Data privacy protection and compliance use method and system

By acquiring access permissions and data characteristics of terminals, filtering characteristic access terminals, and constructing risk curves, the problem of internal personnel abusing permissions is solved, and the efficiency and reliability of data privacy protection and compliant use of the system are improved.

CN120850347AActive Publication Date: 2025-10-28BEIJING JUZHIXING BIG DATA DEVELOPMENT CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202511318217.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-16
Publication Date
2025-10-28
Estimated Expiration
2045-09-16

AI Technical Summary

Technical Problem

Existing technologies have failed to effectively identify and address the problem of internal personnel abusing their privileges to export or snoop on non-essential private data, resulting in insufficient processing efficiency and reliability of data privacy protection and compliant use systems.

Method used

The data acquisition module obtains the access permission characteristics and data characteristics of the accessing terminals. The terminal preprocessing module filters the accessing terminals with characteristics. The terminal analysis module constructs a data access risk curve. The terminal identification module determines whether to perform data isolation based on the risk characterization coefficient.

Benefits of technology

It enables rapid identification of abnormal risks based on the actual characteristics of the access terminal, adaptive adjustment of data processing methods, and improves the processing efficiency and reliability of the data privacy protection and compliant use system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120850347A_ABST
    Figure CN120850347A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, in particular to a data privacy protection and compliance use method and system.The data privacy protection and compliance use method is provided with a data acquisition module, a terminal preprocessing module, a terminal analysis module and a terminal recognition module, and the terminal preprocessing module determines access offset tendency parameters of access terminals to screen feature access terminals; a terminal analysis module constructs a data access risk curve for a single feature access terminal based on a data imbalance tendency parameter, and a terminal identification module determines whether to perform data isolation on the feature access terminal based on a risk representation coefficient of the feature access terminal. According to the method, the access terminal with the abnormal risk is quickly identified according to the actual access characteristics of the access terminal, the data processing mode of the access terminal with the abnormal risk is adaptively adjusted, and the processing efficiency and reliability of data privacy protection and compliance use of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, and in particular to a method and system for data privacy protection and compliant use. Background Technology

[0002] In today's digital age, data has become a core asset for the operation and development of enterprises and organizations. From user behavior data to trade secrets, the value of data is becoming increasingly prominent, and the issues of data privacy protection and compliant use are becoming increasingly serious. With the rapid development of information technology, internal data breaches occur frequently. Many internal personnel with legitimate data access rights may abuse their privileges due to profit motives or a lack of security awareness, exporting or spying on private data that is not essential to their business. These behaviors not only seriously infringe on users' privacy rights, but also bring huge reputational losses and legal risks to enterprises and organizations. Traditional data access monitoring methods are mostly based on simple access control and limited log recording, which makes it difficult to accurately detect the covert behavior of internal personnel abusing their privileges. Internal personnel may use legitimate privileges as a cover to export data, which is difficult to detect in a timely manner through conventional means, resulting in misjudgments and omissions. This makes it difficult to identify and deal with the real risks in a timely manner. Therefore, improving the processing efficiency and reliability of data privacy protection and compliant use systems is an urgent technical problem to be solved.

[0003] For example, Chinese Patent Publication No. CN118981797B discloses a method and device for personal information security protection, belonging to the field of personal information security protection technology. The method includes: verifying the identity information of the information collector and determining whether the information collector has the necessary authorization based on the identity information; verifying the compliance of the collection request through a compliance check algorithm, and requesting authorization from the user after successful verification; encrypting the data in the data card using a data card encryption algorithm, and decrypting and connecting the data after user authorization; monitoring the information collector's collection behavior in real time, and immediately issuing a warning to the user and terminating the collection behavior if abnormal collection behavior is detected; and regularly updating the compliance check algorithm and the data card encryption algorithm. This automatically identifies and verifies the legitimacy of the data collector, while strengthening the protection barrier for the user's data card, improving the security and privacy of the user's personal information.

[0004] The following problems still exist in the existing technology: Existing technologies do not consider the possibility that internal personnel with legitimate data access rights may abuse their privileges to export or spy on private data that is not necessary for their business. Existing technologies cannot quickly identify access terminals with abnormal risks based on the actual access characteristics of the access terminals, nor can they adaptively adjust the data processing methods for access terminals with abnormal risks, thus affecting the processing efficiency and reliability of data privacy protection and compliant use systems. Summary of the Invention

[0005] To address this, the present invention provides a data privacy protection and compliant use method and system to overcome the problems of existing technologies that cannot quickly identify access terminals with abnormal risks based on the actual access characteristics of the access terminals, and cannot adaptively adjust the data processing methods for access terminals with abnormal risks, thus affecting the processing efficiency and reliability of the data privacy protection and compliant use system.

[0006] To achieve the above objectives, the present invention provides a method and system for data privacy protection and compliant use, comprising: The data acquisition module is used to acquire the access permission characteristics, access data characteristics, and access data traffic parameters of each access terminal. The access permission characteristics include the frequency of access to non-authorized associated data and the deviation parameter of data export volume. The access data characteristics include the growth parameter of non-authorized data access and the proportion of privacy data access time. A terminal preprocessing module, which is connected to the data acquisition module, is used to acquire the access permission characteristics of each access terminal within a preset monitoring period, and determine the access offset tendency parameter of the access terminal based on the access permission characteristics, so as to filter a number of characteristic access terminals. The terminal analysis module is connected to the data acquisition module and the terminal preprocessing module respectively, and is used to construct a data access risk curve for a single characteristic access terminal based on several data imbalance tendency parameters. Each of the data imbalance tendency parameters is determined by the access data characteristics of a single characteristic access terminal in the corresponding characteristic sub-period, and each characteristic sub-period is determined based on the usage offset tendency parameters of the characteristic access terminal. The terminal identification module, together with the data acquisition module and the terminal analysis module, is used to determine the risk characterization coefficient based on the data access risk curve, and to determine whether to isolate the characteristic access terminal based on the risk characterization coefficient.

[0007] Further, the terminal preprocessing module is used to determine the access offset tendency parameter based on a weighted sum of the first access offset feature and the second access offset feature, wherein, The first access offset feature is the ratio of the access frequency of non-authorized associated data to the threshold of the access frequency of non-authorized associated data; The second access offset feature is the ratio of the data export deviation parameter to the data export deviation parameter threshold.

[0008] Furthermore, the terminal preprocessing module is also used to filter the access terminal as a characteristic access terminal based on the determination result that the access offset tendency parameter of the access terminal meets the characteristic access terminal conditions, wherein, The characteristic access terminal condition is that the access offset tendency parameter of the access terminal exceeds a preset access offset tendency parameter threshold.

[0009] Furthermore, the terminal preprocessing module is used to determine the usage offset tendency parameter of each monitoring sub-period based on the difference between the maximum value and the minimum value of the access data traffic parameter in each monitoring sub-period. The monitoring sub-period is obtained by dividing the preset monitoring period through the terminal preprocessing module.

[0010] Furthermore, the terminal preprocessing module determines the monitored sub-period as a characteristic sub-period based on the determination result that the usage offset tendency parameter of the monitored sub-period meets the characteristic sub-period conditions, wherein, The characteristic sub-time period condition is that the offset tendency parameter used exceeds a preset offset tendency parameter threshold.

[0011] Furthermore, the terminal analysis module is used to acquire access data characteristics of characteristic access terminals within characteristic sub-time periods, and to determine the data imbalance tendency parameter based on the sum of the first imbalance tendency feature and the second imbalance tendency feature, wherein, The first imbalance tendency feature is the ratio of the non-authorized data access growth parameter to the non-authorized data access growth parameter threshold; The second imbalance tendency feature is the ratio of the percentage of time spent accessing private data to the threshold percentage of time spent accessing private data; The non-authorized data access growth parameter is the ratio of the difference between the number of non-authorized associated data accesses at the last moment of the characteristic sub-period and the number of non-authorized associated data accesses at the first moment of the characteristic sub-period to the duration of the characteristic sub-period. The privacy data access duration percentage is the ratio of the privacy data access duration to the duration of the characteristic sub-period.

[0012] Furthermore, the terminal analysis module is used to fit each of the access risk fluctuation points to construct the data access risk curve. The access risk fluctuation points are determined based on the data imbalance tendency parameter and the characteristic sub-period in which the data imbalance tendency parameter is located. The horizontal axis of the coordinate system in which the data access risk curve is located is time, and the vertical axis is the numerical value of the data imbalance tendency parameter.

[0013] Furthermore, the terminal identification module is used to determine a first risk characterization coefficient and a second risk characterization coefficient based on the data misalignment tendency parameter at each access risk fluctuation point on the data access risk curve, wherein, The first risk characterization coefficient is the difference between the data misalignment tendency parameter of the latter access risk fluctuation point and the data misalignment tendency parameter of the former access risk fluctuation point among two adjacent access risk fluctuation points. The second risk characterization coefficient is the absolute value of the slope difference at adjacent access risk fluctuation points.

[0014] Furthermore, the terminal identification module is used to determine whether to perform data isolation on the feature access terminal based on the judgment result that the risk characterization coefficient of the feature access terminal meets the data isolation condition, wherein, The data isolation condition is that the first risk characterization coefficient exceeds a preset first risk characterization coefficient threshold, and the second risk characterization coefficient exceeds a preset second risk characterization coefficient threshold.

[0015] This invention also provides a method for data privacy protection and compliant use, including: Within a preset monitoring period, the access permission characteristics of each access terminal are acquired, and the access offset tendency parameters of the access terminals are determined based on the access permission characteristics in order to filter characteristic access terminals. The characteristic sub-time period is determined based on the usage offset tendency parameter of the characteristic access terminal; Within the characteristic sub-period, a data misalignment tendency parameter is determined based on the access data characteristics of the characteristic access terminal to determine the data access risk curve; Based on the data access risk curve, a risk characterization coefficient is determined, and based on the risk characterization coefficient of the characteristic access terminal, it is determined whether to isolate the characteristic access terminal.

[0016] Compared with existing technologies, the beneficial effects of this invention are as follows: This invention sets up a data acquisition module, a terminal preprocessing module, a terminal analysis module, and a terminal identification module. The data acquisition module acquires the access permission characteristics, access data characteristics, and access data traffic parameters of each access terminal. The terminal preprocessing module acquires the access permission characteristics of each access terminal within a preset monitoring period and determines the access offset tendency parameters of the access terminals based on the access permission characteristics to filter out several characteristic access terminals. The terminal analysis module constructs a data access risk curve for each characteristic access terminal based on several data imbalance tendency parameters. Each data imbalance tendency parameter is determined by the access data characteristics of a single characteristic access terminal within a corresponding characteristic sub-period, and each characteristic sub-period is determined based on the usage offset tendency parameters of the characteristic access terminal. The terminal identification module determines the risk characterization coefficient based on the data access risk curve and determines whether to isolate the characteristic access terminal based on the risk characterization coefficient. Thus, it realizes the rapid identification of access terminals with abnormal risks based on the actual access characteristics of the access terminals, adaptively adjusts the data processing method for access terminals with abnormal risks, and improves the processing efficiency and reliability of the data privacy protection and compliant use system.

[0017] In particular, this invention uses a terminal preprocessing module to determine the access offset tendency parameter of the access terminal based on access permission characteristics to screen characteristic access terminals. It can be understood that the first access offset feature, determined by the frequency of access to non-permission-related data, and the second access offset feature, determined by the deviation parameter of data export volume, comprehensively consider two key access permission characteristics. This more comprehensively reflects the degree of abnormality of the access terminal, reducing misjudgments or omissions caused by fluctuations in a single parameter. The screened characteristic access terminals are more consistent with actual risk situations, and their potential abuse of permissions is more targeted. Subsequent analysis of these terminals can focus more on high-risk objects, improving credibility and the efficiency of risk identification in the entire system. This provides reliable support for the final risk assessment and data isolation decisions. By determining the access offset tendency parameter of the access terminal based on access permission characteristics to screen characteristic access terminals, this invention achieves rapid identification of access terminals with abnormal risks based on their actual access characteristics, improving the processing efficiency and reliability of the data privacy protection and compliant use system.

[0018] In particular, this invention uses a terminal analysis module to determine characteristic sub-periods based on the usage offset tendency parameters of characteristic access terminals. This means that determining characteristic sub-periods pinpoints the specific time periods during which abnormal data access behavior occurs within the monitored period, avoiding indiscriminate analysis of the entire monitoring period, reducing interference from invalid data, and making subsequent data analysis of characteristic sub-periods more focused, significantly improving the efficiency of risk analysis. Characteristic sub-periods are periods of abnormal data traffic fluctuations in characteristic access terminals. These drastic fluctuations in data traffic are often closely related to the abuse of privileges by internal personnel, such as batch data export or large-scale snooping on unauthorized data in a short period. Based on these characteristics... Using sub-periods as the analysis object allows for more targeted capture of the characteristics of risky behaviors, providing high-quality analytical samples for subsequent calculations of data imbalance tendency parameters and plotting data access risk curves. Furthermore, refining the monitoring period into sub-periods and selecting characteristic sub-periods enables the system to track changes in the risky behaviors of characteristic access terminals from a time perspective. Analysis of different characteristic sub-periods reveals the patterns and durations of risky behaviors, providing precise time-based evidence for dynamic risk assessment and timely intervention. Ultimately, this allows for the determination of characteristic sub-periods based on the actual access characteristics of the access terminals, improving the processing efficiency and reliability of the data privacy protection and compliant use system.

[0019] In particular, this invention uses a terminal analysis module to determine a data imbalance tendency parameter based on the access data characteristics of characteristic access terminals within a specific sub-period, thereby determining a data access risk curve. This allows for precise quantification of risk levels, improving the objectivity of risk assessment. By determining the data imbalance tendency parameter through a first imbalance tendency feature and a second imbalance tendency feature, the abnormality levels of two key access data characteristics are quantitatively integrated, avoiding biases in subjective judgment and enabling objective and accurate measurement of risk levels. This provides comparable quantitative indicators for subsequent risk analysis. The data access risk curve, with time as the horizontal axis and the data imbalance tendency parameter as the vertical axis, reflects the access risk waves across multiple characteristic sub-periods. The curve, formed by dynamic point fitting, intuitively displays the risk changes of characteristic access terminals at different times. By leveraging the waveform characteristics of the curve, the development trend of risks can be tracked in real time, and signs of risk escalation can be detected in a timely manner, providing a timely basis for rapid response and intervention. Analyzing these characteristics within characteristic sub-periods can accurately capture the intensity and persistence of risky behaviors. The risk curve constructed based on this can further extend this targeting to the time dimension, ensuring that the analysis always revolves around the core risk points, thus improving the effectiveness of risk analysis. In turn, it enables the determination of data access risk curves based on the actual access characteristics of access terminals, improving the processing efficiency and reliability of data privacy protection and compliant use systems.

[0020] In particular, this invention uses a terminal identification module to determine whether to isolate data from characteristic access terminals based on risk characterization coefficients. The first risk characterization coefficient represents the increase or decrease in risk through the difference in data imbalance tendency parameters between adjacent access risk fluctuation points. The second risk characterization coefficient represents the intensity of risk curve fluctuations through the average of the absolute values ​​of the slope differences between adjacent characteristic sub-periods. The combination of these two coefficients captures the dynamic characteristics of risk from different dimensions, considering both the growth trend and the stability of risk fluctuations. This effectively avoids misjudgment and isolation due to accidental risk fluctuations, or losses caused by failure to isolate in a timely manner due to continuously escalating risks. It improves the accuracy of risk response and makes risk assessment more scientific and comprehensive. Data isolation operations triggered by this can be promptly blocked before risky behavior causes substantial harm. Precise measures are taken for high-risk terminals, minimizing the risk of data leakage and enhancing the timeliness and targeting of risk prevention and control. Furthermore, it enables adaptive adjustment of data processing methods for access terminals with abnormal risks based on their actual access characteristics, improving the processing efficiency and reliability of the data privacy protection and compliant use system. Attached Figure Description

[0021] Figure 1 This is a functional block diagram of the data privacy protection and compliant use system according to an embodiment of the present invention; Figure 2This is a flowchart illustrating the logic of the terminal preprocessing module filtering features to access the terminal in an embodiment of the present invention. Figure 3 This is a flowchart illustrating the logic of the terminal preprocessing module determining characteristic sub-time periods in an embodiment of the present invention. Figure 4 This is a flowchart illustrating the steps of a data privacy protection and compliant usage method according to an embodiment of the present invention. Detailed Implementation

[0022] In order to make the objects and advantages of the present invention more clearly understood, the present invention is further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0023] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.

[0024] It should be noted that in the description of this invention, the terms "upper," "lower," "inner," "outer," etc., which indicate the direction or positional relationship, are based on the direction or positional relationship shown in the drawings. This is only for the convenience of description and is not intended to indicate or imply that the device or element must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation of this invention.

[0025] Furthermore, it should be noted that, in the description of this invention, unless otherwise explicitly specified and limited, the terms "installation" and "connection" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0026] Please see Figure 1 The diagram shown is a functional block diagram of a data privacy protection and compliant use system according to an embodiment of the present invention. The data privacy protection and compliant use system of the present invention includes: The data acquisition module is used to acquire the access permission characteristics, access data characteristics, and access data traffic parameters of each access terminal. The access permission characteristics include the frequency of access to non-authorized associated data and the deviation parameter of data export volume. The access data characteristics include the growth parameter of non-authorized data access and the proportion of privacy data access time. Specifically, the embodiments of the present invention do not impose specific limitations on the structure of the data acquisition module. Preferably, it can be a traffic mirroring device deployed on a network node and a terminal agent program, used to acquire the access permission characteristics, access data characteristics, and access data traffic parameters of each access terminal, which will not be elaborated further.

[0027] Specifically, the frequency of non-authorized associated data access is the total number of times a terminal accesses non-business-related data outside its own authorized scope within a preset monitoring period. The data export deviation parameter is the degree of deviation between the actual amount of data exported by the terminal in a single session and the baseline value of data export in a normal single session under this business scenario. The baseline value can be the average amount of data in historical data based on the data volume of those skilled in the art. In this embodiment of the invention, the method for determining the access terminal's own permission scope data and sensitive privacy data is not specifically limited. A permission feature library can be established by pre-setting a keyword or field library specific to the access terminal's own permission scope, and a sensitive privacy feature library can be established by pre-setting a keyword or field library specific to sensitive privacy data. A text parsing tool is used to scan the transmitted data content and match and identify the content of the transmitted data. This will not be elaborated further.

[0028] A terminal preprocessing module, which is connected to the data acquisition module, is used to acquire the access permission characteristics of each access terminal within a preset monitoring period, and determine the access offset tendency parameter of the access terminal based on the access permission characteristics, so as to filter a number of characteristic access terminals. Specifically, the embodiments of the present invention do not impose specific limitations on the structure of the terminal preprocessing module. Preferably, it can be a microprocessor used to determine the access offset tendency parameters of the accessing terminal and filter several characteristic accessing terminals, which will not be elaborated further.

[0029] Specifically, the preset monitoring period can be set by those skilled in the art based on the accuracy requirements of data privacy protection and compliant use of the system. The higher the accuracy requirement, the shorter the preset monitoring period. The value range of the preset monitoring period can be [10, 20], with the interval unit being min. Preferably, the preset monitoring period can be 15 min.

[0030] The terminal analysis module is connected to the data acquisition module and the terminal preprocessing module respectively, and is used to construct a data access risk curve for a single characteristic access terminal based on several data imbalance tendency parameters. Each of the data imbalance tendency parameters is determined by the access data characteristics of a single characteristic access terminal in the corresponding characteristic sub-period, and each characteristic sub-period is determined based on the usage offset tendency parameters of the characteristic access terminal. Specifically, the embodiments of the present invention do not specifically limit the structure of the terminal analysis module. Preferably, it can be a processor used in a computer to construct a data access risk curve for a single feature access terminal based on several data imbalance tendency parameters, and to screen several feature access terminals. This will not be elaborated further.

[0031] The terminal identification module, together with the data acquisition module and the terminal analysis module, is used to determine the risk characterization coefficient based on the data access risk curve, and to determine whether to isolate the characteristic access terminal based on the risk characterization coefficient.

[0032] Specifically, the embodiments of the present invention do not impose specific limitations on the structure of the terminal identification module. Preferably, it can be a microprocessor used to determine the risk characterization coefficient and determine whether to isolate the feature access terminal from data. This will not be elaborated further.

[0033] Specifically, the terminal preprocessing module is used to determine the access offset tendency parameter based on a weighted sum of the first access offset feature and the second access offset feature, wherein, The first access offset feature is the ratio of the access frequency of non-authorized associated data to the threshold of the access frequency of non-authorized associated data; The second access offset feature is the ratio of the data export deviation parameter to the data export deviation parameter threshold.

[0034] Specifically, in actual data access scenarios, the data export deviation parameter can more directly reflect whether the terminal has engaged in risky behavior of exporting non-business data in batches. Its threat to data privacy and security is more direct and its impact may be wider. Under this premise, it can better reflect the decisive influence on access permission deviation. At the same time, the weight values ​​are selected according to the frequency of non-permission-related data access in historical data and the degree of influence of the data export deviation parameter on the calculation results. Therefore, in implementation, the risk weight of data export behavior is given priority. Thus, a slightly higher weight is assigned to the second access deviation feature. When performing weighted summation, the weight of the first access deviation feature can be set to 0.4, and the weight of the second access deviation feature can be set to 0.6.

[0035] In this embodiment, the purpose of setting the non-authorized associated data access frequency threshold and the data export deviation parameter threshold is to characterize the situation where the access behavior poses a significant threat to data privacy and security. By calling several historical access data, the historical data of the non-authorized associated data access frequency and the historical data of the data export deviation parameter of the accessing terminal within the same preset monitoring period are obtained. The average non-authorized associated data access frequency and the average data export deviation parameter are calculated. Based on the purpose of setting the above two thresholds, the non-authorized associated data access frequency threshold is determined as the product of the average non-authorized associated data access frequency and the first deviation coefficient, and the data export deviation parameter threshold is determined as the product of the average data export deviation parameter and the second deviation coefficient. The value range of the first deviation coefficient can be [1.1, 1.3], and the value range of the second deviation coefficient can be [1.2, 1.4]. Preferably, the first deviation coefficient can be 1.2 and the second deviation coefficient can be 1.3.

[0036] Please see Figure 2 As shown, this is a flowchart illustrating the logic of the terminal preprocessing module in an embodiment of the present invention for filtering characteristic access terminals. The terminal preprocessing module is further used to filter the access terminal as a characteristic access terminal based on the determination result that the access offset tendency parameter of the access terminal meets the characteristic access terminal condition. If the access offset tendency parameter of the access terminal does not meet the characteristic access terminal conditions, the terminal preprocessing module will not filter the access terminal. The characteristic access terminal condition is that the access offset tendency parameter of the access terminal exceeds a preset access offset tendency parameter threshold.

[0037] Specifically, the preset access offset tendency parameter threshold is the product of the access offset tendency parameter reference value and the access offset coefficient. The access offset tendency parameter reference value is the average value of the access offset tendency parameter in historical data. The access offset coefficient can be set by those skilled in the art based on the accuracy requirements of data privacy protection and compliant use of the system. The higher the accuracy requirement, the smaller the access offset coefficient is set. The value range of the access offset coefficient can be [1.1, 1.4], preferably 1.2.

[0038] Specifically, this embodiment of the invention uses a terminal preprocessing module to determine the access offset tendency parameter of the accessing terminal based on access permission characteristics to filter characteristic accessing terminals. It can be understood that the first access offset characteristic, determined by the frequency of access to non-permission-related data, and the second access offset characteristic, determined by the deviation parameter of data export volume, comprehensively consider two key access permission characteristics. This more comprehensively reflects the degree of abnormality of the accessing terminal, reducing misjudgments or omissions caused by fluctuations in a single parameter. The filtered characteristic accessing terminals are more consistent with actual risk situations, and their potential abuse of permissions is more targeted. Subsequent analysis of these terminals can focus more on high-risk objects, improving credibility and the efficiency of risk identification in the entire system. This provides reliable support for the final risk assessment and data isolation decisions. This embodiment of the invention uses access permission characteristics to determine the access offset tendency parameter of the accessing terminal to filter characteristic accessing terminals. Therefore, it achieves rapid identification of accessing terminals with abnormal risks based on the actual access characteristics of the accessing terminals, improving the processing efficiency and reliability of the data privacy protection and compliant use system.

[0039] Specifically, it's understandable that internal personnel abusing their privileges manifests in two core aspects: first, accessing non-authorized related data beyond the scope of business operations; and second, exporting data in quantities deviating from normal business requirements. The frequency of accessing non-authorized related data reflects the frequency of accessing non-business data; the higher the frequency, the more likely there is a snooping on of non-essential private data. The deviation parameter for the data export volume reflects the degree of deviation between the data export behavior and normal business operations; the greater the deviation, the higher the risk of bulk data export. The first and second access offset features quantify the two behavioral characteristics into multiples relative to their respective thresholds, achieving different dimensions... The parameter normalization process, through weighted summation to obtain the access offset tendency parameter, integrates the influence of two risk behaviors, making the parameter more closely match the actual risk assessment needs. The larger the access offset tendency parameter, the more abnormal the terminal is in terms of unauthorized data access or data export, and the more attention it needs to be paid to it. It is then screened as a characteristic access terminal, ensuring that the system can prioritize in-depth monitoring and analysis of high-risk terminals, thereby effectively preventing the risk of data privacy leakage caused by internal personnel abusing their privileges. In addition, it enables the rapid identification of access terminals with abnormal risks based on the actual access characteristics of the access terminals, improving the processing efficiency and reliability of the data privacy protection and compliant use system.

[0040] Specifically, the terminal preprocessing module is used to determine the usage offset tendency parameter of each monitoring sub-period based on the difference between the maximum value and the minimum value of the access data traffic parameter in each monitoring sub-period. The monitoring sub-period is obtained by dividing the preset monitoring period through the terminal preprocessing module.

[0041] Specifically, the duration of a monitoring sub-period is the product of the preset duration of the monitoring period and the sub-period segmentation factor. The sub-period segmentation factor can be set by those skilled in the art based on the accuracy requirements of data privacy protection and compliant use of the system. The higher the accuracy requirement, the smaller the sub-period segmentation factor is set. The value range of the sub-period segmentation factor can be [0.1, 0.3]. Preferably, the sub-period segmentation factor can be 0.2. The monitoring sub-period contains several monitoring moments. The interval between adjacent monitoring moments is the product of the duration of the monitoring sub-period and the moment segmentation factor. The moment segmentation factor can be set by those skilled in the art based on the accuracy requirements of data privacy protection and compliant use of the system. The higher the accuracy requirement, the smaller the moment segmentation factor is set. The value range of the moment segmentation factor can be [0.2, 0.4]. Preferably, the sub-period segmentation factor can be 0.3.

[0042] Please see Figure 3 As shown, this is a flowchart illustrating the logic of the terminal preprocessing module determining characteristic sub-time periods in an embodiment of the present invention. The terminal preprocessing module determines the monitored sub-time period as a characteristic sub-time period based on the determination result that the usage offset tendency parameter of the monitored sub-time period meets the conditions for a characteristic sub-time period. If the usage offset tendency parameter of the monitored sub-period does not meet the characteristic sub-period conditions, the terminal preprocessing module will not filter the monitored sub-period. The characteristic sub-time period condition is that the offset tendency parameter used exceeds a preset offset tendency parameter threshold.

[0043] Specifically, the preset threshold for the offset tendency parameter is the product of the offset tendency parameter reference value and the offset coefficient. The offset tendency parameter reference value is the average value of the offset tendency parameter in historical data. The offset coefficient can be set by those skilled in the art based on the accuracy requirements of data privacy protection and compliant use of the system. The higher the accuracy requirement, the smaller the offset coefficient should be. The value range of the offset coefficient can be [1.1, 1.3], preferably 1.2.

[0044] Specifically, in this embodiment of the invention, the terminal analysis module determines characteristic sub-periods based on the usage offset tendency parameters of the characteristic access terminal. It can be understood that determining the characteristic sub-periods pinpoints the specific time periods during which the characteristic access terminal exhibits abnormal data access behavior within the monitoring period. This avoids indiscriminate analysis of the entire monitoring period, reduces interference from invalid data, and makes subsequent data analysis for the characteristic sub-periods more focused, significantly improving the efficiency of risk analysis. The characteristic sub-periods are periods of abnormal fluctuation in the data traffic of the characteristic access terminal. Drastic fluctuations in data traffic are often closely related to the abuse of permissions by internal personnel, such as batch exporting data or rapidly accessing large amounts of unauthorized data. Using characteristic sub-periods as the analysis object enables more targeted capture of risky behavior characteristics, providing high-quality analytical samples for subsequent calculations of data imbalance tendency parameters and plotting data access risk curves. At the same time, by refining the monitoring period into sub-periods and selecting characteristic sub-periods, the system can track changes in risky behavior of characteristic access terminals from a time dimension. By analyzing different characteristic sub-periods, information such as the occurrence pattern and duration of risky behavior can be grasped, providing accurate time-dimensional basis for dynamic risk assessment and timely intervention measures. Thus, it is possible to determine characteristic sub-periods based on the actual access characteristics of access terminals, improving the processing efficiency and reliability of the data privacy protection and compliant use system.

[0045] Specifically, it is understandable that when internal personnel abuse their privileges to export large amounts of data in bulk or spy on a large amount of non-business-essential private data, the data transmission volume will far exceed that of normal business operations in a short period of time, causing drastic fluctuations in access data traffic parameters. For example, in normal business operations, the data traffic in a certain monitoring sub-period may fluctuate between 10MB and 20MB. However, when there is bulk data export or large-scale spying on non-business-essential private data, the traffic in that sub-period may surge to over 100MB. At the same time, there may be lower traffic values ​​due to operation intervals, which makes the difference between the maximum and minimum traffic values ​​in that sub-period, i.e., the usage offset tendency parameter, significantly larger. The larger the usage offset tendency parameter, the greater the fluctuation of data traffic in that sub-period, and the higher the risk of privilege abuse. By objectively capturing potential risk periods through parameter changes, subsequent data analysis within the characteristic sub-periods focuses on the time window in which risky behavior is most likely to occur. The results can more realistically reflect the risk status of characteristic access terminals, providing reliable time dimension support for the risk assessment and decision-making of the entire system. In this way, characteristic sub-periods can be determined based on the actual access characteristics of access terminals, improving the processing efficiency and reliability of the data privacy protection and compliant use system.

[0046] Specifically, the terminal analysis module is used to acquire access data characteristics of characteristic access terminals within characteristic sub-time periods, and to determine the data imbalance tendency parameter based on the sum of the first imbalance tendency feature and the second imbalance tendency feature, wherein, The first imbalance tendency feature is the ratio of the non-authorized data access growth parameter to the non-authorized data access growth parameter threshold; The second imbalance tendency feature is the ratio of the percentage of time spent accessing private data to the threshold percentage of time spent accessing private data; The non-authorized data access growth parameter is the ratio of the difference between the number of non-authorized associated data accesses at the last moment of the characteristic sub-period and the number of non-authorized associated data accesses at the first moment of the characteristic sub-period to the duration of the characteristic sub-period. The privacy data access duration percentage is the ratio of the privacy data access duration to the duration of the characteristic sub-period.

[0047] In this embodiment, the purpose of setting the threshold for the non-authorized data access growth parameter and the threshold for the proportion of privacy data access duration are both to characterize the situation where the data access behavior of the characteristic access terminal deviates from the normal business scope and there is a risk of data imbalance during the characteristic sub-period. By calling the historical access data of the characteristic access terminal several times, historical data of the non-authorized data access growth parameter and the historical data of the proportion of privacy data access duration under the same characteristic sub-period length are obtained, and the mean of the non-authorized data access growth parameter and the mean of the proportion of privacy data access duration are calculated. Based on the purpose of setting the above two thresholds, the threshold for the non-authorized data access growth parameter is determined as the product of the mean of the non-authorized data access growth parameter and the first imbalance coefficient, and the threshold for the proportion of privacy data access duration is determined as the product of the mean of the proportion of privacy data access duration and the second imbalance coefficient. The value range of the first imbalance coefficient can be [1.2, 1.4], and the value range of the second imbalance coefficient can be [1.3, 1.5]. Preferably, the first imbalance coefficient can be 1.35 and the second imbalance coefficient can be 1.4.

[0048] Specifically, the terminal analysis module is used to fit each of the access risk fluctuation points to construct the data access risk curve. The access risk fluctuation points are determined based on the data imbalance tendency parameter and the characteristic sub-period in which the data imbalance tendency parameter is located. The horizontal axis of the coordinate system in which the data access risk curve is located is time, and the vertical axis is the magnitude of the data imbalance tendency parameter.

[0049] Specifically, there are no restrictions on the method for constructing the data access risk curve. For example, the data access risk curve can be fitted using MATLAB correlation fitting software, which will not be elaborated further.

[0050] Specifically, the data access risk curve connects each access risk fluctuation point with a smooth curve. The access risk fluctuation point is determined based on the midpoint of the data imbalance tendency parameter and the characteristic sub-period in which the data imbalance tendency parameter is located.

[0051] Specifically, in this embodiment of the invention, the terminal analysis module determines a data imbalance tendency parameter based on the access data characteristics of characteristic access terminals within a characteristic sub-period, thereby determining a data access risk curve. This allows for precise quantification of risk levels, improving the objectivity of risk assessment. By determining the data imbalance tendency parameter through a first imbalance tendency feature and a second imbalance tendency feature, the abnormality levels of two key access data features are quantitatively integrated, avoiding biases in subjective judgment and enabling objective and accurate measurement of risk levels. This provides comparable quantitative indicators for subsequent risk analysis. The data access risk curve is plotted with time on the horizontal axis and the data imbalance tendency parameter on the vertical axis, based on access data from multiple characteristic sub-periods. The risk fluctuation points are fitted to visually demonstrate the risk changes of characteristic access terminals at different times. By leveraging the waveform characteristics of the curve, the development trend of risks can be tracked in real time, and signs of risk escalation can be detected in a timely manner, providing a timely basis for rapid response and intervention. Analyzing these characteristics within characteristic sub-periods can accurately capture the intensity and persistence of risky behaviors. The risk curve constructed based on this can further extend this targeting to the time dimension, ensuring that the analysis always revolves around the core risk points, thus improving the effectiveness of risk analysis. In turn, it enables the determination of data access risk curves based on the actual access characteristics of access terminals, improving the processing efficiency and reliability of data privacy protection and compliant use systems.

[0052] Specifically, it is understandable that the risky behavior of internal personnel abusing their privileges will exhibit two typical characteristics during the characteristic sub-period: first, a rapid increase in access to non-authorized data, manifested as a frequent expansion of the scope of access to non-business data within a short period; and second, a sustained focus on privacy data, manifested as a high proportion of time spent accessing privacy data during the characteristic sub-period. The non-authorized data access growth parameter, which is the ratio of the increase in the number of non-authorized accesses to related data to the duration within the characteristic sub-period, represents the urgency and expansion speed of accessing non-authorized data. The first imbalance tendency characteristic quantifies the degree of deviation of this growth from the normal level. The privacy data access duration proportion, which is the ratio of the privacy data access duration to the duration of the characteristic sub-period, represents the focus on privacy data. Based on the depth of attention, the second dissonance tendency feature quantifies the degree of abnormality of this attention relative to routine business. The data access risk curve integrates the data dissonance tendency parameters of multiple characteristic sub-periods, transforming discrete risk quantification values ​​into continuous trend curves. The abuse behavior of characteristic terminals is often not isolated, but exhibits continuous and changing characteristics in the time dimension. By constructing a data access risk curve, the changing trends and characteristics can be intuitively reflected, accurately capturing the intensity and dynamic changes of risky behavior, effectively improving the system's ability to identify and prevent internal personnel from abusing their privileges. Thus, it realizes the determination of the data access risk curve based on the actual access characteristics of the access terminal, improving the processing efficiency and reliability of the data privacy protection and compliant use system.

[0053] Specifically, the terminal identification module is used to determine a first risk characterization coefficient and a second risk characterization coefficient based on the data imbalance tendency parameter at each access risk fluctuation point on the data access risk curve, wherein... The first risk characterization coefficient is the difference between the data misalignment tendency parameter of the latter access risk fluctuation point and the data misalignment tendency parameter of the former access risk fluctuation point among two adjacent access risk fluctuation points. The second risk characterization coefficient is the absolute value of the slope difference at adjacent access risk fluctuation points.

[0054] Specifically, the terminal identification module is used to determine whether the risk characterization coefficient of the feature-accessed terminal meets the data isolation conditions, and then to determine whether to perform data isolation on the feature-accessed terminal. If the risk characterization coefficient of the feature access terminal does not meet the data isolation conditions, the terminal identification module determines that the feature access terminal will not be isolated from the data. The data isolation condition is that the first risk characterization coefficient exceeds a preset first risk characterization coefficient threshold, and the second risk characterization coefficient exceeds a preset second risk characterization coefficient threshold.

[0055] Specifically, the preset first risk characterization coefficient threshold is the product of the first risk characterization coefficient reference value and the first risk coefficient, and the preset second risk characterization coefficient threshold is the product of the second risk characterization coefficient reference value and the second risk coefficient. The first risk characterization coefficient reference value is the average value of the first risk characterization coefficient in historical data, and the second risk characterization coefficient is the average value of the second risk characterization coefficient in historical data. The first risk coefficient and the second risk coefficient can be set by those skilled in the art according to the accuracy requirements of data privacy protection and compliant use of the system. The higher the accuracy requirement, the smaller the first risk coefficient and the second risk coefficient are set. The value range of the first risk coefficient can be [1.15, 1.3], and the value range of the second risk coefficient can be [1.2, 1.35]. Preferably, the first risk coefficient can be 1.2 and the second risk coefficient can be 1.3.

[0056] Specifically, in this embodiment of the invention, the terminal identification module determines whether to isolate the characteristic access terminal based on the risk characterization coefficient of the characteristic access terminal. It can be understood that the first risk characterization coefficient, through the difference in data imbalance tendency parameters between adjacent access risk fluctuation points, can characterize the increase or decrease in risk. The second risk characterization coefficient, through the average of the absolute values ​​of the slope differences between adjacent characteristic sub-periods, characterizes the intensity of the risk curve fluctuation. The combination of these two coefficients captures the dynamic characteristics of risk from different dimensions, considering both the growth trend and the stability of risk fluctuations. This effectively avoids misjudgment and isolation due to accidental risk fluctuations, or losses caused by the failure to isolate in a timely manner due to continuously escalating risks. It improves the accuracy of risk response and makes risk assessment more scientific and comprehensive. Based on this, the data isolation operation can be timely blocked before risky behavior causes substantial harm. Precise measures are taken for high-risk terminals, minimizing the risk of data leakage and enhancing the timeliness and targeting of risk prevention and control. Furthermore, it enables adaptive adjustment of the data processing method for access terminals with abnormal risks according to the actual access characteristics of the access terminal, improving the processing efficiency and reliability of the data privacy protection and compliant use system.

[0057] Specifically, it's understandable that as abuse intensifies, the data imbalance propensity parameter will continue to rise, and the difference between adjacent fluctuation points—the first risk characterization coefficient—will increase. When attempting to evade monitoring, individuals may deliberately adjust their behavior, causing frequent changes in the slope of the risk curve. This leads to a larger absolute value of the slope difference between adjacent sub-periods—the second risk characterization coefficient. The first risk characterization coefficient reflects the growth trend of risk; a larger value indicates a faster rate of risk escalation in a short period, suggesting that abuse is more likely to be in an active expansion phase, requiring urgent intervention. The second risk characterization coefficient reflects the stability of the risk curve; a larger value indicates more drastic fluctuations in risky behavior, making intervention more likely. Attempts to deliberately conceal their whereabouts must be controlled promptly. The data isolation condition is set so that both coefficients exceed the threshold because a single coefficient exceeding the threshold may lead to misjudgment. For example, if only the first coefficient exceeds the threshold, it may be a short-term operational error; if only the second coefficient exceeds the threshold, it may be a normal business fluctuation. However, if both exceed the threshold simultaneously, it indicates a systemic abuse of privileges. This allows for more accurate identification of high-risk terminals that truly need isolation, avoiding misjudgments that could affect normal business response. Furthermore, it enables adaptive adjustment of data processing methods for access terminals with abnormal risks based on their actual access characteristics, improving the efficiency and reliability of the data privacy protection and compliant use system.

[0058] Please see Figure 4 The diagram illustrates the steps of a data privacy protection and compliant use method according to an embodiment of the present invention. The present invention also provides a data privacy protection and compliant use method, comprising: Step S100: Obtain the access permission characteristics of each access terminal within a preset monitoring period, and determine the access offset tendency parameter of the access terminal based on the access permission characteristics in order to filter characteristic access terminals. Step S200: Determine the characteristic sub-time period based on the usage offset tendency parameter of the characteristic access terminal; Step S300: Within the characteristic sub-period, determine the data misalignment tendency parameter based on the access data characteristics of the characteristic access terminal to determine the data access risk curve; Step S400: Determine the risk characterization coefficient based on the data access risk curve, and determine whether to perform data isolation on the feature access terminal based on the risk characterization coefficient of the feature access terminal.

[0059] Thus far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art may make equivalent changes or substitutions to the relevant technical features, and the technical solutions after such changes or substitutions will fall within the scope of protection of the present invention.

[0060] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A data privacy protection and compliant use system, characterized in that, include: The data acquisition module is used to acquire the access permission characteristics, access data characteristics, and access data traffic parameters of each access terminal. The access permission characteristics include the frequency of access to non-authorized associated data and the deviation parameter of data export volume. The access data characteristics include the growth parameter of non-authorized data access and the proportion of privacy data access time. A terminal preprocessing module, which is connected to the data acquisition module, is used to acquire the access permission characteristics of each access terminal within a preset monitoring period, and determine the access offset tendency parameter of the access terminal based on the access permission characteristics, so as to filter a number of characteristic access terminals. The terminal analysis module is connected to the data acquisition module and the terminal preprocessing module respectively, and is used to construct a data access risk curve for a single characteristic access terminal based on several data imbalance tendency parameters. Each of the data imbalance tendency parameters is determined by the access data characteristics of a single characteristic access terminal in the corresponding characteristic sub-period, and each characteristic sub-period is determined based on the usage offset tendency parameters of the characteristic access terminal. The terminal identification module, together with the data acquisition module and the terminal analysis module, is used to determine the risk characterization coefficient based on the data access risk curve, and to determine whether to isolate the characteristic access terminal based on the risk characterization coefficient.

2. The data privacy protection and compliant use system according to claim 1, characterized in that, The terminal preprocessing module is used to determine the access offset tendency parameter based on a weighted sum of the first access offset feature and the second access offset feature, wherein, The first access offset feature is the ratio of the access frequency of non-authorized associated data to the threshold of the access frequency of non-authorized associated data; The second access offset feature is the ratio of the data export deviation parameter to the data export deviation parameter threshold.

3. The data privacy protection and compliant use system according to claim 2, characterized in that, The terminal preprocessing module is further used to filter the access terminal as a characteristic access terminal based on the determination result that the access offset tendency parameter of the access terminal meets the characteristic access terminal conditions, wherein... The characteristic access terminal condition is that the access offset tendency parameter of the access terminal exceeds a preset access offset tendency parameter threshold.

4. The data privacy protection and compliant use system according to claim 3, characterized in that, The terminal preprocessing module is used to determine the usage offset tendency parameter of each monitoring sub-period based on the difference between the maximum value and the minimum value of the access data traffic parameter in each monitoring sub-period. The monitoring sub-period is obtained by dividing the preset monitoring period through the terminal preprocessing module.

5. The data privacy protection and compliant use system according to claim 4, characterized in that, The terminal preprocessing module determines the monitored sub-period as a characteristic sub-period based on the determination result that the usage offset tendency parameter of the monitored sub-period meets the characteristic sub-period conditions. The characteristic sub-time period condition is that the offset tendency parameter used exceeds a preset offset tendency parameter threshold.

6. The data privacy protection and compliant use system according to claim 5, characterized in that, The terminal analysis module is used to acquire access data characteristics of characteristic access terminals within characteristic sub-time periods, and to determine the data imbalance tendency parameter based on the sum of the first imbalance tendency feature and the second imbalance tendency feature, wherein... The first imbalance tendency feature is the ratio of the non-authorized data access growth parameter to the non-authorized data access growth parameter threshold; The second imbalance tendency feature is the ratio of the percentage of time spent accessing private data to the threshold percentage of time spent accessing private data; The non-authorized data access growth parameter is the ratio of the difference between the number of non-authorized associated data accesses at the last moment of the characteristic sub-period and the number of non-authorized associated data accesses at the first moment of the characteristic sub-period to the duration of the characteristic sub-period. The privacy data access duration percentage is the ratio of the privacy data access duration to the duration of the characteristic sub-period.

7. The data privacy protection and compliant use system according to claim 6, characterized in that, The terminal analysis module is used to fit each of the access risk fluctuation points to construct the data access risk curve. The access risk fluctuation points are determined based on the data imbalance tendency parameter and the characteristic sub-period in which the data imbalance tendency parameter is located. The horizontal axis of the coordinate system in which the data access risk curve is located is time, and the vertical axis is the magnitude of the data imbalance tendency parameter.

8. The data privacy protection and compliant use system according to claim 7, characterized in that, The terminal identification module is used to determine a first risk characterization coefficient and a second risk characterization coefficient based on the data imbalance tendency parameter at each access risk fluctuation point on the data access risk curve, wherein... The first risk characterization coefficient is the difference between the data misalignment tendency parameter of the latter access risk fluctuation point and the data misalignment tendency parameter of the former access risk fluctuation point among two adjacent access risk fluctuation points. The second risk characterization coefficient is the absolute value of the slope difference at adjacent access risk fluctuation points.

9. The data privacy protection and compliant use system according to claim 8, characterized in that, The terminal identification module is used to determine whether the characteristic access terminal meets the data isolation conditions based on the risk characterization coefficient of the characteristic access terminal. The data isolation condition is that the first risk characterization coefficient exceeds a preset first risk characterization coefficient threshold, and the second risk characterization coefficient exceeds a preset second risk characterization coefficient threshold.

10. A method for data privacy protection and compliant use, used in the data privacy protection and compliant use system according to any one of claims 1-9, characterized in that, include: Within a preset monitoring period, the access permission characteristics of each access terminal are acquired, and the access offset tendency parameters of the access terminals are determined based on the access permission characteristics in order to filter characteristic access terminals. The characteristic sub-time period is determined based on the usage offset tendency parameter of the characteristic access terminal; Within the characteristic sub-period, a data misalignment tendency parameter is determined based on the access data characteristics of the characteristic access terminal to determine the data access risk curve; Based on the data access risk curve, a risk characterization coefficient is determined, and based on the risk characterization coefficient of the characteristic access terminal, it is determined whether to isolate the characteristic access terminal.

Citation Information

Patent Citations

  • A personal information security protection method and device

    CN118981797B

  • Information security protection method based on Internet finance and biological recognition and cloud platform

    CN112465503A

  • Data security protection supervision system

    CN119249459A

  • Archive management system and method based on data analysis

    CN119830308A

  • Methods and apparatus for mediating access to derivatives of sensitive data

    US8978159B1