A method and system for verifying the consistency of data outbound
Through the data processing side and verification and inspection side consistency verification subsystem jointly reviewed and confirmed the outbound data strategy and verification rules, combined with privacy computing and blockchain technology, the problems of low manual verification efficiency and high information leakage risk in data exit consistency verification are solved, and safe and efficient automated verification is achieved.
Patent Information
- Application Number
- CN202510142597.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-02-10
AI Technical Summary
In the prior art, data exit consistency verification mainly relies on manual verification methods, and there are problems such as low execution efficiency, objectivity of results, and high risk of information leakage during verification.
Design a data exit consistency verification method, and confirm the exit data policy documents and verification rules documents through the data processing side and verification inspection side consistency verification subsystem, use privacy computing technology to perform consistency verification, and realize verification through blockchain technology to ensure the security and automation of the verification process.
It improves the security and work efficiency of data exit consistency verification, ensures the fairness and objectivity of verification activities and legal effectiveness, and protects the legitimate rights and interests of data processors.
Smart Images

Figure CN119603081B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method and system for verifying the consistency of cross-border data, belonging to the technical field of cross-border data verification. Background Art
[0002] At present, the country attaches great importance to the development of the digital economy. Data has become a new production factor, running neck and neck with traditional factors such as land, labor, capital, and technology. Data realizes its value through flow, and data flow is a key factor in promoting the digital economy and digital trade. In the fields of cross-border scientific research, exchanges, trade, etc., cross-border data flow enables enterprises to make full use of global factor resources, generating huge economic value and social benefits. In this process, the country attaches great importance to the security of cross-border data flow, and strictly manages the cross-border flow of relevant data such as personal information and important data, standardizes cross-border data activities, and promotes the convenient, safe, and compliant cross-border circulation of data.
[0003] When a data processor involves the cross-border transfer of important data or personal information data of a certain scenario and scale, it needs to submit a declaration to the Internet Information Department for the negative list of the free trade pilot zone, record the standard contract for the cross-border transfer of personal information, or submit a declaration for cross-border data security assessment. Only after passing can the cross-border data activity be carried out. The declaration materials shall list the field composition of the cross-border data, the data classification and grading results, and the data scale. In the actual work process after the declaration is approved, both the data processor itself and the regulatory department have the need to verify the consistency between the actual cross-border data situation of the data processor and the declaration materials, so as to supervise whether the data processor strictly conducts cross-border data transfer within the declared scope and avoid illegal cross-border data transfer behavior. Therefore, researching and forming a technical solution for verifying the consistency of cross-border data has become an important component to support the development of related work. In this context, when providing cross-border data for consistency verification, data processors generally have problems such as worrying about the leakage of original data and the lack of automated means support in the verification process, which need to be solved urgently.
[0004] At present, the verification of cross-border data consistency mainly relies on the offline verification method by experts. After the data processor submits the declaration materials and obtains approval, a declared cross-border data field table is formed. When the cross-border data activity is carried out, the actual cross-border data content is formed. Then, through the verification and comparison by experts, it is judged whether there is a cross-border data activity beyond the declared scope. This solution relies on manual verification, and there are doubts about its execution efficiency and result objectivity. At the same time, it is difficult to solve problems such as how to provide the original cross-border data to experts for verification and how to ensure that there is no information leakage incident during the verification process. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide a method for verifying the consistency of outbound data. Based on the outbound data policy file and the outbound verification rule file, the method performs data extraction and consistency verification to improve the security of outbound data and the work efficiency of verification.
[0006] The present invention adopts the following technical solutions to solve the above technical problems: The present invention designs a method for verifying the consistency of outbound data. According to the outbound data policy file jointly reviewed and confirmed by the consistency verification subsystem on the data processing side and the consistency verification subsystem on the verification and inspection side, as well as the outbound data declaration materials uploaded by the corresponding data processor and the outbound verification rule file jointly reviewed and confirmed by the consistency verification subsystem on the data processing side and the consistency verification subsystem on the verification and inspection side, for the outbound data sent by the data processor through the outbound data business system, the consistency verification subsystem on the data processing side extracts the content of each target field of the outbound data according to the extraction strategy of each target field in the outbound data policy file, and constructs an audit log and a statistical log; then, the consistency verification subsystem on the verification and inspection side applies privacy computing technology to perform consistency verification on the audit log and the statistical log according to the outbound verification rule file.
[0007] The outbound data policy file jointly reviewed and confirmed by the consistency verification subsystem on the data processing side and the consistency verification subsystem on the verification and inspection side is obtained according to the following steps A1 to A3;
[0008] Step A1. The consistency verification subsystem on the data processing side configures the outbound data policy file according to the outbound data that the data processor is about to send through the outbound data business system, including the outbound data business scenario, the target output location, the extraction strategy of each target field, and the mapping relationship of each preset target field with respect to important data categories, sensitive personal information categories, and non-sensitive personal information categories. Among them, the extraction strategy of each target field includes the extraction location, extraction range, and preset verification rules corresponding to the outbound data for each preset target field, and then proceeds to Step A2;
[0009] Step A2. The consistency verification subsystem on the data processing side sends the outbound data policy file to the consistency verification subsystem on the verification and inspection side. The consistency verification subsystem on the verification and inspection side reviews the outbound data policy file. If the review is confirmed, the review confirmation result is feedback to the consistency verification subsystem on the data processing side, and the consistency verification subsystem on the data processing side signs the outbound data policy file through the digital certificate signature system; if the review is not confirmed, the content in the outbound data policy file that is not confirmed in the review is returned to the consistency verification subsystem on the data processing side, and proceeds to Step A3;
[0010] Step A3. The data processing side consistency verification subsystem reconfigures the content that has not been confirmed in the outbound data policy file according to the outbound data that the data processor is about to send through the data outbound business system, updates the outbound data policy file, and then returns to Step A2.
[0011] For the outbound data sent by the data processor through the data outbound business system, the data processing side consistency verification subsystem extracts the content of each target field of the outbound data according to the extraction policy of each target field in the outbound data policy file, and according to the preset verification rules in the extraction policy of each target field, verifies the content of each extracted target field, discards the content that fails the verification, obtains the content that passes the verification, and then combines the outbound data business scenario, the domestic business system IP address corresponding to the outbound data, the overseas recipient IP address, and the data transmission time to construct an audit log;
[0012] Then, the data processing side consistency verification subsystem constructs a statistical log according to the mapping relationships of each preset target field in the outbound data policy file with respect to important data categories, sensitive personal information categories, and non-sensitive personal information categories, for the content of each target field corresponding to the extracted outbound data, to count the total number of bytes of the content of each target field corresponding to the important data category, and the total number of distinct people involved in the content of each target field corresponding to the sensitive personal information category and the non-sensitive personal information category;
[0013] Finally, output the audit log and the statistical log to the target output location in the outbound data policy file.
[0014] As a preferred technical solution of the present invention: in the said Step A2, the verification check side consistency verification subsystem performs an audit on the outbound data policy file according to the following Steps A2-1 to A2-3;
[0015] Step A2-1. For each target field in the outbound data policy file, determine whether the target field meets the target specification standard, and whether the target field matches its corresponding extraction range and preset verification rules. If both determinations are yes, then enter Step A2-2; if both determinations are no, then the audit of the outbound data policy file is not confirmed, and determine the content that is not confirmed therein;
[0016] Step A2-2. Based on each target field in the outbound data policy file, determine whether the outbound data business scenario in the outbound data policy file is correct. If yes, then enter Step A2-3; otherwise, the audit of the outbound data policy file is not confirmed, and determine the content that is not confirmed therein;
[0017] Step A2-3. Determine whether the storage space of the target output location in the outbound data policy file is greater than the preset storage threshold space, and determine whether the security protection level corresponding to the target output location meets the preset security threshold level. If both determinations are affirmative, the outbound data policy file is audited and confirmed; if both determinations are negative, the outbound data policy file is not audited and confirmed, and the content that is not audited and confirmed is determined.
[0018] As a preferred technical solution of the present invention: The outbound verification rule file corresponding to the outbound data declaration materials uploaded by the data processor and jointly audited and confirmed by the data processing side consistency verification subsystem and the verification and inspection side consistency verification subsystem is obtained according to the following steps B1 to B3;
[0019] Step B1. The verification and inspection side consistency verification subsystem configures the outbound verification rule file according to the outbound data declaration materials uploaded by the data processor, including the outbound data service scenarios corresponding to the outbound data declaration materials, the content of each target field, the total number of bytes of the content of each target field corresponding to the important data categories, the total number of de-duplicated people involved in the content of each target field corresponding to the sensitive personal information category and the non-sensitive personal information category, as well as the corresponding domestic business system IP address, the overseas recipient IP address, and the data transmission time, and then proceeds to Step B2;
[0020] Step B2. The verification and inspection side consistency verification subsystem sends the outbound verification rule file to the data processing side consistency verification subsystem. The data processing side consistency verification subsystem audits whether the outbound verification rule file is consistent with the outbound data declaration materials. If it is, it is audited and confirmed, and the audit confirmation result is fed back to the verification and inspection side consistency verification subsystem. The verification and inspection side consistency verification subsystem signs the outbound verification rule file through the digital certificate signature system; otherwise, the audit is not confirmed, and the content that is not audited and confirmed in the outbound verification rule file is returned to the verification and inspection side consistency verification subsystem, and Step B3 is entered;
[0021] Step B3. The verification and inspection side consistency verification subsystem reconfigures the content that is not audited and confirmed in the outbound verification rule file according to the outbound data declaration materials uploaded by the data processor, updates the outbound verification rule file, and then returns to Step B2.
[0022] As a preferred technical solution of the present invention: The verification and inspection side consistency verification subsystem applies privacy computing technology according to the outbound verification rule file and performs the following steps I to II to conduct consistency verification on the audit log and the statistical log;
[0023] Step I. The consistency verification subsystem on the inspection side, according to the outbound inspection rule file and based on the private set intersection algorithm, compares the content of each target field in the audit log for each outbound data service scenario with the content of the corresponding target field in the outbound inspection rule file for the same outbound data service scenario, and gives a conclusion on whether the content of each target field in the audit log exceeds the outbound data declaration materials. If it exceeds, it is marked as 1; if it does not exceed, it is marked as 0.
[0024] The consistency verification subsystem on the inspection side, according to the outbound inspection rule file and based on the private set intersection algorithm, compares the data outbound communication link formed by the domestic business system IP address and the overseas recipient IP address in the audit log for each outbound data service scenario with the data outbound communication link in the outbound inspection rule file for the corresponding outbound data service scenario, and gives a conclusion on whether the data outbound communication link in the audit log exceeds the outbound data declaration materials. If it exceeds, it is marked as 1; if it does not exceed, it is marked as 0.
[0025] The consistency verification subsystem on the inspection side, according to the outbound inspection rule file and based on the comparison algorithm of privacy computing, determines whether the total number of bytes of the content of each target field corresponding to each important data category in the statistical log for each outbound data service scenario exceeds the total number of bytes of the content of the corresponding target field for each important data category in the outbound inspection rule file for the same outbound data service scenario. If it does, it is marked as 1; otherwise, it is marked as 0.
[0026] The consistency verification subsystem on the inspection side, according to the outbound inspection rule file and based on the comparison algorithm of privacy computing, determines whether the total number of distinct persons involved in the content of each target field corresponding to the sensitive personal information category and the non-sensitive personal information category in the statistical log for each outbound data service scenario exceeds the total number of distinct persons involved in the content of the corresponding target field for the sensitive personal information category and the non-sensitive personal information category in the outbound inspection rule file for the same outbound data service scenario. If it does, it is marked as 1; otherwise, it is marked as 0.
[0027] Then enter Step II.
[0028] Step II. The consistency verification subsystem on the inspection side performs weighted processing on the marked values of each comparison result according to the preset weights corresponding to each comparison in Step I to obtain the outbound violation risk values corresponding to the audit log and the statistical log.
[0029] As a preferred technical solution of the present invention: It also includes applying blockchain technology to perform on-chain evidence storage for the outbound data policy file, the outbound inspection rule file, and the outbound violation risk values corresponding to the audit log and the statistical log.
[0030] Correspondingly, the technical problem to be solved by the present invention is to provide a system for the method of verifying the consistency of outbound data, and a modular design architecture is used to implement the execution of the design method, so as to improve the security of outbound data and the work efficiency of verification.
[0031] The present invention adopts the following technical solutions to solve the above technical problems: The present invention designs a system for the method of verifying the consistency of outbound data, including a consistency verification subsystem on the data processing side, a consistency verification subsystem on the verification and inspection side, and an outbound data service system. The consistency verification subsystem on the data processing side includes an outbound data log extraction module and a privacy computing node. The consistency verification subsystem on the verification and inspection side includes an outbound data verification rule configuration module and a privacy computing node;
[0032] Among them, the outbound data log extraction module in the consistency verification subsystem on the data processing side is used to execute steps A1 and A3 to configure the outbound data policy file, execute the review of the outbound verification rule file in step B2, execute the signature of the outbound data policy file by the digital certificate signature system in step A2, and extract the content of each target field of the outbound data according to the extraction policy of each target field in the outbound data policy file, and construct an audit log and a statistical log;
[0033] The privacy computing node in the consistency verification subsystem on the data processing side is used as the target output position in the outbound data policy file, and is used to receive the audit log and the statistical log;
[0034] The outbound data verification rule configuration module in the consistency verification subsystem on the verification and inspection side is used to execute steps B1 and B3 to configure the outbound verification rule file, execute the review of the outbound data policy file in step A2, and execute the signature of the outbound verification rule file by the digital certificate signature system in step B2;
[0035] The privacy computing node in the consistency verification subsystem on the verification and inspection side is used to receive the signed outbound verification rule file;
[0036] The outbound data service system is used to provide an outbound data sending service to the data processor;
[0037] The consistency verification subsystem on the verification and inspection side applies privacy computing technology to perform consistency verification on the audit log and the statistical log in the privacy computing node of the consistency verification subsystem on the data processing side according to the outbound verification rule file in its privacy computing node.
[0038] As a preferred technical solution of the present invention: It further includes a blockchain system. The data processing side consistency verification subsystem and the verification check side consistency verification subsystem respectively further include a blockchain evidence storage module. Among them, the blockchain evidence storage module in the data processing side consistency verification subsystem is used to receive the outbound data policy file from the outbound data log extraction module, the audit log and the outbound violation risk value corresponding to the statistical log from the corresponding privacy computing node, and forward them to the blockchain system for on-chain evidence storage;
[0039] The blockchain evidence storage module in the verification check side consistency verification subsystem is used to receive the outbound verification rule file from the data outbound verification rule configuration module, the audit log and the outbound violation risk value corresponding to the statistical log from the corresponding privacy computing node, and forward them to the blockchain system for on-chain evidence storage.
[0040] Compared with the prior art by adopting the above technical solution, the data outbound consistency verification method and system of the present invention have the following technical effects:
[0041] The data outbound consistency verification method designed by the present invention, according to the outbound data policy file and the outbound verification rule file confirmed by joint review, the data processing side consistency verification subsystem extracts the content of each target field corresponding to the outbound data according to the outbound data policy file, and constructs the audit log and the statistical log; then the verification check side consistency verification subsystem, according to the outbound verification rule file, applies the privacy computing technology to perform consistency verification on the audit log and the statistical log, and designs the corresponding system, with the data processing side consistency verification subsystem carrying the outbound data log extraction module and the privacy computing node, and the verification check side consistency verification subsystem carrying the data outbound verification rule configuration module and the privacy computing node. Without exposing the original outbound data, the consistency verification between the outbound data and the outbound data declaration materials is realized, the security of the data outbound consistency verification work is improved, and the legitimate rights and interests of data processors are effectively protected;
[0042] The data outbound consistency verification method designed by the present invention proposes an outbound data policy file and verification conditions for realizing the automatic generation of the audit log and the statistical log, as well as proposes the standard format and verification conditions of the outbound verification rule file, and realizes the integrity protection of the policy file and the rule file based on digital signature and blockchain technology, improving the fairness and objectivity of the consistency verification activity, having better legal effect, and using privacy computing technology to realize the verification process, privacy computing task design, and risk score calculation method, ensuring the security of the verification activity. Description of the Drawings
[0043] Figure 1 It is a schematic diagram of the system architecture of the data outbound consistency verification method designed by the present invention;
[0044] Figure 2 It is a flowchart of the method for verifying the consistency of outbound data in the design of the present invention. Specific embodiments
[0045] The following further elaborates on the specific embodiments of the present invention in conjunction with the accompanying drawings of the specification.
[0046] The present invention designs a method and system for verifying the consistency of outbound data, which is used to verify the outbound data behavior of data processors. In actual applications, the designed system includes a consistency verification subsystem on the data processing side, a consistency verification subsystem on the verification and inspection side, an outbound data service system, and a blockchain system. The consistency verification subsystem on the data processing side includes an outbound data log extraction module, a privacy computing node, and a blockchain evidence storage module. The consistency verification subsystem on the verification and inspection side includes an outbound data verification rule configuration module, a privacy computing node, and a blockchain evidence storage module.
[0047] In actual applications, the method for verifying the consistency of outbound data design first performs the following steps A1 to A3 to obtain an outbound data policy file jointly reviewed and confirmed by the consistency verification subsystem on the data processing side and the consistency verification subsystem on the verification and inspection side.
[0048] Step A1. The outbound data log extraction module in the consistency verification subsystem on the data processing side configures the outbound data policy file according to the outbound data that the data processor is about to send through the outbound data service system. The outbound data policy file includes the outbound data service scenario, the target output location, the extraction policies for each target field, and the mapping relationships of each preset target field with respect to important data categories, sensitive personal information categories, and non-sensitive personal information categories. Among them, the extraction policies for each target field include the extraction location, extraction range, and preset verification rules corresponding to the outbound data for each preset target field, and then proceed to step A2.
[0049] In actual applications, for target fields such as the ID number field and the gender field, the preset verification rule corresponding to the ID number field is an 18-digit numerical value, and the preset verification rule corresponding to the gender field is the value range of "male" or "female".
[0050] Step A2. The outbound data log extraction module in the data processing side's consistency verification subsystem sends the outbound data policy file to the data outbound verification rule configuration module in the verification and inspection side's consistency verification subsystem. The data outbound verification rule configuration module audits the outbound data policy file. If the audit is confirmed, the audit confirmation result is fed back to the outbound data log extraction module in the data processing side's consistency verification subsystem, and the outbound data log extraction module signs the outbound data policy file through the digital certificate signature system. If the audit is not confirmed, the unconfirmed content in the outbound data policy file is returned to the outbound data log extraction module in the data processing side's consistency verification subsystem, and Step A3 is entered.
[0051] In the actual application of the above Step A2, the data outbound verification rule configuration module in the verification and inspection side's consistency verification subsystem performs the audit on the outbound data policy file according to the following Steps A2-1 to A2-3.
[0052] Step A2-1. The data outbound verification rule configuration module in the verification and inspection side's consistency verification subsystem respectively determines whether the target fields in the outbound data policy file comply with the target specification standards and whether the target fields match their corresponding extraction ranges and preset verification rules. If both determinations are yes, Step A2-2 is entered. If both determinations are no, the audit of the outbound data policy file is not confirmed, and the unconfirmed content is determined.
[0053] Step A2-2. The data outbound verification rule configuration module in the verification and inspection side's consistency verification subsystem determines whether the outbound data business scenario in the outbound data policy file is correct based on the target fields in the outbound data policy file. If yes, Step A2-3 is entered. Otherwise, the audit of the outbound data policy file is not confirmed, and the unconfirmed content is determined.
[0054] Step A2-3. The data outbound verification rule configuration module in the verification and inspection side's consistency verification subsystem determines whether the storage space of the target output location in the outbound data policy file is greater than the preset storage threshold space and whether the security protection level corresponding to the target output location meets the preset security threshold level. If both determinations are yes, the audit of the outbound data policy file is confirmed, and this security protection level is used to prevent audit logs and statistical logs from being deleted or tampered with. If both determinations are no, the audit of the outbound data policy file is not confirmed, and the unconfirmed content is determined.
[0055] Step A3. The outbound data log extraction module in the data processing side's consistency verification subsystem reconfigures the unconfirmed content in the outbound data policy file according to the outbound data that the data processor is about to send through the data outbound business system, updates the outbound data policy file, and then returns to Step A2.
[0056] The outbound data policy file, which has been jointly reviewed and confirmed by the data processing side consistency verification subsystem and the verification and inspection side consistency verification subsystem and signed by the digital certificate signature system, ensures the integrity and non-repudiation of the outbound data policy file. The outbound data policy file defines a mapping relationship used to convert the outbound data in the data outbound activities carried out by the data processor into audit logs and statistical logs for consistency verification. Therefore, the outbound data policy file determines the key to the accuracy and comprehensiveness of the audit logs and statistical logs.
[0057] At the same time, the following steps B1 to B3 are executed to obtain the outbound verification rule file that corresponds to the outbound data declaration materials uploaded by the corresponding data processor and has been jointly reviewed and confirmed by the data processing side consistency verification subsystem and the verification and inspection side consistency verification subsystem.
[0058] Step B1. The outbound data verification rule configuration module in the verification and inspection side consistency verification subsystem configures the outbound verification rule file according to the outbound data declaration materials uploaded by the data processor, including the outbound data business scenarios corresponding to the outbound data declaration materials, the content of each target field, the total number of bytes of the content of each target field corresponding to the important data categories, the total number of de-duplicated people involved in the content of each target field corresponding to the sensitive personal information category and the non-sensitive personal information category, as well as the domestic business system IP address, the overseas recipient IP address, and the data transmission time corresponding thereto, and then proceeds to Step B2.
[0059] Step B2. The outbound data verification rule configuration module in the verification and inspection side consistency verification subsystem sends the outbound verification rule file to the outbound data log extraction module in the data processing side consistency verification subsystem. The outbound data log extraction module reviews whether the outbound verification rule file is consistent with the outbound data declaration materials. If so, it is reviewed and confirmed, and the review and confirmation result is fed back to the outbound data verification rule configuration module in the verification and inspection side consistency verification subsystem. The outbound data verification rule configuration module signs the outbound verification rule file through the digital certificate signature system and sends it to the privacy computing node in the verification and inspection side consistency verification subsystem; otherwise, if the review is not confirmed, the content in the outbound verification rule file that is not confirmed in the review is returned to the outbound data verification rule configuration module in the verification and inspection side consistency verification subsystem, and Step B3 is entered.
[0060] Step B3. The outbound data verification rule configuration module in the verification and inspection side consistency verification subsystem reconfigures the content in the outbound verification rule file that is not confirmed in the review according to the outbound data declaration materials uploaded by the data processor, updates the outbound verification rule file, and then returns to Step B2.
[0061] The outbound verification rule file, which has been jointly reviewed and confirmed by the data processing side consistency verification subsystem and the verification inspection side consistency verification subsystem and signed by the digital certificate signature system, ensures the integrity and non-repudiation of the outbound verification rule file.
[0062] Then, for the outbound data sent by the data processor through the outbound data business system, the outbound data log extraction module in the data processing side consistency verification subsystem extracts the content of each target field of the outbound data according to the extraction policies of each target field in the outbound data policy file, and verifies the content of each extracted target field according to the preset verification rules in the extraction policies of each target field, discards the content that fails the verification, obtains the content that passes the verification, and then constructs an audit log in combination with the outbound data business scenario, the domestic business system IP address corresponding to the outbound data, the overseas recipient IP address, and the data transmission time.
[0063] Furthermore, the outbound data log extraction module in the data processing side consistency verification subsystem, according to the mapping relationships of each preset target field in the outbound data policy file with respect to important data categories, sensitive personal information categories, and non-sensitive personal information categories, counts the total number of bytes of the content of each target field corresponding to the important data category and the total number of distinct people involved in the content of each target field corresponding to the sensitive personal information category and the non-sensitive personal information category for the content of each target field of the extracted outbound data, and constructs a statistical log.
[0064] The outbound data log extraction module in the data processing side consistency verification subsystem outputs the audit log and the statistical log to the privacy computing node in the data processing side consistency verification subsystem. Generating the audit log and the statistical log based on the outbound data policy file in this way can ensure the integrity and non-repudiation of the logs.
[0065] Finally, the verification inspection side consistency verification subsystem, according to the outbound verification rule file in its privacy computing node, applies privacy computing technology and performs the following steps I to II to conduct consistency verification on the audit log and the statistical log in the privacy computing node of the data processing side consistency verification subsystem.
[0066] Step I. The verification inspection side consistency verification subsystem, according to the outbound verification rule file in its privacy computing node, based on the private set intersection algorithm, compares the content of each target field in the audit log under each outbound data business scenario with the content of each target field in the corresponding outbound data business scenario in the outbound verification rule file, and gives a conclusion on whether the content of each target field in the audit log exceeds the outbound data declaration materials, marked as 1 if it exceeds and 0 if it does not exceed;
[0067] The consistency verification subsystem on the verification check side compares, based on the privacy intersection algorithm, the data outbound communication links formed by the domestic business system IP address and the overseas recipient IP address in each outbound data business scenario in the audit log with the data outbound communication links in the corresponding outbound data business scenario in the outbound verification rule file in its privacy computing node according to the outbound verification rule file in its privacy computing node, and gives a conclusion on whether the data outbound communication link in the audit log exceeds the data outbound declaration materials. If it exceeds, it is marked as 1; if it does not exceed, it is marked as 0.
[0068] The consistency verification subsystem on the verification check side judges, based on the comparison algorithm of privacy computing, whether the total byte count of the content of each target field corresponding to each important data category in each outbound data business scenario in the statistical log exceeds the total byte count of the content of each target field corresponding to each important data category in the corresponding outbound data business scenario in the outbound verification rule file according to the outbound verification rule file in its privacy computing node. If it exceeds, it is marked as 1; otherwise, it is marked as 0.
[0069] The consistency verification subsystem on the verification check side judges, based on the comparison algorithm of privacy computing, whether the total number of de-duplicated people involved in the content of each target field corresponding to the sensitive personal information category and the non-sensitive personal information category in each outbound data business scenario in the statistical log exceeds the total number of de-duplicated people involved in the content of each target field corresponding to the sensitive personal information category and the non-sensitive personal information category in the corresponding outbound data business scenario in the outbound verification rule file according to the outbound verification rule file in its privacy computing node. If it exceeds, it is marked as 1; otherwise, it is marked as 0.
[0070] Then go to step II.
[0071] Step II. The consistency verification subsystem on the verification check side performs weighted processing on the marked values of each comparison result according to the preset weights corresponding to each comparison in step I to obtain the outbound violation risk values corresponding to the audit log and the statistical log.
[0072] In the actual application of the above design solution, the signed outbound data policy file in the outbound data log extraction module in the consistency verification subsystem on the data processing side is simultaneously forwarded by the corresponding blockchain evidence storage module to the blockchain system for on-chain evidence storage, and the outbound violation risk values corresponding to the audit log and the statistical log in the privacy computing node in the consistency verification subsystem on the data processing side are forwarded by the corresponding blockchain evidence storage module to the blockchain system for on-chain evidence storage.
[0073] Meanwhile, the signed outbound verification rule file in the data outbound verification rule configuration module of the consistency verification subsystem on the verification and inspection side is simultaneously forwarded by the corresponding blockchain evidence storage module to the blockchain system for on-chain evidence storage, and the outbound violation risk values corresponding to the audit log and statistical log in the privacy computing node of the consistency verification subsystem on the verification and inspection side are forwarded by the corresponding blockchain evidence storage module to the blockchain system for on-chain evidence storage.
[0074] For the data outbound consistency verification method designed by the above technical solution, according to the outbound data policy file and outbound verification rule file confirmed by joint review, the consistency verification subsystem on the data processing side extracts the content of each target field corresponding to the outbound data according to the outbound data policy file and constructs the audit log and statistical log; then the consistency verification subsystem on the verification and inspection side applies privacy computing technology to conduct consistency verification on the audit log and statistical log according to the outbound verification rule file, and designs the corresponding system, with the consistency verification subsystem on the data processing side equipped with an outbound data log extraction module and a privacy computing node, and the consistency verification subsystem on the verification and inspection side equipped with a data outbound verification rule configuration module and a privacy computing node, to achieve the consistency verification of the outbound data and the outbound data declaration materials without exposing the original outbound data, improve the security of the data outbound consistency verification work, and effectively protect the legitimate rights and interests of data processors.
[0075] Moreover, the present invention proposes an outbound data policy file and audit conditions for automatically generating audit logs and statistical logs, as well as proposes a standard format and audit conditions for the outbound verification rule file, and realizes the integrity protection of the policy file and rule file based on digital signature and blockchain technology, improving the fairness and objectivity of the consistency verification activity, having better legal effect, and applying privacy computing technology to realize the verification process, privacy computing task design, and risk scoring calculation method to ensure the security of the verification activity.
[0076] The embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the present invention is not limited to the above embodiments, and various changes can be made without departing from the gist of the present invention within the knowledge scope of those of ordinary skill in the art.
Claims
1. A method for verifying the consistency of data outbound, characterized in that According to the outbound data policy file jointly reviewed and confirmed by the data processing side consistency verification subsystem and the verification and inspection side consistency verification subsystem, as well as the outbound data declaration materials uploaded by the corresponding data processor, and the outbound verification rule file jointly reviewed and confirmed by the data processing side consistency verification subsystem and the verification and inspection side consistency verification subsystem, for the outbound data sent by the data processor through the data outbound business system, the data processing side consistency verification subsystem extracts the content of each target field of the outbound data according to the extraction strategy of each target field in the outbound data policy file, and constructs an audit log and a statistical log; then, the verification and inspection side consistency verification subsystem applies privacy computing technology to perform consistency verification on the audit log and the statistical log according to the outbound verification rule file; For the outbound data sent by the data processor through the data outbound business system, the data processing side consistency verification subsystem extracts the content of each target field of the outbound data according to the extraction strategy of each target field in the outbound data policy file, and verifies the content of each extracted target field according to the preset verification rules in the extraction strategy of each target field, discards the content that fails the verification, obtains the content that passes the verification, and then constructs the audit log in combination with the outbound data business scenario, the domestic business system IP address corresponding to the outbound data, the overseas recipient IP address, and the data transmission time; Then, the data processing side consistency verification subsystem counts the total number of bytes of the content of each target field corresponding to the important data category and the total number of distinct people involved in the content of each target field corresponding to the sensitive personal information category and the non-sensitive personal information category according to the mapping relationship of each preset target field in the outbound data policy file with respect to the important data category, the sensitive personal information category, and the non-sensitive personal information category, and constructs the statistical log; Finally, the audit log and the statistical log are output to the target output position in the outbound data policy file.
2. The method for verifying the consistency of cross-border data transfer according to claim 1, wherein: The outbound data policy file jointly reviewed and confirmed by the data processing side consistency verification subsystem and the verification and inspection side consistency verification subsystem is obtained according to the following steps A1 to A3; Step A1. The data processing side consistency verification subsystem configures the outbound data policy file according to the outbound data that the data processor is about to send through the data outbound business system, including the outbound data business scenario, the target output position, the extraction strategy of each target field, and the mapping relationship of each preset target field with respect to the important data category, the sensitive personal information category, and the non-sensitive personal information category. Among them, the extraction strategy of each target field includes the extraction position, extraction range, and preset verification rules corresponding to each preset target field for the outbound data, and then proceeds to step A2; Step A2. The data processing side consistency verification subsystem sends the outbound data policy file to the verification and inspection side consistency verification subsystem. The verification and inspection side consistency verification subsystem conducts an audit on the outbound data policy file. If the audit is confirmed, the verification result is fed back to the data processing side consistency verification subsystem, and the data processing side consistency verification subsystem signs the outbound data policy file through the digital certificate signature system. If the audit is not confirmed, the content in the outbound data policy file that is not confirmed in the audit is returned to the data processing side consistency verification subsystem, and step A3 is entered; Step A3. The data processing side consistency verification subsystem reconfigures the content in the outbound data policy file that is not confirmed in the audit according to the outbound data that the data processor is about to send through the data outbound business system, updates the outbound data policy file, and then returns to step A2.
3. The method for verifying the consistency of cross-border data transfer according to claim 2, wherein: In step A2, the verification and inspection side consistency verification subsystem executes the audit on the outbound data policy file according to the following steps A2-1 to A2-3; Step A2-1. For each target field in the outbound data policy file, determine whether the target field conforms to the target specification standard and whether the target field matches its corresponding extraction range and preset verification rules. If both judgments are affirmative, step A2-2 is entered. If both judgments are negative, the outbound data policy file is not confirmed in the audit, and the content that is not confirmed in the audit is determined; Step A2-2. Based on each target field in the outbound data policy file, determine whether the outbound data business scenario in the outbound data policy file is correct. If it is, step A2-3 is entered; otherwise, the outbound data policy file is not confirmed in the audit, and the content that is not confirmed in the audit is determined; Step A2-3. Determine whether the storage space of the target output location in the outbound data policy file is greater than the preset storage threshold space, and determine whether the security protection level corresponding to the target output location meets the preset security threshold level. If both judgments are affirmative, the outbound data policy file is confirmed in the audit. If both judgments are negative, the outbound data policy file is not confirmed in the audit, and the content that is not confirmed in the audit is determined.
4. The method for verifying the consistency of cross-border data transfer according to claim 2, wherein: The outbound verification rule file corresponding to the outbound data declaration materials uploaded by the data processor and jointly verified and confirmed by the data processing side consistency verification subsystem and the verification and inspection side consistency verification subsystem is obtained according to the following steps B1 to B3; Step B1. The verification and inspection side consistency verification subsystem configures the outbound verification rule file according to the outbound data declaration materials uploaded by the data processor, including the outbound data business scenario corresponding to the outbound data declaration materials, the content corresponding to each target field, the total number of bytes of the content of each target field corresponding to the important data category, the total number of people involved in the content of each target field corresponding to the sensitive personal information category and the non-sensitive personal information category after deduplication, and the domestic business system IP address, overseas recipient IP address, and data transmission time corresponding thereto, and then enters step B2; Step B2. The consistency verification subsystem on the verification and inspection side sends the outbound verification rule file to the consistency verification subsystem on the data processing side. The consistency verification subsystem on the data processing side reviews whether the outbound verification rule file is consistent with the outbound data declaration materials. If it is, the review is confirmed, and the review confirmation result is fed back to the consistency verification subsystem on the verification and inspection side. The consistency verification subsystem on the verification and inspection side signs the outbound verification rule file through the digital certificate signature system. Otherwise, if the review is not confirmed, the content in the outbound verification rule file that is not confirmed in the review is returned to the consistency verification subsystem on the verification and inspection side, and Step B3 is entered; Step B3. The consistency verification subsystem on the verification and inspection side reconfigures the content in the outbound verification rule file that is not confirmed in the review according to the outbound data declaration materials uploaded by the data processor, updates the outbound verification rule file, and then returns to Step B2.
5. The method for verifying the consistency of data outbound according to claim 4, wherein: The consistency verification subsystem on the verification and inspection side applies privacy computing technology according to the outbound verification rule file and performs the following Steps I to II to verify the consistency between the audit log and the statistical log; Step I. The consistency verification subsystem on the verification and inspection side compares the content of each target field in each outbound data business scenario in the audit log with the content of each target field in the corresponding outbound data business scenario in the outbound verification rule file based on the privacy intersection algorithm according to the outbound verification rule file, and gives a conclusion on whether the content of each target field in the audit log exceeds the outbound data declaration materials. Exceeding is marked as 1, and not exceeding is marked as 0; The consistency verification subsystem on the verification and inspection side compares the data outbound communication link formed by the domestic business system IP address and the overseas recipient IP address in each outbound data business scenario in the audit log with the data outbound communication link in the corresponding outbound data business scenario in the outbound verification rule file based on the privacy intersection algorithm according to the outbound verification rule file, and gives a conclusion on whether the data outbound communication link in the audit log exceeds the outbound data declaration materials. Exceeding is marked as 1, and not exceeding is marked as 0; The consistency verification subsystem on the verification and inspection side determines whether the total byte count of the content of each target field corresponding to each important data category in each outbound data business scenario in the statistical log exceeds the total byte count of the content of each target field corresponding to each important data category in the corresponding outbound data business scenario in the outbound verification rule file based on the comparison algorithm of privacy computing according to the outbound verification rule file. If it does, it is marked as 1 for exceeding, otherwise it is marked as 0 for not exceeding; The consistency verification subsystem on the verification and inspection side determines, based on the outbound verification rule file and the comparison algorithm of privacy computing, whether the total number of unique people involved in the target field contents of the corresponding sensitive personal information categories and non-sensitive personal information categories in each outbound data service scenario in the statistical log exceeds the total number of unique people involved in the target field contents of the corresponding sensitive personal information categories and non-sensitive personal information categories in the corresponding outbound data service scenario in the outbound verification rule file. If it exceeds, it is marked as 1; otherwise, it is marked as 0. Then, proceed to step II. Step II. The consistency verification subsystem on the verification and inspection side performs weighted processing on the marked values of each comparison result according to the preset weights corresponding to each comparison in step I to obtain the outbound violation risk value corresponding to the audit log and the statistical log.
6. The data outbound consistency verification method according to claim 2, characterized in that: It also includes applying blockchain technology to perform on-chain evidence storage for the outbound data policy file, the outbound verification rule file, and the outbound violation risk value corresponding to the audit log and the statistical log.
7. A system for implementing the method for verifying the consistency of cross-border data as claimed in claim 4 or 5, characterized in that: It includes the data processing side consistency verification subsystem, the verification and inspection side consistency verification subsystem, and the data outbound service system. The data processing side consistency verification subsystem includes an outbound data log extraction module and a privacy computing node. The verification and inspection side consistency verification subsystem includes a data outbound verification rule configuration module and a privacy computing node. Among them, the outbound data log extraction module in the data processing side consistency verification subsystem is used to perform the configuration of the outbound data policy file in steps A1 and A3, the review of the outbound verification rule file in step B2, the signature of the outbound data policy file through the digital certificate signature system in step A2, and extract the contents of each target field of the outbound data according to the target field extraction policy in the outbound data policy file to construct the audit log and the statistical log. The privacy computing node in the data processing side consistency verification subsystem serves as the target output location in the outbound data policy file and is used to receive the audit log and the statistical log. The data outbound verification rule configuration module in the verification and inspection side consistency verification subsystem is used to perform the configuration of the outbound verification rule file in steps B1 and B3, the review of the outbound data policy file in step A2, and the signature of the outbound verification rule file through the digital certificate signature system in step B2. The privacy computing node in the verification and inspection side consistency verification subsystem is used to receive the signed outbound verification rule file. The data outbound service system is used to provide an outbound data sending service to the data processor. The consistency verification subsystem on the verification and inspection side applies privacy computing technology to perform consistency verification on the audit log and the statistical log in the privacy computing node of the data processing side consistency verification subsystem according to the outbound verification rule file in its privacy computing node.
8. The system of a data outbound consistency verification method according to claim 7, characterized in that: It further includes a blockchain system. The data processing side consistency verification subsystem and the verification and inspection side consistency verification subsystem each further include a blockchain evidence storage module. Among them, the blockchain evidence storage module in the data processing side consistency verification subsystem is used to receive the outbound data policy file from the outbound data log extraction module, the audit log and the outbound violation risk value corresponding to the statistical log from the corresponding privacy computing node, and forward them to the blockchain system for on-chain evidence storage. The blockchain evidence storage module in the verification and inspection side consistency verification subsystem is used to receive the outbound verification rule file from the data outbound verification rule configuration module, the audit log and the outbound violation risk value corresponding to the statistical log from the corresponding privacy computing node, and forward them to the blockchain system for on-chain evidence storage.
Citation Information
Patent Citations
Data cross-border compliance evaluation system
CN117271781A
Exit data security management method and device
CN118611894A