Fuel data sharing system and method
By setting user roles, access control, data encryption and de-identification, and combining user permissions with risk assessment and behavior monitoring, the security issues in fuel data sharing have been resolved, and secure and controllable data sharing has been achieved.
Patent Information
- Application Number
- CN202411008441.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-26
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-07-26
AI Technical Summary
In the process of fuel data sharing, there are problems such as different data permissions, data leakage and abuse, resulting in insufficient data sharing security.
By setting user roles and assigning corresponding fuel data access permissions, multi-level access control is implemented. Fuel data is encrypted and de-identified. The risk value of sharing is determined by weighting the data in combination with user permissions. User behavior is monitored for real-time early warning and anomaly control.
It effectively ensures the secure sharing of fuel data, prevents data leakage and misuse, meets user needs, and improves the security and controllability of data sharing.
Smart Images

Figure CN119249466B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data sharing technology, and in particular to a fuel data sharing system and method. Background Technology
[0002] For in-depth research in the fuel field, researchers can share their fuel analysis data to facilitate the sharing of analytical results across various processes in the fuel field, broaden and stimulate analytical directions and methods, and ultimately achieve efficient flow and integration of analytical results at each stage within the fuel field. However, during the fuel data sharing process, fuel data involves different data permissions at various levels, and there are issues such as data leakage and data misuse, posing security risks to data sharing.
[0003] Therefore, the present invention provides a fuel data sharing system and method. Summary of the Invention
[0004] This invention provides a fuel data sharing system and method, which determines the data sensitivity of fuel data and implements multi-level access control by setting user roles and assigning corresponding fuel data access permissions; performs data encryption and data anonymization processing on the fuel data; weights the data sensitivity of the fuel data in combination with user permissions to determine the user data access sharing risk value; when the user data access sharing risk value is not higher than the preset risk value for the corresponding user data access sharing, the fuel data sharing method is matched according to the user role and fuel data is shared; monitors and analyzes user access behavior and fuel data sharing behavior to provide real-time early warning and execute corresponding preset anomaly control strategies; effectively ensuring the secure sharing of fuel data.
[0005] This invention provides a fuel data sharing system, comprising:
[0006] The access control module is used to set user roles and assign corresponding fuel data access permissions. At the same time, it determines the data sensitivity of fuel data and implements multi-level access control.
[0007] The data encryption module is used to encrypt the data transmission and data storage of fuel data. When the data sensitivity of the fuel data is not lower than the preset desensitization level, data desensitization processing is performed.
[0008] The data sharing module is used to weight the data sensitivity of the fuel data in combination with user permissions to determine the risk value of user data access sharing. When the risk value of user data access sharing is not higher than the preset risk value of the corresponding user data access sharing, the fuel data sharing method is matched according to the user role and the fuel data is shared.
[0009] The monitoring and early warning module is used to monitor and analyze user access behavior and fuel data sharing behavior. When abnormal access and sharing behavior is detected, it generates early warning data, issues real-time warnings, and executes corresponding preset abnormal control strategies.
[0010] According to the present invention, a fuel data sharing system includes an access control module comprising:
[0011] The user role permission unit is used to set different user roles according to user responsibilities and user needs, and to assign corresponding fuel data access permissions to various user roles.
[0012] When a user accesses fuel data, user information is obtained to match user roles. If the match is successful, the corresponding fuel data access permissions are enabled.
[0013] Otherwise, prompt the user to update their user information and re-match the user role;
[0014] The fuel data access control unit is used to implement multi-level access control for fuel data based on data sensitivity and access management strategies.
[0015] The authorization control unit is used to create administrator accounts and assign the highest privileges. It allows administrators to periodically audit and update access permissions for other users and fuel data according to the permission management policy, and to dynamically adjust access permissions for other users and fuel data based on fuel data access needs.
[0016] According to the present invention, a fuel data sharing system includes a fuel data access control unit comprising:
[0017] Data sensitivity block is used to identify fuel data containing data sensitivity and mark it as sensitive fuel data;
[0018] Identify the data types of sensitive fuel data and set corresponding sensitivity levels based on the data types;
[0019] The data sensitivity of the fuel data is determined based on the sensitivity level and the proportion of the corresponding sensitive fuel data in the total fuel data.
[0020] The access control policy block is used to preset access control policies for fuel data with different data sensitivities, as well as user access control policies.
[0021] When data exceeding the sensitivity level of the allowed fuel data is detected, the data will be masked accordingly.
[0022] According to the present invention, a fuel data sharing system includes a data encryption module comprising:
[0023] The data transmission encryption unit is used to connect the fuel data storage terminal and the user access terminal according to a preset data transmission protocol and perform end-to-end encrypted connection.
[0024] The data storage encryption unit is used to call an encryption algorithm of appropriate strength to encrypt the fuel data according to its data sensitivity.
[0025] The data desensitization processing unit is used to obtain the data sensitivity of fuel data containing sensitive fuel data when shared access to sensitive fuel data is detected.
[0026] When the data sensitivity of the fuel data is not lower than the preset desensitization level, a preset data desensitization strategy is invoked according to the data sensitivity and user role. The preset data desensitization strategy includes: data replacement desensitization strategy, data hash desensitization strategy, and data differential privacy desensitization strategy.
[0027] According to the present invention, a fuel data sharing system includes a data sharing module comprising:
[0028] The sensitive data association unit is used to preprocess fuel data and remove invalid data.
[0029] Extract sensitive fuel data from the fuel data, determine the impact value of the sensitive fuel data on the fuel data based on the frequency and weight of the occurrence of the sensitive fuel data, and sort them in descending order of data sensitivity;
[0030] Select key sensitive data according to the order, obtain the data correlation degree between key sensitive data, and establish the correlation relationship between key sensitive data when the data correlation degree between key sensitive data is not higher than the correlation threshold.
[0031] Construct a key sensitive data association structure based on the key sensitive data and the relationships between the key sensitive data;
[0032] A sensitive data processing unit is used to perform an encryption process on the key sensitive data according to the data encryption process.
[0033] The key and sensitive data are then subjected to secondary weighting based on user permissions.
[0034] Based on historical fuel data, a standard association structure for key sensitive data is determined, and the association structure for key sensitive data is subjected to three structural processing steps.
[0035] The fuel data adaptive association unit is used to obtain new sensitive data of the new fuel data when it detects that a user accesses new fuel data, and adaptively associate the fuel data and the new fuel data with the key sensitive data association structure completed by the three-stage structure processing.
[0036] The fuel data association complexity unit is used to determine the data association complexity of the current fuel data by combining the time period from data preprocessing to the completion of adaptive fuel data association, and the average fuel data association time period determined by historical fuel data.
[0037] Access sharing risk unit, used to determine the risk value of user data access sharing;
[0038] ;
[0039] Where F represents the risk value of user data access sharing; x1 represents the number of sensitive fuel data points accurately identified in historical fuel data; and x2 represents the number of sensitive fuel data points not identified in historical fuel data. This indicates that when the i1th fuel data accessed by the user is the key sensitive data, the data sensitivity of the i1th fuel data is output. Otherwise, output 0; This represents the data association time period for the fuel data accessed by the j1th user; This indicates the time period associated with the average fuel data determined from historical fuel data. This represents the user permission level of the j1th user; n1 represents the number of critical and sensitive data in the fuel data; m1 represents the number of users accessing the fuel data.
[0040] When the risk value of user data access sharing is not higher than the preset risk value of the corresponding user accessing shared data, the fuel data sharing method is matched according to the user role and fuel data sharing is carried out.
[0041] Otherwise, mark the corresponding fuel data as risky data and the corresponding user as a risky user.
[0042] According to the present invention, a fuel data sharing system includes a monitoring and early warning module, comprising:
[0043] The fuel data monitoring unit is used to monitor and analyze user access behavior and fuel data sharing behavior. When abnormal access and sharing behavior is detected, it will mark the abnormal behavior as follows: high frequency access, high frequency download and unauthorized access.
[0044] The fuel data early warning unit is used to generate early warning data based on the anomaly marker and the risk marker, provide real-time early warning, and execute corresponding preset anomaly control strategies.
[0045] A fuel data sharing system according to the present invention further includes:
[0046] The data sharing method module is used to match the fuel data sharing method according to user needs and user roles. The fuel data sharing methods include: sharing among all users, logical sharing, and web page sharing.
[0047] The fuel data tag module is used to embed fuel data tags into shared fuel data;
[0048] The access sharing time limit module is used to set a time window for fuel data sharing. When a user's access time exceeds the time window, the user's access is revoked.
[0049] This invention provides a fuel data sharing method, comprising:
[0050] Step 1: Set up user roles and assign corresponding fuel data access permissions. At the same time, determine the data sensitivity of fuel data and implement multi-level access control.
[0051] Step 2: Encrypt the fuel data for both data transmission and data storage. When the data sensitivity of the fuel data is not lower than the preset desensitization level, perform data desensitization processing.
[0052] Step 3: The data sensitivity of the access to shared data is weighted in combination with user permissions to determine the risk value of user data access sharing. When the risk value of user data access sharing is not higher than the preset risk value of the corresponding user accessing shared data, the fuel data sharing method is matched according to the user role and fuel data sharing is performed.
[0053] Step 4: Monitor and analyze user access behavior and fuel data sharing behavior. When abnormal access and sharing behavior is detected, generate early warning data for real-time warning and execute corresponding preset abnormal control strategies.
[0054] Compared with the prior art, the beneficial effects of this application are as follows:
[0055] By setting user roles and assigning corresponding fuel data access permissions, the data sensitivity of fuel data is determined and multi-level access control is implemented; fuel data is encrypted and anonymized; the data sensitivity of the fuel data is weighted in conjunction with user permissions to determine the risk value of user data access sharing; when the risk value of user data access sharing is not higher than the preset risk value for the corresponding user data access sharing, the fuel data sharing method is matched according to the user role and fuel data is shared; user access behavior and fuel data sharing behavior are monitored and analyzed to provide real-time early warnings and execute corresponding preset anomaly control strategies; thus effectively ensuring the secure sharing of fuel data.
[0056] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description and the accompanying drawings.
[0057] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0058] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0059] Figure 1 This is a schematic diagram of the structure of a fuel data sharing system provided in an embodiment of the present invention;
[0060] Figure 2 This is a flowchart illustrating a fuel data sharing method provided in an embodiment of the present invention. Detailed Implementation
[0061] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0062] like Figure 1 As shown, an embodiment of the present invention provides a fuel data sharing system, which mainly includes the following structure:
[0063] The access control module is used to set user roles and assign corresponding fuel data access permissions. At the same time, it determines the data sensitivity of fuel data and implements multi-level access control.
[0064] The data encryption module is used to encrypt the data transmission and data storage of fuel data. When the data sensitivity of the fuel data is not lower than the preset desensitization level, data desensitization processing is performed.
[0065] The data sharing module is used to weight the data sensitivity of the fuel data in combination with user permissions to determine the risk value of user data access sharing. When the risk value of user data access sharing is not higher than the preset risk value of the corresponding user data access sharing, the fuel data sharing method is matched according to the user role and the fuel data is shared.
[0066] The monitoring and early warning module is used to monitor and analyze user access behavior and fuel data sharing behavior. When abnormal access and sharing behavior is detected, it generates early warning data, issues real-time warnings, and executes corresponding preset abnormal control strategies.
[0067] In this embodiment, user roles are defined, such as administrator, operator, and engineer.
[0068] In this embodiment, user roles are set and corresponding fuel data access permissions are assigned. For example, three levels of fuel data access permissions are preset. Level 1 fuel data access permissions only allow access to a portion of fuel data at the same level; Level 2 fuel data access permissions allow access to Level 1 fuel data and a portion of fuel data at the same level; and Level 3 fuel data access permissions allow access to all fuel data.
[0069] In this embodiment, the data sensitivity of fuel data refers to the degree of data privacy of fuel data.
[0070] In this embodiment, the data sensitivity of fuel data is determined and multi-level access control is implemented, such as read-only, edit, and share access control.
[0071] In this embodiment, the preset desensitization level refers to the data sensitivity threshold for data desensitization processing of fuel data. Data desensitization processing is performed when the data sensitivity of the fuel data is not lower than the preset desensitization level.
[0072] In this embodiment, the user data access sharing risk value refers to the risk value when fuel data is shared. The higher the user data access sharing risk value, the lower the security of fuel data sharing.
[0073] The beneficial effects of the above technical solution are as follows: by setting user roles and assigning corresponding fuel data access permissions, the data sensitivity of fuel data is determined and multi-level access control is implemented; fuel data is encrypted and anonymized; the data sensitivity of the fuel data is weighted in conjunction with user permissions to determine the risk value of user data access sharing; when the risk value of user data access sharing is not higher than the preset risk value of the corresponding user data access sharing, the fuel data sharing method is matched according to the user role and fuel data sharing is performed; user access behavior and fuel data sharing behavior are monitored and analyzed to provide real-time early warning and execute corresponding preset anomaly control strategies; thus effectively ensuring the secure sharing of fuel data.
[0074] This invention provides a fuel data sharing system, including an access control module, comprising:
[0075] The user role permission unit is used to set different user roles according to user responsibilities and user needs, and to assign corresponding fuel data access permissions to various user roles.
[0076] When a user accesses fuel data, user information is obtained to match user roles. If the match is successful, the corresponding fuel data access permissions are enabled.
[0077] Otherwise, prompt the user to update their user information and re-match the user role;
[0078] The fuel data access control unit is used to implement multi-level access control for fuel data based on data sensitivity and access management strategies.
[0079] The authorization control unit is used to create administrator accounts and assign the highest privileges. It allows administrators to periodically audit and update access permissions for other users and fuel data according to the permission management policy, and to dynamically adjust access permissions for other users and fuel data based on fuel data access needs.
[0080] In this embodiment, fuel data access permissions include, for example, public access permissions, internal access permissions, confidential access permissions, and the highest level of confidentiality access permissions.
[0081] In this embodiment, higher-level access permissions can access fuel data at the same access permission level as well as fuel data at lower access permission levels.
[0082] In this embodiment, corresponding fuel data access permissions are assigned to various user roles. For example, administrators are assigned the highest level of confidentiality access.
[0083] In this embodiment, user permissions and fuel data permissions are periodically audited and updated. For example, user a1's access permissions are updated from public level to confidential level; fuel data b1's access permissions are updated from public level to internal level.
[0084] In this embodiment, the access control strategy refers to the strategy for controlling user permissions and fuel data access permissions. For example, users with public access permissions can only access fuel data with corresponding public access permissions.
[0085] The beneficial effects of the above technical solution are: by setting user roles and assigning corresponding fuel data access permissions, and implementing multi-level access control based on the data sensitivity of fuel data, the sharing security of fuel data is initially and effectively ensured, and user needs are met.
[0086] This invention provides a fuel data sharing system, including a fuel data access control unit, comprising:
[0087] Data sensitivity block is used to identify fuel data containing data sensitivity and mark it as sensitive fuel data;
[0088] Identify the data types of sensitive fuel data and set corresponding sensitivity levels based on the data types;
[0089] The data sensitivity of the fuel data is determined based on the sensitivity level and the proportion of the corresponding sensitive fuel data in the total fuel data.
[0090] The access control policy block is used to preset access control policies for fuel data with different data sensitivities, as well as user access control policies.
[0091] When data exceeding the sensitivity level of the allowed fuel data is detected, the data will be masked accordingly.
[0092] In this embodiment, the data types of sensitive fuel data are identified, such as public data types, internal data types, confidential data types, and top-secret data types.
[0093] In this embodiment, when it is detected that there is data in the fuel data that the user is allowed to access that exceeds the sensitivity level of the data that the user is allowed to access, the corresponding data blocking process is performed. For example, if user b1 accesses fuel data a1, and there is fuel data a2 in fuel data a1 that user b1 is allowed to access, then fuel data a2 is blocked.
[0094] The beneficial effects of the above technical solution are: marking sensitive fuel data and setting sensitivity levels to determine the data sensitivity of fuel data, which facilitates subsequent security control of sensitive fuel data; and setting access permission management policies and user permission management policies for fuel data with different data sensitivities to ensure the security of fuel data sharing.
[0095] This invention provides a fuel data sharing system, including a data encryption module, comprising:
[0096] The data transmission encryption unit is used to connect the fuel data storage terminal and the user access terminal according to a preset data transmission protocol and perform end-to-end encrypted connection.
[0097] The data storage encryption unit is used to call an encryption algorithm of appropriate strength to encrypt the fuel data according to its data sensitivity.
[0098] The data desensitization processing unit is used to obtain the data sensitivity of fuel data containing sensitive fuel data when shared access to sensitive fuel data is detected.
[0099] When the data sensitivity of the fuel data is not lower than the preset desensitization level, a preset data desensitization strategy is invoked according to the data sensitivity and user role. The preset data desensitization strategy includes: data replacement desensitization strategy, data hash desensitization strategy, and data differential privacy desensitization strategy.
[0100] In this embodiment, a preset data transmission protocol is used, such as SSL or TLS.
[0101] In this embodiment, an encryption algorithm of appropriate strength is called to encrypt the fuel data according to its data sensitivity. For example, a strong encryption algorithm is called to encrypt the fuel data a1.
[0102] In this embodiment, data encryption processing is performed, for example, data encryption processing is performed on statically stored fuel data.
[0103] In this embodiment, the user roles accessing fuel data are anonymized.
[0104] In this embodiment, fuel data of the same type applies the same preset data desensitization strategy. For example, fuel data of type b1 applies the data replacement desensitization strategy to ensure that fuel data of type b1 does not contain sensitive data.
[0105] The beneficial effects of the above technical solution are: by encrypting the data transmission, data storage, and data anonymization of fuel data, the security of shared transmission of fuel data in different network transmission environments is ensured and fuel data leakage is avoided.
[0106] This invention provides a fuel data sharing system, including a data sharing module comprising:
[0107] The sensitive data association unit is used to preprocess fuel data and remove invalid data.
[0108] Extract sensitive fuel data from the fuel data, determine the impact value of the sensitive fuel data on the fuel data based on the frequency and weight of the occurrence of the sensitive fuel data, and sort them in descending order of data sensitivity;
[0109] Select key sensitive data according to the order, obtain the data correlation degree between key sensitive data, and establish the correlation relationship between key sensitive data when the data correlation degree between key sensitive data is not higher than the correlation threshold.
[0110] Construct a key sensitive data association structure based on the key sensitive data and the relationships between the key sensitive data;
[0111] A sensitive data processing unit is used to perform an encryption process on the key sensitive data according to the data encryption process.
[0112] The key and sensitive data are then subjected to secondary weighting based on user permissions.
[0113] Based on historical fuel data, a standard association structure for key sensitive data is determined, and the association structure for key sensitive data is subjected to three structural processing steps.
[0114] The fuel data adaptive association unit is used to obtain new sensitive data of the new fuel data when it detects that a user accesses new fuel data, and adaptively associate the fuel data and the new fuel data with the key sensitive data association structure completed by the three-stage structure processing.
[0115] The fuel data association complexity unit is used to determine the data association complexity of the current fuel data by combining the time period from data preprocessing to the completion of adaptive fuel data association, and the average fuel data association time period determined by historical fuel data.
[0116] Access sharing risk unit, used to determine the risk value of user data access sharing;
[0117] ;
[0118] Where F represents the risk value of user data access sharing; x1 represents the number of sensitive fuel data points accurately identified in historical fuel data; and x2 represents the number of sensitive fuel data points not identified in historical fuel data. This indicates that when the i1th fuel data accessed by the user is the key sensitive data, the data sensitivity of the i1th fuel data is output. Otherwise, output 0; This represents the data association time period for the fuel data accessed by the j1th user; This indicates the time period associated with the average fuel data determined from historical fuel data. This represents the user permission level of the j1th user; n1 represents the number of critical and sensitive data in the fuel data; m1 represents the number of users accessing the fuel data.
[0119] When the risk value of user data access sharing is not higher than the preset risk value of the corresponding user accessing shared data, the fuel data sharing method is matched according to the user role and fuel data sharing is carried out.
[0120] Otherwise, mark the corresponding fuel data as risky data and the corresponding user as a risky user.
[0121] In this embodiment, data preprocessing, for example, involves marking insensitive data in the fuel data as irrelevant data for data removal.
[0122] In this embodiment, key sensitive data refers to sensitive data that appears frequently and has a high weight, and has a significant impact on fuel data.
[0123] In this embodiment, the data correlation between key sensitive data refers to the influence relationship between key sensitive data. For example, if key sensitive data a1 appears, then key sensitive data a2 will appear accordingly; if key sensitive data a1 does not appear, then key sensitive data a2 will not appear accordingly; it is determined that key sensitive data a1 and key sensitive data a2 have a data correlation.
[0124] In this embodiment, the data correlation degree is determined based on the frequency of occurrence and mutual influence between key sensitive data. For example, the data correlation degree between key sensitive data a1 and key sensitive data a2 is determined to be b1; the data correlation degree between key sensitive data a1 and key sensitive data a3 is determined to be b2.
[0125] In this embodiment, when the data correlation between the key sensitive data is not higher than the correlation threshold, the correlation between the key sensitive data is established. For example, if the correlation threshold is b3, b1>b3>b2, then key sensitive data a1 and key sensitive data a2 are not correlated; key sensitive data a1 and key sensitive data a3 are correlated.
[0126] In this embodiment, the key sensitive data association structure is used to simplify the description of sensitive data in the corresponding fuel data.
[0127] In this embodiment, encryption processing refers to ensuring the security of fuel data by encrypting key and sensitive data.
[0128] In this embodiment, the secondary weighting process refers to weighting the user permissions of key and sensitive data to ensure that users do not exceed their access permissions.
[0129] In this embodiment, the three-stage structural processing refers to improving the processing efficiency of fuel data by adjusting the structure of key sensitive data.
[0130] In this embodiment, the more similar the key sensitive data association structure is to the standard association structure, the higher the efficiency of accessing and processing the corresponding fuel data.
[0131] In this embodiment, the first encryption process, the second weighting process, and the third structural process are executed sequentially, and each process is executed.
[0132] In this embodiment, the fuel data and the new fuel data are adaptively associated using the key sensitive data association structure, which facilitates improved access processing efficiency and access security for the same user accessing the new fuel data.
[0133] In this embodiment, data association complexity refers to the complexity of performing three processes and adaptive associations for fuel data sharing and user access.
[0134] In this embodiment, when fuel data is marked as risky data, fuel data sharing is stopped and recorded; when a user is marked as a risky user, user access is stopped and recorded.
[0135] The beneficial effect of the above technical solution is that by combining the data sensitivity of the fuel data with user permissions to determine the risk value of user data access sharing and then controlling fuel data sharing, the security of fuel data sharing is effectively ensured.
[0136] This invention provides a fuel data sharing system and a monitoring and early warning module, comprising:
[0137] The fuel data monitoring unit is used to monitor and analyze user access behavior and fuel data sharing behavior. When abnormal access and sharing behavior is detected, it will mark the abnormal behavior as follows: high frequency access, high frequency download and unauthorized access.
[0138] The fuel data early warning unit is used to generate early warning data based on anomaly markers and risk markers, provide real-time early warnings, and execute corresponding preset anomaly control strategies. Risk markers include risk data and risk users.
[0139] In this embodiment, abnormal access sharing behavior includes abnormal user access behavior and abnormal fuel data sharing behavior.
[0140] In this embodiment, abnormal access sharing behavior and corresponding early warning data are stored independently based on time sequence.
[0141] In this embodiment, anomaly control strategies are preset, such as prohibiting user access, encrypting and desensitizing data, and controlling user permission adjustments.
[0142] The beneficial effects of the above technical solution are: by monitoring and analyzing user access behavior and fuel data sharing behavior, it is easier to carry out real-time early warning and execute corresponding preset anomaly control strategies, thereby further ensuring the security of fuel data sharing.
[0143] This invention provides a fuel data sharing system, which further includes:
[0144] The data sharing method module is used to match the fuel data sharing method according to user needs and user roles. The fuel data sharing methods include: sharing among all users, logical sharing, and web page sharing.
[0145] The fuel data tag module is used to embed fuel data tags into shared fuel data;
[0146] The access sharing time limit module is used to set a time window for fuel data sharing. When a user's access time exceeds the time window, the user's access is revoked.
[0147] In this embodiment, all users share the data, and each user can view the corresponding fuel data according to their user permissions.
[0148] In this embodiment, logic sharing is used to share fuel indicators or underlying fuel logic. Access permissions can be set to allow other users to access them.
[0149] In this embodiment, a time window for sharing fuel data is set. For example, a time window t1 is set for fuel data a1, during which all users are allowed to access fuel data a1.
[0150] The beneficial effects of the above technical solution are: matching fuel data sharing methods according to user needs and user roles effectively meets user needs; embedding fuel data tags facilitates monitoring and tracing of fuel data access and sharing; and setting a time window for fuel data sharing effectively prevents fuel data leakage.
[0151] like Figure 2 As shown, this embodiment of the invention provides a fuel data sharing method, which mainly includes the following steps:
[0152] Step 1: Set up user roles and assign corresponding fuel data access permissions. At the same time, determine the data sensitivity of fuel data and implement multi-level access control.
[0153] Step 2: Encrypt the fuel data for both data transmission and data storage. When the data sensitivity of the fuel data is not lower than the preset desensitization level, perform data desensitization processing.
[0154] Step 3: The data sensitivity of the access to shared data is weighted in combination with user permissions to determine the risk value of user data access sharing. When the risk value of user data access sharing is not higher than the preset risk value of the corresponding user accessing shared data, the fuel data sharing method is matched according to the user role and fuel data sharing is performed.
[0155] Step 4: Monitor and analyze user access behavior and fuel data sharing behavior. When abnormal access and sharing behavior is detected, generate early warning data for real-time warning and execute corresponding preset abnormal control strategies.
[0156] The beneficial effects of the above technical solution are as follows: by setting user roles and assigning corresponding fuel data access permissions, the data sensitivity of fuel data is determined and multi-level access control is implemented; fuel data is encrypted and anonymized; the data sensitivity of the fuel data is weighted in conjunction with user permissions to determine the risk value of user data access sharing; when the risk value of user data access sharing is not higher than the preset risk value of the corresponding user data access sharing, the fuel data sharing method is matched according to the user role and fuel data sharing is performed; user access behavior and fuel data sharing behavior are monitored and analyzed to provide real-time early warning and execute corresponding preset anomaly control strategies; thus effectively ensuring the secure sharing of fuel data.
[0157] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A fuel data sharing system, characterized in that, include: The access control module is used to set user roles and assign corresponding fuel data access permissions. At the same time, it determines the data sensitivity of fuel data and implements multi-level access control. The data encryption module is used to encrypt the data transmission and data storage of fuel data. When the data sensitivity of the fuel data is not lower than the preset desensitization level, data desensitization processing is performed. The data sharing module is used to weight the data sensitivity of the fuel data in combination with user permissions to determine the risk value of user data access sharing. When the risk value of user data access sharing is not higher than the preset risk value of the corresponding user data access sharing, the fuel data sharing method is matched according to the user role and the fuel data is shared. The monitoring and early warning module is used to monitor and analyze user access behavior and fuel data sharing behavior. When abnormal access and sharing behavior is detected, it generates early warning data, issues real-time warnings, and executes corresponding preset abnormal control strategies. The data encryption module includes: The data transmission encryption unit is used to connect the fuel data storage terminal and the user access terminal according to a preset data transmission protocol and perform end-to-end encrypted connection. The data storage encryption unit is used to call an encryption algorithm of appropriate strength to encrypt the fuel data according to its data sensitivity. The data desensitization processing unit is used to obtain the data sensitivity of fuel data containing sensitive fuel data when shared access to sensitive fuel data is detected. When the data sensitivity of the fuel data is not lower than the preset desensitization level, the preset data desensitization strategy is invoked according to the data sensitivity and user role. The preset data desensitization strategy includes: data replacement desensitization strategy, data hash desensitization strategy, and data differential privacy desensitization strategy. The data sharing module includes: The sensitive data association unit is used to preprocess fuel data and remove invalid data. Extract sensitive fuel data from the fuel data, determine the impact value of the sensitive fuel data on the fuel data based on the frequency and weight of the occurrence of the sensitive fuel data, and sort them in descending order of data sensitivity; Select key sensitive data according to the order, obtain the data correlation degree between key sensitive data, and establish the correlation relationship between key sensitive data when the data correlation degree between key sensitive data is not higher than the correlation threshold. Construct a key sensitive data association structure based on the key sensitive data and the relationships between the key sensitive data; A sensitive data processing unit is used to perform a single encryption process on the key sensitive data based on the encryption result of the data encryption module. The key and sensitive data are then subjected to secondary weighting based on user permissions. Based on historical fuel data, a standard association structure for key sensitive data is determined, and the association structure of the key sensitive data is adjusted to improve the processing efficiency of fuel data. Based on historical fuel data, a standard association structure for key sensitive data is determined, and the association structure for key sensitive data is subjected to three structural processing steps. The fuel data adaptive association unit is used to obtain new sensitive data of the new fuel data when it detects that a user accesses new fuel data, and adaptively associate the fuel data and the new fuel data with the key sensitive data association structure completed by the three-stage structure processing. The fuel data association complexity unit is used to determine the data association complexity of the current fuel data by combining the time period from data preprocessing to the completion of adaptive fuel data association, and the average fuel data association time period determined by historical fuel data. Access sharing risk unit, used to determine the risk value of user data access sharing; ; Where F represents the risk value of user data access sharing; x1 represents the number of sensitive fuel data points accurately identified in historical fuel data; and x2 represents the number of sensitive fuel data points not identified in historical fuel data. This indicates that when the i1th fuel data accessed by the user is the key sensitive data, the data sensitivity of the i1th fuel data is output. Otherwise, output 0; This represents the data association time period for the fuel data accessed by the j1th user; This indicates the time period associated with the average fuel data determined from historical fuel data. This represents the user permission level of the j1th user; n1 represents the number of critical and sensitive data in the fuel data; m1 represents the number of users accessing the fuel data. When the risk value of user data access sharing is not higher than the preset risk value of the corresponding user accessing shared data, the fuel data sharing method is matched according to the user role and fuel data sharing is carried out. Otherwise, mark the corresponding fuel data as risky data and the corresponding user as a risky user.
2. The fuel data sharing system according to claim 1, characterized in that, The access control module includes: The user role permission unit is used to set different user roles according to user responsibilities and user needs, and to assign corresponding fuel data access permissions to various user roles. When a user accesses fuel data, user information is obtained to match user roles. If the match is successful, the corresponding fuel data access permissions are enabled. Otherwise, prompt the user to update their user information and re-match the user role; The fuel data access control unit is used to implement multi-level access control for fuel data based on data sensitivity and access management strategies. The authorization control unit is used to create administrator accounts and assign the highest privileges. It allows administrators to periodically audit and update access permissions for other users and fuel data according to the permission management policy, and to dynamically adjust access permissions for other users and fuel data based on fuel data access needs.
3. The fuel data sharing system according to claim 2, characterized in that, The fuel data access control unit includes: Data sensitivity block is used to identify fuel data containing data sensitivity and mark it as sensitive fuel data; Identify the data types of sensitive fuel data and set corresponding sensitivity levels based on the data types; The data sensitivity of the fuel data is determined based on the sensitivity level and the proportion of the corresponding sensitive fuel data in the total fuel data. The access control policy block is used to preset access control policies for fuel data with different data sensitivities, as well as user access control policies. When data exceeding the sensitivity level of the allowed fuel data is detected, the data will be masked accordingly.
4. A fuel data sharing system according to claim 1, characterized in that, The monitoring and early warning module includes: The fuel data monitoring unit is used to monitor and analyze user access behavior and fuel data sharing behavior. When abnormal access and sharing behavior is detected, it will mark the abnormal behavior as follows: high frequency access, high frequency download and unauthorized access. The fuel data early warning unit is used to generate early warning data based on anomaly markers and risk markers, provide real-time early warnings, and execute corresponding preset anomaly control strategies. Risk markers include risk data and risk users.
5. A fuel data sharing system according to claim 1, characterized in that, Also includes: The data sharing method module is used to match the fuel data sharing method according to user needs and user roles. The fuel data sharing methods include: sharing among all users, logical sharing, and web page sharing. The fuel data tag module is used to embed fuel data tags into shared fuel data; The access sharing time limit module is used to set a time window for fuel data sharing. When a user's access time exceeds the time window, the user's access is revoked.
6. A fuel data sharing method, applied to the fuel data sharing system according to any one of claims 1-5, characterized in that, include: Step 1: Set up user roles and assign corresponding fuel data access permissions. At the same time, determine the data sensitivity of fuel data and implement multi-level access control. Step 2: Encrypt the fuel data for both data transmission and data storage. When the data sensitivity of the fuel data is not lower than the preset desensitization level, perform data desensitization processing. Step 3: The data sensitivity of the access to shared data is weighted in combination with user permissions to determine the risk value of user data access sharing. When the risk value of user data access sharing is not higher than the preset risk value of the corresponding user accessing shared data, the fuel data sharing method is matched according to the user role and fuel data sharing is performed. Step 4: Monitor and analyze user access behavior and fuel data sharing behavior. When abnormal access and sharing behavior is detected, generate early warning data for real-time warning and execute corresponding preset abnormal control strategies. Step 2 includes: The fuel data storage terminal is connected to the user access terminal according to the preset data transmission protocol, and an end-to-end encrypted connection is established. The appropriate encryption algorithm is invoked based on the data sensitivity of the fuel data to encrypt the data. When shared access to sensitive fuel data is detected, the data sensitivity of the fuel data containing the sensitive fuel data is obtained. When the data sensitivity of the fuel data is not lower than the preset desensitization level, the preset data desensitization strategy is invoked according to the data sensitivity and user role. The preset data desensitization strategy includes: data replacement desensitization strategy, data hash desensitization strategy, and data differential privacy desensitization strategy. Step 3 includes: Data preprocessing is performed on fuel data to remove invalid data; Extract sensitive fuel data from the fuel data, determine the impact value of the sensitive fuel data on the fuel data based on the frequency and weight of the occurrence of the sensitive fuel data, and sort them in descending order of data sensitivity; Select key sensitive data according to the order, obtain the data correlation degree between key sensitive data, and establish the correlation relationship between key sensitive data when the data correlation degree between key sensitive data is not higher than the correlation threshold. Construct a key sensitive data association structure based on the key sensitive data and the relationships between the key sensitive data; The critical and sensitive data is encrypted once based on the encryption result of the data encryption module. The key and sensitive data are then subjected to secondary weighting based on user permissions. Based on historical fuel data, a standard association structure for key sensitive data is determined, and the association structure of the key sensitive data is adjusted to improve the processing efficiency of fuel data. Based on historical fuel data, a standard association structure for key sensitive data is determined, and the association structure for key sensitive data is subjected to three structural processing steps. When a user accesses new fuel data, new sensitive data of the new fuel data is obtained, and the fuel data and the new fuel data are adaptively associated by combining the key sensitive data association structure completed by the three-stage structural processing. Based on the time period from data preprocessing of fuel data to completion of adaptive fuel data association, and combined with the average fuel data association time period determined from historical fuel data, the data association complexity of the current fuel data is determined. Access sharing risk unit, used to determine the risk value of user data access sharing; ; Where F represents the risk value of user data access sharing; x1 represents the number of sensitive fuel data points accurately identified in historical fuel data; and x2 represents the number of sensitive fuel data points not identified in historical fuel data. This indicates that when the i1th fuel data accessed by the user is the key sensitive data, the data sensitivity of the i1th fuel data is output. Otherwise, output 0; This represents the data association time period for the fuel data accessed by the j1th user; This indicates the time period associated with the average fuel data determined from historical fuel data. This represents the user permission level of the j1th user; n1 represents the number of critical and sensitive data in the fuel data; m1 represents the number of users accessing the fuel data. When the risk value of user data access sharing is not higher than the preset risk value of the corresponding user accessing shared data, the fuel data sharing method is matched according to the user role and fuel data sharing is carried out. Otherwise, mark the corresponding fuel data as risky data and the corresponding user as a risky user.
Citation Information
Patent Citations
Data desensitization method and device
CN116167085A
Data sharing method and device
CN117725611A