A Design Method for a Data Asset Management Platform Based on Mimic Defense

By constructing dynamic heterogeneous executors and mimicking adjudication mechanisms, the service platform blocking or hanging up of the data asset management platform is solved, and high reliability and low cost transformation is achieved.

CN119420505BActive Publication Date: 2025-07-11SHANGHAI DINING DIGITAL TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411400094.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-09
Publication Date
2025-07-11
Estimated Expiration
2044-10-09

AI Technical Summary

Technical Problem

In a mimicry environment, the service platform of the data asset management platform is prone to blockage or hang-up problems, mainly due to the inefficiency of normalized voting for non-idempotent operations caused by large calculations.

Method used

Adopting the core concept of mimic defense, we build dynamic, heterogeneous and redundant executors, and through mimic distribution, mimic adjudication, feedback control and executor scheduling, we construct a safe execution environment to ensure high reliability and rapid discovery of abnormal executors.

Benefits of technology

It realizes the high reliability of the data asset management platform, avoids blocking or hanging up the service platform, reduces system performance losses, and reduces transformation costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119420505B_ABST
    Figure CN119420505B_ABST
Patent Text Reader

Abstract

The present invention provides a design method for a data asset management platform based on mimic defense, which relates to the technical field of data assets, and includes: S1: The mimic distribution gateway obtains external access data; S2: An execution body is established, and the external access data is processed by the mimic distribution gateway and then distributed to the execution body; S3: The execution body processes the external access data and outputs the processing result to the mimic adjudication gateway; S4: The mimic adjudication gateway votes on and records the processing result; S5: The metadata service performs metadata search on the access data and adjudicates and records the search result; By introducing the core concept of mimic defense: dynamic, heterogeneous and redundant, and through the core functional components of mimic defense: mimic distribution, mimic adjudication, feedback control and execution body scheduling, the present invention constructs a secure execution environment for the platform, preventing problems such as blocking or hanging of the service platform due to large computational workload.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital assets, and in particular, to a design method of a data asset management platform based on mimic defense. Background Art

[0002] In today's digital economy, data assets have become one of the most valuable resources for enterprises. The value of data lies not only in its scale, but more importantly, in its ability to provide enterprises with profound insights and decision-making support. Accurately evaluating the value of data assets is crucial for enterprise resource allocation, investment decisions, risk management, and the formulation of business strategies. Therefore, the security protection of data asset trading platforms is becoming increasingly important.

[0003] In the prior art, in a mimic environment, a data asset management platform needs to form n (n>3) parallel execution bodies. When accessing the execution bodies externally, it is necessary to ensure the normalized voting of non-idempotent operations, which may cause problems such as blocking or hanging of the service platform due to large computational workloads. Therefore, a design method of a data asset management platform based on mimic defense is needed to solve the above problems. Summary of the Invention

[0004] Aiming at the deficiencies of the prior art, the purpose of the present invention is to provide a design method of a data asset management platform based on mimic defense. By introducing the core concepts of mimic defense: dynamic, heterogeneous, and redundant, and through the core functional components of mimic defense: mimic distribution, mimic adjudication, feedback control, and execution body scheduling, a secure execution environment for the platform is constructed to prevent problems such as blocking or hanging of the service platform due to large computational workloads.

[0005] To achieve the above purpose, the present invention is implemented through the following technical solutions: A design method of a data asset management platform based on mimic defense, the method comprising the following steps:

[0006] The mimic distribution gateway obtains external access data;

[0007] An execution body is established, and the external access data is distributed to the execution body after being processed by the mimic distribution gateway;

[0008] The execution body processes the external access data and outputs the processing result to the mimic adjudication gateway;

[0009] The mimic adjudication gateway votes on and records the processing result;

[0010] The metadata service performs metadata lookup on the access data, and votes on and records the lookup result.

[0011] Further, establishing an execution body and distributing the external access data to the execution body after being processed by the mimic distribution gateway includes the following sub-steps:

[0012] The mimicry distribution gateway parses the obtained external access data, and extracts the target address, port, and protocol type of the external access data;

[0013] Establish a number of execution bodies, and the execution bodies are heterogeneous execution bodies;

[0014] Establish an execution body scheduler, and the execution body scheduler is used to evaluate the performance of the execution bodies;

[0015] After receiving the access data, the execution body scheduler performs a performance evaluation on all execution bodies, and screens out some execution bodies that meet the conditions and sets them as the first processing execution body 1 to the first processing execution body n;

[0016] The mimicry distribution gateway distributes the target address, port, and protocol type of the external access data to the first processing execution body 1 to the first processing execution body n at the same time.

[0017] Further, the steps for the execution body to process the external access data and output the processing result to the mimicry adjudication gateway include the following sub-steps:

[0018] The first processing execution body 1 to the first processing execution body n perform parallel processing on the received data according to their own hardware configurations, operating systems, and software versions, and obtain processing results 1 to processing results n;

[0019] Send the processing results 1 to the processing results n to the mimicry adjudication gateway.

[0020] Further, the steps for the mimicry adjudication gateway to vote on and record the processing results include the following sub-steps:

[0021] The mimicry adjudication gateway collects the processing results of all execution bodies;

[0022] The mimicry adjudication gateway votes on the processing results 1 to the processing results n through a voting algorithm;

[0023] When the voting results are consistent, randomly select one output result and output it to the metadata service;

[0024] When the voting results are inconsistent, send the results to the feedback controller. The feedback controller records the inconsistent voting results and returns them to the execution body scheduler for re-scheduling.

[0025] Further, the voting algorithm is a consistency voting algorithm, including: when the mimicry adjudication gateway obtains the processing results 1 to the processing results n, compare the processing results 1 to the processing results n. When the processing results 1 to the processing results n are all the same, output that the voting results are consistent. When any one of the processing results 1 to the processing results n is different from other processing results, judge that the voting results are inconsistent.

[0026] Further, the rescheduling includes that the execution body scheduler obtains execution bodies with consistent processing results and sets them as the second processing execution bodies 1 to the second processing execution bodies m, and the mimicry distribution gateway distributes the target address, port, and protocol type of the external access data to the second processing execution bodies 1 to the second processing execution bodies m simultaneously.

[0027] Further, the feedback controller is used to record and detect the security of the system, including: when obtaining inconsistent voting results, setting the execution body that generates the inconsistent voting results as an abnormal execution body, isolating the abnormal execution body, obtaining the execution bodies with consistent voting results, using the execution bodies with consistent voting results to cover the abnormal execution body, and recording the operation;

[0028] When obtaining inconsistent adjudication results, setting the execution body that generates the inconsistent adjudication results as an abnormal execution body, isolating the abnormal execution body, obtaining the execution bodies with consistent adjudication results, using the execution bodies with consistent adjudication results to cover the abnormal execution body, and recording the operation.

[0029] Further, the metadata service performs metadata lookup on the access data, and the adjudication and recording of the lookup results include the following sub-steps:

[0030] After the metadata service receives the output result, it calls the metadata index service to perform metadata lookup or data source import to obtain an operation result;

[0031] Return the operation result of the metadata service to the mimicry adjudication gateway;

[0032] The mimicry adjudication gateway distributes the operation result of the metadata service to the first processing execution bodies 1 to the first processing execution bodies n;

[0033] The first processing execution bodies 1 to the first processing execution bodies n process the operation result to obtain processing information 1 to processing information n;

[0034] The mimicry distribution gateway calls the mimicry adjudication gateway to adjudicate the processing information 1 to processing information n;

[0035] When the adjudication results are consistent, the mimicry adjudication gateway returns an adjudication consistent signal, and the mimicry distribution gateway randomly selects one piece of processing information and returns it to the user;

[0036] When the adjudication results are inconsistent, the results are sent to the feedback controller. The feedback controller records the inconsistent results, and the feedback controller sends a rescheduling signal to the execution body scheduler, and the execution body scheduler performs rescheduling.

[0037] Advantages of the present invention: First, the present invention synchronizes access number data by constructing multiple heterogeneous and redundant execution bodies, which can ensure high reliability of the platform to ensure that services are not blocked or hung up;

[0038] The present invention also votes on the processing results of multiple execution bodies. Through the design method of "finding differences", inconsistent results existing in the execution bodies can be quickly discovered and returned to the feedback controller, and abnormal execution bodies can be quickly isolated, reducing the performance loss of the system;

[0039] The present invention also adopts a non-invasive transformation method. The user side does not need to send special personnel to assist the transformation side in application transformation, and the transformation side does not need to invest a large number of developers in application adaptation, saving a large amount of time cost and labor cost, thereby reducing the overall cost of mimicry transformation.

[0040] Advantages of additional aspects of the present invention will be partially given in the following description of specific embodiments, partially become obvious from the following description, or be understood through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] By reading the detailed description of the non-restrictive embodiments with reference to the following drawings, other features, objectives and advantages of the present invention will become more obvious:

[0042] Figure 1 is a flowchart of the method steps of the present invention;

[0043] Figure 2 is a schematic diagram of the mimicry transformation of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0044] It should be noted that the following detailed description is exemplary and is intended to provide further illustration of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.

[0045] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present invention.

[0046] In the case of no conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.

[0047] Embodiment 1, First aspect, referring to Figure 1 shown, a design method of a data asset management platform based on mimicry defense, the method includes the following steps:

[0048] Step S1: The mimicry distribution gateway obtains external access data; in the specific implementation process, the external access data includes data such as the target address, port, and protocol type of the registration access platform;

[0049] Step S2: Establish execution entities, and distribute the external access data to the execution entities after processing by the mimicry distribution gateway;

[0050] Please refer to Figure 2 As shown, Step S2 includes the following sub-steps:

[0051] Step S201: The mimicry distribution gateway parses the obtained external access data, and extracts the target address, port, and protocol type of the external access data;

[0052] Step S202: Establish several execution entities, and the execution entities are heterogeneous execution entities; in the specific implementation process, the heterogeneous execution entities are composed of heterogeneous components, including different software and hardware components, such as CPUs, DSPs, GPUs, ASICs, FPGAs, etc.; by dynamically scheduling and combining the heterogeneous execution entities, the dynamic nature and unpredictability of the defense strategy can be achieved, further enhancing the security of the system;

[0053] Step S203: Establish an execution entity scheduler, and the execution entity scheduler is used to evaluate the performance of the execution entities; in the specific implementation process, the performance evaluation of the execution entities includes evaluating aspects such as the processing ability, stability, security, maintainability, and integration with the existing system of the execution entities;

[0054] Step S204: After receiving the access data, the execution entity scheduler evaluates the performance of all execution entities, and screens out some execution entities that meet the conditions and sets them as the first processing execution entities 1 to the first processing execution entities n; in the specific implementation process, the first processing execution entities 1 to the first processing execution entities n are randomly selected from the execution entities that meet the conditions, and the randomness of the execution entity selection makes the system exhibit uncertainty, so as to ensure that it is difficult for attackers to construct an effective attack chain;

[0055] Step S205: The mimicry distribution gateway distributes the target address, port, and protocol type of the external access data to the first processing execution entities 1 to the first processing execution entities n at the same time;

[0056] Step S3: The execution entities process the external access data and output the processing results to the mimicry adjudication gateway;

[0057] Step S3 includes the following sub-steps:

[0058] Step S301: The first processing execution entity 1 to the first processing execution entity n perform parallel processing on the received data according to their own hardware configurations, operating systems, and software versions, and obtain processing results 1 to processing results n; in the specific implementation process, the heterogeneity of the processing execution entities not only improves the processing efficiency of the system, but also increases the security and reliability of the system. Even if a certain execution entity fails or is attacked, the data and services can be restored through other execution entities.

[0059] Step S302: Send the processing results 1 to the processing results n to the mimicry arbitration gateway;

[0060] Step S4: The mimicry arbitration gateway votes on and records the processing results; Step S4 includes the following sub-steps:

[0061] Step S401: The mimicry arbitration gateway collects the processing results of all execution entities;

[0062] Step S402: The mimicry arbitration gateway votes on the processing results 1 to the processing results n through a voting algorithm;

[0063] The voting algorithm in Step S402 is a consistency voting algorithm, including: when the mimicry arbitration gateway obtains the processing results 1 to the processing results n, compare the processing results 1 to the processing results n. When the processing results 1 to the processing results n are all the same, output that the voting result is consistent. When any one of the processing results 1 to the processing results n is different from other processing results, judge that the voting result is inconsistent; in the specific implementation process, the consistency voting algorithm requires that the output results of all execution entities participating in the vote are exactly the same before it is considered that the processing result this time is correct. This algorithm has relatively strict requirements and can greatly improve the accuracy of the output results;

[0064] Step S403: When the voting result is consistent, randomly select one output result and output it to the metadata service;

[0065] When the voting result is inconsistent, send the result to the feedback controller. The feedback controller records the inconsistent voting results and returns them to the execution entity scheduler for re-scheduling; in the specific implementation process, the design of the mimicry arbitration gateway changes the traditional practice of "finding friends" and instead adopts the design method of "finding differences". The number of request connections within the finite set is limited. Using the consistency voting algorithm can quickly discover the "outsiders" among them, reducing losses while ensuring the improvement of the processing speed;

[0066] Rescheduling includes the execution body scheduler obtaining execution bodies with consistent processing results and setting them as the second processing execution bodies 1 to the second processing execution bodies m. The mimicry distribution gateway distributes the target address, port, and protocol type of the external access data to the second processing execution bodies 1 to the second processing execution bodies m at the same time; in the specific implementation process, the second processing execution bodies 1 to the second processing execution bodies m will replace the original first processing execution bodies 1 to the first processing execution bodies n for processing;

[0067] The feedback controller is used to record and detect the security of the system, including: when obtaining inconsistent voting results, setting the execution body that generates the inconsistent voting results as an abnormal execution body, isolating the abnormal execution body, obtaining the execution bodies with consistent voting results, using the execution bodies with consistent voting results to cover the abnormal execution body, and recording the operation; in the specific implementation process, for example, in a consistency voting process, if there are two inconsistent voting results, the execution bodies that generate these two voting results are marked as abnormal execution bodies and isolated, and at the same time, any one of the execution bodies with consistent voting results is selected to cover the abnormal execution body. Due to the heterogeneity and randomness of the execution bodies, the system shows uncertainty, making it difficult for attackers to construct an effective attack chain;

[0068] Step S5: The metadata service performs metadata lookup on the access data and makes a ruling and record on the lookup result;

[0069] Step S5 includes the following sub-steps:

[0070] Step S501: After receiving the output result, the metadata service calls the metadata index service to perform metadata lookup or data source import to obtain an operation result; in the specific implementation process, the metadata service includes a unified metadata warehouse for storing the metadata of all data assets. The metadata lookup includes using the metadata index service to retrieve the metadata warehouse to find the target;

[0071] Step S502: Return the operation result of the metadata service to the mimicry ruling gateway;

[0072] Step S503: The mimicry ruling gateway distributes the operation result of the metadata service to the first processing execution bodies 1 to the first processing execution bodies n;

[0073] Step S504: The first processing execution bodies 1 to the first processing execution bodies n process the operation result to obtain processing information 1 to processing information n;

[0074] Step S505: The mimicry distribution gateway invokes the mimicry adjudication gateway to adjudicate processing information 1 to processing information n; in the specific implementation process, the adjudication algorithm uses consistent adjudication: if the output results of all executors are exactly the same, then the result will be directly used as the final decision output;

[0075] When the adjudication results are consistent, the mimicry adjudication gateway returns an adjudication consistent signal, and the mimicry distribution gateway randomly selects one piece of processing information and returns it to the user;

[0076] When the adjudication results are inconsistent, the results are sent to the feedback controller. The feedback controller records the inconsistent results and sends a rescheduling signal to the executor scheduler, and the executor scheduler performs rescheduling;

[0077] In the specific implementation process, when inconsistent adjudication results are obtained, the executor that generates the inconsistent adjudication results is set as an abnormal executor, the abnormal executor is isolated, the executors with consistent adjudication results are obtained, and the executors with consistent adjudication results are used to overwrite the abnormal executor, and the operations are recorded.

[0078] Embodiment 2, Second aspect, the present application provides an electronic device, including a processor and a memory. The memory stores computer-readable instructions. When the computer-readable instructions are executed by the processor, the steps in the above method are run. Through the above technical solution, the processor and the memory are interconnected and communicate with each other through a communication bus and / or other forms of connection mechanisms. The memory stores a computer program executable by the processor. When the electronic device runs, the processor executes the computer program to execute the method in any optional implementation manner of the above embodiment to achieve the following functions: the mimicry distribution gateway obtains external access data; an executor is established, and the external access data is processed by the mimicry distribution gateway and then distributed to the executor; the executor processes the external access data and outputs the processing result to the mimicry adjudication gateway; the mimicry adjudication gateway votes and records the processing result; the metadata service performs metadata lookup on the access data and adjudicates and records the lookup result.

[0079] Embodiment 3, Third aspect, the present application provides a storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method are run. Through the above technical solution, when the computer program is executed by the processor, the method in any optional implementation manner of the above embodiment is executed to achieve the following functions: the mimicry distribution gateway obtains external access data; an executor is established, and the external access data is processed by the mimicry distribution gateway and then distributed to the executor; the executor processes the external access data and outputs the processing result to the mimicry adjudication gateway; the mimicry adjudication gateway votes and records the processing result; the metadata service performs metadata lookup on the access data and adjudicates and records the lookup result.

[0080] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media containing computer-usable program code. Among them, the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. These computer program instructions can also be stored in a computer-readable memory capable of guiding a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured article including an instruction device, and the instruction device implements the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 specified in one block or multiple blocks.

[0081] The above-described embodiments are only specific embodiments of the present invention, which are used to illustrate the technical solutions of the present invention rather than to limit them. The protection scope of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed by the present invention can still modify the technical solutions recorded in the foregoing embodiments or can easily think of changes, or make equivalent replacements for some of the technical features; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A design method for a data asset management platform based on mimic defense, characterized in that, It includes the following steps: The mimicry distribution gateway obtains external access data; An execution body is established, and the external access data is distributed to the execution body after being processed by the mimicry distribution gateway; The execution body processes the external access data and outputs the processing result to the mimicry adjudication gateway; The mimicry adjudication gateway votes on and records the processing result; The metadata service performs metadata lookup on the access data, and adjudicates and records the lookup result; Establishing an execution body and distributing the external access data to the execution body after being processed by the mimicry distribution gateway includes the following sub-steps: The mimicry distribution gateway parses the obtained external access data, extracts the target address, port, and protocol type of the external access data; A number of execution bodies are established, and the execution bodies are heterogeneous execution bodies; An execution body scheduler is established, and the execution body scheduler is used to evaluate the performance of the execution body; After receiving the access data, the execution body scheduler performs a performance evaluation on all execution bodies, and filters out some execution bodies that meet the conditions and sets them as the first processing execution body 1 to the first processing execution body n; The mimicry distribution gateway distributes the target address, port, and protocol type of the external access data to the first processing execution body 1 to the first processing execution body n at the same time; The mimicry adjudication gateway's voting on and recording the processing result includes the following sub-steps: The mimicry adjudication gateway collects the processing results of all execution bodies; The mimicry adjudication gateway votes on the processing results 1 to processing result n through a voting algorithm; When the voting results are consistent, any one of the output results is output to the metadata service; When the voting results are inconsistent, the results are sent to the feedback controller, and the feedback controller records the inconsistent voting results and returns them to the execution body scheduler for rescheduling; The metadata service's performing metadata lookup on the access data and adjudicating and recording the lookup result includes the following sub-steps: After receiving the output result, the metadata service calls the metadata index service for metadata lookup or data source import to obtain an operation result; The operation result of the metadata service is returned to the mimicry adjudication gateway for adjudication and recording.

2. The design method of a data asset management platform based on mimic defense according to claim 1, characterized in that, The execution body's processing the external access data and outputting the processing result to the mimicry adjudication gateway includes the following sub-steps: The first processing execution body 1 to the first processing execution body n perform parallel processing on the received data according to their own hardware configuration, operating system, and software version to obtain processing results 1 to processing result n; The processing results 1 to processing result n are sent to the mimicry adjudication gateway.

3. The design method of a data asset management platform based on mimic defense according to claim 2, characterized in that, The voting algorithm is a consistency voting algorithm, including: when the mimicry adjudication gateway obtains the processing results 1 to processing result n, it compares the processing results 1 to processing result n. When the processing results 1 to processing result n are all the same, it outputs that the voting results are consistent. When any one of the processing results 1 to processing result n is different from other processing results, it is judged that the voting results are inconsistent.

4. The design method of a data asset management platform based on mimic defense according to claim 3, characterized in that, The rescheduling includes that the execution body scheduler obtains the execution bodies with consistent processing results, sets them as the second processing execution body 1 to the second processing execution body m, and the mimicry distribution gateway distributes the target address, port, and protocol type of the external access data to the second processing execution body 1 to the second processing execution body m at the same time.

5. The design method of a data asset management platform based on mimic defense according to claim 4, characterized in that, The feedback controller is used to record and detect the security of the system, including: when an inconsistent voting result is obtained, setting the executor that generates the inconsistent voting result as an abnormal executor, isolating the abnormal executor, obtaining the executors with consistent voting results, using the executors with consistent voting results to overwrite the abnormal executor, and recording the operation; When an inconsistent adjudication result is obtained, setting the executor that generates the inconsistent adjudication result as an abnormal executor, isolating the abnormal executor, obtaining the executors with consistent adjudication results, using the executors with consistent adjudication results to overwrite the abnormal executor, and recording the operation.

6. The design method of a data asset management platform based on mimic defense according to claim 5, characterized in that, The metadata service performs metadata lookup on the accessed data, and the adjudication and recording of the lookup results further include the following sub-steps: The mimicry adjudication gateway distributes the operation results of the metadata service to the first processing executor 1 to the first processing executor n; The first processing executor 1 to the first processing executor n process the operation results to obtain processing information 1 to processing information n; The mimicry distribution gateway calls the mimicry adjudication gateway to adjudicate the processing information 1 to the processing information n; When the adjudication results are consistent, the mimicry adjudication gateway returns an adjudication consistent signal, and the mimicry distribution gateway randomly selects one piece of processing information and returns it to the user; When the adjudication results are inconsistent, the results are sent to the feedback controller, the feedback controller records the inconsistent results, the feedback controller sends a rescheduling signal to the executor scheduler, and the executor scheduler performs rescheduling.

Citation Information

Patent Citations

  • SDN-based mimic Web server and user request processing method

    CN110290100A

  • Electric power Web application mimicry defense system

    CN111191229A