Power internet sensitive personal information compliance risk early warning method and system

By using AI models to evaluate the compliance risks of sensitive personal information in the power Internet business, the problem of compliance relies on manual judgment and lack of fine-grained assessment in the prior art is solved, and more efficient and accurate compliance risk warnings are achieved.

CN120145451APending Publication Date: 2025-06-13国家电网有限公司客户服务中心
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510311778.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-17
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

When processing sensitive personal information, existing power Internet services rely on manual judgments, which are prone to subjective misjudgments and lack independent assessments and compliance risk warnings for the types of minimal granularity information.

Method used

A risk warning method for compliance with sensitive personal information in the power Internet is adopted. By calling a pre-trained AI model, inputting sensitive personal information types and information processing stages, the user's rights impact weight and security guarantee level are obtained respectively. Then, the second AI model is called to calculate the compliance risk level, and warning information is issued based on the risk level.

Benefits of technology

It improves the accuracy and efficiency of sensitive information compliance work, reduces the dependence on the personal experience and subjective misjudgment of auditors, ensures that compliance assessment uses a unified standard process, and can conduct differentiated assessments and early warnings for different information types.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145451A_ABST
    Figure CN120145451A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, in particular to a power internet sensitive personal information compliance risk early warning method and system. The risk early warning method comprises the following steps: acquiring sensitive personal information types of power internet users; determining a personal information processing stage of the sensitive personal information type; calling a first AI model, inputting a sensitive personal information type and an information processing stage, and respectively obtaining a user right influence weight and a safety guarantee level corresponding to the sensitive personal information type; calling a second AI model, and inputting a user right influence weight and a safety guarantee level to obtain a sensitive personal information compliance risk level; and sending risk early warning information according to the compliance risk level. According to the invention, compliance evaluation and early warning can be automatically carried out on sensitive personal information of the power internet, and the accuracy of compliance work is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and particularly to a method and system for early warning of compliance risks of sensitive personal information in the power Internet. Background Art

[0002] With the continuous development of various APPs and mini-programs, illegal acts of collecting and using personal information occur frequently. The security of sensitive personal information such as ID numbers, fingerprints, and faces has attracted the attention of the majority of Internet users. Once leaked, it will seriously infringe on the personal and property safety of users. China has formed a legal system for personal information protection with the Personal Information Protection Law as the core and the Cybersecurity Law, the E-commerce Law, and the Data Security Law as important references. The Personal Information Protection Law defines sensitive information and puts forward relevant protection requirements. The power industry is an important pillar industry of China's national economy. In recent years, the combination of power and the Internet has provided various convenient services for users, and at the same time, a large amount of user personal information has been collected. How to ensure the legality and compliance of the collection and use of sensitive personal information and how to prevent risks during the use process will become particularly important. At present, the difficulties in handling sensitive information in power Internet services mainly focus on the following aspects:

[0003] (1) The compliance basis for the collection and use of existing sensitive personal information is generally judged manually, relying on the experience and professional qualities of auditors, which is prone to subjective misjudgment or inability to fully cover all standards.

[0004] (2) There are various types of sensitive personal information. In specific usage scenarios, it is impossible to independently evaluate the smallest granularity type of sensitive personal information, lacking compliance risk warning weight values, and unable to achieve fine-grained differential evaluation and warning.

[0005] (3) Based on the business characteristics of the power Internet itself, some electricity consumption information is sensitive and should also be protected as sensitive personal information.

[0006] In summary, it is very urgent to develop a method and system for early warning of compliance risks of sensitive personal information in the power Internet. Summary of the Invention

[0007] The present invention aims to provide a method and system for early warning of compliance risks of sensitive personal information in the power Internet to solve the above technical problems and improve the accuracy and efficiency of compliance work. The specific technical solutions are as follows:

[0008] A method for early warning of compliance risks of sensitive personal information in the power Internet includes the following processes:

[0009] S100: Obtain the types of sensitive personal information of power Internet users;

[0010] S200: Determine the personal information processing stage where the type of sensitive personal information is located;

[0011] S300: Invoke the first AI model, input the type of sensitive personal information and the information processing stage, and respectively obtain the user rights and interests impact weight and security guarantee level corresponding to the type of sensitive personal information;

[0012] S400: Invoke the second AI model, input the user rights and interests impact weight and the security guarantee level, and obtain the compliance risk level of sensitive personal information;

[0013] S500: Send a risk warning message according to the compliance risk level.

[0014] Preferably, in S100, the type of sensitive personal information of power Internet users is the sensitive personal information provided by users when using a certain electricity application scenario, including: biometric identification, document information, medical and health information, personal property information, whereabouts trajectory, and highly sensitive power data information within the power system.

[0015] Preferably, the biometric identification information includes: fingerprint, iris, facial recognition features; the document information includes: ID card, household register, military officer's certificate, passport, real estate certificate, social security card; the personal property information includes: bank account, power Internet transaction and consumption records, virtual property information.

[0016] Preferably, in S200, the personal information processing stage includes the collection, storage, use, processing, transmission, provision, disclosure, and deletion of personal information.

[0017] Preferably, in S300, the AI model is a pre-trained convolutional neural network model; the information processing stage includes collection, storage, use, processing, transmission, provision, disclosure, and deletion.

[0018] Preferably, in S400, the risk levels are preset to three levels: no risk, general risk, and serious risk.

[0019] Preferably, in S500, the warning message includes any one or more of the following methods: information pop-up window, prohibited operation, sound and light signal; the warning content includes an explanation of the user rights and interests impact weight and the security guarantee level of sensitive personal information.

[0020] A compliance risk warning system for sensitive personal information in the power Internet includes:

[0021] A personal information type acquisition module, which is used to acquire the type of sensitive personal information of power Internet users;

[0022] A personal information processing stage determination module, which is used to determine the personal information processing stage where the type of sensitive personal information is located;

[0023] The first AI model module is used to call the first AI model, input the types of sensitive personal information and the information processing stages, and respectively obtain the user rights and interests impact weights and security guarantee levels corresponding to the types of sensitive personal information;

[0024] The second AI model module is used to call the second AI model, input the user rights and interests impact weights and security guarantee levels, and obtain the compliance risk levels of sensitive personal information;

[0025] The early warning module is used to send risk early warning information according to the compliance risk levels.

[0026] The present invention provides a method and system for early warning of compliance risks of sensitive personal information in the power Internet, which improves the accuracy of compliance work for sensitive information in the power Internet and reduces the disadvantages of personal experience and subjective misjudgment of auditors.

[0027] Based on preset rules and models for analysis, the present invention can ensure that the compliance assessment and early warning of all sensitive personal information are analyzed using a unified standard process, obtain different compliance risk levels according to the rights and interests impact values and security guarantee levels corresponding to different sensitive information, and give different early warning methods at different business stages, so that the compliance risk early warning is comprehensive and flexible.

[0028] Based on preset rules and models for analysis, the present invention can cover the most fine-grained types of sensitive personal information, and at the same time, combined with the business of the power Internet, conduct compliance risk early warning on the use of sensitive information in the power Internet. Brief Description of the Drawings

[0029] Figure 1 It is a schematic flow chart of a method for early warning of compliance risks of sensitive personal information in the power Internet according to the present invention. Detailed Embodiments

[0030] Explanation of Related Terms:

[0031] Personal information: Personal information is various information related to an identified or identifiable natural person recorded in electronic or other forms, excluding information after anonymization processing.

[0032] Sensitive personal information: Sensitive personal information is personal information that is likely to cause infringement of the personal dignity of a natural person or endanger the personal and property safety of a natural person once leaked or illegally used, including biometric identification, religious belief, specific identity, medical and health, financial account, whereabouts trajectory and other information, as well as personal information of minors under the age of fourteen.

[0033] Personal information processing stage: It includes collection, storage, use, processing, transmission, provision, disclosure, deletion, etc. of personal information.

[0034] AI model: It refers to a model trained through machine learning or deep learning technologies, capable of simulating human intelligent behaviors and completing various tasks, such as language processing, image recognition, natural language generation, etc.

[0035] A compliance risk warning method for sensitive personal information in the power Internet of Things includes the following processes:

[0036] S100: Obtain the types of sensitive personal information of power Internet of Things users; the types of sensitive personal information of power Internet of Things users are the sensitive personal information provided by users when using a certain electricity application scenario, including: biometric identification, document information, medical health, personal property information, whereabouts trajectory, and highly sensitive power data within the power system, etc. The types can be specifically subdivided. Biometric identification information includes fingerprints, irises, facial recognition features, etc.; document information includes ID cards, household registers, military officer certificates, passports, real estate registration certificates, social security cards, etc.; personal property information includes bank accounts, power Internet of Things transaction and consumption records, virtual property information, etc. The impact on personal rights and interests of the processing of each of the above information categories is different.

[0037] S200: Determine the personal information processing stage where the sensitive personal information type is located; the personal information processing stage includes the collection, storage, use, processing, transmission, provision, disclosure, deletion, etc. of personal information. There are relevant regulations in national relevant standards for processing sensitive information at each of the above stages. In the actual application of the power Internet of Things, according to the personal information processing regulations of the State Grid Corporation and the actual business needs, each type of personal information has a specific mapping relationship with the personal information processing stage. After obtaining the personal information type, the specific requirements at which stage of personal information processing can be determined accordingly.

[0038] S300: Invoke the first AI model, input the sensitive personal information type and the information processing stage, and respectively obtain the user rights and interests impact weight and security guarantee level corresponding to the sensitive personal information type; the AI model is a pre-trained convolutional neural network model. The specific training method of the AI model includes: obtaining multiple sensitive personal information samples, summarizing the sensitive personal information in the actual electricity application business according to the Personal Information Protection Law of the People's Republic of China, the national standard Information Security Technology - Personal Information Security Specification, and the personal information protection related regulations of the State Grid Corporation. The specific types of sensitive information are such as fingerprints, irises, facial recognition features, ID cards, household registers, bank accounts, power Internet of Things transaction and consumption records, virtual property information, etc. Use the multiple sample data as the training data set and the test data set, and accordingly input the sample data in the training data set into the convolutional neural network, and adjust the parameters according to the results. Input the test data set. If the calculation result of the test data set meets the result requirements, complete the training of the first AI model.

[0039] S400: Call the AI model, input the types of sensitive personal information and the information processing stages, and obtain the user rights and interests impact weights and security guarantee levels. The information processing stages include collection, storage, use, processing, transmission, provision, disclosure, and deletion, and each stage has specific requirements for sensitive information. For example, in the stage of collecting sensitive personal information, the express consent of the personal information subject should be obtained, and it should be ensured that the express consent of the personal information subject is an autonomous, specific, clear and explicit expression of will on the basis of full knowledge. Before collecting personal biometric information, the personal information subject should be separately informed of the purposes, methods, and scopes of collecting and using personal biometric information, as well as rules such as storage time, and the express consent of the personal information subject should be obtained. In the transmission and storage stages, security measures such as encryption should be adopted, and in principle, the original personal biometric information should not be stored. After using facial recognition features, fingerprints, palm prints, iris, etc. to implement functions such as identity recognition and authentication, the original images that can extract personal biometric information should be deleted. The user rights and interests impact weights are classified into minor weight levels with reference to the classification in the "APP User Rights and Interests Protection Evaluation Specification" of the Ministry of Industry and Information Technology and the actual business situation of the power Internet industry, as follows:

[0040]

[0041] According to the classification of the impact degree of data in the national standard "Data Security Technology - Data Classification and Grading Rules", the security guarantee levels can be divided into general, serious, and especially serious.

[0042] S400: Call the second AI model, input the user rights and interests impact weights and security guarantee levels, and obtain the compliance risk levels of sensitive personal information; the second AI model is trained through a convolutional neural network, and the training method includes: dividing the data set into a training set and a test set, using multiple user rights and interests impact weights and security guarantee level sample data as the training data set and the test data set, and then inputting the sample data in the training data set into the convolutional neural network, and adjusting the parameters according to the results. Input the test data set, and if the calculation results of the test data set meet the result requirements, the training of the second AI model is completed.

[0043] Input the user rights and interests impact weights and security guarantee levels into the second AI model, and output the compliance risk levels of sensitive personal information, which are preset to three levels: no risk, general risk, and serious risk. The risk levels are mainly determined according to relevant national standards and the highest risk items in the user rights and interests impact weights and security guarantee levels respectively.

[0044] S500: Issue a risk warning message according to the compliance risk level; output a warning message according to the severity of the compliance risk level. The warning methods include: information pop-up window, prohibited operation, sound and light signal. The warning content includes the impact weight of the rights and interests of users of sensitive personal information and an explanation of the security guarantee level, and the operator is informed of the compliance risk level of sensitive personal information and the specific reasons for the trigger through the warning prompt and specific prompt information.

Claims

1. A compliance risk warning method for sensitive personal information in the electric power internet, characterized in that: The process includes the following: S100: Obtaining sensitive personal information types of power Internet users; S200: Determine the personal information processing stage of the sensitive personal information type; S300: calling the first AI model, inputting the sensitive personal information type and the information processing stage, and obtaining the user rights impact weight and security level corresponding to the sensitive personal information type; S400: calling the second AI model, inputting the user rights impact weight and security level, and obtaining the compliance risk level of sensitive personal information; S500: Issue risk warning information based on compliance risk level.

2. According to claim 1, a compliance risk warning method for sensitive personal information in the electric power internet is characterized in that: In S100, the sensitive personal information type of the power Internet user is the sensitive personal information provided by the user when using a certain power application scenario, including: biometrics, certificate information, medical health, personal property information, whereabouts, and highly sensitive power data information within the power system.

3. According to claim 2, a compliance risk warning method for sensitive personal information in the electric power internet is characterized in that: The biometric information includes: fingerprints, irises, and facial recognition features; the certificate information includes: identity card, household register, military officer certificate, passport, real estate registration certificate, and social security card; the personal property information includes: bank accounts, power Internet transactions and consumption records, and virtual property information.

4. According to claim 1, a compliance risk warning method for sensitive personal information in the electric power internet is characterized in that: In S200, the personal information processing stage includes the collection, storage, use, processing, transmission, provision, disclosure, and deletion of personal information.

5. According to claim 1, a compliance risk warning method for sensitive personal information in the electric power internet is characterized in that: In S300, the AI ​​model is a pre-trained convolutional neural network model; the information processing stage includes collection, storage, use, processing, transmission, provision, disclosure, and deletion.

6. According to claim 1, a compliance risk warning method for sensitive personal information in the electric power internet is characterized in that: The risk level in S400 is preset into three levels: no risk, general risk, and severe risk.

7. According to claim 1, a compliance risk warning method for sensitive personal information in the electric power internet is characterized in that: The warning information in S500 includes any one or more of the following methods: information pop-up window, prohibited operation, sound and light signal; the warning content includes the impact weight of sensitive personal information user rights and interests and the security level description.

8. A compliance risk early warning system for sensitive personal information in the electric power internet, characterized in that: include: A personal information type acquisition module is used to obtain the sensitive personal information types of power Internet users; A personal information processing stage determination module, used to determine the personal information processing stage that a sensitive personal information type is in; The first AI model module is used to call the first AI model, input the sensitive personal information type and the information processing stage, and obtain the user rights impact weight and security level corresponding to the sensitive personal information type; The second AI model module uses the phrase to call the second AI model, inputs the user rights impact weight and security level, and obtains the compliance risk level of sensitive personal information; The early warning module is used to issue risk warning information based on the compliance risk level.