Safety supervision method, device and equipment for departure data
By setting up application units, approval units, gateways and supervision units in the data exit system, automatic approval and supervision of outbound data is achieved, and the problems of high cost of data exit assessment and insufficient supervision in the existing technology are solved, and approval efficiency and data security are improved.
Patent Information
- Application Number
- CN202311474193.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-07
- Publication Date
- 2025-05-09
AI Technical Summary
The existing technology has high consultation costs and low efficiency when evaluating data before leaving the country, and cannot effectively regulate the entire transmission process of data outbound, resulting in high compliance pressure, long exit cycle, low efficiency and high cost.
By setting up a data exit application unit, a data exit approval unit, a data exit gateway and a data exit supervision unit, automated approval and supervision of outbound data can be realized. The system extracts the first pending information of outbound data for approval, determines the approval result, and transmits data to the overseas recipient through the data outbound gateway, extracts the second pending information in real time to match the approval result, and determines whether to terminate the data transmission.
It reduces the cost of manual approval, improves the approval efficiency, realizes effective supervision of the outbound data transmission process, reduces the probability of non-compliant data transmission, and ensures data security and compliance with outbound.
Smart Images

Figure CN119962849A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security and protection technology, and in particular to a method, device and equipment for security supervision of outbound data. Background Art
[0002] With the implementation of data outbound security assessment measures and other data outbound regulations, enterprises that provide important data and personal information collected and generated in my country to overseas must conduct security assessments on outbound data. In particular, data processors such as multinational companies and foreign-invested enterprises that are involved in data outbound transmission face tremendous compliance pressure in the process of data outbound transmission. If they are not properly managed, it is likely to hinder the continued operation of their business.
[0003] In the existing technology, before data is exported, enterprises generally choose to consult relevant experts for a comprehensive assessment to ensure that the data can be exported safely and in compliance with regulations. However, this expert assessment method has limitations. On the one hand, it requires a lot of consulting costs and is slow to take effect. On the other hand, this method can only conduct a prior assessment of the data to be exported, and cannot control the entire transmission process of the data export, resulting in weak effective supervision of the data export. If the data to be exported is evaluated regularly, the entire export cycle will be longer, and the efficiency and cost of data export will be low.
[0004] Based on this, this specification provides a method, device and equipment for security supervision of outbound data. Summary of the invention
[0005] This specification provides a method, device and equipment for security supervision of outbound data to partially solve the above-mentioned problems existing in the prior art.
[0006] This manual adopts the following technical solutions:
[0007] This specification provides a method for security supervision of outbound data, the method comprising:
[0008] In response to a data export request from a domestic sender, obtaining export data carried in the data export request;
[0009] extracting first pending review information of the outbound data through a data outbound application unit according to the outbound data, and sending the first pending review information to a data outbound approval unit, wherein the first pending review information at least includes attribute information of the outbound data, contract information of the outbound data, and user information of both the sender and the receiver;
[0010] According to the approval rules in the compliance database preset by the data outbound approval unit, the first information to be reviewed is reviewed and approved, and the approval result is determined and sent to the domestic sender and the data outbound supervision unit;
[0011] receiving, through the data outbound application unit, target data determined by the domestic sender according to the approval result and the outbound data, and sending the target data to the data outbound gateway;
[0012] The data outbound gateway sends the target data to the overseas recipient, extracts the second pending review information of the target data, and sends it to the data outbound supervision unit;
[0013] The data exit supervision unit determines a matching result between the second pending information and the approval result, and determines prompt information to be returned to the data exit gateway according to the matching result;
[0014] The data outbound gateway determines whether to stop sending the target data according to the prompt information.
[0015] Optionally, according to the approval rules in the compliance database preset by the data outbound approval unit, approving the first information to be reviewed and determining the approval result specifically includes:
[0016] The data exit approval unit receives the first information to be reviewed, and determines compliance results corresponding to each item of information in the first information to be reviewed according to approval rules in a preset compliance database;
[0017] The approval result of the first information to be reviewed is determined according to the compliance results respectively corresponding to each item of information in the first information to be reviewed.
[0018] Optionally, receiving, by the data outbound application unit, target data determined by the domestic sender according to the approval result and the outbound data, and sending the target data to a data outbound gateway, specifically includes:
[0019] The data export application unit, in response to the data adjustment request of the domestic sender, obtains the export data adjusted by the domestic sender according to the approval result and the export data;
[0020] The data export application unit updates the first pending review information in response to the data export request re-initiated by the domestic sender, and sends the updated first pending review information to the data export approval unit;
[0021] The data outbound approval unit approves the updated first pending information according to the approval rules in the preset compliance database, updates the approval result of the outbound data, and synchronizes the updated approval result to the domestic sender and the data outbound supervision unit;
[0022] The data outbound application unit responds to the data transfer request initiated by the domestic sender according to the updated approval result, and sends the adjusted outbound data as the target data to the data outbound gateway.
[0023] Optionally, extracting the second pending information of the target data and sending it to a data exit supervision unit specifically includes:
[0024] The data outbound gateway splits the target data according to a preset size to obtain sub-data, and sends each sub-data to the overseas recipient one by one;
[0025] The data exit gateway extracts the second pending review information of each sub-data one by one in the order in which each sub-data is sent to the overseas recipient, and sends the extracted second pending review information to the data exit supervision unit, wherein the second pending review information includes at least one of the attribute information of the exit data, the contract information of the exit data, and the user information of the sender and the receiver.
[0026] Optionally, the data exit supervision unit determines a matching result between the second pending information and the approval result, and determines prompt information to be returned to the data exit gateway according to the matching result, specifically including:
[0027] The data exit supervision unit receives the second information to be reviewed, determines whether each item of information in the second information to be reviewed matches the approval result, and determines for each item of information whether the compliance result of the information matching is compliant;
[0028] If both are true, then the determination is normal and is returned as prompt information to the data outbound gateway;
[0029] If any of them is negative, the abnormality is determined and returned to the data outbound gateway as prompt information.
[0030] Optionally, the data egress gateway determines whether to stop sending the target data according to the prompt information, specifically including:
[0031] The data exit gateway receives the prompt information sent by the data exit supervision unit. When the prompt information is normal, the data exit gateway does not suspend the sending of the target data, and continues to determine whether the next received prompt information is normal. When the prompt information is abnormal, the data exit gateway suspends the sending of the target data and sends the prompt information to the domestic sender.
[0032] This specification provides a security supervision system for outbound data, the system comprising: a data outbound application unit, a data outbound approval unit, a data outbound gateway and a data outbound supervision unit; wherein:
[0033] The data export application unit is configured to respond to a data export request from a domestic sender, obtain the export data carried in the data export request, extract first pending review information of the export data, and send the first pending review information to the data export approval unit;
[0034] The data outbound approval unit is configured to receive the first pending information sent by the data outbound application unit; approve the first pending information according to the approval rules in the preset compliance database and determine the approval result; and send the approval result to the domestic sender and the data outbound supervision unit;
[0035] The data outbound gateway is configured to receive the target data sent by the domestic sender and send the target data to the overseas receiver; extract the second pending review information of the target data and send the second pending review information to the data outbound supervision unit; receive prompt information and determine whether to stop sending the target data according to the prompt information;
[0036] The data outbound supervision unit is configured to receive the approval result sent by the data outbound approval unit and receive the second pending review information sent by the data outbound gateway; determine the matching result between the second pending review information and the approval result, and determine the prompt information based on the matching result and return it to the data outbound gateway.
[0037] This specification provides a security monitoring device for outbound data, specifically including:
[0038] an acquisition module, configured to respond to a data outbound request from a domestic sender and acquire outbound data carried in the data outbound request;
[0039] A first pending review module, configured to extract first pending review information of the outbound data through a data outbound application unit according to the outbound data, and send the first pending review information to a data outbound approval unit, wherein the first pending review information at least includes attribute information of the outbound data, contract information of the outbound data, and user information of both the sender and the receiver;
[0040] An approval module, configured to approve the first information to be approved according to the approval rules in the compliance database preset by the data outbound approval unit, determine the approval result, and send it to the domestic sender and the data outbound supervision unit;
[0041] A sending module, configured to receive, through the data outbound application unit, target data determined by the domestic sender according to the approval result and the outbound data, and send the target data to a data outbound gateway;
[0042] A second pending review module, used for the data exit gateway to send the target data to the overseas recipient, and extract the second pending review information of the target data and send it to the data exit supervision unit;
[0043] a prompt module, used for the data exit supervision unit to determine a matching result between the second pending information and the approval result, and to determine prompt information to be returned to the data exit gateway according to the matching result;
[0044] The terminating module is used for the data outbound gateway to determine whether to suspend sending the target data according to the prompt information.
[0045] The present specification provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements a method for security supervision of outbound data.
[0046] The present specification provides an electronic device, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements a security supervision method for outbound data when executing the program.
[0047] At least one of the above technical solutions adopted in this specification can achieve the following beneficial effects: In a security supervision method for outbound data provided in this specification, the outbound data is extracted through the data outbound application unit to obtain the first pending information, and the data outbound approval unit approves the extracted first pending information, determines the approval result of the outbound data, and sends it to the domestic sender and the data outbound supervision unit. The data outbound application unit obtains the target data determined by the domestic sender, and extracts the second pending information of the target data. The data outbound supervision unit determines the matching result of the second pending information and the approval result, and determines the prompt information corresponding to the target data according to the matching result and returns the prompt information to the data outbound gateway.
[0048] From the above method, it can be seen that by pre-approving the outbound data, the domestic sender is prompted to adjust the outbound data. When the target data sent by the domestic sender is obtained, the second pending information extracted from the target data and the approval result obtained by the pre-approval can be matched to determine whether there is abnormal data. This eliminates the need for manual approval of outbound data, provides automated data supervision and approval services for domestic senders, reduces the probability of domestic senders sending non-compliant data, and realizes effective supervision of the transmission process of outbound data. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] The drawings described herein are used to provide a further understanding of this specification and constitute a part of this specification. The illustrative embodiments and descriptions of this specification are used to explain this specification and do not constitute an improper limitation on this specification. In the drawings:
[0050] Figure 1 A flowchart of a method for security supervision of outbound data provided in this specification;
[0051] Figure 2 This is a schematic diagram of the data export application unit provided in this specification;
[0052] Figure 3 This is a schematic diagram of the interaction between the data outbound application unit, data outbound approval unit, data outbound gateway, and data outbound supervision unit provided in this specification;
[0053] Figure 4 A schematic diagram of a security monitoring device for outbound data provided in this manual;
[0054] Figure 5 A schematic diagram of the structure of an electronic device corresponding to a method for implementing security supervision of outbound data provided in this specification. DETAILED DESCRIPTION
[0055] In order to make the purpose, technical solutions and advantages of this specification more clear, the technical solutions of this specification will be clearly and completely described below in combination with the specific embodiments of this specification and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of this specification, not all of them. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this specification.
[0056] At present, before data is exported, enterprises generally choose to consult relevant experts for a comprehensive assessment to ensure that the data can be exported safely and in compliance with regulations. However, this expert assessment method requires a lot of consulting costs and is slow to take effect. On the other hand, it can only conduct a pre-evaluation of the data to be exported, and cannot effectively supervise the transmission process of the data to be exported. If the data to be exported is evaluated regularly, the entire export cycle will be long, the efficiency of data export will be low, and the cost will be high.
[0057] Based on this, this specification provides a method for security supervision of outbound data. In the technical solution provided in this specification, a data outbound application unit, a data outbound approval unit, a data outbound gateway and a data outbound supervision unit are set up to achieve security assessment of outbound data and effective supervision of the transmission process of outbound data. That is, the first pending information of the outbound data can be extracted through the set data outbound application unit, and the first pending information can be approved by the data outbound approval unit to determine the approval result corresponding to the outbound data. After that, the target data determined by the domestic sender based on the approval result and the outbound data is sent to the overseas receiver through the data outbound gateway, and the second pending information is extracted from the target data. The data outbound supervision unit can determine whether there is an abnormality in the transmission process of the target data based on the approval result and the second pending information, and determine the corresponding prompt information and send it to the data outbound gateway. The data outbound gateway can prompt information to determine whether to terminate the transmission of the target data, thereby achieving effective supervision of the transmission process of the target data.
[0058] The technical solutions provided by the embodiments of this specification are described in detail below in conjunction with the accompanying drawings.
[0059] Figure 1 The following is a flowchart of a method for security supervision of outbound data provided in this specification, including the following steps:
[0060] S100: In response to a data outbound request from a domestic sender, obtain outbound data carried in the data outbound request.
[0061] In one or more embodiments of this specification, it is not limited to which device is used to implement the process of the security supervision method for outbound data, such as a personal computer, a mobile terminal, and a server. However, since the subsequent steps involve operations such as data processing, and such operations with high requirements for computing resources are generally performed by a server, this specification will also be described later by taking the server executing a security supervision method for outbound data as an example. Among them, the server can be a single device, or composed of multiple devices, such as a distributed server, and this specification does not limit this.
[0062] As mentioned above, this specification provides a method for the security supervision of outbound data. By deploying a data outbound application unit, a data outbound approval unit, a data outbound gateway, and a data outbound supervision unit, the first pending information of the attribute information, contract information, and user information of both the sender and the receiver of the outbound data is automatically extracted, and the first pending information is approved, and the target data is supervised through the approval result. Therefore, when a domestic sender needs to send data abroad, the data outbound application unit in the server can receive the data outbound request of the domestic sender, and obtain the outbound data carried by the data outbound request according to the data outbound request.
[0063] Specifically, through the data export application unit set up by the server, the domestic sender can upload the export data and initiate a data export request to the data export application unit. The data export application unit can obtain the export data uploaded by the domestic sender through the data export request.
[0064] Data acquisition supports multiple methods, such as file import, application programming interface input, file transfer protocol access, hypertext transfer protocol access, etc., which are not limited in this specification.
[0065] It should be noted that, in addition to the relevant data sent to the overseas recipient, the outbound data should also include the attribute information of the outbound data, the contract information of the outbound data, and the user information of the sender and receiver. The attribute information should include the purpose of the data outbound, the type of data involved, and the amount of data. The contract information should at least clearly state the basic information of the domestic sender and the overseas sender (for example, name, address, contact information), the data protection and security measures that the sender and receiver can take (for example, security measures taken during data transmission, storage, and processing, as well as prevention and response measures for risks such as data leakage and damage), and the term or termination conditions for data outbound. The overseas recipient needs to provide its user information (for example, identity information, letter of responsibility for the authenticity of the information, etc.) to the domestic sender, and the domestic sender will then incorporate the user information into the outbound data.
[0066] S102: extracting first pending information of the outbound data through a data outbound application unit according to the outbound data, and sending the first pending information to a data outbound approval unit, wherein the first pending information at least includes attribute information of the outbound data, contract information of the outbound data, and user information of both the sender and the receiver.
[0067] In one or more embodiments of the present specification, as described above, after the outbound data is obtained, it is necessary to review and approve the outbound data. However, the amount of outbound data is often large, which results in a long transmission time. Also, because not all the data in the outbound data need to be reviewed and approved, the server can automatically extract various information that needs to be reviewed through the data outbound application unit, and send the various information as the first information to be reviewed to the data outbound review unit. In the subsequent steps, the data outbound review unit can review and approve the first information to be reviewed and determine the review result.
[0068] Specifically, the data export application unit extracts the outbound data obtained in step S100, extracts various information that needs to be approved as the first pending information, and sends the first pending information to the data export approval unit. The first pending information includes at least the attribute information of the outbound data, the contract information of the outbound data, and the user information of the sender and receiver. The attribute information and contract information have been summarized in step S100, and this specification will not be repeated here.
[0069] S104: According to the approval rules in the compliance database preset by the data outbound approval unit, the first information to be reviewed is reviewed, and the approval result is determined and sent to the domestic sender and the data outbound supervision unit.
[0070] In one or more embodiments of this specification, it is mentioned in step S102 that not all data in the outbound data need to be approved, and various information that needs to be approved can be extracted and approved. Therefore, this step needs to approve the extracted first information to be approved and determine the approval result. This is used to effectively supervise the transmission process of the outbound data according to the determined approval result in the subsequent steps.
[0071] Specifically, the data exit approval unit set by the server receives the first pending information extracted by the data exit application unit. The data exit approval unit can approve each item of the first pending information according to the approval rules in the preset compliance database, determine whether each item of information is compliant, and determine the compliance results corresponding to each item of information. According to the compliance results of each item of information, the approval result of the first pending information is determined.
[0072] Among them, the approval of the first pending information mainly includes: when it is detected that the data contains personal information, the authorization document for the export of the personal information is detected, whether the attribute information of the export data complies with the approval rules for export, and whether the information in the contract information complies with the approval rules. For example, if personal information is detected, but the authorization document for the personal information is not detected, then the information does not comply with the approval rules. For example, if the data type of the data and the security measures for the data type in the contract information are detected, but the security measures do not comply with the constraint scope of the security measures for the data type in the approval rules, then the data type and the security measures do not comply with the approval rules. For example, the approval rules prohibit the export of chip manufacturing data. Then, when the data type in the attribute information of the export data includes chip manufacturing, the non-compliance and the approval rule will be regarded as the compliance result of the information.
[0073] Therefore, the approval of the first pending information depends on the set approval rules and the scope of the preset compliance database. The larger the preset compliance database and the more detailed the approval rules, the larger the detection scope and the more detailed the approval of the first pending information. This specification does not limit this and can be set according to actual needs.
[0074] S106: receiving, through the data outbound application unit, target data determined by the domestic sender according to the approval result and the outbound data, and sending the target data to the data outbound gateway.
[0075] In one or more embodiments of this specification, in step S104, it is mentioned that the approval result is sent to the domestic sender, then the domestic sender can adjust the outbound data (i.e., add, correct, delete, etc. the outbound data) according to the approval result on the data outbound application unit. And the domestic sender re-initiates the data outbound request and re-approves the adjusted outbound data. Or the domestic sender initiates a data transfer request, and the data outbound application unit can send the determined outbound data as the target data to the data outbound gateway.
[0076] Specifically, through the interactive interface set by the server, the domestic sender can view the approval results of the outbound data, determine the target data to be sent to the overseas recipient, and initiate a data transfer request. In response to the data transfer request initiated by the domestic sender, the data outbound application unit can send the determined target data to the data outbound gateway.
[0077] Optionally, through the interactive interface set by the server, the domestic sender can view the approval results of the outbound data, and by initiating a data adjustment request, the domestic sender can adjust the outbound data. And re-initiate the data outbound request, extract the adjusted outbound data through the data outbound application unit, and send the extracted information as the updated first pending information to the data outbound approval unit. The data outbound approval unit can re-approve the adjusted outbound data, update the approval results, and synchronize the updated approval results to the domestic sender and the data outbound supervision unit.
[0078] The domestic sender receives the updated approval result, determines the target data that can be sent to the overseas recipient, and initiates a data transfer request to the data exit application unit. When the data exit application unit detects the data transfer request initiated by the domestic sender, it can send the adjusted exit data as the target data to the data exit supervision unit.
[0079] It should be noted that the data exit application unit can respond to data exit requests, data adjustment requests and data transfer requests initiated by the domestic sender. When the data exit request is initiated by the domestic sender, the data exit application unit can extract the first pending information of the current outbound data and send it to the data exit approval unit. When the data adjustment request is initiated by the domestic sender, the data exit application unit provides the corresponding adjustment operation page to the domestic sender so that it can adjust the current outbound data. When the data transfer request is initiated by the domestic sender, the data exit application unit can send the current outbound data as the target data to the data exit gateway. Therefore, extraction and sending to the data exit approval unit, adjustment of the outbound data and sending to the data exit gateway depend on the type of request initiated by the domestic sender. Of course, the domestic sender can also re-upload the outbound data and re-upload it as new outbound data, which is not limited in this manual.
[0080] like Figure 2 As shown, the data outbound application unit can respond to a data outbound request or a data adjustment request initiated by a domestic sender to perform data transmission with the data outbound approval unit, and respond to a data transfer request to perform data transmission with the data outbound gateway.
[0081] Among them, the domestic sender can make multiple adjustments to the outbound data. For example, when the domestic sender receives the updated approval result, it can also make a second adjustment to the adjusted outbound data according to the approval result, and send the adjusted outbound data to the data outbound approval unit. The data outbound approval unit can approve the adjusted outbound data again, update the approval result again, and send it to the domestic sender and the data outbound supervision unit again. Until the domestic sender initiates a data transfer request according to the approval result sent by the data outbound approval unit. When the data outbound application unit receives the data transfer request from the domestic sender, it sends the outbound data adjusted multiple times as the target data to the data outbound gateway.
[0082] S108: The data outbound gateway sends the target data to an overseas recipient, extracts second pending review information of the target data, and sends the second pending review information to the data outbound supervision unit.
[0083] In one or more embodiments of this specification, it is mentioned in step S106 that when the domestic sender initiates a data transfer request, the target data will be sent to the data outbound gateway. Since the compliance results of various information have been clearly stated in the approval results received by the domestic sender, the domestic sender may directly send the adjusted but not re-approved outbound data or the unadjusted outbound data as the target data directly to the data outbound gateway. Therefore, in this step, the second pending information of the target data can be extracted through the data outbound gateway, which is used for real-time and effective supervision of the outbound transmission process of the target data to ensure the security and compliance of the target data outbound.
[0084] Specifically, the data exit gateway sends the target data to the overseas recipient, and can extract the second pending review information of the target data and send it to the data exit supervision unit.
[0085] Among them, the data outbound gateway will continue to extract various information of the target data during the process of transmitting the target data to the overseas recipient. That is, if it extracts an information that needs to be approved, it will be sent to the data outbound supervision unit as the second pending information.
[0086] Optionally, the data outbound gateway splits the target data according to a preset size to obtain each sub-data, and sends each sub-data to the overseas recipient one by one. The data outbound gateway extracts the second pending information of each sub-data one by one in the order in which each sub-data is sent to the overseas recipient, and sends the second pending information of the extracted sub-data to the data outbound supervision unit, wherein the second pending information includes at least one of the attribute information of the outbound data, the contract information of the outbound data, and the user information of the sender and the receiver. The preset size can be set according to actual needs, and this manual does not limit this.
[0087] Among them, the target data contains a large amount of data. When the target data is sent to an overseas recipient in the form of a data stream, the second pending information contained in the data stream can be extracted in real time (in the process of continuous transmission of the target data in the form of a data stream, the second pending information of the sub-data of a preset size to be sent is extracted). That is, the target data is split into multiple sub-data according to the preset size, and the order of sending each sub-data to the overseas recipient is determined. According to the sending order, the second pending information of each sub-data is extracted one by one, and the second pending information of the extracted single sub-data is sent to the data exit supervision unit (when the second pending information has been extracted, the extracted second pending information is sent to the data exit supervision unit).
[0088] It should be noted that in the subsequent steps, it takes time for the data outbound supervision unit to determine the prompt information of the target data and return it to the data outbound gateway. Therefore, there may be a situation where the data outbound gateway receives an abnormal prompt information but has already sent it. Therefore, before the data outbound gateway sends the target data, it can pre-process the target data to be sent. After the pre-processed target data, the overseas recipient needs to receive all the data before the target data actually sent can be obtained. Of course, it can also be sent to the overseas recipient by adjusting the preset size of the sub-data or delaying the sending of the target data (or each sub-data), which is not limited in this manual.
[0089] S110: The data exit supervision unit determines a matching result between the second pending information and the approval result, and determines prompt information to be returned to the data exit gateway according to the matching result.
[0090] In one or more embodiments of the present specification, as described above, in order to effectively supervise the transmission process of the target data and prevent the transmission of data that has not been approved and whose compliance results do not meet the approval rules to the overseas recipient, in this step, the matching result of the second pending information and the approval result can be determined, and prompt information can be determined based on the matching result, so that the data outbound gateway can determine whether to terminate the transmission based on the prompt information in the subsequent steps.
[0091] Specifically, the data exit supervision unit is set to determine whether each item of information in the second pending information matches the approval result based on the received second pending information. If it matches, it is also necessary to determine whether the compliance result matching each item of information is compliant. If it does not match or matches but is not compliant, then the abnormal information and the abnormality are returned as prompt information to the data exit gateway. On the contrary, if it matches and is compliant, then the normality is returned as prompt information to the data exit gateway.
[0092] It should be noted that the data outbound supervision unit needs to supervise the target data to be sent according to the approval results. When unapproved outbound data is transmitted through the data outbound gateway, the data outbound supervision unit cannot retrieve the approval results of the outbound data, and the outbound data is not within the supervision scope of the data outbound supervision unit, and an abnormal prompt message will be returned to the data outbound gateway.
[0093] S112: The data outbound gateway determines whether to stop sending the target data according to the prompt information.
[0094] In one or more embodiments of the present specification, the data egress gateway may determine whether to stop sending the target data according to the prompt information determined in step S110.
[0095] Specifically, the data outbound gateway will determine whether the prompt information corresponding to the target data is normal. If it is normal, the data outbound gateway will not stop sending the target data, and will continue to determine whether the next received prompt information is normal. If the prompt information is abnormal, the data outbound gateway will stop the transmission process of the target data and send the prompt information to the domestic sender.
[0096] It should be noted that the prompt information can be sent together with the abnormal information to the domestic sender to inform the domestic sender that the outbound data transmitted to the overseas recipient contains non-compliant data, so that the domestic sender can understand the transmission status of the outbound data.
[0097] In the above-mentioned security supervision method for outbound data, by setting up a data outbound application unit, a data outbound approval unit, a data outbound gateway and a data outbound supervision unit, the approval of the first pending review information of the extracted outbound data is realized, the labor cost required for the approval is reduced, and the approval efficiency is improved. At the same time, through the approval results and the second pending review information, it is avoided that the domestic sender sends unnecessary data and non-compliant data to the overseas receiver, and the effective supervision of the transmission process of the target data is realized, so that the target data can be safely and compliantly outbound.
[0098] like Figure 3 As shown, Figure 3 The schematic diagram is a diagram showing the approval of outbound data and the effective supervision of the transmission process of target data through the data outbound application unit, data outbound approval unit, data outbound gateway and data outbound supervision unit.
[0099] The above is a security supervision method for outbound data provided by one or more embodiments of this specification. Based on the same idea, this specification also provides a corresponding security supervision device for outbound data, such as Figure 4 shown.
[0100] An acquisition module 500, in response to a data outbound request from a domestic sender, acquires outbound data carried in the data outbound request;
[0101] The first pending review module 501 extracts first pending review information of the outbound data through the data outbound application unit according to the outbound data, and sends the first pending review information to the data outbound approval unit, wherein the first pending review information at least includes attribute information of the outbound data, contract information of the outbound data, and user information of both the sender and the receiver;
[0102] An approval module 502, which approves the first pending information according to the approval rules in the compliance database preset by the data outbound approval unit, determines the approval result, and sends it to the domestic sender and the data outbound supervision unit;
[0103] The sending module 503 receives the target data determined by the domestic sender according to the approval result and the outbound data through the data outbound application unit, and sends the target data to the data outbound gateway;
[0104] The second pending review module 504, the data outbound gateway sends the target data to the overseas recipient, extracts the second pending review information of the target data, and sends it to the data outbound supervision unit;
[0105] Prompt module 505, the data exit supervision unit determines the matching result between the second pending information and the approval result, and determines prompt information to be returned to the data exit gateway according to the matching result;
[0106] The termination module 506, the data outbound gateway determines whether to terminate the sending of the target data according to the prompt information.
[0107] Optionally, the approval module 502 is specifically used for the data outbound approval unit to receive the first information to be reviewed, and determine the compliance results corresponding to each item of information in the first information to be reviewed according to the approval rules in a preset compliance database, and determine the approval result of the first information to be reviewed according to the compliance results corresponding to each item of information in the first information to be reviewed.
[0108] Optionally, the sending module 503 is specifically configured for the data exit application unit to respond to the data adjustment request of the domestic sender, obtain the outbound data adjusted by the domestic sender according to the approval result and the outbound data, the data exit application unit to respond to the data exit request re-initiated by the domestic sender, update the first pending review information, and send the updated first pending review information to the data exit approval unit, the data exit approval unit to approve the updated first pending review information according to the approval rules in the preset compliance database, and update the approval result of the outbound data, and synchronize the updated approval result to the domestic sender and the data exit supervision unit, the data exit application unit to respond to the data transfer request initiated by the domestic sender according to the updated approval result, send the adjusted outbound data as target data to the data exit gateway.
[0109] Optionally, the prompt module 505 is specifically used for the data exit supervision unit to receive the second information to be reviewed, determine whether each item of information in the second information to be reviewed matches the approval result, and determine for each item of information whether the compliance result of the information match is compliant. If both are true, it is determined to be normal and returned to the data exit gateway as prompt information; if not, it is determined to be abnormal and returned to the data exit gateway as prompt information.
[0110] Optionally, the termination module 506 is specifically used for the data exit gateway to receive the prompt information sent by the data exit supervision unit. When the prompt information is normal, the data exit gateway does not terminate the sending of the target data, and continues to determine whether the next received prompt information is normal. When the prompt information is abnormal, the data exit gateway terminates the sending of the target data and sends the prompt information to the domestic sender.
[0111] This specification also provides a computer-readable storage medium, which stores a computer program, which can be used to execute the above Figure 1 A security supervision method for outbound data is provided.
[0112] This manual also provides Figure 5 The schematic structure diagram of the electronic device shown in FIG. Figure 5 As shown, at the hardware level, the electronic device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and may also include other hardware required for the business. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to achieve the above Figure 1Of course, in addition to the software implementation, this specification does not exclude other implementations, such as logic devices or a combination of software and hardware, etc., that is, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.
[0113] In the 1990s, improvements to a technology could be clearly distinguished as hardware improvements (for example, improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the method flow). However, with the development of technology, many improvements to the method flow today can be regarded as direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that an improvement in a method flow cannot be implemented using a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to ask a chip manufacturer to design and produce a dedicated integrated circuit chip. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when developing and writing programs, and the original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also know that it is only necessary to program the method flow slightly in the above-mentioned hardware description languages and program it into the integrated circuit, and then it is easy to obtain the hardware circuit that implements the logic method flow.
[0114] The controller can be implemented in any appropriate manner, for example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (such as software or firmware) that can be executed by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in a purely computer-readable program code manner, the controller can be implemented in the form of a logic gate, a switch, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, this controller can be considered as a hardware component, and the devices included therein for implementing various functions can also be regarded as structures within the hardware component. Or even, the devices for implementing various functions can be regarded as both software modules for implementing the method and structures within the hardware component.
[0115] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0116] For the convenience of description, the above device is described in various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0117] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0118] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0119] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0120] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0121] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0122] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0123] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0124] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0125] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0126] This specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0127] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0128] The above description is only an embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the scope of the claims of the present invention.
Claims
1. A security supervision method for outbound data, characterized in that: include: In response to a data export request from a domestic sender, obtaining export data carried in the data export request; extracting first pending review information of the outbound data through a data outbound application unit according to the outbound data, and sending the first pending review information to a data outbound approval unit, wherein the first pending review information at least includes attribute information of the outbound data, contract information of the outbound data, and user information of both the sender and the receiver; According to the approval rules in the compliance database preset by the data outbound approval unit, the first information to be reviewed is reviewed and approved, and the approval result is determined and sent to the domestic sender and the data outbound supervision unit; receiving, through the data outbound application unit, target data determined by the domestic sender according to the approval result and the outbound data, and sending the target data to the data outbound gateway; The data outbound gateway sends the target data to the overseas recipient, extracts the second pending review information of the target data, and sends it to the data outbound supervision unit; The data exit supervision unit determines a matching result between the second pending information and the approval result, and determines prompt information to be returned to the data exit gateway according to the matching result; The data outbound gateway determines whether to stop sending the target data according to the prompt information.
2. The method according to claim 1, characterized in that: Approving the first information to be reviewed according to the review rules in the compliance database preset by the data outbound review unit and determining the review result specifically includes: The data exit approval unit receives the first information to be reviewed, and determines compliance results corresponding to each item of information in the first information to be reviewed according to approval rules in a preset compliance database; The approval result of the first information to be reviewed is determined according to the compliance results respectively corresponding to each item of information in the first information to be reviewed.
3. The method according to claim 1, characterized in that: Receiving, by the data outbound application unit, target data determined by the domestic sender according to the approval result and the outbound data, and sending the target data to the data outbound gateway, specifically includes: The data export application unit, in response to the data adjustment request of the domestic sender, obtains the export data adjusted by the domestic sender according to the approval result and the export data; The data export application unit updates the first pending review information in response to the data export request re-initiated by the domestic sender, and sends the updated first pending review information to the data export approval unit; The data outbound approval unit approves the updated first pending information according to the approval rules in the preset compliance database, updates the approval result of the outbound data, and synchronizes the updated approval result to the domestic sender and the data outbound supervision unit; The data outbound application unit responds to the data transfer request initiated by the domestic sender according to the updated approval result, and sends the adjusted outbound data as the target data to the data outbound gateway.
4. The method according to claim 1, characterized in that: Extracting the second pending review information of the target data and sending it to the data outbound supervision unit specifically includes: The data outbound gateway splits the target data according to a preset size to obtain sub-data, and sends each sub-data to the overseas recipient one by one; The data exit gateway extracts the second pending review information of each sub-data one by one in the order in which each sub-data is sent to the overseas recipient, and sends the extracted second pending review information to the data exit supervision unit, wherein the second pending review information includes at least one of the attribute information of the exit data, the contract information of the exit data, and the user information of the sender and the receiver.
5. The method according to claim 2, characterized in that: The data exit supervision unit determines a matching result between the second pending information and the approval result, and determines prompt information to be returned to the data exit gateway according to the matching result, specifically including: The data exit supervision unit receives the second information to be reviewed, determines whether each item of information in the second information to be reviewed matches the approval result, and determines for each item of information whether the compliance result of the information matching is compliant; If both are true, then the determination is normal and is returned as prompt information to the data outbound gateway; If any of them is negative, the abnormality is determined and returned to the data outbound gateway as prompt information.
6. The method according to claim 5, characterized in that The data outbound gateway determines whether to stop sending the target data according to the prompt information, specifically including: The data exit gateway receives the prompt information sent by the data exit supervision unit. When the prompt information is normal, the data exit gateway does not suspend the sending of the target data, and continues to determine whether the next received prompt information is normal. When the prompt information is abnormal, the data exit gateway suspends the sending of the target data and sends the prompt information to the domestic sender.
7. A security supervision system for outbound data, characterized in that: The system includes: a data outbound application unit, a data outbound approval unit, a data outbound gateway and a data outbound supervision unit; wherein: The data export application unit is configured to respond to a data export request from a domestic sender, obtain the export data carried in the data export request, extract first pending review information of the export data, and send the first pending review information to the data export approval unit; The data outbound approval unit is configured to receive the first pending information sent by the data outbound application unit; approve the first pending information according to the approval rules in the preset compliance database and determine the approval result; and send the approval result to the domestic sender and the data outbound supervision unit; The data outbound gateway is configured to receive the target data sent by the domestic sender and send the target data to the overseas receiver; extract the second pending review information of the target data and send the second pending review information to the data outbound supervision unit; receive prompt information and determine whether to stop sending the target data according to the prompt information; The data outbound supervision unit is configured to receive the approval result sent by the data outbound approval unit and receive the second pending review information sent by the data outbound gateway; determine the matching result between the second pending review information and the approval result, and determine the prompt information based on the matching result and return it to the data outbound gateway.
8. A security monitoring device for outbound data, characterized in that: Specifically include: an acquisition module, configured to respond to a data outbound request from a domestic sender and acquire outbound data carried in the data outbound request; A first pending review module, configured to extract first pending review information of the outbound data through a data outbound application unit according to the outbound data, and send the first pending review information to a data outbound approval unit, wherein the first pending review information at least includes attribute information of the outbound data, contract information of the outbound data, and user information of both the sender and the receiver; An approval module, configured to approve the first information to be approved according to the approval rules in the compliance database preset by the data outbound approval unit, determine the approval result, and send it to the domestic sender and the data outbound supervision unit; A sending module, configured to receive, through the data outbound application unit, target data determined by the domestic sender according to the approval result and the outbound data, and send the target data to a data outbound gateway; A second pending review module, used for the data exit gateway to send the target data to the overseas recipient, and extract the second pending review information of the target data and send it to the data exit supervision unit; a prompt module, used for the data exit supervision unit to determine a matching result between the second pending information and the approval result, and to determine prompt information to be returned to the data exit gateway according to the matching result; The terminating module is used for the data outbound gateway to determine whether to suspend sending the target data according to the prompt information.
9. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
10. An electronic device, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the method according to any one of claims 1 to 6 is implemented when the processor executes the program.