Cross-domain data collaborative management method and device
By integrating task scheduling and data transmission tools into the ferry server and employing encryption and data anonymization algorithms, the problem of low data exchange efficiency between different networks and security domains is solved, enabling secure and efficient cross-domain data transmission and sharing.
Patent Information
- Application Number
- CN202211738700.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-31
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2042-12-31
AI Technical Summary
In the process of digital transformation of enterprises and institutions, traditional methods for achieving efficient and secure data exchange and sharing between different networks and security domains suffer from problems such as high resource consumption, low efficiency, and difficulty in management.
By integrating task scheduling and data transmission tools into the ferry server and employing encryption algorithms, cross-domain data interaction and sharing are achieved. It supports data association and fusion from multiple heterogeneous data sources, and provides a rich variety of data source sharing and exchange types using encrypted transmission mechanisms and data anonymization algorithms.
It enables secure and efficient cross-domain data transmission, reduces resource consumption, improves exchange efficiency, and ensures the security of data exchange through comprehensive monitoring processes.
Smart Images

Figure CN115987676B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information management, in particular to a cross-domain data collaborative management method and device. BACKGROUND
[0002] Generally, in order to protect the security of important data and application systems, multiple networks coexist are generally adopted. However, in the process of digital transformation of enterprises and institutions, the most direct problem is usually how to make the application systems in different networks and different security domains realize information exchange and sharing, that is, how to share and exchange data in different domains.
[0003] In the process of data sharing and exchange, exchange between different security domains or different networks is usually faced, including data exchange between internal and external networks and different secret levels. The traditional exchange mode of data between different security domains or different networks is mainly based on network gateways and optical disc ferry equipment. Since the network gateways cannot realize one-to-many data exchange, if data needs to be sent to multiple parties, it needs to be sent one by one, which has the problems of large resource consumption and low efficiency. And the optical disc ferry needs to record the server data on the optical disc, and the recording behavior cannot automatically leave a record, which will lead to the situation of "unknown data from where, unknown data to where", that is, the problem of not easy to manage. SUMMARY
[0004] The present application provides a cross-domain data collaborative management method and device, which realizes data exchange between different networks and different security domains under the premise of ensuring data security, improves data exchange efficiency, and reduces resource consumption.
[0005] Therefore, the present application provides the following technical solutions:
[0006] A cross-domain data collaborative management method, the method comprising:
[0007] A ferry server connected with a first network and a second network is set, a task scheduling tool and a data transmission tool are integrated on the ferry server, the data transmission tool is integrated with an encryption algorithm, an interactive data source is set on the ferry server, the data source includes a first network data source and a second network data source; the first network and the second network are networks of different security levels;
[0008] The data of the data source is cross-domain interacted and / or cross-domain shared by using the task scheduling tool and the data transmission tool.
[0009] Optionally, the cross-domain interaction of the data of the data source comprises:
[0010] Determining a to-be-interacted data source;
[0011] select a task scheduling tool and bind task period scheduling information;
[0012] The data transmission tool performs cross-domain synchronization operation on the to-be-interacted data source according to the scheduling of the task scheduling tool.
[0013] Optionally, the cross-domain interaction of the data of the data source further includes setting a data collection mode.
[0014] The cross-domain synchronization operation on the to-be-interacted data source includes:
[0015] The cross-domain synchronization operation is performed on the to-be-interacted data source according to the data collection mode.
[0016] Optionally, the data collection mode includes any one or more of the following: a data field encryption rule, a sensitive rule, a data full amount or an incremental mode.
[0017] Optionally, the method further includes setting a target data table.
[0018] The cross-domain synchronization operation on the to-be-interacted data source includes:
[0019] The data of the to-be-interacted data source is written into the target data table.
[0020] Optionally, the cross-domain sharing of the data of the data source includes:
[0021] Determining a to-be-shared data source;
[0022] Generating an API interface according to the to-be-shared data source, so that a subscriber shares the data of the data source through the API interface.
[0023] Optionally, the generating of the API interface according to the to-be-shared data source includes:
[0024] Determining field information required by the interface according to the to-be-shared data source;
[0025] Generating the API interface according to the field information.
[0026] Optionally, the method further includes:
[0027] Writing the API interface into an API service list;
[0028] Dynamically marking the state of each API interface in the API service list, and monitoring the use of each API interface.
[0029] Optionally, the dynamically marking the state of each API interface in the API service list includes:
[0030] If the API interface is reviewed, the state of the API interface is marked as subscribed.
[0031] A cross-domain data collaborative management device, the device comprising:
[0032] A tool integration module connected with the first network and the second network respectively, and integrated with a task scheduling tool and a data transmission tool, the data transmission tool integrated with an encryption algorithm; the first network and the second network are networks of different security levels;
[0033] A setting module for setting an interactive data source, the data source comprising a first network data source and a second network data source;
[0034] A ferry service module for cross-domain interaction and / or cross-domain sharing of data of the data source by using the task scheduling tool and the data transmission tool.
[0035] The cross-domain data collaborative management method and device provided by the application provide rich data source sharing exchange types, support data extraction from multiple heterogeneous data sources, and can directly complete cross-database data correlation fusion extraction. By using the application scheme, safe and efficient data cross-domain transmission can be realized, an encryption transmission mechanism is adopted to encrypt data transmission, a large number of data desensitization algorithms are built-in, and the safety of data is ensured.
[0036] Further, the operation behavior of the system and the data can also be audited, such as task running monitoring, system running monitoring, system audit log, and full-range monitoring process is provided to guarantee the safety of data exchange. BRIEF DESCRIPTION OF DRAWINGS
[0037] Figure 1 is a flowchart of the cross-domain data collaborative management method provided by the embodiment of the application;
[0038] Figure 2 is a flowchart of cross-domain data interaction in the embodiment of the application;
[0039] Figure 3 is a flowchart of cross-domain data sharing in the embodiment of the application;
[0040] Figure 4 is a structural schematic diagram of the cross-domain data collaborative management device provided by the embodiment of the application. DETAILED DESCRIPTION
[0041] In order to enable the persons skilled in the art to better understand the scheme of the embodiment of the application, the embodiment of the application is further described in detail below in combination with the drawings and embodiments.
[0042] In view of the problems of large resource consumption, low efficiency and difficult management in existing cross-domain data interaction, the embodiment of the application provides a cross-domain data collaborative management method and device, a ferry server connected with an internal network and an external network is arranged, a task scheduling tool and a data transmission tool are integrated on the ferry server, the data transmission tool is integrated with an encryption algorithm, an interactive data source is arranged on the ferry server, and the data of the data source is cross-domain interacted and / or cross-domain shared by using the task scheduling tool and the data transmission tool. Not only the security of data interaction can be ensured, but also the interaction efficiency can be improved, and system resources can be saved.
[0043] As shown in Figure 1 , it is a flow chart of the cross-domain data collaborative management method provided by the embodiment of the application, comprising the following steps:
[0044] Step 101, a ferry server connected with a first network and a second network is arranged, a task scheduling tool and a data transmission tool are integrated on the ferry server, the data transmission tool is integrated with an encryption algorithm, an interactive data source is arranged on the ferry server, and the data source includes a first network data source and a second network data source.
[0045] It should be noted that the first network and the second network are networks of different security levels, for example, they are an internal network and an external network respectively, or two internal networks of different security levels.
[0046] Among them, the task scheduling tool Xxjob is used to realize the timing execution and scheduling of synchronous exchange tasks, and the data transmission tool DataX is used to realize the transmission exchange of cross-domain data.
[0047] It should be noted that different task scheduling tools Xxjob and data transmission tools DataX can be configured for different data sources.
[0048] In specific application, the corresponding name, identification, registration mode and address of each task scheduling tool Xxjob and data transmission tool DataX can be set.
[0049] Step 102, the data of the data source is cross-domain interacted and / or cross-domain shared by using the task scheduling tool and the data transmission tool.
[0050] The detailed process of cross-domain interaction and cross-domain sharing of data by using the task scheduling tool and the data transmission tool will be described in detail below. Figure 2 and Figure 3 respectively.
[0051] As shown in Figure 2 , it is a flow chart of cross-domain data interaction in the embodiment of the application, comprising the following steps:
[0052] Step 201, determine the data source to be interacted.
[0053] Specifically, the data source to be interacted can be found on the pass-through server.
[0054] Step 202, select a task scheduling tool and bind the task period scheduling information.
[0055] The scheduling template can be set on the pass-through server, and the scheduling period, routing strategy, executor, failure retry strategy and other scheduling information can be set by using the scheduling template. The set scheduling information is bound to the selected task scheduling tool, so that the task scheduling tool performs corresponding scheduling on the data source to be interacted according to the set scheduling information.
[0056] Step 203, the data transmission tool performs cross-domain synchronization operation on the data source to be interacted according to the scheduling of the task scheduling tool.
[0057] The data collection method can also be set in advance, and the cross-domain synchronization operation is performed on the data source to be interacted according to the data collection method.
[0058] Further, in order to ensure the security of the data, the encryption rule and / or the field sensitive rule of the field can also be configured. The encryption rule includes an encrypted field, an encryption algorithm, an encryption condition, etc. The sensitive rule includes the basic attribute of the desensitization rule and the desensitization method, etc.
[0059] In specific applications, a target data table can be set. Correspondingly, the data transmission tool can write the data of the data source to be interacted into the target data table according to the scheduling of the task scheduling tool.
[0060] Of course, in actual applications, other interaction methods can also be used, which are not limited by the embodiments of the present application.
[0061] As shown in FIG. 1, it is a flow chart of cross-domain data sharing in the embodiments of the present application, comprising the following steps: Figure 3
[0062] Step 301, determine the data source to be shared.
[0063] Step 302, generate an API interface according to the data source to be shared, so that the data of the data source is shared by the API interface.
[0064] Specifically, when generating the API interface, the API information can be filled in, including the name of the API and the description of the API, the data source to be shared is selected, and the data input field and the return field and other information are configured. Correspondingly, the configuration information is saved, and the API interface is generated.
[0065] Different domains of users can access the shared data source by using the API interface, that is, the data of the data source to be shared can be shared.
[0066] In order to facilitate the use of the shared data by other users, the API interface can be written into an API service list, and other users can find the interface of the data source to be shared through the API service list.
[0067] Correspondingly, when a user needs the data of the data source to be shared, the data can be obtained through subscription. Specifically, the API interface to be subscribed is selected, and the subscription is selected after setting the subscription time.
[0068] Further, the user can also view the API interface details, such as basic information, field information, API interface request examples, and the like, through the API service list.
[0069] In order to ensure the security of the API interface, the API interface request of the user can also be audited. If the audit is passed, the user can access the corresponding data source through the API interface.
[0070] Further, the state of each API interface in the API service list can also be dynamically marked. Specifically, if the API interface is audited, the state of the API interface is marked as subscription.
[0071] Further, the use of each API interface can also be monitored.
[0072] The cross-domain data collaborative management method provided by the application provides rich data source sharing exchange types, supports data extraction from multiple heterogeneous data sources, and can directly complete cross-database data association fusion extraction. By using the application scheme, safe and efficient data cross-domain transmission can be realized, an encryption transmission mechanism is adopted to encrypt the data transmission, a large number of data desensitization algorithms are built-in, and the safety of the data is ensured.
[0073] Further, the operation behavior of the system and the data can also be audited, such as task running monitoring, system running monitoring, system audit log, and full-range monitoring process is provided to guarantee the safety of data exchange.
[0074] Correspondingly, the application embodiment also provides a cross-domain data collaborative management device, as shown in Figure 4 Fig. 1 is a structural schematic diagram of a cross-domain data collaborative management device provided by the application embodiment.
[0075] The cross-domain data collaborative management device 400 comprises the following modules:
[0076] The tool integration module 401 is connected with the first network and the second network respectively, and is integrated with a task scheduling tool and a data transmission tool, and the data transmission tool is integrated with an encryption algorithm.
[0077] The setting module 402 is used for setting the data source capable of being interacted, and the data source includes a first network data source and a second network data source.
[0078] The ferry service module 403 is used for cross-domain interaction and / or cross-domain sharing of data of the data source by using the task scheduling tool and the data transmission tool.
[0079] When data interaction is needed, the task scheduling tool and the data transmission tool provided by the tool integration module 401 can be selected, and the data source capable of being interacted provided by the setting module 402 can be selected, and the ferry service module 403 is used for cross-domain interaction and / or cross-domain sharing of data of the data source by using the tool selected by a user and setting information related to the tool. Figure 2
[0080] When data sharing is needed, the data source capable of being interacted provided by the setting module 402 is selected, and an API interface is generated, so that a subscriber shares data of the data source through the API interface, and a specific process can be referred to the description of the embodiment shown in Figure 3
[0081] Further, the cross-domain data collaborative management device provided by the application can also audit a subscription request sent by a subscriber, and only when the subscription request passes the audit, the API interface of the request can be shared.
[0082] Further, the cross-domain data collaborative management device provided by the application can also monitor usage of each API interface.
[0083] The cross-domain data collaborative management device provided by the application provides rich data source sharing and exchange types, supports extraction of data from multiple heterogeneous data sources, and can directly complete data correlation and fusion extraction across databases. By using the application scheme, safe and efficient data cross-domain transmission can be realized, an encryption transmission mechanism is adopted to encrypt data transmission, a large number of data desensitization algorithms are built-in, and the safety of data is ensured.
[0084] Further, operation behaviors of the system and the data can also be audited, for example, task running monitoring, system running monitoring, system audit log, and a full-range monitoring process is provided to guarantee the safety of data exchange.
[0085] It should be noted that the cross-domain data collaborative management device provided by the application can be used as an independent server to realize data interaction and sharing between networks of different security levels.
[0086] By the scheme, the cross-domain data collection is safer, the encrypted transmission mechanism is used to encrypt the data transmission, and the safety of the data is effectively ensured; the scheme combines the scheduling tool Xxjob with the transmission tool DataX, and the scheduling period of the data collection task is more flexible.
[0087] Further, in the data sharing process, the API interface is automatically generated, the data sharing operation is more convenient, and in addition, the API interface approval can make the data sharing more reliable.
[0088] It should be noted that the terms "comprising" and "having" and any variations thereof in the specification and claims of the present application and in the above description are intended to cover not only the inclusion of the recited elements but also the exclusion of any other elements. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those clearly listed, but can include other steps or units that are not clearly listed or inherent to such processes, methods, products, or apparatuses.
[0089] Each of the embodiments in the specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the difference from other embodiments. Moreover, the above-described system embodiments are only illustrative, and the modules and units described as separate components can be or can not be physically separated, that is, can be located on one network unit or can be distributed to multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiment scheme. Those skilled in the art can understand and implement it without creative labor.
[0090] The above describes the embodiments of the present application in detail, and the present application is described by applying the specific implementation manner. The above embodiment description is only used to help understand the method and system of the present application, and only a part of the embodiment of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should belong to the protection scope of the present application, and the content of the specification should not be understood as the limitation of the present application. Therefore, any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application should be included in the protection scope of the present application.
Claims
1. A method for cross-domain data collaborative management, characterized in that, The method comprises: setting a ferry server connected with a first network and a second network, integrating a task scheduling tool and a data transmission tool on the ferry server, the data transmission tool integrating an encryption algorithm, setting an interactive data source on the ferry server, the data source including a first network data source and a second network data source; the first network and the second network are networks of different security levels; using the task scheduling tool and the data transmission tool to perform cross-domain interaction and / or cross-domain sharing of data of the data source; wherein the cross-domain interaction of the data source comprises: determining a data source to be interacted; selecting a task scheduling tool and binding task period scheduling information; setting a scheduling template on the ferry server, setting scheduling period, routing strategy, executor, and failure retry strategy scheduling information by using the scheduling template, and binding the set scheduling information to the selected task scheduling tool, so that the task scheduling tool performs corresponding scheduling on the data source to be interacted according to the set scheduling information; the data transmission tool performs cross-domain synchronization operation on the data source to be interacted according to the scheduling of the task scheduling tool; the cross-domain sharing of the data source comprises: determining a data source to be shared; generating an API interface according to the data source to be shared, so that a subscriber shares data of the data source through the API interface; the generation of the API interface according to the data source to be shared comprises: determining field information required by the interface according to the data source to be shared; generating an API interface according to the field information.
2. The method of claim 1, wherein, The cross-domain interaction of the data source further comprises setting a data collection mode; the cross-domain synchronization operation on the data source to be interacted comprises: performing cross-domain synchronization operation on the data source to be interacted according to the data collection mode.
3. The method of claim 2, wherein, The data collection mode includes any one or more of the following: data field encryption rule, sensitive rule, data full amount or incremental mode.
4. The method of claim 1, wherein, The method further comprises: setting a target data table; the cross-domain synchronization operation on the data source to be interacted comprises:
5. The method of claim 1, wherein, writing data of the data source to be interacted into the target data table. The method further comprises: writing the API interface into an API service list; 6. The method of claim 5, wherein, dynamically marking the state of each API interface in the API service list, and monitoring the use of each API interface. The dynamic marking of the state of each API interface in the API service list comprises:
7. A cross-domain data collaboration management apparatus, characterized by comprising: if the API interface is reviewed in detail, marking the state of the API interface as subscribed. The device comprises: a tool integration module connected with a first network and a second network respectively, and integrating a task scheduling tool and a data transmission tool, the data transmission tool integrating an encryption algorithm; the first network and the second network are networks of different security levels; a setting module for setting an interactive data source, the data source including a first network data source and a second network data source; a ferry service module for using the task scheduling tool and the data transmission tool to perform cross-domain interaction and / or cross-domain sharing of data of the data source; The cross-domain interaction of the data of the data source comprises: determining a data source to be interacted with; selecting a task scheduling tool and binding task period scheduling information; setting a scheduling template on the cross-domain data collaborative management device, setting scheduling period, routing strategy, executor, and failure retry strategy scheduling information using the scheduling template, binding the set scheduling information to the selected task scheduling tool, and causing the task scheduling tool to perform corresponding scheduling on the data source to be interacted with according to the set scheduling information; the data transmission tool performs cross-domain synchronization operation on the data source to be interacted with according to the scheduling of the task scheduling tool; The cross-domain sharing of the data of the data source comprises: determining a data source to be shared; generating an API interface according to the data source to be shared, so that a subscriber shares the data of the data source through the API interface; The API interface is generated according to the data source to be shared, comprising: determining field information required by the interface according to the data source to be shared; generating an API interface according to the field information.
Citation Information
Patent Citations
Cross-domain collaborative interaction method based on collaborative gateway
CN111083177A
Data exchange and sharing platform
CN112448972A
Supply chain collaborative data exchange system and method based on multiple networks
CN115314497A