Data processing method, storage medium, electronic device and program product

By converting legal and regulatory texts into executable code policies, identifying and processing sensitive data, and combining compliance verification, the problem of dynamic compliance in data processing in the field of embodied intelligence is solved, ensuring data security, compliance, and integrity.

CN120804736APending Publication Date: 2025-10-17SHANGHAI MIFENG EMBODIED INTELLIGENT TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511075066.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

The current business processes in the field of embodied intelligence cannot meet the dynamic security and compliance requirements in the closed loop of data processing, resulting in potential security risks for data during circulation and difficulty in adapting to ever-changing security and compliance standards, which in turn leads to security issues such as data leakage and abuse.

Method used

By converting data-related legal and regulatory texts into executable code policies, identifying sensitive data, matching appropriate processing policies based on sensitive data, and performing compliance verification after executing the processing policies, a closed-loop mechanism is formed to ensure the compliance of data processing.

Benefits of technology

It achieves dynamic compliance in the data processing process, reduces the risk of data leakage and abuse, ensures that data complies with regulatory requirements throughout its life cycle, and improves data security and compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120804736A_ABST
    Figure CN120804736A_ABST
Patent Text Reader

Abstract

The invention provides a data processing method, a storage medium, electronic equipment and a program product, and relates to the technical field of data compliance. The data processing method comprises the steps that an executable code strategy is obtained, wherein the executable code strategy represents a strategy in a code form obtained after law and regulation texts related to data are converted; identifying sensitive data in the target data based on an executable code strategy; based on the sensitive data, determining a first target processing strategy matched with the sensitive data; and executing the first target processing strategy on the sensitive data, and performing compliance verification on the target data after executing the first target processing strategy.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data compliance, and particularly relates to a data processing method, a storage medium, an electronic device and a program product. BACKGROUND

[0002] The current business process in the field of embodied intelligence cannot meet the dynamic security compliance requirements in the data processing closed loop, so that the data faces potential security risks in the whole circulation process, and it is difficult to adapt to the changing security compliance standards, thereby leading to security problems such as data leakage and misuse.

[0003] Therefore, it is necessary to optimize and improve the existing business process, and establish a sound data security compliance mechanism to protect the security and compliance use of data. SUMMARY

[0004] Therefore, the embodiments of the present application provide a data processing method, a storage medium, an electronic device and a program product.

[0005] In a first aspect, an embodiment of the present application provides a data processing method, comprising: obtaining an executable code policy, the executable code policy representing a policy in code form obtained by converting a legal and regulatory text related to data; identifying sensitive data in target data based on the executable code policy; determining a first target processing policy matched with the sensitive data based on the sensitive data; executing the first target processing policy on the sensitive data, and performing compliance verification on the target data after executing the first target processing policy.

[0006] In combination with the first aspect, in some implementation manners of the first aspect, determining the first target processing policy matched with the sensitive data based on the sensitive data comprises: if the sensitive data is structured data, determining the first target processing policy matched with the sensitive data based on a sensitive level corresponding to a sensitive field in the structured data; if the sensitive data is unstructured data in an image format, determining the first target processing policy matched with the sensitive data based on a sensitive level corresponding to a sensitive area in the image; if the sensitive data is unstructured data in a text format, determining the first target processing policy matched with the sensitive data based on a sensitive level corresponding to a sensitive event in the text.

[0007] In combination with the first aspect, in some implementation manners of the first aspect, if the sensitive level is a first sensitive level, the first target processing policy matched with the sensitive data is determined as complete retention; if the sensitive level is a second sensitive level, the first target processing policy matched with the sensitive data is determined as partial masking; if the sensitive level is a third sensitive level, the first target processing policy matched with the sensitive data is determined as encrypted storage; and if the sensitive level is a fourth sensitive level, the first target processing policy matched with the sensitive data is determined as rejection storage.

[0008] With reference to the first aspect, in some implementations of the first aspect, before obtaining the executable code policy, the method further includes at least one of the following: hot updating the executable code policy; adding the executable code policy to a data processing link, the data processing link being a data processing link corresponding to a lifecycle of the target data; and inserting a target code segment at a specified operation node of the data processing link, the target code segment being configured to execute a second target processing policy matching a data category of the target data and / or a specified parameter in the target data.

[0009] With reference to the first aspect, in some implementations of the first aspect, the compliance verification of the target data after execution of the first target processing policy includes: performing a static rule check on the target data after execution of the first target processing policy before the target data after execution of the first target processing policy is written to storage, so as to verify whether the target data after execution of the first target processing policy is compliant; and / or calculating a compliance risk index of the target data after execution of the first target processing policy based on a data bloodline graph after the target data after execution of the first target processing policy is written to storage, so as to verify whether the target data after execution of the first target processing policy is compliant based on the compliance risk index.

[0010] With reference to the first aspect, in some implementations of the first aspect, after the compliance verification of the target data after execution of the first target processing policy, the method further includes: if there is non-compliant data in the target data after execution of the first target processing policy, determining a violation level corresponding to the non-compliant data; if the violation level corresponding to the non-compliant data is a first violation level, correcting a storage location of the non-compliant data; if the violation level corresponding to the non-compliant data is a second violation level, performing desensitization correction on sensitive data in the non-compliant data; and if the violation level corresponding to the non-compliant data is a third violation level, freezing access permissions of the non-compliant data; wherein the first violation level is less than the second violation level, and the second violation level is less than the third violation level.

[0011] With reference to the first aspect, in some implementations of the first aspect, the target data after the compliance verification includes data for model training, and after the compliance verification of the target data after execution of the first target processing policy, the method further includes: restricting a usage scenario of the data for model training based on an access control policy; injecting a traceable feature into the data for model training, and detecting a matching degree between the feature and the traceable feature in model output data in a model inference stage to determine a data leakage risk; and / or isolating learning parameters of the model through a trusted execution environment, and recording gradient exchange operations of the model.

[0012] In some implementations of the first aspect, before obtaining the executable code policy, the method further includes: extracting compliance elements in the data-related legal regulation text, the compliance elements including data categories and target processing policies matched with the data categories; and converting the compliance elements into the executable code policy.

[0013] In some implementations of the first aspect, the method further includes: writing at least one of process data of identifying the sensitive data, process data of executing the first target processing policy, process data of the compliance verification, and data of repair operations on the existing non-compliant data into the blockchain network for audit and evidence storage.

[0014] In some implementations of the first aspect, the blockchain network includes a core layer and an acceleration layer, the core layer adopts an improved MPT tree structure, and the acceleration layer is an evidence generation engine. The audit and evidence storage of at least one of the process data of identifying the sensitive data, the process data of executing the first target processing policy, the process data of the compliance verification, and the data of the repair operations on the existing non-compliant data into the blockchain network includes: performing the audit and evidence storage of at least one of the process data of identifying the sensitive data, the process data of executing the first target processing policy, the process data of the compliance verification, and the data of the repair operations on the existing non-compliant data through the core layer to obtain audit records; and exporting the audit records in the core layer to a readable report through the acceleration layer.

[0015] In a second aspect, an embodiment of the present application provides a data processing system, including: a dynamic compliance rule engine configured to obtain an executable code policy, the executable code policy representing a code-form policy obtained by converting a data-related legal regulation text; a sensitive information identification engine configured to identify sensitive data in target data based on the executable code policy; a policy determination module configured to determine a first target processing policy matched with the sensitive data based on the sensitive data; and a compliance self-checking module configured to execute the first target processing policy on the sensitive data and perform compliance verification on the target data after the execution of the first target processing policy.

[0016] In a third aspect, an embodiment of the present application provides a computer readable storage medium storing a computer program for executing the data processing method of the first aspect.

[0017] In a fourth aspect, an embodiment of the present application provides an electronic device, including: a processor; a memory for storing processor-executable instructions; and the processor configured to execute the data processing method of the first aspect.

[0018] In a fifth aspect, an embodiment of the present application provides a computer program product, which comprises instructions for causing an electronic device to implement the data processing method of the first aspect when the instructions are executed on the electronic device.

[0019] In the present application, the legal and regulatory texts related to data are converted into executable code policies, and the regulatory requirements are integrated into the data processing flow to control risks from the source and avoid data leakage and misuse. Then, based on the executable code policy, sensitive data is accurately identified to improve the pertinence and efficiency and reduce the risks caused by omissions. At the same time, according to the matching of the sensitive data, appropriate processing strategies are matched to flexibly cope with different data types and scenarios, adapt to regulatory changes, and ensure that the processing strategies keep pace with the times. Finally, through compliance verification to form a closed loop, deviations are found and adjusted in time to ensure that the processing results meet the regulatory requirements and reduce compliance risks. It can be seen that the present scheme effectively solves the problem that data processing in the existing business process is difficult to dynamically comply with regulations, guarantees data security and compliance, and promotes the healthy development of data. BRIEF DESCRIPTION OF DRAWINGS

[0020] The above and other objects, features and advantages of the present application will become more apparent from the following detailed description of embodiments of the present application, taken in conjunction with the accompanying drawings. The drawings provided in the present application are used to provide a further understanding of the embodiments of the present application, and constitute a part of the specification, and are used to explain the present application together with the embodiments of the present application, and do not constitute a limitation of the present application. In the drawings, the same reference numerals generally represent the same components or steps.

[0021] Figure 1 Fig. 1 shows a flowchart of a data processing method provided by an embodiment of the present application.

[0022] Figure 2 Fig. 2 shows a flowchart of determining an executable code policy provided by an embodiment of the present application.

[0023] Figure 3 Fig. 3 shows a flowchart of determining a first target processing strategy matched with sensitive data provided by an embodiment of the present application.

[0024] Figure 4 Fig. 4 shows a flowchart of compliance verification on target data after executing the first target processing strategy provided by an embodiment of the present application.

[0025] Figure 5 Fig. 5 shows a flowchart of a data processing method provided by another embodiment of the present application.

[0026] Figure 6 Fig. 6 shows a flowchart of a data processing method provided by still another embodiment of the present application.

[0027] Figure 7Fig. 1 shows an architecture diagram of a data processing flow according to an embodiment of the present application.

[0028] Figure 8 Fig. 2 shows a structural schematic diagram of a data processing system according to an embodiment of the present application.

[0029] Figure 9 Fig. 3 shows a structural schematic diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0030] The technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative labor fall within the scope of protection of the present application.

[0031] In the field of embodied intelligence, the life cycle of data covers multiple key nodes, including end-side collection, storage, post-processing, cross-cluster synchronization, model training, and archiving. However, there are many security compliance risks in the entire link. For example, in the end-side collection stage, due to the lack of real-time desensitization, original sensitive data (such as device operating parameters, operation logs, etc.) may be directly uploaded to the cloud; the storage object storage adopts a unified encryption strategy, without implementing differentiated protection, and there is a risk of intermediate state data leakage during cross-cluster synchronization, for example, the transmission link is not encrypted; in the post-processing process, data cleaning and labeling may expose personal identity information, and there is a lack of automatic adaptation to regulatory texts; in terms of training data management, fine-grained permission control is not implemented when downloading training data from a jump machine, and the data leakage path after model training cannot be tracked.

[0032] Based on the above, the present application is provided. Specifically, Figure 1 Fig. 1 shows a flowchart of a data processing method according to an embodiment of the present application. As shown in Figure 1 The method includes the following steps.

[0033] In step S110, an executable code policy is obtained.

[0034] Specifically, the executable code policy represents a policy in the form of code obtained after converting a legal and regulatory text related to data. For example, the legal and regulatory text related to data includes the Industrial Data Classification and Grading Guide, which stipulates the principles, requirements, and restrictions that data processing activities should follow in different situations.

[0035] That is, the executable code policy is to convert the provisions, requirements, etc. in the legal and regulatory texts related to data into a code form that the computer can understand and execute. It clearly shows how to ensure that the data processing process meets the requirements of the regulations through technical means, including the operation specifications and limitation conditions of each link of data storage, access, processing, transmission, etc.

[0036] It can be understood that directly performing data processing operations according to the legal and regulatory texts related to data is often not intuitive and specific, so it is necessary to convert it into an executable code policy, so that the subsequent data processing program can operate according to these rules, thereby ensuring the legality and compliance of data processing.

[0037] Step S120, based on the executable code policy, identifying sensitive data in the target data.

[0038] Target data refers to a set of data that needs to be analyzed and processed in a specific data processing scenario. Further, in the target data, the data that meets the sensitive features or conditions defined in the executable code policy is the target data, which usually has high privacy, confidentiality or security requirements.

[0039] Optionally, the executable code policy contains features, patterns or conditions of sensitive data, so the target data is compared and matched with these standards in the executable code policy one by one to determine which data meets the definition of sensitive data and accurately identify it from the target data.

[0040] Step S130, based on the sensitive data, determining a first target processing strategy matching the sensitive data.

[0041] The first target processing strategy is a general term for specific processing methods and operation schemes formulated for sensitive data to meet the purpose of protecting data security and privacy. It can be understood that different target processing strategies correspond to different processing means, such as desensitization, encryption, anonymization, etc.

[0042] For example, for some sensitive data with high privacy requirements but also need to retain part of the data features in the business process, desensitization strategy is selected; and for sensitive data with extremely high confidentiality requirements, encryption strategy is selected, so as to accurately match the processing strategy that can best protect data security and meet compliance requirements according to the specific circumstances of sensitive data.

[0043] Step S140, executing the first target processing strategy on the sensitive data, and performing compliance verification on the target data after executing the first target processing strategy.

[0044] Compliance verification is the process of inspecting and verifying processed data to ensure that the results comply with laws, regulations, industry standards, and internal data processing requirements. Compliance verification can also include checking the accuracy, completeness, consistency, and security of the data to confirm that the data processing process meets the predetermined compliance objectives.

[0045] It is understandable that the target data after executing the first target processing strategy may not meet the compliance requirements due to various factors (such as errors in the processing process, the specificity of the data itself, etc.). Therefore, compliance verification is required to confirm whether the processed data has truly achieved the expected compliance goals and ensure the legality and security of the data processing. In some embodiments, if the verification fails, it is necessary to readjust the processing strategy and execute and verify it again until the processed data passes the compliance verification.

[0046] In this embodiment, the text of data-related laws and regulations is converted into executable code policies, so that regulatory requirements are integrated into the data processing process, risks are controlled at the source, and data leakage and abuse are avoided. Then, sensitive data is accurately identified based on the executable code policy, which improves targeting and efficiency and reduces risks caused by omissions. At the same time, appropriate processing strategies are matched according to sensitive data to flexibly respond to different data types and scenarios, adapt to changes in regulations, and ensure that processing strategies keep pace with the times. Finally, a closed loop is formed through compliance verification, deviations are discovered and adjusted in a timely manner, and the processing results are guaranteed to meet regulatory requirements and reduce compliance risks. It can be seen that this solution effectively solves the problem of dynamic compliance of data processing in existing business processes, ensures data security and compliance, and promotes the healthy development of data.

[0047] Figure 2 The figure shows a flow chart of determining an executable code strategy provided by an embodiment of the present application. Figure 1 Based on the embodiment shown, Figure 2 The embodiment shown is described below in detail. Figure 2 The embodiment shown is Figure 1 The differences and similarities between the illustrated embodiments are not described in detail.

[0048] like Figure 2 As shown, in this embodiment, before obtaining the executable code policy, the following steps are also included.

[0049] Step S210: extracting compliance elements from legal and regulatory texts related to the data.

[0050] The compliance element is a key information unit extracted from the data-related legal regulation text, which can reflect the compliance requirements of the regulation. The elements include data categories and target processing strategies matched with the data categories, etc. The data category is the classification of different types of data, such as personal identity information, process data, research and development data, etc. The target processing strategy is the processing method specified for these data categories, such as encryption, desensitization, anonymization, etc., to ensure that the data processing complies with the regulations.

[0051] For example, the data-related legal regulation text is: core research and development data needs to be physically isolated and stored. The structure of the output compliance element is: {action: "isolated storage", object: "core research and development data", method: "physical isolation", condition: ""}.

[0052] In an implementation, a BiLSTM+CRF model is used to analyze the data-related legal regulation text and automatically extract key compliance elements.

[0053] In step S220, the compliance element is converted into an executable code policy.

[0054] Optionally, a rule-code converter is used to convert the compliance element into an executable code policy.

[0055] For example, for the example in step S210, the corresponding executable code policy is:

[0056] public class GD_4_2_1 implements ComplianceRule {

[0057] void execute(DataPacket packet) {

[0058] if (packet.getLabel().equals("core research and development data")) {

[0059] packet.setStoragePolicy(StoragePolicy.PHYSICAL_ISOLATION);

[0060] }

[0061] }

[0062] }

[0063] In this embodiment, by extracting compliance elements in the legal and regulatory texts related to data, the data categories and corresponding processing strategies are clearly defined, providing precise compliance basis for data processing, establishing the connection between regulatory requirements and data processing lines, and avoiding compliance omissions and misunderstandings. On this basis, further converting compliance elements into executable code strategies enhances the compliance and efficiency of data processing, effectively reducing compliance risks.

[0064] In some embodiments, after converting the compliance elements into executable code strategies, it further includes: hot updating the executable code strategies; or adding the executable code strategies to the data processing link; or inserting the target code segment at the specified operation node of the data processing link.

[0065] Specifically, hot updating the executable code strategies means monitoring regulations in real time, and once new regulations are detected, automatically triggering version upgrade of the executable code strategy library, and gradually updating the previous executable code strategies in a gray release manner. This way can quickly adapt the data processing strategy to the new regulatory requirements without affecting the normal operation of existing business, ensuring that the compliance of data processing always remains up-to-date.

[0066] The data processing link refers to the data processing link corresponding to the life cycle of the target data. By adding the executable code strategies to the data processing link, the code strategies for data compliance processing can be embedded into each link of data processing. This greatly improves the efficiency of data processing, reduces the cumbersome steps and potential risks of manual intervention. At the same time, it ensures the compliance of data processing, making data comply with regulatory requirements at every link in the entire life cycle, enhancing the security of data processing.

[0067] In this embodiment, the target code segment is used to execute a second target processing strategy that matches the data category of the target data and / or the specified parameter in the target data. The specified parameter refers to a parameter in the target data that has a specific meaning or purpose, which can be part of the data or an attribute or feature related to the data, helping to further refine and determine the specific way of data processing. Exemplarily, the specified operation node includes data storage, cleaning, etc.

[0068] In one implementation, through the compliance checkpoint forced injection technology, the corresponding code segment is inserted at the key link of data processing to realize automatic compliance control of data processing. For example, for "core research and development data", the physical isolation storage strategy is forcibly executed through the target code segment without manual intervention. This way ensures the compliance of data processing, improves efficiency, reduces errors and omissions caused by manual configuration, and makes data processing more reliable and secure.

[0069] Figure 3 The figure shows a flow chart of determining a first target processing strategy that matches sensitive data provided by an embodiment of the present application. Figure 1 Based on the embodiment shown, Figure 3 The embodiment shown is described below in detail. Figure 3 The embodiment shown and Figure 1 The differences and similarities between the illustrated embodiments are not described in detail.

[0070] like Figure 3 As shown, in this embodiment, based on the sensitive data, determining a first target processing strategy that matches the sensitive data includes the following steps.

[0071] Step S310: If the sensitive data is structured data, a first target processing strategy matching the sensitive data is determined based on the sensitivity level corresponding to the sensitive field in the structured data.

[0072] Structured data refers to data with a fixed format and clear structure. For example, regular expression libraries can be used to match structured data such as ID numbers and employee numbers. Furthermore, structured data also includes specific fields that store sensitive information. For example, the middle digits of an ID number are sensitive fields.

[0073] Sensitivity levels are a classification of the sensitivity of sensitive fields in structured data, used to indicate the importance of the data and the protection requirements. Sensitivity levels are typically categorized from low to high, such as L1, L2, L3, and L4. Higher levels indicate more sensitive data and require stricter protection measures.

[0074] Specifically, the first target processing strategy includes at least one of full retention, partial masking, encrypted storage, and storage rejection.

[0075] Full preservation means that sensitive data is not modified or altered in any way, and is stored or transmitted in its original, unencrypted, and unmasked form. Partial masking hides or replaces a portion of sensitive data, so that when displayed or transmitted, only part of the content is exposed, while the rest is masked. Encrypted storage encrypts sensitive data using a specific encryption algorithm, converting the data into ciphertext for storage. Only those with the correct key or decryption algorithm can restore the ciphertext to the original data. Denial of storage refers to directly refusing to store certain highly sensitive data in the system, or refusing to store data from specific sources or with specific characteristics.

[0076] Exemplarily, if the sensitive field is L1, the first target processing strategy is complete reservation; if the sensitive field is L2, the first target processing strategy is partial masking; if the sensitive field is L3, the first target processing strategy is encrypted storage; and if the sensitive field is a fourth sensitive level L4, the first target processing strategy is storage rejection.

[0077] In step S320, if the sensitive data is image format unstructured data, a first target processing strategy matching the sensitive data is determined based on a sensitive level corresponding to a sensitive region in the image.

[0078] The image format unstructured data refers to data in the form of an image, without a fixed format or structure, such as photos, pictures, scans, etc. It can be understood that the region with specific sensitive information in the image includes a face, a fingerprint, a private space, etc. when a robot with a specific body collects image data.

[0079] In some embodiments, a modified YOLOv5s model is used to detect the sensitive region in the image data.

[0080] Similarly, if the sensitive region is L1, the first target processing strategy is complete reservation; if the sensitive region is L2, the first target processing strategy is partial masking; if the sensitive region is L3, the first target processing strategy is encrypted storage; and if the sensitive region is L4, the first target processing strategy is storage rejection.

[0081] In step S330, if the sensitive data is unstructured data, a first target processing strategy matching the sensitive data is determined based on a sensitive level corresponding to a sensitive event in the text.

[0082] The text format unstructured data refers to data in the form of natural language text, without a fixed format or structure, such as emails, documents, instant messages, etc. The sensitive event is a specific situation or information described or related in the text. For example, a private conversation between users collected by a robot in a home environment, which contains information such as a home address, personal contact information, and a user's health condition.

[0083] In an implementation manner, a RoBERTa fine-tuning model is used to identify the sensitive event in the text.

[0084] Similarly, if the sensitive event is L1, the first target processing strategy is complete reservation; if the sensitive event is L2, the first target processing strategy is partial masking; if the sensitive event is L3, the first target processing strategy is encrypted storage; and if the sensitive event is L4, the first target processing strategy is storage rejection.

[0085] In some embodiments, the corresponding target processing strategy is automatically determined based on the executable code strategy corresponding to the legal and regulatory text related to the data. For example, the executable code strategy is:

[0086]

[0087] Specifically, if the data category is "process parameters" and the sensitivity level is L2, a partial masking (desensitization) method is applied to the data, specifically retaining the first 3 digits and the last 2 digits of the data and masking the middle part. If the data category is "user behavior log", the SM4 encryption algorithm is applied to the data, and the encryption key is dynamically generated through the device motion hash.

[0088] In some embodiments, after data compliance is verified, differentiated encryption storage is also implemented for data of different sensitivity levels. For example, L1 data is encrypted with AES-128 and stored in a private cloud; L3 data is encrypted with AES-256 and Shamir secret sharing, with sharded storage distributed across three physically isolated clusters.

[0089] Furthermore, after data is stored but before it is transmitted, the intermediate data is double-encapsulated and encrypted (such as inner SM4 algorithm + outer private protocol encapsulation), and a temporary session key is generated based on a physically unclonable function to effectively defend against man-in-the-middle attacks.

[0090] This embodiment precisely matches the corresponding first-target processing strategy (full retention, partial masking, encrypted storage, or storage denial) based on the different data types (structured, image, text) and the sensitivity levels of sensitive fields, sensitive areas, and sensitive events, achieving refined management of data processing. This targeted processing improves the flexibility and effectiveness of data protection and meets diverse compliance requirements.

[0091] Figure 4 The figure shows a flow chart of a process for verifying the compliance of target data after executing the first target processing strategy provided by an embodiment of the present application. Figure 1 Based on the embodiment shown, Figure 4 The embodiment shown is described below in detail. Figure 4 The embodiment shown and Figure 1 The differences and similarities between the illustrated embodiments are not described in detail.

[0092] like Figure 4 As shown, in this embodiment, compliance verification is performed on target data after executing the first target processing strategy, including the following steps.

[0093] Step S410, before the target data after executing the first target processing strategy is written into the storage, performing static rule check on the target data after executing the first target processing strategy.

[0094] The static rule check refers to checking according to the preset fixed rules before the data is written into the storage, so as to verify whether the target data after executing the first target processing strategy is compliant.

[0095] Exemplarily, the execution code of the static rule check is as follows:

[0096]

[0097]

[0098] Specifically, if the classification of the target data is "core process" and its storage strategy is not physical isolation, an error is returned, prompting that the GD421 clause is violated. If the target data contains personal identity information but has not been desensitized, an error is returned, prompting that the personal identity information is not desensitized. If neither of the above two cases exists, the function returns nil, indicating that the target data meets the compliance requirements and no error is found.

[0099] Step S420, after the target data after executing the first target processing strategy is written into the storage, calculating the compliance risk index of the target data after executing the first target processing strategy based on the data bloodline graph.

[0100] The data bloodline graph is a kind of visualization tool describing the data source, flow path and processing process, which records the detailed information of the data from generation to storage, processing, transmission and other links, including the source system of the data, generation time, processing steps, associated data, etc., which can help understand the whole life cycle of the data and the relationship between the links.

[0101] The compliance risk index is used to evaluate the gap between the data processing process or result and the compliance requirements. It can be understood that the higher the index, the greater the compliance risk of data processing. Alternatively, it can be calculated according to multiple factors, such as the sensitivity level of the target data, the access frequency and the latest audit result, etc.

[0102] In an implementation mode, the detailed information of the data flow and processing process recorded by the data bloodline graph is utilized, combined with the preset compliance risk assessment model, to calculate the compliance risk index. If the index is within the set compliance threshold range, it can be considered that the target data basically meets the compliance requirements; otherwise, if the index exceeds the compliance threshold, it indicates that the target data has compliance risk and needs to be further investigated and processed.

[0103] For example, according to the data lineage record, the target data has undergone a series of processing procedures from the original collection system, including data cleaning, conversion, storage, etc., and has been accessed 1000 times in the past month. The latest audit result shows that there is a slight non-compliance item in the data processing process (such as incomplete access log record of part of the data), and the sensitivity level is L3.

[0104] According to the preset compliance risk index calculation formula: compliance risk index = 0.4 x sensitivity level + 0.3 x access frequency + 0.3 x latest audit result.

[0105] Substitute the formula to calculate: compliance risk index = 0.4 x 3 + 0.3 x 0.8 + 0.3 x 0.5 = 1.2 + 0.24 + 0.15 = 1.59.

[0106] If the corresponding compliance risk threshold is 1.5, the calculated compliance risk index 1.59 exceeds the threshold, indicating that the target data has compliance risks, and further review and rectification of the related data processing process is needed to ensure the compliance of data processing.

[0107] In this embodiment, before writing to storage, the target data is forcibly checked by static rule checking to ensure that it meets the regulatory requirements, such as enforcing physical isolation storage strategy for core process data to timely discover and correct illegal storage behavior. After writing to storage, the compliance risk index is calculated based on the data lineage graph, considering factors such as sensitivity level, access frequency and audit result, to quantitatively evaluate the compliance of the target data. This scheme forms a double compliance verification mechanism, effectively improving the data security and compliance guarantee level, and reducing the risk of data leakage and illegal operation.

[0108] Figure 5 The flowchart of the data processing method provided by another embodiment of the application is shown. In Figure 1 The embodiment shown extends Figure 5 The embodiment shown, the differences between Figure 5 The embodiment shown and Figure 1 The differences between the embodiments are not repeated.

[0109] As Figure 5 shown, in this embodiment, after the target data after executing the first target processing strategy is verified for compliance, the following steps are further included.

[0110] Step S510, if there is non-compliant data in the target data after executing the first target processing strategy, determine the violation level corresponding to the non-compliant data.

[0111] The non-compliant data refers to data that does not meet the requirements of relevant laws and regulations, industry standards or enterprise internal regulations. For example, data generated under the condition of not being properly desensitized, not meeting the security level requirements of the storage location, unauthorized access, etc.

[0112] Optionally, according to the nature, influence range, potential risk and other factors of the non-compliant data, the violation degree is classified by level. It can be understood that different violation levels correspond to different severity of violation and corresponding processing measures.

[0113] Step S520, if the violation level corresponding to the non-compliant data is the first violation level, the storage location of the non-compliant data is corrected.

[0114] Specifically, if the violation level of the non-compliant data is the first violation level, the non-compliant data originally stored in the position not meeting the security level requirements is migrated to the designated storage area meeting the security level requirements of the non-compliant data, to ensure the compliance and security of data storage.

[0115] Step S530, if the violation level corresponding to the non-compliant data is the second violation level, the sensitive data in the non-compliant data is desensitized and corrected.

[0116] Specifically, if the violation level of the non-compliant data is the second violation level, some technical means and algorithms are used to desensitize the sensitive information contained in the non-compliant data, so as to reduce the sensitivity and leakage risk of the sensitive data while ensuring a certain information availability, thereby meeting the compliance requirements.

[0117] Step S540, if the violation level corresponding to the non-compliant data is the third violation level, the access permission of the non-compliant data is frozen.

[0118] Specifically, if the violation level of the non-compliant data is the third violation level, the restriction measures are taken to prevent the non-compliant data from being further accessed, used or spread, so that only under certain conditions or after special authorization can the data be accessed, thereby effectively controlling the risk and avoiding potential data leakage or illegal use and other adverse consequences.

[0119] Further, the first violation level is less than the second violation level, and the second violation level is less than the third violation level. As can be seen, the first violation level corresponds to a violation behavior that has less impact on data security and compliance, such as a non-compliant storage location. Such problems mainly violate the requirements of data classification and hierarchical storage, but the content and sensitivity of the data itself may not be harmful, and only the security level of the storage location does not meet the requirements, which poses a certain potential risk. Therefore, correcting the storage location is a direct and effective way to quickly meet the compliance requirements. By migrating the data to a storage area that meets its security level, the risk of unauthorized access or leakage of data can be effectively reduced, and the integrity and availability of the data can be ensured.

[0120] The second violation level has a higher violation level than the first violation level, involving sensitivity issues of the data content itself, such as not desensitizing sensitive data. Therefore, desensitizing sensitive data can minimize the sensitivity of the data while ensuring data availability.

[0121] The third violation level is the most serious violation level, and the data may have significant risks such as tampering, leakage, or unauthorized widespread dissemination. Therefore, freezing access rights is a powerful control measure that can stop the further spread and use of data in the shortest possible time and control the risk to the smallest extent. At the same time, it can also avoid the negative impact of non-compliant data on the normal operation of other systems.

[0122] In some embodiments, at least one of the process data for identifying sensitive data, the process data for executing the first target processing strategy, the process data for compliance verification, and the repair operation data for existing non-compliant data is written to the blockchain network for audit evidence.

[0123] The process data for identifying sensitive data and the process data for executing the first target processing strategy refer to Figure 1 In the embodiment shown, based on the executable code policy, the process data for identifying sensitive data in the target data, and Figure 1 The process data for executing the first target processing strategy on the sensitive data in the embodiment shown. The repair operation data for existing non-compliant data refers to Figure 5 The process data for processing non-compliant data of different violation levels in the embodiment shown.

[0124] The process data for compliance verification includes but is not limited to verification time, verification results (such as whether it is compliant or not, specific violation points, etc.), data object identifiers involved, verification rules executed, and other information.

[0125] The blockchain network is a distributed database network maintained by multiple nodes, with characteristics such as decentralization, non-tamperability, data transparency and traceability.

[0126] In this embodiment, the blockchain network serves as a reliable, secure and tamper-proof storage and sharing platform for storing these process data, to ensure the authenticity and integrity of these data. At the same time, through the audit evidence of the blockchain network, the credibility and traceability of the data can be enhanced, the audit process can be simplified, the audit efficiency can be improved, and the data can be effectively prevented from being tampered with or forged.

[0127] Further, the blockchain network includes a core layer and an acceleration layer, the core layer adopts an improved MPT tree structure, and the acceleration layer is an evidence generation engine; at least one of the process data for identifying sensitive data, the process data for executing the first target processing strategy, the process data for compliance verification, and the repair operation data for the existing non-compliant data is written into the blockchain network for audit evidence, including: performing audit evidence of at least one of the process data for identifying sensitive data, the process data for executing the first target processing strategy, the process data for compliance verification, and the repair operation data for the existing non-compliant data through the core layer, to obtain an audit record; the audit record in the core layer is exported to a readable report through the acceleration layer.

[0128] In this embodiment, the core layer is the basic part of the blockchain network, mainly responsible for data storage and tamper-proofing. It adopts an improved MPT (Merkle Patricia Trie, optimized hash tree level) tree structure, so that data can be efficiently and securely stored, and the consistency and integrity of the data are guaranteed, not only improving the data storage efficiency and query speed, but also enhancing the protection ability of the data.

[0129] The acceleration layer is built on the core layer and focuses on improving the speed of data processing and report generation. As an evidence generation engine, it can quickly extract the audit records in the core layer and convert them into a readable report format, greatly improving the efficiency and convenience of audit work, meeting the demand for fast response and accurate audit report in actual business.

[0130] Specifically, after the identification of sensitive data, the execution of the first target processing strategy, the compliance verification, and the repair of non-compliant data, these process data are written into the core layer of the blockchain network. Moreover, each audit record is added to the blockchain as a new data block, and is connected to the previous data block through an encryption hash algorithm, forming a tamper-proof chain structure, thereby ensuring the authenticity and integrity of the audit records.

[0131] On this basis, the acceleration layer can efficiently extract audit records and convert them into common report formats (such as PDF or Excel) so that auditors, regulatory authorities, and others can easily view and use these data. This design not only improves the efficiency of audit work, but also makes the audit results more intuitive and easy to understand, facilitating decision-making and action by relevant personnel.

[0132] Figure 6 The flowchart of the data processing method provided by another embodiment of the application is shown. Figure 1 The embodiment shown extends to Figure 6 The embodiment shown, the following focuses on the description Figure 6 The embodiment shown and Figure 1 The differences between the embodiments shown, the same place will not be repeated.

[0133] As Figure 6 shown, the target data after compliance verification includes data for model training, and after compliance verification of the target data after executing the first target processing strategy, the following steps are included.

[0134] Step S610, based on the access control policy, restricts the use scenarios of the data for model training.

[0135] Optionally, the access control policy specifies which subjects can perform which operations (e.g., read-only, read-write, execute, etc.) on the data for model training under what conditions, thereby ensuring that the use of model training data complies with security and compliance requirements. Illustratively, the access control policy includes granting a specific user role (algorithm engineer) download permissions for dataset_23 within a specified time (9:00-18:00) and a specific IP range (192.168.1.0 / 24), and requiring multi-factor authentication to achieve the restriction of the use scenario of the data for model training.

[0136] In this step, only authorized users or applications can use these model training data under specific circumstances and conditions, such as training only on designated training servers and accessing only within specified time periods, ensuring that the use of model training data complies with the enterprise's security policies and regulatory requirements, preventing misuse or leakage of data.

[0137] Step S620, inject traceable features into the data for model training, and detect the matching degree of the features in the model output data and the traceable features in the model inference stage.

[0138] The traceable feature is a feature identification with uniqueness and recognizability, such as a watermark, added or generated in the data for model training, which can be detected and recognized for tracing the flow and use of the data.

[0139] In this step, traceable features are injected into the data for model training for further protection of the data and timely discovery of potential data leakage risks. In the model inference stage, when the model uses the trained data to make predictions or decisions, it detects whether the traceable features are contained in the model output data and calculates the matching degree of the features. If the matching degree exceeds a certain threshold, it indicates that there may be a data leakage risk, that is, the sensitive information in the training data is exposed in the model output data, and at this time, a leakage alarm is triggered to take corresponding measures for prevention and response.

[0140] In step S630, the learning parameters of the model are isolated by the trusted execution environment, and the gradient exchange operation of the model is recorded.

[0141] The trusted execution environment refers to an isolated and secure computing environment. In this environment, code and data can be protected during execution to prevent being stolen or tampered with by external malicious programs or unauthorized users. It provides a secure running space for the learning parameters of the model, ensuring the confidentiality and integrity of the parameters during training and updating. Illustratively, the learning parameters of the model are isolated by the trusted execution environment of the TEE+SGX technology, and all gradient exchange operations of the model are recorded to the audit chain.

[0142] In this embodiment, the use scenarios of the data for model training are constrained based on the access control policy, which can accurately limit the data access authority and ensure that the data is only used by authorized personnel at a specified time and on a specified device, thereby effectively preventing data abuse or leakage and enhancing the controllability and compliance of data use. Then, traceable features are injected into the data for model training, and the feature matching degree is detected in the inference stage to provide early warning for data leakage, thereby improving the security and traceability of the data for model training. Finally, the learning parameters of the model are isolated by the trusted execution environment to prevent the parameters from being stolen or tampered with, ensuring the confidentiality and integrity of the model training process, and recording the gradient exchange operation provides detailed audit records for the model training process, facilitating problem tracing and responsibility definition, thereby further improving the reliability and security of the model training.

[0143] Figure 7 An architecture diagram of a data processing flow provided by an embodiment of the application is shown. As shown in FIG. 1, the data processing flow includes the following steps. Figure 7As shown, first, the compliance policy management center will issue an executable code policy to the multi-modal PII recognition engine (multi-modal personal identity information recognition engine) and the compliance self-check algorithm. Then, in the entire data processing link, after the raw data is collected, it is input into the multi-modal PII recognition engine. The multi-modal PII recognition engine identifies sensitive data in the raw data according to the executable code policy, and performs a first target processing policy on the sensitive data. Then, the data after executing the first target processing policy is input into the compliance self-check algorithm, and the compliance self-check algorithm performs compliance detection on the data according to the executable code policy to obtain compliant data and non-compliant data.

[0144] Further, for the compliant data, hierarchical encryption storage is performed; for the non-compliant data, a self-recovery compensation mechanism is performed, that is, corresponding processing is performed according to the violation level of the non-compliant data. Finally, the multi-modal PII recognition engine uploads its operation log, the compliance verification process (i.e., audit record) of the compliance self-check algorithm, and the repair record of the self-recovery compensation mechanism to the blockchain for evidence.

[0145] The above describes the data processing method embodiment of the present application in detail. Figures 1 to 7 The data processing system embodiment of the present application is described in detail below. Figure 8 It should be understood that the description of the data processing method embodiment corresponds to the description of the data processing system embodiment, and therefore, the parts not described in detail can be referred to the previous method embodiment.

[0146] Figure 8 As shown, the data processing system 80 provided by the embodiment of the present application includes: Figure 8 As shown, the data processing system 80 provided by the embodiment of the present application includes:

[0147] The dynamic compliance rule engine 810 is configured to obtain an executable code policy, the executable code policy representing a code form of policy obtained by converting a legal and regulatory text related to data; the sensitive information recognition engine 820 is configured to identify sensitive data in target data based on the executable code policy; the policy determination module 830 is configured to determine a first target processing policy matched with the sensitive data based on the sensitive data; and the compliance self-check module 840 is configured to execute the first target processing policy on the sensitive data and perform compliance verification on the target data after executing the first target processing policy.

[0148] In an embodiment of the present application, the policy determination module 830 is further configured to, if the sensitive data is structured data, determine the first target processing policy matched with the sensitive data based on the sensitive level corresponding to the sensitive field in the structured data; if the sensitive data is unstructured data in an image format, determine the first target processing policy matched with the sensitive data based on the sensitive level corresponding to the sensitive region in the image; and if the sensitive data is unstructured data in a text format, determine the first target processing policy matched with the sensitive data based on the sensitive level corresponding to the sensitive event in the text.

[0149] In an embodiment of the present application, the policy determination module 830 is further configured to, if the sensitive level is the first sensitive level, determine that the first target processing policy matched with the sensitive data is complete retention; if the sensitive level is the second sensitive level, determine that the first target processing policy matched with the sensitive data is partial masking; if the sensitive level is the third sensitive level, determine that the first target processing policy matched with the sensitive data is encrypted storage; and if the sensitive level is the fourth sensitive level, determine that the first target processing policy matched with the sensitive data is rejection storage.

[0150] In an embodiment of the present application, the dynamic compliance rule engine 810 is further configured to perform hot update on the executable code policy; add the executable code policy to a data processing link, the data processing link being a data processing link corresponding to a life cycle of the target data; and insert a target code segment at a specified operation node of the data processing link, the target code segment being used to execute a second target processing policy matched with the data category of the target data and / or a specified parameter in the target data.

[0151] In an embodiment of the present application, the compliance self-checking module 840 is further configured to, before the target data after execution of the first target processing policy is written into storage, perform static rule checking on the target data after execution of the first target processing policy, so as to verify whether the target data after execution of the first target processing policy is compliant; and / or after the target data after execution of the first target processing policy is written into storage, calculate a compliance risk index of the target data after execution of the first target processing policy based on a data bloodline graph, so as to verify whether the target data after execution of the first target processing policy is compliant based on the compliance risk index.

[0152] In an embodiment of the present application, the compliance self-checking module 840 is further configured to, if there is non-compliant data in the target data after the first target processing strategy is executed, determine a violation level corresponding to the non-compliant data; if the violation level corresponding to the non-compliant data is a first violation level, correct the storage location of the non-compliant data; if the violation level corresponding to the non-compliant data is a second violation level, perform desensitization correction on sensitive data in the non-compliant data; if the violation level corresponding to the non-compliant data is a third violation level, freeze the access permission of the non-compliant data; wherein the first violation level is less than the second violation level, and the second violation level is less than the third violation level.

[0153] In an embodiment of the present application, the target data after the compliance verification includes data used for model training, and the data processing system 80 further includes a data management module 850 configured to restrict the use scenarios of the data used for model training based on an access control strategy; inject a traceable feature in the data used for model training, and detect the matching degree of the feature in the model output data and the traceable feature in the model inference stage to determine the data leakage risk; and / or isolate the learning parameters of the model through a trusted execution environment, and record the gradient exchange operation of the model.

[0154] In an embodiment of the present application, the dynamic compliance rule engine 810 is further configured to extract compliance elements in the legal and regulatory texts related to the data, the compliance elements including data categories and target processing strategies matched with the data categories; and convert the compliance elements into executable code strategies.

[0155] In an embodiment of the present application, the data processing system 80 further includes a blockchain storage module 860 configured to write at least one of the process data for identifying sensitive data, the process data for executing the first target processing strategy, the process data for compliance verification, and the repair operation data for the existing non-compliant data into a blockchain network for audit storage.

[0156] In an embodiment of the present application, the blockchain network includes a core layer and an acceleration layer, the core layer adopts an improved MPT tree structure, and the acceleration layer is a evidence generation engine; the blockchain storage module 860 is further configured to perform audit storage of at least one of the process data for identifying sensitive data, the process data for executing the first target processing strategy, the process data for compliance verification, and the repair operation data for the existing non-compliant data through the core layer to obtain audit records; and export the audit records in the core layer into a readable report through the acceleration layer.

[0157] Next, the electronic device according to an embodiment of the present application will be described with reference to the accompanying drawings. Figure 9 The electronic device according to an embodiment of the present application will be described with reference to the accompanying drawings. Figure 9 FIG. 1 shows a structural schematic diagram of an electronic device according to an example embodiment of the present application.

[0158] AsFigure 9 As shown, the electronic device 90 includes one or more processors 901 and memory 902.

[0159] The processor 901 can be a central processing unit (CPU) or other form of processing unit having data processing and / or instruction execution capabilities, and can control other components in the electronic device 90 to perform desired functions.

[0160] The memory 902 can include one or more computer program products, which can include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory, for example, can include random access memory (RAM), cache memory, and / or the like. The non-volatile memory, for example, can include read-only memory (ROM), hard disk, flash memory, and / or the like. One or more computer program instructions can be stored on the computer-readable storage media, and the processor 901 can run the program instructions to implement the data processing method of various embodiments of the present application described above and / or other desired functions.

[0161] In one example, the electronic device 90 can further include an input device 903 and an output device 904, which are interconnected through a bus system and / or other forms of connection mechanisms (not shown).

[0162] The input device 903 can include, for example, a keyboard, a mouse, and / or the like.

[0163] The output device 904 can output various information to the outside, and can include, for example, a display, a speaker, a printer, a communication network and a remote output device connected thereto, and / or the like.

[0164] Of course, in order to simplify, Figure 9 Only some of the components in the electronic device 90 related to the present application are shown in the figure, and components such as buses, input / output interfaces, and / or the like are omitted. In addition, the electronic device 90 can include any other appropriate components according to specific application cases.

[0165] In addition to the above method and device, the embodiments of the present application can also be a computer program product, which includes computer program instructions that, when executed by a processor, cause the processor to perform the steps of the data processing method according to various embodiments of the present application described above in the specification.

[0166] The computer program product can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computing device, partly on the user's computing device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device or entirely on the remote computing device or server. The embodiments of the present application are not limited by the programming languages made use of, as long as they can be used to implement the methods according to the embodiments of the present application.

[0167] In addition, an embodiment of the present application can also be a computer readable storage medium, which stores computer program instructions, and when the computer program instructions are run on a processor, the processor executes the steps of the data processing method according to various embodiments of the present application described above in the specification.

[0168] The computer readable storage medium can be any combination of one or more computer readable medium(s). The computer readable medium can be a computer readable signal medium or a computer readable storage medium. A computer readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the above. More specific examples (a non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable disc, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0169] The above describes the basic principles of the present application in combination with specific embodiments, but it should be noted that the advantages, advantages, effects and the like mentioned in the present application are only examples and are not limiting, and these advantages, advantages, effects and the like cannot be considered as the must-have of each embodiment of the present application. In addition, the above specific details are only for the purpose of example and understanding, and the above details do not limit the present application to the must-use specific details.

[0170] The block diagrams of the devices, devices, equipment, and systems involved in this application are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As will be appreciated by those skilled in the art, these devices, devices, equipment, and systems can be connected, arranged, or configured in any manner. Words such as "include," "comprise," "have," and the like are open-ended words, meaning "including but not limited to," and can be used interchangeably therewith. The words "or" and "and" used herein refer to the words "and / or" and can be used interchangeably therewith, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to," and can be used interchangeably therewith.

[0171] It should also be noted that in the apparatus, device, and method of the present application, each component or each step can be decomposed and / or recombined, and such decomposition and / or recombination should be regarded as equivalent solutions of the present application.

[0172] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present application. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present application. Therefore, the present application is not intended to be limited to the aspects shown herein, but rather to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0173] The above description has been provided for the purpose of illustration and description. Furthermore, this description is not intended to limit the embodiments of the present application to the forms disclosed herein. Although a number of example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.

Claims

1. A data processing method, characterized in that: Applied to the field of embodied intelligence, the method includes: Obtaining an executable code policy, wherein the executable code policy represents a policy in code form obtained by converting the legal and regulatory text related to the data; identifying sensitive data in the target data based on the executable code policy; Based on the sensitive data, determining a first target processing strategy that matches the sensitive data; The first target processing policy is executed on the sensitive data, and compliance verification is performed on the target data after the first target processing policy is executed.

2. The data processing method according to claim 1, wherein: The determining, based on the sensitive data, a first target processing strategy that matches the sensitive data includes: If the sensitive data is structured data, determining the first target processing strategy that matches the sensitive data based on the sensitivity level corresponding to the sensitive field in the structured data; If the sensitive data is unstructured data in an image format, determining the first target processing strategy that matches the sensitive data based on the sensitivity level corresponding to the sensitive area in the image; If the sensitive data is unstructured data in text format, the first target processing strategy that matches the sensitive data is determined based on the sensitivity level corresponding to the sensitive event in the text.

3. The data processing method according to claim 2, characterized in that: Also includes: If the sensitivity level is the first sensitivity level, determining that the first target processing strategy matching the sensitive data is fully retained; If the sensitivity level is the second sensitivity level, determining that the first target processing strategy matching the sensitive data is a partial mask; If the sensitivity level is the third sensitivity level, determining that the first target processing strategy matching the sensitive data is encrypted storage; If the sensitivity level is the fourth sensitivity level, it is determined that the first target processing policy matching the sensitive data is to deny storage.

4. The data processing method according to claim 1, wherein: Before obtaining the executable code strategy, at least one of the following items is also included: Performing a hot update on the executable code policy; Adding the executable code policy to a data processing link, where the data processing link refers to a data processing link corresponding to the life cycle of the target data; A target code segment is inserted into a designated operation node of the data processing link, wherein the target code segment is used to execute a second target processing strategy that matches the data category of the target data and / or designated parameters in the target data.

5. The data processing method according to claim 1, wherein: The performing compliance verification on the target data after executing the first target processing strategy includes: Before writing the target data after executing the first target processing policy into storage, performing a static rule check on the target data after executing the first target processing policy to verify whether the target data after executing the first target processing policy is compliant; and / or, After the target data after executing the first target processing strategy is written to the storage, the compliance risk index of the target data after executing the first target processing strategy is calculated based on the data lineage map, so as to verify whether the target data after executing the first target processing strategy is compliant based on the compliance risk index.

6. The data processing method according to claim 1, wherein: After performing compliance verification on the target data after executing the first target processing strategy, the method further includes: If non-compliant data exists in the target data after executing the first target processing strategy, determining a violation level corresponding to the non-compliant data; If the violation level corresponding to the non-compliant data is the first violation level, correcting the storage location of the non-compliant data; If the violation level corresponding to the non-compliant data is the second violation level, performing desensitization correction on the sensitive data in the non-compliant data; If the violation level corresponding to the non-compliant data is the third violation level, freezing the access rights to the non-compliant data; The first violation level is smaller than the second violation level, and the second violation level is smaller than the third violation level.

7. The data processing method according to claim 1, wherein: The target data after the compliance verification includes data used for model training. After the compliance verification is performed on the target data after the first target processing strategy is executed, the method further includes: Based on the access control policy, constrain the usage scenarios of the data used for the model training; Injecting traceable features into the data used for model training, and detecting the degree of match between features in the model output data and the traceable features during the model inference phase to determine the risk of data leakage; and / or, The model's learning parameters are isolated through a trusted execution environment, and the model's gradient exchange operations are recorded.

8. The data processing method according to claim 1, wherein: Before obtaining the executable code strategy, the method further includes: Extracting compliance elements from legal and regulatory texts related to the data, the compliance elements including data categories and target processing strategies matching the data categories; The compliance elements are converted into the executable code policy.

9. The data processing method according to any one of claims 1 to 8, characterized in that: Also includes: At least one of the process data for identifying the sensitive data, the process data for executing the first target processing strategy, the process data for compliance verification, and the repair operation data for existing non-compliant data is written into the blockchain network for audit and evidence storage.

10. The data processing method according to claim 9, characterized in that: The blockchain network includes a core layer and an acceleration layer. The core layer adopts an improved MPT tree structure, and the acceleration layer is an evidence generation engine. Writing at least one of the process data of identifying the sensitive data, the process data of executing the first target processing strategy, the process data of the compliance verification, and the repair operation data of the existing non-compliant data into the blockchain network for audit and evidence storage includes: Auditing and recording at least one of the following data: process data for identifying the sensitive data, process data for executing the first target processing strategy, process data for compliance verification, and data for repairing the existing non-compliant data, to obtain an audit record; The audit records in the core layer are exported as readable reports through the acceleration layer.

11. A computer-readable storage medium, characterized in that The storage medium stores a computer program, and the computer program is used to execute the data processing method according to any one of claims 1 to 10.

12. An electronic device, characterized in that: include: processor; a memory for storing instructions executable by the processor; The processor is used to execute the data processing method according to any one of claims 1 to 10.

13. A computer program product, characterized in that The computer program product includes instructions, which, when executed on an electronic device, enable the electronic device to implement the data processing method according to any one of claims 1 to 10.