A label-based sensitive data tracking and tracing method, device and medium
By splitting sensitive semantics into complementary semantic fragments and constructing semantic closure rules, the first semantic transition event is identified, which solves the problem of insufficient efficiency and accuracy in the tracking and tracing of sensitive data in existing technologies, and realizes fine-grained tracking and rapid location of sensitive semantics.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHANGYUE (SHANGHAI) PRINTING CO LTD
- Filing Date
- 2026-05-08
- Publication Date
- 2026-07-31
AI Technical Summary
Existing technologies struggle to effectively identify sensitive semantics after multiple fragments have been recombined in the tracing and source tracking of sensitive data, and their efficiency and accuracy are limited in complex scenarios.
Sensitive semantics are identified at the field and combination levels, split into multiple complementary semantic fragments, generate complementary semantic fragment labels, construct a semantic closure rule table, identify the first semantic transition event, perform hierarchical unclosure repair, and perform reverse contraction tracing based on the transition evidence labels.
It enables fine-grained tracking of recoverable sensitive semantics, dynamically detects the risk of sensitive semantic recombination and recovery, and quickly locates the processing node in abnormal outflow processing that causes sensitive semantics to change from an unrecoverable state to a recoverable state.
Smart Images

Figure CN122490577A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security technology, and in particular to a tag-based method, device, and medium for tracing and tracking sensitive data. Background Technology
[0002] In data security governance scenarios, sensitive data tracing and source tracking typically revolves around field identification, tagging, access control, log retention, and audit playback. Conventional methods often involve tagging sensitive fields such as ID card numbers, mobile phone numbers, transaction accounts, location information, and medical information, and recording the processing trajectory during copying, transmission, exporting, sharing, and API calls. This allows for accountability and path tracing after abnormal data transfer or leakage incidents, thereby meeting the application requirements for data classification and hierarchical protection, compliance auditing, and security management.
[0003] However, as data processing chains become increasingly complex, conventional methods still have limitations in two aspects: First, existing methods mostly focus on tracking single fields or static tags, lacking the ability to identify the reconstructable sensitive semantics formed after multiple fragments are reassembled downstream; second, existing methods mostly rely on full log replay for tracing, making it difficult to narrow down the location around key state change nodes, resulting in limited tracing efficiency and accuracy in complex scenarios. In contrast, this invention emphasizes the dynamic identification and targeted backtracking of the sensitive semantic recovery process. Summary of the Invention
[0004] In view of the aforementioned existing problems, the present invention is proposed.
[0005] Therefore, this invention provides a label-based sensitive data tracking and tracing method to solve the problems of insufficient recognition of sensitive semantic recombination and recovery in existing technologies, as well as limited tracing and shrinking capabilities under complex links.
[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution: In a first aspect, the present invention provides a label-based sensitive data tracking and tracing method, comprising: acquiring the original data object; performing field-level and combination-level identification on the original data object to determine the sensitive semantics it carries; splitting the sensitive semantics into multiple complementary semantic fragments to generate complementary semantic fragment labels; merging and combining the effective complementary semantic fragment labels to determine the fragment combination that can minimally recover the corresponding sensitive semantics as the semantic closure rule; updating the fragment validity status of the complementary semantic fragment labels in the current output object, and performing the first semantic leap identification based on the updated complementary semantic fragment label set and the semantic closure rule; performing hierarchical unclosure repair around the first semantic leap event, and determining the object classification data and disposal data based on the repaired first semantic leap value and unclosure regression value; generating leap evidence labels by associating object information before and after processing, and performing reverse contraction tracing based on the leap evidence labels when the abnormal outflow object is in a semantically recoverable state to determine the priority tracing node.
[0007] As a preferred embodiment of the tag-based sensitive data tracking and tracing method of the present invention, the determination of the sensitive semantics carried includes: when the field-level identification data hits the single-field judgment condition in the sensitive semantics judgment table, determining that the original data object carries the corresponding single-field sensitive semantics; when the combination-level identification data hits the multi-field combination judgment condition in the sensitive semantics judgment table, determining that the original data object carries the corresponding combination sensitive semantics; when the field-level identification data and the combination-level identification data hit different sensitive semantics judgment conditions respectively, all the hit sensitive semantics are jointly determined as the sensitive semantics carried by the original data object; the sensitive semantics judgment table is a rule table for determining the sensitive semantics carried by the original data object, formed by classifying and organizing the field composition methods and combination recovery methods in historical sensitive data samples.
[0008] As a preferred embodiment of the label-based sensitive data tracking and tracing method of the present invention, the generation of complementary semantic fragment labels includes fragment identifier, associated sensitive semantic identifier, fragment source location, fragment completeness, fragment validity status, and closure number; the fragment completeness is calculated by the effective character retention ratio, structural position retention ratio, and distortion ratio of the complementary semantic fragment.
[0009] As a preferred embodiment of the label-based sensitive data tracking and tracing method of the present invention, the semantic closure rule includes: filtering complementary semantic fragment labels with valid fragment states from the complementary semantic fragment label set; merging the valid complementary semantic fragment labels according to their respective sensitive semantic identifiers and closure numbers to form corresponding same semantic fragment groups; combining the complementary semantic fragments in each same semantic fragment group according to the number of fragments from few to many, and comparing each fragment combination with the sensitive semantic judgment conditions to determine the semantic closure rule.
[0010] As a preferred embodiment of the label-based sensitive data tracking and tracing method of the present invention, the step of updating the fragment validity status of complementary semantic fragment labels in the current output object includes: extracting the semantic content and structural position information corresponding to each complementary semantic fragment in the current output object, and updating the fragment validity status of each complementary semantic fragment label in combination with the fragment completeness of each complementary semantic fragment; and checking the semantic closure rule based on the updated complementary semantic fragment label set.
[0011] As a preferred embodiment of the label-based sensitive data tracking and tracing method of the present invention, the first semantic transition identification includes: determining the triggered semantic closure rule based on the complementary semantic fragment label that the fragment's valid state is valid; calculating the first semantic transition value and the dominant transition criterion based on the triggered semantic closure rule; comparing the previous processing state corresponding to the current output object with the currently triggered semantic closure rule, and identifying the occurrence of the first semantic transition when the previous processing state is an unrecoverable state, the current existence of a triggered semantic closure rule, and the first semantic transition value is not less than the first semantic transition threshold.
[0012] As a preferred embodiment of the label-based sensitive data tracking and tracing method of the present invention, the determination of object classification data and disposal data includes: when the transition dominant criterion is not less than the transition dominant threshold, determining the current output object as a single closed dominant transition and performing single-point unclosing trial repair; when the transition dominant criterion is less than the transition dominant threshold, determining the current output object as a multi-closed concurrent transition and performing linked unclosing trial repair; when the repaired first semantic transition value is not greater than the first semantic transition threshold and the unclosing regression value is not less than the unclosing regression threshold, determining the object classification data corresponding to the current output object as a regressible object, and determining the disposal data as allowed to circulate or delayed to circulate; when the repaired first semantic transition value is greater than the first semantic transition threshold, or the unclosing regression value is less than the unclosing regression threshold, determining the object classification data corresponding to the current output object as a residual recovery object, and determining the disposal data as manual approval or blocked to circulate.
[0013] As a preferred embodiment of the label-based sensitive data tracing and source tracing method of the present invention, the determination of the priority source tracing node includes: taking the transition evidence label that is the most recent in time and whose post-transition object summary and abnormal outflow object summary are consistent as the first backtracking entry point; when there is no transition evidence label with completely consistent post-transition object summary, taking the transition evidence label with consistent key complementary semantic fragment set and consistent triggered semantic closure rule number as the first backtracking entry point; searching upstream for associated transition evidence labels around the first backtracking entry point and shrinking the key complementary semantic fragments; when the previous processing state has an unrecoverable state mark and the current processing node has triggered a semantic closure rule, determining the corresponding processing node as the priority source tracing node.
[0014] In a second aspect, the present invention provides a computer device including a memory and a processor, wherein the memory stores a computer program, wherein when the computer program is executed by the processor, it implements any step of the tag-based sensitive data tracking and tracing method described in the first aspect of the present invention.
[0015] Thirdly, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements any step of the tag-based sensitive data tracking and tracing method described in the first aspect of the present invention.
[0016] The beneficial effects of this invention are as follows: by splitting sensitive semantics into multiple complementary semantic fragments and generating complementary semantic fragment labels, fine-grained tracking of recoverable sensitive semantics is achieved; by constructing a semantic closure rule table and identifying the first semantic transition event, dynamic detection of the risk of sensitive semantic recombination and recovery is achieved; by performing hierarchical unclosure repair and performing reverse contraction tracing based on transition evidence labels, rapid location of the processing node that first changes the sensitive semantics from an unrecoverable state to a recoverable state in abnormal outflow processing is achieved. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is a flowchart of a label-based sensitive data tracking and tracing method.
[0019] Figure 2 A flowchart for generating complementary semantic fragment tags.
[0020] Figure 3A flowchart for constructing semantic closure rules and identifying the first semantic transition event.
[0021] Figure 4 This is a flowchart for hierarchical unblocking repair and reverse contraction tracing. Detailed Implementation
[0022] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0023] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.
[0024] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.
[0025] Reference Figures 1-4 This is one embodiment of the present invention, which provides a tag-based sensitive data tracking and tracing method, including the following steps: S1. Obtain the original data object, perform field-level and combination-level identification on the original data object, determine the sensitive semantics it carries, split the sensitive semantics into multiple complementary semantic fragments, and generate complementary semantic fragment labels.
[0026] Obtain the original data object that enters the processing flow, and perform field-level recognition and combination-level recognition on the original data object.
[0027] Among them, field-level recognition is used to identify single-field sensitive content in ID card numbers, mobile phone numbers, bank card numbers, addresses, medical records, transaction accounts, precise locations, and biometric features; combination-level recognition is used to identify sensitive content that a single field is insufficient to recover complete sensitive semantics, but multiple fields combined can recover the subject's identity, transaction relationship, location trajectory, or health status; based on field-level recognition data and combination-level recognition data, the sensitive semantics carried in the current original data object are determined.
[0028] It should be noted that when field-level identification data hits a single-field judgment condition in the sensitive semantic judgment table, the current original data object is determined to carry the corresponding single-field sensitive semantic; when combination-level identification data hits a multi-field combination judgment condition in the sensitive semantic judgment table, the current original data object is determined to carry the corresponding combination sensitive semantic; when field-level identification data and combination-level identification data hit different sensitive semantic judgment conditions respectively, all the hit sensitive semantics are jointly determined as the sensitive semantic carried in the current original data object.
[0029] It should be noted that the sensitive semantic judgment table is formed by classifying and organizing the field composition and combination recovery methods in historical sensitive data samples. The sensitive semantic judgment table includes at least the sensitive semantic name, the corresponding field set, and the corresponding combination conditions.
[0030] Furthermore, each sensitive semantic is broken down into multiple complementary semantic segments. Specifically, when the sensitive semantic is a subject identity recovery semantic, it is broken down into identity identifier segment, contact information segment, and location association segment; when the sensitive semantic is a transaction relationship recovery semantic, it is broken down into account identifier segment, transaction time segment, and transaction object segment; when the sensitive semantic is a trajectory recovery semantic, it is broken down into location segment, time segment, and behavior segment; and when the sensitive semantic is a health status recovery semantic, it is broken down into diagnosis and treatment segment, medication segment, and examination result segment.
[0031] Among them, complementary semantic fragments refer to the smallest semantic units that are insufficient to recover the corresponding sensitive semantics when existing alone, but can recover the sensitive semantics when they appear together with other specified fragments under the same sensitive semantics.
[0032] Furthermore, complementary semantic fragment labels are generated for each complementary semantic fragment.
[0033] Among them, the complementary semantic fragment label includes fragment identifier, sensitive semantic identifier, fragment source location, fragment completeness, fragment validity status, and closure number; multiple complementary semantic fragments corresponding to the same sensitive semantic share the same closure number.
[0034] It should be noted that the fragment source location is used to record the field position, record position, or table position of the complementary semantic fragment in the original data object, which is obtained by recording the field number, record number, or table number of the complementary semantic fragment in the original data object; the fragment validity status is used to characterize whether the complementary semantic fragment can still be recovered from the current output object in subsequent processing; the fragment integrity is used to characterize the degree to which the current complementary semantic fragment retains its original semantic expression.
[0035] It should be noted that the closure number is obtained by assigning the same number to all complementary semantic fragments under the same sensitive semantic; the sensitive semantic identifier is obtained by comparing the field-level identification data and the combination-level identification data with the judgment conditions in the sensitive semantic judgment table item by item, and taking the sequential number corresponding to the sensitive semantic name that is hit.
[0036] Furthermore, to quantify whether complementary semantic segments still possess the ability to participate in closure during subsequent processing, segment completeness is calculated using the following expression: ; in, For the first Fragment completeness of complementary semantic segments For the first The effective character retention ratio of complementary semantic segments For the first The ratio of structural position retention of complementary semantic segments For the first The distortion ratio of complementary semantic segments.
[0037] It should be noted that, Through the first The ratio of the number of valid characters that still retain the original semantic information in a complementary semantic segment to the number of original characters is obtained. Through the first The ratio of the number of structural positions retained in the current output object to the number of original structural positions of each complementary semantic fragment is obtained. Through the first The ratio of the number of characters masked, generalized, truncated, or replaced to the original number of characters in a complementary semantic segment is obtained.
[0038] When the fragment completeness is greater than zero and the current complementary semantic fragment still exists in the structural position of the current output object, the fragment is determined to be valid; when the fragment completeness is equal to zero or the current complementary semantic fragment no longer exists in the structural position of the current output object, the fragment is determined to be invalid.
[0039] S2. Merge and combine the effective complementary semantic fragment labels to determine the fragment combination that can recover the corresponding sensitive semantics at the minimum and is the semantic closure rule.
[0040] In the set of complementary semantic fragment tags, select complementary semantic fragment tags with valid status; merge complementary semantic fragment tags according to their respective sensitive semantic identifiers and closure numbers to obtain the same semantic fragment groups corresponding to the same sensitive semantic.
[0041] For each semantic fragment group, complementary semantic fragments are combined in ascending order of fragment quantity, and the results of each fragment combination are compared with the corresponding judgment conditions in the sensitive semantic judgment table. When a fragment combination result can recover the corresponding sensitive semantics, and the corresponding sensitive semantics cannot be recovered after deleting any complementary semantic fragment from the fragment combination, the fragment combination is determined as a semantic closure rule, and the corresponding closure rule number and key complementary semantic fragment set are recorded.
[0042] It should be noted that the set of key complementary semantic segments refers to the set of segments that can recover the corresponding sensitive semantics when they co-occur in the same semantic closure rule, and whose corresponding sensitive semantics cannot be recovered after deleting any of the complementary semantic segments.
[0043] It should be noted that being able to recover the corresponding sensitive semantics means that the fragment combination result contains all the complementary semantic fragment types listed in the corresponding field set conditions of the sensitive semantics determination table, and that each complementary semantic fragment has the same subject identifier, the same transaction identifier, or the same combination of time identifier and location identifier consistent with the corresponding combination conditions of the sensitive semantics determination table.
[0044] Furthermore, to quantify the recovery ability of different semantic closure rules for corresponding sensitive semantics, the semantic recovery strength is calculated, expressed as: ; in, For the first The semantic recovery strength of a semantic closure rule. For the first The sensitive attribute recovery ratio of semantic closure rules To utilize the first The subject unique recovery ratio of semantic closure rules, In order to be with the first The percentage of alternative combinations of semantic closure rules.
[0045] It should be noted that, By the first The ratio of the number of sensitive attribute items that can be recovered by a semantic closure rule to the total number of all sensitive semantic attribute items is obtained. It is by utilizing the first The ratio of the number of subjects that can be uniquely located by a single semantic closure rule to the total number of subjects in the same sensitive semantic sample is obtained; It is by connecting with the first The ratio of the number of alternative fragment combinations with the same recovery result of the semantic closure rule to the total number of fragment combinations compared for the sensitive semantic is obtained.
[0046] Furthermore, the closure rule number, the set of key complementary semantic segments, the semantic recovery strength, and the corresponding sensitive semantic identifier are written into the semantic closure rule table.
[0047] Furthermore, check whether the valid complementary semantic fragment tags carried in the current output object satisfy any semantic closure rule in the semantic closure rule table; when the valid complementary semantic fragment tags carried in the current output object cannot completely cover any key complementary semantic fragment set, write an unrecoverable state flag for the current output object; when the valid complementary semantic fragment tags carried in the current output object completely cover at least one key complementary semantic fragment set, generate a closure trigger record for the current output object.
[0048] The closure trigger record includes at least the closure rule number, the set of key complementary semantic segments that are triggered, and the corresponding sensitive semantic identifier.
[0049] It should be noted that an unrecoverable state marker refers to a state marker in which the effective complementary semantic fragment labels carried in the current output object are insufficient to satisfy any semantic closure rule.
[0050] S3. Update the valid status of complementary semantic fragment labels in the current output object, and perform the first semantic transition recognition based on the updated set of complementary semantic fragment labels and semantic closure rules.
[0051] When the current output object carrying complementary semantic fragment tags is filtered, copied, aggregated, connected, exported, shared, returned by an interface, output by a model call, or generated as a report, the retention status of each complementary semantic fragment in the current output object is checked first, and the fragment validity status in each complementary semantic fragment tag is updated.
[0052] Specifically, when a complementary semantic segment still retains at least one of the corresponding subject identifier, transaction identifier, time identifier, location identifier, or original semantic character in the current output object, and the segment completeness corresponding to the complementary semantic segment is greater than zero, the segment validity status of the complementary semantic segment is determined to be valid; when a complementary semantic segment no longer retains the corresponding subject identifier, transaction identifier, time identifier, location identifier, and original semantic character in the current output object, or the segment completeness corresponding to the complementary semantic segment is equal to zero, the segment validity status of the complementary semantic segment is determined to be invalid, and the updated complementary semantic segment tag set is obtained.
[0053] Furthermore, based on the updated set of complementary semantic fragment labels, the current output object is re-examined to see if it satisfies any of the semantic closure rules in the semantic closure rule table. Specifically, the set of key complementary semantic fragments in the semantic closure rule table is read one by one, and it is determined whether the complementary semantic fragments in the current output object whose fragment validity status is valid completely cover the set of key complementary semantic fragments. When there is complete coverage, a closure trigger record corresponding to the semantic closure rule is generated. When there is incomplete coverage, no corresponding closure trigger record is generated. If the current output object does not have any closure trigger records, the unrecoverable state mark is maintained. If the current output object has at least one closure trigger record, the unrecoverable state mark is canceled.
[0054] Furthermore, to quantify the strength of the transition from an unrecoverable state to a recoverable state in the current output object, the first semantic transition value is calculated, expressed as: ; ; in, For a moment The first semantic transition value of the current output object. This represents the number of semantic closure rules triggered in the current output object. For a moment Next The semantic recovery strength of a semantic closure rule. For a moment Next The product of fragment completeness corresponding to each semantic closure rule For a moment Next Co-occurrence coefficients of semantic closure rules within the same window. For a moment Reduce the sensitivity of the current output object by a certain amount; The product of the completeness of complementary semantic segments participating in the current semantic closure rule before the desensitization process; This is the product of the completeness of complementary semantic segments that participate in the current semantic closure rule after desensitization processing.
[0055] It should be noted that, By the first The completeness of all segments in the set of key complementary semantic segments corresponding to a semantic closure rule is obtained by multiplying the completeness of each segment in turn. By judging the first The key complementary semantic fragments corresponding to the semantic closure rule are obtained if they are simultaneously located in the same current output object. If they are simultaneously located in the same current output object, the value is 1; otherwise, the value is 0.
[0056] It should be noted that desensitization processing refers to performing at least one of the following processing on key complementary semantic segments participating in the current semantic closure rule: masking, generalization, intervalization, segment fragmentation, deletion, or isolation, in order to reduce the fragment integrity of the key complementary semantic segments or remove the current semantic closure rule.
[0057] Furthermore, to distinguish whether the semantic recovery in the current output object is dominated by a single closure rule or driven by multiple closure rules, the transition dominance criterion is calculated, expressed as: ; in, For a moment The dominant criterion for the transition of the current output object.
[0058] Furthermore, the previous processing result corresponding to the current output object is compared with the current closure trigger result; when the previous processing result has an unrecoverable state marker, and the current output object has a closure trigger record, and the first semantic transition value is not less than the first semantic transition threshold, it is determined that the first semantic transition event has occurred; when the previous processing result has an unrecoverable state marker, but the current output object does not have a closure trigger record, or the first semantic transition value is less than the first semantic transition threshold, it is determined that the first semantic transition event has not occurred.
[0059] It should be noted that the initial semantic transition threshold is obtained by calculating the initial semantic transition value for each historical normal output object corresponding to the same sensitive semantic category, and the maximum value of the initial semantic transition value among the historical normal output objects is taken, preferably with a value greater than 0.
[0060] It should be noted that the first semantic transition event refers to the event in which the current output object changes from an unrecoverable state of the previous processing result to a recoverable state of the current processing result.
[0061] S4. Perform hierarchical unblocking and repair around the first semantic transition event, and determine the object classification data and disposal data based on the repaired first semantic transition value and unblocking regression value.
[0062] When the initial semantic transition event identification result indicates that the initial semantic transition event has occurred, the trial repair entry point is determined based on the transition dominance criterion and the transition dominance threshold.
[0063] Specifically, when the transition dominance criterion is not less than the transition dominance threshold, the current output object is determined to be a single closed dominant transition, and a single-point unclosing test repair is performed first; when the transition dominance criterion is less than the transition dominance threshold, the current output object is determined to be a multi-closed concurrent transition, and a linked unclosing test repair is performed first.
[0064] It should be noted that the transition dominance threshold is obtained by calculating the transition dominance criterion for each historical normal output object corresponding to the same sensitive semantic category, and the maximum value of the transition dominance criterion in the historical normal output objects is taken. The preferred value range is [0,1].
[0065] Furthermore, single-point unclosing trial repair refers to selecting the semantic closure rule with the strongest semantic recovery strength from the closure trigger record of the current output object, and then selecting the complementary semantic segment with the highest segment completeness from the set of key complementary semantic segments corresponding to this semantic closure rule as the first trial repair segment. Masking is performed on the first trial repair segment. If the current output object still satisfies the semantic closure rule after masking, generalization processing is performed on the first trial repair segment. If the current output object still satisfies the semantic closure rule after generalization, deletion or isolation processing is performed on the first trial repair segment, thereby obtaining the current output after single-point unclosing trial repair. The linked declosing and trial repair refers to selecting all triggered semantic closure rules from the closure trigger record of the current output object, extracting the key complementary semantic fragment set corresponding to each semantic closure rule, and performing masking processing on the complementary semantic fragment with the highest fragment completeness in each key complementary semantic fragment set. If the current output object still satisfies at least one semantic closure rule after performing masking processing, then generalization processing is performed on the complementary semantic fragment. If the current output object still satisfies at least one semantic closure rule after performing generalization processing, then deletion processing or isolation processing is performed on the corresponding complementary semantic fragment, thereby obtaining the current output object after linked declosing and trial repair.
[0066] It should be noted that masking refers to replacing some characters in the key complementary semantic fragment with fixed mask characters; generalization refers to replacing the exact content in the key complementary semantic fragment with the corresponding superordinate category content; deletion refers to directly removing the corresponding key complementary semantic fragment from the current output object; and isolation refers to removing the corresponding key complementary semantic fragment from the current output object and saving it separately in a restricted object.
[0067] Furthermore, for the current output object after single-point unblocking trial repair and the current output object after linked unblocking trial repair, the effective state update and the first semantic transition value calculation are re-executed respectively to obtain the first semantic transition value after single-point unblocking trial repair and the first semantic transition value after linked unblocking trial repair. When the first semantic transition value after single-point unblocking trial repair is less than the first semantic transition value after linked unblocking trial repair, the formal repair entry point is determined to be single-point unblocking repair. When the first semantic transition value after single-point unblocking trial repair is greater than or equal to the first semantic transition value after linked unblocking trial repair, the formal repair entry point is determined to be linked unblocking repair.
[0068] Furthermore, perform minimal unblocking repair according to the formal repair entry point.
[0069] It should be noted that minimal unclosing repair refers to the unclosing repair process that minimizes the number of processing actions and the number of key complementary semantic segments involved in the processing, provided that the current output object no longer satisfies any semantic closure rule, or the first semantic transition value after repair is less than the first semantic transition threshold.
[0070] Specifically, when the formal repair entry point is single-point unclosure repair, processing continues along the first trial repair segment determined in the single-point unclosure trial repair, and the first semantic transition value is recalculated after each processing is completed; when the formal repair entry point is linked unclosure repair, processing continues along the combination of key complementary semantic segments determined in the linked unclosure trial repair, and the first semantic transition value is recalculated after each processing is completed; when the current output object no longer satisfies any semantic closure rule, or the first semantic transition value after repair is less than the first semantic transition threshold, the minimum unclosure repair ends, thereby obtaining the set of key complementary semantic segments and the current output object after completing the minimum unclosure repair.
[0071] Furthermore, to characterize the semantic recovery reduction effect and residual recovery degree of minimal unclosure repair on the current output object, the unclosure regression value is calculated, expressed as: ; in, For a moment The unclosed regression value of the current output object. This is the value of the first semantic transition after repair. To determine the number of key complementary semantic segments involved in minimum unclosing repair. This represents the closure residual ratio.
[0072] It should be noted that, It is the ratio of the number of complementary semantic segments that remain valid after repair and still participate in any semantic closure rule to the total number of complementary semantic segments.
[0073] Furthermore, when the repaired first semantic transition value is not greater than the first semantic transition threshold and the unclosure regression value is not less than the unclosure regression threshold, the current output object is determined to be a regressible object; when the repaired first semantic transition value is greater than the first semantic transition threshold, or the unclosure regression value is less than the unclosure regression threshold, the current output object is determined to be a residual recovery object, and object classification data is obtained.
[0074] It should be noted that the unclosure regression threshold is obtained by performing repair playback on each historical normal output object corresponding to the same sensitive semantic category and calculating the unclosure regression value, and the minimum value of the unclosure regression value among the historical normal output objects is taken, preferably in the range of [0,1].
[0075] Furthermore, disposal data is determined based on object classification data.
[0076] Specifically, when the object classification result is a regressible object, the output disposal data is either allow circulation or delay circulation; when the object classification data is a residual recovery object, the output disposal data is either manual approval or block circulation.
[0077] It should be noted that "allowed flow" means that the current output object can directly enter the subsequent processing flow; "delayed flow" means that the current output object enters the subsequent processing flow after completing supplementary processing; "manual approval" means that the current output object needs to be manually confirmed before it can enter the subsequent processing flow; and "blocked flow" means that the current output object is stopped from entering the subsequent processing flow.
[0078] S5. Generate transition evidence tags from the object information before and after association processing, and when the abnormal outflow object is in a semantically recoverable state, perform reverse shrinkage tracing based on the transition evidence tags to determine the priority tracing node.
[0079] The current output object is associated with the object summary before and after the execution of minimal unclosure repair, the triggered semantic closure rule number, the set of key complementary semantic segments, the processing action identifier, the processing subject, the object classification result, and the disposal data to generate a transition evidence label.
[0080] The transition evidence labels include the object summary before transition, the object summary after transition, the triggered semantic closure rule number, the set of key complementary semantic segments, the processing action identifier, the processing subject, the object classification result, and the disposal data.
[0081] Furthermore, when an abnormal outflow object is detected, the field content, record content, file content, or interface return content in the abnormal outflow object are first obtained, and the complementary semantic fragments in the abnormal outflow object are extracted again. The complementary semantic fragment tag set, closure trigger record, and first semantic transition value corresponding to the abnormal outflow object are regenerated. When the abnormal outflow object has a closure trigger record and the corresponding first semantic transition value is not less than the first semantic transition threshold, the abnormal outflow object is determined to be in a semantically recoverable state.
[0082] It should be noted that abnormal outflow objects refer to output objects that have flowed without a predetermined authorized path, left the original controlled processing environment, and pose a risk of external exposure. Output objects can be exported files, interface return objects, shared objects, report objects, or copied copies.
[0083] Furthermore, after determining that the abnormal outflow object is in a semantically recoverable state, the transition evidence tag that is the most recent in time and whose post-transition object summary is consistent with the abnormal outflow object summary is used as the first backtracking entry point; when there is no transition evidence tag that is completely consistent with the post-transition object summary, the transition evidence tag that is consistent with the set of key complementary semantic segments and whose triggered semantic closure rule numbers are consistent is used as the first backtracking entry point; the set of key complementary semantic segments and the processing subject corresponding to the first backtracking entry point are read, and the source field position, source record position or source table position of each key complementary semantic segment in the original data object is determined one by one in combination with the segment source position.
[0084] Furthermore, a reverse contraction tracing is performed around the first backtracking entry point. Specifically, the processing entity corresponding to the first backtracking entry point and the triggered semantic closure rule number are read, and then upstream is searched for upstream transition evidence tags that were generated before the current transition evidence tag and are associated with the complementary semantic fragment tag set corresponding to the same closure number. When an upstream transition evidence tag exists, the key complementary semantic fragment set in the upstream transition evidence tag is compared with the key complementary semantic fragment set in the current transition evidence tag. If the two are completely consistent, the upstream transition evidence tag is determined as the node to continue backtracking. If the two are not completely consistent, the key complementary semantic fragment that is consistent with the fragment source position in the abnormal outflow object is retained, and the remaining inconsistent fragments are deleted before continuing backtracking, so that the backtracking path always contracts around the key complementary semantic fragment that caused the abnormal outflow object to reach a semantically recoverable state.
[0085] Furthermore, when tracing back to a certain processing node, if the previous processing result corresponding to that processing node carries an unrecoverable state marker, and the transition evidence label corresponding to that processing node indicates that the current output object has triggered the semantic closure rule, then that processing node is determined to be the first processing node that changes the sensitive semantic from an unrecoverable state to a recoverable state, and is identified as the priority source node; if this condition is not met, the upstream transition evidence label retrieval and key complementary semantic fragment shrinkage are continued until the priority source node is determined or there is no more upstream transition evidence label.
[0086] It should be noted that the object summary before and after the transition are obtained by performing summary extraction on the current output objects before and after minimal unclogging repair.
[0087] It should be noted that the abnormal outflow object can be an abnormal exported file, an abnormal interface returned object, an abnormal shared object, an abnormal report object, or an abnormal copy.
[0088] It should be noted that the priority tracing node refers to the processing node that, during the reverse shrinking tracing process, is the first to change the sensitive semantics from an unrecoverable state to a recoverable state.
[0089] Thus, the generation of transition evidence tags is completed, as well as the reverse contraction tracing based on the transition evidence tags, thereby locating the processing node that first transforms the sensitive semantics from an unrecoverable state to a recoverable state after the abnormal outflow occurs.
[0090] This embodiment also provides a computer device applicable to the tag-based sensitive data tracking and tracing method, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the tag-based sensitive data tracking and tracing method proposed in the above embodiment.
[0091] The computer device can be a terminal, comprising a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, carrier networks, NFC (Near Field Communication), or other technologies. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the computer device's casing, or an external keyboard, touchpad, or mouse.
[0092] This embodiment also provides a storage medium storing a computer program that, when executed by a processor, implements the tag-based sensitive data tracking and tracing method proposed in the above embodiments. The storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Red-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.
[0093] In summary, this invention achieves fine-grained tracking of recoverable sensitive semantics by splitting sensitive semantics into multiple complementary semantic fragments and generating complementary semantic fragment labels; it achieves dynamic detection of the risk of sensitive semantic recombination and recovery by constructing a semantic closure rule table and identifying the first semantic transition event; and it achieves rapid location of the processing node that first transforms sensitive semantics from an unrecoverable state to a recoverable state in abnormal outflow processing by performing hierarchical unclosure repair and reverse contraction tracing based on transition evidence labels.
[0094] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A tag-based sensitive data tracking and tracing method, characterized in that, include: Obtain the original data object, perform field-level and combination-level identification on the original data object, determine the sensitive semantics it carries, split the sensitive semantics into multiple complementary semantic fragments, and generate complementary semantic fragment tags; The effective complementary semantic fragment labels are merged and compared to determine the fragment combination that can recover the corresponding sensitive semantics at the minimum, which is the semantic closure rule; Update the valid state of the complementary semantic fragment labels in the current output object, and perform the first semantic transition recognition based on the updated set of complementary semantic fragment labels and semantic closure rules; A hierarchical unclosure and repair process is performed around the first semantic transition event, and the object classification data and disposal data are determined based on the repaired first semantic transition value and unclosure regression value. The system generates transition evidence tags based on the object information before and after the association process. When the abnormal outflow object is in a semantically recoverable state, it performs reverse shrinkage tracing based on the transition evidence tags to determine the priority tracing node.
2. The label-based sensitive data tracking and tracing method as described in claim 1, characterized in that, The determination of the sensitive semantics carried includes: When the field-level identification data matches the single-field judgment condition in the sensitive semantic judgment table, it is determined that the original data object carries the corresponding single-field sensitive semantic. When the combined identification data matches the multi-field combination judgment condition in the sensitive semantic judgment table, it is determined that the original data object carries the corresponding combined sensitive semantics. When field-level identification data and combined-level identification data respectively hit different sensitive semantic judgment conditions, all the hit sensitive semantics will be jointly determined as the sensitive semantics carried by the original data object; The sensitive semantics determination table is a rule table formed by classifying and organizing the field composition and combination recovery methods in historical sensitive data samples, and is used to determine the sensitive semantics carried by the original data object.
3. The tag-based sensitive data tracking and tracing method as described in claim 1 or 2, characterized in that, The generated complementary semantic fragment tags include fragment identifier, associated sensitive semantic identifier, fragment source location, fragment completeness, fragment validity status, and closure number; The fragment integrity is calculated by the effective character retention ratio, structural position retention ratio, and distortion ratio of the complementary semantic fragment.
4. The tag-based sensitive data tracking and tracing method as described in claim 3, characterized in that, The semantic closure rules include: Filter complementary semantic fragment tags from the set of complementary semantic fragment tags to ensure that the fragment's valid state is valid. The effective complementary semantic fragment tags are merged according to their respective sensitive semantic identifiers and closure numbers to form corresponding semantic fragment groups; Complementary semantic segments in each semantic segment group are combined in ascending order of the number of segments, and each segment combination is compared with the sensitive semantic judgment condition to determine the semantic closure rule.
5. The tag-based sensitive data tracking and tracing method as described in claim 4, characterized in that, The process of updating the valid state of complementary semantic fragment labels in the current output object includes: Extract the semantic content and structural position information corresponding to each complementary semantic fragment in the current output object, and update the fragment validity status of each complementary semantic fragment tag based on the fragment completeness of each complementary semantic fragment. The semantic closure rule is checked based on the updated set of complementary semantic fragment labels.
6. The tag-based sensitive data tracking and tracing method as described in claim 5, characterized in that, The initial semantic transition recognition includes: The triggered semantic closure rule is determined based on the complementary semantic fragment label whose valid state is valid; The initial semantic transition value and the dominant transition criterion are calculated based on the triggered semantic closure rule; The previous processing state corresponding to the current output object is compared with the currently triggered semantic closure rule. If the previous processing state is an unrecoverable state, there is a currently triggered semantic closure rule, and the first semantic transition value is not less than the first semantic transition threshold, it is identified as the first semantic transition.
7. The tag-based sensitive data tracking and tracing method as described in claim 6, characterized in that, The identified object classification data and disposal data include: When the transition dominance criterion is not less than the transition dominance threshold, the current output object is determined to be a single closed dominant transition and a single-point unclosing test repair is performed. When the transition dominance criterion is less than the transition dominance threshold, the current output object is determined to be a multi-closed concurrent transition and a linkage unclosing test repair is performed. When the first semantic transition value after repair is not greater than the first semantic transition threshold and the unclosing regression value is not less than the unclosing regression threshold, the object classification data corresponding to the current output object is determined to be a regressible object, and the disposal data is determined to be allowed to flow or delayed to flow. When the first semantic transition value after repair is greater than the first semantic transition threshold, or the unclosing regression value is less than the unclosing regression threshold, the object classification data corresponding to the current output object is determined to be a residual recovery object, and the disposal data is determined to be manually approved or blocked from circulation.
8. The label-based sensitive data tracking and tracing method as described in claim 7, characterized in that, The determination of priority tracing nodes includes: The jump evidence label that is the most recent in time and whose post-jump object summary is consistent with the abnormal outflow object summary is used as the first backtracking entry point; When there is no transition evidence label that is completely consistent with the object summary after the transition, the transition evidence label that is consistent with the set of key complementary semantic segments and has the same semantic closure rule number is used as the first backtracking entry point. Search upstream for related transition evidence tags around the first backtracking entry point and shrink key complementary semantic segments. When the previous processing state has an unrecoverable state mark and the current processing node has triggered the semantic closure rule, the corresponding processing node is determined as the priority source node.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the tag-based sensitive data tracking and tracing method according to any one of claims 1 to 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the tag-based sensitive data tracking and tracing method according to any one of claims 1 to 8.