application and a medium

By performing voiceprint recognition and 3D spatial reconstruction on the recorded information, and combining the recording time and personnel information to locate the eavesdropping location, the problem of tracing information leakage in corporate meeting minutes has been solved, enabling the tracking and locking of the leaking personnel and improving the confidentiality and reliability of the data.

CN116340998BActive Publication Date: 2026-07-28BEIJING SOUVI INFORMATION TECH INC CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING SOUVI INFORMATION TECH INC CO LTD
Filing Date
2023-03-04
Publication Date
2026-07-28

AI Technical Summary

Technical Problem

Existing technologies fail to effectively trace those responsible for information leaks during the storage of corporate meeting minutes, resulting in low information confidentiality and poor reliability, especially lacking protection during the data storage stage.

Method used

By performing voiceprint recognition and 3D spatial reconstruction on the recorded information, a model of the meeting venue is reconstructed. Combined with the recording time and personnel information, the location of the eavesdropping can be located, enabling the tracking and locking of the person who leaked the information. Confidential information is protected through preset protocols and dynamic passwords.

Benefits of technology

It improves the confidentiality and reliability of meeting data, effectively tracks and identifies those who leak information, and enhances information security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116340998B_ABST
    Figure CN116340998B_ABST
Patent Text Reader

Abstract

The application relates to the field of data leakage processing, in particular to a multi-scene applied data leakage processing method and device, equipment and medium. The method comprises the following steps: acquiring recording information, the recording information comprising a recording file and a recording time; performing sound feature analysis on the recording file to obtain conference participant information and sound channel information in the recording file; performing three-dimensional space reconstruction on the sound channel information to obtain at least one sound scene model; combining the at least one sound scene model with the conference participant information to obtain at least one group of personnel positions; calling a conference image according to the recording time and the conference participant information to obtain a conference scene image; positioning personnel positions of the conference scene image to obtain actual personnel positions; and obtaining an eavesdropping position according to the actual personnel positions and the at least one group of personnel positions. The application has the effect of improving the confidentiality of confidential information in different scenes.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of data leakage processing, and in particular to a data leakage processing method and device for multiple scenarios, equipment and medium. BACKGROUND

[0002] In recent years, data leakage events in China have shown a growing trend, especially in the second half of 2021, data leakage events have occurred frequently, and the promulgation of the Data Security Law and the Personal Information Protection Law in the second half of 2021 further illustrates the seriousness of current data leakage and the importance of data security in China.

[0003] In terms of data security protection, data protection during the data storage stage is relatively lacking. Among them, the data storage related to the market mainly exists in enterprise conference records, report materials, etc. The current commonly used enterprise conference report storage method is: a person specially records the conference content on the spot, and after the conference ends, the recording content and the conference recording are collated and audited to form the final conference draft and store it in the warehouse. It can be seen that the above storage process does not involve tracking the leakage personnel after the information is leaked on the spot, nor does it realize the perfect storage of the final conference draft. The conference data security problems such as low information confidentiality and poor reliability brought by this need to be solved. SUMMARY

[0004] In order to solve the problems existing in the prior art, the present application provides a data leakage processing method and device for multiple scenarios, equipment and medium.

[0005] In a first aspect, the present application provides a data leakage processing method for multiple scenarios, which adopts the following technical solution: A data leakage processing method for multiple scenarios, comprising: obtaining recording information, the recording information comprising a recording file and a recording time; performing sound feature analysis on the recording file to obtain conference personnel information and sound channel information in the recording file; performing three-dimensional space reconstruction on the sound channel information to obtain at least one sound scene model, the sound scene model being used to represent the positions of sound sources in the conference; combining the at least one sound scene model with the conference personnel information to obtain at least one group of personnel positions; according to the recording time and the conference personnel information, calling a conference image to obtain a conference scene image; positioning the personnel positions in the conference scene image to obtain actual personnel positions, the actual personnel positions being used to represent the actual positions of the conference personnel information in the conference; The eavesdropping location is obtained based on the actual location of the personnel and the location of at least one group of personnel. The eavesdropping location is used to indicate the specific eavesdropping location when eavesdropping on each sound source in the meeting.

[0006] In another possible implementation, the three-dimensional spatial reconstruction of the vocal tract information to obtain at least one sound scene model includes: Obtain the actual spatial information of the meeting; The vocal tract information is input into a well-trained sound localization algorithm to obtain at least one set of on-site sound source coordinates, which are used to represent the spatial coordinates of different sound sources within the vocal tract information in the conference. A field model is obtained by performing data analysis on the actual spatial information, and the field model is used to represent the digital model of the sound source site; The at least one set of on-site sound source coordinates is combined with the on-site model to obtain the at least one sound on-site model.

[0007] In another possible implementation, the matching analysis of the actual location of the personnel with the at least one set of personnel locations to obtain the eavesdropping location includes: The actual locations of the personnel are matched with the locations of at least one group of personnel to obtain a target scene model; The location of the eavesdropping is obtained by locking the position of the target scene model.

[0008] In another possible implementation, the method also includes: Obtain confidential information and corresponding confidentiality level information, wherein the confidential information is used to represent pre-stored confidential information; The preset protocol is matched with the confidentiality level information to obtain attack information corresponding to the confidentiality level information. The preset protocol is used to represent the correspondence between the confidentiality level information and the attack information, and the attack information is used to represent information about attacking the illegal disclosure of the confidential information object. In another possible implementation, a preset protocol is matched with the security level information to obtain attack information corresponding to the security level information, and then the process further includes: Upon detecting a file retrieval command, the login information in the file retrieval command is verified to be compliant. The file retrieval command is used to indicate the operator's operation instruction to retrieve the confidential information. If the login information is compliant, the system will control the display of the confidential information and generate a real-time monitoring instruction. The real-time monitoring instruction is used to control the data acquisition device to monitor the operator in real time.

[0009] In another possible implementation, verifying the compliance of the login information in the file retrieval instruction includes: If the login information is not compliant, a verification limit is generated and displayed, and the number of verification limit attempts is used to indicate the remaining number of verification attempts; Determine whether the verification limit is a preset value; if so, overlay the confidential information according to the preset disguise information. Determine whether the operator has performed a copy operation on the preset disguised information. If so, write the attack information into the preset disguised information to obtain attack file information, and change the copy operation target to the attack file information.

[0010] In another possible implementation, it is determined whether the operator has performed a copy operation on the preset disguised information. If so, the attack information is written into the preset disguised information to obtain attack file information, and the copy operation target is changed to the attack file information. This further includes: Obtain information on whitelisted personnel and the personnel identity information corresponding to the whitelisted personnel information, wherein the whitelisted personnel information is used to represent personnel information who perform compliant operations on the confidential information; A dynamic password is generated based on the personnel identity information and preset dynamic password rules, and the dynamic password is sent to the target device, which is a communication device corresponding to the personnel identity information. Upon detecting the account information sent by the target device, the password in the account information is verified to correspond to the dynamic password. If the verification is successful, the disguised information is reverse-overwritten according to the confidential information.

[0011] Secondly, this application provides a data leakage handling device for multi-scenario applications, comprising: The information acquisition module is used to acquire recording information, which includes the recording file and the recording time. The feature analysis module is used to perform sound feature analysis on the audio file to obtain information about the meeting participants and audio channels within the audio file. The spatial reconstruction module is used to perform three-dimensional spatial reconstruction of the audio channel information to obtain at least one sound scene model, which is used to represent the location of each sound source in the meeting; The location combination module is used to combine the at least one sound scene model with the meeting personnel information to obtain at least one set of personnel locations; The image retrieval module is used to retrieve meeting images based on the recording time and the meeting participants' information to obtain images of the meeting venue; The location positioning module is used to locate the positions of people in the meeting scene image to obtain the actual positions of the people. The actual positions of the people are used to represent the actual positions of the meeting participants in the meeting. A position fitting module is used to obtain the eavesdropping position based on the actual position of the personnel and the position of at least one group of personnel. The eavesdropping position is used to represent the specific eavesdropping position when eavesdropping on each sound source in the meeting.

[0012] In another possible implementation, the spatial reconstruction module performs three-dimensional spatial reconstruction on the vocal tract information to obtain at least one sound scene model, specifically used for: Obtain the actual spatial information of the meeting; The vocal tract information is input into a well-trained sound localization algorithm to obtain at least one set of on-site sound source coordinates, which are used to represent the spatial coordinates of different sound sources within the vocal tract information in the conference. A field model is obtained by performing data analysis on the actual spatial information, and the field model is used to represent the digital model of the sound source site; The at least one set of on-site sound source coordinates is combined with the on-site model to obtain the at least one sound on-site model.

[0013] In another possible implementation, the location fitting module performs matching analysis between the actual location of the person and the at least one set of personnel locations to obtain the eavesdropping location, specifically for: The actual locations of the personnel are matched with the locations of at least one group of personnel to obtain a target scene model; The location of the eavesdropping is obtained by locking the position of the target scene model.

[0014] In another possible implementation, the apparatus further includes: a module for acquiring confidential information and a module for matching attack information, wherein, The confidential information acquisition module is used to acquire confidential information and confidentiality level information corresponding to the confidential information, wherein the confidential information is used to represent pre-stored confidential information; The attack information matching module is used to match a preset protocol with the security level information to obtain attack information corresponding to the security level information. The preset protocol is used to represent the correspondence between the security level information and the attack information, and the attack information is used to represent information about attacking the illegal disclosure of the confidential information object. In another possible implementation, the device further includes: a verification information module and a compliance operation module, wherein, The verification information module is used to verify whether the login information in the file acquisition instruction is compliant when a file acquisition instruction is detected. The file acquisition instruction is used to represent the operation instruction of the operator to acquire the confidential information. The compliance operation module is used to control the display of the confidential information and generate a real-time monitoring instruction if the login information is compliant. The real-time monitoring instruction is used to control the data acquisition device to monitor the operator in real time.

[0015] In another possible implementation, the verification information module verifies whether the login information in the file retrieval instruction is compliant, specifically for: If the login information is not compliant, a verification limit is generated and displayed, and the number of verification limit attempts is used to indicate the remaining number of verification attempts; Determine whether the verification limit is a preset value; if so, overlay the confidential information according to the preset disguise information. Determine whether the operator has performed a copy operation on the preset disguised information. If so, write the attack information into the preset disguised information to obtain attack file information, and change the copy operation target to the attack file information.

[0016] In another possible implementation, the apparatus further includes: a personnel identification module, a dynamic password generation module, and a dynamic password verification module, wherein, The personnel identity acquisition module is used to acquire whitelist personnel information and personnel identity information corresponding to the whitelist personnel information. The whitelist personnel information is used to represent personnel information who perform compliant operations on the confidential information. The dynamic password generation module is used to generate a dynamic password based on the personnel identity information and preset dynamic password rules, and send the dynamic password to the target device, wherein the target device is a communication device corresponding to the personnel identity information; The dynamic password verification module is used to verify whether the password in the account information corresponds to the dynamic password after detecting the account information sent by the target device. If the verification is successful, the disguised information is reverse-overwritten according to the confidential information.

[0017] Thirdly, this application provides an electronic device that adopts the following technical solution: An electronic device comprising: At least one processor; Memory; At least one application, wherein the at least one application is stored in memory and configured to be executed by at least one processor, the at least one application being configured to: execute the data leakage handling method described above for multi-scenario applications.

[0018] Fourthly, a computer-readable storage medium is provided, which stores at least one instruction, at least one program, code set, or instruction set, wherein the at least one instruction, at least one program, code set, or instruction set is loaded and executed by a processor to implement a data leakage handling method for multi-scenario applications as shown in any possible implementation of the first aspect.

[0019] In summary, this application includes the following beneficial technical effects: This application provides a data leakage processing method, apparatus, device, and readable storage medium for multi-scenario applications. Compared with related technologies, in this application, spatial models of meeting participants and the sound scene (i.e., sound scene model) are obtained by performing voiceprint recognition and spatial reconstruction on the recording information. Then, the positions of the meeting participants are located in the sound scene model to obtain the relative positions of the meeting participants with respect to the eavesdropping location, i.e., the personnel positions.

[0020] By retrieving the recording time from the audio file and the identified meeting attendees, images of the meeting venue can be obtained. The locations of the attendees in the meeting venue images can then be determined to obtain their relative positions with respect to the meeting venue, i.e., their actual positions.

[0021] By fitting the actual location of personnel to the actual location of the eavesdropping points, the relative location of the eavesdropping points with respect to the meeting venue is obtained, i.e., the specific eavesdropping locations. At this point, the eavesdropping locations within the meeting venue have been determined. Based on these locations, suspected individuals who may have leaked meeting information can be identified, enabling the tracking and locating of the leakers, thereby improving the confidentiality and reliability of meeting data. Attached Figure Description

[0022] Figure 1 This is a flowchart illustrating a data leakage handling method for multiple application scenarios according to an embodiment of this application; Figure 2 This is a block diagram of a data leakage processing device for multi-scenario applications according to an embodiment of this application; Figure 3 This is a schematic diagram of a data leakage processing device for multi-scenario applications according to an embodiment of this application. Detailed Implementation

[0023] The following is in conjunction with the appendix Figures 1-3 This application will be described in further detail.

[0024] After reading this specification, those skilled in the art may make modifications to this embodiment without contributing any inventive step, but such modifications are protected by patent law as long as they fall within the scope of the claims of this application.

[0025] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0026] Furthermore, the term "and / or" in this document merely describes the relationship between related objects, indicating that three relationships can exist. For example, "a method, apparatus, electronic device, and storage medium for multimodal transport schedule selection and / or B" can represent: the existence of a method, apparatus, equipment, and medium for multimodal transport schedule selection alone; the simultaneous existence of a method, apparatus, equipment, and medium for multimodal transport schedule selection and B; or the existence of B alone. Additionally, the character " / " in this document, unless otherwise specified, generally indicates that the related objects before and after it are in an "or" relationship.

[0027] The embodiments of this application will now be described in further detail with reference to the accompanying drawings.

[0028] This application provides a data leakage handling method for multiple application scenarios, executed by an electronic device. This electronic device can be a server or a terminal device. The server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The terminal device can be a smartphone, tablet, laptop, desktop computer, etc., but is not limited to these. The terminal device and the server can be directly or indirectly connected via wired or wireless communication. This application does not impose any limitations on this. Figure 1 As shown, the method includes: Step A001: Obtain audio recording information.

[0029] Step A002: Perform sound feature analysis on the recording file to obtain information about the meeting participants and audio channels within the recording file.

[0030] The audio recording information includes the audio file and the recording time.

[0031] In this embodiment of the application, an audio recording file is obtained from the audio storage device, and the corresponding recording time is obtained based on the recording file. The recording file is sampled and quantized to obtain an audio waveform, features are extracted from the obtained audio waveform, and meeting participant information is obtained based on the audio features and the recording time.

[0032] For example, if the recording time is 8:30 am on February 20, 2000, and the number of meetings that were held at the same time is not equal to 1, then the voice feature vector obtained after voice feature extraction is used to identify the voiceprints of the people in the multiple meetings, so as to determine the unique set of meetings with a matching degree of 1, and identify the participants of the meetings with a matching degree of 1 as meeting personnel, and at the same time, the names and positions of the meeting personnel are used as meeting personnel information. If the number of meetings is equal to 1, the voice feature vector obtained after voice feature extraction is matched with the voiceprint of the participants in the meeting. When the matching degree is 1, the participants are identified as meeting participants, and their names and positions are used as meeting participant information.

[0033] Specifically, the information of the meeting participants should be determined based on the actual situation, including but not limited to the information described in the embodiments of this application.

[0034] Step A003: Perform three-dimensional spatial reconstruction on the audio channel information to obtain at least one sound scene model.

[0035] Among them, the sound scene model is the scene space model after determining the location of each sound source in the meeting, and the sound acquisition device is a sound acquisition device with multiple microphones built in.

[0036] In this embodiment of the application, an auditory transfer function is obtained by measuring historical audio data. This auditory transfer function is then decomposed to obtain a directional transfer function and a common transfer function. Simultaneously, the time difference within the auditory transfer function is extracted.

[0037] The directional transfer function and the common transfer function are processed and approximated. The time-domain impulse responses of the two functions obtained after approximation are convolved with each other and added to the previously extracted time difference to obtain the head-related impulse responses in different directions. This indicates that the sound model has been successfully established.

[0038] The historical space is divided into regions, and simulated sound source devices and sound acquisition devices are set up. The time difference when multiple microphones receive simulated sound sources is recorded. Multiple sets of time differences are used as training data to train the neural network algorithm. When the output of the neural network algorithm approaches the actual position of the simulated sound source device, the training is considered successful.

[0039] A virtual scene model is obtained by inputting the vocal tract information into a successfully built sound model. Then, the virtual scene model is input into a successfully trained neural network algorithm to obtain at least one sound scene model with the sound acquisition device as the auditory center.

[0040] Specifically, the number of microphones in the sound acquisition device should be at least three to provide two sets of time differences in the received sound to determine the sound location in two-dimensional space. The choice of neural network algorithm includes, but is not limited to, the BP neural network algorithm.

[0041] Step A004: Combine at least one sound scene model with the meeting personnel information to obtain at least one set of personnel locations.

[0042] The personnel location includes the coordinates of the meeting participants' markers and their information.

[0043] In this embodiment of the application, the meeting participants' information is marked on the sound scene model based on the sound features obtained in step A002. This coordinate is used as the coordinates of the meeting participants on the sound scene model, and the obtained coordinates are identified as the participants' positions. At least one set of participants' positions is obtained by combining different sound scene models with the meeting participants' information. For example, marking the positions of meeting participants Zhang San and Li Si on different sound models yields at least one set of participants' positions.

[0044] Step A005: Retrieve meeting images based on recording time and meeting attendee information to obtain meeting scene images.

[0045] In this embodiment of the application, the recording time is used as the first filtering condition and the meeting participants' information is used as the second filtering condition. The meeting records are filtered according to the first and second filtering conditions, and the meeting images that meet the filtering conditions are retrieved and used as the meeting scene images.

[0046] Specifically, the screening methods currently used are widely available in the market, and will not be described in detail in the embodiments of this application.

[0047] Step A006: Locate the positions of personnel in the meeting scene images to obtain their actual positions.

[0048] The actual location of the personnel refers to their actual position during the meeting.

[0049] In this embodiment of the application, face localization and face recognition are performed on the meeting scene image. The identified person's identity and the position obtained by face localization (or the movement trajectory determined by continuous movement position) are combined and used as the person's actual position.

[0050] The actual dimensions of the meeting venue are obtained by reconstructing the meeting venue images to their true scale, and a coordinate system is constructed based on the actual dimensions of the meeting venue to represent the actual positions of the personnel.

[0051] Specifically, the methods for representing the actual location of personnel include, but are not limited to, one described in the embodiments of this application.

[0052] Step A007: Obtain the eavesdropping location based on the actual location of the personnel and the location of at least one group of personnel.

[0053] The eavesdropping location is used to indicate the specific eavesdropping location during the eavesdropping of the meeting.

[0054] In this embodiment of the application, the coordinate system used to determine the actual location coordinates of the personnel and the coordinate system used in the sound scene model are fitted together, and the zero point of the fitted coordinate system is taken as the eavesdropping position.

[0055] This application provides a data leakage processing method for multiple application scenarios. By performing voiceprint recognition and spatial reconstruction on the recorded information, spatial models of meeting participants and the sound scene (i.e., sound scene model) are obtained respectively. Then, the positions of the meeting participants are located in the sound scene model to obtain the relative positions of the meeting participants with respect to the eavesdropping location, i.e., the personnel positions.

[0056] By retrieving the recording time from the audio file and the identified meeting attendees, images of the meeting venue can be obtained. The locations of the attendees in the meeting venue images can then be determined to obtain their relative positions with respect to the meeting venue, i.e., their actual positions.

[0057] By fitting the actual location of personnel to the actual location of the eavesdropping points, the relative location of the eavesdropping points with respect to the meeting venue is obtained, i.e., the specific eavesdropping locations. At this point, the eavesdropping locations within the meeting venue have been determined. Based on these locations, suspected individuals who may have leaked meeting information can be identified, enabling the tracking and locating of the leakers, thereby improving the confidentiality and reliability of meeting data.

[0058] One possible implementation of this application embodiment is that step A003 includes steps A008 (not shown in the figure), A009 (not shown in the figure), A010 (not shown in the figure), and A011 (not shown in the figure), wherein, Step A008: Obtain the actual spatial information of the meeting.

[0059] Step A009: Input the vocal tract information into the well-trained sound localization algorithm to obtain at least one set of on-site sound source coordinates.

[0060] Among them, the on-site spatial information is the spatial information of the meeting venue, and the on-site sound source coordinates are the spatial coordinates of different sound sources within the sound channel information during the meeting.

[0061] For the embodiments of this application, the actual choice of sound localization algorithm is not limited. The following uses the BP neural network algorithm as an example to introduce how to construct a sound localization algorithm.

[0062] The HRTF (Head-Related Transfer Function) function was obtained through experimental measurements of historical vocal tract information. This HRTF function was then decomposed into a directional transfer function (DTF) and a common transfer function (CTF) independent of actual orientation. The interaural time difference (ITD) at different angles was extracted. The DTF and CTF were analyzed using a low-order finite-impulse-response (FIR) model, and the minimum phase function was used to approximate both the CTF and DTF models. The deviation of the reconstructed signal from the original measurement was represented by a normalized error.

[0063] When the rate of error reduction gradually slows down as the order of CTF and DTF increases, the CTF and DTF models at this point are considered the best approximation models. The temporal impulse responses of the obtained CTF and DTF are convolved together, and an ITD extracted in advance from the experimental measurement data is added to obtain the HRTR (head-related impulse response) in different directions. At this point, the sound model is considered to have been successfully constructed.

[0064] The ground area of ​​the historical conference site was divided, and a simulated sound source device was set up. A sound acquisition device with multiple (at least 3) microphones was used to record the time difference of the sound received from the simulated sound source device. The obtained time difference was used as training data and input into the input layer of the BP neural network. When the output result approximates the actual sound source location of the simulated sound source device, the BP neural network is considered to have been successfully trained.

[0065] The duct information is input into the established sound model to obtain a virtual scene model. Then, the virtual scene model is input into the BP neural network algorithm to obtain at least one sound scene model.

[0066] Establish a coordinate system for the sound field model with the sound acquisition device as the zero point, and mark the position of the simulated sound source device within it. Use the marked position coordinates of the simulated sound source device as the coordinates of the sound source on site.

[0067] Specifically, when determining whether the output of the BP neural network approximates the actual position of the simulated sound source device, the method used should be selected according to the actual situation.

[0068] For example, a fixed location at the meeting venue is selected, or the historical meeting venue is divided into areas. The sound acquisition device is used as the zero point of the coordinate system. A coordinate system is established using this zero point to obtain the coordinates of the simulated sound source device within the coordinate system. When the output of the BP neural network matches the obtained coordinates with a high degree of similarity (e.g., greater than or equal to 95%), it is considered that the output of the BP neural network has successfully approximated the simulated sound source device.

[0069] Step A010: Perform data analysis on the actual spatial information to obtain an actual model.

[0070] The spatial information includes: the actual dimensions of the meeting venue, and the on-site model is a simulation model of the sound source location.

[0071] In this embodiment of the application, a spatial simulation model of the meeting venue is constructed based on the actual dimensions of the meeting venue as the basic parameter, and this spatial simulation model is used as the actual model.

[0072] Step A011: Combine at least one set of on-site sound source coordinates with the on-site model to obtain at least one sound on-site model.

[0073] In this embodiment of the application, the coordinates of any on-site sound source obtained in step A009 are determined within the spatial simulation model obtained in step A010 to obtain at least one sound on-site model.

[0074] In one possible implementation of this application embodiment, step A007 includes step A012 (not shown in the figure) and step A013 (not shown in the figure), wherein, Step A012: Match the actual location of the personnel with at least one set of personnel locations to obtain the target site model.

[0075] In this embodiment of the application, the coordinates of the personnel's actual location are matched with the marked coordinates of any group of personnel locations. If the match is successful, the meeting personnel information corresponding to the personnel's location is bound to the personnel's location coordinates to obtain a sound space model with the eavesdropping location as the sound collection center. This sound space model is then used as the target scene model.

[0076] Step A013: Locate the target scene model to obtain the eavesdropping location.

[0077] In this embodiment of the application, a match is made between the coordinate system of the personnel location coordinates in the target site model and the coordinate system of any marker coordinates. When a match is successful, the zero point of the coordinate system of the successfully matched marker coordinates is taken as the eavesdropping location.

[0078] One possible implementation of this application embodiment further includes steps A014 (not shown in the figure) and A015 (not shown in the figure), wherein... Step A014: Obtain confidential information and the corresponding confidentiality level information.

[0079] Step A015: Match the preset protocol with the security level information to obtain the attack information corresponding to the security level information.

[0080] Among them, confidential information includes pre-stored confidential information, preset protocols are the correspondence between confidentiality level information and attack information, and attack information is information about the targets of attacks that illegally leak confidential information.

[0081] In this embodiment of the application, confidential information in the memory is obtained and the corresponding confidentiality level is obtained according to the correspondence between confidential information and confidentiality level.

[0082] By mapping the security level to a preset protocol, attack information corresponding to the security level is obtained.

[0083] For example, the default protocol is: Security Level (Level 1) – Attack Information (Class A Attack); Security Level (Level 2) - Attack Information (Class B Attack).

[0084] If the security level is 1, it corresponds to a type A attack; if the security level is 2, it corresponds to a type B attack.

[0085] In one possible implementation of this application embodiment, step A015 is followed by steps A016 (not shown in the figure) and A017 (not shown in the figure), wherein... Step A016: After a file retrieval command is detected, verify whether the login information in the file retrieval command is compliant.

[0086] Step A017: If the login information is compliant, control the display of confidential information and generate real-time monitoring instructions.

[0087] Among them, the real-time monitoring command is to control the acquisition equipment to monitor the operators in real time, and the file acquisition command includes login information.

[0088] In this embodiment of the application, the login information in the file retrieval instruction is matched with the standard login information. If the matching degree is greater than the preset matching threshold, the login information is deemed compliant; conversely, if the matching degree is less than or equal to the preset matching threshold, the login information is deemed non-compliant.

[0089] If the login information is deemed compliant, confidential information will be displayed, and the data acquisition device will begin capturing the current image in real time.

[0090] Specifically, the matching method used should be selected based on the actual situation and needs, and the methods include, but are not limited to, facial feature matching, character matching, fingerprint matching, and voiceprint matching. This application's embodiments use facial feature matching as an example for further explanation.

[0091] If the login information is facial features, the image captured by the acquisition device is obtained, the acquired image is preprocessed, and OpenCV (a cross-platform computer vision library, an open-source tool library that can be used for image processing) technology is used to collect facial features from the processed image.

[0092] The DeepFace algorithm (one of the face recognition algorithms) is used to match the collected facial features with the facial features pre-stored in the database. If the matching degree is greater than the standard matching threshold of 85%, the login information is considered compliant; conversely, if the matching degree is less than or equal to the standard matching threshold of 85%, the login information is considered non-compliant.

[0093] In one possible implementation of this application embodiment, step A016 includes steps A018 (not shown in the figure), A019 (not shown in the figure), and A020 ​​(not shown in the figure), wherein, Step A018: If the login information is not compliant, generate and control the display of verification limit attempts.

[0094] The verification limit is the number of remaining verification attempts.

[0095] In this embodiment of the application, the login information in the file acquisition instruction is matched with the preset login information. If the matching degree is less than or equal to the standard matching threshold, the login information is deemed non-compliant, and the remaining verification count is displayed. When the number of times the login information is deemed non-compliant increases (n times), the remaining verification count is reduced accordingly (n times).

[0096] Specifically, the verification limit in this embodiment should be selected according to the actual situation. For example, if the confidentiality level of the information is high, the verification limit is 2 times; if the confidentiality level of the information is low, the verification limit is 3 times. Furthermore, the matching method should correspond to the method actually used in step A017. For example, if step A017 uses facial recognition to determine whether the login information is compliant, then this step should also use facial recognition to determine whether the login information is compliant. The actual process of the matching method in step A017 has been described in detail, and will not be repeated in this embodiment.

[0097] Step A019: Determine whether the verification limit is a preset value. If so, overlay the confidential information according to the preset disguise information.

[0098] In this embodiment of the application, the preset value is 0, and the preset disguise information is a pre-stored non-confidential file.

[0099] If the remaining verification attempts equal a preset value (i.e., 0), the displayed object will be changed to the preset disguised information and its display will be controlled. For example, if the method for determining whether the login information is compliant in step A017 is password authentication, the number of verification attempts is limited to 2, the confidential file is A, and the disguised confidential file is B (i.e., the preset disguised information), then when the pop-up window providing the login password is entered incorrectly 3 times, the pop-up window will automatically close and the interface displaying the disguised confidential file B will be opened.

[0100] Specifically, the methods for overlaying and displaying confidential information include, but are not limited to, one described in the embodiments of this application, and are not limited in this application.

[0101] Step A020: Determine whether the operator has performed a copy operation on the preset disguised information. If so, write the attack information into the preset disguised information to obtain the attack file information, and change the copy operation target to the attack file information.

[0102] In this embodiment of the application, the operator's operation method is obtained. If the operation method includes a copy operation, the attack information is written into the preset disguise information to obtain the attack file, and the copy object is pointed to the attack file.

[0103] Specifically, there are no restrictions on how the attack information is displayed or how it is written to the preset disguise information. For example, the attack information can be displayed as a BMP image file, and the attack information can be bundled with the preset disguise information to obtain attack file information. When the obtained attack file information starts running, the attack information will start running synchronously.

[0104] In one possible implementation of this application embodiment, step A020 ​​is followed by steps A021 (not shown in the figure), A022 (not shown in the figure), and A023 (not shown in the figure), wherein... Step A021: Obtain information on whitelisted personnel and the corresponding personnel identity information.

[0105] Step A022: Generate a dynamic password based on the personnel's identity information and the preset dynamic password rules, and send the dynamic password to the target device.

[0106] The whitelist information consists of personnel who perform compliant operations on confidential information, the target device is the communication device corresponding to the personnel's identity information, and the preset dynamic password rule is a dynamic password generation algorithm.

[0107] In this embodiment of the application, the whitelist personnel information and personnel identity information in the memory are obtained, the text information in the personnel identity information is converted into digital symbols, and the digital symbols are encrypted according to the dynamic password generation algorithm to obtain the dynamic password.

[0108] Based on the personnel's identity information, the corresponding communication device and communication method are obtained, and the dynamic password is sent to the communication device through this communication method.

[0109] Specifically, the personnel identification information may include name, ID number, and gender, and the dynamic password generation algorithm may include: OTP (one-time-password, i.e., a dynamic password algorithm used on a count-by-use basis) and TOTP (Time-based One-time Password algorithm, i.e., a dynamic password algorithm used on a time-by-use basis). Relatedly, dynamic password generation algorithms are already widely available in the current market, and will not be described in detail in the embodiments of this application.

[0110] Step A023: After detecting the account information sent by the target device, verify whether the password in the account information corresponds to the dynamic password. If the verification is successful, the confidential information is overwritten with the disguised information.

[0111] The account information includes the identity information and password of the person on the whitelist, and the target device is the communication device corresponding to the person's identity information. In this embodiment of the application, when the account information sent by the communication device corresponding to the personnel identity information is received, the password in the account information is matched with the dynamic password. If the matching degree is not 1, the verification is deemed to have failed; if the matching degree is 1, the verification is deemed to have succeeded, and the object to be operated on is changed to confidential information.

[0112] In summary, by locating or attacking suspicious individuals in different leakage scenarios, the confidentiality of confidential data has been improved in a targeted manner.

[0113] The above embodiments describe a method for screening multimodal transport schedules from the perspective of process flow. The following embodiments describe a device for screening multimodal transport schedules from the perspective of virtual modules or virtual units. For details, please refer to the following embodiments.

[0114] This application provides a data leakage handling device for multiple application scenarios, such as... Figure 2 As shown, the data leakage processing device 20 for multi-scenario applications may specifically include: an information acquisition module 21, a feature analysis module 22, a spatial reconstruction module 23, a location combination module 24, an image retrieval module 25, a location positioning module 26, and a location fitting module 27, wherein, The information acquisition module 21 is used to acquire recording information, which includes the recording file and the recording time. The feature analysis module 22 is used to perform sound feature analysis on the recording file to obtain information about the meeting participants and the audio channel information in the recording file. The spatial reconstruction module 23 is used to perform three-dimensional spatial reconstruction of the audio channel information to obtain at least one sound scene model, which is used to represent the location of each sound source in the meeting. Location combining module 24 is used to combine at least one sound scene model with meeting personnel information to obtain at least one set of personnel locations; The image retrieval module 25 is used to retrieve meeting images based on the recording time and the meeting participants information to obtain meeting scene images; The location positioning module 26 is used to locate the positions of the people in the meeting scene image to obtain the actual positions of the people. The actual positions of the people are used to represent the actual positions of the meeting participants in the meeting. The position fitting module 27 is used to obtain the eavesdropping position based on the actual position of the personnel and at least one group of personnel positions. The eavesdropping position is used to represent the specific eavesdropping position when eavesdropping on each sound source in the meeting.

[0115] In another possible implementation of this application embodiment, the spatial reconstruction module 23 performs three-dimensional spatial reconstruction of the channel information to obtain at least one sound scene model, specifically used for: Obtain on-site spatial information for the meeting; Input the vocal tract information into a well-trained sound localization algorithm to obtain at least one set of on-site sound source coordinates. The on-site sound source coordinates are used to represent the spatial coordinates of different sound sources within the vocal tract information in the conference. Data analysis of on-site spatial information yields an on-site model, which is then used as a digital model to represent the sound source location. At least one set of on-site sound source coordinates is combined with the on-site model to obtain at least one sound on-site model.

[0116] In another possible implementation of this application embodiment, the location fitting module 27 matches and analyzes the actual location of the personnel with at least one set of personnel locations to obtain the eavesdropping location, specifically used for: Match the actual location of personnel with at least one set of personnel locations to obtain a target site model; The location of the target site model is locked to obtain the eavesdropping location.

[0117] In another possible implementation of this application embodiment, the apparatus 20 further includes: a module for acquiring confidential information and a module for matching attack information, wherein... The confidential information acquisition module is used to acquire confidential information and the corresponding confidentiality level information. The confidential information is used to represent the pre-stored confidential information. The attack information matching module is used to match the preset protocol with the security level information to obtain the attack information corresponding to the security level information. The preset protocol is used to represent the correspondence between the security level information and the attack information, and the attack information is used to represent the information of the target of attacking the illegally leaked confidential information. In another possible implementation of this application embodiment, the apparatus 20 further includes: a verification information module and a compliance operation module, wherein... The verification information module is used to verify whether the login information in the file retrieval instruction is compliant when a file retrieval instruction is detected. The file retrieval instruction is used to indicate the operation instruction of the operator to obtain confidential information. The compliance operation module is used to control the display of confidential information and generate real-time monitoring instructions if the login information is compliant. The real-time monitoring instructions are used to control the data collection device to monitor the operator in real time.

[0118] Another possible implementation of this application embodiment involves a verification information module verifying the compliance of the login information in the file retrieval instruction, specifically used for... If the login information is not compliant, a verification limit will be generated and displayed, and the number of verification limits will be used to indicate the remaining number of verification attempts. Determine if the verification limit is within a preset value; if so, overwrite the confidential information with the preset disguise information. Determine whether the operator has copied the preset disguised information. If so, write the attack information into the preset disguised information to obtain the attack file information, and change the copy operation target to the attack file information.

[0119] In another possible implementation of this application embodiment, the device 20 further includes: a personnel identity acquisition module, a dynamic password generation module, and a dynamic password verification module, wherein... The personnel identification module is used to obtain information on whitelisted personnel and the corresponding personnel identification information. The whitelisted personnel information is used to represent personnel who perform compliant operations on confidential information. The dynamic password generation module is used to generate dynamic passwords based on personnel identity information and preset dynamic password rules, and send the dynamic passwords to the target device, which is a communication device corresponding to the personnel identity information. The dynamic password verification module is used to verify whether the password in the account information sent by the target device corresponds to the dynamic password after the account information is detected. If the verification is successful, the disguised information is overwritten according to the confidential information.

[0120] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0121] This application also describes an electronic device from the perspective of a physical device, such as... Figure 3 As shown, Figure 3 The illustrated electronic device 300 includes a processor 301 and a memory 303. The processor 301 and the memory 303 are connected, for example, via a bus 302. Optionally, the electronic device 300 may also include a transceiver 304. It should be noted that in practical applications, the transceiver 304 is not limited to one type, and the structure of this electronic device 300 does not constitute a limitation on the embodiments of this application.

[0122] Processor 301 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 301 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.

[0123] Bus 302 may include a pathway for transmitting information between the aforementioned components. Bus 302 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. Bus 302 can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in Figure 03, but this does not indicate that there is only one bus or one type of bus.

[0124] The memory 303 may be a ROM (Read Only Memory) or other type of static storage device capable of storing static information and instructions, RAM (Random Access Memory) or other type of dynamic storage device capable of storing information and instructions, or an EEPROM (Electrically Erasable Programmable Read Only Memory), CD-ROM (Compact Disc Read Only Memory) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto.

[0125] The memory 303 is used to store application code that executes the solution of this application, and its execution is controlled by the processor 301. The processor 301 is used to execute the application code stored in the memory 303 to implement the content shown in the foregoing method embodiments.

[0126] Among them, electronic devices include, but are not limited to: mobile terminals such as mobile phones, laptops, digital radio receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), and in-vehicle terminals (such as in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers, and can also be servers, etc. Figure 3 The electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.

[0127] This application provides a computer-readable storage medium storing a computer program that, when run on a computer, enables the computer to execute the corresponding content in the aforementioned method embodiments. In this application embodiment, spatial models (i.e., sound scene models) of meeting participants and the sound environment are obtained by performing voiceprint recognition and spatial reconstruction on the recorded information. The positions of the meeting participants are then located within the sound scene model to obtain their relative positions with respect to the eavesdropping location, i.e., their positions.

[0128] By retrieving the recording time from the audio file and the identified meeting attendees, images of the meeting venue can be obtained. The locations of the attendees in the meeting venue images can then be determined to obtain their relative positions with respect to the meeting venue, i.e., their actual positions.

[0129] By fitting the actual location of personnel to the actual location of the eavesdropping points, the relative location of the eavesdropping points with respect to the meeting venue is obtained, i.e., the specific eavesdropping locations. At this point, the eavesdropping locations within the meeting venue have been determined. Based on these locations, suspected individuals who may have leaked meeting information can be identified, enabling the tracking and locating of the leakers, thereby improving the confidentiality and reliability of meeting data.

[0130] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0131] The above are only some embodiments of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A data leakage handling method for multi-scenario applications, characterized in that, include: The process involves: acquiring recording information, including the recording file and recording time; performing sound feature analysis on the recording file to obtain information about meeting participants and their audio channels; acquiring the actual spatial information of the meeting; inputting the audio channel information into a well-trained sound localization algorithm to obtain at least one set of on-site sound source coordinates, which represent the spatial coordinates of different sound sources within the audio channel information in the meeting; performing data analysis on the on-site spatial information to obtain a field model, which represents a digital model of the sound source location; combining the at least one set of on-site sound source coordinates with the field model to obtain at least one sound scene model; the sound scene model represents the location of each sound source in the meeting; and analyzing the sound features obtained from the sound feature analysis. The meeting attendees' information is marked on the sound scene model, which serves as the coordinates of the attendees on the sound scene model, and the obtained coordinates are identified as the attendees' positions. At least one set of attendees' positions is obtained by combining different sound scene models with the meeting attendees' information. Meeting images are retrieved based on the recording time and the meeting attendees' information to obtain meeting scene images. The attendees' positions are located on the meeting scene images to obtain their actual positions, which represent the actual positions of the meeting attendees within the meeting. The actual positions are matched with the at least one set of attendees' positions to obtain a target scene model. The target scene model is then used to lock positions to obtain eavesdropping locations, which represent the specific eavesdropping locations when eavesdropping on various sound sources within the meeting.

2. The method according to claim 1, characterized in that, The method further includes: acquiring confidential information and confidentiality level information corresponding to the confidential information, wherein the confidential information is used to represent pre-stored confidential information; matching a preset protocol with the confidentiality level information to obtain attack information corresponding to the confidentiality level information, wherein the preset protocol is used to represent the correspondence between the confidentiality level information and the attack information, and the attack information is used to represent information about attacking an object that illegally leaks the confidential information.

3. The method according to claim 2, characterized in that, The system matches a preset protocol with the confidentiality level information to obtain attack information corresponding to the confidentiality level information. The process then includes: upon detecting a file retrieval command, verifying the compliance of the login information in the file retrieval command, which represents an operator's instruction to retrieve the confidential information; if the login information is compliant, controlling the display of the confidential information and generating a real-time monitoring command, which controls the acquisition device to perform real-time monitoring of the operator.

4. The method according to claim 3, characterized in that, The verification of the login information in the file acquisition instruction for compliance includes: if the login information is non-compliant, generating and controlling the display of verification restrictions, with the number of verification restrictions used to represent the remaining number of verification attempts; determining whether the number of verification restrictions is a preset value, and if so, overwriting the confidential information according to preset disguise information; determining whether the operator has performed a copy operation on the preset disguise information, and if so, writing the attack information into the preset disguise information to obtain attack file information, and changing the copy operation object to the attack file information.

5. The method according to claim 4, characterized in that, The process involves determining whether the operator has copied the preset disguised information. If so, the attack information is written into the preset disguised information to obtain attack file information, and the copy operation target is changed to the attack file information. The process further includes: obtaining whitelisted personnel information and corresponding personnel identity information, whereby the whitelisted personnel information represents personnel who perform compliant operations on the confidential information; generating a dynamic password based on the personnel identity information and preset dynamic password rules, and sending the dynamic password to a target device, where the target device is a communication device corresponding to the personnel identity information; upon detecting account information sent by the target device, verifying whether the password in the account information corresponds to the dynamic password; if the verification is successful, then the disguised information is reverse-overwritten based on the confidential information.

6. A data leakage processing device for multi-scenario applications employing the data leakage processing method for multi-scenario applications according to claim 1, characterized in that, include: The information acquisition module is used to acquire recording information, which includes the recording file and the recording time. The system includes a feature analysis module for analyzing the sound features of the recording file to obtain information about the meeting participants and their vocal channels; a spatial reconstruction module for reconstructing the vocal channel information in three dimensions to obtain at least one sound scene model, which represents the location of each sound source in the meeting. Specifically, this involves: acquiring the actual spatial information of the meeting; inputting the vocal channel information into a well-trained sound localization algorithm to obtain at least one set of on-site sound source coordinates, which represent the spatial coordinates of different sound sources within the vocal channel information in the meeting; performing data analysis on the on-site spatial information to obtain an on-site model, which represents a digital model of the sound source scene; and combining the at least one set of on-site sound source coordinates with the on-site model to obtain at least one sound scene model; and a location combination module for combining the at least one sound scene model with the meeting participant information to obtain at least one set of participant locations. The image retrieval module is used to retrieve meeting images based on the recording time and the meeting participants' information to obtain meeting scene images; the location positioning module is used to locate the positions of the participants in the meeting scene images to obtain their actual positions, which represent the actual positions of the meeting participants in the meeting; the location fitting module is used to obtain eavesdropping positions based on the actual positions of the participants and at least one group of participants' positions, which represent the specific eavesdropping positions when eavesdropping on each sound source in the meeting.

7. An electronic device, characterized in that, The electronic device includes: at least one processor; a memory; at least one application, wherein the at least one application is stored in the memory and configured to be executed by the at least one processor, said at least one application being configured to: perform the data leakage handling method for multi-scenario applications as described in any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed in the computer, the computer is instructed to perform the data leakage handling method for multi-scenario applications as described in any one of claims 1 to 5.