Data cross-border security guarantee method

By marking sensitive information and analyzing the data flow, generating a desensitized feature map, formulating strategies and negotiating and adjusting it, combining encryption and blockchain auditing, complexity and dynamic supervision issues in cross-border data security guarantees are solved, and the balance between data security and availability is achieved.

CN120378135APending Publication Date: 2025-07-25GUANGXI BEITOU XINCHUANG TECH INVESTMENT GRP CO LTD
View PDF 0 Cites 8 Cited by

Patent Information

Application Number
CN202510323886.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

Existing cross-border data security guarantee methods are difficult to effectively respond to complex data security challenges, cannot deeply understand data content, is difficult to adapt to dynamic regulatory requirements, limit data availability, and makes it difficult to balance the contradiction between security and availability.

Method used

By obtaining the original data stream, sensitive information marking and contextual relationship analysis, generating a desensitization feature map, formulating source-end and target-end strategies, conducting policy negotiation and dynamic adjustment, combining context-aware deformation, hierarchical encryption and blockchain auditing, the secure transmission and availability guarantee of data are achieved.

Benefits of technology

It realizes that in the process of cross-border data transmission, data security and compliance are not only guaranteed, but also retains data availability to the greatest extent, supports cross-border data collaboration and innovative applications, and provides flexible and efficient cross-border data security guarantees.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378135A_ABST
    Figure CN120378135A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data cross-border management, in particular to a data cross-border security guarantee method. The method comprises the following steps: acquiring an original data stream; performing sensitive information marking on the original data stream to obtain a sensitive information mark; performing context relation analysis on the sensitive information label to obtain a context relation structure; performing semantic abstract replacement according to the sensitive information label and the context relation structure to obtain preliminary anonymized data; generating a desensitization characteristic spectrum according to the preliminary anonymization data to obtain the desensitization characteristic spectrum; making a source end strategy according to the desensitization characteristic spectrum to obtain a source end initial strategy; and carrying out policy negotiation according to the source end initial policy, and carrying out policy dynamic adjustment to obtain a negotiated and adjusted policy. According to the method, a more intelligent, flexible and efficient data cross-border security guarantee method is realized based on a semantic desensitization and context reconstruction method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cross-border data management, and particularly to a method for cross-border data security protection. Background Art

[0002] Existing cross-border data security protection methods are difficult to effectively cope with the increasingly complex data security challenges. Simple data encryption and transmission means, although able to provide basic confidentiality protection, often prove inadequate when faced with different data regulatory requirements and emerging security threats in different countries and regions. Especially in the scenario of cross-border data collaborative analysis, how to maximize the availability and analysis value of data while ensuring data security has become an urgent problem to be solved.

[0003] Traditional cross-border data security methods mainly have the following deficiencies:

[0004] 1. Lack of understanding of data content: Most existing methods are unable to deeply understand the content of data, making it difficult to distinguish sensitive information from non-sensitive information, resulting in a "one-size-fits-all" security strategy. This either overprotects and restricts the normal use of data, or provides insufficient protection and leaves security risks.

[0005] 2. Difficulty in adapting to dynamic regulatory requirements: The regulatory environments of various countries and regions change dynamically, and existing static security strategies are difficult to flexibly adjust to meet new compliance requirements, increasing the difficulty and cost of cross-border data circulation.

[0006] 3. Restriction of data availability: To meet security requirements, some methods overly encrypt or anonymize data, resulting in the loss of its due analysis value and the inability to support cross-border data collaboration and innovative applications.

[0007] Therefore, there is an urgent need for a more intelligent, flexible and efficient cross-border data security protection method to balance security and availability and promote the safe and orderly flow of cross-border data. Summary of the Invention

[0008] Based on this, it is necessary to provide a cross-border data security protection method to solve at least one of the above technical problems.

[0009] To achieve the above object, a cross-border data security protection method includes the following steps:

[0010] Step S1: Obtain the original data stream; perform sensitive information marking on the original data stream to obtain sensitive information annotation; perform context relationship parsing on the sensitive information annotation to obtain a context relationship structure; perform semantic abstraction replacement based on the sensitive information annotation and the context relationship structure to obtain preliminary anonymized data; generate a desensitization feature map based on the preliminary anonymized data to obtain a desensitization feature map;

[0011] Step S2: Obtain source - side security requirement data and target - side security requirement data; the source side formulates an initial source - side policy based on the source - side security requirement data and the desensitization feature map to obtain an initial source - side policy; the target side formulates an initial target - side policy based on the target - side security requirement data to obtain an initial target - side policy; conduct policy negotiation based on the initial source - side policy and the initial target - side policy, and perform policy dynamic adjustment to obtain a negotiated and adjusted policy; perform policy confirmation and signing on the negotiated and adjusted policy to obtain a consensus - reached policy;

[0012] Step S3: The source side performs context - aware transformation execution on the original data stream according to the desensitization feature map and the consensus - reached policy to obtain transformed data; perform structured adjustment on the transformed data according to the consensus - reached policy, and perform hierarchical encryption processing to obtain hierarchical encrypted data segments; perform payload encapsulation on the hierarchical encrypted data segments to obtain transformed encrypted payloads;

[0013] Step S4: Transmit the transformed encrypted payload to the target side, perform unpacking of the transformed encrypted payload to obtain data segments to be reconstructed; perform hierarchical decryption on the data segments to be reconstructed, and perform reverse transformation to obtain data to be authorized for access; perform identity authentication and permission parsing on the user requesting access to obtain a user permission list; generate a policy - driven view of the data to be authorized for access according to the user permission list to obtain an authorized access view;

[0014] Step S5: Through a listener, monitor and capture the data cross - border process to obtain an audit event record; construct a blockchain - based trusted audit chain according to the audit event record to obtain a trusted audit chain; query and verify audit information on the trusted audit chain to obtain an audit report, so as to achieve the task of ensuring data cross - border security.

[0015] The present invention realizes the preliminary desensitization and structuring of data through data cleaning, sensitive information identification, contextual relationship analysis and semantic abstract replacement, laying the foundation for subsequent policy negotiation and data deformation, while improving the efficiency and accuracy of data processing and retaining the availability of data to the greatest extent. Through the formulation, exchange, difference analysis, negotiation and confirmation of source and target end policies, a consistent security policy is finally reached, ensuring the security and compliance of data in the cross-border transmission process, while taking into account the needs and interests of both parties, and realizing flexible policy formulation. Through operations such as context-aware deformation, structural adjustment, layered encryption and payload encapsulation, data is protected at multiple levels, ensuring the confidentiality and integrity of data during transmission, while improving the efficiency of data transmission. Through operations such as payload unpacking, layered decryption, reverse deformation, user identity authentication, authority parsing and view generation, secure reconstruction and controlled access to data are realized, ensuring that only authorized users can access data, and controlling the access scope according to their authority, achieving a balance between data security and data availability. Through operations such as event monitoring, data capture, structured processing, summary generation, transaction construction, blockchain storage and audit query, a full audit of the cross-border data process is achieved, ensuring the traceability of operations, the integrity of data and the reliability of audits, providing strong protection for compliance reviews. Therefore, the present invention provides a cross-border data security assurance method, which is based on the "semantic desensitization and context reconstruction" method, combined with the technical means of policy negotiation, context-aware deformation, layered encryption and blockchain auditing, and effectively solves the complex regulatory environment, continuously evolving security threats, and the contradiction between the needs and security challenges of cross-border collaborative analysis faced by the current cross-border data security assurance field. A more intelligent, flexible and efficient cross-border data security assurance method is achieved.

[0016] Preferably, step S1 comprises the following steps:

[0017] Step S11: obtaining the original data stream; performing preliminary cleaning on the original data stream to obtain loaded data;

[0018] Step S12: identifying sensitive information of the loaded data and marking the sensitive information to obtain a sensitive information label;

[0019] Step S13: performing contextual relationship analysis on the sensitive information annotation to obtain a contextual relationship structure;

[0020] Step S14: Perform semantic abstract replacement according to the sensitive information annotation and context relationship structure to obtain preliminary anonymized data;

[0021] Step S15: constructing a graph structure based on the preliminary anonymized data and the contextual relationship structure to obtain a feature graph to be reviewed;

[0022] Step S16: Conduct map review on the feature map to be reviewed and perform map correction to obtain a desensitized feature map.

[0023] Through the preliminary cleaning operation, the present invention improves the data quality, ensures the effectiveness and consistency of the data processed in subsequent steps, avoids the interference of dirty data or data with incorrect formats on steps such as sensitive information identification and context relationship parsing, and improves the reliability of the entire cross-border data security protection method. Accurately identifying and marking sensitive information is the basis for subsequent desensitization operations, ensuring that only sensitive information will be included in the protection scope, avoiding over-processing of non-sensitive information, and while ensuring data security, maximizing the availability and analysis value of the data. Context relationship parsing enables the system to understand the association and dependency relationships between sensitive information, provides richer semantic information for subsequent semantic abstraction replacement and strategy formulation, thereby realizing more refined and intelligent desensitization and reconstruction, and enhancing the accuracy and effectiveness of cross-border data security protection. Semantic abstraction replacement effectively masks the specific values of sensitive information while retaining the data structure and context relationship, achieving preliminary anonymization processing, reducing the security risks during cross-border data transmission, and providing more secure intermediate data for subsequent transformation and encryption operations. Converting the data into a map structure more clearly shows the relationships between the data, provides a more intuitive expression for subsequent policy negotiation and data transformation, facilitates more in-depth analysis and understanding of the data, and helps to formulate more reasonable cross-border data security strategies. Map review and correction ensure the accuracy and integrity of the map, eliminate the influence of potential incorrect or abnormal data on subsequent steps, further improve the reliability and availability of the desensitized feature map, and provide a more reliable basis for subsequent data transformation and reconstruction.

[0024] Preferably, step S14 includes the following steps:

[0025] Step S141: Classify sensitive information according to sensitive information annotation and a pre-constructed tag library to obtain sensitive information classification data;

[0026] Step S142: Perform context information matching on the sensitive information classification data and the context relationship structure to obtain context-related sensitive information;

[0027] Step S143: Select a replacement strategy according to the context-related sensitive information and the pre-constructed tag library to obtain the information to be replaced and the strategy;

[0028] Step S144: Execute semantic replacement according to the information to be replaced and the strategy to obtain a replaced data segment;

[0029] Step S145: Integrate the original data stream and the replaced data segment to obtain preliminarily anonymized data.

[0030] By classifying sensitive information, the present invention can manage and process different types of sensitive information more precisely, laying a foundation for subsequent selection of appropriate replacement strategies, and improving the pertinence and effectiveness of semantic abstract replacement. Associating sensitive information with its context information can more accurately understand the meaning and role of sensitive information, avoiding semantic loss or misunderstanding that may be caused by processing sensitive information in isolation, thereby improving the accuracy and effectiveness of the replacement strategy. Selecting an appropriate replacement strategy based on context-associated sensitive information can better balance data security and data availability, ensuring that while protecting sensitive information, the analysis value of the data is retained as much as possible, achieving more flexible and intelligent desensitization processing. Semantic replacement execution replaces specific sensitive information with semantic labels or other alternative values, effectively masking the sensitive information, reducing the risk of data leakage, while retaining the structure and context information of the data, facilitating subsequent data analysis and utilization. Integrating the replaced data fragments back into the original data stream ensures data integrity and consistency, forming a preliminarily anonymized data set, providing a more secure data foundation for subsequent cross-border transmission and processing.

[0031] Preferably, step S2 includes the following steps:

[0032] Step S21: Obtain the source-side security requirement data. The source side formulates the source-side initial policy based on the desensitization feature map and the source-side security requirement data.

[0033] Step S22: Obtain the target-side expected data usage and the target-side security requirement data. The target side formulates the target-side initial policy based on the target-side expected data usage and the target-side security requirement data.

[0034] Step S23: Exchange the source-side initial policy and the target-side initial policy, and perform policy difference analysis in parallel to obtain a policy difference report.

[0035] Step S24: Conduct policy negotiation based on the policy difference report, the source-side initial policy, and the target-side initial policy, and perform dynamic policy adjustment to obtain the negotiated and adjusted policy.

[0036] Step S25: Confirm and sign the negotiated and adjusted policy to obtain the agreed-upon policy.

[0037] Through formulating the initial source - side strategy, this invention clarifies the specific requirements for data security and privacy protection on the source side during cross - border data transmission, provides a basis for subsequent policy negotiation, and ensures that the data security policy on the source side is consistent with the actual data situation, such as sensitive data types and distributions. The formulation of the target - side strategy takes into account data usage and security requirements, ensuring that the received data not only meets its usage needs but also complies with its security specifications, providing constraints from the target - side for subsequent policy negotiation. Policy exchange and difference analysis enable both parties to clearly understand each other's security requirements and policy differences, provide a clear direction for subsequent policy negotiation and adjustment, and improve efficiency through parallel processing. The policy negotiation and dynamic adjustment mechanism can effectively resolve policy conflicts between the source side and the target side. By combining automatic negotiation and manual intervention, a compromise solution acceptable to both parties is finally reached, ensuring a balance between the security and availability of cross - border data transmission. The policy confirmation and signing steps ensure the non - deniability and traceability of the negotiated policy, provide a credible basis for subsequent data transformation, reconstruction, and auditing, and guarantee the recognition and compliance of both parties with the final policy.

[0038] Preferably, step S24 includes the following steps:

[0039] Step S241: Perform a difference priority ranking on the policy difference report to obtain policy difference ranking data;

[0040] Step S242: Obtain historical negotiation records; use the historical negotiation records and a pre - constructed expert knowledge base to generate policy adjustments based on the policy difference ranking data to obtain policy adjustment suggestion data;

[0041] Step S243: Select a negotiation plan based on the policy adjustment suggestion data, the initial source - side policy, and the initial target - side policy to obtain a preliminary negotiation plan;

[0042] Step S244: Verify the plan for the preliminary negotiation plan and perform plan conflict detection to obtain a plan verification result;

[0043] Step S245: Iteratively optimize the plan based on the plan verification result, the preliminary negotiation plan, the initial source - side policy, the initial target - side policy, the historical negotiation records, and the pre - constructed expert knowledge base to obtain the adjusted - after - negotiation policy.

[0044] Through differential priority sorting, the negotiation process of the present invention is more targeted, which can give priority to processing key fields or important policy differences, improve the negotiation efficiency, and ensure that key data is protected preferentially. By using historical negotiation records and expert knowledge bases, it is possible to provide references and guidance for policy adjustment, avoid repeated and ineffective negotiations, and generate more reasonable policy adjustment suggestions based on past experience and expert opinions, thereby improving the intelligence level of negotiation. Based on the policy adjustment suggestion data, the negotiation plan is selected, which can more quickly find a policy that meets the needs of both parties, reduce the number of negotiation iterations, improve the negotiation efficiency, and ensure the rationality and feasibility of the preliminary plan. Scheme verification and conflict detection can detect potential problems early, avoid applying incorrect or conflicting policies to actual data transmission, and ensure the security, effectiveness, and consistency of the negotiation plan. The iterative optimization process continuously improves the negotiation plan. Through repeated verification and adjustment, a policy that meets the security requirements of both parties and has no conflicts is finally obtained, ensuring the security and reliability of cross-border data transmission and maximizing the retention of data availability.

[0045] Preferably, step S3 includes the following steps:

[0046] Step S31: Parse the negotiated policy, and generate transformation rule generation for policy determination in combination with the desensitization feature map to obtain a transformation rule list;

[0047] Step S32: The source end performs context-aware transformation execution on the original data stream according to the desensitization feature map and the transformation rule list to obtain transformed data;

[0048] Step S33: Perform structured adjustment and reorganization on the transformed data according to the negotiated policy to obtain structured transformed data;

[0049] Step S34: Perform hierarchical encryption processing on the structured transformed data according to the negotiated policy to obtain hierarchical encrypted data segments;

[0050] Step S35: Perform metadata encapsulation on the hierarchical encrypted data segments according to the desensitization feature map to obtain metadata encapsulated data; perform data segment marking on the encapsulated data according to the negotiated policy to obtain tokenized encrypted data;

[0051] Step S36: Perform payload encapsulation and transmission preparation on the tokenized encrypted data in a predetermined format to obtain a transformed encrypted payload.

[0052] The present invention generates a list of transformation rules by parsing the consensus strategy and combining the desensitization feature map, ensuring the accuracy and pertinence of the transformation operation. It can accurately transform data according to the preset strategy, while considering the context information of the data, providing clear guidance for subsequent transformation operations. Context-aware transformation execution can perform flexible transformation according to the specific semantics and context environment of the data, maximizing the retention of the analytical value of the data while protecting sensitive information, and improving the flexibility and security of cross-border data transmission. Structured adjustment and reorganization can optimize the organizational structure of the data to better meet the data processing requirements at the target end, improve the usability of the data at the target end, and further enhance the data privacy protection effect. Hierarchical encryption processing adopts different encryption strategies according to the sensitivity of different data fields, reducing unnecessary computational overhead while ensuring data security, and achieving more refined and efficient data security protection. Metadata encapsulation and data segment marking provide the necessary context information and operation guidance for data reconstruction at the target end, ensuring that the target end can correctly decrypt and restore the data and understand the desensitization method of the data. Payload encapsulation and transmission preparation steps convert the data into a transmissible format and perform necessary compression and encoding, improving the efficiency and security of data transmission and completing the final preparation for cross-border data transmission.

[0053] Preferably, step S32 includes the following steps:

[0054] Step S321: Parse the transformation rule list to obtain the parsed transformation rules;

[0055] Step S322: Distribute the original data stream using the desensitization feature map and perform context association to obtain the data units to be processed;

[0056] Step S323: Match the data units to be processed according to the parsed transformation rules and perform transformer routing to obtain the transformation instructions to be executed;

[0057] Step S324: Execute the basic transformation operation according to the transformation instructions to be executed to obtain the preliminarily transformed data;

[0058] Step S325: Perform transformation chain processing on the preliminarily transformed data according to the transformation instructions to be executed and perform result merging to obtain the transformation result of the current unit;

[0059] Step S326: Output the transformed data stream according to the transformation result of the current unit to obtain the transformed data.

[0060] The present invention parses the list of transformation rules, converts the rules into an executable format, improves the processing efficiency of the transformation engine, and prepares for subsequent rule matching and transformation operations. Data flow distribution and context association combine data with its context information, providing more complete information for subsequent transformation operations, enabling the transformation engine to perform more refined processing based on the context, and supporting distributed processing to improve efficiency. Rule matching and transformer routing associate the data units to be processed with the corresponding transformation rules and transformers, ensuring that each data unit is correctly transformed and realizing the automation and intelligence of the transformation operation. Execute basic transformation operations to perform preliminary transformation processing on the data, such as replacement, generalization, encryption, etc., laying a foundation for subsequent chained processing and result merging. Chained transformation processing and result merging support complex and multi-step transformation operations on the data and can merge the results of multiple transformation operations into the final transformed result, improving the flexibility and efficiency of data transformation. Output the transformed data units to form a complete transformed data stream, completing the data transformation process and preparing for subsequent data transmission and processing.

[0061] Preferably, step S4 includes the following steps:

[0062] Step S41: Transmit the transformed encrypted payload to the target end, and the target end decrypts the transformed encrypted payload to obtain the data segment to be reconstructed;

[0063] Step S42: Load the policy and graph according to the data segment to be reconstructed to obtain the loaded policy graph;

[0064] Step S43: Perform hierarchical decryption on the data segment to be reconstructed according to the loaded policy graph and perform reverse transformation to obtain the data to be authorized for access;

[0065] Step S44: Authenticate the user requesting access to the data to obtain the authentication data; parse the permissions of the authentication data according to the predefined access control policy to obtain the user permission list;

[0066] Step S45: Generate a policy-driven view of the data to be authorized for access according to the user permission list and the loaded policy graph to obtain the authorized access view.

[0067] The present invention securely transmits the deformed encrypted payload to the target end and decrypts it, preparing the necessary encrypted data and metadata for subsequent data reconstruction operations, ensuring the confidentiality and integrity of the data during transmission. Loading the policy and map information provides guidance for subsequent decryption and reverse deformation operations, ensuring that the target end can correctly reconstruct the data according to the predetermined policy and data structure. The hierarchical decryption and reverse deformation operations restore the encrypted data to its original state and restore the original structure and semantics of the data, preparing for subsequent authorized access control. User identity authentication and permission parsing ensure that only authorized users can access the data and control the scope and granularity of their access to the data according to the user's role and permissions, achieving fine-grained data access control. Generating an authorized access view based on the user permissions and policy map ensures that users can only access the data they are authorized to and access the data in a manner that conforms to their permissions and needs, achieving a balance between data security and data availability.

[0068] Preferably, step S43 includes the following steps:

[0069] Step S431: Locate the key according to the data segment to be reconstructed and the loaded policy map, and perform permission verification to obtain the data segment to be decrypted and the corresponding key information;

[0070] Step S432: Identify the decryption algorithm for the data segment to be decrypted and the corresponding key information to obtain the decrypted data segment;

[0071] Step S433: Extract reverse rules from the loaded policy map to obtain reverse rules; sort the reverse rules to obtain a sequence of reverse rules to be executed;

[0072] Step S434: Perform basic reverse operation execution on the decrypted data segment according to the sequence of reverse rules to be executed to obtain basic reverse restored data;

[0073] Step S435: Perform reverse structural adjustment execution on the basic reverse restored data according to the sequence of reverse rules to be executed to obtain structurally reverse adjusted data;

[0074] Step S436: Perform data integrity verification on the structurally reverse adjusted data according to the loaded policy map to obtain verified data; merge the reconstructed data for the verified data to obtain data to be authorized for access.

[0075] Through key positioning and permission verification, the present invention ensures that only the target end system with legitimate permissions can obtain the correct decryption key, preventing unauthorized access and key abuse, and guaranteeing the security of data decryption. Accurately identifying the decryption algorithm and performing the decryption operation restores the encrypted data segment into readable plaintext data, providing a basis for subsequent reverse transformation operations. Extracting and sorting reverse rules ensures that the reverse transformation operations are executed in the correct order, enabling effective restoration of the data to its pre-transformation state and avoiding data restoration failures or errors caused by incorrect order. Performing basic reverse operations, such as de-generalization and de-replacement, gradually restores the data to its pre-transformation state, preparing for subsequent reverse structure adjustment operations. The reverse structure adjustment operation restores the structure of the data to its pre-transformation state, such as splitting merged fields, ensuring that the data structure is consistent with the original data. Data integrity verification ensures that the data has not been tampered with during the decryption and reverse transformation processes, guaranteeing the reliability of the data. Reconstructing data merging combines all the verified data segments into a complete record, preparing for subsequent authorized access control.

[0076] Preferably, step S5 includes the following steps:

[0077] Step S51: Monitor the data cross-border process through a listener to obtain data cross-border process events; capture the data cross-border process events to obtain audit event records;

[0078] Step S52: Structure the event data of the audit event records and generate a digest to obtain an audit data digest;

[0079] Step S53: Construct a transaction from the audit data digest and perform a digital signature to obtain a transaction to be submitted;

[0080] Step S54: Broadcast the transaction to be submitted to each node in the blockchain network for node consensus confirmation and block generation to obtain block data;

[0081] Step S55: Link the block data in a chain structure to obtain a trusted audit chain;

[0082] Step S56: Query and verify the audit information of the trusted audit chain to obtain an audit report.

[0083] The present invention provides a complete event record for subsequent audits by listening for and capturing key events in the cross-border data process, ensuring that all key operations are recorded and achieving the traceability of operations. Structuring and digest generation simplify the storage and processing of audit data, and the integrity of the data is guaranteed through hash digests, enabling quick verification of whether the data has been tampered with. Constructing transactions and performing digital signatures ensure the non-repudiation and anti-tampering of audit data. Only entities with the private key can generate valid signatures, thus ensuring the authenticity of audit data. Broadcasting the transactions to the blockchain network and reaching a consensus guarantee the distributed storage and consistency of audit data. No single node can tamper with the data alone, improving the reliability and security of audit data. The chained structure links all blocks together to form an immutable audit chain, further enhancing the security of audit data. Any tampering with historical data will be immediately detected. The audit information query and verification functions facilitate the review and supervision of the cross-border data process by auditors and can generate audit reports, providing reliable evidence for compliance reviews. BRIEF DESCRIPTION OF THE DRAWINGS

[0084] Figure 1 It is a schematic diagram of the step flow of a method for ensuring cross-border data security;

[0085] Figure 2 It is a schematic diagram of the detailed implementation steps of step S1 in the present invention;

[0086] Figure 3 It is a schematic diagram of the detailed implementation steps of step S2 in the present invention.

[0087] The realization of the object, functional features and advantages of the present invention will be further described in conjunction with the embodiments with reference to the accompanying drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0088] The technical method of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0089] In addition, the accompanying drawings are only schematic diagrams of the present invention and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and thus their repeated description will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. The functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor methods and / or microcontroller methods.

[0090] It should be understood that although terms such as "first", "second", etc. may be used herein to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, without departing from the scope of the exemplary embodiments, the first unit may be referred to as the second unit, and similarly, the second unit may be referred to as the first unit. The term "and / or" used herein includes any and all combinations of one or more of the listed associated items.

[0091] To achieve the above object, please refer to Figures 1 to 3 , a method for ensuring cross-border data security, comprising the following steps:

[0092] Step S1: Obtain the original data stream; perform sensitive information marking on the original data stream to obtain sensitive information annotation; perform context relationship parsing on the sensitive information annotation to obtain a context relationship structure; perform semantic abstraction substitution based on the sensitive information annotation and the context relationship structure to obtain preliminary anonymized data; generate a desensitization feature map based on the preliminary anonymized data to obtain a desensitization feature map;

[0093] Step S2: Obtain source-side security requirement data and target-side security requirement data; the source side formulates a source-side initial policy based on the source-side security requirement data and the desensitization feature map to obtain a source-side initial policy; the target side formulates a target-side initial policy based on the target-side security requirement data to obtain a target-side initial policy; perform policy negotiation based on the source-side initial policy and the target-side initial policy, and perform policy dynamic adjustment to obtain a negotiated and adjusted policy; perform policy confirmation and signing on the negotiated and adjusted policy to obtain a consensus policy;

[0094] Step S3: The source side performs context-aware deformation execution on the original data stream according to the desensitization feature map and the consensus policy to obtain deformed data; perform structured adjustment on the deformed data according to the consensus policy, and perform hierarchical encryption processing to obtain hierarchical encrypted data segments; perform payload encapsulation on the hierarchical encrypted data segments to obtain deformed encrypted payloads;

[0095] Step S4: Transmit the deformed encrypted payload to the target side, perform unpacking of the deformed encrypted payload to obtain data segments to be reconstructed; perform hierarchical decryption on the data segments to be reconstructed, and perform reverse deformation to obtain data to be authorized for access; perform identity authentication and permission parsing on the user requesting access to obtain a user permission list; generate a policy-driven view of the data to be authorized for access according to the user permission list to obtain an authorized access view;

[0096] Step S5: Monitor and capture the data cross - border process through a listener to obtain an audit event record; construct a blockchain - based trusted audit chain according to the audit event record to obtain a trusted audit chain; query and verify audit information for the trusted audit chain to obtain an audit report, so as to achieve the task of ensuring data cross - border security.

[0097] In the embodiment of the present invention, refer to Figure 1 As shown, it is a schematic diagram of the step - by - step process of the data cross - border security guarantee method of the present invention. In this example, the data cross - border security guarantee method includes the following steps:

[0098] Step S1: Obtain the original data stream; mark the sensitive information for the original data stream to obtain sensitive information annotation; parse the context relationship for the sensitive information annotation to obtain a context relationship structure; perform semantic abstraction substitution according to the sensitive information annotation and the context relationship structure to obtain preliminarily anonymized data; generate a desensitization feature map based on the preliminarily anonymized data to obtain a desensitization feature map;

[0099] In the embodiment of the present invention, the original data stream is obtained from a MySQL database and preliminarily cleaned, including format verification and missing value filling. The BERT model is used for named entity recognition to mark sensitive information. Stanford CoreNLP is used for dependency syntax analysis to parse the context relationship and store it in a Neo4j graph database. Sensitive information is semantically abstracted and replaced according to a predefined tag library and context relationship. Finally, a desensitization feature map is constructed based on the preliminarily anonymized data and the context relationship, and Spark GraphX is used for map review and correction and stored in the Neo4j database.

[0100] Step S2: Obtain the source - side security requirement data and the target - side security requirement data; the source - side formulates a source - side initial policy based on the source - side security requirement data and the desensitization feature map to obtain a source - side initial policy; the target - side formulates a target - side initial policy based on the target - side security requirement data to obtain a target - side initial policy; perform policy negotiation according to the source - side initial policy and the target - side initial policy, and perform dynamic policy adjustment to obtain a negotiated and adjusted policy; confirm and sign the negotiated and adjusted policy to obtain a negotiated and consistent policy;

[0101] In the embodiments of the present invention, the source end and the target end respectively formulate initial policies according to their respective security requirement data and expected data usage. The source end policy also refers to the desensitization feature map. The policies are stored in JSON format and include allowed fields, desensitization methods, and levels. The two parties exchange policies through a TLS secure connection and perform parallel differential analysis to generate a differential report. Based on the differential report, historical negotiation records, and the expert knowledge base in the Drools rule engine, automatic or manual negotiation and policy adjustment are carried out. Finally, the two parties use the RSA algorithm to digitally sign the negotiated policy and verify the signature to form a consensus policy.

[0102] Step S3: The source end performs context-aware transformation execution on the original data stream according to the desensitization feature map and the consensus policy to obtain the transformed data; performs structured adjustment on the transformed data according to the consensus policy, and performs hierarchical encryption processing to obtain hierarchical encrypted data segments; performs payload encapsulation on the hierarchical encrypted data segments to obtain transformed encrypted payloads;

[0103] In the embodiments of the present invention, the source end generates a transformation rule list according to the desensitization feature map and the consensus policy. Use Spark to traverse the original data stream and perform transformation operations such as replacement, generalization, and encryption according to the rule list and context information. The transformed data is structurally adjusted, such as field merging or splitting. Then, the data is hierarchically encrypted according to the policy, and JCA and KMS are used for key management. Finally, metadata, data segment markers are added, and ProtocolBuffers serialization, gzip compression, and Base64 encoding are used to encapsulate into transformed encrypted payloads.

[0104] Step S4: Transmit the transformed encrypted payload to the target end, perform unpacking of the transformed encrypted payload to obtain the data segments to be reconstructed; perform hierarchical decryption on the data segments to be reconstructed and perform reverse transformation to obtain the data to be authorized for access; perform identity authentication and permission parsing on the user requesting access to obtain a user permission list; generate a policy-driven view of the data to be authorized for access according to the user permission list to obtain an authorized access view;

[0105] In the embodiments of the present invention, the target end receives the transformed encrypted payload through HTTPS and performs unpacking, decoding, and deserialization. Load the consensus policy and the desensitization feature map. According to the policy and the map, use KMS to obtain the key and perform hierarchical decryption and reverse transformation on the data. The user uses the OAuth 2.0 protocol for identity authentication, and the system parses the user permissions according to the RBAC policy. Finally, according to the user permissions and the policy map, use Spark SQL to generate an authorized access view.

[0106] Step S5: Monitor and capture the data cross-border process through a listener to obtain an audit event record; construct a trusted audit chain based on the blockchain according to the audit event record to obtain a trusted audit chain; query and verify audit information for the trusted audit chain to obtain an audit report, so as to implement the data cross-border security guarantee task;

[0107] In the embodiment of the present invention, listeners are deployed at the source end and the target end, and AspectJ is used to capture key events of the data cross-border process and record them in a log file. The log records are structured into a JSON format, and a digest is generated using the SHA-256 algorithm. The digest and JSON data are constructed into a blockchain transaction, and digital signatures are performed using the ECDSA algorithm. The signed transaction is submitted to the Hyperledger Fabric network, and after consensus confirmation, a block is generated and linked to the trusted audit chain. Authorized users can use the Fabric SDK to query the audit chain and verify the data to generate an audit report.

[0108] Preferably, step S1 includes the following steps:

[0109] Step S11: Obtain the original data stream; perform preliminary cleaning on the original data stream to obtain the loaded data;

[0110] Step S12: Identify sensitive information in the loaded data and perform sensitive information marking to obtain sensitive information annotation;

[0111] Step S13: Parse the context relationship of the sensitive information annotation to obtain a context relationship structure;

[0112] Step S14: Perform semantic abstraction replacement according to the sensitive information annotation and the context relationship structure to obtain preliminary anonymized data;

[0113] Step S15: Construct a graph structure according to the preliminary anonymized data and the context relationship structure to obtain a feature graph to be audited;

[0114] Step S16: Audit the feature graph to be audited and perform graph correction to obtain a desensitized feature graph.

[0115] As an example of the present invention, refer to Figure 2 As shown, in this example, step S1 includes:

[0116] Step S11: Obtain the original data stream; perform preliminary cleaning on the original data stream to obtain the loaded data;

[0117] In an embodiment of the present invention, the data source is a table named `customer_data` in a MySQL database. A connection to the database is established using a JDBC driver. The SQL query statement `SELECT*FROM customer_data` retrieves all customer data. The retrieved data is stored in a memory buffer in the form of a data stream. Each row of data in the memory buffer is traversed, and it is checked whether the data format conforms to a predefined JSON Schema specification. For data records that do not conform to the specification, error information is recorded and discarded. For data records missing the `age` field, the average age value of `35` is used for filling. All data that conforms to the specification and has been preprocessed is loaded into a DataFrame of Apache Spark to form "loaded data".

[0118] Step S12: Identify sensitive information from the loaded data and perform sensitive information marking to obtain sensitive information annotation;

[0119] In an embodiment of the present invention, data is read row by row from the loaded Spark DataFrame. A pre-trained named entity recognition (NER) model based on the BERT architecture is used to identify sensitive information in the `name`, `address`, `phone`, and `id_card` fields. The identified sensitive information types and their start and end positions in the text are stored as JSON-formatted tags, such as `{"entity": "name", "start": 0, "end": 5}`. All identified sensitive information tags are added to a new `sensitive_info` column in the corresponding DataFrame row to form "sensitive information annotation".

[0120] Step S13: Parse the context relationship of the sensitive information annotation to obtain a context relationship structure;

[0121] In an embodiment of the present invention, the Stanford CoreNLP library is used to perform dependency syntactic analysis on the `description` field in the loaded data. The relationships between sensitive information are extracted. For example, if the `name` entity and the `address` entity appear in the same sentence and the `address` is a modifier of the `name`, a "residence" relationship is established. These relationships are stored in a graph structure, where nodes represent sensitive information entities and edges represent the relationship types between entities, such as (Zhang San)-[residence]->(Chaoyang District, Beijing). All parsed relationships are stored in a Neo4j graph database to form a "context relationship structure".

[0122] Step S14: Perform semantic abstraction and replacement based on sensitive information annotation and context relationship structure to obtain preliminary anonymized data;

[0123] In the embodiment of the present invention, each row of data in the Spark DataFrame is traversed. According to the labels in the `sensitive_info` column, the `name` field is replaced with `<person's name>`, the `address` field is replaced with `<address>`, the `phone` field is replaced with `<phone number>`, and the `id_card` field is replaced with `<ID card>`. If there is a "residence" relationship between `name` and `address`, then `<address>` is further refined to `<residential address>`. The replaced data is stored in a new Spark DataFrame to form "preliminary anonymized data".

[0124] Step S15: Construct a graph structure based on the preliminary anonymized data and context relationship structure to obtain a feature graph to be audited;

[0125] In the embodiment of the present invention, each row of data in the preliminary anonymized data is used as a node in the graph. The node attributes include all non-sensitive fields and the replaced sensitive field labels. Using the context relationship structure stored in the Neo4j database in step S13, edges are established between the graph nodes. For example, if the `name` fields of two nodes are the same, an edge of "the same person" is established. The constructed graph is stored in the Neo4j database to form a "feature graph to be audited".

[0126] Step S16: Audit the feature graph to be audited and perform graph correction to obtain a desensitized feature graph.

[0127] In the embodiment of the present invention, the Apache Spark GraphX is used to load the feature graph to be audited. Execute graph algorithms to detect whether there are cyclic structures in the graph. If so, record and mark them. Manually audit the marked cyclic structures to determine whether they are caused by abnormal data. If it is confirmed that they are abnormal data, the corresponding nodes and edges are deleted. Manually audit the nodes with too high degrees in the graph to confirm whether their connection relationships are correct. The audited and corrected graph is stored back in the Neo4j database to form a "desensitized feature graph".

[0128] Preferably, step S14 includes the following steps:

[0129] Step S141: Classify sensitive information according to sensitive information annotation and a pre-constructed label library to obtain sensitive information classification data;

[0130] Step S142: Perform context information matching on the sensitive information classification data and the context relationship structure to obtain context-related sensitive information;

[0131] Step S143: Select a replacement strategy based on the context-related sensitive information and the pre-built tag library to obtain the information to be replaced and the strategy;

[0132] Step S144: Execute semantic replacement according to the information to be replaced and the strategy to obtain the replaced data fragment;

[0133] Step S145: Integrate the original data stream and the replaced data fragment to obtain the preliminary anonymized data.

[0134] In the embodiment of the present invention, the pre-built tag library is stored in JSON format, including tag names, hierarchical relationships, and regular expression rules, such as `{"tag": "email", "regex": "[^@]+@[^@]+\\.[^@]+"}`. Read each tag from the sensitive information annotation generated in Step S12. Use a regular expression library (such as the `re` module in Python) to match the sensitive information with the regular expressions in the tag library. If the sensitive information matches the regular expression of a certain tag, assign that tag to the sensitive information. For example, if the `email` field value "test@example.com" matches the regular expression of the `email` tag, assign the `email` tag to this field value. Store all the classified sensitive information and the corresponding tags in a new Spark DataFrame column `classified_sensitive_info` to form the "sensitive information classification data".

[0135] Load the context relationship structure from the Neo4j graph database. Traverse the "sensitive information classification data" in the Spark DataFrame. For each classified sensitive information, according to its position information in the original data stream, find the relevant context relationship in the Neo4j database. For example, find information such as "user name" or "registration time" associated with "test@example.com". Add the found context information to the `classified_sensitive_info` column to form a new column `contextual_sensitive_info`, which contains sensitive information, tags, and associated context information, to form the "context-related sensitive information".

[0136] Define a replacement strategy configuration file (in YAML format) that contains replacement strategies for different tags and context conditions. For example, for the `email` tag, if the context contains "public" information, it is replaced with `<public email>`; if the context contains "private" information, the email address is one-way hashed using the SHA-256 hashing algorithm and then replaced. Traverse the `contextual_sensitive_info` column in the DataFrame, and based on the tag and context information, look up the corresponding replacement strategy from the replacement strategy configuration file. Store the sensitive information, tag, context information, and the selected replacement strategy in a new DataFrame column `replacement_strategy` to form "information to be replaced and strategies".

[0137] Traverse the `replacement_strategy` column in the DataFrame. Replace the sensitive information according to the selected replacement strategy. For example, replace "test@example.com" with `<public email>` or its SHA-256 hash value. Store the replaced data fragments in a new DataFrame column `replaced_fragments` to form "replaced data fragments". At the same time, maintain a replacement mapping table that records the correspondence between the original sensitive information and the replaced value for subsequent auditing and reverse operations.

[0138] Create a new Spark DataFrame. Directly copy the fields in the original data stream that are not marked as sensitive information into the new DataFrame. Fill in the replaced data fragments in the `replaced_fragments` column according to the positions of the sensitive information in the original data stream. Finally, the new DataFrame contains all the original data with sensitive information replaced, forming "preliminary anonymized data".

[0139] Preferably, step S2 includes the following steps:

[0140] Step S21: Obtain the source-side security requirement data. The source side formulates the source-side strategy based on the desensitization feature map and the source-side security requirement data to obtain the source-side initial strategy;

[0141] Step S22: Obtain the target-side expected data usage and the target-side security requirement data; the target side formulates the target-side strategy based on the target-side expected data usage and the target-side security requirement data to obtain the target-side initial strategy;

[0142] Step S23: Exchange the source-side initial strategy and the target-side initial strategy, and perform policy difference analysis in parallel to obtain a policy difference report;

[0143] Step S24: Perform policy negotiation based on the policy difference report, the source - side initial policy, and the target - side initial policy, and perform dynamic policy adjustment to obtain the negotiated and adjusted policy;

[0144] Step S25: Perform policy confirmation and signing on the negotiated and adjusted policy to obtain the consensus - reached policy.

[0145] As an example of the present invention, refer to Figure 3 As shown, in this example, step S2 includes:

[0146] Step S21: Obtain the source - side security requirement data. The source - side formulates the source - side policy based on the desensitization feature map and the source - side security requirement data to obtain the source - side initial policy;

[0147] In the embodiment of the present invention, the source - side security requirement data is stored in a configuration file in YAML format, which defines the data fields allowed for cross - border transmission, the allowed desensitization methods (e.g., replacement, generalization, encryption), and the minimum desensitization level for each data field. Read the YAML configuration file and parse it into a Java object. Based on the desensitization feature map, identify all sensitive data fields and their corresponding semantic tags. Traverse each sensitive data field and generate the corresponding desensitization policy according to the definition in the security requirement data. For example, for the `id_card` field, the security requirement data stipulates that it must be encrypted, so a policy of using AES - 256 encryption is generated. Store all the generated policies in the `source_initial_policy.json` file in JSON format to form the "source - side initial policy".

[0148] Step S22: Obtain the target - side expected data usage and the target - side security requirement data; the target - side formulates the target - side policy based on the target - side expected data usage and the target - side security requirement data to obtain the target - side initial policy;

[0149] In the embodiments of the present invention, the expected data usage at the target end is provided in JSON format, for example, `{"purpose": "marketing analysis", "required_fields": ["age", "gender", "city"]}`. The security requirements for the data at the target end are stored in a configuration file in YAML format, which defines the allowed data fields to be received and the allowed desensitization methods. Read and parse the JSON and YAML files. Based on the expected data usage and the security requirements data, formulate the initial policy at the target end. For example, if the expected data usage is for market analysis and the security requirements data allows the receipt of a generalized version of the `city` field, then generate a policy to generalize the `address` field to the city. Store all the policies in the `target_initial_policy.json` file in JSON format to form the "initial policy at the target end".

[0150] Step S23: Perform policy exchange on the initial policy at the source end and the initial policy at the target end, and conduct policy difference analysis in parallel to obtain a policy difference report.

[0151] In the embodiments of the present invention, the source end and the target end exchange the `source_initial_policy.json` and `target_initial_policy.json` files through a secure TLS connection. Use multi-threading to compare the policies in the two JSON files in parallel. For each data field, compare the desensitization methods and desensitization levels at the source end and the target end. If there are differences, record the details of the differences. For example, the source end policy is encryption and the target end policy is generalization. Store all the difference information in the `policy_difference_report.json` file in JSON format to form the "policy difference report".

[0152] Step S24: Perform policy negotiation based on the policy difference report, the initial policy at the source end, and the initial policy at the target end, and conduct dynamic policy adjustment to obtain the negotiated and adjusted policy.

[0153] In the embodiments of the present invention, based on the difference information in the `policy_difference_report.json` file, start an automatic negotiation program. The automatic negotiation program adjusts the policy according to the predefined negotiation rules. For example, if the source end policy is encryption and the target end policy is generalization, then select a more stringent encryption policy according to the predefined rules. If automatic negotiation fails, send the difference information to manual review, and update the policy after manual review. Store the adjusted policy in the `negotiated_policy.json` file in JSON format to form the "negotiated and adjusted policy".

[0154] Step S25: Perform policy confirmation and signing on the negotiated and adjusted policy to obtain the agreed-upon policy;

[0155] In the embodiment of the present invention, the source end and the target end respectively perform digital signatures on the `negotiated_policy.json` file using the RSA algorithm and their respective private keys. The signed policy files are exchanged, and the signatures of the other party are verified. After the verification passes, the signed `negotiated_policy.json` file is respectively stored in the secure storage of the source end and the target end as the final "agreed-upon policy".

[0156] Preferably, step S24 includes the following steps:

[0157] Step S241: Sort the differences in the policy difference report by priority to obtain policy difference sorting data;

[0158] Step S242: Obtain historical negotiation records; use the historical negotiation records and a pre-built expert knowledge base to generate policy adjustments according to the policy difference sorting data to obtain policy adjustment recommendation data;

[0159] Step S243: Select a negotiation plan based on the policy adjustment recommendation data, the source end initial policy, and the target end initial policy to obtain a preliminary negotiation plan;

[0160] Step S244: Verify the preliminary negotiation plan and detect plan conflicts to obtain a plan verification result;

[0161] Step S245: Iteratively optimize the plan based on the plan verification result, the preliminary negotiation plan, the source end initial policy, the target end initial policy, the historical negotiation records, and the pre-built expert knowledge base to obtain the negotiated and adjusted policy.

[0162] In the embodiment of the present invention, the `policy_difference_report.json` file is read, which contains detailed information about all policy differences, such as field names, source end policies, target end policies, and difference types. The differences are sorted according to predefined priority rules. The priority rules are defined as follows: encryption policy difference > generalization policy difference > replacement policy difference. If the difference types are the same, they are sorted according to the sensitivity of the fields, and the sensitivity is defined in a separate configuration file. For example, the sensitivity of `id_card` is higher than that of `age`. The sorting result is stored in the `sorted_policy_differences.json` file to form the "policy difference sorting data".

[0163] Read historical negotiation records from the database. The records include previous policy differences, negotiation plans, and results. The pre-built expert knowledge base is stored in the Drools rule engine in the form of rules, which define recommended negotiation plans for different types of differences and contexts. For example, if the policy difference in the `id_card` field is a different encryption algorithm, a more secure encryption algorithm is recommended. According to the difference information in `sorted_policy_differences.json`, match the rules in the Drools rule engine one by one, and generate policy adjustment suggestions in combination with historical negotiation records. Store the suggestions in the `policy_adjustment_suggestions.json` file to form "policy adjustment suggestion data".

[0164] Read the `policy_adjustment_suggestions.json`, `source_initial_policy.json`, and `target_initial_policy.json` files. For each policy difference, select a negotiation plan according to the suggestion data. For example, if the suggestion data recommends using a more secure encryption algorithm, select that encryption algorithm as the negotiation plan. If there is no corresponding suggestion for a certain difference, default to selecting a stricter policy. Store the selected negotiation plans in the `preliminary_negotiation_plan.json` file to form the "preliminary negotiation plan".

[0165] Use a policy validation engine to validate the plans in the `preliminary_negotiation_plan.json` file. The validation engine checks whether the plans meet the security requirements of the source and target ends and detects whether there are conflicts between the plans. For example, check whether the selected encryption algorithm is supported by the target end and whether there are conflicts between the desensitization policies of two fields. The validation results are stored in the `plan_validation_results.json` file, including the validation results and conflict information for each plan, to form the "plan validation results".

[0166] If there are plans with validation failures or conflicts in the `plan_validation_results.json` file, start the iterative optimization program. The iterative optimization program adjusts the preliminary negotiation plan according to the validation results and the rules in the expert knowledge base. For example, if the selected encryption algorithm is not supported by the target side, select another more secure supported algorithm. The iterative optimization process will refer to the historical negotiation records to avoid repeating failed attempts. After the iterative optimization is completed, store the final negotiation plan in the `negotiated_policy.json` file to form the "negotiation-adjusted policy".

[0167] Preferably, step S3 includes the following steps:

[0168] Step S31: Perform policy parsing on the consensus policy, and combine it with the desensitization feature map to generate policy determination transformation rules, obtaining a transformation rule list;

[0169] Step S32: The source side performs context-aware transformation execution on the original data stream according to the desensitization feature map and the transformation rule list to obtain the transformed data;

[0170] Step S33: Perform structured adjustment and reorganization on the transformed data according to the consensus policy to obtain structured transformed data;

[0171] Step S34: Perform hierarchical encryption processing on the structured transformed data according to the consensus policy to obtain hierarchical encrypted data segments;

[0172] Step S35: Perform metadata encapsulation on the hierarchical encrypted data segments according to the desensitization feature map to obtain metadata-encapsulated data; perform data segment marking on the encapsulated data according to the consensus policy to obtain tokenized encrypted data;

[0173] Step S36: Perform payload encapsulation and transmission preparation on the tokenized encrypted data in a predetermined format to obtain the transformed encrypted payload.

[0174] In the embodiment of the present invention, read the `negotiated_policy.json` file from the secure storage. This file contains the consensus policy, such as the desensitization methods and parameters for each field. Use the Jackson library to parse the JSON file into a Java object. Traverse each node in the desensitization feature map (representing a data record), and generate specific transformation rules according to the attributes of the node (field name and data type) and the consensus policy. For example, if the policy stipulates generalization of the `age` field, generate a rule to convert the age to an age range (e.g., 20 - 30 years old). Store all the generated rules in the `transformation_rules.json` file to form the "transformation rule list".

[0175] Read the original data stream and the `transformation_rules.json` file. Use Apache Spark to iterate through each record in the original data stream. According to the desensitization feature map, obtain the context information of each field in each record, such as the relationships between fields. Based on the context information of the fields and the corresponding transformation rules in the `transformation_rules.json` file, transform the data. For example, if the context of the `age` field indicates that the record belongs to a child, replace the age with `<18 years old` according to the predefined rules. Store the transformed data in a new Spark DataFrame to form the "transformed data".

[0176] Adjust the transformed data according to the structuring adjustment policy defined in the `negotiated_policy.json` file. For example, if the policy stipulates that the `first_name` and `last_name` fields should be merged into a `full_name` field, perform the corresponding operations in the Spark DataFrame, create a new `full_name` column, and store the concatenated values of `first_name` and `last_name` in it. Delete the original `first_name` and `last_name` columns. Store the adjusted data in a new Spark DataFrame to form the "structured transformed data".

[0177] Perform hierarchical encryption on the structured transformed data according to the encryption policy defined in the `negotiated_policy.json` file. For example, if the policy stipulates that the `id_card` field should be encrypted using AES-256, call the AES-256 algorithm to encrypt the field using the Java Cryptography Architecture (JCA). Use the Key Management System (KMS) to obtain the corresponding encryption key. Store the encrypted data in a new Spark DataFrame to form the "hierarchically encrypted data segment".

[0178] Add metadata to each hierarchically encrypted data segment, such as the data source, transformation rule ID, encryption algorithm, and key version used. The metadata is extracted from the desensitization feature map and the negotiated policy. Package the metadata and the data segment together in JSON format. According to the negotiated policy, add tags to each data segment, such as "anonymized", "generalized", or "encrypted". Store the packaged and tagged data in the `metadata_encrypted_data.json` file to form the "tagged encrypted data".

[0179] Serialize the `metadata_encrypted_data.json` file into a binary format using Protocol Buffers. Compress the serialized data using the gzip compression algorithm. Base64-encode the compressed data for easy transmission via text protocols. Package the encoded data and some necessary header information (such as data length, compression algorithm, encoding method) into the final "transformed encrypted payload" for cross-border transmission.

[0180] Preferably, step S32 includes the following steps:

[0181] Step S321: Parse the transformation rule list to obtain the parsed transformation rules;

[0182] Step S322: Distribute the original data stream using the desensitization feature map and perform context association to obtain the data units to be processed;

[0183] Step S323: Match the data units to be processed according to the parsed transformation rules and perform transformer routing to obtain the transformation instructions to be executed;

[0184] Step S324: Execute the basic transformation operation according to the transformation instructions to be executed to obtain the preliminarily transformed data;

[0185] Step S325: Perform a transformation chain process on the preliminarily transformed data according to the transformation instructions to be executed and merge the results to obtain the transformation result of the current unit;

[0186] Step S326: Output the transformed data stream according to the transformation result of the current unit to obtain the transformed data.

[0187] In the embodiment of the present invention, read the `transformation_rules.json` file, which contains transformation rules for different data fields and is stored in JSON format, such as `{"field": "age", "rule": "generalize", "params": {"range": 10}}`. Use the Jackson library to parse the JSON string into a Java object, such as a `TransformationRule` object, which contains `field`, `rule`, and `params` attributes. Store the parsed rules in a hash table in memory, with the field name as the key and the corresponding `TransformationRule` object set as the value, forming the "parsed transformation rules".

[0188] Read the original data stream using Apache Spark and distribute the data to different executor nodes. Each executor node loads a copy of the desensitized feature map. For each data record, look up the corresponding nodes and relationships in the desensitized feature map according to the field names in the record. Package the data in the record and the context information extracted from the map (e.g., neighbor nodes of the node, type of the edge) into a `DataUnit` object to form a "data unit to be processed".

[0189] Traverse each `DataUnit` object. Look up the corresponding set of `TransformationRule` objects in the hash table of the parsed transformation rules according to the field names in the `DataUnit`. If multiple rules are found, sort them according to the predefined rule priorities. For example, specific context rules take precedence over general rules. Package the `DataUnit`, the matching `TransformationRule`, and the corresponding transformer (e.g., `GeneralizationTransformer`, `EncryptionTransformer`) into a `TransformationInstruction` object to form a "transformation instruction to be executed".

[0190] Traverse each `TransformationInstruction` object. Call the `transform` method of the transformer object specified in the `TransformationInstruction` and use the `DataUnit` as the input parameter. For example, the `transform` method of `GeneralizationTransformer` will convert the age to an age range according to the parameters in the rule. The transformed data is stored in the `DataUnit` object to form "preliminary transformed data".

[0191] If multiple transformation rules need to be applied to a field sequentially, perform the transformation operations in the order of the `TransformationInstruction` objects. For example, first generalize the `address` field to the city level and then encrypt it. The result of each transformation operation is used as the input for the next transformation operation. Store the `DataUnit` after all transformation operations are completed as the "transformation result of the current unit".

[0192] Convert the `DataUnit` objects of all "transformation results of the current unit" into rows of a Spark DataFrame. Write the new DataFrame to a distributed file system (e.g., HDFS) or a database to form "transformed data".

[0193] Preferably, step S4 includes the following steps:

[0194] Step S41: Transmit the deformed encrypted payload to the target end, and the target end performs deformed encrypted payload decryption to obtain the data segment to be reconstructed;

[0195] Step S42: Load the policy and graph according to the data segment to be reconstructed to obtain the loaded policy graph;

[0196] Step S43: Perform hierarchical decryption on the data segment to be reconstructed according to the loaded policy graph and perform reverse deformation to obtain the data to be authorized for access;

[0197] Step S44: Authenticate the identity of the user requesting access to obtain the identity authentication data; perform permission parsing on the identity authentication data according to the predefined access control policy to obtain the user permission list;

[0198] Step S45: Generate a policy-driven view for the data to be authorized for access according to the user permission list and the loaded policy graph to obtain the authorized access view.

[0199] In the embodiment of the present invention, the source end uses the HTTPS protocol to transmit the deformed encrypted payload to the target end. After receiving the payload, the target end first verifies the validity of the HTTPS connection, including certificate verification and domain name matching. Then, perform Base64 decoding on the received binary data, and then use the gzip algorithm to decompress it. Finally, use Protocol Buffers to deserialize the data to obtain the `metadata_encrypted_data.json` file in JSON format, which contains the encrypted data segment and the corresponding metadata. Store the decrypted data segment in memory to form the "data segment to be reconstructed".

[0200] Read the `negotiated_policy.json` file (policy negotiated with the source end) and the `anonymized_feature_graph.json` file (desensitized feature graph) from the target end's secure storage. Use the Jackson library to parse the JSON files into Java objects. Load the parsed policy and graph data into a hash table and a graph database (such as Neo4j) in memory for quick access. The policy data is stored in the hash table with the field name as the key and the policy content as the value. The graph data is stored in the graph database, maintaining the original graph structure and node attributes, to form the "loaded policy graph".

[0201] Traverse each data segment in the data segment to be reconstructed. According to the metadata information of the data segment (such as encryption algorithm and key version), obtain the corresponding decryption key from the Key Management System (KMS). Use the Java Cryptography Architecture (JCA) to call the corresponding decryption algorithm (such as AES-256) for decryption. After decryption, perform reverse transformation operations according to the transformation rules in the loaded policy graph, such as anti-generalization, anti-replacement, etc. Store the decrypted and reverse-transformed data in a new Spark DataFrame to form the "data to be authorized for access".

[0202] The user uses the OAuth 2.0 protocol for authentication, providing the username and password. The authentication server verifies the user information and returns an access token. The target system verifies the validity and signature of the access token. According to the predefined Role-Based Access Control (RBAC) policy, parse the user's roles and permissions. For example, the role "analyst" can only access the desensitized data, and the role "auditor" can access the original data. Store the user's roles and permissions in the `user_permissions.json` file to form the "user permission list".

[0203] Read the `user_permissions.json` file and the loaded policy graph. Filter and transform the data to be authorized for access according to the user's permissions. For example, if the user can only access the desensitized data, replace the sensitive fields with semantic tags or generalized values. Use Spark SQL to generate the final authorized access view according to the user's permissions and data requirements. Return the view data to the user in tabular form or store it in the database for the user to query.

[0204] Preferably, step S43 includes the following steps:

[0205] Step S431: Locate the key according to the data segment to be reconstructed and the loaded policy graph, and perform permission verification to obtain the data segment to be decrypted and the corresponding key information;

[0206] Step S432: Identify the decryption algorithm for the data segment to be decrypted and the corresponding key information to obtain the decrypted data segment;

[0207] Step S433: Extract reverse rules from the loaded policy graph to obtain reverse rules; sort the reverse rules to obtain the sequence of reverse rules to be executed;

[0208] Step S434: Perform basic reverse operation execution on the decrypted data segment according to the sequence of reverse rules to be executed to obtain the basic reverse restored data;

[0209] Step S435: Reverse execute the structural adjustment on the basic reverse restoration data according to the reverse rule sequence to be executed, and obtain the structurally reverse adjusted data;

[0210] Step S436: Perform data integrity verification on the structurally reverse adjusted data according to the loaded policy graph to obtain the verified data; perform reconstructed data merging on the verified data to obtain the data to be authorized for access.

[0211] In the embodiment of the present invention, each data segment in the data segment to be reconstructed is traversed. The encryption algorithm identifier (e.g., "AES-256") and the key version number are extracted from the metadata of the data segment. According to the encryption algorithm identifier and the key version number, the corresponding key path is searched in the policy part of the loaded policy graph. The API of the Key Management System (KMS) is used to obtain the key according to the key path. The KMS will verify the identity and permissions of the target end system to ensure that only authorized systems can access the key. The data segment, the key path, and the obtained key are encapsulated into a `DecryptionData` object to form "the data segment to be decrypted and the corresponding key information".

[0212] Each `DecryptionData` object is traversed. According to the encryption algorithm identifier in the `DecryptionData` object, the corresponding decryption algorithm implementation (e.g., `AES / CBC / PKCS5Padding`) is loaded using the Java Cryptography Architecture (JCA). The data segment is decrypted using the key in the `DecryptionData` object. The decrypted data is stored in the `DecryptionData` object in the form of a byte array to form "the decrypted data segment".

[0213] The deformation rules are extracted from the loaded policy graph. The deformation rules are stored in the policy file in JSON format, including the field name, the deformation type (e.g., "generalization", "substitution", "encryption") and the parameters. The order of reverse operations is defined according to the priority of the deformation type. For example, the reverse operation of encryption has a higher priority than generalization. The reverse rules are sorted according to the priority and stored in a list to form "the reverse rule sequence to be executed".

[0214] Traverse each reverse rule in the sequence of reverse rules to be executed. According to the type of the rule, perform the corresponding reverse operation. For example, if the rule type is "generalization", perform the anti-generalization operation to convert the age group into an age range. If the rule type is "substitution", replace the semantic label back to the original value according to the substitution mapping table. Store the data after the reverse operation in the `DecryptionData` object to form the "basic reverse restoration data".

[0215] According to the structure adjustment rules in the sequence of reverse rules to be executed, perform structure adjustment on the basic reverse restoration data. For example, if a field merging operation was performed at the source end, perform a field splitting operation in this step to restore the merged field into the original multiple fields. Store the data after the structure adjustment in the `DecryptionData` object to form the "structure reverse adjustment data".

[0216] Extract the data integrity verification rules, such as the hash algorithm and the verification value, from the loaded policy graph. Calculate the hash value of the structure reverse adjustment data using the specified hash algorithm and compare the calculation result with the verification value stored in the policy graph. If the hash values match, the data integrity verification passes, and the data is marked as "verified data". Merge all the verified data segments to restore the complete record and form the "data to be authorized for access".

[0217] Preferably, step S5 includes the following steps:

[0218] Step S51: Monitor the data cross-border process through a listener to obtain data cross-border process events; capture the data cross-border process events to obtain audit event records;

[0219] Step S52: Structure the event data of the audit event records and generate a digest to obtain the audit data digest;

[0220] Step S53: Construct a transaction for the audit data digest and perform a digital signature to obtain the transaction to be submitted;

[0221] Step S54: Broadcast the transaction to be submitted to each node in the blockchain network for node consensus confirmation and block generation to obtain block data;

[0222] Step S55: Link the block data in a chain structure to obtain a trusted audit chain;

[0223] Step S56: Query and verify the audit information of the trusted audit chain to obtain an audit report.

[0224] In the embodiments of the present invention, event listeners are deployed in the source and target systems. The listeners use the AspectJ framework to intercept key method calls in the data cross-border process, such as data transformation, encryption, decryption, access control, etc. When a key method is called, the listener captures information such as the input parameters, return value, call time, and caller identity of the method. The captured information is stored in the `audit_events.log` file to form an "audit event record". The log file uses the append write mode to ensure the integrity of the audit information.

[0225] Read each record in the `audit_events.log` file. Parse each record into JSON format, including fields such as event type, timestamp, operating user, operation object, and operation result. Use the SHA-256 algorithm to calculate the hash value of the structured JSON data, generating a 256-bit hash value as the "audit data digest". Store the digest and the corresponding JSON data in the `audit_data_digests.json` file.

[0226] Read the audit data digest and the corresponding JSON data from the `audit_data_digests.json` file. Use the digest and JSON data as transaction data to construct a blockchain transaction. The transaction data is encoded in JSON format. Use the ECDSA algorithm and the private key of the system to digitally sign the transaction data, generating a digital signature. Package the signed transaction data and the digital signature into a `SignedTransaction` object to form a "transaction to be submitted".

[0227] Use the Hyperledger Fabric SDK to submit the transaction to be submitted to the blockchain network. The transaction is broadcast to all ordering nodes in the network. The ordering nodes sort and package the transactions to generate a block. The transactions in the block are arranged in the order of receipt. Nodes in the network use the Raft consensus algorithm to verify and confirm the block. The confirmed block is added to the blockchain to form "block data".

[0228] Each block contains the hash value of the previous block. The hash value of the newly generated block is calculated using the SHA-256 algorithm and includes the hash value of the previous block. This chained structure ensures the immutability of the blockchain. Any modification to a historical block will cause a change in the hash value of the subsequent blocks. All linked blocks form a "trusted audit chain".

[0229] Use the Hyperledger Fabric SDK to query the block data on the trusted audit chain. Retrieve relevant transaction data according to the query conditions (such as time range, event type, operating user). Verify the digital signature of the transaction data to ensure the integrity and authenticity of the data. Organize the query results and verification results into an `audit_report.pdf` file to form an "audit report".

[0230] Therefore, from any point of view, the embodiments should be regarded as exemplary and non-restrictive. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the application document are intended to be encompassed within the present invention.

[0231] The above are only specific embodiments of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features invented herein.

Claims

1. A method for ensuring cross-border data security, characterized in that, It includes the following steps: Step S1: Obtain the original data stream; Perform sensitive information marking on the original data stream to obtain sensitive information annotation; Perform context relationship parsing on the sensitive information annotation to obtain a context relationship structure; Perform semantic abstraction replacement based on the sensitive information annotation and the context relationship structure to obtain preliminary anonymized data; Generate a desensitization feature map based on the preliminary anonymized data to obtain a desensitization feature map; Step S2: Obtain source-side security requirement data and target-side security requirement data; The source side formulates a source-side initial policy based on the source-side security requirement data and the desensitization feature map to obtain a source-side initial policy; The target side formulates a target-side initial policy based on the target-side security requirement data to obtain a target-side initial policy; Perform policy negotiation based on the source-side initial policy and the target-side initial policy, and perform dynamic policy adjustment to obtain a negotiated and adjusted policy; Perform policy confirmation and signing on the negotiated and adjusted policy to obtain a consensus policy; Step S3: The source side performs context-aware transformation execution on the original data stream according to the desensitization feature map and the consensus policy to obtain transformed data; Perform structured adjustment on the transformed data according to the consensus policy, and perform hierarchical encryption processing to obtain hierarchical encrypted data segments; Perform payload encapsulation on the hierarchical encrypted data segments to obtain transformed encrypted payloads; Step S4: Transmit the transformed encrypted payload to the target side, and perform unpacking of the transformed encrypted payload to obtain data segments to be reconstructed; Perform hierarchical decryption on the data segments to be reconstructed, and perform reverse transformation to obtain data to be authorized for access; Authenticate the identity and resolve the permissions of the user requesting access to the data to obtain a user permission list; Generate a policy-driven view of the data to be authorized for access according to the user permission list to obtain an authorized access view; Step S5: Monitor and capture the data cross-border process through a listener to obtain an audit event record; construct a blockchain-based trusted audit chain according to the audit event record to obtain a trusted audit chain; Query and verify audit information on the trusted audit chain to obtain an audit report to achieve the task of ensuring data cross-border security.

2. The data cross-border security guarantee method according to claim 1, wherein Step S1 includes the following steps: Step S11: Obtain the original data stream; perform preliminary cleaning on the original data stream to obtain loaded data; Step S12: Identify sensitive information in the loaded data and perform sensitive information marking to obtain sensitive information annotation; Step S13: Perform context relationship parsing on the sensitive information annotation to obtain a context relationship structure; Step S14: Perform semantic abstraction replacement based on the sensitive information annotation and the context relationship structure to obtain preliminary anonymized data; Step S15: Construct a graph structure based on the preliminary anonymized data and the context relationship structure to obtain a feature graph to be audited; Step S16: Audit the feature graph to be audited and perform graph correction to obtain a desensitization feature map.

3. The data cross-border security guarantee method according to claim 2, wherein Step S14 includes the following steps: Step S141: Classify sensitive information according to the sensitive information annotation and a pre-constructed tag library to obtain sensitive information classification data; Step S142: Perform context information matching on the sensitive information classification data and the context relationship structure to obtain context-related sensitive information; Step S143: Select a replacement strategy based on the context-related sensitive information and the pre-constructed tag library to obtain the information to be replaced and the strategy; Step S144: Execute semantic replacement according to the information to be replaced and the strategy to obtain the replaced data segment; Step S145: Integrate the original data stream and the replaced data segment to obtain the preliminary anonymized data.

4. The data cross-border security guarantee method according to claim 1, wherein Step S2 includes the following steps: Step S21: Obtain the source-side security requirement data. The source side formulates the source-side initial strategy based on the desensitization feature map and the source-side security requirement data; Step S22: Obtain the target-side expected data usage and the target-side security requirement data; The target side formulates the target-side initial strategy based on the target-side expected data usage and the target-side security requirement data; Step S23: Exchange the source-side initial strategy and the target-side initial strategy, and perform policy difference analysis in parallel to obtain a policy difference report; Step S24: Conduct policy negotiation based on the policy difference report, the source-side initial strategy, and the target-side initial strategy, and perform dynamic policy adjustment to obtain the negotiated and adjusted strategy; Step S25: Confirm and sign the negotiated and adjusted strategy to obtain the consensus strategy.

5. The data cross-border security guarantee method according to claim 4, wherein Step S24 includes the following steps: Step S241: Sort the differences in the policy difference report by priority to obtain the policy difference sorting data; Step S242: Obtain the historical negotiation records; Use the historical negotiation records and the pre-constructed expert knowledge base to generate policy adjustments according to the policy difference sorting data to obtain the policy adjustment suggestion data; Step S243: Select a negotiation plan based on the policy adjustment suggestion data, the source-side initial strategy, and the target-side initial strategy to obtain a preliminary negotiation plan; Step S244: Verify the preliminary negotiation plan and detect plan conflicts to obtain the plan verification result; Step S245: Iteratively optimize the plan based on the plan verification result, the preliminary negotiation plan, the source-side initial strategy, the target-side initial strategy, the historical negotiation records, and the pre-constructed expert knowledge base to obtain the negotiated and adjusted strategy.

6. The data cross-border security guarantee method according to claim 1, characterized in that Step S3 includes the following steps: Step S31: Analyze the consensus strategy, and generate the deformation rule list by determining the deformation rules in combination with the desensitization feature map; Step S32: The source side performs context-aware deformation execution on the original data stream according to the desensitization feature map and the deformation rule list to obtain the deformed data; Step S33: Perform structured adjustment and reorganization on the deformed data according to the consensus strategy to obtain the structured deformed data; Step S34: Perform hierarchical encryption processing on the structured deformed data according to the consensus strategy to obtain the hierarchical encrypted data segment; Step S35: Perform metadata encapsulation on the hierarchical encrypted data segment according to the desensitization feature map to obtain the metadata encapsulated data; Mark the encapsulated data according to the consensus strategy to obtain the tokenized encrypted data; Step S36: perform payload encapsulation and transmission preparation on the tokenized encrypted data in a predetermined format to obtain a deformed encrypted payload.

7. The data cross-border security guarantee method according to claim 6, wherein Step S32 includes the following steps: Step S321: parsing the deformation rule list to obtain the parsed deformation rules; Step S322: using the desensitized feature map to distribute the original data stream, and perform context association to obtain a data unit to be processed; Step S323: matching the data unit to be processed according to the parsed deformation rule, and performing deformation routing to obtain the deformation instruction to be executed; Step S324: performing basic deformation operations according to the deformation instruction to be executed to obtain preliminary deformation data; Step S325: performing deformation chain processing on the preliminary deformation data according to the deformation instruction to be executed, and merging the results to obtain the deformation result of the current unit; Step S326: Output the deformed data stream according to the deformation result of the current unit to obtain the deformed data.

8. The data cross-border security guarantee method according to claim 1, wherein Step S4 includes the following steps: Step S41: transmitting the deformed encrypted payload to the target end, and the target end decapsulates the deformed encrypted payload to obtain a data segment to be reconstructed; Step S42: Loading strategies and graphs according to the data segment to be reconstructed to obtain loaded strategy graphs; Step S43: hierarchically decrypt the data segment to be reconstructed according to the loaded policy graph, and perform reverse transformation to obtain the data to be authorized for access; Step S44: authenticating the user who requests to access the data to obtain authentication data; parsing the authentication data according to the predefined access control policy to obtain a user authority list; Step S45: Generate a policy-driven view of the access data to be authorized based on the user permission list and the loaded policy graph to obtain an authorized access view.

9. The data cross-border security guarantee method according to claim 8, characterized in that, Step S43 includes the following steps: Step S431: locate the key according to the data segment to be reconstructed and the loaded policy map, and perform authority verification to obtain the data segment to be decrypted and the corresponding key information; Step S432: performing decryption algorithm identification on the data segment to be decrypted and the corresponding key information to obtain the decrypted data segment; Step S433: extracting reverse rules from the loaded strategy graph to obtain reverse rules; sorting the reverse rules to obtain a sequence of reverse rules to be executed; Step S434: performing basic reverse operations on the decrypted data segment according to the reverse rule sequence to be executed to obtain basic reverse restored data; Step S435: performing reverse execution of structural adjustment on the basic reverse restoration data according to the reverse rule sequence to be executed, and obtaining structural reverse adjustment data; Step S436: Perform data integrity verification on the structure reverse adjustment data according to the loaded strategy map to obtain verified data; perform reconstructed data merging on the verified data to obtain data to be authorized for access.

10. The data cross-border security guarantee method according to claim 1, wherein Step S5 includes the following steps: Step S51: monitor the cross-border data process through a listener to obtain cross-border data process events; capture data of the cross-border data process events to obtain audit event records; Step S52: Structure the event data of the audit event record and generate a summary to obtain an audit data summary; Step S53: Construct a transaction from the audit data summary and perform a digital signature to obtain a transaction to be submitted; Step S54: Broadcast the transaction to be submitted to each node in the blockchain network, perform node consensus confirmation, and generate a block to obtain block data; Step S55: Link the block data in a chain structure to obtain a trusted audit chain; Step S56: Query and verify the audit information on the trusted audit chain to obtain an audit report.

Citation Information

Cited By

  • Cross-border data weight compliance verification method and system based on knowledge graph

    CN120880961A

  • Supervision submission-oriented data encryption storage method and system

    CN120951361A

  • Data encryption storage method and system for regulatory reporting

    CN120951361B

  • Cross-border VPN (Virtual Private Network) data desensitization transmission method and system adaptive to multi-region compliance

    CN121396664A

  • Methods and systems for cross-border VPN data anonymization and transmission that are compatible with multiple regions and comply with regulations.

    CN121396664B