Aiming at the problem of low evaluation efficiency caused by complex and large number of policies in the complex network, in view of the characteristics of a label are flexible, lightweight, and efficient policy matching, we propose a label-based data flow control mechanism. We build the system model and design the label description method around the operation of data. Our model covers a variety of control models based on roles, relationships and attributes, which can be adapted to more application scenarios. The label only includes the attribute rules necessary for flow control and allows users to customize it according to security requirements, so as to achieve the purposes of lightweight, fine-grained, and high flexibility. The label constraint rules are formulated and the corresponding algorithm for generating a visitor's permission set is proposed. The selection of the attribute rule type is added to the label, which makes the policy evaluation more efficient. Finally, performance analysis and use case analysis illustrate the availability and effectiveness of our mechanism.