Data security management method and device, electronic equipment and storage medium
By encrypting and storing sensitive data to different servers, performing desensitization operations and sandbox analysis, a data sharing platform is established, data security and privacy protection issues are solved, and flexible and controllable data sharing and efficient utilization are achieved.
Patent Information
- Application Number
- CN202510316511.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-03-18
AI Technical Summary
The existing technology lacks effective security measures in data management, which leads to the easy leakage of sensitive data and lacks fine-grained permission control during data sharing, resulting in unintentional leakage of sensitive information.
Encrypt and store sensitive data and regular data to different servers, and perform regular backups; desensitize sensitive information based on preset desensitization rules, perform data analysis through a pre-built sandbox environment, establish a data sharing platform, and realize data sharing through API interface.
Improve data security, ensure data integrity and availability, prevent data leakage, realize flexible and controllable data sharing, and improve data utilization efficiency.
Smart Images

Figure CN120387185A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and particularly to a data security management method, apparatus, electronic device, and storage medium. Background Art
[0002] With the rapid development of information technology, data has become an important asset for enterprises and organizations. However, the management and sharing of data face many challenges, especially in terms of data security and privacy protection. Information data usually includes sensitive data and regular data. Sensitive data such as personal identity information, financial information, etc., once leaked, may lead to serious privacy violations and economic losses. Although regular data does not involve sensitive information, its integrity and availability are equally important.
[0003] Traditional data management methods often store sensitive data and regular data mixedly, lacking effective security measures and being easily targeted by attacks. In addition, during the data sharing process, the lack of fine-grained permission control may lead to the unintentional leakage of sensitive information. Summary of the Invention
[0004] The main purpose of the embodiments of the present invention is to propose a data security management method, apparatus, electronic device, and storage medium, in order to solve at least one problem of the prior art. The present invention can achieve data security management.
[0005] To achieve the above object, on the one hand, an embodiment of the present invention proposes a data security management method, which includes:
[0006] Obtain the information data to be managed; the information data includes sensitive data and regular data;
[0007] Encrypt and store the sensitive data and regular data in different servers, and perform regular backups on the data stored in the servers;
[0008] Perform a desensitization operation on the sensitive information in the information data based on a preset desensitization rule to obtain desensitized data;
[0009] Based on the desensitized data, perform target data analysis through a pre-constructed sandbox environment to obtain a data analysis result;
[0010] Among them, the desensitized data and the data analysis result are stored in the server;
[0011] Establish a data sharing platform based on the server according to a preset permission scope and control policy;
[0012] In response to a data sharing request from an authorized object, share the target data with the authorized object through the API interface of the data sharing platform.
[0013] In some embodiments, encrypting and storing sensitive data and regular data in different servers includes the following steps:
[0014] Storing sensitive data in a local server; encrypting the data on the local server using a preset encryption algorithm;
[0015] Storing regular data in a cloud server; encrypting and controlling the data in the cloud server using the security functions of the cloud service provider.
[0016] In some embodiments, the server includes a local server and a cloud server; regularly backing up the data stored in the server includes the following steps:
[0017] Performing a full backup and an incremental backup on the data on the local server regularly based on a preset period; wherein, the execution period of the incremental backup is longer than that of the full backup, and the backup data is stored at a different physical location on the local server compared to the data being backed up;
[0018] Using the backup function of the cloud service provider to regularly back up the data on the cloud server, and regularly testing the data recovery process of the cloud server; wherein, each backup copy obtained through different backup processes is stored at a different physical location on the cloud server.
[0019] In some embodiments, performing a desensitization operation on sensitive information in information data based on a preset desensitization rule includes the following steps:
[0020] Marking sensitive information in the information data in response to a preset data element review rule;
[0021] wherein, the data types of the sensitive information include a first type, a second type, and a third type;
[0022] Performing a desensitization process on the sensitive data of the first type;
[0023] Performing a generalization process on the sensitive data of the second type;
[0024] Performing a strong encryption process on the sensitive data of the third type;
[0025] Constructing a desensitization mapping table based on the correspondence between the sensitive information and the obtained desensitized data.
[0026] In some embodiments, performing target data analysis based on desensitized data through a pre-constructed sandbox environment to obtain a data analysis result includes the following steps:
[0027] Creating a sandbox environment by configuring target computing resources through network isolation in response to a preset configuration requirement;
[0028] Among them, an analysis algorithm to be executed is integrated in the sandbox environment;
[0029] Input the desensitized data into the sandbox environment, perform target data analysis based on the analysis algorithm, and output the data analysis result through the sandbox environment.
[0030] In some embodiments, according to the preset permission scope and control policy, a data sharing platform is established based on the server, including the following steps:
[0031] Respond to the customization requirements of the management object for the permission and scope of data access, and determine the shared data scope of the data sharing platform;
[0032] Configure the security and privacy settings of the data sharing platform through the control policy;
[0033] Among them, the control policy includes an access control policy, a data encryption policy, and an audit log recording policy.
[0034] In some embodiments, in response to the data sharing request of the authorized object, share the target data with the authorized object through the API interface of the data sharing platform, including the following steps:
[0035] Respond to the data sharing request of the authorized object and determine the data to be shared;
[0036] Perform data cleaning processing on the data to be shared to obtain the data to be transmitted;
[0037] Based on the preset transport layer security protocol, encrypt and transmit the data to be transmitted to the authorized object through the API interface of the data sharing platform to complete the data sharing.
[0038] To achieve the above object, another aspect of the embodiments of the present invention proposes a data security management device, the device includes:
[0039] A first module for obtaining information data to be managed; the information data includes sensitive data and regular data;
[0040] A second module for encrypting and storing sensitive data and regular data in different servers, and performing regular backups on the data stored in the servers;
[0041] A third module for performing desensitization operations on the sensitive information in the information data based on the preset desensitization rules to obtain desensitized data;
[0042] A fourth module for performing target data analysis based on the desensitized data through a pre-constructed sandbox environment to obtain a data analysis result;
[0043] Among them, the desensitized data and the data analysis result are stored in the server;
[0044] The fifth module is used to establish a data sharing platform based on a server according to a preset permission scope and control policy;
[0045] The sixth module is used to respond to a data sharing request of an authorized object and share target data with the authorized object through the API interface of the data sharing platform.
[0046] To achieve the above object, on the other hand, an embodiment of the present invention provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the above method is implemented.
[0047] To achieve the above object, on the other hand, an embodiment of the present invention provides a computer-readable storage medium, which stores a computer program, and when the computer program is executed by a processor, the above method is implemented.
[0048] The present invention provides a data security management method, device, electronic device and storage medium. The solution includes obtaining information data to be managed; the information data includes sensitive data and regular data; encrypting and storing the sensitive data and regular data in different servers, and regularly backing up the data stored in the servers; performing a desensitization operation on the sensitive information in the information data based on a preset desensitization rule to obtain desensitized data; performing target data analysis through a pre-constructed sandbox environment based on the desensitized data to obtain a data analysis result; wherein, the desensitized data and the data analysis result are stored in the server; establishing a data sharing platform based on the server according to a preset permission scope and control policy; responding to a data sharing request of an authorized object, and sharing target data with the authorized object through the API interface of the data sharing platform. The present invention has the following beneficial effects:
[0049] 1. Data security improvement: By encrypting and storing sensitive data and regular data in different servers respectively, the risk of data leakage is effectively reduced, thereby improving the overall data security.
[0050] 2. Data backup: Regularly backing up the data stored in the server to ensure quick recovery in case of data loss or damage, and guaranteeing the integrity and availability of the data.
[0051] 3. Sensitive information desensitization: Performing a desensitization operation on sensitive information based on a preset desensitization rule to generate desensitized data. While retaining the data value, the desensitized data eliminates the risk of sensitive information leakage and is applicable to scenarios such as data analysis and testing.
[0052] 4. Secure data analysis environment: Performing target data analysis through a pre-constructed sandbox environment to ensure the security and isolation of the data analysis process, and preventing misoperation or leakage of the original data during the data analysis process.
[0053] 5. Data sharing controllability: Based on the preset permission scope and control policies, a data sharing platform is established to ensure that only authorized objects can access specific data. Data sharing is achieved through API interfaces, providing a flexible and controllable data sharing mechanism to meet the access needs of different authorized objects.
[0054] 6. Improve data utilization efficiency: On the premise of ensuring data security, through the data sharing platform and desensitized data analysis, the data utilization efficiency is improved to support enterprise decision-making, business innovation and other needs.
[0055] In summary, the embodiments of the present invention provide significant beneficial effects in terms of data security, privacy protection, data sharing and utilization efficiency, and are applicable to various scenarios that require efficient, secure management and sharing of data. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] Figure 1 is a flowchart of the data security management method provided by the embodiments of the present invention;
[0057] Figure 2 is a schematic structural diagram of the data security management device provided by the embodiments of the present invention;
[0058] Figure 3 is a schematic hardware structure diagram of the electronic device provided by the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0059] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the embodiments of the present invention. They are only examples of devices and methods that are consistent with some aspects of the embodiments of the present invention detailed in the appended claims.
[0060] It can be understood that the terms "first", "second", etc. used in the present invention can be used to describe various concepts in the present invention, but unless otherwise specified, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of the present invention, the first information can also be referred to as the second information, and similarly, the second information can also be referred to as the first information. Depending on the context, the words "if", "when" as used herein can be interpreted as "when...", "while...", or "in response to determining".
[0061] The terms "at least one", "a plurality", "each", "any one", etc. used in the present invention, "at least one" includes one, two or more, "a plurality" includes two or more, "each" refers to each of the corresponding plurality, and "any one" refers to any one of the plurality.
[0062] Unless otherwise defined, all technical and scientific terms used in the present invention have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs. The terms used in the present invention are only for the purpose of describing the embodiments of the present invention and are not intended to limit the present invention.
[0063] The data security management method provided by the embodiments of the present invention relates to the technical field of data processing. The data security management method provided by the embodiments of the present invention can be applied to a terminal, can also be applied to a server, or can also be software running on a terminal or a server. In some embodiments, the terminal may be a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart speaker, a smart watch, a vehicle-mounted terminal, etc., but is not limited thereto; the server side may be configured as an independent physical server, or may be configured as a server cluster or a distributed system composed of multiple physical servers, or may also be configured as a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The server may also be a node server in a blockchain network; the software may be an application implementing the data security management method, etc., but is not limited to the above forms.
[0064] The present invention can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multi-processor systems, microprocessor-based systems, set-top boxes, programmable consumer electronic devices, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and so on. The present invention can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present invention can also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media including storage devices.
[0065] Figure 1 is an optional flowchart of the data security management method provided by the embodiments of the present invention, Figure 1 The method in may include but is not limited to steps S100 to S600.
[0066] S100. Obtain the information data to be managed;
[0067] Among them, the information data includes sensitive data and regular data;
[0068] Exemplarily, in some specific embodiments, taking the vehicle as the acquisition end of the information data as an example, the data acquisition can be achieved as follows:
[0069] S11. Extract personal information:
[0070] Operation: The system extracts the basic information of the vehicle owner and driving habit data from the vehicle management system.
[0071] According to the preset data acquisition requirements, access the information system and sensors of the vehicle to extract the corresponding data.
[0072] The extracted data includes:
[0073] Owner Information: including name, contact information, driver's license information, etc., for identifying and contacting the vehicle owner.
[0074] Driving Habits Data: including driving speed, acceleration, braking frequency, etc., for analyzing driving behavior.
[0075] Vehicle Usage Data: including driving mileage, maintenance records, fuel consumption, etc., for evaluating vehicle performance and maintenance requirements.
[0076] S12. Extract environmental detection information:
[0077] Operation: The system extracts data such as the temperature, humidity, and air quality of the driving environment from the vehicle's environmental monitoring system.
[0078] The extracted data includes:
[0079] Environmental Parameters: including temperature, humidity, air quality index, etc., for evaluating the vehicle driving environment.
[0080] S200. Encrypt and store the sensitive data and regular data in different servers, and regularly back up the data stored in the servers;
[0081] It should be noted that in some embodiments, encrypting and storing sensitive data and regular data on different servers may include the following steps: storing sensitive data on a local server; encrypting the data on the local server using a preset encryption algorithm; storing regular data on a cloud server; and using the security features of the cloud service provider to encrypt and control the data on the cloud server.
[0082] Exemplarily, in some specific embodiments, taking the application scenario of the information data of the foregoing vehicle as an example, data storage can be implemented as follows:
[0083] The system first classifies the collected data to identify which data contains sensitive information, such as the personal information and driving habits of the vehicle owner, and which data is regular environmental monitoring information.
[0084] For data containing sensitive information, the system will choose to store it on a local server to facilitate better control of physical access and encryption measures. For example, the personal information and driving habit data of the vehicle owner will be stored on the secure servers within the company, which are located in a controlled data center and have 24 / 7 monitoring and access logging.
[0085] For regular environmental monitoring information, the system may choose to store it on a cloud server because this data usually does not require frequent physical access, and cloud service providers usually offer highly available and scalable storage solutions. For example, the temperature, humidity, and air quality data of the vehicle driving environment will be uploaded to the storage buckets of the cloud service provider, which are located in different geographical locations to ensure data redundancy and fast access.
[0086] Specifically, corresponding security measures can be implemented for different servers, and it can be specifically implemented as follows:
[0087] For the sensitive data stored on the local server, the system will use the SM4 encryption algorithm to encrypt the data to ensure that even if the data is illegally accessed, it cannot be interpreted. At the same time, the system will set strict access controls so that only authorized employees can access this data, and all access attempts will be recorded and monitored.
[0088] For the data stored on the cloud server, the system will utilize the security features of the cloud service provider, such as storage bucket encryption and access policies, to ensure that only authorized applications and services can access the data. In addition, the system will regularly conduct security audits on the cloud storage buckets to check for unauthorized access attempts or configuration errors.
[0089] It should be noted that the server includes a local server and a cloud server; in some embodiments, performing regular backups on the data stored in the server may include the following steps: performing full backups and incremental backups on the data on the local server at regular intervals based on a preset period; wherein, the execution period of the incremental backup is longer than that of the full backup, and the backup data is stored at a different physical location on the local server compared to the data being backed up; using the backup function of the cloud service provider to perform backup processing on the data on the cloud server at regular intervals, and regularly testing the data recovery process of the cloud server; wherein, each backup copy obtained through different backup processes is stored at a different physical location on the cloud server.
[0090] Exemplarily, in some specific embodiments, the data backup for the server can be implemented as follows:
[0091] For the data on the local server, the system will perform a full backup once a day, and perform incremental backups weekly and monthly. The backup data will be stored at different physical locations to prevent catastrophic events at the original storage location. For example, the daily backup will be copied to another data center, while the monthly backup will be stored in a secure off - line location.
[0092] For the data stored in the cloud, the system will use the backup function of the cloud service provider to ensure that multiple copies of the data are stored at different geographical locations. The system will also regularly test the recovery process to ensure that the data can be quickly restored in case of data loss or damage.
[0093] S300. Perform a desensitization operation on the sensitive information in the information data based on a preset desensitization rule to obtain desensitized data;
[0094] It should be noted that in some embodiments, performing a desensitization operation on the sensitive information in the information data based on a preset desensitization rule may include the following steps: in response to a preset data element review rule, mark the sensitive information in the information data; wherein, the data types of the sensitive information include the first type, the second type, and the third type; perform desensitization processing on the sensitive data of the first type; perform generalization processing on the sensitive data of the second type; perform strong encryption processing on the sensitive data of the third type; construct a desensitization mapping table according to the correspondence between the sensitive information and the obtained desensitized data.
[0095] Exemplarily, in some specific embodiments, taking the application scenario of the information data of the aforementioned vehicle as an example, the definition of the desensitization rule can be implemented as follows:
[0096] Operation: The system first conducts a review of information data related security and privacy regulations to determine which data elements are considered sensitive information. For example, according to the General Data Protection Regulation, personal identity information (PII) needs to be desensitized. In the scenario of GPS data, the system will formulate a set of rules specifying which information must be replaced (generalized processing, such as latitude and longitude information of routes, etc.) or encrypted (i.e., strong encryption processing). Among them, when performing the desensitization operation, the system will retain a mapping table for tracking the correspondence between the original data and the desensitized data, but this mapping table will be strictly protected and only authorized data managers can access it.
[0097] S400. Based on the desensitized data, perform target data analysis through a pre-built sandbox environment to obtain the data analysis result;
[0098] Among them, the desensitized data and the data analysis result are stored in the server;
[0099] It should be noted that in some embodiments, performing target data analysis through a pre-built sandbox environment based on the desensitized data to obtain the data analysis result may include the following steps: In response to a preset configuration requirement, create a sandbox environment by configuring target computing resources through network isolation; among them, the analysis algorithms to be executed are integrated in the sandbox environment; input the desensitized data into the sandbox environment, perform target data analysis based on the analysis algorithms, and output the data analysis result through the sandbox environment.
[0100] Exemplarily, in some specific embodiments, taking the application scenario of the information data of the vehicle mentioned above as an example, first, create a virtualized sandbox environment, configure the required computing resources and implement network isolation to ensure its complete isolation from the external network. Next, integrate the analysis algorithms to be executed (such as route optimization algorithms) into the sandbox and conduct a strict review of these algorithms to ensure their compliance with security standards and privacy protection requirements. Subsequently, the system inputs the desensitized data (such as GPS trajectories) into the sandbox environment. These data have been desensitized before entering the sandbox to reduce privacy risks. In the sandbox, the system uses technologies such as multi-party secure computing (MPC) and federated learning (FL) to perform data analysis. The calculation process is carried out within the sandbox, and all operations are monitored and recorded to ensure no data leakage. After the calculation is completed, the sandbox environment will output the analysis result, such as the optimized driving route, and at this time, all original data and intermediate calculation results will be completely cleared to prevent data leakage.
[0101] S500. Based on the server, establish a data sharing platform according to the preset permission scope and control policy;
[0102] It should be noted that in some embodiments, based on a server, a data sharing platform may be established according to a preset permission scope and control policy, which may include the following steps: in response to the customization requirements of the management object for the access permission and scope of data, determining the shared data scope of the data sharing platform; configuring the security and privacy settings of the data sharing platform through the control policy; wherein, the control policy includes an access control policy, a data encryption policy, and an audit log recording policy.
[0103] Exemplarily, in some specific embodiments, taking the application scenario of the information data of the vehicle described above as an example, the data sharing platform may be implemented as follows:
[0104] S51. Establish a data sharing platform:
[0105] The system establishes a data sharing platform and provides an API interface for external modules to access data services. The design of this platform aims to achieve modular services for data, allowing users to customize data access permissions and scopes according to their needs. For example, through this platform, anonymized GPS data and other relevant data (such as driving habit data and environmental monitoring information) can be securely provided to authorized partners and research institutions.
[0106] S52. Ensure data security:
[0107] The system ensures the security and privacy of data on the sharing platform by implementing measures such as access control, data encryption, and audit log recording. To prevent data leakage, the system will conduct strict security checks on the shared data to ensure that all shared data complies with privacy regulations and privacy protection requirements. At the same time, all transmitted data will be encrypted before being sent to ensure security during the sharing process.
[0108] S600. In response to the data sharing request of the authorized object, share the target data with the authorized object through the API interface of the data sharing platform.
[0109] It should be noted that in some embodiments, in response to the data sharing request of the authorized object, sharing the target data with the authorized object through the API interface of the data sharing platform may include the following steps: in response to the data sharing request of the authorized object, determining the data to be shared; performing data cleaning processing on the data to be shared to obtain the data to be transmitted; based on a preset transport layer security protocol, encrypting and transmitting the data to be transmitted to the authorized object through the API interface of the data sharing platform to complete data sharing.
[0110] Exemplarily, in some specific embodiments, taking the application scenario of the information data of the vehicle described above as an example, the data sharing may be specifically implemented as follows:
[0111] S61. Implement a data sharing mechanism:
[0112] The system realizes data sharing through the API interface to ensure security during the sharing process. Specifically, the system will implement data access control measures to ensure that only authorized users can access specific data. At the same time, all shared data transmissions will use encryption technology to prevent data from being stolen or tampered with during transmission. In addition, the system will also record audit logs to track data access and usage, ensuring transparency and compliance.
[0113] S62. Sharing data with partners:
[0114] The system shares the desensitized data with partners, research institutions or government departments for analysis and decision-making support. These data will include GPS route data and related driving behavior data that have been desensitized and processed through sandbox computing, ensuring that these data comply with privacy regulations and privacy protection requirements when shared. In this way, partners and research institutions can use the data for in-depth analysis and research without disclosing personal privacy, thereby supporting policy-making and business decisions.
[0115] To explain the principle of the technical solution of the present invention in detail, the overall process of the present invention will be described below in conjunction with some specific embodiments. It is easy to understand that the following is an explanation of the technical principle of the present invention and should not be regarded as a limitation of the present invention.
[0116] First of all, it should be noted that existing data management systems mainly focus on data storage, processing and sharing, but there are deficiencies in data security and privacy protection. Especially in the automotive field, with the development of vehicle networking technology, a large amount of personal information and environmental detection information are collected and used, and the security and privacy of these data have become urgent problems to be solved.
[0117] Although current technologies can desensitize data and perform sandbox computing, the security and authentication of data transmission, storage and processing are still not in place enough, and there may be risks of data leakage and unauthorized access. Although there is data desensitization technology, in complex data processing scenarios, how to ensure privacy protection is still a difficult problem, especially when sharing data and applying it across platforms. Existing data management systems usually lack flexibility and scalability and are difficult to keep up with changing business needs and technological progress. Although existing data sharing platforms can achieve "usable but invisible" data, sometimes they sacrifice the efficiency of sharing and utilization, resulting in the value of data not being fully utilized. Most current technologies are isolated and lack an overall solution to simultaneously solve the problems of secure data storage, privacy protection, sharing and utilization.
[0118] In view of this, a data management solution for data availability and invisibility proposed by the present invention integrates and optimizes existing technologies, aiming to provide a more secure and efficient data management solution, especially for the secure storage and sharing of personal information and environmental detection information in the automotive field. In this way, the present invention not only inherits the advantages of existing technologies but also improves and innovates on the deficiencies of existing technologies to better meet the requirements of data security and privacy protection.
[0119] In some specific application scenarios, the embodiments of the present invention can be specifically implemented through the following process steps:
[0120] S1. Data collection:
[0121] S11. Extract personal information:
[0122] Operation: The system extracts the basic information and driving habit data of the vehicle owner from the vehicle management system.
[0123] According to the preset data collection requirements, access the vehicle's information system and sensors to extract the corresponding data.
[0124] The extracted data includes:
[0125] Owner Information: including name, contact information, driver's license information, etc., for identifying and contacting the vehicle owner.
[0126] Driving Habits Data: including driving speed, acceleration, braking frequency, etc., for analyzing driving behavior.
[0127] Vehicle Usage Data: including driving mileage, maintenance records, fuel consumption, etc., for evaluating vehicle performance and maintenance requirements.
[0128] S12. Extract environmental detection information:
[0129] Operation: The system extracts data such as the temperature, humidity, and air quality of the driving environment from the vehicle's environmental monitoring system.
[0130] The extracted data includes:
[0131] Environmental Parameters: including temperature, humidity, air quality index, etc., for evaluating the vehicle driving environment.
[0132] S2. Data storage:
[0133] S21. Determine the storage location:
[0134] The system first classifies the collected data to identify which data contains sensitive information, such as the personal information and driving habits of the vehicle owner, and which data is regular environmental monitoring information.
[0135] For data containing sensitive information, the system will choose to store it on a local server for better control of physical access and encryption measures. For example, the personal information and driving habit data of the vehicle owner will be stored on the company's internal secure servers, which are located within a controlled data center and have 24 / 7 monitoring and access logging.
[0136] For regular environmental monitoring information, the system may choose to store it on a cloud server because this data usually does not require frequent physical access, and cloud service providers typically offer highly available and scalable storage solutions. For example, the temperature, humidity, and air quality data of the vehicle driving environment will be uploaded to the storage buckets of the cloud service provider, which are located in different geographical locations to ensure data redundancy and fast access.
[0137] S22. Implement security measures:
[0138] For sensitive data stored on local servers, the system will use the SM4 encryption algorithm to encrypt the data to ensure that even if the data is illegally accessed, it cannot be interpreted. At the same time, the system will set strict access controls so that only authorized employees can access this data, and all access attempts will be logged and monitored.
[0139] For data stored on cloud servers, the system will utilize the security features of the cloud service provider, such as storage bucket encryption and access policies, to ensure that only authorized applications and services can access the data. In addition, the system will regularly conduct security audits of the cloud storage buckets to check for unauthorized access attempts or misconfigurations.
[0140] S23. Regular backups:
[0141] For the data on local servers, the system will perform a full backup once a day and incremental backups weekly and monthly. The backup data will be stored in different physical locations in case of a catastrophic event at the original storage location. For example, the daily backup will be copied to another data center, and the monthly backup will be stored in an offline secure location.
[0142] For data stored in the cloud, the system will utilize the backup function of the cloud service provider to ensure that multiple copies of the data are stored in different geographical locations. The system will also regularly test the recovery process to ensure that data can be quickly restored in case of data loss or corruption.
[0143] S3. Data masking:
[0144] S31. Define the desensitization rules:
[0145] Operation: The system first conducts a review of the relevant security and privacy regulations for information data to determine which data elements are considered sensitive information. For example, according to the General Data Protection Regulation, personal identity information (PII) needs to be desensitized. In the scenario of GPS data, the system will formulate a set of rules specifying which information must be replaced or encrypted.
[0146] For GPS route data, the system may decide to generalize specific latitude and longitude coordinates, replacing the specific values with a range. For example, represent the latitude and longitude "39.9042°N, 116.4074°E" of a certain location as the range "near the center of Beijing", or describe "the driving route from point A to point B" as "from one area to another area".
[0147] Among them, it should be noted that generalization means replacing specific data with a broader category or range to reduce the accuracy of the data while still retaining its analytical value. The purpose of generalization is to reduce the identifiability of the data so that it cannot be traced back to an individual.
[0148] Desensitization refers to processing sensitive data so that the original information cannot be identified without changing the data format or structure. The purpose of desensitization is to protect the privacy and security of the data and prevent personal identity from being identified when the data is leaked.
[0149] In the problem, adjusting the desensitization strategy generally involves encrypting the user's personal identity. For example, replacing the real name with a random ID 12345, and it is difficult to formulate a desensitization strategy.
[0150] The generalization strategy, however, can be changed according to different requirements. The specific degree of generalization can be defined in detail based on the sensitivity of the data, the usage scenario, the analysis requirements, and the requirements of relevant regulations.
[0151] For example: How many people near the center of Beijing may need to purchase a certain insurance? For this example problem, for the customer population, the target customers can be generalized as "medium to high-income people between 35 and 50 years old in Beijing".
[0152] For the area near the center of Beijing, a central point (such as Tiananmen Square, Wangfujing, etc.) can be selected as the center of Beijing, and then a radius (such as 3 km, 5 km or 10 km) can be set to define the scope of "nearby". Several districts around the center of Beijing can also be selected as the scope, such as Dongcheng District, Xicheng District, Chaoyang District, Haidian District, etc. These districts are generally considered to be "near the center". Areas with relatively high population density near the center of Beijing can be selected. These areas are usually places where commerce and residence are mixed, and census data or Geographic Information System (GIS) data can be used to define them.
[0153] The specific degree of generalization is still determined according to the needs, and factors such as analysis cost, existing data sources, target customer groups, and market environment need to be comprehensively considered.
[0154] Maintain flexibility during the analysis process, dynamically adjust the scope according to the preliminary analysis results and market feedback, and the specific degree after generalization can be provided for the demander to choose, such as choosing a radius of how many kilometers or choosing Dongcheng District and Xicheng District or choosing data of which part of the high-population-density aggregation area.
[0155] Formulate different generalization strategies according to different scenarios and needs: For example, if a certain user is inclined to buy a certain brand of laptop, different generalization strategies can be formulated according to different needs. There may be the following needs:
[0156] ① To find potential customer groups for keyboards and mice:
[0157] Generalization strategy:
[0158] Description of purchase preference: Replace the specific purchase record such as "The user purchased a mechanical keyboard and a wireless mouse of a certain brand in 2023" with "A certain user purchased a variety of peripheral products in the past year".
[0159] Behavior data: Aggregate the behavior data, such as replacing "The user viewed 10 keyboard and mouse products in the past three months" with "A certain user viewed a variety of peripheral products in the past three months".
[0160] ② To find potential customer groups for a certain brand:
[0161] Generalization strategy:
[0162] Description of purchase tendency: Replace the specific tendency description "The user has a strong interest in a certain brand of laptop" with "The potential customer group shows interest in a certain brand of laptop".
[0163] ③ To find users interested in laptops at a specific price range (such as 5000 - 8000 yuan):
[0164] Generalization strategy:
[0165] Price range description: Generalize the specific price description. For example, replace "User B viewed a laptop computer priced at 6,000 yuan" with "Customer B showed interest in laptop computers in the price range of 5,000 - 8,000 yuan."
[0166] For data that needs to be encrypted, the system will use strong encryption standards such as AES - 256 to encrypt the data. For example, if the system stores the detailed information of a specific driving route, this information will be encrypted into an unreadable string before storage. Only authorized personnel with the correct key can decrypt and view it.
[0167] Specific example: If the system records the driving trajectory of a vehicle: The trajectory shows that the vehicle owner drove from "a certain street in Chaoyang District, Beijing" to "a certain street in Haidian District, Beijing". According to the desensitization rules, the system can replace "a certain street in Chaoyang District" with "Chaoyang District" or "a certain commercial area", and "a certain street in Haidian District" with "Haidian District" or "near a certain school". After such processing, the data can still be used for analysis, but no longer be able to identify specific geographical locations.
[0168] S32. Perform desensitization operations:
[0169] When performing desensitization operations, the system will retain a mapping table for tracking the correspondence between the original data and the desensitized data, but this mapping table will be strictly protected and only authorized data managers can access it. In this way, the desensitized data can still be used for analysis and research while ensuring the protection of personal privacy. For example, researchers can use the processed GPS data to analyze traffic flow without specifically referring to any individual or specific location.
[0170] Basis for formulation:
[0171] The formulation of desensitization rules needs to comprehensively consider data types, usage purposes, and industry standards to ensure that data can be effectively utilized while strictly protecting personal privacy. For example, when processing market research data, strict protection of personal data is required according to relevant privacy regulations. The data to be used at this time includes consumer survey data such as age, gender, income level, and purchase preferences, and the usage purpose is to conduct market trend analysis to formulate relevant marketing strategies.
[0172] Specific standards:
[0173] Different types of data have different sensitivities. Data should be classified according to its nature (such as personal identity information, financial information, health records, etc.), and corresponding data desensitization rules should be formulated. For example, personal identity information requires more stringent desensitization processing, while general market research data can be moderately generalized. Considering the storage and presentation forms of data, such as text, numerical values, images, etc., data processing specifications for different formats should be formulated. For example, character replacement is performed on text data, and range generalization is performed on numerical data.
[0174] S4. Sandbox Computing:
[0175] First, the system creates a virtualized sandbox environment, configures the required computing resources and implements network isolation to ensure its complete isolation from the external network. Next, the analysis algorithms to be executed (such as route optimization algorithms) are integrated into the sandbox, and these algorithms are strictly reviewed to ensure their compliance with security standards and privacy protection requirements. Subsequently, the desensitized data (such as GPS trajectories) is input into the sandbox environment. These data have been desensitized before entering the sandbox to reduce privacy risks. In the sandbox, the system uses technologies such as multi-party secure computing (MPC) and federated learning (FL) to perform data analysis. The calculation process takes place within the sandbox, and all operations are monitored and recorded to ensure no data leakage. After the calculation is completed, the sandbox environment outputs the analysis results, such as the optimized driving route, and at this time, all original data and intermediate calculation results are completely cleared to prevent data leakage.
[0176] Algorithm Review:
[0177] 1.1 Security Review:
[0178] Code Review: Perform static analysis on the implementation code of the algorithm to check for security vulnerabilities (such as buffer overflows, SQL injections, etc.).
[0179] Dependency Library Review: Check the third-party libraries and modules on which the algorithm depends to confirm that they have no known security vulnerabilities and ensure that the versions used are the latest.
[0180] 1.2 Privacy Protection Performance:
[0181] Data Desensitization Verification: Confirm whether the input desensitized data meets the privacy protection requirements to ensure that the original information cannot be restored during the data processing.
[0182] Privacy Protection Mechanism: Review whether privacy protection technologies (such as differential privacy, encryption technologies, etc.) are embedded in the algorithm and evaluate its ability to protect personal privacy in the output results.
[0183] 1.3 Performance Evaluation:
[0184] Efficiency Testing: Evaluate the running efficiency of the algorithm in a sandbox environment to ensure that it can complete computational tasks within a reasonable time.
[0185] Resource Consumption Analysis: Analyze the usage of computing resources by the algorithm to confirm that it will not consume excessive resources during the calculation process.
[0186] 1.4 Compliance Review:
[0187] Compliance Check: Ensure that the algorithm follows relevant regulations (such as GDPR, PIPL, etc.) and industry standards, especially the requirements in data processing and privacy protection.
[0188] 2. Review Criteria:
[0189] Security Standards: Comply with industry standards (such as OWASP, NIST, etc.) and the organization's internal security policies.
[0190] Privacy Protection Standards: Ensure that the adopted privacy protection measures reach industry best practices and can effectively prevent data leakage and personal identification.
[0191] Performance Standards: The running time and resource consumption of the algorithm should be within an acceptable range, usually evaluated according to the benchmarks defined by the organization.
[0192] Compliance Standards: Ensure that the algorithm and processing procedures comply with applicable regulations and standards, and ensure that appropriate regulatory bases are adopted when processing personal data.
[0193] 3. Review Process
[0194] Submission of Application: The development team submits an algorithm review application, accompanied by algorithm documentation and relevant code.
[0195] Initial Assessment: The review team conducts an initial assessment to confirm the completeness of the application materials and conducts a preliminary code review.
[0196] Detailed Review:
[0197] Conduct in-depth code reviews, detailed analyses in aspects such as security, privacy protection performance, and compliance, etc.
[0198] Implement a method that combines automated tools and manual checks.
[0199] Review Report: The review team writes a review report, summarizes the review results, points out existing problems and improvement suggestions.
[0200] Feedback and Revision: Feedback the review report to the development team, require it to make revisions according to the suggestions, and then resubmit for review.
[0201] Final review: Conduct a final review of the revised algorithm. After confirming that it meets all the standards, it can be released and executed in the sandbox environment.
[0202] 4. Handling measures when the review is unqualified:
[0203] Problem recording: The review team records the reasons for non - compliance and existing problems and forms a problem list.
[0204] Feedback mechanism: Provide detailed review results to the development team, along with improvement suggestions and repair guidance.
[0205] Re - review requirement: Require the development team to resubmit a review application after fixing all the problems and re - enter the review process.
[0206] Temporary disablement: For algorithms that do not meet the security and privacy protection standards, temporarily disable them and do not allow them to run in the sandbox environment.
[0207] Risk assessment: If the non - compliance of the algorithm leads to potential risks, conduct a risk assessment and take necessary remedial measures, such as data cleaning, additional security controls, etc.
[0208] Such as data optimization algorithms:
[0209] 1.1 Data privacy protection:
[0210] Input data review:
[0211] Ensure that the input GPS data has been desensitized, and delete or encrypt the user's personally identifiable information (PII), such as name, address, mobile phone number, etc.
[0212] Verify whether the desensitized data can prevent the recovery of the user's identity, that is, ensure that the data cannot be traced back to a specific user.
[0213] Output data review:
[0214] Review the output results of the algorithm to ensure that they do not contain any personal information or sensitive data. If the output results need to include geographical information, the specific location information should be generalized to a wider area description (such as "from Area A to Area B") instead of a specific address.
[0215] 1.2 Algorithm privacy protection mechanism:
[0216] Privacy protection technology:
[0217] Review whether the algorithm integrates privacy protection technologies, such as Differential Privacy and Homomorphic Encryption, to prevent the leakage of the user's location information during the data processing process.
[0218] Then, review is conducted in accordance with the review criteria and process, which can effectively protect the privacy of users and ensure that sensitive information is not disclosed during data analysis and processing.
[0219] During the review process, it is necessary to ensure the protection of user privacy:
[0220] Data minimization principle: Only collect and use the necessary data during the processing to avoid excessive exposure of user information.
[0221] Data de-identification: Ensure that data is de-identified during storage and processing to eliminate the ability to identify users.
[0222] User consent: Ensure that clear consent from users is obtained before collecting and processing user data, and provide transparent information about the purpose and scope of data use.
[0223] Audit and monitoring: Implement monitoring during the execution of the algorithm, record all operations for subsequent auditing and problem tracking.
[0224] S5. Data sharing platform:
[0225] S51. Establish a data sharing platform:
[0226] The system establishes a data sharing platform and provides API interfaces for external modules to access data services. The design of this platform aims to achieve modular data services, allowing users to customize data access permissions and scope according to their needs. For example, through this platform, desensitized GPS data and other relevant data (such as driving habit data and environmental monitoring information) can be safely provided to authorized partners and research institutions.
[0227] S52. Ensure data security:
[0228] The system ensures the security and privacy of data on the sharing platform by implementing measures such as access control, data encryption, and audit log recording. To prevent data leakage, the system will conduct strict security checks on the shared data to ensure that all shared data complies with relevant privacy regulations and privacy protection requirements. At the same time, all transmitted data will be encrypted before being sent to ensure security during sharing.
[0229] The system ensures data security and privacy by implementing measures such as access control, data encryption, and audit logging. In terms of encryption, according to FIPS140-2 / 3 (U.S. Federal Information Processing Standards) and ISO / IEC 27001 (Information Security Management Standard issued by the International Organization for Standardization), encryption algorithms such as AES, RC4, and ECC can be used to encrypt transmitted data. At the same time, during the process of transmitting data, TLS (Transport Layer Security Protocol) and VPN (Virtual Private Network) are used for data transmission to ensure that data is encrypted during network transmission and prevent man-in-the-middle attacks.
[0230] In terms of access control policies, the following two policies can be adopted:
[0231] Role-Based Access Control (RBAC): Permissions are assigned based on the user's role to ensure that only authorized users can access sensitive data. For example, administrators can access all data, while ordinary users can only access the data required for their work.
[0232] Attribute-Based Access Control (ABAC): Dynamically determines permissions using user attributes, resource attributes, and environmental conditions (such as time and location) to provide more fine-grained control. Throughout the process, the principle of least privilege is followed: users and systems only obtain the minimum permissions required to complete tasks to reduce potential security risks.
[0233] In terms of the access control mechanism, authentication and permission review are adopted to ensure the security of data access:
[0234] Authentication: Use multi-factor authentication (MFA), such as passwords, SMS verification codes, or biometric technologies, to ensure the authenticity of the user's identity.
[0235] Permission review: Regularly review user permissions to ensure that data that is no longer needed for access is withdrawn in a timely manner.
[0236] In terms of audit logging, the recorded content includes:
[0237] User activity logs: Record the user's login / logout time, accessed data, executed operations, modified records, etc.
[0238] System event logs: Record system security events, such as permission changes, abnormal access attempts, data sharing, etc.
[0239] Data access logs: Detail who accessed which data at what time, including information such as the source IP address of the access request.
[0240] Query methods include:
[0241] Centralized Log Management: Use a centralized log management system (such as ELK Stack, Splunk, etc.) to facilitate the storage, search, and analysis of logs.
[0242] Real-time Monitoring and Alerting: The system should have the ability to monitor in real time, automatically trigger alerts for abnormal access behaviors, and remind security administrators to conduct investigations.
[0243] Regular Auditing: Generate audit reports regularly, analyze access patterns and potential security threats, and ensure the integrity and accuracy of logs.
[0244] S6. Data Sharing Process:
[0245] In the process of data sharing, ensuring data security and compliance is crucial. The following is the detailed process of data sharing, including data preparation, transmission methods, allocation and management of access rights, and the regulations and restrictions that partners should abide by when receiving and using data.
[0246] S61. Implementation of Data Sharing Mechanism:
[0247] Data Preparation:
[0248] Data Masking: Ensure that all data to be shared undergoes data masking. For GPS route data and driving behavior data, remove or encrypt users' personally identifiable information (PII), such as names, contact information, and specific addresses, and replace them with more general descriptions.
[0249] Data Cleaning: Before sharing, conduct data cleaning to ensure data accuracy and integrity, and delete invalid or redundant data records.
[0250] Data Formatting: Convert the data into a standard format (such as CSV, JSON, etc.) to facilitate subsequent transmission and analysis.
[0251] Transmission Methods:
[0252] API Interfaces: Use secure API interfaces for data transmission to ensure the security of data requests and responses.
[0253] Encryption Technology: During data transmission, use TLS (Transport Layer Security Protocol) to encrypt all data to prevent it from being stolen or tampered with during transmission.
[0254] Allocation and Management of Access Rights:
[0255] Permission Management: Implement role-based access control (RBAC) or attribute-based access control (ABAC) according to users' roles and requirements to ensure that only authorized users can access specific data.
[0256] Example of role - based access control:
[0257] ① For research institutions:
[0258] Roles: Researcher, Project Manager, Data Analyst.
[0259] Access permissions:
[0260] Researcher: Can access the de - identified dataset for research and analysis, and is prohibited from accessing any personally identifiable information (PII).
[0261] Project Manager: Can access project - related data and analysis results, and view the overall data usage.
[0262] Data Analyst: Can access detailed analysis tools and data reports, but cannot modify the original data or access unprocessed sensitive data.
[0263] ② For business partners:
[0264] Roles: Marketing Manager, Sales Representative.
[0265] Access permissions:
[0266] Marketing Manager: Can access market research and consumer behavior data to help formulate market strategies.
[0267] Sales Representative: Can access aggregated sales - related data, but cannot view the detailed purchase records of users.
[0268] Example of attribute - based access control:
[0269] ① Definition of partner attributes:
[0270] User attributes:
[0271] Identity: Identity information of the partner (e.g., "Researcher of a certain research institution").
[0272] Role: Specific role of the user (e.g., "Project Manager" or "Data Analyst").
[0273] Authentication status: Whether the user is authenticated (e.g., MFA authentication).
[0274] Resource attributes:
[0275] Data type: The type of data shared (e.g., "de - identified GPS data", "driving behavior data").
[0276] Data sensitivity: The sensitivity level of the data (e.g., "low sensitivity", "high sensitivity").
[0277] Environmental conditions:
[0278] Time: The time when the user accesses the data (such as working hours or non - working hours).
[0279] Location: The physical location of the user (such as a specific network environment or VPN access).
[0280] ② Permission decision - making process:
[0281] Dynamic decision - making: Dynamically determine whether the user has the right to access specific data based on the user's attributes, the attributes of the requested resources, and the current environmental conditions. For example:
[0282] If the user is a "researcher", and the requested data is "de - identified GPS data", and the request occurs during working hours, access is allowed.
[0283] If the user attempts to access data during non - working hours, the request is rejected.
[0284] User authentication: Implement multi - factor authentication (MFA) to ensure the authenticity of the user's identity who requests to access the data.
[0285] Regular review: Regularly review and update access permissions to ensure that data that is no longer needed is withdrawn in a timely manner.
[0286] S62. Sharing data with partners:
[0287] ① Partner selection:
[0288] Screen partners: Ensure that partners (such as research institutions, government departments, etc.) with whom data is shared are legal and compliant and can comply with relevant requirements for data privacy protection.
[0289] ② Provisions and restrictions on receiving and using data:
[0290] Compliance commitment: Partners are required to sign a confidentiality agreement and a data use agreement when receiving data, clearly defining the privacy regulations and privacy protection requirements they need to follow when using the data.
[0291] Restriction on use purposes: Partners can only use the shared data for specific analysis and decision - making support, and it is strictly prohibited to use the data for other unauthorized purposes.
[0292] Restriction on data re - sharing: Partners shall not re - share the received data with a third party unless they obtain the explicit authorization of the data provider.
[0293] Data storage and destruction: After using the data, partners should store the data securely in accordance with the agreement requirements and destroy it completely in accordance with the regulations when it is no longer needed.
[0294] Audit and Monitoring: The provider has the right to audit the partner's data usage to ensure compliance with the data sharing agreement and privacy protection regulations.
[0295] ③ Data Feedback Mechanism:
[0296] Regular Feedback: Partners should regularly provide feedback to the data provider on the usage effects and analysis results of the data to continuously improve the data sharing mechanism.
[0297] Problem Reporting: In the process of data usage, if any privacy leakage or data security issues are found, they should be promptly reported to the data provider for corresponding measures to be taken.
[0298] In summary, aiming at the disadvantages of the prior art, the purpose of the present invention is to provide an improved data management system with the following characteristics:
[0299] The present invention aims to make data more secure during transmission, storage, and processing through some advanced security technologies and authentication mechanisms, preventing data leakage and unauthorized access. At the same time, it also provides some more comprehensive data privacy protection measures to ensure the effective protection of personal privacy in various data processing situations. In addition, by optimizing the data sharing mechanism, it can also improve the sharing and utilization efficiency of data and maximize the value of data.
[0300] This solution not only solves the problems of data secure storage, privacy protection, sharing, and utilization, but also meets the data management requirements of the automotive industry and other industries. By achieving these goals, it promotes the technological progress of the data management system, especially in the automotive field, ensuring the secure storage and sharing of personal information and environmental monitoring information, and providing a more reliable and efficient solution.
[0301] Compared with the prior art, the technical feature effects achieved by the embodiments of the present invention include but are not limited to:
[0302] 1. Enhanced Data Security and Authentication Mechanism:
[0303] The present invention ensures the security of data during transmission, storage, and processing by integrating advanced security technologies and authentication mechanisms, solves the problem of insufficient security in the prior art, and prevents data leakage and unauthorized access. Especially for the privacy protection challenges in data sharing and cross-platform applications, it provides a more comprehensive solution.
[0304] 2. Dynamic Data Masking Processing Mechanism:
[0305] For complex data processing scenarios, the present invention designs a set of dynamic data masking rules that can be flexibly processed according to data types (such as GPS route data and driving habit data). The data masking measures not only include simple replacement and encryption, but also can generalize the data to ensure the effective protection of personal privacy in diverse applications.
[0306] 3. Efficient data sharing platform:
[0307] The present invention provides a modular data sharing platform that allows users to customize data access permissions and scopes according to their needs. This platform not only realizes "usable but invisible" data, but also optimizes the data sharing mechanism to ensure that the efficiency of data utilization is not sacrificed during the sharing process, thereby maximizing the commercial value of the data.
[0308] 4. Secure application of sandbox computing environment:
[0309] The present invention applies sandbox computing technologies (such as trusted execution environment, MPC, and federated learning) to build a secure computing environment to ensure the privacy of data during analysis and processing. This innovation solves the problem of insufficient privacy protection in the prior art during data processing and ensures that sensitive data is not leaked during use.
[0310] 5. Flexibility and scalability design:
[0311] The data management system has high flexibility and scalability, can quickly adapt to changing business requirements and technological progress, overcome the problems of insufficient flexibility and scalability in existing systems, and ensure that it can continuously meet the data management needs in different fields (such as the automotive industry).
[0312] 6. Holistic data management solution:
[0313] The present invention provides an overall data management framework that can simultaneously solve the problems of secure data storage, privacy protection, sharing, and utilization, avoiding the deficiencies brought by isolated solutions in the prior art. This solution is particularly suitable for the data management needs of the automotive industry and other industries, promoting the technological progress of data management systems.
[0314] Such as Figure 2 As shown, an embodiment of the present invention further provides a data security management device 900, which may include:
[0315] A first module 901 for obtaining information data to be managed; the information data includes sensitive data and regular data;
[0316] A second module 902 for encrypting and storing sensitive data and regular data in different servers and performing regular backups on the data stored in the servers;
[0317] The third module 903 is configured to desensitize sensitive information in information data based on a preset desensitization rule to obtain desensitized data;
[0318] The fourth module 904 is configured to perform target data analysis through a pre-constructed sandbox environment based on the desensitized data to obtain a data analysis result;
[0319] Among them, the desensitized data and the data analysis result are stored in the server;
[0320] The fifth module 905 is configured to establish a data sharing platform based on the server according to a preset permission range and control policy;
[0321] The sixth module 906 is configured to, in response to a data sharing request from an authorized object, share target data with the authorized object through the API interface of the data sharing platform.
[0322] The content of the method embodiment of the present invention is applicable to the apparatus embodiment of the present invention. The functions specifically implemented by the apparatus embodiment of the present invention are the same as those of the above method embodiment, and the beneficial effects achieved are also the same as those of the above method.
[0323] The embodiment of the present invention further provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the above data security management method is implemented. The electronic device can be any intelligent terminal including a tablet computer, an in-vehicle computer, etc.
[0324] It can be understood that the content in the above method embodiment is applicable to the device embodiment of the present invention. The functions specifically implemented by the device embodiment of the present invention are the same as those of the above method embodiment, and the beneficial effects achieved are also the same as those of the above method embodiment.
[0325] Please refer to Figure 3 , Figure 3 which shows the hardware structure of an electronic device 1000 according to another embodiment. The electronic device 1000 includes:
[0326] A processor 1001, which can be implemented by using a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is configured to execute relevant programs to implement the technical solution provided by the embodiment of the present invention;
[0327] The memory 1002 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM), etc. The memory 1002 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1002 and are called by the processor 1001 to execute the data security management method of the embodiments of the present invention;
[0328] The input / output interface 1003 is used to implement information input and output;
[0329] The communication interface 1004 is used to implement communication interaction between this device and other devices. Communication can be achieved through a wired method (such as USB, network cable, etc.) or through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.);
[0330] The bus 1005 transmits information between the various components of the device (such as the processor 1001, the memory 1002, the input / output interface 1003, and the communication interface 1004);
[0331] Among them, the processor 1001, the memory 1002, the input / output interface 1003, and the communication interface 1004 achieve communication connections with each other inside the device through the bus 1005.
[0332] The embodiments of the present invention also provide a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the above-mentioned data security management method.
[0333] It can be understood that the content in the above method embodiments is applicable to the embodiments of this storage medium. The functions specifically implemented by the embodiments of this storage medium are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those of the above method embodiments.
[0334] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include a high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory optionally includes a memory remotely provided relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above networks include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0335] The data security management method, data security management device, electronic device, and storage medium provided by the embodiments of the present invention obtain information data to be managed; the information data includes sensitive data and regular data; encrypt and store the sensitive data and regular data in different servers, and regularly back up the data stored in the servers; perform a desensitization operation on the sensitive information in the information data based on a preset desensitization rule to obtain desensitized data; perform target data analysis through a pre-constructed sandbox environment based on the desensitized data to obtain a data analysis result; wherein, the desensitized data and the data analysis result are stored in the server; establish a data sharing platform based on the server according to a preset permission range and control policy; in response to a data sharing request from an authorized object, share the target data with the authorized object through the API interface of the data sharing platform. The present invention has the following beneficial effects:
[0336] 1. Improvement of data security: By encrypting and storing sensitive data and regular data separately in different servers, the risk of data leakage is effectively reduced, thereby improving the overall data security.
[0337] 2. Data backup: Regularly back up the data stored in the server to ensure quick recovery in case of data loss or damage, and guarantee the integrity and availability of the data.
[0338] 3. Desensitization of sensitive information: Perform a desensitization operation on the sensitive information based on a preset desensitization rule to generate desensitized data. While retaining the data value, the desensitized data eliminates the risk of sensitive information leakage and is applicable to scenarios such as data analysis and testing.
[0339] 4. Secure data analysis environment: Perform target data analysis through a pre-constructed sandbox environment to ensure the security and isolation of the data analysis process, and prevent misoperation or leakage of the original data during the data analysis process.
[0340] 5. Controllability of data sharing: Based on a preset permission range and control policy, establish a data sharing platform to ensure that only authorized objects can access specific data. Implement data sharing through the API interface, providing a flexible and controllable data sharing mechanism to meet the access needs of different authorized objects.
[0341] 6. Improvement of data utilization efficiency: On the premise of ensuring data security, through the data sharing platform and desensitized data analysis, the data utilization efficiency is improved, supporting the needs of enterprise decision-making, business innovation, etc.
[0342] In summary, the embodiments of the present invention provide significant beneficial effects in terms of data security, privacy protection, data sharing, and utilization efficiency, and are applicable to various scenarios that require efficient, secure management, and sharing of data.
[0343] The embodiments described in the embodiments of the present invention are to more clearly illustrate the technical solutions of the embodiments of the present invention, and do not constitute a limitation to the technical solutions provided by the embodiments of the present invention. Those skilled in the art can know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present invention are equally applicable to similar technical problems.
[0344] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation to the embodiments of the present invention, and may include more or fewer steps than those shown in the figures, or combine certain steps, or different steps.
[0345] The system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present invention.
[0346] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and their appropriate combinations.
[0347] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present invention and the above drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0348] It should be understood that in the present invention, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one (item) of the following" or its similar expressions refer to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0349] In several embodiments provided by the present invention, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the above division of units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of systems or units can be in electrical, mechanical or other forms.
[0350] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of the embodiments of the present invention.
[0351] In addition, the functional units in each embodiment of the present invention can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0352] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention. The aforementioned storage medium includes: various media that can store programs, such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs.
[0353] The preferred embodiments of the embodiments of the present invention have been described above with reference to the accompanying drawings, and thus do not limit the scope of the rights of the embodiments of the present invention. Any modifications, equivalent replacements, and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of the present invention shall be within the scope of the rights of the embodiments of the present invention.
Claims
1. A data security management method, characterized in that, The method includes the following steps: Obtain information data to be managed; the information data includes sensitive data and regular data; Encrypt and store the sensitive data and the regular data in different servers, and perform regular backups on the data stored in the servers; Perform a desensitization operation on the sensitive information in the information data based on a preset desensitization rule to obtain desensitized data; Execute target data analysis through a pre-constructed sandbox environment based on the desensitized data to obtain a data analysis result; Among them, the desensitized data and the data analysis result are stored in the server; Establish a data sharing platform based on the server according to a preset permission range and control policy; In response to a data sharing request from an authorized object, share the target data to the authorized object through the API interface of the data sharing platform.
2. The data security management method according to claim 1, wherein The encrypting and storing the sensitive data and the regular data in different servers includes the following steps: Store the sensitive data in a local server; use a preset encryption algorithm to encrypt the data on the local server; Store the regular data in a cloud server; use the security function of the cloud service provider to encrypt and control the data in the cloud server.
3. The data security management method according to claim 1, characterized in that, The server includes a local server and a cloud server; the performing regular backups on the data stored in the servers includes the following steps: Perform full backups and incremental backups on the data on the local server regularly based on a preset period; among them, the execution period of the incremental backup is longer than that of the full backup, and the backup data is stored in a different physical location on the local server compared to the data being backed up; Use the backup function of the cloud service provider to perform backup processing on the data in the cloud server regularly, and regularly test the data recovery process of the cloud server; among them, each backup copy obtained from different backup processes is stored in a different physical location on the cloud server.
4. The data security management method according to claim 1, wherein The performing a desensitization operation on the sensitive information in the information data based on a preset desensitization rule includes the following steps: In response to a preset data element review rule, mark the sensitive information in the information data; Among them, the data types of the sensitive information include a first type, a second type, and a third type; Perform desensitization processing on the sensitive data of the first type; Perform generalization processing on the sensitive data of the second type; Perform strong encryption processing on the sensitive data of the third type; Construct a desensitization mapping table according to the correspondence between the sensitive information and the obtained desensitized data.
5. The data security management method according to claim 1, wherein The executing target data analysis through a pre-constructed sandbox environment based on the desensitized data to obtain a data analysis result includes the following steps: In response to a preset configuration requirement, create the sandbox environment by configuring target computing resources through network isolation; Among them, an analysis algorithm to be executed is integrated in the sandbox environment; Input the desensitized data into the sandbox environment, execute the target data analysis based on the analysis algorithm, and output the data analysis result through the sandbox environment.
6. The data security management method according to claim 1, wherein Based on the preset permission scope and control policy, a data sharing platform is established based on the server, including the following steps: In response to the customization requirements of the management object for the access rights and scope of data, determine the shared data scope of the data sharing platform; Configure the security and privacy settings of the data sharing platform through the control policy; Among them, the control policy includes an access control policy, a data encryption policy, and an audit log recording policy.
7. The data security management method according to claim 1, characterized in that, In response to the data sharing request of the authorized object, share the target data with the authorized object through the API interface of the data sharing platform, including the following steps: In response to the data sharing request of the authorized object, determine the data to be shared; Perform data cleaning processing on the data to be shared to obtain the data to be transmitted; Based on the preset transport layer security protocol, encrypt and transmit the data to be transmitted to the authorized object through the API interface of the data sharing platform to complete data sharing.
8. A data security management device, characterized in that, The device includes: A first module for obtaining information data to be managed; the information data includes sensitive data and regular data; A second module for encrypting and storing the sensitive data and the regular data in different servers, and regularly backing up the data stored in the servers; A third module for performing a desensitization operation on the sensitive information in the information data based on a preset desensitization rule to obtain desensitized data; A fourth module for performing target data analysis based on the desensitized data through a pre-constructed sandbox environment to obtain a data analysis result; Among them, the desensitized data and the data analysis result are stored in the server; A fifth module for establishing a data sharing platform based on the server according to the preset permission scope and control policy; A sixth module for, in response to the data sharing request of the authorized object, sharing the target data with the authorized object through the API interface of the data sharing platform.
9. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Business data processing method and device based on cloud platform
CN106487775A
Self describing configuration with support for sharing data tables
CN108604278A
Data security management method and device, computer equipment and storage medium
CN114372286A
Medical data sharing system and method based on security mechanism
CN118965439A
Grading use method based on sensitive data
CN119167425A