Data security management method and system and blockchain
By deploying smart contracts on the blockchain and integrating consensus on cross-system data leakage, blacklists, and special data, the problem of manual handling in cross-system security collaboration is solved, and efficient and accurate data security management is achieved.
Patent Information
- Application Number
- CN202311473023.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-06
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2043-11-06
AI Technical Summary
In existing technologies, cross-system security collaboration relies on work order approval processes and manual handling, which involves time cycles and creates security vacuum periods. This makes it difficult to effectively address cross-system data security risks, and there is a lack of evidence of responsibilities and rights.
By connecting multiple target systems to the blockchain and pre-deploying smart contracts, the smart contracts integrate cross-system data leakage consensus, blacklist consensus, and special data consensus. When an event is triggered, security policies are automatically executed to achieve cross-system data security management.
It improves the efficiency of cross-system security coordination, reduces the security vacuum period, avoids the escalation of security incidents, and achieves precise data security control.
Smart Images

Figure CN118797735B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data security, and particularly relates to a data security management method and system and a blockchain. BACKGROUND
[0002] Data security has always been an important concern in the field of data governance. For example, for operators, massive user data involves a lot of privacy information. In the data governance process, data security needs to be taken as a prerequisite and basic principle to ensure the security and controllability of various sensitive information. Due to the complex information system of operators, various systems are standing, resulting in the problem of information chimney. The processing capacity of cross-system security linkage is also weak. For cross-system data security risk problems.
[0003] At present, the solution to the cross-system security coordination problem mainly relies on work order approval transfer and manual disposal. Such processing method can meet the requirements of cross-system security coordination to a certain extent, but also has obvious shortcomings. On the one hand, manual disposal has a time cycle, which will leave a large security problem vacuum period, and is easy to cause the expansion of security problems. On the other hand, for the spread of cross-system security problems, the responsibility and evidence are missing, and it is difficult to trace back. SUMMARY
[0004] The present application provides a data security management method and system and a blockchain, which solves the problem that the solution to the cross-system security coordination problem in the prior art relies on work order approval transfer and manual disposal, and manual disposal has a time cycle, which will leave a large security problem vacuum period, and is easy to cause the expansion of security problems.
[0005] The present application provides a data security management method, comprising:
[0006] A plurality of target systems are connected to a blockchain, the blockchain is pre-deployed with a smart contract, the smart contract is constructed by integrating cross-system data leakage consensus, blacklist consensus and special data consensus, and the special data consensus is based on information defined in the target system;
[0007] When a target event in any of the target systems triggers the smart contract, the blockchain controls the smart contract to be run in each of the target systems to control each of the target systems to execute a security policy corresponding to the target event in the smart contract.
[0008] According to the data security management method provided by the present application, the smart contract comprises a data leakage management contract, a user blacklist management contract, a special data management contract, a data security management contract and a policy contract.
[0009] The data leakage management contract is obtained by integrating the cross-system data leakage consensus; the user blacklist management contract is obtained by integrating the cross-system blacklist consensus; and the special data management contract is obtained by integrating the cross-system special data consensus.
[0010] The data security management contract includes a mapping relationship between the target event and the security policy, and a trigger condition of the smart contract; and the policy contract includes a plurality of security policies.
[0011] According to the data security management method provided by the application, the data leakage management contract includes leakage data information, leakage location information, leakage time, sensitivity level, and management requirements.
[0012] The user blacklist management contract includes blacklist user information, blacklisting time, blacklisting operation account, blacklisting description, and data authority of the blacklisted user.
[0013] The special data management contract includes special data information, special marking time, marking operation account, and marking execution location; the special data information is defined in the target system, the special marking time is the time when the special data information is defined or marked, and the blacklisting operation account refers to the account corresponding to the current blacklisting operation.
[0014] According to the data security management method provided by the application, the security policy is a data leakage management policy, a blacklist management policy, or a special data management policy; the data leakage management policy includes encryption processing of each target system on the external leakage plaintext data; the blacklist management policy includes disabling the corresponding blacklisted user in each target system; and the special data management policy includes encryption or access prohibition of the corresponding special data in each target system.
[0015] According to the data security management method provided by the application, the smart contract is run in each target system to control each target system to execute the security policy corresponding to the target event in the smart contract.
[0016] In the process of controlling each target system to execute the security policy corresponding to the target event in the smart contract, accounting is performed to obtain the accounting information of each target system, and the accounting information includes accounting time, contract call record, and contract execution result.
[0017] According to the data security management method provided by the application, the smart contract is compiled into a bytecode file by a preset blockchain compilation tool and deployed on the blockchain.
[0018] The application further provides a data security management system, comprising:
[0019] a target system access module, configured to access a plurality of target systems to a blockchain, wherein the blockchain is pre-deployed with a smart contract, and the smart contract is constructed by integrating a data leakage consensus, a blacklist consensus and a special data consensus across systems, and the special data consensus is based on information defined in the target systems;
[0020] a security management module, configured to control the blockchain to call the smart contract when a target event in any of the target systems triggers the smart contract, and run the smart contract in each of the target systems respectively, so as to control each of the target systems to execute a security policy corresponding to the target event in the smart contract.
[0021] The application further provides a blockchain, comprising: a plurality of blockchain nodes, which are target systems in the data security management method according to any of the above, and the blockchain is provided with a smart contract, wherein the smart contract is constructed by integrating a data leakage consensus, a blacklist consensus and a special data consensus across systems, and the special data consensus is information defined in the target systems; and the blockchain is configured to call the smart contract when a target event in any of the target systems triggers the smart contract, and run the smart contract in each of the target systems respectively, so as to control each of the target systems to execute a security policy corresponding to the target event in the smart contract.
[0022] The application further provides an electronic device, comprising a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the data security management method according to any of the above.
[0023] The application further provides a non-transitory computer readable storage medium, which stores a computer program, and the computer program is executable on a processor to implement the data security management method according to any of the above.
[0024] The application has the beneficial effects that the data security management method, system and blockchain provided by the application can connect multiple target systems to the blockchain, the blockchain is pre-deployed with a smart contract, the smart contract is constructed by integrating cross-system data leakage consensus, blacklist consensus and special data consensus, the special data consensus is obtained based on information defined in the target system, when a target event in any target system triggers the smart contract, the control blockchain calls the smart contract, and the smart contract is run in each target system to control each target system to execute the security policy corresponding to the target event in the smart contract. The method can actively solve the cross-system security problem through the smart contract, effectively improves the efficiency of cross-system security linkage, reduces the security problem vacuum period caused by previous manual communication docking, avoids the expansion of a single security event, and makes the cross-system data security management more perfect and accurate. BRIEF DESCRIPTION OF DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the application or prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the application, and for those skilled in the art, other drawings can also be obtained without creative labor.
[0026] Figure 1 is a flowchart of the data security management method provided by the application;
[0027] Figure 2 is an exemplary schematic diagram of the smart contract call in the data security management method provided by the application;
[0028] Figure 3 is a flowchart of the first embodiment of the data security management method provided by the application;
[0029] Figure 4 is a flowchart of the first embodiment of the data security management method provided by the application;
[0030] Figure 5 is a flowchart of the first embodiment of the data security management method provided by the application;
[0031] Figure 6 is a structural schematic diagram of the data security management system provided by the application;
[0032] Figure 7 is a structural schematic diagram of the electronic device provided by the application. DETAILED DESCRIPTION
[0033] In order to make the objects, technical solutions and advantages of the present application clearer, the technical solutions in the present application will be described clearly and completely below in conjunction with the drawings in the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work belong to the protection scope of the present application.
[0034] The present application is described below in the form of examples in conjunction with Figures 1-7 The data security management method, system, electronic device and storage medium provided by the present application are described.
[0035] Please refer to Figure 1 The data security management method provided by the present application comprises:
[0036] S110: connecting a plurality of target systems to a blockchain, the blockchain being pre-deployed with a smart contract, the smart contract being constructed by integrating cross-system data leakage consensus, blacklist consensus and special data consensus, the special data consensus being based on information defined in the target system.
[0037] Specifically, a plurality of target systems, such as a plurality of business systems, are connected to the blockchain, each target system becoming a blockchain node of the blockchain, forming a blockchain network covering all target systems. It should be noted that the smart contract is an important component of the blockchain, which is a computer protocol designed to disseminate, verify or execute contracts in an information-based manner. The smart contract in the present embodiment is deployed in the blockchain, which is equivalent to being deployed in the blockchain node. When the target event set in the smart contract is triggered, the smart contract will automatically execute, without the need for third-party participation, traceable and irreversible. In order to better solve the cross-system data security problem, the present embodiment integrates cross-system data leakage consensus, blacklist consensus and special data consensus to construct a smart contract, and deploys the smart contract in the blockchain, thereby realizing the management and control of cross-system data security problems, reducing the security problem vacuum period caused by previous manual communication docking, avoiding the expansion of a single security event, making the cross-system data security management and control more perfect and accurate, and effectively reducing the manual communication cost.
[0038] It should be noted that the special data consensus can be information artificially defined in the target system, such as information of leaders, stars and relationships between users.
[0039] It should also be noted that the present embodiment designs and deploys the smart contract for the cross-system data security problem, such as the leakage of certain data plaintext to other systems, the non-consensus of a user blacklist between cross-systems, and the non-consensus of special sensitive data between cross-systems, thereby realizing the management and control of cross-system data security.
[0040] S120: when a target event in any of the target systems triggers the smart contract, the blockchain is controlled to call the smart contract, and the smart contract is respectively run in each of the target systems to control each of the target systems to execute a security policy corresponding to the target event in the smart contract.
[0041] Specifically, when an event in any of the target systems matches a preset target time in the smart contract, the time is determined as the target time, and the smart contract is triggered. In the case of triggering the smart contract, the smart contract is called and respectively run in each of the target systems of the blockchain to control each of the target systems to execute a security policy corresponding to the target event in the smart contract. Thus, the cross-system data security is realized, and the timeliness of the control is strong, the expansion of a single security event can be avoided, and the control accuracy is high.
[0042] It should be noted that, regarding the deployment of the smart contract in the above embodiment, the smart contract can be designed based on common cross-system data security events. Then, based on the designed smart contract, the corresponding smart contract source code is developed. And the code is compiled into a bytecode file by using a blockchain compiling tool. Finally, the bytecode file is saved in the blockchain, thereby completing the deployment of the smart contract. When a related cross-system security event, i.e. a target event, is triggered, the blockchain calls the smart contract to run in each blockchain node to execute the security policy agreed in the contract, respond to various security events or target events, and reduce and avoid the expansion of the security situation.
[0043] Please refer to Figure 2 In some embodiments, the smart contract includes a data leakage management contract, a user blacklist management contract, a special data management contract, a data security management contract, and a policy contract.
[0044] The data leakage management contract is obtained by integrating the cross-system data leakage consensus; the user blacklist management contract is obtained by integrating the cross-system blacklist consensus; and the special data management contract is obtained by integrating the cross-system special data consensus.
[0045] The data security management contract includes a mapping relationship between the target event and the security policy, and a trigger condition of the smart contract; and the policy contract includes a plurality of security policies.
[0046] It should be noted that, by setting the above smart contract, the cross-system data security management can be more perfect and comprehensive. In addition, the data security management contract also includes execution information of the smart contract, i.e. information on how to execute the corresponding security policy.
[0047] It should be noted that the smart contract described in the above embodiment can meet the needs of most cross-system data security management and control. However, due to the differences in actual application scenarios and application requirements, in addition to the above-mentioned contract, other contracts such as user white list management contract can be designed according to actual conditions on the basis of the above-mentioned embodiment, which will not be described here.
[0048] Further, the data leakage management contract includes leakage data information, leakage location information, leakage time, sensitivity level, and control requirements.
[0049] Specifically, the leakage data information refers to the information of the leaked data, that is, the leaked data. The leakage location information refers to the location or address where the data leakage event occurs. The sensitivity level corresponds to the leakage data information. The control requirements refer to the control requirements for the leaked data.
[0050] The user blacklist management contract includes blacklist user information, blacklisting time, blacklisting operation account, blacklisting explanation, and blacklist user data authority.
[0051] Specifically, the blacklisting operation account refers to the account blacklisted by the system. The blacklisting explanation is an explanation added by the user on the business side, that is, an explanation added on the target system. The blacklist user data authority refers to the data authority of the user on the blacklist.
[0052] The special data management contract includes special data information, special marking time, marking operation account, and marking execution location. The special data information is the information defined in the target system. The special marking time is the time when the special data information is defined or marked. The blacklisting operation account refers to the account corresponding to the current blacklisting operation or the account blacklisted by the system.
[0053] It should be noted that by setting the above information in the above-mentioned smart contract, the comprehensiveness of cross-system data security management and control can be better ensured.
[0054] In some embodiments, the security policy is a data leakage management policy, a blacklist management policy, or a special data management policy. The data leakage management policy includes: each target system respectively encrypts the plaintext data leaked outside; the blacklist management policy includes: each target system disables the authority of the corresponding blacklist user; and the special data management policy includes: each target system encrypts or prohibits access to the corresponding special data.
[0055] It should be noted that by setting the management policy in the above-mentioned embodiment, the accuracy of cross-system data security management and control can be better improved.
[0056] In some embodiments, the step of running the smart contract on each of the target systems respectively to control each of the target systems to execute the security policy corresponding to the target event in the smart contract comprises:
[0057] In the process of controlling each of the target systems to execute the security policy corresponding to the target event in the smart contract, accounting is performed to obtain accounting information of each of the target systems, the accounting information comprising: accounting time, contract calling record and contract execution result. It should be noted that by performing accounting in the process of executing the security policy corresponding to the target event in the smart contract on the target system, reliable evidence can be obtained for each triggering execution of the smart contract, and the security characteristics of the block chain cannot be tampered with, thereby ensuring traceability and traceability of the contract execution process.
[0058] The data security management method in the above embodiments will be further explained and described below with reference to several specific exemplary embodiments.
[0059] Embodiment one:
[0060] Please refer to Figure 3 , S310: detecting data plaintext leakage. Specifically, it is detected that sensitive data of a certain target system is transferred to other target systems in plaintext form, thereby triggering a smart contract.
[0061] S320: calling a smart contract. Specifically, the smart contract is called, the smart contract is run on each target system, and each target system is controlled to execute the security policy corresponding to the data plaintext leakage event in the smart contract.
[0062] S330: each node data encryption. Specifically, each target system encrypts the sensitive data to avoid the expansion of the leakage and cause unnecessary loss.
[0063] S340: each node accounting. That is, when each target system executes the corresponding security policy, accounting is performed to ensure traceability and traceability of the contract execution process.
[0064] Embodiment two:
[0065] Please refer to Figure 4 , S410: querying special data. For example, certain customer information is relatively sensitive and business personnel do not want to query it, so the customer information is defined as special data to trigger a smart contract. That is, when a special data definition operation occurs, a smart contract is triggered.
[0066] S420: calling a smart contract.
[0067] S430: Each node limits the query. Specifically, each blockchain node, i.e., the target system, runs the smart contract and performs the operation of limiting the query. Thus, the client information is limited in each target system, and the privacy of the client is protected.
[0068] S440: Each node records the account.
[0069] Embodiment three:
[0070] Please refer to Figure 5 S510: A user blacklist write operation is detected. For example, a target system business personnel is suspected of violating the rules, and the target system writes the personnel into the user blacklist. At this time, the user blacklist write operation is detected. At the same time, the user blacklist write operation triggers the smart contract.
[0071] S520: The smart contract is called.
[0072] S530: Each node disables the user. Specifically, on the basis of the above example, each target system runs the smart contract and disables the personnel to avoid causing a data security accident.
[0073] S540: Each node records the account.
[0074] The data security management and control system provided by the present application is described below. The data security management and control system described below can be mutually corresponding and referred to with the data security management and control method described above.
[0075] Please refer to Figure 6 The data security management and control system provided by the present embodiment comprises:
[0076] The target system access module 610 is configured to access a plurality of target systems to a blockchain, wherein the blockchain is pre-deployed with a smart contract, and the smart contract is constructed by integrating a cross-system data leakage consensus, a blacklist consensus, and a special data consensus, and the special data consensus is based on information defined in the target system;
[0077] The security management and control module 620 is configured to control the blockchain to call the smart contract when a target event in any of the target systems triggers the smart contract, and run the smart contract in each of the target systems to control each of the target systems to execute a security policy corresponding to the target event in the smart contract. The data security management and control system in the present embodiment can actively solve the cross-system security problem through the smart contract, effectively improve the efficiency of cross-system security linkage, reduce the security problem vacuum period caused by previous manual communication and docking, avoid the expansion of a single security event, make the cross-system data security management and control more perfect and accurate, and has a lower cost and higher implementability.
[0078] In some embodiments, the security control module 620 includes: an accounting unit, used to perform accounting during the process of controlling each of the target systems to execute the security policy corresponding to the target event in the smart contract, and to obtain accounting information of each of the target systems, the accounting information including: accounting time, contract call record and contract execution result.
[0079] Figure 7 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 7 As shown, the electronic device may include a processor 710, a communications interface 720, a memory 730, and a communication bus 740. The processor 710, communications interface 720, and memory 730 communicate with each other via the communication bus 740. The processor 710 can call logical instructions in the memory 730 to execute a data security management method. This method includes: connecting multiple target systems to a blockchain, where smart contracts are pre-deployed. The smart contracts are constructed by integrating cross-system data leakage consensus, blacklist consensus, and special data consensus, with the special data consensus based on information defined in the target systems. When a target event in any target system triggers the smart contract, the control blockchain calls the smart contract, running the smart contracts on each target system to control each target system to execute the security policy corresponding to the target event in the smart contract.
[0080] Furthermore, the logical instructions in the aforementioned memory 730 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0081] In yet another aspect, the present application also provides a non-transitory computer readable storage medium having stored thereon a computer program, which, when executed by a processor, implements a data security management method provided by any of the above methods, the method comprising: connecting a plurality of target systems to a blockchain, the blockchain being pre-deployed with a smart contract, the smart contract being constructed by integrating a data leakage consensus, a blacklist consensus, and a special data consensus across systems, the special data consensus being based on information defined in the target systems; when a target event in any of the target systems triggers the smart contract, controlling the blockchain to invoke the smart contract, and running the smart contract in each of the target systems to control the target systems to execute a security policy corresponding to the target event in the smart contract.
[0082] The apparatus embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, i.e., may be located in one place, or may be distributed on multiple network units. Part or all of the modules can be selected to achieve the purpose of the present embodiment scheme according to actual needs. Those skilled in the art can understand and implement without creative labor.
[0083] From the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be realized by means of software and necessary general hardware platform, and of course can also be realized by hardware. Based on such understanding, the above technical solutions, essentially or in the form of software products, can be embodied in a computer readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., including a number of instructions to make a computer device (which can be a personal computer, server, or network device, etc.) execute the methods described in each embodiment or some parts of the embodiments.
[0084] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement to some technical features; and these modifications or replacements do not make the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A data security management and control method, characterized in that, include: Multiple target systems are connected to a blockchain, which is pre-deployed with smart contracts. These smart contracts are constructed by integrating cross-system data leakage consensus, blacklist consensus, and special data consensus, which are obtained based on information defined in the target systems. When a target event in any of the target systems triggers the smart contract, the blockchain is controlled to call the smart contract and run the smart contract in each of the target systems to control each target system to execute the security policy in the smart contract corresponding to the target event; The smart contracts include: a data leakage management contract, a user blacklist management contract, a special data management contract, a data security control contract, and a policy contract; the data leakage management contract is obtained by integrating the cross-system data leakage consensus; the user blacklist management contract is obtained by integrating the cross-system blacklist consensus; the special data management contract is obtained by integrating the cross-system special data consensus; the data security control contract includes: the mapping relationship between the target event and the security policy, and the triggering conditions of the smart contract; the policy contract includes multiple security policies; The security policy is a data leakage management policy, a blacklist management policy, or a special data management policy; the data leakage management policy includes: each of the target systems encrypts the leaked plaintext data; the blacklist management policy includes: each of the target systems disables the corresponding blacklist users; the special data management policy includes: each of the target systems encrypts or prohibits access to the corresponding special data.
2. The data security management method according to claim 1, characterized in that, The data breach management contract includes: breached data information, breach location information, breach time, sensitivity level, and control requirements; The user blacklist management contract includes: blacklist user information, blacklist time, blacklist operation account, blacklist instructions, and blacklist user data permissions; the blacklist operation account is the account corresponding to the current blacklist operation. The special data management contract includes: special data information, special marking time, marking operation account, and marking execution location; the special data information is information defined in the target system, and the special marking time is the time when the special data information is defined or marked.
3. The data security management method according to claim 1, characterized in that, The steps of running the smart contract on each of the target systems to control each target system to execute the security policy in the smart contract corresponding to the target event include: During the process of controlling each target system to execute the security policy corresponding to the target event in the smart contract, accounting is performed to obtain accounting information for each target system. The accounting information includes: accounting time, contract call record, and contract execution result.
4. The data security management method according to claim 1, characterized in that, The smart contract is compiled into bytecode files using a preset blockchain compilation tool and then deployed on the blockchain.
5. A data security management and control system, characterized in that, include: The target system access module is used to connect multiple target systems to the blockchain. The blockchain is pre-deployed with smart contracts. The smart contracts are constructed by integrating cross-system data leakage consensus, blacklist consensus, and special data consensus. The special data consensus is based on information defined in the target system. The security control module is used to control the blockchain to call the smart contract when a target event in any of the target systems triggers the smart contract, and to run the smart contract in each of the target systems respectively, so as to control each of the target systems to execute the security policy in the smart contract corresponding to the target event; The smart contracts include: a data leakage management contract, a user blacklist management contract, a special data management contract, a data security control contract, and a policy contract; the data leakage management contract is obtained by integrating the cross-system data leakage consensus; the user blacklist management contract is obtained by integrating the cross-system blacklist consensus; the special data management contract is obtained by integrating the cross-system special data consensus; the data security control contract includes: the mapping relationship between the target event and the security policy, and the triggering conditions of the smart contract; the policy contract includes multiple security policies; The security policy is a data leakage management policy, a blacklist management policy, or a special data management policy; the data leakage management policy includes: each of the target systems encrypts the leaked plaintext data; the blacklist management policy includes: each of the target systems disables the corresponding blacklist users; the special data management policy includes: each of the target systems encrypts or prohibits access to the corresponding special data.
6. A blockchain, characterized in that, include: Multiple blockchain nodes, wherein the blockchain nodes are the target systems in the data security management method as described in any one of claims 1 to 4, the blockchain is equipped with smart contracts, the smart contracts are constructed by integrating cross-system data leakage consensus, blacklist consensus, and special data consensus, the special data consensus being information defined in the target system; the blockchain is used to call the smart contract when a target event in any of the target systems triggers the smart contract, and run the smart contract in each of the target systems respectively, so as to control each of the target systems to execute the security policy in the smart contract corresponding to the target event; The smart contracts include: a data leakage management contract, a user blacklist management contract, a special data management contract, a data security control contract, and a policy contract; the data leakage management contract is obtained by integrating the cross-system data leakage consensus; the user blacklist management contract is obtained by integrating the cross-system blacklist consensus; the special data management contract is obtained by integrating the cross-system special data consensus; the data security control contract includes: the mapping relationship between the target event and the security policy, and the triggering conditions of the smart contract; the policy contract includes multiple security policies; The security policy is a data leakage management policy, a blacklist management policy, or a special data management policy; the data leakage management policy includes: each of the target systems encrypts the leaked plaintext data; the blacklist management policy includes: each of the target systems disables the corresponding blacklist users; the special data management policy includes: each of the target systems encrypts or prohibits access to the corresponding special data.
7. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the data security management method as described in any one of claims 1 to 4.
8. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the data security management method as described in any one of claims 1 to 4.
Citation Information
Patent Citations
A cross-domain shared data security decision-making method and model based on a block chain
CN109711182A
Defensible disposition of data
US20200174968A1