Method and system for protecting user real-name information of event reservation software
By dynamically generating and optimizing protection strategies, the problem of insufficient static strategies for protecting users' real-name information in event booking software has been solved. This enables dynamic adjustments to information security, compliance, and efficiency, adapting to the needs of complex data interaction and cross-regional operations.
Patent Information
- Application Number
- CN202511343500.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-19
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2045-09-19
AI Technical Summary
Existing event booking software suffers from insufficient static protection strategies for protecting users' real-name information, which cannot be dynamically adjusted, resulting in inadequate information security, flexibility, and compliance. In particular, it struggles to meet the needs when facing complex data interactions and cross-regional operations.
By acquiring users' real-name information, performing preprocessing and extracting sensitive features, an initial protection strategy is generated. Based on trend prediction and simulation optimization, an optimized protection strategy is generated. The protection measures are dynamically adjusted to adapt to changes in information usage scenarios and sensitivity levels. Finally, an executable strategy is output to the event booking software.
It achieves dynamic information protection in event booking scenarios, ensuring information security and compliance, adapting to fluctuations in user scale and complex data interactions, reducing operational risks, and improving software operating efficiency and user trust.
Smart Images

Figure CN120832690B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information security protection, in particular to a user real-name information protection method and system for event reservation software. BACKGROUND
[0002] With the vigorous development of sports event industry, various types of event reservation software have emerged, greatly facilitating the process of user registration and participation in events. In order to ensure the authenticity of event participants' identity, maintain the order of events and meet the relevant management regulations, such software usually requires users to provide real-name information, including name, ID number, contact information and other key content. However, these user real-name information is highly sensitive data, once leaked, misused or tampered with, not only will it cause serious invasion of users' personal privacy, but also may cause security problems such as fraud and identity theft, thereby affecting users' trust in event reservation software.
[0003] At present, there are some conventional means for user information protection, such as simple encryption storage of data or partial hiding of key information when displayed. However, in the context of event reservation, these methods have obvious limitations. Data interaction involving multiple links in the process of event organization, such as registration information review, ticket management, on-site verification, etc., simple protection measures are difficult to balance information security and efficient coordination of each link; existing methods are mostly static protection strategies, which cannot dynamically adjust the protection strength according to the use frequency, sensitivity of user information and potential security threats, resulting in poor protection effect when facing new network attacks or complex data use scenarios.
[0004] The user scale of event reservation software often fluctuates greatly with the popularity of events. When the number of users increases dramatically, the data processing pressure increases, and if the information protection strategy is not reasonably designed, it may affect the efficiency of the software, and even cause system failure. At the same time, there are differences in laws and regulations for personal information protection in different regions, and if the event reservation software involves cross-regional operation, the existing information protection methods may not meet the compliance requirements of different regions, increasing the legal risk of software operation. Therefore, how to build a user real-name information protection method that takes into account security, flexibility, efficiency and compliance in the context of event reservation has become a problem to be solved. SUMMARY
[0005] The purpose of the present application is to provide a user real-name information protection method and system for event reservation software to solve the problems raised in the background art.
[0006] To achieve the above purpose, the present application provides a user real-name information protection method for event reservation software, which comprises:
[0007] Obtaining user real-name information, the user real-name information including user name, ID number and contact information;
[0008] Preprocessing the user real-name information to obtain desensitization preparation data;
[0009] Extracting sensitive features of the desensitization preparation data to determine sensitive feature distribution information;
[0010] Based on the preset privacy constraint information, the initial protection strategy is generated in combination with the sensitive feature distribution information;
[0011] Trend prediction is performed on the sensitive feature distribution information and usage record data to obtain predicted feature distribution information and predicted usage data;
[0012] Based on the predicted feature distribution information and the predicted usage data, the initial protection strategy is compensated and optimized to generate an optimized protection strategy;
[0013] The optimized protection strategy is applied to protect the user real-name information;
[0014] According to the optimized protection strategy, the reverse deduction is performed to simulate the protection effect;
[0015] Based on the simulated protection effect, the optimized protection strategy is adjusted to obtain a final protection strategy;
[0016] The final protection strategy is output to the event reservation software for execution.
[0017] Preferably, the preprocessing of the user real-name information to obtain desensitization preparation data comprises:
[0018] Identifying sensitive fields in the user real-name information;
[0019] According to the preset desensitization rule, the sensitive fields are labeled;
[0020] The labeled user real-name information is classified into desensitizable data and non-desensitizable data;
[0021] The desensitization preparation data is generated in combination with the classification result.
[0022] Preferably, the extraction of sensitive features of the desensitization preparation data to determine sensitive feature distribution information comprises:
[0023] Building a user information model;
[0024] The desensitization preparation data is input into the user information model to output a sensitive feature cloud map;
[0025] Based on the preset privacy constraint information and the sensitive feature cloud map, the sensitive feature distribution information is analyzed.
[0026] Preferably, the initial protection strategy is generated based on the preset privacy constraint information and the sensitive feature distribution information, including:
[0027] The decision space is associated and calibrated according to the sensitive feature distribution information and the use record data, to obtain a first calibrated decision space;
[0028] The decision feature trigger interval in the first calibrated decision space is identified, to obtain a first decision feature trigger space;
[0029] The initial protection decision is generated based on the first decision feature trigger space;
[0030] The fitness value of the initial protection decision is calculated;
[0031] It is judged whether the fitness value meets a preset fitness constraint condition;
[0032] If yes, the initial protection decision is added to the initial protection strategy.
[0033] Preferably, the trend of the sensitive feature distribution information and the use record data is predicted to obtain predicted feature distribution information and predicted use data, including:
[0034] The historical feature distribution data is loaded;
[0035] The future feature change trend is predicted by combining the historical feature distribution data and the current use record data;
[0036] The predicted feature distribution information and the predicted use data are output.
[0037] Preferably, the initial protection strategy is compensated and optimized based on the predicted feature distribution information and the predicted use data to generate an optimized protection strategy, including:
[0038] The decision space is associated and calibrated according to the predicted feature distribution information and the predicted use data, to obtain a second calibrated decision space;
[0039] The decision feature trigger interval in the second calibrated decision space is identified, to obtain a second decision feature trigger space;
[0040] The compensation protection strategy is generated by iteratively deciding based on a preset fitness constraint condition and the second decision feature trigger space;
[0041] The initial protection strategy is optimized by combining the compensation protection strategy, to obtain the optimized protection strategy.
[0042] Preferably, the application of the optimization protection strategy to the protection processing of the user real-name information comprises:
[0043] Analyzing the protection rules in the optimization protection strategy;
[0044] According to the protection rules, the user real-name information is desensitized or encrypted;
[0045] The protected user data is generated.
[0046] Preferably, the reverse deduction according to the optimization protection strategy, the simulation protection effect comprises:
[0047] Loading the simulation use scene data;
[0048] The optimization protection strategy is applied to the simulation use scene data, and the simulation protection result is output;
[0049] The information leakage risk in the simulation protection result is analyzed.
[0050] Preferably, the optimization protection strategy is adjusted based on the simulation protection effect to obtain the final protection strategy, comprising:
[0051] The information leakage risk is compared with the preset risk threshold;
[0052] If the information leakage risk is higher than the preset risk threshold, the protection rules in the optimization protection strategy are adjusted;
[0053] The adjusted protection strategy is generated as the final protection strategy;
[0054] The final protection strategy is output to the event reservation software for execution, comprising:
[0055] The final protection strategy is converted into executable instructions;
[0056] The executable instructions are integrated into the reservation process of the event reservation software, and the protection state of the user real-name information is monitored in real time.
[0057] Preferably, the application further comprises a user real-name information protection system for event reservation software, the system comprises a memory, a processor and a computer program stored in the memory and running on the processor, and the processor realizes the steps of the above-mentioned user real-name information protection method for event reservation software when executing the computer program.
[0058] Compared with the prior art, the application has the following advantages:
[0059] A comprehensive and dynamic solution is provided for user real-name information protection through a series of coherent and rigorous steps. First, the user real-name information is preprocessed to obtain desensitization preparation data, which can reduce the risk of sensitive information leakage in the initial stage of data processing and lay a good foundation for subsequent protection measures. Extracting sensitive features of desensitization preparation data and determining sensitive feature distribution information can help accurately grasp the sensitivity and distribution of different information, making the protection strategy more targeted and avoiding the problem of resource waste or insufficient protection caused by blind protection.
[0060] Generating an initial protection strategy based on preset privacy constraint information combined with sensitive feature distribution information can ensure that the protection measures meet the basic privacy protection requirements and the specific needs of the event reservation scene from the beginning, so that information protection is carried out within the compliance framework. Trend prediction of sensitive feature distribution information and usage record data to obtain predicted feature distribution information and predicted usage data can make the protection strategy forward-looking. Through this prediction, changes in information sensitivity and possible usage risks can be perceived in advance, providing a basis for optimization of the protection strategy and avoiding the lag of static protection strategies when facing changes.
[0061] Compensatory optimization of the initial protection strategy based on predicted feature distribution information and predicted usage data generates an optimized protection strategy, so that the protection strategy can be dynamically adjusted according to the actual situation, achieving precise matching of protection strength with information usage scenarios and changes in sensitivity. This dynamic adjustment can better adapt to the data usage needs of different stages in the event reservation process while ensuring information security, ensuring efficient coordination of event registration, review, verification, and other stages, and not affecting the normal event organization process due to excessive protection.
[0062] After applying the optimized protection strategy to protect the user real-name information, the protection effect is simulated in reverse according to the optimized protection strategy, and the optimized protection strategy is adjusted based on the simulation effect to obtain the final protection strategy, forming a closed-loop optimization mechanism. Through reverse deduction, possible vulnerabilities or unreasonable aspects in the protection strategy can be discovered in advance, and then adjusted and improved, making the final protection strategy more reliable.
[0063] The final protection strategy is output to the event reservation software for execution, which can ensure that the protection measures are effectively implemented in actual application. This method not only can cope with complex data interaction and use cases in the event reservation scene, but also can adapt to the impact of user scale fluctuations, maintain the running efficiency of the software while ensuring information security. At the same time, since the entire protection process fully considers sensitive feature changes and potential risks, it can better meet the legal and regulatory requirements of different regions for personal information protection, reduce the legal risks of software operation, enhance the trust of users in the event reservation software, and is conducive to the long-term stable operation of the software. BRIEF DESCRIPTION OF DRAWINGS
[0064] Figure 1 A working principle diagram of the user real-name information protection method for event reservation software according to the present application;
[0065] Figure 2 A flowchart for user real-name information preprocessing;
[0066] Figure 3 A flowchart for generating an initial protection strategy;
[0067] Figure 4 A flowchart for generating an optimized protection strategy by compensation optimization;
[0068] Figure 5 A flowchart for generating a final protection strategy by adjusting and optimizing the protection strategy. DETAILED DESCRIPTION
[0069] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.
[0070] Please refer to Figure 1 The present application provides a user real-name information protection method for event reservation software, which comprises:
[0071] The method realizes comprehensive protection of user real-name information through a multi-level dynamic protection mechanism. The method first acquires user real-name information including user name, ID number and contact information, and then preprocesses the information to form desensitization preparation data. By extracting sensitive features and analyzing their distribution rules, an initial protection strategy is generated in combination with preset privacy constraints. The system further predicts feature distribution and usage trends, dynamically optimizes and compensates the initial strategy to form an optimized protection strategy. After implementing the protection processing, the protection effect is simulated by reverse deduction, and finally an executable final protection strategy is generated and output to the event reservation software.
[0072] Embodiment 1: Refer to Figure 2 , involving the preprocessing of user real-name information and the sensitive feature extraction process. In the preprocessing stage, the system receives raw real-name information data containing user name, ID number and contact information. The information recognition module adopts a multi-level scanning mechanism, the first level scanning is based on the pre-defined sensitive field dictionary for pattern matching, which contains common sensitive data types and their feature patterns. For the ID number, the system applies a regular expression engine to identify the structural features of the 18-character sequence, focusing on the 7th to 14th birth date segment and the last 1st check code. For the mobile phone number, the system identifies the first three digits of the operator code and the middle four digits of the user number through the number segment database.
[0073] The labeling process uses a dynamic labeling system to automatically generate a three-level labeling system according to the data type. The first level label identifies the basic type of the field, the second level label marks the sensitivity, and the third level label records the data processing suggestions. During the labeling process, the system synchronously establishes field metadata index, records the original position, length and association of each field. The classification engine executes three times of filtering according to the labeling results: first, exclude the legal and regulatory mandatory retention fields, second, analyze the necessity of the field in the business scenario, and finally, evaluate the sensitivity of the field combination. The classification results form a three-color marking system, red marking completely desensitized fields, yellow marking partially desensitized fields, and green marking non-desensitized fields.
[0074] The generation of desensitization preparation data uses structured packaging technology. The system creates a data container object, containing three core components: original data reference, classification label matrix, and field association graph. The container object uses a hierarchical storage structure, the original data layer retains the initial information, the metadata layer stores the labeling classification results, and the strategy mapping layer records the subsequent processing rule index. Data fingerprint is generated synchronously during data packaging, using SHA-256 algorithm to calculate the data integrity check value.
[0075] In the feature extraction stage, the user information model is constructed as a multi-dimensional feature space. The model input layer receives the desensitization preparation data container, and the feature mapping layer converts the data elements into a 128-dimensional feature vector. The vector dimension design includes three categories: basic attributes, associated attributes, and behavior attributes, each category has multiple sub-dimensions. The feature conversion process uses a convolutional neural network architecture, the network contains three convolutional layers and two pooling layers, the convolution kernel size is 3x3, 5x5, 3x3 respectively, and the pooling method uses maximum pooling.
[0076] The generation of the sensitive feature cloud map is based on feature vector space calculation. The system establishes a three-dimensional coordinate system, with the X-axis representing the feature sensitivity score, which is determined by the field type, data content, and associated fields; the Y-axis representing the feature usage frequency, which is dynamically calculated based on historical access logs; and the Z-axis representing the feature association risk value, reflecting the association strength of the feature with other sensitive data. The cloud map generation algorithm uses kernel density estimation technology to calculate the density distribution of feature points in space through a Gaussian kernel function. When rendering the cloud map, heat gradient coloring is used, with high-density areas showing warm colors and low-density areas showing cool colors.
[0077] The privacy constraint analysis module integrates a legal rule engine to convert preset privacy constraints into mathematical constraint conditions. The constraint conditions include seven categories such as data type constraints, usage scenario constraints, and storage period constraints. The analysis process uses a constraint satisfaction problem solving framework to match and calculate the feature cloud map data with the constraint conditions. The calculation process is executed in three steps: first, a feature-constraint association matrix is established, second, a constraint satisfaction score is calculated, and finally, a feature weight distribution map is generated. The output results include a feature sensitivity distribution heat map, a feature association network graph, and a feature weight matrix table.
[0078] The determination of sensitive feature distribution information uses multi-source data fusion technology. The system integrates feature cloud map analysis results, constraint analysis results, and historical feature distribution data to generate a comprehensive feature distribution report through data fusion algorithms. The report includes a feature distribution statistics table, a feature clustering analysis graph, and an abnormal feature warning list. The statistics table records the distribution frequency, sensitivity average, and risk value standard deviation of various features; the clustering analysis graph displays the similarity relationships between features, using spectral clustering algorithms to divide features into different groups; and the warning list marks feature points that exceed the normal fluctuation range, indicating their deviation degree and potential risk level. The entire processing process is completed in an encrypted memory area, and intermediate calculation data is automatically cleared after processing is completed.
[0079] Embodiment 2: See Figure 3 , which involves the generation mechanism of the initial protection policy and the feature trend prediction process. The decision space correlation calibration stage uses multi-dimensional space modeling technology to construct a six-dimensional decision hyperspace structure. Each dimension of the space represents feature type distribution, usage scenario classification, access permission level, time decay coefficient, geographical restriction range, and emergency unlocking conditions. The calibration process performs Monte Carlo simulation to generate a million-level virtual scenario data set in a simulated environment, with each scenario containing a mapping relationship between feature combinations and usage records. The simulation is executed using a distributed computing architecture, with the computing load distributed to multiple processing nodes through a task fragmentation mechanism.
[0080] The spatial calibration algorithm adopts a sliding window detection mechanism. The window size is dynamically adjusted according to the standard deviation of the feature distribution, and the initial window size is three times the standard deviation range. When the window slides along each dimension of the decision space, the density distribution of the data points in the window is calculated in real time. When the aggregation degree of the feature combination exceeds the preset threshold, the system marks the area as the decision feature trigger interval. The trigger interval boundary is calculated using the convex hull algorithm to generate the smallest boundary polygon. The first decision feature trigger space is thus formed, containing multiple trigger areas and their boundary parameters.
[0081] The initial protection decision generation adopts a genetic algorithm framework. The algorithm initializes by randomly generating 200 decision schemes to form an initial population, each encoded as a binary gene sequence. The gene sequence includes parameters such as protection rule type, execution intensity, and action range. The iterative evolution process is executed for 50 rounds, and each iteration includes selection, crossover, and mutation. The selection operation uses the tournament selection mechanism, randomly selecting 10 individuals to compete for the next generation each time. The crossover operation uses the two-point crossover method, with a crossover probability of 0.85. The mutation operation uses the bit flip mechanism, with a mutation probability of 0.01.
[0082] The fitness function is designed as a multi-objective comprehensive evaluation system. The information security dimension includes data confidentiality, integrity, and availability, with a weight of 60%. The system performance dimension includes processing delay, resource consumption, and throughput, with a weight of 30%. The user experience dimension includes operation convenience and interface friendliness, with a weight of 10%. The scores of each sub-item are obtained through simulation testing, and the final weighted comprehensive fitness value is calculated. The preset fitness constraint condition is set as a threshold of not less than 0.85. When the decision scheme reaches this threshold, the system decodes its gene sequence into executable rules and adds it to the initial protection strategy library.
[0083] The loading of historical feature distribution data uses a time series database management. The system retrieves the feature distribution records of the past three years and aligns the data by time granularity. In the data preprocessing stage, missing value filling and smoothing are performed, and linear interpolation is used to supplement incomplete data points. The time series analysis constructs an ARIMA prediction model, and the model parameters are determined through an automatic optimization process. The optimization process calculates the AIC information criterion value for different parameter combinations, and selects the parameter configuration with the smallest AIC. The difference order is determined through ADF unit root test to ensure the stationarity of the sequence.
[0084] The future feature change trend prediction adopts the LSTM neural network architecture. The network contains three hidden layers, and each layer has 256 neurons. The input layer receives the historical feature sequence, and the time step is set to 30 consecutive periods. The network training uses the Adam optimization algorithm, and the initial learning rate is 0.001, which is reduced by 50% every 10 rounds. The training data is divided into 70% training set, 15% validation set and 15% test set. The prediction process performs multi-step rolling prediction, predicting the feature distribution of the next three periods each time. The prediction of recorded data uses a collaborative filtering algorithm to analyze the similarity of user behavior patterns and infer the probability distribution of future usage scenarios.
[0085] The prediction result output includes two parts: predicted feature distribution information and predicted usage data. The feature distribution information is stored in the form of a three-dimensional tensor, recording the expected distribution state of each feature at different time periods. The usage data prediction result generates a probability distribution table listing the occurrence probability and expected frequency of each usage scenario. All prediction results are accompanied by a confidence score reflecting the reliability of the prediction results. The system establishes a prediction result version management mechanism to retain historical prediction records for continuous model optimization. The prediction module is set to automatically calibrate when the actual data deviates from the predicted value beyond the allowed range, triggering model retraining. The entire prediction process is executed on a dedicated prediction server cluster, and the calculation results are encrypted and transmitted to the strategy generation module.
[0086] Embodiment 3: see Figure 4 , which involves the compensation optimization process of the protection strategy, which realizes the dynamic improvement of the strategy by expanding the dimension of the decision space and applying reinforcement learning technology. The second calibration decision space adds a prediction dimension to the first calibration decision space, forming a seven-dimensional decision hyperspace structure. The new prediction dimension includes three sub-dimensions: feature distribution change rate, usage frequency fluctuation coefficient and risk trend slope, which are calculated through time series analysis. Space calibration uses an improved particle swarm optimization algorithm, deploying 200 probe particles in the seven-dimensional space, each carrying a position vector and a velocity vector. The particle movement process follows the spatial topological constraints and automatically adjusts the search step when detecting feature aggregation areas. The identification of the decision feature trigger interval uses the density peak clustering algorithm to determine the key decision points in the space by calculating the local density and relative distance.
[0087] The implementation of the deep Q-learning algorithm is based on the Markov model of the decision space. The state space is defined as the transition probability matrix of the feature distribution, containing 512 discrete states. The action space design includes 12 standard protection operations such as data encryption, field desensitization and access control, with three intensity levels for each operation. The design of the reward function considers the balance between risk control and system overhead, and its calculation expression is:
[0088] ;
[0089] where R represents the comprehensive reward value, n represents the number of risk types, wi represents the weight coefficient of the ith risk type, ri represents the reduction degree of the risk type, and m represents the number of resource types, cj represents the cost coefficient of the jth resource type, qj represents the consumption amount of the resource type. The discount factor γ is set to 0.9 to control the decay rate of the long-term return. The network structure adopts a double DQN architecture, including an evaluation network and a target network, and the network parameters are updated synchronously in each round of training.
[0090] The generation process of the compensation protection strategy adopts a policy gradient method. The policy network includes four fully connected layers with 256, 128, 64, and 12 neurons respectively. The learning rate is set to 0.001, and the adaptive momentum optimization method is used to update the network parameters. The training process performs 1000 iterations, and 256 transition samples are sampled from the experience replay pool in each iteration. The policy improvement adopts the trust region optimization technique to limit the variation amplitude of the policy in each update. The final output compensation strategy includes a priority queue, which sorts the execution order of the protection measures according to the operation urgency.
[0091] The strategy fusion stage adopts an ensemble learning method to construct an optimized protection strategy. The initial strategy and the compensation strategy are mixed in a 7:3 ratio, and the mixing process performs weighted integration at the rule level. For conflicting protection rules, the system calculates the confidence scores of each rule, considering three factors: rule source, historical execution effect, and current environment matching degree. Rules with higher confidence scores are given priority to be retained, and rule conflict resolution records are generated. The integrated strategy is compressed through knowledge distillation technology, using a teacher-student network framework to convert complex strategies into lightweight decision trees.
[0092] The structure of the optimized protection strategy includes rule set, execution condition, and monitoring indicator. The rule set adopts a hierarchical organization method, with scene classification rules at the top, feature matching rules in the middle, and specific operation rules at the bottom. The execution condition defines the threshold standards for triggering the strategy, including feature distribution threshold, risk level threshold, and system load threshold. The monitoring indicator sets up an evaluation system for the execution effect of the strategy, including risk control rate, response delay, and resource occupancy rate. The strategy version management adopts an incremental update mechanism, generating a new strategy branch in each optimization, and preserving historical versions for rollback.
[0093] The policy optimization process sets multiple verification links. Static verification checks the logical consistency of policy rules, excluding contradictory rule combinations. Dynamic verification simulates policy execution in a sandbox environment to evaluate actual operation effects. The expert verification link invites security analysts to review key policy changes. After all verifications are passed, the optimized protection policy is marked as deployable and waits for subsequent processing stages. The intermediate data generated during the entire optimization process is protected using differential privacy techniques to ensure the confidentiality of the policy generation process.
[0094] The policy knowledge base update mechanism enables continuous learning. After each policy execution, the system collects actual effect data and calculates policy utility values. Policy fragments with utility values above the threshold enter the excellent policy library, and policy fragments with utility values below the threshold trigger optimization alarms. The knowledge base uses a graph database to store the association between policies, supporting policy retrieval based on similarity. Regular policy knowledge distillation converts complex policy networks into interpretable rule sets, improving policy transparency and maintainability. The policy rollback mechanism preserves the complete policy set of the last five versions, allowing quick recovery to a stable historical version when abnormal conditions are detected.
[0095] Embodiment 4: Covers the application execution and protection effect simulation verification process of the optimized protection policy. In the policy parsing stage, the system loads the optimized protection policy file and decomposes the policy statements into executable atomic operations through the semantic analysis engine. The parsing process uses context-free grammar to build a syntax tree, with leaf nodes corresponding to specific protection operation instructions. Each instruction contains operation type, object, and execution parameter. After parsing, the operation instruction sequence is generated, and the instruction dependency graph is established to ensure correct operation order.
[0096] Taking the real-name information protection of user Zhang San as an example, the original data includes the name "Zhang San", the ID number "11010119900307783X", and the mobile phone number "13901234567". After policy parsing, three operation instructions are generated: the first instruction performs partial desensitization on the ID number, retaining the first 6 digits and the last 4 digits; the second instruction performs AES encryption storage on the mobile phone number; the third instruction adds an access control label to the name field. The system determines the execution order based on data association: first process the ID number, then process the mobile phone number, and finally set the access control.
[0097] The protection processing adopts a hybrid operation mode. The desensitization operation implements a dynamic masking technique and applies differentiated processing rules for different field types. The identity card number processing adopts segmented masking, retains the administrative division code and check code, and masks the birth date segment. The mobile phone number processing adopts a combination of encrypted storage and display masking. During storage, the complete number is encrypted using the AES-256 algorithm, and the key management adopts a (3, 5) threshold secret sharing scheme. During display, only the first three and last four digits are displayed. The encryption operation implements a hybrid encryption system, with symmetric encryption using the SM4 algorithm to process the data subject, and asymmetric encryption using the SM2 algorithm to protect the symmetric key. The access control of sensitive fields implements an attribute-based access control model, setting up a multi-level permission system.
[0098] The protected user data generates three core components: processed data subject, operation metadata, and security label. The data subject stores the actual content after desensitization or encryption; the operation metadata records the type of operation performed, timestamp, and operator identity; and the security label defines the data classification and access policy. The system embeds digital watermarks when encapsulating data, with watermark information including data processing serial number, operation time, device fingerprint, etc., embedded in the frequency domain using the discrete cosine transform algorithm. The final output data packet is encapsulated in JSON format, containing header, payload, and signature three-part structure.
[0099] A multi-scenario test environment is constructed to verify the simulation protection effect. The system preloads 100 typical scenario data, divided into normal operation scenarios and attack scenarios. Normal scenarios simulate regular operations such as reservation, query, and modification; attack scenarios include malicious behaviors such as SQL injection, privilege escalation, and data sniffing. Scenario data is described in YAML format, including initial state, operation sequence, and expected results.
[0100] Table 1: Shows some typical test scenarios.
[0101] Scenario number Scenario type Description Data characteristics Expected operation S-07 Normal operation User booking events Contains complete real name information Desensitization display part field S-12 Normal operation Customer service query user information Need to verify identity Decrypt complete mobile phone number A-03 Unauthorized access Ordinary user attempts to access other people's information Cross-account ID request Block access and warn A-15 Data crawling High-frequency batch query user information Same IP short-term multiple requests Trigger flow limiting and verification code challenge A-22 Injection attack SQL injection attempts to obtain plaintext data Contains malicious injection statements Filter special characters and block requests F-05 System failure Database exception interruption Service unavailable Start backup and data consistency check The simulation execution engine adopts a containerized deployment architecture, with each scenario running in an independent container instance. The engine core components include scenario loader, policy executor, and behavior monitor. The execution process records detailed operation logs, including policy trigger points, execution actions, and system responses. The effect analysis module processes the execution logs and extracts risk feature indicators.
[0102] The information leakage risk analysis adopts a multi-dimensional evaluation model. The access path dimension analyzes the reliability of the request source, distinguishing between trusted terminals, unknown devices, and anonymous access; the impact range dimension evaluates the amount and sensitivity of data that may be leaked; and the repair difficulty dimension measures the complexity of remedial measures after the event. Risk quantification uses a weighted scoring method, with the weights of each dimension dynamically adjusted according to the scenario type. The analysis results generate a risk heat map, marking the distribution of system vulnerabilities and protection strengths.
[0103] The risk report contains three parts: the first part is a scenario execution summary, which statistics basic indicators such as the total number of scenarios, the number of successful interceptions, and the number of false operations; the second part is a risk distribution analysis, which shows the proportion of different risk levels and associated scenarios; and the third part lists key findings, including effective protection points, potential vulnerabilities, and improvement suggestions. The report output uses an interactive visualization interface, supporting multi-dimensional filtering and viewing by risk level, scenario type, attack vector, etc.
[0104] The simulation verification process sets up an iterative optimization mechanism. When a protection vulnerability is found, the system automatically generates a scenario reproduction package containing the initial state, operation sequence, and actual results. Security analysts debug protection rules based on the reproduction package and modify them to be re-added to the test queue. The verification cycle continues to execute until all high-risk scenarios are effectively protected. The final verification report is stored together with the optimized protection strategy as a basis for policy deployment documentation. Temporary data generated during the entire simulation process is automatically destroyed at the end of execution, ensuring that the test environment is strictly isolated from the production environment.
[0105] Example 5: Referring to Figure 5 , covers the final adjustment of the protection strategy and the system integration process. The risk threshold comparison mechanism uses a dynamic calculation model, with a basic risk threshold set to 7.0 points. This score is based on the Common Vulnerability Scoring Standard. The threshold floating parameters include a software version coefficient and a user scale coefficient. The version coefficient is adjusted according to the major version number, and the user scale coefficient is calculated using a logarithmic function. The system monitors information leakage risk values in real-time, and triggers the strategy adjustment process when the risk value exceeds the dynamic threshold.
[0106] The strategy adjustment process performs incremental updates at the rule level. The system scans all rules in the optimized protection strategy and identifies rule entries with a risk contribution higher than the average. Parameter fine-tuning is performed for high-contribution rules, with adjustment directions including enhancing protection strength, expanding the scope of action, and adding verification steps. The adjustment amplitude of each rule is proportional to its risk contribution, while being constrained by system performance margins. The adjusted rule set recalculates priorities, considering factors such as rule effectiveness speed, resource consumption rate, and false interception rate.
[0107] The final protection policy generation includes policy signing and version marking. The policy file is attached with a digital signature, and the signature value is generated using the elliptic curve digital signature algorithm. The version marking adopts a four-segment encoding structure, representing the main version, feature version, revision version, and build number, respectively. The policy file is packaged into a policy package in a specific format, containing four components: policy body, dependent library list, compatibility declaration, and rollback pointer.
[0108] The instruction conversion process uses a hierarchical compilation technique. The high-level policy language is first compiled into an intermediate representation, which uses a control-flow-based instruction sequence. The intermediate representation is platform-independent optimized, including constant propagation, dead code elimination, and loop unrolling. The target code generation stage performs specific optimization for the running environment of the event reservation software, generating ARM instruction sets for mobile applications and x86 instruction sets for server-side. The final output executable instructions include two types: protection operation instruction set and monitoring instruction set.
[0109] The system integration process uses a modular injection method. Five key hook points are inserted in the software's data access layer: data read before hook, data read after hook, data write before hook, data write after hook, and data transmission hook. Each hook point registers the corresponding protection processing function, and the function call follows a unified interface specification. The integration process performs dependency checks to ensure that the system library version is compatible and meets the minimum resource requirements.
[0110] The real-time monitoring system builds a distributed data collection network. Lightweight probes are deployed on terminal devices to collect basic indicators such as data access frequency, operation type, and response time. Deep monitoring agents are deployed on the server side to record memory access patterns, network traffic characteristics, and abnormal behavior traces. Monitoring data uses a streaming processing architecture, transmitting data to the analysis center through a message queue.
[0111] The anomaly detection mechanism uses a multi-model fusion architecture. The basic detection layer uses an improved isolation forest algorithm, adding time series analysis dimensions. The secondary detection layer applies a hidden Markov model to identify state transition anomalies. The tertiary detection layer deploys a deep anomaly detection network containing long short-term memory units and self-attention mechanisms. The detection results generate an anomaly score, and scores exceeding the threshold trigger an alarm.
[0112] The response system designs a three-level linkage mechanism. The first-level response performs local interception, including terminating operations, resetting sessions, and clearing caches. The second-level response triggers system-level protection, including process isolation, network throttling, and key rotation. The third-level response initiates global emergency, including data migration, service degradation, and audit tracking. Response actions are executed in priority order, and high-priority responses can interrupt low-priority responses.
[0113] The visualization system builds a dynamic topology model. Nodes represent data entities and user entities, and edges represent access relations and operation flows. A graph rendering engine calculates node positions in real time, and important nodes are automatically focused. Views include data flow view, risk distribution view and protection status view Figure 3 A mode is supported for free switching. A risk heat map is displayed on the topology graph, indicating risk levels with a color gradient.
[0114] The state subscription service supports multiple notification channels. Users can configure WeChat, SMS and email notifications, and set notification thresholds for different risk levels. Notification content includes event type, risk level, impact range and recommended measures. Key event notifications have an additional confirmation mechanism, and recipients must confirm the alert within a limited time.
[0115] The system maintenance mechanism includes automatic inspection and manual debugging modes. Automatic inspection is performed daily at midnight to check policy effectiveness, monitoring completeness and response readiness. Inspection reports are generated in HTML format, with pending items marked. The manual debugging mode is open to security administrators, supporting policy sandbox testing and monitoring simulation playback. All operations are recorded in detailed audit logs, and log retention periods meet regulatory requirements.
[0116] It should be noted that, in the present text, relational terms such as first and second are used merely to distinguish one entity or action from another, without necessarily requiring or implying any such actual relationship or order between such entities or actions. Moreover, the terms "comprises", "comprising", or any other variant thereof are intended to cover non-exclusive inclusions, so that a process, method, article or apparatus that includes a list of elements does not only include those elements, but also includes other elements not expressly listed, or inherent to such a process, method, article or apparatus.
[0117] Although embodiments of the present application have been shown and described, it will be understood by those having ordinary skill in the art that various changes, modifications, substitutions and alterations can be made hereto without departing from the principles and spirit of the present application, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A method for protecting user real-name information in event booking software, characterized in that, include: Obtain user real-name information, which includes user name, ID number, and contact information; The user's real-name information is preprocessed to obtain de-identified preparation data; Extract the sensitive features from the desensitized data preparation data and determine the distribution information of the sensitive features; An initial protection strategy is generated based on preset privacy constraints and the sensitive feature distribution information. Perform trend prediction on the sensitive feature distribution information and usage record data to obtain predicted feature distribution information and predicted usage data; Based on the predicted feature distribution information and the predicted usage data, the initial protection strategy is compensated and optimized to generate an optimized protection strategy. The optimized protection strategy described above is applied to protect the user's real-name information. The protection effect is simulated by performing a reverse simulation based on the optimized protection strategy. The optimized protection strategy is adjusted based on the simulated protection effect to obtain the final protection strategy; The final protection strategy is output to the event booking software for execution; The generation of an initial protection strategy based on preset privacy constraints and the distribution information of sensitive features includes: Based on the sensitive feature distribution information and the recorded data, the decision space is correlated and calibrated to obtain a first calibrated decision space; Identify the decision feature triggering intervals in the first calibration decision space to obtain the first decision feature triggering space; Initial protection decisions are generated based on the first decision feature trigger space; Calculate the fitness value of the initial protection decision; Determine whether the fitness value satisfies the preset fitness constraint condition; If satisfied, the initial protection decision is added to the initial protection strategy; The step of compensating and optimizing the initial protection strategy based on the predicted feature distribution information and the predicted usage data to generate an optimized protection strategy includes: A six-dimensional decision hyperspace structure is constructed by using multi-dimensional spatial modeling technology. Each dimension of this space represents the feature type distribution, usage scenario classification, access permission level, time decay coefficient, geographical restriction range, and emergency unlocking conditions, respectively. The decision space is correlated and calibrated based on the predicted feature distribution information and the predicted data to obtain a second calibrated decision space. Identify the decision feature triggering intervals in the second calibration decision space to obtain the second decision feature triggering space; Iterative decision-making is performed based on preset fitness constraints and the second decision feature triggering space to generate a compensation protection strategy. The initial protection strategy is optimized by combining the compensation protection strategy to obtain the optimized protection strategy.
2. The method for protecting user real-name information in event booking software according to claim 1, characterized in that, The preprocessing of the user's real-name information to obtain de-identified preparation data includes: Identify sensitive fields in the user's real-name information; The sensitive fields are labeled according to the preset desensitization rules; The labeled user real-name information is classified into data that can be anonymized and data that cannot be anonymized. The desensitization preparation data is generated based on the classification results.
3. The method for protecting user real-name information in event reservation software according to claim 2, characterized in that, The step of extracting sensitive features from the desensitized data and determining the distribution information of sensitive features includes: Build a user information model; Input the desensitization preparation data into the user information model and output a sensitive feature cloud map; Based on the preset privacy constraint information and the sensitive feature cloud map, the sensitive feature distribution information is analyzed.
4. The method for protecting user real-name information in event booking software according to claim 3, characterized in that, The step of performing trend prediction on the sensitive feature distribution information and usage record data to obtain predicted feature distribution information and predicted usage data includes: Load historical feature distribution data; By combining the historical feature distribution data and current usage record data, future feature change trends can be predicted; Output the predicted feature distribution information and the predicted data.
5. The method for protecting user real-name information in event reservation software according to claim 1, characterized in that, The application of the optimized protection strategy to protect the user's real-name information includes: Analyze the protection rules in the optimized protection strategy; The user's real-name information is desensitized or encrypted according to the protection rules. Generate protected user data.
6. The method for protecting user real-name information in event booking software according to claim 5, characterized in that, The step of performing reverse engineering based on the optimized protection strategy to simulate the protection effect includes: Load simulated usage scenario data; The optimized protection strategy is applied to the simulated usage scenario data, and the simulated protection results are output. Analyze the information leakage risk in the simulation protection results.
7. The method for protecting user real-name information in event booking software according to claim 6, characterized in that, The step of adjusting the optimized protection strategy based on the simulated protection effect to obtain the final protection strategy includes: Compare the information leakage risk with a preset risk threshold; If the risk of information leakage is higher than the preset risk threshold, adjust the protection rules in the optimized protection strategy; The adjusted protection strategy is generated as the final protection strategy; The step of outputting the final protection strategy to the event booking software for execution includes: Convert the final protection strategy into executable instructions; The executable instructions are integrated into the event booking software's booking process to monitor the protection status of the user's real-name information in real time.
8. A user real-name information protection system for event booking software, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the user real-name information protection method for event reservation software as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Private data protection method and system based on homomorphic encryption and federated learning
CN119513919A
Self-adaptive data security management and risk early warning system based on intelligent analysis under cloud platform
CN120358082A