A privacy information protection method, device and medium
By targeted encryption processing based on path characteristics and privacy levels for real-time data information in the network environment, the computing burden and resource waste caused by massive data encryption are solved, and efficient privacy information protection is achieved.
Patent Information
- Application Number
- CN202510157779.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-02-13
AI Technical Summary
In the network environment, in the face of the encryption processing of massive data information, the computing burden has been increased and resources has been wasted. How to protect information in a targeted manner to reduce computing burden and resource waste has become a technical problem that needs to be solved urgently.
By obtaining real-time data information, if it contains real-time privacy information, the target path is determined based on the path characteristic information. If there are abnormal nodes in the target path, the privacy level is determined based on the privacy information type, and the level is encrypted to replace the original data input target path.
The protection mechanism is realized only when privacy protection is identified, so as to avoid unnecessary resource waste, and determine whether and how to perform encryption through layer-by-layer detection, reducing computing burden and resource waste.
Smart Images

Figure CN119622821B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a privacy information protection method, device and medium. Background Art
[0002] With the rapid development of the Internet and information technology, especially the widespread penetration of emerging technologies such as the Internet, big data, cloud computing and the Internet of Things in various fields, privacy information protection faces unprecedented severe challenges.
[0003] With the development of technology, encryption algorithms have emerged. The purpose of data protection is achieved by encrypting data. However, in the network environment, facing massive amounts of data information, if all of them are encrypted, it will undoubtedly increase the computing burden and waste a lot of resources. Therefore, how to carry out information protection in a targeted manner to reduce the computing burden of network devices and reduce resource waste has become a technical problem that needs to be solved urgently. Summary of the invention
[0004] In order to solve the above problems, the present application provides a privacy information protection method, device and medium.
[0005] According to one aspect of the present application, a privacy information protection method is provided, which is applied to a network device, and the method includes:
[0006] Get real-time data information;
[0007] If the real-time data information includes real-time privacy information, determining a target path of the real-time data information according to path characteristic information of the real-time data information, wherein the target path includes a plurality of target network nodes;
[0008] If the multiple target network nodes include an abnormal node, determining the real-time privacy level of the real-time data information according to the real-time privacy type of the real-time privacy information;
[0009] The real-time data information is encrypted according to the real-time privacy level of the real-time privacy information to obtain the encrypted real-time encrypted data information, so as to replace the real-time data information with the real-time encrypted data information and put it into the target path.
[0010] According to one aspect of the present application, a network device for privacy information protection is provided, the device further comprising:
[0011] Processor; and
[0012] A memory arranged to store computer executable instructions which, when executed, cause the processor to perform the operations of any of the methods described above.
[0013] According to one aspect of the present application, a computer-readable medium storing instructions is provided, wherein when the instructions are executed, the system performs the operation of any of the methods described above.
[0014] Compared with the prior art, the present application determines the target path of the real-time data information according to the path characteristic information of the real-time data information when the real-time data information includes real-time privacy information; the privacy protection mechanism is triggered only when it is identified that the real-time data information needs to be protected, thereby avoiding unnecessary waste of resources. If the multiple target network nodes of the target path include abnormal nodes, the real-time privacy level of the real-time data information is determined according to the real-time privacy type of the real-time privacy information; in terms of the privacy protection mechanism, it is creatively proposed to pre-detect whether the target path of the real-time data information containing real-time privacy information is safe. If the target path is safe, the real-time data information may not be processed. If there are abnormal nodes in the target path, the real-time privacy level of the real-time data information is determined according to the real-time privacy type of the real-time privacy information. Further, the real-time data information is encrypted according to the real-time privacy level to obtain the encrypted real-time encrypted data information; encryption processing is performed in a targeted manner. By detecting the transmission security level of the real-time data information in the network environment layer by layer, it is determined whether the real-time data information is encrypted, and when encryption processing is required, encryption processing is performed in a targeted manner. The purpose of reducing the computing burden of network devices and reducing resource waste is achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Other features, objects and advantages of the present application will become more apparent by reading the detailed description of non-limiting embodiments made with reference to the following drawings:
[0016] Figure 1 A method flow chart showing a privacy information protection method according to an embodiment of the present application;
[0017] Figure 2 A schematic diagram showing the structure of a network device for protecting privacy information according to an embodiment of the present application;
[0018] Figure 3 An exemplary system is shown that can be used to implement the various embodiments described in this application. DETAILED DESCRIPTION
[0019] The present application is described in further detail below in conjunction with the accompanying drawings.
[0020] In a typical configuration of the present application, the terminal, the device of the service network and the trusted party all include one or more processors (eg, a central processing unit (CPU)), an input / output interface, a network interface and a memory.
[0021] Memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash memory. Memory is an example of a computer-readable medium.
[0022] Computer readable media include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, Phase-Change Memory (PCM), Programmable Random Access Memory (PRAM), Static Random-Access Memory (SRAM), Dynamic Random Access Memory (DRAM), other types of random access memory (RAM), Read-Only Memory (ROM), Electrically-Erasable Programmable Read-Only Memory (EEPROM), Flash memory or other memory technology, Compact Disc Read-Only Memory (CD-ROM), Digital Versatile Disc (DVD) or other optical storage, magnetic cassettes, tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.
[0023] The devices referred to in this application include but are not limited to terminals, network devices, or devices formed by integrating terminals and network devices through a network. The terminal includes but is not limited to any mobile electronic product that can interact with a user (for example, interact with a user through a touchpad), such as a smart phone, a tablet computer, etc. The mobile electronic product can use any operating system, such as an Android operating system, an iOS operating system, etc. Among them, the network device includes an electronic device that can automatically perform numerical calculations and information processing according to pre-set or stored instructions, and its hardware includes but is not limited to a microprocessor, an application specific integrated circuit (ASIC), a programmable logic device (PLD), a field programmable gate array (FPGA), a digital signal processor (DSP), an embedded device, etc. The network device includes but is not limited to a computer, a network host, a single network server, a plurality of network server sets or a cloud composed of multiple servers; here, the cloud is composed of a large number of computers or network servers based on cloud computing (Cloud Computing), wherein cloud computing is a type of distributed computing, a virtual supercomputer composed of a group of loosely coupled computer sets. The network includes but is not limited to the Internet, wide area network, metropolitan area network, local area network, VPN network, wireless self-organizing network (Ad Hoc network), etc. Preferably, the device may also be a program running on the terminal, network device, or a device formed by integrating the terminal and network device, network device, touch terminal, or network device and touch terminal through a network.
[0024] Of course, those skilled in the art should understand that the above-mentioned devices are only examples, and other existing or future devices that are applicable to the present application should also be included in the scope of protection of the present application and are included here by reference.
[0025] In the description of the present application, “plurality” means two or more, unless otherwise clearly and specifically defined.
[0026] Figure 1A method flow chart of a privacy information protection method according to an embodiment of the present application is shown, which is applied to a network device side, and the method includes step S11, step S12, step S13 and step S14. In step S11, the network device obtains real-time data information; in step S12, if the real-time data information includes real-time privacy information, the target path of the real-time data information is determined according to the path characteristic information of the real-time data information, wherein the target path includes multiple target network nodes; in step S13, if the multiple target network nodes include abnormal nodes, the real-time privacy level of the real-time data information is determined according to the real-time privacy type of the real-time privacy information; in step S14, the network device encrypts the real-time data information according to the real-time privacy level of the real-time privacy information to obtain the encrypted real-time encrypted data information, so as to replace the real-time data information with the real-time encrypted data information and put it into the target path.
[0027] Specifically, in step S11, the network device obtains real-time data information. In some embodiments, the real-time data information includes, but is not limited to, data information sent by the corresponding user device to the network device (for example, including but not limited to request information, upload information, etc.), and data information sent by the network device to the corresponding user device (for example, response information, push information, etc.). For example, when the real-time data information includes data information sent by the corresponding user device to the network device, the network device triggers the present solution in response to the real-time data information sent by the corresponding user device, detects whether the real-time data information includes real-time privacy information, and processes based on the present solution. For another example, when the real-time data information includes data information sent by the network device to the corresponding user device, after the network device determines the real-time data information to be sent to the corresponding user device, it detects whether the real-time data information includes real-time privacy information, and processes based on the present solution.
[0028] In step S12, if the real-time data information includes real-time privacy information, the target path of the real-time data information is determined according to the path characteristic information of the real-time data information, wherein the target path includes a plurality of target network nodes. For example, real-time privacy information in the real-time data information is identified. In some embodiments, the privacy information includes but is not limited to name, ID number, bank card number, telephone number, home address, etc. In some embodiments, the privacy number information such as ID number, bank card number, telephone number, etc. can be identified according to the number format. For example, the number standard format of various numbers is pre-set in the network device, and the privacy number information is identified according to the number standard format. For example, the ID number has 18 digits, which include address code, date of birth code, sequence code, and check code in sequence. For the ID number, the number standard format of 18 digits, address code, and date of birth code can be pre-set. If the number of digits of a certain group of digits is 18 digits, and the first 6 digits match a certain address code, and the following 8 digits match the date of birth, then the digital information is determined to be the ID number. In some embodiments, it is possible to determine whether the following 8 digits are consistent with the date of birth based on the current date. For example, if the first 4 digits of the 8 digits are the current year or the year before the current year, and the last 4 digits of the 8 digits are the current date or the date before the current date, it is determined that the following 8 digits are consistent with the date of birth; otherwise, it is determined that the following 8 digits are inconsistent with the date of birth. For another example, the bank card number is usually 16, 18 or 19 digits. The first few digits of the bank card numbers of different banks include the bank identification code of the bank. The network device can pre-set the number of digits and bank identification code of the bank cards of different banks, which is the same or similar to the identification of the above-mentioned ID card number, and identifies whether it is a bank card number based on the number of digits and bank identification code of the bank card numbers of different banks. The identification of numbers such as telephone numbers is the same or similar to the identification process of the above-mentioned ID card number and bank card number, and will not be repeated here. In some embodiments, the identification of a name can be identified by identifying the surname. In some embodiments, the identification of a home address can also be identified based on the address format (for example, province + city + community name + unit number + house number). In some embodiments, if it is detected that the real-time data information includes real-time privacy information, the path characteristic information of the real-time data information is determined. In some embodiments, the path information includes but is not limited to source address information and target address information. For example, the source address and target address of data information A and data information B are the same, and the paths of data information A and data information B in the cloud service environment are usually the same. In some embodiments, based on the network architecture in the cloud service environment, the paths corresponding to different source addresses and target addresses can be preset, so as to determine the target path corresponding to the source address information and target address information based on the source address information and target address information of the real-time data information.In other embodiments, in order to improve the accuracy of path prediction, the target path can also be determined by a path prediction model. For the specific description of this part, please refer to the following corresponding embodiments, which will not be repeated here. In some embodiments, the network nodes include but are not limited to firewalls, switches, application servers, database servers, etc. For example, the network nodes that data information of different path feature information passes through are different.
[0029] In step S13, if multiple target network nodes include abnormal nodes, the real-time privacy level of the real-time data information is determined according to the real-time privacy type of the real-time privacy information. In some embodiments, abnormal nodes include but are not limited to network nodes with vulnerabilities or functional failures. In some embodiments, the network device detects whether there are abnormal nodes among multiple target network nodes. If there are abnormal nodes, the real-time privacy level of the real-time data information is determined according to the real-time privacy type of the real-time privacy information, so as to protect the real-time data information in a timely manner. In some embodiments, privacy types include but are not limited to personal privacy, corporate privacy, departmental privacy, etc. In some embodiments, privacy levels include but are not limited to primary, secondary and other level information. For example, the higher the level, the higher the privacy. In some embodiments, it can be detected whether multiple target network nodes include abnormal nodes based on an abnormal node database. In some embodiments, the real-time privacy type can be determined based on keyword information. For a specific description of this embodiment, please refer to the corresponding specific embodiment below, which will not be repeated here.
[0030] In step S14, the network device encrypts the real-time data information according to the real-time privacy level of the real-time privacy information to obtain the encrypted real-time encrypted data information. For example, data information of different privacy levels are encrypted using different encryption methods so as to perform encryption processing in a targeted manner, while ensuring data security and reducing unnecessary encryption processing, avoiding excessive encryption processing, reducing computing pressure, and saving resources. In some embodiments, the network device determines the target encryption method corresponding to the real-time data information according to the real-time privacy level of the real-time privacy information, wherein there is a mapping relationship between the real-time privacy level and the target encryption method, and the target encryption method includes a symmetric encryption method or an asymmetric encryption method; the target encryption algorithm is obtained according to the purpose type of the real-time data information and the target encryption method, and the real-time data information is encrypted by the target encryption algorithm to obtain the encrypted real-time encrypted data information. For the specific introduction of this part, please refer to the corresponding embodiment below, which will not be repeated here.
[0031] In some embodiments, determining the target path of the real-time data information according to the path characteristic information of the real-time data information includes: extracting features from the metadata of the real-time data information to obtain the path characteristic information of the real-time data information; and outputting the target path of the real-time data information by inputting the path characteristic information into the path prediction model, wherein the path characteristic information includes at least one of the following: source address information; target address information; port number; protocol type; data type. Of course, those skilled in the art will understand that the above path characteristic information is only an example, and other existing or future path characteristic information that may appear is also within the scope of protection of the present application if it is applicable to the present application, and is included here by reference. In some embodiments, the metadata includes path characteristic information such as source address information, target address information, port number, protocol type, data type, etc., and the network device extracts path features from the metadata of the real-time data information to obtain the path characteristic information of the real-time data information. In some embodiments, in order to improve the accuracy of the target path prediction, the target path of the real-time data information is obtained by inputting the path characteristic information into the path prediction model. For the acquisition process of the path prediction model, please refer to the corresponding embodiment below, which will not be repeated here.
[0032] In some embodiments, the path prediction model is trained by the following method: based on a machine learning algorithm, the historical path feature information of multiple historical data information and the historical path training model corresponding to each historical data information are used to obtain the path prediction model. For example, the location information, connection relationship and configuration parameters of all network devices such as routers, switches, firewalls, etc. in the network are collected. The network topology is obtained through a network management protocol (such as SNMP). A large amount of historical data information and the actual path of each historical data information are collected, and the actual path is used as the historical path of the corresponding historical data information. In some embodiments, in order to improve the prediction accuracy of the path prediction model, the historical data information includes but is not limited to data information of different types (for example, Web browsing (HTTP / HTTPS), file transfer (FTP), instant messaging (Volp), video streaming (RTSP), P2P, etc.). For example, specifically, by extracting features from the metadata of each historical data information, the path feature information of each historical data information is obtained, and the machine learning model is trained through a large amount of path feature information and the corresponding historical path to obtain the path prediction model. In some embodiments, the machine learning algorithm includes but is not limited to a neural network.
[0033] In some embodiments, the method further includes step S15 (not shown) before step S12. In step S15, the abnormal node database is queried based on multiple target network nodes to determine whether the target network node exists, wherein the abnormal node database includes multiple network nodes marked as abnormal. In some embodiments, an abnormal node database is pre-established in the network device, and abnormal nodes are recorded in the abnormal node database. In some embodiments, abnormal nodes include but are not limited to vulnerable nodes, functional failure nodes, etc. For example, the network device detects abnormal conditions of each network device in real time, and updates and records the abnormal nodes in the abnormal node database in real time, or deletes the record of the node in the abnormal node database after the abnormal node is restored. In some embodiments, the detection includes but is not limited to vulnerability scanning, Ping test, packet capture test, traffic simulation test, etc. For example, each network device is scanned in real time by a vulnerability scanning tool (such as Burp Suite, Nmap), and when a vulnerability is found, the corresponding network device is marked as abnormal and recorded in the abnormal node database.
[0034] In some embodiments, determining the real-time privacy level of the real-time data information according to the real-time privacy type of the real-time privacy information includes: determining the real-time privacy type of the real-time privacy information contained in the real-time data information according to the metadata of the real-time data information and the real-time privacy information; querying the privacy level that has a mapping relationship with the real-time privacy type from the privacy level database according to the real-time privacy type of the real-time privacy information, and determining the privacy level as the real-time privacy level of the real-time data information, wherein the privacy level database includes multiple privacy levels, and the mapping relationship between each privacy level and one or more privacy types corresponding to the privacy level. In some embodiments, a privacy level database is pre-established in the network device, and the privacy level database records multiple privacy levels and the mapping relationship between the privacy types corresponding to each privacy level, so that based on the real-time privacy type, the real-time privacy level corresponding to the real-time privacy level can be queried from the privacy level database. In some embodiments, the metadata records the source address information, the target address information and other information of the real-time data information. In this embodiment, the real-time privacy type is determined in combination with the metadata, which is more suitable for the scenario of the network cloud environment of this solution.
[0035] In some embodiments, the metadata of the real-time data information includes real-time address information, and the real-time privacy type of the real-time privacy information contained in the real-time data information is determined according to the metadata of the real-time data information and the real-time privacy information, including: querying and obtaining the real-time user information corresponding to the real-time address information from the address database according to the real-time address information, wherein the address database includes multiple address information and user information corresponding to each address information; if the real-time user information belongs to the target department, determining that the real-time privacy type of the real-time privacy information included in the real-time data information includes department privacy information; otherwise, determining the real-time privacy type of the real-time privacy information from the information database according to one or more real-time keywords included in the real-time privacy information, wherein the information database includes multiple privacy types and one or more keywords corresponding to each privacy type. In some embodiments, the real-time address information includes but is not limited to the source address information and the target address information of the real-time data information. In some embodiments, the address information includes but is not limited to the IP address. In some embodiments, an address database is pre-established in the network device, and multiple address information and user information corresponding to each address information are recorded in the address database, so as to query and obtain the real-time user information corresponding to the real-time address information from the address database based on the real-time address information. In some embodiments, the user information includes but is not limited to family, enterprises, institutions, departments, etc. In some embodiments, the target department includes but is not limited to enterprise departments such as enterprise R&D department and enterprise finance department. In some embodiments, one or more target departments are pre-set in the network device. If the real-time user information is determined to be department A through the address database, and department A belongs to the target department, the real-time privacy type of the real-time privacy information included in the real-time data information is directly determined to be department privacy information. If the real-time user information is determined to be department B through the address database, and department B does not belong to the target department, the real-time privacy type needs to be determined based on the real-time privacy information. For example, the information database includes multiple privacy types, and one or more keywords corresponding to each privacy type. For example, the real-time privacy information includes keywords such as name, home address, and telephone number, and in the information database, the privacy type of personal privacy corresponds to a keyword combination of name, home address, and telephone number, then the real-time privacy type of the real-time privacy information is determined to be personal privacy. For another example, the real-time privacy information includes a company name and a bank card number, and in the information database, the privacy type of corporate privacy corresponds to a keyword combination of company name and bank card number, then the real-time privacy type of the real-time privacy information is determined to be corporate privacy.
[0036] In some embodiments, the real-time address information includes real-time source address information or real-time target address information, and the real-time user information corresponding to the real-time address information is queried from the address database according to the real-time address information, including: if the real-time data information includes data information sent from the corresponding user equipment, the real-time address information includes real-time source address information, and the real-time user information corresponding to the real-time source address information is queried from the address database according to the real-time source address information; if the real-time data information includes data information sent to the corresponding user equipment, the real-time address information includes real-time target address information, and the real-time user information corresponding to the real-time target address information is queried from the address database according to the real-time destination address information, wherein the address database includes multiple source address information and user information corresponding to each source address information, and the address database also includes multiple target address information and user information corresponding to each target address information. When the real-time data information is data information sent by the user equipment and received by the network device, the real-time address information includes the real-time source address information. In other words, when the real-time data information is data information sent by the user equipment, the real-time user information corresponding to the real-time source address information is queried from the address database based on the real-time source address information of the real-time data information. When the real-time data information is data information that the network device wants to send to the user device (for example, when the network device obtains data information to be sent to the user device from a database, or generates data information to be sent to the user device), the real-time address information includes real-time target address information. In other words, when the real-time data information is data information that the network device wants to send to the user device, the real-time user information corresponding to the real-time target address information is queried from the address database based on the real-time target address information of the real-time data information.
[0037] In some embodiments, the real-time data information is encrypted according to the real-time privacy level of the real-time privacy information to obtain the encrypted real-time encrypted data information, including: determining the target encryption method corresponding to the real-time data information according to the real-time privacy level of the real-time privacy information, wherein there is a mapping relationship between the real-time privacy level and the target encryption method, and the target encryption method includes a symmetric encryption method or an asymmetric encryption method; obtaining a target encryption algorithm according to the purpose type of the real-time data information and the target encryption method, and encrypting the real-time data information through the target encryption algorithm to obtain the encrypted real-time encrypted data information. In some embodiments, there is a mapping relationship between different privacy levels and the encryption methods corresponding to the privacy levels, so as to determine the target encryption method corresponding to the real-time privacy level based on the real-time privacy level. For example, the privacy level includes level one and level two, wherein the higher the level, the higher the privacy. There is a mapping relationship between the level two privacy level and the asymmetric encryption algorithm, and there is a mapping relationship between the level one privacy level and the symmetric encryption algorithm. In some embodiments, the purpose type includes but is not limited to receiving data (for example, data information received from a user device and sent to a network device, such as request information, upload data, etc.), forwarding data (for example, data sent by a user device to another user device when the network device acts as a transfer station), and sending data (for example, data sent by a network device to a user device, such as push data, response data, etc.). In some embodiments, for receiving data, the network device can identify it through the original address information and the target address information. For example, when the network device receives real-time data information, it checks the source address information and the target address information in the data packet header. If the target address information is an interface address of the network device itself (such as an IP address, a MAC address, etc.), the real-time data information is determined to be received data. For example, when the network device receives an HTTP request from a user device, the target address of the request data packet is the IP address of the server, which can be determined to be received data. In some embodiments, for forwarding data, if the target address information in the data packet header is not the network device itself, and the source address information is other user devices, the real-time data information is determined to be forwarding data. In some embodiments, for sending data, when the source address information is the network device itself and the target address information is other user devices, it can be determined to be sending data. In some embodiments, for received data, both the key of the encryption algorithm and the public key and private key of the asymmetric encryption can be obtained on the network device side. For example, if the purpose type is to receive data and the target encryption method is symmetric encryption, the network device generates a key for the real-time data information based on the symmetric encryption algorithm, uses the key to encrypt the real-time data information, obtains real-time encrypted data information, and includes the key in the key database, as well as the mapping relationship between the key and the identification information of the real-time data information.The real-time encrypted data information is transmitted in a network environment. After being transmitted to the target address (for example, a database in a network device), the key of the real-time data information is obtained based on the identification information of the real-time data information, and the key is used to decrypt the real-time encrypted data information, so as to perform subsequent data processing based on the real-time data information. For another example, if the purpose type is to receive data and the target encryption method is asymmetric encryption, the real-time data information is encrypted using the public key of the network device to obtain the real-time encrypted data information. When the real-time encrypted data information reaches the target address, the corresponding private key is used to decrypt the real-time encrypted data information. For example, if the purpose type is to forward data and the target encryption method is symmetric encryption, the network device encrypts the real-time data information based on the shared key of the user device of the sender and the user device of the receiver, or based on the key exchange protocol, the network device and the user device of the sender and the user device of the receiver exchange some public information in advance, negotiate the same symmetric encryption key based on a mathematical algorithm, and encrypt the real-time data information using the encryption key. For another example, the purpose type includes sending data. If the target encryption method includes symmetric encryption, the network device encrypts the real-time data information based on the shared key of the network device and the user device of the recipient, or based on the key exchange protocol, the network device and the user device of the recipient exchange some public information in advance, negotiate the same symmetric encryption key based on a mathematical algorithm, and use the encryption key to encrypt the real-time data information. For another example, the purpose type includes sending data, and the target encryption method includes asymmetric encryption. The network device can use the public key of the user device of the recipient to encrypt the real-time data information to obtain real-time encrypted data information. In this embodiment, the symmetric key can be stored in the key database, and a mapping relationship between the key and the identification information of the real-time data information is established in the database, or a mapping relationship between the key and the device identification of the user device of the sender and the device identification of the user device of the recipient is established, so that the key can be obtained. In some embodiments, for receiving data, in response to the completion of encryption and decryption of the received data, the corresponding key can be deleted from the key database to release space. In some embodiments, after obtaining the real-time encrypted data information, the real-time encrypted data information is put into the target path. In other words, the real-time encrypted data information is replaced with the real-time data information for transmission in the network environment.
[0038] Figure 2A schematic diagram of the device structure of a network device for privacy protection according to an embodiment of the present application is shown, the device includes module 11, module 12, module 13, and module 14, wherein module 11 is used to obtain real-time data information; module 12 is used to determine the target path of the real-time data information according to the path characteristic information of the real-time data information if the real-time data information includes real-time privacy information, wherein the target path includes multiple target network nodes; module 13 is used to determine the real-time privacy level of the real-time data information according to the real-time privacy type of the real-time privacy information if the multiple target network nodes include abnormal nodes; module 14 is used to encrypt the real-time data information according to the real-time privacy level of the real-time privacy information to obtain encrypted real-time encrypted data information.
[0039] Here, the specific implementations corresponding to module 11, module 12, and module 13 are the same as or similar to the specific implementations of step S11, step S12, and step S13, and are therefore not repeated here and are included herein by reference.
[0040] In addition to the methods and devices described in the above embodiments, the present application also provides a computer-readable storage medium, which stores computer code. When the computer code is executed, the method described in any of the preceding items is executed.
[0041] The present application also provides a computer program product. When the computer program product is executed by a computer device, the method described in any of the preceding items is executed.
[0042] The present application also provides a computer device, the computer device comprising:
[0043] one or more processors;
[0044] a memory for storing one or more computer programs;
[0045] When the one or more computer programs are executed by the one or more processors, the one or more processors are caused to implement the method as described in any of the preceding items.
[0046] Figure 3 An exemplary system that can be used to implement various embodiments described in this application is shown;
[0047] like Figure 3In some embodiments shown, the system 300 can be used as any of the devices in the various described embodiments. In some embodiments, the system 300 may include one or more computer-readable media (e.g., system memory or NVM / storage device 320) with instructions and one or more processors (e.g., (one or more) processors 305) coupled to the one or more computer-readable media and configured to execute instructions to implement modules to perform the actions described in this application.
[0048] For one embodiment, system control module 310 may include any suitable interface controller to provide any suitable interface to at least one of processor(s) 305 and / or any suitable device or component in communication with system control module 310 .
[0049] The system control module 310 may include a memory controller module 330 to provide an interface to the system memory 315. The memory controller module 330 may be a hardware module, a software module, and / or a firmware module.
[0050] The system memory 315 may be used, for example, to load and store data and / or instructions for the system 300. For one embodiment, the system memory 315 may include any suitable volatile memory, such as a suitable DRAM. In some embodiments, the system memory 315 may include double data rate type four synchronous dynamic random access memory (DDR4 SDRAM).
[0051] For one embodiment, system control module 310 may include one or more input / output (I / O) controllers to provide interfaces to NVM / storage device 320 and communication interface(s) 325 .
[0052] For example, NVM / storage device 320 may be used to store data and / or instructions. NVM / storage device 320 may include any suitable non-volatile memory (e.g., flash memory) and / or may include any suitable non-volatile storage device(s) (e.g., one or more hard disk drives (HDDs), one or more compact disk (CD) drives, and / or one or more digital versatile disk (DVD) drives).
[0053] NVM / storage device 320 may include storage resources that are physically part of the device on which system 300 is installed, or it may be accessible to the device without being part of the device. For example, NVM / storage device 320 may be accessed over a network via communication interface(s) 325.
[0054] Communication interface(s) 325 may provide an interface for system 300 to communicate over one or more networks and / or with any other suitable devices. System 300 may wirelessly communicate with one or more components of a wireless network in accordance with any of one or more wireless network standards and / or protocols.
[0055] For one embodiment, at least one of the processor(s) 305 may be packaged together with the logic of one or more controllers of the system control module 310 (e.g., the memory controller module 330). For one embodiment, at least one of the processor(s) 305 may be packaged together with the logic of one or more controllers of the system control module 310 to form a system-in-package (SiP). For one embodiment, at least one of the processor(s) 305 may be integrated on the same die with the logic of one or more controllers of the system control module 310. For one embodiment, at least one of the processor(s) 305 may be integrated on the same die with the logic of one or more controllers of the system control module 310 to form a system on chip (SoC).
[0056] In various embodiments, the system 300 may be, but is not limited to: a server, a workstation, a desktop computing device, or a mobile computing device (e.g., a laptop computing device, a handheld computing device, a tablet computer, a netbook, etc.). In various embodiments, the system 300 may have more or fewer components and / or a different architecture. For example, in some embodiments, the system 300 includes one or more cameras, a keyboard, a liquid crystal display (LCD) screen (including a touch screen display), a non-volatile memory port, multiple antennas, a graphics chip, an application specific integrated circuit (ASIC), and a speaker.
[0057] It should be noted that the present application can be implemented in software and / or a combination of software and hardware, for example, it can be implemented using an application-specific integrated circuit (ASIC), a general-purpose computer or any other similar hardware device. In one embodiment, the software program of the present application can be executed by a processor to implement the steps or functions described above. Similarly, the software program of the present application (including related data structures) can be stored in a computer-readable recording medium, for example, a RAM memory, a magnetic or optical drive or a floppy disk and the like. In addition, some steps or functions of the present application can be implemented using hardware, for example, as a circuit that cooperates with a processor to perform various steps or functions.
[0058] In addition, a part of the present application may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present application through the operation of the computer. Those skilled in the art should understand that the existence of computer program instructions in computer-readable media includes but is not limited to source files, executable files, installation package files, etc., and accordingly, the way in which computer program instructions are executed by a computer includes but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to the computer.
[0059] Communication media include media by which communication signals containing, for example, computer readable instructions, data structures, program modules, or other data are transmitted from one system to another. Communication media may include guided transmission media such as cables and wires (e.g., fiber optic, coaxial, etc.) and wireless (unguided transmission) media that can propagate energy waves, such as acoustic, electromagnetic, RF, microwave, and infrared. Computer readable instructions, data structures, program modules, or other data may be embodied as a modulated data signal in, for example, a wireless medium such as a carrier wave or similar mechanism such as embodied as part of spread spectrum technology. The term "modulated data signal" refers to a signal whose one or more characteristics are changed or set in such a manner as to encode information in the signal. Modulation may be analog, digital, or a hybrid modulation technique.
[0060] By way of example and not limitation, computer-readable storage media may include volatile and nonvolatile, removable and non-removable media implemented in any method or technology for storage of information such as computer-readable instructions, data structures, program modules or other data. For example, computer-readable storage media include, but are not limited to, volatile memory, such as random access memory (RAM, DRAM, SRAM); and non-volatile memory, such as flash memory, various read-only memories (ROM, PROM, EPROM, EEPROM), magnetic and ferromagnetic / ferroelectric memories (MRAM, FeRAM); and magnetic and optical storage devices (hard disks, magnetic tapes, CDs, DVDs); or other media now known or later developed that can store computer-readable information / data for use with a computer system.
[0061] Here, according to an embodiment of the present application, a device is included, which includes a memory for storing computer program instructions and a processor for executing the program instructions, wherein, when the computer program instructions are executed by the processor, the device is triggered to run the methods and / or technical solutions based on the aforementioned multiple embodiments of the present application.
[0062] It is obvious to those skilled in the art that the present application is not limited to the details of the above exemplary embodiments, and that the present application can be implemented in other specific forms without departing from the spirit or essential features of the present application.
Claims
1. A privacy information protection method, characterized in that: Applied to a network device, the method includes: Get real-time data information; If the real-time data information includes real-time privacy information, determining a target path of the real-time data information according to path characteristic information of the real-time data information, wherein the target path includes a plurality of target network nodes; If the multiple target network nodes include an abnormal node, determining the real-time privacy level of the real-time data information according to the real-time privacy type of the real-time privacy information; The real-time data information is encrypted according to the real-time privacy level of the real-time privacy information to obtain encrypted real-time encrypted data information.
2. The method according to claim 1, characterized in that The determining the target path of the real-time data information according to the real-time data information path characteristic information includes: Extracting features from metadata of the real-time data information to obtain path feature information of the real-time data information; The target path of the real-time data information is output by inputting the path characteristic information into a path prediction model, wherein the path characteristic information includes at least one of the following: Source address information; Target address information; Port number; Protocol type; Data type.
3. The method according to claim 2, characterized in that The path prediction model is trained by the following method: Based on a machine learning algorithm, the path prediction model is obtained through historical path feature information of multiple historical data information and a historical path training model corresponding to each historical data information.
4. The method according to claim 1, characterized in that: If the real-time data information includes real-time privacy information, the method further includes: determining the target path of the real-time data information according to the path characteristic information of the real-time data information; The abnormal node database is queried according to the multiple target network nodes to determine whether the target network node exists, wherein the abnormal node database includes multiple network nodes marked as abnormal.
5. The method according to claim 1, characterized in that The determining the real-time privacy level of the real-time data information according to the real-time privacy type of the real-time privacy information includes: Determine the real-time privacy type of the real-time privacy information contained in the real-time data information according to the metadata of the real-time data information and the real-time privacy information; According to the real-time privacy type of the real-time privacy information, a privacy level that has a mapping relationship with the real-time privacy type is queried from a privacy level database, and the privacy level is determined as the real-time privacy level of the real-time data information, wherein the privacy level database includes multiple privacy levels and a mapping relationship between each privacy level and one or more privacy types corresponding to the privacy level.
6. The method according to claim 5, characterized in that The metadata of the real-time data information includes real-time address information, and determining the real-time privacy type of the real-time privacy information contained in the real-time data information according to the metadata of the real-time data information and the real-time privacy information includes: According to the real-time address information, query from an address database to obtain real-time user information corresponding to the real-time address information, wherein the address database includes multiple address information and user information corresponding to each address information; If the real-time user information belongs to the target department, determine that the real-time privacy type of the real-time privacy information included in the real-time data information includes department privacy information; otherwise, determine the real-time privacy type of the real-time privacy information from an information database based on one or more real-time keywords included in the real-time privacy information, wherein the information database includes multiple privacy types and one or more keywords corresponding to each privacy type.
7. The method according to claim 6, characterized in that The real-time address information includes real-time source address information or real-time target address information, and the step of querying and acquiring the real-time user information corresponding to the real-time address information from an address database according to the real-time address information includes: If the real-time data information includes data information received from a corresponding user device, the real-time address information includes real-time source address information, and the real-time user information corresponding to the real-time source address information is queried from the address database according to the real-time source address information; if the real-time data information includes data information sent to a corresponding user device, the real-time address information includes real-time target address information, and the real-time user information corresponding to the real-time target address information is queried from the address database according to the real-time target address information, wherein the address database includes multiple source address information and user information corresponding to each source address information, and the address database also includes multiple target address information and user information corresponding to each target address information.
8. The method according to claim 1, characterized in that The real-time data information is encrypted according to the real-time privacy level of the real-time privacy information to obtain encrypted real-time encrypted data information, including: Determining a target encryption mode corresponding to the real-time data information according to the real-time privacy level of the real-time privacy information, wherein there is a mapping relationship between the real-time privacy level and the target encryption mode, and the target encryption mode includes a symmetric encryption mode or an asymmetric encryption mode; A target encryption algorithm is obtained according to the purpose type of the real-time data information and the target encryption method, and the real-time data information is encrypted by the target encryption algorithm to obtain encrypted real-time encrypted data information, wherein the purpose type includes receiving data, forwarding data, and sending data.
9. A computer device for protecting privacy information, comprising a memory, a processor, and a computer program stored in the memory, characterized in that: The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 8.
10. A computer-readable storage medium having a computer program / instruction stored thereon, characterized in that: When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Behavior prediction system of network attack knowledge graph
CN113691550A
Data transmission method based on privacy computing network, electronic equipment and storage medium
CN115913790A