Personal information compliance inspection method and system
By obtaining and verifying the registration information and credit rating of the collector, combining compliance inspection and correlation analysis models, the problem of legality verification of the data collector is solved, and effective protection and security improvement of personal information is achieved.
Patent Information
- Application Number
- CN202510061237.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-22
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The prior art is difficult to effectively identify and verify the legitimacy of the data collector, which leads to the risk of illegal collection and abuse of personal information on the Internet.
By obtaining the registration information and credit ratings of collectors from different sources, calculating the comprehensive assessment of credit, verifying the identity information of the collectors, and using compliance inspection algorithms and correlation analysis models, checking the compliance and relevance of the collection requests, and determining the legality of the collection requests.
It realizes automatic identification and verification of the legitimacy of the data collector, enhances the protection barrier of user data cards, prevents illegal data collection activities, and improves the security and privacy of personal information.
Smart Images

Figure CN119989405A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of personal information security protection, and in particular to a personal information compliance checking method and system. Background Art
[0002] With the rapid development of the Internet, a huge amount of personal information data is collected and analyzed, which has brought new challenges to personal information security. The development of the Internet has changed the way we live and work, and it has also made the issue of personal information security protection more complicated. To this end, people in this field have developed a personal information security protection method based on big data technology to automatically identify the legitimacy of the collector and strengthen the protection of user data cards to avoid illegal collection by special means. Summary of the invention
[0003] The present invention provides a method for checking compliance of personal information, the method comprising:
[0004] Obtaining the registration information and credit ratings of collectors from different sources, calculating the comprehensive credit rating, and verifying the identity information of the information collector based on the comprehensive credit rating;
[0005] Set up compliance check algorithms to perform compliance checks on the collection requests of the collectors;
[0006] Set a loss function for distinguishing the correlation between the collection items and the collection purpose in the collection request, determine the total loss value of the correlation analysis model training according to the loss function, and use the gradient descent method to adjust the model parameters to minimize the total loss value;
[0007] Based on the adjusted correlation analysis model, check the correlation between the collection items in the collection request and the collection purpose;
[0008] Determine the legitimacy of the collection request based on the compliance check results and relevance results.
[0009] A personal information compliance inspection method as described above, wherein the registration information and credit ratings of collectors from different sources are obtained, the comprehensive credit rating is calculated, and the identity information of the information collector is verified based on the comprehensive credit rating, specifically:
[0010] Obtain the enterprise registration information of the collector from official channels and other third-party enterprise information platforms, compare the registration information from different sources, and check whether there are any inconsistent information items;
[0011] Combine the credit ratings of the collectors on different platforms and the litigation disputes under the name of the enterprise to comprehensively assess its creditworthiness;
[0012] A verification domain is set for the comprehensive credit. When the comprehensive credit exceeds the scope of the verification domain, it is deemed that the collector does not have the collection license qualification and the collector's identity information is unqualified.
[0013] A personal information compliance inspection method as described above, wherein the gradient descent method is used to adjust the model parameters to minimize the total loss value, specifically using the loss function to calculate the loss value of the correlation model on the validation data set, and observing the changing trends of the loss function curve on the training set and the validation set respectively, to ensure that the changing trends caused by the adjusted model parameters are consistent, until the loss function no longer decreases.
[0014] A personal information compliance check method as described above, wherein if the output check result indicates that the collection items in the collection request do not exceed the standards of laws and regulations, and the collection items are all directly related to the collection purpose, an authorization notice is issued; if at least one of the collection items exceeds the standards of laws and regulations, or at least one collection item and its collection purpose are not directly related, a warning notice is issued.
[0015] A personal information compliance checking method as described above, wherein, after the legality is determined, the encryption center uses the data card encryption algorithm to encrypt the data in the data card. The encryption center is local and automatically starts the flight model during the export and import process to physically isolate external intrusion.
[0016] A personal information compliance checking method as described above, wherein the data in the data card is encrypted using a data card encryption algorithm, also includes: when all exported data are encrypted, the data items in different storage areas are cyclically shifted backward according to encryption parameters to form a new data sequence, and finally the new data item sequence is re-imported into the data card.
[0017] A personal information compliance inspection method as described above, wherein the encryption center completes the decryption and connection of the data, specifically: the data in the storage area pointed to by the access behavior is exported to the encryption center, the encryption center restores the data item queue according to the encryption parameters, and then inversely operates the data card encryption algorithm to obtain the original data item, and finally returns the restored data to the access interface.
[0018] The beneficial effects achieved by the present invention are as follows: automatically identifying and verifying the legitimacy of the data collector, while enhancing the protection barrier for user data cards, resisting and preventing illegal data collection activities using advanced technical means or special methods, and improving the security and privacy of user personal information. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0020] Figure 1 This is a flow chart of a personal information security protection method provided in Example 1 of the present invention. DETAILED DESCRIPTION
[0021] The following is a clear and complete description of the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.
[0022] Embodiment 1
[0023] like Figure 1 As shown, Embodiment 1 of the present invention provides a method for protecting personal information security, including:
[0024] Step S10: verifying the identity information of the information collector, and judging whether the information collector has the collection license qualification according to the identity information;
[0025] When the collector sends a collection request, first determine whether it has the collection license qualification. If it does, proceed to the next step of verification. If not, intercept the collection request and send a warning notification to the user. The judgment conditions are: the collector must be real-name authenticated, that is, its registration information can be queried from official channels, and the registered company has a good credit. These data can be obtained from the identity information of the collector. Of course, the premise is the authenticity of the identity information. Verifying the identity information of the information collector is specifically divided into the following sub-steps:
[0026] Step S11: Verify whether the digital certificate of the collector is authentic and valid;
[0027] The digital certificate is obtained during the SSL / TLS handshake process. Its integrity is confirmed by checking the certificate chain, verifying that the domain name in the certificate is consistent with the current access domain name, confirming that the certificate is within the validity period, and using the CA public key to verify the digital signature on the certificate. After this series of verification processes, it can be determined that the digital certificate of the collector is authentic and valid.
[0028] Step S12: After the digital certificate is verified, cross-verify the enterprise registration information and comprehensive credit of the collector;
[0029] First, obtain the enterprise registration information of the collector from official channels and other third-party enterprise information platforms, compare the registration information from different sources, and check whether there are inconsistent information items. Then, combine the credit rating of the collector on different platforms and the litigation disputes under the name of the enterprise to comprehensively assess its creditworthiness. The formula for comprehensive credit assessment is expressed as:
[0030] Where C is the comprehensive credit of the collector, A diff A is the number of information items in the collection party’s registration information on the third-party enterprise information platform that are inconsistent with the registration information on the official channel. total is the total number of registered information in the official channel, B q represents the credit score of the collector in the qth platform with credit rating, q ranges from 1 to Q, Q is the number of platforms with credit rating, D represents the number of lawsuits under the name of the collector, ε is an adjustable parameter, D p Indicates the number of lawsuits involving personal information security in the name of the collector, They are the weights of the impact of inconsistent registration information, third-party ratings, and lawsuits on the credit rating of the collector.
[0031] A verification domain is set for the comprehensive credit. When the calculation result C exceeds the scope of the verification domain, or the verification of the digital certificate fails, it is deemed that the collector does not have the collection license qualification.
[0032] Step S20: Verify the compliance of the collection request through a compliance check algorithm, and request authorization from the user after the verification is passed;
[0033] The compliance of the collection items requested by the information collector is verified through the compliance check algorithm, which specifically includes the following sub-steps:
[0034] Step S21: Processing the collection items and collection purposes in the collection request into data pairs, and arranging them into an input set;
[0035] The collection items and collection purposes are extracted from the privacy policy or user agreement provided by the collector. When collating the data set, it is necessary to ensure that the collection items and their collection purposes are in the form of data pairs for easy inspection. For example, if the collection item is a mobile phone number and the reason is to meet the real identity information authentication requirements stipulated by relevant laws, it is expressed as (E1, F1), where E1 represents the collection item mobile phone number, F1 represents the collection reason, and subscript 1 represents the first collection item.
[0036] Step S22: using a compliance check algorithm, providing check results for each pair of collection items and collection purpose data in the input set;
[0037] The compliance check algorithm includes a legal and regulatory database and a correlation analysis model. The legal and regulatory database stores the data items that are allowed to be collected. Based on the legal and regulatory database, it can be queried whether the collection items in the input set are within the scope of collection allowed by laws and regulations; the correlation analysis model is used to check the direct correlation between the collection items in the input set and the collection purpose. The training process of the correlation analysis model includes the following sub-steps:
[0038] Step S221: Create a training data set and a verification data set based on a standard acquisition party protocol;
[0039] The collection items and their collection purposes in the standard collection party agreement are extracted. The data pairs formed by these collection items and collection purposes are known positive samples with direct correlation, so their classification label is 1. If the collection purpose in the positive sample is replaced with the collection purpose of other collection items, it constitutes a negative sample, and the classification label of the negative sample is 0. The training data set contains a large number of positive and negative samples. The data type in the verification data set is consistent with the training data set, but the content must be relatively independent, that is, the collection items that appear in the verification data set do not appear in the training data set. Such a verification data set can reflect the fitting ability of the model.
[0040] Step S222: designing a loss function for the correlation analysis model;
[0041] The goal of the loss function is to enable the model to distinguish which collection items are directly relevant to the collection purpose (positive samples) and which are not directly relevant (negative samples). The loss function designed with this sub-goal is expressed as:
[0042] L((E i ,F i ),Y i )=-[Y i log(σ(M(E i ,F i )))+(1-Y i )log(1-σ(M(E i ,F i )))],in
[0043] (E i ,F i ) is the i-th sample of the input model, E i is the collection item in the i-th sample, F i For the collection purpose in the i-th sample, Y i represents the true classification label of the i-th sample, the positive sample is 1, the negative sample is 0, M(E i ,F i ) represents the model's response to the input sample (E i ,Fi ) is the predicted classification label output, σ() is the sigmoid function, which is used to return the predicted classification label M(E i ,F i )’s output probability.
[0044] Step S223: training the correlation analysis model using the training data set, and adjusting the model parameters based on the loss function during the training process;
[0045] The total loss value of a training batch is expressed as: Where L((E i ,F i ),y i ) is the sample (E i ,F i ), E i is the collection item in the i-th sample, F i For the collection purpose in the i-th sample, Y i represents the true classification label of the i-th sample, i ranges from 1 to N, N is the size of a training batch, and then the gradient descent method is used to adjust the model parameters to minimize the total loss value L batch .
[0046] Step S224: achieving convergence of the correlation analysis model in combination with the validation data set;
[0047] During the training process, it is also necessary to use the loss function to calculate the loss value of the correlation model on the validation data set, and observe the changing trends of the loss function curve on the training set and the validation set respectively to ensure that the changing trends caused by the adjusted model parameters are consistent until the loss function no longer decreases.
[0048] Step S23: Determine whether to issue a warning notification or an authorization notification based on the inspection result;
[0049] If the output check result indicates that the collection items in the collection request do not exceed the standards of laws and regulations, and all the collection items are directly related to the collection purpose, an authorization notice will be issued; if at least one of the collection items exceeds the standards of laws and regulations, or at least one collection item and its collection purpose are not directly related, a warning notice will be issued.
[0050] Step S30: encrypt the data in the data card using the data card encryption algorithm, and after the user authorizes access, the encryption center completes the decryption and connection of the data;
[0051] Data cards can be various types of storage devices, such as smart cards, SIM cards, SD cards, etc. They are usually used to store sensitive information, such as communication information, personal identity information, financial information, etc. Using data card encryption algorithms to protect data in data cards specifically includes the following sub-steps:
[0052] Step S31: exporting the data in the data card to the encryption center;
[0053] The encryption center is local, and the flight model will be automatically enabled during the export and import process to physically isolate it from external intrusion.
[0054] Step S32: the encryption center encrypts the data in the data card using the data card encryption algorithm, and then re-imports the data into the data card;
[0055] The encryption formula of the data card encryption algorithm is expressed as: Among them, H j is the data item V j The encrypted data, V j is the jth original data in the encryption queue, V j+τ is the j+τth original data in the encryption queue, τ is the encryption parameter, and % is the modulo operation.
[0056] When all exported data are encrypted, the data items in different storage areas are shifted backward cyclically according to the encryption parameter τ to form a new data sequence, that is, the original j-th data item is actually at the position j+τ, and the last data item is at the position of τ items back from the starting position. Finally, the new data item sequence is re-imported into the data card.
[0057] Step S33: After the user authorizes the data card access behavior, the encryption center completes the decryption and connection of the data;
[0058] First, the data in the storage area pointed to by the access behavior is exported to the encryption center. The encryption center restores the data item queue according to the encryption parameter τ, then inverses the data card encryption algorithm to obtain the original data item, and finally returns the restored data to the access interface.
[0059] Step S40: monitor the collection behavior of the information collector in real time, and immediately issue a warning to the user and terminate the collection behavior if abnormal collection behavior is found;
[0060] After the collection behavior begins, the collection behavior of the collector will still be monitored to detect whether the collection behavior exceeds the collection scope specified in the privacy policy or user agreement given by the collector. If it exceeds the scope, it will be regarded as abnormal collection behavior, and the collection behavior will be terminated immediately and a warning notification will be issued to the user.
[0061] Step S50: regularly updating the compliance check algorithm and the data card encryption algorithm;
[0062] Updating the compliance detection algorithm is to update the legal and regulatory database according to the updated terms of the permitted collection scope of laws and regulations, and to incrementally train the correlation analysis model using the privacy policy or user agreement documents provided by the known and recognized standard collectors;
[0063] Updating the data card encryption algorithm refers to updating the encryption parameters therein to avoid using the same encryption parameters to encrypt data for a long time, thereby reducing the probability of being cracked.
[0064] Embodiment 2
[0065] Embodiment 2 of the present invention provides a personal information security protection device, including: a collection party identity authentication module, a compliance check module, a collection behavior monitoring module, and a data card protection module;
[0066] (1) The collector identity verification module is used to verify the identity information of the information collector and determine whether the information collector has the collection license qualification based on the identity information, including a digital certificate verification submodule and a credit comprehensive verification submodule;
[0067] 1. Digital certificate verification submodule, used to verify whether the digital certificate of the collector is authentic and valid;
[0068] The digital certificate is obtained during the SSL / TLS handshake process. Its integrity is confirmed by checking the certificate chain, verifying that the domain name in the certificate is consistent with the current access domain name, confirming that the certificate is within the validity period, and using the CA public key to verify the digital signature on the certificate. After this series of verification processes, it can be determined that the digital certificate of the collector is authentic and valid.
[0069] 2. Credit comprehensive verification submodule, used to cross-verify the enterprise registration information and comprehensive credit of the collector;
[0070] First, obtain the enterprise registration information of the collector from official channels and other third-party enterprise information platforms, compare the registration information from different sources, and check whether there are inconsistent information items. Then, combine the credit rating of the collector on different platforms and the litigation disputes under the name of the enterprise to comprehensively assess its creditworthiness. The formula for comprehensive credit assessment is expressed as:
[0071] Where C is the comprehensive credit of the collector, A diff A is the number of information items in the collection party’s registration information on the third-party enterprise information platform that are inconsistent with the registration information on the official channel. total is the total number of registered information in the official channel, B q represents the credit score of the collector in the qth platform with credit rating, q ranges from 1 to Q, Q is the number of platforms with credit rating, D represents the number of lawsuits under the name of the collector, ε is an adjustable parameter, Dp Indicates the number of lawsuits involving personal information security in the name of the collector, They are the weights of the impact of inconsistent registration information, third-party ratings, and lawsuits on the credit rating of the collector.
[0072] A verification domain is set for the comprehensive credit. When the calculation result C exceeds the scope of the verification domain, or the verification of the digital certificate fails, it is deemed that the collector does not have the collection license qualification.
[0073] (2) a compliance check module, which is used to verify the compliance of the collection request using a compliance check algorithm and request authorization from the user after the verification is passed, including a collection scope check submodule, a correlation analysis submodule, and a compliance check algorithm update submodule;
[0074] 1. The collection scope check submodule is used to check whether the collection items in the collection request are within the scope permitted by laws and regulations;
[0075] The compliance check algorithm includes a legal and regulatory database and a correlation analysis model. The legal and regulatory database stores data items that are allowed to be collected. Based on the legal and regulatory database, it is possible to query whether the collection items in the input set are within the scope of collection permitted by laws and regulations.
[0076] 2. The correlation analysis submodule is used to check whether the collection items in the collection request are directly correlated with the collection purpose;
[0077] The correlation analysis model in the compliance check algorithm is used to check the direct correlation between the collection items and the collection purpose in the input set. First, the collection items and collection purposes in the collection request are sorted into data pairs and sorted into an input set. Then, the correlation analysis model is used to output the check results for each pair of collection items and collection purposes.
[0078] The training process of the correlation analysis model includes the following sub-steps:
[0079] I. Create training and validation datasets based on standard acquisition protocols;
[0080] The collection items and their collection purposes in the standard collection party agreement are extracted. The data pairs formed by these collection items and collection purposes are known positive samples with direct correlation, so their classification label is 1. If the collection purpose in the positive sample is replaced with the collection purpose of other collection items, it constitutes a negative sample, and the classification label of the negative sample is 0. The training data set contains a large number of positive and negative samples. The data type in the verification data set is consistent with the training data set, but the content must be relatively independent, that is, the collection items that appear in the verification data set do not appear in the training data set. Such a verification data set can reflect the fitting ability of the model.
[0081] II. Design a loss function for the correlation analysis model;
[0082] The goal of the loss function is to enable the model to distinguish which collection items are directly relevant to the collection purpose (positive samples) and which are not directly relevant (negative samples). The loss function designed with this sub-goal is expressed as:
[0083] L((E i ,F i ),Y i )=-[Y i log(σ(M(E i ,F i )))+(1-Y i )log(1-σ(M(E i ,F i )))],in
[0084] (E i ,F i ) is the i-th sample of the input model, E i is the collection item in the i-th sample, F i For the collection purpose in the i-th sample, Y i represents the true classification label of the i-th sample, the positive sample is 1, the negative sample is 0, M(E i ,F i ) represents the model's response to the input sample (E i ,F i ) is the predicted classification label output, σ() is the sigmoid function, which is used to return the predicted classification label M(E i ,F i )’s output probability.
[0085] III. Use the training data set to train the correlation analysis model and adjust the model parameters based on the loss function during the training process;
[0086] The total loss value of a training batch is expressed as: Where L((E i ,F i ),y i ) is the sample (E i ,F i ), E i is the collection item in the i-th sample, F i For the collection purpose in the i-th sample, Y i represents the true classification label of the i-th sample, i ranges from 1 to N, N is the size of a training batch, and then the gradient descent method is used to adjust the model parameters to minimize the total loss value L batch .
[0087] IV. Combine the validation data set to achieve the convergence of the correlation analysis model;
[0088] During the training process, it is also necessary to use the loss function to calculate the loss value of the correlation model on the validation data set, and observe the changing trends of the loss function curve on the training set and the validation set respectively to ensure that the changing trends caused by the adjusted model parameters are consistent until the loss function no longer decreases.
[0089] If the inspection results of the collection scope inspection submodule and the correlation analysis submodule indicate that the collection items in the collection request do not exceed the standards of laws and regulations, and the collection items are all directly related to the collection purpose, an authorization notice is issued; if at least one of the collection items exceeds the standards of laws and regulations, or at least one collection item and its collection purpose are not directly related, an early warning notice is issued.
[0090] 3. Compliance check algorithm update submodule, used to regularly update the compliance check algorithm according to the updated terms of laws and regulations and new collection protocols;
[0091] Update the legal and regulatory database in the compliance check algorithm according to the updated terms of the permitted collection scope in laws and regulations, and use the privacy policy or user agreement documents provided by known and recognized standard collection parties to incrementally train the relevance analysis model.
[0092] (3) A collection behavior monitoring module, which is used to monitor the collection behavior of the information collector in real time. If abnormal collection behavior is found, an early warning is immediately issued to the user and the collection behavior is terminated;
[0093] After the collection behavior begins, the collection behavior of the collector will still be monitored to detect whether the collection behavior exceeds the collection scope specified in the privacy policy or user agreement given by the collector. If it exceeds the scope, it will be regarded as abnormal collection behavior, and the collection behavior will be terminated immediately and a warning notification will be issued to the user.
[0094] (4) a data card protection module, which is used to protect the data in the data card using a data card encryption algorithm, including an encryption center submodule, a data import and export submodule, and an encryption algorithm update submodule;
[0095] 1. The encryption center submodule is used to encrypt and decrypt the data in the data card using the data card encryption algorithm;
[0096] The encryption formula of the data card encryption algorithm is expressed as: Among them, H j is the data item V j The encrypted data, V j is the jth original data in the encryption queue, V j+τis the j+τth original data in the encryption queue, τ is the encryption parameter, and % is the modulo operation.
[0097] When all the data are encrypted, the data items in different storage areas are shifted backward cyclically according to the encryption parameter τ to form a new data item sequence, that is, the original j-th data item is actually at the position j+τ, and the last data item is at the position of τ items back from the starting position.
[0098] After the user authorizes the data card access behavior, the encryption center will complete the decryption and connection of the data;
[0099] First, the data in the storage area pointed to by the access behavior is exported to the encryption center. The encryption center restores the data item queue according to the encryption parameter τ, then inverses the data card encryption algorithm to obtain the original data item, and finally returns the restored data to the access interface.
[0100] 2. Data import and export submodule, used to realize the import and export of data between the data card and the encryption center;
[0101] The flight model will be automatically turned on during the export and import process to physically isolate it from external intrusion.
[0102] 3. Encryption algorithm update submodule, used to update encryption parameters in the encryption algorithm;
[0103] Updating the data card encryption algorithm refers to updating the encryption parameters therein to avoid using the same encryption parameters to encrypt data for a long time, thereby reducing the probability of being cracked.
[0104] The specific implementation methods described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific implementation method of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made on the basis of the technical solution of the present invention should be included in the scope of protection of the present invention.
Claims
1. A personal information compliance inspection method, characterized in that: The method comprises: Obtaining the registration information and credit ratings of collectors from different sources, calculating the comprehensive credit rating, and verifying the identity information of the information collector based on the comprehensive credit rating; Set up compliance check algorithms to perform compliance checks on the collection requests of the collectors; Set a loss function for distinguishing the correlation between the collection items and the collection purpose in the collection request, determine the total loss value of the correlation analysis model training according to the loss function, and use the gradient descent method to adjust the model parameters to minimize the total loss value; Based on the adjusted correlation analysis model, check the correlation between the collection items in the collection request and the collection purpose; Determine the legitimacy of the collection request based on the compliance check results and relevance results.
2. A personal information compliance checking method according to claim 1, characterized in that: Obtain the registration information and credit ratings of collectors from different sources, calculate the comprehensive credit rating, and verify the identity information of the information collector based on the comprehensive credit rating, specifically: Obtain the enterprise registration information of the collector from official channels and other third-party enterprise information platforms, compare the registration information from different sources, and check whether there are any inconsistent information items; Combine the credit ratings of the collectors on different platforms and the litigation disputes under the name of the enterprise to comprehensively assess its creditworthiness; A verification domain is set for the comprehensive credit. When the comprehensive credit exceeds the scope of the verification domain, it is deemed that the collector does not have the collection license qualification and the collector's identity information is unqualified.
3. A personal information compliance checking method according to claim 1, characterized in that: Use the gradient descent method to adjust the model parameters and minimize the total loss value. Specifically, use the loss function to calculate the loss value of the correlation model on the validation data set, and observe the changing trend of the loss function curve on the training set and the validation set respectively to ensure that the changing trend caused by the adjusted model parameters is consistent until the loss function no longer decreases.
4. A personal information compliance checking method according to claim 1, characterized in that: Also includes: The digital certificate is obtained during the SSL / TLS handshake process. Its integrity is confirmed by checking the certificate chain, verifying that the domain name in the certificate is consistent with the current access domain name, confirming that the certificate is within the validity period, and using the CA public key to verify the digital signature on the certificate. After this series of verification processes, it is determined that the digital certificate of the collector is authentic and valid.
5. A personal information compliance checking method according to claim 1, characterized in that: The collection items and collection purposes are extracted from the privacy policy or user agreement provided by the collector. When collating the data set, it is necessary to ensure that the collection items and their collection purposes are in the form of data pairs.
6. A personal information compliance checking method according to claim 1, characterized in that: The data items that are allowed to be collected are stored in the legal and regulatory database, and it is inquired based on the legal and regulatory database whether the collected items are within the scope of collection permitted by the laws and regulations.
7. A personal information compliance checking method according to claim 1, characterized in that: If the output check result indicates that the collection items in the collection request do not exceed the standards of laws and regulations, and all the collection items are directly related to the collection purpose, an authorization notice will be issued; if at least one of the collection items exceeds the standards of laws and regulations, or at least one collection item and its collection purpose are not directly related, a warning notice will be issued.
Citation Information
Patent Citations
Resident travel feature analysis method based on mobile big data
CN110769375A
Method and device for discriminating compliance of application program
CN113326536A
Student information privacy protection method based on deep learning fusion
CN116861485A
Method for constructing credit rating system for small, medium and micro enterprises
CN117635304A
Method and device for monitoring personal information spreading, medium and equipment
CN117668820A