Spam processing apparatus and system capable of protecting personal privacy, and medium

By introducing technical means such as hierarchical classification, encrypted storage and ciphertext identification into the mobile spam processing device, the problem of user privacy data leakage in mobile spam processing is solved, and more efficient spam detection and user privacy protection are achieved.

WO2025138625A1PCT designated stage expired Publication Date: 2025-07-03CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/099077
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-28
Filing Date
2024-06-13
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

In the process of controlling mobile spam information, the prior art can easily cause user privacy data leakage and information security problems, and does not fully protect user personal identity information.

Method used

Spam information processing devices that protect personal privacy are adopted, including reporting modules, management modules, processing modules and monitoring modules. Data security and privacy protection are ensured through technical means such as hierarchical and classified processing, encrypted storage, real-time monitoring and ciphertext identification.

Benefits of technology

It effectively reduces user privacy data leakage and information security issues, improves the detection rate of mobile spam information, and creates a healthy and orderly mobile communication environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024099077_03072025_PF_FP_ABST
    Figure CN2024099077_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the field of network security, and provides a spam processing apparatus and system capable of protecting personal privacy, and a medium. The spam processing apparatus capable of protecting personal privacy comprises a reporting module, a management module, a processing module and a monitoring module of a server end, and a data receiving module and a data reporting module of a client, wherein the data reporting module respectively transmits erroneously marked spam and unmarked spam to the processing module and the reporting module; the reporting module performs hierarchical classification processing on data; the management module securely stores and shares the data; the processing module monitors a malicious behavior, records data determined as spam, and transmits, to the monitoring module, detected spam needing to be identified; the monitoring module identifies the spam needing to be identified. Therefore, the leakage of user privacy data and an information security problem can be reduced, and the protection on the personal identity information of a user in a mobile spam processing process is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Spam processing devices, systems, and media for protecting personal privacy

[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on December 28, 2023, with application number 202311843833.X and application name “Garbage Information Processing Device, System and Medium for Protecting Personal Privacy”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of network security, and in particular to a spam information processing device, system, and medium for protecting personal privacy. Background Art

[0003] With the rapid development of telecommunication services, solutions to combat mobile spam messages based on text messages, phone calls, etc. have emerged frequently.

[0004] Existing technical solutions focus primarily on improving mobile spam detection rates, but protecting users' personal identity information during the spam control process has been somewhat neglected. For example, when using a user's phone number, existing methods typically encrypt the middle four digits before parsing the data. However, these digits are actually the area code, and the user's actual number can be obtained by leveraging other location information. Another example is when using keyword technology to filter text messages, which are typically sent in plain text, making it relatively easy to obtain the user's text message content directly through technical means.

[0005] In summary, in the process of processing mobile spam, the existing technology is likely to cause leakage of user's private data and cause information security problems.

[0006] Summary of the Invention

[0007] The present application provides a spam processing device, system and medium for protecting personal privacy, which are used to solve the user privacy data leakage and information security problems caused by the existing technology in the process of processing mobile spam.

[0008] In a first aspect, the present application provides a spam processing device for protecting personal privacy, comprising:

[0009] Reporting module, management module, processing module and monitoring module;

[0010] The reporting module is used to perform hierarchical classification processing on the data according to the data type and importance characteristics, and the data is the unmarked or unfiltered junk information in the mobile information uploaded by the client;

[0011] The management module is used to encrypt and securely store subscriber data and cancel filtering services based on the needs of the subscriber;

[0012] The processing module is used to monitor malicious behavior and record data determined to be spam using filtering rules and form log data;

[0013] The processing module is further configured to transmit spam information that needs to be identified to the monitoring module, and delete the spam information that needs to be identified after the transmission, wherein the spam information that needs to be identified includes spam information that is incorrectly marked in the mobile information uploaded by the client and received by the processing module, and spam information captured using honeypot technology;

[0014] The monitoring module is used to identify the junk information that needs to be identified, and to record and monitor the identification process of the junk information that needs to be identified, and the identification process uses a ciphertext identification method.

[0015] In a possible design of the first aspect, the processing module is further configured to detect the spam information that needs to be identified before transmitting the spam information that needs to be identified to obtain a detection result, wherein the detection result is used to indicate whether there is a virus in the spam information that needs to be identified.

[0016] In a possible design of the first aspect, the reporting module is further used to notify the client of data sharing information, where the data sharing information is used to indicate data to be shared with a third party.

[0017] In a possible design of the first aspect, the processing module is further configured to destroy data that is not marked as spam.

[0018] In a possible design of the first aspect, the monitoring module is further configured to delete the user personal data contained in the spam information that needs to be identified before identifying the spam information that needs to be identified.

[0019] In a possible design of the first aspect, the management module is further used to encrypt data that needs to be shared with management modules of other organizations.

[0020] In a possible design of the first aspect, a secure interface is used for data transmission between the modules in the reporting module, the management module, the processing module and the monitoring module, and the secure interface is used to build an end-to-end encryption channel to protect the confidentiality and integrity of the data.

[0021] In a second aspect, the present application provides a spam processing device for protecting personal privacy, comprising:

[0022] Data receiving module and data reporting module;

[0023] The data receiving module is used to receive movement information;

[0024] The data reporting module is used to upload the junk information in the mobile information that has not been marked or filtered and the junk information in the mobile information that has been marked incorrectly to the server.

[0025] In a third aspect, the present application provides a spam processing system for protecting personal privacy, comprising: a server and a client in at least one terminal device; wherein the server is provided with the spam processing device for protecting personal privacy as described in any one of the first aspects, and the client is provided with the spam processing device for protecting personal privacy as described in the second aspect.

[0026] In a fourth aspect, the present application provides a computer storage medium storing a computer program. When the computer program is executed by a processor, the computer program implements the functions of the spam processing device for protecting personal privacy as described in any one of the first or second aspects.

[0027] In a fifth aspect, the present application provides a chip, comprising a memory and a processor, wherein the memory stores code and data, the memory is coupled to the processor, and the processor runs the program in the memory so that the chip is used to perform the functions of the spam processing device for protecting personal privacy as described in any one of the first or second aspects above.

[0028] In a sixth aspect, the present application provides a program product, comprising: a computer program, which, when executed on a computer, enables the computer to execute the functions of the spam processing device for protecting personal privacy as described in any one of the first or second aspects above.

[0029] In a seventh aspect, the present application provides a computer program, which, when executed by a processor, is used to perform the functions of the spam processing device for protecting personal privacy as described in any one of the first aspect or the second aspect above.

[0030] The present application provides a spam processing device, system, and medium that protects personal privacy and can be used in the field of network security. The spam processing device that protects personal privacy includes a reporting module, a management module, a processing module, and a monitoring module on the server side, as well as a data receiving module and a data reporting module on the client side. Data is transmitted between each module via a secure interface, and each independent module presets different security measures based on requirements. For example, the reporting module sets hierarchical classification processing for received data. The management module implements secure storage and sharing of data. The processing module monitors malicious behavior in real time and performs detection operations on data that requires authentication before being transmitted to the monitoring module to avoid the presence of virus data. Before authenticating the data, the monitoring module deletes information containing user personal data. The modules work together to reduce user privacy data leakage and information security issues that may arise during the process of managing mobile spam, thereby effectively protecting users' personal identity information. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0032] FIG1 is a schematic diagram of an application scenario of the spam processing device for protecting personal privacy provided by this application;

[0033] FIG2 is a schematic diagram of a first embodiment of a spam processing device for protecting personal privacy provided by the present application;

[0034] FIG3 is a schematic diagram of a second embodiment of a spam processing device for protecting personal privacy provided by the present application;

[0035] FIG4 is a schematic diagram of a spam information processing system for protecting personal privacy provided by this application.

[0036] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION

[0037] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.

[0038] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0039] Figure 1 is a schematic diagram of an application scenario for the privacy-protecting spam processing apparatus provided in this application. As shown in Figure 1 , the privacy-protecting spam processing apparatus 100 includes a server 101 and clients 102. As an example, Figure 1 shows four clients: client 102-1, client 102-2, client 102-3, and client 102-4. It should be understood that in actual applications, the privacy-protecting spam processing apparatus 100 may include more or fewer clients 102. Clients 102 are connected to server 101 via a communication network.

[0040] Server 101 is typically maintained and managed by a mobile spam processing operator. Operators can use server 101 to assist users in filtering and blocking mobile spam. Operators can also collect user complaint data to generate sample data sets, and process these sample data sets to improve mobile spam filtering and reduce false positives and missed negatives. Although Figure 1 shows only one server 101, it should be understood that two or more servers 101 may be present.

[0041] Client 102 is configured in any mobile terminal capable of sending and receiving information data. When receiving information data, client 102, with the assistance of server 101, can intercept some mobile information data according to certain filtering rules, thereby reducing the user's exposure to mobile spam. Client 102 can also report collected mobile spam to server 101, thereby enriching server 101's mobile spam database.

[0042] However, in the process of the server 101 assisting the client 102 in combating mobile spam, there are problems of leakage of user privacy data and information security.

[0043] Currently, common approaches to this problem involve encryption technology and keyword filtering rules. For example, when using a user's phone number, the middle four digits are typically encrypted before data analysis. Another example is text message filtering, which primarily relies on keyword technology. Mobile messages received by the client are filtered and intercepted based on pre-set keywords.

[0044] However, this solution has the following issues: the encrypted middle four digits of a user's phone number are actually the area code, allowing the user's actual number to be obtained by leveraging other location information. When using keyword filtering for SMS messages, SMS messages are typically sent in plain text, making it relatively straightforward to obtain the actual content through technical means. Therefore, this mobile spam control solution still poses concerns about user privacy and data security.

[0045] In view of the above problems, the inventors found in the process of studying the leakage of user privacy data and information security issues in the process of managing mobile spam that operators usually focus on how to improve the detection rate of mobile spam, but ignore the protection of users' personal identity information, which to a certain extent easily leads to leakage of user privacy data and information security issues. Based on this, the inventors considered whether it is possible to protect user privacy data with the help of encryption technology and setting up security interfaces in the process of managing mobile spam, thereby reducing the probability of leakage of user privacy data and information security issues. Specifically, in the process of managing mobile spam, the entire life cycle of information data is considered, namely data collection / data generation, data transmission, data storage, data processing, data sharing and data destruction, and different security functions are designed according to different stages of the information data life cycle, so as to effectively protect users' personal identity information and reduce leakage of user privacy data and information security issues.

[0046] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0047] It should be understood that the modules involved in the embodiments of the present application refer to functional modules in the framework of a spam information processing system that protects personal privacy.

[0048] Figure 2 is a schematic diagram of a first embodiment of a spam processing device for protecting personal privacy provided by this application. As shown in Figure 2, a spam processing device for protecting personal privacy deployed on a server 201 is provided.

[0049] The spam processing device for protecting personal privacy deployed in the server 201 includes four modules: a reporting module 2011, a management module 2012, a processing module 2013, and a monitoring module 2014. The four modules mainly use API interfaces using secure protocols such as https and TLS for data transmission.

[0050] The following is a detailed introduction to the functions of the four modules mentioned above.

[0051] The reporting module 2011 is used to classify and process data according to data type and importance characteristics. The data is junk information that has not been marked or filtered in the mobile information uploaded by the client.

[0052] Specifically, the reporting module 2011 is a functional module in the spam processing device for protecting personal privacy, and is mainly used to receive mobile spam complaints from users and perform hierarchical classification on this data information.

[0053] The number of clients can be one or more, and they can be installed in different terminal devices. The data information obtained by the reporting module 2011 from the clients involves user complaints of spam mobile information, which includes harassing calls and spam text messages. The data sources for these spam mobile information complaints include two parts: the first part is the unmarked or unfiltered spam in encrypted mobile information transmitted through the clients by users who have subscribed to the spam processing function. The second part is the mobile spam transmitted through the clients by users who have not subscribed to the spam processing function.

[0054] For example, if user A, who has subscribed to the spam handling function, receives a mobile message that is not a normal mobile message, user A can transmit the mobile message via the client to the reporting module 2011 in the server 201. For another example, if user B, who has not subscribed to the spam handling function, receives a mobile spam message, user B can transmit the mobile spam message via the client to the reporting module 2011 in the server 201 to avoid receiving similar mobile spam messages in the future.

[0055] When the reporting module 2011 receives mobile spam complaints from users, it will classify and process the spam according to its type and importance. Classification is a key part of data protection, with the primary purpose being to facilitate data management, use, and sharing. The classification methods involved are primarily based on the type of data, its importance, and the potential consequences and impact of data leaks. For example, in one possible implementation, the reporting module 2011 can ultimately classify the data into at least the following three categories:

[0056] Level 0: This data is harmless or useless to anyone, such as Trojans, viruses, fraudulent data, etc.

[0057] Level 1: This data is useless or unwanted for certain groups of people, such as commercial advertisements.

[0058] Level 2: This data is related to a person, such as personal identity information.

[0059] Based on hierarchical classification, spam mobile information reported by users can be categorized into multiple types, generating spam data signatures. Data such as Trojans, viruses, and fraudulent content can be directly deleted, preventing them from infecting spam processing devices. Spam mobile information, such as commercial advertisements, can be processed by the reporting module 2011 to generate spam data signatures, which can then be securely shared with the management module 2012.

[0060] The management module 2012 is used to encrypt and securely store subscriber data and cancel filtering services based on subscriber needs.

[0061] Specifically, the management module 2012 is a functional module in the spam processing device for protecting personal privacy, and is mainly used to encrypt and securely store subscriber data and cancel filtering services based on subscriber needs.

[0062] Here, subscribers refer to users who subscribe to the spam mobile information processing function. When the reporting module 2011 forms new spam mobile information data features, it will securely share these newly formed spam mobile information data features with the management module 2012. These features are obtained based on spam mobile information complaints submitted by users through the client. Therefore, after the management module 2012 receives the new spam mobile information data features transmitted by the reporting module 2011, it will encrypt and securely store the subscriber data involved. Encryption methods include MD5 encryption, SHA1 encryption, 3DES encryption, AES encryption, RC4 encryption, and RC5 encryption. The specific encryption method to be applied needs to be determined based on the different types of data, which involves the data processing stage of the entire data life cycle.

[0063] Management module 2012 also provides a filtering cancellation service based on subscriber requests. For example, if a user who previously subscribed to the mobile spam processing function wishes to cancel the service, the user can send a request to cancel the filtering service to management module 2012 deployed in server 201 via the client. Upon receiving the cancellation request from the subscriber, management module 2012 will cancel the mobile information filtering function provided to the user and securely delete all data associated with the user.

[0064] In one possible implementation, management module 2012 also receives spam mobile information from third-party partners. These third-party partners can be business partners of the operator, security management departments, and so on. If a user who subscribes to the spam mobile information processing function wishes to add custom spam filtering rules, they can send these custom spam filtering rules to management module 2012 deployed in server 201 via the client. This involves the data collection and generation phases of the data lifecycle.

[0065] The management module 2012 formulates spam filtering rules based on the new spam data features sent by the reporting module 2011, the spam mobile information sent by third-party partners, and the user-defined spam filtering rules, and transmits them to the processing module 2013 in real time.

[0066] The processing module 2013 is used to monitor malicious behavior and record data determined to be spam using filtering rules and generate log data.

[0067] Specifically, the processing module 2013 is a functional module in the spam processing device for protecting personal privacy, and is mainly used to monitor malicious behavior and record data determined as spam using filtering rules and form log data.

[0068] Monitoring malicious behavior refers to the real-time monitoring by processing module 2013 to determine whether spam filtering rules have been maliciously altered, thereby ensuring the effectiveness of these rules. If these rules are maliciously altered, users who subscribe to the mobile spam processing feature will receive a large amount of spam, potentially exposing their personal privacy data to potential data security breaches. Spam filtering rules are transmitted from management module 2012 to processing module 2013 via a secure interface.

[0069] The processing module 2013 also provides spam filtering for users who have subscribed to the spam processing function based on the spam filtering rules sent by the management module 2012. For example, the terminal device of user C who has subscribed to the spam processing function receives mobile messages sent by other terminal devices at any time and anywhere. Among these sent mobile messages, spam mobile messages are inevitable. In this case, the spam filtering rules can filter these mobile messages with spam characteristics in real time, preventing user C from receiving spam.

[0070] While processing module 2013 provides spam filtering for users who subscribe to the spam handling function, it also records data identified as spam using the filtering rules in real time and creates log data. For example, if the spam data filtered by processing module 2013 for user D who subscribes to the spam handling function is messageA, processing module 2013 will record the spam data messageA in real time, create log data corresponding to user D, and save it to the corresponding log database. Each user who subscribes to the spam handling function has a corresponding log database in processing module 2013, which details the spam filtered out by processing module 2013 using the filtering rules for that user.

[0071] The processing module 2013 is also used to transmit the spam information that needs to be identified to the monitoring module 2014, and delete the spam information that needs to be identified after the transmission. The spam information that needs to be identified includes the spam information that is incorrectly marked in the mobile information uploaded by the client and received by the processing module 2013, and the spam information captured by using the honeypot technology.

[0072] Specifically, in addition to providing monitoring of malicious behavior and recording data that will be determined as spam using filtering rules and forming log data, the processing module 2013 is also used to transmit spam that needs to be identified to the monitoring module 2014, and delete the spam that needs to be identified after transmission.

[0073] The spam information that needs to be identified includes two parts: the first part is the spam information that is incorrectly marked in the mobile information uploaded by the client and received by the processing module 2013. The second part is the spam information captured by using the honeypot technology.

[0074] The spam information that is incorrectly marked in the mobile information uploaded by the client specifically refers to the situation where a user who subscribes to the spam processing function finds that some non-spam information, i.e., normal information, is incorrectly marked as spam information during the process of applying spam filtering rules. At this time, the user can feedback the existence of this phenomenon to the processing module 2013 through the client.

[0075] Spam captured using honeypot technology specifically refers to the monitoring of user data that has subscribed to the spam processing function by the processing module 2013 in a preset manner. The preset method involved is setting up honeypot technology, which is an active defense technology that actively exposes some vulnerabilities and sets some bait to lure attackers to attack, thereby capturing and analyzing data suspected of spam. This involves the data collection / generation stage of the entire data life cycle.

[0076] After receiving spam information requiring identification, processing module 2013 securely transmits it to monitoring module 2014 via a secure interface. After the transmission is complete, the spam information is deleted. Deletion involves clearing the storage space for the spam information and overwriting it with new data. This deletion aims to remove useless spam information requiring identification, thereby avoiding excessive storage space usage and increasing data leakage points.

[0077] The monitoring module 2014 is used to identify spam information that needs to be identified, and to record and monitor the identification process of the spam information that needs to be identified, and the identification process uses a ciphertext identification method.

[0078] Specifically, the monitoring module 2014 is a functional module in the spam information processing device for protecting personal privacy, and is mainly used to identify spam information that needs to be identified, and to record and monitor the identification process of the spam information that needs to be identified.

[0079] The spam messages that require identification are securely transmitted from the processing module 2013 to the monitoring module 2014 via a secure interface. After receiving the spam messages, the monitoring module 2014 performs identification on them. This identification primarily involves manual verification, which checks whether the spam messages that users have reported as incorrectly marked are legitimate. The identification results can be either: if they are legitimate, they are placed in a spam database; if they are legitimate, no processing is performed.

[0080] During the authentication process, the authentication method used is ciphertext authentication. Ciphertext authentication involves encrypting the information to be authenticated, converting it into encrypted data, and then comparing and identifying it using the encrypted data. Ciphertext authentication can use data fingerprints or digest values ​​for comparison, or it can be performed in pure ciphertext form. Authentication results include suspected spam and non-suspected spam. Suspected spam can be blocked or flagged and sent to the management module 2012, while non-suspected spam can be sent directly to the management module 2012.

[0081] The privacy-protecting spam processing device provided in this embodiment is applied on a server. It includes a reporting module 2011, a management module 2012, a processing module 2013, and a monitoring module 2014. The reporting module 2011 is configured to classify and categorize data. The management module 2012 is used to securely store and share data. The processing module 2013 and the monitoring module 2014 respectively filter and identify spam. These modules work together to provide users with spam filtering capabilities. At the same time, the privacy-protecting spam processing device protects data privacy, reducing data leaks and information security issues.

[0082] In one possible implementation, the processing module 2013 in the spam processing device for protecting personal privacy provided by the present application is further configured to detect the spam to be identified before transmitting the spam to be identified to the monitoring module 2014, and obtain a detection result, wherein the detection result is used to indicate whether there is a virus in the spam to be identified.

[0083] Specifically, before transmitting the spam information to be identified to the monitoring module 2014 , the processing module 2013 needs to perform a detection operation on the spam information to be identified.

[0084] The purpose of the detection operation is to indicate whether viruses are present in the spam information to be identified. The types of data detected are executable files and links. Detection methods include manual detection, behavior monitoring, feature detection, sandbox detection, etc. There are two types of detection results. One is that there are no problems with the spam information data to be identified. In this case, the processing module 2013 will securely transmit this part of the data without any problems to the monitoring module 2014. The other is that the spam information data to be identified includes suspected malicious data, such as viruses, Trojans, etc. In this case, the processing module 2013 will delete this part of the spam information data that contains malicious data and no longer transmit it to the monitoring module 2014, thereby preventing viruses from invading the spam information processing device.

[0085] The spam processing device for protecting personal privacy provided in this embodiment primarily illustrates how the server-side processing module must perform a detection operation on spam information before transmitting it to the monitoring module. This detection operation can filter out malicious data and prevent viruses contained in malicious data from invading the spam processing device, thereby effectively protecting user privacy and improving information security.

[0086] In a possible implementation, the reporting module 2011 in the apparatus for processing spam for protecting personal privacy provided by this application is further configured to notify the client of data sharing information, where the data sharing information indicates data to be shared with a third party.

[0087] Specifically, the reporting module 2011 is further used to notify the client of data sharing information.

[0088] Among them, the client specifically refers to the client that has subscribed to the spam processing function. The third party refers to the business partners, security management departments, etc. that cooperate with the operator. The purpose of sharing is to jointly improve the spam filtering rules. When the reporting module 2011 wants to share some data information with a third party, it needs to inform the user who has subscribed to the spam processing function in advance. After obtaining the user's permission, the corresponding data information can be shared with the third party. The content of informing the user in advance mainly includes the specific data information shared with the third party and the specific purpose of this data. At the same time, these data need to be encrypted before being shared with the third party. The specific encryption method can be MD5 encryption, SHA1 encryption, 3DES encryption, AES encryption, RC4 encryption and RC5 encryption, etc. In the specific application process, at least one of them can be selected for data encryption.

[0089] This embodiment provides a privacy-protecting spam processing device. The main purpose is to ensure that a server-side service module, before sharing data with a third party, must notify the user in advance through the client. Only after obtaining the user's consent can the data be securely transmitted to the third party. Informing the user in advance of the specific content and functions of the data to be shared with the third party, and then sharing after obtaining permission, ensures that the user's privacy is not leaked and enhances information security.

[0090] In a possible implementation, the processing module 2013 in the apparatus for processing spam information for protecting personal privacy provided by the present application is further configured to destroy data that is not marked as spam information.

[0091] Specifically, the processing module 2013 is further configured to destroy data that is not marked as spam.

[0092] In the process of applying filtering rules to filter spam for users who subscribe to the spam processing function, the processing module 2013 may determine that some information is not spam, ie, normal information. The processing module 2013 will destroy this normal information data in a timely manner.

[0093] The processing module 2013 destroys the non-junk information data by deleting it, such as deleting the non-junk information data storage space or overwriting other data, etc. The purpose of destruction is to reduce data leakage points.

[0094] This embodiment provides a spam processing device for protecting personal privacy, primarily illustrating the server-side processing module 2013's ability to promptly destroy data not marked as spam. This timely destruction of data not marked as spam by processing module 2013 alleviates data storage space pressure, reduces data leakage points, and enhances the protection of users' personal privacy.

[0095] In a possible implementation, the monitoring module 2014 in the apparatus for processing spam information for protecting personal privacy provided by the present application is further configured to delete the user personal data contained in the spam information to be identified before identifying the spam information to be identified.

[0096] Specifically, before identifying the spam information to be identified, the monitoring module 2014 needs to delete the user's personal data contained in the spam information to be identified.

[0097] The spam messages that require identification are detected by processing module 2013 and then transmitted to monitoring module 2014 via a secure interface. Upon receiving this spam, monitoring module 2014 first deletes the user's personal data contained in the spam messages. This personal data includes names, phone numbers, home addresses, and ID numbers. This deletion is done by deleting data storage space or overwriting other data. Furthermore, before deleting the spam messages that require identification, processing module 2013 performs encryption on the data. Specific encryption operations include MD5, SHA1, 3DES, AES, RC4, and RC5. This involves the entire data processing phase of the data lifecycle.

[0098] This embodiment provides a spam processing device that protects personal privacy. The monitoring module deployed on the server side provides a function for deleting user personal data from spam messages before identifying the spam. This user personal data primarily involves the user's personal privacy. Deleting this data before identification can protect the user's privacy to a certain extent and prevent privacy data leaks.

[0099] In a possible implementation, the management module 2012 in the spam information processing apparatus for protecting personal privacy provided by the present application is further configured to encrypt data that needs to be shared with the management modules of other organizations.

[0100] Specifically, the management module 2012 is further used to encrypt data that needs to be shared with management modules of other organizations.

[0101] Here, "other organizations" specifically refers to other operators. Other operators have also deployed similar spam processing devices, and their spam processing devices also include management modules that provide similar functions to the management module. For example, the spam processing device deployed by operator A includes management module 1, while the spam processing device deployed by operator B, which is different from operator A, includes management module 2. In this case, operator A's management module 1 wants to share data with operator B's management module 2. Operator A needs to perform encryption operations on the data to be shared. Specific encryption methods include MD5 encryption, SHA1 encryption, 3DES encryption, AES encryption, RC4 encryption, and RC5 encryption, which involve the data processing stage of the entire data lifecycle. The specific data encryption method to be applied can be determined based on actual conditions.

[0102] The data shared mainly includes spam blacklists, spam feature libraries, spam libraries, etc. If the data to be transmitted is related to users who have subscribed to the spam processing function, it must be encrypted and shared only after the user's consent in advance.

[0103] This embodiment provides a privacy-protecting spam processing device. The server-side management module encrypts data before sharing it with other management modules. Encrypted data is less susceptible to capture and tampering during transmission, effectively protecting user privacy and ensuring data security.

[0104] In one possible implementation, the reporting module 2011, management module 2012, processing module 2013, and monitoring module 2014 in the spam processing device for protecting personal privacy provided by the present application all use a secure interface for data transmission. The secure interface is used to build an end-to-end encrypted channel to protect the confidentiality and integrity of the data.

[0105] Specifically, the reporting module 2011, the management module 2012, the processing module 2013 and the monitoring module 2014 involved in the spam information processing apparatus for protecting personal privacy deployed on the server side all use secure interfaces for data transmission.

[0106] The security interface primarily provides an end-to-end encrypted channel, protecting data confidentiality and integrity. Examples of secure interface methods include the HTTPS protocol. Data confidentiality can be protected by encrypting data transmitted between modules. The encryption algorithms used include one or more of MD5, SHA1, 3DES, AES, RC4, and RC5. Data integrity can also be protected by using a hash algorithm for data transmitted between modules.

[0107] The spam processing device for protecting personal privacy provided in this embodiment primarily utilizes secure interfaces for data transmission between various modules deployed on the server side. Encryption operations are performed on the data transmitted between modules to protect data confidentiality. Furthermore, a hash algorithm is applied to the data transmitted between modules to protect data integrity. This secure interface ensures data protection during transmission, preventing tampering or interception, and enhancing information security.

[0108] Figure 3 is a schematic diagram of a second embodiment of a spam processing device for protecting personal privacy provided by this application. As shown in Figure 3, a spam processing device for protecting personal privacy deployed on a client 301 is provided.

[0109] The spam information processing device for protecting personal privacy deployed in the client 301 includes two modules: a data receiving module 3011 and a data reporting module 3012 .

[0110] The following is a detailed introduction to the functions of the two modules.

[0111] The data receiving module 3011 is used to receive movement information.

[0112] Specifically, the data receiving module 3011 is a functional module deployed in the spam information processing device for protecting personal privacy in the client, and the main function of the module is to receive mobile information.

[0113] Among them, mobile information includes four parts. The first part refers to non-spam information, that is, normal information, such as text messages sent by relatives and friends, and phone calls made.

[0114] The second part refers to spam, such as spam text messages and spam calls. Spam text messages are short messages sent to users without their consent that they do not want to receive, or short messages that users cannot choose to refuse to receive. It mainly includes the following two attributes. The first part is commercial and advertising short messages sent to users without their consent. The second part is short messages that violate industry self-regulatory regulations. Spam calls are calls made to users without their consent that they do not want to receive, or calls that users cannot choose to refuse to receive.

[0115] The third part refers to spam that has not been marked or filtered. That is, after applying the spam filtering rules provided by the spam processing device that protects personal privacy, this part of information is not identified as spam and is mistakenly identified as non-spam, that is, normal information.

[0116] The fourth part refers to spam that is incorrectly marked, that is, this part of information is incorrectly identified as spam after applying the spam filtering rules provided by the spam processing device that protects personal privacy.

[0117] The data reporting module 3012 is used to upload the unmarked or unfiltered junk information in the mobile information and the incorrectly marked junk information in the mobile information to the server.

[0118] Specifically, the data reporting module 3012 is another functional module deployed in the spam processing device for protecting personal privacy in the client. The main function of this module is to upload spam that is not marked or filtered in mobile information and spam that is incorrectly marked in mobile information to the server.

[0119] The data reporting module 3012 mainly encrypts the unmarked or unfiltered junk information in the mobile information in the data receiving module 3011 and the junk information marked incorrectly in the mobile information and uploads them to the server.

[0120] Unmarked or unfiltered spam in mobile information refers to information that is actually spam, but after applying spam filtering rules, it is not filtered out by the spam filtering rules, that is, it is not marked as spam. In this case, the user will receive this information. Once the user confirms that it is not legitimate information, the data reporting module 3012 in the client can encrypt this portion of mobile information that has not been marked or filtered, and then upload it to the data reporting module on the server for subsequent processing.

[0121] Mistakenly marked spam in mobile information refers to information that is actually legitimate, but after applying spam filtering rules, this legitimate information is mistakenly marked as spam, and the user is unable to receive this legitimate information. Once the user confirms that the information is legitimate, the client's data reporting module 3012 encrypts the mislabeled spam information in the mobile information and uploads it to the server's data processing module for subsequent processing.

[0122] This embodiment provides a spam processing device for protecting personal privacy, which is applied to a client. The device includes a data receiving module and a data reporting module. The data receiving module filters information data according to filtering rules configured on the server, obtaining normal information and marked spam. The data reporting module securely transmits encrypted spam data via a secure interface. This device can accurately filter spam, increase user satisfaction, and enhance the protection of user privacy data.

[0123] The following uses the client and server collaboratively processing spam as a specific application scenario to provide a specific example to explain in detail the spam processing system that protects personal privacy. Figure 4 is a schematic diagram of a spam processing system that protects personal privacy provided by this application. As shown in Figure 4, the spam processing system that protects personal privacy provided by this application includes: a server 201 and a client 301 in at least one terminal device. The server 201 is used to execute the technical solution involved in the server in Figure 2, and the client is used to execute the technical solution involved in the client in Figure 3. Below, in conjunction with this spam processing system that protects personal privacy, a detailed explanation will be given on how to protect users' personal identity information in the process of managing mobile spam.

[0124] After a user subscribes to the spam handling feature, their client 301 installs a designated security application, which primarily provides spam filtering and personal information protection. If the privacy-preserving spam handling system needs to share user data with a third party, the security application will activate a clear notification feature, informing the user of the data being collected and how it will be used. Only after the user's consent is obtained can this data be collected and shared with the third party.

[0125] In actual use, when a text message or phone call is sent or made to a user who has subscribed to the spam handling function, the processing module 2013 in the server 201 applies the spam filtering rules transmitted by the management module to filter the text message or phone call. After filtering, the data receiving module 3011 in the client 301 receives mobile information. The mobile information includes non-spam messages, spam messages, spam messages that have not been marked or filtered among non-spam messages, and spam messages that have been incorrectly marked. If the user does not want to receive spam messages, they can cancel the spam reception service through the client 301.

[0126] The non-spam messages received by the data receiving module in client 301 are text messages or phone calls that pass the filtering rules. In this case, the user can receive the text messages or answer the phone calls normally. The spam messages received by the data receiving module in client 301 are text messages or phone calls that do not pass the filtering rules. In this case, the user can choose whether to receive or not receive these spam messages according to actual needs. The spam messages that are not marked or filtered among the non-spam messages received by the data receiving module in client 301 are spam messages that have not been identified by the spam filtering rules. The spam messages that are incorrectly marked and received by the data receiving module in client 301 are normal messages that have been mistakenly identified as spam by the spam filtering rules.

[0127] After receiving the mobile information, if the user discovers that the mobile information contains unmarked or unfiltered information, i.e., spam, the data reporting module 3012 of the client 301 can encrypt this data and securely transmit it to the reporting module 2011 of the server 201 via a secure interface. If the user discovers that the mobile information contains incorrectly marked spam, i.e., normal information, the data reporting module 3012 of the client 301 can also encrypt this data and securely transmit it to the processing module 2013 of the server 201 via a secure interface. Encryption methods include MD5, SHA1, 3DES, AES, RC4, and RC5.

[0128] After receiving data transmitted by the data reporting module 3012 of the client 301, the reporting module 2011 in the server 201 first applies a data monitoring function to the received data to determine whether the data is illegal. If it is illegal, the reporting module 2011 promptly deletes it. If it is not illegal, the reporting module 2011 confirms whether the unmarked or unfiltered information in the mobile information transmitted by the data reporting module 3012 is junk information. If it is junk information, the characteristics of this junk information data are extracted. After the monitoring and confirmation operations are completed, the reporting module 2011 classifies and processes the data according to different data types and securely stores the processed data. Finally, the reporting module 2011 securely transmits information such as the junk information characteristics to the management module 2012 via a secure interface.

[0129] After receiving the spam characteristics transmitted by the reporting module 2011 of the server 201, the management module 2012 of the server 201 promptly updates the spam filtering rule model, generates new spam filtering rules, and transmits them to the processing module 2013 in real time. Furthermore, the management module 2012 receives mobile information from carrier partners, security management departments, and other organizations, and encrypts the unencrypted data in these mobile information. The mobile information transmitted by carrier partners, security management departments, and other organizations primarily consists of spam data characteristics, which are used to refine the spam filtering rule model and provide better spam processing capabilities for users. If the privacy-protecting spam processing system wishes to share spam data with carrier partners, it must notify the user through the explicit notification function in the reporting module 2011. Only after obtaining the user's consent can the privacy-protecting spam processing system share the spam data with carrier partners. Furthermore, if the privacy-protecting spam processing system wishes to share spam data characteristics and other content with the management modules of other organizations, it must first encrypt the data to be shared to ensure the security of the data transmission process.

[0130] After the management module 2012 formulates and updates spam filtering rules based on spam features transmitted by the reporting module 2011 and a third party, it securely transmits the formulated spam filtering rules to the processing module 2013 via a secure interface in real time.

[0131] After receiving the spam filtering rules transmitted in real time by the management module 2012 of the server 201, the processing module 2013 of the server 201 uses the latest spam filtering rules to filter user mobile information. It also records data identified as spam and logs it, while promptly destroying non-spam data. Furthermore, the processing module 2013 of the server 201 also employs honeypot-like technology, primarily to monitor data from users who have subscribed to the spam processing function and obtain data suspected of spam.

[0132] At this point, the spam received by processing module 2013 of server 201 primarily consists of two parts: the first part is the incorrectly marked spam data in the mobile information transmitted via the secure interface by data reporting module 3012 of client 301; the second part is the suspected spam data captured by processing module 2013 using honeypot technology. These two parts of data must be securely transmitted via the secure interface to monitoring module 2014 for identification. Prior to identification, processing module 2013 must also perform detection operations on these two parts of data, deleting any malicious data, etc.

[0133] After receiving the two pieces of data from the processing module 2013, the monitoring module 2014 of the server 201 first removes the information containing the user's personal data from the data and then applies a ciphertext authentication method to authenticate the data after the personal data has been deleted. The monitoring module 2014 monitors the entire authentication process to ensure data security.

[0134] After the monitoring module 2014 on the server side 201 authenticates the encrypted data, it analyzes the authentication results and securely transmits the analysis results to the management module 2012 on the server side 201 via a secure interface. The analysis results include the amount and characteristics of spam messages, as well as new spam patterns.

[0135] After receiving the analysis results transmitted by the monitoring module 2014 , the management module 2012 of the server 201 updates the spam processing and filtering rules and transmits them to the processing module 2013 in real time and securely.

[0136] If a user cancels the subscription to the spam information processing function, the reporting module 2011 , the management module 2012 , the processing module 2013 and the monitoring module 2014 of the server 201 will safely delete all data associated with the user.

[0137] The spam processing system for protecting personal privacy provided in this embodiment includes a server and a client in at least one terminal device. Four modules provided in the server and two modules provided in the client frequently transmit and interact with encrypted data, and spam filtering rules are updated in real time. This improves spam detection rates and reduces the leakage of user privacy data, thereby creating a healthy and orderly mobile communication environment for users.

[0138] An embodiment of the present application provides a computer storage medium, wherein the computer storage medium stores a computer program. When the computer program is executed by a processor, it is used to implement the module functions in the device of any one of the aforementioned embodiments.

[0139] An embodiment of the present application provides a chip, which includes a memory and a processor. The memory stores code and data. The memory is coupled to the processor. The processor runs the program in the memory so that the chip is used to execute the module function in the device of any of the aforementioned embodiments.

[0140] An embodiment of the present application provides a program product, including: a computer program, which, when the program product is run on a computer, enables the computer to execute the module functions in the device of any one of the aforementioned embodiments.

[0141] An embodiment of the present application provides a computer program, which, when executed by a processor, is used to execute the module functions in the device of any one of the aforementioned embodiments.

[0142] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all optional embodiments, and the actions and modules involved are not necessarily required by this application.

[0143] It should be further noted that, although the various steps in the flowchart are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps may be performed in other orders. Moreover, at least a portion of the steps in the flowchart may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily performed at the same time, but may be performed at different times. The execution order of these sub-steps or stages is not necessarily to be performed in sequence, but may be performed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.

[0144] It should be understood that the above-described device embodiments are merely illustrative, and the device of the present application may also be implemented in other ways. For example, the division of units / modules in the above-described embodiments is merely a logical functional division, and actual implementations may employ other division methods. For example, multiple units, modules, or components may be combined or integrated into another system, or some features may be omitted or not implemented.

[0145] In addition, unless otherwise specified, the functional units / modules in the various embodiments of the present application may be integrated into a single unit / module, each unit / module may exist physically separately, or two or more units / modules may be integrated together. The aforementioned integrated units / modules may be implemented in the form of hardware or software program modules.

[0146] If the integrated unit / module is implemented in hardware, the hardware may be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor may be any appropriate hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC. Unless otherwise specified, the storage unit may be any appropriate magnetic storage medium or magneto-optical storage medium, such as resistive random access memory (RRAM), dynamic random access memory (DRAM), static random access memory (SRAM), enhanced dynamic random access memory (EDRAM), high-bandwidth memory (HBM), hybrid memory cube (HMC), etc.

[0147] If the integrated unit / module is implemented in the form of a software program module and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a memory and includes a number of instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned memory includes various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0148] In the above embodiments, the description of each embodiment has its own emphasis. For parts not described in detail in a particular embodiment, please refer to the relevant description of other embodiments. The technical features of the above embodiments can be combined in any way. To keep the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0149] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.

[0150] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

Claims

1. A junk information processing device for protecting personal privacy, characterized in that, including: a reporting module, a management module, a processing module, and a monitoring module; wherein, the reporting module is used to perform hierarchical classification processing on data according to data types and importance characteristics, and the data is junk information in the mobile information uploaded by the client that has not been marked or filtered; the management module is used to encrypt and securely store subscriber data, and cancel the filtering service based on the needs of the subscriber; the processing module is used to monitor malicious behaviors, and record and form log data for the data determined as junk information using filtering rules; the processing module is further used to transmit the junk information to be identified to the monitoring module, and delete the junk information to be identified after transmission, wherein the junk information to be identified includes the junk information mislabeled in the mobile information uploaded by the client received by the processing module, and the junk information captured using the honeypot technology; the monitoring module is used to identify the junk information to be identified, record and monitor the identification process of the junk information to be identified, and the identification process uses a ciphertext identification method.

2. The device according to claim 1, wherein the processing module is further used to detect the junk information to be identified before transmitting it to the monitoring module, and obtain a detection result, wherein the detection result is used to indicate whether there is a virus in the junk information to be identified.

3. The device according to claim 1, characterized in that the reporting module is further used to notify the client of data sharing information, and the data sharing information is used to indicate the data to be shared with a third party.

4. The device according to claim 1 or 2, characterized in that, the processing module is further used to destroy the data not marked as junk information.

5. The device according to claim 1, characterized in that, the monitoring module is further used to delete the user personal data included in the junk information to be identified before identifying the junk information to be identified.

6. The device according to claim 1, characterized in that, the management module is further used to encrypt the data that needs to be shared with the management module of other organizations.

7. The device according to claim 1 or 2, characterized in that, a secure interface is used for data transmission between the reporting module, the management module, the processing module, and the monitoring module, and the secure interface is used to construct an end-to-end encrypted channel to protect the confidentiality and integrity of the data.

8. A spam information processing device for protecting personal privacy, characterized in that, including: a data receiving module and a data reporting module; the data receiving module is used to receive mobile information; the data reporting module is used to upload the junk information in the mobile information that has not been marked or filtered and the junk information mislabeled in the mobile information to the server.

9. A spam information processing system for protecting personal privacy, characterized in that, including: a server and a client in at least one terminal device; wherein, the server is provided with the junk information processing device for protecting personal privacy according to any one of claims 1 to 7, and the client is provided with the junk information processing device for protecting personal privacy according to claim 8.

10. A computer storage medium, characterized in that, a computer program is stored in the computer storage medium, and when the computer program is run by a processor, it realizes the functions in the junk information processing device for protecting personal privacy according to any one of claims 1 to 8.

11. A chip, characterized in that, The chip includes a memory and a processor. Code and data are stored in the memory. The memory is coupled to the processor. The processor runs the program in the memory so that the chip is used to execute the functions in the junk information processing device for protecting personal privacy according to any one of claims 1 to 8 above.

12. A program product, characterized in that, Comprising: A computer program which, when the program product runs on a computer, causes the computer to execute the functions in the junk information processing device for protecting personal privacy according to any one of claims 1 to 8 above.

13. A computer program, characterized in that, When the computer program is executed by a processor, it is used to execute the functions in the junk information processing device for protecting personal privacy according to any one of claims 1 to 8 above.

Citation Information

Patent Citations

  • Method and device for determining garbage information

    CN106878994A

  • Junk short message identification method and system based on differential privacy joint learning

    CN110955778A

  • Junk information clearing system and device based on communication big data

    CN115065972A

  • Junk information processing device and system capable of protecting personal privacy and medium

    CN117081807A

  • Junk information processing device and system capable of protecting personal privacy and medium

    CN117749517A