A data compliance management method and system based on security capability scenario arrangement

By employing a scenario-based orchestration approach based on security capabilities, and utilizing workflow engines and resource scheduling algorithms, the problem of inconsistent data security protection strategies was resolved, achieving consistency and collaborative protection of security policies and improving data protection effectiveness.

CN114091051BActive Publication Date: 2026-05-12GLOBAL ENERGY INTERCONNECTION RES INST CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GLOBAL ENERGY INTERCONNECTION RES INST CO LTD
Filing Date
2021-10-28
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

In existing technologies, inconsistent data security protection strategies lead to the failure of protection strategies and even make the data unusable. Furthermore, the fragmented deployment of data security tools limits their effectiveness.

Method used

By employing a scenario-based orchestration approach based on security capabilities, a workflow engine is used to determine the data security hardware and software tools and generate invocation instructions. The tool status information and collaboration relationships are considered to ensure the consistency of security policies. The leaky bucket algorithm and token bucket algorithm are used to optimize resource scheduling and ensure the effective execution of protection policies.

Benefits of technology

It achieves consistency in security policies, improves protection effectiveness, ensures collaborative protection of data security tools, avoids the failure of protection policies, and improves the reliability of data use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114091051B_ABST
    Figure CN114091051B_ABST
Patent Text Reader

Abstract

The application provides a data compliance management method and system based on security capability scenario arrangement, comprising: based on a data security protection process to be executed, determining a data security software and hardware tool to be called from a pre-prepared workflow engine, and acquiring state information of the data software and hardware tool; based on the workflow engine, the state information of the data security software and hardware tool, and a preset calling mode, generating a calling instruction for calling the data security software and hardware tool; wherein the workflow engine is obtained by using a computer language to describe a security policy involved in a data security protection process, a data security software and hardware tool required by the security policy, and a cooperation relationship between the data security software and hardware tools. The application realizes consistency of the security policy, and better plays the efficiency of the protection policy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of scenario-based orchestration, specifically to a data compliance management method and system based on scenario-based orchestration of security capabilities. Background Technology

[0002] In the process of data security protection, different data security measures may be used simultaneously. Consistent security strategies are essential for effective protection; otherwise, the protection strategy may fail, or even render the data unusable. Currently, most data security tools are provided independently by vendors, resulting in fragmented deployment of data security measures and difficulty in ensuring consistent data security strategies, which limits the effectiveness of these tools. Power grid data applications are complex and face diverse data security risks. Therefore, it is necessary to achieve coordinated protection by flexibly utilizing various data security capabilities based on specific scenarios, while maintaining unified management of various data security tools. Summary of the Invention

[0003] To address the problem of inconsistent security policies in existing technologies leading to protection strategy failures and even data unusability, this invention provides a data compliance management method based on scenario-based orchestration of security capabilities, including:

[0004] Based on the data security protection process to be executed, the data security software and hardware tools to be invoked are determined from the pre-defined workflow engine, and the status information of the data software and hardware tools is obtained.

[0005] Based on the workflow engine, the status information of the data security software and hardware tools, and the preset invocation method, an invocation instruction for invoking the data security software and hardware tools is generated;

[0006] The workflow engine is described using computer language to describe the security policies involved in the data security protection process, the data security software and hardware tools required by the security policies, and the collaborative relationships between the various data security software and hardware tools.

[0007] Preferably, the workflow engine is developed through the following steps:

[0008] The relevant security strategies are determined based on the data security protection process;

[0009] The data security hardware and software tools to be used are determined based on each security policy;

[0010] Based on the collaborative relationships between various data security software and hardware tools, the execution order of each data security software and hardware tool is generated;

[0011] The workflow engine is derived by describing the various data security hardware and software tools in the order of execution using computer language.

[0012] Preferably, the collaborative relationship includes: chain mode, parallel aggregation mode, and branch mode.

[0013] Preferably, the step of generating the invocation instruction for the data security software and hardware tools based on the status information of the workflow engine and the data security software and hardware tools, and a preset invocation method, includes:

[0014] Based on the workflow engine, the required data security software and hardware tools and the collaborative relationships between these tools are determined.

[0015] Based on the collaboration relationship between the data security software and hardware tools and the status information of the data security software and hardware tools, the consistency between the data security software and hardware tools is measured to obtain the measurement results;

[0016] Based on the status information of the data security software and hardware tools, the measurement results, and the invocation method, an invocation instruction for invoking the data security software and hardware tools is generated;

[0017] The invocation methods include: sequential automatic invocation or scenario-triggered invocation.

[0018] Preferably, the measurement of consistency among the data security software and hardware tools based on their collaborative relationship and status information, to obtain measurement results, includes:

[0019] The measurement results of the various data security software and hardware tools that are executed serially or whose execution results affect each other are considered to have strong consistency.

[0020] The measurement results of the various data security software and hardware tools that are executed in parallel or whose execution results do not affect each other are considered weakly consistent.

[0021] Preferably, the step of generating the invocation instruction for the data security software and hardware tools based on the status information of the data security software and hardware tools and the measurement results includes:

[0022] Determine whether the status information of the data security software and hardware tools exceeds the load capacity limit of the data security software and hardware tools.

[0023] When the load capacity limit of the data security software and hardware tools is exceeded, and the measurement results among the data security software and hardware tools are strongly consistent, the leaky bucket algorithm or token bucket algorithm is used to control the rate at which business requests enter the system, and function start and function end instructions are generated.

[0024] When the load capacity limit of the data security software and hardware tools is not exceeded, and the measurement results among the data security software and hardware tools are strongly consistent, the workflow engine generates function start and function end instructions accordingly.

[0025] When the load capacity limit of the data security software and hardware tools is not exceeded, and the measurement results between the data security software and hardware tools are weakly consistent, the workflow engine generates a function suspension instruction.

[0026] Based on the same inventive concept, this invention also provides a data compliance management method based on security capability scenario-based orchestration, including:

[0027] The data security hardware and software tools feed back status information to the data security capability scheduling module and execute tasks based on the call instructions issued by the data security capability scheduling module;

[0028] The data security capability scheduling module generates a call instruction based on the status information fed back by the pre-defined workflow engine and the data security software and hardware tools.

[0029] The workflow engine is described using computer language to describe the security policies involved in the data security protection process, the data security software and hardware tools required by the security policies, and the collaborative relationships between the various data security software and hardware tools.

[0030] Based on the same inventive concept, the present invention also provides a data compliance management system based on security capability scenario orchestration, including: a data security capability scheduling module;

[0031] The data security capability scheduling module is used to determine the data security software and hardware tools from the pre-defined workflow engine according to the data security protection process to be executed, obtain the status information fed back by the data security software and hardware tools, and generate a call instruction.

[0032] The workflow engine is described using computer language to describe the security policies involved in the data security protection process, the data security software and hardware tools required by the security policies, and the collaborative relationships between the various data security software and hardware tools.

[0033] Preferably, it also includes a scenario-based script description module;

[0034] The scenario-based script description module is used to determine the security strategies involved based on the data security protection process, then determine the data security software and hardware tools to be used based on each security strategy, and then generate the execution order of each data security software and hardware tool based on the cooperation relationship between them. Finally, the workflow engine is obtained by describing each data security software and hardware tool in computer language according to the execution order.

[0035] Preferably, the scenario-based script description module includes a script editing submodule and a workflow engine conversion module. The script editing submodule is used to describe the security policies corresponding to each scenario, the data security software and hardware tools required by the security policies, the mutual cooperation relationships between the data security software and hardware tools, and the calling methods using computer language, thereby obtaining the scripts corresponding to each scenario. The workflow engine conversion module is used to generate the execution order of each data security software and hardware tool in the scripts corresponding to each scenario according to the calling methods of each scenario and the cooperation relationships between the data security software and hardware tools. The workflow engine is constructed by the data security software and hardware tools and the execution order, and the workflow engine is sent to the data security capability scheduling module.

[0036] Preferably, the data security capability scheduling module includes: a resource on-demand scheduling submodule, a policy consistency judgment submodule, and a capability standardization interface submodule;

[0037] The policy consistency judgment submodule is used to receive status information fed back by the data security software and hardware tools, measure the consistency between each data security software and hardware tool, and send the measurement result to the resource on-demand scheduling submodule.

[0038] The resource on-demand scheduling submodule is used to generate a call instruction based on the status information of the workflow engine sent by the workflow engine conversion module, the status information fed back by the data security software and hardware tools, and the measurement results between the data security software and hardware tools, and then send it to the capability standardization interface submodule.

[0039] The capability standardization interface submodule is used to control the security software and hardware tools according to the calling instructions.

[0040] Preferably, the policy consistency judgment submodule includes: a strong consistency unit, a weak consistency unit, and a forwarding unit;

[0041] The strong consistency unit is used to ensure that the measurement results of the various data security software and hardware tools, which are executed serially or whose execution results affect each other, are strongly consistent.

[0042] The weak consistency unit is used to classify the measurement results of the various data security software and hardware tools that are executed in parallel or whose execution results do not affect each other as weakly consistent.

[0043] The forwarding unit is used to send the measurement results of strong consistency and weak consistency identified by the strong consistency unit and the weak consistency unit to the resource on-demand scheduling submodule.

[0044] Preferably, the resource on-demand scheduling submodule includes: a judgment unit and an instruction generation unit;

[0045] The judgment unit is used to determine whether the load capacity of the data security software and hardware tool exceeds the capacity limit based on the status information fed back by the data security software and hardware tool, and send the judgment result to the instruction generation unit.

[0046] The instruction generation unit is used to control the rate at which business requests enter the system by using a leaky bucket algorithm or a token bucket algorithm when the judgment result is that the capacity limit is exceeded and the measurement results between various data security software and hardware tools are strongly consistent, and to generate function start and function end instructions.

[0047] When the judgment result is that the capacity limit is exceeded and the measurement results between various data security software and hardware tools are weakly consistent, the workflow engine generation function is suspended.

[0048] When the judgment result is that the capacity limit has not been exceeded and the measurement results between the various data security software and hardware tools are strongly consistent, the workflow engine generates function start and function end instructions according to the above.

[0049] When the judgment result is that the capacity limit has not been exceeded, and the measurement results between various data security software and hardware tools are weakly consistent, the workflow engine generates a suspension instruction.

[0050] Preferably, the scenarios include at least one of the following: sensitive data identification scenario, data classification and grading scenario, data desensitization scenario, and data watermarking scenario.

[0051] Preferably, the cooperative relationships include: chain mode, parallel aggregation mode, and branch mode;

[0052] The invocation methods include: automatic invocation and scenario-triggered invocation.

[0053] In another aspect, the present invention also provides a computer device, comprising: one or more processors;

[0054] The processor is used to generate a call instruction to invoke the data security software and hardware tools based on the status information of the data security software and hardware tools generated by the pre-built workflow engine and the scenario-based script description module.

[0055] When the calling instruction is executed by the processor, the above-described data compliance management method is implemented.

[0056] In another aspect, the present invention also provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed, the above-mentioned data compliance management method is implemented.

[0057] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0058] This invention provides a data compliance management method and system based on scenario-based orchestration of security capabilities, comprising: determining the data security software and hardware tools to be invoked from a pre-defined workflow engine based on the data security protection process to be executed, and obtaining the status information of the data security software and hardware tools; generating invocation instructions for invoking the data security software and hardware tools based on the workflow engine, the status information of the data security software and hardware tools, and a preset invocation method; wherein, the workflow engine is obtained by using computer language to describe the security policies involved in the data security protection process, the data security software and hardware tools required by the security policies, and the collaborative relationships between the various data security software and hardware tools. This invention uses a scenario-based orchestration approach to combine basic security function services to form an executable workflow engine, which can flexibly manage and invoke data security capabilities, and consider the status information fed back by the data security software and hardware tools, thereby achieving consistency in security policies and better leveraging the protective effectiveness of the protection policies. Attached Figure Description

[0059] Figure 1 This is a flowchart of a data compliance management method based on security capability scenario-based orchestration according to the present invention;

[0060] Figure 2 This is a schematic diagram of the structure of a data compliance management system based on security capability scenario-based orchestration according to the present invention;

[0061] Figure 3 This is a schematic diagram of the leaky bucket algorithm in data security capability scheduling of the present invention;

[0062] Figure 4 This is a schematic diagram of the token bucket algorithm in the data security capability scheduling of the present invention;

[0063] Figure 5 This is a schematic diagram illustrating the specific structure of a data compliance management method based on security capability scenario-based orchestration according to the present invention. Detailed Implementation

[0064] Existing technologies suffer from inconsistent security policies, leading to protection policy failures and even data unusability. This invention provides a data compliance management method and system based on security capability scenario-based orchestration. This device achieves consistent security policies and better leverages the protective effectiveness of protection policies.

[0065] Security capability orchestration can combine basic security functional services according to business scenarios to form an executable business process. This process coordinates the interaction of various related security service functions, ultimately achieving data security protection for the specific scenario. After orchestration, security capabilities take the form of a composite service. This integrated composite service has complete service interfaces and service description files. During security service registration and use, it is indistinguishable from basic security services. The only difference is that this composite service is implemented through security capability orchestration, rather than through program development code. Security capability orchestration enables end-to-end data security protection for specific scenarios and allows for flexible management and invocation of data security capabilities, achieving synergy among various data security capabilities to maximize the protective effect.

[0066] Example 1: This invention provides a data compliance management method based on security capability scenario-based orchestration, such as... Figure 1 As shown, it includes:

[0067] Step 1: Based on the data security protection process to be executed, determine the data security software and hardware tools to be called from the pre-defined workflow engine, and obtain the status information of the data software and hardware tools;

[0068] Step 2: Generate the invocation command for calling the data security software and hardware tools based on the status information of the workflow engine and data security software and hardware tools and the preset invocation method;

[0069] The workflow engine is a computer language-based description of the security policies involved in the data security protection process, the data security software and hardware tools required for the security policies, and the collaborative relationships between the various data security software and hardware tools.

[0070] The workflow engine is developed through the following steps:

[0071] The relevant security strategies are determined based on the data security protection process;

[0072] The data security hardware and software tools to be used are determined based on each security policy;

[0073] Based on the collaborative relationships between various data security software and hardware tools, the execution order of each data security software and hardware tool is generated;

[0074] The workflow engine is derived by describing the various data security software and hardware tools in the order of execution using computer language.

[0075] Preferably, the collaborative relationships include: chain mode, parallel aggregation mode, and branch mode.

[0076] Preferably, the call instructions for invoking the data security software and hardware tools are generated based on the status information of the workflow engine and the data security software and hardware tools, and the preset invocation method, including:

[0077] The workflow engine determines the data security software and hardware tools that need to be used and the collaborative relationships between these tools.

[0078] Based on the collaboration relationship and status information of various data security software and hardware tools, the consistency between various data security software and hardware tools is measured, and the measurement results are obtained.

[0079] The command to invoke the data security software and hardware tools is generated based on the status information, measurement results, and invocation method of the data security software and hardware tools.

[0080] The invocation methods include: sequential automatic invocation or scenario-triggered invocation.

[0081] Preferably, the consistency between various data security software and hardware tools is measured based on the collaboration relationship and status information of each tool, yielding measurement results including:

[0082] The measurement results of various data security software and hardware tools that are executed serially or whose execution results affect each other are considered to have strong consistency.

[0083] Measurement results from data security software and hardware tools that execute in parallel or whose execution results do not affect each other are considered weakly consistent.

[0084] Preferably, the method of generating invocation instructions for data security software and hardware tools based on the status information and measurement results includes:

[0085] Determine whether the status information of data security software and hardware tools exceeds the load capacity limit of the data security software and hardware tools.

[0086] When the load capacity of data security software and hardware tools is exceeded, and the measurement results between the various data security software and hardware tools are strongly consistent, the leaky bucket algorithm or token bucket algorithm is used to control the rate at which business requests enter the system and generate function start and function end instructions.

[0087] When the load capacity of the data security software and hardware tools is not exceeded, and the measurement results between the data security software and hardware tools are strongly consistent, the function start and function end instructions are generated according to the workflow engine.

[0088] When the load capacity of the data security software and hardware tools is not exceeded, and the measurement results between the various data security software and hardware tools are weakly consistent, the workflow engine generates a function suspension instruction.

[0089] Example 2:

[0090] Based on the same inventive concept, the present invention also provides a data compliance management system based on security capability scenario orchestration, including: a data security capability scheduling module;

[0091] The data security capability scheduling module is used to determine the data security software and hardware tools from the pre-defined workflow engine according to the data security protection process to be executed, obtain the status information fed back by the data security software and hardware tools, and generate a call instruction.

[0092] The workflow engine is described using computer language to describe the security policies involved in the data security protection process, the data security software and hardware tools required by the security policies, and the collaborative relationships between the various data security software and hardware tools.

[0093] This invention provides a data compliance management system based on security capability scenario-based orchestration, such as... Figure 2 As shown: It also includes: a scenario-based script description module and data security software and hardware tools;

[0094] The scenario-based script description module is used to describe the security policies corresponding to each scenario, the data security software and hardware tools required by the security policies, the mutual cooperation relationship between the data security software and hardware tools, and the calling method using computer language, so as to obtain the workflow engine corresponding to each scenario and send it to the data security capability scheduling module.

[0095] The data security hardware and software tools are used to execute tasks based on the call instructions and feed back status information to the data security capability scheduling module.

[0096] The following is a detailed introduction to each part:

[0097] The scenario-based script description module is designed to be oriented towards data application scenarios. It converts data security protection processes into scripts and arranges various measures together in the scripts to achieve coordinated operation of data security protection measures at each stage.

[0098] The data security protection measures or data security software and hardware tools are converted into an editable and executable computer language script. During script editing, the data security protection measures or data security software and hardware tools are described in detail according to logical relationships such as sequence, parallelism, branching, or conditional operations. During script execution, the data security protection measures or data security software and hardware tools are coordinated and operated at each stage based on the described call relationships.

[0099] The script's logic is oriented towards data application scenarios; therefore, different scenarios correspond to different script logic. The script logic is determined and edited by security personnel and automatically executed during actual operation by being triggered by the scenarios. Because data security protection measures or data security software and hardware tools used at different stages are described and edited within the same script, it effectively supports security personnel at different stages in achieving consistent security protection strategies.

[0100] The implementation of the specific scenario-based script description module includes the following two steps:

[0101] The first step is to analyze the data security protection measures for the entire process of power data application scenarios, as well as the data security protection tools required for each security protection measure.

[0102] The second step involves logically associating the data security protection tools that need to be used and invoked according to their collaborative relationships. The association patterns used include, but are not limited to, the following three:

[0103] (1) Chained Mode. The chained mode is suitable for serial invocation of data security capabilities. For example, after sensitive data is identified and it is determined which data needs to be de-identified, the process of invoking data de-identification security capabilities for data processing is a chained mode. In the chained mode, all security services use synchronous message passing, and the system will block until each security service link in the chain is completed.

[0104] (2) Parallel Aggregation Mode. Parallel aggregation mode is suitable for calling multiple data security capabilities that can be processed in parallel. For example, data classification and grading can be performed simultaneously with sensitive data identification. Sensitive data classification and grading after sensitive data identification can be performed in parallel and without interdependence. The aggregation mode realizes the specific functions required for data security compliance scenarios by calling multiple security services and simply aggregating the processing results returned by each lower-level service to return the result.

[0105] (3) Branching mode. Branching mode is a service orchestration pattern that combines aggregation mode and chaining mode. Branching mode is suitable for orchestrating and scheduling security services for more complex business scenarios. For example, after identifying sensitive data, data anonymization is performed, and at the same time, security control is exercised over database data access permissions. These two tasks are independent of each other but complex, so branching mode is used to decompose security capabilities.

[0106] The collaborative relationships are determined and edited by security personnel based on the security requirements of the scenario, and are automatically executed by the scenario during actual operation.

[0107] As described in the details, the three association modes are: chain mode, suitable for serial invocation of data security capabilities; parallel aggregation mode, suitable for invocation of multiple data security capabilities that can be processed in parallel; and branch mode, a service orchestration mode combining aggregation and chain modes. These are methods used by security personnel when determining and editing scripts based on scenario security requirements. For example, in business data operations and maintenance, data anonymization is required first, followed by data maintenance through the operations and maintenance rule execution module; this requires the use of chain mode. If data anomaly detection is also needed, then the invocation of the data anomaly monitoring module is parallel to the data operations and maintenance rule execution module, and the parallel aggregation mode should be used in the script.

[0108] The third step involves describing the collaborative relationships, security policies, and invocation methods of the data security protection tools to be adopted and invoked using computer language, thus completing the data security scenario-based script editing. This computer language can be C, Java, or other languages, primarily based on the user's system development technology selection. The framework is as follows:

[0109]

[0110] The invocation method refers to whether data security protection measures or data security software and hardware tools are invoked automatically in sequence or triggered by a scenario, which is the same as the computer programming method.

[0111] The script is logically structured, and in actual operation, it is automatically executed by scene triggers. The script editing framework mainly includes various data security protection measures or calls to data security software and hardware tools.

[0112] The fourth step is to transform the completed script editing into a workflow engine that can be invoked on demand. For example, when the script needs to call the sensitive data identification function, it can connect to the API interface exposed by the sensitive data identification tool, including function startup, parameter configuration, function suspension, and function termination.

[0113] For example, when a script needs to call the sensitive data identification function, it can connect to the API interface exposed by the sensitive data identification tool, including function startup, parameter configuration, function suspension, and function termination. The execution of the script is mainly implemented by the workflow engine. When the sensitive data identification tool is called, the workflow engine determines when to start, suspend, and terminate the tool. The workflow engine not only obtains the sensitive data identification tool call parameters from the script but also obtains the current load status of the sensitive data identification tool from the data security capability scheduling module, choosing whether to execute at full speed or suspend the task for later execution.

[0114] The data security capability scheduling module is used to schedule data security capabilities on demand, based on different script logic, while ensuring the consistency of data security tool protection strategies at each stage.

[0115] Fifth, the data security capability scheduling module will, according to the scripts constructed by the scenario-based script description module and the workflow engine, call data security tools as needed to complete the entire data security protection process. In the event of resource scarcity of data security tools, the following strategy will be used for function scheduling:

[0116] (1) Consistency of protection strategies for various data security tools. This method aims to ensure strong consistency of protection strategies for scenario-based scripts that are executed serially or whose execution results affect each other, and to implement weak consistency of protection strategies for scenario-based scripts that are executed in parallel or whose execution results do not affect each other.

[0117] Strong consistency means that once the security service has completed its execution, any subsequent access by multiple processes or threads will return the latest updated value.

[0118] Weak consistency means that after a service reads or writes business data, the system does not guarantee that subsequent accesses by other services will return the latest updated value. The system does not promise that the latest written value will be available immediately after a successful data write, nor does it specify a timeframe after which it will be available.

[0119] Consistency here refers to keeping data consistent, including strong consistency and weak consistency. Strong consistency means that at any given time, the data in all nodes is the same; weak consistency means that after a period of time, the data between nodes will eventually reach a consistent state.

[0120] This invention implements strong and weak consistency protection measures for certain scripts, ensuring the consistency of security policies and avoiding problems such as protection policy failure or even data unusability caused by inconsistent security policies.

[0121] (2) Load balancing of data security tools. When the computing tasks carried by data security tools exceed their load capacity limit, resulting in slow service response, reduced response quality, or inability to process requests, this method will use two task load optimization techniques to ensure the smooth execution of security capability orchestration results as much as possible.

[0122] 1) Leaky bucket algorithm, such as Figure 3 As shown, the system controls the rate at which business requests enter the system, smoothly handling sudden surges in business request traffic.

[0123] 2) Token bucket algorithm, such as Figure 4 As shown, data security tool call requests are responded to at a constant rate. If a request needs to be processed, a token needs to be obtained from the bucket, and if no token is available in the bucket, the service is denied.

[0124] Data security software and hardware tools are used to generate call instructions based on the workflow engine sent by the scenario-based script description module and the status information fed back by the data security software and hardware tools, and then send them to the data security software and hardware tools.

[0125] Step 6: After the above data security capabilities are orchestrated in a scenario-based manner, we will wait for the data application scenario to be triggered. Once the scenario triggers the orchestration result, various data security tools will be called in sequence without the need for security personnel to manually connect them.

[0126] This invention employs the leaky bucket algorithm and the token bucket algorithm to ensure the smooth execution of the security capability orchestration results.

[0127] When data is used in a specific scenario, the scenario-specific data security capabilities will be executed according to the script. For example, when data operations personnel enter the business data operations workbench and start business data operations work, the business data operations security protection script will be triggered and executed.

[0128] Example 3:

[0129] Based on the same inventive concept, the present invention also provides a data compliance management method based on security capability scenario orchestration, including: a scenario-based script description module uses computer language to describe the security policies corresponding to each scenario, the data security software and hardware tools required by the security policies, the mutual cooperation relationship between the data security software and hardware tools and the calling method, to obtain the workflow engine corresponding to each scenario, and send it to the data security scheduling module.

[0130] The data security capability scheduling module generates a call instruction based on the status information from the workflow engine and data security software and hardware tools sent by the scenario-based script description module, and then sends it to the data security software and hardware tools.

[0131] Data security hardware and software tools are used to execute tasks based on call commands and feed back status information to the data security capability scheduling module.

[0132] The scenario-based script description module uses computer language to describe the security policies corresponding to each scenario, the data security hardware and software tools required by the security policies, the interoperability between the data security hardware and software tools, and the calling methods, thereby obtaining the workflow engine corresponding to each scenario and sending it to the data security scheduling module, including:

[0133] The script editing submodule of the scenario-based script description module uses computer language to describe the security policies corresponding to each scenario, the data security software and hardware tools required by the security policies, the mutual cooperation relationship between the data security software and hardware tools, and the calling method, so as to obtain the script corresponding to each scenario.

[0134] The workflow engine conversion module of the scenario-based script description module converts the data security software and hardware tools or security policies in the script corresponding to each scenario into execution order according to the calling method of each scenario and the collaboration relationship between each data security software and hardware tools or security policies. The workflow engine is then constructed by each data security software and hardware tool or security policy and the execution order, and the workflow engine is sent to the data security capability scheduling module.

[0135] The data security capability scheduling module generates invocation instructions based on the status information from the workflow engine and data security software and hardware tools sent by the scenario-based script description module, and then sends these instructions to the data security software and hardware tools, including:

[0136] The policy consistency judgment submodule of the data security capability scheduling module receives status information fed back by data security software and hardware tools, measures the consistency between each data security software and hardware tool, and sends the measurement results to the resource on-demand scheduling submodule.

[0137] The resource on-demand scheduling submodule of the data security capability scheduling module generates a call instruction based on the status information sent by the workflow engine conversion module, the data security software and hardware tools, and the measurement results between the various data security software and hardware tools, and sends it to the capability standardization interface submodule.

[0138] The standardized interface submodule of the data security capability scheduling module controls security software and hardware tools according to the calling instructions.

[0139] A data compliance management method based on security capability scenario-based orchestration, such as Figure 5As shown: The scenario-based script description module edits scripts based on scenarios such as data access, data analysis, data distribution, and data operation and maintenance, and generates a script generation workflow engine based on each scenario, and sends the generated workflow engine to the data security scheduling module.

[0140] The data security scheduling module performs on-demand resource scheduling and policy consistency planning based on the status information fed back by the workflow engine and data security software and hardware tools, generates call instructions, and distributes the call instructions to various data security software and hardware tools through the capability standardization interface. The data security software and hardware tools here include tools that implement functions such as sensitive identification, data classification and grading, data desensitization, and data watermarking.

[0141] Example 4:

[0142] Based on the same inventive concept, the present invention also provides a computer device, comprising: one or more processors;

[0143] The processor is used to generate a call instruction to invoke the data security software and hardware tools based on the status information of the data security software and hardware tools generated by the pre-built workflow engine and the scenario-based script description module.

[0144] When the calling instruction is executed by the processor, the above-described data compliance management method is implemented.

[0145] Example 5:

[0146] Based on the same inventive concept, the present invention also provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed, the above-described data compliance management method is implemented.

[0147] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0148] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0149] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0150] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0151] The above are merely embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention are included within the scope of the claims of the present invention pending approval.

Claims

1. A data compliance management method based on security capability scenario-based orchestration, characterized in that, include: Based on the data security protection process to be executed, the data security software and hardware tools to be invoked are determined from the pre-defined workflow engine, and the status information of the data software and hardware tools is obtained. Based on the workflow engine, the required data security software and hardware tools and the collaborative relationships between these tools are determined. The measurement results of the various data security software and hardware tools that are executed serially or whose execution results affect each other are considered to have strong consistency. The measurement results of the various data security software and hardware tools that are executed in parallel or whose execution results do not affect each other are considered weakly consistent. Determine whether the status information of the data security software and hardware tools exceeds the load capacity limit of the data security software and hardware tools. When the load capacity limit of the data security software and hardware tools is exceeded, and the measurement results among the data security software and hardware tools are strongly consistent, the leaky bucket algorithm or token bucket algorithm is used to control the rate at which business requests enter the system, and function start and function end instructions are generated. When the load capacity of the data security software and hardware tools is exceeded, and the measurement results between the data security software and hardware tools are weakly consistent, the workflow engine generation function is suspended. When the load capacity limit of the data security software and hardware tools is not exceeded, and the measurement results among the data security software and hardware tools are strongly consistent, the workflow engine generates function start and function end instructions accordingly. When the load capacity limit of the data security software and hardware tools is not exceeded, and the measurement results between the data security software and hardware tools are weakly consistent, the workflow engine generates a function suspension instruction. The workflow engine is described using computer language to describe the security policies involved in the data security protection process, the data security software and hardware tools required by the security policies, and the collaborative relationships between the various data security software and hardware tools.

2. The method as described in claim 1, characterized in that, The workflow engine is developed through the following steps: The relevant security strategies are determined based on the data security protection process; The data security hardware and software tools to be used are determined based on each security policy; Based on the collaborative relationships between various data security software and hardware tools, the execution order of each data security software and hardware tool is generated; The workflow engine is derived by describing the various data security hardware and software tools in the order of execution using computer language.

3. The method as described in claim 2, characterized in that, The collaborative relationships include: chain mode, parallel aggregation mode, and branch mode.

4. The method as described in claim 1, characterized in that, The invocation methods include: sequential automatic invocation or scenario-triggered invocation.

5. A system for implementing the data compliance management method based on security capability scenario-based orchestration as described in any one of claims 1-4, characterized in that, include: Data security hardware and software tools and data security capability scheduling module; Data security hardware and software tools are used to execute tasks based on invocation commands and feed back status information to the data security capability scheduling module. The data security capability scheduling module is used to determine the data security software and hardware tools from the pre-defined workflow engine according to the data security protection process to be executed, obtain the status information fed back by the data security software and hardware tools, and generate a call instruction based on the pre-defined workflow engine and the status information fed back by the data security software and hardware tools. The workflow engine is described using computer language to describe the security policies involved in the data security protection process, the data security software and hardware tools required by the security policies, and the collaborative relationships between the various data security software and hardware tools.

6. The system as described in claim 5, characterized in that, It also includes a scenario-based script description module; The scenario-based script description module is used to determine the security strategies involved based on the data security protection process, then determine the data security software and hardware tools to be used based on each security strategy, and then generate the execution order of each data security software and hardware tool based on the cooperation relationship between them. Finally, the workflow engine is obtained by describing each data security software and hardware tool in computer language according to the execution order.

7. The system as described in claim 6, characterized in that, The scenario-based script description module includes a script editing submodule and a workflow engine conversion module. The script editing submodule is used to describe the security policies corresponding to each scenario, the data security software and hardware tools required by the security policies, the mutual cooperation relationships between the data security software and hardware tools, and the calling methods using computer language, thereby obtaining the scripts corresponding to each scenario. The workflow engine conversion module is used to generate the execution order of each data security software and hardware tool in the scripts corresponding to each scenario according to the calling methods of each scenario and the cooperation relationships between the data security software and hardware tools. The workflow engine is constructed by the data security software and hardware tools and the execution order, and the workflow engine is sent to the data security capability scheduling module.

8. The system as described in claim 7, characterized in that, The data security capability scheduling module includes: a resource on-demand scheduling submodule, a policy consistency judgment submodule, and a capability standardization interface submodule; The policy consistency judgment submodule is used to receive status information fed back by the data security software and hardware tools, measure the consistency between each data security software and hardware tool, and send the measurement result to the resource on-demand scheduling submodule. The resource on-demand scheduling submodule is used to generate a call instruction based on the status information of the workflow engine sent by the workflow engine conversion module, the status information fed back by the data security software and hardware tools, and the measurement results between the data security software and hardware tools, and then send it to the capability standardization interface submodule. The capability standardization interface submodule is used to control the security software and hardware tools according to the calling instructions.

9. The system as described in claim 8, characterized in that, The policy consistency judgment submodule includes: a strong consistency unit, a weak consistency unit, and a forwarding unit; The strong consistency unit is used to ensure that the measurement results of the various data security software and hardware tools, which are executed serially or whose execution results affect each other, are strongly consistent. The weak consistency unit is used to classify the measurement results of the various data security software and hardware tools that are executed in parallel or whose execution results do not affect each other as weakly consistent. The forwarding unit is used to send the measurement results of strong consistency and weak consistency identified by the strong consistency unit and the weak consistency unit to the resource on-demand scheduling submodule.

10. The system as described in claim 9, characterized in that, The resource on-demand scheduling submodule includes: a judgment unit and an instruction generation unit; The judgment unit is used to determine whether the load capacity of the data security software and hardware tool exceeds the capacity limit based on the status information fed back by the data security software and hardware tool, and send the judgment result to the instruction generation unit. The instruction generation unit is used to control the rate at which business requests enter the system by using a leaky bucket algorithm or a token bucket algorithm when the judgment result is that the capacity limit is exceeded and the measurement results between various data security software and hardware tools are strongly consistent, and to generate function start and function end instructions. When the judgment result is that the capacity limit is exceeded and the measurement results between various data security software and hardware tools are weakly consistent, the workflow engine generation function is suspended. When the judgment result is that the capacity limit has not been exceeded and the measurement results between the various data security software and hardware tools are strongly consistent, the workflow engine generates function start and function end instructions according to the above. When the judgment result is that the capacity limit has not been exceeded, and the measurement results between various data security software and hardware tools are weakly consistent, the workflow engine generates a suspension instruction.

11. The system as described in claim 7, characterized in that, The scenarios include at least one of the following: sensitive data identification scenario, data classification and grading scenario, data desensitization scenario, and data watermarking scenario.

12. The system as described in claim 7, characterized in that, The cooperative relationships include: chain mode, parallel aggregation mode, and branch mode; The invocation methods include: automatic invocation and scenario-triggered invocation.

13. A computer device, characterized in that, include: One or more processors; The processor is used to generate a call instruction to invoke the data security software and hardware tools based on the status information of the data security software and hardware tools generated by the pre-built workflow engine and the scenario-based script description module. When the calling instruction is executed by the processor, the data compliance management method as described in any one of claims 1-4 is implemented.

14. A computer-readable storage medium, characterized in that, It contains a computer program, which, when executed, implements the data compliance management method as described in any one of claims 1 to 4; The workflow engine is described using computer language to describe the security policies involved in the data security protection process, the data security software and hardware tools required by the security policies, and the collaborative relationships between the various data security software and hardware tools.