Security protection method for customer privacy data

By combining automation tools and manual audit data classification methods, building a zero-trust secure access control system and deploying an AI-driven threat detection system, the security protection challenges faced by customers' private data are solved, and a comprehensive and multi-level security protection effect is achieved.

CN120124104AInactive Publication Date: 2025-06-10北京数升慧科技有限公司
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510276150.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2025-06-10
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The security protection challenges faced by customer privacy data in the digital era include huge data scale and diverse types, continuous evolution of attack methods, and weak internal security awareness of enterprises, making it difficult to effectively deal with new threats.

Method used

Through the combination of automation tools and manual audits, customer privacy data is classified and security tags are assigned, a zero-trust secure access control system based on identity authentication is built, an AI-driven threat detection system is deployed, internal and external threat intelligence is integrated, and user behavior patterns are analyzed using machine learning algorithms to monitor abnormal activities in real time.

Benefits of technology

A comprehensive and multi-level customer privacy data security protection system has been built to effectively protect customer privacy data security, respond to new threats, and reduce the risk of data leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124104A_ABST
    Figure CN120124104A_ABST
Patent Text Reader

Abstract

The invention relates to a security protection method for customer privacy data, and relates to the technical field of artificial intelligence, and the method comprises the steps: classifying the customer privacy data through a mode of combining an automatic tool with manual auditing, and distributing a security label for each data item, so as to draw a data flow map; a zero-trust security access control system based on identity authentication is constructed, a multi-factor authentication means is adopted to verify the identity of a user, a micro-isolation technology is utilized to limit transverse movement of a network, all access behaviors are continuously monitored and audited, an AI-driven threat detection system is deployed, and internal and external threat intelligence is integrated. The machine learning algorithm is utilized to analyze the user behavior mode and monitor the abnormal activity in real time, the abnormal behavior can be identified more accurately through the machine learning algorithm, false alarm and missing report can be reduced, the risk of data leakage can be reduced, and the security protection of the privacy data of the customer can be facilitated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence technology. More specifically, the present invention relates to a method for secure protection of customer privacy data. Background Art

[0002] In today's digital age, customer privacy data has become a key asset for enterprise operation and decision-making. With the rapid development of technologies such as the Internet, cloud computing, big data, and artificial intelligence, enterprises' capabilities to collect, store, and process customer data have been enhanced unprecedentedly. However, this has also brought unprecedented risks of privacy leakage.

[0003] However, there are many challenges in the secure protection of customer privacy data. First, the large scale and diverse types of data bring difficulties to data classification, grading, and management. Second, the attack means are constantly evolving, and traditional security protection measures are difficult to effectively cope with new threats. In addition, problems such as weak internal security awareness, imperfect security management systems, and insufficient technical capabilities in enterprises also exacerbate the risk of data leakage. Summary of the Invention

[0004] In view of the technical problems existing in the prior art, the present invention provides a method for secure protection of customer privacy data to solve the problems raised in the above background art.

[0005] The technical solution of the present invention to solve the above technical problems is as follows: A method for secure protection of customer privacy data specifically includes the following steps:

[0006] Step 101: Classify customer privacy data through a combination of automated tools and manual review, and assign security labels to each data item to draw a data flow map;

[0007] Step 102: Build a zero-trust security access control system based on identity authentication, use multi-factor authentication means to verify user identities, use micro-segmentation technology to restrict lateral network movement, and continuously monitor and audit all access behaviors;

[0008] Step 103: Deploy an AI-driven threat detection system, integrate internal and external threat intelligence, use machine learning algorithms to analyze user behavior patterns, and real-time monitor abnormal activities.

[0009] In a preferred embodiment, in the said Step 101, the specific steps of classifying customer privacy data through a combination of automated tools and manual review, and assigning security labels to each data item to draw a data flow map are as follows:

[0010] Step A1: Automatically scan the storage locations of customer privacy data using a data discovery tool, and manually review the results of the automated scan to confirm the accuracy and integrity of the data. Record the confirmed data in the data asset management knowledge base, including the data name, description, location, format, and owner information, and classify the data in the data asset management knowledge base;

[0011] Step A2: Automatically assign security tags to each data item according to the content, importance, and usage of the data. Each security tag can correspond to a different security level, and different security levels have different access control permissions. Draw a data flow map through the data flow path within the knowledge base. The data flow map can clearly show the entire life cycle of the data from collection, storage, processing to destruction.

[0012] In a preferred embodiment, in step 102, a zero-trust security access control system based on identity authentication is constructed. Multifactor authentication means are used to verify the user identity, micro-segmentation technology is used to restrict network lateral movement, and all access behaviors are continuously monitored and audited to ensure that only authorized users and devices can access customer privacy data. The specific steps are as follows:

[0013] Step B1: Identity authentication and multifactor authentication: Construct a dynamic and adaptive zero-trust security framework, combine multifactor authentication based on identity authentication with an intelligent device identification mechanism, perform real-time identity verification before any access behavior occurs, and use AI technology to automatically evaluate the risk levels of users and devices and dynamically adjust access permissions. It further includes the following steps:

[0014] Step B101: The first factor: When the user accesses, first enter the username u and password p for identity verification;

[0015] Step B102: The second factor: When the username and password verification pass, send a text message verification code v to the user's registered mobile phone. After the user receives the text message verification code, enter the verification code for verification;

[0016] Step B103: The third factor: When the username and password verification pass and the verification code verification is successful, the user provides fingerprint and facial recognition for biometric verification. When the username, password, verification code, and biometric data all pass the verification, return f(u, p, v, b) = 1, indicating "authentication passed" and allowing access; when any factor verification fails, return "authentication failed" and reject the user access, where u is the username, p is the password, v is the verification code, and b is the biometric data;

[0017] Step B2: Use micro - isolation technology to partition users and protect data transmission through encrypted tunnels. Divide the network into multiple small and secure areas to limit lateral movement of the network, reduce the attack surface, and assign the minimum access permissions to each application and device. It further includes the following steps:

[0018] Step B201: Network division and separation: Divide the network into multiple regions according to security levels. Devices within each region can only access authorized services, and represent the access permission matrix between regions where A[i, j]=1 indicates that region i can access region j, otherwise A[i, j]=0;

[0019] Step B202: Control access permissions: Inside each network region, configure different access control policies to strictly control the traffic between different regions, and use encrypted tunnels to protect data transmission between network regions to prevent data from being tampered with during transmission.

[0020] In a preferred embodiment, in step 103, deploy an AI - driven threat detection system, integrate internal and external threat intelligence, use machine learning algorithms to analyze user behavior patterns, and monitor abnormal activities in real - time. The specific steps are as follows:

[0021] Step C1: Collect user behavior data, including network traffic data, system log data, and application log data, and clean the collected data to remove noise and outliers. The network traffic data includes source IP address, destination IP address, port number, protocol type, and traffic volume. The system log data includes user login logs, process startup logs, and file access logs. The application log data includes application access logs and error logs;

[0022] Step C2: Extract features from user behavior data, including user login frequency, access resource type, data transmission volume, and access time period, to train a machine learning model. It further includes the following steps:

[0023] Step C201: The user login frequency reflects the activity of the user logging in to the system. Within a time period T, user u logs in n times, and the calculated login frequency of the user is: where F login (u) represents the login frequency of user u, n represents the number of logins, and T represents the time window;

[0024] Step C202: According to user u and time window T, calculate the transmission volume as where, V data (u) is the total data transmission volume of user u within time window T, traffic i is the traffic of the i - th data transmission;

[0025] Step C203: Extract the access time feature by calculating the user's activity level in different time periods. The specific calculation formula is: where T 1 , T 2 ,... are the divided time periods, and I(u, t) is an indicator of whether user u has activities in time period t. 1 indicates activities, and 0 indicates no activities;

[0026] Step C3: Anomaly detection: From the extracted feature data, use machine learning algorithms to train a threat detection model. The behavior score output by model M is S(u, T) = Model(F login (u, T), F time (u, T), V data (u, T),...). When S(u, T) exceeds the threshold θ, it indicates abnormal behavior and the alarm mechanism is activated. Among them, S(u, T) is the behavior score output by the model, F login (u, T) represents the degree of abnormal behavior of user u in time period T, V data (u, T) is the login frequency feature of user u in time period T, and F time (u, T) is the data transmission volume of user u in time period T, which is the activity level of user u in time period T.

[0027] The beneficial effects of the present invention are as follows: By combining automated tools with manual review, classify customer privacy data, assign security labels to each data item, draw a data flow map, construct a zero-trust security access control system based on identity authentication, use multi-factor authentication means to verify user identities, use micro-segmentation technology to restrict network lateral movement, continuously monitor and audit all access behaviors, deploy an AI-driven threat detection system, integrate internal and external threat intelligence, use machine learning algorithms to analyze user behavior patterns, and monitor abnormal activities in real time. Through data classification, zero-trust security architecture, and AI-driven threat detection, the present invention constructs an all-round and multi-level security protection system for customer privacy data to protect the security of customer privacy data. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 is the flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0029] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.

[0030] In the description of the present application, the terms "first" and "second" are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of the described features. In the description of the present application, the meaning of "a plurality" is two or more, unless otherwise specifically defined.

[0031] In the description of the present application, the term "for example" is used to mean "used as an example, illustration, or explanation". Any embodiment described as "for example" in the present application is not necessarily construed as being more preferred or having more advantages than other embodiments. In order for any person skilled in the art to implement and use the present invention, the following description is given. In the following description, details are set forth for purposes of explanation. It should be understood that those of ordinary skill in the art can recognize that the present invention can be implemented without using these specific details. In other instances, well-known structures and processes are not elaborated in detail to avoid obscuring the description of the present invention with unnecessary details. Therefore, the present invention is not intended to be limited to the embodiments shown, but is consistent with the broadest scope that conforms to the principles and features disclosed in the present application.

[0032] Embodiment 1

[0033] This embodiment provides a security protection method for customer privacy data as Figure 1 shown, specifically including the following steps:

[0034] Step 101: Classify customer privacy data through a combination of automated tools and manual review, and assign security labels to each data item to draw a data flow map;

[0035] Step 102: Build a zero-trust security access control system based on identity authentication, use multi-factor authentication means to verify user identities, use micro-segmentation technology to restrict network lateral movement, and continuously monitor and audit all access behaviors;

[0036] Step 103: Deploy an AI-driven threat detection system, integrate internal and external threat intelligence, use machine learning algorithms to analyze user behavior patterns, and monitor abnormal activities in real time.

[0037] Preferably, in step 101, the customer privacy data is classified by combining an automated tool with manual review, and a security label is assigned to each data item to draw a data flow map. The specific steps are as follows:

[0038] Step A1: Use a data discovery tool to automatically scan the storage locations of the customer privacy data, and manually review the results of the automated scan to confirm the accuracy and integrity of the data. Record the confirmed data in the data asset management knowledge base, including the name, description, location, format, and owner information of the data, and classify the data in the data asset management knowledge base.

[0039] Step A2: Automatically assign a security label to each data item according to the content, importance, and usage of the data. Each security label can correspond to a different security level, and different security levels have different access control permissions. Draw a data flow map through the flow path of the data in the knowledge base. The data flow map can clearly show the entire life cycle of the data from collection, storage, processing to destruction.

[0040] Preferably, in step 102, a zero-trust security access control system based on identity authentication is constructed. Multifactor authentication means are used to verify the user identity, and micro-segmentation technology is used to restrict network lateral movement. All access behaviors are continuously monitored and audited to ensure that only authorized users and devices can access the customer privacy data. The specific steps are as follows:

[0041] Step B1: Identity authentication and multifactor authentication: Construct a dynamic and adaptive zero-trust security framework, combine multifactor authentication based on identity authentication with an intelligent device recognition mechanism, perform real-time identity verification before any access behavior occurs, and use AI technology to automatically evaluate the risk levels of users and devices and dynamically adjust access permissions. It further includes the following steps:

[0042] Step B101: The first factor: When the user accesses, first enter the username u and password p for identity verification.

[0043] Step B102: The second factor: When the username and password verification are passed, send a text message verification code v to the user's registered mobile phone. After the user receives the text message verification code, enter the verification code for verification.

[0044] Step B103, Third Factor: When the username and password are verified successfully and the verification code is also verified successfully, the user provides fingerprints and facial recognition for biometric verification. When the username, password, verification code, and biometric features all pass the verification, return f(u, p, v, b) = 1, indicating "authentication passed" and allowing access; when any factor fails the verification, return "authentication failed" and deny the user access, where u is the username, p is the password, v is the verification code, and b is the biometric data;

[0045] Step B2: Use micro-segmentation technology to partition users and protect data transmission through encrypted tunnels. Divide the network into multiple small, secure areas to limit lateral movement of the network and reduce the attack surface. Assign the minimum access permissions to each application and device. It further includes the following steps:

[0046] Step B201, Network Division and Segmentation: Divide the network into multiple regions according to the security level. Devices within each region can only access authorized services, and represent the access permissions between regions as a matrix where A[i, j] = 1 indicates that region i can access region j, otherwise A[i, j] = 0;

[0047] Step B202, Control Access Permissions: Inside each network region, configure different access control policies to strictly control the traffic between different regions, and use encrypted tunnels to protect the data transmission between network regions to prevent data from being tampered with during transmission.

[0048] Preferably, in step 103, deploy an AI-driven threat detection system, integrate internal and external threat intelligence, and use machine learning algorithms to analyze user behavior patterns and monitor abnormal activities in real time. The specific steps are as follows:

[0049] Step C1, Collect user behavior data, including network traffic data, system log data, and application log data, and clean the collected data to remove noise and outliers. The network traffic data includes source IP address, destination IP address, port number, protocol type, and traffic volume. The system log data includes user login logs, process startup logs, and file access logs. The application log data includes application access logs and error logs;

[0050] Step C2, Extract features from user behavior data, including user login frequency, access resource type, data transmission volume, and access time period, to train a machine learning model. It further includes the following steps:

[0051] Step C201, The user login frequency reflects the activity of the user logging in to the system. Within a period of time T, user u logs in n times, and the login frequency of the user is calculated as: where Flogin (u) represents the login frequency of user u, n represents the number of logins, and T represents the time window;

[0052] Step C202: Calculate the transmission volume according to user u and time window T as Where V data (u) is the total data transmission volume of user u within the time window T, and traffic i is the traffic volume of the i-th data transmission;

[0053] Step C203: Extract the access time feature by calculating the activity of the user in different time periods. The specific calculation formula is: Where T 1 , T 2 ,... are the divided time periods, and I(u, t) is an indicator of whether user u has activities in time period t. 1 indicates activity, and 0 indicates no activity;

[0054] Step C3: Anomaly detection: Use a machine learning algorithm to train a threat detection model from the extracted feature data. The behavior score output by model M is S(u, T) = Model(F login (u, T), F time (u, T), V data (u, T),...). When S(u, T) exceeds the threshold θ, it indicates abnormal behavior and activates the alarm mechanism. Where S(u, T) is the behavior score output by the model, and F login (u, T) represents the degree of abnormal behavior of user u within time period T, and V data (u, T) is the login frequency feature of user u within time period T, and F time (u, T) is the data transmission volume of user u within time period T, and is the activity of user u within time period T.

[0055] It should be noted that in the above embodiments, the descriptions of each embodiment have their own emphases. For the parts not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0056] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0057] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and combinations of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general purpose computer, special purpose computer, embedded computer, or other programmable data processing device to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing device generate means for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.

[0058] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including instruction means for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.

[0059] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one flow Figure 1 one flow or multiple flows and / or blocks Figure 1 or means for implementing the functions specified in one block or multiple blocks.

[0060] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made to these embodiments by those skilled in the art once they learn of the basic inventive concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present invention.

[0061] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A method for protecting customer privacy data, characterized in that: The specific steps include: Step 101: Classify customer privacy data by combining automated tools with manual review, and assign security labels to each data item to draw a data flow map; Step 102: Build a zero-trust security access control system based on identity authentication, use multi-factor authentication to verify user identity, use micro-isolation technology to limit lateral network movement, and continuously monitor and audit all access behaviors; Step 103: Deploy an AI-driven threat detection system, integrate internal and external threat intelligence, use machine learning algorithms to analyze user behavior patterns, and monitor abnormal activities in real time.

2. A method for protecting customer privacy data according to claim 1, characterized in that: In step 101, the customer privacy data is classified by combining automated tools with manual review, and a security label is assigned to each data item to draw a data flow map. The specific steps are as follows: Step A1: Use data discovery tools to automatically scan the storage location where customer privacy data is stored, and manually review the results of the automated scan. Record the confirmed data in the data asset management knowledge base, including the name, description, location, format, and owner information of the data, and classify the data in the data asset management knowledge base; Step A2: Automatically assign security labels to each data item based on the content, importance and usage of the data. Each security label can correspond to a different security level. Different security levels have different access control permissions. Draw a data flow map based on the flow path of the data in the knowledge base. The data flow map can clearly display the entire life cycle of data from collection, storage, processing to destruction.

3. A method for protecting customer privacy data according to claim 1, characterized in that: In step 102, a zero-trust security access control system based on identity authentication is constructed, multi-factor authentication is used to verify user identity, micro-isolation technology is used to limit lateral network movement, and all access behaviors are continuously monitored and audited. The specific steps are as follows: Step B1, identity authentication and multi-factor authentication: Build a dynamic and adaptive zero-trust security framework, combining identity-based multi-factor authentication and smart device recognition mechanisms to perform real-time identity authentication before any access behavior occurs; Step B2: Use micro-segmentation technology to partition users and protect data transmission through encrypted tunnels, divide the network into multiple small, secure areas to limit lateral movement of the network, reduce the attack surface, and assign minimum privilege access to each application and device.

4. A method for protecting customer privacy data according to claim 3, characterized in that: In the identity authentication and multi-factor authentication of step B1, the multi-factor authentication based on identity authentication and the smart device identification mechanism are combined to perform real-time identity authentication before any access behavior occurs, further comprising the following steps: Step B101, first factor: when accessing, the user first enters the user name u and password p for identity authentication; Step B102, second factor: when the user name and password are verified, a text message verification code v is sent to the user's registered mobile phone. After receiving the text message verification code, the user enters the verification code for verification; Step B103, the third factor: when the username and password are verified and the verification code is verified successfully, the user provides fingerprint and facial recognition for biometric verification. When the username, password, verification code and biometrics are all verified, f(u, p, v, b) = 1 is returned, indicating "authentication passed", and access is allowed; when any factor verification fails, "authentication failed" is returned and the user access is denied, where u is the username, p is the password, v is the verification code, and b is the biometric data.

5. A method for protecting customer privacy data according to claim 3, characterized in that: In step B2, micro-isolation technology is used to partition users, and data transmission is protected through encrypted tunnels, further comprising the following steps: Step B201, network division and separation: divide the network into multiple areas according to security levels. Devices in each area can only access authorized services, and the access rights between areas are represented by a matrix. Where A[i,j]=1 means that region i can access region j, otherwise A[i,j]=0; Step B202, control access rights: configure different access control policies within each network area, strictly control the traffic between different areas, use encrypted tunnels to protect data transmission between network areas, and prevent data from being tampered with during transmission.

6. A method for protecting customer privacy data according to claim 1, characterized in that: In step 103, an AI-driven threat detection system is deployed to integrate internal and external threat intelligence, analyze user behavior patterns using machine learning algorithms, and monitor abnormal activities in real time. The specific steps are as follows: Step C1: Collect user behavior data, including network traffic data, system log data, and application log data, and clean the collected data to remove noise and outliers; Step C2: extracting features from user behavior data, including user login frequency, access resource type, data transmission volume, and access time period, to train a machine learning model; Step C3, anomaly detection: Use machine learning algorithms to train threat detection models from the extracted feature data. The behavior score output by model M is S(u,T)=Model(F login (u,T),F time (u,T),V data (u,T),...), when S(u,T) ​​exceeds the threshold θ, it indicates abnormal behavior and the alarm mechanism is activated, where S(u,T) ​​is the behavior score output by the model, and F login (u,T) ​​represents the abnormal behavior of user u in time period T, V data (u,T) ​​is the login frequency feature of user u in time period T, F time (u,T) ​​is the data transmission volume of user u in time period T, and is the activity of user u in time period T.

7. A method for protecting customer privacy data according to claim 6, characterized in that: In the step C2, features are extracted from the user behavior data, including user login frequency, access resource type, data transmission volume, and access time period, to train the machine learning model, further comprising the following steps: Step C201: The user login frequency reflects the activity of the user logging into the system. Within a period of time T, user u logs in n times. The user login frequency is calculated as: where F login (u) represents the login frequency of user u, n represents the number of logins, and T represents the time window; Step C202: According to user u and time window T, the transmission amount is calculated as Among them, V data (u) is the total data transmission volume of user u in time window T, traffic i is the flow rate of the i-th data transmission; Step C203: extract access time features by calculating the user's activity in different time periods. The specific calculation formula is: Among them, T1, T2, ... are divided time periods, and I(u,t) is an indicator of whether user u has activity in time period t, 1 indicates activity and 0 indicates no activity.

Citation Information

Patent Citations

  • Zero-trust security protection system and protection method

    CN114465814A

  • Zero-trust network construction method and system

    CN117811764A

  • Network information security analysis method and system based on data analysis

    CN118784348A

  • Data security analysis method and intelligent calculation data security workstation

    CN119249440A

  • Internet data security protection method and system based on intelligent algorithm

    CN119272339A