Strong-isolation private domain agent data processing method and server
By deploying a strongly isolated private domain agent architecture on the server, using department identification routing and temporary access credential mechanisms, the problems of data leakage and cross-departmental access in cloud processing are solved, and localized secure processing and efficient analysis of sensitive data are realized.
Patent Information
- Application Number
- CN202510698495.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2045-05-28
AI Technical Summary
When existing intelligent analytics and decision-making systems rely on cloud engines to process sensitive data, there is a risk of data breaches and cross-departmental unauthorized access, especially in governments, finance, and medical institutions, data privacy and sensitivity.
A strongly isolated private domain agent architecture is adopted, including the data storage layer, the engine layer and the data service interface layer. Through department identification, precise routing, temporary access credentials and multi-layer isolation mechanisms, data is ensured locally and securely transmitted.
It realizes localized processing and strict isolation of sensitive data, prevents cross-departmental unauthorized access and data leakage, meets data privacy requirements, and retains the efficient capabilities of intelligent analysis and decision-making.
Smart Images

Figure CN120434015A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of data security, and in particular to a strongly isolated private domain intelligent body data processing method and server. Background Art
[0002] With the rapid development of artificial intelligence (AI), intelligent analysis and decision-making systems have been widely used in various fields. However, most current mainstream intelligent analysis and decision-making systems rely on cloud-based engines for data processing.
[0003] For specific sectors like government agencies, financial institutions, and medical institutions, the data they handle (such as official documents, policy documents, and personal privacy information) is highly private and sensitive. Due to the privacy nature of this data, data between different departments in these sectors must be strictly isolated. If this data is uploaded to a public cloud or external server using a cloud-based engine for processing, it not only increases the risk of data leakage but also increases the risk of unauthorized access and information leakage between different departments.
[0004] Therefore, a solution is urgently needed to solve the above data security issues. Summary of the Invention
[0005] The embodiments of the present application provide a strongly isolated private domain intelligent body data processing method and server, which are used to reduce the risk of data leakage and the risk of unauthorized access and information leakage between different departments.
[0006] To achieve the above objectives, the embodiments of the present application adopt the following technical solutions:
[0007] In a first aspect, a strongly isolated private domain agent data processing method is provided, which is applied to a server, wherein a private domain agent is deployed on the server, and the private domain agent includes a data storage layer, an engine layer, and a data service interface layer. The data storage layer includes multiple internal data storage areas, the engine layer includes an agent engine, and the data service interface layer includes an output interface module and multiple internal data interface modules. The method includes:
[0008] Receive a data processing request sent by a user through a user terminal and obtain a department ID;
[0009] Routing the data processing request to the corresponding internal data interface module based on the department ID, wherein the internal data interface module is used to parse the data processing request, obtain the processing task, and call the agent engine, which is used to obtain a temporary access credential based on the department ID and access the department's internal data storage area based on the temporary access credential to obtain the data to be processed; and
[0010] The intelligent agent engine is used to execute processing tasks, analyze and process the data to be processed, obtain processing results, and transmit the processing results to the user terminal through the output interface module.
[0011] In a possible implementation of the first aspect, receiving a data processing request sent by a user through a user terminal and obtaining a department identifier includes:
[0012] Receive official document data uploaded by the user through the user terminal and assign a unique identifier to the official document data;
[0013] Receive a data processing request for official document data sent by a user, where the data processing request includes a unique identifier and a department identifier.
[0014] In another possible implementation of the first aspect, the internal data storage area is isolated by a physical isolation method and / or a strong logical isolation method.
[0015] Another possible implementation of the first aspect includes:
[0016] In the case where the internal data storage area is isolated by a physical isolation method, the internal data storage area includes a plurality of storage array partitions, each storage array partition corresponds to a department identifier on a one-to-one basis, and data between each storage array partition and other storage array partitions cannot be accessed by physical isolation, wherein the physical isolation method is physical network isolation;
[0017] When the internal data storage area is isolated by a strong logical isolation method, the internal data storage area includes multiple independent logical volumes corresponding to department identifiers one by one, and the data between each independent logical volume and other independent logical volumes cannot be accessed by each other through the strong logical isolation method.
[0018] In another possible implementation of the first aspect, the strong logical isolation method includes:
[0019] Use VLAN technology to divide the internal data storage area into independent network areas, and restrict each department's internal data interface module and the corresponding internal data storage area access path to the corresponding VLAN;
[0020] Use firewall policies to prevent unauthorized access across VLANs and prevent direct or indirect communication between data storage areas within different departments;
[0021] Create a corresponding independent logical volume for each department and assign different database user permissions to each independent logical volume;
[0022] Use separate directories for file storage and configure operating system-level access control permissions.
[0023] In another possible implementation of the first aspect, the data service interface layer further includes an external data gateway module, the data storage layer further includes an external data cache area, and the agent engine executes the processing task, analyzes and processes the data to be processed, and obtains a processing result, including:
[0024] The intelligent agent engine analyzes the data to be processed and determines whether external data support is needed;
[0025] When external data support is needed, the agent engine sends an external data request to the external data gateway module. The external data gateway module is used to obtain external data from the external network according to preset rules and store the external data in the external data cache area;
[0026] The intelligent agent engine accesses the external data cache, obtains external data, and executes processing tasks to analyze and process the data to be processed and the external data to obtain processing results, wherein the processing tasks include at least one of data analysis, pattern recognition, text classification, information extraction or decision support.
[0027] In another possible implementation of the first aspect, the private domain intelligent agent further includes a security management layer, the security management layer includes a unified authentication and authorization center, the intelligent agent engine obtains a temporary access credential based on the department identifier, and accesses the department's internal data storage area based on the temporary access credential to obtain data to be processed, including:
[0028] The intelligent agent engine sends a permission request to the unified authentication and authorization center. The permission request includes the department ID. The unified authentication and authorization center is used to generate a temporary access credential based on the department ID and return the temporary access credential to the intelligent agent engine. The temporary access credential has and only has the permission to access the corresponding department's internal data storage area.
[0029] The intelligent agent engine uses temporary access credentials to access the corresponding department's internal data storage area to obtain the data to be processed.
[0030] In another possible implementation of the first aspect, the data storage layer further includes a public external data area, and the method further includes:
[0031] Before executing a processing task, the agent engine obtains the user terminal's access rights to the data to be processed, and determines the data access scope of the user terminal to the data to be processed based on the access rights;
[0032] In the process of executing the processing task, the agent engine accesses the internal data storage area within the data access range;
[0033] After executing the processing task, the intelligent agent engine clears the temporary data in the process of executing the processing task and releases the temporary access credentials.
[0034] In a second aspect, the present application provides a server deployed with a private domain intelligent agent, the private domain intelligent agent including a data storage layer, an engine layer, and a data service interface layer, the data storage layer including multiple internal data storage areas, the engine layer including an intelligent agent engine, and the data service interface layer including an output interface module and multiple internal data interface modules, including:
[0035] a memory configured to store instructions; and
[0036] The processor is configured to call the instructions from the memory and implement the above-mentioned strongly isolated private domain intelligent body data processing method when executing the instructions.
[0037] In a third aspect, the present application provides a computer program product, comprising a computer program or instructions, which implement the above method when executed by a processing device.
[0038] Through the above technical solution, by deploying a private domain intelligent body architecture including a data storage layer, an engine layer, and a data service interface layer on the server, local processing and strict isolation of sensitive data are achieved, effectively solving the data security problem in the traditional cloud processing model; precise routing is performed based on department identification to ensure that data processing requests are only directed to authorized internal data interface modules, and access rights to internal data storage areas are strictly controlled through a temporary access credential mechanism, fundamentally preventing unauthorized data access across departments; at the same time, the intelligent body engine performs data analysis and processing tasks in the local environment, avoiding the risk of sensitive data being transmitted externally, and the processing results are only transmitted to the user terminal that initiated the request through the output interface module, ensuring the security and isolation of the entire data processing process. This architectural design not only meets the strict requirements for data privacy in specific fields such as government, finance, and medical care, but also retains the efficient capabilities of intelligent analysis and decision-making, providing a safe, reliable, and fully functional technical solution for processing highly sensitive information.
[0039] Other features and advantages of the embodiments of the present application will be described in detail in the subsequent detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 A schematic diagram of the overall process of a strongly isolated private domain intelligent agent data processing method provided in an embodiment of the present application;
[0041] Figure 2 A flowchart of a strongly isolated private domain agent data processing method provided in an embodiment of the present application;
[0042] Figure 3 A strongly isolated private domain intelligent entity architecture diagram provided for an embodiment of the present application. DETAILED DESCRIPTION
[0043] To make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the specific implementation methods described herein are only used to illustrate and explain the embodiments of the present application and are not used to limit the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0044] It should be noted that if the embodiments of the present application involve directional indications (such as up, down, left, right, front, back, etc.), the directional indications are only used to explain the relative position relationship, movement status, etc. between the various components under a certain specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indications will also change accordingly.
[0045] In addition, if there are descriptions involving "first", "second", etc. in the embodiments of the present application, the descriptions of "first", "second", etc. are only for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the number of the indicated technical features. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of such features. In addition, the technical solutions between the various embodiments can be combined with each other, but they must be based on the fact that they can be implemented by ordinary technicians in this field. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such a combination of technical solutions does not exist and is not within the scope of protection required by this application.
[0046] like Figure 1 and Figure 2 As shown, an embodiment of the present application provides a strongly isolated private domain intelligent body data processing method, which is applied to a server, and a private domain intelligent body is deployed on the server. The private domain intelligent body includes an infrastructure layer, a data storage layer, an engine layer, a data service interface layer and a security management layer. The data storage layer includes multiple internal data storage areas and external data cache areas. The engine layer includes an intelligent body engine. The data service interface layer includes multiple internal data interface modules, external data gateway modules and output interface modules. The security management layer includes a unified authentication and authorization center, a security audit module and a monitoring and management platform. The method may include the following steps.
[0047] S110, receiving a data processing request sent by a user through a user terminal, and obtaining a department ID;
[0048] S120. Routing the data processing request to the corresponding internal data interface module based on the department identifier, wherein the internal data interface module is used to parse the data processing request, obtain a processing task, and call the agent engine. The agent engine is used to obtain a temporary access credential based on the department identifier and access the department's internal data storage area based on the temporary access credential to obtain the data to be processed; and
[0049] S130, the intelligent agent engine is used to execute processing tasks, analyze and process the data to be processed, obtain processing results, and transmit the processing results to the user terminal through the output interface module.
[0050] Figure 3 The following diagram shows a strongly isolated private domain intelligent entity architecture provided by an embodiment of the present application. Figure 3 The private domain intelligent agent is deployed on the server and includes the infrastructure layer, data storage layer, engine layer, data service interface layer, and security management layer. The data storage layer includes multiple internal data storage areas and external data cache areas, the engine layer includes the intelligent agent engine, the data service interface layer includes multiple internal data interface modules, external data gateway modules, and output interface modules, and the security management layer includes a unified authentication and authorization center, a security audit module, and a monitoring and management platform.
[0051] The private domain intelligent agent receives data processing requests from the user terminal through the data service interface layer. Data processing requests can be sent in a variety of ways, including but not limited to HTTP / HTTPS requests, WebSocket connections, dedicated API calls, or secure file transfer protocols. In actual implementation, when a user needs to process data from a specific department, he or she first needs to initiate a request to the server through the user terminal (such as a computer, tablet, or mobile device). The request may be for tasks such as text analysis, data mining, information retrieval, or decision support. The request must include a department identifier to indicate the source of the data and the scope of processing authority.
[0052] The department identifier can be a clear department code (such as "DEPT-001" for the finance department and "DEPT-002" for the human resources department), or it can be department association information implicit in the user's identity authentication information. In one embodiment, the user first uploads the official document data to the server, and the server assigns a unique identifier to the document. The data processing request initiated by the user will then contain the unique identifier and the corresponding department identifier. For example, after the user uploads a financial report, the server assigns the identifier "DOC-20250430-001", and the user then sends an analysis request containing the identifier and "DEPT-001" (finance department). The server will verify the user's access rights to the department's data to ensure that only authorized personnel can process the data of the corresponding department, thereby implementing data isolation and access control at the request reception stage, laying the foundation for subsequent security processing.
[0053] Routing data processing requests to the corresponding internal data interface module based on department ID effectively isolates departmental data. The private domain agent precisely routes requests to the corresponding department's internal data interface module based on the department ID included in the request. This routing process utilizes a rule-based mapping mechanism, establishing a one-to-one correspondence between department IDs and corresponding internal data interface modules through a preconfigured routing table. For example, when the department ID "DEPT-001" is identified, the request is routed to the Finance department's internal data interface module. Upon receiving the request, the internal data interface module first parses the request, breaking it down into structured processing tasks. This parsing process includes parameter extraction, format validation, and semantic analysis to ensure the integrity and validity of the processing tasks. For example, for a text analysis request, the interface module extracts parameters such as the analysis type (e.g., sentiment analysis, key information extraction), processing scope, and output format. After parsing is complete, the internal data interface module invokes the agent engine and passes the processing task parameters. The agent engine then sends a permission request to the unified authentication and authorization center, including the department ID. Based on the department's identification and pre-set security policies, the unified authentication and authorization center generates temporary access credentials. These credentials are strictly time-sensitive and scope-restricted, allowing access only to the designated department's internal data storage area. After obtaining the temporary access credentials, the agent engine uses them to access the corresponding department's internal data storage area and retrieve the data to be processed. This temporary credential-based access mechanism ensures that the principle of least privilege is adhered to even within the server, effectively preventing unauthorized data access across departments.
[0054] When the intelligent agent engine executes a processing task, analyzes and processes the data to be processed, obtains processing results, and transmits the processing results to the user terminal via the output interface module, it first invokes the corresponding algorithms and models based on the type and parameters of the processing task. Processing tasks can include various types, such as data analysis, pattern recognition, text classification, information extraction, or decision support. For example, for text classification tasks, the intelligent agent engine can use pre-trained machine learning models, such as deep learning models, to classify text. During processing, the intelligent agent engine analyzes whether external data support is required. If so, the engine sends a request to the external data gateway module, which retrieves data from the external network based on pre-set rules and stores it in an external data cache. External data may include public regulations, policy documents, industry standards, or other non-sensitive reference materials. The intelligent agent engine then accesses the external data cache to obtain this auxiliary data and combines it with internal data for comprehensive analysis. After processing is complete, the intelligent agent engine generates structured processing results, which may include analysis reports, decision recommendations, data visualizations, or extracted key information. These results are transmitted to the user terminal via the output interface module, which converts and securely processes the results based on the type of user terminal and the output format specified in the request. It should be noted that throughout the entire processing process, the agent engine strictly adheres to the permissions of the temporary access credentials and will not cross the boundaries to access data from other departments. All operations are logged for subsequent compliance checks by the security audit module.
[0055] In this embodiment, the infrastructure layer includes a local server cluster and network devices. The local server cluster provides computing, storage and network resources. The network devices include switches, routers and firewalls. To ensure security, the following steps are also included: deploying a virtualization platform or a container platform on the local server cluster for resource pooling, rapid deployment and application environment isolation; on the virtualization platform or container platform, deploying independent virtual machines or container instances for the internal data interface modules of each department; configuring the firewall to only allow the internal data interface modules of each department to access the corresponding internal data storage area.
[0056] In this embodiment, the infrastructure layer includes a local server cluster and network devices, wherein the local server cluster is responsible for providing computing, storage, and network resources, and the network devices include switches, routers, and firewalls.
[0057] To ensure security, a virtualization platform or containerization platform is deployed on the local server cluster for resource pooling, rapid deployment, and application environment isolation. For specific implementation, open source KVM or containerization platforms such as Kubernetes can be chosen. Virtualization platforms create a virtual layer on top of physical hardware, abstracting physical resources into resource pools to achieve unified management and dynamic allocation of computing, storage, and network resources. This resource pooling mechanism enables servers to flexibly adjust resource allocation based on the actual needs of each department, improving resource utilization. Virtualization technology also supports rapid deployment. Using pre-configured templates or images, new virtual machines or container instances can be created and started in a short period of time, significantly shortening the deployment cycle. More importantly, virtualization platforms provide a powerful isolation mechanism. Through technologies such as hardware-assisted virtualization and memory page table isolation, they ensure strict separation of resources and data between different virtual environments. Even if one virtual environment is compromised, the security of other environments will not be affected.
[0058] Secondly, on a virtualization or containerization platform, independent virtual machines or container instances are deployed for each department's internal data interface module. Each department's internal data interface module runs in a dedicated virtual environment, completely isolated from the interface modules of other departments. In a virtual machine implementation, each virtual machine has an independent operating system kernel, file system, and network stack, providing strong isolation. In a containerized implementation, while sharing the host kernel, effective isolation is also achieved through mechanisms such as namespace isolation, control group restrictions, and security context configuration. This independent deployment ensures that even if a department's interface module develops a security vulnerability or is attacked by malicious intent, it will not directly affect the interface modules of other departments. Furthermore, each virtual machine or container instance is allocated the minimum necessary resources and permissions, adhering to the principle of least privilege, further reducing the potential attack surface.
[0059] The firewall is configured to only allow each department's internal data interface modules to access their corresponding internal data storage areas. As a core component of network security, the firewall is configured in this embodiment to enforce strict access control policies. The implementation utilizes a multi-layered firewall architecture, consisting of a network boundary firewall and internal partitioned firewalls. The boundary firewall controls communication between the entire system and the external network, preventing unauthorized external access; the internal partitioned firewall is responsible for isolating access between different departments. Firewall rules are designed based on the "deny by default" principle, meaning that all cross-departmental communication requests are denied unless explicitly permitted. For each department's internal data interface module, the firewall is configured with precise access control lists, allowing only access to the corresponding internal data storage areas and prohibiting direct cross-departmental data access. These rules are not only based on IP addresses and ports but also incorporate advanced features such as application-layer protocol inspection, stateful inspection, and deep packet inspection to identify and block disguised unauthorized access attempts. Furthermore, the firewall is equipped with detailed logging to record all access attempts, providing a basis for security audits and incident response.
[0060] The above security configuration realizes resource pooling and application environment isolation through virtualization or containerization technology, which not only improves the resource utilization and deployment efficiency of the infrastructure, but also establishes a solid security isolation foundation at the technical architecture level, preventing the risk of cross-departmental data leakage. In addition, the deployment of independent virtual machines or container instances for each department further strengthens the isolation protection at the application level. Even if the application of a department is attacked or a vulnerability occurs, it will not affect the systems and data of other departments. Through refined firewall configuration, strict access control is achieved at the network level, ensuring that data access strictly follows the authorized path, effectively preventing unauthorized cross-departmental data access. The above three protection mechanisms work together to form a deep defense system, which greatly improves the overall security of the private domain intelligent body. At the same time, the virtualization-based architecture also has good scalability and flexibility, and can be quickly adjusted and expanded as business needs change, maintaining the continuous and safe operation of the system. In summary, the security configuration of this embodiment provides a safe, reliable, efficient and flexible operating environment for the private domain intelligent body, which is particularly suitable for application scenarios such as government agencies, financial institutions and medical institutions that process highly sensitive data.
[0061] In this embodiment, the security audit module records all key operations and data access logs, including user identity, access time, access resources, operation type and operation results; the monitoring and management platform monitors server status, service operation status, resource utilization and security events in real time; when abnormal access patterns or unauthorized access attempts are detected, the monitoring and management platform triggers a security alarm and executes automatic protection measures according to preset policies.
[0062] The internal data interface module is used to parse data processing requests and obtain processing tasks, which can include the following steps:
[0063] S1, the internal data interface module parses the data processing request and extracts the data identifier and processing type;
[0064] S2. Locate the data to be processed in the corresponding department's internal data storage area according to the data identifier;
[0065] S3. Determine the processing tasks to be performed based on the processing type, where the processing tasks include at least one of data analysis, pattern recognition, text classification, information extraction, or decision support.
[0066] This embodiment ensures the strict separation of data from different departments through a multi-level isolation mechanism, including physical isolation and strong logical isolation, effectively preventing unauthorized cross-departmental data access. The temporary access credential mechanism further enhances the security of data access and realizes refined permission control. At the same time, the local deployment of the private domain intelligent body avoids the risk of uploading sensitive data to the public cloud or external server, fundamentally solving the hidden dangers of data leakage. In addition, the design of the external data gateway module enables the server to reasonably utilize external knowledge resources while ensuring the security of internal data, thereby improving the comprehensiveness and accuracy of data processing. The overall architectural design takes into account both security and functionality, and is particularly suitable for scenarios such as government agencies, financial institutions, and medical institutions that process highly sensitive data. It can significantly reduce data security risks while providing high-quality intelligent analysis services, providing safe and reliable technical support for data-driven decision-making within the organization.
[0067] Reference Figure 1 In one implementation of this embodiment, receiving a data processing request sent by a user through a user terminal and obtaining a department identifier include the following steps:
[0068] S210, receiving official document data uploaded by a user through a user terminal, and assigning a unique identifier to the official document data;
[0069] S220: Receive a data processing request for official document data sent by a user, where the data processing request includes a unique identifier and a department identifier.
[0070] In this embodiment, the private domain agent provides a secure file upload channel through the data service interface layer, supporting multiple upload methods to suit different user scenarios. These upload methods include but are not limited to HTTPS-based web form upload, secure FTP transfer, dedicated client software upload, or encrypted API calls.
[0071] To ensure the security of the transmission process, all upload channels in this embodiment use the TLS1.3 encryption protocol to achieve end-to-end encryption, preventing data from being stolen or tampered with during transmission. When a user uploads official document data through a terminal (such as a computer, tablet, or mobile device), the server will first perform an integrity check on the uploaded file, calculate the hash value of the file and compare it with the checksum provided by the user terminal to ensure that the file has not been damaged or tampered with during transmission. Subsequently, the server will scan the file for viruses and malicious code, using the latest virus signature library and heuristic detection algorithm to ensure that the uploaded file does not contain malicious code that may endanger the security of the server.
[0072] After a file passes the security check, the server extracts the file's metadata, including basic attributes such as file name, format, size, and creation time, as well as possible content attributes such as author, title, and keywords. For structured documents (such as Word and PDF), the server also attempts to extract structural information, such as chapter divisions and table structures, to provide a foundation for subsequent intelligent processing. After completing this basic processing, the server generates a globally unique identifier for each uploaded document. The identifier format can be "DOC-{timestamp}-{department code}-{random string}." This unique identifier is stored in a temporary buffer along with the document data, awaiting subsequent processing requests from the user. The server also returns a confirmation message confirming the successful upload, including the generated unique identifier, which the user can reference in subsequent processing requests. Throughout the upload process, the server records detailed operation logs, including upload time, user information, file information, and the generated identifier. This log information is securely stored and regularly backed up to ensure that every document is accurately tracked and managed.
[0073] The private domain agent receives user processing requests through the data service interface layer. These processing requests are typically initiated after a user uploads a document, with the goal of performing specific intelligent analysis or processing on the uploaded document. Data processing requests can be sent via a variety of secure channels, including but not limited to encrypted HTTP / HTTPS requests, secure WebSocket connections, dedicated API calls, or asynchronous requests based on message queues.
[0074] Data processing requests sent by users must contain two key elements: a unique identifier and a department ID. The unique identifier is a globally unique ID assigned during the document upload phase and is used to precisely locate the document data to be processed. The department ID indicates the department or business unit to which the document belongs and serves as the basis for implementing data isolation and access control.
[0075] After receiving a request for processing, the server first verifies the request format and parameters, ensuring that the request structure is complete, the parameter types are correct, and the values are within the valid range. The server then verifies the validity of the unique identifier, checking whether the identifier exists on the server and whether the corresponding document data is accessible. If the identifier is invalid or the corresponding document does not exist, the server returns an appropriate error message and logs the abnormal request.
[0076] For valid identifiers, the server will further verify the user's access rights to the document and check whether the user belongs to or has the right to access the department specified in the request. After the verification is passed, the server will parse the processing parameters in the request. The parameters may include processing type (such as text analysis, information extraction, document classification, etc.), processing priority, result format requirements, etc. The server will build a structured processing task description based on the parameters to prepare for subsequent intelligent processing. At the same time, the server records detailed information about the request received, including request time, user information, request parameters, verification results, etc. In summary, the server establishes multi-level security protection before processing begins, ensuring the security and compliance of data processing, and effectively preventing the risk of unauthorized access and cross-departmental data leakage.
[0077] This implementation achieves precise tracking and management of sensitive documents by assigning globally unique identifiers to uploaded official document data, avoiding the risk of document confusion and mishandling. During the request reception phase, the server verifies the combination of the unique identifier and department ID, implementing strict access control to ensure that users can only process departmental data to which they are authorized. This not only enhances the security and traceability of data processing, but also improves the server's user-friendliness, allowing users to conveniently reference and process uploaded documents. This effectively safeguards the security of sensitive document data during upload and processing, making it particularly suitable for government, financial, and healthcare organizations handling highly sensitive information.
[0078] In one implementation of this embodiment, the internal data storage area is isolated in a physical isolation manner and / or a strong logical isolation manner.
[0079] In the data storage layer of a private-domain intelligent entity, internal data storage areas are isolated using physical and / or strong logical isolation. Specifically, physical isolation involves hardware-level separation, ensuring that data from different departments is stored in physically independent devices or network areas, fundamentally preventing cross-departmental data access. In actual deployments, physical isolation can be achieved in a variety of ways.
[0080] First, you can configure independent storage devices for different departments, such as dedicated storage servers, storage arrays, or network-attached storage (NAS) devices. These devices do not share any physical connections or storage media. Second, you can use network-level physical isolation to ensure that the data networks of different departments are completely physically separated by deploying completely independent network infrastructure, including independent switches, routers, and network lines. For example, the finance department's data is stored in a completely independent network segment, with no physical connection points between this segment and the human resources department's network segment.
[0081] The advantage of physical isolation is that its security is virtually independent of the correctness of software configuration and policy execution. Even if server software vulnerabilities or configuration errors exist, physically disconnected servers cannot access each other, providing the strongest possible protection for sensitive data. However, physical isolation also carries with it high hardware costs, management complexity, and operational challenges. Therefore, in practice, physical isolation is typically implemented selectively for the most critical departmental data, based on data sensitivity and security requirements, while strong logical isolation is employed for other departments.
[0082] Strong logical isolation uses strict software-level control mechanisms to effectively isolate data while sharing physical infrastructure. Compared to physical isolation, strong logical isolation offers greater flexibility and cost-effectiveness.
[0083] Strong logical isolation is typically achieved through a combination of multi-layered technical measures. First, at the network level, virtual local area networks (VLANs) can be used to divide the same physical network into multiple logically isolated segments. Each department's data storage and access paths are restricted to specific VLANs. For example, the Finance department's servers and storage devices might be assigned to VLAN 10, while the HR department's equipment is assigned to VLAN 20. Through VLAN configuration on switches and routers, the network traffic of these two departments is logically isolated. Second, advanced firewalls and access control lists (ACLs) can be deployed to strictly control communication between different VLANs. Firewall policies can be configured to deny all cross-VLAN communication by default, allowing only authorized, necessary communication. For example, rules can be set to allow all departments access to a central authentication server while prohibiting any direct inter-departmental data access. At the storage level, logical unit number (LUN) isolation in a storage area network (SAN) or shared isolation in network-attached storage (NAS) can be used to create independent storage volumes for different departments. While these volumes may physically reside on the same storage array, strict access control policies ensure that each department can only access its allocated storage space. For example, on a large storage array, you can create multiple independent RAID volume groups and use LUN masking to ensure that each department's servers can only see and access the LUNs assigned to that department. At the database level, you can use technologies such as schema isolation, row-level security, or column-level encryption to logically isolate data from different departments within the same database instance. For example, you can create independent database users and schemas for each department, and use the database's access control mechanisms to ensure that users in each department can only access their own data schemas.
[0084] In this implementation, physical isolation fundamentally cuts off access channels between data from different departments through hardware-level separation, providing the highest level of protection for the most sensitive data; while strong logical isolation achieves effective data isolation while maintaining server flexibility and cost-effectiveness through strict control at the software level. This dual isolation strategy enables the server to flexibly select the appropriate isolation method based on the sensitivity and security requirements of data from different departments, meeting the highest security standards while avoiding unnecessary hardware investment and management complexity. In this way, private domain intelligent entities can securely process sensitive data from multiple departments in a single server, effectively preventing data leakage and unauthorized access. It is particularly suitable for fields with strict data security requirements such as government, finance, and healthcare, providing these institutions with a secure and efficient intelligent data processing solution.
[0085] In one implementation of this embodiment, the following further comprises:
[0086] In the case where the internal data storage area is isolated by a physical isolation method, the internal data storage area includes a plurality of storage array partitions, each storage array partition corresponds to a department identifier on a one-to-one basis, and data between each storage array partition and other storage array partitions cannot be accessed by physical isolation, wherein the physical isolation method is physical network isolation;
[0087] When the internal data storage area is isolated using a strong logical isolation method, the internal data storage area includes multiple independent logical volumes or database instances corresponding to department identifiers one by one, and the data between each independent logical volume and other independent logical volumes cannot be accessed by each other through the strong logical isolation method.
[0088] When the internal data storage area is isolated by physical isolation, the internal data storage area adopts a multiple storage array partition architecture, each storage array partition specifically corresponds to a specific department identifier, forming a one-to-one correspondence. This storage array partition can be implemented through a variety of physical devices, including independent storage servers, dedicated storage array devices, or network attached storage (NAS) servers. Each storage array partition is completely independent physically, with its own storage controller, cache server, and disk array, ensuring complete isolation of data at the physical level. For example, the data of the finance department is stored in an independent RAID 10 configured storage array, while the data of the human resources department is stored in another independent RAID 5 configured storage array. There are no shared components or cross-access paths between the two storage arrays.
[0089] Physical network isolation is a key technical means to achieve complete isolation between storage array partitions. By configuring an independent network infrastructure for each storage array partition, including dedicated network interface cards (NICs), switches, and routers, a completely independent data transmission channel is built. There are no physical connection points between these independent network components, completely cutting off the access paths between data from different departments from a network topology perspective. In actual deployment, a variety of network isolation technologies can be used, such as deploying independent physical networks, using dedicated VLANs in conjunction with physical port isolation, and implementing strict network segmentation. Through this physical network isolation mechanism, even if there are vulnerabilities or configuration errors in the server software, data from different departments cannot be accessed across physical network boundaries, fundamentally eliminating the risk of cross-departmental data leakage.
[0090] When strong logical isolation is used for the internal data storage area, data isolation is achieved by creating multiple independent logical volumes or database instances, each of which corresponds to a specific department identifier. Independent logical volumes are logical storage units divided on a shared physical storage infrastructure using storage virtualization technology. Each logical volume has independent storage space and access control policies. In actual implementation, these logical volumes can be created and managed using the logical unit number (LUN) technology of the storage area network (SAN) or software-defined storage (SDS) technology. For example, on a large storage array, multiple independent RAID volume groups can be created, and dedicated logical volumes can be allocated to each department.
[0091] For database storage, independent database instances can be created for different departments. Each instance has its own data files, log files, and configuration parameters, which are completely logically separated. Strong logical isolation ensures that data between different logical volumes or database instances cannot access each other through multi-level access control mechanisms. These mechanisms include but are not limited to: LUN masking and LUN mapping technology to ensure that each server can only see and access the logical volumes assigned to it; storage-level access control lists (ACLs) to define which hosts can access specific storage resources; multi-factor authentication and encrypted communications to ensure that only authorized users and servers can access storage resources; and fine-grained permission control to limit users to specific operations (such as read-only access or full control). Through these strong logical isolation measures, effective isolation of data from different departments can be achieved even in the case of shared physical infrastructure, preventing unauthorized cross-departmental data access.
[0092] This implementation method builds a comprehensive and in-depth data security protection system through a combination of physical isolation and strong logical isolation. The physical isolation method cuts off the access channels between data of different departments from the hardware level through completely independent storage array partitions and physical network isolation, providing the highest level of security for the most sensitive data. The strong logical isolation method uses independent logical volumes or database instances, combined with a multi-level access control mechanism, to achieve effective data isolation under the condition of shared physical infrastructure. This dual isolation strategy enables the server to select the most suitable isolation method based on the sensitivity and security requirements of data from different departments, which not only meets strict security standards but also takes into account the flexibility and cost-effectiveness of the server. In this way, the private domain intelligent body can safely process sensitive data from multiple departments in a single server, effectively preventing data leakage and unauthorized access, and is particularly suitable for fields with strict requirements on data security, such as government, finance, and medical care.
[0093] In one implementation of this embodiment, the strong logical isolation method includes the following steps:
[0094] S510, using VLAN technology to divide the internal data storage area into independent network areas, and restricting the internal data interface module of each department and the corresponding internal data storage area access path to the corresponding VLAN;
[0095] S520. Use a firewall policy to prevent unauthorized access across VLANs and prevent direct or indirect communication between data storage areas within different departments.
[0096] S530. Create a corresponding independent logical volume or database instance for each department, and assign different database user permissions to each independent logical volume;
[0097] S540. Use a separate directory for file storage and configure operating system-level access control permissions.
[0098] In the steps of using VLAN technology to divide the internal data storage area into independent network areas and restricting each department's internal data interface module and the corresponding internal data storage area access path to the corresponding VLAN, Virtual Local Area Network (VLAN) technology was adopted to achieve logical isolation at the network level. VLAN is a technology that divides a single physical network into multiple logical networks. By adding VLAN tags (IEEE802.1Q standard) to data frames, even devices connected to the same physical switch can be divided into different broadcast domains, as if they were connected to different physical networks.
[0099] In actual deployment, the network switch must first be configured with VLANs to assign a unique VLAN ID to each department. After configuration is complete, the ports of each department's servers, storage devices, and network devices are assigned to the corresponding VLANs. At the same time, the internal data interface module is configured so that it can only access the corresponding department's internal data storage area through a specific VLAN. This configuration can be achieved through switch port VLAN membership settings, 802.1Q trunk link configuration, and VLAN access control lists (VACLs). Through this VLAN isolation mechanism, even if devices from different departments are physically connected to the same network infrastructure, their network traffic will be restricted to their respective VLANs and will not be able to directly access devices and resources in other VLANs, thus achieving strong departmental data isolation at the network level.
[0100] In implementing a firewall strategy to prevent unauthorized cross-VLAN access and direct or indirect communication between data storage areas within different departments, a multi-layered firewall and access control mechanism was deployed to supplement and reinforce VLAN isolation. The core of the firewall strategy is the strict default-deny principle, which means that all cross-VLAN communication is blocked unless explicitly permitted.
[0101] Within the network architecture, various firewall deployment models can be adopted, including deploying traditional firewalls at inter-VLAN routing points, enabling distributed firewall functionality on core switches, or deploying next-generation firewalls for more advanced protection. Firewall rule configuration adheres to the principle of least privilege, allowing only necessary, explicitly authorized traffic. For example, a rule can be configured to allow all VLANs access to the central authentication server (located in VLAN 999), but prohibit any direct communication between VLAN 100 (Finance Department) and VLAN 200 (HR Department). To prevent indirect communication and data leakage, the firewall also implements deep packet inspection (DPI) and application-layer filtering to identify and block advanced techniques that may be used to circumvent isolation, such as tunneling protocols, proxy services, or data smuggling. Furthermore, the firewall logs all cross-VLAN access attempts, especially blocked access attempts, and these logs are sent in real time to a security information and event management server for analysis to identify potential security threats. These strict firewall policies not only effectively prevent unauthorized cross-VLAN access but also prevent indirect communication through intermediate servers or services, thereby establishing a solid security barrier at the network level.
[0102] By creating independent logical volumes or database instances for each department and assigning distinct database user permissions to each independent logical volume, we implement isolation measures at both the storage and database levels, ensuring effective data isolation between departments even when sharing physical storage infrastructure. At the storage level, we use storage virtualization technology to create independent logical volumes for each department. These logical volumes can be implemented based on storage area network logical unit number technology, software-defined storage technology, or virtualized storage array technology. Each logical volume has independent storage space, performance configuration, and security settings, providing complete logical separation. For example, on an enterprise-class storage array, we can create multiple RAID volume groups and allocate dedicated logical volumes to different departments based on these volume groups. At the database level, various isolation strategies can be adopted: 1. Deploy a completely independent database instance for each department, each with its own processes, memory space, and configuration parameters; 2. Create independent database schemas within a shared database instance and implement isolation through the database's access control mechanisms; 3. Use multi-tenant database technology to create logically isolated tenant spaces for different departments within the same database. Regardless of the strategy adopted, strict database user permissions must be configured. This includes creating department-specific database user accounts, implementing role-based access control, limiting each user to access only the data of their department, and further subdividing permissions based on user responsibilities (such as read-only, read-write, or administrator permissions). In this way, even at the database level, effective isolation of data from different departments can be achieved to prevent unauthorized cross-departmental data access.
[0103] By using separate directories for file storage and configuring operating system-level access control permissions, file system-level isolation measures are implemented, providing additional protection for unstructured data (such as documents, images, and videos). When designing the file storage architecture, first create a separate top-level directory structure for each department on the file system or network-attached storage device. These directories can be physically separate file systems or logically isolated folders. For example, top-level directories such as " / finance," " / hr," and " / legal" can be created to store file data for the finance, HR, and legal departments, respectively. Within these separate directories, strict operating system-level access control permissions are configured to restrict user access to only the directories of their respective departments. This access control can be implemented through a variety of mechanisms, including the traditional permissions model and access control lists in UNIX / Linux systems; NTFS permissions and share permissions in Windows systems; and more advanced mandatory access control or attribute-based access control.
[0104] During specific configuration, ownership of departmental directories can be assigned to a dedicated system user group, and appropriate permission masks can be set to ensure that only members of this user group can access the corresponding directories. For example, the finance department's directories may be configured to allow access only to members of the "finance_group" group, while prohibiting direct access by other users or even system administrators. In addition, file system encryption can be implemented to encrypt file data using department-specific encryption keys, protecting data security even at the physical access level. These file system-level isolation measures ensure the secure storage and access of unstructured data and prevent unauthorized cross-departmental file data access.
[0105] This implementation method builds a data security architecture with deep defense, forming a complete security protection chain. VLAN technology creates logical isolation boundaries at the network level, firewall policies strengthen these boundaries and prevent any unauthorized cross-border access, independent logical volumes and database isolation ensure the secure storage and access of structured data, and file server-level access control protects the security of unstructured data. This comprehensive and strong logical isolation mechanism achieves security guarantees close to the physical isolation level in the case of shared physical infrastructure, while maintaining server flexibility and cost-effectiveness. In this way, private domain intelligent entities can securely process sensitive data from multiple departments in a single server, effectively preventing data leakage and unauthorized access, and are particularly suitable for application scenarios that require a balance between data security and server flexibility.
[0106] In one implementation of this embodiment, the data service interface layer further includes an external data gateway module, the data storage layer further includes an external data cache area, and the agent engine performs processing tasks, analyzes and processes the data to be processed, and obtains processing results, including the following steps:
[0107] S610, the intelligent agent engine analyzes the data to be processed and determines whether external data support is needed;
[0108] S620: When external data support is required, the agent engine sends an external data request to the external data gateway module. The external data gateway module is used to obtain external data from the external network according to preset rules and store the external data in the external data cache area.
[0109] S630, the intelligent agent engine accesses the external data cache, obtains external data, and executes processing tasks to analyze and process the data to be processed and the external data to obtain processing results, wherein the processing tasks include at least one of data analysis, pattern recognition, text classification, information extraction or decision support.
[0110] In this embodiment, the intelligent agent engine first performs a preliminary analysis and evaluation on the data to be processed obtained from the internal data storage area to determine whether additional external data is needed to supplement, verify or enrich the existing data, thereby improving the accuracy and completeness of the processing results.
[0111] During specific implementation, the intelligent agent engine will first perform a structured analysis of the data to be processed, extract key entities, attributes and relationships, and build a preliminary knowledge graph or semantic network. Subsequently, the engine will evaluate the completeness and adequacy of the existing data based on the predefined domain knowledge model. For example, when processing a policy analysis task, if a document mentions a certain regulation but lacks specific terms, the engine will mark this information gap. Various factors will be considered in the evaluation process, including the timeliness of the data (whether the latest external data update is required), completeness (whether key information is missing), accuracy (whether external data verification is required), and contextual relevance (whether additional background information is needed). If the existing data has at least one of the above factors, it is determined that external data support is required.
[0112] The agent engine sends an external data request to the external data gateway module. This module retrieves external data from the external network according to pre-set rules and stores it in the external data cache, implementing a secure and controllable external data acquisition mechanism. When the agent engine determines that external data support is required, it constructs a structured external data request, including the type, scope, timeliness requirements, and purpose of the required data.
[0113] These requests are sent through an internal secure channel to the external data gateway module, which is responsible for all external data interactions. Upon receiving the request, the external data gateway module first evaluates it according to pre-set security rules. These rules define various constraints, such as the types of external data permitted, accessible external data sources, access frequency limits, and data sensitivity checks. For example, the rules allow access to official regulatory repositories and public academic databases, but prohibit access to unverified data sources.
[0114] Once the assessment is passed, the gateway module selects appropriate external data sources for query based on the request. These data sources include public government databases, regulatory repositories, academic resource repositories, industry standard repositories, or other authorized reference repositories. The data acquisition process uses secure communication protocols (such as HTTPS, SFTP, etc.) and may require identity authentication and access authorization. The acquired external data then undergoes security processing, including format standardization, integrity verification, malicious code scanning, and sensitive information filtering to ensure data security and availability.
[0115] Processed external data is stored in the external data cache, a dedicated storage space physically or logically isolated from the internal data storage area, used to temporarily store externally acquired data. The cache utilizes strict access controls and data lifecycle management to ensure that external data is not mixed with sensitive internal data and is promptly cleared after use. This strictly controlled external data acquisition mechanism enables private-domain agents to obtain necessary external knowledge support while ensuring security.
[0116] The intelligent agent engine accesses the external data cache, obtains external data, and executes processing tasks to analyze and process the data to be processed and external data to obtain processing results. The intelligent agent engine can integrate and analyze internal data with external data, thereby giving full play to the complementary advantages of the two data sources and improving the quality and value of the processing results.
[0117] Specifically, the intelligent agent engine reads external data stored in the external data cache through a controlled access channel. This access process is subject to strict permission control and behavior monitoring to ensure that only authorized processing tasks can use these external data. After obtaining the external data, the engine will perform data fusion processing to associate, compare and integrate the external data with the internal data to be processed. The technical means used in data fusion include entity alignment (identifying records referring to the same entity in different data sources), relationship mapping (establishing logical associations between different data sets), time series alignment (processing data of different time granularities), etc. The fused data set provides a more comprehensive information basis for subsequent in-depth analysis.
[0118] The intelligent agent engine then performs the corresponding analysis and processing based on the specific requirements of the processing task. For data analysis tasks, methods such as statistical analysis, time series analysis, or association rule mining may be used to discover implicit patterns and trends in the data. For pattern recognition tasks, machine learning algorithms such as support vector machines, random forests, or deep neural networks may be applied to identify complex data patterns. For text classification tasks, natural language processing techniques such as bag-of-words models, TF-IDF, or pre-trained language models may be used to classify text content. For information extraction tasks, named entity recognition, relationship extraction, or event detection techniques may be used to extract structured information from unstructured text. For decision support tasks, methods such as rule reasoning, decision trees, or Bayesian networks may be combined to provide decision recommendations.
[0119] After processing is complete, the engine generates structured results, clearly marking which parts are based on internal data and which parts reference external data, ensuring interpretability and traceability. Finally, the engine cleans up temporary data used during processing and updates the external data usage record to provide a basis for subsequent audits and security checks. Through this integrated analysis and processing mechanism for internal and external data, the private domain intelligent agent can fully utilize external knowledge resources while protecting the security of internal sensitive data, providing more comprehensive and accurate analysis results.
[0120] This implementation method builds a secure and controllable knowledge expansion channel. Through the demand analysis of the intelligent agent engine, the secure acquisition of external data gateways and the isolated storage of external data cache areas, the secure integration of internal sensitive data and external public data is achieved. Under the premise of ensuring data security, the knowledge breadth and processing capabilities of the private domain intelligent agent are significantly enhanced. The introduction of external data enables the intelligent agent to obtain the latest laws, regulations, policies, industry standards and public reference materials, avoids the information island effect, and improves the timeliness and comprehensiveness of the analysis results. At the same time, strict external data acquisition rules and isolated storage mechanisms ensure that external data will not become a security vulnerability, effectively preventing data leakage and pollution risks. This design that balances security and functionality enables private domain intelligent agents to provide open-view intelligent services in a closed environment.
[0121] In one implementation of this embodiment, the private domain agent further includes a security management layer, which includes a unified authentication and authorization center, a security audit module, and a monitoring and management platform. The agent engine obtains a temporary access credential based on the department identifier and accesses the department's internal data storage area based on the temporary access credential to obtain data to be processed, including the following steps:
[0122] S710. The intelligent agent engine sends a permission request to the unified authentication and authorization center. The permission request includes a department identifier. The unified authentication and authorization center generates a temporary access credential based on the department identifier and returns the temporary access credential to the intelligent agent engine. The temporary access credential only has the authority to access the corresponding department's internal data storage area.
[0123] S720. The intelligent agent engine uses the temporary access credentials to access the corresponding department's internal data storage area to obtain the data to be processed.
[0124] In this embodiment, when the intelligent agent engine needs to access the internal data of a specific department, it first constructs a structured permission request message, which contains multiple key elements: the identity of the request initiator (the unique identifier of the intelligent agent engine), the request timestamp, the department identifier (indicating the target department data that needs to be accessed), the purpose of the request (the type and description of the processing task), the requested data range (the type and range of data that needs to be accessed), and the request validity period (the expected duration of data access). This information is sent to the unified authentication and authorization center in the security management layer through a secure channel (such as a TLS encrypted connection). As the core security component of the private domain intelligent agent, the unified authentication and authorization center is responsible for all access control decisions, and it maintains a complete permission policy library and access control matrix.
[0125] Upon receiving a permission request, the Unified Authentication and Authorization Center (hereinafter referred to as the Center) first verifies the authenticity and integrity of the request, ensuring it has not been tampered with and originates from a legitimate agent engine. The Center then queries the permission policy library based on the department ID to assess the legitimacy of the request. This assessment considers various factors, including but not limited to: the current security policy configuration, the requester's historical behavior, the data sensitivity classification, and access time window restrictions.
[0126] If the assessment result is that access is allowed, the center will generate a temporary access credential. This credential is in the format of an encrypted token (such as JWT, JSON Web Token) and contains the following information: credential ID, authorization scope (limited to the internal data storage area of a specific department), validity period (usually short-term, such as 15 minutes), access restrictions (such as read-only or read-write permissions), and digital signatures (signed with the center's private key to ensure that the credential cannot be forged). The generated temporary access credential is returned to the intelligent agent engine through a secure channel. At the same time, the center will record a complete authorization log, including request details, decision results, and credential information. These logs will be sent to the security audit module for subsequent compliance checks and security analysis. Through this temporary credential-based authorization mechanism, the server implements the principle of least privilege and dynamic authorization control, ensuring that even internal components must undergo strict permission verification before accessing sensitive data.
[0127] After obtaining the temporary access credentials, the agent engine uses them to access the target department's internal data storage. The access process begins by constructing a secure access request. The engine embeds the temporary access credentials into the data access request, forming a complete authentication request. This request is sent to the target department's internal data storage via a dedicated secure data access protocol (such as a secure API call, an encrypted database connection, or a secure file transfer protocol).
[0128] The access control layer of the internal data store receives and processes this request, first verifying the validity of the temporary access credentials. This includes checking the digital signature of the credentials (using the public key of the unified certification authority), confirming that the credentials have not expired, and verifying that the access scope specified in the credentials matches the current request. Once verification is successful, the access control layer determines the specific datasets that are allowed access based on the scope of authorization in the credentials.
[0129] After determining the access scope, the data storage area will perform the actual data retrieval operation, which may include database queries, file reading, or object storage access. The retrieved data will be returned to the intelligent agent engine after sensitive fields are desensitized, data format standardization, or data integrity verification. During the entire access process, the server will record detailed access logs, including access time, credentials used, data scope accessed, and data operation type (such as reading, writing, or modifying). These logs are sent to the security audit module in real time for access behavior analysis and anomaly detection. It is worth noting that temporary access credentials have strict scope restrictions, ensuring that the intelligent agent engine can only access data of a specific department and cannot cross the boundary to access data of other departments. At the same time, the temporary nature of the credentials also reduces the risk window of credential leakage or abuse. Through this refined access control mechanism based on temporary credentials, the server minimizes the risk of data leakage and unauthorized access while providing necessary data access capabilities.
[0130] This implementation achieves security control by separating permission requests and data access into two independent steps. That is, the intelligent agent engine must first obtain a valid temporary access credential before it can use the credential to access the target data. In this way, even the internal components of the server must undergo strict authentication and authorization before accessing sensitive data, further enhancing the security of the data and effectively preventing advanced attack methods such as privilege escalation and lateral movement. At the same time, the unified authentication and authorization center, as a central authority management point, provides consistent security policy enforcement and comprehensive access auditing capabilities, enabling security managers to globally control the data access behavior of the server. This security mechanism, while ensuring data isolation, still allows the intelligent agent engine to efficiently process data within the authorized scope, achieving a balance between security and functionality. For government, financial, medical and other institutions that handle highly sensitive data, this refined permission control based on temporary credentials provides a data processing solution that meets compliance requirements, effectively reducing the risk of data leakage.
[0131] In one implementation of this embodiment, the data storage layer further includes a public external data area, and further includes the following steps:
[0132] S810. Before executing a processing task, the agent engine obtains the user terminal's access rights to the data to be processed, and determines a data access scope of the user terminal to the data to be processed based on the access rights.
[0133] S820, the agent engine accesses the internal data storage area and the public external data area within the data access range during the execution of the processing task;
[0134] S830. After executing the processing task, the intelligent agent engine clears the temporary data in the process of executing the processing task and releases the temporary access credentials.
[0135] In the data storage layer, in addition to each department's internal data storage area, a public external data area is also established. This public external data area is used to store non-sensitive data that can be shared and accessed by multiple departments, such as public policy documents, shared reference materials, and industry standards and specifications. While this data is not highly sensitive, it still holds important reference value for each department's business operations. While the public external data area utilizes centralized storage management, strict access control policies are still implemented to ensure data integrity and availability. Physically, the public external data area can be deployed on a separate storage array or logically separated from the internal data storage area and managed through different storage pools and access paths. The establishment of a public external data area reduces redundant data storage while improving server resource utilization. It also meets the shared data access needs of different departments, maximizing data resource utilization while ensuring data security.
[0136] Before executing a processing task, the intelligent agent engine first needs to obtain the user terminal's access rights to the data to be processed, and determine the data access scope of the user terminal to the data to be processed based on the access rights. In specific implementation, the intelligent agent engine will extract the user identity information and department identification from the data processing request sent by the user terminal, and then send a permission verification request to the unified authentication and authorization center of the security management layer. The unified authentication and authorization center will perform permission evaluation based on the pre-configured permission matrix, combined with multi-dimensional information such as user identity, department, and rank. During the permission evaluation process, the user's precise access scope to the data to be processed can be dynamically calculated. For example, ordinary staff members of a government department may only be authorized to access the department's non-confidential documents and public reference materials; while department leaders may be authorized to access all the department's files and some shared files of other specific departments.
[0137] After permission verification is passed, the unified authentication and authorization center generates a permission token containing a detailed description of the access scope and returns it to the agent engine. The agent engine parses the permission token and extracts the specific data access scope, including restrictions such as the type of data, data hierarchy, and time range. This refined permission control mechanism ensures that users can only access and process data within the authorized scope, effectively preventing unauthorized access and data leakage risks, while also providing clear boundary constraints for subsequent data processing operations.
[0138] In the process of executing processing tasks, the intelligent agent engine accesses the internal data storage area and the public external data area strictly within the determined data access scope. In specific implementation, the intelligent agent engine will first analyze the required data type and source according to the needs of the processing task. For operations that require access to the internal data storage area, the intelligent agent engine will use the temporary access credentials obtained above to connect to the internal data storage area of the corresponding department through a secure channel. During the access process, the intelligent agent engine will check in real time whether each data request is within the authorized access scope. If it is found that the request is out of scope, it will immediately reject and record the abnormal access attempt. For access to public external data areas, the intelligent agent engine also needs to verify the user's access rights to public data. Although this data is relatively insensitive, it is still necessary to follow the principle of minimum necessity and only obtain the data required for the processing task.
[0139] During data access, the agent engine maintains an operation log, recording all data access behaviors, including access time, access object, access type, and other information, for subsequent audit and traceability. This strictly controlled data access mechanism ensures that processing tasks can obtain necessary data support while effectively preventing cross-border access and misuse of data, achieving a balance between data security and efficiency.
[0140] After executing a processing task, the intelligent agent engine needs to clear the temporary data generated during the processing task and release the temporary access credentials. In specific implementation, the intelligent agent engine will first identify and collect all temporary data generated during the processing process, including intermediate calculation results, temporary cache files, data objects in memory, etc. For temporary files stored on the disk, secure erasure technology is used to completely delete them, such as multiple overwrites or the use of professional data erasure algorithms to ensure that the data cannot be recovered by data recovery tools. For temporary data in memory, the intelligent agent engine will explicitly release the relevant memory space and overwrite the memory when necessary to prevent sensitive information from remaining in the memory. For temporary tables or records in the database, cleanup operations will be performed to ensure that no processing traces are left. While clearing temporary data, the intelligent agent engine will also send a credential release request to the unified authentication and authorization center to cancel the temporary access credentials obtained previously.
[0141] After receiving the request, the unified authentication and authorization center will immediately revoke the validity of the credential and update the permission status record. In order to prevent the abuse of credentials, the server will also implement credential lifecycle management. Even if the intelligent agent engine does not actively release it, the temporary access credential will automatically expire after the preset validity period. In addition, the intelligent agent engine will also generate an execution report for the processing task, recording the main steps of data processing, result summary, and resource usage, but does not include original sensitive data. This report will be securely stored for subsequent audits and analysis. Through this strict post-processing mechanism, it is ensured that sensitive data will not be leaked or retained due to the execution of processing tasks, further enhancing the data security protection capabilities of the server.
[0142] This embodiment achieves efficient sharing and secure use of data resources in a strongly isolated environment by adding a public external data area to the private domain intelligent body and implementing strict permission control and data lifecycle management. First, through a refined permission management mechanism, the server can dynamically determine the data access scope based on user identity and business needs, ensuring that users can only operate data within the authorized scope, effectively preventing unauthorized access. Secondly, during the execution of the task, the intelligent body engine strictly accesses data within the authorized scope, and through secure channels and real-time permission verification, it ensures the compliance and security of data access. Finally, by completely clearing temporary data and releasing access credentials in a timely manner, the server eliminates potential security risks that may exist after data processing, ensuring that sensitive information will not be leaked due to processing tasks. This comprehensive data security protection mechanism not only meets the strict requirements of government agencies, financial institutions, etc. for data privacy, but also achieves efficient sharing of non-sensitive data through the setting of public external data areas, thereby improving server resource utilization and data processing efficiency. Overall, the solution provided by this embodiment maximizes the use of data value while ensuring data security, providing reliable technical support for the application of private domain intelligent bodies in highly sensitive fields.
[0143] The embodiment of the present application further provides a server, which is deployed with a private domain intelligent agent. The private domain intelligent agent includes a data storage layer, an engine layer, and a data service interface layer. The data storage layer includes multiple internal data storage areas, the engine layer includes an intelligent agent engine, and the data service interface layer includes an output interface module and multiple internal data interface modules, including:
[0144] a memory configured to store instructions; and
[0145] The processor is configured to call instructions from the memory and implement the above-mentioned strongly isolated private domain intelligent body data processing method when executing the instructions.
[0146] An embodiment of the present application also provides a computer program product, including a computer program or instructions, which implements the above method when the computer program or instructions are executed on a processing device.
[0147] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0148] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram and the combination of the processes and / or blocks in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0149] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0150] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0151] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0152] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0153] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0154] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0155] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
Claims
1. A strongly isolated private domain intelligent agent data processing method, characterized in that: The method is applied to a server, where a private domain agent is deployed. The private domain agent includes a data storage layer, an engine layer, and a data service interface layer. The data storage layer includes multiple internal data storage areas, the engine layer includes an agent engine, and the data service interface layer includes an output interface module and multiple internal data interface modules. Receive a data processing request sent by a user through a user terminal and obtain a department ID; Routing the data processing request to the corresponding internal data interface module based on the department ID, wherein the internal data interface module is used to parse the data processing request, obtain the processing task, and call the agent engine, which is used to obtain a temporary access credential based on the department ID and access the department's internal data storage area based on the temporary access credential to obtain the data to be processed; and The intelligent agent engine is used to execute processing tasks, analyze and process the data to be processed, obtain processing results, and transmit the processing results to the user terminal through the output interface module.
2. The method according to claim 1, characterized in that Receive a data processing request sent by a user through a user terminal and obtain the department ID, including: Receive official document data uploaded by the user through the user terminal and assign a unique identifier to the official document data; Receive a data processing request for official document data sent by a user, where the data processing request includes a unique identifier and a department identifier.
3. The method according to claim 1, characterized in that The internal data storage area is isolated by physical isolation and / or strong logical isolation.
4. The method according to claim 1, wherein include: In the case where the internal data storage area is isolated by a physical isolation method, the internal data storage area includes a plurality of storage array partitions, each storage array partition corresponds to a department identifier on a one-to-one basis, and data between each storage array partition and other storage array partitions cannot be accessed by physical isolation, wherein the physical isolation method is physical network isolation; When the internal data storage area is isolated by a strong logical isolation method, the internal data storage area includes multiple independent logical volumes corresponding to department identifiers one by one, and the data between each independent logical volume and other independent logical volumes cannot be accessed by each other through the strong logical isolation method.
5. The method according to claim 4, characterized in that Strong logical isolation methods include: Use VLAN technology to divide the internal data storage area into independent network areas, and restrict each department's internal data interface module and the corresponding internal data storage area access path to the corresponding VLAN; Use firewall policies to prevent unauthorized access across VLANs and prevent direct or indirect communication between data storage areas within different departments; Create a corresponding independent logical volume for each department and assign different database user permissions to each independent logical volume; Use separate directories for file storage and configure operating system-level access control permissions.
6. The method according to claim 1, characterized in that The data service interface layer also includes an external data gateway module, and the data storage layer also includes an external data cache area. The intelligent agent engine performs processing tasks, analyzes and processes the data to be processed, and obtains processing results, including: The intelligent agent engine analyzes the data to be processed and determines whether external data support is needed; When external data support is needed, the agent engine sends an external data request to the external data gateway module. The external data gateway module is used to obtain external data from the external network according to preset rules and store the external data in the external data cache area; The intelligent agent engine accesses the external data cache, obtains external data, and executes processing tasks to analyze and process the data to be processed and the external data to obtain processing results, wherein the processing tasks include at least one of data analysis, pattern recognition, text classification, information extraction or decision support.
7. The method according to claim 1, characterized in that The private domain intelligent agent also includes a security management layer, which includes a unified authentication and authorization center. The intelligent agent engine obtains temporary access credentials based on the department ID and accesses the department's internal data storage area based on the temporary access credentials to obtain the data to be processed, including: The intelligent agent engine sends a permission request to the unified authentication and authorization center. The permission request includes the department ID. The unified authentication and authorization center is used to generate a temporary access credential based on the department ID and return the temporary access credential to the intelligent agent engine. The temporary access credential has and only has the permission to access the corresponding department's internal data storage area. The intelligent agent engine uses temporary access credentials to access the corresponding department's internal data storage area to obtain the data to be processed.
8. The method according to claim 1, characterized in that The data storage layer further includes a public external data area, and the method further includes: Before executing a processing task, the agent engine obtains the user terminal's access rights to the data to be processed, and determines the data access scope of the user terminal to the data to be processed based on the access rights; In the process of executing the processing task, the agent engine accesses the internal data storage area within the data access range; After executing the processing task, the intelligent agent engine clears the temporary data in the process of executing the processing task and releases the temporary access credentials.
9. A server, characterized in that: A private domain agent is deployed, which includes a data storage layer, an engine layer, and a data service interface layer. The data storage layer includes multiple internal data storage areas, the engine layer includes an agent engine, and the data service interface layer includes an output interface module and multiple internal data interface modules, including: a memory configured to store instructions; and A processor is configured to call the instructions from the memory and to implement the strongly isolated private domain intelligent body data processing method according to any one of claims 1 to 8 when executing the instructions.
10. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed on a processing device, the method according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Authority control method and business processing method
CN117375856A
Data access method, device and equipment and readable storage medium
CN119203181A
Enterprise information sharing management method, system and device and storage medium
CN119272256A
Efficient Dispatch of Messages Based on Message Headers
US20070168546A1
System and method for subscriber-based policy management
US20140126369A1
Cited By
Network security isolation system based on rail transit vehicle network information processing
CN121585462A
Intelligent agent development and safe operation method and system based on private cloud
CN121711148A
An agent credential isolation method, system, device and medium
CN122548754A