Data privacy protection method and system based on zero trust principle
By adopting a method based on the principle of zero trust in data protection, including technical means such as identity authentication, encryption, continuous monitoring and data desensitization, the problem of traditional data protection methods lacking fine-grained and dynamic verification is solved, and a stronger data privacy protection capability is achieved.
Patent Information
- Application Number
- CN202510245558.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-06-20
AI Technical Summary
Traditional data protection methods lack fine-grained and dynamic continuous verification, making it difficult to effectively prevent data breaches and abuse.
Using a zero-trust principle approach, it uses an authentication to users, use encryption algorithms during data transmission, continuously monitor user and device behavior, desensitize and anonymize sensitive data, and collect and analyze log data to detect abnormal behavior.
It realizes a fine-grained authorization strategy for data, dynamically adjusts access rights, reduces the risk of data leakage and abuse, and strengthens data privacy protection capabilities.
Smart Images

Figure CN120180489A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data privacy protection, and more specifically, to a data privacy protection method and system based on the zero-trust principle. Background Art
[0002] In the digital age, data privacy protection has become a globally prominent focus topic. With the rapid development of technologies such as the Internet, big data, and artificial intelligence, individuals and enterprises have generated a large amount of data, which contains huge value. However, at the same time, problems such as data leakage and abuse have become increasingly frequent, bringing serious risks to people's lives and enterprise operations.
[0003] The zero-trust concept is a security idea and method based on dynamic policies. It emphasizes taking data resources as the center and formulating fine-grained authorization policies for the data to be protected. These policies are constructed through the multi-dimensional attributes of the subject, object, and environment and are continuously evaluated.
[0004] However, when traditional data protection methods are actually used, there are still some drawbacks. For example, traditional security protection methods and ideas generally perform coarse-grained and static authentication and authorization at the boundary or network level, lacking fine-grained and dynamic continuous verification for data. Summary of the Invention
[0005] In order to overcome the above-mentioned defects of the prior art, embodiments of the present invention provide a data privacy protection method and system based on the zero-trust principle to solve the problems raised in the above background art.
[0006] To achieve the above object, the present invention provides the following technical solutions:
[0007] Step A1: Authenticate the user who requests to access the data, and verify the user's identity information and access permissions;
[0008] Step A2: During the process of data transmission from the source end to the destination end, use an encryption algorithm to encrypt the data;
[0009] Step A3: Continuously monitor the behaviors and environmental information of the user, device, and application, and dynamically adjust the access permissions according to the real-time risk assessment results;
[0010] Step A4: For sensitive data during storage and processing, use desensitization technology and anonymization algorithms to process the data so that the processed data cannot be directly associated with specific individuals and organizations, protecting the privacy of the data subject;
[0011] Step A5: Collect the operation logs and data access logs within the system, and use an audit analyzer to analyze and mine the collected logs.
[0012] Preferably, in step A1, when the user registers in the system, the user provides identity information such as username, password, email address, mobile phone number, etc.; the user registers biometric information such as fingerprints and facial recognition data, and the system generates a security token for the user, and the user can receive the token through a mobile application or a hardware device.
[0013] Preferably, in step A2, the steps of using the encryption algorithm are specifically as follows:
[0014] Step B1: Select a quantum state. The sender A prepares qubits and selects two bases for encoding; the base states are divided into α and β, and the superposition states are divided into C and D. The specific calculation method of C in the superposition state is as follows:
[0015] where C represents the C state in the superposition state, α represents the α state in the base state, and β represents the β state in the base state;
[0016] The specific calculation method of D in the superposition state is as follows:
[0017] where D represents the D state in the superposition state, α represents the α state in the base state, and β represents the β state in the base state;
[0018] Step B2: Send the selected qubits to the receiver B through a quantum channel. The qubits received by the receiver are n, and the received qubits are measured. The qubit n includes α and β in the base state, and C and D in the superposition state;
[0019] Step B3: After measurement, verify the security of the newly arrived data. The specific calculation method of the qubit error rate is as follows:
[0020] where E represents the qubit error rate, M represents the number of error bits detected, and N represents the total number of bits sent;
[0021] The qubit error rate affects the length of the security key. The specific calculation method of the key length is as follows:
[0022] L = N(1 - H(E)), where L represents the key length, N represents the total number of bits sent, and H(E) represents the entropy;
[0023] The specific calculation method of the entropy is as follows:
[0024] H(E) = -Elog2 E - (1 - E)log2(1 - E), where H(E) represents the entropy and E represents the qubit error rate;
[0025] The data is encrypted through steps B1 to B3.
[0026] Preferably, in step A3, monitor the user's login time, location, access frequency, and operation mode, and detect whether there are any abnormal behaviors, such as: logging in from a different location, accessing sensitive data during non-working hours, etc.
[0027] Check the security of the device, including the operating system version, security patch update status, and whether there is any malware; monitor the network environment, geographical location, and the connection status between the device and the network to ensure that the access request comes from a secure environment.
[0028] Analyze the monitored user behaviors, device status, and environmental information through a rule-based algorithm to evaluate the risk level of the current access request.
[0029] Preferably, in step A4, audit the existing data sources to identify sensitive data, perform desensitization using the desensitization technique of character replacement, and formulate corresponding desensitization rules for different data fields; install the Delphix Engine in the cloud environment or on the local server, set the network and security configurations of Delphix, connect to the original data source through the Delphix management console, and select the dataset to be desensitized;
[0030] Create a desensitization template in Delphix, apply the formulated desensitization rules, and configure the corresponding desensitization methods according to the field type; create a desensitization job based on the configured desensitization template; run the desensitization job and monitor its execution status; check the desensitized data: verify the desensitized data to ensure that the sensitive information has been effectively desensitized; ensure that the desensitized data is consistent with the original data in logic and format.
[0031] Preferably, in step A5, collect the operation logs and data access logs within the system, including behaviors such as user login, data access, and permission changes; for data access activities, generate detailed data access logs for both internal users and external requests; these logs should include access time, IP address, device ID, access target, access type, and access result information; the collected logs should be stored in a centralized log management system for subsequent analysis and auditing; at the same time, take encryption and access control measures to protect the security and integrity of the log data; the audit analyzer should preprocess the collected logs, including log cleaning, deduplication, formatting, etc., to improve the analysis efficiency and accuracy; the audit analyzer should identify normal operation behavior patterns and data access patterns; this helps to discover abnormal or suspicious behavior patterns, such as frequent failed login attempts and a large amount of data access during non-working hours; based on the preset security policies and rules, the audit analyzer should perform real-time detection on the abnormal behaviors or potential threats in the logs and generate corresponding warning information; these warning information contain detailed abnormal descriptions, the scope of influence, and recommended handling measures;
[0032] Use the big data analysis tool Splunk to monitor and analyze log data in real time; identify abnormal transaction flows and potential risks through the log analysis tool EY Helix; according to the analysis results, evaluate the risk level of data access behavior, and take corresponding response measures.
[0033] Technical effects and advantages of the present invention:
[0034] The present invention strictly authenticates the users accessing the data, including passwords, biometrics, etc., and determines their roles and permissions. During the data transmission process, encryption algorithms are used to ensure security, and the quantum state selection and encryption steps are detailed. At the same time, continuously monitor the behaviors of users, devices, and applications, and dynamically adjust permissions to reduce risks. Desensitize and anonymize sensitive data to protect personal privacy. Finally, by collecting and analyzing operation logs and access logs, detect abnormal behaviors in a timely manner and give early warnings; the present invention strengthens the data privacy protection ability, formulates fine-grained authorization policies for the data to be protected, and effectively prevents data leakage and abuse. Description of the Drawings
[0035] Figure 1 It is a schematic diagram of the method flow of the present invention.
[0036] Figure 2 It is a schematic diagram of the module connection of the present invention. Detailed Embodiments
[0037] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0038] Please refer to Figure 1 As shown, the present invention provides a data privacy protection method based on the zero-trust principle, and its method is as follows:
[0039] Step A1: Authenticate the user who requests to access the data, and verify the user's identity information and access permissions;
[0040] In the said step A1, when the user registers in the system, the user provides identity information, such as username, password, email address, mobile phone number, etc.; the user registers biometric information, such as fingerprint, facial recognition data, and the system generates a security token for the user, and the user can receive the token through a mobile application or a hardware device;
[0041] When the user logs in, the user enters identity information, which includes a username and a password, and the system verifies whether the password entered by the user is correct;
[0042] The system queries the user's role to determine the role to which the user belongs; the system queries the permissions of the role to determine the data and operations that the role can access; the system maintains a permission list, and each permission corresponds to an operation; a role is assigned a set of permissions, and these permissions define the data and operations that the role can access.
[0043] The system queries the permissions of the role to determine the data and operations that the role can access. The permission information is usually stored in the role database.
[0044] Step A2: During the process of data transmission from the source end to the destination end, an encryption algorithm is used to encrypt the data;
[0045] In the said step A2, the steps of using the encryption algorithm are specifically as follows:
[0046] Step B1: Select a quantum state. The sender A prepares qubits and selects two bases for encoding; the base states are divided into α and β, and the superposition states are divided into C and D. The specific calculation method of C in the superposition state is as follows:
[0047] Wherein, C represents the C state in the superposition state, α represents the α state in the base state, and β represents the β state in the base state;
[0048] The specific calculation method of D in the superposition state is as follows:
[0049] Wherein, D represents the D state in the superposition state, α represents the α state in the base state, and β represents the β state in the base state;
[0050] Step B2: Send the selected qubits to the receiver B through the quantum channel. The qubits received by the receiver are n, and the received qubits are measured. The qubit n includes α and β in the base state, and C and D in the superposition state;
[0051] After measurement, to verify the security of the newly arrived, the specific calculation method of the qubit error rate is as follows:
[0052] Wherein, E represents the qubit error rate, M represents the number of error bits detected, and N represents the total number of bits sent;
[0053] The qubit error rate affects the length of the security key, and the specific calculation method of the key length is as follows:
[0054] L = N(1 - H(E)), where L represents the key length, N represents the total number of bits sent, and H(E) represents the entropy;
[0055] The specific method for calculating entropy is as follows:
[0056] H(E) = -E log2 E - (1 - E) log2(1 - E), where H(E) represents the entropy and E represents the quantum bit error rate;
[0057] The data is encrypted through steps B1 to B3.
[0058] Step A3: Continuously monitor the behaviors and environmental information of users, devices, and applications, and dynamically adjust the access permissions according to the real-time risk assessment results;
[0059] In the said step A3, monitor the user's login time, location, access frequency, and operation mode, and detect whether there are abnormal behaviors, such as: logging in from a different location, accessing sensitive data during non-working hours, etc.
[0060] Check the security of the device, including the operating system version, security patch update status, and whether there is malware; monitor the network environment, geographical location, and the connection status between the device and the network to ensure that the access request comes from a secure environment.
[0061] Through a rule-based algorithm, analyze the monitored user behaviors, device status, and environmental information to evaluate the risk level of the current access request; the specific method for calculating the risk value is as follows:
[0062] K = K1 + K2 + K3 + K4 + K5 + K6, where K represents the risk value, K1 represents the user abnormal access value, K2 represents the device network abnormal value, K3 represents the application response time value, K4 represents the network environment value, K5 represents the application error rate value, and K6 represents the physical environment value;
[0063] For abnormal access patterns, set non-working hours, which are from 20:00 to 7:00 the next day. If a user accesses sensitive data during non-working hours, K1 takes 10; for frequent access, if the same sensitive data is accessed more than 10 times within 1 hour, K1 takes 15; for data operation behaviors, if more than 100 sensitive records are deleted or modified at one time, K1 takes 20;
[0064] For network connection abnormalities, when the packet loss rate exceeds 20% within 1 minute, K2 takes 15, and when there are more than 5 bad sectors in the hard disk during a hardware failure, K2 takes 20;
[0065] When the application response time is extended by more than 50% compared to the average response time and lasts for more than 10 minutes, K3 takes 10, and when the error rate increases by more than 10%, K5 takes 10;
[0066] When an IP address from a high-risk area accesses, K4 is assigned 20 points. High-risk areas are identified as regions with a high incidence of network attacks; when the temperature in the data center exceeds 30°C for more than 1 hour, K6 is assigned 5;
[0067] The risk levels are divided into low-risk level, medium-risk level, and high-risk level. Among them, the calculated risk value within 0 - 20 is the low-risk level, the calculated risk value within 21 - 40 is the medium-risk level, and the calculated risk value of 41 and above is the high-risk level;
[0068] Based on the user's activities, historical behaviors, and the environment they are in, assign a risk score to the user and adjust the security policy accordingly;
[0069] Use user and entity behavior analysis technology to detect abnormal activities.
[0070] Step A4: For sensitive data during storage and processing, use desensitization technology and anonymization algorithms to process the data so that the processed data cannot be directly associated with specific individuals and organizations, protecting the privacy of data subjects;
[0071] In the said step A4, audit the existing data sources, identify sensitive data, use character replacement desensitization technology for desensitization, and formulate corresponding desensitization rules for different data fields; install DelphixEngine on the cloud environment or local server, set the network and security configurations of Delphix, connect to the original data source through the Delphix management console, and select the data set to be desensitized;
[0072] Create a desensitization template in Delphix, apply the formulated desensitization rules, configure the corresponding desensitization methods according to the field type; based on the configured desensitization template, create a desensitization job; run the desensitization job and monitor its execution status; check the desensitized data: verify the desensitized data to ensure that sensitive information has been effectively desensitized; ensure that the desensitized data is consistent with the original data in logic and format.
[0073] Use the desensitized data to verify the application functions to ensure normal operation and data integrity in the real environment; publish the desensitized data to the development, testing, or other non-production environments; use the data virtualization function of Delphix for real-time data updates; ensure that only authorized personnel can access the desensitized data.
[0074] Step A5: Collect the operation logs and data access logs within the system, and use an audit analyzer to analyze and mine the collected logs;
[0075] In step A5, operation logs and data access logs within the system are collected, including behaviors such as user logins, data accesses, and permission changes; for data access activities, detailed data access logs are generated for both internal users and external requests; these logs should include access time, IP address, device ID, access target, access type, and access result information; the collected logs should be stored in a centralized log management system for subsequent analysis and auditing; meanwhile, encryption and access control measures are taken to protect the security and integrity of the log data; the audit analyzer should preprocess the collected logs, including log cleaning, deduplication, formatting, etc., to improve the analysis efficiency and accuracy; the audit analyzer should identify normal operation behavior patterns and data access patterns; this helps to discover abnormal or suspicious behavior patterns, such as frequent failed login attempts and a large number of data accesses during non-working hours; based on preset security policies and rules, the audit analyzer should conduct real-time detection of abnormal behaviors or potential threats in the logs and generate corresponding warning messages; these warning messages contain detailed abnormal descriptions, the scope of influence, and recommended handling measures.
[0076] Use the big data analysis tool Splunk to conduct real-time monitoring and analysis of the log data; identify abnormal transaction flows and potential risks through the log analysis tool EY Helix; according to the analysis results, evaluate the risk level of the data access behavior and take corresponding response measures.
[0077] Please refer to Figure 2 As shown, in this embodiment, it should be specifically noted that the present invention provides a data privacy protection system based on the zero-trust principle, including the following modules:
[0078] Verification module: used to authenticate the identity of users requesting access to data, and verify the identity information and access permissions of users.
[0079] Encryption module: used to encrypt the data using an encryption algorithm during the process of data transmission from the source end to the destination end.
[0080] Access control module: used to continuously monitor the behaviors and environmental information of users, devices, and applications, and dynamically adjust access permissions based on real-time risk assessment results.
[0081] Data processing module: used to process sensitive data during storage and processing using desensitization techniques and anonymization algorithms, so that the processed data cannot be directly associated with specific individuals and organizations, protecting the privacy of data subjects.
[0082] Log analysis module: collect operation logs and data access logs within the system, and use an audit analyzer to analyze and mine the collected logs.
[0083] Finally, the above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A data privacy protection method based on the zero trust principle, characterized in that: include: Step A1: Authenticate the user who requests to access the data and verify the user's identity information and access rights; Step A2: In the process of transmitting data from the source end to the destination end, an encryption algorithm is used to encrypt the data; Step A3: Continuously monitor the behavior and environment information of users, devices, and applications, and dynamically adjust access rights based on real-time risk assessment results; Step A4: For sensitive data in the storage and processing process, desensitization technology and anonymization algorithms are used to process the data so that the processed data cannot be directly associated with specific individuals and organizations, thereby protecting the privacy of the data subject; Step A5: Collect operation logs and data access logs in the system, and use the audit analyzer to analyze and mine the collected logs.
2. According to claim 1, a data privacy protection method based on the zero trust principle is characterized in that: In step A1, when a user registers in the system, he / she provides identity information, such as user name, password, email address, mobile phone number, etc.; the user registers biometric information, such as fingerprint and facial recognition data, and the system generates a security token for the user, which the user can receive through a mobile phone application or hardware device; When a user logs in, the user enters identity information, which includes a user name and password. The system verifies whether the password entered by the user is correct; The system queries the user's role and determines the role to which the user belongs; The system queries the role's permissions to determine the data and operations that the role has access to; The system maintains a list of permissions, each of which corresponds to an operation; a role is assigned a set of permissions that define the data and operations that the role can access.
3. According to a data privacy protection method based on the zero trust principle as described in claim 1, it is characterized by: In step A2, the steps of using the encryption algorithm are specifically as follows: Step B1: Select the quantum state. Sender A prepares the qubit and selects two bases for encoding. The base state is divided into α and β, and the superposition state is divided into C and D. The calculation method of C in the superposition state is as follows: Among them, C represents the C state in the superposition state, α represents the α state in the ground state, and β represents the β state in the ground state; The calculation method of D in the superposition state is as follows: Where D represents the D state in the superposition state, α represents the α state in the ground state, and β represents the β state in the ground state; Step B2: Send the selected qubit to receiver B through the quantum channel. The qubit received by the receiver is n. The received qubit is measured. The qubit n includes α and β in the ground state and C and D in the superposition state. Step B3: After measurement, verify the newly arrived security, then the calculation method of the quantum bit error rate is specifically as follows: Where E represents the quantum bit error rate, M represents the number of error bits detected, and N represents the total number of bits sent; The quantum bit error rate affects the length of the security key, so the key length is calculated as follows: L = N (1-H (E)), where L represents the key length, N represents the total number of bits sent, and H (E) represents entropy; The specific method for calculating entropy is: H(E) = -Elog2 E-(1-E)log2(1-E), where H(E) represents entropy and E represents the quantum bit error rate; The data is encrypted through steps B1 to B3.
4. According to a data privacy protection method based on the zero trust principle as described in claim 1, it is characterized by: In step A3, the user's login time, location, access frequency, and operation mode are monitored to detect whether there is any abnormal behavior; Through rule-based algorithms, the monitored user behavior, device status, and environmental information are analyzed to assess the risk level of the current access request; The specific method for calculating risk value is: K=K1+K2+K3+K4+K5+K6, where K represents the risk value, K1 represents the user abnormal access value, K2 represents the device network abnormal value, K3 represents the application response time value, K4 represents the network environment value, K5 represents the application error rate value, and K6 represents the physical environment value.
5. According to claim 4, a data privacy protection method based on the zero trust principle is characterized in that: Abnormal access mode, set non-working hours, non-working hours are 20:00-7:00 the next day. If the user accesses sensitive data during non-working hours, K1 is 10; frequent access means accessing the same sensitive data more than 10 times within 1 hour, K1 is 15; for data operation behavior, if more than 100 sensitive records are deleted or modified at one time, K1 is 20; If the network connection is abnormal and the packet loss rate exceeds 20% within 1 minute, K2 is set to 15; if the hard disk has more than 5 bad sectors due to hardware failure, K2 is set to 20; When the application response time is more than 50% longer than the average response time and lasts for more than 10 minutes, K3 is 10; when the error rate increases by more than 10%, K5 is 10; When the IP address accesses from a high-risk area, K4 is 20 points. High-risk areas are identified as areas with high incidence of network attacks. When the temperature of the data center exceeds 30°C for more than 1 hour, K6 is 5 points. The risk level is divided into low risk level, medium risk level and high risk level. The calculated risk value between 0-20 is a low risk level, the calculated risk value between 21-40 is a medium risk level, and the calculated risk value of 41 and above is a high risk level. Assign risk scores to users based on their activities, historical behavior, and environment, and adjust security policies accordingly; Detect anomalous activity using user and entity behavior analytics.
6. According to claim 1, a data privacy protection method based on the zero trust principle is characterized in that: In step A4, the existing data source is audited to determine sensitive data, desensitize the data using a desensitizing technique of character replacement, and corresponding desensitizing rules are formulated for different data fields; the Delphix Engine is installed in a cloud environment or a local server, the network and security configuration of Delphix is set, the original data source is connected to the Delphix management console, and the data set to be desensitized is selected; Create a desensitization template in Delphix, apply the established desensitization rules, and configure the corresponding desensitization method according to the field type; Create a desensitization job based on the configured desensitization template; Run desensitization jobs and monitor their execution status; Check desensitized data: Verify desensitized data to ensure that sensitive information has been effectively desensitized; Ensure that the desensitized data is consistent with the original data in terms of logic and format; Use masked data to verify application functionality and ensure normal operation and data integrity in a real environment; publish masked data to development, test or other non-production environments; use Delphix's data virtualization capabilities for real-time data updates; ensure that only authorized personnel can access masked data.
7. According to claim 1, a data privacy protection method based on the zero trust principle is characterized in that: In step A5, the operation logs and data access logs in the system are collected, including user login, data access, permission change and other behaviors; Generate detailed data access logs for both internal users and external requests. These logs should include access time, IP address, device ID, access target, access type, and access result information. The collected logs should be stored in a centralized log management system for subsequent analysis and auditing; at the same time, encryption and access control measures should be taken to protect the security and integrity of log data; The audit analyzer should pre-process the collected logs, including log cleaning, deduplication, formatting, etc., to improve the analysis efficiency and accuracy; the audit analyzer should identify normal operation behavior patterns and data access patterns; this helps to discover abnormal or suspicious behavior patterns, such as frequent failed login attempts and large amounts of data access during non-working hours; Based on preset security policies and rules, the audit analyzer should detect abnormal behaviors or potential threats in the logs in real time and generate corresponding warning information; these warning information include detailed abnormal descriptions, scope of impact, and recommended disposal measures.
8. A data privacy protection system based on the zero trust principle, using a data privacy protection method based on the zero trust principle as claimed in any one of claims 1 to 7, characterized in that: Verification module: used to authenticate users who request access to data, and verify the user's identity information and access rights; Encryption module: used to encrypt data using encryption algorithms during data transmission from the source end to the destination end; Access control module: used to continuously monitor the behavior and environment information of users, devices and applications, and dynamically adjust access rights based on real-time risk assessment results; Data processing module: used to process sensitive data in the storage and processing process using desensitization technology and anonymization algorithms, so that the processed data cannot be directly associated with specific individuals and organizations, protecting the privacy of the data subject; Log analysis module: collects operation logs and data access logs within the system, and uses the audit analyzer to analyze and mine the collected logs.
Citation Information
Cited By
Data security dynamic evaluation system and protection method
CN120934811A
Data privacy protection method for data governance system
CN121167780A
Dynamic data secure transmission and processing channel construction device and method based on zero trust
CN121644169A
Zero-trust based dynamic data security transmission and processing channel construction device and method
CN121644169B