Data security processing method and system oriented to privacy protection
By performing data processing and differential privacy technology in a local environment, we can solve the privacy leakage problem of children's data stored in a centralized manner, implement a data security processing system, ensure children's privacy protection and device robustness, and provide personalized learning guidance and safety functions.
Patent Information
- Application Number
- CN202510853397.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-09-09
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In existing technologies, the centralized storage and uploading mode of children's data poses serious risks of privacy leakage. In addition, under the centralized data processing mode, children's sensitive information can be easily obtained illegally, making it difficult to detect data leakage in a timely manner, thereby violating privacy compliance requirements.
By processing data in the local environment, combining differential privacy technology, data classification and de-privacy processing are carried out, and model algorithms are deployed on the terminal to analyze children's behavior in real time, generate application results and early warning reminders, and at the same time encrypt and store access logs and perform multi-level verification to ensure data security.
Significantly reduce the risk of data leakage during transmission and centralized storage, improve the system's ability to resist attacks, ensure that parents can monitor data usage in real time, implement personalized learning guidance and safe Internet filtering, and balance privacy protection and device robustness.
Smart Images

Figure CN120611418A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of children's privacy protection, and in particular to a data security processing method and system for privacy protection. Background Art
[0002] With the prevalence of smart devices and internet applications in children's education and entertainment, a large amount of data involving children's personal information is being generated and collected. Traditional solutions often upload this data to cloud servers for storage and analysis. This model poses a serious risk of children's privacy leakage. Numerous security incidents have shown that large-scale, centralized storage of children's data is highly vulnerable to attacks, and even data leaks can be difficult to detect. Parents have little recourse for leaked children's information. This shows that under the current centralized data processing model, once a data leak occurs, children's sensitive information may be illegally obtained, posing long-term potential risks. At the same time, existing smart children's apps' reliance on cloud-based big data and centralized model training also poses privacy risks. To provide personalized content or accurate analytical results, many products need to collect large amounts of child user data for model training. However, centralized collection of children's data not only violates the principles of "data minimization" and "limited retention," but also increases the likelihood of sensitive information leakage. Even with anonymization, the centralized transmission and storage of large-scale data can be exploited by attackers. In summary, how to minimize the "clouding" of children's data while ensuring functionality, allowing parents to control the retention of data, and meeting increasingly stringent privacy compliance requirements has become a pressing technical challenge. In response to the above technical problems, this application proposes a solution. Summary of the Invention
[0003] In the present invention, by limiting data processing to the local environment and supplemented by technologies such as differential privacy, the security risks of uploading unprotected sensitive information to the cloud are eliminated, and the risk of data being stolen during transmission and centralized storage is greatly reduced. The cloud data does not contain the original data of children, thereby avoiding privacy leaks. The overall ability of the system to resist data leaks and hacker attacks is improved. By matching and storing access logs and matching hash values, it is ensured that if the access logs are modified, they can be directly discovered and warned. This solves the problem that a large amount of data involving children's privacy is uploaded to the cloud, making the data set easy to become an attack target, leading to data leaks, and difficult to be discovered in time after data leaks. A data security processing method and system for privacy protection are proposed.
[0004] The purpose of the present invention can be achieved through the following technical solutions: The data security processing method for privacy protection includes the following steps: Step 1: Collect initial data through the terminal device and perform preliminary processing on the collected data to obtain preliminary screening data; Step 2: Classify the initial screening data according to the locally deployed algorithm, and apply the classification results to obtain multiple application results; Step 3: Use the application results to issue corresponding warning reminders and push operations; Step 4: Obtain a data cloud usage request, de-identify the data based on the usage request, and upload it to the cloud. At the same time, generate a data lifecycle. Step 5: Obtain data access request, perform multi-level verification on data access identity, and encrypt and store data access logs.
[0005] The data security processing system for privacy protection includes a terminal data collection module, a local data processing module, a data privacy processing module, a data access verification module, and a data application module. The terminal data collection module is used to collect usage data and filter the collected usage data to obtain preliminary screening data. After the local data processing module obtains the preliminary screening data, it classifies the preliminary screening data through the locally deployed model algorithm, applies different types of preliminary screening data after the classification is completed, and obtains corresponding application results based on the application results. The local data processing module sends the application results to the data application module; The data privacy processing module is used to perform privacy removal processing on the primary screening data obtained by the terminal data acquisition module to obtain fuzzy data. The data privacy processing module is also used to control the sending and receiving of data. When data sending and receiving is required, the fuzzy data is uploaded to the cloud; The data access verification module is used to connect to the data access port and confirm the data access identity through the data access port, grant different access rights or deny access according to different data access identities, and encrypt and store the access records; After the data application module obtains the application result, it performs push control and reminder control on the terminal device according to the application result.
[0006] As a preferred embodiment of the present invention, the usage data collected by the terminal data acquisition module includes voice data, image data and device usage data, wherein the device usage data further includes the type of device usage and the usage time corresponding to the type. The terminal data acquisition module filters the collected usage data and records the remaining data as preliminary screening data.
[0007] As a preferred embodiment of the present invention, the terminal data collection module determines whether the data is obviously invalid in the following manner: The terminal data acquisition module obtains the data type required for local model evaluation through the local data processing module. The data type that can be applied to the local model evaluation is recorded as valid data, while the data that cannot be applied to the local model evaluation is recorded as invalid data.
[0008] As a preferred embodiment of the present invention, the local data processing module classifies the initial screening data into behavior recognition data, learning data and push simulation data, wherein: behavior recognition data is used to analyze children's behavior, learning data is used to judge the completion of children's learning, and push simulation data is used to judge learning progress and entertainment plans respectively.
[0009] As a preferred embodiment of the present invention, when the local data processing module uses the behavior recognition data, it identifies the child's behavior through voice and image, obtains the child's current behavior, and compares it with the preset inappropriate behavior database, and generates and records the inappropriate behavior warning based on the comparison result; When the local data processing module uses the learning data, it uses the collected usage time of the learning device as a benchmark and determines whether the user is in a focused state of learning through voice and image. If the user is in a focused state, the learning time is determined to be valid. If the user is not in a focused state, the learning time is corrected according to a set ratio to obtain an equivalent learning time. The valid learning time and the equivalent learning time are summed to obtain the total learning time. The total learning time is compared with the preset learning plan time. Based on the comparison result, it is determined whether the learning is completed or not, and the result is recorded. When the local data processing module uses the pushed simulation data, it performs weighted quantitative analysis based on the collected question accuracy and answering time, takes the question accuracy as the benchmark, and corrects the question accuracy based on the answering time to obtain the learning mastery status, and then compares the learning mastery status with the set learning progress to determine whether the learning standard is met or not; When the local data processing module uses the pushed simulation data, it collects the usage time of the smart toy and compares it with the set time range, and generates a children's entertainment time determination result based on the comparison.
[0010] As a preferred embodiment of the present invention, the data privacy processing module can receive data usage requests through the cloud and extract the type and amount of data to be used. The data privacy processing module performs de-privacy processing on the initial screening data that needs to be uploaded to the cloud, and at the same time generates a data lifespan for the fuzzy data uploaded to the cloud, where the data lifespan includes the data retention time and the number of data uses. When the time after the data is uploaded to the cloud reaches the data retention time or the number of times the data is used reaches the generated data usage number, the data is formatted.
[0011] As a preferred embodiment of the present invention, the data access verification module performs multi-level confirmation of the data access identity through the data access port, and determines whether the identity is normal or abnormal based on the confirmation result. After determining that the identity is normal, the data access verification module records the accessed data content and the access identity. After determining that the identity is abnormal, the data access verification module records the login time and login address corresponding to the denied access identity. The data access verification module integrates the recorded content into an access log data packet, and generates a corresponding paired hash value from the access log data packet through a hash algorithm. The data access verification module pairs and stores the access log data packet and the paired hash value.
[0012] As a preferred embodiment of the present invention, when the data access verification module checks the access log data packet, the data access verification module generates a verification hash value for the access log data again through the same hash algorithm, and compares the verification hash value with the pairing hash value. If the comparison result is overlap, the access log data packet is fed back as normal and the access log data packet is displayed. If the comparison result is not overlap, the access log data packet is fed back as abnormal and an abnormality warning is generated.
[0013] Compared with the prior art, the present invention has the following beneficial effects: 1. In the present invention, by limiting data processing to the local environment and supplemented by technologies such as differential privacy, the security risks of uploading unprotected sensitive information to the cloud are eliminated, and the risk of data being stolen during transmission and centralized storage is greatly reduced. Even if an attacker invades the cloud, he or she will not be able to obtain the child's original data, thereby avoiding privacy leakage. The overall ability of the system to resist data leakage and hacker attacks is improved. At the same time, with the help of the local simulation mode, the system can still independently complete the core functions when the terminal is in a poor network or offline environment, thereby improving the robustness and availability of children's devices.
[0014] 2. In the present invention, through multi-level access security control and local storage mechanism, parents can obtain data related to their children in real time. At the same time, by recording the access log, parents can ensure that they can view the situation of children's related data being viewed or used. At the same time, in order to avoid the access log from being modified, the access log and the matching hash value are matched and stored to ensure that if the access log is modified, it can be directly discovered and an early warning is issued, so that data leakage can be discovered in time, thereby reducing data loss or stopping subsequent data leakage.
[0015] 3. In the present invention, by deploying models and algorithms locally, the system can analyze children's behavior in real time and provide feedback, realizing functions such as personalized learning guidance, safe Internet filtering, and inappropriate behavior warning. At the same time, local processing combined with de-privacy data aggregation can also support distributed model training, thereby improving the overall model performance while protecting privacy, taking into account both security and device usage experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] To facilitate understanding by those skilled in the art, the present invention is further described below with reference to the accompanying drawings.
[0017] Figure 1 is a system block diagram of the present invention; Figure 2 It is a system flow chart of the present invention. DETAILED DESCRIPTION
[0018] The following is a clear and complete description of the technical solutions of the present invention in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0019] Example 1: See also Figure 1 - Figure 2 As shown, the data security processing method and system for privacy protection are characterized by including a terminal data acquisition module, a local data processing module, a data privacy processing module, a data access verification module and a data application module; The terminal data collection module is used to collect usage data. The collected usage data includes voice data, image data, and device usage data. The device usage data includes the type of device used and the corresponding usage time. Specifically, the device usage types include tablet computers, learning machines, smart toys, etc., and the corresponding usage time is the time the child uses each type of device. Voice data and image data are generally obtained through monitoring devices such as cameras to obtain the child's status in real time. The terminal data collection module filters the collected usage data to filter out obviously invalid data and record the remaining data as preliminary screening data; The method for determining obviously invalid data is as follows: the terminal data acquisition module obtains the data type required for local model evaluation through the local data processing module. The data type that can be applied to the local model evaluation is recorded as valid data, while the data that cannot be applied to the local model evaluation is recorded as invalid data. After the local data processing module obtains the preliminary screening data, it classifies the preliminary screening data through the locally deployed model algorithm, thereby dividing the preliminary screening data into behavior recognition data, learning data, and push simulation data. The behavior recognition data is used to analyze the child's behavior, identify the child's behavior through voice and image, obtain the child's current behavior, and compare it with the preset inappropriate behavior database. If the child's current behavior matches the preset inappropriate behavior database, an inappropriate behavior warning is generated and recorded; Learning data is used to judge the completion of children's learning. Simulation analysis is performed through voice, image, and the usage time of the learning device. Based on the usage time of the learning device, voice and image are used to judge whether the child is in a state of concentration in learning. If the child is in a state of concentration, the learning time is determined to be valid. If the child is not in a state of concentration, the learning time is corrected according to a set ratio to obtain an equivalent learning time. Finally, the effective learning time and the equivalent learning time are summed to obtain the final total learning time, and the total learning time is compared with the preset learning plan time. If the total learning time reaches the preset learning plan time, the learning is determined to be completed. If the total learning time does not reach the preset learning plan time, the learning is determined to be incomplete, and the completion or incompleteness of the learning is recorded; Push simulation data is used to judge learning progress and entertainment plans respectively. The learning progress is judged by the learning mastery status obtained through learning devices such as learning machines and learning tablets. If the learning mastery status reaches the preset learning progress, it is determined that the learning standard is met. If the learning mastery status does not reach the preset learning progress, it is determined that the learning standard is not met. The judgment of learning mastery can be made by weighted quantitative analysis of question accuracy and answering time. The question accuracy is used as the basis and corrected by answering time to obtain learning mastery. The learning mastery is directly proportional to the question accuracy and negatively correlated with the excess answering time. The excess answering time is the amount of time that the answering time exceeds the preset time limit. The entertainment plan is judged by simulating the use of voice, images and the use time of the smart toy to determine whether the child's entertainment time is within the set time range. If the child's entertainment time is within the set time range, the entertainment plan is judged to be normal. If the child's entertainment time is less than the minimum value in the set time range, the child's entertainment plan is judged to be insufficient. If the child's entertainment time is greater than the maximum value in the set time range, the child's entertainment time is judged to be too long. At the same time, when the local data processing module judges the entertainment plan, if there are multiple different smart toys, it simulates the time proportions of multiple different smart toys to obtain the child's interest inclination, and records the child's interest inclination as content push data; The local data processing module records the improper behavior warning, learning completion or incompleteness, learning failure, children's entertainment time determination results, and content push data as application results, and sends the application results to the data application module; After obtaining the application results of learning completion or incomplete learning, learning failure, and children's entertainment time judgment results, the data application module generates a reminder message containing the corresponding application results, sends it to the supervision end through the network, and outputs the application results through the reminder message to realize reminder control; After obtaining the content push data, the data application module sends the push content to learning devices such as learning machines and parent supervision terminals to achieve push control.
[0020] Example 2: See also Figure 1 - Figure 2 As shown, when processing data, the privacy-oriented data security processing system applies the main data supervision, model application, etc. locally through local computing power. When data needs to be obtained from the cloud, a data use request is generated through the cloud, and the data use request is received by the data privacy processing module, and the type and amount of data to be used are extracted. The data privacy processing module performs de-privacy processing on the initial screening data that needs to be uploaded to the cloud, where the de-privacy processing methods include local differential privacy, fuzzy address, etc., to obtain fuzzy data. The data privacy processing module uploads the fuzzy data to the cloud. After uploading to the cloud, the cloud again performs cloud differential privacy processing on a large amount of data within the cloud, and at the same time generates a data lifespan for the fuzzy data uploaded to the cloud, where the data lifespan includes the data retention time and the number of data uses. When the time after the data is uploaded to the cloud reaches the data retention time or the number of times the data is used reaches the generated data use times, the data is formatted; The local differential privacy processing of the data is face differential privacy, which involves automatically identifying faces in image information and adding noise to the identified facial feature vectors to prevent facial information leakage. Differential privacy processing in the cloud adds controllable noise to the data in the cloud database, making the query results of the data insensitive to changes in a single data point.
[0021] Example 3: See also Figure 1 - Figure 2As shown, the data access verification module is used to connect to the data access port, which can be an APP, a web page, etc., and confirm the data access identity through the data access port, wherein the data access identity confirmation includes password verification, login IP verification, device identification code verification, and multi-level comprehensive verification of the number of login blocks. The number of login blocks is the number of incorrect passwords. The data access verification module determines that the identity is normal when the password verification passes and the number of other verification passes is greater than or equal to the set number. If the password verification fails or the number of other verification items passed is less than the set number, it is determined that the identity is abnormal; After determining that the identity is normal, the data access verification module identifies the identity and grants corresponding access rights through preset permissions. After determining that the identity is abnormal, the data access verification module denies access; After the data access verification module determines that the identity is normal, it records the accessed data content and the access identity. After the data access verification module determines that the identity is abnormal, it records the login time and login address corresponding to the denied access identity. The data access verification module integrates the recorded content into an access log data packet, and generates a corresponding hash value from the access log data packet through a hash algorithm. The data access verification module pairs the access log data packet with the corresponding hash value and stores them; When the supervisory end reviews the access log data packet, the data access verification module first generates a verification hash value through the access log data using the same hash algorithm again, and compares the verification hash value with the paired hash value. If the comparison result is identical, the access log data packet is fed back as normal and the access log data packet is displayed. If the comparison result is inconsistent, the access log data packet is fed back as abnormal and an abnormality warning is generated.
[0022] The preferred embodiments of the present invention disclosed above are intended only to help illustrate the present invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the present invention to specific embodiments. Obviously, many modifications and variations are possible based on the contents of this specification. These embodiments are selected and described in detail in this specification to better explain the principles and practical applications of the present invention, thereby enabling those skilled in the art to better understand and utilize the present invention. The present invention is limited only by the claims and their full scope and equivalents.
Claims
1. A data security processing method for privacy protection, characterized in that: The following steps are involved: Step 1: Collect initial data through the terminal device and perform preliminary processing on the collected data to obtain preliminary screening data; Step 2: Classify the initial screening data according to the locally deployed algorithm, and apply the classification results to obtain multiple application results; Step 3: Use the application results to issue corresponding warning reminders and push operations; Step 4: Obtain a data cloud usage request, de-identify the data based on the usage request, and upload it to the cloud. At the same time, generate a data lifecycle. Step 5: Obtain data access request, perform multi-level verification on data access identity, and encrypt and store data access logs.
2. A data security processing system for privacy protection, characterized by: It includes a terminal data acquisition module, a local data processing module, a data privacy processing module, a data access verification module and a data application module. The terminal data acquisition module is used to collect usage data and filter the collected usage data to obtain preliminary screening data; After the local data processing module obtains the preliminary screening data, it classifies the preliminary screening data through the locally deployed model algorithm, applies different types of preliminary screening data after the classification is completed, and obtains corresponding application results based on the application results. The local data processing module sends the application results to the data application module; The data privacy processing module is used to perform privacy removal processing on the primary screening data obtained by the terminal data acquisition module to obtain fuzzy data. The data privacy processing module is also used to control the sending and receiving of data. When data sending and receiving is required, the fuzzy data is uploaded to the cloud; The data access verification module is used to connect to the data access port and confirm the data access identity through the data access port, grant different access rights or deny access according to different data access identities, and encrypt and store the access records; After the data application module obtains the application result, it performs push control and reminder control on the terminal device according to the application result.
3. The data security processing system for privacy protection according to claim 2, characterized in that: The usage data collected by the terminal data collection module includes voice data, image data and device usage data, wherein the device usage data includes the type of device usage and the usage time corresponding to the type. The terminal data collection module filters the collected usage data and records the remaining data as preliminary screening data.
4. The data security processing system for privacy protection according to claim 3, characterized in that: The terminal data collection module determines the obviously invalid data in the following way: The terminal data acquisition module obtains the data type required for local model evaluation through the local data processing module. The data type that can be applied to the local model evaluation is recorded as valid data, while the data that cannot be applied to the local model evaluation is recorded as invalid data.
5. The data security processing system for privacy protection according to claim 2, characterized in that: When the local data processing module classifies the initial screening data, it is divided into behavior recognition data, learning data and push simulation data, among which: behavior recognition data is used to analyze children's behavior, learning data is used to judge the completion of children's learning, and push simulation data is used to judge learning progress and entertainment plans respectively.
6. The data security processing system for privacy protection according to claim 5, characterized in that: When the local data processing module uses the behavior recognition data, it identifies the child's behavior through voice and image, obtains the child's current behavior, and compares it with the preset inappropriate behavior database, generates and records inappropriate behavior warnings based on the comparison results; When the local data processing module uses the learning data, it uses the collected usage time of the learning device as a benchmark and determines whether the user is in a focused state of learning through voice and image. If the user is in a focused state, the learning time is determined to be valid. If the user is not in a focused state, the learning time is corrected according to a set ratio to obtain an equivalent learning time. The valid learning time and the equivalent learning time are summed to obtain the total learning time. The total learning time is compared with the preset learning plan time. Based on the comparison result, it is determined whether the learning is completed or not, and the result is recorded. When the local data processing module uses the pushed simulation data, it performs weighted quantitative analysis based on the collected question accuracy and answering time, takes the question accuracy as the benchmark, and corrects the question accuracy based on the answering time to obtain the learning mastery status, and then compares the learning mastery status with the set learning progress to determine whether the learning standard is met or not; When the local data processing module uses the pushed simulation data, it collects the usage time of the smart toy and compares it with the set time range, and generates a children's entertainment time determination result based on the comparison.
7. The data security processing system for privacy protection according to claim 2, characterized in that: The data privacy processing module can receive data usage requests through the cloud and extract the type and amount of data to be used. The data privacy processing module performs de-privacy processing on the initial screening data that needs to be uploaded to the cloud, and at the same time generates a data lifespan for the fuzzy data uploaded to the cloud, where the data lifespan includes the data retention time and the number of data uses. When the time after the data is uploaded to the cloud reaches the data retention time or the number of times the data is used reaches the generated data usage number, the data is formatted.
8. The data security processing system for privacy protection according to claim 2, characterized in that: The data access verification module performs multi-level confirmation on the data access identity through the data access port, and determines whether the identity is normal or abnormal based on the confirmation result. After determining that the identity is normal, the data access verification module records the accessed data content and the access identity at the same time. After determining that the identity is abnormal, the data access verification module records the login time and login address corresponding to the denied access identity; The data access verification module integrates the recorded content into an access log data packet, and generates a corresponding paired hash value from the access log data packet through a hash algorithm. The data access verification module pairs and stores the access log data packet and the paired hash value.
9. The data security processing system for privacy protection according to claim 2, characterized in that: When the data access verification module checks the access log data packet, the data access verification module generates a verification hash value for the access log data again through the same hash algorithm, and compares the verification hash value with the paired hash value. If the comparison result is overlap, the access log data packet is fed back as normal and the access log data packet is displayed. If the comparison result is not overlap, the access log data packet is fed back as abnormal and an abnormality warning is generated.