A data protection protocol management method and device
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2024-10-25
- Publication Date
- 2026-06-26
AI Technical Summary
In existing technologies, the increasing number of software programs deployed in smart terminals leads to high maintenance costs for personal data protocols and makes them prone to oversights that could result in legal disputes and affect the normal operation of the software.
By setting a management identifier for each service, terminal devices and the cloud can obtain and update data protection protocols based on the management identifier, enabling canary releases and group management, supporting user signing of agreements, and providing a visual editing and query interface.
It improves the efficiency of data protection protocols, meets regulatory requirements, reduces app version updates, supports flexible protocol management and querying, and reduces maintenance difficulty.
Smart Images

Figure CN122295897A_ABST
Abstract
Description
A data protection protocol management method and apparatus Technical Field
[0001] This application relates to the field of data protection protocol management technology, and in particular to a data protection protocol management method and apparatus. Background Technology
[0002] With the rapid development of science and technology, various smart terminals are gradually entering people's daily lives. Typically, smart terminals deploy a wide variety of software. For example, taking a vehicle as an example, a smart terminal can deploy dashcam software, autonomous driving software, and navigation software. As another example, taking a smartphone as an example, a smartphone can deploy vehicle management software and over-the-air (OTA) update software.
[0003] Currently, when registering / login to the aforementioned software, users are required to sign user agreements, data protection policies, or data protection statements (also known as data protection agreements) to comply with data protection regulations. However, because these software programs integrate personal data agreements, the number of such agreements increases as the software's business (or services) grows, leading to increased costs for maintaining them. Specifically, maintaining a large number of personal data agreements for each service is time-consuming and labor-intensive, making maintenance difficult. Furthermore, negligence on the part of maintenance personnel in failing to update the personal data agreements for one or more services may result in violations of data protection regulations, potentially leading to legal disputes or even the software being taken offline, causing unnecessary losses to the company. Therefore, further research is needed on how to effectively utilize the data protection agreements of various services.
[0004] Summary of the Invention
[0005] This application provides a data protection protocol management method and apparatus for effectively using the data protection protocols of various services.
[0006] Firstly, this application provides a data protection protocol management method, which can be executed by a data protection protocol management device. For example, data protection protocol management can be executed by a terminal device or a module of the terminal device (such as a processor, processing unit, chip, chip system, or circuit). It should be understood that the method can also be implemented by a logical node, logical module, or software capable of implementing all or part of the functions of the terminal device. Exemplarily, the following example illustrates the execution of the data protection protocol management method by a terminal device. The terminal device has a first application program (APP) installed, which provides at least one service. The method may include the following steps: in response to a first user clicking on a first service, a terminal device may send first information; subsequently, the terminal device may receive and display the data protection protocol of the first service; in response to the first user signing or not signing the data protection protocol of the first service, the terminal device may obtain the signing result of the data protection protocol of the first service; then, the terminal device may send the signing result of the data protection protocol of the first service. The first service is included in at least one service; the first information is used to request the data protection protocol of the first service; the first information includes a first management identifier, which is used to identify the data protection protocol of the first service; the first information may also include a user identifier of the first user, wherein the user identifier of the first user belongs to a first user identifier group, the first user identifier group is associated with a first gray-scale release identifier, the data protection protocol corresponding to the first gray-scale release identifier can be used as the data protection protocol of the first service, and the first management identifier can also be used to identify the data protection protocol corresponding to the first gray-scale release identifier.
[0007] In this method, the terminal device can obtain the data protection protocol of the first service online in a timely and accurate manner based on the management identifier corresponding to the data protection protocol of the first service. Therefore, compared with the existing solution of publishing the data protection protocol in the APP version, it can reduce the APP version update caused by the data protection protocol update, making it more convenient to use and thus improving the efficiency of data protection protocol usage (i.e., improving the efficiency of data protection protocols for each service), realizing the effective use of data protection protocols for each service, and better meeting data protection specification requirements (or data protection protocol signing compliance requirements). In addition, this method can also implement gray-scale release identifiers based on data protection protocols, grouping different users. The gray-scale released data protection protocols can be associated with specific groups, so that even in scenarios where some services are updated and the corresponding data protection protocols are updated synchronously, the terminal device can still obtain the corresponding (or matched or associated) data protection protocol according to different users, thereby improving the efficiency of data protection protocol usage and meeting data protection specification requirements.
[0008] In one possible implementation, the first management identifier may include at least one of the following: application identifier, application version number, region, language, protocol type, protocol version number, service identifier, and service type; wherein, the application identifier is used to identify the first APP, the application version number is the version number of the first APP, the service identifier is used to identify the first service, the service type is the type of the first service, the region is the region where the data protection protocol of the first service is located, and the language is the language adopted by the data protection protocol of the first service.
[0009] In the above implementation, by setting a corresponding management identifier for the data protection protocol of each service (which can be understood as managing the data protection protocols of different services based on management identifiers for different business scenarios (or service scenarios), the terminal device can obtain the corresponding data protection protocol in a timely manner based on the management identifier.
[0010] In one possible implementation, at least one service may be arranged sequentially according to service type; or, at least one service's data protection protocol may be arranged sequentially according to service type.
[0011] The above implementation method enables terminal devices to sequentially obtain the data protection protocols of at least one service based on the orchestration order of at least one service (or the orchestration order of the data protection protocols of at least one service or the order of the service types of at least one service), which helps to avoid confusion in the use of data protection protocols on services, thereby enabling more reasonable or appropriate use of data protection protocols in the multi-service scenario (or multi-business scenario) of the first APP.
[0012] In one possible implementation, the service type of at least one service may include at least one of the following: basic type, enhanced type, marketing type, and individual consent type.
[0013] In one possible implementation, at least one service may include at least one of the following: account service, vehicle binding service, remote control service, remote parking service, over-the-air (OTA) upgrade service, remote operation and maintenance service, and entertainment service.
[0014] Secondly, this application provides a data protection protocol management method, which can be executed by a data protection protocol management device. For example, data protection protocol management can be executed by the cloud or a cloud module (such as a processor, processing unit, chip, chip system, or circuit). It should be understood that the method can also be implemented by a logical node, logical module, or software capable of implementing all or part of the cloud functions. For example, the following describes the execution of a data protection protocol management method in the cloud. The method can include the following steps: the cloud can receive first information, then the cloud can send a data protection protocol for a first service, and then the cloud can receive the signing result of the data protection protocol for the first service. The first information is used to request the data protection protocol for the first service. The first information includes a first management identifier, which is used to identify the data protection protocol for the first service. The first service is included in at least one service. The first information may also include a user identifier for a first user, wherein the user identifier for the first user belongs to a first user identifier group, the first user identifier group is associated with a first gray-scale release identifier, the data protection protocol corresponding to the first gray-scale release identifier can be used as the data protection protocol for the first service, and the first management identifier can also be used to identify the data protection protocol corresponding to the first gray-scale release identifier.
[0015] The technical effects achievable in the second aspect are similar to those achievable in the first aspect, and will not be elaborated upon here.
[0016] In one possible implementation, if the first information does not include the user identifier of the first user, the method further includes:
[0017] The cloud can determine the data protection protocol of the first service based on the first management identifier and the first mapping relationship. The first mapping relationship can include the mapping relationship between M management identifiers and N data protection protocols. The M management identifiers can include the first management identifier, and the N data protection protocols can include the data protection protocol of the first service. M and N are positive integers.
[0018] The above implementation method enables the cloud to provide the corresponding data protection protocol to the terminal device in real time based on the corresponding management identifier provided by the terminal device (such as the management identifier corresponding to the data protection protocol of a certain service). This helps to reduce the need for APP version updates due to data protection protocol updates, thereby improving the efficiency of data protection protocol usage (i.e., improving the efficiency of data protection protocols for each service), achieving the effective use of data protection protocols for each service, and better meeting the requirements of data protection specifications.
[0019] In one possible implementation, if the first information also includes the user identifier of the first user, the method further includes:
[0020] The cloud can determine that the user identifier of the first user belongs to the first user identifier group. Then, the cloud can determine the first gray-scale release identifier based on the first user identifier group and the second mapping relationship. Then, the cloud can determine the data protection protocol corresponding to the first gray-scale release identifier based on the first gray-scale release identifier and the third mapping relationship. The second mapping relationship can include the mapping relationship between P user identifier groups and Q gray-scale release identifiers, where P user identifier groups include the first user identifier group and Q gray-scale release identifiers include the first gray-scale release identifier, and P and Q are positive integers. The third mapping relationship can include the mapping relationship between Q gray-scale release identifiers and K data protection protocols, where K data protection protocols include the data protection protocol corresponding to the first gray-scale release identifier, and K is a positive integer.
[0021] The above implementation method enables the cloud to provide corresponding data protection protocols to the APP on the terminal device according to different users. In this way, even when some services are updated and the corresponding data protection protocols are updated synchronously, the terminal device can still obtain the corresponding data protection protocol according to different users, thereby improving the efficiency of data protection protocol usage and meeting the requirements of data protection specifications.
[0022] In one possible implementation, the method further includes:
[0023] The cloud can provide a first interface, responding to the second user's first operation on the first interface. The cloud can obtain the first management identifier and the data protection protocol of the first service. The first interface can be an interface for editing the data protection protocol, and the first operation can be the operation of the second user editing and submitting the data protection protocol of the first service on the first interface.
[0024] In the above implementation, by providing a first interface to the second user, human-computer interaction can be achieved, making the user's data protection protocol editing operation more intuitive and convenient, realizing the visual editing of the data protection protocol. This allows the user to edit the data protection protocol of one or more services in a timely and effective manner according to actual needs, and at the same time, it can realize the visual display of the data protection protocol of one or more services.
[0025] In one possible implementation, the method further includes:
[0026] The cloud can provide a second interface. In response to a second user's second operation on the second interface, the cloud can display the signing result of the data protection agreement of the first service. The second interface is used to query the signing result of the data protection agreement. The second operation is the operation of the second user to edit and submit the query information on the second interface. The query information may include the query parameters of the signing result corresponding to the data protection agreement of the first service.
[0027] In the above implementation method, by providing a second interface to the second user, human-computer interaction can be realized, making the user's data protection agreement signing result query operation more intuitive and convenient, realizing the visual editing of the data protection agreement signing result query request, thereby enabling the user to query the signing results of one or more services' data protection agreements in a timely and effective manner according to actual needs, and at the same time realizing the visual display of the signing results.
[0028] In one possible implementation, the first management identifier may include at least one of the following: application identifier, application version number, region, language, protocol type, protocol version number, service identifier, and service type; wherein, the application identifier is used to identify the first APP, the application version number is the version number of the first APP, the service identifier is used to identify the first service, the service type is the type of the first service, the region is the region where the data protection protocol of the first service is located, and the language is the language adopted by the data protection protocol of the first service.
[0029] The technical effects achievable by the above implementation method can be referred to the technical effects of the corresponding implementation method in the first aspect above, and will not be repeated here.
[0030] In one possible implementation, the service type of at least one service may include at least one of the following: basic type, enhanced type, marketing type, and individual consent type.
[0031] In one possible implementation, at least one service may include at least one of the following: account service, vehicle binding service, remote control service, remote parking service, over-the-air (OTA) upgrade service, remote operation and maintenance service, and entertainment service.
[0032] Thirdly, this application provides a data protection protocol management apparatus, including units or means for performing the various steps of any implementation method in the first aspect described above.
[0033] For example, the data protection protocol management device can be a terminal device, or a module within the terminal device (such as a processor, processing unit, chip system, circuit, or chip). The data protection protocol management device has the functionality to implement the method in any of the possible implementations of the first aspect described above. This functionality can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the aforementioned functionality.
[0034] Fourthly, this application provides a data protection protocol management apparatus, including units or means for performing the various steps of any implementation method in the second aspect described above.
[0035] For example, the data protection protocol management device can be in the cloud or a module within the cloud (such as a processor, processing unit, chip system, circuit, or chip). This data protection protocol management device has the functionality to implement the methods in any of the possible implementations of the second aspect described above. This functionality can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the aforementioned functionality.
[0036] Fifthly, this application provides a data protection protocol management device, which has the functions involved in the first and second aspects mentioned above. For example, the data protection protocol management device includes modules, units or means corresponding to the operations involved in the first and second aspects mentioned above. The functions, units or means can be implemented by software, or by hardware, or by hardware executing corresponding software.
[0037] In one possible implementation, the data protection protocol management device may include a transceiver module (or communication module, transceiver unit, or communication unit for sending and receiving data). Optionally, the data protection protocol management device may further include a processing module (or processing unit). The transceiver module can be used to send and receive signals to enable communication between the data protection protocol management device and other devices; for example, the transceiver module can be used to send data to other communication devices. The processing module can be used to perform some internal operations of the data protection protocol management device. The functions performed by the transceiver module and the processing module may correspond to the operations involved in the first to second aspects described above.
[0038] In one possible implementation, the data protection protocol management device includes a processor that can be coupled to a memory. The memory can store necessary computer programs or instructions for implementing the functions described in the first to second aspects above. The processor can execute the computer programs or instructions stored in the memory, causing the data protection protocol management device to implement the methods in any possible implementation of any of the first to second aspects above when the computer programs or instructions are executed.
[0039] In one possible implementation, the data protection protocol management device includes a processor and a memory, the memory of which can store necessary computer programs or instructions for implementing the functions involved in the first to second aspects described above. The processor can execute the computer programs or instructions stored in the memory, and when the computer programs or instructions are executed, the data protection protocol management device implements the methods in any possible implementation of any of the first to second aspects described above.
[0040] In one possible implementation, the data protection protocol management device includes a processor and an interface circuit (or communication interface), wherein the processor is used to communicate with other devices via the transceiver and to execute the methods in any of the possible implementations of the first to second aspects described above. The transceiver is used to enable the data protection protocol management device to communicate with other devices, for example, to receive signals from other communication devices and transmit them to the processor, or to send signals from the processor of the data protection protocol management device to other communication devices, such as the transmission or reception of data and / or signals. Exemplarily, the communication interface may be a transceiver, circuit, bus, module, or other type of communication interface.
[0041] It is understood that, in the fifth aspect mentioned above, the processor can be implemented in hardware or software. When implemented in hardware, the processor can be a logic circuit, integrated circuit, etc.; when implemented in software, the processor can be a general-purpose processor that reads software code stored in memory. Furthermore, there can be one or more processors, and one or more memories. The memory can be integrated with the processor, or the memory and processor can be separate. In specific implementations, the memory can be integrated with the processor on the same chip, or it can be set on different chips. This application does not limit the type of memory or the arrangement of the memory and processor.
[0042] Sixthly, this application provides a terminal device including the aforementioned data protection protocol management device.
[0043] Seventhly, this application provides a cloud platform including the aforementioned data protection protocol management device.
[0044] Eighthly, this application provides a computer program product comprising a computer program or instructions that, when executed on a computer, cause the computer to perform the method in any possible implementation of any of the first to second aspects described above.
[0045] Ninthly, this application provides a computer-readable storage medium storing a computer program or instructions that, when executed by a computer, cause the computer to perform the method in any possible implementation of any of the first to second aspects described above.
[0046] In a tenth aspect, this application provides a chip that may include a processor and may also include a memory (or the chip may be coupled to the memory). The chip executes program instructions in the memory to cause the chip to perform any possible implementation of any of the first to second aspects described above. Here, "coupling" refers to two components being directly or indirectly connected to each other, such as coupling referring to an electrical connection between two components.
[0047] Eleventhly, this application also provides a chip system including a processor for supporting a computer device in implementing any possible implementation of the methods in any of the first to second aspects described above. In one possible implementation, the chip system further includes a memory for storing programs and data necessary for the computer device. The chip system may be composed of chips or may include chips and other discrete devices.
[0048] Based on the implementation methods provided in the above aspects, this application can be further combined to provide more implementation methods. Attached Figure Description
[0049] Figure 1 illustrates a possible application scenario provided by an embodiment of this application.
[0050] Figure 2 illustrates a schematic diagram of a cloud-based functional module structure provided in an embodiment of this application.
[0051] Figure 3 illustrates a flowchart of a data protection protocol management method provided in an embodiment of this application;
[0052] Figure 4 illustrates a schematic diagram of a data protection protocol orchestration and management provided in an embodiment of this application.
[0053] Figure 5a illustrates a flowchart of another data protection protocol management method provided in an embodiment of this application;
[0054] Figure 5b illustrates a flowchart of another data protection protocol management method provided in an embodiment of this application;
[0055] Figure 6 illustrates a schematic diagram of a possible data protection protocol management device provided in an embodiment of this application.
[0056] Figure 7 illustrates a schematic diagram of another possible data protection protocol management device provided in an embodiment of this application. Detailed Implementation
[0057] The embodiments of this application will now be described in detail with reference to the accompanying drawings.
[0058] The following describes the application scenarios to which the data protection protocol management method provided in this application is applicable. It should be noted that this description is for the convenience of those skilled in the art and does not constitute a limitation on the scope of protection claimed in this application.
[0059] Please refer to Figure 1, which is a schematic diagram of a possible application scenario applicable to an embodiment of this application. As shown in Figure 1, this application scenario may include a terminal device 100 and a cloud 200. The terminal device 100 and the cloud 200 can communicate via one or more networks. This network can be a wireless network, such as a Wi-Fi (Wi-Fi) network, a mobile cellular network, or other forms of network; this embodiment of the application does not limit the specific network used.
[0060] The terminal device 100 is equipped with target applications that provide users with various services and functions.
[0061] Understandably, the target application can be a client (also known as an application or application software, such as an in-vehicle client, a personal computer (PC) client, or a mobile client), a web application, or a mini-program embedded in other applications. For example, the target application can include, but is not limited to, vehicle applications, news applications, music applications, game applications, social applications, payment applications, or video applications.
[0062] For example, taking a vehicle application as the target application, it can include a vehicle management application (also known as a vehicle management app), a dashcam application, or a smart driving application. The vehicle management application can provide users with vehicle management-related services (such as account services, vehicle binding services, remote control services, remote parking services, navigation services, remote maintenance services (such as vehicle monitoring, vehicle diagnostics, vehicle maintenance, etc.), OTA upgrade services, etc.). The dashcam application can provide users with services related to driving recording (such as account services, playback of video and audio from a specific time or period, and querying of historical driving records, etc.). The smart driving application can provide users with services related to smart driving (such as account services, automatic parking services, and autonomous driving services, etc.).
[0063] Optionally, the aforementioned terminal device 100 is a device that provides data connectivity to users. The terminal device may also be referred to as a terminal, user equipment (UE), access terminal device, vehicle-mounted terminal, UE unit, UE station, mobile station, mobile station (MS), mobile terminal (MT), remote station, remote terminal device, mobile device, UE terminal device, terminal device, wireless communication device, UE agent, or UE apparatus, etc. In the embodiments of this application, the terminal device may be fixed in location or mobile; this application does not limit its location.
[0064] For example, terminal device 100 can be a smartphone, tablet computer, desktop computer, computer with wireless transceiver capabilities (such as a laptop computer), PPD (Personal Digital Assistant), mobile internet device (MID), vehicle, in-vehicle terminal equipment (or in-vehicle functional module or in-vehicle device, such as a vehicle infotainment system or intelligent driving system), wearable device with wireless communication capabilities (such as a smartwatch, smart bracelet, smart glasses, or smart helmet), virtual reality (VR) device, or augmented reality (AR) device, etc. It should be understood that this application does not limit the specific form of the terminal device.
[0065] Cloud 200 can refer to a device, component, or chip with processing capabilities. This includes physical devices such as hosts or processors, virtual devices such as virtual machines or containers, and chips or integrated circuits. In this embodiment, cloud 200 can be used to provide data protection protocols (also called data protection documents) for various services (or functions or businesses) to terminal device 100. For example, consider a smartphone with a vehicle management application installed on it. The vehicle management application may include, but is not limited to, account services (such as account registration / login services), vehicle binding services, remote control services, or remote parking services. Cloud 200 can provide data protection protocols for account services, vehicle binding services, remote control services, or remote parking services to the smartphone, and so on. It is understood that in the Internet of Vehicles (IoV), cloud 200 can typically be an IoV server. For example, data protection protocols may include, but are not limited to, user agreements, data protection statements, or data protection policies.
[0066] Optionally, the cloud 200 can be a standalone physical server, or a server cluster or distributed system consisting of multiple physical servers. For example, the cloud 200 can be a cloud server (or cloud, cloud computing, server-side, or cloud computing device) used to provide cloud services, cloud computing, cloud storage, cloud communication, network services, security services, and big data, or it can be a regular data center, server, or other form of computing device.
[0067] For example, consider a vehicle user as the user, a smartphone as the terminal device 100, and a vehicle management application as the target application. The vehicle management application is installed on the smartphone. For instance, when a vehicle user needs to log in to the vehicle management application, they can click the application's icon to enter its registration interface (essentially clicking the account registration service). In response to this click, the smartphone obtains the vehicle management application's identifier (or index or name), version number, service identifier (or service index or service name) of the account registration service, service type (e.g., basic type, also known as basic service type), and the language, region (or country or area), protocol version number, and protocol type (e.g., user agreement, data protection policy) of the data protection protocol. Then, the smartphone generates a management identifier S1 based on the vehicle management application's identifier, version number, service identifier, service type, and the corresponding language, region, protocol version number, and protocol type of the data protection protocol. Finally, the smartphone sends information A1 to the cloud 200. Information A1 may include management identifier S1. Information A1 can be used to request the data protection agreement for the account registration service. It is understood that the data protection agreement for the account registration service may include a user agreement and a data protection policy. Management identifier S1 is used to identify (or indicate) the data protection agreement for the account registration service. It should be understood that management identifier S1 includes the identifier of the vehicle management application, the version number of the vehicle management application, the service identifier of the account registration service, the service type of the account registration service, and the language, region, protocol version number, and protocol type corresponding to the data protection agreement of the account registration service.
[0068] After receiving information A1, cloud-based 200 can obtain management identifier S1 from information A1. Then, based on management identifier S1 and the mapping relationship between multiple management identifiers and multiple data protection protocols, cloud-based 200 determines the data protection protocol corresponding to management identifier S1 (i.e., the data protection protocol for the account registration service). Cloud-based 200 can then send the data protection protocol corresponding to management identifier S1 to a smartphone. Upon receiving the data protection protocol corresponding to management identifier S1, the smartphone can display it. After seeing the data protection protocol corresponding to management identifier S1, the vehicle user can choose whether to sign it. In response to the vehicle user's signing action, the smartphone can obtain the signing result (also known as the signing record or signing status) of the data protection protocol corresponding to management identifier S1 and send the signing result to cloud-based 200. For example, the signing result of the data protection protocol corresponding to management identifier S1 can be either signed or unsigned. For example, when a vehicle user agrees to (or acknowledges or authorizes) the content (or data) contained in the data protection agreement corresponding to management identifier S1, the vehicle user can click the "Agree" button, the "Check" button, or the "Yes" button. In response to the vehicle user's actions, the smartphone can obtain the signing result of the data protection agreement corresponding to management identifier S1. At this time, the signing result of the data protection agreement corresponding to management identifier S1 is "signed," which can be understood as the vehicle user agreeing to the content contained in the data protection agreement corresponding to management identifier S1. When a vehicle user does not agree to (or does not acknowledge or authorize) the content contained in the data protection agreement corresponding to management identifier S1, the vehicle user can click the "Disagree or Reject" button, not click the "Check" button, or click the "No" button. In response to the vehicle user's actions, the smartphone can obtain the signing result of the data protection agreement corresponding to management identifier S1. At this time, the signing result of the data protection agreement corresponding to management identifier S1 is "unsigned," which can be understood as the vehicle user disagreeing to the content contained in the data protection agreement corresponding to management identifier S1.
[0069] After receiving the signing result of the data protection agreement corresponding to the management identifier S1, Cloud200 can archive (or archive or store) the signing result of the data protection agreement corresponding to the management identifier S1, which will facilitate subsequent querying.
[0070] Optionally, the data protection protocol management method provided in this application embodiment can be applied to multiple fields (such as the Internet of Vehicles, intelligent driving, smart home, smart living, etc.).
[0071] It should be understood that Figure 1 only schematically provides one possible application scenario. This illustrative application scenario is intended to more clearly illustrate the technical solutions of the embodiments of this application and does not constitute a limitation on the application scenarios of the data protection protocol management method provided in this application. Furthermore, those skilled in the art will recognize that with the emergence of new application scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0072] Based on the application scenario shown in Figure 1, and to facilitate understanding of this application, this embodiment provides a functional module structure for a cloud-based 200. As shown in Figure 2, the cloud-based 200 can functionally include three modules: a data protection protocol management module, a data protection protocol signing module, and an access module. It is understood that the cloud-based 200 can also provide a management interface. For example, the cloud-based 200 can also include a display (or screen) for presenting (or displaying) the management interface, enabling human-computer interaction. The management interface (e.g., a web interface) has the function of supporting users (e.g., administrators) to perform at least one of the following operations: entering (or editing or importing) a data protection protocol, deleting a data protection protocol, modifying a data protection protocol, updating a data protection protocol, and querying (or viewing) the signing results of the data protection protocol. For example, users can perform operations such as entering, displaying, deleting, and modifying data protection protocols on the management interface provided by the cloud-based 200, or they can also perform operations such as querying the signing results of data protection protocols. It should be noted that the connection relationship between the functional modules shown in Figure 2 is only an example and does not constitute a limitation of this application. The functions of each functional module are described below.
[0073] The data protection protocol management module provides management functions for data protection protocols. For example, it is responsible for management operations such as entering, deleting, modifying, updating, querying (or providing externally) data protection protocols.
[0074] The data protection agreement signing module provides management functions for the signing results of data protection agreements. For example, it can record (or store) the signing results of data protection agreements for one or more services. Furthermore, it can be used to query (or search for or view) the signing results of data protection agreements for one or more services.
[0075] The access module is responsible for data transmission (or information transmission) between the cloud 200 and the terminal device 100. For example, the access module can receive data protection protocol requests from the terminal device 100. These data protection protocol requests are used to request the data protection protocol for a specific service. As another example, the access module can send a data protection protocol for a specific service to the terminal device 100. Yet another example is receiving the signing result of a data protection protocol for a specific service from the terminal device 100.
[0076] Optionally, the data protection protocol management module, data protection protocol signing module, and access module can all be implemented in software or hardware. For example, the implementation of the data protection protocol management module will be described below. Similarly, the implementation of the data protection protocol signing module and access module can refer to the implementation of the data protection protocol management module, and will not be repeated here.
[0077] When implemented in software, the data protection protocol management module can be an application or code block running on a computing device (or control unit, etc.) with data processing capabilities in the cloud 200. The computing device can be at least one of a physical host, virtual machine, container, etc. Furthermore, there can be one or more computing devices. For example, the data protection protocol management module can be an application running on multiple hosts / virtual machines / containers.
[0078] When implemented in hardware, the data protection protocol management module may include at least one server (or processor or chip, etc.). Alternatively, the data protection protocol management module may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof.
[0079] Furthermore, it is understood that the module division in the embodiments of this application is illustrative and only represents a logical functional division; in actual implementation, there may be other division methods. The functional modules in the embodiments of this application can be integrated into one module, or each module can exist physically separately, or two or more modules can be integrated into one module. For example, taking the data protection protocol management module and the caching module as examples, the data protection protocol management module and the caching module can be integrated into one module, or the data protection protocol management module and the caching module can be the same module. The integrated unit described above can be implemented in hardware or as a software functional unit.
[0080] Based on the application scenario shown in Figure 1, the specific implementation of the data protection protocol management method in this application embodiment will be described in detail below.
[0081] Figure 3 illustrates a flowchart of a data protection protocol management method provided in an embodiment of this application. This method is applicable to the application scenario shown in Figure 1. For example, the data protection protocol management method shown in Figure 3 is illustrated using a terminal device and the cloud as the execution entities in the interaction illustration, but this application does not limit the execution entities in the interaction illustration. It is understood that the method executed by the cloud in this application can also be executed by a module applied to the cloud (such as a processor, processing unit, chip system, circuit, or chip, etc.), or by a logical node, logical module, or software capable of implementing all or part of the cloud functions. Similarly, the method executed by the terminal device in this application can also be executed by a module applied to the terminal device (such as a processor, processing unit, chip system, circuit, or chip, etc.), or by a logical node, logical module, or software capable of implementing all or part of the terminal device functions.
[0082] As shown in Figure 3, the method includes:
[0083] Step 301: The terminal device responds to the first user's click on the first service by sending the first information. Correspondingly, the cloud receives the first information.
[0084] The terminal device has a first application (APP) installed. The first APP can be used to provide at least one service. The first service is included among the at least one services. Optionally, "service" can also be described as "function" or "business". It is understood that the first APP can have multiple application types; for example, a first APP installed on a smartphone is a mobile APP. Or, a first APP installed in a vehicle is a vehicle infotainment APP. Or, a first APP installed on a smartwatch is a smartwatch APP.
[0085] For example, the first type of app can refer to vehicle apps, news apps, music apps, game apps, social apps, payment apps, or video apps, etc. Among them, vehicle apps can include, but are not limited to, vehicle management apps, dashcam apps, or smart driving apps.
[0086] In one example, let's take a vehicle management app as the first example. A vehicle management app can provide users with at least one service related to vehicle management, such as account services (e.g., account registration / login service), vehicle binding service, remote control service, remote parking service, navigation service, remote operation and maintenance service (e.g., vehicle monitoring, vehicle diagnostics, vehicle maintenance, etc.), OTA upgrade service, or entertainment service, etc.
[0087] In another example, let's take a news and information app as the first example. A news and information app can provide users with at least one service related to news and information, such as account services (e.g., account registration / login service), news hot topic push service, comment interaction service, or channel subscription service, etc.
[0088] In another example, let's take a music app as the first example. A music app can provide users with at least one music-related service, such as account services (e.g., account registration / login service), song recording services, community interaction services, or trending music push services.
[0089] In another example, let's take a payment app as an example. A payment app can provide users with at least one payment-related service, such as account services (e.g., account registration / login services), cross-border payment services, wealth management services, lifestyle services, loan services, or promotional activities.
[0090] The following examples illustrate the first information. This first information can be used to request the data protection protocol of the first service.
[0091] Example A1: The first information includes a first management identifier. The first management identifier can be used to identify the data protection protocol of the first service.
[0092] For example, the format of the data protection protocol for the first service can be found in Table 1. It is understood that Table 1 is merely a simple example, intended to illustrate the technical solutions in the embodiments of this application, and does not constitute a limitation on the technical solutions in the embodiments of this application.
[0093] Table 1
[0094] Understandably, basic services refer to those that require signing a data protection agreement when using the app. Enhanced services refer to those that require signing a data protection agreement when using a specific function within the app. Marketing services refer to those that require signing a data protection agreement when the app needs to push commercial messages. Separate consent services refer to those that require signing a data protection agreement when requesting a specific permission from the app.
[0095] In this embodiment, the first management identifier may include at least one of the following: application identifier, application version number, region, language, protocol type, protocol version number, service identifier, or service type, etc. Specifically, the application identifier identifies the first APP, the application version number is the version number of the first APP, the service identifier identifies the first service, the service type is the type of the first service, the region is the region where the data protection protocol of the first service is located, and the language is the language used by the data protection protocol of the first service.
[0096] For example, consider a vehicle management app installed on a smartphone that provides at least one service (also known as at least one feature service) such as account service, vehicle binding service, remote control service, and OTA upgrade service. For instance, the account service is a basic service type, and its data protection protocol is a user agreement and / or data protection policy. The vehicle binding service is a marketing service type, and its data protection protocol is a data protection statement. The remote control service is an enhanced service type, and its data protection protocol is a data protection statement. The OTA upgrade service is an enhanced service type, and its data protection protocol is a data protection statement.
[0097] The user agreement, data protection policy, and data protection statement may be in a language such as Chinese, German, or French. The geographical location (e.g., country) of the user agreement, data protection policy, and data protection statement may be, for example, China or Switzerland. The version number of the user agreement, data protection policy, and data protection statement may be version 1.0.1, version 1.0.2, or another version number.
[0098] For example, taking a smartphone as the terminal device, user A as the first user, a vehicle management app installed on the smartphone, and a car binding service as the first service. When user A needs to activate the car binding service, user A can log in to the vehicle management app and click on the car binding service within the app. In response to user A's click on the car binding service, the smartphone can send information 1 to the cloud. Information 1 is used to request the data protection protocol of the car binding service. Information 1 includes a management identifier u1, which identifies the data protection protocol of the car binding service. For example, the management identifier u1 may include at least one of the following: the application identifier of the vehicle management app, the application version number of the vehicle management app, the language used by the data protection protocol of the car binding service, the region where the data protection protocol of the car binding service is located, the service identifier of the car binding service, the service type of the car binding service, the protocol type of the data protection protocol of the car binding service, or the protocol version number of the data protection protocol of the car binding service. For example, the management identifier u1 may include the application identifier of the vehicle management app, the service identifier of the car binding service, the service type of the car binding service, and the protocol type of the data protection protocol of the car binding service. In one example, after detecting that user A clicked on the car-binding service, the vehicle management app can notify the smartphone of this action. Then, upon receiving this information, the smartphone can obtain the vehicle management app's application identifier, the car-binding service's service identifier, the car-binding service's service type, and the car-binding service's data protection protocol type. The smartphone can then generate information 1 based on these parameters. Furthermore, the smartphone can send information 1 to the cloud.
[0099] In another example, after detecting that user A clicks on the car-binding service, the vehicle management app can send the service identifier, service type, and data protection protocol type of the car-binding service to a smartphone. The smartphone, after obtaining the service identifier, service type, and data protection protocol type of the car-binding service, can also obtain the application identifier of the vehicle management app. Then, based on the application identifier, service identifier, service type, and data protection protocol type of the car-binding service, the smartphone can generate information 1. Furthermore, the smartphone can send information 1 to the cloud.
[0100] For example, the service type of at least one service may include at least one of the following: basic type, enhanced type, marketing type, or individual consent type, etc.
[0101] For example, let's continue with the example of a vehicle management app providing at least one service: account service, vehicle binding service, remote control service, and OTA upgrade service. Among these, account service is the basic service type, vehicle binding service is the marketing service type, remote control service is the enhanced service type, and OTA upgrade service is also an enhanced service type.
[0102] In this embodiment, the at least one service provided by the first APP installed on the terminal device can be arranged sequentially according to the service type of the at least one service, or the data protection protocol of the at least one service can be arranged sequentially according to the service type of the at least one service. This allows the terminal device to sequentially obtain the data protection protocol of the at least one service based on the arrangement order of the at least one service (or the arrangement order of the data protection protocol of the at least one service or the order of the service types of the at least one service), which helps to avoid confusion in the use of data protection protocols on services. It is understood that by reasonably arranging at least one service based on the service type of the at least one service, the first APP on the terminal device can be assisted in achieving the order of service execution according to the execution order of service types. This enables the first APP to use data protection protocols more reasonably or appropriately in multi-service scenarios (or multi-business scenarios), and can achieve the use of separate data protection protocols according to specific services (or specific business scenarios), which helps to maximize the reasonable use of data protection protocols, thereby improving the efficiency of data protection protocol use and meeting data protection specification requirements.
[0103] For example, taking vehicle management apps in applications such as vehicle networking and intelligent driving as an example, vehicle management apps involve a variety of complex services, including account services, vehicle binding services, remote control services, OTA upgrade services, remote parking services, remote maintenance services, and entertainment services. Each of these complex services corresponds to a different data protection protocol. To avoid confusion in the use of data protection protocols, this embodiment of the application manages these services in the vehicle management app based on their service types. This allows the terminal device to sequentially obtain the data protection protocols of these services according to their arrangement. In other words, when user A uses the vehicle management app, the vehicle management app (or the terminal device with the vehicle management app installed) can automatically obtain the corresponding data protection protocols and display them to user A in the order of at least one service arrangement.
[0104] Figure 4 illustrates a data protection protocol orchestration and management diagram provided in an embodiment of this application. Figure 4 uses the account service, vehicle binding service, OTA upgrade service, remote control service, and remote parking service provided by the aforementioned vehicle management APP as examples. The account service is a basic service type, the vehicle binding service is a marketing service type, and the OTA upgrade service, remote control service, and remote parking service are enhanced service types.
[0105] The account service, vehicle binding service, OTA upgrade service, remote control service, and remote parking service can be arranged sequentially according to their service types. For example, the arrangement order (or position) of the basic type account service precedes the arrangement order of the marketing type vehicle binding service; that is, the data protection protocol acquisition order of the account service precedes that of the vehicle binding service. Similarly, the arrangement order of the marketing type vehicle binding service precedes that of the enhanced type OTA upgrade service; and the arrangement order of the marketing type vehicle binding service precedes that of the enhanced type remote control service; and the arrangement order of the vehicle binding service data protection protocol precedes that of the remote control service. The order of car-binding services with a marketing service type is before that of remote parking services with an enhanced service type. In other words, the order in which the data protection protocol of the car-binding service is obtained is before that of the data protection protocol of the remote parking service.
[0106] Optionally, the order of OTA upgrade services, remote control services, and remote parking services of the enhanced service type can be the same, or they can have different orders. For example, the order of OTA upgrade services, remote control services, and remote parking services can be set according to preset rules.
[0107] Optionally, for the remote parking service, the remote parking service includes at least one sub-service, such as a location information collection sub-service or other sub-services. The service type of the location information collection sub-service is a separate agreement type.
[0108] For example, regarding the account service, if user A has not yet registered for the vehicle management app (or before user A registers for the vehicle management app), when user A clicks the vehicle management app icon on their terminal device (which can be understood as clicking the vehicle management app's account service), the vehicle management app can respond to user A's click action regarding the account service, obtain the account service's data protection agreement, and can display the data protection agreement to user A. If user A agrees to the account service's data protection agreement, user A can sign the account service's data protection agreement. For example, user A can complete the signing of the account service's data protection agreement in the following ways: clicking the "Agree" button on the interface displaying the account service's data protection agreement, or checking the box in the agreement selection box (such as selecting the button indicating that they have read and agree to the account service's data protection agreement). After user A signs the account service's data protection agreement, the vehicle management app can display the corresponding interface to user A (such as the homepage interface), which is the corresponding interface that user A enters when accessing the vehicle management app. Optionally, after entering the corresponding interface of the vehicle management APP, user A can perform corresponding operations on the corresponding interface of the vehicle management APP, such as browsing the corresponding content on the corresponding interface of the vehicle management APP, activating a certain service on the corresponding interface of the vehicle management APP, clicking to view a certain service on the corresponding interface of the vehicle management APP, or clicking to view a certain promotional activity on the corresponding interface of the vehicle management APP, and so on.
[0109] Optionally, after the vehicle management app displays the corresponding interface to user A, if user A wants to activate the car binding service on the corresponding interface of the vehicle management app, user A can click on the car binding service on the corresponding interface of the vehicle management app. In response to user A's click on the car binding service, the vehicle management app can obtain the data protection agreement for the car binding service and can display the data protection agreement to user A. If user A agrees to the data protection agreement for the car binding service, user A can sign the data protection agreement. For example, user A can sign the data protection agreement for the car binding service by clicking the "Agree" button on the interface displaying the data protection agreement for the car binding service, or by checking the box in the "Agree to Data Protection Agreement" selection box (e.g., selecting the button indicating that the user has read and agrees to the data protection agreement for the car binding service). After user A signs the data protection agreement for the car binding service, the vehicle management app can display the car binding service interface to user A, that is, user A enters the car binding service interface (or enters the car binding function) or user A uses the car binding service. After entering the car binding service interface, User A can perform corresponding operations, such as browsing the corresponding service content or functions on the car binding service interface, or clicking to view a certain function service on the car binding service interface, or activating a certain function service on the car binding service interface, and so on.
[0110] Optionally, after the vehicle management app displays the vehicle binding service interface to user A, if user A wants to activate a specific service within the vehicle binding service interface (such as remote parking service), user A can click on the remote parking service within the vehicle binding service interface. In response to user A's click on the remote parking service, the vehicle management app can obtain the remote parking service's data protection agreement and can display it to user A. If user A agrees to the remote parking service's data protection agreement, user A can sign the data protection agreement. For example, user A can sign the remote parking service's data protection agreement by clicking the "Agree" button on the interface displaying the data protection agreement, or by checking the box in the "Agree to Data Protection Agreement" selection box (e.g., selecting the "I have read and agree to the remote parking service's data protection agreement" button). After user A signs the remote parking service's data protection agreement, the vehicle management app can display the remote parking service interface to user A, meaning user A enters the remote parking service interface (or enters the remote parking function) or uses the remote parking service. After entering the remote parking service interface, User A can perform various operations, such as selecting a target parking space for their vehicle, browsing relevant service content or functions, or activating a specific service. Optionally, if User A wants to activate the remote control service in the vehicle binding service interface, they can click on the remote control service. In response to User A's click on the remote control service, the vehicle management app can obtain the data protection agreement for the remote control service and display it to User A. If User A agrees to the data protection agreement, they can sign it. After User A signs the data protection agreement, the vehicle management app can display the remote control service interface to User A, allowing User A to access the remote control service (or access the remote control function) or use the remote control service, such as remotely turning on the vehicle's air conditioning.
[0111] Optionally, after the vehicle management app displays the remote parking service interface to user A, if user A wants to activate a specific service within the remote parking service interface (such as the location information collection sub-service), user A can click on the location information collection sub-service within the remote parking service interface. In response to user A's click on the location information collection sub-service, the vehicle management app can obtain the data protection agreement for the location information collection sub-service and can display the data protection agreement to user A. If user A agrees to the data protection agreement for the location information collection sub-service, user A can sign the data protection agreement. For example, user A can sign the data protection agreement for the location information collection sub-service by clicking the "Agree" button on the interface displaying the data protection agreement for the location information collection sub-service, or by checking the box to agree to the data protection agreement. After user A signs the data protection agreement for the location information collection sub-service, the vehicle management app can display the location information collection sub-service interface to user A, meaning user A enters the location information collection sub-service (or enters the location information collection function) or uses the location information collection sub-service.
[0112] Example A2: The first information includes the first management identifier and the user identifier of the first user.
[0113] The user identifier of the first user belongs to the first user identifier group. The first user identifier group is associated with (or corresponds to, maps to, or is bound to) the first gray-scale release identifier. The data protection protocol corresponding to the first gray-scale release identifier can be used as the data protection protocol of the first service. The first management identifier can also be used to identify the data protection protocol corresponding to the first gray-scale release identifier. It should be understood that the relevant description of the first management identifier can be found in the relevant introduction of the first management identifier in Example A1 above, and will not be repeated here.
[0114] In this embodiment, users can be grouped based on the gray-scale release identifier of the data protection protocol, and the gray-scale release data protection protocol can be associated with a specific group. For example, consider two data protection protocols (such as the data protection protocol for car-binding service and the data protection protocol for remote parking service) and two user identifier groups (such as user identifier group F1 and user identifier group F2). User identifier group F1 is associated with the new version of the data protection protocol for car-binding service; that is, user identifier group F1 can be associated with the gray-scale release identifier (such as gray-scale release identifier G1) corresponding to the new version of the data protection protocol for car-binding service. Other users who need to use the car-binding service are associated with the old version of the data protection protocol for car-binding service. User identifier group F2 is associated with the new version of the data protection protocol for remote parking service; that is, user identifier group F2 can be associated with the gray-scale release identifier (such as gray-scale release identifier G2) corresponding to the new version of the data protection protocol for remote parking service. Other users who need to use the remote parking service are associated with the old version of the data protection protocol for remote parking service. For example, user ID group F1 includes at least one user ID (such as user ID A, etc.), and user ID group F2 includes at least one user ID (such as user ID A', etc.).
[0115] Understandably, Example A2 above can be applied to scenarios where data protection protocols have different user scopes. For example, when some services (or some businesses) are upgraded, the corresponding data protection protocols need to be updated synchronously. The new version of the data protection protocol is first made available to a group of users, while other users can continue to use the old version. This allows terminal devices to obtain the corresponding data protection protocol according to different users (or specific users). For instance, users associated with the gray-scale release identifier corresponding to the new version of the data protection protocol can use the new version, while users not associated with the gray-scale release identifier can use the old version. Thus, even in scenarios where some services are updated and the corresponding data protection protocols are updated synchronously, terminal devices can still obtain the corresponding data protection protocols according to different users, thereby improving the efficiency of data protection protocol usage and meeting data protection specification requirements.
[0116] For example, continuing with the terminal device as a smartphone, the first user as user A, the first app installed on the smartphone as a vehicle management app, and the first service as a car binding service. When user A needs to activate the car binding service, user A can log in to the vehicle management app and click on the car binding service within the app. In response to user A's click on the car binding service, the smartphone can send information 2 to the cloud. Information 2 is used to request the data protection protocol for the car binding service. Information 2 includes a management identifier u1 and user A's identifier. The management identifier u1 is used to identify the data protection protocol for the car binding service. User A's identifier belongs to user identifier group F1. User identifier group F1 is associated with the gray-scale release identifier G1. The data protection protocol corresponding to the gray-scale release identifier G1 can be used as the data protection protocol for the car binding service.
[0117] For example, let's take the management identifier u1, which includes the application identifier of the vehicle management app, the service identifier of the car-binding service, the service type of the car-binding service, and the protocol type of the data protection protocol for the car-binding service. In one example, after detecting that user A clicked on the car-binding service, the vehicle management app can notify the smartphone of this action. Then, after learning that user A clicked on the car-binding service, the smartphone can obtain the application identifier of the vehicle management app, the service identifier of the car-binding service, the service type of the car-binding service, and the protocol type of the data protection protocol for the car-binding service. Then, the smartphone can generate information 2 based on user A's identifier, the application identifier of the vehicle management app, the service identifier of the car-binding service, the service type of the car-binding service, and the protocol type of the data protection protocol for the car-binding service. Furthermore, the smartphone can send information 2 to the cloud.
[0118] In another example, after the vehicle management app detects that user A clicks on the car-binding service, it can send user A's identifier, the car-binding service's service identifier, the car-binding service's service type, and the car-binding service's data protection protocol type to a smartphone. The smartphone can then obtain both user A's identifier, the car-binding service's service identifier, the car-binding service's service type, and the car-binding service's data protection protocol type, as well as the vehicle management app's application identifier. The smartphone can then generate information 2 based on these information. Furthermore, the smartphone can send information 2 to the cloud.
[0119] In another example, after the vehicle management app detects that user A clicks on the car-binding service, it can send the service identifier, service type, and data protection protocol type of the car-binding service to the smartphone. The smartphone, having obtained the service identifier, service type, and data protection protocol type, can also obtain user A's identifier and the vehicle management app's application identifier. Then, based on user A's identifier, the vehicle management app's application identifier, the car-binding service's service identifier, service type, and data protection protocol type, the smartphone can generate information 2. Furthermore, the smartphone can send information 2 to the cloud.
[0120] Step 302: The cloud sends the data protection protocol for the first service. The terminal device receives and displays the data protection protocol for the first service.
[0121] The following examples illustrate the implementation process of the data protection protocol for sending the first service from the cloud.
[0122] Example B1: When the first information includes a first management identifier, the cloud can obtain the first management identifier from the first information after receiving it. Then, the cloud can determine the data protection protocol for the first service based on the first management identifier and the first mapping relationship (also known as the first correspondence relationship). The cloud can then send the data protection protocol for the first service. Optionally, after receiving the data protection protocol for the first service from the cloud, the terminal device can display the data protection protocol for the first service. The first mapping relationship can include a mapping relationship between M management identifiers and N data protection protocols. The M management identifiers include the first management identifier. The N data protection protocols include the data protection protocol for the first service. M and N are both positive integers. For example, M and N can be equal, or M and N can be unequal.
[0123] In this embodiment, the cloud can provide a data protection agreement signing result query service to a second user (such as an administrator or a person with the authority to edit the data protection agreement). For example, the cloud can provide a user interface (UI), such as a first interface. The first interface is used to assist the second user in editing the data protection agreement. It is understood that by providing the second user with the first interface, human-computer interaction can be achieved, making the user's data protection agreement editing operation more intuitive and convenient, realizing visual editing of the data protection agreement. This allows users to edit the data protection agreements of one or more services in a timely and effective manner according to actual needs, while also enabling a visual display of the data protection agreements of one or more services.
[0124] The second user can perform corresponding operations on the first interface, such as editing the data protection agreement of one or more services, and editing the management identifiers corresponding to the data protection agreements of one or more services. In response to the second user's first operation on the first interface, the cloud can obtain the first management identifier and the data protection agreement of the first service. The first operation can be either the second user editing and submitting the data protection agreement of the first service on the first interface, or it can be the second user editing and submitting relevant information about the data protection agreement of the first service on the first interface. Optionally, the cloud can also display the first management identifier and the data protection agreement of the first service for the second user to confirm, view, or modify.
[0125] Optionally, after obtaining the first management identifier and the data protection protocol of the first service, the cloud can store the first management identifier and the data protection protocol of the first service in correspondence, or it can generate a mapping relationship between the first management identifier and the data protection protocol of the first service. In this way, the cloud can store M management identifiers and N data protection protocols in correspondence, or it can generate a mapping relationship between M management identifiers and N data protection protocols, thus enabling effective management of each data protection protocol. The mapping relationship between the M management identifiers and N data protection protocols forms the first mapping relationship.
[0126] For example, consider a user (e.g., an administrator) editing the data protection agreement for a car-binding service on the first interface. If the user needs to edit the data protection agreement, they can log in to the first interface via the cloud and edit the management identifier and the agreement itself. For instance, suppose the management identifier for the data protection agreement edited by the user on the first interface includes the vehicle management app's application identifier, the car-binding service's service identifier, the car-binding service's service type, the data protection agreement's protocol type, the data protection agreement's protocol version number, and the language used by the data protection agreement. Afterward, the user can submit the edited data protection agreement and its corresponding management identifier on the first interface. In response to the user's submission, the cloud can obtain the data protection agreement, the vehicle management app's application identifier, the car-binding service's service identifier, the car-binding service's service type, the data protection agreement's protocol type, the data protection agreement's protocol version number, and the language used by the data protection agreement. Then, the cloud can generate a management identifier for the vehicle binding service's data protection protocol, such as management identifier v1, based on the vehicle management app's application identifier, the vehicle binding service's service identifier, the vehicle binding service's service type, the vehicle binding service's data protection protocol type, the vehicle binding service's data protection protocol version number, and the language used by the vehicle binding service's data protection protocol. Furthermore, the cloud can store the management identifier v1 in correspondence with the vehicle binding service's data protection protocol, or it can generate a mapping relationship between the management identifier v1 and the vehicle binding service's data protection protocol.
[0127] Example B1 above allows the data protection protocol of an app on a terminal device (such as a specific data protection protocol within the app) to be retrieved online from the cloud without needing to be released with each application version. The terminal device can obtain the corresponding data protection protocol online based on its management identifier (such as the management identifier corresponding to a service's data protection protocol). This helps reduce the need for app version updates due to data protection protocol updates, thereby improving the efficiency of data protection protocol usage (i.e., improving the efficiency of data protection protocols across services), ensuring the effective use of data protection protocols for each service, and better meeting data protection regulatory requirements. Furthermore, compared to existing solutions that release data protection protocols within app versions, Example B1 is more convenient to use. It is also more convenient than existing solutions that release or query the signing results of data protection protocols separately for each app, effectively improving the efficiency of data protection protocol usage. It should be understood that the data protection protocol on the cloud side is updated in a timely manner, and the data protection protocol requested by the terminal device is also the latest. Therefore, the data protection protocol displayed to the user is also the latest, effectively preventing violations related to data protection and better meeting data protection regulatory requirements. For example, let's take the case of user A signing a data protection agreement for a car-binding service. After user A signs the agreement, the data protection agreement is updated. Then, the next time user A uses the car-binding service (e.g., by clicking on the car-binding service), the terminal device can request the latest data protection agreement from the cloud. The terminal device can then display this updated agreement to user A, allowing user A to either re-sign or not re-sign the agreement. This effectively protects user rights and avoids unnecessary disputes.
[0128] For example, the cloud-related implementation in Example B1 above can be executed by the data protection protocol management module in the cloud, as shown in Figure 5a. Figure 5a illustrates the data protection protocol management method using the data protection protocol management module in the cloud and the terminal device as the interactive execution entities, but this application does not limit the execution entities used in the interactive illustration.
[0129] As shown in Figure 5a, the implementation process may include:
[0130] Step 501a: In response to the first user's click on the first service, the terminal device sends the first information. Accordingly, the data protection protocol management module receives the first information.
[0131] The first information includes the first management identifier.
[0132] The data protection protocol management module can manage the data protection protocols for multiple services. For example, the data protection protocol management module can store a first mapping relationship, or it can list multiple management identifiers and their corresponding data protection protocols.
[0133] For example, taking the first service as a car-binding service, the first information is used to request the data protection protocol for the car-binding service. The first information includes the management identifier corresponding to the data protection protocol of the car-binding service, such as the management identifier k1.
[0134] Step 502a: The data protection protocol management module determines the data protection protocol for the first service based on the first mapping relationship and the first management identifier included in the first information.
[0135] For example, continuing with the example of the car-binding service as the first service and the first information used to request the data protection protocol for the car-binding service, the data protection protocol management module, upon receiving the first information, can obtain the management identifier k1 from it. The management identifier k1 identifies the data protection protocol for the car-binding service. Then, the data protection protocol management module can determine the data protection protocol for the car-binding service based on the first mapping relationship and the management identifier k1. The first mapping relationship includes the mapping relationship between the management identifier k1 and the data protection protocol for the car-binding service. Finally, the data protection protocol management module can send the data protection protocol for the car-binding service to the terminal device.
[0136] Optionally, the data protection protocol management module can also query the data protection protocol of the first service corresponding to the first management identifier in the storage area that stores multiple management identifiers and their corresponding multiple data protection protocols, based on the first management identifier.
[0137] Step 503a: The data protection protocol management module sends the data protection protocol for the first service. Correspondingly, the terminal device receives the data protection protocol for the first service.
[0138] Step 504a: The terminal device displays the data protection protocol for the first service.
[0139] After receiving the data protection protocol of the first service, the terminal device can display the data protection protocol of the first service. For example, the terminal device can display the data protection protocol of the first service in the form of a pop-up window, such as the terminal device can pop up a window or interface displaying the data protection protocol of the first service.
[0140] Optionally, after the terminal device displays the data protection protocol of the first service, the first user can perform corresponding operations on the data protection protocol of the first service.
[0141] For example, if the first user agrees to the data protection agreement of the first service (i.e., agrees to or acknowledges the contents of the data protection agreement), the first user can sign the data protection agreement. For instance, the first user can sign the data protection agreement by clicking the "Agree" button on the interface displaying the data protection agreement or by checking the box to agree. In response to the first user's signing of the data protection agreement, the terminal device can obtain the signing result. Then, the terminal device can send the signing result of the data protection agreement to the cloud. In this example, the signing result of the data protection agreement is "signed".
[0142] For example, if the first user does not agree to the data protection agreement of the first service (i.e., does not agree to or acknowledge the content contained in the data protection agreement), the first user can choose not to sign the data protection agreement. For instance, the first user can choose not to sign the data protection agreement by: closing the display interface of the data protection agreement, clicking the "Disagree" button, or not checking the box to agree to the data protection agreement. In response to the first user's action of not signing the data protection agreement, the terminal device can obtain the signing result of the data protection agreement. Then, the terminal device can send the signing result of the data protection agreement to the cloud. In this example, the signing result of the data protection agreement is "Not Signed".
[0143] Example B2: When the first information includes a first management identifier and a first user's user identifier, after receiving the first information, the cloud can obtain the first management identifier and the first user's user identifier from the first information. Then, the cloud can determine that the first user's user identifier belongs to a first user identifier group based on the first user identifier group. Next, the cloud can determine a first grayscale release identifier based on the first user identifier group and a second mapping relationship. Afterward, the cloud can determine the data protection protocol corresponding to the first grayscale release identifier based on the first grayscale release identifier and a third mapping relationship. Then, the cloud can send the data protection protocol corresponding to the first grayscale release identifier. Optionally, after receiving the data protection protocol corresponding to the first grayscale release identifier from the cloud, the terminal device can display the data protection protocol corresponding to the first grayscale release identifier. The data protection protocol corresponding to the first grayscale release identifier can be used as the data protection protocol for the first service. The second mapping relationship can include a mapping relationship between P user identifier groups and Q grayscale release identifiers. The P user identifier groups can include the first user identifier group, and the Q grayscale release identifiers can include the first grayscale release identifier. P and Q can be positive integers. For example, P and Q can be equal, or P and Q can be unequal. The third mapping relationship can include the mapping relationship between Q grayscale release identifiers and K data protection protocols. The K data protection protocols can include the data protection protocols corresponding to the first grayscale release identifier. K can be a positive integer. For example, Q and K can be equal, or Q and K can be unequal.
[0144] Example B2 above enables the cloud to provide corresponding data protection protocols to the APP on the terminal device according to different users. This allows the terminal device to obtain the corresponding data protection protocol well according to different users even when there are some service updates and corresponding data protection protocols are updated synchronously. This improves the efficiency of data protection protocol usage and meets the requirements of data protection specifications.
[0145] For example, the cloud-related implementation in Example B2 above can be executed by the data protection protocol management module in the cloud, as shown in Figure 5b. Figure 5b illustrates the data protection protocol management method using the data protection protocol management module in the cloud and the terminal device as the interactive execution entities, but this application does not limit the execution entities used in the interactive illustration.
[0146] As shown in Figure 5b, the implementation process may include:
[0147] Step 501b: In response to the first user's click on the first service, the terminal device sends the first information. Accordingly, the data protection protocol management module receives the first information.
[0148] The first information includes the first management identifier and the user identifier of the first user.
[0149] The data protection protocol management module can manage the data protection protocols for multiple services. For example, it can store a second mapping relationship, or it can list multiple user identifier groups and their corresponding canary release identifiers. It can also store a third mapping relationship, or it can list multiple canary release identifiers and their corresponding data protection protocols.
[0150] For example, taking the first service as a car-binding service, the first information as the data protection protocol for requesting the car-binding service, and the first user as user A, the first information includes the management identifier (e.g., management identifier k1) corresponding to the data protection protocol of the car-binding service and user A's user identifier.
[0151] Step 502b: The data protection protocol management module determines the first user identifier group to which the first user identifier belongs based on the user identifier of the first user included in the first information.
[0152] For example, consider a data protection protocol for requesting a car-binding service, where the first information is user A, and user A's user identifier belongs to user identifier group F1. The first information includes a management identifier k1 and user A's user identifier. The management identifier k1 identifies the data protection protocol for the car-binding service. After receiving the first information, the data protection protocol management module can obtain the management identifier k1 and user A's user identifier from it. Then, based on user A's user identifier, the data protection protocol management module can determine that user A's user identifier belongs to user identifier group A. For example, the data protection protocol management module can query user identifier group F1 corresponding to user A's user identifier among multiple user identifier groups, or it can match (or compare) user A's user identifier with each user identifier in multiple user identifier groups to determine the user identifier group F1 corresponding to user A's user identifier.
[0153] Step 503b: The data protection protocol management module determines the first grayscale release identifier based on the first user identifier group and the second mapping relationship.
[0154] For example, continuing with the first service being car-binding service, the first information is used to request the data protection protocol for car-binding service, the first user is user A, and user A's user identifier belongs to user identifier group F1. The first information includes management identifier k1 and user A's user identifier. After determining that user A's user identifier corresponds to user identifier group F1, the data protection protocol management module can determine the gray-scale release identifier corresponding to management identifier k1, such as gray-scale release identifier G1, based on the second mapping relationship and management identifier k1. The second mapping relationship includes the mapping relationship between management identifier k1 and gray-scale release identifier G1.
[0155] Step 504b: The data protection protocol management module determines the data protection protocol corresponding to the first gray-scale release identifier based on the first gray-scale release identifier and the third mapping relationship.
[0156] Among them, the data protection protocol corresponding to the first grayscale release identifier can be used as the data protection protocol for the first service.
[0157] For example, continuing with the first service being the car-binding service, the first information is used to request the data protection protocol for the car-binding service, the first user is user A, and user A's user identifier belongs to user identifier group F1. The first information includes management identifier k1 and user A's user identifier. After determining the gray-scale release identifier G1 corresponding to management identifier k1, the data protection protocol management module can determine the data protection protocol for the car-binding service corresponding to gray-scale release identifier G1 based on the third mapping relationship and gray-scale release identifier G1. For example, the data protection protocol for the new version of the car-binding service corresponding to gray-scale release identifier G1. Afterwards, the data protection protocol management module can send the data protection protocol for the car-binding service corresponding to gray-scale release identifier G1 to the terminal device.
[0158] Step 505b: The data protection protocol management module sends the data protection protocol corresponding to the first grayscale release identifier. Correspondingly, the terminal device receives the data protection protocol corresponding to the first grayscale release identifier.
[0159] Step 506b: The terminal device displays the data protection protocol corresponding to the first grayscale release identifier.
[0160] After receiving the data protection protocol corresponding to the first grayscale release identifier (which can be understood as the data protection protocol for the first service), the terminal device can display the data protection protocol corresponding to the first grayscale release identifier. For example, the terminal device can display the data protection protocol corresponding to the first grayscale release identifier in the form of a pop-up window, such as the terminal device can pop up a window or interface displaying the data protection protocol corresponding to the first grayscale release identifier.
[0161] Step 303: The terminal device responds to the operation of whether the first user has signed or not signed the data protection agreement for the first service, and obtains the signing result of the data protection agreement for the first service.
[0162] Step 304: The terminal device sends the signing result of the data protection agreement for the first service. Correspondingly, the cloud receives the signing result of the data protection agreement for the first service.
[0163] For example, the signing status of the data protection agreement for First Service includes both signed and unsigned. In other words, the signing status of the data protection agreement for First Service includes both signed and unsigned states.
[0164] For example, if the first user agrees to the first service's data protection agreement (i.e., agrees to or acknowledges the contents of the first service's data protection agreement), then the first user can sign the first service's data protection agreement. For instance, the first user can sign the first service's data protection agreement by clicking the "Agree" button on the interface displaying the first service's data protection agreement or by checking the box to agree to the data protection agreement. Conversely, if the first user does not agree to the first service's data protection agreement (i.e., does not agree to or acknowledge the contents of the first service's data protection agreement), then the first user can choose not to sign the first service's data protection agreement. For instance, the first user can choose not to sign the first service's data protection agreement by closing the first service's data protection agreement display interface, clicking the "Disagree" button, or not checking the box to agree to the data protection agreement.
[0165] In this embodiment of the application, after receiving the signing result of the data protection agreement of the first service, the cloud can store or archive the signing result of the data protection agreement of the first service, so as to realize the effective management of the signing results of the data protection agreements of each service.
[0166] Optionally, after storing the signing results of data protection agreements for at least one service, the cloud can also provide a data protection agreement signing result query service to a second user (such as an administrator or someone with the authority to edit data protection agreements). For example, the cloud can provide a user interface, such as a second interface. This second interface is used to assist the second user in querying the signing results of the data protection agreements. Understandably, by providing a second interface to the second user, human-computer interaction can be achieved, making the user's data protection agreement signing result query operation more intuitive and convenient, enabling visual editing of the data protection agreement signing result query request. This allows users to query the signing results of data protection agreements for one or more services in a timely and effective manner according to their actual needs, while also providing a visual display of the signing results.
[0167] The second user can perform corresponding operations on the second interface, such as editing query information (or query parameters), or editing (or entering) data protection agreement signing result query requirements. For example, data protection agreement signing result query requirements or query information may include data protection agreement signing result query parameters (also known as signing result query parameters). Data protection agreement signing result query parameters may include at least one of the following: management identifier, user identifier, or query time period.
[0168] In response to a second operation on the second user's second interface, the cloud can display the signing result of the data protection agreement for the first service. Optionally, the cloud can also display other information about the signing result of the data protection agreement for the first service, such as the signing time, the signing user identifier, the agreement name, agreement version number, or agreement type of the data protection agreement for the first service. The second operation can be an operation where the second user edits and submits query information on the second interface, or an operation where the second user edits their query request for the signing result of the data protection agreement for the first service on the second interface. The query information can include query parameters for the signing result of the data protection agreement corresponding to the data protection agreement for the first service. The query request for the signing result of the data protection agreement can include query parameters for the signing result of the data protection agreement corresponding to the data protection agreement for the first service. For example, the query parameters for the signing result of the data protection agreement can include at least one of the following: a first management identifier, a first user identifier, or a query time period.
[0169] For example, consider a user (e.g., an administrator) editing a data protection agreement signing result query request on the second interface. If the user needs to query the signing result of the data protection agreement for the car-binding service, they can log in to the second interface on the cloud and edit the query request, for example, the query request might include the management identifier u1 of the car-binding service's data protection agreement. Then, the user can submit the query request edited on the second interface. In response to the user's submission on the second interface, the cloud can obtain the data protection agreement signing result query request corresponding to the car-binding service. Then, the cloud can query the data protection agreement signing result corresponding to the management identifier u1 based on the query request and display the result to the user. Optionally, the cloud can query the data protection agreement signing result corresponding to the management identifier u1 in the data protection agreement signing result cache area, the database used to store data protection agreement signing results, or other storage areas.
[0170] As can be seen from steps 301 to 304 above, the terminal device can obtain the data protection protocol of the first service online from the cloud in a timely and accurate manner based on the management identifier corresponding to the data protection protocol of the first service. Therefore, compared with the existing solution of publishing the data protection protocol in the APP version, it can reduce the APP version update caused by the data protection protocol update, making it more convenient to use and thus improving the efficiency of data protection protocol usage (i.e., improving the efficiency of data protection protocols for each service), realizing the effective use of data protection protocols for each service, and better meeting the requirements of data protection specifications. In addition, the solution provided in steps 301 to 304 above can also realize the gray release identifier based on the data protection protocol, grouping different users. The gray release data protection protocol can be associated with a specific group, so that even in scenarios where some services are updated and the corresponding data protection protocols are updated synchronously, the terminal device can also obtain the corresponding (or matched or associated) data protection protocol according to different users, thereby improving the efficiency of data protection protocol usage and meeting the requirements of data protection specifications.
[0171] It should be noted that in the description of this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, "at least one of A, B, and C" includes A, B, C, AB, AC, BC, or ABC. Furthermore, unless otherwise specified, the ordinal numbers "first," "second," "third," etc., mentioned in the embodiments of this application are used to distinguish multiple objects and are not used to limit the order, sequence, priority, or importance of multiple objects. In addition, the terms "including," "comprising," "having," and their variations appearing in this application all mean "including but not limited to," unless otherwise specifically emphasized.
[0172] Furthermore, it should be noted that each step in the above embodiments can be executed by the corresponding device, or by components such as chips, processors, or chip systems within that device. This application does not limit the scope of these steps. The above embodiments are only illustrated by examples of execution by the corresponding device.
[0173] It should be noted that in the above embodiments, some steps may be selected for implementation, and the order of the steps in the figures may be adjusted. This application does not limit this. It should be understood that performing some of the steps in the figures, adjusting the order of the steps, or combining them in a specific implementation all fall within the protection scope of this application.
[0174] It is understood that, in order to achieve the functions described in the above embodiments, each device involved in the above embodiments includes a hardware structure and / or software module corresponding to perform each function. Those skilled in the art should readily recognize that, based on the units and method steps of the various examples described in conjunction with the embodiments disclosed in this application, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed by hardware or by computer software driving hardware depends on the specific application scenario and design constraints of the technical solution.
[0175] It should be noted that the "steps" in the embodiments of this application are merely illustrative and are intended to better understand one method of presentation used in the embodiments. They do not constitute a substantial limitation on the execution of the solution of this application. For example, the "step" can also be understood as a "feature". Furthermore, the steps do not constitute any limitation on the execution order of the solution of this application. Any changes to the order of steps, or the merging or splitting of steps made on this basis without affecting the overall solution implementation, resulting in a new technical solution, are also within the scope of disclosure of this application.
[0176] The following are schematic diagrams of possible data protection protocol management devices provided in embodiments of this application. These data protection protocol management devices can be used to implement the functions of the data protection protocol management devices in the above method embodiments, and thus can also achieve the beneficial effects of the above method embodiments. For example, the data protection protocol management device can be the terminal device 100 shown in FIG1 or the cloud 200 shown in FIG1, or it can be a module (such as a chip) applied to the terminal device 100 or the cloud 200.
[0177] As shown in Figure 6, the data protection protocol management device 600 includes a transceiver module 610 (or a communication module or transceiver unit, used for sending and receiving data) and a processing module 620 (or a processing unit). The data protection protocol management device 600 is used to implement the functions of the cloud or terminal device in the method embodiment shown in Figure 3. For example, the transceiver module 610 can perform the receiving and sending actions performed by the data protection protocol management device in the method embodiment. The processing module 620 can perform other actions besides the sending and receiving actions performed by the data protection protocol management device in the method embodiment.
[0178] Optionally, the transceiver module 610 may include a receiving module and / or a transmitting module. The receiving module can be used by the data protection protocol management device 600 to receive signals (or information or data, etc.); the transmitting module can be used by the data protection protocol management device 600 to transmit signals (or information or data, etc.). The transmitting module can transmit signals (or information or data, etc.) under the control of the processing module 620, and the receiving module can receive signals (or information or data, etc.) under the control of the processing module 620.
[0179] When the data protection protocol management device 600 is used to implement the functions of the terminal device in the method embodiment shown in Figure 3 above: the transceiver module 610 is used to send first information in response to the first user clicking on the first service. The first service may be included in at least one service, and the at least one service is provided by a first APP installed on the terminal device. The first information is used to request the data protection protocol of the first service. The first information may include a first management identifier. The first management identifier is used to identify the data protection protocol of the first service. Optionally, the first information may also include the user identifier of the first user. The user identifier of the first user belongs to a first user identifier group, and the first user identifier group is associated with a first grayscale release identifier. The data protection protocol corresponding to the first grayscale release identifier can be used as the data protection protocol of the first service. The first management identifier can also be used to identify the data protection protocol corresponding to the first grayscale release identifier. The transceiver module 610 is also used to receive the data protection protocol of the first service. The processing module 620 is used to control the display module (e.g., a display screen) to display the data protection protocol of the first service. The transceiver module 610 is also used to obtain the signing result of the data protection protocol of the first service in response to the first user's operation of signing or not signing the data protection protocol of the first service. The transceiver module 610 is also used to send the signing result of the data protection agreement for the first service.
[0180] When the data protection protocol management device 600 is used to implement the cloud functions in the method embodiment shown in Figure 3 above: the transceiver module 610 is used to receive first information. The first information is used to request the data protection protocol of the first service. The first information may include a first management identifier. The first management identifier is used to identify the data protection protocol of the first service. The first service may be included in at least one service, and at least one service is provided by a first APP installed on the terminal device. Optionally, the first information may also include a user identifier of a first user. The user identifier of the first user belongs to a first user identifier group, and the first user identifier group is associated with a first gray-scale release identifier. The data protection protocol corresponding to the first gray-scale release identifier can be used as the data protection protocol of the first service. The first management identifier can also be used to identify the data protection protocol corresponding to the first gray-scale release identifier. The transceiver module 610 is also used to send the data protection protocol of the first service. The transceiver module 610 is also used to receive the signing result of the data protection protocol of the first service. The processing module 620 is used to perform corresponding processing operations, such as calling the transceiver module 610 to execute the transceiver actions required by the cloud in the above method embodiment, or generating a management identifier (such as the first management identifier), etc.
[0181] For a more detailed description of the transceiver module 610 and the processing module 620, please refer to the relevant description in the method embodiment shown in Figure 3 above, which will not be repeated here.
[0182] It should be understood that the transceiver module 610 in the embodiments of this application can be implemented by an interface circuit (or communication interface or transceiver) or interface circuit-related circuit components, and the processing module 620 can be implemented by a processor or processor-related circuit components.
[0183] It should be noted that the module division in the embodiments of this application is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, exist as separate physical entities, or have two or more units integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.
[0184] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, or a server, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0185] The data protection protocol management device 700 shown in Figure 7 includes an interface circuit 710 and a processor 720. The processor 720 and the interface circuit 710 are coupled together. It is understood that the interface circuit 710 can be a transceiver or an input / output interface. The input / output interface is used for inputting and / or outputting information; output can be understood as sending, and input can be understood as receiving. Optionally, the data protection protocol management device 700 may further include a memory 730 for storing instructions executed by the processor 720, or storing input data required by the processor 720's execution instructions, or storing data generated after the processor 720 executes the instructions.
[0186] When the data protection protocol management device 700 is used to implement the method embodiment shown in FIG3, the processor 720 is used to implement the functions of the processing module 620, and the interface circuit 710 is used to implement the functions of the transceiver module 610. The processor 720 can be a central processing unit (CPU), a network processor (NP), or a combination of a CPU and an NP, etc. The processor 720 may further include a hardware chip. The hardware chip can be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The processor 720 can implement the above functions through hardware, or it can implement them by executing corresponding software.
[0187] Based on the same concept, this application also provides a computer program product, which includes a computer program or instructions that, when run on a computer, cause the computer to perform the methods provided in the above embodiments.
[0188] Based on the same concept, embodiments of this application also provide a computer-readable storage medium storing a computer program or instructions, which, when executed by a computer, causes the computer to perform the methods provided in the above embodiments.
[0189] The storage medium can be any available medium that a computer can access. For example, but not limited to, a computer-readable medium can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer.
[0190] Based on the same concept, embodiments of this application also provide a chip, which may include a processor and a memory (or the chip may be coupled to the memory). The chip executes program instructions in the memory to perform the methods provided in the above embodiments. Here, "coupling" refers to two components being directly or indirectly connected to each other; for example, coupling can refer to an electrical connection between two components.
[0191] Based on the same concept, embodiments of this application also provide a chip system, which includes a processor for supporting a computer device in implementing the functions involved in the cloud or terminal devices described in the above embodiments. In one possible design, the chip system further includes a memory for storing necessary programs and data of the computer device. This chip system may be composed of chips or may include chips and other discrete components.
[0192] The methods provided in this application can be implemented entirely or partially through software, hardware, firmware, or any combination thereof. When implemented in software, they can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., high-density digital video discs (DVDs)), or semiconductor media (e.g., solid-state drives (SSDs)).
[0193] The steps of the methods described in the embodiments of this application can be directly embedded in hardware, a software unit executed by a processor, or a combination of both. The software unit can be stored in RAM, ROM, EEPROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium in the art. Exemplarily, the storage medium can be connected to the processor so that the processor can read information from the storage medium and write information to the storage medium. Optionally, the storage medium can also be integrated into the processor. The processor and the storage medium can be housed in an ASIC.
[0194] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.
[0195] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.
[0196] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A data protection protocol management method, characterized in that, Applied to a terminal device, wherein a first application (APP) is installed on the terminal device, and the first APP is used to provide at least one service, the method includes: In response to a first user clicking on a first service, a first message is sent, the first service being included in the at least one service. The first message is used to request the data protection protocol of the first service. The first message includes a first management identifier, which is used to identify the data protection protocol of the first service. The first message also includes a user identifier of the first user, which belongs to a first user identifier group. The first user identifier group is associated with a first gray-scale release identifier. The data protection protocol corresponding to the first gray-scale release identifier serves as the data protection protocol of the first service. The first management identifier is also used to identify the data protection protocol corresponding to the first gray-scale release identifier. Receive and display the data protection protocol of the first service; In response to the first user's action of signing or not signing the data protection agreement of the first service, obtain the signing result of the data protection agreement of the first service; Send the signing result of the data protection agreement for the first service.
2. The method as described in claim 1, characterized in that, The first management identifier includes at least one of the following: application identifier, application version number, region, language, protocol type, protocol version number, service identifier, and service type; wherein, the application identifier is used to identify the first APP, the application version number is the version number of the first APP, the service identifier is used to identify the first service, the service type is the type of the first service, the region is the region where the data protection protocol of the first service is located, and the language is the language used by the data protection protocol of the first service.
3. The method as described in claim 1 or 2, characterized in that, The at least one service is arranged sequentially according to service type; or... The data protection protocols for at least one service are arranged sequentially according to the service type.
4. The method as described in claim 2 or 3, characterized in that, The service type of the at least one service includes at least one of the following: basic type, enhanced type, marketing type, and individual consent type.
5. The method according to any one of claims 1-4, characterized in that, The at least one service includes at least one of the following: account service, vehicle binding service, remote control service, remote parking service, over-the-air (OTA) upgrade service, remote operation and maintenance service, and entertainment service.
6. A data protection protocol management method, characterized in that, Applied to the cloud, the method includes: The system receives first information, which is used to request the data protection protocol of a first service. The first information includes a first management identifier, which is used to identify the data protection protocol of the first service. The first service is included in at least one service. The first information also includes a user identifier of a first user, which belongs to a first user identifier group. The first user identifier group is associated with a first gray-scale release identifier. The data protection protocol corresponding to the first gray-scale release identifier serves as the data protection protocol of the first service. The first management identifier is also used to identify the data protection protocol corresponding to the first gray-scale release identifier. Send the data protection protocol of the first service; Receive the signing result of the data protection agreement for the first service.
7. The method as described in claim 6, characterized in that, If the first information does not include the user identifier of the first user, the method further includes: Based on the first management identifier and the first mapping relationship, the data protection protocol of the first service is determined. The first mapping relationship includes the mapping relationship between M management identifiers and N data protection protocols. The M management identifiers include the first management identifier, and the N data protection protocols include the data protection protocol of the first service. M and N are positive integers.
8. The method as described in claim 6, characterized in that, If the first information also includes the user identifier of the first user, the method further includes: Determine that the user identifier of the first user belongs to the first user identifier group; Based on the first user identifier group and the second mapping relationship, a first grayscale release identifier is determined. The second mapping relationship includes the mapping relationship between P user identifier groups and Q grayscale release identifiers. The P user identifier groups include the first user identifier group, and the Q grayscale release identifiers include the first grayscale release identifier. P and Q are positive integers. Based on the first grayscale release identifier and the third mapping relationship, the data protection protocol corresponding to the first grayscale release identifier is determined. The third mapping relationship includes the mapping relationship between the Q grayscale release identifiers and K data protection protocols. The K data protection protocols include the data protection protocol corresponding to the first grayscale release identifier, where K is a positive integer.
9. The method according to any one of claims 6-8, characterized in that, The method further includes: A first interface is provided, which is an interface for editing data protection protocols; In response to a first operation by a second user on the first interface, the first management identifier and the data protection agreement of the first service are obtained. The first operation is the operation by which the second user edits and submits the data protection agreement of the first service on the first interface.
10. The method according to any one of claims 6-9, characterized in that, The method further includes: A second interface is provided, which is used to query the signing results of the data protection agreement; In response to a second user’s second operation on the second interface, the signing result of the data protection agreement of the first service is displayed. The second operation is the second user’s operation of editing and submitting query information on the second interface. The query information includes the query parameters of the signing result corresponding to the data protection agreement of the first service.
11. A data protection protocol management device, characterized in that, It includes modules or units for performing the method as described in any one of claims 1-5, or modules or units for performing the method as described in any one of claims 6-10.
12. A data protection protocol management device, characterized in that, Includes processor and interface circuitry; The interface circuit is used to receive signals from other communication devices and transmit them to the processor, or to send signals from the processor to other communication devices. The processor is configured to implement the method as described in any one of claims 1-5 or the method as described in any one of claims 6-10 through logic circuits or executing code instructions.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program or instructions that, when executed by a computer, cause the method as described in any one of claims 1-5 or any one of claims 6-10 to be implemented.