Scene-adaptive data refinement security level execution method and system

By setting security level assessment indicators and strategies, the data encryption level is automatically adjusted, solving the problem of low efficiency in manual judgment in existing technologies, and improving the security and efficiency of data transmission and use.

CN121887487APending Publication Date: 2026-04-17DAREWAY SOFTWARE
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
DAREWAY SOFTWARE
Filing Date
2026-01-08
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing data encryption methods rely on manual judgment of data security strategies, which is inefficient and cannot automatically execute appropriate security levels according to different scenarios, resulting in insufficient security for data transmission and use.

Method used

The system employs a scenario-adaptive data-level encryption method and system. By setting encryption level evaluation indicators and strategies, it automatically determines the encryption level of data products based on scenario information and dynamically adjusts it during the delivery process.

Benefits of technology

It achieves automated and secure data transmission and usage, reduces human error, lowers data delivery risks, optimizes processes, and improves transaction efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887487A_ABST
    Figure CN121887487A_ABST
Patent Text Reader

Abstract

The invention discloses a scene-adaptive data refinement security classification execution method and system, and relates to the technical field of data encryption, and the method comprises the steps: setting an index item and an index value of security classification evaluation; setting security level strategies of different levels; setting a security level judgment rule according to the index item and the index value; after the data provider and the data demander achieve a data product transaction, according to the index item, the index value and the security level judgment rule, determining a security level strategy and a delivery mode which need to be adopted by the current transaction; and executing data product delivery according to the determined security level strategy and delivery mode, and adjusting the security level strategy according to the feedback condition in the execution process. In the data product delivery process, different data security guarantee strategies are automatically executed according to different scene information, and the data transmission and use security is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data encryption technology, and in particular to a scenario-adaptive method and system for refining data encryption levels. Background Technology

[0002] The statements in this section are merely background information related to the present invention and do not necessarily constitute prior art.

[0003] The circulation of data elements is a crucial driving force for unleashing the value of data and empowering the development of the digital economy. A trusted data space is the infrastructure supporting the circulation and utilization of data elements, and an application ecosystem for the co-creation of data element value, playing a vital role in promoting the trading, circulation, development, and utilization of data elements.

[0004] In a trusted data space, data elements are traded and circulated in the form of data products. The same type of data product often requires different encryption levels when dealing with different trading partners. For example, in the financial sector, when data providers sell to large banks, given the banks' robust credit systems and robust security measures, ordinary encryption measures are sufficient for data delivery. However, when selling to smaller fintech companies, considering their weaker security capabilities, they might employ higher-level encryption algorithms and add signature authentication mechanisms to enhance the data delivery security level, ensuring data security during transmission and use. Current implementation methods rely on manual judgment of which data security level to apply in a given scenario, which is inefficient. Summary of the Invention

[0005] To address the aforementioned issues, this invention proposes a scenario-adaptive data fine-grained security level execution method and system. During data product delivery, different data security protection strategies are automatically executed based on different scenario information to ensure data transmission and usage security.

[0006] To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a scenario-adaptive data fine-grained security level execution method, comprising: Define the indicators and values ​​for security classification; Set different levels of security classification strategies; Establish confidentiality level assessment rules based on indicator items and indicator values; Once the data provider and the data demander reach a data product transaction agreement, the security level strategy and delivery method to be adopted for the current transaction are determined based on the indicator items, indicator values, and security level assessment rules. Based on the established security classification strategy and delivery method, execute the delivery of data products, and adjust the security classification strategy according to the feedback during the execution process.

[0007] As an optional implementation method, the indicator items include data type, nature of data user unit, industry to which the data user unit belongs, and application scenario type; The data type metrics include public data / anonymized data, general business data / indirect personal information, and core business data / sensitive personal information; The indicator values ​​for data users include state-owned enterprises, private enterprises, public institutions, and government departments; The indicator values ​​for the industry to which the data user belongs include regulated industries, industries with data security systems but no industry regulation, and individual users / small organizations without professional compliance teams; The indicator values ​​for application scenario types include real-time decision-making scenarios, offline analysis scenarios, and one-time query scenarios.

[0008] As an alternative implementation method, the security classification strategy includes: The high-security strategy delivers computational results / model training data, personal detailed data, and anonymized / de-identified datasets. The computational results / model training data are delivered using privacy computing technology, the personal detailed data is delivered using blockchain technology with personal authorization, and the anonymized / de-identified datasets are delivered after data anonymization / de-identification. The medium-security level strategy includes delivery methods such as one-time delivery and continuous delivery; one-time delivery is delivered via controlled encrypted data transmission, while continuous delivery is delivered via secure API interfaces. The low-security strategy includes delivery methods such as direct delivery and copyright-controlled delivery; direct delivery is delivered via file transfer, while copyright-controlled delivery is delivered with watermarking.

[0009] As an alternative implementation method, the security level strategy corresponding to different indicator items and their values ​​is configured as follows: Based on data type, public data / de-identified data corresponds to a low-level security policy, while general business data / indirect personal information and core business data / sensitive personal information correspond to a high-level security policy. Based on the nature of the data user, state-owned enterprises, public institutions, and government departments are assigned a low-secrecy policy, while private enterprises are assigned a medium-secrecy policy. For data users, the financial / healthcare industry, which is subject to regulation, corresponds to a low-secrecy strategy; the retail / education industry, which has data security systems but no industry regulation, and individual users or small organizations without professional compliance teams, correspond to a medium-secrecy strategy. Depending on the application scenario, offline analysis scenarios correspond to low-density strategies, while real-time decision-making scenarios and one-time query scenarios correspond to medium-density strategies.

[0010] As an alternative implementation method, the evaluation process includes: Based on the data requirements of the data requester, determine whether this delivery includes all data items of the data product; if not, then mask out any data items not required by the data requester. If so, then based on the data type and the corresponding indicator value, determine the security level as follows: Level 1; based on the nature of the data user and the corresponding indicator value; Level 2; based on the industry of the data user and the corresponding indicator value; Level 3; and Level 4. Based on the comprehensive assessment of the confidentiality levels of each indicator, the highest confidentiality level is selected as the confidentiality level strategy for the current transaction. The delivery method is determined within the current security classification policy, taking into account the delivery format agreed upon by the data provider and the data requester.

[0011] As an alternative implementation method, the process of adjusting the security classification strategy based on feedback during execution includes: Regularly audit the access logs and delivery records of data products to determine if any risky behavior exists. If risky behavior is found, upgrade the security level policy by one level and adjust the delivery method. If the original security level policy uses the highest security level delivery policy, send a notification to the data provider, who will then determine whether to adjust the delivery method. Risky behaviors include: high-frequency access exceeding the normal business needs of the data requester, exceeding the threshold number of data accesses during non-working hours, downloading more than the set amount of data within a set time interval, and exceeding the set threshold number of times sensitive fields agreed upon by both parties are queried.

[0012] Secondly, the present invention provides a scenario-adaptive data fine-grained security level execution system, comprising: The indicator item management module is configured to set the indicator items and indicator values ​​for security level assessment; The security classification policy management module can be configured to set different levels of security classification policies; The evaluation rule management module is configured to set confidentiality evaluation rules based on indicator items and indicator values; The automatic security classification module is configured to determine the security classification strategy and delivery method required for the current transaction based on indicator items, indicator values, and security classification rules after the data provider and data requester reach a data product transaction. The security classification policy execution module is configured to deliver data products according to the determined security classification policy and delivery method, and to adjust the security classification policy based on feedback during the execution process.

[0013] Thirdly, the present invention provides an electronic device including a memory and a processor, and computer instructions stored in the memory and running on the processor, wherein the computer instructions, when executed by the processor, perform the method described in the first aspect.

[0014] Fourthly, the present invention provides a computer-readable storage medium for storing computer instructions, which, when executed by a processor, perform the method described in the first aspect.

[0015] Fifthly, the present invention provides a computer program product, including a computer program that, when executed by a processor, implements the method described in the first aspect.

[0016] Compared with the prior art, the beneficial effects of the present invention are as follows: This invention proposes a scenario-adaptive data fine-grained security level execution method and system. In the delivery of data products, different data security protection strategies are automatically executed according to different scenario information to ensure the security of data transmission and use.

[0017] The method of this invention reduces human factors in the data delivery process and lowers data security risks by automating and refining the data security level assessment and execution.

[0018] The method of this invention automatically determines the security level strategy for data product delivery. Data providers can automatically determine and execute the delivery method and form without manual configuration, effectively reducing the cost for data providers in data product delivery.

[0019] The method of this invention automatically determines the confidentiality level of data product transactions and automatically executes confidentiality level strategies without human intervention, effectively optimizing the data product delivery process, enhancing the security of data product delivery, and improving the efficiency of data product transaction circulation.

[0020] Advantages of additional aspects of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0022] Figure 1 The flowchart of the scenario-adaptive data fine-grained security level execution method provided in Embodiment 1 of the present invention is as follows: Figure 2 This is a flowchart of the confidentiality assessment process provided in Embodiment 1 of the present invention; Figure 3 This is a diagram of the scenario-adaptive data refinement and security level execution system architecture provided in Embodiment 2 of the present invention. Detailed Implementation

[0023] The present invention will be further described below with reference to the accompanying drawings and embodiments.

[0024] It should be noted that the following detailed descriptions are exemplary and intended to provide further illustration of the invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.

[0025] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments of the invention. As used herein, unless the context clearly indicates otherwise, the singular form is intended to include the plural form as well. Furthermore, it should be understood that the terms “comprising” and “including”, and any variations thereof, are intended to cover non-exclusive inclusion, for example, a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0026] Where there is no conflict, the embodiments and features in the embodiments of the present invention can be combined with each other.

[0027] Example 1 This embodiment provides a scenario-adaptive data fine-grained security level execution method, including: Define the indicators and values ​​for security classification; Set different levels of security classification strategies; Establish confidentiality level assessment rules based on indicator items and indicator values; Once the data provider and the data demander reach a data product transaction agreement, the security level strategy and delivery method to be adopted for the current transaction are determined based on the indicator items, indicator values, and security level assessment rules. Based on the established security classification strategy and delivery method, execute the delivery of data products, and adjust the security classification strategy according to the feedback during the execution process.

[0028] like Figure 1 As shown, the above method specifically includes the following steps: S1: Indicator configuration.

[0029] The data provider sets various indicators for determining the security level based on the type of data product, and sets the indicator values.

[0030] Specifically: The indicators include data type, nature of the data user, industry of the data user, and type of application scenario; The data type metrics include public data / anonymized data, general business data / indirect personal information, and core business data / sensitive personal information, etc. The indicator values ​​for data users include state-owned enterprises, private enterprises, public institutions, and government departments, etc. The indicator values ​​for the industry to which the data user belongs include industries that are strictly regulated, such as finance and healthcare; retail and education, which have data security systems but no special industry regulations; and individual users or small organizations without professional compliance teams. The metrics for application scenario types include real-time decision-making scenarios (requiring real-time API interfaces), offline analysis scenarios (delivered periodically via batch files), and one-time query scenarios (delivered via single customized delivery), etc.

[0031] This step provides data providers with the ability to configure and manage indicator items, supporting the configuration of indicator items and indicator values ​​for judging the confidentiality level strategy according to the delivery requirements of data products.

[0032] S2: Security level policy configuration.

[0033] The data provider can set up a refined security classification strategy, and can set and combine various delivery forms and methods freely according to the needs and within the space capacity.

[0034] The security classification strategy includes: High-security strategies can be delivered using privacy computing technologies such as secure multi-party computation, federated learning, and trusted execution environments; delivered via blockchain technology after personal authorization; or delivered after data desensitization or anonymization. Medium-security level strategies can employ delivery methods such as controlled encrypted data transmission and delivery, and secure API interface delivery. Low-security strategies can employ delivery methods such as adding watermarks to the data before delivery or file transfer.

[0035] This step provides data providers with the ability to configure data protection policies for various security levels, supporting the configuration of different data protection policies for different security levels. This includes different delivery methods such as API delivery, privacy computing delivery, and blockchain-based personal authorization delivery, as well as different delivery formats such as plaintext and ciphertext, forming different data delivery chains based on different security level policies.

[0036] S3: Evaluation rule configuration.

[0037] The data provider configures the confidentiality assessment rules based on the indicator items and indicator values.

[0038] The security level strategy configurations for different indicator items and their values ​​are as follows: Based on data type, public data / de-identified data corresponds to a low-level security policy, while general business data / indirect personal information and core business data / sensitive personal information correspond to a high-level security policy. Based on the nature of the data user, state-owned enterprises, public institutions, and government departments are assigned a low-secrecy policy, while private enterprises are assigned a medium-secrecy policy. For the industry of the data user, the low-secrecy strategy corresponds to industries with strict regulations such as finance and healthcare, while the medium-secrecy strategy corresponds to industries with data security systems but no special industry regulations, such as retail and education, and individual users or small organizations without professional compliance teams. Depending on the application scenario, offline analysis scenarios correspond to low-density strategies, while real-time decision-making scenarios and one-time query scenarios correspond to medium-density strategies.

[0039] This step provides data providers with the ability to configure and manage confidentiality assessment rules, supporting the configuration of confidentiality assessment rules for data delivery based on indicator items and indicator values.

[0040] S4: Data product transactions.

[0041] The data provider configures the delivery format and corresponding delivery method of the data product according to different security level policies.

[0042] Specifically: Under the low-security policy, delivery methods include direct delivery and copyright-controlled delivery; direct delivery is delivered via file transfer, while copyright-controlled delivery is delivered by adding a watermark.

[0043] Under the medium-security level strategy, delivery methods include one-time delivery and continuous delivery; one-time delivery is delivered via controlled encrypted data transmission, while continuous delivery is delivered via secure API interfaces.

[0044] Under the high-security strategy, the delivery formats include computation results / model training, personal detailed data, and desensitized / anonymized datasets. Among them, the delivery of computation results / model training is carried out using privacy computing technologies such as secure multi-party computation, federated learning, and trusted execution environments. The delivery of personal detailed data is carried out based on blockchain technology after personal authorization. The delivery of desensitized / anonymized datasets is carried out after data desensitization / anonymization.

[0045] After the data provider and the data demander agree on the delivery method of the data product, a data product transaction is reached, forming a data product transaction order.

[0046] S5: Automatic security level assessment.

[0047] After a transaction occurs between the supply and demand sides of data products, the security level of the current transaction is assessed based on the configured indicators, indicator values, and security level assessment rules. Based on the assessment results, a security level strategy for the delivery of data products is matched to the current transaction.

[0048] like Figure 2 As shown, the confidentiality assessment process includes: (1) After the supply and demand parties reach a data transaction and generate a transaction order, the data delivery mode is first determined based on the data demand of the data demander.

[0049] (2) Determine whether all data items of this product are delivered in this delivery; if not all data items are required, then mask out the data items other than the data requirements of the data requester.

[0050] (3) Evaluate the transaction order based on the configured security classification criteria; specifically: Based on the data type and corresponding indicator value, the security level is determined to be level one; Based on the nature of the data-using unit and the corresponding indicator values, the security level is determined to be level two; Based on the industry of the data user and the corresponding indicator values, the security level is determined to be level three; Based on the data usage application scenario type and corresponding indicator values, the security level is determined to be four.

[0051] (4) Based on the comprehensive assessment of the confidentiality levels of the above indicators, the highest confidentiality level is selected as the data delivery confidentiality level corresponding to this transaction.

[0052] (5) Based on the data product delivery method agreed upon by both parties, select the data product delivery method from the current security level strategy; and determine whether there are any special requirements in the data usage application scenario, such as the requirement to encrypt transmission, anonymize / de-identify, etc.; if so, add the special requirement to the currently selected data product delivery method.

[0053] It should be noted that after matching the security level, the delivery method corresponding to the current security level or a higher security level can be used, but the delivery method corresponding to a lower security level cannot be used.

[0054] S6: Enforcement of security-level policies.

[0055] After determining the security level strategy and delivery method based on the automatic security level assessment results, the data product delivery operation is executed to ensure data delivery security.

[0056] This step provides data providers with the ability to automatically execute security classification policies. Based on the security classification assessment results, the configured security classification policies will be used to take corresponding data protection measures for the delivery of data products.

[0057] S7: Delivery feedback and security level policy adjustment, selecting a more secure delivery strategy and delivery chain for data delivery.

[0058] Specifically: Regularly audit information such as access logs and delivery records of data products to determine whether there are risky behaviors such as high-frequency access far exceeding the normal business needs of the data requester, large-scale data access during non-working hours, downloading far more data than is normally used in a short period of time, and frequent querying of sensitive fields agreed upon by both parties.

[0059] If risky behavior is found, the security level of the data product will be increased by one level, and the delivery method will be adjusted. If the highest security level delivery strategy was originally adopted, a prompt will be sent to the data provider, who will then determine whether to adjust the delivery method.

[0060] Example 2 like Figure 3 As shown, this embodiment provides a scenario-adaptive data fine-grained security level execution system, including: The indicator item management module is configured to set the indicator items and indicator values ​​for security level assessment; The security classification policy management module can be configured to set different levels of security classification policies; The evaluation rule management module is configured to set confidentiality evaluation rules based on indicator items and indicator values; The automatic security classification module is configured to determine the security classification strategy and delivery method required for the current transaction based on indicator items, indicator values, and security classification rules after the data provider and data requester reach a data product transaction. The security classification policy execution module is configured to deliver data products according to the determined security classification policy and delivery method, and to adjust the security classification policy based on feedback during the execution process.

[0061] It should be noted that the above modules correspond to the steps described in Embodiment 1, and the examples and application scenarios implemented by the above modules and the corresponding steps are the same, but are not limited to the content disclosed in Embodiment 1. It should also be noted that the above modules, as part of the system, can be executed in a computer system such as a set of computer-executable instructions.

[0062] In further embodiments, the following is also provided: An electronic device includes a memory and a processor, as well as computer instructions stored in the memory and running on the processor, wherein the computer instructions, when executed by the processor, perform the method described in Embodiment 1. For brevity, further details are omitted here.

[0063] It should be understood that in this embodiment, the processor can be a central processing unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.

[0064] Memory may include read-only memory and random access memory, and provides instructions and data to the processor. A portion of memory may also include non-volatile random access memory. For example, memory may also store information about the device type.

[0065] A computer-readable storage medium for storing computer instructions, which, when executed by a processor, perform the method described in Embodiment 1.

[0066] The method in Example 1 can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor. The software modules can reside in readily available storage media in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method. To avoid repetition, a detailed description is not provided here.

[0067] A computer program product includes a computer program that, when executed by a processor, implements the method described in Embodiment 1.

[0068] The present invention also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions, such as instructions included in program modules, which execute in a device on a target real or virtual processor to perform the processes / methods described above. Typically, program modules include routines, programs, libraries, objects, classes, components, data structures, etc., that perform specific tasks or implement specific abstract data types. In various embodiments, the functionality of program modules can be combined or divided among program modules as needed. The machine-executable instructions for the program modules can execute within a local or distributed device. In a distributed device, the program modules can reside in both local and remote storage media.

[0069] The computer program code used to implement the methods of the present invention may be written in one or more programming languages. This computer program code may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the computer or other programmable data processing device, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a computer, partially on a computer, as a stand-alone software package, partially on a computer and partially on a remote computer, or entirely on a remote computer or server.

[0070] In the context of this invention, computer program code or related data may be carried by any suitable carrier to enable a device, apparatus, or processor to perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, and the like. Examples of signals may include electrical, optical, radio, sound, or other forms of propagation signals, such as carrier waves, infrared signals, etc.

[0071] Those skilled in the art will recognize that the units and algorithm steps described in connection with the various examples of this embodiment can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this invention.

[0072] It should be noted that all data acquisition is conducted in accordance with laws and regulations and with user consent, and the data is used legally.

[0073] While the specific embodiments of the present invention have been described above in conjunction with the accompanying drawings, this is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art without creative effort based on the technical solutions of the present invention are still within the scope of protection of the present invention.

Claims

1. A scenario-adaptive data fine-grained density-level execution method, characterized in that, include: Define the indicators and values ​​for security classification; Set different levels of security classification strategies; Establish confidentiality level assessment rules based on indicator items and indicator values; Once the data provider and the data demander reach a data product transaction agreement, the security level strategy and delivery method to be adopted for the current transaction are determined based on the indicator items, indicator values, and security level assessment rules. Based on the established security classification strategy and delivery method, execute the delivery of data products, and adjust the security classification strategy according to the feedback during the execution process.

2. The scenario-adaptive data fine-grained density level execution method as described in claim 1, characterized in that, The indicators include data type, nature of the data user, industry of the data user, and application scenario type; The data type metrics include public data / anonymized data, general business data / indirect personal information, and core business data / sensitive personal information; The indicator values ​​for data users include state-owned enterprises, private enterprises, public institutions, and government departments; The indicator values ​​for the industry to which the data user belongs include regulated industries, industries with data security systems but no industry regulation, and individual users / small organizations without professional compliance teams; The indicator values ​​for application scenario types include real-time decision-making scenarios, offline analysis scenarios, and one-time query scenarios.

3. The scenario-adaptive data fine-grained density level execution method as described in claim 1, characterized in that, Security classification strategies include: The high-security strategy delivers data in the form of computation results / model training, personal detailed data, and desensitized / anonymized datasets. The computation results / model training are delivered using privacy computing technology, the personal detailed data is delivered using blockchain technology with personal authorization, and the desensitized / anonymized datasets are delivered after data desensitization / anonymization. The medium-security level strategy includes delivery methods such as one-time delivery and continuous delivery; one-time delivery is delivered via controlled encrypted data transmission, while continuous delivery is delivered via secure API interfaces. The low-security strategy includes delivery methods such as direct delivery and copyright-controlled delivery; direct delivery is delivered via file transfer, while copyright-controlled delivery is delivered with watermarking.

4. A scenario-adaptive data refinement and density-level execution method as described in claim 2 or 3, characterized in that, The security level strategy configurations for different indicator items and their values ​​are as follows: Based on data type, public data / de-identified data corresponds to a low-level security policy, while general business data / indirect personal information and core business data / sensitive personal information correspond to a high-level security policy. Based on the nature of the data user, state-owned enterprises, public institutions, and government departments are assigned a low-secrecy policy, while private enterprises are assigned a medium-secrecy policy. Based on the industry of the data user, the financial / healthcare industry, which is subject to regulation, corresponds to a low-secrecy strategy; the retail / education industry, which has data security systems but no industry regulation, and individual users or small organizations without professional compliance teams, correspond to a medium-secrecy strategy. Depending on the application scenario, offline analysis scenarios correspond to low-density strategies, while real-time decision-making scenarios and one-time query scenarios correspond to medium-density strategies.

5. The scenario-adaptive data fine-grained density level execution method as described in claim 1, characterized in that, The evaluation process includes: Based on the data requirements of the data requester, determine whether this delivery includes all data items of the data product; if not, then mask out any data items not required by the data requester. If so, then based on the data type and the corresponding indicator value, determine the security level as follows: Level 1; based on the nature of the data user and the corresponding indicator value; Level 2; based on the industry of the data user and the corresponding indicator value; Level 3; and Level 4. Based on the comprehensive assessment of the confidentiality levels of each indicator, the highest confidentiality level is selected as the confidentiality level strategy for the current transaction. The delivery method is determined within the current security classification policy, taking into account the delivery format agreed upon by the data provider and the data requester.

6. The scene-adaptive data fine-grained density level execution method as described in claim 1, characterized in that, The process of adjusting the security classification strategy based on feedback during implementation includes: Regularly audit the access logs and delivery records of data products to determine if any risky behavior exists. If risky behavior is found, upgrade the security level policy by one level and adjust the delivery method. If the original security level policy adopted the highest security level delivery policy, send a prompt to the data provider, who will then determine whether to adjust the delivery method. Risky behaviors include: high-frequency access exceeding the normal business needs of the data requester, exceeding the threshold number of data accesses during non-working hours, downloading more than the set amount of data within a set time interval, and exceeding the set threshold number of times sensitive fields agreed upon by both parties are queried.

7. A scenario-adaptive data-refined security level execution system, characterized in that, include: The indicator item management module is configured to set the indicator items and indicator values ​​for security level assessment; The security classification policy management module can be configured to set different levels of security classification policies; The evaluation rule management module is configured to set confidentiality evaluation rules based on indicator items and indicator values; The automatic security classification module is configured to determine the security classification strategy and delivery method required for the current transaction based on indicator items, indicator values, and security classification rules after the data provider and data requester reach a data product transaction. The security classification policy execution module is configured to deliver data products according to the determined security classification policy and delivery method, and to adjust the security classification policy based on feedback during the execution process.

8. An electronic device, characterized in that, It includes a memory and a processor, as well as computer instructions stored in the memory and running on the processor, which, when executed by the processor, perform the method according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, Used to store computer instructions, which, when executed by a processor, perform the method described in any one of claims 1-6.

10. A computer program product, characterized in that, Includes a computer program, which, when executed by a processor, implements the method described in any one of claims 1-6.