Data management method and device, electronic equipment, storage medium and program product

By obtaining the content service list generated by the database system and analyzing the data privacy parameters of the target operation instructions, dynamically adjusting the data management strategy to promptly discover faults, solving the problem of single data privacy protection measures in the existing technology, and achieving security and continuity of data interaction.

CN120296790APending Publication Date: 2025-07-11CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510413938.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

Data privacy protection measures in the prior art are usually relatively single, difficult to meet complex and changeable data security needs, and cannot promptly discover and prevent high-risk operations, affecting the continuity and security of data interaction.

Method used

By obtaining the content service list generated by the database system, analyzing the data privacy parameters of the target operation instructions, dynamically adjusting the data management strategy, combining the self-test mechanism of the front-end equipment and the database system, timely discovering and handling faults to ensure the security of data access and storage.

Benefits of technology

It realizes dynamic adjustment of security measures according to the degree of data sensitivity, timely discover and handle equipment failures, ensure the security and continuity of data interaction, effectively protect data privacy, and adapt to complex and changeable data security needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296790A_ABST
    Figure CN120296790A_ABST
Patent Text Reader

Abstract

The invention discloses a data management method and device, electronic equipment, a storage medium and a program product. The method comprises the following steps: in response to a data related instruction sent by front-end equipment, obtaining a content service list which is generated by a database system and corresponds to the data related instruction, and sending the content service list to the front-end equipment; a target operation instruction sent by the front-end equipment is obtained, and the target operation instruction is triggered under the condition that a user selects at least one service option in the content service list; a data private density parameter corresponding to the target operation instruction is determined, a corresponding data management strategy when the target operation instruction is executed is determined according to the data private density parameter, and the data private density parameter is used for representing the private degree of data planned to be accessed by the target operation instruction. According to the data privacy protection method and device, the technical problem that complex and changeable data security requirements are difficult to meet due to the fact that data privacy protection measures in related technologies are generally single is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of data security management, and in particular, to a data management method, apparatus, electronic device, storage medium, and program product. Background Art

[0002] With the rapid development of information technology, the value of data has become increasingly prominent in various fields. Whether it is an enterprise or an individual, they rely on data for decision-making, operation, and management. However, the security issues of data have become increasingly severe. Security incidents such as data leakage, unauthorized access, and data tampering occur frequently, posing a serious threat to personal privacy, corporate interests, and social stability.

[0003] The data privacy protection measures in related technologies are usually relatively single and difficult to meet the complex and changing data security requirements.

[0004] To address the above problems, no effective solution has been proposed yet. Summary of the Invention

[0005] Embodiments of the present application provide a data management method, apparatus, electronic device, storage medium, and program product to at least solve the technical problem that the data privacy protection measures in related technologies are usually relatively single and difficult to meet the complex and changing data security requirements.

[0006] According to one aspect of the embodiments of the present application, a data management method is provided, including: in response to a data-related instruction sent by a front-end device, obtaining a content service list corresponding to the data-related instruction generated by a database system, and sending the content service list to the front-end device, where the data-related instruction is used to represent the type of data processing operation planned to be executed by a user; obtaining a target operation instruction sent by the front-end device, where the target operation instruction is triggered when the user selects at least one service option in the content service list, and the target operation instruction is used to perform a data processing operation on the data corresponding to the service option in the database system; determining a data privacy parameter corresponding to the target operation instruction, and determining a data management strategy corresponding to the execution of the target operation instruction according to the data privacy parameter, where the data privacy parameter is used to represent the privacy degree of the data planned to be accessed by the target operation instruction.

[0007] Optionally, the types of data processing operations planned to be executed by the user include at least one of the following: data reading, data storage. The target operation instructions include: the first operation instruction, the second operation instruction. The method further includes: when the type of the data-related instruction is the data reading type, obtaining the first operation instruction sent by the front-end device, where the first operation instruction is triggered when the user selects at least one service option in the content service list, and the service option is used to characterize the data type and attributes of the data planned to be read by the user; when the type of the data-related instruction is the data storage type, obtaining the second operation instruction sent by the front-end device, where the second operation instruction is triggered when the user selects at least one service option in the content service list and inputs the data to be stored, and the service option is used to characterize the type and attributes of the data table where the data to be stored is planned to be stored.

[0008] Optionally, determining the data privacy parameter corresponding to the target operation instruction includes: when the target operation instruction is the first operation instruction, determining the read permission information of the data planned to be read corresponding to the first operation instruction in the database system; determining the role permission information of the user who triggers the first operation instruction; and determining the data privacy parameter corresponding to the first operation instruction based on the read permission information and the role permission information.

[0009] Optionally, determining the data privacy parameter corresponding to the target operation instruction further includes: when the target operation instruction is the second operation instruction, determining the storage permission information of the data table corresponding to the second operation instruction in the database system; extracting features of the data to be stored corresponding to the second operation instruction to obtain the data features corresponding to the data to be stored, where the data features include at least one of the following: data type, content sensitivity parameter, data structure; and determining the data privacy parameter corresponding to the second operation instruction based on the storage permission information and the data features.

[0010] Optionally, the method further includes: determining the instruction attribute information corresponding to the target operation instruction, where the instruction attribute information includes at least one of the following: the timestamp when the target operation instruction is sent, the location information and Internet protocol address of the front-end device that sends the target operation instruction; and determining the data privacy parameter corresponding to the target operation instruction based on the instruction attribute information.

[0011] Optionally, according to the data privacy density parameter, determining the data management policy corresponding to the execution of the target operation instruction includes: when the data privacy density parameter indicates that the data in the database system is prohibited from being accessed by the target operation instruction, determining the information of the authority management department corresponding to the data, and according to the information of the authority management department, sending an authority request message to the authority management department corresponding to the data, where the authority request message is used to request the authority management department to grant the authority to access the data; when the data privacy density parameter indicates that the data in the database system is allowed to be accessed by the target operation instruction, directly executing the target operation instruction to implement the storage and / or reading operation of the data in the database system.

[0012] Optionally, when the content service list is not received within the first preset duration after the front-end device sends the data-related instruction, the front-end device is further configured to: send a first test instruction to the control end; when the first verification instruction returned by the control end is not received within the second preset duration after sending the first test instruction, send a first alarm message, where the first alarm message is used to indicate that a fault occurs in the front-end device; when the first verification instruction is received within the second preset duration after sending the first test instruction, send a database system detection instruction to the control end, where the control end is configured to send a second test instruction to the database system when receiving the database system detection instruction, and send a second alarm message when the second verification instruction returned by the database system is not received within the third preset duration after sending the second test instruction, where the second alarm message is used to indicate that a fault occurs in the database system.

[0013] According to another aspect of the embodiments of the present application, a data management device is further provided, including: a list acquisition module, configured to acquire a content service list corresponding to the data-related instruction generated by the database system in response to the data-related instruction sent by the front-end device, and send the content service list to the front-end device, where the data-related instruction is used to indicate the type of data processing operation planned to be executed by the user; an instruction acquisition module, configured to acquire a target operation instruction sent by the front-end device, where the target operation instruction is triggered when at least one service option in the content service list is selected by the user, and the target operation instruction is used to perform a data processing operation on the data corresponding to the service option in the database system; a privacy density analysis module, configured to determine the data privacy density parameter corresponding to the target operation instruction, and according to the data privacy density parameter, determine the data management policy corresponding to the execution of the target operation instruction, where the data privacy density parameter is used to indicate the privacy degree of the data planned to be accessed by the target operation instruction.

[0014] According to yet another aspect of the embodiments of the present application, an electronic device is further provided, including: a memory and a processor, where the processor is configured to run a program stored in the memory, and when the program runs, it executes the data management method.

[0015] According to another aspect of the embodiments of the present application, a non-volatile storage medium is further provided. The non-volatile storage medium includes a stored computer program. Wherein, the device where the non-volatile storage medium is located executes a data management method by running the computer program.

[0016] According to another aspect of the embodiments of the present application, a computer program product is further provided, including a computer program, and the steps of a data management method are implemented when the computer program is executed by a processor.

[0017] In the embodiments of the present application, in response to a data-related instruction sent by a front-end device, a content service list corresponding to the data-related instruction generated by a database system is obtained and sent to the front-end device, where the data-related instruction is used to characterize the type of data processing operation planned to be executed by a user; a target operation instruction sent by the front-end device is obtained, where the target operation instruction is triggered when at least one service option in the content service list is selected by the user, and the target operation instruction is used to perform a data processing operation on the data corresponding to the service option in the database system; a data privacy density parameter corresponding to the target operation instruction is determined, and based on the data privacy density parameter, a data management policy corresponding to the execution of the target operation instruction is determined, where the data privacy density parameter is used to characterize the privacy degree of the data planned to be accessed by the target operation instruction. By determining the data privacy density parameter and adjusting the data management policy accordingly, corresponding security measures can be dynamically implemented according to the sensitivity of the data, achieving the purpose of effectively protecting data privacy, and further solving the technical problem that the data privacy protection measures in the related art are usually relatively single and difficult to meet the complex and changeable data security requirements. Description of the Drawings

[0018] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0019] Figure 1 is a hardware structure block diagram of a computer terminal (or electronic device) for implementing a data management method according to an embodiment of the present application;

[0020] Figure 2 is a schematic diagram of a data management method flow according to an embodiment of the present application;

[0021] Figure 3 is a schematic diagram of the structure of a data management device according to an embodiment of the present application. Detailed Embodiments

[0022] To enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.

[0023] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products or devices.

[0024] In the related art, data privacy protection measures are usually relatively single, such as simple encryption or desensitization processing, and it is difficult to cope with complex and changeable data security requirements. Existing systems are often not dynamic and real-time enough in risk assessment, and cannot perform risk prediction and adjustment based on real-time data and operation behaviors, which may lead to high-risk operations not being discovered and blocked in time.

[0025] In addition, during the data interaction process, data reading or storage is performed through an intermediate device. When the intermediate device fails, such as a front-end device (such as a data display device) or a database system fails, if the failure cannot be discovered in time, it will cause the cycle of data reading or storage to increase, and even lead to the inability to read or store data normally, affecting the continuity of the business.

[0026] To solve the above problems, relevant solutions are provided in the embodiments of this application, which will be described in detail below.

[0027] According to the embodiments of this application, an embodiment of a method for data management is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described here can be executed in a different order than here.

[0028] The method embodiments provided by the embodiments of this application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Figure 1The following shows a hardware block diagram of a computer terminal (or electronic device) for implementing a data management method. As Figure 1 shown, the computer terminal 10 (or electronic device) may include one or more processors 102 (illustrated as 102a, 102b, ……, 102n in the figure) (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only illustrative and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than Figure 1 shown therein, or have a different configuration from Figure 1 that shown.

[0029] It should be noted that the above one or more processors 102 and / or other data processing circuits are generally referred to as "data processing circuits" herein. The data processing circuit may be embodied in whole or in part as software, hardware, firmware, or any combination thereof. In addition, the data processing circuit may be a single independent processing module, or be incorporated in whole or in part into any one of the other elements in the computer terminal 10 (or electronic device). As involved in the embodiments of the present application, the data processing circuit is a processor control (such as the selection of a variable resistor terminal path connected to an interface).

[0030] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the data management method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above data management method. The memory 104 may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories may be connected to the computer terminal 10 through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0031] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0032] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables users to interact with the user interface of the computer terminal 10 (or electronic device).

[0033] Under the above operating environment, an embodiment of the present application provides a data management method. Figure 2 It is a schematic diagram of a method flow for data management provided according to an embodiment of the present application. As Figure 2 shown, the method includes the following steps:

[0034] Step S202, in response to a data-related instruction sent by a front-end device, obtain a content service list corresponding to the data-related instruction generated by a database system, and send the content service list to the front-end device, where the data-related instruction is used to represent the type of data processing operation that the user plans to execute;

[0035] Step S204, obtain a target operation instruction sent by the front-end device, where the target operation instruction is triggered when the user selects at least one service option in the content service list, and the target operation instruction is used to perform a data processing operation on the data corresponding to the service option in the database system;

[0036] Step S206, determine a data privacy parameter corresponding to the target operation instruction, and based on the data privacy parameter, determine a data management policy corresponding to the execution of the target operation instruction, where the data privacy parameter is used to represent the privacy degree of the data planned to be accessed by the target operation instruction.

[0037] Through the above steps, by determining the data privacy parameter and adjusting the data management policy accordingly, corresponding security measures can be dynamically implemented according to the sensitivity of the data, achieving the purpose of effectively protecting data privacy, and thus solving the technical problem that the data privacy protection measures in the related art are usually relatively single and difficult to meet the complex and changeable data security requirements.

[0038] The data management method in steps S202 to S206 of the embodiment of the present application will be further introduced below.

[0039] First, the user can send data-related instructions to the database system based on the front-end device (data display device) and wait to obtain the feedback information from the database system. In this embodiment, the data-related instructions can be data reading instructions or storage instructions;

[0040] For example, assume that the user is a financial staff member of a company and can operate using financial software on the front-end device. The user clicks the "Query this month's financial statements" button, and at this time, the front-end device sends a data reading instruction to the company's database (database system).

[0041] After that, based on the data-related instructions, the database system can obtain the content service list associated with the data-related instructions and send it to the front-end device. In this embodiment, the content service list can include: the first service list associated with the data reading instruction, the second service list associated with the data storage instruction, etc.

[0042] For example, when the front-end device sends a data-related instruction of the data reading type, the database system returns a first service list, and the content may include service options such as "Read this month's financial statements", "Read last month's financial statements", "Read annual financial summary", etc.; when the front-end device sends a data-related instruction of the data storage type, the database system returns a second service list, and the content may include service options such as "Save this month's financial statements", "Update financial data", "Backup financial data", etc.

[0043] The user can perform further operations based on the content in the content service list. The front-end device can generate different target operation instructions based on different operations of the user. The specific steps are as follows.

[0044] In some embodiments of the present application, the types of data processing operations planned to be executed by the user include at least one of the following: data reading, data storage. The target operation instructions include: the first operation instruction, the second operation instruction. The method further includes the following steps: in the case where the type corresponding to the data-related instruction is the data reading type, obtain the first operation instruction sent by the front-end device, where the first operation instruction is triggered when the user selects at least one service option in the content service list, and the service option is used to represent the data type and attributes of the data planned to be read by the user; in the case where the type corresponding to the data-related instruction is the data storage type, obtain the second operation instruction sent by the front-end device, where the second operation instruction is triggered when the user selects at least one service option in the content service list and inputs the data to be stored, and the service option is used to represent the type and attributes of the data table where the data to be stored is planned to be stored.

[0045] Specifically, if the content service list is the first service list, the user can select the data type to be read for the first service list; the front-end device generates a first operation instruction according to the read data type; if the content service list is the second service list, the user can input stored data to the front-end device, and the front-end device generates a second operation instruction according to the stored data.

[0046] For example, if the user selects the data type to be read (such as "read this month's sales data") from the first service list, the front-end device can generate a corresponding first operation instruction according to the selected service option. This first operation instruction is used to read the sales data of this month in the database system; or, if the user inputs stored data (such as inputting new sales data) to the front-end device and selects the service option of "save this month's sales data" from the second service list, the front-end device can generate a corresponding second operation instruction. This second operation instruction can be used to store the input new sales data into the data table corresponding to this month's sales data in the database system.

[0047] In the actual operation process, there may be a situation where the front-end device or the database system fails. In order to avoid the failure of the front-end device and the database system from affecting the user's operation time. In the embodiments of the present application, when the user performs data operations, the front-end device and the database system can also be troubleshot, specifically as follows.

[0048] Specifically, record the sending time of the data-related instruction; make a judgment and processing according to the sending time to determine the status of the front-end device and the status of the database system; if the status of the front-end device is that it cannot send the data-related instruction and the status of the database system is the normal operation state, prompt the user to replace the front-end device and resend the data-related instruction to the database system; if the database system cannot receive the data-related instruction, prompt the user to reselect the time for data operation; if the status of the front-end device is the normal operation state and the status of the database system is the normal operation state, after the front-end device sends the data-related instruction to the database system, the database system sends feedback information (content service list) to the front-end device.

[0049] Among them, the specific process steps for making a judgment and processing according to the sending time to determine the status of the front-end device and the status of the database system are as follows.

[0050] In some embodiments of the present application, when the front-end device does not receive the content service list within the first preset duration after sending the data-related instruction, the front-end device is further configured to: send a first test instruction to the control end; when the first verification instruction returned by the control end is not received within the second preset duration after sending the first test instruction, send a first warning message, where the first warning message is used to indicate that the front-end device has a fault; when the first verification instruction is received within the second preset duration after sending the first test instruction, send a database system detection instruction to the control end, where the control end is configured to, when receiving the database system detection instruction, send a second test instruction to the database system, and when the second verification instruction returned by the database system is not received within the third preset duration after sending the second test instruction, send a second warning message, where the second warning message is used to indicate that the database system has a fault.

[0051] For example, assume that a user is using a computer (front-end device) to access the company's database system, and clicks the "Query this month's sales data" button. The computer records the time point of this operation (e.g., 10:00:00 on March 20, 2025). If the front-end device does not receive the feedback information from the database system within the first preset duration (e.g., within 3 seconds), the front-end device sends a first test instruction to the control end. If the first verification instruction from the control end is not received within the second preset duration (e.g., within 5 seconds), the front-end device sends a first warning message, such as displaying "Unable to send data-related instruction".

[0052] If the front-end device receives the feedback information from the database system within the first preset duration (e.g., within 3 seconds), the front-end device sends a database system detection instruction to the control end. After receiving the database system detection instruction, the control end sends a second test instruction to the database system. If the control end does not receive the second verification instruction returned by the database system within the third preset duration (e.g., within 10 seconds), it sends a second warning message data, such as displaying "The database system is unable to receive data-related instructions" on the front-end device.

[0053] By self-checking the front-end device and the database system, the embodiments of the present application can timely detect the faults of the front-end device and the database system, avoid prolonging the data reading or data storage cycle, and at the same time, reduce the risk of property damage caused by the faults of the front-end device and the database system.

[0054] After the control end obtains the target operation instruction (the first operation instruction and / or the second operation instruction) generated by the front-end device, it can analyze the target operation instruction to determine the data privacy density parameter corresponding to the target operation instruction. The specific steps are as follows.

[0055] In some embodiments of the present application, determining the data privacy density parameter corresponding to the target operation instruction includes the following steps: When the target operation instruction is the first operation instruction, determine the read permission information of the data planned to be read corresponding to the first operation instruction in the database system; determine the role permission information of the user triggering the first operation instruction; and determine the data privacy density parameter corresponding to the first operation instruction based on the read permission information and the role permission information.

[0056] In some embodiments of the present application, determining the data privacy density parameter corresponding to the target operation instruction further includes the following steps: When the target operation instruction is the second operation instruction, determine the storage permission information of the data table planned to be stored corresponding to the second operation instruction in the database system; perform feature extraction on the data to be stored corresponding to the second operation instruction to obtain the data features corresponding to the data to be stored, where the data features include at least one of the following: data type, content sensitivity parameter, data structure; and determine the data privacy density parameter corresponding to the second operation instruction based on the storage permission information and the data features.

[0057] Specifically, for the first operation instruction, the control end can retrieve in the database system according to the data type of the data planned to be read to determine whether permission is required to read the data planned to be read in the database system; if permission is required to read the data in the database system, the control end outputs the data privacy density parameter corresponding to the data as "no read permission"; if permission is not required to read the data in the database system, the control end outputs the data privacy density parameter corresponding to the data as "has read permission", and then, the control end sends the first operation instruction to the database system to start reading the data and transmitting the data to the front-end device.

[0058] For example, assume that after the control end retrieves, it is found that high-level permission is required to read the monthly sales data (for example, only the financial manager can access, and the role permission of the current user account is an ordinary employee), then the control end can output the data privacy density parameter as "high" and indicate that the current first operation instruction has no read permission item.

[0059] For the second operation instruction, the control end can perform feature extraction on the data to be stored to obtain the key data features of the stored data; retrieve in the database system according to the key data features of the data to be stored to determine whether permission is required to store the key features of the data to be stored in the database system; if storage requires permission, the control end outputs the data privacy density parameter as "no storage permission"; if storage does not require permission, the control end outputs the data privacy density parameter as "has storage permission"; then, the control end can store the data in the database system.

[0060] Additionally, as an alternative implementation manner, in the embodiments of the present application, the method further includes the following steps: determining instruction attribute information corresponding to a target operation instruction, where the instruction attribute information includes at least one of the following: the timestamp when the target operation instruction is sent, the location information and Internet protocol address of the front-end device that issues the target operation instruction; determining a data privacy density parameter corresponding to the target operation instruction according to the instruction attribute information.

[0061] Specifically, the control end can also identify the data type corresponding to the target operation instruction, which not only includes the category of the data (such as financial data, customer information, technical documents, etc.), but also involves the specific content of the data (such as whether it contains sensitive information, whether it involves privacy data, etc.). Natural language processing technology can be used to perform semantic analysis on the data content to identify keywords and sensitive information in the data. For example, if the first operation instruction is "read this month's sales data", the intelligent control end identifies "sales data" as belonging to the financial category through NLP, and further analyzes the data content and finds that it contains sensitive information such as customer names and transaction amounts.

[0062] And / or, the control end can also analyze in combination with context information, including the identity of the visitor, the access time, the access location, etc., which helps to judge the rationality and security of the current operation. For example, if the visitor is within the company's internal network (confirmed by the IP address) and initiates an operation during working hours (9:00 am - 6:00 pm), the control end will consider this to be a normal operation scenario; if the visitor initiates an operation outside of working hours or from an external network of the company, the intelligent control end will mark it as a high-risk operation and further strengthen the security check.

[0063] The control end determines the final data privacy density parameter by synthesizing all the above analysis results. In this implementation, the privacy density can be divided into multiple levels (such as low, medium, high), and it is indicated whether the current instruction has the corresponding operation authority. Subsequently, corresponding security measures can be taken according to the data privacy density parameter.

[0064] In the embodiments of the present application, the specific steps for determining the data management strategy corresponding to the execution of the target operation instruction according to the data privacy density parameter are as follows.

[0065] In some embodiments of the present application, determining the data management policy corresponding to the execution of the target operation instruction according to the data privacy density parameter includes the following steps: when the data privacy density parameter indicates that the data in the database system is prohibited from being accessed by the target operation instruction, determining the information of the authority management department corresponding to the data, and sending an authority request message to the authority management department corresponding to the data according to the information of the authority management department, where the authority request message is used to request the authority management department to grant the authority to access the data; when the data privacy density parameter indicates that the data in the database system is allowed to be accessed by the target operation instruction, directly execute the target operation instruction to implement the storage and / or reading operation of the data in the database system.

[0066] Specifically, the control end can determine the information of the authority department corresponding to the target operation instruction according to the data privacy density parameter, and send the information of the authority department to the front-end device. The user can apply for authority to the authority department according to the information of the authority department, obtain the authorization instruction, and can perform data reading or data storage after obtaining the authorization instruction.

[0067] In this embodiment, different departments correspond to different private data. Therefore, the authorization instructions are also different. Therefore, when it is necessary to read or store private data, it is necessary to obtain the authorization instruction from the affiliated department to proceed, avoiding the leakage of private data and causing property damage.

[0068] It can be understood that data is divided into public data and private data. Therefore, for the security of private data, it is necessary to encrypt and protect private data. Different private data belong to different departments. Therefore, it is necessary to analyze the data type, determine the department to which the private data belongs, and apply for permission to the department to which the private data belongs to read or store data, avoiding the leakage of private data and also avoiding property losses caused by the leakage of private data.

[0069] The solution of the present application can detect the status of the front-end device and the database system, discover faults in time and take corresponding measures to avoid data interaction failures caused by device failures; by analyzing the operation instructions and data characteristics, determine the privacy density of the data in advance to provide a basis for subsequent security measures; dynamically adjust the access rights and data protection policies according to the sensitivity of the data and the context information of the operation to ensure that only authorized users can access or store sensitive data. It can effectively cope with complex and changeable data security threats and provide a safe, reliable and efficient data management environment for users.

[0070] According to the embodiments of the present application, an embodiment of a data management device is also provided. Figure 3 It is a schematic structural diagram of a data management device provided according to the embodiments of the present application. As Figure 3 shown, the device includes:

[0071] A list acquisition module 30, configured to, in response to a data-related instruction sent by a front-end device, acquire a content service list corresponding to the data-related instruction generated by a database system, and send the content service list to the front-end device, where the data-related instruction is used to represent the type of a data processing operation planned to be executed by a user;

[0072] An instruction acquisition module 32, configured to acquire a target operation instruction sent by the front-end device, where the target operation instruction is triggered when at least one service option in the content service list is selected by the user, and the target operation instruction is used to perform a data processing operation on data corresponding to the service option in the database system;

[0073] A privacy analysis module 34, configured to determine a data privacy parameter corresponding to the target operation instruction, and determine a data management policy corresponding to the execution of the target operation instruction according to the data privacy parameter, where the data privacy parameter is used to represent the privacy degree of data planned to be accessed by the target operation instruction.

[0074] Optionally, the type of the data processing operation planned to be executed by the user includes at least one of the following: data reading, data storage, and the target operation instruction includes: a first operation instruction, a second operation instruction; the instruction acquisition module is configured to: when the type corresponding to the data-related instruction is a data reading type, acquire the first operation instruction sent by the front-end device, where the first operation instruction is triggered when at least one service option in the content service list is selected by the user, and the service option is used to represent the data type and attribute of the data planned to be read by the user; when the type corresponding to the data-related instruction is a data storage type, acquire the second operation instruction sent by the front-end device, where the second operation instruction is triggered when at least one service option in the content service list is selected by the user and the data to be stored is input, and the service option is used to represent the type and attribute of the data table where the data to be stored is planned to be stored.

[0075] Optionally, determining the data privacy parameter corresponding to the target operation instruction includes: when the target operation instruction is the first operation instruction, determining the read permission information of the data planned to be read corresponding to the first operation instruction in the database system; determining the role permission information of the user who triggers the first operation instruction; determining the data privacy parameter corresponding to the first operation instruction according to the read permission information and the role permission information.

[0076] Optionally, determining the data privacy density parameter corresponding to the target operation instruction further includes: when the target operation instruction is the second operation instruction, determining the storage permission information of the data table planned to be stored corresponding to the second operation instruction in the database system; extracting features of the data to be stored corresponding to the second operation instruction to obtain the data features corresponding to the data to be stored, where the data features include at least one of the following: data type, content sensitivity degree parameter, data structure; determining the data privacy density parameter corresponding to the second operation instruction according to the storage permission information and the data features.

[0077] Optionally, the privacy density analysis module is further configured to: determine the instruction attribute information corresponding to the target operation instruction, where the instruction attribute information includes at least one of the following: the timestamp when the target operation instruction is sent, the location information and Internet protocol address of the front-end device that sends the target operation instruction; determining the data privacy density parameter corresponding to the target operation instruction according to the instruction attribute information.

[0078] Optionally, determining the data management policy corresponding to the execution of the target operation instruction according to the data privacy density parameter includes: when the data privacy density parameter indicates that the data in the database system is prohibited from being accessed by the target operation instruction, determining the information of the permission management department corresponding to the data, and according to the information of the permission management department, sending a permission request message to the permission management department corresponding to the data, where the permission request message is used to request the permission management department to grant the permission to access the data; when the data privacy density parameter indicates that the data in the database system is allowed to be accessed by the target operation instruction, directly execute the target operation instruction to implement the storage and / or reading operation of the data in the database system.

[0079] Optionally, when the front-end device does not receive the content service list within the first preset duration after sending the data-related instruction, the front-end device is further configured to: send a first test instruction to the control end; when the first verification instruction returned by the control end is not received within the second preset duration after sending the first test instruction, send a first warning message, where the first warning message is used to indicate that the front-end device has a fault; when the first verification instruction is received within the second preset duration after sending the first test instruction, send a database system detection instruction to the control end, where the control end is configured to, when receiving the database system detection instruction, send a second test instruction to the database system, and when the second verification instruction returned by the database system is not received within the third preset duration after sending the second test instruction, send a second warning message, where the second warning message is used to indicate that the database system has a fault.

[0080] It should be noted that each module in the above data management device can be a program module (for example, a set of program instructions that implements a specific function), or a hardware module. For the latter, it can be presented in the following forms, but not limited to this: the manifestation form of each of the above modules is a processor, or the functions of each of the above modules are implemented by a processor.

[0081] It should be noted that the data management device provided in this embodiment can be used to execute Figure 2 the data management method shown. Therefore, the relevant explanations of the above data management method also apply to the embodiments of this application and will not be repeated here.

[0082] The embodiments of this application also provide a non-volatile storage medium, which includes a stored computer program. Among them, the device where the non-volatile storage medium is located executes the following data management method by running the computer program: in response to a data-related instruction sent by a front-end device, obtain a content service list corresponding to the data-related instruction generated by the database system, and send the content service list to the front-end device, where the data-related instruction is used to represent the type of data processing operation that the user plans to execute; obtain a target operation instruction sent by the front-end device, where the target operation instruction is triggered when the user selects at least one service option in the content service list, and the target operation instruction is used to perform a data processing operation on the data corresponding to the service option in the database system; determine the data privacy density parameter corresponding to the target operation instruction, and determine the data management strategy corresponding to the execution of the target operation instruction according to the data privacy density parameter, where the data privacy density parameter is used to represent the privacy degree of the data planned to be accessed by the target operation instruction.

[0083] The embodiments of this application also provide a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the steps of the data management method described in each embodiment of this application: in response to a data-related instruction sent by a front-end device, obtain a content service list corresponding to the data-related instruction generated by the database system, and send the content service list to the front-end device, where the data-related instruction is used to represent the type of data processing operation that the user plans to execute; obtain a target operation instruction sent by the front-end device, where the target operation instruction is triggered when the user selects at least one service option in the content service list, and the target operation instruction is used to perform a data processing operation on the data corresponding to the service option in the database system; determine the data privacy density parameter corresponding to the target operation instruction, and determine the data management strategy corresponding to the execution of the target operation instruction according to the data privacy density parameter, where the data privacy density parameter is used to represent the privacy degree of the data planned to be accessed by the target operation instruction.

[0084] The serial numbers of the embodiments of the present application above are only for description and do not represent the superiority or inferiority of the embodiments.

[0085] In the above embodiments of the present application, the descriptions of each embodiment have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0086] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.

[0087] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0088] In addition, the functional units in each embodiment of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0089] If the above integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. And the foregoing storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs and other various media that can store program codes.

[0090] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A data management method, characterized in that, Including: In response to a data-related instruction sent by a front-end device, obtain a content service list generated by a database system corresponding to the data-related instruction, and send the content service list to the front-end device, where the data-related instruction is used to characterize the type of data processing operation that the user plans to execute; Obtain a target operation instruction sent by the front-end device, where the target operation instruction is triggered when the user selects at least one service option in the content service list, and the target operation instruction is used to perform a data processing operation on the data corresponding to the service option in the database system; Determine a data privacy parameter corresponding to the target operation instruction, and based on the data privacy parameter, determine a data management policy corresponding to the execution of the target operation instruction, where the data privacy parameter is used to characterize the privacy degree of the data planned to be accessed by the target operation instruction.

2. The data management method according to claim 1, wherein The type of data processing operation that the user plans to execute includes at least one of the following: data reading, data storage, and the target operation instruction includes: a first operation instruction, a second operation instruction; the method further includes: When the type corresponding to the data-related instruction is the data reading type, obtain a first operation instruction sent by the front-end device, where the first operation instruction is triggered when the user selects at least one of the service options in the content service list, and the service option is used to characterize the data type and attributes of the data that the user plans to read; When the type corresponding to the data-related instruction is the data storage type, obtain a second operation instruction sent by the front-end device, where the second operation instruction is triggered when the user selects at least one of the service options in the content service list and inputs the data to be stored, and the service option is used to characterize the type and attributes of the data table where the data to be stored is planned to be stored; 3. The data management method according to claim 2, wherein Determining the data privacy parameter corresponding to the target operation instruction includes: When the target operation instruction is the first operation instruction, determine the read permission information of the data planned to be read corresponding to the first operation instruction in the database system; Determine the role permission information corresponding to the user who triggers the first operation instruction; Based on the read permission information and the role permission information, determine the data privacy parameter corresponding to the first operation instruction.

4. The data management method according to claim 2, characterized in that Determining the data privacy parameter corresponding to the target operation instruction further includes: When the target operation instruction is the second operation instruction, determine the storage permission information of the data table corresponding to the second operation instruction in the database system; Extract features from the data to be stored corresponding to the second operation instruction to obtain data features corresponding to the data to be stored, where the data features include at least one of the following: data type, content sensitivity parameter, data structure; Based on the storage permission information and the data features, determine the data privacy parameter corresponding to the second operation instruction.

5. The data management method according to claim 3 or 4, characterized in that The method further includes: Determine the instruction attribute information corresponding to the target operation instruction, where the instruction attribute information includes at least one of the following: the timestamp when the target operation instruction is sent, the location information and Internet protocol address of the front-end device that issues the target operation instruction; Determine the data privacy density parameter corresponding to the target operation instruction according to the instruction attribute information.

6. The data management method according to claim 1, wherein Determine the data management policy corresponding to the execution of the target operation instruction according to the data privacy density parameter, including: When the data privacy density parameter indicates that the data in the database system is prohibited from being accessed by the target operation instruction, determine the permission management department information corresponding to the data, and send a permission request message to the permission management department corresponding to the data according to the permission management department information, where the permission request message is used to request the permission management department to grant permission to access the data; When the data privacy density parameter indicates that the data in the database system is allowed to be accessed by the target operation instruction, directly execute the target operation instruction to implement the storage and / or reading operation of the data in the database system.

7. The data management method according to claim 1, wherein In the case that the content service list is not received within the first preset duration after the front-end device sends the data-related instruction, the front-end device is further configured to: Send a first test instruction to the control end; In the case that the first verification instruction returned by the control end is not received within the second preset duration after sending the first test instruction, send a first warning message, where the first warning message is used to indicate that the front-end device has a fault; In the case that the first verification instruction is received within the second preset duration after sending the first test instruction, send a database system detection instruction to the control end, where the control end is configured to send a second test instruction to the database system in the case of receiving the database system detection instruction, and send a second warning message in the case that the second verification instruction returned by the database system is not received within the third preset duration after sending the second test instruction, where the second warning message is used to indicate that the database system has a fault.

8. A data management device, characterized in that, Include: A list acquisition module, configured to respond to a data-related instruction sent by a front-end device, acquire a content service list generated by a database system corresponding to the data-related instruction, and send the content service list to the front-end device, where the data-related instruction is used to indicate the type of data processing operation planned to be executed by a user; An instruction acquisition module, configured to acquire a target operation instruction sent by the front-end device, where the target operation instruction is triggered when the user selects at least one service option in the content service list, and the target operation instruction is used to perform a data processing operation on data corresponding to the service option in the database system; A privacy analysis module for determining a data privacy parameter corresponding to the target operation instruction and, based on the data privacy parameter, determining a data management policy corresponding to the execution of the target operation instruction, where the data privacy parameter is used to characterize the privacy level of the data planned to be accessed by the target operation instruction.

9. An electronic device, characterized in that, Comprising: A memory and a processor, the processor being configured to run a program stored in the memory, where the program, when running, executes the data management method according to any one of claims 1 to 7.

10. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored computer program, where the device where the non-volatile storage medium is located executes the data management method according to any one of claims 1 to 7 by running the computer program.

11. A computer program product, comprising a computer program, characterized in that, The computer program, when executed by a processor, implements the steps of the data management method according to any one of claims 1 to 7.