Business and financial fusion data security interaction method and system based on credential creation

Through multi-dimensional data collection and machine learning algorithms, the dynamic access control rule database is built, and data traceability and intelligent audit is realized in combination with blockchain technology, which solves the problem of dynamic access control and data traceability difficulties in the business finance integration system, improves the system's security and management efficiency, and promotes the integration of emerging technologies.

CN120259009AInactive Publication Date: 2025-07-04CHINA POWER CONSTR ZHIXIANG CLOUD DATA CO LTD

Patent Information

Application Number
CN202510712261.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-07-04
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The accuracy of dynamic access control in the existing industrial and financial integration system is insufficient, data traceability and auditing are difficult, and the integration of emerging technologies is difficult to limit the improvement of system performance and security.

Method used

A dynamic access control rule library is built using multi-dimensional data collection and machine learning algorithms, combining blockchain technology to realize data traceability and intelligent auditing, and analyzing operation logs using natural language processing and machine learning technology to identify abnormal behaviors and risk assessment.

Benefits of technology

It realizes the accuracy and flexibility of dynamic access control, improves the efficiency and quality of data traceability and auditing, promotes seamless integration of emerging technologies, and improves the security and management efficiency of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120259009A_ABST
    Figure CN120259009A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of business and financial fusion data security interaction scheme design based on credential creation, in particular to a business and financial fusion data security interaction method and system based on credential creation. The method comprises the steps of collecting, standardizing, storing and encrypting business and financial data, constructing a dynamic access control rule base by utilizing multi-dimensional information and a machine learning algorithm to carry out accurate access control, adding an identifier and a timestamp for interactive data, realizing data tracing through a block chain, and realizing data tracing through a block chain. And analyzing the operation log and the data traceability information by adopting a natural language processing and machine learning technology to perform exception auditing. The system comprises a data acquisition module, a standardization module, a storage module, an encryption module, a dynamic access control module and a data traceability auditing module. According to the invention, the data security and management efficiency of the business and financial fusion system are improved to a great extent, and the problems of inaccurate dynamic access control, difficult data tracing and emerging technology fusion are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of designing a secure data interaction solution for the integration of business and finance based on information technology innovation, and specifically to a secure data interaction method and system for the integration of business and finance based on information technology innovation. Background Art

[0002] With the rapid development of information technology, the business-finance integration system in the information and innovation environment has become a key support platform for enterprise operation and management. The system has achieved deep integration of business processes and financial management, significantly improving the efficiency of enterprise operations. However, in practical applications, there are still many problems that need to be solved.

[0003] At present, the lack of accuracy in dynamic access control is an important factor restricting the security of business-finance integration systems. Traditional access control models are difficult to adapt to complex business scenarios and dynamically changing user needs, resulting in unreasonable authority allocation and increased risk of data leakage. At the same time, data traceability and audit difficulties are also problems that plague system managers. In the process of processing massive data, the lack of effective data identification and timestamp recording mechanisms makes it difficult to trace data operation records, and audit work faces huge challenges.

[0004] In addition, the difficulty of integrating with emerging technologies has limited the innovative development of the system. Emerging technologies such as artificial intelligence and blockchain have brought new development opportunities to the business-finance integration system, but existing technologies have technical bottlenecks when integrating these emerging technologies, resulting in the inability to effectively improve system performance and security. How to solve the above problems and improve the data security and management efficiency of the business-finance integration system has become the focus of attention of enterprises and scientific research institutions.

[0005] Therefore, the prior art needs to be further developed. Summary of the invention

[0006] The purpose of the present invention is to overcome the above-mentioned technical deficiencies and provide a method and system for secure interaction of business-finance integrated data based on information technology to solve the problems existing in the prior art.

[0007] To achieve the above technical objectives, according to a first aspect of the present invention, the present invention provides a method for secure interaction of business-finance fusion data based on information innovation, the method comprising: Step A: Collect business data and financial data in the business-finance integration system under the information innovation environment; Step B: Standardizing the collected business data and financial data to unify data formats and coding rules; Step C: Store the standardized data into the Xinchuang database; Step D: Encrypting the stored data according to the preset security policy; Step E: When there is data interaction, collect the user's role information, permission information, operation environment information, and behavior history information; Step F: Based on the role information, permission information, operation environment information, and behavior history information, use machine learning algorithms to construct a dynamic access control rule library, and perform dynamic access control on the user according to the rule library; Step G: During the data interaction process, add a unique identifier and a timestamp to the data, and record the operation logs at the same time. Record the key data operations on the blockchain to achieve data traceability; Step H: Use natural language processing and machine learning technologies to analyze the operation logs and data traceability information to automatically identify abnormal operation behaviors and potential risks, and generate an audit report.

[0008] Specifically, in the above-mentioned Step A, the business data includes sales orders, purchase orders, and production plans, and the financial data includes accounting vouchers, financial statements, and budget data.

[0009] Specifically, in the above-mentioned Step B, the standardization processing includes data cleaning, data conversion, and data normalization.

[0010] Specifically, in the above-mentioned Step D, the security policy includes a combination of symmetric encryption and asymmetric encryption.

[0011] Specifically, in the above-mentioned Step E, the operation environment information includes geographical location, device type, and network status.

[0012] Specifically, in the above-mentioned Step F, the machine learning algorithms include decision tree algorithms, neural network algorithms, or support vector machine algorithms.

[0013] Specifically, in the above-mentioned Step G, the blockchain adopts a consortium chain architecture to improve data processing efficiency.

[0014] Specifically, in the above-mentioned Step G, the unique identifier is generated using the UUID algorithm.

[0015] Specifically, in the above-mentioned Step H, the natural language processing and machine learning technologies are used to analyze the text information and behavior patterns in the operation logs to identify abnormal operation behaviors.

[0016] According to the second aspect of the present invention, a data security interaction system for industry and finance integration based on Xinchuang is provided, including: An acquisition module for collecting business data and financial data in the industry and finance integration system in the Xinchuang environment; A control module for standardizing the collected business data and financial data to unify the data format and coding rules; for storing the standardized data into a domestic innovation database; for encrypting the stored data according to a preset security policy; for collecting the user's role information, permission information, operation environment information, and behavior history information during data interaction; for constructing a dynamic access control rule library using machine learning algorithms based on the role information, permission information, operation environment information, and behavior history information, and performing dynamic access control on the user according to the rule library; for adding a unique identifier and timestamp to the data during the data interaction process, and at the same time recording the operation log, and recording key data operations on the blockchain to achieve data traceability; for analyzing the operation log and data traceability information using natural language processing and machine learning technologies to automatically identify abnormal operation behaviors and potential risks, and generating an audit report.

[0017] Advantageous effects: The method and system for secure data interaction of business and finance integration based on domestic innovation provided by the present invention have significant advantages: In terms of dynamic access control, the dynamic access control rule library constructed through multi-dimensional data collection and machine learning algorithms can accurately judge the user's access permissions, effectively resist illegal access, and greatly improve the security of the system. At the same time, the real-time monitoring and dynamic adjustment mechanism can adjust the access policy in a timely manner according to the user's behavior and environmental changes, ensuring the flexibility and adaptability of access control.

[0018] Data traceability and auditing become more convenient and efficient. The full-link data traceability system and intelligent auditing tools, combined with the immutable characteristics of the blockchain, ensure the authenticity and integrity of data operation records. Auditors can quickly and accurately locate problems, improving the auditing efficiency and quality.

[0019] In terms of integration with emerging technologies, the constructed technology integration platform realizes the seamless integration of the domestic innovation environment and various emerging technologies. The optimized artificial intelligence model training mechanism and blockchain consensus algorithm adjustment improve the data processing ability and system performance, providing strong support for the digital transformation of enterprises. The present invention comprehensively improves the security, management efficiency, and innovation ability of the business and finance integration system, and has broad application prospects. Brief description of the drawings

[0020] Figure 1 is a flowchart of the method for secure data interaction of business and finance integration based on domestic innovation provided in the specific embodiment of the present invention; Figure 2 is a schematic diagram of the system composition of the system for secure data interaction of business and finance integration based on domestic innovation provided in the specific embodiment of the present invention. Detailed implementation manners

[0021] To enable those skilled in the art to better understand the technical solution of the present invention, the following will clearly and completely describe the technical solution of the present invention in conjunction with the accompanying drawings of the present invention. Based on the embodiments in this application, other similar embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of this application. In addition, for the directional terms mentioned in the following embodiments, in the preferred embodiments of the present invention, "up", "down", "left", "right", etc. are only the directions with reference to the accompanying drawings. Therefore, the directional terms used are for illustration rather than limiting the present invention.

[0022] The present invention will be further described below in conjunction with the accompanying drawings and preferred embodiments.

[0023] Please refer to Figure 1 , the present invention provides a data security interaction method for business and finance integration based on information technology application innovation, including: Step A: Collect business data and financial data in the business and finance integration system in the information technology application innovation environment.

[0024] Specifically, in the step A, the business data includes sales orders, purchase orders, and production plans, and the financial data includes accounting vouchers, financial statements, and budget data.

[0025] It should be further noted that regarding step A, the solution designed by the present invention includes: Interface development and configuration: Develop interface programs for business systems and financial systems and configure them according to different system interface specifications. For RESTful API interfaces, configure the request URL, request method (preferably GET and POST in the present invention), request parameters, and response format. For ESB interfaces, configure information such as the service address, port, and service name. During the configuration process, ensure the security of the interface, use the HTTPS protocol for data transmission, and use digital certificates for identity authentication.

[0026] Timed polling and message listening: Initiate a timed polling request to the business system at a set time interval (preferably 5 minutes in the present invention). Carry necessary parameters in the request, preferably the timestamp of the last collection in the present invention, to obtain the latest data. At the same time, start a message listening thread to continuously listen for notification messages in the message queue. When receiving real-time messages such as order status changes, immediately extract the key information (preferably the order number) in the message and initiate a targeted data collection request.

[0027] Step B: Standardize the collected business data and financial data to unify the data format and coding rules.

[0028] Specifically, in the step B, the standardization process includes data cleaning, data conversion, and data normalization.

[0029] It should be further noted that regarding step B, the solution designed by the present invention includes: Data cleaning operation process Duplicate record detection: For the collected business data and financial data, construct a hash table according to a predetermined combination of key fields (preferably the order number and voucher number in the present invention). Store the unique hash value of each data record in the hash table. When a new data record arrives, calculate its hash value and compare it with the values in the hash table. If a duplicate hash value is found, further check the integrity and accuracy of the data record. If it is confirmed as a duplicate record, delete the subsequent duplicate records from the data record set and retain the record that appears for the first time.

[0030] Error data processing: For records with incorrect date formats, use regular expressions to match non-standard date strings. In a preferred embodiment of the present invention, the regular expression "\d{4}[- / ]\d{1,2}[- / ]\d{1,2}" is used to match date formats containing "-" or " / " delimiters. For the matched incorrect date formats, use a date parsing library (preferably the datetime.strptime function in Python in the present invention) for parsing and conversion, and convert the date to the standard format "YYYY-MM-DD".

[0031] Unified processing of amount units: Check the unit identifiers in the amount strings. If there are multiple currency units (preferably US dollars and euros in the present invention), convert them into RMB amounts uniformly according to the preset exchange rate conversion rules. The exchange rate data is obtained from external financial information services and updated regularly to ensure accuracy. Keep the converted amount to two decimal places to meet the requirements of financial accounting.

[0032] Data conversion execution: Use a programming language (preferably Python or Java in the present invention) to call the date processing library and string processing functions to implement the conversion of date formats and amount units. During the conversion process, verify the conversion results. If the conversion fails, record the error log and feedback the error data to the relevant business departments for processing.

[0033] Data normalization operation: According to the defined coding specifications and data range constraint conditions, check and correct the collected data one by one. For cases where the employee numbers do not conform to the specifications, obtain the correct employee information through the interface with the human resources system and regenerate the standardized numbers. For cases where the data range exceeds the limit, mark them as abnormal data and process them according to the business logic. Preferably, prompt the user to re-enter or correct the data in the present invention.

[0034] Step C: Store the data after standardization processing into the Xinchuang database.

[0035] It should be further noted that regarding step C, the solution designed by the present invention includes: Database connection and configuration: Use a database connection driver (preferably the JDBC driver provided by DM Database in the present invention) to establish a connection with the DM Database. In the connection configuration file, set necessary parameters such as the database server address, port number, username, and password. At the same time, configure the database connection pool to improve the reuse rate of database connections and system performance. The maximum and minimum connection numbers of the connection pool are reasonably set according to the concurrent access volume of the system. The maximum connection number is set to 200, and the minimum connection number is set to 10.

[0036] Data writing and storage: Write the standardized business data and financial data into the specified database table according to the preset table structure and data type. During the writing process, perform data verification and constraint checks to ensure data integrity and consistency. For data that violates data constraints (preferably foreign key constraints and uniqueness constraints in the present invention), reject the writing and record error information. At the same time, record the timestamp of data writing and the operating user for subsequent auditing and traceability.

[0037] Step D: Encrypt the stored data according to the preset security policy.

[0038] Specifically, in the said step D, the security policy includes a combination of symmetric encryption and asymmetric encryption.

[0039] It should be further noted that regarding step D, the solution designed by the present invention includes: Key generation and management: In the system initialization stage, use a secure random number generator to generate an RSA key pair with a key length of 2048 bits. The private key is stored in a hardware-based secure storage device (HSM), which has physical isolation and access control functions to ensure the security of the private key. Access the private key through the API interface provided by the HSM for encryption and decryption operations. Use the cryptography library of Python to generate a 256-bit AES symmetric key for data encryption.

[0040] Data encryption process: For the business data and financial data stored in the database, use the AES algorithm for encryption. Before encryption, pad the data to an integer multiple of the AES block size (128 bits). Use the CBC mode for encryption, and use a randomly generated initialization vector (IV). Store the IV together with the encrypted data in the database. The generation of the IV uses a secure random number generator to ensure its randomness and unpredictability. During the encryption process, use the symmetric key to encrypt the data, and the encrypted data is stored in the specified field of the database in binary format.

[0041] Symmetric key encryption: Use the public key of the RSA algorithm to encrypt the AES symmetric key, and store the encrypted key together with the encrypted data. After the data is encrypted, map the relationship between the encrypted key and the encrypted data so that the symmetric key can be correctly obtained when decryption is required.

[0042] It can be understood that the preferred parameters and selection reasons for step D in the present invention are shown in Table 1: Table 1 Preferred parameters and selection reasons for step D Step E: When data is interacted, collect the user's role information, permission information, operating environment information, and behavior history information.

[0043] Specifically, in the step E, the operating environment information includes geographical location, device type, and network status.

[0044] Step F: Based on the role information, permission information, operating environment information, and behavior history information, use a machine learning algorithm to construct a dynamic access control rule library, and perform dynamic access control on the user according to the rule library.

[0045] Specifically, in the step F, the machine learning algorithm includes a decision tree algorithm, a neural network algorithm, or a support vector machine algorithm.

[0046] It should be further noted that for step F, the solution designed by the present invention includes: 1. Information collection and integration: Obtain the user role and permission information from the enterprise's unified identity authentication system (LDAP server). Synchronize the user information regularly (at 2:00 am every day) through the LDAP protocol. During the synchronization process, check the integrity of the data. If data loss or inconsistency is found, record the error log and contact the LDAP server administrator for repair. When the user logs in to the system and initiates a data access request, use a browser plugin or client program to obtain the operating environment information. Obtain the geographical location of the user through an IP address location service, use a user agent string analysis tool to parse the device type, and integrate the operating environment information with the user's historical behavior records.

[0047] 2. Decision tree algorithm training Data preprocessing optimization: For the collected user information and behavior history data, first perform data cleaning to remove records with more than 30% missing values. For records with fewer missing values, use mean filling, median filling, or model-based filling methods (the present invention is preferably the K-nearest neighbor algorithm) to fill in. Then perform feature selection, using indicators such as information gain ratio (calculation method is the same as described above) and chi-square test to select features that are more strongly associated with access rights. Divide the data into training set, validation set, and test set, with the training set accounting for 60%, the validation set accounting for 20%, and the test set accounting for 20%.

[0048] 3. Model training and parameter adjustment: The decision tree algorithm is implemented using the Scikit-learn library, and the initial parameter settings of the present invention are preferably as described above. During the training process, the parameters are adjusted according to the evaluation results (accuracy, recall rate and F1-value) of the validation set. A grid search algorithm is used to search within a predefined parameter range (the present invention preferably has a max_depth range of 3-8, a min_samples_split range of 5-15, and a min_samples_leaf range of 3-8) to find the optimal parameter combination. After multiple experiments and optimizations, it was finally determined that when max_depth=6, min_samples_split=8, and min_samples_leaf=4, the model performed best on the validation set.

[0049] 4. Rule extraction decision tree model: Extract the decision path from the trained decision tree model as the dynamic access control rule. Starting from the root node, perform a depth-first search according to the conditions of the decision node, and record each decision path from the root node to the leaf node. The value of the leaf node represents the access control decision result (allow or deny) corresponding to the path. In a preferred embodiment of the present invention, a decision path is "User role = financial manager, and device security level = high, and historical access compliance rate >= 90%, then access to financial statements is allowed", and such rules are stored in the rule base.

[0050] 5. Real-time access control: When a user initiates a data access request, the characteristic information of the current user is collected, including role, authority, geographic location, device type, historical operation records, etc. These characteristic information are matched with the decision tree model, starting from the root node of the decision tree, and the branches of the decision tree are traversed downward step by step according to the current characteristic value. If a node that does not meet the conditions is encountered during the traversal process, the traversal is terminated, and a decision is made according to the rule corresponding to the termination node (the present invention preferably denies access); if the leaf node is successfully traversed, it is decided whether to allow the user to access the data based on the decision result of the leaf node (allow or deny). At the same time, the detailed information of each access decision is recorded, including user identification, access time, requested resources, decision results, etc., for subsequent audit and analysis.

[0051] It is understandable that the preferred parameters and reasons for selection regarding step F in the present invention are shown in Table 2 as follows: Table 2 Preferred Parameters and Reasons for Selection of Step F Step G: During the data interaction process, add a unique identifier and a timestamp to the data, and at the same time record the operation log, and record the key data operations on the blockchain to achieve data traceability.

[0052] Specifically, in the said step G, the blockchain adopts a consortium chain architecture to improve data processing efficiency.

[0053] Specifically, in the said step G, the unique identifier is generated using the UUID algorithm.

[0054] It should be further noted that regarding step G, the design solution of the present invention includes: 1. Unique identifier and timestamp recording: In the data collection stage, generate a unique UUID for each data record, and store the generated timestamp together with the data record in the database. The generation of UUID uses the uuid library of Python to ensure its global uniqueness. The timestamp recording uses the high-precision time function of the system clock, accurate to milliseconds. At the same time, the timestamp is updated at each key step (creation, modification, deletion) of the data operation, and the operation type (creation, update, deletion) and relevant information of the operating user (user name, user ID) are recorded.

[0055] 2. Blockchain recording process: When a key data operation occurs, organize and package the detailed information of the operation (preferably the operation time, operation type, operating user, data identifier, etc. in the present invention) according to a predefined structure. In the preferred embodiment of the present invention, the operation information structure body includes the following fields: Operation information = {operation time (accurate to milliseconds), operation type (creation, modification, deletion), operating user (user name, user ID), data identifier (business data number, financial data number)} Use the consensus mechanism on the blockchain node (preferably the PBFT consensus algorithm in the present invention) to verify and reach a consensus on the packaged operation information. The PBFT consensus process is divided into a pre-preparation stage, a preparation stage, and a submission stage. In the pre-preparation stage, the proposing node (the node initiating the operation) sends a pre-preparation message to other nodes, including the operation information and the proposal number; in the preparation stage, after receiving the pre-preparation message, other nodes verify the legality of the message and send a preparation message to other nodes; in the submission stage, when a node receives enough preparation messages, it sends a submission message to other nodes, and when more than two-thirds of the nodes' confirmations are obtained, the operation information is packaged into a block and added to the blockchain.

[0056] 3. Intelligent auditing process Natural language processing and Trigram model: Preprocess the text information in the operation logs to remove punctuation marks, stop words (preferably words with no practical meaning such as "of", "is", etc. in this invention), and irrelevant characters. Use the NLTK library in Python to build a vocabulary and calculate the co-occurrence frequency of three adjacent words. The conditional probability formula for calculating Trigram is preferably as follows in this invention: where, represents the number of occurrences of Trigram in the corpus, represents the number of occurrences of the first two words simultaneously in the corpus. For the log records in the test set, calculate the probability of Trigram in them. If the probability of a certain Trigram is lower than the set threshold (preferably 0.01 in this invention), then mark this log record as abnormal.

[0057] 4. Application of Isolation Forest algorithm: Construct a multi-dimensional data set from the historical operation data of users. Each data point represents a user operation, and the dimensions of the features include operation time, operation frequency, accessed data type, operation duration, etc. Randomly select features and split points from the data set and construct isolation trees according to the following steps: (1) Randomly select a feature from the data set, and randomly select a split point within the value range of this feature.

[0058] (2) Divide the data set into two subsets according to the split point . The left subset is the data points less than or equal to the split point , and the right subset is the data points greater than the split point .

[0059] (3) Recursively divide the subsets until the stop condition is met (preferably the number of data points in the subset is less than the set threshold or reaches the specified tree depth). Calculate the path length of each data point in the isolation tree. The path length refers to the number of edges passed from the root node to this data point. Calculate the average isolation cost, and the formula is: where, is the number of data points. Calculate the mean and standard deviation based on the average isolation cost of all data points.

[0060] Set the anomaly threshold T = μ + 3σ. If the average isolation cost of a certain data point exceeds T, it is determined as an abnormal operation. In a preferred embodiment of the present invention, when μ = 4.5 and σ = 1.2, T = 4.5 + 3×1.2 = 8.1, and data points exceeding this value need to be marked with emphasis.

[0061] It can be understood that the preferred parameters and selection reasons for step G in the present invention are shown in Table 3: Table 3 Preferred parameters and selection reasons for step G Step H: Use natural language processing and machine learning techniques to analyze operation logs and data traceability information to automatically identify abnormal operation behaviors and potential risks, and generate an audit report.

[0062] Specifically, in the said step H, the natural language processing and machine learning techniques are used to analyze the text information and behavior patterns in the operation logs to identify abnormal operation behaviors.

[0063] 5. Audit report generation: For the identified abnormal operations, extract key features and generate a structured audit report.

[0064] In a preferred example of the present invention, the said key features include at least one of the following: Abnormal operation ID, name of the operating user, operation time, type of anomaly, risk level, associated data.

[0065] Next, illustrate the said key features by way of example: { "Abnormal operation ID": "LOG_20241015_001", "Operating user": "Zhang San", "Operation time": "2024-10-15T14:32:18.123Z", "Type of anomaly": "High-frequency data deletion", "Risk level": "High", "Associated data": ["Order number ORD123456", "Customer information CUST789"] } It should be further noted that the audit report is pushed to the person in charge of the audit department in real time through system emails or the management console.

[0066] Specifically, the present invention also designs a dynamic rule optimization mechanism: Feedback learning: Auditors can manually review the abnormal operations marked by the system, and confirm the results to be fed back to the model training module for dynamically adjusting the decision tree parameters or updating the Trigram model corpus. For example, if a certain type of normal operation is frequently misjudged as abnormal, the system automatically reduces the weight of this operation or corrects the N-Gram pattern matching rules.

[0067] Incremental learning: Implement online learning function through Spark MLlib. The newly generated audit data is integrated into the training set in real time, and the model is incrementally updated regularly (such as weekly) to ensure that the rule base continuously matches the business scenario.

[0068] Specifically, the present invention also conducts verification on the implementation effect of the patent, and the results are as follows: (1) Improvement in the accuracy of dynamic access control Comparative experiment Deploy this solution in the enterprise financial system of a large manufacturing enterprise, and the comparison results with the baseline method (based on the static RBAC model) are shown in Table 4: Table 4 Comparison results Typical case When a financial staff member temporarily queries sales order data across departments, the system dynamically grants a 30-minute restricted access permission according to the role and operation environment (VPN geographical location verification) with temporarily granted operation permissions, and audits its operation track in real time.

[0069] (2) Data traceability and audit efficiency Performance indicators Conduct a full-link traceability test on 10TB of enterprise financial data, and the test results are shown in Table 5: Table 5 Test results Abnormal detection case The system identifies that a branch manager deletes purchase order records abnormally frequently (53 times a day, 8.3 times higher than the department average) through the Isolation Forest algorithm, and combines blockchain traceability to find its associated external IP operation, triggering a real-time alarm.

[0070] (3) Verification of the integration of emerging technologies AI model integration Deploy a lightweight access control model on edge devices (such as financial audit terminals) using TensorFlow Lite, and the inference latency is reduced to 97ms, with a 62% speedup compared to the cloud solution.

[0071] Blockchain performance tuning Through the sharding technology, the throughput of the consortium blockchain is increased from 500↑ to 2,100 TPS, and the success rate of 98.7% is maintained when the concurrent verification nodes are expanded from 16 to 64.

[0072] It can be understood that the method and system for secure data interaction in the integration of business and finance based on Xinchuang provided by the present invention have significant advantages: In terms of dynamic access control, the dynamic access control rule library constructed through multi-dimensional data collection and machine learning algorithms can accurately judge user access rights, effectively resist illegal access, and greatly improve the security of the system. At the same time, the real-time monitoring and dynamic adjustment mechanism can adjust the access policy in a timely manner according to user behavior and environmental changes, ensuring the flexibility and adaptability of access control.

[0073] Data traceability and auditing become more convenient and efficient. The full-link data traceability system and intelligent auditing tools, combined with the immutable characteristics of the blockchain, ensure the authenticity and integrity of data operation records. Auditors can quickly and accurately locate problems, improving the efficiency and quality of auditing.

[0074] In terms of integration with emerging technologies, the constructed technology integration platform realizes the seamless integration of the Xinchuang environment and various emerging technologies. The optimized artificial intelligence model training mechanism and blockchain consensus algorithm adjustment improve data processing capabilities and system performance, providing strong support for the digital transformation of enterprises. The present invention comprehensively improves the security, management efficiency, and innovation capabilities of the business and finance integration system, and has broad application prospects.

[0075] Please refer to Figure 2 , the present invention provides another embodiment. This embodiment provides a secure data interaction system for the integration of business and finance based on Xinchuang, and the secure data interaction system for the integration of business and finance based on Xinchuang includes: An acquisition module 100, configured to collect business data and financial data in the business and finance integration system in the Xinchuang environment; A control module 200 is configured to perform standardization processing on the collected business data and financial data to unify the data format and coding rules; store the standardized data in a Xinchuang database; perform encryption processing on the stored data according to a preset security policy; collect the user's role information, permission information, operation environment information, and behavior history information during data interaction; construct a dynamic access control rule library using machine learning algorithms based on the role information, permission information, operation environment information, and behavior history information, and perform dynamic access control on the user according to the rule library; add a unique identifier and timestamp to the data during the data interaction process, record the operation log at the same time, and record the key data operations on the blockchain to achieve data traceability; analyze the operation log and data traceability information using natural language processing and machine learning technologies to automatically identify abnormal operation behaviors and potential risks, and generate an audit report.

[0076] It should be noted here that the Xinchuang-based business-financial integration data security interaction method and system provided by the present invention have significant advantages: In terms of dynamic access control, the dynamic access control rule library constructed through multi-dimensional data collection and machine learning algorithms can accurately judge the user's access permissions, effectively resist illegal access, and greatly improve the security of the system. At the same time, the real-time monitoring and dynamic adjustment mechanism can adjust the access policy in a timely manner according to the user's behavior and environmental changes, ensuring the flexibility and adaptability of access control.

[0077] Data traceability and auditing become more convenient and efficient. The full-link data traceability system and intelligent auditing tools, combined with the immutable characteristics of the blockchain, ensure the authenticity and integrity of data operation records. Auditors can quickly and accurately locate problems, improving the auditing efficiency and quality.

[0078] In terms of integration with emerging technologies, the constructed technology integration platform realizes the seamless integration of the Xinchuang environment and various emerging technologies. The optimized artificial intelligence model training mechanism and blockchain consensus algorithm adjustment improve the data processing ability and system performance, providing strong support for the digital transformation of enterprises. The present invention comprehensively improves the security, management efficiency, and innovation ability of the business-financial integration system, and has broad application prospects.

[0079] In a preferred embodiment, the present application further provides an electronic device, which includes: A memory; and a processor, wherein computer-readable instructions are stored on the memory, and when the computer-readable instructions are executed by the processor, the above-mentioned method for secure data interaction in business and finance integration based on Xinchuang is implemented. This computer device can generally be a server, a terminal, or any other electronic device with necessary computing and / or processing capabilities. In one embodiment, this computer device may include a processor, a memory, a network interface, a communication interface, etc. connected through a system bus. The processor of this computer device can be used to provide necessary computing, processing, and / or control capabilities. The memory of this computer device may include a non-volatile storage medium and an internal memory. An operating system, computer programs, etc. may be stored in or on the non-volatile storage medium. The internal memory can provide an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface and communication interface of this computer device can be used to connect and communicate with external devices through a network. When the computer program is executed by the processor, it executes the steps of the method of the present invention.

[0080] The present invention can be implemented as a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method of the embodiments of the present invention are caused to be executed. In one embodiment, the computer program is distributed on a plurality of network-coupled computer devices or processors, so that the computer program is stored, accessed, and executed in a distributed manner by one or more computer devices or processors. A single method step / operation, or two or more method steps / operations, can be executed by a single computer device or processor or by two or more computer devices or processors. One or more method steps / operations can be executed by one or more computer devices or processors, and one or more other method steps / operations can be executed by one or more other computer devices or processors. One or more computer devices or processors can execute a single method step / operation, or execute two or more method steps / operations.

[0081] Those of ordinary skill in the art can understand that the method steps of the present invention can be used to instruct relevant hardware. The present invention is preferably completed by a computer device or a processor, and the computer program can be stored in a non-transitory computer-readable storage medium. When the computer program is executed, the steps of the present invention are caused to be executed. Depending on the situation, any reference to a memory, storage, database, or other medium herein may include non-volatile and / or volatile memories. Examples of non-volatile memories include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory, magnetic tape, floppy disk, magneto-optical data storage device, optical data storage device, hard disk, solid state disk, etc. Examples of volatile memories include random access memory (RAM), external cache memory, etc.

[0082] It is understandable that the data security interaction method and system based on Xinchuang for the integration of business and finance provided by the present invention have significant advantages: In terms of dynamic access control, the dynamic access control rule library constructed through multi-dimensional data collection and machine learning algorithms can accurately judge user access permissions, effectively resist illegal access, and greatly improve the security of the system. At the same time, the real-time monitoring and dynamic adjustment mechanism can adjust access policies in a timely manner according to user behavior and environmental changes, ensuring the flexibility and adaptability of access control.

[0083] Data traceability and auditing become more convenient and efficient. The full-link data traceability system and intelligent auditing tools, combined with the immutable characteristics of the blockchain, ensure the authenticity and integrity of data operation records. Auditors can quickly and accurately locate problems, improving the efficiency and quality of auditing.

[0084] In terms of integration with emerging technologies, the constructed technology integration platform realizes the seamless integration of the Xinchuang environment and various emerging technologies. The optimized artificial intelligence model training mechanism and blockchain consensus algorithm adjustment improve data processing capabilities and system performance, providing strong support for the digital transformation of enterprises. The present invention comprehensively improves the security, management efficiency, and innovation capabilities of the business and finance integration system, and has broad application prospects.

[0085] The technical features described above can be combined arbitrarily. Although all possible combinations of these technical features are not described, any combination of these technical features should be considered to be covered by this specification as long as such a combination does not exist in contradiction.

[0086] The specific implementation manners of the present invention described above do not constitute a limitation on the protection scope of the present invention. Any other corresponding changes and deformations made according to the technical concept of the present invention should be included in the protection scope of the claims of the present invention.

Claims

1. A data security interaction method for the integration of business and finance based on domestic information technology innovation, characterized in that, The method includes: Step A: Collect business data and financial data in the business-finance integration system in the Xinchuang environment; Step B: Perform standardization processing on the collected business data and financial data to unify the data format and coding rules; Step C: Store the standardized data in the Xinchuang database; Step D: Encrypt the stored data according to the preset security policy; Step E: When data is exchanged, collect the user's role information, permission information, operation environment information, and behavior history information; Step F: Based on the role information, permission information, operation environment information, and behavior history information, use machine learning algorithms to construct a dynamic access control rule library, and perform dynamic access control on the user according to the rule library; Step G: During the data exchange process, add a unique identifier and a timestamp to the data, and record the operation log at the same time. Record the key data operations on the blockchain to achieve data traceability; Step H: Use natural language processing and machine learning technologies to analyze the operation log and data traceability information to automatically identify abnormal operation behaviors and potential risks, and generate an audit report.

2. The method for secure interaction of enterprise finance integration data based on domestic information technology innovation according to claim 1, wherein In the step A, the business data includes sales orders, purchase orders, and production plans, and the financial data includes accounting vouchers, financial statements, and budget data.

3. The method for secure interaction of enterprise finance integration data based on domestic information technology innovation according to claim 1, wherein In the step B, the standardization processing includes data cleaning, data conversion, and data normalization.

4. The method for secure interaction of business and financial integration data based on domestic information technology innovation according to claim 1, characterized in that, In the step D, the security policy includes a combination of symmetric encryption and asymmetric encryption.

5. The method for secure interaction of enterprise finance integration data based on domestic information technology innovation according to claim 1, wherein In the step E, the operation environment information includes geographical location, device type, and network status.

6. The method for secure interaction of enterprise finance integration data based on domestic information technology innovation according to claim 1, wherein In the step F, the machine learning algorithms include decision tree algorithms, neural network algorithms, or support vector machine algorithms.

7. The method for secure interaction of enterprise finance integration data based on domestic information technology innovation according to claim 1, characterized in that In the step G, the blockchain adopts a consortium chain architecture to improve data processing efficiency.

8. The method for secure interaction of enterprise finance integration data based on domestic information technology innovation according to claim 7, characterized in that, In the step G, the unique identifier is generated using the UUID algorithm.

9. The method for secure interaction of business and financial integration data based on domestic information technology innovation according to claim 1, characterized in that, In the step H, the natural language processing and machine learning technologies are used to analyze the text information and behavior patterns in the operation log to identify abnormal operation behaviors.

10. A business-financial integration data security interaction system based on information technology innovation, characterized in that, It includes: An acquisition module for collecting business data and financial data in the business-finance integration system in the Xinchuang environment; A control module for performing standardization processing on the collected business data and financial data to unify the data format and coding rules; for storing the standardized data in the Xinchuang database; For encrypting the stored data according to the preset security policy; It is used to collect the user's role information, permission information, operating environment information, and behavior history information during data interaction; it is used to construct a dynamic access control rule library based on the role information, permission information, operating environment information, and behavior history information, and perform dynamic access control on the user according to the rule library; it is used to add a unique identifier and timestamp to the data during the data interaction process, record the operation logs at the same time, and record the key data operations on the blockchain to achieve data traceability; it is used to analyze the operation logs and data traceability information by using natural language processing and machine learning technologies to automatically identify abnormal operation behaviors and potential risks, and generate an audit report.

Citation Information

Patent Citations

  • Block chain-based sports enterprise financial data security system

    CN116680756A

  • Financial centralized management system with business and financial integration

    CN117575825A

  • Emergency data secure circulation method and device, computer equipment and medium

    CN118713872A

  • Enterprise financial data security management system and method thereof

    CN118864132A

  • Data security analysis method and intelligent calculation data security workstation

    CN119249440A

Cited By

  • Self-adaptive access control method based on block chain

    CN120602204A