Data outbound security management and control method and system based on dynamic authorization

By identifying the mapping relationship between personal information and subject data in domestic databases, and combining dynamic authorization mechanisms and cross-border gateway systems, the problem of insufficient control over the amount of personal information leaving the country in existing technologies has been solved, and dynamic, accurate and compliant management of data leaving the country has been achieved.

CN121808807APending Publication Date: 2026-04-07BEIJING XINLIAN SHUAN TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-25
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing security control solutions for cross-border transfer of personal information mainly focus on access control at the database table level, lacking effective control over the amount of personal information transferred abroad, making it difficult to achieve dynamic, accurate, and compliant management of cross-border data activities.

Method used

By identifying the mapping relationship between personal information data and individual subject data in domestic databases, counting the number of data that have been exported, and combining this with cross-border query operations, a dynamic authorization mechanism is designed and a cross-border gateway system is deployed to realize logical verification and authorization control of database access operations.

Benefits of technology

It enables dynamic, precise, and compliant control over cross-border personal information data, improves the efficiency of security management of outbound data, avoids the risk of violations, and ensures data compliance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121808807A_ABST
    Figure CN121808807A_ABST
Patent Text Reader

Abstract

The invention relates to a data departure security management and control method based on dynamic authorization, and the method comprises the steps: carrying out the statistics of the number of duplicate-removed personal subject data mapped by departure personal information data based on the mapping relation between each piece of personal information data and each piece of personal subject data in a domestic database in combination with the classification of the personal information data; and recording database access operations related to personal information data cross-border query operations for domestic databases, and designing logic access verification and dynamic authorization for completing operation access for target database access operations executed for databases, tables or fields, so as to realize data outbound control. And a cross-border gateway system is deployed in front of the domestic database, a corresponding system is established, and all functional modules are built in to jointly complete a data exit security control method, so that the aim of cross-border dynamic, accurate and compliant control of personal information data is fulfilled.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to a data outbound security management method and system based on dynamic authorization, and belongs to the technical field of data outbound security. BACKGROUND

[0002] During the process of carrying out data cross-border activities, data processors need to strictly follow regulatory requirements, control the scale of personal information and important data according to the data outbound business scenario, and perform necessary evaluation and filing procedures. In the actual business development process, how to control data cross-border behavior in real time, especially personal information data outbound behavior, and ensure business compliance have become technical problems to be solved.

[0003] In cross-border business, data query and analysis through remote access is a common data cross-border business scenario. In this scenario, overseas business personnel will access the database system in the territory through remote access, execute database query, export and other statements, and view or obtain data in the territory. According to the requirements of data outbound related policies and regulations, the data collected and generated by the data processor are stored in the territory, and the behavior of querying, calling, downloading and exporting by overseas institutions, organizations or individuals is a data outbound behavior. If the number of personal information queried and called in the cross-border remote access process reaches the threshold value specified in the policy, the data processor needs to report the data outbound security evaluation, sign a standard contract for personal information outbound, or pass the personal information protection certification. At the same time, after completing the reporting and filing operation, the actual data cross-border business development situation also needs to be consistent with the reporting situation. This puts forward high requirements for the security management of personal information data remote access. The current personal information data outbound security management scheme mainly focuses on the management granularity of the access permission of the database table level, and the access management of the number of outbound personal information is obviously insufficient, lacking effective technical means and methods. SUMMARY

[0004] The technical problem to be solved by the application is to provide a data outbound security management method based on dynamic authorization, to design logical access verification for the database operation behavior of cross-border remote access, to complete operation authorization access control, and to achieve the goal of dynamic, accurate and compliant control of personal information data cross-border.

[0005] To address the aforementioned technical problems, this invention employs the following technical solution: This invention designs a data export security control method based on dynamic authorization. It involves real-time scanning of domestic databases to identify the mapping relationship between each piece of personal information data and each piece of uniquely identified personal subject data. Combined with the classification of personal information data, it counts the number of duplicate personal subject data mapped to exported personal information data, records database access operations involving cross-border queries of personal information data in domestic databases, and then targets target database access operations from overseas that are query operations on database, table, or field values, thereby achieving data export security control.

[0006] As a preferred technical solution of the present invention: based on real-time scanning of domestic databases, the following steps a to d are performed;

[0007] Step a. Scan domestic databases to perform data classification, identify individual pieces of personal information, and construct a list of personal information data. Each piece of personal information data is recorded under various personal information fields, and each uniquely identified individual subject data is also recorded under the individual subject field. Then, a mapping relationship is established between each piece of personal information data and each piece of individual subject data. Construct a mapping set Then proceed to step b;

[0008] Step b. Count the number of individual subject data entries after deduplication of the individual subject field. Based on the mapping relationship set For each type of personal information field, the number of deduplicated personal data entries mapped to each piece of personal information data under that field is counted, thereby obtaining the number of deduplicated personal data entries mapped to each type of personal information field. Then proceed to step c;

[0009] Step c. Based on the mapping relationship set The individual subject data mapped to each piece of personal information that has been exported are statistically analyzed and deduplicated before being added to the overall personal information export record table. Then, for each type of personal information field, the individual subject data mapped to each piece of personal information data that has been exported under that personal information field is statistically analyzed, and duplicate records are added to the corresponding personal information export subject record table for that personal information field, thereby obtaining the personal information export subject record table for each type of personal information field. Then proceed to step d;

[0010] Step d. Record the historical database access statements that successfully involved cross-border queries of personal information data in domestic databases to the cross-border query record table. .

[0011] As a preferred technical solution of the present invention: for target database access operations from overseas that are of the type of query operations on the values ​​of databases, tables or fields, the following steps A to F are performed to achieve data export security control;

[0012] Step A. Determine the number of deduplicated personal subject data entries in the domestic database. Whether it exceeds the preset threshold, and judgment If the threshold for the amount of personal subject data allowed to leave the country as declared by the domestic database processor is exceeded, and both judgments are negative, then the target database access operation on the domestic database is received, and the corresponding target execution result data is exported; otherwise, proceed to step B.

[0013] Step B. Extract the databases, tables, and fields involved in the target database access operation, and determine whether it involves a list of personal information data. If the personal information data in the database is correct, proceed to step C; otherwise, receive the target database access operation to operate on the domestic database and execute the export of the corresponding target execution result data.

[0014] Step C. Extract the target operation statements used by the target database access operation, and traverse the cross-border query record table. For each historical database access operation statement, determine whether there are any query results corresponding to the execution of the historical database access operation, including the query results corresponding to the execution of the target operation statement. If so, accept the operation of the target database access operation on the domestic database and execute the export of the corresponding target execution result data; otherwise, proceed to step D.

[0015] Step D. Traverse the various target personal information fields in the target execution result data to obtain the number of deduplicated personal subject data mapped to each type of target personal information field. and the corresponding record form of personal information of the subject leaving the country. length And according to the following formula:

[0016] ;

[0017] Calculation results This allows us to obtain the results corresponding to each of the various target personal information fields. Judge each result Whether all results do not exceed the preset threshold, and the judgment of each result. If both conditions are met, the target database access operation is received and executed on the domestic database, and the corresponding target execution result data is exported; otherwise, proceed to step E.

[0018] Step E. Based on the mapping set Mapping relationships Based on the target database access operation, an operation instruction is constructed to retrieve deduplicated outbound individual subject data from the domestic database. After execution, the individual subject data mapped to each piece of personal information data in the corresponding target execution result data is obtained, and deduplicated data is constructed to form an outbound individual subject record table corresponding to the target execution result data. Then proceed to step F;

[0019] Step F. Compile a record of entities exporting personal information abroad. Overall Personal Information Outbound Individual Entity Record Form The system merges and deduplicates the number of individual subject data, and determines whether it exceeds a preset threshold and whether it exceeds the threshold for the number of individual subject data that the domestic database processor is allowed to export. If both determinations are negative, the system executes the export of the corresponding target execution result data; otherwise, it rejects the export of the corresponding target execution result data.

[0020] As a preferred embodiment of the present invention: after the export of the corresponding target execution result data in step F, the process proceeds to step G as follows:

[0021] Step G. Add the target database access operation and its corresponding target execution result data to the cross-border query record table. Update the Personal Information Export Entity Record Form Add to the overall personal information exit record form In the middle, and on Perform deduplication and update; update the personal information export entity record form. Each individual's data is added to the corresponding personal information exit record table for each type of target personal information field. and for each Perform a deduplication update.

[0022] As a preferred technical solution of the present invention: for database access operations that are of the type of creating, modifying, or deleting operations on the structure of a database, table, or field, after the database access operation is successfully executed on a domestic database, a scan of the domestic database is triggered, and steps a to c are executed; for database access operations that are of the type of inserting, updating, or deleting operations on the value of a database, table, or field, after the database access operation is successfully executed on a domestic database, a scan of the domestic database is triggered, and steps a to b are executed.

[0023] Corresponding to the above, the technical problem to be solved by the present invention is to provide a system for a data export security control method based on dynamic authorization, which uses a cross-border gateway system previously deployed in the domestic database to complete the designed data export security control method and achieve the goal of dynamic, accurate and compliant cross-border control of personal information data.

[0024] To solve the above-mentioned technical problems, the present invention adopts the following technical solution: The present invention designs a system for data export security control based on dynamic authorization, including deploying a cross-border gateway system in front of a domestic database. The cross-border gateway system executes the data export security control method based on dynamic authorization. The cross-border gateway system includes a data access control module, a personal information subject association mapping module, and an export personal information subject detection module. The data access control module is connected in series on the communication link between the domestic database and the overseas database. At the same time, the data access control module communicates with the personal information subject association mapping module and the export personal information subject detection module. The personal information subject association mapping module and the export personal information subject detection module interact with the domestic database. Meanwhile, the personal information subject association mapping module provides data to the export personal information subject detection module.

[0025] As a preferred technical solution of the present invention: the data access control module is used to receive and analyze database access operations for domestic databases. If the database access operation is a query operation on the value of a database, table or field, the data access control module forwards the database access operation to the outbound personal information subject detection module for processing. Based on the feedback from the outbound personal information subject detection module, the data access control module decides whether to allow the database access operation to be executed. After the database access operation is successfully executed, the data access control module executes the outbound export of the corresponding execution result data and forwards the corresponding execution result data to the outbound personal information subject detection module.

[0026] If the database access operation is a creation, modification, or deletion operation on the structure of a database, table, or field, or an insertion, update, or deletion operation on the value of a database, table, or field, the data access control module allows the database access operation to be performed on a domestic database. After the database access operation is successfully executed, the data access control module will forward the corresponding execution result data to the personal information subject association mapping module.

[0027] As a preferred technical solution of the present invention: the personal information subject association mapping module is used to perform real-time scanning of the domestic database and execute steps a to b; and after the database access operation of the domestic database is successfully executed, the personal information subject association mapping module is triggered to scan the domestic database and execute steps a to b.

[0028] As a preferred technical solution of the present invention: the outbound personal information subject detection module is used to perform real-time scanning of the domestic database and execute steps c to d; and for target database access operations from overseas that belong to the type of query operation on the value of the database, table or field, the outbound personal information subject detection module executes steps A to G and feeds back to the data access control module.

[0029] The data export security control method and system based on dynamic authorization described in this invention, compared with the prior art, has the following technical advantages:

[0030] (1) This invention designs a data export security control method based on dynamic authorization. Based on the mapping relationship between each piece of personal information data and each piece of personal subject data in the domestic database, combined with the classification of personal information data, the number of duplicate personal subject data mapped by the personal information data that has been exported is counted, and the database access operations involving cross-border query operations of personal information data in the domestic database are recorded. Then, for the target database access operations performed on the database, table or field, logical access verification is designed to complete the dynamic authorization of operation access, realize data export control, and deploy a cross-border gateway system in front of the domestic database to build a corresponding system. Through the built-in functional modules, the data export security control method is completed to achieve the goal of dynamic, accurate and compliant cross-border control of personal information data.

[0031] (2) The present invention designs a data export security control method and system based on dynamic authorization. By intercepting database access operation requests between overseas data recipients and domestic data processors, and using the method of estimating the number of personal information exported, combined with the improved granularity of personal information data security control through association mapping, the database access operation statements are automatically modified to construct a two-level judgment architecture for accurate query of the number of personal information. The personal information subjects intending to export are queried and detected to determine whether to grant database access authorization for the personal information data behavior of export. Compared with the prior art, the design scheme of the present invention can clearly and objectively count the number of personal information subjects exporting, avoid the risk of violations, and improve the efficiency of export data control. Attached Figure Description

[0032] Figure 1 This is a flowchart of the data export security management method based on dynamic authorization designed in this invention;

[0033] Figure 2 This is a system architecture diagram of the data export security management method based on dynamic authorization designed in this invention. Detailed Implementation

[0034] The specific embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.

[0035] This invention designs a data export security control method based on dynamic authorization. In practical applications, it is based on real-time scanning of domestic databases, such as... Figure 1 As shown, perform the following steps a to d to identify the mapping relationship between each piece of personal information data and each piece of personal subject data with a unique identifier. In combination with the classification of personal information data, count the number of duplicate personal subject data mapped to the personal information data that has been exported, and record the database access operations involving cross-border query operations of personal information data in the domestic database.

[0036] Step a. Scan domestic databases to perform data classification, identify individual pieces of personal information, and construct a list of personal information data. Each piece of personal information data is recorded under various personal information fields, and each uniquely identified individual subject data is also recorded under the individual subject field. Then, a mapping relationship is established between each piece of personal information data and each piece of individual subject data. Construct a mapping set Then proceed to step b.

[0037] In practical applications, such as mapping relationships .in, This describes the mapping relationship. For personal information fields, For example, the User ID field is a unique identifier for an individual. Table A contains both User ID and other personal information fields such as ID card number and payment information. The mapping relationship between fields like ID card number and payment information will be defined. Set as map= For cases where a same-table scan fails, a cross-table scan can be performed using database foreign keys. For example, table A may have personal information fields such as height and weight, but no user ID field. However, it can be linked to table B through a foreign key field – medical record number. Table B may have a user ID field. Therefore, the mapping relationship between the height, weight, and other fields can be set to... ,in, For table A, For table B, This represents the medical record number field.

[0038] If multiple cross-table joins are required, a combined mapping can be set up. For example, to obtain the user ID field from table C by further joining the ID number field from table B, this can be denoted as... ,in, For table C, This represents the ID card number field.

[0039] Therefore, a mapping set is established between any personal information data in the database and the personal subject data with unique identifiers. , For each mapping relationship, This represents the total number of mapping relationships. Any piece of personal information data can be mapped to a unique individual subject data.

[0040] Step b. Count the number of individual subject data entries after deduplication of the individual subject field. Based on the mapping relationship set For each type of personal information field, the number of deduplicated personal data entries mapped to each piece of personal information data under that field is counted, thereby obtaining the number of deduplicated personal data entries mapped to each type of personal information field. Then proceed to step c.

[0041] Step c. Based on the mapping relationship set The individual subject data mapped to each piece of personal information that has been exported are statistically analyzed and deduplicated before being added to the overall personal information export record table. Then, for each type of personal information field, the individual subject data mapped to each piece of personal information data that has been exported under that personal information field is statistically analyzed, and duplicate records are added to the corresponding personal information export subject record table for that personal information field, thereby obtaining the personal information export subject record table for each type of personal information field. Then proceed to step d.

[0042] Step d. Record the historical database access statements that successfully involved cross-border queries of personal information data in domestic databases to the cross-border query record table. .

[0043] Based on the above scanning of domestic databases, in practical applications, for target database access operations originating from overseas that involve querying the values ​​of databases, tables, or fields, such as... Figure 1 As shown, the specific steps A to F are executed to achieve data export security control.

[0044] Step A. Determine the number of deduplicated personal subject data entries in the domestic database. Whether it exceeds the preset threshold, and judgment If the threshold for the amount of personal subject data allowed to leave the country as declared by the domestic database processor is exceeded, and both judgments are negative, then the target database access operation on the domestic database is received, and the corresponding target execution result data is exported; otherwise, proceed to step B.

[0045] Step B. Extract the databases, tables, and fields involved in the target database access operation, and determine whether it involves a list of personal information data. If the personal information data is correct, proceed to step C; otherwise, receive the target database access operation to operate on the domestic database and execute the export of the corresponding target execution result data.

[0046] Step C. Extract the target operation statements used by the target database access operation, and traverse the cross-border query record table. For each historical database access operation statement, determine whether there are any query results corresponding to the execution of the historical database access operation, including the query results corresponding to the execution of the target operation statement. If so, accept the operation of the target database access operation on the domestic database and execute the export of the corresponding target execution result data; otherwise, proceed to step D.

[0047] Step D. Traverse the various target personal information fields in the target execution result data to obtain the number of deduplicated personal subject data mapped to each type of target personal information field. and the corresponding record form of personal information of the subject leaving the country. length And according to the following formula:

[0048] ;

[0049] Calculation results This allows us to obtain the results corresponding to each of the various target personal information fields. Judge each result Whether all results do not exceed the preset threshold, and the judgment of each result. If both conditions are met, the target database access operation is received and executed on the domestic database, and the corresponding target execution result data is exported; otherwise, proceed to step E.

[0050] Step E. Based on the mapping set Mapping relationships Based on the target database access operation, an operation instruction is constructed to retrieve deduplicated outbound individual subject data from the domestic database. After execution, the individual subject data mapped to each piece of personal information data in the corresponding target execution result data is obtained, and deduplicated data is constructed to form an outbound individual subject record table corresponding to the target execution result data. Then proceed to step F.

[0051] Step F. Compile a record of entities exporting personal information abroad. Overall Personal Information Outbound Individual Entity Record Form The system merges and deduplicates the number of individual subject data, and determines whether it exceeds a preset threshold and whether it exceeds the threshold for the number of individual subject data allowed to leave the country as declared by the domestic database processor. If both determinations are negative, the system executes the export of the corresponding target execution result data and proceeds to step G; otherwise, the system rejects the export of the corresponding target execution result data.

[0052] Step G. Add the target database access operation and its corresponding target execution result data to the cross-border query record table. Update the Personal Information Export Entity Record Form Add to the overall personal information exit record form In the middle, and on Perform deduplication and update; update the personal information export entity record form. Each individual's data is added to the corresponding personal information exit record table for each type of target personal information field. and for each Perform a deduplication update.

[0053] In practical applications, for example, assuming there are three tables A, B, and C in the database, with a globally unified personal identity field... This refers to the pid field in table C.

[0054] The query statement for this cross-border query operation is:

[0055] SELECT height FROM A WHERE age >= 1980;

[0056] Among them, based on the results of data classification and grading research, the height field in Table A belongs to , and is a personal information field.

[0057] The mapping relationship of the height field is pi_map = (height, pid, map);

[0058] map = <B, medical record number><C, ID number><C, pid>;

[0059] Therefore, the modified query statement is:

[0060] SELECT DISTINCT C.pid FROM A, B, C WHERE A.age >= 1980 AND A.medical record number = B.medical record number AND B.ID number = C.ID number.

[0061] After execution, a list of all deduplicated personal information subject field values that will be obtained in this cross-border query can be obtained, that is, the deduplicated pid values of all personal information subjects that will go abroad.

[0062] In practical applications, for operations on domestic databases, it also includes database access operations a of the type of creating, modifying, and deleting the structure of databases, tables, or fields, and database access operations b of the type of inserting, updating, and deleting the values of databases, tables, or fields. When the database access operation a is successfully executed for the domestic database, it triggers a scan of the domestic database and executes steps a to c; when the database access operation b is successfully executed for the domestic database, it triggers a scan of the domestic database and executes steps a to b.

[0063] Implementing the above-designed data outbound security control method in practical applications, such as Figure 2 As shown, by deploying a cross-border gateway system before the domestic database, constructing a corresponding system, the cross-border gateway system executes the data outbound security control method based on dynamic authorization, and specifically designs that the cross-border gateway system includes a data access control module, a personal information subject association mapping module, and an outbound personal information subject detection module. The data access control module is connected in series on the communication link between the domestic database and abroad. At the same time, the data access control module communicates with the personal information subject association mapping module and the outbound personal information subject detection module respectively. The personal information subject association mapping module and the outbound personal information subject detection module communicate and interact with the domestic database respectively. At the same time, the personal information subject association mapping module provides data to the outbound personal information subject detection module for communication.

[0064] The data access control module receives and analyzes database access operations targeting domestic databases. If the database access operation is a query operation on the value of a database, table, or field, the data access control module forwards the database access operation to the outbound personal information subject detection module for processing. Based on the feedback from the outbound personal information subject detection module, the data access control module decides whether to allow the database access operation to be executed. After the database access operation is successfully executed, the data access control module executes the outbound export of the corresponding execution result data and forwards the corresponding execution result data to the outbound personal information subject detection module.

[0065] If the database access operation is a creation, modification, or deletion operation on the structure of a database, table, or field, or an insertion, update, or deletion operation on the value of a database, table, or field, the data access control module allows the database access operation to be performed on a domestic database. After the database access operation is successfully executed, the data access control module will forward the corresponding execution result data to the personal information subject association mapping module.

[0066] The Personal Information Subject Association Mapping Module is used to perform real-time scanning of domestic databases and execute steps a to b; and after the database access operation for domestic databases is successfully executed, the Personal Information Subject Association Mapping Module is triggered to scan domestic databases and execute steps a to b.

[0067] The outbound personal information subject detection module is used to perform real-time scanning of domestic databases and execute steps c to d; and for target database access operations from overseas that are of the type of query operation on the value of database, table or field, the outbound personal information subject detection module executes steps A to G and feeds back to the data access control module.

[0068] The aforementioned technical solution, based on dynamic authorization, designs a data export security control method. This method leverages the mapping relationship between individual personal data and individual subject data within the domestic database. It combines the classification of personal data to count the number of duplicate individual subject data mapped to exported personal data, records database access operations involving cross-border queries of personal data within the domestic database, and designs logical access verification for target database access operations on databases, tables, or fields. This achieves dynamic authorization of access operations, controls data export, and deploys a cross-border gateway system before the domestic database. By building corresponding systems and integrating various functional modules, the method collectively completes the data export security control, achieving the goal of dynamic, accurate, and compliant cross-border control of personal data.

[0069] In this design, the database access requests between overseas data recipients and domestic data processors are intercepted. A method for estimating the quantity of outbound personal information is used, combined with improved granularity of personal information security control through correlation mapping. Database access statements are automated, and a two-level analysis architecture for accurate querying of personal information quantities is constructed. This architecture queries and detects individuals intending to leave the country, determining whether to grant database access authorization for outbound personal information data. Compared to existing technologies, this invention provides a clear and objective count of outbound personal information entities, avoiding violations and improving the efficiency of outbound data control.

[0070] The embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the present invention is not limited to the above embodiments. Within the scope of knowledge possessed by those skilled in the art, various changes can be made without departing from the spirit of the present invention.

Claims

1. A method for data export security control based on dynamic authorization, characterized in that: Based on real-time scanning of domestic databases, the mapping relationship between each piece of personal information data and each piece of uniquely identified personal subject data is identified. Combined with the classification of personal information data, the number of deduplicated personal subject data mapped by personal information data that has been exported is counted, and database access operations involving cross-border queries of personal information data in domestic databases are recorded. Then, for target database access operations from overseas that are of the type of query operation on the value of database, table or field, data export security control is achieved.

2. The data export security control method based on dynamic authorization according to claim 1, characterized in that: Based on real-time scanning of domestic databases, perform the following steps a to d; Step a. Scan domestic databases to perform data classification, identify individual pieces of personal information, and construct a list of personal information data. Each piece of personal information data is recorded under various personal information fields, and each uniquely identified individual subject data is also recorded under the individual subject field. Then, a mapping relationship is established between each piece of personal information data and each piece of individual subject data. Construct a mapping set Then proceed to step b; Step b. Count the number of individual subject data entries after deduplication of the individual subject field. Based on the mapping relationship set For each type of personal information field, the number of deduplicated personal data entries mapped to each piece of personal information data under that field is counted, thereby obtaining the number of deduplicated personal data entries mapped to each type of personal information field. Then proceed to step c; Step c. Based on the mapping relationship set The individual subject data mapped to each piece of personal information that has been exported are statistically analyzed and deduplicated before being added to the overall personal information export record table. Then, for each type of personal information field, the individual subject data mapped to each piece of personal information data that has been exported under that personal information field is statistically analyzed, and duplicate records are added to the corresponding personal information export subject record table for that personal information field, thereby obtaining the personal information export subject record table for each type of personal information field. Then proceed to step d; Step d. Record the historical database access statements that successfully involved cross-border queries of personal information data in domestic databases to the cross-border query record table. .

3. The data export security control method based on dynamic authorization according to claim 2, characterized in that: For target database access operations originating from overseas that involve querying values ​​of databases, tables, or fields, execute steps A through F below to achieve data export security control. Step A. Determine the number of deduplicated personal subject data entries in the domestic database. Whether it exceeds the preset threshold, and judgment Whether the amount of personal subject data allowed to leave the country exceeds the threshold declared by the domestic database processor; if both judgments are negative, then the target database access operation on the domestic database is accepted, and the corresponding target execution result data is exported. Conversely, proceed to step B; Step B. Extract the databases, tables, and fields involved in the target database access operation, and determine whether it involves a list of personal information data. If the personal information data in the database is correct, proceed to step C; otherwise, receive the target database access operation to operate on the domestic database and execute the export of the corresponding target execution result data. Step C. Extract the target operation statements used by the target database access operation, and traverse the cross-border query record table. For each historical database access operation statement, determine whether there are any query results corresponding to the execution of the historical database access operation, including the query results corresponding to the execution of the target operation statement. If so, accept the operation of the target database access operation on the domestic database and execute the export of the corresponding target execution result data. Otherwise proceed to step D; Step D. Traverse the various target personal information fields in the target execution result data to obtain the number of deduplicated personal subject data mapped to each type of target personal information field. and the corresponding record form of personal information of the subject leaving the country. length And according to the following formula: ; Calculation results This allows us to obtain the results corresponding to each of the various target personal information fields. Judge each result Whether all results do not exceed the preset threshold, and the judgment of each result. If both conditions are met, the target database access operation is received and executed on the domestic database, and the corresponding target execution result data is exported; otherwise, proceed to step E. Step E. Based on the mapping set Mapping relationships Based on the target database access operation, an operation instruction is constructed to retrieve deduplicated outbound individual subject data from the domestic database. After execution, the individual subject data mapped to each piece of personal information data in the corresponding target execution result data is obtained, and deduplicated data is constructed to form an outbound individual subject record table corresponding to the target execution result data. Then proceed to step F; Step F. Compile a record of individuals leaving the country using their personal information. Overall Personal Information Outbound Individual Entity Record Form The system merges and deduplicates the number of individual subject data, and determines whether it exceeds a preset threshold and whether it exceeds the threshold for the number of individual subject data that the domestic database processor is allowed to export. If both determinations are negative, the system executes the export of the corresponding target execution result data; otherwise, it rejects the export of the corresponding target execution result data.

4. The data export security control method based on dynamic authorization according to claim 3, characterized in that: After the corresponding target execution result data is exported in step F, the process proceeds to step G as follows: Step G. Add the target database access operation and its corresponding target execution result data to the cross-border query record table. Update the Personal Information Export Entity Record Form Add to the overall personal information exit record form In the middle, and on Perform deduplication and update; update the personal information export entity record form. Each individual's data is added to the corresponding personal information exit record table for each type of target personal information field. and for each Perform a deduplication update.

5. The data export security control method based on dynamic authorization according to claim 4, characterized in that: For database access operations that are of the type of creating, modifying, or deleting operations on the structure of a database, table, or field, after the database access operation is successfully executed on a domestic database, a scan of the domestic database is triggered, and steps a to c are executed. For database access operations that involve inserting, updating, or deleting values ​​in a database, table, or field, after the database access operation is successfully executed on a domestic database, a scan of the domestic database is triggered, and steps a to b are executed.

6. A system for implementing the data export security control method based on dynamic authorization as described in claim 5, characterized in that: This includes deploying a cross-border gateway system before the domestic database. The cross-border gateway system executes a data export security control method based on dynamic authorization. The cross-border gateway system includes a data access control module, a personal information subject association mapping module, and an export personal information subject detection module. The data access control module is connected in series on the communication link between the domestic database and the overseas database. At the same time, the data access control module communicates with the personal information subject association mapping module and the export personal information subject detection module. The personal information subject association mapping module and the export personal information subject detection module interact with the domestic database. Meanwhile, the personal information subject association mapping module communicates with the export personal information subject detection module to provide data.

7. The system according to claim 6, characterized in that: The data access control module is used to receive and analyze database access operations for domestic databases. If the database access operation is a query operation on the value of a database, table or field, the data access control module forwards the database access operation to the outbound personal information subject detection module for processing. Based on the feedback from the outbound personal information subject detection module, the data access control module decides whether to allow the database access operation to be executed. After the database access operation is successfully executed, the data access control module executes the outbound export of the corresponding execution result data and forwards the corresponding execution result data to the outbound personal information subject detection module. If the database access operation is a creation, modification, or deletion operation on the structure of a database, table, or field, or an insertion, update, or deletion operation on the value of a database, table, or field, the data access control module allows the database access operation to be performed on a domestic database. After the database access operation is successfully executed, the data access control module will forward the corresponding execution result data to the personal information subject association mapping module.

8. The system according to claim 6, characterized in that: The Personal Information Subject Association Mapping Module is used to perform real-time scanning of domestic databases and execute steps a to b; and after the database access operation for domestic databases is successfully executed, the Personal Information Subject Association Mapping Module is triggered to scan domestic databases and execute steps a to b.

9. The system according to claim 6, characterized in that: The outbound personal information subject detection module is used to perform real-time scanning of domestic databases and execute steps c to d; and for target database access operations from overseas that are of the type of query operation on the value of database, table or field, the outbound personal information subject detection module executes steps A to G and feeds back to the data access control module.