A cross-border data verification system and method

By setting up a trusted third party in the country, the data subject sends encrypted data security certificates and identity identifications to overseas recipients, and the domestic agents conduct verification, solving the problem of poor security of cross-border data verification and improving the security and accuracy of cross-border data verification.

CN119652674BActive Publication Date: 2025-07-18北京国际大数据交易有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510166646.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-07-18
Estimated Expiration
2045-02-14

AI Technical Summary

Technical Problem

The security of cross-border data verification in the existing technology is poor, mainly because overseas recipients need to verify the identity privacy information based on the domestic data subject, resulting in the risk of leakage of identity privacy information during transmission.

Method used

By setting up a trusted third party in the country, the data subject directly sends data security certificates and identity identification to the overseas recipient, and encrypts the overseas recipient and sends it to the domestic agent. The domestic agent verifies the data stored by the domestic trusted third party to ensure that the verification process is completed within the country.

Benefits of technology

It effectively avoids the risk of leakage of identity privacy information during cross-border transmission, improves the security and accuracy of cross-border data verification, and prevents the risk of forging data proof documents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652674B_ABST
    Figure CN119652674B_ABST
Patent Text Reader

Abstract

The present application provides a cross-border data verification system and method. In this system, it includes a data subject, an overseas recipient, and a domestic agent with a domestic trusted third party. The data subject sends the first data security certification document of the target cross-border data and the data subject identity identifier to the overseas recipient. The overseas recipient performs data encryption processing on the first data security certification document and the data subject identity identifier to obtain a second data security certification document and a cross-border business identifier, and sends at least one of the second data security certification document and the cross-border business identifier to the domestic agent and the data subject. The domestic agent verifies the target cross-border data based on the first data security certification document, the second data security certification document, the data subject identity identifier, and the cross-border business identifier stored by the domestic trusted third party, obtains the target verification result, and sends it to the overseas recipient, thereby achieving the effect of improving the verification security of cross-border data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of cross-border data processing, and in particular to a cross-border data verification system and method. Background Art

[0002] In traditional cross-border data verification solutions, it is often necessary for data recipients outside the country to verify cross-border data to ensure the compliance of cross-border data. However, since the verification of cross-border data by overseas recipients requires the identity privacy information of the data subject (i.e., the cross-border data provider), and the identity privacy information of the data subject is often provided by a specific data source within the country. The data source stores the identity privacy information of multiple different data subjects, so as to uniformly provide a basis for overseas recipients to verify cross-border data. There is a certain risk of data leakage during the data transmission process of these identity privacy information through the data source, resulting in poor security for the verification of cross-border data currently.

[0003] Therefore, how to solve the problem of poor security in verifying cross-border data in related technologies has become a technical problem that needs to be urgently solved by those skilled in the art. Summary of the Invention

[0004] Based on the above problems, in order to improve the security of cross-border data verification, the embodiments of this application provide a cross-border data verification system and method.

[0005] The embodiments of this application disclose the following technical solutions:

[0006] In a first aspect, the embodiments of this application provide a cross-border data verification system, including: a data subject, an overseas recipient, and a domestic agent; the domestic agent includes: a domestic trusted third party;

[0007] The data subject is used to send a first data security certificate file for the target cross-border data and a data subject identity identifier to the overseas recipient; the first data security certificate file is generated by the domestic trusted third party through security verification based on the target cross-border data and the identity data of the data subject;

[0008] The overseas recipient is used to perform data encryption processing on the first data security certificate file and the data subject identity identifier to obtain a second data security certificate file and a cross-border business identifier, and send at least one of the second data security certificate file and the cross-border business identifier to the domestic agent and the data subject;

[0009] The domestic agent is used to perform data verification on the target cross-border data based on the first data security certification file stored in the domestic trusted third party, the second data security certification file, the data subject identity identifier, and the cross-border business identifier, obtain a target verification result, and send the target verification result to the overseas recipient.

[0010] In a possible implementation manner, the domestic agent includes: a domestic data calling module; the domestic data calling module is specifically used for:

[0011] Receive the data subject identity identifier sent by the data subject;

[0012] Perform data encryption processing on the data subject identity identifier to obtain a domestic business identifier;

[0013] Based on the domestic business identifier, call the first data security certification file from the domestic trusted third party.

[0014] In a possible implementation manner, the domestic agent includes: a domestic data processing module; the domestic data processing module is specifically used for:

[0015] Use the same data encryption method as the overseas recipient to perform encryption processing on the first data security certification file to obtain a third data security certification file.

[0016] In a possible implementation manner, the domestic agent includes: a domestic data verification module; the domestic data verification module is specifically used for:

[0017] Perform integrity comparison between the second data security certification file and the third data security certification file to obtain a security certification file comparison result, and perform integrity comparison between the cross-border business identifier and the domestic business identifier to obtain a business identifier comparison result;

[0018] When both the security certification file comparison result and the business identifier comparison result are the same in comparison, determine that the target verification result is verification passed.

[0019] In a possible implementation manner, the data subject includes: a data feedback module; the data feedback module is specifically used for:

[0020] Receive the cross-border business identifier fed back by the overseas recipient;

[0021] According to the cross-border business identifier, send the data subject identity identifier to the domestic agent.

[0022] In a possible implementation, the data subject includes: a data acquisition module, and specifically, the data acquisition module is configured to:

[0023] Send the identity data and the target cross-border data to the domestic trusted third party;

[0024] Obtain the first data security certification document generated by the domestic trusted third party based on the identity data and the target cross-border data; the first data security certification document is used to prove the security and compliance of the target cross-border data.

[0025] In a possible implementation, the domestic trusted third party includes: a security verification module; and specifically, the security verification module is configured to:

[0026] Receive the target cross-border data and the identity data;

[0027] Extract the target cross-border business requirements and cross-border original data from the target cross-border data;

[0028] Conduct a compliance analysis on the target cross-border business requirements and an integrity analysis on the cross-border original data to obtain a cross-border data compliance certificate;

[0029] Conduct a security analysis on the identity data to generate an identity security certification document;

[0030] Determine the cross-border data compliance certificate and the identity security certification document as the first data security certification document.

[0031] In a possible implementation, the domestic data verification module further includes: a mapping establishment unit; and specifically, the mapping establishment unit is configured to:

[0032] Establish a data verification mapping relationship between the target verification result, the second data security certification document, and the cross-border business identifier;

[0033] Send the data verification mapping relationship and the target verification result to the overseas recipient.

[0034] In a second aspect, an embodiment of the present application provides a cross-border data verification method, which is applied to a cross-border data verification system. The cross-border data verification system includes: a data subject, an overseas recipient, and a domestic agent; the domestic agent includes: a domestic trusted third party; the method includes:

[0035] Control the data subject to send the first data security certification document for the target cross-border data and the data subject identity identifier to the overseas recipient; the first data security certification document is generated by the domestic trusted third party through security verification based on the target cross-border data and the identity data of the data subject.

[0036] Control the overseas recipient to perform data encryption processing on the first data security certification document and the data subject identity identifier to obtain a second data security certification document and a cross-border business identifier, and send at least one of the second data security certification document and the cross-border business identifier to the domestic agent and the data subject.

[0037] Control the domestic agent to perform data verification on the target cross-border data based on the first data security certification document, the second data security certification document, the data subject identity identifier, and the cross-border business identifier stored in the domestic trusted third party to obtain a target verification result, and send the target verification result to the overseas recipient.

[0038] In a possible implementation manner, the domestic trusted third party includes: a security verification module; the security verification module is specifically used for:

[0039] Receive the target cross-border data and the identity data.

[0040] Perform security and compliance verification on the target cross-border data and the identity data to generate the first data security certification document.

[0041] Compared with the prior art, the present application has the following beneficial effects: The embodiments of the present application provide a cross-border data verification system and method. In this system, there are a data subject, an overseas recipient, and a domestic agent with a domestic trusted third party inside. Among them, the data subject directly sends the first data security certificate file regarding the target cross-border data and its own data subject identity identifier to the overseas recipient. Among them, the identity identifier regarding identity privacy is provided by the data subject to the overseas recipient by itself without going through a specific data source party, thus avoiding the risk of leakage of identity privacy information at the data source party and ensuring the security of cross-border data verification. However, the security certificate file transmitted by the data subject may also be forged. In order to prove that the cross-border data transmitted by the data subject is real and secure, the overseas recipient needs to perform data encryption processing on the received first data security certificate file and data subject identity identifier, and send the encrypted second data security certificate file and cross-border business identifier to the domestic agent. Subsequently, the domestic agent verifies the target cross-border data according to the first data security certificate file, the second data security certificate file, the data subject identity identifier, and the cross-border business identifier stored in the domestic trusted third party. While preventing the data subject from forging the security certificate file to improve the verification accuracy, the verification process for the target cross-border data is transferred from overseas to the domestic, thus avoiding the risk of data leakage during the transmission of privacy data overseas and effectively improving the security of cross-border data verification. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0043] Figure 1 It is a schematic structural diagram of a cross-border data verification system provided by an embodiment of the present application;

[0044] Figure 2 It is a schematic flowchart of a method for calling domestic data provided by an embodiment of the present application;

[0045] Figure 3 It is a schematic flowchart of a method for verifying domestic data provided by an embodiment of the present application;

[0046] Figure 4 It is a schematic flowchart of a method for verifying cross-border data provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0047] To make the objectives, technical solutions, and advantages of this application clearer and more understandable, the following further elaborates on this application in detail with reference to specific embodiments and the accompanying drawings. It should be noted in particular that the embodiments described in the embodiments of this application are only a part of the embodiments of this application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts belong to the scope of protection of this application.

[0048] It should be noted that unless otherwise defined, the technical terms or scientific terms used in the embodiments of this application should have the ordinary meaning understood by those of ordinary skill in the art to which this application belongs. The "first", "second", and similar terms used in the embodiments of this application do not denote any order, quantity, or importance, but are only used to distinguish different components. Words such as "including" or "comprising" mean that the elements or objects appearing before this word cover the elements or objects listed after this word and their equivalents, without excluding other elements or objects. Words such as "connected" or "linked" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. "Up", "down", "left", "right", etc. are only used to indicate relative position relationships, and when the absolute position of the object being described changes, the relative position relationship may also change accordingly.

[0049] As described above, in traditional cross-border data verification solutions, it is often necessary for data recipients outside the country to verify cross-border data to ensure the compliance of cross-border data. However, since the verification of cross-border data by overseas recipients requires the identity privacy information of the data subject (i.e., the cross-border data provider), and the identity privacy information of the data subject is often provided by a specific data source within the country. The data source stores the identity privacy information of multiple different data subjects to uniformly provide a basis for cross-border data verification for overseas recipients. There is a certain risk of data leakage during the process of data transmission of these identity privacy information through the data source, resulting in poor security for the current verification of cross-border data.

[0050] To solve the above problems, an embodiment of the present application provides a cross-border data verification system and method. In this system, there are a data subject, an overseas recipient, and a domestic agent with a domestic trusted third party. Among them, the data subject directly sends the first data security certification document regarding the target cross-border data and its own data subject identity identifier to the overseas recipient. Among them, the identity identifier regarding identity privacy is provided by the data subject to the overseas recipient by itself, without going through a specific data source party, thus avoiding the risk of leakage of identity privacy information at the data source party and ensuring the security of cross-border data verification. However, the security certification document transmitted by the data subject may also be forged. To prove that the cross-border data transmitted by the data subject is real and secure, the overseas recipient needs to perform data encryption processing on the received first data security certification document and data subject identity identifier, and send the encrypted second data security certification document and cross-border business identifier to the domestic agent. Subsequently, the domestic agent verifies the target cross-border data based on the first data security certification document, the second data security certification document, the data subject identity identifier, and the cross-border business identifier stored in the domestic trusted third party. While preventing the data subject from forging the security certification document to improve the verification accuracy, the verification process for the target cross-border data is transferred from overseas to the domestic, thereby avoiding the risk of data leakage during the transmission of private data overseas and effectively improving the security of cross-border data verification.

[0051] To enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0052] Next, the cross-border data verification system provided by the embodiments of the present application will be introduced with reference to specific embodiment drawings.

[0053] See Figure 1 , Figure 1 which is a schematic structural diagram of a cross-border data verification system provided by an embodiment of the present application. By Figure 1It can be seen that in the cross-border data verification system provided by the embodiments of the present application, there are a data subject, an overseas recipient, and a domestic agent. Among them, the data subject is used to represent the subject that has cross-border business needs and needs to send target cross-border data to the overseas recipient. The domestic agent belongs to a relatively broad category concept, and its core essence lies in acting on behalf of the overseas recipient to verify cross-border data. Therefore, in actual application scenarios, the domestic agent can be a subsidiary of the overseas recipient, or a specialized agency responsible for cross-border data verification, or even a combination of a subsidiary and a verification agency. Its essence is to cooperate together to complete the domestic data verification agency work. The embodiments of the present application will not elaborate on this.

[0054] In the embodiments of the present application, although the domestic agent can be a subsidiary of the overseas recipient or any cross-border data verification agency, etc., in order to prove that the target cross-border data transmitted by the data subject is safe and compliant, a domestic trusted third party must be set up in the domestic agent to serve as the source for proving the security of the target cross-border data.

[0055] The main function of the domestic trusted third party is to provide a trusted source for the data to be exported and ensure the compliance and security of cross-border data. When the data subject needs to send target cross-border data to the overseas recipient to carry out cross-border business, the data acquisition module in the data subject needs to send the target cross-border data and its own identity data to the trusted third party, so that the trusted third party can verify the compliance and security of the target cross-border data, and thus receive the first data security certification document feedback by the trusted third party.

[0056] When the trusted third party receives the target cross-border data and identity data sent by the data subject, the security verification module in the trusted third party extracts the target cross-border business requirements and the original data to be cross-border transmitted from the target cross-border data, and conducts compliance analysis and integrity analysis on them respectively to obtain a cross-border data compliance certification. This cross-border data compliance certification can ensure the compliance of the target cross-border data from two levels: cross-border business requirements and original data.

[0057] Meanwhile, its security verification module verifies whether the identity information of the data subject has been forged through the identity data sent by the other party of the data subject, so as to ensure the security of the cross-border data source and obtain an identity security certificate. In this way, the identity security certificate and the cross-border data compliance certificate can be determined as the first data security certificate, so as to ensure the security of the target cross-border data and improve the verification accuracy of cross-border data through three levels: cross-border business requirements, original data, and identity information. Among them, the first data security certificate can be in various different forms such as a single value, multiple combined values, a single file, and multiple combined files. It can contain all or part of the target cross-border data inside to facilitate the overseas recipient to verify the security of the target cross-border data. The first data security certificate can also be attached with specific electronic signatures, trusted time stamps and other identifiers to ensure the authenticity of the security certificate.

[0058] In addition, during the process of the data subject sending identity data to a trusted third party within the territory, one or more identity identifiers of the data subject are also included in the identity data. The trusted third party within the territory needs to pre-agree with the data subject on the identity identifier of the data subject that needs to be used in the entire cross-border data verification process based on the received identity data, so as to ensure that the outside world can call the security certificate of the data subject through the uniformly agreed identity identifier of the data subject and guarantee traceability.

[0059] The data subject is used to send the first data security certificate for the target cross-border data and the data subject identity identifier to the overseas recipient; the first data security certificate is generated by the trusted third party within the territory through security verification based on the target cross-border data and the identity data of the data subject.

[0060] After the data subject receives the first data security certificate feedback by the trusted third party within the territory, the data subject sends the first data security certificate and its own data subject identity identifier to the overseas recipient to initiate a cross-border business request to the overseas recipient and prove the security of the target cross-border data to the overseas recipient.

[0061] Among them, the data subject identity identifier is only a simple piece of information used to identify the data subject's identity, such as a processed mobile phone number, a specific number, etc. It can be a specific number pre-agreed by the data subject and the overseas recipient. Therefore, the cross-border transmission of the data subject identity identifier will not disclose the identity privacy information of the data subject. At the same time, the first data security certification document is only used to prove the data security of the target cross-border data and does not contain the original data of the target cross-border data. Therefore, the first data security certification document and the data subject identity identifier transmitted by the data subject to the overseas recipient can declare the data subject's cross-border business requirements and the security of the cross-border data to the overseas recipient without disclosing the privacy data during the cross-border transmission process.

[0062] In a possible implementation manner, the data subject can also synchronously send a data processing authorization letter to the overseas recipient to grant the overseas recipient the right to perform encryption and other processing on the received data.

[0063] The overseas recipient is used to perform data encryption processing on the first data security certification document and the data subject identity identifier to obtain a second data security certification document and a cross-border business identifier, and send at least one of the second data security certification document and the cross-border business identifier to the domestic agent and the data subject.

[0064] Although the first data security certification document can prove that the target cross-border data transmitted by the data subject is secure, in actual application scenarios, it is also possible that the data subject forges the first data security certification document. Therefore, in order to confirm the authenticity of the first data security certification document, the overseas recipient needs to feedback the received first data security certification document to the domestic agent, and the agent will verify the authenticity of the first data security certification document, thereby transferring the cross-border data verification work that should have been performed overseas to be performed domestically.

[0065] Among them, in order to prevent information leakage when the first data security certification document is transmitted back to the domestic agent, the overseas recipient needs to perform data encryption processing on the first data security certification document to convert the first data security certification document into an anonymous and data security certification document with verification, that is, the second data security certification document. The second data security certification document after encryption processing cannot be used to uniquely identify and restore the data subject, thereby ensuring the security of cross-border data transmission. At the same time, in order to provide the domestic agent with the required index basis for data verification, the overseas recipient also needs to synchronously encrypt the data subject identity identifier to obtain a cross-border business identifier, and feedback the cross-border business identifier to the domestic agent and the data subject, thereby assigning a specific index label (i.e., the cross-border business identifier) to the target cross-border data and providing an index basis for subsequent data verification.

[0066] When the data feedback module within the data subject receives the cross-border business identifier feedback by the overseas recipient, since the overseas recipient also synchronously feeds back the cross-border business identifier to the domestic agent, the data feedback module can determine the specific domestic agent through the cross-border business identifier, so as to provide its own identity identifier for the domestic agent, facilitating the domestic agent to call the first data security certification document from the domestic trusted third party through the identity identifier.

[0067] In a possible implementation, the encryption method of the overseas recipient for the first data security certification document and the data subject identity identifier can be a hash encryption algorithm, de-identification technology, data desensitization technology, or a combination of various encryption technologies, etc. Taking the hash encryption algorithm as an example, the overseas recipient encrypts the first data security certification document and the data subject identity identifier, converting them into a single hash string to ensure the security of cross-border data transmission.

[0068] In another possible implementation, the overseas recipient can also establish a mapping between the cross-border business identifier and the second data security certification document to facilitate the subsequent development of cross-border data verification work.

[0069] The domestic agent is used to perform data verification on the target cross-border data based on the first data security certification document, the second data security certification document, the data subject identity identifier, and the cross-border business identifier stored in the domestic trusted third party, obtain the target verification result, and send the target verification result to the overseas recipient.

[0070] The domestic agent is used to execute the data verification work for the target cross-border data that should originally be performed by the overseas recipient. Its purpose is to verify the target cross-border data through the second data security certification document, the data subject identity identifier, and the cross-border business identifier. The entire data verification process for the target cross-border data is completed by the domestic data calling module, the domestic data processing module, and the domestic data verification module set by the domestic agent. Next, the functions specifically implemented by the above three modules will be introduced respectively.

[0071] First, the domestic data calling module will be introduced. Specifically, reference can be made to Figure 2 , Figure 2 , which is a schematic flowchart of a domestic data calling method provided by an embodiment of the present application, specifically including the following steps:

[0072] S1011: Receive the data subject identity identifier sent by the data subject;

[0073] S1012: Perform data encryption processing on the data subject identity identifier to obtain a domestic business identifier;

[0074] S1013: Invoke the first data security certification document from the domestic trusted third party based on the domestic service identifier.

[0075] The second data security certification document and the cross-border service identifier fed back by the overseas receiving party to the domestic agent are received by the domestic data invocation module within the domestic agent. As known from the foregoing, when the data subject receives the cross-border service identifier fed back by the overseas receiving party, since the overseas receiving party also feeds back the cross-border service identifier to the domestic agent, the data subject can, through the cross-border service identifier, determine the data to be sent to the domestic agent, and then send the same data subject identity identifier as that sent to the overseas receiving party to the domestic agent, so that the domestic agent can invoke the security certification document based on the identity identifier.

[0076] The data subject identity identifier is a representation of the data subject's identity information. Since, during the generation stage of the first data security certification document, the data subject has transmitted its own identity data to the domestic trusted third party, and the domestic trusted third party has generated the corresponding first data security certification document according to its identity data and the target cross-border data. Therefore, the domestic invocation module can invoke the first data security certification document from the domestic trusted third party through the data subject identity identifier. Since this first data security certification document is stored in the trusted third party, there is no risk of being forged by the data subject, thus ensuring the accuracy of data verification.

[0077] Among them, when invoking the first data security certification document through the data subject identity identifier, in order to prevent the identity identifier from being tampered with by the outside world, it is necessary to perform data encryption processing on the data subject identity identifier sent to the trusted third party. And as known from the foregoing, the overseas receiving party also performs encryption processing on the data subject identity identifier to generate the cross-border service identifier. In order to confirm that the data subject feeds back the same identity identifier to the domestic agent and the overseas receiving party, the domestic invocation module needs to use the same encryption method as the overseas receiving party to perform data encryption processing on the data subject identity identifier to obtain the domestic service identifier, and invoke the first data security certification document based on the domestic identifier, so that the domestic agent and the overseas receiving party adopt the same data processing method for the data security certification document, thereby improving the accuracy of cross-border data verification.

[0078] Next, the domestic data processing module will be introduced. Among them, the domestic data processing module is mainly used to perform the following steps:

[0079] Step 1: Use the same data encryption method as the overseas receiving party to perform encryption processing on the first data security certification document to obtain the third data security certification document.

[0080] Since the second data security certification document is obtained based on the data encryption process of the first data security certification document by the overseas recipient. To ensure the accuracy of cross-border data verification, it is necessary to use the same encryption method as the overseas recipient to perform data encryption processing on the first data security certification document to obtain the third data security certification document. During subsequent cross-border data verification, because the data processing stage of the domestic agent uses the same data processing method as the overseas recipient for both the security certification document and the business identifier, when performing cross-border data verification, the third data security certification document can be directly compared with the second data security certification document for consistency, and the cross-border data can be verified by judging whether the two are the same.

[0081] In addition, except for the first data security certification document, the cross-border business identifier, the second data security certification document, and the generated domestic business identifier received by the overseas data call module will all be sent to the domestic data processing module. After the domestic data processing module generates the third data security certification document, it will send the third data security certification document, the second data security certification document, the cross-border business identifier, and the domestic business identifier to the domestic data verification module to facilitate the domestic data verification module to perform data verification on the target cross-border data.

[0082] Next, the domestic data verification module will be introduced. Specifically, refer to Figure 3 , which is a schematic flowchart of a domestic data verification method provided by an embodiment of this application, and it includes the following steps:

[0083] S2011: Compare the integrity of the second data security certification document with the third data security certification document to obtain a security certification document comparison result, and compare the integrity of the cross-border business identifier with the domestic business identifier to obtain a business identifier comparison result;

[0084] S2012: When both the security certification document comparison result and the business identifier comparison result are the same in comparison, determine that the target verification result is verification passed.

[0085] In the data verification stage for target cross-border data, the domestic data verification module needs to conduct data verification from two aspects: business identification and security certification documents. At the level of security certification documents, since the second data security certification document and the third data security certification document are both obtained through the same data encryption process, if the data subject does not tamper with or forge the first data security certification document during transmission, then the second data security certification document and the third data security certification document will be exactly the same. Therefore, by comparing the consistency of the second data security certification document and the third data security certification document, it can be used as the basis for data verification of the target cross-border data, and the comparison result of the security certification documents can be obtained. If the two are different, it proves that the first data security report has been tampered with during transmission to the overseas recipient, and the corresponding target verification result is determined to be failed.

[0086] Similarly, at the level of business identification, the cross-border business identification is compared with the domestic business identification for consistency to obtain the comparison result of the business identification. Only when the comparison result of the business identification and the comparison result of the security certification documents are exactly the same can it be determined that the target cross-border data has not been tampered with or forged, and the target verification result can be determined to be passed.

[0087] The above is the introduction to the domestic data calling module, domestic data processing module, and domestic data verification module. It should be noted that in actual application scenarios, when there is a third-party cross-border data verification agency or a subsidiary of the overseas recipient, the work content executed by any of the above modules can be implemented by any one of the domestic trusted third party, the overseas recipient's subsidiary, and the third-party cross-border data verification agency. At the same time, the functions of all modules can also be implemented by any one party. When there are multiple institutions or participants for data verification, the data flow is the same as that of the above three modules, and this embodiment does not make any restrictions on this.

[0088] In a possible extreme scenario, the domestic trusted third party can be responsible for all the work content of the domestic data calling module, domestic data processing module, and domestic data verification module, that is, taking the domestic trusted third party as the actual domestic agent. If the domestic trusted third party does not directly face the market, the corresponding authorized party of the domestic trusted third party can execute the corresponding work process.

[0089] In a possible implementation, a mapping establishment unit may also be set in the domestic data verification module. The mapping establishment unit is used to establish a data verification mapping relationship between the target verification result, the second data security certification document, and the cross-border business identifier. When the obtained target verification result is fed back to the overseas recipient, the data verification mapping relationship and the target verification result may be further sent to the overseas recipient together, so that the overseas recipient can confirm the cross-border business involved in the target verification result according to the data verification mapping relationship, improving the processing efficiency of the overseas recipient.

[0090] The embodiments of the present application provide a cross-border data verification system and method. In this system, there are a data subject, an overseas recipient, and a domestic agent with a domestic trusted third party. Among them, the data subject directly sends the first data security certification document regarding the target cross-border data and its own data subject identity identifier to the overseas recipient. Among them, the identity identifier regarding identity privacy is provided by the data subject to the overseas recipient by itself without going through a specific data source party, thus avoiding the risk of leakage of identity privacy information at the data source party and ensuring the security of cross-border data verification. However, the security certification document transmitted by the data subject may also be forged. In order to prove that the cross-border data transmitted by the data subject is true and secure, the overseas recipient needs to perform data encryption processing on the received first data security certification document and data subject identity identifier, and send the encrypted second data security certification document and cross-border business identifier to the domestic agent. Subsequently, the domestic agent verifies the target cross-border data according to the first data security certification document, the second data security certification document, the data subject identity identifier, and the cross-border business identifier stored in the domestic trusted third party. While preventing the data subject from forging the security certification document to improve the verification accuracy, the verification process for the target cross-border data is transferred from overseas to domestic, thus avoiding the risk of data leakage during the transmission of privacy data overseas and effectively improving the security of cross-border data verification.

[0091] Next, a cross-border data verification method provided by the embodiments of the present application will be introduced. The cross-border data verification method described below can be correspondingly referred to the cross-border data verification system described above.

[0092] See Figure 4 , this figure is a schematic flowchart of a cross-border data verification method provided by the embodiments of the present application. This method is applied to a cross-border data verification system, and the cross-border data verification system includes: a data subject, an overseas recipient, and a domestic agent; the domestic agent includes: a domestic trusted third party. This method includes the following steps:

[0093] S101: Control the data subject to send the first data security certification document for the target cross-border data and the data subject identity identifier to the overseas recipient; the first data security certification document is generated by the domestic trusted third party through security verification based on the target cross-border data and the identity data of the data subject.

[0094] S102: Control the overseas recipient to perform data encryption processing on the first data security certification document and the data subject identity identifier to obtain a second data security certification document and a cross-border business identifier, and send at least one of the second data security certification document and the cross-border business identifier to the domestic agent and the data subject.

[0095] S103: Control the domestic agent to perform data verification on the target cross-border data based on the first data security certification document stored in the domestic trusted third party, the second data security certification document, the data subject identity identifier, and the cross-border business identifier to obtain a target verification result, and send the target verification result to the overseas recipient.

[0096] In a possible implementation manner, the domestic trusted third party includes: a security verification module; the security verification module is specifically used for:

[0097] Receive the target cross-border data and the identity data;

[0098] Perform security and compliance verification on the target cross-border data and the identity data to generate the first data security certification document.

[0099] It should be noted that each embodiment in this specification is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the method and system, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiment. The method and system described above are only illustrative. The units described as separate components may or may not be physically separated, and the components indicated as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative work.

[0100] As described above, it is only a specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed in the present application should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A cross-border data verification system, characterized in that, Comprising: A data subject, an overseas recipient, and a domestic agent; The domestic agent includes: a domestic trusted third party; The data subject is used to send a first data security certification document for target cross-border data and a data subject identity identifier to the overseas recipient; the first data security certification document is generated by the domestic trusted third party through security verification based on the target cross-border data and the identity data of the data subject; The overseas recipient is used to perform data encryption processing on the first data security certification document and the data subject identity identifier to obtain a second data security certification document and a cross-border business identifier, and send at least one of the second data security certification document and the cross-border business identifier to the domestic agent and the data subject; The domestic agent is used to perform data verification on the target cross-border data based on the first data security certification document, the second data security certification document, the data subject identity identifier, and the cross-border business identifier stored in the domestic trusted third party to obtain a target verification result, and send the target verification result to the overseas recipient; The domestic trusted third party includes: a security verification module; the security verification module is specifically used for: Receiving the target cross-border data and the identity data; Extracting a target cross-border business requirement and cross-border original data from the target cross-border data; Performing compliance analysis on the target cross-border business requirement and integrity analysis on the cross-border original data to obtain a cross-border data compliance certification; Performing security analysis on the identity data to generate an identity security certification document; Determining the cross-border data compliance certification and the identity security certification document as the first data security certification document.

2. The system according to claim 1, wherein The domestic agent includes: a domestic data invocation module; the domestic data invocation module is specifically used for: Receiving the data subject identity identifier sent by the data subject; Performing data encryption processing on the data subject identity identifier to obtain a domestic business identifier; Invoking the first data security certification document from the domestic trusted third party based on the domestic business identifier.

3. The system according to claim 2, wherein The domestic agent includes: a domestic data processing module; the domestic data processing module is specifically used for: Performing encryption processing on the first data security certification document using the same data encryption method as the overseas recipient to obtain a third data security certification document.

4. The system according to claim 3, wherein The domestic agent includes: a domestic data verification module; the domestic data verification module is specifically used for: Performing integrity comparison between the second data security certification document and the third data security certification document to obtain a security certification document comparison result, and performing integrity comparison between the cross-border business identifier and the domestic business identifier to obtain a business identifier comparison result; When both the security certification document comparison result and the business identifier comparison result are the same in comparison, determining that the target verification result is verification passed.

5. The system according to claim 1, wherein The data subject includes: a data feedback module; the data feedback module is specifically used for: Receiving the cross-border business identifier fed back by the overseas recipient; Send the data subject identity identifier to the domestic agent according to the cross-border business identifier.

6. The system according to claim 1, wherein The data subject includes: a data acquisition module, and the data acquisition module is specifically configured to: Send the identity data and the target cross-border data to the domestic trusted third party. Obtain the first data security certification document generated by the domestic trusted third party based on the identity data and the target cross-border data; the first data security certification document is used to prove the security and compliance of the target cross-border data.

7. The system according to claim 4, wherein The domestic data verification module further includes: a mapping establishment unit; and the mapping establishment unit is specifically configured to: Establish a data verification mapping relationship between the target verification result, the second data security certification document, and the cross-border business identifier. Send the data verification mapping relationship and the target verification result to the overseas recipient.

8. A cross-border data verification method, characterized in that, Applied to a cross-border data verification system, the cross-border data verification system includes: a data subject, an overseas recipient, and a domestic agent; the domestic agent includes: a domestic trusted third party; the method includes: Control the data subject to send the first data security certification document for the target cross-border data and the data subject identity identifier to the overseas recipient; the first data security certification document is generated by the domestic trusted third party through security verification based on the target cross-border data and the identity data of the data subject. Control the overseas recipient to perform data encryption processing on the first data security certification document and the data subject identity identifier to obtain a second data security certification document and a cross-border business identifier, and send at least one of the second data security certification document and the cross-border business identifier to the domestic agent and the data subject. Control the domestic agent to perform data verification on the target cross-border data based on the first data security certification document, the second data security certification document, the data subject identity identifier, and the cross-border business identifier stored in the domestic trusted third party to obtain a target verification result, and send the target verification result to the overseas recipient. The domestic trusted third party includes: a security verification module; and the security verification module is specifically configured to: Receive the target cross-border data and the identity data. Extract the target cross-border business requirements and cross-border original data from the target cross-border data. Perform compliance analysis on the target cross-border business requirements and integrity analysis on the cross-border original data to obtain a cross-border data compliance certification. Perform security analysis on the identity data to generate an identity security certification document. Determine the cross-border data compliance certification and the identity security certification document as the first data security certification document.

9. The method according to claim 8, characterized in that, The domestic trusted third party includes: a security verification module; and the security verification module is specifically configured to: Receive the target cross-border data and the identity data. Perform security and compliance verification on the target cross-border data and the identity data to generate the first data security certification document.

Citation Information

Patent Citations

  • Data cross-border transmission system, method and equipment

    CN119011705A

  • Cross-domain secure interaction method and system, terminal, and storage medium

    WO2023010608A1