Method, device, equipment, medium and product for uniformly processing data requests

By unifying data requests through a data management platform and employing multiple acquisition modes and encrypted storage and transmission technologies, the problems of low efficiency and high cost in traditional data management have been solved, enabling efficient and secure management of data assets throughout their entire lifecycle.

CN120974532APending Publication Date: 2025-11-18BEIJING ZITIAO NETWORK TECH CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511074517.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Traditional data management technologies have room for improvement in terms of management efficiency, management cost, and management capabilities. In particular, they are difficult to achieve efficient and unified management in the process of decentralized acquisition and use of data assets, resulting in low management efficiency, high costs, and difficulty in covering the data lifecycle.

Method used

Data requests are processed uniformly through a data management platform. Based on the verification of the data request, the acquisition mode is determined from multiple data acquisition modes to obtain the target data. Access is provided based on the scope of use, including multiple modes such as interface, proxy, instruction set and data table. Combined with encrypted storage and secure transmission, unified data collection and distribution are achieved.

Benefits of technology

It improves the security and management efficiency of data assets, reduces management costs, covers the entire data lifecycle, and enhances the controllability and security of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120974532A_ABST
    Figure CN120974532A_ABST
Patent Text Reader

Abstract

According to the embodiment of the invention, a method, a device and equipment for uniformly processing data, a storage medium and a program product are provided. In the method, a data request for target data is obtained, and the data request is related to a data demand scene and at least comprises the use range of the target data. And in response to the fact that the data request passes verification, determining at least one data acquisition mode from a plurality of data acquisition modes based on data protection requirements related to the target data, different data acquisition modes in the plurality of data acquisition modes being configured to acquire business data having different data protection requirements. And acquiring target data according to the at least one data acquisition mode. And providing access to the target data based on the range of use.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Example embodiments of the present disclosure generally relate to the field of computers, and in particular, to a method, apparatus, device, computer-readable storage medium, and computer program product for unified processing of data requests. BACKGROUND

[0002] With the continuous growth of the digital economy, data assets have become an important asset component of enterprises and organizations as an important production factor. At the same time, there is more and more concern about the security and compliance of data assets, and higher requirements are put forward for the management of data assets. However, the traditional data management technology still needs to be improved in terms of management efficiency, management cost and management ability. SUMMARY

[0003] In a first aspect of the present disclosure, a method for unified processing of data requests is provided. The method comprises: obtaining a data request for target data, the data request being related to a data demand scenario and at least including a usage range of the target data; in response to the data request passing verification, determining at least one data acquisition mode from a plurality of data acquisition modes based on a data protection requirement related to the target data, different data acquisition modes in the plurality of data acquisition modes being configured to acquire business data with different data protection requirements; acquiring the target data according to the at least one data acquisition mode; and providing access to the target data based on the usage range.

[0004] In a second aspect of the present disclosure, an apparatus for unified processing of data requests is provided. The apparatus comprises: a first obtaining module configured to obtain a data request for target data, the data request being related to a data demand scenario and at least including a usage range of the target data; a determining module configured to, in response to the data request passing verification, determine at least one data acquisition mode from a plurality of data acquisition modes based on a data protection requirement related to the target data, different data acquisition modes in the plurality of data acquisition modes being configured to acquire business data with different data protection requirements; a second obtaining module configured to acquire the target data according to the at least one data acquisition mode; and a providing module configured to provide access to the target data based on the usage range.

[0005] In a third aspect of the present disclosure, an electronic device is provided. The device comprises at least one processing unit; and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit. The instructions, when executed by the at least one processing unit, cause the device to perform the method of the first aspect.

[0006] In a fourth aspect of the present disclosure, a computer readable storage medium is provided. The computer readable storage medium has stored thereon a computer program, the computer program being executable by a processor to implement the method of the first aspect. It should be understood that the content described in this section is not intended to limit key or important features of the embodiments of the present disclosure or limit the scope of the present disclosure. Other features of the present disclosure will become apparent from the following description.

[0007] In a fifth aspect of the present disclosure, a computer program product is provided, the program product comprising a computer program executable by a processor to implement the method of the first aspect. BRIEF DESCRIPTION OF DRAWINGS

[0008] The above and other features, aspects and advantages of embodiments of the present disclosure will become more apparent from the following detailed description when taken in conjunction with the accompanying drawings. In the drawings, like reference numerals refer to like elements, in which:

[0009] FIG. 1 A schematic diagram illustrating an example environment in which embodiments according to the present disclosure can be implemented is shown;

[0010] FIG. 2 A schematic diagram illustrating an example architecture for unified processing of data requests according to some embodiments of the present disclosure is shown;

[0011] FIG. 3A A schematic diagram illustrating an example architecture for obtaining target data according to some embodiments of the present disclosure is shown;

[0012] FIGS. 3B-3F A schematic diagram illustrating a plurality of data obtaining modes according to some embodiments of the present disclosure is shown;

[0013] FIG. 4 A schematic diagram illustrating an example architecture of a data center according to some embodiments of the present disclosure is shown;

[0014] FIG. 5 A flowchart illustrating an example process for unified processing of data requests according to some embodiments of the present disclosure is shown;

[0015] FIG. 6 A schematic block diagram of an example apparatus for unified processing of data requests according to some embodiments of the present disclosure is shown; and

[0016] FIG. 7 A block diagram of an electronic device capable of implementing embodiments of the present disclosure is shown. DETAILED DESCRIPTION

[0017] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. While certain embodiments of the present disclosure are shown in the drawings, it is understood that the present disclosure can be embodied in various forms and should not be construed as being limited to the embodiments set forth herein; rather, these embodiments are provided so that the present disclosure will be thoroughly and completely understood. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.

[0018] It should be noted that the titles of any sections / sub-sections provided herein are not limiting. Various embodiments are described throughout this document and any type of embodiment can be included under any section / sub-section. Furthermore, embodiments described in any section / sub-section can be combined with any other embodiments described in the same section / sub-section and / or different section / sub-section in any manner.

[0019] In the description of embodiments of the present disclosure, the term "includes" and its derivatives, such as "including," should be understood in an open, inclusive sense, that is, "including, but not limited to." The term "based on" should be understood as "based at least in part on." The term "one embodiment" or "an embodiment" should be understood as "at least one embodiment." The term "some embodiments" should be understood as "at least some embodiments." Other explicitly and implicitly recited definitions can also be found below. The terms "first," "second," and the like can refer to different or identical objects. Other explicit and implicit definitions can also be found below.

[0020] Data of users, acquisition and / or use of data, etc. can be involved in embodiments of the present disclosure. These aspects all comply with corresponding laws and regulations and relevant provisions. In embodiments of the present disclosure, all data collection, acquisition, processing, processing, forwarding, use, etc. are performed on the premise that the user is aware of and confirms. Accordingly, when implementing embodiments of the present disclosure, the type of data or information that can be involved, the scope of use, the scenario of use, etc. should be informed to the user and authorized by the user in a proper manner according to relevant laws and regulations. The specific informing and / or authorization manner can vary according to actual situations and application scenarios, and the scope of the present disclosure is not limited in this respect.

[0021] In the present specification and embodiments, if personal information processing is involved, it will be processed on the premise of legality (for example, obtaining the consent of the subject of personal information, or being necessary for the performance of a contract, etc.), and only within the scope prescribed or agreed. Users refuse to process personal information other than the necessary information required for basic functions, which will not affect the user's use of basic functions.

[0022] As used herein, the term“model” can learn a relationship between a corresponding input and an output from training data, such that after training is completed, a corresponding output can be generated for a given input. The generation of a model can be based on a machine learning technique. Deep learning is a machine learning algorithm that processes an input and provides a corresponding output by using multiple layers of processing units. A machine learning model is one example of a model based on deep learning. In this document, a“model” can also be referred to as a“machine learning model,” a“learning model,” a“machine learning network,” or a“learning network,” which are used interchangeably herein.

[0023] As mentioned above, with the continuous growth of the digital economy, data assets have become an important asset component for enterprises and organizations as an important production factor. The management of data assets requires a high degree of management difficulty throughout the entire life cycle of data collection, storage, application, and destruction. For some reasons, there is a demand for the use of data assets. Generally, depending on factors such as data demand scenarios, data demand parties can be scattered in different departments, teams, etc. within the same enterprise or organization. Similarly, data providers also have different data query channels, data storage media, and different compliance requirements, etc.

[0024] Currently, in the process of using data assets, different data demand parties directly obtain corresponding data assets from the operation platform or database of the relevant business and use them. In the current solution, the process of obtaining data assets and using data assets is relatively scattered, resulting in low management efficiency and high management cost of data assets. In addition, this solution is difficult to cover the entire life cycle of data assets.

[0025] Therefore, embodiments of the present disclosure propose a solution for unified processing of data requests. The solution can be implemented in a data management party, such as a data management platform or a data center for data management. In this solution, the unified data management party determines at least one data acquisition mode from a plurality of data acquisition modes based on a verified data request to acquire target data. Subsequently, the data management party provides access to the target data to the data request party based on the usage scope indicated by the data request.

[0026] In this way, the target data is acquired by the data management party and provided to the data request party, thereby realizing the unified collection and distribution of data. Thus, the data assets are controlled throughout the entire data life cycle, thereby improving the security of the data assets.

[0027] Example Environment

[0028] FIG. 1A schematic diagram illustrating an example environment 100 in which embodiments of the present disclosure can be implemented is shown. As shown FIG. 1 The example environment 100 can include a data management platform 110 and a terminal device 120.

[0029] FIG. 1 A schematic diagram illustrating an example environment 100 in which embodiments of the present disclosure can be implemented is shown. As shown FIG. 1 The example environment 100 can include a data management platform 110, which can be implemented by a data management party, for example. In this example environment 100, the data management platform 110 can be used to manage the use of data assets within an organization (e.g., an enterprise, a government agency, other group, etc.). The data management platform 110 can be implemented as a transparency center or as a part of a transparency center, for example.

[0030] By way of example, the terminal device 120 of the user 130 can run a client of the data management platform 110, which can support the user’s interaction with the data management platform 110 provided by the server. In the case where the data management platform 110 runs locally on the user’s terminal device, the user 130 can directly utilize the terminal device 120 to interact with the local data management platform 110. In the case where the data management platform 110 runs on a server device, the server device can implement the service provision to the client running on the terminal device based on the communication connection between the terminal device 120 and the server device.

[0031] In some embodiments, the user 130 can initiate a data request to the data management platform 110 to describe the user’s data use requirement. In some embodiments, the user 130 can initiate a data access request to the data management platform 110 to access the data to be used.

[0032] The data management platform 110 can run on a suitable electronic device. The electronic device here can be any type of device with computing capability, including a terminal device or a server device. The terminal device can be any type of mobile terminal, fixed terminal, or portable terminal including a mobile phone, a desktop computer, a laptop computer, a notebook computer, a netbook computer, a tablet computer, a media computer, a multimedia tablet, a personal communication system (PCS) device, a personal navigation device, a personal digital assistant (PDA), an audio / video player, a digital camera / camcorder, a positioning device, a television receiver, a radio broadcast receiver, an electronic book device, a game device, or any combination thereof, including accessories and peripherals of these devices or any combination thereof. The server device can include a computing system / server, such as a mainframe, an edge computing node, a computing device in a cloud environment, etc. In some embodiments, the data management platform 110 can be implemented based on a cloud service.

[0033] It should be understood that the structure and functionality of the various elements in environment 100 are described for illustrative purposes only and do not imply any limitation on the scope of the present disclosure.

[0034] Various example implementations of the approach are described in further detail below in conjunction with the accompanying drawings.

[0035] Example Architecture

[0036] FIG. 2 A schematic diagram illustrating one example architecture 200 for unified processing of data requests is shown, in accordance with some embodiments of the present disclosure.

[0037] In some embodiments, data management platform 110 can be associated to one or more business systems of an organization to maintain control over the usage of data assets (e.g., operational data of the business) in the business systems. In some embodiments, data management platform 110 can provide data corresponding to a data request 210 to a corresponding data requester based on the data request 210 provided by the data requester or other unit.

[0038] In some embodiments, data management platform 110 obtains a data request for target data. The target data can be business data that a data requester initiating the data request 210 desires to obtain. The data request 210 is related to a data requirement scenario and includes at least a usage scope of the target data. In the data request 210, the target data can be specified at various suitable granularities. In some embodiments, the target data is specified at a field granularity. By refining the specified granularity of the target data, the usage of data can be more precisely controlled.

[0039] The usage scope can define the usage of the target data from one or more dimensions. Examples of the one or more dimensions can include a data type dimension, a data usage scenario dimension, a permission dimension, or a time dimension, etc. Accordingly, in some embodiments, the usage scope of the target data can include at least one of a type of the target data, scenario information of the data requirement scenario, a permission scope that is able to access the target data, or a time scope of the target data.

[0040] In some embodiments, the type of the target data can indicate information corresponding to the target data. For example, the type of the target data can include product identification information (e.g., product name or product number), product sales information, or product promotion information, etc. In some embodiments, the type of the target data (which can also be referred to as a data topic) can include multiple levels. For example, a first level type indicates a business to which the target data belongs, e.g., an e-commerce data type. A second level type indicates a sub-type of the first level type, e.g., order data, etc. A third level type indicates a specific field in the sub-type, e.g., an order number, etc.

[0041] The scenario information of the data demand scenario indicates under which scenario the data request 210 is initiated. Illustratively, the data demand scenario can be a business research scenario or a fault checking scenario, etc. The permission scope that can access the target data can refer to the personnel scope that can access the target data. The personnel in the permission scope can or can not include the data requester. For example, the personnel in the permission scope can include the data requester, and can additionally include other personnel other than the data requester. For another example, the personnel in the permission scope can not include the data requester, but include other personnel other than the data requester. The time scope of the target data indicates the time during which the target data is expected to be accessible or the existence time of the target data.

[0042] In some embodiments, the data request 210 can be a request input by a user. Illustratively, if a user needs to view data related to case A, the user can directly input “I need data related to case A to handle claim B” to the data management platform 110. In this case, “handling claim B” is the data demand scenario related to the data request 210. In some embodiments, the data management platform 110 can obtain the data request 210 through configurable items provided to the user. Illustratively, the data management platform 110 can provide configurable items for the type of target data, scenario information, permission scope, and time scope to the user. Based on the user’s interaction with the configurable items, the corresponding data request 210 is generated. Illustratively, for the type of target data, if a data request creation indication (e.g., a trigger for the type of target data) is detected, the data management platform 110 can present multiple candidate fields indicating different data types to the user. If the user’s selection of a target field in the multiple candidate fields is received, the data request 210 is created based on the user’s selected target field. For example, if the user selects the “product identification” field, the data request 210 for data of the “product identification” type is generated. In this way, the data management platform can determine the type of target data that the user expects to obtain based on the data request, so as to more accurately provide data for the user.

[0043] In some embodiments, the data request 210 can be determined by the data management platform 110 based on user input or information obtained in other processes. For example, if the preceding process is a process related to the processing of case A, the data management platform 110 can determine the corresponding data request 210 based on information related to the preceding process (e.g., input of the preceding process or processing result of the preceding process, etc.). In some embodiments, the data management platform 110 can use a language model (e.g., a large language model) to generate the corresponding data request 210 based on the user input or the execution result of the preceding process. For example, the user input or the execution result of the preceding process can be provided to the language model, and the language model can be used to determine the use range of the target data, thereby generating the data request 210.

[0044] In some embodiments, in order to further improve the security of the data asset, the data management platform 110 can verify the obtained data request. As shown in FIG. 2 , in the data application approval stage, the data management platform 110 verifies the data request 210. If the data request 210 passes the verification, the data management platform 110 obtains the target data from the data provider. In FIG. 2 , the verification of the data request 210 can include pre-approval 211 from the data requestor and business approval 212 from the data provider. If the data request 210 passes the pre-approval 211 and the business approval 212, it indicates that both the data requestor and the data provider approve the data request. If the data request 210 fails the verification, the data application process is terminated. The data management platform 110 can send information about whether the verification is passed to the risk control system, so that the risk control system determines the security of the data asset. For example, the pre-approval 211 can be evaluated by relevant personnel of the data requestor to assess the feasibility of the data request 210. The business approval 212 can be judged by relevant personnel of the data provider to determine whether the data request 210 meets the protocol requirements of the corresponding business system. In some embodiments, the data management platform 110 can check the matching degree of the data request 210 and the data use scenario to determine whether there is a data leakage risk.

[0045] If the data request 210 passes the verification, it enters the data acquisition stage. The data management platform 110 performs data acquisition 213. The data management platform 110 determines at least one data acquisition mode from a plurality of data acquisition modes based on data protection requirements related to the target data. In some embodiments, the data management platform 110 can obtain the target data from the corresponding data provider according to the determined at least one data acquisition mode. For example, the data provider can be a business system or a data storage system of a business system, etc.

[0046] In some embodiments, the data management platform 110 can support acquiring requested data through multiple data acquisition modes. In some embodiments, different data acquisition modes among the multiple data acquisition modes are configured to acquire business data with different data protection requirements. As used herein, data protection requirements can refer to requirements for one or more elements of data protection, such as data security level, data privacy level, data activity level, data storage format, requirements of the business system to which the data belongs, etc. The data management platform 110 can determine one or more data acquisition modes from the multiple data acquisition modes based on the data protection requirements related to the target data. The target data is then acquired through these one or more data acquisition modes. The determined data acquisition modes are used to acquire at least a portion of the target data, such as data from a portion of fields or data from a portion of the subject.

[0047] The following is for reference. FIGS. 3A-3F To describe several examples of data acquisition patterns. For example... FIG. 3A As shown, the data acquisition modes may include task assignment-based acquisition mode 320, interface-based acquisition mode 322, agent-based acquisition mode 324, instruction set-based acquisition mode 326, or data table-based acquisition mode 328. The data management platform 110 can utilize one or more of these acquisition modes to acquire target data 310 from one or more business systems 330.

[0048] The data management platform 110 can determine one or more data acquisition modes corresponding to the data request 210 from multiple data acquisition modes based on the data protection requirements of the target data, thereby acquiring the target data. In some embodiments, the determination of the data acquisition mode can be performed at the field level. For example, the target data may include multiple fields, and the data management platform 110 can determine a suitable data acquisition mode for each of these fields. In some embodiments, the determination of the data acquisition mode can be performed at the subject level. For example, the target data may include data from multiple data subjects, and the data management platform 110 can determine a suitable data acquisition mode for each of these data subjects.

[0049] For example, if a field or data topic in the target data has a low security level or high data activity (e.g., target data such as customer service data or operational data), the data management platform 110 can retrieve the data for that field or data topic from the business system 330 using interface-based retrieval mode 322, proxy-based retrieval mode 324, or data table-based retrieval mode 328. In this way, the data management platform can retrieve data through simple operations or processes.

[0050] In some embodiments, for at least a portion of the target data (e.g., one or more fields, one or more data subjects), the data management platform 110 can determine an interface-based acquisition mode 322. Accordingly, the data management platform 110 can determine, based on the business related to the at least a portion, an interface connected to a business system of the business, such as an application programming interface (API). Then, the data management platform 110 can acquire the at least a portion of the target data from the business system through the interface, FIG. 3B An example architecture diagram of the interface-based acquisition mode 322 is shown. As FIG. 3B shown, the API 332 is connected to the business system 335. The data management platform 110 can acquire the at least a portion of the target data 310, such as data of one or more fields, from the business system 335 by invoking the API 332.

[0051] In some embodiments, for at least a portion of the target data (e.g., one or more fields, one or more data subjects), the data management platform 110 can determine a proxy-based acquisition mode 324. FIG. 3C An example architecture diagram of the proxy-based acquisition mode 324 is shown. As FIG. 3C shown, the data management platform 110 can acquire the at least a portion of the target data 310 by utilizing a data proxy 341. Illustratively, the data management platform 110 determines, based on the business related to the at least a portion of the target data, a data proxy that communicates with a first data storage system 340 of the business. The determined data proxy is configured to acquire business data from the first data storage system 340 based on a data acquisition request. The first data storage system 340 is used to store business information of the business. In this disclosure, the data storage system of the business can be, for example, a data warehouse used to store business data. Subsequently, the data management platform 110 provides the data acquisition request to the data proxy 341 based on the data request.

[0052] The data proxy 341 acquires the requested data from the first data storage system 340 based on the received data acquisition request, and sends a response to the data acquisition request to the data management platform 110. Accordingly, the data management platform 110 receives the response to the data acquisition request from the data proxy. The response can include the requested data, i.e., the at least a portion of the target data. In such embodiments, the data proxy can be used as an intermediary between the business system and the data management platform, and can provide unified encapsulation services for data of the business system. Through the data proxy, data security management and control can be performed on the data of the business system.

[0053] In some embodiments, for at least a portion of the target data (e.g., one or more fields, one or more data topics), the data management platform 110 can determine a data table based access pattern 328. Accordingly, the data management platform 110 can FIG. 3D An example architecture of the data table based access pattern is shown. As FIG. 3D As shown, the data management platform 110 determines the business related to at least a portion of the target data, and based on the at least a portion, determines a business data table 351, e.g., a business base table, with access rights from a second data storage system 352 of the business. Accordingly, the data management platform 110 can read the at least a portion of the target data from the determined business data table 351. The second data storage system 352 is used to store business information of the business, and can include a plurality of business data tables, e.g., a plurality of business base tables, of the business. For example, for a certain data topic in the target data, the data management platform 110 can determine to utilize the data table based access pattern 328. Based on the data topic, the data management platform 110 can determine which business data table stores data of the data topic. In this way, the data management platform 110 can read the data of the data topic from the business data table.

[0054] In this pattern, the data management platform 110 can be pre-authorized by the business system or a portion thereof, e.g., the second data storage system 352. In this way, upon receiving a data request, the data management platform 110 can read data in the authorized business data table.

[0055] In some embodiments, for at least a portion of the target data (e.g., one or more fields, one or more data topics), the data management platform 110 can determine a task assignment based access pattern 320. For example, if the security level related to the target data is high, the data management platform 110 can utilize the task assignment based access pattern 320 to access at least a portion of the target data 310 from the business system 330. For example, the data management platform 110 can pre-determine the types of business data that the data providers are able to provide. The data management platform 110 can present the types of business data provided by the data providers to the user in the form of candidate fields. The user determines the target field from the candidate fields, and creates a corresponding data request 210.

[0056] FIG. 3E An example architecture of the task assignment based access pattern 320 is shown. As FIG. 3EAs shown, the data management platform 110 determines a data acquisition instruction 360 for acquiring at least a portion of the target data if receiving the data request 210. The data acquisition instruction 360 can be a notification message of the data acquisition. The data acquisition instruction 360 can indicate the data to be acquired, the usage scope of the data, etc. Subsequently, the data management platform 110 provides the data acquisition instruction to the data provider to initiate a data acquisition task 361 corresponding to the data request 210 at the data provider. The data management platform 110 receives an execution result 362 of the data acquisition task from the data provider, and the execution result 362 includes at least a portion of the target data.

[0057] For example, after sending the data acquisition instruction 360, the data management platform 110 can present an interface of the data acquisition task on a terminal device of a relevant personnel of the data provider. The interface displays information of the data acquisition task, such as the data to be acquired, the usage scope of the data, the data providing entry, etc. For another example, a data template can be downloaded through the interface, so that the relevant personnel fills the data into the template. The template can be generated by the data management platform 110 based on the data request or the data to be acquired, or can be provided by the requestor initiating the data request. Subsequently, the relevant personnel can feed back the acquired data to the data management platform 110 through the interface or other interfaces, for example, the relevant personnel can enter or upload the data (for example, upload the filled template) through the data providing entry.

[0058] In some embodiments, the data management platform 110 can verify the business data included in the execution result 362 to determine whether the business data can satisfy the data request 210. If yes, the business data is taken as the target data. If no, the data acquisition task 361 is executed again to acquire updated business data.

[0059] In some embodiments, the data management platform 110 can determine the instruction set-based acquisition mode 322 for at least a portion (for example, one or more fields, one or more data topics) of the target data. For example, if the security level of the target data 210 is high or the corresponding business has its own data protection policy, the data management platform 110 can acquire at least a portion of the target data 310 from the business system 330 by using the instruction set-based acquisition mode 326. In these embodiments, the instruction set can be a set of executable instructions deployed in the business system, such as a runnable script. FIG. 3FAn example architecture of the instruction set based acquisition mode 326 is shown. In some embodiments, based on the business related to at least a portion of the target data, a target instruction set deployed in a business system of the business is determined. For example, for a certain data subject, the data management platform 110 can determine the business to which the data subject belongs, and further determine the instruction set deployed in the business system of the business, such as a remote script deployed in the business system. The instruction set can be regarded as remotely deployed in the data reading service of the business system.

[0060] Subsequently, the data management platform 110 provides the remote call parameter 381 to the business system 389 to call the corresponding target instruction set 382. The target instruction set 382 acquires the business data corresponding to the data request 210 from the first data storage area 371 of the business system after obtaining the remote call parameter 381. The first data storage area 371 is used to store the business data table, such as the business base table. That is, the target instruction set 382 can read the required data in the business data table, such as the data of one or more fields, the data of one or more data subjects. Subsequently, the target instruction set 382 can store the obtained business data to the second data storage area 372 of the business system 389. The data management platform 110 can acquire the target data from the second data storage area 372. The second data storage area is different from the first data storage area. The data required by the data management platform 110 is stored separately from the data of the business system itself. In this way, the business system can facilitate data tracking, and the business system can also apply its own data protection policy. In this way, the controllability and traceability of data use can be further improved.

[0061] In some embodiments, at block 383, the target instruction set 382 can be configured to encrypt the obtained business data with a second key to improve data security. The second key is a key specific to the business system 389. In this way, the leakage of a key of a certain business system is prevented from leading to the leakage of data of other business systems. In such embodiments, the business data in the second storage area 372 is encrypted. Accordingly, at block 384, the data management platform 110 can decrypt the obtained data with the second key. At block 385, the data management platform 110 can encrypt the decrypted data with a first key. The first key is held by the data management platform 110, and the first key can be used to encrypt data obtained from different business systems. At block 386, the data management platform 110 can store the encrypted data to the platform itself for user access.

[0062] The data management platform 110 can obtain target data through various acquisition modes. Different data acquisition modes obtain data of different types and in different forms. In order to improve the uniformity and usability of the data, in some embodiments, the data management platform 110 can process (e.g., integrate) the target data obtained through different acquisition modes. In some embodiments, the data management platform 110 obtains initial data from at least one data provider based on a data request, the initial data including a plurality of data items of different data types. The plurality of data items are grouped based on the respective data types of the plurality of data items to determine a plurality of groups of data. For example, e-commerce data is taken as one group of data, and human resource data is taken as one group of data. Subsequently, standardization processing is performed on each group of data in the plurality of groups of data (e.g., uniform data format, deletion of duplicate and invalid data, etc.) to determine a plurality of groups of processed data as target data.

[0063] With continued reference to FIG. 2 After the data is obtained from one or more business systems in the data acquisition phase, the data management platform 110 can perform encrypted storage 214 of the data. For example, the data management platform 110 can encrypt the obtained target data using the first key described above, and store the encrypted data. That is, the data stored by the data management platform 110 is ciphertext data. In some embodiments, the first key can be dedicated to the unified processing of data requests, that is, the data management platform 110 can encrypt the respective target data of a plurality of data requests using the first key. In some embodiments, the data management platform 110 can encrypt the obtained target data using different keys. For example, the data management platform 110 can determine the key used for encryption according to the initiator of the data request, or determine the key used for encryption according to the type of the target data.

[0064] In the data usage stage, the data management platform 110 can provide the access to the target data to the access party based on the usage scope of the target data. The access to the target data includes data viewing and data downloading, etc. In some embodiments, if a viewing request for the target data is received, the data management platform 110 can determine whether the request party initiating the viewing request has the viewing right of the target data based on the right scope. If the viewing right is available, the target data 210 is presented to the request party, as shown in block 215. In some embodiments, the target data 210 is stored in the data management platform 110 in an encrypted manner. In this case, in order to present the target data 210 to the request party securely at the terminal device of the request party, a secure transmission strategy can be applied to the target data 210 in the process of transmitting the target data 210 from the data management platform 110 to the terminal device of the request party. For example, the data management platform 110 can first decrypt the target data 210, and then establish a secure tunnel between the terminal device of the request party and the data management platform 110 by using a suitable secure transmission protocol, and transmit the target data 210 to the terminal device of the request party through the secure tunnel. Examples of such secure transmission protocol can include the Hypertext Transfer Protocol Secure (HTTPS), the Point-to-Point Tunneling Protocol (PPTP).

[0065] In some embodiments, if a downloading request for the target data is received, the data management platform 110 can determine whether the request party initiating the downloading request has the downloading right of the target data based on the right scope, the downloading request indicating the downloading data in the target data and the usage scenario of the downloading data. If it is determined that the request party has the downloading right of the target data and the usage scenario matches the data demand scenario, the downloading data is determined from the target data and provided to the request party, as shown in block 216. For example, the data demand scenario of the target data A is “reference data for the third party B to evaluate C”. If the usage scenario of the downloading data is “provided to the B unit”, it is determined that the usage scenario matches the data demand scenario. Subsequently, the downloading data is provided to the request party. In this way, it is ensured that the target data is downloaded only under necessary conditions, and the security of the target data is improved. In some embodiments, the downloading data can be carried by a predetermined type of data object (e.g., a document). The data object can be embedded with a steganographic watermark. The steganographic watermark can include, for example, information of the data management platform (e.g., platform identification), information of the request party initiating the downloading request (e.g., account, time), etc.

[0066] In some embodiments, the target data provided by the data management platform 110 to the access party is the minimum necessary data. That is to say, if the data request 210 received is for the sub-data set a in the data set A, only the data related to the sub-data set a is provided to the access party.

[0067] In some embodiments, after providing the downloaded data to the requester, the data management platform 110 can utilize predetermined protection strategies or methods to prevent data leakage. For example, the data management platform 110 can enable a data leakage prevention (DLP) policy on the requester's device for the downloaded data. For instance, the DLP policy can be used to detect whether the data object sent externally by the requester contains the aforementioned watermark, and if the watermark is present, the external transmission of the data object can be intervened during the process or audited afterward. Alternatively, the data management platform 110 can prevent data leakage by restricting the requester's device, network, and access conditions.

[0068] In some embodiments, if a business person is included in the access scope, that business person can access the target data. In some embodiments, the access scope may include multiple business persons. Multiple business persons may have the same access rights or different access rights. For example, the access scope may include person A and person B. Person A can access target data of type C, and person B can access target data of type D. In some embodiments, if a business person is included in the access scope and is currently within the permitted access time range, that business person can access the corresponding target data. If not within the permitted time range, the business person is not allowed to access the target data 210.

[0069] like FIG. 2 As shown, during the data destruction phase, the data management platform 110 can perform data destruction 218. As mentioned above, the scope of data use can include the permitted time range for data use. If the permitted time range for using the target data is reached or exceeded, the data management platform 110 can delete the encrypted target data. Timely data destruction is a crucial step for the secure and controllable use of data and can reduce data security risks.

[0070] FIG. 4 A schematic diagram of an example architecture 400 of a data management platform 110 according to some embodiments of the present disclosure is shown. FIG. 4 As shown, the data management platform 110 (e.g., a transparent center) can implement a data acquisition unit 420 and a data management unit 450. The data acquisition unit 420 establishes a database based on the business data table 410, service-related data 411, and data uploaded by users 412, to provide data query services for business personnel. In some embodiments, the data obtained by the data acquisition unit 420 is data that has undergone security verification.

[0071] In some embodiments, the user 130 can send a login request to the data management platform 110 through the external system 460 carried by the terminal device 120. If the external system 460 is a system permitted to log in the data management platform 110, for example, the network address of the external system 460 is a preset network address (for example, an internal network address), or the identification information of the external system 460 meets a preset condition, the data management platform 110 permits the login request, so that the user 130 can access the data management platform 110 through the external system 460.

[0072] The data management platform 110 can receive the data request 210 sent by the user 130 to provide corresponding data services for the user 130. In some embodiments, the data management unit 450 can perform tasks such as obtaining corresponding target data, presenting or exporting target data, file proofreading, file transmission, and file encryption based on the data request 210 sent by the user 130. For example, the data management platform 110 can prevent data leakage caused by traffic replay by transmitting target data through encryption. In the data storage task, the data management platform 110 can store the obtained business data to facilitate data access parties to query or download. The business data stored by the data management platform 110 can only be accessed within a limited time. If the storage time of the target data exceeds the use time range, the target data is deleted. In some embodiments, the data management platform 110 encrypts the obtained target data by using a key management service (KMS) to further improve data security.

[0073] In some embodiments, the data management platform 110 can be used for security alarm operation investigation triggered by unreasonable distribution of exported files, attack and defense drills, elimination of redundant permissions, and the like, to further improve the security of the data management platform 110. In some embodiments, the data management platform 110 can jointly explain and review the results of the use of business data by the data request party.

[0074] In some embodiments, the behavior tracking unit 440 can record user actions within the data management platform 110 for later traceability and auditing. In some embodiments, the data management platform 110 can utilize the blockchain system 470 to record user behavior and data results generated during the data lifecycle. For example, the blockchain system 470 can generate identification information for the target data based on data requests, target data, and the processing procedure of the target data. For example, the processing procedure of the target data may include the data management platform 110 obtaining a data request for the target data, the data management platform 110 obtaining the target data using at least one data acquisition mode, the data management platform 110 storing the target data, the data management platform 110 providing access to the target data, and the data management platform 110 deleting the target data. The identification information can characterize the lifecycle of the target data. For example, the identification information may include the generation time of the target data, the provider of the target data, and the data acquisition mode used to obtain the target data. Subsequently, the data management platform 110 writes the identification information into the blockchain. For example, if user A views data C at time B, a hash value or other identification information is generated based on information related to that event. The generated identification information is then written into the blockchain for later review. This method enables data traceability and verification.

[0075] According to embodiments of this disclosure, a data management platform can establish a data lifecycle security process domain and a general security process domain, with data control as the core objective, throughout the data lifecycle. The data lifecycle security process domain includes data acquisition security, data transmission security, data storage security, data usage security, and data destruction security. The general security process domain includes endpoint DLP policies, endpoint data security, security operations, access control, organization and personnel management, privacy protection, and periodic auditing. In this way, data is controlled and distributed throughout the data lifecycle, improving data security.

[0076] Example Process

[0077] FIG. 5 A flowchart of an example process 500 for uniformly processing data requests according to some embodiments of the present disclosure is shown. Process 500 can be implemented at a data management platform 110. Reference is made below. FIG. 1 Let's describe process 500. The following is just an example of how to describe process 500.

[0078] like FIG. 5 As shown in box 510, the data management platform 110 obtains a data request for the target data. The data request is related to the data requirement scenario and at least includes the scope of use of the target data.

[0079] In some embodiments, obtaining the data request for the target data comprises: in response to receiving a data request creation indication, presenting a plurality of candidate fields indicating different data types; and in response to receiving a selection of at least one target field in the plurality of candidate fields, creating the data request based on the at least one target field.

[0080] In some embodiments, the usage scope comprises at least one of: a type of the target data, scenario information of a data requirement scenario, a permission scope of accessing the target data, or a usage time range of the target data.

[0081] At block 520, the data management platform 110 determines at least one data acquisition mode from a plurality of data acquisition modes based on data protection requirements related to the target data, different data acquisition modes in the plurality of data acquisition modes being configured to acquire business data having different data protection requirements.

[0082] At block 530, the data management platform 110 acquires the target data according to the at least one data acquisition mode.

[0083] In some embodiments, acquiring the target data according to the at least one data acquisition mode comprises: acquiring initial data according to the at least one data acquisition mode, the initial data comprising a plurality of data items of different data types; grouping the plurality of data items based on respective data types of the plurality of data items to determine a plurality of groups of data; and performing standardization processing on each group of data in the plurality of groups of data to acquire a plurality of groups of processed data as the target data.

[0084] In some embodiments, the at least one data acquisition mode comprises an interface-based acquisition mode, and acquiring the target data comprises: determining, based on a business related to at least a portion of the target data, an interface connected to a business system of the business; and acquiring, from the business system, the at least a portion of the target data through the interface.

[0085] In some embodiments, the at least one data acquisition mode comprises a proxy-based acquisition mode, and acquiring the target data comprises: determining, based on a business related to at least a portion of the target data, a data proxy in communication with a first data storage system of the business; providing, based on the data request, a data acquisition request to the data proxy, the data proxy being configured to acquire business data from the first data storage system based on the data acquisition request; and receiving, from the data proxy, a response to the data acquisition request, the response comprising the at least a portion of the target data.

[0086] In some embodiments, the at least one data acquisition mode includes an instruction set based acquisition mode, and acquiring the target data comprises: determining, based on the business related to the at least one portion of the target data, a target instruction set deployed in a business system of the business; invoking, based on the data request, the target instruction set, the target instruction set being configured to acquire data from a first data storage area of the business system and store the acquired data to a second data storage area of the business system; and acquiring the at least one portion of the target data from the second data storage area.

[0087] In some embodiments, acquiring the at least one portion of the target data from the second data storage area comprises: reading, from the second data storage area, the at least one portion of the encrypted target data; decrypting, based on a second key related to the business, the at least one portion of the encrypted target data to acquire the at least one portion of the target data.

[0088] In some embodiments, the at least one data acquisition mode includes a data table based acquisition mode, and acquiring the target data comprises: determining the business related to the at least one portion of the target data; determining, based on the at least one portion of the target data, a business data table having access rights from a second storage system of the business; and reading the at least one portion of the target data from the determined business data table.

[0089] In some embodiments, the at least one data acquisition mode includes a task assignment based acquisition mode, and acquiring the target data comprises: determining, based on the data request, a data acquisition instruction for acquiring the at least one portion of the target data; providing the data acquisition instruction to a data provider to initiate, at the data provider, a data acquisition task corresponding to the data request; and receiving, from the data provider, an execution result of the data acquisition task, the execution result including the at least one portion of the target data.

[0090] In some embodiments, the process 500 further comprises: in response to determining that the at least one portion of the target data does not satisfy the data request, generating an update request for the at least one portion of the target data; and providing the update request to the data provider to acquire an updated at least one portion of the target data.

[0091] At block 540, the data management platform 110 provides access to the target data based on the usage scope.

[0092] In some embodiments, the usage scope includes a permission scope that enables access to the target data, and providing access to the target data comprises: in response to receiving a view request for the target data, determining, based on the permission scope, whether a requestor that initiates the view request has a view permission of the target data; and in response to determining that the requestor has the view permission of the target data, presenting the target data to the requestor.

[0093] In some embodiments, the scope of use includes the permission scope to access the target data, and providing access to the target data includes: in response to receiving a download request for the target data, determining whether the requester initiating the download request has the permission to download the target data based on the permission scope, wherein the download request indicates the download data in the target data and the use scenario of the download data; in response to determining that the requester has the permission to download the target data and that the use scenario matches the data requirement scenario, determining the download data from the target data; and providing the download data to the requester.

[0094] In some embodiments, the scope of use includes indicating a time range for the use of target data, and the method further includes: deleting the stored target data in response to detecting that the storage time of the target data exceeds the time range for use.

[0095] In some embodiments, process 500 further includes encrypting target data using a first key dedicated to the unified processing of data requests; and storing the encrypted target data.

[0096] In some embodiments, process 500 further includes: generating identification information for the target data based on the data request, the target data, and the processing procedure of the target data, wherein the identification information characterizes the lifecycle of the target data; and writing the identification information into a blockchain.

[0097] Example Devices and Apparatus

[0098] Embodiments of this disclosure also provide corresponding apparatus for implementing the above methods or processes. FIG. 6 A schematic structural block diagram of an example apparatus 600 for unified processing of data requests according to certain embodiments of the present disclosure is shown. Apparatus 600 may be implemented as or included in a data management platform 110. The various modules / components in apparatus 600 may be implemented by hardware, software, firmware, or any combination thereof.

[0099] like FIG. 6 As shown, the device 600 includes a first acquisition module 610, configured to acquire a data request for target data, the data request being related to a data requirement scenario and at least including the scope of use of the target data. The device 600 also includes a determination module 620, configured to determine at least one data acquisition mode from multiple data acquisition modes based on data protection requirements related to the target data, the different data acquisition modes being configured to acquire business data with different data protection requirements. The device 600 also includes a second acquisition module 630, configured to acquire the target data according to at least one data acquisition mode. The device 600 further includes a providing module 640, configured to provide access to the target data based on the scope of use.

[0100] In some embodiments, the first obtaining module 610 is further configured to, in response to receiving the data request creation indication, present a plurality of candidate fields indicating different data types; and in response to receiving a selection of at least one target field from the plurality of candidate fields, create the data request based on the at least one target field.

[0101] In some embodiments, the usage range includes at least one of a type of the target data, scenario information of a data requirement scenario, a permission range capable of accessing the target data, or a time range of the target data.

[0102] In some embodiments, the second obtaining module 630 is further configured to obtain initial data according to at least one data obtaining mode, the initial data including a plurality of data items of different data types; group the plurality of data items based on respective data types of the plurality of data items to determine a plurality of groups of data; and perform standardization processing on each group of data from the plurality of groups of data to obtain a plurality of groups of processed data as the target data.

[0103] In some embodiments, the at least one data obtaining mode includes an interface-based obtaining mode, and the second obtaining module 630 is further configured to, based on a business related to at least part of the target data, determine an interface connected to a business system of the business; and obtain the at least part of the target data from the business system through the interface.

[0104] In some embodiments, the at least one data obtaining mode includes a proxy-based obtaining mode, and the second obtaining module 630 is further configured to, based on a business related to at least part of the target data, determine a data proxy in communication with a first data storage system of the business; provide a data obtaining request to the data proxy based on the data request, the data proxy being configured to obtain business data from the first data storage system based on the data obtaining request; and receive a response to the data obtaining request from the data proxy, the response including the at least part of the target data.

[0105] In some embodiments, the at least one data obtaining mode includes an instruction set-based obtaining mode, and the second obtaining module 630 is further configured to, based on a business related to at least part of the target data, determine a target instruction set deployed in a business system of the business; invoke the target instruction set based on the data request, the target instruction set being configured to obtain data from a first data storage area of the business system and store the obtained data in an encrypted manner to a second data storage area of the business system; and obtain the at least part of the target data from the second data storage area.

[0106] In some embodiments, the second obtaining module 630 is further configured to read the at least part of the encrypted target data from the second data storage area; decrypt the at least part of the encrypted target data based on a second key related to the business to obtain the at least part of the target data.

[0107] In some embodiments, the at least one data acquisition mode includes a data table based acquisition mode, and the second acquisition module 630 is further configured to determine a business related to the at least part of the target data; determine, based on the at least part of the target data, a business data table with access right from a second storage system of the business; and read the at least part of the target data from the determined business data table.

[0108] In some embodiments, the at least one data acquisition mode includes a task assignment based acquisition mode, and the second acquisition module 630 is further configured to determine, based on the data request, a data acquisition instruction for acquiring the at least part of the target data; provide the data acquisition instruction to the data provider to initiate a data acquisition task corresponding to the data request at the data provider; and receive an execution result of the data acquisition task from the data provider, the execution result including the at least part of the target data.

[0109] In some embodiments, the apparatus 600 further includes an update module configured to, in response to determining that the at least part of the target data does not satisfy the data request, generate an update request for the at least part of the target data; and provide the update request to the data provider to acquire an updated at least part of the target data.

[0110] In some embodiments, the usage scope includes a right scope of accessing the target data, and the providing module 640 is further configured to, in response to receiving a viewing request for the target data, determine, based on the right scope, whether a requestor initiating the viewing request has a viewing right of the target data; and in response to determining that the requestor has the viewing right of the target data, present the target data to the requestor.

[0111] In some embodiments, the usage scope includes a right scope of accessing the target data, and the providing module 640 is further configured to, in response to receiving a download request for the target data, determine, based on the right scope, whether a requestor initiating the download request has a download right of the target data, the download request indicating download data in the target data and a usage scenario of the download data; in response to determining that the requestor has the download right of the target data and the usage scenario matches a data demand scenario, determine the download data from the target data; and provide the download data to the requestor.

[0112] In some embodiments, the usage scope includes an usage time range of the target data, and the apparatus 600 further includes a deletion module configured to, in response to detecting that a storage time of the target data exceeds the usage time range, delete the stored target data.

[0113] In some embodiments, the apparatus 600 further includes an encryption module configured to encrypt target data using a first key dedicated to unified processing of data requests; and to store the encrypted target data.

[0114] In some embodiments, the device 600 further includes an identification information generation module, configured to generate identification information for the target data based on the data request, the target data, and the processing of the target data, wherein the identification information characterizes the lifecycle of the target data; and to write the identification information into the blockchain.

[0115] like FIG. 7 As shown, electronic device 700 is in the form of a general-purpose electronic device. Components of electronic device 700 may include, but are not limited to, one or more processors or processing units 710, memory 720, storage device 730, one or more communication units 740, one or more input devices 750, and one or more output devices 760. Processing unit 710 may be a physical or virtual processor and is capable of performing various processes according to programs stored in memory 720. In a multiprocessor system, multiple processing units execute computer-executable instructions in parallel to improve the parallel processing capability of electronic device 700.

[0116] Electronic device 700 typically includes multiple computer storage media. Such media can be any accessible media that is accessible to electronic device 700, including but not limited to volatile and non-volatile media, removable and non-removable media. Memory 720 can be volatile memory (e.g., registers, cache, random access memory (RAM)), non-volatile memory (e.g., read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. Storage device 730 can be removable or non-removable media and can include machine-readable media, such as flash drives, disks, or any other media that can be used to store information and / or data and can be accessed within electronic device 700.

[0117] Electronic device 700 may further include additional removable / non-removable, volatile / non-volatile storage media. Although not explicitly stated... FIG. 7 As shown, disk drives for reading from or writing to removable, non-volatile disks (e.g., "floppy disks") and optical disk drives for reading from or writing to removable, non-volatile optical disks can be provided. In these cases, each drive can be connected to a bus (not shown) via one or more data media interfaces. Memory 720 may include computer program product 725 having one or more program modules configured to perform various methods or actions of various embodiments of this disclosure.

[0118] The communication unit 740 enables communication through the communication medium with other electronic devices. Additionally, the functionality of the components of the electronic device 700 can be implemented in a single computing cluster or a plurality of computer machines capable of communicating over a communication connection. As such, the electronic device 700 can operate in a networked environment using logical connections to one or more other servers, network personal computers (PCs), or another network node in the networking environment.

[0119] The input device 750 can be one or more input devices, such as a mouse, a keyboard, a trackball, etc. The output device 760 can be one or more output devices, such as a display, a speaker, a printer, etc. The electronic device 700 can also communicate with one or more external devices (not shown), such as a storage device, a display device, etc., through the communication unit 740, as needed, with one or more devices that enable a user to interact with the electronic device 700, or with any devices (e.g., a network card, a modem, etc.) that enable the electronic device 700 to communicate with one or more other electronic devices. Such communication can be carried out via an input / output (I / O) interface (not shown).

[0120] According to an example implementation of the present disclosure, a computer readable storage medium is provided having computer executable instructions stored thereon, where the computer executable instructions are executed by a processor to implement the method described above. According to an example implementation of the present disclosure, a computer program product is also provided that is tangibly stored on a non-transitory computer readable medium and includes computer executable instructions, where the computer executable instructions are executed by a processor to implement the method described above.

[0121] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0122] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0123] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer, other programmable data processing apparatus, or other device implement the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0124] The flow diagrams and the block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods and computer program products according to various implementations of the present disclosure. In this regard, each block in the flow diagrams and the block diagrams can represent a module, segment, or portion of instructions, which comprises one or more executable instructions for implementing the specified logic functions (s). In some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in some cases, be executed substantially concurrently, or the blocks can sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart illustrations, and combinations thereof, can be implemented by a dedicated hardware-based system that performs the specified functions or acts, or combinations of hardware and software.

[0125] implementations. Numerous modifications and adaptations will be apparent to those skilled in the art without departing from the scope and spirit of the described implementations. The herein disclosed implementations are meant to be illustrative and not limiting, of the scope or spirit of the implementations. It will be apparent to those reasonably skilled in the art that varying substitutions and modifications can be made to the implementations disclosed here without departing from the scope and spirit of the implementations. And, other implementations that are apparent to those of ordinary skill in the art, are within the scope of the disclosed implementations.

Claims

1. A method for uniformly processing data requests, comprising: Obtain a data request for target data, wherein the data request is related to the data requirement scenario and at least includes the scope of use of the target data; In response to the data request being verified, at least one data acquisition mode is determined from multiple data acquisition modes based on data protection requirements related to the target data, wherein different data acquisition modes among the multiple data acquisition modes are configured to acquire business data with different data protection requirements. The target data is obtained according to the at least one data acquisition mode; as well as Based on the scope of use, access to the target data is provided.

2. The method of claim 1, wherein the scope of use includes the permission scope to access the target data, and providing access to the target data includes: In response to receiving a viewing request for the target data, determine whether the requester initiating the viewing request has viewing permission for the target data based on the permission scope; as well as In response to determining that the requesting party has viewing permission for the target data, the target data is presented to the requesting party.

3. The method of claim 1, wherein the scope of use includes the permission scope to access the target data, and providing access to the target data includes: In response to receiving a download request for the target data, the system determines whether the requester initiating the download request has the permission to download the target data based on the permission scope. The download request indicates the downloadable data in the target data and the usage scenario of the downloadable data. In response to determining that the requester has download permission for the target data and that the use case matches the data requirement scenario, the download data is determined from the target data; as well as The downloaded data is provided to the requesting party.

4. The method according to claim 1, wherein the scope of use includes the time range of use of the target data, and the method further comprises: In response to the detection that the storage time of the target data exceeds the usage time range, the stored target data is deleted.

5. The method of claim 1, wherein obtaining a data request for the target data includes: In response to receiving a data request creation instruction, present multiple candidate fields indicating different data types; as well as In response to receiving a selection of at least one target field from the plurality of candidate fields, the data request is created based on the at least one target field.

6. The method according to claim 1, wherein acquiring the target data according to the at least one data acquisition mode comprises: Initial data is obtained according to the at least one data acquisition mode, and the initial data includes multiple data items of different data types; The multiple data items are grouped based on their corresponding data types to determine multiple groups of data; as well as Standardization processing is performed on each of the multiple sets of data to obtain multiple sets of processed data as the target data.

7. The method according to claim 1, further comprising: Based on the data request, the target data, and the processing procedure of the target data, identification information for the target data is generated, and the identification information represents the lifespan of the target data. as well as Write the identification information into the blockchain.

8. The method of claim 1, wherein the scope of application includes at least one of the following: The type of the target data, The scenario information of the data requirement scenario, The scope of permissions to access the target data, or The time range for the use of the target data.

9. The method according to claim 1, further comprising: The target data is encrypted using a first key, which is dedicated to the unified processing of data requests; as well as The encrypted target data is stored.

10. The method of claim 1, wherein the at least one data acquisition mode includes an interface-based acquisition mode, and acquiring the target data includes: Based on the business related to at least a portion of the target data, determine the interface that connects to the business system of the business. as well as At least a portion of the target data is obtained from the business system through the interface.

11. The method of claim 1, wherein the at least one data acquisition mode includes a proxy-based acquisition mode, and acquiring the target data includes: Based on services related to at least a portion of the target data, a data proxy is determined that communicates with a first data storage system of the services. Based on the data request, a data acquisition request is provided to the data agent, and the data agent is configured to acquire business data from the first data storage system based on the data acquisition request. as well as Receive a response from the data broker for the data acquisition request, the response including at least a portion of the target data.

12. The method of claim 1, wherein the at least one data acquisition mode includes an instruction set-based acquisition mode, and acquiring the target data includes: Based on the business related to at least a portion of the target data, determine the target instruction set deployed in the business system of the business; Based on the data request, the target instruction set is invoked, and the target instruction set is configured to retrieve data from the first data storage area of ​​the business system and encrypt and store the retrieved data in the second data storage area of ​​the business system. as well as At least a portion of the target data is obtained from the second data storage area.

13. The method of claim 12, wherein obtaining at least a portion of the target data from the second data storage area comprises: Read at least a portion of the encrypted target data from the second data storage area; The at least portion of the encrypted target data is decrypted using a second key associated with the business to obtain the at least portion of the target data.

14. The method of claim 1, wherein the at least one data acquisition mode includes a data table-based acquisition mode, and acquiring the target data includes: Identify the business related to at least a portion of the target data; Based on at least a portion of the target data, determine the business data table with access permissions from the second storage system of the business; as well as Read at least a portion of the target data from the determined business data table.

15. The method of claim 1, wherein the at least one data acquisition mode includes a task assignment-based acquisition mode, and acquiring the target data includes: Based on the data request, a data acquisition instruction is determined for acquiring at least a portion of the target data; The data acquisition instruction is provided to the data provider so that the data provider can initiate a data acquisition task corresponding to the data request. as well as The execution result of the data acquisition task is received from the data provider, and the execution result includes at least a portion of the target data.

16. The method of claim 15, further comprising: In response to determining that at least a portion of the target data does not satisfy the data request, an update request is generated for at least a portion of the target data; as well as The update request is provided to the data provider to obtain the updated target data, at least a portion thereof.

17. An apparatus for uniformly processing data requests, comprising: The first acquisition module is configured to acquire a data request for target data, the data request being related to the data requirement scenario and at least including the scope of use of the target data; The determination module is configured to, in response to the data request being verified, determine at least one data acquisition mode from a plurality of data acquisition modes based on data protection requirements related to the target data, wherein different data acquisition modes among the plurality of data acquisition modes are configured to acquire business data with different data protection requirements; The second acquisition module is configured to acquire the target data according to the at least one data acquisition mode; as well as A module is provided, configured to provide access to the target data based on the scope of use.

18. An electronic device comprising: At least one processing unit; as well as At least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, the instructions causing the electronic device to perform the method according to any one of claims 1 to 16 when executed by the at least one processing unit.

19. A computer-readable storage medium having a computer program stored thereon, the computer program being executable by a processor to implement the method according to any one of claims 1 to 16.

20. A computer program product comprising a computer program, wherein the computer program, when executed by a processor, implements the method according to any one of claims 1 to 16.

Citation Information

Patent Citations

  • Business data processing method and device, electronic equipment and medium

    CN113961311A

  • Data access control method and device

    CN115357880A

  • Method, device and equipment for data security and storage medium

    CN115758419A

  • Data access method and device based on business scene, equipment and medium

    CN116094832A

  • Request processing method and apparatus, and device and storage medium

    WO2025077302A1