An enterprise financial comprehensive management system based on cloud computing

By introducing cloud-based permission management and storage management modules in the enterprise financial management system, the shortcomings of existing systems in access control and data storage are solved, and higher data security and storage efficiency are achieved.

CN119228567BActive Publication Date: 2025-06-27GUANGZHOU DINGHE SOFTWARE TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411283737.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-13
Publication Date
2025-06-27
Estimated Expiration
2044-09-13

AI Technical Summary

Technical Problem

The existing enterprise financial management system has flaws in access control and data storage, resulting in an increased risk of internal leaks and single point failures.

Method used

Design a comprehensive enterprise financial management system based on cloud computing, using permission management module and storage management module. The permission management module automatically classifies and assigns financial data to employees through machine learning and natural language processing technology, ensuring that each employee can only access data related to their responsibilities. The storage management module dynamically allocates data to the optimal storage node through sensitivity analysis and performance monitoring.

Benefits of technology

The principle of minimum permissions is implemented, reducing the risk of permission abuse and data leakage; through dynamic storage policies, the security and effectiveness of data storage are improved, and the risk of single point of failure is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119228567B_ABST
    Figure CN119228567B_ABST
Patent Text Reader

Abstract

The present invention discloses an enterprise financial comprehensive management system based on cloud computing, which relates to the technical field of enterprise financial management. The system includes a server, a permission management module, and a storage management module. Through machine learning classification algorithms and natural language processing technologies, financial data is automatically classified and relevant tags and keywords are generated. Association analysis is performed between the word segments and the responsibility tags and keywords of employees to determine the partial financial data corresponding to each employee. Different sensitivity values are set for the importance of sensitive words to calculate the sensitivity of the partial financial data assigned to each employee. By dynamically monitoring the performance information of storage nodes and combining the sensitivity of the partial financial data assigned to employees, the storage node with the best performance and the lowest risk is selected in real time to store data, ensuring efficient and reliable data storage. At the same time, by regularly updating the node performance information, it is ensured that each storage operation is based on the latest data and the distribution strategy is dynamically adjusted.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of enterprise financial management, and particularly to an integrated enterprise financial management system based on cloud computing. Background Art

[0002] Enterprise financial data is particularly important because it not only reflects the financial status of the enterprise, but also involves the core secrets and business strategies of the enterprise; an important goal of financial management is to protect this financial data and prevent data leakage or improper use; therefore, for enterprises, enterprise financial management is particularly important;

[0003] At present, in the management of many enterprise finances, the access control of financial data is not strict enough, resulting in unauthorized personnel being able to access, modify, or delete sensitive financial information, increasing the risk of internal leakage; in addition, some enterprises store all financial data centrally in a single server or database, increasing the risk of single point of failure and data leakage. If this storage location is attacked or misused by internal personnel, it will lead to the leakage or loss of all financial data, causing inestimable losses to the enterprise. Summary of the Invention

[0004] Based on this, in view of the problems mentioned in the above background art, it is necessary to provide an integrated enterprise financial management system based on cloud computing.

[0005] The object of the present invention can be achieved by the following technical solutions: An integrated enterprise financial management system based on cloud computing, comprising a server, a permission management module, and a storage management module;

[0006] The server stores enterprise financial data, performance information of each storage node, and historical risk information;

[0007] The permission management module decomposes and distributes the enterprise's financial data based on the scope of responsibilities of each employee, so that each employee can obtain a part of the financial data that is the same as their scope of responsibilities;

[0008] The storage management module distributes and stores the partial financial data of each employee into appropriate storage nodes respectively. The specific steps are as follows:

[0009] Step 1: Perform a sensitivity analysis on the partial financial data of each employee to obtain the sensitivity of the partial financial data of each employee,

[0010] Arrange the employees in order from largest to smallest according to the sensitivity of the partial financial data corresponding to each employee; select the employee with the largest sensitivity as the calibrated employee;

[0011] Step 2: Retrieve the performance information of each storage node at each collection moment, where the performance information includes storage margin, read / write speed, and throughput, and denote them as Cp, Vp, and Tp respectively; use the set formula to calculate the performance value CT of the storage node at each collection moment, where d1, d2, and d3 are respectively set proportionality coefficients, and η is the risk accumulation coefficient;

[0012] Step 3: Sort each storage node in descending order according to its corresponding performance value, and select the storage node with the largest performance value as the calibrated storage node, and send part of the financial data of the calibrated employee to the calibrated storage node for storage; after the storage operation is completed, re-obtain the performance information of the storage node and update it to Step 2;

[0013] Step 4: Repeat Step 1 to Step 3 until all the partial financial data of all employees are stored separately.

[0014] In some embodiments, the specific process of performing sensitivity analysis on the partial financial data of each employee is as follows:

[0015] Set that there are several sensitive words, and each sensitive word corresponds to a sensitivity value; identify the number of sensitive words existing in each word segment and the sensitivity values corresponding to each sensitive word; compare and analyze the sensitivity values with the set sensitivity interval to classify the sensitive words corresponding to the sensitivity values into highly sensitive words, moderately sensitive words, and lowly sensitive words, and respectively count the cumulative quantities of highly sensitive words, moderately sensitive words, and lowly sensitive words existing in the word segment, and denote them as L1, L2, and L3 respectively; perform summation calculations on the sensitivity values corresponding to the highly sensitive words, moderately sensitive words, and lowly sensitive words to obtain the highly sensitive value, moderately sensitive value, and lowly sensitive value, and denote them as L4, L5, and L6 respectively;

[0016] Substitute L1, L2, L3, L4, L5, and L6 into the set formula

[0017]

[0018] to calculate the word segment sensitivity value Lb, where are respectively set proportionality coefficients, and b1 > b2 > b3 > 1; perform summation calculations on the word segment sensitivity values of each word segment in the partial financial data corresponding to the employee to obtain the sensitivity of the partial financial data, and thus obtain the sensitivity of the partial financial data corresponding to each employee.

[0019] In some embodiments, the solution process of the risk accumulation coefficient is as follows:

[0020] Retrieve the risk information of each storage node, where the risk information includes historical hardware failure information and historical security events; the historical hardware failure information includes the number of hardware failures and the duration corresponding to each failure; the historical security events include the number of successful interceptions and the number of failed interceptions, and record them as S1 and S2;

[0021] Compare and analyze the failure duration with the set duration interval. When the failure duration is greater than the maximum value in the set duration interval, accumulate one severe failure; when the failure duration is within the set duration interval, accumulate one moderate failure; when the failure duration is less than the minimum value in the set duration interval, accumulate one minor failure; separately count the cumulative number of severe failures, moderate failures, and minor failures, and record them as Z1, Z2, and Z3 respectively; calculate the average value of the failure duration corresponding to each failure to obtain the average failure duration denoted as Z4;

[0022] Substitute the number of successful interceptions S1, the number of failed interceptions S2, the cumulative number of severe failures Z1, the cumulative number of moderate failures Z2, the cumulative number of minor failures Z3, and the average failure duration Z4 into the set formula

[0023] Perform the calculation to obtain the risk coefficient η, where f1, f2, f3, f4 are respectively the set proportionality coefficients, and f1 > f2 > f3 > 0.

[0024] In some embodiments, the specific process of decomposing and distributing the enterprise's financial data based on the scope of responsibilities of each employee is as follows:

[0025] 401: According to the responsibilities of employees in different positions within the enterprise, set a number of tags corresponding to each employee's responsibilities. Each tag corresponds to a number of keywords respectively, and thus the tags of each employee and the keywords corresponding to each tag can be obtained;

[0026] 402: Use the classification algorithm in machine learning to perform a preliminary classification of the financial data, and thus the financial data can be decomposed into several segments; use advanced natural language processing technologies such as word embedding or BERT to perform semantic understanding on the content of each segment to generate several tags related to its semantics and a number of keywords corresponding to each tag; thus, several tags and the keywords corresponding to the tags can be used to accurately locate the segments;

[0027] 403: Conduct a correlation analysis between each word segment and each employee to obtain the correlation value between the word segment and the employee. Set a correlation threshold for each employee respectively. Compare and analyze the correlation value of the word segment with the correlation threshold of the employee. When the correlation value is greater than or equal to the set threshold, assign the word segment to the employee. Thus, each word segment can be assigned to each employee respectively. After each employee logs in successfully through the corresponding identity verification, they can view the corresponding part of the financial data.

[0028] In some embodiments, the specific process of conducting a correlation analysis between each word segment and each employee is as follows:

[0029] 501: Compare the label of the word segment with the label of the employee. If the labels of the word segment are all the same as the label of the employee, record the employee as the full-coverage word segment of the word segment, and record the same label as the full-coverage label; when there is partial overlap between the label of the word segment and the label of the employee, and record the overlapping label as the semi-coverage label, then record the word segment as the semi-coverage word segment of the employee; respectively extract the keywords under the full-coverage word segment and the full-coverage label corresponding to the employee, and compare the keywords of the two one by one to obtain the number of intersection keywords and the number of union keywords under each full-coverage label;

[0030] 502: Similarly, respectively extract the keywords under the semi-coverage word segment and the semi-coverage label corresponding to the employee, and compare the keywords of the two one by one to obtain the number of intersection keywords and the number of union keywords under each semi-coverage label, and record them as M1j and M2j respectively; where j = 1, 2, 3... J, J takes a positive integer, J represents the total number of semi-coverage labels in the semi-coverage word segment, i represents the serial number of any one semi-coverage label, and record them as N1i and N2i respectively; where i = 1, 2, 3... I, I takes a positive integer, I represents the total number of full-coverage labels in the word segment, and i represents the serial number of any one full-coverage label;

[0031] 503: Use the TF-IDF information retrieval technology to identify the important score of each intersection keyword of each full-coverage label in the full-coverage word segment in the full-coverage word segment, and record it as Fiq; where q = 1, 2, 3... Q, Q takes a positive integer, Q represents the number of intersection keywords under a certain full-coverage label, and q represents the serial number of any one intersection keyword under a certain full-coverage label; Compare and analyze the important scores corresponding to each intersection keyword with the set score interval to classify the keywords corresponding to the important scores into high-level keywords, medium-level keywords and low-level keywords, respectively count the number of high-level keywords, medium-level keywords and low-level keywords, and perform formulaic calculation and analysis to obtain the key coefficient of each full-coverage label in the full-coverage word segment, denoted as βi;

[0032] 504: Similarly, use the TF-IDF information retrieval technology to identify the importance scores of the intersection keywords of each semi-covered label in the semi-covered word segment within the semi-covered word segment, and denote it as Fjk; k == 1, 2, 3... K, where K represents the number of intersection keywords under a certain semi-covered label, and k represents the serial number of any one of the intersection keywords under a certain semi-covered label; compare and analyze the importance scores corresponding to the intersection keywords of each semi-covered label to obtain the key coefficient of each semi-covered label in the semi-covered word segment, denoted as βj;

[0033] 505: Substitute the importance scores (Fiq or Fjk), the number of intersection keywords (N1i or M1j), the number of union keywords (N2i or M2j), and the key coefficients (βi or βj) of each keyword into the set formula group

[0034] Perform calculations to obtain the association value GF between each word segment and the employee, where g1, g2, g3, g4 are respectively set proportionality coefficients; αi, αj are respectively the constant coefficients of the fully covered word segment and the semi-covered word segment, and αi > αj > 1.

[0035] Compared with the prior art, the beneficial effects of the present invention are:

[0036] 1. Through the machine learning classification algorithm and natural language processing technology, automatically classify financial data and generate relevant labels and keywords; perform association analysis between the word segment and the employee's responsibility labels and keywords to determine the partial financial data corresponding to each employee, ensuring that employees can only access data highly relevant to their work content, greatly reducing the risks of unauthorized access and data leakage; realizing the principle of least privilege, the automation and high efficiency of permission management;

[0037] 2. Set different sensitivity values for the importance of sensitive words, and calculate the sensitivity of the partial financial data assigned to each employee through formulas; classify the data according to the sensitivity to ensure that high-sensitivity data is properly stored on nodes with optimal performance, rather than treating all data equally, improving the security and effectiveness of data storage; by dynamically monitoring the performance parameters of the storage nodes (such as storage margin, read and write speed, throughput), and combining the calculation of the risk coefficient, it is possible to select the storage node with the best performance and the lowest risk to store data in real time, ensuring the efficient and reliable storage of data; at the same time, by regularly updating the node performance information, ensuring that each storage operation is based on the latest data and dynamically adjusting the distribution strategy. Brief Description of the Drawings

[0038] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0039] Figure 1 It is a principle block diagram of the present invention. Detailed implementation manners

[0040] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will provide a detailed description of the specific implementation manners of the present invention in conjunction with the accompanying drawings. Many specific details are set forth in the following description to facilitate a full understanding of the present invention. However, the present invention can be implemented in many other ways different from those described herein. Those skilled in the art can make similar improvements without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0041] As Figure 1 shown, an enterprise financial comprehensive management system based on cloud computing includes: a server, an authorization management module, and a storage management module;

[0042] The present invention takes large enterprises as specific application scenarios. For large enterprises, due to their numerous departments and a large number of employees, especially the huge amount of data involved in the financial department, a single storage node usually has difficulty in bearing such a large amount of data and there are also risks of failures. It is assumed that there are several financial employees within the large enterprise, and multiple storage nodes are set up to reduce the memory limitations and failure risks of a single storage node, etc.;

[0043] The server stores enterprise financial data, performance information of each storage node, and historical risk information;

[0044] The permission management module authorizes the enterprise's financial data based on the job natures of each employee in the enterprise to ensure that each employee can only access the financial data related to their responsibilities, implementing the principle of least privilege and avoiding the risk of data leakage caused by over-allocation of permissions; specifically:

[0045] According to the responsibilities of employees in different positions within the enterprise, several tags corresponding to their responsibilities are set for each employee, and each tag corresponds to several keywords respectively; for example, the financial supervisor may be responsible for "budget management" and "financial planning", while accounting personnel may be related to "daily transactions" and "bookkeeping processing"; each tag can be further refined into multiple keywords, and these keywords can cover a more specific business scope. For example, the "budget management" tag may correspond to keywords such as "annual budget", "department budget", "expenditure control", etc.;

[0046] The financial supervisor is associated with the "Budget Management" label, while the accounting staff is associated with the "Daily Transactions" label; thus, the label for each employee and the keywords corresponding to each label can be obtained.

[0047] Use classification algorithms in machine learning (such as decision trees, random forests, SVM, etc.) to initially classify financial data; for example, financial data can be classified into different segments according to features such as transaction type, subject category, and amount size (before classification, feature extraction and preprocessing of financial data are required, such as numerical normalization, category encoding, etc., to improve the performance and accuracy of the classification algorithm); after classification, the financial data is decomposed into several "segments", and each segment represents a specific classification, such as "income", "expenditure", "assets and liabilities", etc.; use advanced natural language processing (NLP) technologies such as Word Embedding or BERT to perform a deeper semantic understanding of the content of each segment. These technologies can identify the key meanings and themes in the segment by learning the data context and word relationships; by analyzing the content of each segment, labels semantically related to it can be automatically generated to mark the main financial category or theme of the segment; based on semantic analysis, the keywords that best represent the content of the segment are extracted. Technologies such as BERT can understand the precise meaning of words according to the context, so the extracted keywords are usually closely related to the semantics of the segment; each segment will be assigned multiple labels, and each label corresponds to several keywords. These labels and keywords can be further used for permission control and refined management; thus, each segment can obtain the corresponding several labels and the keywords corresponding to each label.

[0048] Compare the labels of the word segments with the labels of the employees. If all the labels of the word segments are the same as the labels of the employees, specifically: the labels of the word segments are the same as the labels of the employees or the labels of the employees can cover the labels of the word segments; then mark this employee as the full-coverage word segment of this word segment, and mark the same label as the full-coverage label; when there is partial overlap between the labels of the word segment and the labels of the employee, and mark the overlapping labels as semi-coverage labels, then mark this word segment as the semi-coverage word segment of this employee; separately extract the keywords under the full-coverage word segment and the corresponding full-coverage labels of the employee, and compare the keywords of the two one by one to obtain the number of intersection keywords and the number of union keywords under each full-coverage label, and record them as N1i and N2i respectively; where i = 1, 2, 3... I, I takes positive integers, I represents the total number of full-coverage labels in the word segment, and i represents the serial number of any one full-coverage label; it should be noted that, for example, there is a full-coverage label A, the keywords corresponding to the full-coverage label A in the word segment are: A1, A5, A8, A9; the keywords corresponding to the full-coverage label A in the employee are A2, A3, A5, A8, A9; then the intersection keywords of the full-coverage label A are: A5, A8, A9; the union keywords are: A1, A2, A3, A5, A8, A9;

[0049] Separate extract the keywords under the semi-coverage word segment and the corresponding semi-coverage labels of the employee, and compare the keywords of the two one by one to obtain the number of intersection keywords and the number of union keywords under each semi-coverage label, and record them as M1j and M2j respectively; where j = 1, 2, 3... J, J takes positive integers, J represents the total number of semi-coverage labels in the semi-coverage word segment, and i represents the serial number of any one semi-coverage label;

[0050] Use the TF-IDF (term frequency - inverse document frequency) information retrieval technology to identify the important scores of the intersection keywords of each full-coverage label in the full-coverage word segment in this full-coverage word segment, and record them as Fiq; where q = 1, 2, 3... Q, Q takes positive integers, Q represents the number of intersection keywords under a certain full-coverage label, and q represents the serial number of any one intersection keyword under a certain full-coverage label; Compare and analyze the important scores corresponding to each intersection keyword with the set score range. When the important score of the intersection keyword is greater than the maximum value in the set score range, then mark this intersection keyword as a high-level keyword; when the important score of the intersection keyword is within the set score range, then mark this intersection keyword as a medium-level keyword; when the important score of the intersection keyword is less than the minimum value in the set score range, then mark this intersection keyword as a low-level keyword; separately count the number of high-level keywords, medium-level keywords and low-level keywords, and record them as D1, D2, D3 respectively; Use the set formula

[0051]

[0052] Calculations are performed to obtain the key coefficients, where a1, a2, and a3 are respectively set proportionality coefficients, and a1 > a2 > a3 > 0; thus, the key coefficients of each full-coverage label are denoted as βi;

[0053] Similarly, using the TF-IDF (term frequency-inverse document frequency) information retrieval technique, identify the important scores of the intersection keywords of each semi-coverage label in the semi-coverage word segment within the semi-coverage word segment, and denote them as Fjk; k = 1, 2, 3... K, where K represents the number of intersection keywords under a certain semi-coverage label, and k represents the serial number of any one of the intersection keywords under a certain semi-coverage label;

[0054] Similarly, compare and analyze the important scores corresponding to the intersection keywords of each semi-coverage label to obtain the key coefficients of each semi-coverage label, denoted as βj;

[0055] Using the set formula group

[0056]

[0057] Perform calculations to obtain the association value GF between each word segment and the employee, where g1, g2, g3, and g4 are respectively set proportionality coefficients; αi and αj are respectively the constant coefficients of the full-coverage word segment and the semi-coverage word segment, and αi > αj > 1; set that each employee corresponds to an association threshold, compare and analyze the association value of the word segment with the employee's association threshold. When the association value is greater than or equal to the set threshold, then allocate the word segment to the employee. Thus, each word segment can be allocated to each employee respectively. It can be obtained that each employee can be allocated the corresponding part of the financial data according to their job responsibilities; each employee can view the corresponding part of the financial data after successfully logging in through the corresponding identity verification;

[0058] Through machine learning classification algorithms and natural language processing techniques, automatically classify the financial data and generate relevant labels and keywords; perform association analysis between the word segments and the employee's responsibility labels and keywords to determine the corresponding part of the financial data for each employee, ensuring that employees can only access data highly relevant to their work content, greatly reducing the risks of privilege abuse and data leakage; realizing the principle of least privilege, automation, and high efficiency of privilege management.

[0059] The storage management module performs distributed storage based on the parts of the financial data allocated to each employee to reduce the risks caused by single-node storage failures and achieve the safe and efficient storage of financial data; specifically:

[0060] Step 1: Obtain the partial financial data assigned to each employee (the partial financial data consists of several segments). Suppose there are several sensitive words (it should be noted that the sensitive words are set by those skilled in the art according to the needs of the enterprise. For example, account balance, accounts payable, shareholder list and the income details of each shareholder, customer list and the payment details corresponding to each customer, etc.); each sensitive word corresponds to a sensitivity value respectively. The higher the sensitivity value, the more important the sensitive word is for the enterprise; identify the number of sensitive words existing in each segment and the sensitivity values corresponding to each sensitive word; compare and analyze the sensitivity values with the set sensitivity range. When the sensitivity value is greater than the maximum value in the set sensitivity range, accumulate a highly sensitive word once; when the sensitivity value is within the set sensitivity range, accumulate a moderately sensitive word once; when the sensitivity value is less than the minimum value in the set sensitivity range, accumulate a lowly sensitive word once; respectively count the cumulative quantities of highly sensitive words, moderately sensitive words and lowly sensitive words existing in the segment, and record them as L1, L2 and L3 respectively; sum up the sensitivity values corresponding to the highly sensitive words, moderately sensitive words and lowly sensitive words to obtain the highly sensitive value, moderately sensitive value and lowly sensitive value, and record them as L4, L5 and L6 respectively; use the set formula

[0061]

[0062] to calculate the segment sensitivity value Lb, where are respectively the set proportionality coefficients, and b1 > b2 > b3 > 1; sum up the segment sensitivity values of each segment in the partial financial data corresponding to the employee to obtain the sensitivity of the partial financial data; thus, the sensitivities of the partial financial data corresponding to each employee can be obtained; sort the employees in order from the largest to the smallest according to the sensitivities of the partial financial data corresponding to each employee; select the employee with the largest sensitivity as the calibrated employee;

[0063] Step 2: Retrieve the performance information of each storage node at each collection moment. The performance information includes storage margin, read / write speed (I / O speed, a higher I / O speed means that the node can process data requests more quickly, thereby reducing the data access latency time) and throughput (the higher the throughput, the larger the scale of data traffic the node can handle, suitable for high-load application scenarios), and record them as Cp, Vp and Tp respectively; use the set formula

[0064] to calculate the performance value CT of the storage node at each collection moment, where d1, d2, d3 are respectively the set proportionality coefficients, and η is the risk accumulation coefficient;

[0065] The solving process of the risk accumulation coefficient is as follows:

[0066] Retrieve the risk information of each storage node, where the risk information includes historical hardware failure information and historical security events; the historical hardware failure information includes the number of hardware failures (hardware usually refers to hard disks, memory, CPUs, etc., and nodes with frequent hardware failures usually have poor stability and higher risks) and the duration corresponding to each failure; the historical security events include the number of successful interceptions (a successful interception usually means that an intrusion detection system alarm has been triggered and successfully intercepted) and the number of failed interceptions, and record them as S1 and S2 respectively;

[0067] Compare and analyze the failure duration with the set duration interval. When the failure duration is greater than the maximum value in the set duration interval, accumulate one severe failure; when the failure duration is within the set duration interval, accumulate one moderate failure; when the failure duration is less than the minimum value in the set duration interval, accumulate one minor failure; separately count the cumulative number of severe failures, moderate failures, and minor failures, and record them as Z1, Z2, and Z3 respectively; calculate the average failure duration for each failure and record it as Z4; use the set formula

[0068]

[0069] Perform the calculation to obtain the risk coefficient η, where f1, f2, f3, f4 are respectively set proportionality coefficients, and f1 > f2 > f3 > 0;

[0070] Step 3: Sort the storage nodes in descending order according to their corresponding performance values, and select the storage node with the largest performance value as the calibration storage node. Send part of the financial data of the calibrated employee to the calibration storage node for storage; after the storage operation is completed, re-obtain the performance information of the storage node and update it to Step 2;

[0071] Step 4: Repeat Steps 1 to 3 until all parts of the financial data of all employees are stored separately;

[0072] By setting different sensitivity values for the importance of sensitive words and calculating the sensitivity of the part of the financial data assigned to each employee through a formula; perform hierarchical processing on the data according to the sensitivity to ensure that high-sensitivity data is properly stored on the nodes with the best performance, rather than treating all data equally, which improves the security and effectiveness of data storage; by dynamically monitoring the performance parameters of the storage nodes (such as storage margin, read / write speed, throughput) and combining the calculation of the risk coefficient, it is possible to select the storage node with the best performance and the lowest risk to store data in real time to ensure the efficient and reliable storage of data; at the same time, by regularly updating the node performance information, ensure that each storage operation is based on the latest data and dynamically adjust the distribution strategy.

[0073] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the various technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as falling within the scope described in this specification.

[0074] The above-described embodiments merely represent several implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the present invention patent shall be subject to the appended claims.

Claims

1. A cloud computing-based enterprise financial integrated management system, including a rights management module and a storage management module; characterized in that: The authority management module breaks down and distributes the company's financial data based on the responsibilities of each employee, so that each employee gets the same part of the financial data as his or her responsibilities; The storage management module allocates some of the financial data of each employee to store them in the corresponding storage nodes. The specific steps are as follows: Step 1: Conduct sensitivity analysis on some of the financial data of each employee to obtain the sensitivity of some of the financial data of each employee; sort the employees in descending order according to the sensitivity of the corresponding part of the financial data of each employee; select the employee with the highest sensitivity as the calibration employee; Step 2: retrieve the performance information of each storage node at each collection time, where the performance information includes storage margin, read / write speed, and throughput, and record them as Cp, Vp, and Tp respectively; use the set formula The performance value CT of the storage node at each collection time is calculated, where d1, d2, and d3 are the set proportional coefficients, and η is the risk accumulation coefficient; Step 3: Sort the storage nodes in descending order according to their corresponding performance values, select the storage node with the largest performance value as the calibration storage node, and send part of the financial data of the calibration employee to the calibration storage node for storage; After the storage operation is completed, the performance information of the storage node is re-obtained and updated to step 2; The solution process of the risk accumulation coefficient is: Retrieve risk information of each storage node, including historical hardware failure information and historical security events; Historical hardware failure information includes the number of hardware failures and the duration of each failure; historical security events include the number of successful interceptions and the number of failed interceptions, which are recorded as S1 and S2; Compare and analyze the fault duration with the set duration interval. When the fault duration is greater than the maximum value in the set duration interval, a severe fault is accumulated; when the fault duration is within the set duration interval, a moderate fault is accumulated; when the fault duration is less than the minimum value in the set duration interval, a low fault is accumulated; the accumulated times of severe faults, moderate faults and low faults are counted respectively and recorded as Z1, Z2 and Z3 respectively; The fault duration corresponding to each fault is averaged and the average fault duration is recorded as Z4; Substitute the number of successful interception S1, the number of failed interception S2, the cumulative number of severe faults Z1, the cumulative number of moderate faults Z2, the cumulative number of minor faults Z3 and the average fault length Z4 into the set formula The risk coefficient η is calculated, where f1, f2, f3, and f4 are respectively the set proportional coefficients; The specific process of breaking down and allocating the company's financial data based on the responsibilities of each employee is as follows: 401: According to the responsibilities of employees in different positions within the enterprise, set several tags related to each employee's responsibilities, and each tag corresponds to several keywords, thereby obtaining the tags of each employee and the keywords corresponding to each tag; 402: Use the classification algorithm in machine learning to preliminarily classify the financial data, thereby breaking down the financial data into several word segments; use word embedding or BERT advanced natural language processing technology to understand the semantics of each word segment to generate several labels related to its semantics and each label corresponds to several keywords; thereby, the word segment can be accurately located using several labels and the keywords corresponding to the labels; 403: Perform correlation analysis between each word segment and each employee to obtain the correlation value between each word segment and the employee, set a correlation threshold corresponding to each employee, compare and analyze the correlation value of the word segment with the correlation threshold of the employee, and when the correlation value is greater than or equal to the set threshold, the word segment is assigned to the employee. In this way, each word segment can be assigned to each employee. Each employee can view the corresponding part of the financial data after successfully logging in through the corresponding identity authentication.

2. The cloud computing-based enterprise financial integrated management system according to claim 1, characterized in that: The specific process of conducting sensitivity analysis on some of the financial data of each employee is as follows: It is assumed that there are several sensitive words, each of which corresponds to a sensitivity value; the number of sensitive words in each word segment and the sensitivity value corresponding to each sensitive word are identified; the sensitivity value is compared and analyzed with the set sensitivity interval to divide the sensitive words corresponding to the sensitivity value into highly sensitive words, moderately sensitive words and low sensitive words, and the cumulative number of highly sensitive words, moderately sensitive words and low sensitive words in the word segment is counted respectively, and the sensitivity values ​​corresponding to the highly sensitive words, moderately sensitive words and low sensitive words are summed up to obtain the highly sensitive value, moderately sensitive value and low sensitive value respectively; The cumulative number of highly sensitive words, the cumulative number of moderately sensitive words, the cumulative number of lowly sensitive words, the highly sensitive value, the moderately sensitive value and the lowly sensitive value are calculated and analyzed in a formula to obtain the segment sensitivity value; The sensitivity of the partial financial data is obtained by summing up the segment sensitivity values ​​of each segment in the partial financial data corresponding to the employee, thereby obtaining the sensitivity of the partial financial data corresponding to each employee.

3. The cloud computing-based enterprise financial integrated management system according to claim 1, characterized in that: The specific process of analyzing the correlation between each word segment and each employee is as follows: 501: Compare the label of the segment with the label of the employee. If the labels of the segment are the same as the label of the employee, the employee is recorded as a fully covered segment of the segment, and the same label is recorded as a fully covered label. When the label of the segment partially overlaps with the label of the employee, the overlapping label is recorded as a semi-covered label, and the segment is recorded as a semi-covered segment of the employee. Extract the keywords under the fully covered word segments and the fully covered labels of employees respectively, and compare the keywords of the two one by one to obtain the number of intersection keywords and the number of union keywords under each fully covered label; 502: Similarly, extract the keywords under the semi-covered word segments and the employee's corresponding semi-covered labels respectively, and compare the keywords of the two one by one to obtain the number of intersection keywords and the number of union keywords under each semi-covered label; 503: using TF-IDF information retrieval technology to identify the importance scores of the intersection keywords of all the fully covered labels in the fully covered segment; comparing and analyzing the importance scores corresponding to the intersection keywords with the set score range to classify the keywords corresponding to the importance scores into high-level keywords, medium-level keywords and low-level keywords, respectively counting the number of high-level keywords, medium-level keywords and low-level keywords, and performing formulaic calculation and analysis to obtain the key coefficient of all the fully covered labels in the fully covered segment; 504: Similarly, using TF-IDF information retrieval technology to identify the importance scores of the intersection keywords of each half-covering tag in the half-covering segment; comparing and analyzing the importance scores corresponding to each intersection keyword of each half-covering tag to obtain the key coefficient of each half-covering tag in the half-covering segment; 505: The importance score of each keyword, the number of intersection keywords, the number of union keywords, and the key coefficient are normalized and their values ​​are obtained, and the correlation value between each word segment and the employee is obtained by numerical analysis.

Citation Information

Patent Citations

  • Data processing method and device, computer equipment and storage medium

    CN116069952A

  • Secure storage management method and system for data

    CN116611116A