A cloud data processing system based on a cloud server

The cloud data processing system, through multi-level security verification mechanisms and hierarchical storage, solves the problem of poor confidentiality during cloud data storage, and achieves efficient data protection and rapid response.

CN119026164BActive Publication Date: 2025-12-19KAIYUAN CLOUD (BEIJING) TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411110875.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-14
Publication Date
2025-12-19
Estimated Expiration
2044-08-14

AI Technical Summary

Technical Problem

In existing cloud data processing systems, the confidentiality of cloud data storage is poor, posing a risk of data leakage or tampering.

Method used

A multi-level security verification mechanism is adopted, including first-level account password verification, second-level security questionnaire verification, and third-level feature deviation verification. Combined with biometric information, user data is stored hierarchically, and communication and data transmission between system modules are realized through a central processing unit.

Benefits of technology

It significantly improves data confidentiality, reduces the risk of data leakage or tampering through multi-layered encryption and authentication, ensures differentiated protection for data of different importance levels, and provides a rapid response mechanism in emergency situations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119026164B_ABST
    Figure CN119026164B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of cloud data processing, in particular to a cloud data processing system based on a cloud server, which comprises a cloud server platform capable of storing cloud data and controlling the operation of various modules of the system, realizing the analysis and processing of the cloud data; a data processing module capable of integrating user operation data, forming a unified data view, and deeply mining the integrated data; a data management module verifying the user identity through third-level security verification and unlocking the cloud data content in stages; and an interactive module displaying the components of the system through a visual window and executing specific operations. The application improves the confidentiality of the cloud data through the implementation of multistage security verification, implements differentiated protection strategies for data content of different importance levels, ensures the maximum protection of the data value, and effectively reduces the risk of data leakage or tampering through identity verification and access control and the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cloud data processing technology, and in particular to a cloud data processing system based on a cloud server. Background Technology

[0002] With the advent of the big data era, traditional data processing methods are no longer sufficient to meet the demands of processing massive amounts of data. The emergence of cloud servers and cloud data processing technologies offers a new solution. Cloud servers provide the necessary computing and storage resources for cloud data processing. During cloud data processing, a large number of computing tasks need to be executed by cloud servers, and the data generated during processing also needs to be stored on cloud servers. This can significantly reduce data processing costs and improve data processing efficiency, but there are still shortcomings in areas such as data security and privacy protection.

[0003] Chinese Patent Publication No. CN115858170A discloses a cloud server adaptive data processing system, including a cloud server processing host. The cloud server processing host internally includes a data system, a central processing system, an output system, a back-end auxiliary system, and a multi-device monitoring module. The multi-device monitoring module monitors each device in the cloud server in real time. The data system internally includes a data input module, a data processing module, and a front-end processing unit. The data system inputs and processes front-end data in the cloud server. An access control module obtains control permissions for the data when the front-end data processing module processes data. The data processing module detects the input data.

[0004] This shows that the confidentiality of cloud data storage in current cloud data processing systems is poor, and there is a risk of data leakage or tampering. Summary of the Invention

[0005] To address this issue, the present invention provides a cloud data processing system based on a cloud server, which overcomes the problem of poor confidentiality in the cloud data storage process in the prior art, and the risk of data leakage or tampering.

[0006] To achieve the above objectives, the present invention provides a cloud data processing system based on a cloud server, comprising:

[0007] A cloud server platform, which includes several databases and a central processing unit, is capable of storing cloud data and controlling the operation of various system modules, enabling the analysis and processing of cloud data;

[0008] The data processing module can integrate user operation data to form a unified data view, and conduct in-depth mining of the integrated data to discover patterns and trends in the data. Based on business needs, it can allocate data resources to different users or units.

[0009] The data management module verifies the user identity through the first, second and third verification units respectively, and unlocks the cloud data content in stages.

[0010] The interactive module displays the components of the system through the visual window display system, and enables the user to enter the corresponding module or unit by clicking the button on the visual window to perform a specific operation.

[0011] Further, the data processing module comprises,

[0012] The data integration unit integrates the data calling path in the user operation process in a unified format and stores it into a calling path set.

[0013] The data analysis unit deeply mines the calling path set, discovers the rules and trends in the data, forms a feature point set, and establishes a virtual user image according to the feature point set.

[0014] The data comparison unit compares each calling path in the calling path set with the established virtual user image, calculates the feature deviation amount, and feeds back the feature deviation amount result set to the third verification unit.

[0015] The data updating unit can save the data calling path in the user operation process, and after the user operation is completed, it transmits the user operation data to the data integration unit for processing.

[0016] Further, the data management module comprises,

[0017] The first verification unit verifies through the account password form, and after successful login, the cloud server platform opens the first database permission, and the user can call all the data of the first database.

[0018] The second verification unit verifies the user identity through the security questionnaire, and after the user identity is matched successfully, the cloud server platform opens the second database permission, and the user can call all the data of the second database.

[0019] The third verification unit collects the data calling path in the user operation process, and through the central processing unit, it is summarized to the data processing module, and according to the feature deviation amount fed back by the data processing module, it determines whether to open or close the third database permission.

[0020] Further, the cloud server platform comprises,

[0021] The user database is divided into a first database, a second database and a third database, which respectively store data of different privacy levels.

[0022] A central processing unit is capable of realizing the communication connection between the modules of the system, completing data transmission, and controlling the execution of the work of each module.

[0023] Further, the cloud server platform further comprises a user information unit capable of managing user personal information and the content of the security questionnaire of the second-level verification unit, wherein the user personal information includes the user's account password and biometric information.

[0024] Further, the cloud server platform further comprises a permission setting unit capable of changing the storage level of cloud data and the upper limit of the number of temporary verification unit starts according to user needs.

[0025] Further, the third-level verification unit further comprises a temporary verification unit, which is started when the user urgently calls the content of the third-level database, verifies the user's identity by matching the user's biometric information, and determines whether to open or close the third-level database permission according to the verification result; The switch of the temporary verification unit is in the visual window of the interactive module, and in a non-emergency situation, the content of the third-level database needs to pass through all three verification processes; The number of times the temporary verification unit is started has an upper limit, which can be adjusted through the permission setting unit.

[0026] Further, the first-level verification unit is an account password verification, and when the user uses the cloud server for the first time, the user registers an account and sets a password through the cloud server platform, sets a security questionnaire, and enters the user's biometric information, which is saved to the user information unit;

[0027] The central processing unit allocates storage space and establishes a user database dedicated to the account, which is divided into three levels, and the central processing unit stores the cloud data into the user database according to the data classification algorithm, and the user can manually change the storage level of the cloud data through the permission setting unit;

[0028] The first-level verification unit verifies the user's identity by matching the input account password information with the account password information in the user information unit,

[0029] If the matching is successful, the cloud server platform opens the first-level database permission, and the user can call all the data of the first-level database;

[0030] If the matching fails, the cloud server platform closes the first-level database permission, and the user cannot call all the data of the first-level database.

[0031] Further, the second level verification unit is a security questionnaire verification. When the content of the second level database needs to be called, the second level verification unit button on the interactive module is selected to verify the user identity by matching the input security questionnaire content with the security questionnaire content in the user information unit,

[0032] If the matching is successful, the cloud server platform opens the second level database permission, and the user can call all the data of the second level database;

[0033] If the matching fails, the cloud server platform closes the second level database permission, and the user cannot call all the data of the second level database.

[0034] Further, the third level verification unit is a calling feature verification. The third level verification unit saves the user operation process and sends it to the data processing module. The data update unit in the data processing module saves the calling path of the cloud data in each operation process of the user as a separate data group. After the user operation is completed, the data groups are all transmitted to the data integration unit. The data integration unit forms the calling path in a unified format and stores it in the calling path set. The data analysis unit deeply mines the rules and trends in the calling path to form a calling path feature point set. A virtual user image is established according to the calling path feature point set. With long-term use of the user, the size of the calling path feature point set will continuously expand, and the virtual user image will be continuously updated.

[0035] When the content of the third level database needs to be called, the third level verification unit button on the interactive module is selected. The third level verification unit saves all user operations before the current application of opening the third level database and sends it to the data processing module. The data processing module counts the number of calling paths and establishes the calling path set. Each calling path in the calling path set is compared with the virtual user image that has been established. The proportion of the feature points in each calling path that do not match the virtual user image in the total feature points of the calling path is the feature deviation amount of the calling path. A calling path feature deviation amount set is summarized and fed back to the third level verification unit. The elements in the calling path feature deviation amount set are compared with the feature deviation amount evaluation value set by the third level verification unit,

[0036] When the calling path feature deviation amount set is empty, it cannot be compared, and it is directly jumped to the temporary verification unit;

[0037] When the calling path feature deviation amount set is not empty, if the feature deviation amount of any calling path is greater than or equal to the feature deviation amount evaluation value, it means that the calling path deviation is too large, and it is determined that it is not the user's own operation. The current user is forced to log out, and the calling path data of this time is cleared,

[0038] If the feature deviation amount of all the calling paths is less than the feature deviation amount evaluation value, then the feature deviation amount score is further calculated according to the number of the current calling paths;

[0039] If the number of the current calling paths is less than or equal to one, it is considered that the user needs to urgently call the content of the third-level database, and the temporary verification unit is automatically jumped to, and the user identity is verified by matching the biological identification information;

[0040] If the number of the current calling paths is greater than one, the feature deviation amount score is calculated, and the feature deviation amount score is compared with the evaluation value of the feature deviation amount score set in the third-level verification unit,

[0041] If the feature deviation amount score is greater than or equal to the evaluation value of the feature deviation amount score, it is considered that the calling path deviation is too large, and it is determined that the current user is not operated by the user himself, and the current user is forced to log out, and the current calling path data is cleared,

[0042] If the feature deviation amount score is less than the evaluation value of the feature deviation amount score, it is determined that the current user is operated by the user himself, and the third-level database permission is opened;

[0043] The evaluation value of the feature deviation amount score set in the third-level verification unit is different according to the number of the calling paths, and the third-level verification unit is provided with a mean value of the number of the calling paths under general operation, and the number of the current calling paths is compared with the mean value of the number of the calling paths under general operation,

[0044] If the number of the current calling paths is greater than the number of the calling paths under general operation, the evaluation value of the feature deviation amount score is a fixed value;

[0045] If the number of the current calling paths is less than or equal to the number of the calling paths under general operation, the evaluation value of the feature deviation amount score is calculated according to the number of the current calling paths.

[0046] When the user calls the third-level database for the first time, since the virtual user image has not been established, when the user clicks the third-level verification unit button on the interactive module, the temporary verification unit is directly jumped to, and the verification is performed by matching the biological identification information.

[0047] Compared with the prior art, the beneficial effects of the present application are that the data storage process is comprehensively and meticulously protected by implementing the multi-level security verification mode, the data security is significantly improved, the differentiated protection strategy is implemented for different important level data contents, the maximum protection of the data value is ensured, and the risk of data leakage or tampering is effectively reduced through multi-layer encryption, identity verification and access control and other means.

[0048] Especially, in order to cope with the data call demand in emergency or emergency, the system sets up a temporary verification unit, which allows users to quickly pass the verification through the biological information identification method under the premise of ensuring safety, calls the required important data, and improves the flexibility and response speed of the system.

[0049] Further, the feature points of the third-level verification unit are constantly updated and optimized according to the user's usage habits, behavior patterns and other information, so as to gradually improve the virtual user image generated by the system, which not only enhances the accuracy and reliability of the verification, but also reduces the probability of large feature deviation error caused by insufficient or outdated feature points. BRIEF DESCRIPTION OF DRAWINGS

[0050] Figure 1 The figure is a schematic diagram of the overall structure of a cloud data processing system based on a cloud server in an embodiment of the present application.

[0051] Figure 2 The figure is a first-level verification flowchart in an embodiment of the present application.

[0052] Figure 3 The figure is a second-level verification flowchart in an embodiment of the present application.

[0053] Figure 4 The figure is a third-level verification flowchart in an embodiment of the present application.

[0054] Figure 5 The figure is a temporary verification flowchart in an embodiment of the present application. DETAILED DESCRIPTION

[0055] In order to make the purpose and advantages of the present application clearer and more apparent, the present application will be further described below with reference to the embodiments; it should be understood that the specific embodiments described herein are only used to explain the present application, and do not limit the present application.

[0056] The preferred embodiments of the present application will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the present application, and are not intended to limit the protection scope of the present application.

[0057] It should be noted that in the description of the present application, the terms "up", "down", "left", "right", "in", "out" and the like indicate the direction or positional relationship of the terms based on the direction or positional relationship shown in the drawings, which is only for the convenience of description, and does not indicate or imply that the device or element must have a particular orientation, be constructed and operated in a particular orientation, therefore it cannot be understood as a limitation of the present application.

[0058] Moreover, it needs to be explained that, in the description of the present application, unless otherwise explicitly specified and limited, the terms "mounting", "connection", "connecting" should be understood in a broad sense, for example, can be fixed connection, can also be detachable connection, or integrally connected, can be mechanical connection, can also be electrical connection, can be directly connected, can also be indirectly connected through intermediate medium, can be the communication inside two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.

[0059] Please refer to Figures 1-5 shown, Figure 1 is a schematic diagram of the overall structure of a cloud data processing system based on a cloud server in an embodiment of the present application; Figure 2 is a first-level verification flowchart in an embodiment of the present application; Figure 3 is a second-level verification flowchart in an embodiment of the present application; Figure 4 is a third-level verification flowchart in an embodiment of the present application; Figure 5 is a temporary verification flowchart in an embodiment of the present application.

[0060] The present application provides a cloud data processing system based on a cloud server, comprising,

[0061] a cloud server platform comprising a plurality of databases and a central processing unit, capable of storing cloud data and controlling the operation of each module of the system, realizing the analysis and processing of cloud data;

[0062] a data processing module capable of integrating user operation data, forming a unified data view, and deeply mining the integrated data to find the rules and trends in the data, and according to the business requirements, distributing the data resources to different users or units;

[0063] a data management module, which verifies the user identity through a first-level verification unit, a second-level verification unit and a third-level verification unit, respectively, and unlocks the cloud data content in stages.

[0064] an interactive module which displays each part of the system through a visual window, and can enter the corresponding module or unit by clicking the button on the visual window to perform a specific operation.

[0065] Specifically, the data processing module comprises,

[0066] a data integration unit which integrates the calling path of data in the user operation process in a unified format and stores it into a calling path set;

[0067] a data analysis unit which deeply mines the calling path set to find the rules and trends in the data, forms a feature point set, and establishes a virtual user image according to the feature point set;

[0068] a data comparison unit, which compares each of the call paths in the call path set with the virtual user image that has been established, calculates a feature deviation amount, and feeds a feature deviation amount result set to the third level check unit;

[0069] a data update unit, which can save the call paths for data during user operation, and after the user operation is completed, transmits all of the user call process data to the data integration unit for processing.

[0070] Specifically, the data management module includes,

[0071] a first level check unit, which verifies through an account password form, and after login is successful, the cloud server platform opens a first level database permission, and the user can call all of the data of the first level database;

[0072] a second level check unit, which verifies the user identity through a security questionnaire, and after the user identity is matched successfully, the cloud server platform opens a second level database permission, and the user can call all of the data of the second level database;

[0073] a third level check unit, which collects the call paths for data during user operation, and through the central processing unit, the call paths are summarized to the data processing module, and according to the feature deviation amount fed back by the data processing module, the third level database permission is determined to be opened or closed.

[0074] Specifically, the cloud server platform includes,

[0075] a user database, which is divided into a first level database, a second level database, and a third level database, and stores data of different privacy levels respectively;

[0076] a central processing unit, which can realize communication connection between the modules of the system, complete data transmission, and control the modules to perform work.

[0077] Specifically, the cloud server platform further includes a user information unit, which can manage user personal information and security questionnaire content of the second level check unit, and the user personal information includes an account password and biological identification information of the user.

[0078] Specifically, the cloud server platform further includes a permission setting unit, which can change the storage level of cloud data and the upper limit of the number of times of temporary check units according to user needs.

[0079] Specifically, the third level verification unit also includes a temporary verification unit, which is started when a user urgently calls the content of the third level database, verifies the user's identity by matching the user's biological identification information, determines the opening or closing of the third level database permission according to the verification result, and the switch of the temporary verification unit is started in the visual window of the interactive module. The number of times the temporary verification unit is turned on has an upper limit. In a non-emergency situation, calling the content of the third level database needs to go through the entire three-level verification process. The upper limit of the number of times the temporary verification unit is turned on can be adjusted by the permission setting unit.

[0080] Taking the normal calling of the data in the third level database by the user after using for a period of time as an example,

[0081] Specifically, the first level verification unit is account password verification. When a user uses the cloud server for the first time, the user registers an account and sets a password through the cloud server platform, sets a security questionnaire, enters the user's biological identification information, and saves it to the user information unit.

[0082] The central processing unit allocates storage space and establishes a user database dedicated to the account. The user database is divided into three levels. The central processing unit stores cloud data into the user database according to a data classification algorithm. The user can manually change the storage level of the cloud data through the permission setting unit.

[0083] The first level verification unit verifies the user's identity by matching the input account password information with the account password information in the user information unit.

[0084] If the matching is successful, the cloud server platform opens the first level database permission, and the user can call all the data of the first level database.

[0085] If the matching fails, the cloud server platform closes the first level database permission, and the user cannot call all the data of the first level database.

[0086] Specifically, the second level verification unit is security questionnaire verification. When the content of the second level database needs to be called, the second level verification unit button on the interactive module is selected, the user's identity is verified by matching the input security questionnaire content with the security questionnaire content in the user information unit,

[0087] If the matching is successful, the cloud server platform opens the second level database permission, and the user can call all the data of the second level database.

[0088] If the matching fails, the cloud server platform closes the second level database permission, and the user cannot call all the data of the second level database.

[0089] Specifically, the third level verification unit is to call the feature verification, the third level verification unit saves the user operation process and sends to the data processing module, the data updating unit in the data processing module saves the user's calling path of cloud data in each operation process as a separate data group, after the user operation is completed, all these data groups are transmitted to the data integration unit, the data integration unit forms the calling path with a unified format according to the data group content, stores it in the calling path set, and the data analysis unit deeply mines the rules and trends in it to form the calling path feature point set, and establishes a virtual user image according to the calling path feature point set, with the long-term use of the user, the scale of the calling path feature point set will be continuously expanded, and the virtual user image will be continuously updated;

[0090] When the content of the third level database needs to be called, the third level verification unit button on the interactive module is selected, and the verification process of the third level verification unit is as follows:

[0091] The third level verification unit saves all user operations before the user applies to open the third level database this time, and sends them to the data processing module. The data processing module counts the number of calling paths n this time and establishes the calling path set this time. Each calling path in the calling path set this time is compared with the virtual user image that has been established. The proportion of the feature points in each calling path that do not match the virtual user image in the total feature points of the calling path is the feature deviation amount Xi of the calling path. The calling path feature deviation amount set A = {X1, X2,..., Xn} is summarized and fed back to the third level verification unit. The elements in A are compared with the feature deviation amount evaluation value Xk set by the third level verification unit,

[0092] When A is an empty set, it cannot be compared, and it is directly jumped to the temporary verification unit;

[0093] When A is not an empty set, if there exists any Xi≥Xk, it means that the calling path deviation is too large, and it is judged that it is not the user's own operation. The current user is forced to log out, and the calling path data this time is cleared,

[0094] If all Xi<Xk, the feature deviation amount score is further calculated according to the number of calling paths this time;

[0095] If the number of calling paths this time n≤1, it is considered that the user needs to urgently call the content of the third level database, and it is automatically jumped to the temporary verification unit and verified by matching the biological recognition information;

[0096] If the number of calling paths this time n>1, the feature deviation amount score F is calculated,

[0097] Where The greater the value of Xi, the greater the value of ai;

[0098] The feature deviation score F is compared with the evaluation value Fp of the feature deviation score set in the third level verification unit,

[0099] If F≥Fp, it is determined that the user is not operating by himself / herself, the current user is forced to log out, and the current call path data is cleared,

[0100] If F<Fp, it is determined that the user is operating by himself / herself, and the third level database permission is opened;

[0101] The size of the evaluation value Fp of the feature deviation score set in the third level verification unit is different according to the different number n of call paths. The smaller the number n of call paths, the higher the probability of error in the calculation process of the feature deviation score F. Therefore, when the value of the number n of call paths is small, the value of the evaluation value Fp of the feature deviation score is increased to reduce the influence of the error;

[0102] N1 is set as the average number of call paths under normal operation,

[0103] When n>N1, the evaluation value Fp of the feature deviation score is Fp1, and Fp1 is a fixed value;

[0104] When n≤N1, the evaluation value of the feature deviation score is

[0105] When the user first calls the third level database, since the virtual user image has not been established, when the user clicks the third level verification unit button on the interactive module, the temporary verification unit is directly jumped to, and the verification is performed by matching the biological recognition information.

[0106] Taking the user's emergency call of the data in the third level database as an embodiment,

[0107] Specifically, the user needs to first pass the verification of the first level verification unit and the second level verification unit, click the temporary verification unit start button in the interactive module, enter the biological recognition information matching process, match the real-time input biological recognition information with the biological recognition information stored in the user information unit,

[0108] If the matching is successful, the cloud server platform opens the third level database permission, and the user can call all the data of the third level database;

[0109] If the matching fails, the cloud server platform closes the third level database permission, and the user cannot call all the data of the third level database.

[0110] So far, the technical solutions of the present application have been described in combination with the preferred embodiments shown in the drawings, but it is easy for those skilled in the art to understand that the protection scope of the present application is obviously not limited to these specific embodiments. Those skilled in the art can make equivalent changes or replacements to the related technical features without departing from the principles of the present application, and the technical solutions after the changes or replacements will all fall within the protection scope of the present application.

[0111] The above only describes the preferred embodiments of the present application and is not intended to limit the present application; the present application can have various changes and variations for those skilled in the art. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A cloud data processing system based on a cloud server, characterized by, Comprising, a cloud server platform comprising several databases and central processing units, capable of storing cloud data and controlling the operation of each module of the system, realizing the analysis and processing of cloud data; the cloud server platform further comprises a user information unit capable of managing user personal information and the content of the second-level verification unit's security questionnaire, the user personal information including the user's account password and biometric information; a data processing module capable of integrating user operation data, forming a unified data view, and deeply mining the integrated data to find the rules and trends in the data, and according to the business requirements, allocating data resources to different users or units; a data integration unit that integrates the calling path of data in the user operation process in a unified format and stores it into the calling path set; a data analysis unit that deeply mines the calling path set to find the rules and trends in the data, forms a feature point set, and establishes a virtual user image according to the feature point set; a data management module that verifies the user's identity through the first, second, and third verification units and unlocks the cloud data content in stages; an interactive module that displays the components of the system through a visual window and can enter the corresponding module or unit by clicking the button on the visual window to perform limited operations; the data management module includes a third verification unit that collects the calling path of data in the user operation process and aggregates it to the data processing module through the central processing unit, and determines whether to open or close the third database permission according to the feature deviation amount fed back by the data processing module; the third verification unit is a calling feature verification, and the third verification unit saves the user operation process and sends it to the data processing module, the data update unit in the data processing module saves the calling path of cloud data in each user operation process as a separate data group, and after the user operation is completed, all these data groups are transmitted to the data integration unit, which forms the calling path in a unified format from the data group content and stores it in the calling path set, and through the data analysis unit, the rules and trends in the data are deeply mined to form a calling path feature point set, and a virtual user image is established according to the calling path feature point set; when the content of the third database needs to be called, select the third verification unit button on the interactive module, the third verification unit saves all user operations before this application to open the third database, and sends it to the data processing module, the data processing module counts the number of calling paths and establishes the calling path set, compares each calling path in the calling path set with the virtual user image that has been established, the proportion of feature points in each calling path that do not match the virtual user image in the total feature points of the calling path is the feature deviation amount of the calling path, a calling path feature deviation amount set is aggregated, and feedback is given to the third verification unit, the elements in the calling path feature deviation amount set are compared with the feature deviation amount evaluation value set by the third verification unit, When the set of feature deviation amounts of the calling path is empty, comparison is impossible, and the temporary verification unit is directly jumped to; When the set of feature deviation amounts of the calling path is not empty, if the feature deviation amount of any calling path is greater than or equal to the feature deviation amount evaluation value, it is indicated that the calling path deviation is too large, it is determined that the operation is not performed by the user himself, the current user is forced to log out, and the calling path data of this time is cleared, If the feature deviation amount of all calling paths is less than the feature deviation amount evaluation value, the feature deviation amount score is further calculated according to the number of calling paths this time; If the number of calling paths this time is less than or equal to one, it is considered that the user needs to urgently call the content of the third-level database, and the temporary verification unit is automatically jumped to, and the user identity is verified by matching the biological identification information; If the number of calling paths this time is greater than one, the feature deviation amount score is calculated, and the feature deviation amount score is compared with the evaluation value of the feature deviation amount score set in the third-level verification unit, If the feature deviation amount score is greater than or equal to the evaluation value of the feature deviation amount score, it is indicated that the calling path deviation is too large, it is determined that the operation is not performed by the user himself, the current user is forced to log out, and the calling path data of this time is cleared; If the feature deviation amount score is less than the evaluation value of the feature deviation amount score, it is determined that the operation is performed by the user himself, and the third-level database permission is opened; The third-level verification unit further includes a temporary verification unit, which is started when the user urgently calls the content of the third-level database, verifies the user identity by matching the biological identification information of the user, and determines whether the third-level database permission is opened or closed according to the verification result; The switch for starting the temporary verification unit is in the visual window of the interactive module, and in a non-emergency situation, the content of the third-level database needs to pass through all the third-level verification processes; The evaluation value of the feature deviation amount score set in the third-level verification unit is different according to the number of calling paths, the third-level verification unit is provided with a mean value of the number of calling paths in a regular operation situation, and the number of calling paths this time is compared with the mean value of the number of calling paths in the regular operation situation, If the number of calling paths this time is greater than the number of calling paths in the regular operation situation, the evaluation value of the feature deviation amount score is a fixed value; If the number of calling paths this time is less than or equal to the number of calling paths in the regular operation situation, the evaluation value of the feature deviation amount score is calculated according to the number of calling paths this time.

2. The cloud data processing system based on cloud server according to claim 1, characterized in that, The data processing module includes, A data comparison unit compares each calling path in the set of calling paths with the established virtual user image, calculates the feature deviation amount, and feeds back the set of feature deviation amount results to the third-level verification unit; A data updating unit can save the calling path of data in the user operation process, and after the user operation is completed, the user calling process data is all transmitted to the data integration unit for processing.

3. The cloud data processing system based on cloud server according to claim 1, wherein, The data management module includes, A first-level verification unit verifies through an account password form, after successful login, the cloud server platform opens the first-level database permission, and the user can call all the data of the first-level database; The second level verification unit verifies the user identity through the security questionnaire, and the cloud server platform opens the second level database permission after the user identity is matched successfully, and the user can call all data of the second level database.

4. The cloud data processing system based on cloud server according to claim 1, characterized in that, The cloud server platform comprises, The user database is divided into a first level database, a second level database and a third level database, and stores data of different privacy levels respectively. The central processing unit can realize communication connection between system modules, complete data transmission and control each module to perform work.

5. The cloud data processing system based on cloud server according to claim 4, characterized in that, The cloud server platform further comprises a permission setting unit which can change the storage level of cloud data and the upper limit of the number of times of starting the temporary verification unit according to user demand.

6. The cloud data processing system based on cloud server according to claim 3, characterized in that, The number of times of starting the temporary verification unit has an upper limit, which can be adjusted through the permission setting unit.

7. The cloud data processing system based on cloud server according to claim 3, characterized in that, The first level verification unit is account password verification, and the user registers an account and sets a password through the cloud server platform when using the cloud server for the first time, sets a security questionnaire and inputs biological identification information of the user to save to the user information unit; The central processing unit allocates a storage space and establishes a user database special for the account, and the user database is divided into three levels, the central processing unit stores cloud data into the user database according to a data classification algorithm, and the user can manually change the storage level of cloud data through the permission setting unit; The first level verification unit verifies the user identity by matching the input account password information with the account password information in the user information unit, If the matching is successful, the cloud server platform opens the first level database permission, and the user can call all data of the first level database; If the matching fails, the cloud server platform closes the first level database permission, and the user cannot call all data of the first level database.

8. The cloud data processing system based on the cloud server according to claim 3, characterized in that, The second level verification unit is security questionnaire verification, and when the content of the second level database is called, the second level verification unit button on the interactive module is selected to verify the user identity by matching the input security questionnaire content with the security questionnaire content in the user information unit, If the matching is successful, the cloud server platform opens the second level database permission, and the user can call all data of the second level database; If the matching fails, the cloud server platform closes the second level database permission, and the user cannot call all data of the second level database.

9. The cloud data processing system based on the cloud server according to claim 1, characterized in that, When the third level database is called for the first time, the virtual user image has not been established, and when the user clicks the third level verification unit button on the interactive module, the temporary verification unit is directly jumped to verify through matching of the biological identification information.

Citation Information

Patent Citations

  • Verification request method and device, computer equipment and storage medium

    CN110505198A

  • Online office public security defense processing method in big data scene and big data server

    CN114218034A