WO2024255583A1 - 设备隐私管理方法、装置、电子设备及存储介质 - Google Patents

设备隐私管理方法、装置、电子设备及存储介质 Download PDF

Info

Publication number
WO2024255583A1
WO2024255583A1 PCT/CN2024/095704 CN2024095704W WO2024255583A1 WO 2024255583 A1 WO2024255583 A1 WO 2024255583A1 CN 2024095704 W CN2024095704 W CN 2024095704W WO 2024255583 A1 WO2024255583 A1 WO 2024255583A1
Authority
WO
WIPO (PCT)
Prior art keywords
privacy
score
protection
security
item
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2024/095704
Other languages
English (en)
French (fr)
Inventor
罗康
黎明德
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Shenzhen TCL New Technology Co Ltd
Original Assignee
Shenzhen TCL New Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Shenzhen TCL New Technology Co Ltd filed Critical Shenzhen TCL New Technology Co Ltd
Priority to EP24822535.1A priority Critical patent/EP4730179A1/en
Publication of WO2024255583A1 publication Critical patent/WO2024255583A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/602Providing cryptographic facilities or services
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G06F21/577Assessing vulnerabilities and evaluating computer system security
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • G06F21/6218Protecting access to data via a platform, e.g. using keys or access control rules to a system of files or objects, e.g. local or distributed file system or database
    • G06F21/6245Protecting personal data, e.g. for financial or medical purposes

Definitions

  • the embodiments of the present application relate to the field of computer technology, and specifically to a device privacy management method, apparatus, electronic device and storage medium, wherein the storage medium includes a computer-readable storage medium.
  • the embodiments of the present application provide a device privacy management method, apparatus, electronic device, and storage medium, which can improve the accuracy of product privacy protection measurement results.
  • an embodiment of the present application provides a device privacy management method, including:
  • an embodiment of the present application further provides a device privacy management apparatus, including:
  • a first measurement module used to measure the privacy protection level of the device under test to obtain a first privacy measurement result
  • a second measurement module used to measure the privacy management level of the supplier to which the device under test belongs, to obtain a second privacy measurement result
  • a score generating module configured to generate a privacy protection score of the device under test according to the first privacy measurement result, the second privacy measurement result and a preset score weight;
  • the privacy management module is used to upgrade the privacy protection of the device under test according to the privacy protection score.
  • the first measurement module includes:
  • An acquisition unit used to acquire the privacy security score of the device under test in the privacy protection item
  • a first generating unit configured to generate a first privacy measurement result according to the score sub-weight corresponding to the privacy protection item and the privacy safety score corresponding to the privacy protection item;
  • the privacy protection items include at least one of product compliance risk test items, product privacy and security protection technology test items, product adaptation law test items or product privacy protection requirement test items.
  • the acquisition unit includes:
  • Configuration subunit used to configure compliance risk test cases
  • a testing subunit configured to test the device to be tested according to the compliance risk test case to obtain a compliance risk test result, wherein the compliance risk test result corresponds to a risk level score;
  • the first calculation subunit is used to calculate the average value of the risk level scores corresponding to each compliance risk test case to obtain an average risk level score
  • the first generating subunit is used to use the average risk level score as the privacy security score of the device under test in the product compliance risk test item.
  • the acquisition unit includes:
  • a first determination subunit is used to determine the privacy and security protection technology items supported by the device under test
  • An acquisition subunit is used to acquire a preset mapping relationship set, wherein the preset mapping relationship set includes a mapping relationship between the type, strength, and quantity of preset privacy and security protection technologies and security scores;
  • a third determination subunit is used to determine a security score according to the preset mapping relationship set and the type, strength or quantity of the privacy and security protection technology applied by the privacy and security protection technology item;
  • the second generating subunit is used to use the average security score as the privacy security score of the device under test in the product privacy security protection technology test item.
  • the acquisition unit includes: a region determination subunit, which is used to determine the target region where the device to be tested is to be put online;
  • a baseline determination subunit used to determine a target legal baseline that the target area needs to meet
  • the score determination subunit is used to determine the privacy security score of the device under test according to the actual legal baseline currently satisfied by the device under test and the target legal baseline.
  • the second measurement module includes:
  • a supplier determination unit used to determine the supplier to which the device under test belongs
  • a management level determination unit used to measure the privacy management level of the supplier according to the reference privacy information management system and the privacy maturity model to obtain a privacy management level score
  • a first matching unit configured to match a reference software security development lifecycle with an actual software security development lifecycle of the device under test to obtain a first matching result
  • a second matching unit configured to match the reference R&D privacy protection design process with the actual R&D privacy protection design process of the device under test to obtain a second matching result
  • the second generating unit is used to generate a second privacy measurement result according to the privacy management level score and the developed and designed privacy control score.
  • a protection technology determination unit configured to determine a current privacy protection technology corresponding to the privacy protection item of the device under test if the privacy protection degree score does not meet the score threshold;
  • the privacy management unit is used to upgrade the privacy protection of the device under test according to the updated privacy protection score.
  • the embodiment of the present application also provides an electronic device, the electronic device includes a memory, a processor and a storage device stored in the memory A computer program in a memory and executable on a processor, when the processor executes the computer program, implements the steps in the device privacy management method in the first aspect or implements the steps in the device privacy management method in the third aspect.
  • an embodiment of the present application further provides a storage medium, which includes a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps in the above-mentioned device privacy management method are implemented.
  • the embodiments of the present application further provide a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium.
  • the processor of the computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the method provided in various optional implementations described in the embodiments of the present application.
  • the embodiment of the present application measures the privacy protection level of the device under test to obtain a first privacy measurement result, measures the privacy management level of the supplier to which the device under test belongs to obtain a second privacy measurement result, generates a privacy protection score for the device under test based on the first privacy measurement result and the second privacy measurement result, and upgrades the privacy protection of the device under test based on the privacy protection score.
  • the second privacy measurement result is obtained by measuring the privacy management level of the supplier, and the privacy protection score of the device under test is generated based on the second privacy measurement result and the first privacy measurement result for the privacy of the product itself.
  • the embodiment of the present application enriches the measurement dimension of product privacy protection, improves the accuracy of the product privacy protection measurement result, and facilitates the implementation of privacy and security protection management of the product.
  • FIG1 is a schematic diagram of a scenario of a device privacy management method provided in an embodiment of the present application.
  • FIG2 is a schematic diagram of a process flow of a device privacy management method provided in an embodiment of the present application.
  • FIG3 is a result diagram of various privacy and security protection technical items and their corresponding security scores provided in an embodiment of the present application
  • FIG4 is a schematic diagram of the architecture of device privacy management provided in an embodiment of the present application.
  • FIG5 is another schematic diagram of a device privacy management method provided in an embodiment of the present application.
  • FIG6 is a schematic diagram of the structure of a device privacy management apparatus provided in an embodiment of the present application.
  • FIG. 7 is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application.
  • the embodiments of the present application provide a device privacy management method, apparatus, electronic device and storage medium.
  • the embodiments of the present application provide a device privacy management apparatus suitable for electronic devices, wherein the electronic devices include terminals, wherein the terminals include but are not limited to mobile phones, tablet computers, computers or televisions and other devices.
  • the server 10 obtains configuration parameter information of the device under test 11, and measures the privacy protection level of the device under test 11 according to the configuration parameter information to obtain a first privacy measurement result;
  • the server 10 obtains the supplier information of the device under test, and measures the privacy management level of the supplier to obtain a second privacy measurement result;
  • a privacy protection score is generated according to the first privacy measurement result and the second privacy measurement result, and the privacy protection of the device under test is upgraded according to the privacy protection score.
  • the embodiment of the present application enriches the measurement dimensions of product privacy protection, improves the accuracy of product privacy protection measurement results, and facilitates the implementation of privacy and security protection management of products.
  • FIG 2 is a schematic diagram of the process of the device privacy management method provided by the embodiment of the present application.
  • the specific process of the device privacy management method can be as follows: 101. Measure the privacy protection level of the device to be tested to obtain a first privacy measurement result.
  • the device under test refers to the device that needs to undergo privacy protection assessment, such as equipment that leaves the factory after production, equipment used for research and development testing, or equipment that needs to be tested due to privacy and security issues during the application process.
  • the privacy management level of the supplier refers to the control level of the privacy protection of the supplier, wherein the supplier is the enterprise that develops or produces the device.
  • the privacy protection level of the device can be analyzed from more dimensions. For example, the higher the privacy protection control level of the company, the higher the privacy protection level of the corresponding product will generally be.
  • the privacy protection score is a score for the device in terms of user data privacy protection. The higher the score, the better the privacy protection of the device or product. Conversely, the lower the score, the worse the privacy protection of the device or product.
  • the score weight reflects the proportion of the score corresponding to each privacy measurement result.
  • the score weights of the first privacy measurement result and the second privacy measurement result each account for 50%.
  • the score weight can be flexibly adjusted according to actual needs, and the specific value of the score weight is not limited here.
  • whether the introduction of corresponding equipment is allowed can also be determined based on the privacy protection score. For example, when the privacy protection score of the equipment is low, the introduction of the equipment will be rejected. When the privacy protection score of the equipment reaches the standard, the introduction of the equipment will be allowed.
  • equipment introduction is also called equipment introduction, which refers to the purchase or import of equipment.
  • the first privacy measurement result is a privacy score of the device during the application process. Therefore, by obtaining the privacy security score of the device under test in each privacy protection item, the first privacy measurement result of the device under test can be obtained. That is, optionally, in some embodiments of the present application, the step of "measuring the privacy protection level of the device under test to obtain the first privacy measurement result" includes:
  • the privacy protection items include at least one of product compliance risk test items, product privacy and security protection technology test items, product adaptation law test items or product privacy protection requirement test items.
  • the privacy protection items are several detection items that the device under test mainly targets, and these detection items realize the detection of device privacy security from different dimensions.
  • the dynamic first privacy measurement result of the device during the application process is obtained by comprehensively analyzing the privacy security scores of various detection items.
  • the score weight reflects the score proportion of each privacy protection item. For example, when there are four privacy protection items, the score weight of each privacy protection item can be 25%. The specific value of the score weight can also be flexibly adjusted according to actual needs.
  • the product compliance risk test item is a test for whether the device has compliance risk.
  • a test case can be constructed, and the device can be tested based on the test case to obtain the test result for the compliance risk. That is, optionally, in some embodiments of the present application, if the privacy protection item is a product compliance risk test item, the step of "obtaining the privacy security score of the device to be tested in the privacy protection item" includes:
  • the average risk level score is used as the privacy security score of the device under test in the product compliance risk test item.
  • the compliance risk test case is a test case established for the device under test in terms of product compliance risk testing. Based on the execution of the test case, the risk situation of the device under test in terms of product compliance is obtained. Among them, the compliance risk test case includes the project to be tested and related test files and test input data.
  • Compliance risk test cases can include multiple cases, each of which corresponds to a test result.
  • the test result can be expressed as a score between 0 and 5. Different scores correspond to different risk levels, for example, severe: 0 points; high risk: 1 point; medium risk: 2 points; low risk: 4 points; no risk (pass): 5 points.
  • the privacy security score of the product compliance risk test item for the device can be obtained by combining the compliance risk test results of multiple test cases, for example, (L i represents the test result score of the i-th test case), where N is the number of test cases or items, that is, the privacy security score of the compliance risk test item of the product is represented by the average of the test result scores of multiple compliance risk test cases.
  • the product privacy and security protection technology test item is a test of the privacy and security protection technology configured for the device, and the product privacy and security protection technology of the device can be scored from the perspectives of the type, strength or number of privacy and security protection technologies applied, that is, optionally, in some embodiments of the present application, if the privacy protection item is a product privacy and security protection technology test item, the step of "obtaining the privacy security score of the device under test in the privacy protection item" includes:
  • For each privacy and security protection technology item determine the type, strength, and quantity of privacy and security protection technology applied by the privacy and security protection technology item;
  • the preset mapping relationship set includes a mapping relationship between the type, strength, and quantity of preset privacy and security protection technologies and security scores;
  • the average security score is used as the privacy security score of the device under test in the product privacy security protection technology test item.
  • the security score of each current privacy and security protection technology item can be obtained based on a pre-established mapping relationship between the type, strength, number, and security score of the privacy and security protection technology, and then the privacy and security score of the device under test for the product privacy and security protection technology test item can be obtained based on the average of each security score.
  • the privacy and security score for the product privacy and security protection technology test item can also be obtained by comprehensively analyzing the security scores of multiple privacy and security protection technology items corresponding to the product privacy and security protection technology test item. For example, (L i represents the security score of the i-th privacy and security protection technology item).
  • the product adaptation legal test item is a privacy security test for whether the device meets the legal requirements of the corresponding country or region, for example, whether the laws used by the product meet the privacy security legal baseline of the corresponding region, that is, optionally, in some embodiments of the present application, if the privacy protection item is a product adaptation legal test item, the step of "obtaining the privacy security score of the device to be tested in the privacy protection item" includes:
  • a privacy security score of the device under test is determined according to an actual legal baseline currently satisfied by the device under test and the target legal baseline.
  • the legal baseline is the benchmark corresponding to the law, that is, the legal requirements met by the device.
  • the legal baseline mainly refers to the privacy legal requirements corresponding to the device in terms of privacy law.
  • the privacy security score of the device in the product adaptation legal test items can be obtained. For example, if the privacy law requirements of country A are relatively low or there is no privacy law, but the privacy protection measures taken by the product have exceeded the legal requirements of country A, the score is 5 points; the privacy law requirements of country B are particularly high, but the product has not taken privacy protection measures, then the score is 0 points.
  • the product privacy protection requirement is used as the privacy security score of the device under test for the product type.
  • the mapping relationship includes the mapping relationship between the preset product type and the preset product privacy protection requirement. It can be understood that the mapping relationship can be predefined according to the degree of protection of data privacy requirements of different products.
  • the product privacy protection requirement for smart lighting control, smart curtains, smart range hoods, and Bluetooth temperature and humidity sensors is 1, and the product privacy protection requirement for smart air conditioners, smart refrigerators (without screens), smart washing machines, smart air purifiers, smart fresh air systems, and Bluetooth body fat scales is 2.
  • the product privacy protection requirement for smart sweeping robots (without cameras) and smart refrigerators (with screens) is 3, and the product privacy protection requirement for smart TVs and smart gateways is 4.
  • the product privacy protection requirement for smart door locks, smart cameras, smart doorbells, smart cat eyes, smart sweeping robots (with cameras), smart watches, and smart phones is 5, etc.
  • the second privacy measurement result is a scoring result of the privacy management level of the enterprise that develops or designs the device and the R&D and design process of the enterprise
  • the privacy management level of the enterprise and the scoring results of the R&D and design process of the enterprise reflect the privacy protection of the developed device to a certain extent. For example, if the privacy management level of the enterprise is high, and the scoring result of the R&D and design process is that the design process is more standardized, then the privacy protection and specification of the corresponding developed device will also be higher. Therefore, the evaluation result of the enterprise can be used as a reference for the privacy protection of the corresponding device. That is, optionally, in some embodiments of the present application, the step of "measuring the privacy management level of the supplier to which the device to be tested belongs to obtain a second privacy measurement result" includes:
  • a second privacy measurement result is generated based on the privacy management level score and the developed and designed privacy control score.
  • the matching result reflects the degree of matching, which can be expressed as a percentage or a decimal between 0 and 1. For example, a higher percentage of the first matching result indicates that the two life cycles are relatively close or consistent, and a lower percentage of the first matching result indicates that the similarity between the two life cycles is low; for example, a higher percentage of the second matching result indicates that the privacy protection design process is relatively close or consistent, and conversely, a lower percentage of the second matching result indicates that the two privacy protection design processes are basically different or have low overlap.
  • the degree of matching between the two comparison objects is reflected in the form of percentage.
  • the first matching result and the second matching result can also be calculated by weight ratio to obtain the R&D design privacy control score. For example, the percentages corresponding to the two matching results are multiplied by the weight ratio and then added to obtain the final R&D design privacy control score.
  • the privacy management level score reflects the level of privacy management of the enterprise
  • the R&D and design privacy control score reflects the privacy control score of the enterprise during the development of the device.
  • the software security development life cycle (SSDLC) and the privacy protection design process (PbD, Privacy by Design) have corresponding reference standards.
  • the R&D and design privacy management score of the enterprise is determined by judging whether the enterprise meets the corresponding standards.
  • the device privacy protection score can be analyzed through aspects such as the device R&D life cycle and the privacy protection design process.
  • the company's R&D software security development life cycle (SSDLC) level can be analyzed.
  • the company’s R&D privacy protection design process (PbD) level is evaluated to obtain a privacy design process evaluation score.
  • the static measurement module A includes the company internal control measurement part a1 and the R&D management and control measurement part a2, each accounting for 50%.
  • the company internal control measurement part a1 includes the privacy information management system test part a11 and the privacy maturity model test part a12, among which the management system evaluation score of the privacy information management system test part a11 accounts for 80% of the company internal control measurement part a1, and the model evaluation score of the privacy maturity model test part a12 accounts for 20% of the company internal control measurement part a1.
  • the second privacy measurement result St of the static measurement module A is: (management system evaluation score*0.8+model evaluation score*0.2)*0.5+R&D control measurement score*0.5.
  • the dynamic measurement module B includes product compliance risk test item b1, product privacy and security protection technology test item b2, product adaptation law test item b3 or product privacy protection requirement test item b4, wherein the fusion weights of each test item account for 40%, 40%, 10% and 10% of the dynamic measurement module B respectively.
  • the first privacy measurement result Dy of the dynamic measurement module B is: compliance risk detection score*0.4+product privacy and security protection technology score*0.4+legal adaptability*0.1+1/selected product type privacy protection requirement strength*0.1.
  • a new privacy protection score can be obtained by adjusting the privacy protection data of the device under test, and the privacy protection data suitable for the device under test is determined according to the change of the new privacy protection score. That is, optionally, in some embodiments of the present application, the step of “upgrading the privacy protection of the device under test according to the privacy protection score” includes:
  • the first privacy measurement result is updated according to the target privacy protection technology to obtain an updated first privacy measurement result; an updated privacy protection score is obtained according to the updated first privacy measurement result and the second privacy measurement result; and the privacy protection of the device under test is upgraded according to the updated privacy protection score.
  • the embodiment of the present application realizes the engineering configuration of the device privacy security protection assessment process through static measurement, dynamic measurement and result visualization, and the privacy security protection assessment of each device can be realized based on this process.
  • the privacy security assessment of the device can reduce the professional skill requirements for operators, reduce the application cost, and realize the privacy security assessment of the device from multiple dimensions such as the enterprise and the device itself, so as to have a more comprehensive understanding of the privacy defects of the product.
  • different privacy protection scores can be obtained by adjusting the privacy protection technology applied to each privacy protection item, so as to realize different measures according to the cost to judge the degree of privacy protection and whether it meets the requirements of local laws and regulations.
  • the device After conducting a privacy and security assessment on the device, corresponding privacy and security improvements can be made to the device to obtain a device with better privacy protection effects.
  • the user uses the device for communication or application, the user's data can be better protected and privacy and security can be improved.
  • FIG. 5 is a flow chart of another method for device privacy management provided in an embodiment of the present application, wherein the specific process of the device privacy management includes:
  • step 203 Whether to update the company's internal control metrics. If yes, execute step 203;
  • the company's internal control measurement is usually updated every year, and it is not necessary to update it every time. And the company's internal control measurement value remains basically unchanged every year. Therefore, if you do not choose to update, you can continue to use the historical company's internal control measurement results.
  • the privacy maturity models include ISC2, NIST, GAPP, and CNIL.
  • step 206 Whether to update the R&D control metrics, if so, execute step 206;
  • the R&D control metric is usually updated every year and does not need to be updated every time; and the R&D control metric value remains basically unchanged every year. Therefore, if you do not choose to update, you can continue to use the historical R&D control metric results.
  • the product privacy protection requirement level score corresponding to the current product type is determined according to the corresponding relationship between the product type and the product privacy protection requirement level.
  • the current privacy and security technology security score of the smart home is obtained.
  • the risks of smart products can be detected through automatic detection and a score can be obtained; for example, compliance risk test cases can be configured and executed, and the scores of each compliance risk test case can be averaged to obtain the privacy security score of the smart home in compliance risk detection.
  • the privacy protection score [(management system assessment score*0.8+model assessment score*0.2)*0.5+(R&D cycle assessment score*0.5+privacy design process assessment score*0.5)*0.5]*0.5+[compliance risk privacy security score*0.4+privacy security technology security score*0.4+legal privacy security score*0.1+product privacy protection requirement score*0.1]*0.5.
  • the privacy protection items that can be improved refer to the privacy protection items with lower scores.
  • the present application also provides a device privacy management apparatus based on the above device privacy management method.
  • the meaning of the third target term is the same as that in the above device privacy management method, and the specific implementation details can refer to the description in the method embodiment.
  • FIG. 6 is a schematic diagram of the structure of a device privacy management apparatus provided in an embodiment of the present application, wherein the device privacy management apparatus Private management devices may include:
  • a first measurement module 301 is used to measure the privacy protection level of the device under test to obtain a first privacy measurement result
  • a second measurement module 302 is used to measure the privacy management level of the supplier to which the device under test belongs, and obtain a second privacy measurement result;
  • a score generating module 303 configured to generate a privacy protection score of the device under test according to the first privacy measurement result, the second privacy measurement result and a preset score weight;
  • the privacy management module 304 is used to upgrade the privacy protection of the device under test according to the privacy protection score.
  • the first metric module 301 includes:
  • An acquisition unit used to acquire the privacy security score of the device under test in the privacy protection item
  • a first generating unit configured to generate a first privacy measurement result according to the score sub-weight corresponding to the privacy protection item and the privacy safety score corresponding to the privacy protection item;
  • the privacy protection items include at least one of product compliance risk test items, product privacy and security protection technology test items, product adaptation law test items or product privacy protection requirement test items.
  • the acquisition unit includes:
  • Configuration subunit used to configure compliance risk test cases
  • a testing subunit configured to test the device to be tested according to the compliance risk test case to obtain a compliance risk test result, wherein the compliance risk test result corresponds to a risk level score;
  • the first calculation subunit is used to calculate the average value of the risk level scores corresponding to each compliance risk test case to obtain an average risk level score
  • the first generating subunit is used to use the average risk level score as the privacy security score of the device under test in the product compliance risk test item.
  • the acquisition unit includes:
  • a first determination subunit is used to determine the privacy and security protection technology items supported by the device under test
  • a second determination subunit is used to determine, for each privacy and security protection technology item, the type, strength and quantity of the privacy and security protection technology applied by the privacy and security protection technology item;
  • An acquisition subunit is used to acquire a preset mapping relationship set, wherein the preset mapping relationship set includes a mapping relationship between the type, strength, and quantity of preset privacy and security protection technologies and security scores;
  • a third determination subunit is used to determine a security score according to the preset mapping relationship set and the type, strength or quantity of the privacy and security protection technology applied by the privacy and security protection technology item;
  • the second calculation subunit is used to calculate the average security score of each privacy and security protection technology item to obtain an average security score
  • the acquisition unit includes: a region determination subunit, which is used to determine the target region where the device to be tested is to be put online;
  • the score determination subunit is used to determine the privacy security score of the device under test according to the actual legal baseline currently satisfied by the device under test and the target legal baseline.
  • the second metric module 302 includes:
  • a supplier determination unit used to determine the supplier to which the device under test belongs
  • a management level determination unit used to measure the privacy management level of the supplier according to the reference privacy information management system and the privacy maturity model to obtain a privacy management level score
  • a second matching unit configured to match the reference R&D privacy protection design process with the actual R&D privacy protection design process of the device under test to obtain a second matching result
  • a research and development level determination unit configured to obtain a research and development design privacy management score according to the first matching result and the second matching result
  • the second generating unit is used to generate a second privacy measurement result according to the privacy management level score and the developed and designed privacy control score.
  • the privacy management module 304 includes:
  • a protection technology determination unit configured to determine a current privacy protection technology corresponding to the privacy protection item of the device under test if the privacy protection degree score does not meet the score threshold;
  • a measurement result updating unit configured to re-measure based on the target privacy protection technology to obtain an updated first privacy measurement result
  • a score updating unit configured to multiply the updated first privacy measurement result by the first score weight to obtain a first protection score, multiply the second privacy measurement result by the second score weight to obtain a second protection score, and add the first protection score and the second protection score to obtain an updated privacy protection score
  • a privacy management unit is used to upgrade the privacy protection of the device under test according to the updated privacy protection score.
  • the first measurement module 301 first measures the privacy protection level of the device under test to obtain a first privacy measurement result
  • the second measurement module 302 measures the privacy management level of the supplier to which the device under test belongs to obtain a second privacy measurement result
  • the score generation module 303 generates a privacy protection score for the device under test according to the first privacy measurement result, the second privacy measurement result and a preset score weight
  • the privacy management module 304 upgrades the privacy protection of the device under test according to the privacy protection score.
  • the embodiment of the present application obtains a second privacy measurement result by measuring the privacy management level of the supplier, and generates a privacy protection score for the device under test based on the second privacy measurement result and the first privacy measurement result for the privacy of the product itself.
  • the embodiment of the present application enriches the measurement dimensions of product privacy protection, improves the accuracy of product privacy protection measurement results, and facilitates the implementation of privacy and security protection management of products.
  • FIG7 shows a schematic diagram of the structure of the electronic device involved in the present application, specifically:
  • the electronic device may include components such as a processor 401 with one or more processing cores, a memory 402 with one or more computer-readable storage media, a power supply 403, and an input unit 404.
  • a processor 401 with one or more processing cores
  • a memory 402 with one or more computer-readable storage media
  • a power supply 403 with one or more computer-readable storage media
  • an input unit 404 may be included in the electronic device.
  • FIG. 7 does not constitute a limitation on the electronic device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently. Among them:
  • the processor 401 is the control center of the electronic device, which uses various interfaces and lines to connect various parts of the entire electronic device, and executes various functions of the electronic device and processes data by running or executing software programs and/or modules stored in the memory 402, and calling data stored in the memory 402.
  • the processor 401 may include one or more processing cores; preferably, the processor 401 may integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, object interface and application programs, etc., and the modem processor mainly processes wireless communications. It is understandable that the above-mentioned modem processor may not be integrated into the processor 401.
  • the memory 402 can be used to store software programs and modules.
  • the processor 401 executes various functional applications and device privacy management by running the software programs and modules stored in the memory 402.
  • the memory 402 may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc.; the data storage area may store data created according to the use of the electronic device, etc.
  • the memory 402 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage device. Accordingly, the memory 402 may also A memory controller is included to provide processor 401 with access to memory 402 .
  • the electronic device also includes a power supply 403 for supplying power to each component.
  • the power supply 403 can be logically connected to the processor 401 through a power management system, so as to manage charging, discharging, power consumption and other functions through the power management system.
  • the power supply 403 can also include one or more DC or AC power supplies, recharging systems, power failure detection circuits, power converters or inverters, power status indicators and other arbitrary components.
  • the electronic device may also include an input unit 404, which can be used to receive input digital or character information, and generate keyboard, mouse, joystick, optical or trackball signal input related to object setting and function control.
  • the electronic device may also include a display unit, etc., which will not be repeated here.
  • the processor 401 in the electronic device will load the executable files corresponding to the processes of one or more applications into the memory 402 according to the following instructions, and the processor 401 will run the application stored in the memory 402, thereby implementing the steps in any device privacy management method provided in this application.
  • the privacy protection level of the device under test is measured to obtain a first privacy measurement result
  • the privacy management level of the supplier to which the device under test belongs is measured to obtain a second privacy measurement result
  • a privacy protection score of the device under test is generated according to the first privacy measurement result, the second privacy measurement result and the preset score weight, and the privacy protection of the device under test is upgraded according to the privacy protection score.
  • the second privacy measurement result is obtained by measuring the privacy management level of the supplier
  • the privacy protection score of the device under test is generated according to the second privacy measurement result and the first privacy measurement result for the privacy of the product itself.
  • the embodiment of the present application enriches the measurement dimension of product privacy protection, improves the accuracy of the product privacy protection measurement result, and facilitates the implementation of privacy and security protection management of the product.
  • the computer readable storage medium may include: read-only memory (ROM), random access memory (RAM), disk or CD, etc.
  • the instructions stored in the computer-readable storage medium can execute the steps in any device privacy management method provided in the present application, the beneficial effects that can be achieved by any device privacy management method provided in the present application can be achieved. Please refer to the previous embodiments for details and will not be repeated here.
  • the present application involves the configuration data of the device to be tested (compliance risk data, adaptation legal data, privacy and security protection technology, product type, etc.), and the relevant information of the enterprise corresponding to the device to be tested (the name of the enterprise, the privacy management level of the enterprise, including the level of privacy management and the life cycle of the equipment developed and the corresponding privacy design process) and other related data.
  • the relevant information of the enterprise corresponding to the device to be tested the name of the enterprise, the privacy management level of the enterprise, including the level of privacy management and the life cycle of the equipment developed and the corresponding privacy design process

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • General Engineering & Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Software Systems (AREA)
  • Bioethics (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Medical Informatics (AREA)
  • Databases & Information Systems (AREA)
  • Computing Systems (AREA)
  • Storage Device Security (AREA)

Abstract

本申请实施例公开了一种设备隐私管理方法,包括:对待测设备进行隐私保护水平度量,得到第一隐私度量结果;对待测设备所属的供应商进行隐私管理水平度量,得到第二隐私度量结果;根据第一隐私度量结果、第二隐私度量结果和预设的得分权重,生成隐私保护度评分;对待测设备的隐私保护进行升级。实现隐私安全保护管理。

Description

设备隐私管理方法、装置、电子设备及存储介质
本申请要求申请日为2023年06月14日、申请号为202310707303.6、申请名称为“设备隐私管理方法、装置、电子设备及存储介质”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请实施例涉及计算机技术领域,具体涉及一种设备隐私管理方法、装置、电子设备及存储介质,其中,存储介质包括计算机可读存储介质。
背景技术
随着全球隐私保护立法越来越多和执法越来越严格,企业面临着越来越大的隐私保护方面的压力。智能家居发展速度加快,大量智能家电进入千家万户,它的安全与隐私保护得到了广泛关注。
技术问题
目前,很多产品的用户数据隐私保护还主要仅针对在产品本身,使得难以准确衡量产品的隐私保护情况,无法对产品进行隐私安全保护管理。
技术解决方案
本申请实施例提供一种设备隐私管理方法、装置、电子设备及存储介质,可以提升产品隐私保护衡量结果的准确性。
第一方面,本申请实施例提供了一种设备隐私管理方法,包括:
对待测设备进行隐私保护水平度量,得到第一隐私度量结果;
对所述待测设备所属的供应商进行隐私管理水平度量,得到第二隐私度量结果;
根据所述第一隐私度量结果、所述第二隐私度量结果和预设的得分权重,生成所述待测设备的隐私保护度评分;
根据所述隐私保护度评分对所述待测设备的隐私保护进行升级。
第二方面,本申请实施例还提供了一种设备隐私管理装置,包括:
第一度量模块,用于对待测设备进行隐私保护水平度量,得到第一隐私度量结果;
第二度量模块,用于对所述待测设备所属的供应商进行隐私管理水平度量,得到第二隐私度量结果;
评分生成模块,用于根据所述第一隐私度量结果、所述第二隐私度量结果和预设的得分权重,生成所述待测设备的隐私保护度评分;
隐私管理模块,用于根据所述隐私保护度评分对所述待测设备的隐私保护进行升级。
其中,在本申请的一些实施例中,第一度量模块包括:
获取单元,用于获取待测设备在隐私保护项的隐私安全得分;
第一生成单元,用于根据所述隐私保护项对应的得分子权重以及所述隐私保护项对应的所述隐私安全得分生成第一隐私度量结果;
所述隐私保护项包括产品合规风险测试项、产品隐私安全保护技术测试项、产品适配法律测试项或产品隐私保护要求度测试项中的至少一种。
其中,在本申请的一些实施例中,若所述隐私保护项为产品合规风险测试项,获取单元包括:
配置子单元,用于配置合规风险测试用例;
测试子单元,用于根据所述合规风险测试用例对待测设备进行测试,得到合规风险测试结果,所述合规风险测试结果对应一风险等级得分;
第一计算子单元,用于计算各个合规风险测试用例对应的风险等级得分的平均值,得到平均风险等级得分;
第一生成子单元,用于将所述平均风险等级得分作为所述待测设备在所述产品合规风险测试项的隐私安全得分。
其中,在本申请的一些实施例中,若所述隐私保护项为产品隐私安全保护技术测试项,获取单元包括:
第一确定子单元,用于确定待测设备支持的隐私安全保护技术项;
第二确定子单元,用于针对每个隐私安全保护技术项,确定所述隐私安全保护技术项所应用的隐私安全保护技术的类型、强度以及数量;
获取子单元,用于获取预设映射关系集合,所述预设映射关系集合包括预设的隐私安全保护技术的类型、强度以及数量和安全评分的映射关系;
第三确定子单元,用于根据所述预设映射关系集合,根据所述隐私安全保护技术项应用的隐私安全保护技术的类型、强度或者数量确定安全评分;
第二计算子单元,用于计算各个隐私安全保护技术项的安全评分的平均值,得到平均安全评分;
第二生成子单元,用于将所述平均安全评分作为所述待测设备在所述产品隐私安全保护技术测试项的隐私安全得分。
其中,在本申请的一些实施例中,若所述隐私保护项为产品适配法律测试项,获取单元包括:区域确定子单元,用于确定待测设备待上线的目标区域;
基线确定子单元,用于确定所述目标区域所需满足的目标法律基线;
得分确定子单元,用于根据所述待测设备当前满足的实际法律基线和所述目标法律基线,确定所述待测设备的隐私安全得分。
其中,在本申请的一些实施例中,第二度量模块包括:
供应商确定单元,用于确定所述待测设备所属的供应商;
管理水平确定单元,用于根据参考隐私信息管理体系和隐私成熟度模型对所述供应商的隐私管理水平进行度量,得到隐私管理水平得分;
第一匹配单元,用于将参考软件安全开发生命周期与所述待测设备的实际软件安全开发生命周期进行匹配,得到第一匹配结果;
第二匹配单元,用于将参考研发隐私保护设计流程与所述待测设备的实际研发隐私保护设计流程进行匹配,得到第二匹配结果;
研发水平确定单元,用于根据所述第一匹配结果和所述第二匹配结果得到研发设计隐私管控得分;
第二生成单元,用于根据所述隐私管理水平得分和所研发设计隐私管控得分,生成第二隐私度量结果。
其中,在本申请的一些实施例中,隐私管理模块包括:
保护技术确定单元,用于若所述隐私保护度评分不满足评分阈值,则确定待测设备的隐私保护项对应的当前隐私保护技术;
保护技术变更单元,用于变更所述当前隐私保护技术,得到目标隐私保护技术;
度量结果更新单元,用于基于所述目标隐私保护技术重新度量得到更新后第一隐私度量结果;评分更新单元,用于将更新后第一隐私度量结果与第一得分权重相乘得到第一保护度得分,将第二隐私度量结果与第二得分权重相乘得到第二保护度得分,将第一保护度得分和第二保护度得分相加,得到更新后隐私保护度评分;
隐私管理单元,用于根据所述更新后隐私保护度评分对所述待测设备的隐私保护进行升级。第三方面,本申请实施例还提供了一种电子设备,电子设备包括存储器、处理器及存储在存 储器中并可在处理器上运行的计算机程序,处理器执行计算机程序时实现上述第一方面中的设备隐私管理方法中的步骤或者实现上述第三方面中的设备隐私管理方法中的步骤。
第四方面,本申请实施例还提供了一种存储介质,该存储介质包括计算机可读存储介质,计算机可读存储介质上存储有计算机程序,计算机程序被处理器执行时实现上述的设备隐私管理方法中的步骤。
第五方面,本申请实施例还提供了一种计算机程序产品或计算机程序,该计算机程序产品或计算机程序包括计算机指令,该计算机指令存储在计算机可读存储介质中。计算机设备的处理器从计算机可读存储介质读取该计算机指令,处理器执行该计算机指令,使得该计算机设备执行本申请实施例所述的各种可选实现方式中提供的方法。
有益效果
本申请实施例对待测设备进行隐私保护水平度量,得到第一隐私度量结果,对所述待测设备所属的供应商进行隐私管理水平度量,得到第二隐私度量结果,根据所述第一隐私度量结果和所述第二隐私度量结果,生成所述待测设备的隐私保护度评分,根据所述隐私保护度评分对所述待测设备的隐私保护进行升级。其中,通过对供应商的隐私管理水平进行度量得到第二隐私度量结果,并根据该第二隐私度量结果以及针对产品本身的隐私的第一隐私度量结果生成待测设备的隐私保护度评分,相较于传统的仅针对产品本身的隐私水平的评估方案,本申请实施例丰富了产品隐私保护的衡量维度,提升产品隐私保护衡量结果的准确性,便于实现对产品的隐私安全保护管理。
附图说明
为了更清楚地说明本申请中的技术方案,下面将对实施例描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1是本申请实施例提供的设备隐私管理方法的场景示意图;
图2是本申请实施例提供的设备隐私管理方法的流程示意图;
图3是本申请实施例提供的各个隐私安全保护技术项及其对应的安全评分的结果示意图;
图4是本申请实施例提供的设备隐私管理的架构示意图;
图5是本申请实施例提供的设备隐私管理方法的另一示意图;
图6是本申请实施例提供的设备隐私管理装置的结构示意图;
图7是本申请实施例提供的电子设备的结构示意图。
本发明的实施方式
下面将结合本申请中的附图,对本申请中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
本申请实施例提供一种设备隐私管理方法、装置、电子设备及存储介质。具体地,本申请实施例提供适用于电子设备的设备隐私管理装置,其中,电子设备包括终端,其中,终端包括但不限于手机、平板电脑、计算机或者电视等设备。
请参阅图1,以终端设备执行设备隐私管理方法为例,其中,设备隐私管理方法的具体执行过程如下:
服务器10获取待测设备11的配置参数信息,根据该配置参数信息对该待测设备11进行隐私保护水平度量,得到第一隐私度量结果;
随后,服务器10获取该待测设备的供应商信息,以并对该供应商的隐私管理水平进行度量,得到第二隐私度量结果;
然后,根据第一隐私度量结果和第二隐私度量结果生成隐私保护度评分,根据该隐私保护度评分对待测设备的隐私保护进行升级。
可以理解的是,通过对供应商的隐私管理水平进行度量得到第二隐私度量结果,并根据该第二隐私度量结果以及针对产品本身的隐私的第一隐私度量结果生成待测设备的隐私保护度评分,相较于传统的仅针对产品本身的隐私水平的评估方案,本申请实施例丰富了产品隐私保护的衡量维度,提升产品隐私保护衡量结果的准确性,便于实现对产品的隐私安全保护管理。
以下分别进行详细说明。需说明的是,以下实施例的描述顺序不作为对实施例优先顺序的限定。
请参阅图2,图2是本申请实施例提供的设备隐私管理方法的流程示意图。该设备隐私管理方法的具体流程可以如下:101、对待测设备进行隐私保护水平度量,得到第一隐私度量结果。
需要说明的是,设备的隐私保护水平指该设备在应用时对用户数据的隐私保护水平,由设备在应用时设备的相关配置参数决定,即,第一隐私度量结果是针对设备本身而言得到的评估结果。
其中,待测设备指需要进行隐私保护评估的设备,例如,生产后出厂的设备、研发测试所用的设备或者应用过程中存在隐私安全问题而需要进行测试的设备等。
102、对所述待测设备所属的供应商进行隐私管理水平度量,得到第二隐私度量结果。需要说明的是,供应商的隐私管理水平指该供应商隐私保护的控制水平,其中,该供应商为开发或者生产该设备的企业。
可以理解的是,通过对生产该设备的企业针对隐私管理水平的度量,可以从更多维度分析设备的隐私保护水平,例如,该企业的隐私保护的控制水平越高,则相应的产品的隐私保护水平也通常较高。
103、根据所述第一隐私度量结果、所述第二隐私度量结果和预设的得分权重,生成所述待测设备的隐私保护度评分。
可以理解的是,隐私保护度评分是针对设备在用户数据隐私保护方面的评分,该评分越高,则说明该设备或者该产品的隐私保护越好,反之,评分越低,则说明该设备或者该产品的隐私保护越差。
可以理解的是,通过从多个维度的度量结果生成隐私保护度评分,实现从多个维度对设备隐私保护情况进行度量、以及评分,提升隐私保护度评分的准确性。
其中,得分权重反映每个隐私度量结果对应的得分的占比情况,例如,在本申请实施例中,第一隐私度量结果和第二隐私度量结果的的得分权重各占50%。其中,在本申请实施例中,得分权重可以根据实际需要进行灵活调整,在此对得分权重的具体数值不做限定。
104、根据所述隐私保护度评分对所述待测设备的隐私保护进行升级。
其中,通过得到设备的隐私保护度评分,则可以根据该隐私保护度评分对设备进行隐私保护升级,例如,若设备的隐私保护度评分较低,则需要通过调整设备在隐私保护方面的技术、强度等方式来提升设备的隐私保护度评分。
相应的,根据该隐私保护度评分也可以判断是否允许相应的设备引入,例如,当设备的隐私保护度评分较低时,则拒绝该设备的引入,当设备的隐私保护度评分达到标准时,才允许该设备引入,其中,设备引入也称设备引进,指设备购入或者进口设备等。
可以理解的是,通过对供应商的隐私管理水平进行度量得到第二隐私度量结果,并根据该第二隐私度量结果以及针对产品本身的隐私的第一隐私度量结果生成待测设备的隐私保护度 评分,相较于传统的仅针对产品本身的隐私水平的评估方案,本申请实施例丰富了产品隐私保护的衡量维度,提升产品隐私保护衡量结果的准确性,便于实现对产品的隐私安全保护管理。
可选的,在本申请实施例中,第一隐私度量结果是针对设备在应用过程中隐私评分情况,因此,通过得到待测设备在各个隐私保护项的隐私安全得分,便可以得到该待测设备的第一隐私度量结果,即,可选的,在本申请的一些实施例中,步骤“对待测设备进行隐私保护水平度量,得到第一隐私度量结果”,包括:
获取待测设备在隐私保护项的隐私安全得分;
根据所述隐私保护项对应的得分子权重以及所述隐私保护项对应的所述隐私安全得分生成第一隐私度量结果;
所述隐私保护项包括产品合规风险测试项、产品隐私安全保护技术测试项、产品适配法律测试项或产品隐私保护要求度测试项中的至少一种。
需要说明的是,隐私保护项是待测设备主要针对的几个检测项,该几个检测项从不同的维度实现对设备隐私安全的检测。
其中,通过各个检测项的隐私安全得分综合得到设备在应用过程中的动态的第一隐私度量结果。
相应的,得分子权重反映每个隐私保护项的得分占比情况,例如,当隐私保护项为四个时,则各个隐私保护项的得分子权重可以分别为25%。其中,该得分子权重的具体数值也可以根据实际需要进行灵活调整。
需要说明的是,产品合规风险测试项是针对设备是否合规风险的检测,在该过程中,可以构建测试用例,基于测试用例对设备进行测试,以获取到针对合规风险的测试结果,即,可选的,在本申请的一些实施例中,若所述隐私保护项为产品合规风险测试项,步骤“获取待测设备在隐私保护项的隐私安全得分”,包括:
配置合规风险测试用例;
根据所述合规风险测试用例对待测设备进行测试,得到合规风险测试结果,所述合规风险测试结果对应一风险等级得分;
计算各个合规风险测试用例对应的风险等级得分的平均值,得到平均风险等级得分;
将所述平均风险等级得分作为所述待测设备在所述产品合规风险测试项的隐私安全得分。可以理解的是,合规风险测试用例是针对待测设备在产品合规风险测试方面建立的测试用例,基于该测试用例的执行,获取待测设备在产品合规方面的风险情况。其中,合规风险测试用例中包括所针对的待测试项目以及相关的测试文件及测试输入数据等。
合规风险测试用例可以包括多条,每条测试用例分别对应一个测试结果,测试结果可以用得分表示,得分0-5之间,不同的得分对应不同的风险等级,例如,严重:0分;高危:1分:中危:2分;低危:4分;无风险(通过):5分。
相应的,针对设备的产品合规风险测试项的隐私安全得分,可以由多个测试用例的合规风险测试结果来综合得到,例如,(Li表示第i条测试用例的测试结果得分),其中,N为测试用例的数量或者条数,即以多个合规风险测试用例的测试结果得分的均值来表示该产品合规风险测试项的隐私安全得分。
需要说明的是,产品隐私安全保护技术测试项是针对设备配置的隐私安全保护技术的测试,可以从应用的隐私安全保护技术的类型、强度或者数量多少等角度来对设备的产品隐私安全保护技术进行评分,即,可选的,在本申请的一些实施例中,若所述隐私保护项为产品隐私安全保护技术测试项,步骤“获取待测设备在隐私保护项的隐私安全得分”,包括:
确定待测设备支持的隐私安全保护技术项;
针对每个隐私安全保护技术项,确定所述隐私安全保护技术项所应用的隐私安全保护技术的类型、强度以及数量;
获取预设映射关系集合,所述预设映射关系集合包括预设的隐私安全保护技术的类型、强度以及数量和安全评分的映射关系;
根据所述预设映射关系集合,根据所述隐私安全保护技术项应用的隐私安全保护技术的类型、强度或者数量确定安全评分;
计算各个隐私安全保护技术项的安全评分的平均值,得到平均安全评分;
将所述平均安全评分作为所述待测设备在所述产品隐私安全保护技术测试项的隐私安全得分。
需要说明的是,隐私安全保护技术项是设备为达到隐私安全的目的而采用的保护技术项目,例如,请参阅图3,图3是本申请实施例提供的各个隐私安全保护技术项及其对应的安全评分的结果示意图,其中,隐私安全保护技术项包括数据加密、数据备份和回复、安全套接层协议传输数据、云端采用的安全产品、接口认证授权、数据脱敏、匿名算法、差分隐私等技术项,相应的,针对每个隐私安全保护技术项,根据该隐私安全保护技术项所应用到的保护技术的类型、强度或者数量等确定相应的隐私安全保护技术项的安全评分。
例如,保护技术的类型越安全,保护强度越高,以及保护技术的数量越多,对应的安全评分越高。具体的,在本申请实施例中,可以根据隐私安全保护技术的类型、强度、数量和安全评分之间预先建立的映射关系,来得到当前的各个隐私安全保护技术项的安全评分,进而根据各个安全评分的均值,得到待测设备针对该产品隐私安全保护技术测试项的隐私安全得分。相应的,针对产品隐私安全保护技术测试项的隐私安全得分,也可以由该产品隐私安全保护技术测试项对应的多个隐私安全保护技术项的安全评分来综合得到,例如, (Li表示第i条隐私安全保护技术项的安全得分)。
需要说明的是,产品适配法律测试项是针对设备是否满足相应国家或者区域的法律需求,针对该法律需求进行的隐私安全测试,例如,产品所使用的法律是否满足相应地区的隐私安全法律基线等,即,可选的,在本申请的一些实施例中,若所述隐私保护项为产品适配法律测试项,步骤“获取待测设备在隐私保护项的隐私安全得分”,包括:
确定待测设备待上线的目标区域;
确定所述目标区域所需满足的目标法律基线;
根据所述待测设备当前满足的实际法律基线和所述目标法律基线,确定所述待测设备的隐私安全得分。
可以理解的,法律基线是法律对应的基准,即设备所满足的法律要求,如,本申请实施例中,法律基线主要指设备在隐私法方面所对应的隐私法律要求。根据设备当前适用的实际法律基线与上线区域的目标法律基线的比较,可以得到该设备在产品适配法律测试项的隐私安全得分。例如,如A国的隐私法要求比较低或者没有隐私法,但是产品采取的隐私保护措施已超出了A国法律要求,则评分为5分;B国的隐私法要求特别高,但是产品未采取的隐私保护措施,则评分为0分。
可选的,在本申请实施例中,还可以根据产品的类型来确定该设备需要满足的隐私保护要求度,即,每种产品类型对应的隐私保护要求度不同,相应的,若隐私保护项为产品隐私保护要求度测试项,则“获取待测设备在隐私保护项的隐私安全得分”包括:
确定待测设备的产品类型;
根据该产品类型和映射关系,确定该待测设备对应的产品隐私保护要求度;
将所述产品隐私保护要求度作为所述待测设备针对所述产品类型方面的隐私安全得分。其中,该映射关系包括预设的产品类型与预设的产品隐私保护要求度之间的映射关系。可以理解的是,该映射关系可以根据不同产品的数据隐私要求保护程度进行预定义,例如,智能灯光控制、智能窗帘、智能抽油烟机、蓝牙温湿度传感器对应的产品隐私保护要求度为1,智能空调、智能冰箱(不带屏幕)、智能洗衣机、智能空气净化器、智能新风系统和蓝牙体脂称的产品隐私保护要求度为2,智能扫地机器人(不带摄像头)和智能冰箱(带屏幕)的产品隐私保护要求度为3,智能电视和智能网关的产品隐私保护要求度为4,智能门锁、智能摄像头、智能门铃、智能猫眼、智能扫地机器人(带摄像头)、智能手表和智能手机的产品隐私保护要求度为5等。
需要说明的是,第二隐私度量结果是针对研发或者设计该设备的企业的隐私管理水平以及该企业研发设计流程进行的评分结果,而企业的隐私管理水平以及该企业研发设计流程的评分结果在一定程度上反映研发出的设备的隐私保护情况,例如,若企业的隐私管理水平较高,且研发设计流程的评分结果为设计流程较规范,则对应研发出的设备的隐私保护和规范也相应会更高,因此,可以将该企业的评估结果作为相应设备隐私保护的参考,即,可选的,在本申请的一些实施例中,步骤“对所述待测设备所属的供应商进行隐私管理水平度量,得到第二隐私度量结果”,包括:
确定所述待测设备所属的供应商;
根据参考隐私信息管理体系和隐私成熟度模型对所述供应商的隐私管理水平进行度量,得到隐私管理水平得分;
将参考软件安全开发生命周期与所述待测设备的实际软件安全开发生命周期进行匹配,得到第一匹配结果;
将参考研发隐私保护设计流程与所述待测设备的实际研发隐私保护设计流程进行匹配,得到第二匹配结果;
根据所述第一匹配结果和所述第二匹配结果得到研发设计隐私管控得分;
根据所述隐私管理水平得分和所研发设计隐私管控得分,生成第二隐私度量结果。
其中,匹配结果反映匹配程度,可以用百分比或者0-1之间的小数进行表示,例如,第一匹配结果的百分比较高则说明两个生命周期较为接近或者一致,第一匹配结果的百分比较低则说明两个生命周期相似性较低;又例如,第二匹配结果的百分比比较高则说明隐私保护设计流程较为接近或者一致,反之,第二匹配结果的百分比比较低则说明两个隐私保护设计流程基本不同或者重合性较低。其中,用百分比的方式反映两个比较对象之间的匹配程度。相应的,第一匹配结果和第二匹配结果也可以通过权重占比的方式计算得到研发设计隐私管控得分,例如,将两个匹配结果对应的百分比分别与权重占比相乘后相加得到最终的研发设计隐私管控得分。
可以理解的是,隐私管理水平得分反映的是企业针对隐私管理的水平,研发设计隐私管控得分反映的是企业针对设备在研发时的隐私管控得分。
其中,软件安全开发生命周期:(SSDLC,Software security development life cycle)和隐私保护设计流程(PbD,Privacy by Design)具有相应的参考标准,通过判断该企业是否满足相应的标准,来判断该企业的研发设计隐私管控得分。
相应的,针对隐私管理水平得分,可以通过企业是否满足相关的隐私信息管理体系,以及还可以通过隐私成熟度模型来分析企业的隐私管理水平,例如,根据ISO27701隐私管理体系对公司整体隐私管理水平进行评估后得出管理体系评估分数;根据经典隐私成熟度模型如ISC2、NIST、GAPP、CNIL对公司整体隐私管理水平进行模型评估分数。
相应的,针对研发设计隐私管控得分,可以通过设备研发的生命周期以及隐私保护设计流程等方面来分析设备的隐私保护得分,例如,对公司研发软件安全开发生命周期(SSDLC)水 平进行评估,得出研发周期评估分数;对公司研发隐私保护设计流程(PbD)水平进行评估,得出隐私设计流程评估分数。
相应的,在得到各个检测项的评分后,可以通过各个检测项的权重将各个评分进行融合,得到隐私保护度评分,例如,请参阅图4,图4是本申请实施例提供的设备隐私管理的架构示意图,其中,该设备隐私管理的架构包括静态度量模块A、动态度量模块B和结果可视化模块C,其中,静态度量模块A用于对研发或者设计该待测设备的企业的隐私管理水平的评估,动态度量模块B用于对待测设备在应用过程中的动态隐私数据进行评估,结果可视化模块C用于将静态度量模块A和动态度量模块B融合得到的隐私保护度评分进行可视化展示。其中,在本申请实施例中。静态度量模块A和动态度量模块B的融合权重各占50%;
相应的,针对静态度量模块A,静态度量模块A又包括公司内控度量部分a1和研发管控度量部分a2,各占50%,公司内控度量部分a1包括隐私信息管理体系测试部分a11和隐私成熟度模型测试部分a12,其中,隐私信息管理体系测试部分a11的管理体系评估分数占公司内控度量部分a1的80%,隐私成熟度模型测试部分a12的模型评估分数占公司内控度量部分a1的20%。
例如,静态度量模块A的第二隐私度量结果St为:(管理体系评估分数*0.8+模型评估分数*0.2)*0.5+研发管控度量得分*0.5。
相应的,针对动态度量模块B,该动态度量模块B包括产品合规风险测试项b1、产品隐私安全保护技术测试项b2、产品适配法律测试项b3或产品隐私保护要求度测试项b4,其中,各个测试项的融合权重分别占动态度量模块B的40%、40%、10%和10%。
例如,动态度量模块B的第一隐私度量结果Dy为:合规风险检测评分*0.4+产品隐私安全保护技术评分*0.4+法律适配度*0.1+1/选择产品类型隐私保护要求强度*0.1。
可选的,在根据隐私保护度评分对待测设备的隐私保护进行升级时,则可以通过调整待测设备的隐私保护数据,来得到新的隐私保护度评分,根据新的隐私保护度评分的变化情况,来确定适合该待测设备的隐私保护数据,即,可选的,在本申请的一些实施例中,步骤“根据所述隐私保护度评分对所述待测设备的隐私保护进行升级”,包括:
确定待测设备的隐私保护项对应的当前隐私保护技术;
变更所述当前隐私保护技术,得到目标隐私保护技术;
根据所述目标隐私保护技术更新所述第一隐私度量结果,得到更新后第一隐私度量结果;根据所述更新后第一隐私度量结果和所述第二隐私度量结果,得到更新后隐私保护度评分;根据所述更新后隐私保护度评分对所述待测设备的隐私保护进行升级。
其中,通过选择或添加其他隐私保护技术,查看不同的隐私保护技术对应产品隐私保护分数的影响,看看是否达到了上线国家的隐私保护要求。
可以理解的是,本申请实施例通过静态度量、动态度量以及结果可视化的形式实现对设备隐私安全保护评估流程的工程化配置,基于该流程可以实现对各个设备的隐私安全保护评估。基于该评估流程对设备进行隐私安全评估,可降低对操作人员的专业技能要求,降低应用成本,从企业和设备本身等多个维度实现对设备的隐私安全评估,能更加全面了解产品隐私缺陷,在动态度量部分,还可以通过调整各个隐私保护项所应用的隐私保护技术来得到不同的隐私保护度评分,实现根据成本采取不同的措施,来判断隐私保护的程度以及是否满足当地法律法规要求。
相应的,在对设备进行隐私安全评估后,可以通过对设备进行相应的隐私安全改进,进而得到隐私保护效果较好的设备,当用户使用该设备进行通信或者应用时,则可以较好的保护用户的数据,提升隐私安全性。
请参阅图5,图5是本申请实施例提供的设备隐私管理的另一方法流程图,其中,该设备隐私管理的具体流程包括:
201、启动隐私保护管理系统;
先启动静态度量部分:
202、是否更新公司内控度量,若选择,则执行步骤203;
其中,该公司内控度量通常每年更新,不需要每次都更新。且每年中该公司内控度量值基本不变,因此,若未选择更新,则延用历史的公司内控度量结果即可。
203、根据ISO27701隐私管理体系对公司整体隐私管理水平进行评估,得出管理体系评估分数;
204、根据经典隐私成熟度模型对公司整体隐私管理水平进行评估分数,得到模型评估分数;其中,隐私成熟度模型包括ISC2、NIST、GAPP、CNIL。
205、是否更新研发管控度量,若是,则执行步骤206;
其中。该研发管控度量通常每年更新,不需要每次都更新;且每年中该研发管控度量值基本不变,因此,若未选择更新,则延用历史的研发管控度量结果即可。
206、对公司研发软件安全开发生命周期(SSDLC)水平进行评估,得出研发周期评估分数;
207、对公司研发隐私保护设计流程(PbD)水平进行评估,得出隐私设计流程评估分数;启动动态度量部分:
208、选择智能家居产品上线国家的法律,确定针对法律适配的法律隐私安全得分;
209、选择待评估的智能家居产品类型,得到产品隐私保护要求程度得分;
其中,根据产品类型与产品隐私保护要求度之间的对应关系确定当前产品类型对应的产品隐私保护要求程度得分。
210、选择待评估的智能家居产品类型目前采用的隐私安全保护技术或待采用的隐私安全保护技术,得到隐私安全技术安全评分;
其中,根据预先建立的隐私安全保护技术的类型、强度、数量和安全评分之间的映射关系,得到当前的智能家居的隐私安全技术安全评分。
211、对智能家居产品进行合规风险检测,得到合规风险隐私安全得分;
其中,可以通过自动检测的方式检测智能产品存在的风险,并得出分数;例如,配置并执行合规风险测试用例,将各个合规风险测试用例的得分进行平均处理,得到智能家居在合规风险检测方面的隐私安全得分。
212、将管理体系评估分数、模型评估分数、研发周期评估分数和隐私设计流程评估分数、法律隐私安全得分、产品隐私保护要求程度得分、隐私安全技术安全评分和合规风险隐私安全得分,进行加权、计算最终分数,得到隐私保护度评分;
例如,隐私保护度评分=[(管理体系评估分数*0.8+模型评估分数*0.2)*0.5+(研发周期评估分数*0.5+隐私设计流程评估分数*0.5)*0.5]*0.5+[合规风险隐私安全得分*0.4+隐私安全技术安全评分*0.4+法律隐私安全得分*0.1+产品隐私保护要求程度得分*0.1]*0.5。
213、显示智能家居隐私保护度评分,以及各维度评分、可提升的隐私保护项;
其中,可提升的隐私保护项指评分较低的隐私保护项。
214、根据可提升的隐私保护项,选择是否重新计算当前评估分数,重复步骤208-213,直至没有可提升的隐私保护项。
可以理解的是,本申请实施例结合了多种隐私保护评估方法和安全开发流程,能更加全面了解产品隐私缺陷。可根据成本采取不同的措施,来判断隐私保护的程度以及是否满足当地法律法规要求。
为便于更好的实施本申请的设备隐私管理方法,本申请还提供一种基于上述设备隐私管理方法的设备隐私管理装置。其中第三目标词语的含义与上述设备隐私管理方法中相同,具体实现细节可以参考方法实施例中的说明。
请参阅图6,图6是本申请实施例提供的设备隐私管理装置的结构示意图,其中,该设备隐 私管理装置可以包括:
第一度量模块301,用于对待测设备进行隐私保护水平度量,得到第一隐私度量结果;
第二度量模块302,用于对所述待测设备所属的供应商进行隐私管理水平度量,得到第二隐私度量结果;
评分生成模块303,用于根据所述第一隐私度量结果、所述第二隐私度量结果和预设的得分权重,生成所述待测设备的隐私保护度评分;
隐私管理模块304,用于根据所述隐私保护度评分对所述待测设备的隐私保护进行升级。
其中,在本申请的一些实施例中,第一度量模块301包括:
获取单元,用于获取待测设备在隐私保护项的隐私安全得分;
第一生成单元,用于根据所述隐私保护项对应的得分子权重以及所述隐私保护项对应的所述隐私安全得分生成第一隐私度量结果;
所述隐私保护项包括产品合规风险测试项、产品隐私安全保护技术测试项、产品适配法律测试项或产品隐私保护要求度测试项中的至少一种。
其中,在本申请的一些实施例中,若所述隐私保护项为产品合规风险测试项,获取单元包括:
配置子单元,用于配置合规风险测试用例;
测试子单元,用于根据所述合规风险测试用例对待测设备进行测试,得到合规风险测试结果,所述合规风险测试结果对应一风险等级得分;
第一计算子单元,用于计算各个合规风险测试用例对应的风险等级得分的平均值,得到平均风险等级得分;
第一生成子单元,用于将所述平均风险等级得分作为所述待测设备在所述产品合规风险测试项的隐私安全得分。
其中,在本申请的一些实施例中,若所述隐私保护项为产品隐私安全保护技术测试项,获取单元包括:
第一确定子单元,用于确定待测设备支持的隐私安全保护技术项;
第二确定子单元,用于针对每个隐私安全保护技术项,确定所述隐私安全保护技术项所应用的隐私安全保护技术的类型、强度以及数量;
获取子单元,用于获取预设映射关系集合,所述预设映射关系集合包括预设的隐私安全保护技术的类型、强度以及数量和安全评分的映射关系;
第三确定子单元,用于根据所述预设映射关系集合,根据所述隐私安全保护技术项应用的隐私安全保护技术的类型、强度或者数量确定安全评分;
第二计算子单元,用于计算各个隐私安全保护技术项的安全评分的平均值,得到平均安全评分;
第二生成子单元,用于将所述平均安全评分作为所述待测设备在所述产品隐私安全保护技术测试项的隐私安全得分。
其中,在本申请的一些实施例中,若所述隐私保护项为产品适配法律测试项,获取单元包括:区域确定子单元,用于确定待测设备待上线的目标区域;
基线确定子单元,用于确定所述目标区域所需满足的目标法律基线;
得分确定子单元,用于根据所述待测设备当前满足的实际法律基线和所述目标法律基线,确定所述待测设备的隐私安全得分。
其中,在本申请的一些实施例中,第二度量模块302包括:
供应商确定单元,用于确定所述待测设备所属的供应商;
管理水平确定单元,用于根据参考隐私信息管理体系和隐私成熟度模型对所述供应商的隐私管理水平进行度量,得到隐私管理水平得分;
第一匹配单元,用于将参考软件安全开发生命周期与所述待测设备的实际软件安全开发生命 周期进行匹配,得到第一匹配结果;
第二匹配单元,用于将参考研发隐私保护设计流程与所述待测设备的实际研发隐私保护设计流程进行匹配,得到第二匹配结果;
研发水平确定单元,用于根据所述第一匹配结果和所述第二匹配结果得到研发设计隐私管控得分;
第二生成单元,用于根据所述隐私管理水平得分和所研发设计隐私管控得分,生成第二隐私度量结果。
其中,在本申请的一些实施例中,隐私管理模块304包括:
保护技术确定单元,用于若所述隐私保护度评分不满足评分阈值,则确定待测设备的隐私保护项对应的当前隐私保护技术;
保护技术变更单元,用于变更所述当前隐私保护技术,得到目标隐私保护技术;
度量结果更新单元,用于基于所述目标隐私保护技术重新度量得到更新后第一隐私度量结果;评分更新单元,用于将更新后第一隐私度量结果与第一得分权重相乘得到第一保护度得分,将第二隐私度量结果与第二得分权重相乘得到第二保护度得分,将第一保护度得分和第二保护度得分相加,得到更新后隐私保护度评分;
隐私管理单元,用于根据所述更新后隐私保护度评分对所述待测设备的隐私保护进行升级。其中,在本申请实施例首先由第一度量模块301对待测设备进行隐私保护水平度量,得到第一隐私度量结果,接着,由第二度量模块302对所述待测设备所属的供应商进行隐私管理水平度量,得到第二隐私度量结果,随后,由评分生成模块303根据所述第一隐私度量结果、所述第二隐私度量结果和预设的得分权重,生成所述待测设备的隐私保护度评分,然后,由隐私管理模块304根据所述隐私保护度评分对所述待测设备的隐私保护进行升级。
其中,本申请实施例通过对供应商的隐私管理水平进行度量得到第二隐私度量结果,并根据该第二隐私度量结果以及针对产品本身的隐私的第一隐私度量结果生成待测设备的隐私保护度评分,相较于传统的仅针对产品本身的隐私水平的评估方案,本申请实施例丰富了产品隐私保护的衡量维度,提升产品隐私保护衡量结果的准确性,便于实现对产品的隐私安全保护管理。
此外,本申请还提供一种电子设备,如图7所示,其示出了本申请所涉及的电子设备的结构示意图,具体来讲:
该电子设备可以包括一个或者一个以上处理核心的处理器401、一个或一个以上计算机可读存储介质的存储器402、电源403和输入单元404等部件。本领域技术人员可以理解,图7中示出的电子设备结构并不构成对电子设备的限定,可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置。其中:
处理器401是该电子设备的控制中心,利用各种接口和线路连接整个电子设备的各个部分,通过运行或执行存储在存储器402内的软件程序和/或模块,以及调用存储在存储器402内的数据,执行电子设备的各种功能和处理数据。可选的,处理器401可包括一个或多个处理核心;优选的,处理器401可集成应用处理器和调制解调处理器,其中,应用处理器主要处理操作系统、对象界面和应用程序等,调制解调处理器主要处理无线通信。可以理解的是,上述调制解调处理器也可以不集成到处理器401中。
存储器402可用于存储软件程序以及模块,处理器401通过运行存储在存储器402的软件程序以及模块,从而执行各种功能应用以及设备隐私管理。存储器402可主要包括存储程序区和存储数据区,其中,存储程序区可存储操作系统、至少一个功能所需的应用程序(比如声音播放功能、图像播放功能等)等;存储数据区可存储根据电子设备的使用所创建的数据等。此外,存储器402可以包括高速随机存取存储器,还可以包括非易失性存储器,例如至少一个磁盘存储器件、闪存器件、或其他易失性固态存储器件。相应地,存储器402还可以 包括存储器控制器,以提供处理器401对存储器402的访问。
电子设备还包括给各个部件供电的电源403,优选的,电源403可以通过电源管理系统与处理器401逻辑相连,从而通过电源管理系统实现管理充电、放电、以及功耗管理等功能。电源403还可以包括一个或一个以上的直流或交流电源、再充电系统、电源故障检测电路、电源转换器或者逆变器、电源状态指示器等任意组件。
该电子设备还可包括输入单元404,该输入单元404可用于接收输入的数字或字符信息,以及产生与对象设置以及功能控制有关的键盘、鼠标、操作杆、光学或者轨迹球信号输入。尽管未示出,电子设备还可以包括显示单元等,在此不再赘述。具体在本实施例中,电子设备中的处理器401会按照如下的指令,将一个或一个以上的应用程序的进程对应的可执行文件加载到存储器402中,并由处理器401来运行存储在存储器402中的应用程序,从而实现本申请所提供的任一种设备隐私管理方法中的步骤。
对待测设备进行隐私保护水平度量,得到第一隐私度量结果,对所述待测设备所属的供应商进行隐私管理水平度量,得到第二隐私度量结果,根据所述第一隐私度量结果、所述第二隐私度量结果和预设的得分权重,生成所述待测设备的隐私保护度评分,根据所述隐私保护度评分对所述待测设备的隐私保护进行升级。其中,通过对供应商的隐私管理水平进行度量得到第二隐私度量结果,并根据该第二隐私度量结果以及针对产品本身的隐私的第一隐私度量结果生成待测设备的隐私保护度评分,相较于传统的仅针对产品本身的隐私水平的评估方案,本申请实施例丰富了产品隐私保护的衡量维度,提升产品隐私保护衡量结果的准确性,便于实现对产品的隐私安全保护管理。
本领域普通技术人员可以理解,上述实施例的各种方法中的全部或部分步骤可以通过指令来完成,或通过指令控制相关的硬件来完成,该指令可以存储于一计算机可读存储介质中,并由处理器进行加载和执行。
为此,本申请提供一种存储介质,该存储介质包括计算机可读存储介质,该计算机可读存储介质上存储有计算机程序,该计算机程序能够被处理器进行加载,以执行本申请所提供的任一种设备隐私管理方法中的步骤。
其中,该计算机可读存储介质可以包括:只读存储器(ROM,Read Only Memory)、随机存取记忆体(RAM,Random Access Memory)、磁盘或光盘等。
由于该计算机可读存储介质中所存储的指令,可以执行本申请所提供的任一种设备隐私管理方法中的步骤,因此,可以实现本申请所提供的任一种设备隐私管理方法所能实现的有益效果,详见前面的实施例,在此不再赘述。
以上对本申请所提供的一种设备隐私管理方法、装置、电子设备以及存储介质进行了详细介绍,本文中应用了具体个例对本发明的原理及实施方式进行了阐述,以上实施例的说明只是用于帮助理解本发明的方法及其核心思想;同时,对于本领域的技术人员,依据本发明的思想,在具体实施方式及应用范围上均会有改变之处,综上,本说明书内容不应理解为对本发明的限制。
其中,可以理解的是,在本申请的具体实施方式中,涉及到待测设备的配置数据(合规风险数据、适配法律数据、隐私安全保护技术、产品类型等),以及该待测设备对应的企业的相关信息(企业的名称、企业的隐私管理水平,包括管理隐私的水平和研发该设备的生命周期和相应的隐私设计流程)等相关的数据,当本申请以上实施例运用到具体产品或技术中时,需要获得用户许可或者同意,且相关数据的收集、使用和处理需要遵守相关国家和地区的相关法律法规和标准。

Claims (20)

  1. 一种设备隐私管理方法,其中,包括:
    对待测设备进行隐私保护水平度量,得到第一隐私度量结果;
    对所述待测设备所属的供应商进行隐私管理水平度量,得到第二隐私度量结果;
    根据所述第一隐私度量结果、所述第二隐私度量结果和预设的得分权重,生成所述待测设备的隐私保护度评分;
    根据所述隐私保护度评分对所述待测设备的隐私保护进行升级。
  2. 根据权利要求1所述的方法,其中,所述对待测设备进行隐私保护水平度量,得到第一隐私度量结果,包括:
    获取待测设备在隐私保护项的隐私安全得分;
    根据所述隐私保护项对应的得分子权重以及所述隐私保护项对应的所述隐私安全得分生成第一隐私度量结果;
    所述隐私保护项包括产品合规风险测试项、产品隐私安全保护技术测试项、产品适配法律测试项或产品隐私保护要求度测试项中的至少一种。
  3. 根据权利要求2所述的方法,其中,若所述隐私保护项为产品合规风险测试项,所述获取待测设备在隐私保护项的隐私安全得分,包括:
    配置合规风险测试用例;
    根据所述合规风险测试用例对待测设备进行测试,得到合规风险测试结果,所述合规风险测试结果对应一风险等级得分;
    计算各个合规风险测试用例对应的风险等级得分的平均值,得到平均风险等级得分;
    将所述平均风险等级得分作为所述待测设备在所述产品合规风险测试项的隐私安全得分。
  4. 根据权利要求2所述的方法,其中,若所述隐私保护项为产品隐私安全保护技术测试项,所述获取待测设备在隐私保护项的隐私安全得分,包括:
    确定待测设备支持的隐私安全保护技术项;
    针对每个隐私安全保护技术项,确定所述隐私安全保护技术项所应用的隐私安全保护技术的类型、强度以及数量;
    获取预设映射关系集合,所述预设映射关系集合包括预设的隐私安全保护技术的类型、强度以及数量和安全评分的映射关系;
    根据所述预设映射关系集合,根据所述隐私安全保护技术项应用的隐私安全保护技术的类型、强度或者数量确定安全评分;
    计算各个隐私安全保护技术项的安全评分的平均值,得到平均安全评分;
    将所述平均安全评分作为所述待测设备在所述产品隐私安全保护技术测试项的隐私安全得分。
  5. 根据权利要求2所述的方法,其中,若所述隐私保护项为产品适配法律测试项,所述获取待测设备在隐私保护项的隐私安全得分,包括:
    确定待测设备待上线的目标区域;
    确定所述目标区域所需满足的目标法律基线;
    根据所述待测设备当前满足的实际法律基线和所述目标法律基线,确定所述待测设备的隐私安全得分。
  6. 根据权利要求1所述的方法,其中,所述对所述待测设备所属的供应商进行隐私管理水平度量,得到第二隐私度量结果,包括:
    确定所述待测设备所属的供应商;
    根据参考隐私信息管理体系和隐私成熟度模型对所述供应商的隐私管理水平进行度量,得到隐私管理水平得分;
    将参考软件安全开发生命周期与所述待测设备的实际软件安全开发生命周期进行匹配,得到第一匹配结果;
    将参考研发隐私保护设计流程与所述待测设备的实际研发隐私保护设计流程进行匹配,得到第二匹配结果;
    根据所述第一匹配结果和所述第二匹配结果得到研发设计隐私管控得分;
    根据所述隐私管理水平得分和所研发设计隐私管控得分,生成第二隐私度量结果。
  7. 根据权利要求2所述的方法,其中,所述根据所述隐私保护度评分对所述待测设备的隐私保护进行升级,包括:
    若所述隐私保护度评分不满足评分阈值,则确定待测设备的隐私保护项对应的当前隐私保护技术;
    变更所述当前隐私保护技术,得到目标隐私保护技术;
    基于所述目标隐私保护技术重新度量得到更新后第一隐私度量结果;
    根据所述更新后第一隐私度量结果和所述第二隐私度量结果,得到更新后隐私保护度评分;
    根据所述更新后隐私保护度评分对所述待测设备的隐私保护进行升级。
  8. 根据权利要求7所述的方法,其中,所述根据所述更新后第一隐私度量结果和所述第二隐私度量结果,得到更新后隐私保护度评分,包括:
    将更新后第一隐私度量结果与第一得分权重相乘得到第一保护度得分;
    将第二隐私度量结果与第二得分权重相乘得到第二保护度得分;
    将第一保护度得分和第二保护度得分相加,得到更新后隐私保护度评分。
  9. 根据权利要求2所述的方法,其中,所述获取待测设备在隐私保护项的隐私安全得分,包括:
    确定待测设备的产品类型;
    根据该产品类型和映射关系,确定该待测设备对应的产品隐私保护要求度;
    将所述产品隐私保护要求度作为所述待测设备针对所述产品类型方面的隐私安全得分。
  10. 根据权利要求1所述的方法,其中,所述隐私保护水平是所述设备在使用时对用户数据的隐私保护水平,由所述设备在使用时所述设备的相关配置参数决定;
    所述隐私管理水平指所述供应商隐私保护的控制水平,其中,所述供应商为开发或者生产所述设备的企业。
  11. 根据权利要求1所述的方法,其中,所述预设的得分权重包括针对第一隐私度量结果的第一得分权重和针对所述第二隐私度量结果的第二得分权重,所述第一得分权重和所述第二得分权重分别包括50%。
  12. 根据权利要求4所述的方法,其中,所述隐私安全保护技术项包括数据加密、数据备份和回复、安全套接层协议传输数据、云端采用的安全产品、接口认证授权、数据脱敏、匿名算法、差分隐私中的至少一种。
  13. 根据权利要求6所述的方法,其中,所述根据所述第一匹配结果和所述第二匹配结果得到研发设计隐私管控得分,包括:
    将所述第一匹配结果对应的第一百分比和所述第二匹配结果对应的第二百分比,按照权重数据运算后得到研发设计隐私管控得分。
  14. 根据权利要求6所述的方法,其中,所述参考隐私信息管理体系包括ISO27701,所述隐私成熟度模型包括ISC2、NIST、GAPP、CNIL中的至少一种。
  15. 一种设备隐私管理装置,其中,包括:
    第一度量模块,用于对待测设备进行隐私保护水平度量,得到第一隐私度量结果;
    第二度量模块,用于对所述待测设备所属的供应商进行隐私管理水平度量,得到第二隐私度量结果;
    评分生成模块,用于根据所述第一隐私度量结果、所述第二隐私度量结果和预设的得分权重,生成所述待测设备的隐私保护度评分;
    隐私管理模块,用于根据所述隐私保护度评分对所述待测设备的隐私保护进行升级。
  16. 根据权利要求15所述的装置,其中,所述第一度量模块包括:
    获取单元,用于获取待测设备在隐私保护项的隐私安全得分;
    第一生成单元,用于根据所述隐私保护项对应的得分子权重以及所述隐私保护项对应的所述隐私安全得分生成第一隐私度量结果;
    所述隐私保护项包括产品合规风险测试项、产品隐私安全保护技术测试项、产品适配法律测试项或产品隐私保护要求度测试项中的至少一种。
  17. 根据权利要求16所述的装置,其中,所述隐私保护项为产品合规风险测试项,所述获取单元包括:
    配置子单元,用于配置合规风险测试用例;
    测试子单元,用于根据所述合规风险测试用例对待测设备进行测试,得到合规风险测试结果,所述合规风险测试结果对应一风险等级得分;
    第一计算子单元,用于计算各个合规风险测试用例对应的风险等级得分的平均值,得到平均风险等级得分;
    第一生成子单元,用于将所述平均风险等级得分作为所述待测设备在所述产品合规风险测试项的隐私安全得分。
  18. 根据权利要求16所述的装置,其中,所述隐私保护项为产品隐私安全保护技术测试项,所述获取单元包括:
    第一确定子单元,用于确定待测设备支持的隐私安全保护技术项;
    第二确定子单元,用于针对每个隐私安全保护技术项,确定所述隐私安全保护技术项所应用的隐私安全保护技术的类型、强度以及数量;
    获取子单元,用于获取预设映射关系集合,所述预设映射关系集合包括预设的隐私安全保护技术的类型、强度以及数量和安全评分的映射关系;
    第三确定子单元,用于根据所述预设映射关系集合,根据所述隐私安全保护技术项应用的隐私安全保护技术的类型、强度或者数量确定安全评分;
    第二计算子单元,用于计算各个隐私安全保护技术项的安全评分的平均值,得到平均安全评分;
    第二生成子单元,用于将所述平均安全评分作为所述待测设备在所述产品隐私安全保护技术测试项的隐私安全得分。
  19. 一种电子设备,其中,所述电子设备包括存储器、处理器及存储在所述存储器中并可在所述处理器上运行的计算机程序,所述处理器执行所述计算机程序时实现如权利要求1-14任一项所述设备隐私管理方法的步骤。
  20. 一种计算机可读存储介质,其中,所述计算机可读存储介质上存储有计算机程序,所述计算机程序被处理器执行时实现如权利要求1-14任一项所述设备隐私管理方法的步骤。
PCT/CN2024/095704 2023-06-14 2024-05-28 设备隐私管理方法、装置、电子设备及存储介质 Ceased WO2024255583A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
EP24822535.1A EP4730179A1 (en) 2023-06-14 2024-05-28 Device privacy management method and apparatus, electronic device, and storage medium

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202310707303.6A CN117407892A (zh) 2023-06-14 2023-06-14 设备隐私管理方法、装置、电子设备及存储介质
CN202310707303.6 2023-06-14

Publications (1)

Publication Number Publication Date
WO2024255583A1 true WO2024255583A1 (zh) 2024-12-19

Family

ID=89496798

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2024/095704 Ceased WO2024255583A1 (zh) 2023-06-14 2024-05-28 设备隐私管理方法、装置、电子设备及存储介质

Country Status (3)

Country Link
EP (1) EP4730179A1 (zh)
CN (1) CN117407892A (zh)
WO (1) WO2024255583A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN120068156A (zh) * 2025-04-18 2025-05-30 南京霈玥科技有限公司 一种眼科临床医疗数据管理与共享系统

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN117407892A (zh) * 2023-06-14 2024-01-16 深圳Tcl新技术有限公司 设备隐私管理方法、装置、电子设备及存储介质
CN118364514A (zh) * 2024-06-20 2024-07-19 广州信安数据有限公司 App敏感行为自动化合规检测方法和计算机程序产品

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20140173684A1 (en) * 2012-12-14 2014-06-19 Nymity, Inc. Methods, software, and devices for automatically scoring privacy protection measures
CN109716345A (zh) * 2016-04-29 2019-05-03 普威达有限公司 计算机实现的隐私工程系统和方法
CN111400747A (zh) * 2020-02-24 2020-07-10 西安交通大学 一种基于轨迹隐私保护的度量方法
CN113221161A (zh) * 2021-04-22 2021-08-06 朱洪东 在线教育大数据场景下的信息防护方法及可读存储介质
CN114357509A (zh) * 2021-12-28 2022-04-15 深圳Tcl新技术有限公司 隐私安全评估方法、装置、计算机设备和可读存储介质
CN117407892A (zh) * 2023-06-14 2024-01-16 深圳Tcl新技术有限公司 设备隐私管理方法、装置、电子设备及存储介质

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20140173684A1 (en) * 2012-12-14 2014-06-19 Nymity, Inc. Methods, software, and devices for automatically scoring privacy protection measures
CN109716345A (zh) * 2016-04-29 2019-05-03 普威达有限公司 计算机实现的隐私工程系统和方法
CN111400747A (zh) * 2020-02-24 2020-07-10 西安交通大学 一种基于轨迹隐私保护的度量方法
CN113221161A (zh) * 2021-04-22 2021-08-06 朱洪东 在线教育大数据场景下的信息防护方法及可读存储介质
CN114357509A (zh) * 2021-12-28 2022-04-15 深圳Tcl新技术有限公司 隐私安全评估方法、装置、计算机设备和可读存储介质
CN117407892A (zh) * 2023-06-14 2024-01-16 深圳Tcl新技术有限公司 设备隐私管理方法、装置、电子设备及存储介质

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
ANONYMOUS: "Huawei releases its first white paper on privacy protection and governance - Huawei Privacy Compliance 17/27 Framework", HUAWEI TECHNOLOGIES CO., LTD., 9 November 2022 (2022-11-09), XP093248073, Retrieved from the Internet <URL:https://www.huawei.com/cn/news/2022/11/huawei-privacy-protection-whitepaper> *

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN120068156A (zh) * 2025-04-18 2025-05-30 南京霈玥科技有限公司 一种眼科临床医疗数据管理与共享系统

Also Published As

Publication number Publication date
CN117407892A (zh) 2024-01-16
EP4730179A1 (en) 2026-04-22

Similar Documents

Publication Publication Date Title
WO2024255583A1 (zh) 设备隐私管理方法、装置、电子设备及存储介质
CN108255653B (zh) 一种产品的测试方法及其终端
CN110889710B (zh) 设备信息管理方法、服务器及存储介质
US20230162203A1 (en) Emissions records ledger for correlated emission analytics
CN108573381A (zh) 数据处理方法以及装置
JP7795744B2 (ja) 管理装置
CN107944731A (zh) 典型工程造价模板的建立方法及装置
CN111537884A (zh) 获取动力电池寿命数据的方法、装置、计算机设备及介质
CN110322143A (zh) 模型实体化管理方法、装置、设备及计算机存储介质
CN112907220A (zh) 一种工程造价的系统、方法及装置
WO2021068591A1 (zh) 基于区块链的日产日清核算方法、装置、设备及存储介质
CN118521359A (zh) 计费方法和装置
CN108073699B (zh) 大数据聚合分析方法及装置
CN115525897A (zh) 终端设备的系统检测方法、装置、电子装置和存储介质
CN115587701A (zh) 一种企业风险评估处理方法、装置及电子设备
CN115080412A (zh) 软件更新质量评估方法、装置、设备及计算机存储介质
WO2019227320A1 (zh) 维修设备管理方法、服务器和计算机可读存储介质
CN118822689A (zh) 设备管控方法、装置、电子设备及计算机可读存储介质
CN107832080A (zh) 一种软件演化环境下基于结点介数的构件重要性度量方法
CN111625753A (zh) 用于计算直燃机能效参数的方法、装置、设备及存储介质
CN118172124A (zh) 交易参数的确定方法、装置、可读存储介质及电子设备
CN114328487A (zh) 一种质检评估方法及装置
CN117829592B (zh) 基于可配置模型的风险评估方法和装置
CN112116439A (zh) 一种清结算测试方法、装置、终端及存储介质
CN111222739A (zh) 核电站的任务分配方法及核电站的任务分配系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 24822535

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2024822535

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2024822535

Country of ref document: EP

Effective date: 20260114

ENP Entry into the national phase

Ref document number: 2024822535

Country of ref document: EP

Effective date: 20260114

ENP Entry into the national phase

Ref document number: 2024822535

Country of ref document: EP

Effective date: 20260114

ENP Entry into the national phase

Ref document number: 2024822535

Country of ref document: EP

Effective date: 20260114

WWP Wipo information: published in national office

Ref document number: 2024822535

Country of ref document: EP