Usage control method for data standard semantic transformation oriented to data privacy protection
By employing technologies such as data anonymization, encrypted storage and transmission, privacy computing, and access control, the system addresses data privacy protection and usage control issues in multi-party data sharing scenarios, achieving data privacy protection and compliance support, and meeting GDPR requirements.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- SHANGHAI JINRON DIGITS TECHNOLOGY CO LTD
- Filing Date
- 2025-03-07
- Publication Date
- 2026-07-23
AI Technical Summary
In multi-party data sharing scenarios, how can we ensure data privacy protection and usage control, and meet the requirements of regulations such as GDPR regarding data sovereignty and transparency of use?
By employing data anonymization processing, encrypted storage and transmission, privacy computing technology, access control and management, data standard semantic transformation, and regulatory compliance and risk assessment, combined with technologies such as RDF, OWL, ODRL, SHACL, SPARQL, AES, RSA, DES, blockchain, and smart contracts, data privacy protection and compliance support are achieved.
It achieves strong privacy protection and compliance support in the process of data sharing and use, ensures the data provider's sovereignty over the data and the transparency of the use process, and implements strict control through encryption technology and distributed identity management. It also uses smart contracts to track access and permission changes, meeting GDPR regulatory requirements.
Smart Images

Figure CN2025081224_23072026_PF_FP_ABST
Abstract
Description
A use control method for data standard semantic conversion oriented to data privacy protection TECHNICAL FIELD
[0001] The present application relates to the technical field of standard semantic conversion and dynamic use control in a data privacy protection environment, in particular to a use control method for data standard semantic conversion oriented to data privacy protection. BACKGROUND
[0002] Data semanticization is a way of converting data into a readable and understandable form to facilitate better understanding and analysis of data. TECHNICAL PROBLEM
[0003] In the multi-party data sharing scenario, the data privacy protection and use control problem is difficult to ensure the privacy and security of data in the sharing process, while meeting the requirements of GDPR and other regulations on data sovereignty and use transparency; therefore, there is an urgent need in the market to develop a use control method for data standard semantic conversion oriented to data privacy protection to help people solve existing problems. TECHNICAL SOLUTION
[0004] The purpose of the present application is to provide a use control method for data standard semantic conversion oriented to data privacy protection to solve the data privacy protection and use control problem in the multi-party data sharing scenario as proposed in the background art, to ensure the privacy and security of data in the sharing process, and to meet the requirements of GDPR and other regulations on data sovereignty and use transparency.
[0005] To achieve the above purpose, the present application provides the following technical solution: a use control method for data standard semantic conversion oriented to data privacy protection, comprising the following steps:
[0006] S1: data desensitization processing;
[0007] S2: encrypted storage and transmission;
[0008] S3: application of privacy computing technology;
[0009] S4: permission control and access management;
[0010] S5: data standard semantic conversion;
[0011] S6: regulation compliance and risk assessment;
[0012] The S1 includes a privacy semantic model construction, defines a data privacy related ontology and semantic rule, adopts a semantic technical standard including but not limited to RDF and OWL, the S2 includes dynamic use control, realizes policy-based dynamic use control in combination with ODRL and SHACL, the S3 includes privacy compliance verification, and the verification and query of a data privacy policy are realized by using SHACL and SPARQL.
[0013] By the above technical scheme, standard semantic conversion and dynamic use control in a data privacy protection environment are realized. By combining data sovereignty with semantic web technology, strong privacy protection and compliance support are provided for data in the sharing and use process. The system adopts semantic technical standards such as RDF and OWL, defines data privacy policies by using SHACL, and realizes strict control of data access by using encryption technology and distributed identity management. By using smart contracts and dynamic use policies, the access, use and permission change in the data sharing process are tracked and verified in real time, so as to guarantee the sovereignty of data providers over their data and the transparency of the use process
[0014] In a preferred example, the application can be further configured as: the S4 includes distributed identity and access management, and the identity and access permission management is realized by a distributed system, the S6 includes smart contract and audit, and the traceability and audit of the data use process are realized by using blockchain technology.
[0015] In a preferred example, the application can be further configured as: the S1 includes but is not limited to character replacement, hash encryption and data randomization, and sensitive information in original data is processed so as to be unable to be directly identified, thereby protecting personal privacy.
[0016] In a preferred example, the application can be further configured as: the S2 includes but is not limited to AES, RSA and DES, and sensitive data is stored by encryption, so as to ensure the security of data in the storage and transmission process.
[0017] In a preferred example, the application can be further configured as: the S3 includes but is not limited to secure multi-party computation based on protocol rules, federated learning based on modern cryptography and trusted execution environment technology based on hardware closed loop, and data calculation and analysis are realized without leaking original data, thereby protecting data privacy.
[0018] In a preferred example, the application can be further configured as: the S4 includes role-based access control (RBAC) and attribute-based access control (ABAC), and the access permission of users to data is dynamically controlled by defining the permission or access strategy of different roles, thereby protecting data privacy.
[0019] In a preferred embodiment, the present invention can be further configured such that: in step S5, natural language processing and machine learning techniques are used to analyze and transform the semantics of the data, ensuring that the data can be accurately and effectively understood and used while protecting privacy.
[0020] In a preferred embodiment, the present invention can be further configured such that: in the entire data privacy protection process, the GDPR-related regulatory requirements must be strictly followed in S6, and a privacy risk assessment needs to be conducted to identify and reduce the privacy risks faced when processing personal information. Beneficial effects
[0021] Compared with the prior art, the beneficial effects of the present invention are:
[0022] This invention achieves standard semantic transformation and dynamic usage control within a data privacy-preserving environment. By combining data sovereignty with Semantic Web technology, it provides robust privacy protection and compliance support for data sharing and use. The system adopts semantic technology standards such as RDF and OWL, combined with SHACL to define data privacy policies, and implements strict control over data access through encryption technology and distributed identity management. Utilizing smart contracts and dynamic usage policies, it tracks and verifies access, use, and permission changes in real time during data sharing, thereby ensuring the data provider's sovereignty over its data and the transparency of its usage process. Attached Figure Description
[0023] Figure 1 is a flowchart of a data standard semantic transformation usage control method for data privacy protection according to this utility model. Embodiments of the present invention
[0024] The technical solutions in the embodiments of the present invention will be clearly and completely described. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.
[0025] One embodiment of the present invention: Referring to Figure 1, a method for controlling the use of data standard semantic transformation for data privacy protection includes the following steps:
[0026] S1: Data anonymization processing;
[0027] S2: Encrypted storage and transmission;
[0028] S3: Applications of privacy-preserving computing technology;
[0029] S4: Access Control and Management;
[0030] S5: Data standard semantic conversion;
[0031] S6: Regulatory Compliance and Risk Assessment;
[0032] S1 includes the construction of a privacy semantic model, defining the ontology and semantic rules related to data privacy, and adopting semantic technology standards including but not limited to RDF and OWL. S2 includes dynamic usage control, which combines ODRL and SHACL to implement policy-based dynamic usage control. S3 includes privacy compliance verification, which uses SHACL and SPARQL to verify and query data privacy policies.
[0033] S4 includes distributed identity and access management, which manages identity and access permissions through a distributed system. S6 includes smart contracts and auditing, which uses blockchain technology to achieve traceability and auditing of data usage.
[0034] S1 includes, but is not limited to, character replacement, hash encryption, and data randomization. It processes sensitive information in the original data to make it unrecognizable, thereby protecting personal privacy.
[0035] S2 includes, but is not limited to, AES, RSA, and DES, which encrypt and store sensitive data to ensure data security during storage and transmission.
[0036] S3 includes, but is not limited to, secure multi-party computation based on protocol rules, federated learning based on modern cryptography, and trusted execution environment technology based on hardware closed loops, which enable data computation and analysis without disclosing the original data, thereby protecting data privacy.
[0037] S4 includes Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC), which dynamically control users' access permissions to data by defining different roles or access policies, thereby protecting data privacy.
[0038] S5 utilizes natural language processing and machine learning technologies to analyze and transform the semantics of data, ensuring that data can be accurately and effectively understood and used while protecting privacy.
[0039] Throughout the entire data privacy protection process in S6, GDPR-related regulations must be strictly followed. At the same time, a privacy risk assessment is required to identify and mitigate the privacy risks faced when processing personal information.
[0040] Working Principle: First, clarify the goals and principles of data privacy protection, determine the types of data requiring protection, their sensitivity, and specific privacy protection requirements, and comply with relevant laws and regulations, such as GDPR, to ensure the legality and compliance of data processing activities.1 Second, classify and categorize the data, comprehensively reviewing it and classifying it according to its sensitivity and importance. Set corresponding security levels and access permissions for different categories of data to ensure hierarchical data management.2 Next, select and apply privacy protection technologies. Based on the data classification and categorization results, select appropriate privacy protection technologies, such as data anonymization, encryption, and privacy computing. Data anonymization can delete or replace sensitive information in the data, making it unidentifiable; encryption technology can encrypt the data to ensure its security during transmission and storage; privacy computing technology can perform data analysis and processing without exposing the original data.13 Finally, design and implement access control policies, formulating strict... Access control mechanisms should be established to restrict access to data. Identity verification and access control should be implemented to ensure that only authorized users can access sensitive data. An auditing and monitoring mechanism should be established to record data access and usage, and to promptly detect and handle abnormal behavior.2 Furthermore, the construction of a data security management system should be strengthened. A comprehensive data security management system should be developed, data security responsibilities should be clearly defined, data security training should be enhanced to improve employees' data security awareness and skills, and regular data security risk assessments and audits should be conducted to promptly identify and rectify security vulnerabilities.5 At the same time, attention should be paid to the dynamic development of data privacy protection, closely monitoring the development trends of privacy protection technologies and changes in laws and regulations, and updating and adjusting privacy protection measures in a timely manner to adapt to the new technological environment and legal requirements.6 Finally, an emergency response mechanism should be established, and emergency response plans for security incidents such as data breaches should be developed. Once a security incident occurs, the emergency response mechanism should be activated immediately, measures should be taken quickly to control the situation, and reports and handling should be carried out in accordance with regulations.
[0041] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.
Claims
1. A method for controlling the use of data standard semantic transformation for data privacy protection, characterized in that, Includes the following steps: S1: Data anonymization processing; S2: Encrypted storage and transmission; S3: Applications of privacy-preserving computing technology; S4: Access Control and Management; S5: Data standard semantic conversion; S6: Regulatory Compliance and Risk Assessment; S1 includes the construction of a privacy semantic model, defining data privacy-related ontology and semantic rules, and adopting semantic technology standards including but not limited to RDF and OWL. S2 includes dynamic usage control, combining ODRL and SHACL to achieve policy-based dynamic usage control. S3 includes privacy compliance verification, using SHACL and SPARQL to verify and query data privacy policies.
2. The method for controlling the use of data standard semantic transformation for data privacy protection according to claim 1, characterized in that: S4 includes distributed identity and access management, which manages identity and access permissions through a distributed system. S6 includes smart contracts and auditing, which utilizes blockchain technology to achieve traceability and auditing of the data usage process.
3. The method for controlling the use of data standard semantic transformation for data privacy protection according to claim 1, characterized in that: The S1 process includes, but is not limited to, character replacement, hash encryption, and data randomization. These processes handle sensitive information in the original data, making it impossible to directly identify and thus protecting personal privacy.
4. The method for controlling the use of data standard semantic transformation for data privacy protection according to claim 1, characterized in that: The S2 includes, but is not limited to, AES, RSA, and DES, which are used to encrypt and store sensitive data to ensure data security during storage and transmission.
5. The method for controlling the use of data standard semantic transformation for data privacy protection according to claim 1, characterized in that: The S3 includes, but is not limited to, secure multi-party computation based on protocol rules, federated learning based on modern cryptography, and trusted execution environment technology based on hardware closed loop, which perform data computation and analysis without disclosing the original data, thereby protecting data privacy.
6. The method for controlling the use of data standard semantic transformation for data privacy protection according to claim 1, characterized in that: S4 includes role-based access control (RBAC) and attribute-based access control (ABAC). By defining permissions or access policies for different roles, it dynamically controls users' access permissions to data, thereby protecting data privacy.
7. The method for controlling the use of data standard semantic transformation for data privacy protection according to claim 1, characterized in that: In S5, natural language processing and machine learning technologies are used to analyze and transform the semantics of the data, ensuring that the data can be accurately and effectively understood and used while protecting privacy.
8. The method for controlling the use of data standard semantic transformation for data privacy protection according to claim 1, characterized in that: In the S6 process, GDPR requirements must be strictly followed throughout the entire data privacy protection process. At the same time, a privacy risk assessment is required to identify and reduce the privacy risks faced when processing personal information.