Data is used to determine methods, devices, media, equipment, and products using control strategies.

CN121144566BActive Publication Date: 2026-08-14BEIJING ELECTRONIC DIGITAL INTELLIGENCE TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-15
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

但是由于数据使用控制策略极为繁琐,涉及面广,给用户(特指数据持有方)带来诸多操作上的不便

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121144566B_ABST
    Figure CN121144566B_ABST
Patent Text Reader

Abstract

This disclosure relates to a method, apparatus, medium, device, and product for determining a data usage control strategy, belonging to the field of data circulation technology. The method includes: acquiring data usage demand information input by a user and generating a data usage demand vector; retrieving a control strategy template and data usage constraints from a knowledge base based on similarity retrieval according to the data usage demand vector; updating the control strategy template according to the data usage demand vector and the data usage constraints, thereby generating a data usage control strategy corresponding to the data usage demand information. This method can automatically generate a data usage control strategy based on user input information, reducing the complexity of data usage control strategy configuration and improving data circulation efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of data circulation technology, and more specifically, to a method, apparatus, medium, equipment, and product for determining data usage control strategies. Background Technology

[0002] With the increasing trend of data flow, configuring control strategies for data circulation and use is a common practice. For example, trusted data space products require configuration of security policies for data circulation and use. However, data use control strategies are extremely cumbersome and involve a wide range of aspects, causing many operational inconveniences for users (especially data holders). Common data use control strategies include: constraints on the scope of data users, constraints on the time of data use, constraints on the number of times data is used, constraints on the terminals that operate on the data, and constraints on the applications that use the data, etc. Currently, products generally use drop-down lists or input boxes to allow users to configure these strategies one by one. Completing the configuration of a single strategy requires an average of more than ten clicks and several page jumps, which is time-consuming and seriously affects the efficiency of data circulation. Summary of the Invention

[0003] To overcome the problems existing in the related technologies, this disclosure provides a data processing method, apparatus, electronic device, storage medium, and program product.

[0004] According to a first aspect of the present disclosure, a method for determining a data usage control strategy is provided, comprising: Obtain user input data usage requirements information and generate a data usage requirements vector; Based on similarity retrieval, control strategy templates and data usage constraints are obtained from the knowledge base according to the data usage demand vector; The control strategy template is updated based on the data usage demand vector and the data usage constraints to generate a data usage control strategy corresponding to the data usage demand information.

[0005] Optionally, the knowledge base includes a suggestion-type knowledge base and a constraint-type knowledge base. The similarity-based retrieval of control strategy templates and data usage constraints from the knowledge base according to the data usage demand vector includes: Based on similarity retrieval, control strategy templates are obtained from the suggestion knowledge base according to the data usage demand vector, and data usage constraints are obtained from the constraint knowledge base.

[0006] Optionally, generating a data usage control strategy corresponding to the data usage requirement information includes: During the generation of the data using the control strategy, conflict detection is performed; When a policy conflict is detected, a conflict query message is output, which is used to enable the user to input conflict resolution information based on the conflict query message. Obtain the conflict resolution information input by the user, and update the control strategy template based on the data usage demand vector, the data usage constraints, and the conflict resolution information.

[0007] Optionally, the method further includes: The output data uses a control strategy; Obtain confirmation information from the user regarding the use of control policies on the data; When the confirmation information includes modification information for the data usage control policy, the data usage control policy is updated according to the modification information; When the confirmation information does not include the modification information, the data is published using a control strategy.

[0008] Optionally, the method further includes: The knowledge base is updated using a control strategy based on the data.

[0009] Optionally, the data usage requirement information includes one or more of the following: data description information, data user identifier, data usage time constraint, data usage frequency constraint, device identifier, application identifier, secure computing technology constraint, approval method, and application scenario description information.

[0010] According to a second aspect of the present disclosure, a data usage control strategy determination apparatus is provided, comprising: The acquisition module is used to acquire user-input data usage requirement information and generate a data usage requirement vector. The retrieval module is used to retrieve control strategy templates and data usage constraints from the knowledge base based on similarity retrieval and the data usage demand vector. The generation module is used to update the control strategy template according to the data usage demand vector and the data usage constraints, and generate a data usage control strategy corresponding to the data usage demand information.

[0011] According to a third aspect of the present disclosure, a non-transitory computer-readable storage medium is provided, on which a computer program is stored, wherein when the program is executed by a processor, it implements the steps of the data usage control strategy determination method provided in the first aspect above.

[0012] According to a fourth aspect of the present disclosure, an electronic device is provided, comprising: A memory on which computer programs are stored; A processor is configured to execute the computer program in the memory to implement the steps of the data determination method using a control strategy provided in the first aspect above.

[0013] According to a fifth aspect of the present disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of the data usage control strategy determination method provided in the first aspect above.

[0014] The above technical solution obtains user-inputted data usage requirement information and generates a data usage requirement vector. Based on similarity retrieval, a control strategy template and data usage constraints are retrieved from a knowledge base according to this data usage requirement vector. The control strategy template is then updated based on the data usage requirement vector and the data usage constraints, generating a data usage control strategy corresponding to the data usage requirement information. This method can automatically generate data usage control strategies based on user input information, reducing the complexity of data usage control strategy configuration and improving data flow efficiency.

[0015] Other features and advantages of this disclosure will be described in detail in the following detailed description section. Attached Figure Description

[0016] The accompanying drawings are provided to further understand the present disclosure and form part of the specification. They are used together with the following detailed description to explain the present disclosure, but do not constitute a limitation thereof.

[0017] Figure 1 This is a flowchart illustrating a data usage control strategy determination method according to an exemplary embodiment.

[0018] Figure 2 This is a flowchart illustrating a data usage control strategy determination method according to an exemplary embodiment.

[0019] Figure 3 This is a flowchart illustrating a data usage control strategy determination method according to an exemplary embodiment.

[0020] Figure 4 This is a schematic diagram of a data usage control strategy determination device 400 according to an exemplary embodiment.

[0021] Figure 5 This is a block diagram illustrating an electronic device 500 according to an exemplary embodiment.

[0022] Figure 6 This is a block diagram illustrating an electronic device 600 according to an exemplary embodiment. Detailed Implementation

[0023] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.

[0024] It is understood that the terms "first," "second," etc., used in this disclosure are used to describe various types of information, but such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another and do not indicate a particular order or degree of importance.

[0025] It is further understood that although operations are described in a specific order in the accompanying drawings in the embodiments of this disclosure, this should not be construed as requiring these operations to be performed in the specific order or serial order shown, or requiring all of the shown operations to be performed to obtain the desired result. In certain environments, multitasking and parallel processing may be advantageous.

[0026] It should be noted that all actions involving the acquisition of signals, information, or data in this application are carried out in compliance with the relevant data protection laws and policies of the country where the application is located, and with the authorization granted by the owner of the relevant device.

[0027] Data holders (users) typically need to configure different data usage control policies for different data users. These policies can include: constraints on the scope of data users, such as global searchability, industry-specific searchability, or searchability for specific user groups; constraints on the duration of data use, such as unlimited use or use within specific time periods; constraints on the number of times data is used, such as no limit or a specified number of uses; constraints on the terminals that handle the data, such as requiring device authentication for designated terminals; constraints on the applications that use the data, such as specifying that the data is used for statistical analysis, model training, or other purposes; restrictions on the secure computing technologies used to access the data, such as privacy computing, requiring specific security technologies for circulation; and constraints on approval policies, such as requiring manual approval or requiring approval at a specific management level before circulation. In addition to the above constraints, the data usage control policy can also include deeper constraints such as data sensitivity level (top secret / confidential / public), circulation scenario attributes (scientific research / commercial / governmental), and additional compliance conditions (GDPR special provisions, industry regulatory requirements).

[0028] Therefore, the current method of allowing users to configure the above strategies one by one using dropdown menus or input boxes has many drawbacks, including: It requires multiple clicks and page navigation on average to complete the configuration of a single strategy, resulting in long processing times and severely impacting data flow efficiency. The operation is difficult and prone to errors: users need to have professional data compliance knowledge, otherwise they may encounter risks due to conflicts between configuration and policies and regulations; for example, a company once failed to pay attention to the revision of the "Measures for Security Assessment of Data Export", and mistakenly configured sensitive data to "export directly without approval", which triggered compliance risks. Frequent logical contradictions: Manual configuration is difficult to avoid logical conflicts, such as setting "unlimited time use" and "specified number of times 3" at the same time, which can cause abnormalities when the strategy is executed.

[0029] Long response time: When policies and regulations are updated or business scenarios change, the traditional model requires manual updates of all relevant strategy configurations, resulting in a long average response time and difficulty in coping with rapidly changing compliance requirements.

[0030] To address the aforementioned issues, this disclosure provides a method for determining data usage control strategies. This method uses user-inputted data usage requirements to search a knowledge base for the control strategy template and data usage constraints that have the highest similarity to the user's input data usage requirements. The control strategy template is then updated based on the data usage requirements and constraints, thereby automatically generating a data usage control strategy corresponding to the user's data usage requirements. This approach enables rapid generation of data usage control strategies, reduces logical inconsistencies caused by manual configuration, and improves data flow efficiency.

[0031] Figure 1 This is a flowchart illustrating a method for determining data using a control strategy, according to an exemplary embodiment. Figure 1 As shown, the method includes the following steps: In step S11, the user-inputted data usage requirement information is obtained, and a data usage requirement vector is generated.

[0032] For example, during the generation of data usage control strategies, users can describe the data flow scenario in natural language (such as text / voice and other multimodal forms) as data usage requirement information input by the user. In the process of generating the data usage requirement vector based on this information, the corresponding data usage requirement vector can be generated through keyword extraction, expansion, and other methods based on natural language processing (NLP). This disclosure does not limit the method used to generate the data usage requirement vector.

[0033] Optionally, the data usage requirement information includes one or more of the following: data description information, data user identifier, data usage time constraint, data usage frequency constraint, device identifier, application identifier, secure computing technology constraint, approval method, and application scenario description information.

[0034] For example, the data usage requirement information may include: data description information, such as data security attributes, number of data entries, and other information closely related to the data application value (such as data timeliness); data user identifiers, such as the data user's identity ID or data user group ID; data usage time constraints, such as start and end dates, time duration, or expiration date; data usage frequency constraints, such as the maximum number of uses; device identifiers, such as the device ID or device group ID using the data; application identifiers, such as the application ID using the data, which can be bound to the application's hash value; secure computing technology constraints, such as one of the technologies such as de-identification, encryption, sandboxing, or privacy computing; application scenario description information, such as a natural language description of the application scenario, which can be keywords, such as statistical analysis, large model training, or financial risk control; and approval methods, such as the data manager's approval method for data usage control strategies, which may be manual, automatic, or a combination of methods.

[0035] In step S12, based on similarity retrieval, control strategy templates and data usage constraints are obtained from the knowledge base according to the data usage demand vector.

[0036] For example, similarity search can find the most similar data to a given query in a large dataset. For instance, it can use word embeddings (such as Word2Vec and BERT) to convert text into vectors, that is, to convert data usage requirement information into data usage requirement vectors. Then, it can calculate the cosine similarity between the data usage requirement vector and the vectors in the knowledge base to obtain the most similar control strategy template and data usage constraints.

[0037] Optionally, the knowledge base includes a suggestion-type knowledge base and a constraint-type knowledge base. Step S12 includes retrieving control strategy templates from the suggestion-type knowledge base based on similarity and using the data usage requirement vector, and retrieving data usage constraints from the constraint-type knowledge base.

[0038] For example, before obtaining the control strategy template and the data usage constraints, a knowledge base needs to be built first. This knowledge base can read past data usage case materials. By building a data circulation knowledge base containing N-tuples based on past data usage case materials, it can provide users with interfaces for collection, supplementation, and query. This knowledge base can also support manual supplementation of case strategies.

[0039] In one possible embodiment, the knowledge base may include a suggestion-type knowledge base and a constraint-type knowledge base; This suggestion-based knowledge base can provide feasible suggestions for data usage control strategies. Combining user historical experience and application scenarios, it refines and optimizes control strategy templates. This suggestion-based knowledge base can be represented in the form of N-tuples, for example: <data description information, data user identifier, data usage time constraint, data usage frequency constraint, device identifier, application identifier, secure computing technology constraint, approval method, application scenario description information>. The fields in this N-tuple can be expanded according to actual needs. Furthermore, to handle similarity searches, key information such as "data description information," "data user identifier," and "application scenario description information" can be vectorized and stored.

[0040] This constraint-based knowledge base can be used to verify whether the configuration of data usage control policies violates existing laws and regulations. It is formed by extracting constraint clauses from existing policies, laws, and standards, including general data usage rules such as existing data security laws and personal information protection laws (e.g., regarding the circulation of personal information, it is prohibited to use it by third parties without the individual's separate authorization); and knowledge rules applicable to the enterprise (e.g., data above security level 3 cannot be circulated or used externally without desensitization and downgrading). For example, this constraint-based knowledge base can be represented in the form of 2-tuples, such as <data security attribute information, prohibition / constraint condition>. Data security attribute information can include: whether it is personal information, whether it is corporate secret information, security level information, etc. For example, when the data to be circulated is personal information, the configuration of the usage control policy should clearly state that the data has been authorized by the individual; or, when corporate secret information is at security level 4, it should prompt that desensitization and downgrading are required, otherwise it cannot be circulated directly; or, when the data is at security level 2, if the security policy configuration does not use encryption technology but only uses partial field desensitization and replacement, the system will prompt a contradiction and suggest the use of encryption technology. Furthermore, this constraint-based knowledge base can automatically read in policy, legal, regulatory, and standard documents, setting keywords such as "personal information," "corporate secrets," "sensitive data," and "security level" as "data security attributes." It also adds corresponding "prohibited / constrained conditions" (only filtering those applicable to data circulation scenarios) to the binary tuples. The set of binary tuples can be continuously mined and supplemented based on policy updates. Therefore, data usage constraints obtained from this constraint-based knowledge base can be used in the data circulation control strategy generation stage to identify and match data about to be circulated based on "data security attribute information," and provide real-time compliance alerts.

[0041] Optionally, the method also includes updating the knowledge base using a control strategy based on the data.

[0042] For example, after generating the data usage control policy, the knowledge base can be updated according to the data usage control policy. For instance, the data usage control policy can be added to the knowledge base as a new control policy template to ensure that the knowledge base has richer content, thereby providing a more accurate usage control template. In step S13, the control strategy template is updated according to the data usage demand vector and the data usage constraints to generate a data usage control strategy corresponding to the data usage demand information.

[0043] For example, after obtaining the control policy template, the control policy template can be updated according to the data usage demand vector and the data usage constraints. This update process may include modifying, deleting, or adding corresponding data usage terms to the control policy template; this disclosure does not limit the update process. In one possible embodiment, when obtaining the control policy template from the knowledge base, the K most similar control policy templates can be obtained, and K data usage control policies can be generated based on these K templates. The generated K data usage control policies are then sent to the user, who can select a data usage control policy from among them.

[0044] The above technical solution obtains user-inputted data usage requirement information and generates a data usage requirement vector. Based on similarity retrieval, a control strategy template and data usage constraints are retrieved from a knowledge base according to this data usage requirement vector. The control strategy template is then updated based on the data usage requirement vector and the data usage constraints, generating a data usage control strategy corresponding to the data usage requirement information. This method can automatically generate data usage control strategies based on user input information, reducing the complexity of data usage control strategy configuration and improving data flow efficiency.

[0045] Figure 2 This is a flowchart illustrating a method for determining data using a control strategy, according to an exemplary embodiment. Figure 2 As shown, step S13 includes: In step S131, conflict detection is performed during the process of generating the data using the control strategy.

[0046] For example, conflict detection during the generation of the data usage control policy can avoid logical contradictions and regulatory conflicts in the generated data usage control policy. For instance, the generated data usage control policy may contain parallel clauses, such as setting "unlimited time use" and "specified number of times 3" at the same time, which may cause anomalies when the policy is executed. Or, if the corresponding data usage constraints are detected, such as data circulation requiring authorization but not being authorized, or encrypted data not being encrypted, the generated data usage control policy may fail to meet the user's needs.

[0047] In step S132, when a policy conflict is detected, a conflict query message is output, which is used to allow the user to input conflict resolution information based on the conflict query message.

[0048] In step S133, the conflict resolution information input by the user is obtained, and the control strategy template is updated based on the data usage demand vector, the data usage constraints, and the conflict resolution information.

[0049] In the example line, to avoid policy conflicts in the generated data usage control policy, a conflict query can be sent to the user upon detecting a conflict. The user can then input conflict resolution information based on this query, and the control policy template is updated according to the data usage requirement vector, the data usage constraints, and the conflict resolution information. For instance, if both "unlimited time use" and "specified number of times (3)" need to be set simultaneously when generating the data usage control policy, a message can be sent to the user indicating a policy conflict between these two options. If the user selects "specified number of times (3)" as the conflict resolution information, the control policy template is updated based on this "specified number of times (3)," the data usage requirement vector, and the data usage constraints to generate a data usage control policy corresponding to the data usage requirement information. For example, when generating the data usage control policy, if the corresponding data usage constraints are detected, such as the need for data circulation to be encrypted, a prompt message can be sent to the user to encrypt the circulating data, so that the user can encrypt the circulating data according to the message. After obtaining the user's information that the encryption has been completed, the data usage control policy corresponding to the data usage requirement information can be regenerated.

[0050] In one possible embodiment, this method can be applied to medical data circulation scenarios. If the user inputs data usage requirements as "providing diabetes patient diagnosis and treatment data to 3 pharmaceutical companies for new drug development, the data needs to be anonymized, and the usage period is 12 months," the method retrieves the data usage control strategy with the highest similarity in the knowledge base, "providing hypertension data to XX pharmaceutical company in 2024," as a control strategy template. Based on this control strategy template, the data usage period can be adjusted from "6 months" to "12 months," the hypertension data can be updated to diabetes data, and an "ethics committee" step can be added to the approval process (because diabetes is a special disease). Secondly, the retrieved data usage constraints include "although the data has been anonymized, it is still necessary to confirm whether it complies with Article 15 of the 'Measures for Ethical Review of Biomedical Research Involving Human Subjects.'" Therefore, this confirmation information needs to be sent to the user. After receiving the user's confirmation information, the data usage control strategy is published, and the case is automatically stored in the knowledge base to improve the accuracy of generating data usage control strategies for similar scenarios in the future.

[0051] In one possible implementation, this method can be applied to financial data circulation scenarios. For example, a bank needs to provide corporate credit data to a cooperating credit reporting agency for risk control model training. The data includes basic corporate information and transaction records (security level: confidential). The configuration process may require simultaneous compliance with the Data Security Law, the Personal Information Protection Law, and specific requirements of the State Financial Regulatory Commission, resulting in complex strategy combinations. Traditional manual configuration easily overlooks compliance requirements such as "confidential data must be transmitted encrypted" and "applications must be bound to hash values."

[0052] Using the method provided in this disclosure, if the user's input data usage requirement information is "providing corporate credit data to credit reporting agencies for risk control model training, with a data security level of confidentiality"; based on similarity retrieval, the data with the highest similarity in the knowledge base, "providing personal credit data to XX credit reporting agency in 2025", is used as the control policy template. This control policy template includes: user scope: specified credit reporting agency ID; secure computing technology constraints: national cryptographic SM4 encryption + privacy computing joint modeling; approval process: automatic approval by the head office data security department + manual review; and updating the control policy according to the user's input data usage requirement information. Simplified template: Due to the confidentiality of the data, the encryption technology is upgraded from SM4 to a combination of SM2 and SM4; the application is bound to the hash value (0x123abc...) of the credit reporting agency's risk control model; and "if the data contains corporate transaction records, a conflict inquiry message must be sent to the user to confirm whether the de-identification processing required by the 'Financial Data Security Data Lifecycle Security Specification' has been completed"; after obtaining the user's confirmation that "field de-identification has been completed (hiding two decimal places of the transaction amount)," the data usage control policy is released, and this case is stored in the knowledge base to improve the accuracy of data usage control policy generation in subsequent similar scenarios.

[0053] In another possible embodiment, the method can also be applied to power data scenarios. For example, a provincial power company needs to provide a research institution with power load data and user electricity consumption behavior data for some regions to study new power load forecasting models and user-side demand response strategies. This data involves power load curves at different voltage levels, as well as information on the electricity consumption periods and electricity consumption of tens of millions of users. The data is highly sensitive and its security level is confidential. Traditional configuration processes are complex and prone to problems: they must meet the "Power Data Security Management Measures" and relevant regulations of the National Energy Administration. Policy configuration must take into account multiple requirements such as data classification and hierarchical protection, transmission encryption, and access approval, making manual processing extremely tedious. Since the data involves user privacy, strict standards must be followed in data anonymization and desensitization. Manual configuration is prone to overlooking key steps, such as failing to effectively obfuscate user electricity addresses, which poses a risk of privacy leakage. The configuration time is long, averaging 2-3 hours from identifying requirements to completing policy settings, which seriously affects the efficiency of research projects.

[0054] Using the method provided in this disclosure, if the user's input data usage requirement information is "to provide energy research institutions with partial regional power load data and user electricity consumption behavior data for power load forecasting and demand response research, with a data security level of confidential," the data usage control strategy template is used based on the most similar data retrieved from the knowledge base: "providing power grid fault data to XX university in 2024 for scientific research analysis." This control strategy template includes: User scope: a unique identifier for the designated energy research institution; Data usage time constraint: limited to a project period of 18 months; Secure computing technology constraint: using homomorphic encryption technology to ensure data transmission and computing security; Approval process: preliminary review by the power company's data security department + final review by the scientific research management department. The control policy template is updated based on user input data and usage requirements: Given the confidentiality of the data, encryption requirements for data storage are increased, and AES-256 encryption can be used to encrypt locally stored data; considering the privacy characteristics of user electricity consumption data, data anonymization rules are automatically configured, such as irreversible encryption of sensitive fields like user names and ID numbers, and obfuscation of electricity addresses (retaining only regional information); and "if data containing user electricity consumption information is detected, a conflict inquiry message must be sent to the user to confirm whether the minimum necessary principle of screening has been completed in accordance with the Personal Information Protection Law, ensuring that only research-related data is provided"; after obtaining supplementary explanations from the user that data screening has been completed, retaining only core fields such as electricity consumption time and electricity consumption, the data usage control policy is generated and published, and the case is stored in the knowledge base to improve the accuracy of generating data usage control policies for similar scenarios in the future.

[0055] In summary, the data use control strategy determination method provided in this disclosure has a short configuration time for a single strategy, which can improve configuration efficiency; it can also improve the compliance rate of strategy configuration through real-time regulatory verification and contradiction detection; it can respond to policy and regulatory updates in a timely manner and automatically synchronize updated rules; and it does not require users to have professional compliance knowledge, thus reducing labor costs.

[0056] Figure 3 This is a flowchart illustrating a method for determining data using a control strategy, according to an exemplary embodiment. Figure 3 As shown, the method also includes: In step S14, the data is output using a control strategy.

[0057] In step S15, the user's confirmation information regarding the use of control policies on the data is obtained.

[0058] In step S16, if the confirmation information contains modification information regarding the control policy for the data, the control policy for the data is updated according to the modification information.

[0059] In step S17, if the confirmation information does not contain the modification information, the data is published using the control policy.

[0060] For example, after generating the data usage control policy, to improve its accuracy, the policy can be sent to the user for verification. During verification, the user can choose to receive or modify the policy. Therefore, after sending the policy to the user, confirmation information can be obtained. If the confirmation information does not contain any modification information, the policy can be published. If the confirmation information does contain modification information, the policy can be updated accordingly. For instance, if the policy specifies a data usage period of one month, and the modification information changes it to three months, the modified policy will have a data usage period of three months. Furthermore, it is understood that after each update, the updated policy can be sent to the user for confirmation until the received confirmation information no longer contains modification information, at which point the policy can be published.

[0061] The above technical solution obtains user-inputted data usage requirement information and generates a data usage requirement vector. Based on similarity retrieval, a control strategy template and data usage constraints are retrieved from a knowledge base according to this data usage requirement vector. The control strategy template is then updated based on the data usage requirement vector and the data usage constraints, generating a data usage control strategy corresponding to the data usage requirement information. This method can automatically generate data usage control strategies based on user input information, reducing the complexity of data usage control strategy configuration and improving data flow efficiency.

[0062] Figure 4 This is a schematic diagram illustrating a data usage control strategy determination device 400 according to an exemplary embodiment. Figure 4 As shown, the device 400 includes: an acquisition module 410, a retrieval module 420, and a generation module 430; The acquisition module 410 is used to acquire user-inputted data usage requirement information and generate a data usage requirement vector. The retrieval module 420 is used to retrieve control strategy templates and data usage constraints from the knowledge base based on similarity retrieval and the data usage demand vector. The generation module 430 is used to update the control strategy template based on the data usage demand vector and the data usage constraints, and generate a data usage control strategy corresponding to the data usage demand information.

[0063] Optionally, the knowledge base includes a suggestion-type knowledge base and a constraint-type knowledge base. The retrieval module 420 is used to retrieve control strategy templates from the suggestion-type knowledge base and data usage constraints from the constraint-type knowledge base based on similarity retrieval and according to the data usage requirement vector.

[0064] Optionally, the generation module 430 includes: a detection submodule, a sending submodule, and an update submodule; This detection submodule is used to perform conflict detection during the process of generating the data using the control strategy; The sending submodule is used to output conflict query information when a policy conflict is detected. The conflict query information is used to enable the user to input conflict resolution information based on the conflict query information. This update submodule is used to obtain the conflict resolution information input by the user, and update the control strategy template based on the data usage demand vector, the data usage constraints, and the conflict resolution information.

[0065] Optionally, the generation module 430 is used for: This data is output using a control strategy; Obtain confirmation information from the user regarding the control policy applied to this data; When the confirmation information contains modification information regarding the control policy used on the data, the control policy used on the data is updated according to the modification information; If the confirmation information does not include the modified information, the data is published using the control policy.

[0066] Optionally, the generation module 430 is also used to update the knowledge base using a control strategy based on the data.

[0067] Optionally, the data usage requirement information includes one or more of the following: data description information, data user identifier, data usage time constraint, data usage frequency constraint, device identifier, application identifier, secure computing technology constraint, approval method, and application scenario description information.

[0068] The above technical solution obtains user-inputted data usage requirement information and generates a data usage requirement vector. Based on similarity retrieval, a control strategy template and data usage constraints are retrieved from a knowledge base according to this data usage requirement vector. The control strategy template is then updated based on the data usage requirement vector and the data usage constraints, generating a data usage control strategy corresponding to the data usage requirement information. This method can automatically generate data usage control strategies based on user input information, reducing the complexity of data usage control strategy configuration and improving data flow efficiency.

[0069] Regarding the apparatus in the above embodiments, the specific manner in which each module performs its operation has been described in detail in the embodiments related to the method, and will not be elaborated upon here.

[0070] Figure 5 This is a block diagram illustrating an electronic device 500 according to an exemplary embodiment. For example... Figure 5 As shown, the electronic device 500 may include a processor 501 and a memory 502. The electronic device 500 may also include one or more of a multimedia component 503, an input / output (I / O) interface 504, and a communication component 505.

[0071] The processor 501 controls the overall operation of the electronic device 500 to complete all or part of the steps in the data usage control strategy determination method described above. The memory 502 stores various types of data to support the operation of the electronic device 500. This data may include, for example, instructions for any application or method operating on the electronic device 500, and application-related data such as contact data, sent and received messages, pictures, audio, video, etc. The memory 502 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read-Only Memory (EPROM), Programmable Read-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The multimedia component 503 may include a screen and audio components. The screen may be, for example, a touchscreen, and the audio component is used to output and / or input audio signals. For example, the audio component may include a microphone for receiving external audio signals. The received audio signals may be further stored in memory 502 or transmitted via communication component 505. The audio component also includes at least one speaker for outputting audio signals. I / O interface 504 provides an interface between processor 501 and other interface modules, such as a keyboard, mouse, buttons, etc. These buttons may be virtual or physical. Communication component 505 is used for wired or wireless communication between the electronic device 500 and other devices. Wireless communication, such as Wi-Fi, Bluetooth, Near Field Communication (NFC), 2G, 3G, 4G, NB-IoT, eMTC, or other 5G technologies, or combinations thereof, is not limited here. Therefore, the corresponding communication component 505 may include: a Wi-Fi module, a Bluetooth module, an NFC module, etc.

[0072] In an exemplary embodiment, the electronic device 500 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the data usage control strategy determination method described above.

[0073] In another exemplary embodiment, a computer-readable storage medium including program instructions is also provided, which, when executed by a processor, implement the steps of the data usage control policy determination method described above. For example, the computer-readable storage medium may be the memory 502 including the program instructions described above, which may be executed by the processor 501 of the electronic device 500 to complete the data usage control policy determination method described above.

[0074] Figure 6 This is a block diagram illustrating an electronic device 600 according to an exemplary embodiment. For example, the electronic device 600 may be provided as a server. (Refer to...) Figure 6 The electronic device 600 includes a processor 622, which may be one or more, and a memory 632 for storing computer programs executable by the processor 622. The computer program stored in the memory 632 may include one or more modules, each corresponding to a set of instructions. Furthermore, the processor 622 may be configured to execute the computer program to perform the aforementioned data usage control strategy determination method.

[0075] Additionally, the electronic device 600 may also include a power supply component 626 and a communication component 650. The power supply component 626 can be configured to perform power management of the electronic device 600, and the communication component 650 can be configured to enable communication of the electronic device 600, such as wired or wireless communication. Furthermore, the electronic device 600 may also include an input / output (I / O) interface 658. The electronic device 600 can operate on an operating system stored in memory 632.

[0076] In another exemplary embodiment, a computer-readable storage medium including program instructions is also provided, which, when executed by a processor, implement the steps of the data usage control policy determination method described above. For example, the non-transitory computer-readable storage medium may be the memory 632 including the program instructions described above, which may be executed by the processor 622 of the electronic device 600 to complete the data usage control policy determination method described above.

[0077] In another exemplary embodiment, a computer program product is also provided, the computer program product comprising a computer program executable by a programmable device, the computer program having a code portion for performing the above-described data usage control strategy determination method when executed by the programmable device.

[0078] The preferred embodiments of this disclosure have been described in detail above with reference to the accompanying drawings. However, this disclosure is not limited to the specific details of the above embodiments. Within the scope of the technical concept of this disclosure, various simple modifications can be made to the technical solutions of this disclosure, and these simple modifications all fall within the protection scope of this disclosure.

[0079] It should also be noted that the various specific technical features described in the above specific embodiments can be combined in any suitable manner without contradiction. In order to avoid unnecessary repetition, this disclosure will not describe the various possible combinations separately.

[0080] Furthermore, various different embodiments of this disclosure can be combined in any way, as long as they do not violate the spirit of this disclosure, they should also be regarded as the content disclosed in this disclosure.

Claims

1. A method for determining data using a control strategy, characterized in that, include: Obtain user input data usage requirements information and generate a data usage requirements vector; Based on similarity retrieval, control strategy templates and data usage constraints are obtained from the knowledge base according to the data usage demand vector; The control strategy template is updated based on the data usage demand vector and the data usage constraints to generate a data usage control strategy corresponding to the data usage demand information. The output data uses a control strategy; Obtain confirmation information from the user regarding the use of control policies on the data; When the confirmation information includes modification information for the data usage control policy, the data usage control policy is updated according to the modification information; When the confirmation information does not contain the modification information, the data is published using a control strategy; The generation of a data usage control strategy corresponding to the data usage requirement information includes: During the generation of the data using the control strategy, conflict detection is performed; When a policy conflict is detected, a conflict query message is output, which is used to enable the user to input conflict resolution information based on the conflict query message. Obtain the conflict resolution information input by the user, and update the control strategy template based on the data usage demand vector, the data usage constraints, and the conflict resolution information.

2. The method according to claim 1, characterized in that, The knowledge base includes a suggestion-type knowledge base and a constraint-type knowledge base. The similarity-based retrieval process, which retrieves control strategy templates and data usage constraints from the knowledge base according to the data usage demand vector, includes: Based on similarity retrieval, control strategy templates are obtained from the suggestion knowledge base according to the data usage demand vector, and data usage constraints are obtained from the constraint knowledge base.

3. The method according to claim 1, characterized in that, The method further includes: The knowledge base is updated using a control strategy based on the data.

4. The method according to any one of claims 1 to 3, characterized in that, The data usage requirement information includes one or more of the following: data description information, data user identifier, data usage time constraint, data usage frequency constraint, device identifier, application identifier, secure computing technology constraint, approval method, and application scenario description information.

5. A data usage control strategy determination device, characterized in that, include: The acquisition module is used to acquire user-input data usage requirement information and generate a data usage requirement vector. The retrieval module is used to retrieve control strategy templates and data usage constraints from the knowledge base based on similarity retrieval and the data usage demand vector. The generation module is used to update the control strategy template according to the data usage demand vector and the data usage constraints, and generate a data usage control strategy corresponding to the data usage demand information; The generation module is further configured to output the data usage control policy; obtain confirmation information from the user regarding the data usage control policy; update the data usage control policy according to the modification information when the confirmation information includes modification information; and publish the data usage control policy when the confirmation information does not include the modification information. The generation of a data usage control strategy corresponding to the data usage requirement information includes: During the generation of the data using the control strategy, conflict detection is performed; When a policy conflict is detected, a conflict query message is output, which is used to enable the user to input conflict resolution information based on the conflict query message. Obtain the conflict resolution information input by the user, and update the control strategy template based on the data usage demand vector, the data usage constraints, and the conflict resolution information.

6. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the steps of the method described in any one of claims 1 to 4.

7. An electronic device, characterized in that, include: A memory on which computer programs are stored; A processor for executing the computer program in the memory to implement the steps of the method according to any one of claims 1 to 4.

8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Specifying an access control policy

    CN102341808A

  • Access-control-policy template generating device, and system, method and program thereof

    CN102388387A