Reliable user privacy protection method
By implementing multi-dimensional protection measures at the technical, management and legal levels in APP applications, the problem of user privacy data leakage in APP applications is solved, efficient and secure protection of user data is achieved, and user experience and overall data privacy protection level in the industry is improved.
Patent Information
- Application Number
- CN202510275291.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-06-10
AI Technical Summary
Existing APP applications have excessive demands in the data collection process, resulting in user privacy data leakage, seriously affecting the user's sense of security and the reputation of the enterprise.
Through the technical, management and legal level, APP applications are fully standardized and protected, and technical means such as technical encryption, access control, data desensitization, network protection and security sandboxing are adopted, combined with management training and legal compliance measures, to ensure the security of user privacy data.
It effectively prevents theft of users' personal privacy data, improves the security of users using APP applications, enhances the user's sense of security and privacy, and improves the user's user experience, while promoting the level of data privacy protection in the APP industry.
Smart Images

Figure CN120124103A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of program data privacy protection, and in particular to a reliable user privacy protection method. Background Art
[0002] In the digital age, APP applications have profoundly changed people's lives and work patterns. From map navigation apps used for daily travel, to e-commerce apps relied on for shopping and consumption, to various platforms that are indispensable for social entertainment, APP has penetrated into every corner of life in all aspects. While enjoying the convenience and efficiency brought by APP, user data privacy and security are facing unprecedented severe challenges. Many APPs have excessive demands in the data collection process. From a personal perspective, if the user's privacy is exposed, they may be bombarded with spam, harassing calls, and fraudulent information, seriously interfering with their normal life. For companies, data leakage incidents will greatly damage the company's reputation and image, leading to a sharp drop in user trust, and then causing user loss, which will deal a heavy blow to the company's sustainable development. Strengthening APP user data privacy protection has become a key issue that needs to be urgently addressed.
[0003] Therefore, the present invention proposes a reliable user privacy protection method, which comprehensively regulates the use of APP application programs, thereby greatly reducing the possibility of privacy data leakage when users use APP. Summary of the invention
[0004] 1. Technical issues to be resolved
[0005] In view of the deficiencies in the prior art, the present invention provides a reliable method for protecting user privacy. By analyzing the threats to user data privacy during the development and use of APP applications, it is proposed to use three dimensions of technical level protection, management level protection and legal level protection to regulate and restrict APP applications. Through technical encryption, access control and other technologies are used to provide direct protection for data privacy, effectively preventing the theft of user personal privacy data, greatly improving the security of users using APP applications, and not only enhancing users' sense of security and privacy and protecting their personal rights and interests, but also greatly improving users' usage experience.
[0006] (II) Technical solution
[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions: A reliable user privacy protection method, which is applied to an APP application program. The user privacy protection method comprehensively protects the user privacy data in the APP application program from the technical level, management level, and legal and regulatory levels. The user privacy protection method conducts privacy protection at the technical level through the login recognition function and data storage module in the APP application program. The user privacy protection method realizes the protection of user privacy data at the management level and legal level by training the staff of the company where the APP application program is located. At the technical protection level, technical protection is carried out through network protection function, data encryption function, access protection function, technical desensitization function, and security sandbox function. At the management protection level, the security protection function of the database is improved, the data stored in the database is managed periodically, privacy protection rules are formulated, and company employees are given security training on data privacy protection, and management-level protection is carried out through daily periodic audits and monitoring. At the legal protection level, user data is collected legally and compliantly, the data is stored and used safely and compliantly, data sharing is carried out in accordance with the law and regulations, the APP application program is operated legally in accordance with the law, and the relevant laws and regulations on data privacy protection are interpreted professionally to clarify the relevant boundaries of the laws and regulations;
[0008] Through the above technical solutions, the use of the APP is standardized from three dimensions: technical level, management level, and legal level, so as to comprehensively and efficiently protect the user privacy data.
[0009] Preferably, in the user privacy protection method, data encryption is carried out by using an asymmetric encryption algorithm and a hash algorithm to encrypt and protect the user's data. The asymmetric encryption algorithm uses a public key and a private key. The public key is publicly distributed to any party that needs to communicate with the data owner, and the private key is held by the data owner. The sender uses the public key of the receiver to encrypt the original data to generate a ciphertext, and the receiver can only decrypt the ciphertext with its own private key to restore the original data. Hash algorithm encryption is based on the one-way principle of the hash algorithm. Any length of input data is converted into a fixed-length hash value through a specific hash function. The hash value can be easily calculated from the original data, but it is almost impossible to reverse-derive the original data from the hash value for data encryption;
[0010] Through the above technical solution, the advantage of asymmetric key encryption is that even if the public key is made public, it is difficult for an attacker to deduce the private key from the public key, and thus impossible to decrypt the ciphertext. This encryption method has important applications in scenarios such as digital signatures and authentication. In the process of signing an electronic contract, the signing party can use its own private key to digitally sign the contract content, and the receiving party uses the public key of the signing party to verify the signature, thereby ensuring the authenticity and integrity of the contract. The hash algorithm plays an important role in data integrity verification, password storage, etc. In terms of user password storage, the system usually does not directly store the user's plaintext password, but stores the hash value of the password. When the user logs in, the system calculates the hash value of the password entered by the user and compares it with the stored hash value to verify the correctness of the password. Even if the hash value in the database is leaked, it is difficult for an attacker to restore the user's plaintext password from the hash value, improving the security of the user's password.
[0011] Preferably, in the user privacy protection method, access protection hierarchically identifies the login recognition function through the Role-Based Access Control (RBAC) method, sets database access to three levels: highest privilege, management privilege, and normal privilege, strictly manages and controls the user's access rights to data, and ensures that only authorized users can access specific data resources. Access protection is set with login access records, and the database access records are recorded using blockchain, ensuring that the access time and access times of all roles will be recorded on all public blockchains, guaranteeing that the access record data cannot be changed;
[0012] Through the above technical solution, role-based access control can simplify the complexity of permission management. When an employee joins the company, only need to assign them to the corresponding role, and the system will automatically grant all the permissions corresponding to that role to the employee, without setting permissions for them one by one. When the employee's role changes, only need to adjust their role, and the corresponding permissions will also change accordingly. The access information data recorded by the blockchain recording method cannot be tampered with or deleted, so that every access can be recorded in real time, preventing insiders from taking advantage of their power to secretly enter the data and steal the data.
[0013] Preferably, in the user privacy protection method, technical desensitization and anonymization can remove and replace the user's personal privacy data. When collecting the user's personal privacy data, the K-anonymity technology method is used to replace the user's name with a unique identifier generated by the system, and at the same time encrypt the user's mobile phone number, only retaining the first three digits and the last four digits of the number, and replacing the middle part with asterisks. Technical desensitization performs transformation processing on the user's sensitive data, reducing the sensitivity of the data while ensuring the availability of the data, preventing the leakage of sensitive information;
[0014] Through the above technical solution, the desensitization technology processes sensitive data in a specific way to make it unidentifiable to a certain extent. For the sensitive information of ID numbers, the common rule-based desensitization method is to retain the first few and the last few digits and replace the middle part of the digits with fixed characters, so as to find a balance between protecting privacy and meeting the data usage requirements. For the data analysis scenario, the desensitized data needs to retain certain features and information for effective data analysis and mining.
[0015] Preferably, in the user privacy protection method, network protection uses an intrusion detection system (IDS) and network firewall technology to protect the network security of the database and prevent data from being maliciously invaded and stolen by hackers. The network firewall blocks unauthorized external access by filtering IP addresses and blocking ports for the data packets entering and leaving the internal network of the database. The IDS hardware intrusion detection system monitors abnormal activities in the network in real time.
[0016] Preferably, in the user privacy protection method, the security sandbox technology adds an independent, enclosed and strictly monitored running environment for APP applications. With the support of the hardware level, the trusted execution environment (TEE) technology is used to control the permissions of APP applications. In the sandbox environment, the APP can only access system resources such as cameras, microphones, and address books within the scope clearly authorized by the user. If the APP application frequently reads a large amount of sensitive data or attempts to connect to a malicious server, the sandbox will immediately take measures, such as blocking the further execution of the behavior and directly terminating the operation of the APP application.
[0017] Through the above technical solution, when the APP is installed, a dedicated sandbox directory is established, which contains all the files of the APP, such as application code, data files, and cache files. During the operation of the APP, it can only access the files in its own sandbox directory and cannot directly access the key files of other APPs or the system, thus avoiding data leakage between APPs and attacks by malicious programs through the file system.
[0018] Preferably, in the user privacy protection method, at the management level, security protection for the placement area of the database is strengthened to prevent anyone from stealing data by sneaking into the database base, and a comprehensive data full-life cycle management system is constructed. In the data collection stage, a strict review mechanism is established to evaluate the necessity of collecting data. Only data that has been reviewed and determined to be directly relevant and necessary to the APP function is allowed to be collected. In the data storage link, the storage location, storage method, and storage period of different types of data are specified, and strict access permissions are set. According to the job positions and responsibilities of employees, corresponding data access permissions are assigned to ensure that only authorized personnel can access specific data. When the data reaches the storage period or the user requests to delete the data, the data deletion and destruction operations are carried out strictly in accordance with the regulations. Ensure that the data is completely deleted and cannot be restored to prevent privacy risks caused by data residue. And formulate user data privacy protection rules within the company and conduct security training for all employees to prevent the situation of employees stealing from within. And through regular audit logs, establish a comprehensive security audit log system to record all access and operation behaviors of users to data, including information such as access time, access IP, operation type, and involved data, and regularly check and eliminate security hazards.
[0019] Preferably, in the user privacy protection method, legal protection interprets relevant domestic and foreign laws and regulations to define the boundaries of connecting user data collection and use, so that APP application programs standardize data collection, use, storage, transmission and other links. APP developers must collect user data within the scope permitted by law, and shall not over-collect or compulsorily collect user data. At the same time, they need to clearly inform users of the purpose, method, and scope of collecting data and obtain user consent. And for the collected user data, APP developers are responsible for taking reasonable security measures for storage and use to prevent data leakage, tampering, and loss, and share the data in accordance with the law. If the APP needs to share or transfer user data to a third party, it must obtain the clear authorization of the user and sign a strict data protection agreement with the third party to ensure that the third party complies with relevant laws and regulations and protects user data privacy.
[0020] Through the above technical solutions, through laws, regulations and management ideology, the awareness of APP developers and managers to actively protect user data privacy is enhanced. If APP developers and managers steal user data privacy, they may face huge fines. By implementing effective privacy protection methods, APP developers can ensure the compliance of their own operations and reduce legal risks.
[0021] (III) Beneficial effects
[0022] The present invention provides a reliable user privacy protection method, which has the following beneficial effects:
[0023] 1. The present invention provides a reliable user privacy protection method. By analyzing the threats to user data privacy during the development and use of APP applications, it is proposed to regulate and restrict APP applications from three dimensions: technical protection, management protection, and legal protection. Through technical encryption, technologies such as access control directly safeguard data privacy, effectively preventing the theft of users' personal privacy data, greatly improving the security of users using APP applications, not only enhancing users' sense of security and privacy and protecting users' personal rights and interests, but also greatly improving users' usage experience.
[0024] 2. The present invention provides a reliable user privacy protection method. For developers of APP applications, it is necessary to clarify laws and regulations and conduct effective management. APPs that pay attention to user privacy protection are more likely to gain users' trust, attract more users to download and use, improve user retention rate and loyalty. Compliance and effective privacy protection measures help enhance the brand image of APPs, making them stand out among many similar APPs, and overall improving the data privacy protection level of the APP industry, creating a healthy and trustworthy mobile Internet environment, and promoting the sustainable development of the entire industry. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 It is the general method diagram of the user privacy protection method of the present invention;
[0026] Figure 2 It is the method diagram of the technical protection module of the user privacy protection method of the present invention;
[0027] Figure 3 It is the method diagram of the management protection module of the user privacy protection method of the present invention;
[0028] Figure 4 It is the method diagram of the legal protection module of the user privacy protection method of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0029] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of them. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention. In the description of this application, it should be noted that the terms used here are only for describing specific embodiments and are not intended to limit the exemplary embodiments of this application. For the convenience of description, the sizes of the various parts shown in the drawings are not drawn according to the actual proportional relationship. Technologies, methods, and devices known to those of ordinary skill in the relevant fields may not be discussed in detail, but where appropriate, the said technologies, methods, and devices should be regarded as part of the authorization specification. In all the examples shown and discussed here, any specific value should be interpreted as merely exemplary and not as a limitation. Therefore, other examples of the exemplary embodiments may have different values. It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.
[0030] Embodiment 1:
[0031] As Figures 1-4 shown, the embodiment of the present invention provides a reliable user privacy protection method. The reliable user privacy protection method is applied to the APP application program. The user privacy protection method comprehensively protects the user privacy data in the APP application program from the technical level, management level, and legal and regulatory levels. The user privacy protection method conducts technical-level privacy protection through the login recognition function and data storage module in the APP application program. The user privacy protection method realizes the protection of user privacy data at the management level and legal level through the management training of the staff of the company where the APP application program is located. The technical protection level conducts technical protection through network protection function, data encryption function, access protection function, technical desensitization function, and security sandbox function. The management protection level conducts management-level protection by improving the security protection function of the database, performing periodic security management on the data stored in the database, formulating privacy protection rules and conducting security training on data privacy protection for company employees, and through daily periodic auditing and monitoring. The legal protection level collects user data legally and compliantly, stores and uses the data safely and compliantly, conducts data sharing legally and compliantly, operates the APP application program legally in accordance with the law, and conducts professional interpretation of the relevant laws and regulations on data privacy protection to clarify the relevant boundaries of the laws and regulations. The use of the APP is regulated from three dimensions: technical level, management level, and legal level, so as to comprehensively and efficiently protect the user privacy data.
[0032] In the user privacy protection method, data encryption protects user data by using asymmetric encryption algorithms and hash algorithms. The asymmetric encryption algorithm uses a public key and a private key. The public key is publicly distributed to any party that needs to communicate with the data owner, while the private key is held by the data owner. The sender uses the recipient's public key to encrypt the original data to generate ciphertext, and the recipient can only decrypt the ciphertext with their own private key to restore the original data. Hash algorithm encryption is based on the one-way principle of the hash algorithm. Any length of input data is converted into a fixed-length hash value through a specific hash function. It is easy to calculate the hash value from the original data, but it is almost impossible to reverse-derive the original data from the hash value for data encryption. The advantage of asymmetric key encryption is that even if the public key is made public, it is difficult for an attacker to deduce the private key from the public key, and thus impossible to decrypt the ciphertext. This encryption method has important applications in scenarios such as digital signatures and authentication. In the process of signing an electronic contract, the signing party can use their own private key to digitally sign the contract content, and the recipient uses the public key of the signing party to verify the signature, thus ensuring the authenticity and integrity of the contract. The hash algorithm plays an important role in data integrity verification, password storage, etc. In terms of user password storage, the system usually does not directly store the user's plaintext password, but stores the hash value of the password. When the user logs in, the system calculates the hash value of the password entered by the user and compares it with the stored hash value to verify the correctness of the password. Even if the hash value in the database is leaked, it is difficult for an attacker to restore the user's plaintext password from the hash value, improving the security of the user's password.
[0033] In the user privacy protection method, access protection hierarchically identifies the login recognition function through the Role-Based Access Control (RBAC) method, sets database access to three levels: highest privilege, management privilege, and normal privilege, and strictly manages and controls the user's access rights to data to ensure that only authorized users can access specific data resources. Access protection sets up login access records, and the database access records are recorded using blockchain to ensure that the access time and access times of all roles are recorded on all public blockchains, ensuring that the access record data cannot be changed. Role-based access control can simplify the complexity of permission management. When an employee joins the company, they only need to be assigned to the corresponding role, and the system will automatically assign all the permissions corresponding to that role to the employee, without setting permissions for them one by one. When an employee's role changes, only their role needs to be adjusted, and the corresponding permissions will also change accordingly. The access information data recorded by the blockchain recording method cannot be tampered with or deleted, so that every access can be recorded in real time to prevent insiders from stealing data by taking advantage of their power.
[0034] In the user privacy protection method, technical desensitization and anonymization can remove and replace users' personal privacy data. When collecting users' personal privacy data, the K-anonymity technology method is used to replace the users' names with unique identifiers generated by the system. At the same time, the users' mobile phone numbers are encrypted, only the first three and the last four digits of the number are retained, and the middle part is replaced by asterisks. Technical desensitization performs transformation processing on users' sensitive data. On the premise of ensuring data availability, it reduces the sensitivity of the data and prevents the leakage of sensitive information. The desensitization technology makes the sensitive data lose its identifiability to a certain extent through specific processing of the sensitive data. For the sensitive information of the ID number, the common rule desensitization method is to retain the first few and the last few digits and replace the middle part of the digits with fixed characters, so as to find a balance between protecting privacy and meeting the data usage requirements. For the data analysis scenario, the desensitized data needs to retain certain features and information for effective data analysis and mining.
[0035] In the user privacy protection method, network protection uses intrusion detection systems (IDS) and network firewall technologies to provide network security protection for the database to prevent data from being maliciously invaded and stolen by hackers. The network firewall blocks unauthorized external access by filtering IP addresses and blocking ports for the data packets entering and leaving the internal network of the database. The IDS hardware intrusion detection system monitors abnormal activities in the network in real time. In the user privacy protection method, the secure sandbox technology is used to add an independent, closed and strictly monitored running environment for APP application programs. With the support of the hardware level, the trusted execution environment (TEE) technology is used to control the permissions of APP application programs. In the sandbox environment, the APP can only access system resources such as cameras, microphones, and address books within the scope clearly authorized by the user. If the APP application program frequently reads a large amount of sensitive data and tries to connect to a malicious server, etc., the sandbox will immediately take measures, such as blocking the further execution of the behavior and directly terminating the running of the APP application program. When the APP is installed, a dedicated sandbox directory is established, which contains all the files of the APP, such as application program code, data files, and cache files. The APP can only access the files in its own sandbox directory during the running process and cannot directly access the key files of other APPs or the system, thus avoiding data leakage between APPs and attacks by malicious programs through the file system.
[0036] In the user privacy protection method, at the management level, protection is achieved by strengthening the security protection of the database placement area to prevent anyone from stealing data by sneaking into the database base, and building a comprehensive data full-life cycle management system. In the data collection stage, a strict review mechanism is established to evaluate the necessity of collecting data. Only data that has been reviewed and determined to be directly related to and necessary for the APP function is allowed to be collected. In the data storage link, the storage location, storage method, and storage period of different types of data are specified, and strict access permissions are set. According to the job positions and responsibilities of employees, corresponding data access permissions are assigned to ensure that only authorized personnel can access specific data. When the data reaches the storage period or the user requests to delete the data, the data deletion and destruction operations are carried out strictly in accordance with the regulations. Ensure that the data is completely deleted and cannot be recovered to prevent privacy risks caused by data residues. And formulate user data privacy protection rules within the company and conduct safety training for all employees to prevent the situation of employees stealing from within. And through regular audit logs, establish a comprehensive security audit log system to record all access and operation behaviors of users on the data, including information such as access time, access IP, operation type, and involved data, and regularly check and eliminate potential safety hazards. In the user privacy protection method, legal protection is achieved by interpreting relevant domestic and foreign laws and regulations to clarify the boundaries of connecting user data collection and use, so that the APP application program standardizes the links of data collection, use, storage, transmission, etc. APP developers must collect user data within the scope permitted by law, and shall not over-collect or forcefully collect user data. At the same time, they need to clearly inform users of the purpose, method, and scope of data collection and obtain user consent. And for the collected user data, APP developers are responsible for taking reasonable security measures for storage and use to prevent data leakage, tampering, and loss, and legally share the data. If the APP needs to share or transfer user data to a third party, it must obtain the clear authorization of the user and sign a strict data protection agreement with the third party to ensure that the third party complies with relevant laws and regulations and protects user data privacy. Through laws, regulations, and management ideology, enhance the awareness of APP developers and managers to actively protect user data privacy. If APP developers and managers steal user data privacy, they may face huge fines. By implementing effective privacy protection methods, APP developers can ensure the compliance of their own operations and reduce legal risks.
[0037] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A reliable user privacy protection method, characterized by: The user privacy protection method is applied to APP applications. The user privacy protection method comprehensively protects user privacy data in APP applications through technical, management and legal and regulatory levels. The user privacy protection method performs technical privacy protection through the login identification function and data storage module in the APP application. The user privacy protection method implements management and legal user privacy data protection through management training for the staff of the company where the APP application is located; At the technical protection level, technical protection is provided through network protection functions, data encryption functions, access protection functions, technical desensitization functions and security sandbox functions. At the management protection level, protection is provided by improving the security protection functions of the database, conducting periodic security management of data stored in the database, formulating privacy protection rules and conducting security training on data privacy protection for company employees, and conducting management-level protection through daily periodic audits and monitoring. At the legal protection level, user data is collected legally and in compliance with regulations, and data is stored and used safely and in compliance with regulations, data is shared in compliance with regulations, APP applications are operated legally in accordance with legal provisions, and relevant laws and regulations on data privacy protection are professionally interpreted to clarify the relevant boundaries of laws and regulations.
2. A reliable user privacy protection method according to claim 1, characterized in that: In the user privacy protection method, data encryption is performed by using an asymmetric encryption algorithm and a hash algorithm to encrypt and protect user data. The asymmetric encryption algorithm uses a public key and a private key. The public key is publicly distributed to any party that needs to communicate with the data owner, and the private key is held by the data owner. The sender uses the receiver's public key to encrypt the original data to generate a ciphertext, and the receiver uses his own private key to decrypt the ciphertext to restore the original data. The hash algorithm encryption is based on the unidirectional principle of the hash algorithm. It converts input data of any length into a hash value of a fixed length through a specific hash function. The hash value can be easily calculated from the original data, but the original data can hardly be reversely deduced from the hash value to perform data encryption.
3. A reliable user privacy protection method according to claim 1, characterized in that: In the user privacy protection method, access protection uses a role-based access control (RBAC) method to perform hierarchical identification of login identification functions, sets database access to three levels: highest authority, management authority, and general authority, and strictly manages and controls user access to data to ensure that only authorized users can access specific data resources. Access protection is set with login access records, and database access records are recorded in blockchain to ensure that the access time and access times of all roles will be recorded on all public blockchains to ensure that the access record data cannot be changed.
4. A reliable user privacy protection method according to claim 1, characterized in that: In the user privacy protection method, technical desensitization and anonymization can remove and replace the user's personal privacy data. When collecting the user's personal privacy data, the K-anonymity technology method is used to replace the user's name with a unique identifier generated by the system. At the same time, the user's mobile phone number is encrypted, and only the first three and last four digits of the number are retained, and the middle part is replaced by asterisks. Technical desensitization deforms the user's sensitive data, reduces the sensitivity of the data while ensuring the availability of the data, and prevents the leakage of sensitive information.
5. A reliable user privacy protection method according to claim 1, characterized in that: In the user privacy protection method, network protection uses intrusion detection system (IDS) and network firewall technology to perform network security protection on the database to prevent data from being maliciously invaded and stolen by hackers. The network firewall prevents unauthorized external access by filtering the IP addresses of data packets entering and leaving the database internal network and blocking the ports. The IDS hardware intrusion detection system monitors abnormal activities in the network in real time.
6. A reliable user privacy protection method according to claim 1, characterized in that: In the user privacy protection method, a security sandbox technology is used to add an independent, closed and strictly monitored operating environment to the APP application. With the help of the trusted execution environment (TEE) technology supported by the hardware level, the permissions of the APP application are managed. In the sandbox environment, the APP can only access system resources such as cameras, microphones, and address books within the scope of explicit user authorization. If the APP application frequently reads a large amount of sensitive data, attempts to connect to a malicious server, etc., the sandbox will immediately take measures, such as preventing further execution of the behavior and directly terminating the operation of the APP application.
7. A reliable user privacy protection method according to claim 1, characterized in that: In the user privacy protection method, the management level protects the database placement area to strengthen security protection to prevent someone from stealing data by sneaking into the database base, and builds a comprehensive data life cycle management system. In the data collection stage, a strict review mechanism is established to evaluate the necessity of collecting data. Only after review, it is determined that the data is directly related to the APP function and necessary, is it allowed to be collected. In the data storage link, the storage location, storage method and storage period of different types of data are clarified, and strict access rights are set. According to the job position and responsibilities of employees, the corresponding data access rights are allocated to ensure that only authorized personnel can access specific data. When the data reaches the storage period or the user requires the data to be deleted, the data is deleted and destroyed in strict accordance with the regulations. Ensure that the data is completely deleted and cannot be restored to prevent privacy risks caused by data residues, formulate user data privacy protection rules within the company and conduct security training for all employees to prevent employees from stealing, and establish a comprehensive security audit log system through regular audit logs to record all user access and operation behaviors to the data, including access time, access IP, operation type, data involved and other information, and regularly check and eliminate security risks.
8. A reliable user privacy protection method according to claim 1, characterized in that: In the user privacy protection method described above, legal protection connects the boundaries of user data collection and use by interpreting relevant domestic and foreign laws and regulations, so that APP applications regulate data collection, use, storage, transmission and other links. APP developers must collect user data within the scope permitted by law, and must not collect user data excessively or forcibly. At the same time, they must clearly inform users of the purpose, method and scope of data collection and obtain user consent. In addition, APP developers are responsible for taking reasonable security measures to store and use the collected user data to prevent data leakage, tampering and loss, and share the data in accordance with the law. If the APP needs to share or transfer user data to a third party, it must obtain explicit authorization from the user and sign a strict data protection agreement with the third party to ensure that the third party complies with relevant laws and regulations and protect user data privacy.
Citation Information
Cited By
Data privacy protection method and device, computer equipment and storage medium
CN120337297A