Basin information security architecture construction method and device, computer equipment and product
By building a watershed information security architecture and utilizing hierarchical relationships and permission control, the challenges of data security in the watershed information management system are resolved, the confidentiality, integrity, and availability of data are improved, and the business needs of different sub-platforms are adapted.
Patent Information
- Application Number
- CN202510039740.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-10
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-01-10
AI Technical Summary
In the existing watershed information management system, the security architecture cannot effectively guarantee the confidentiality, integrity and availability of data. Especially when the scale and complexity of watershed informatization construction increase, data security faces challenges.
Build a river basin information security architecture that includes a security policy management layer, a security policy control layer, and a security policy execution layer. Manage data transmission through hierarchical relationships and divide it into river basin information production areas, operation areas, and Internet of Things areas. Restrict data transmission permissions between different areas and conduct security management in combination with identity policies and control policies.
It improves the security and transmission security of watershed information data, adapts to the business needs of different watershed information sub-platforms, and enhances the security and applicability of network policy management.
Smart Images

Figure CN119484154B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of watershed information management technology, and in particular to methods, devices, computer equipment and products for constructing a watershed information security architecture. Background Art
[0002] Security Architecture is a collection of security policies, technologies, and controls designed and implemented in an information system or network to protect assets from unauthorized access, use, disclosure, disruption, or modification.
[0003] In the watershed information model, the security architecture is the guarantee for watershed applications and can provide security for business architecture, data architecture, application architecture and technical architecture.
[0004] The scale, relevance, and complexity of river basin informatization are increasing. River basin data covers multiple areas, including water resource allocation, water pollution control, and flood prevention and disaster reduction. This includes data of varying levels of confidentiality. The security of river basin information management systems directly impacts data security. An inappropriate security architecture cannot guarantee the confidentiality, integrity, availability, and security of river basin information data. Summary of the Invention
[0005] In view of this, the present invention provides a method, device, computer equipment and product for constructing a watershed information security architecture to improve the security of watershed information data.
[0006] In the first aspect, the present invention provides a method for constructing a watershed information security architecture, which includes: constructing a security policy management layer, a security policy control layer and a security policy execution layer based on the watershed information network, constructing a watershed information production area, a watershed information operation area and a watershed information Internet of Things area based on watershed information data, and transmitting data in the watershed information production area, the watershed information operation area and the watershed information Internet of Things area in a unidirectional manner in the security policy management layer, the security policy control layer and the security policy execution layer according to the transmission authority; constructing a watershed information security policy by using the security policy management layer, applying the watershed information security policy to the watershed information platform, and sending the watershed information security policy to the security policy control layer; generating a watershed information security sub-policy based on the watershed information security policy by using the security policy control layer, applying the watershed information security sub-policy to the watershed information sub-platform, and sending the watershed information security sub-policy to the security policy execution layer; and executing the watershed information security sub-policy by using the security policy execution layer.
[0007] In this implementation, a watershed information security architecture including a security policy management layer, a security policy control layer, and a security policy execution layer is constructed. The hierarchical relationship is used from top to bottom, and the security policy control layer is controlled by the security policy management layer, and the security policy execution layer is controlled by the security policy control layer to ensure policy management security. At the same time, a general security policy is set for the watershed information platform, and corresponding security sub-policies are set according to different watershed information sub-platforms. This can ensure data security between different watershed information sub-platforms and further improve network policy management security. The security architecture of this application can be migrated and customized to increase the scope of adaptability while ensuring security. On the basis of network security, data is divided into watershed information production areas, watershed information operation areas, and watershed information Internet of Things areas. By limiting the data transmission permissions in different areas, the confidentiality of data and the security of data transmission are guaranteed.
[0008] In an optional implementation, the watershed information security policy includes an overall security policy and a meta-security policy, and the watershed information security policy is sent down to the security policy control layer, including: using the overall security policy to send the meta-security policy down to the corresponding watershed information sub-platform in the security policy control layer.
[0009] In an optional implementation, the security policy control layer is used to generate a watershed information security sub-policy based on the watershed information security policy, and the watershed information security sub-policy is applied to the watershed information sub-platform, including: using the security policy control layer to generate a watershed information security sub-policy in combination with the business and meta-security policies of the watershed information sub-platform; and applying the watershed information security sub-policy to the corresponding watershed information sub-platform.
[0010] In this implementation, the security policy is divided into an overall security policy and a meta-security policy. The overall security policy distributes the meta-security policy according to different river basin information sub-platforms to ensure the security of policy distribution. For different river basin information sub-platforms, security sub-policies are generated according to business adaptability, which can generate policies that meet the business security requirements of the river basin information sub-platform, ensure the internal data security of each river basin information sub-platform and the data security between different river basin information sub-platforms, and further improve the security of policy management. At the same time, the security policy control layer of this application allows for construction and expansion based on the meta-network security policy according to the application system and business, thereby improving applicability and scalability.
[0011] In an optional implementation, the meta-security policy includes an identity policy and a control policy, wherein the identity policy is used for identity management and identity authentication of the watershed information sub-platform; the control policy is used to set access rights based on the user's security level on the watershed information sub-platform and to authenticate requests to access the watershed information sub-platform.
[0012] In this implementation, identity strategies and control strategies are used to ensure user access security of the watershed information sub-platform.
[0013] In an optional embodiment, the watershed information production area includes a variety of watershed information production data, the watershed information operation area includes a variety of watershed information operation data, and the watershed information Internet of Things area includes a variety of watershed information Internet of Things data. The data in the watershed information production area, the watershed information operation area and the watershed information Internet of Things area are transmitted unidirectionally in the security policy management layer, the security policy control layer and the security policy execution layer according to the transmission authority, including: using the security policy execution layer to collect watershed information production data, and processing the watershed information production data and then transmitting it to the security policy control layer; using the security policy control layer to collect watershed information operation data, and processing the watershed information operation data, and transmitting the processed watershed information production data and / or watershed information operation data to the security policy management layer; using the security policy management layer to collect watershed information management data.
[0014] In this implementation method, by restricting the transmission method between the watershed information production area, the watershed information operation area and the watershed information Internet of Things area, it is ensured that data can only flow from the watershed information production area to the watershed information operation area, and from the watershed information operation area to the watershed information Internet of Things area, ensuring that the underlying data cannot be widely disseminated, thereby improving data management security.
[0015] In an optional embodiment, constructing a watershed information production area, a watershed information operation area and a watershed information Internet of Things area based on watershed information data includes: obtaining a business architecture for watershed information data; dividing the watershed information data into watershed characteristic data, watershed element data and watershed object data according to the watershed vision, business domain and business process in the business architecture, each watershed object data corresponds to multiple watershed element data, and each watershed element data corresponds to multiple watershed characteristic data; constructing a watershed information production area based on watershed characteristic data, constructing a watershed information operation production area based on watershed element data, and constructing a watershed information Internet of Things area based on watershed object data.
[0016] In this implementation method, by dividing the data into watershed characteristic data, watershed element data and watershed object data according to the hierarchy, the watershed characteristic data with the highest confidentiality is divided into the watershed information production area, the watershed element data with the second lowest confidentiality is divided into the watershed information operation and production area, and the watershed object data is divided into the watershed information Internet of Things area. Combined with the corresponding management level of each area, the security of the watershed data can be further guaranteed.
[0017] In the second aspect, the present invention provides a device for constructing a watershed information security architecture, which includes: a construction module, which is used to construct a security policy management layer, a security policy control layer and a security policy execution layer based on the watershed information network, and construct a watershed information production area, a watershed information operation area and a watershed information Internet of Things area based on the watershed information data. The data in the watershed information production area, the watershed information operation area and the watershed information Internet of Things area are transmitted unidirectionally in the security policy management layer, the security policy control layer and the security policy execution layer according to the transmission permission; a policy management module, which is used to use the security policy management layer to construct a watershed information security policy, apply the watershed information security policy to the watershed information platform, and send the watershed information security policy to the security policy control layer; a policy control module, which is used to use the security policy control layer to generate a watershed information security sub-policy based on the watershed information security policy, apply the watershed information security sub-policy to the watershed information sub-platform, and send the watershed information security sub-policy to the security policy execution layer; a policy execution module, which is used to use the security policy execution layer to execute the watershed information security sub-policy.
[0018] In the third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, computer instructions stored in the memory, and the processor executing the computer instructions to execute the method for constructing a watershed information security architecture according to the first aspect or any corresponding embodiment thereof.
[0019] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the method for constructing a watershed information security architecture according to the first aspect or any corresponding embodiment thereof.
[0020] In a fifth aspect, the present invention provides a computer program product comprising computer instructions, the computer instructions being used to enable a computer to execute the method for constructing a watershed information security architecture according to the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0022] Figure 1 is a flow chart of a method for constructing a watershed information security architecture according to an embodiment of the present invention;
[0023] Figure 2is a schematic diagram of a watershed information security architecture according to an embodiment of the present invention;
[0024] Figure 3 is a flowchart of another method for constructing a watershed information security architecture according to an embodiment of the present invention;
[0025] Figure 4 is a schematic diagram of another watershed information security architecture according to an embodiment of the present invention;
[0026] Figure 5 is a structural block diagram of a device for constructing a watershed information security architecture according to an embodiment of the present invention;
[0027] Figure 6 Schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0028] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of the present invention.
[0029] The watershed information model of this application includes business architecture, data architecture, application architecture, technical architecture, security architecture, etc. The security architecture is the guarantee of watershed applications and can provide security for business architecture, data architecture, application architecture and technical architecture.
[0030] Therefore, a reasonable security architecture can ensure the confidentiality, integrity, availability and security of watershed information data.
[0031] According to an embodiment of the present invention, an embodiment of a method for constructing a watershed information security architecture is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0032] In this embodiment, a method for constructing a watershed information security architecture is provided. Figure 1 This is a flow chart of a method for constructing a watershed information security architecture according to an embodiment of the present invention. It should be noted that if there are substantially the same results, this embodiment does not use Figure 1 The process sequence shown is limited. Figure 1 As shown, the process includes the following steps:
[0033] Step S101: construct a security policy management layer, a security policy control layer, and a security policy execution layer based on the watershed information network, and construct a watershed information production area, a watershed information operation area, and a watershed information Internet of Things area based on the watershed information data.
[0034] This application divides the river basin information network into security policy management layer, security policy control layer and security policy execution layer from the perspective of policy management.
[0035] Among them, the management relationship between the security policy management layer, the security policy control layer and the security policy execution layer is "total-division-total-division" management, the security policy control layer manages the security policy execution layer, and the security policy execution layer manages the security policy execution layer.
[0036] On the basis of strategy zoning, the river basin information production area, river basin information operation area and river basin information Internet of Things area are constructed based on the river basin information data. The data in the river basin information production area, river basin information operation area and river basin information Internet of Things area are transmitted one-way in the security policy management layer, security policy control layer and security policy execution layer according to the transmission permissions.
[0037] Specifically, see Figure 2 , Figure 2 is a schematic diagram of a watershed information security architecture according to an embodiment of the present invention. Figure 2 As shown, the security policy management layer distributes policies to the security policy control layer. When security threats are detected, the layer blocks attacks. The security policy control layer distributes policies to the security policy execution layer. When security threats are detected, the layer blocks attacks. The security policy execution layer transmits data to the security policy control layer, which in turn transmits data to the security policy management layer.
[0038] Step S102: construct a watershed information security policy using the security policy management layer, apply the watershed information security policy to the watershed information platform, and send the watershed information security policy to the security policy control layer.
[0039] Use the security policy management layer to analyze the current watershed information data, and specify the watershed information security policy based on the analysis results. Apply the watershed information security policy to the watershed information platform, use the watershed information platform to distribute and link the policy, and send the watershed information security policy to the security policy control layer.
[0040] Step S103, using the security policy control layer to generate a watershed information security sub-policy based on the watershed information security policy, applying the watershed information security sub-policy to the watershed information sub-platform, and sending the watershed information security sub-policy to the security policy execution layer.
[0041] It is understandable that different watershed information sub-platforms process different watershed information services, and the corresponding data access rights, data management methods, etc. are all different. This application will adaptively adjust each security policy in the corresponding watershed information sub-platform.
[0042] Specifically, based on the corresponding policy requirements of each watershed information sub-platform, the watershed information security policy is adjusted to generate a watershed information security sub-policy, the watershed information security sub-policy is applied to the corresponding watershed information sub-platform, and the watershed information security sub-policy is sent to the corresponding watershed information sub-platform.
[0043] Step S104: Utilize the security policy execution layer to execute the watershed information security sub-strategy.
[0044] The security policy execution layer is the data source for the security policy control layer and the security policy management layer. The security policy execution layer connects various perception front-ends and terminal devices, and controls the secure access and data collection of each terminal device according to the security sub-policy.
[0045] The method for constructing a watershed information security architecture provided in this embodiment constructs a watershed information security architecture including a security policy management layer, a security policy control layer, and a security policy execution layer. The hierarchical relationship is used from top to bottom, and the security policy management layer controls the security policy control layer, and the security policy control layer controls the security policy execution layer to ensure policy management security. At the same time, an overall security policy is set for the watershed information platform, and corresponding security sub-policies are set according to different watershed information sub-platforms, which can ensure data security between different watershed information sub-platforms and further improve network policy management security. The security architecture of this application can be migrated and customized to increase the scope of adaptability while ensuring security. On the basis of network security, data is divided into watershed information production areas, watershed information operation areas, and watershed information Internet of Things areas. By limiting the data transmission permissions within different areas, the confidentiality of data and the security of data transmission are guaranteed.
[0046] In this embodiment, a method for constructing a watershed information security architecture is provided. Figure 3 This is a flowchart of another method for constructing a watershed information security architecture according to an embodiment of the present invention. It should be noted that if there are substantially the same results, this embodiment does not use Figure 3 The process sequence shown is limited. Figure 3 As shown, the process includes the following steps:
[0047] Step S301: construct a security policy management layer, a security policy control layer, and a security policy execution layer based on the watershed information network.
[0048] Specifically, see Figure 4 , Figure 4 is another schematic diagram of a watershed information security architecture according to an embodiment of the present invention.Figure 4 As shown, the security policy management layer operates on the watershed information platform, the security policy control layer operates on the watershed information sub-platform, and the security policy execution layer operates on various sensing front-ends and terminal devices. The security policy management layer deploys policies on the watershed information platform and distributes them to the watershed information sub-platform of the security policy control layer. When security threats are present, attacks are blocked. The security policy control layer deploys policies on the watershed information sub-platform and distributes them to the security policy execution layer. When security threats are present, attacks are blocked. The security policy execution layer uses collection devices to collect basic data and transmits the basic data to the multiple watershed information sub-platforms of the security policy control layer. Each watershed information sub-platform collects data from the corresponding sub-platform and transmits it to the watershed information platform of the security policy management layer.
[0049] Step S302: construct a watershed information security policy using the security policy management layer, apply the watershed information security policy to the watershed information platform, and send the watershed information security policy to the security policy control layer.
[0050] Specifically, the above step S302 includes:
[0051] Step S3021: Use the security policy management layer to construct a watershed information security policy, and apply the watershed information security policy to the watershed information platform.
[0052] See also Figure 4 , use the security policy management layer to build a situational awareness system from factor perception to situation understanding to situation prediction, and build a watershed information security model based on the situational awareness system, and use the security model to determine the corresponding watershed information security strategy.
[0053] Specifically, basic data and information about the watershed are acquired through various sensors, monitoring equipment, or information sources to form a basic understanding of the watershed. Based on this elemental perception, a comprehensive scenario description is constructed through comprehensive analysis of the watershed information data, revealing the inherent connections and development trends within the watershed information. Based on this existing situational understanding and historical data, inferences are made about possible future watershed information scenarios. Based on this, a watershed information security model is constructed, and preventive measures or optimization strategies are formulated based on this security model.
[0054] Furthermore, the watershed information security policy is applied to the watershed information platform, and the watershed information platform is used for policy distribution and linkage processing. Among them, policy distribution is used to distribute security policies to the security policy control layer, and linkage processing is used to link multiple watershed information sub-platforms of the security policy control layer.
[0055] Among them, the watershed information security strategy is the basic security library of the watershed information platform, which includes the overall security strategy and meta-security strategy.
[0056] Step S3022: Use the overall security policy to send the meta-security policy to the corresponding watershed information sub-platform in the security policy control layer.
[0057] Among them, the overall security strategy is responsible for issuing the meta-security strategy of the river basin information platform to each river basin information sub-platform, and supports each river basin information sub-platform to establish each river basin security sub-strategy based on the meta-security strategy.
[0058] For example, the basin information sub-platforms include the immigration management platform, the hydrological and sedimentation platform, and the meteorological and water regime platform. Based on the overall security strategy, the basin information master platform determines the corresponding meta-security policies for the immigration management platform, the hydrological and sedimentation platform, and the meteorological and water regime platform, and distributes these meta-security policies to the corresponding sub-platforms.
[0059] Furthermore, the meta-security policy includes identity policy and control policy.
[0060] Specifically, identity strategies are used for identity management and authentication of the watershed information sub-platform.
[0061] Illustratively, identity policies include user management, organizational management, user identity verification, user token management, application token management, and the like.
[0062] Specifically, the control policy is used to set access permissions based on the user's security level on the watershed information sub-platform and to authenticate requests to access the watershed information sub-platform.
[0063] For example, the control policy sets user access rights. When a user accesses the data service of the watershed information sub-platform, the user request is dynamically and finely authenticated; when the user security level changes, the user's access rights are updated in a timely manner.
[0064] In this implementation, identity strategies and control strategies are used to ensure user access security of the watershed information sub-platform.
[0065] Step S303: Use the security policy control layer to generate a watershed information security sub-policy based on the watershed information security policy, apply the watershed information security sub-policy to the watershed information sub-platform, and send the watershed information security sub-policy to the security policy execution layer.
[0066] Specifically, the above step S303 includes:
[0067] Step S3031: Generate a watershed information security sub-policy by utilizing the security policy control layer and combining the business and meta-security policies of the watershed information sub-platform.
[0068] It is understandable that different watershed information sub-platforms process different watershed information services, and the corresponding data access rights, data management methods, etc. are all different. This application will adaptively adjust each security policy in the corresponding watershed information sub-platform.
[0069] Specifically, the business of each watershed information sub-platform is obtained, the meta-security strategy is adaptively adjusted according to business needs, and the watershed information security sub-strategy of each watershed information sub-platform is constructed.
[0070] For example, for the immigration management platform, security sub-policies are adjusted based on user management, organizational management, user identity verification, user token management, application token management, and authentication methods to generate a corresponding immigration management platform security policy. Similarly, a hydrological and sedimentation platform security policy is generated for the hydrological and sedimentation platform, and a meteorological and water regime platform security policy is generated for the meteorological and water regime platform.
[0071] Step S3032: Apply the watershed information security sub-strategy to the corresponding watershed information sub-platform.
[0072] For example, the immigration management platform security policy is applied to the immigration management platform to perform immigration management identity management and identity authentication; the hydrological and sediment platform security policy is applied to the hydrological and sediment platform to perform hydrological and sediment identity management and identity authentication; the meteorological and water situation platform security policy is applied to the meteorological and water situation platform to perform meteorological and water situation identity management and identity authentication.
[0073] In this implementation, the security policy is divided into an overall security policy and a meta-security policy. The overall security policy distributes the meta-security policy according to different river basin information sub-platforms to ensure the security of policy distribution. For different river basin information sub-platforms, security sub-policies are generated according to business adaptability, which can generate policies that meet the business security requirements of the river basin information sub-platform, ensure the internal data security of each river basin information sub-platform and the data security between different river basin information sub-platforms, and further improve the security of policy management. At the same time, the security policy control layer of this application allows for construction and expansion based on the meta-network security policy according to the application system and business, thereby improving applicability and scalability.
[0074] Step S304: Utilize the security policy execution layer to execute the watershed information security sub-strategy.
[0075] The security policy execution layer is the data source for the security policy control layer and the security policy management layer. The security policy execution layer connects various perception front-ends and terminal devices, and controls the secure access and data collection of each terminal device according to the security sub-policy.
[0076] Step S305: construct a watershed information production area, a watershed information operation area, and a watershed information Internet of Things area based on the watershed information data.
[0077] Specifically, the above step S305 includes:
[0078] Step S3051, obtaining the business architecture of the watershed information data.
[0079] Obtain the watershed vision, business domain, and business processes of the business architecture for watershed information data.
[0080] Step S3052: divide the watershed information data into watershed feature data, watershed element data and watershed object data according to the watershed vision, business domain and business process in the business architecture.
[0081] The data characteristics of the watershed information data are determined based on the watershed vision, business domain and business process in the business architecture. Combined with the spatial position, spatial relationship and time relationship, the watershed information data is modeled according to "feature-element-object" and divided into watershed feature data, watershed element data and watershed object data.
[0082] Among them, the watershed vision is used to clarify the research objectives of watershed information, the business domain is used to clarify resource allocation and department division, and the business process is used for specific business nodes.
[0083] Watershed object data defines the fundamental objects of watershed information. Each watershed object data corresponds to multiple watershed feature data. Watershed feature data defines the fundamental elements of watershed information. Each watershed feature data corresponds to multiple watershed characteristic data. Watershed characteristic data defines the fundamental characteristics of watershed information. Each watershed object class has corresponding attributes, behaviors, and rules, and data connections exist between each object class.
[0084] Specifically, the watershed information data describing natural objects and socio-economic objects are divided into watershed object data.
[0085] For example, natural objects mainly include rivers, mountains, oceans, etc., and socio-economic objects include humans, various industrial activities, agricultural activities, commercial activities, production activities, etc.
[0086] Specifically, the watershed information data describing the natural elements and socio-economic elements contained in the watershed object is divided into watershed element data.
[0087] For example, natural elements are elements that represent the natural form of the earth's surface, such as geology, geophysics, topography, landforms, hydrology, meteorology, climate, soil quality, vegetation, animals, natural disasters, etc.; socio-economic elements are elements formed by human beings transforming nature in production activities, such as settlements, transportation networks, administrative boundaries, population, history, culture, enterprises and institutions, industrial and agricultural output value, commerce, trade, communications, electricity, disease and prevention, and tourist facilities.
[0088] Specifically, the watershed information data describing the natural characteristics and socio-economic characteristics of watershed element attributes are divided into watershed characteristic data.
[0089] For example, natural characteristics mainly describe the natural characteristics within the basin, which refer to the attributes of natural elements, such as runoff, sediment content, flood season, freezing period, water self-purification capacity, presence or absence of ice floods, flow rate and water level, etc.; socio-economic characteristics mainly describe the socio-economic characteristics within the basin, which refer to the attributes of socio-economic elements, population attributes, such as birth rate, death rate, number, gender ratio, etc., and road attributes, such as location, length and width, type, pavement material, usage function, maintenance status, etc.
[0090] Specifically, in the "feature-element-object" model, relationships between objects or between two different feature classes are defined. For example, the relationship between rivers and administrative divisions (i.e., river section A belongs to province A) and the relationship between immigrants and their destinations are examples.
[0091] Specifically, in the "feature-element-object" model, constraints are imposed on the values of elements and objects. For example, a specific person must belong to a certain administrative division.
[0092] Step S3053: construct a watershed information production area based on the watershed characteristic data, construct a watershed information operation and production area based on the watershed element data, and construct a watershed information Internet of Things area based on the watershed object data.
[0093] The river basin information production area includes a variety of river basin information production data, the river basin information operation area includes a variety of river basin information operation data, and the river basin information Internet of Things area includes a variety of river basin information Internet of Things data.
[0094] In one implementation, the watershed characteristic data is used as the watershed information production data, the watershed element data is used as the watershed information operation data, and the watershed object data is used as the watershed information Internet of Things data.
[0095] In another implementation, the basin information production area includes data describing the natural characteristics of the basin, such as river topography data and meteorological station data within the basin; socioeconomic data on all power production within the basin; and basin-specific data on socioeconomic objects related to production operations, such as power production data. The basin information operation area includes basin-specific element data on socioeconomic objects such as the company's operating conditions, population activity, industrial and agricultural conditions, and basin-related commercial activities for each company managing the basin; as well as basin-specific element data on natural objects that affect the company's cascade scheduling within the basin.
[0096] Furthermore, data within the river basin information production area, river basin information operation area and river basin information Internet of Things area are transmitted unidirectionally according to transmission permissions.
[0097] In one implementation, the security policy execution layer is used to collect watershed information production data, and the watershed information production data is processed and then transmitted to the security policy control layer.
[0098] Specifically, the data transmission of watershed information production data is limited according to the confidentiality level. Watershed information production data is only allowed to be transmitted to the watershed information operation area and the watershed information Internet of Things area after processing. If the watershed information operation area and the watershed information Internet of Things area want to transmit data in the reverse direction, they need to go through the reverse isolation device. Direct transmission and instruction issuance are not allowed.
[0099] In one implementation, the security policy control layer is used to collect watershed information operation data, and the watershed information operation data is processed, and the processed watershed information production data and / or watershed information operation data is transmitted to the security policy management layer.
[0100] Specifically, data from the security policy control layer can be directly transmitted to the river basin IoT area, but the river basin IoT area is not allowed to directly transmit data to this area or issue instructions.
[0101] In one implementation, the security policy management layer is used to collect watershed information management data.
[0102] Specifically, the river basin IoT region is a region for extensive information transmission within the river basin information, covering the entire river basin information domain. The data generated in this area, except for the river basin information management data specified by the confidentiality level, can be widely disseminated within the river basin IoT region.
[0103] This embodiment provides a method for constructing a watershed information security architecture. In this implementation, by restricting the transmission methods between the watershed information production area, the watershed information operation area, and the watershed information IoT area, data is ensured to flow only from the watershed information production area to the watershed information operation area, and from the watershed information operation area to the watershed information IoT area. This ensures that the underlying data cannot be widely disseminated, thereby improving data management security. Data is divided into watershed characteristic data, watershed element data, and watershed object data according to the hierarchy. This ensures that the watershed characteristic data with the highest confidentiality is divided into the watershed information production area, the watershed element data with the second highest confidentiality is divided into the watershed information operation production area, and the watershed object data is divided into the watershed information IoT area. Combined with the corresponding management level of each area, the security of watershed data can be further guaranteed.
[0104] In this embodiment, a device for constructing a watershed information security architecture is also provided, which is used to implement the above-mentioned embodiments and preferred implementation methods. The details that have been explained will not be repeated here. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware, is also possible and conceivable.
[0105] This embodiment provides a device for constructing a watershed information security architecture. Figure 5 As shown, Figure 5 2 is a block diagram of a device for constructing a watershed information security architecture according to an embodiment of the present invention. The device for constructing a watershed information security architecture includes:
[0106] Construction module 501 is used to construct a security policy management layer, a security policy control layer and a security policy execution layer based on the river basin information network, and to construct a river basin information production area, a river basin information operation area and a river basin information Internet of Things area based on the river basin information data. The data in the river basin information production area, the river basin information operation area and the river basin information Internet of Things area are transmitted unidirectionally among the security policy management layer, the security policy control layer and the security policy execution layer according to the transmission authority.
[0107] The policy management module 502 is used to construct the watershed information security policy by using the security policy management layer, apply the watershed information security policy to the watershed information platform, and send the watershed information security policy to the security policy control layer.
[0108] The policy control module 503 is used to generate a watershed information security sub-policy based on the watershed information security policy using the security policy control layer, apply the watershed information security sub-policy to the watershed information sub-platform, and send the watershed information security sub-policy to the security policy execution layer.
[0109] The policy execution module 504 is used to execute the watershed information security sub-policy using the security policy execution layer.
[0110] In some optional implementations, the policy management module 502 includes:
[0111] The sub-policy management unit is used to use the overall security policy to distribute the meta-security policy to the corresponding watershed information sub-platform within the security policy control layer. The meta-security policy includes identity policy and control policy. The identity policy is used for identity management and authentication on the watershed information sub-platform; the control policy is used to set access permissions based on the user's security level on the watershed information sub-platform and authenticate requests to access the watershed information sub-platform.
[0112] In some optional implementations, the policy control module 503 includes:
[0113] The generation unit is used to generate a watershed information security sub-policy by utilizing the security policy control layer in combination with the business and meta-security policies of the watershed information sub-platform.
[0114] The application unit is used to apply the watershed information security sub-strategy to the corresponding watershed information sub-platform.
[0115] In some optional implementations, the apparatus for constructing a watershed information security architecture further includes:
[0116] The data management module is used to construct the watershed information production area, watershed information operation area and watershed information Internet of Things area based on the watershed information data. The data in the watershed information production area, watershed information operation area and watershed information Internet of Things area are transmitted one-way according to the transmission authority.
[0117] In some optional implementations, the building block 501 includes:
[0118] The acquisition unit is used to obtain the business architecture of watershed information data.
[0119] The division unit is used to divide the watershed information data into watershed characteristic data, watershed element data and watershed object data according to the watershed vision, business domain and business process in the business architecture. Each watershed object data corresponds to multiple watershed element data, and each watershed element data corresponds to multiple watershed characteristic data.
[0120] Construct sub-units to build watershed information production areas based on watershed characteristic data, build watershed information operation and production areas based on watershed element data, and build watershed information Internet of Things areas based on watershed object data.
[0121] In some optional implementations, the building block 501 includes:
[0122] The first transmission unit is used to collect watershed information production data using the security policy execution layer, and transmit the watershed information production data to the security policy control layer after processing the data.
[0123] The second transmission unit is used to collect watershed information operation data using the security policy control layer, process the watershed information operation data, and transmit the processed watershed information production data and / or watershed information operation data to the security policy management layer.
[0124] The third transmission unit is used to collect watershed information management data using the security policy management layer.
[0125] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0126] The watershed information security architecture construction device in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.
[0127] The embodiment of the present invention also provides a computer device having the above Figure 5 The watershed information security architecture construction device shown.
[0128] See also Figure 6 , Figure 6 is a structural diagram of a computer device provided by an optional embodiment of the present invention, such as Figure 6 As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components utilize different buses to communicate with each other and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of a GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories. Equally, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 6 A processor 10 is taken as an example.
[0129] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.
[0130] The memory 20 stores instructions that can be executed by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.
[0131] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0132] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 20 may also include a combination of the above types of memory.
[0133] The computer device also includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 can be connected via a bus or other means. Figure 6 The bus connection is taken as an example.
[0134] The input device 30 can receive input digital or character information and generate key signal input related to user settings and function control of the computer device. Examples include a touch screen, keypad, mouse, trackpad, touchpad, pointing stick, one or more mouse buttons, trackball, joystick, etc. The output device 40 may include a display device, auxiliary lighting devices (e.g., LEDs), and tactile feedback devices (e.g., vibration motors). Such display devices include, but are not limited to, liquid crystal displays, light emitting diodes, monitors, and plasma displays. In some optional embodiments, the display device may be a touch screen.
[0135] The embodiments of the present application further provide a computer readable storage medium, and the method according to the embodiments of the present application can be implemented in hardware, firmware, or recorded in a storage medium, or stored in a remote storage medium or a non-transitory machine readable storage medium and downloaded to a local storage medium through network, so that the method described herein can be processed by such software on a storage medium using a general purpose computer, a special purpose processor, or programmable or special hardware. The storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk, or a solid state disk, etc. Further, the storage medium can also include a combination of the above-mentioned memories. It can be understood that the computer, the processor, the microprocessor controller, or the programmable hardware includes a storage component that can store or receive software or computer code, when the software or computer code is accessed and executed by the computer, the processor, or the hardware, the method shown in the above embodiments is implemented.
[0136] Part of the present application can be applied as a computer program product, for example, computer program instructions, when executed by a computer, the operation of the computer can invoke or provide the method and / or technical solutions according to the present application. Those skilled in the art should understand that the form of computer program instructions in computer readable medium includes but is not limited to source file, executable file, installation package file, etc. Correspondingly, the way of computer program instructions executed by computer includes but is not limited to: the computer directly executes the instructions, or the computer compiles the instructions and then executes the corresponding compiled program, or the computer reads and executes the instructions, or the computer reads and installs the instructions and then executes the corresponding installed program. Here, the computer readable medium can be any available computer readable storage medium or communication medium accessible to the computer.
[0137] Although the embodiments of the present application are described in conjunction with the accompanying drawings, various modifications and changes can be made by those skilled in the art without departing from the spirit and scope of the present application, and such modifications and changes fall within the scope defined by the appended claims.
Claims
1. A method for constructing a watershed information security architecture, characterized in that: The method comprises: Construct security policy management layer, security policy control layer and security policy execution layer based on the river basin information network; Acquire a business architecture for watershed information data; divide the watershed information data describing natural objects and socio-economic objects into watershed object data according to the watershed vision, business domain, and business process in the business architecture; divide the watershed information data describing natural elements and socio-economic elements contained in the watershed objects into watershed element data; divide the watershed information data describing the natural characteristics and socio-economic characteristics of watershed element attributes into watershed feature data, wherein each watershed object data corresponds to a plurality of watershed element data, and each watershed element data corresponds to a plurality of watershed feature data; A watershed information production area is constructed based on the watershed characteristic data, a watershed information operation area is constructed based on the watershed element data, and a watershed information IoT area is constructed based on the watershed object data. The watershed information production area includes a variety of watershed information production data, the watershed information operation area includes a variety of watershed information operation data, and the watershed information IoT area includes a variety of watershed information IoT data. The security policy execution layer is used to collect the watershed information production data, and after processing the watershed information production data, it is unidirectionally transmitted to the security policy control layer according to the transmission authority; the security policy control layer is used to collect the watershed information operation data, and the watershed information operation data is processed, and the processed watershed information production data and / or the watershed information operation data are unidirectionally transmitted to the security policy management layer according to the transmission authority; the security policy management layer is used to collect watershed information management data, and the watershed information management data is the data specified by the confidentiality level in the watershed information IoT data; Utilize the security policy management layer to construct a watershed information security policy, apply the watershed information security policy to the watershed information platform, and send the watershed information security policy to the security policy control layer; Utilizing the security policy control layer to generate a watershed information security sub-policy based on the watershed information security policy, applying the watershed information security sub-policy to the watershed information sub-platform, and issuing the watershed information security sub-policy to the security policy execution layer; The security policy execution layer is used to execute the watershed information security sub-policy.
2. The method for constructing a watershed information security architecture according to claim 1, characterized in that: The watershed information security policy includes an overall security policy and a meta-security policy. The sending of the watershed information security policy to the security policy control layer includes: The meta-security policy is sent down to the corresponding watershed information sub-platform in the security policy control layer using the overall security policy.
3. The method for constructing a watershed information security architecture according to claim 2, characterized in that: The step of generating a watershed information security sub-strategy based on the watershed information security policy by using the security policy control layer, and applying the watershed information security sub-strategy to the watershed information sub-platform includes: Utilizing the security policy control layer to combine the services of the watershed information sub-platform and the meta-security policy to generate the watershed information security sub-policy; Apply the watershed information security sub-strategy to the corresponding watershed information sub-platform.
4. The method for constructing a watershed information security architecture according to claim 2, characterized in that: The meta-security policy includes identity policy and control policy, wherein: The identity strategy is used for identity management and identity authentication of the watershed information sub-platform; The control strategy is used to set access rights according to the user's security level on the watershed information sub-platform and to authenticate requests for access to the watershed information sub-platform.
5. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, computer instructions are stored in the memory, and the processor executes the method for constructing a watershed information security architecture according to any one of claims 1 to 4 by executing the computer instructions.
6. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the method for constructing a watershed information security architecture according to any one of claims 1 to 4.
7. A computer program product, characterized in that It includes computer instructions, which are used to enable a computer to execute the watershed information security architecture construction method described in any one of claims 1 to 4.
Citation Information
Patent Citations
Data distribution method and device and storage medium
CN114866553A
Multi-level collaborative security policy deployment method, system, equipment and medium
CN118551385A