IP Library Granted Patent US 11,669,632
Granted Patent B2
US 11,669,632 · App. 17/585,442 · Granted Jun 6, 2023

Method and apparatus for control of data access

Inventors: Jianqing Zhang (Los Angeles, CA); Zhengqin Luo (Los Angeles, CA); Xingxiu Chen (Beijing, CN); Zhipeng Tian (Culver City, CA); Hengming Dai (Culver City, CA)
Assignee: BEIJING BYTEDANCE NETWORK TECHNOLOGY CO., LTD.
G06F21/6227G06F21/62G06F21/6245G06F21/60G06F21/6254
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,669,632
App. No.
17/585,442
Granted
Jun 6, 2023
Kind
B2
Abstract

According to examples of the present disclosure, there is provided a method and device for controlling data access. The method comprises: receiving a data query request characterizing that a first user requests target data; obtaining a business data access capability attribute corresponding to the first user and obtaining a business security attribute corresponding to the target data; wherein the business data access capability attribute is used to characterize capability of accessing data in a business environment in the charge of a user based on a business attribute of the user; determining a data query processing policy corresponding to the data query request by invoking a data access security model based on the business data access capability attribute of the first user and the business security attribute of the target data; and processing the target data by invoking the data query processing policy and generating a response message for feedback.

Claims (31)

1. A method for control of data access, characterized in that the method comprises:

receiving a data query request characterizing that a first user requests target data using a query keyword;

obtaining a business data access capability attribute corresponding to the first user and obtaining a first business security attribute corresponding to the target data and a second business security attribute corresponding to the query keyword,

wherein the business data access capability attribute is used to characterize capability of accessing data in a business environment in the charge of a user based on a business attribute of the user, and

each of the first business security attribute and the second business security attribute is used to characterize an identification attribute for classifying data based on business security requirements, and comprises one or more of a public level, an identifiability level, and a time level of data, and wherein the public level indicates a degree of difficulty in obtaining the data, the identifiability level indicates whether the data can identify a user, a natural person, or an entity, and the time level indicates whether the association between user data and a user will become invalid within a threshold time period;

determining a data query processing policy corresponding to the data query request by invoking a data access security model based on the business data access capability attribute of the first user, the first business security attribute of the target data and the second business security attribute of the query keyword; and

processing the target data by invoking the data query processing policy and generating a response message for feedback.

2. The method of claim 1 , characterized in that processing the target data by invoking the data query processing policy and generating a response message for feedback comprises:

when the data query processing policy corresponding to the data query request is an anonymization policy, performing anonymization processing on data to be protected in the target data, and generating a response message for feedback based on the target data processed with the anonymization processing.

3. The method of claim 1 , characterized in that processing the target data by invoking the data query processing policy and generating a response message for feedback comprises:

generating a response message including the target data for feedback based on the target data when the data query processing policy corresponding to the data query request is a data pass-through policy.

4. The method of claim 1 , characterized in that processing the target data by invoking the data query processing policy and generating a response message for feedback comprises:

generating a response message characterizing that the data query request is not allowed for feedback when the data query processing policy corresponding to the data query request is a data isolation policy.

5. The method of claim 1 , characterized in that

determining the data query processing policy corresponding to the data query request by invoking the data access security model based on the business data access capability attribute of the first user, the first business security attribute of the target data and the second business security attribute of the query keyword comprises:

when the business data access capability attribute of the first user identifies that the first user is of a type of limited data access right, the first business security attribute of the target data identifies that the target data is non-public, and the second business security attribute of the query keyword identifies that the keyword is public, invoking the data access security model to determine that the data query processing policy corresponding to the data query request is a data isolation policy, the data isolation policy being used to prevent the first user from querying the target data.

6. The method of claim 1 , characterized in that processing the target data by invoking the data query processing policy and generating the response message for feedback comprises:

processing the target data by invoking the data query processing policy and generating a response message, and configuring an effective time for specified data in the target data included in the response message and feeding back the response message, the effective time being used to indicate a validity period for use of the specified data in business.

7. The method of claim 1 , wherein each of the first business security attribute and the second business security attribute comprises or indicates one or more of a public level, an identifiability level, and a time level of the data.

8. An electronic device, comprising:

a memory and a processor;

wherein the memory is used to store one or more computer instructions which are executed by the processor to

receive a data query request characterizing that a first user requests target data using a query keyword;

obtain a business data access capability attribute corresponding to the first user and obtaining a first business security attribute corresponding to the target data and a second business security attribute corresponding to the query keyword, wherein the business data access capability attribute is used to characterize capability of accessing data in a business environment in the charge of a user based on a business attribute of the user, and each of the first business security attribute and the second business security attribute is used to characterize an identification attribute for classifying data based on business security requirements, and comprises one or more of a public level, an identifiability level, and a time level of data, and wherein the public level indicates a degree of difficulty in obtaining the data, the identifiability level indicates whether the data can identify a user, a natural person, or an entity, and the time level indicates whether the association between user data and a user will become invalid within a threshold time period;

determine a data query processing policy corresponding to the data query request by invoking a data access security model based on the business data access capability attribute of the first user, the first business security attribute of the target data and the second business security attribute of the query keyword; and

process the target data by invoking the data query processing policy and generating a response message for feedback.

9. A computer program product comprising computer readable storage medium storing one or more computer instructions thereon which are executed by a processor to

receive a data query request characterizing that a first user requests target data using a query keyword;

obtain a business data access capability attribute corresponding to the first user and obtaining a first business security attribute corresponding to the target data and a second business security attribute corresponding to the query keyword, wherein the business data access capability attribute is used to characterize capability of accessing data in a business environment in the charge of a user based on a business attribute of the user, and each of the first business security attribute and the second business security attribute is used to characterize an identification attribute for classifying data based on business security requirements, and comprises one or more of a public level, an identifiability level, and a time level of data, and wherein the public level indicates a degree of difficulty in obtaining the data, the identifiability level indicates whether the data can identify a user, a natural person, or an entity, and the time level indicates whether the association between user data and a user will become invalid within a threshold time period;

determine a data query processing policy corresponding to the data query request by invoking a data access security model based on the business data access capability attribute of the first user, the first business security attribute of the target data and the second business security attribute of the query keyword; and

process the target data by invoking the data query processing policy and generating a response message for feedback.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2022
From: CHEN, XINGXIU
To: BEIJING ZITIAO NETWORK TECHNOLOGY CO., LTD.
Reel/Frame 062021/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2022
From: TIAN, ZHIPENG; DAI, HENGMING
To: TIKTOK INC.
Reel/Frame 062021/0454 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2022
From: ZHANG, JIANQING; LUO, ZHENGQIN
To: BYTEDANCE INC.
Reel/Frame 062021/0642 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2022
From: BYTEDANCE INC.
To: BEIJING BYTEDANCE NETWORK TECHNOLOGY CO., LTD.
Reel/Frame 062021/0747 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2022
From: BEIJING ZITIAO NETWORK TECHNOLOGY CO., LTD.
To: BEIJING BYTEDANCE NETWORK TECHNOLOGY CO., LTD.
Reel/Frame 062022/0088 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 8, 2022
From: TIKTOK INC.
To: BEIJING BYTEDANCE NETWORK TECHNOLOGY CO., LTD.
Reel/Frame 062022/0198 →
Priority Claims (1)
CN 202111306878.4 · Nov 5, 2021 · national
Continuity (1)
Related Publication 20230145130A1 · May 11, 2023