Network data management method and device, computer device, readable storage medium and program product
By using multi-layered labeling technology to perform compliance verification and routing management of network data, the problems of difficult data circulation traceability and type identification are solved, and efficient compliance management and secure transmission of data throughout its entire lifecycle are achieved.
Patent Information
- Application Number
- CN202411938698.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-26
- Publication Date
- 2025-12-12
- Estimated Expiration
- 2044-12-26
AI Technical Summary
The existing network data governance framework and technical means lack a unified, flexible, and efficient standard system, which makes it difficult to trace data circulation, identify data types, and verify compliance, thus increasing management complexity and security risks.
By employing multi-layered tagging technology, integrating multi-dimensional information such as data, identity, and network, data tags and network tags are generated. Compliance verification and routing are performed through the regulatory gateway, and management codes are generated and reported to the regulatory platform to achieve data flow path management.
It enables full lifecycle management of data from generation to storage and processing, improving the efficiency and security of data circulation and ensuring the traceability and compliance of data transmission.
Smart Images

Figure CN119743316B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a network data management method and device, computer equipment, readable storage medium and program product. BACKGROUND
[0002] With the extensive application of data and the increasing demand for cross-border flow, it is particularly important to ensure the security and compliance of data in the flow process. However, in actual application, data flow scenarios such as cross-domain, cross-network, cross-region and cross-border present the characteristics of multi-party participation, long transmission chain and complex link. Due to the flow of data among multiple participants and complex links, there is a lack of unified and efficient data tracking mechanism, which makes it difficult to accurately track the source and destination of data. In addition, in the data circulation, there are various types of data, and the security attributes and compliance requirements of different data types are different, which often cannot accurately identify the data type, thereby causing potential data security risks. SUMMARY
[0003] Therefore, it is necessary to provide a network data management method, device, computer equipment, readable storage medium and program product capable of effectively ensuring the security of data circulation in view of the above technical problems.
[0004] In a first aspect, the present application provides a network data management method, comprising:
[0005] receiving network data transmitted by a client; the network data carries a label identifier, the label identifier including a data label identifier and a network label identifier, the data label identifier being used to represent source information of the network data, and the network label identifier being used to represent network service information of the network data;
[0006] analyzing the network data, and performing compliance verification on the network data according to the label identifier obtained through the analysis;
[0007] in a case where the compliance verification is passed, performing routing addressing according to the network label identifier in the label identifier, and transmitting the network data after label removal to a next-hop routing according to an addressing result;
[0008] generating a management code according to the label identifier, and reporting the management code to a supervision platform, so as to instruct the supervision platform to manage a circulation path of the network data according to all the management codes reported by the network data in a transmission process; the management code including upstream and downstream gateway information of a current supervision gateway.
[0009] In one of the embodiments, the data label identifies include data source code, data content code and regulatory identification; the data source code is registered according to the identity information of the data sender; the data content code is obtained by identifying the network data through the combination of the large model and the small model; and the regulatory identification is determined according to the sensitive information in the network data.
[0010] In one of the embodiments, the network label identifies include service identification and transmission identification; the service identification is obtained according to the resource demand degree of the network data; and the transmission identification is obtained by marking the consistency of the data content code and the regulatory identification at the network layer.
[0011] In one of the embodiments, the label identification is obtained by sequentially marking the authorized regulatory layer, marking the application layer, marking the network layer and encapsulating the identification network.
[0012] In one of the embodiments, the step of performing compliance verification on the network data according to the parsed label identification includes:
[0013] In the case that the regulatory gateway is in an online state, the parsed label identification is subjected to consistency verification, and in the case that the consistency verification is passed, the network data is subjected to compliance verification according to the label identification;
[0014] In the case that the regulatory gateway is in an offline state, the network data and the label identification are subjected to compliance analysis based on big data.
[0015] In one of the embodiments, the method further includes:
[0016] The network data is captured by the regulatory probe in the transmission process of the traffic data;
[0017] The label identification of the traffic data is obtained;
[0018] The network data is subjected to transmission reliability verification according to the label identification of the traffic data and the label identification of the network data.
[0019] In the second aspect, the application further provides a network data management device, which includes:
[0020] The receiving module is configured to receive the network data transmitted by the client; the network data carries label identification, and the label identification includes data label identification and network label identification; the data label identification is used to represent the source information of the network data, and the network label identification is used to represent the network service information of the network data;
[0021] The verification module is configured to parse the network data, and perform compliance verification on the network data according to the parsed label identification;
[0022] The transmission module is configured to, in the case that the compliance verification passes, perform routing addressing according to a network label identifier in the label identifier, and transmit the untagged network data to a next hop routing according to an addressing result.
[0023] The management module is configured to generate a management code according to the label identifier, and report the management code to a supervision platform, so as to instruct the supervision platform to manage a circulation path of the network data according to all the management codes reported by the network data in a transmission process. The management code includes upstream and downstream gateway information of a current supervision gateway.
[0024] In a third aspect, the present application further provides a computer device, including a memory and a processor, the memory stores a computer program, and the processor implements the method steps of any one of the first aspect when executing the computer program.
[0025] In a fourth aspect, the present application further provides a computer readable storage medium, which stores a computer program, and the computer program implements the method steps of any one of the first aspect when executed by a processor.
[0026] In a fifth aspect, the present application further provides a computer program product, including a computer program, and the computer program implements the method steps of any one of the first aspect when executed by a processor.
[0027] The network data management method, device, computer device, readable storage medium and program product described above can prevent unauthorized data transmission, guarantee network security, realize whole life cycle management of data from generation, transmission to storage and processing, and when the network data passes through a supervision gateway, the supervision gateway reports upstream and downstream gateway information to a supervision platform, so that the supervision platform can trace and manage a circulation path of the network data according to all the gateway information in a transmission process, thereby improving efficiency and security of data circulation. BRIEF DESCRIPTION OF DRAWINGS
[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the drawings needed to be used in the description of the embodiments of the present application or the related art will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.
[0029] Figure 1 An application environment diagram of a network data management method in an embodiment;
[0030] Figure 2 Flowchart of network data management method in one embodiment;
[0031] Figure 3 Schematic diagram of label identification generation system in one embodiment;
[0032] Figure 4 Schematic diagram of label identification encapsulation process in one embodiment;
[0033] Figure 5 Schematic diagram of network data management architecture in one embodiment;
[0034] Figure 6 Schematic diagram of label identification quality assessment in another embodiment;
[0035] Figure 7 Block diagram of network data management device structure in one embodiment;
[0036] Figure 8 Internal structure diagram of computer equipment in one embodiment. DETAILED DESCRIPTION
[0037] In order to make the purpose, technical scheme and advantages of the present application clearer, the present application will be further described in detail below in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.
[0038] With the rapid development of information technology and the widespread use of the Internet, data has become an indispensable important resource in modern society. Data not only plays a crucial role in enterprise operations and scientific research, but also plays a bridge role in cross-border cooperation and exchange. However, with the widespread use of data and the increasing demand for cross-border data flow, how to ensure the security and compliance of data in the flow process has become a problem to be solved.
[0039] In the scenarios of data cross-domain, cross-network, cross-region and cross-border flow, due to the characteristics of multi-party participation, long transmission chain, complex link, etc., network data governance faces many challenges. Specifically, these challenges include but are not limited to data flow tracing difficulties, data type identification difficulties, processing compliance verification difficulties, etc. These problems not only bring major challenges to network data supervision, but also restrict the effective use and value of data.
[0040] However, the existing network data governance framework and technical means often lack unified, flexible and efficient standard system and technical architecture, resulting in difficulties in accurately identifying, quickly tracing and efficiently verifying data in the process of data circulation and use, which not only increases the difficulty and complexity of data management, but also reduces the efficiency and security of data circulation.
[0041] In this context, as a technology for implementing identity feature identification and security attribute marking on data resources, the label identification technology can achieve accurate tracking and compliance verification of data by implementing label identification on data in the process of data circulation and use, thereby providing a new idea and method for solving the problems in network data governance.
[0042] However, the existing label identification technology can only achieve simple identification and classification of data, and cannot fully capture the multi-dimensional features of data, nor can it fully utilize data transmission network resources to achieve transmission reliability. Therefore, how to build a new network data flow risk monitoring system to achieve accurate identification of data types, rapid tracking of data circulation, and efficient disposal of risk identification has become a key problem to be solved.
[0043] Based on this, the embodiment of the present application provides a network data management method, which solves the problems in existing network data governance by using a multi-layer label identification technology that fuses multi-dimensional information such as data, identity, network, and a network data governance technology architecture, realizes the whole life cycle management of data from generation, transmission to storage and processing, and applies the label identification technology to the compliance verification of data, builds an automated compliance detection system to reduce management cost and complexity, and improves the efficiency and security of data circulation.
[0044] The network data management method provided by the embodiment of the present application can be applied to an application environment as shown in Figure 1 The supervision gateway 102 communicates with the client 104 and the supervision platform 106 through the network. The supervision gateway 102 is used to receive the network data transmitted by the client 104. The network data carries a label identification, which includes a data label identification and a network label identification. The data label identification is used to represent the source information of the network data, and the network label identification is used to represent the network service information of the network data. The network data is parsed, and the compliance of the network data is verified according to the label identification obtained by the parsing. If the compliance verification is passed, the network data after the label is removed is transmitted to the next hop routing according to the network label identification in the label identification and the addressing result. The management code is generated according to the label identification, and the management code is reported to the supervision platform 106 to instruct the supervision platform 106 to manage the circulation path of the network data according to all the management codes reported by the network data in the transmission process. The management code includes the upstream and downstream gateway information of the current supervision gateway.
[0045] In an exemplary embodiment, as shown in Figure 2 A network data management method is provided, and the method is applied to Figure 1The regulatory gateway 102 in the network environment is taken as an example to illustrate the method, including the following steps 202 to 208. Among them:
[0046] S202: receiving network data transmitted by the client; the network data carries a label identifier, the label identifier including a data label identifier and a network label identifier, the data label identifier being used to represent source information of the network data, and the network label identifier being used to represent network service information of the network data.
[0047] Optionally, before the client transmits the network data, a corresponding label identifier is generated according to a unified label identifier generation rule, which is fused with an identity, content and network label identifier. For example, for the identity identifier part, the sender of the data (such as a specific enterprise, department, etc.) is taken as a part of the source information in the data label identifier, and for the network label identifier part, the network label identifier is generated according to the required network bandwidth, transmission priority and other contents reflecting the network service information. In addition, the label identifier also includes an identifier prefix, through which compatibility with the industrial internet identifier system can be realized, and the universality in a wider network environment is ensured. It should be noted that the label identifier is generated according to a unified coding specification, for example, binary coding, XML coding, database field storage, etc., which can ensure the compatibility and operability of the label identifier in different storage and transmission scenarios, so that the label identifier carried by the network data transmitted by the client can accurately convey the source information and network service information contained therein in a suitable coding form, facilitating the processing of subsequent links.
[0048] Optionally, under different network transmission requirements, the label identifier can be bound to the network data in three modes of embedding, encapsulation and separation, so that the label identifier can be stably combined with the network data and transmitted to the receiving end (i.e. the regulatory gateway) together with the network data, so that the network data received by the regulatory gateway can carry a complete and rule-compliant label identifier to accurately reflect the source and network service related information.
[0049] S204: analyzing the network data, and performing compliance verification on the network data according to the label identifier obtained by the analysis.
[0050] Optionally, the regulatory network parses the label identification carried by the network data, extracts the data label identification and the network label identification, and checks the compliance of the network data. When checking, the parsed label identification can be compared with a unified label template provided by a label identification standard library covering various data types, sensitivity levels, and compliance requirements to check the compliance. For example, the source of the data (reflected by the data label identification) is checked to see if it is a legal and compliant source and whether it meets the management requirements for data of the corresponding sensitivity level. For network service information (reflected by the network label identification), it is checked to see if the requirements are within the allowed range and whether they meet the relevant standards for network resource allocation and management. At the same time, the label identification has a security protection mechanism, and its integrity and confidentiality are protected by encryption technology and digital signature, ensuring that the label identification relied on when checking is unaltered and authentic, so that the compliance of the network data can be accurately determined.
[0051] S206: In the case where the compliance check passes, routing addressing is performed according to the network label identification in the label identification, and the network data after label removal (i.e., the network data without the label identification) is transmitted to the next hop routing according to the addressing result.
[0052] Optionally, when the compliance check passes, routing addressing is performed according to the network label identification in the data label identification, where the network label identification can indicate where the data should be forwarded, and the regulatory gateway can find the next hop routing according to this information and transmit the network data after label removal (i.e., the network data without the label identification) to the next hop routing.
[0053] S208: A management code is generated according to the label identification, and the management code is reported to the regulatory platform to instruct the regulatory platform to manage the circulation path of the network data according to all the management codes reported by the network data during the transmission process. The management code includes the upstream and downstream gateway information of the current regulatory gateway.
[0054] Optionally, when the network data passes through the regulatory gateway, the regulatory network generates a management code according to the data label identification, where the management code contains the upstream and downstream gateway information of the current regulatory gateway. The regulatory gateway reports the management code to the regulatory platform, and the regulatory platform manages the circulation path of the network data by collecting all the management codes reported by the network data during the transmission process. For example, the regulatory platform can track all the gateways through which the network data passes, thereby achieving comprehensive management of the data circulation path.
[0055] In the network data management method, by fusing multi-dimensional information such as data content, sender identity, network demand, a multi-layer label identifier is formed, and the compliance of network data is verified according to the label identifier, which can prevent unauthorized data transmission, ensure network security, realize whole life cycle management of data from generation, transmission to storage and processing, and when the network data passes through the supervision gateway, the upstream and downstream gateway information is reported to the supervision platform through the supervision gateway, so that the supervision platform can trace the circulation path of the network data according to all the gateway information in the transmission process, ensure the traceability of the data flow process, and improve the efficiency and security of data circulation.
[0056] In an exemplary embodiment, the data label identifier includes data source encoding, data content encoding, and supervision identifier; the data source encoding is obtained by registration according to the identity information of the data sender; the data content encoding is obtained by identifying the network data through the combination of the large model and the small model; and the supervision identifier is determined according to the sensitive information in the network data.
[0057] Optionally, in the whole data label identifier system, the data source encoding is a key identifier for clearly indicating where the data comes from, wherein the data source encoding is generated by information registration of the data sender, and is used to represent the identity of the data source device and user. For example, in a telecommunications business, it can be embodied as specific information such as customer number, device number, service type, etc. The sender registers its own identity information in the corresponding system according to certain rules and processes, and the system generates a unique data source encoding according to these registration contents, thereby clearly marking the source of the data, providing a basis for subsequent data traceability, management, and compliance judgment.
[0058] Specifically, since data often has significant business characteristics, the knowledge formed after learning a large amount of business data by an AI large model can quickly preliminarily identify the type of data and determine the business category to which the data belongs. After the large model completes the preliminary identification of the data type, the AI small model can further classify the result identified by the large model according to more detailed rules and simple judgment logic. When encoding the data content, an automatic algorithm can be used to flexibly select different analysis models according to the complexity of the data, such as sensitive word matching, self-training NLP model, large model analysis, etc. Through these different analysis methods and the AI large and small model fusion technology, not only the specific type of data can be accurately determined, but also the classification and grading of the data, the timeliness characteristics, the network service demand, the transmission security level, and other aspects can be further analyzed, and finally the data content encoding is formed to comprehensively and accurately reflect the actual content characteristics of the network data.
[0059] Further, the network data may contain different degrees of sensitive information, and the regulatory identifier is determined according to these sensitive information. Through the AI large model fusion technology, the regulatory gateway can automatically identify sensitive information and its quantity. For example, through deep scanning analysis of network data, the semantic understanding ability of the large model and the rule-based investigation ability of the small model are used to accurately find sensitive content related to privacy.
[0060] For example, according to the current regulatory setting of the sensitive information quantity range, such as 1 million sensitive information, 1 million-100 thousand, 100 thousand, etc. Different magnitudes, respectively confirm the regulatory methods required for review, record and authentication license, and mark the corresponding regulatory requirements as regulatory identifiers. Based on this, the regulatory identifier can reflect the rules and measures that need to be followed in the regulatory level for this network data, providing clear guidance for subsequent data compliance management and regulatory processing at different stages.
[0061] In this embodiment, the data source code is obtained by registering the identity information of the data sender, which can clearly identify the source of the network data, and then quickly locate the data sender through the data source code. The data content code is obtained by using the combination of large model and small model for data recognition, which can realize accurate classification of data, so that the data can be effectively regulated through the data tag identifier, and the data transmission security is ensured.
[0062] In an exemplary embodiment, the network tag identifier includes a service identifier and a transmission identifier; the service identifier is obtained according to the resource demand degree of the network data; and the transmission identifier is obtained by consistent marking of the data content code and the regulatory identifier at the network layer.
[0063] Optionally, the service identifier in the network tag identifier is determined based on the demand degree of various resources in the transmission process of the network data. Different network data has different demands for network resources such as bandwidth, delay, processing capacity, etc. due to the differences in their own characteristics and application scenarios. Through multi-level analysis of device type, service demand, transmission data, etc., the network data is classified according to its demand degree for different resources, and is mapped to different service types, so as to obtain the corresponding service identifier.
[0064] Optionally, the transmission identifier needs to refer to the data content code and the regulatory identifier in the data domain, wherein the data content code is obtained by combining the large model and the small model to identify the network data, which contains the feature description of the data itself, such as data type, classification and grading information, and the regulatory identifier is determined according to the sensitive information in the network data, which reflects the requirements and characteristics of the data in the regulatory aspect.
[0065] Further, at the network layer, the data content encoding and regulatory identification are consistent marked, that is, to ensure the accuracy and consistency of these identifications in network transmission. Through consistent marking, the transmission identification in the network tag identification is generated, which is used for more accurate management and control of data in network transmission.
[0066] As shown in the examples, Figure 3 Figure 3 The generation system of the tag identification, wherein, in the data domain, data analysis is performed by combining large models and small models to generate data tag identification, and then data payload is carried and processed at the application layer of the network to ensure that the data can be correctly transmitted and processed at the application layer. The data tag identification includes device object attributes (i.e., the sender device of network data), content resource attributes (i.e., network data resources), and application service attributes (i.e., application service requirements). The device object attributes include device type, serial number, manufacturer, and other information, which are used to uniquely identify devices in the network. The device type determines the function and application scenario of the device, the serial number is used to distinguish different devices of the same type, and the manufacturer information is used to represent the source and quality of the device. The content resource attributes include resource name, resource type, version information, and other content, which are used to describe the content resources in the network. The resource name and type facilitate the classification and search of resources, and the version information is used for resource update and management. The application service attributes include service name, service type, security level, and other information, which are used to describe the application services in the network. The service name and type help users identify and select services, and the security level reflects the protection level of the service in terms of data protection and privacy.
[0067] Further, in the network domain, resource awareness is performed through telemetry technology and device interface interaction, network label identification is generated, and then the network label identification is further extended and applied on the basis of IPv6. The network label identification includes network link state, computing power facility state, and storage service state. The network link state includes bandwidth, connected devices, device load, and identification generation, and is used to describe the characteristics of network connection. For example, the bandwidth of the network determines the upper limit of the data transmission speed, the number and type of connected devices affect the network topology and management method, the device load reflects the busy degree of network devices, and the identification generation may be related to the identity of network devices. The computing power facility state includes computing power type, computing power location, device load, and identification generation. The computing power type and location are crucial for understanding the distribution of computing resources in the network. Different types of computing power facilities (such as CPU, GPU, etc.) are suitable for different computing tasks, and their locations affect the efficiency and delay of data processing. The device load also reflects the usage of computing power facilities, and the identification generation may be used to uniquely identify these computing power facilities. The storage service state includes device type, read-write speed, remaining space, and identification generation. The device type includes the medium and performance characteristics of storage, the read-write speed affects the efficiency of data storage and reading, the remaining space reflects the availability of storage resources, and the identification generation is used to identify storage devices.
[0068] In this embodiment, the network resources can be reasonably allocated through the service identification, and the efficiency of network data transmission can be ensured. The data content is encoded and supervised, and the consistency is marked at the network layer. Since the data content encoding reflects the characteristics of the data itself, and the supervision identification reflects the sensitivity and supervision requirements of the data, the consistency marking at the network layer can ensure the integrity and security of the data in the transmission process.
[0069] In an exemplary embodiment, the label identification is obtained by sequentially marking the authorization supervision layer, marking the application layer, marking the network layer, and encapsulating the identification network.
[0070] As shown in Figure 4 , the label identification is obtained by sequentially marking the authorization supervision layer, marking the application layer, marking the network layer, and encapsulating the identification network. Figure 4The encapsulation process schematic diagram for the tag identification, wherein the authorized supervision layer marking includes rule identification, standard contract, Hash certificate, digital certificate, verification information, reserved coding and authorization Token, etc. The authorized supervision layer mainly processes the tag identification from the supervision and authorization perspective, to ensure the legality and security of the data, wherein the identifications are performed at the data content level, to ensure the legality, security and integrity of the data, and are also important parts of the data tag identification generation. The application layer marking is used to map the data content to higher level identifications, including country code, industry code, enterprise code, supervision code, sender identification, receiver identification, data resource attribute, data service attribute, data security attribute, data application attribute, data reserved coding, data content, etc. The network tag identification generation result is mapped to the data tag identification in this layer, so that the data can be correctly identified and processed in the application layer. Then, the network layer marking is performed through the tag identification mapping, wherein the network layer marking includes source network identity identification, destination network identity identification, network layer service attribute, network layer security attribute, network layer transmission identification, network layer verification credential and reserved coding, payload, etc. These identifications are key parts of the network tag identification generation, to ensure that the data in the network can be correctly identified, routed and processed. Finally, the identification network encapsulation is performed through the identity location mapping, wherein the identification network encapsulation includes source network location identification and next hop network location identification, which is a basic part of the network domain tag identification generation, mainly focusing on the location information in the network.
[0071] By Figure 4 It can be known that the network tag identification generation is the basis, which starts from the network location identification at the bottom layer, and gradually adds network identity, service attribute, security attribute, etc. to provide basic identification and guarantee for the data transmission in the network. The data tag identification generation is the upper application, which adds data content related identifications based on the network tag identification generation result at a higher level, to ensure the correct identification, processing and security of the data in the application layer. The network tag identification generation and the data tag identification generation are associated with each other at each level, from the network location to the data content, to jointly ensure the correct transmission and processing of the data in the network and application.
[0072] In this embodiment, the tag identification is obtained through multi-layer encapsulation. In the multi-layer encapsulation process, the data can be safely processed at different levels, to prevent the data from being stolen or tampered during the transmission process, and to improve the security of the network data transmission.
[0073] In an exemplary embodiment, the step of performing compliance verification on the network data according to the parsed label identifier includes: when the regulatory gateway is in an online state, performing consistency verification on the parsed label identifier, and when the consistency verification passes, performing compliance verification on the network data according to the label identifier; when the regulatory gateway is in an offline state, performing compliance analysis on the network data and the label identifier based on big data.
[0074] Optionally, when the regulatory gateway is in an online state, consistency verification is performed on the parsed label identifier to determine whether the label identifier remains consistent at each link, and if the consistency verification passes, compliance verification is performed on the network data according to the label identifier, wherein the compliance verification determines whether the network data complies with the regulations according to the relevant information in the label identifier. For example, for a data label identifier, if the data source code does not comply with the registration information, or the data type in the data content code does not match the actual data type, or the regulatory identifier indicates that the data involves sensitive information but no corresponding processing measures are taken, it will be determined as non-compliant. For a network label identifier, if the network resources required by the service identifier do not match the actual provided network resources, or the transmission identifier does not comply with the security control requirements of the network layer, it will also be considered as non-compliant.
[0075] Optionally, when the regulatory gateway is in an offline state, real-time consistency verification on the label identifier cannot be performed, and at this time, compliance analysis is performed on the network data and the label identifier based on big data. For example, by learning a large amount of historical compliance data, a data model is established, and when offline network data arrives, the model is used to analyze whether the label identifier and the data content of the network data comply with the compliance requirements.
[0076] In this embodiment, through the consistency verification and compliance verification in the online state, tampering behavior of the data in the transmission process can be found in time, and the integrity and security of the data are ensured, and through the compliance analysis based on big data in the offline state, the transmission security of the network data can be further ensured.
[0077] In an exemplary embodiment, the method further includes: capturing traffic data of the network data in the transmission process by a regulatory probe; obtaining a label identifier of the traffic data; and performing transmission reliability verification on the network data according to the label identifier of the traffic data and the label identifier of the network data.
[0078] Optionally, a supervision probe is deployed in the network to capture traffic data of the network data in the transmission process. For example, in an enterprise network, the supervision probe can be set at key network nodes such as gateways, core switches, etc. to comprehensively monitor the transmission of network data. The captured traffic data contains various information in the network data transmission process, such as packet size, transmission time, source IP address, destination IP address, transmission protocol, etc., reflecting the actual transmission state of the network data in the network.
[0079] Further, the tag identifier is obtained from the captured traffic data, and the network data is subjected to transmission reliability verification according to the tag identifier of the traffic data and the tag identifier of the network data itself, to prevent unauthorized transmission and processing. The transmission reliability verification usually includes data integrity verification (such as whether the data is tampered with during transmission), data transmission path verification (such as whether it is transmitted according to the required path of the tag identifier), network resource matching verification (such as whether the required network resources such as bandwidth, delay, etc. of the tag identifier are obtained), etc.
[0080] In this embodiment, through the verification of transmission reliability, it can be found whether the network data is tampered with during transmission, so as to guarantee the security and integrity of the data.
[0081] In an exemplary embodiment, as shown in Figure 5 A network data management architecture is provided, in which business party A and business party B both have business servers containing important data and personal information, which are managed and displayed through a data asset map. The data asset map can help understand the distribution and attributes of the data. In addition, business party A and business party B both have data flow gateways responsible for data inflow and outflow, ensuring the safe transmission of data within and outside the unit. Each unit also has a policy management module for formulating and managing data processing and circulation policies to ensure that data operations comply with internal regulations and requirements. The data in business party A and business party B flows to the identification network through the data flow gateway, and the data is marked with "trusted subject tag identification flow" during data outflow, which helps the identification network identify the source and reliability of the data.
[0082] After receiving data from Business A and Business B, the Identification Network performs multi-layered tagging, including data content tagging, application layer tagging, and network layer tagging. These tags are used to classify, manage, and protect the data. Data is also encrypted within the Identification Network to ensure security. Simultaneously, data flow within the Identification Network is monitored and managed to prevent data leakage and misuse. The Identification Network is connected to the internet and interacts with external systems through a regulatory gateway. This gateway is responsible for compliance checks and management of data entering and leaving the Identification Network, ensuring that data flow complies with relevant laws and regulations. Furthermore, the Identification Network is connected to a compliance monitoring system, which oversees data operations and circulation within the Identification Network, ensuring the compliance of the entire data management process.
[0083] When data flows from the tagging network to the internet, it undergoes processes such as tag removal, traffic identification, and tag verification to ensure its security and accuracy during the outflow process. Simultaneously, the data also undergoes heterogeneous computing power scheduling and DPU traffic probe monitoring during outflow to optimize data transmission and prevent abnormal data outflow.
[0084] Data flowing into the Identification Network from the Internet undergoes CA authentication and identifier resolution to ensure its legality and reliability. After entering the Identification Network, external data is also tagged accordingly and undergoes compliance checks and management to ensure it meets the network's data management requirements.
[0085] The compliance monitoring system comprehensively oversees data operations and circulation within the identification network. Through functions such as compliance verification, traffic authorization, traceability management, policy management, and source tracking, it ensures that data management within the identification network complies with relevant laws and regulations. Furthermore, the compliance monitoring system works closely with the monitoring gateway to strictly monitor data entering and leaving the identification network, preventing unauthorized data operations and leaks.
[0086] For example, such as Figure 6 As shown, Figure 6 This diagram illustrates the tag quality assessment for a regulatory gateway. The tag quality assessment involves evaluating accuracy, coverage, consistency, and business relevance, and mainly includes three parts: tag resolution, large-scale tag traffic verification engine, and data management.
[0087] The tag identifier parsing includes:
[0088] (1) The label identification resolution system is the starting point of the whole process. It is responsible for registration, resolution and data management. Through this system, basic operations on label identification can be realized.
[0089] (2) Heterogeneous label identification interoperability mechanism: Ensures that different structures of label identification can interoperate and convert. Through mutual recognition operation, the compatibility problem between different identification systems (such as standard identification system and heterogeneous identification system) is solved.
[0090] (3) Complete label identification coding rule: Based on label identification traffic and NIC (DU) and other information, a complete label identification coding rule is formulated to ensure the accuracy and integrity of the label identification.
[0091] Among them, the large-scale identification traffic includes:
[0092] (1) Heterogeneous data label identification verification model: used for processing the original user data and label identification data content verification model, and verifying the label identification through automatic language understanding, image, voice recognition and other methods.
[0093] (2) Consistency verification: based on the results generated by the label identification, consistency verification is performed to check whether the label identification remains consistent at different links.
[0094] (3) De-identification and data processing: after the consistency verification passes, de-identification processing is performed, the de-identified data is output, and supervision side evidence collection, accountability and big data analysis are supported.
[0095] Among them, data management includes:
[0096] (1) Execution and record: records the execution time, whether the execution is successful or not, and other information, and manages the identity, content depth verification, security level and other information.
[0097] (2) Result storage and analysis: store the results in the database and perform big data analysis. This helps to evaluate the quality and effectiveness of the label identification.
[0098] In this embodiment, by fusing multi-dimensional information such as data content, sender identity, network demand, etc., multi-layer label identification is formed, and the compliance of network data is verified according to the label identification, which can prevent unauthorized data transmission, protect network security, realize the whole life cycle management of data from generation, transmission to storage and processing, and when the network data passes through the supervision gateway, the upstream and downstream gateway information is reported to the supervision platform through the supervision gateway, so that the supervision platform can trace the flow path of the network data according to all the gateway information in the transmission process, ensure the traceability of the data flow process, and improve the efficiency and security of the data flow.
[0099] It should be understood that although the steps in the flowcharts involved in the above embodiments are shown in sequence according to the arrows, the steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, the execution of the steps is not strictly limited in sequence, and the steps can be executed in other orders. Moreover, at least some of the steps in the flowcharts involved in the above embodiments can include multiple steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution order of the steps or stages is not necessarily sequential, but can be alternately executed with other steps or steps or stages in other steps.
[0100] Based on the same inventive concept, the embodiments of the present application also provide a network data management device for implementing the above-mentioned network data management method. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme described in the above method, so the specific limitations in one or more network data management device embodiments provided below can refer to the limitations of the network data management method described above, which will not be repeated here.
[0101] In one exemplary embodiment, as shown in Figure 7 A network data management device is provided, comprising: a receiving module 10, a verification module 20, a transmission module 30 and a management module 40, wherein:
[0102] The receiving module 10 is configured to receive network data transmitted by a client; the network data carries a label identifier, the label identifier comprising a data label identifier and a network label identifier, the data label identifier being used to represent source information of the network data, and the network label identifier being used to represent network service information of the network data.
[0103] The verification module 20 is configured to parse the network data, and perform compliance verification on the network data according to the parsed label identifier.
[0104] The transmission module 30 is configured to, in the case that the compliance verification is passed, perform routing addressing according to the network label identifier in the label identifier, and transmit the network data after label removal to a next hop routing according to an addressing result.
[0105] The management module 40 is configured to generate a management code according to the label identifier, and report the management code to a supervision platform, so as to instruct the supervision platform to manage a circulation path of the network data according to all management codes reported by the network data in a transmission process; the management code comprising upstream and downstream gateway information of a current supervision gateway.
[0106] In an example embodiment, the data tag identification involved in the receiving module 10 includes data source coding, data content coding and regulatory identification; the data source coding is registered according to the identity information of the data sender; the data content coding is obtained by identifying the network data through the combination of the large model and the small model; and the regulatory identification is determined according to the sensitive information in the network data.
[0107] In an example embodiment, the network tag identification involved in the receiving module 10 includes service identification and transmission identification; the service identification is obtained according to the resource demand degree of the network data; and the transmission identification is obtained by marking the consistency of the data content coding and the regulatory identification at the network layer.
[0108] In an example embodiment, the tag identification involved in the receiving module 10 is obtained by the authorization regulatory layer marking, the application layer marking, the network layer marking and the identification network encapsulation in sequence.
[0109] In an example embodiment, the checking module 20 is further configured to, when the regulatory gateway is in an online state, perform consistency checking on the parsed tag identification, and when the consistency checking is passed, perform compliance checking on the network data according to the tag identification; and when the regulatory gateway is in an offline state, perform compliance analysis on the network data and the tag identification based on big data.
[0110] In an example embodiment, the management module 40 is further configured to capture traffic data of the network data in the transmission process through the regulatory probe; obtain the tag identification of the traffic data; and perform transmission reliability checking on the network data according to the tag identification of the traffic data and the tag identification of the network data.
[0111] The above-mentioned various modules in the network data management device can be realized by software, hardware and combinations thereof in whole or in part. The above-mentioned various modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory in the computer device in software form, so as to be called and executed by the processor to perform the operations corresponding to the above-mentioned various modules.
[0112] In an example embodiment, a computer device is provided, which can be a server, and the internal structure diagram thereof can be as shown in Figure 8As shown in the figure. The computer device includes a processor, a memory, an Input / Output (I / O) interface and a communication interface. Among them, the processor, the memory and the input / output interface are connected through the system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capability. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store network data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through network connection. The computer program is executed by the processor to implement a network data management method.
[0113] Those skilled in the art can understand that, Figure 8 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different component arrangement.
[0114] In one exemplary embodiment, a computer device is provided, comprising a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the following steps: receiving network data transmitted by a client; the network data carrying a label identification, the label identification including a data label identification and a network label identification, the data label identification being used to represent the source information of the network data, and the network label identification being used to represent the network service information of the network data; parsing the network data, and performing compliance verification on the network data according to the label identification obtained by parsing; in the case that the compliance verification is passed, performing routing addressing according to the network label identification in the label identification, and transmitting the network data after label removal to the next hop routing according to the addressing result; generating a management code according to the label identification, and reporting the management code to a supervision platform to instruct the supervision platform to manage the circulation path of the network data according to all the management codes reported by the network data in the transmission process; the management code including the upstream and downstream gateway information of the current supervision gateway.
[0115] In one embodiment, the data label identification involved when the processor executes the computer program includes a data source code, a data content code and a supervision identification; the data source code is obtained by registration according to the identity information of the data sender; the data content code is obtained by identifying the network data through the combination of a large model and a small model; and the supervision identification is determined according to the sensitive information in the network data.
[0116] In one embodiment, the network tag identification involved when the processor executes the computer program includes a service identification and a transmission identification; the service identification is obtained according to the resource requirement degree of the network data; and the transmission identification is obtained by consistent marking at the network layer through encoding and supervision identification of the data content.
[0117] In one embodiment, the tag identification involved when the processor executes the computer program is obtained in sequence through authorization supervision layer marking, application layer marking, network layer marking and identification network encapsulation.
[0118] In one embodiment, the compliance verification of the network data according to the parsed tag identification when the processor executes the computer program includes: in the case that the supervision gateway is in an online state, performing consistent verification on the parsed tag identification, and in the case that the consistent verification is passed, performing compliance verification of the network data according to the tag identification; in the case that the supervision gateway is in an offline state, performing compliance analysis of the network data and the tag identification based on big data.
[0119] In one embodiment, the processor executing the computer program further implements the following steps: capturing traffic data of the network data in the transmission process through a supervision probe; obtaining the tag identification of the traffic data; and performing transmission reliability verification of the network data according to the tag identification of the traffic data and the tag identification of the network data.
[0120] In one embodiment, a computer readable storage medium is provided, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to implement the following steps: receiving network data transmitted by a client; the network data carries a tag identification, and the tag identification includes a data tag identification and a network tag identification, the data tag identification is used to represent source information of the network data, and the network tag identification is used to represent network service information of the network data; performing analysis on the network data, and performing compliance verification of the network data according to the parsed tag identification; in the case that the compliance verification is passed, performing routing addressing according to the network tag identification in the tag identification, and transmitting the network data after the tag is removed to a next hop routing according to the addressing result; generating a management code according to the tag identification, and reporting the management code to a supervision platform to instruct the supervision platform to manage the circulation path of the network data according to all the management codes reported by the network data in the transmission process; and the management code includes upstream and downstream gateway information of a current supervision gateway.
[0121] In one embodiment, the data tag identification involved when the computer program is executed by the processor includes data source coding, data content coding and supervision identification; the data source coding is obtained according to the identity information of the data sender; the data content coding is obtained by identifying the network data through the combination of a large model and a small model; and the supervision identification is determined according to sensitive information in the network data.
[0122] In one embodiment, the network tag identification involved when the computer program is executed by the processor includes a service identification and a transmission identification; the service identification is obtained according to the resource requirement degree of the network data; and the transmission identification is obtained by marking the network layer consistently through encoding and supervision identification of the data content.
[0123] In one embodiment, the tag identification involved when the computer program is executed by the processor is obtained in sequence through authorization supervision layer marking, application layer marking, network layer marking and identification network encapsulation.
[0124] In one embodiment, the compliance verification of the network data according to the parsed tag identification when the computer program is executed by the processor includes: in the case that the supervision gateway is in an online state, performing consistency verification on the parsed tag identification, and in the case that the consistency verification is passed, performing compliance verification of the network data according to the tag identification; in the case that the supervision gateway is in an offline state, performing compliance analysis of the network data and the tag identification based on big data.
[0125] In one embodiment, the computer program executed by the processor further implements the following steps: capturing traffic data of the network data in the transmission process through a supervision probe; obtaining the tag identification of the traffic data; and performing transmission reliability verification of the network data according to the tag identification of the traffic data and the tag identification of the network data.
[0126] In one embodiment, a computer program product is provided, including a computer program, which, when executed by a processor, implements the following steps: receiving network data transmitted by a client; the network data carrying a tag identification, the tag identification including a data tag identification and a network tag identification, the data tag identification being used to represent source information of the network data, and the network tag identification being used to represent network service information of the network data; parsing the network data, and performing compliance verification of the network data according to the parsed tag identification; in the case that the compliance verification is passed, performing routing addressing according to the network tag identification in the tag identification, and transmitting the network data after the tag is removed to a next hop routing according to the addressing result; generating a management code according to the tag identification, and reporting the management code to a supervision platform, so as to instruct the supervision platform to manage the circulation path of the network data according to all the management codes reported by the network data in the transmission process; and the management code including upstream and downstream gateway information of a current supervision gateway.
[0127] In one embodiment, the data tag identification involved when the computer program is executed by the processor includes data source coding, data content coding and supervision identification; the data source coding is obtained by registration according to identity information of a data sender; the data content coding is obtained by identification of the network data through combination of a large model and a small model; and the supervision identification is determined according to sensitive information in the network data.
[0128] In one embodiment, the network tag identification involved when the computer program is executed by the processor includes a service identification and a transmission identification; the service identification is obtained according to the resource requirement degree of the network data; and the transmission identification is obtained by consistent marking at the network layer through encoding and supervision identification of the data content.
[0129] In one embodiment, the tag identification involved when the computer program is executed by the processor is obtained by, in sequence, marking at the authorization supervision layer, marking at the application layer, marking at the network layer, and identification network encapsulation.
[0130] In one embodiment, the compliance verification of the network data according to the parsed tag identification when the computer program is executed by the processor includes: in the case that the supervision gateway is in an online state, performing consistent verification on the parsed tag identification, and in the case that the consistent verification is passed, performing compliance verification of the network data according to the tag identification; and in the case that the supervision gateway is in an offline state, performing compliance analysis of the network data and the tag identification based on big data.
[0131] In one embodiment, the computer program is executed by the processor to further implement the following steps: capturing traffic data of the network data in the transmission process by a supervision probe; obtaining the tag identification of the traffic data; and performing transmission reliability verification of the network data according to the tag identification of the traffic data and the tag identification of the network data.
[0132] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of the related data need to comply with relevant regulations.
[0133] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when executed, can include the processes of the above-mentioned embodiment methods. Any reference to memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. The non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical storage, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. The volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration but not limitation, the RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The database involved in the embodiments provided in the present application can include at least one of a relational database and a non-relational database. The non-relational database can include a distributed database based on a block chain, etc., without being limited thereto. The processor involved in the embodiments provided in the present application can be a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., without being limited thereto.
[0134] The technical features of the above embodiments can be combined in any manner. To make the description concise, not all possible combinations of the technical features in the above embodiments are described, but as long as the combinations of the technical features do not exist contradictions, they should be considered as the scope of the present application.
[0135] The above-described embodiments are merely illustrative of several embodiments of the present application, and the description is relatively specific and detailed, but should not be understood as a limitation on the scope of the patent. It should be noted that for those skilled in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are all within the scope of the present application. Therefore, the scope of protection of the present application should be subject to the appended claims.
Claims
1. A network data management method characterized by, The method is applied to a regulatory gateway, and comprises the following steps: Receiving network data transmitted by a client; the network data carries a label identifier, which includes a data label identifier and a network label identifier; the data label identifier is used to represent the source information of the network data, and the network label identifier is used to represent the network service information of the network data; the data label identifier includes data source coding, data content coding and regulatory identification; the data source coding is obtained according to the identity information of a data sender; the data content coding is obtained by identifying the network data through a combination of a large model and a small model; the regulatory identification is determined according to sensitive information in the network data; the label identifier is obtained by sequentially passing through authorized regulatory layer marking, application layer marking, network layer marking and identification network encapsulation; the network label identifier includes service identification and transmission identification; the service identification is obtained according to the resource demand degree of the network data; the transmission identification is obtained by performing consistency annotation on the data content coding and the regulatory identification in the network layer; Analyzing the network data, and performing compliance verification on the network data according to the analyzed label identifier; In the case where the compliance verification is passed, performing routing addressing according to the network label identifier in the label identifier, and transmitting the network data after label removal to the next hop routing according to the addressing result; Generating a management code according to the label identifier, and reporting the management code to a regulatory platform, so as to instruct the regulatory platform to manage the circulation path of the network data according to all the management codes reported by the network data in the transmission process; the management code includes upstream and downstream gateway information of the current regulatory gateway.
2. The method of claim 1, wherein, The compliance verification on the network data according to the analyzed label identifier comprises the following steps: In the case where the regulatory gateway is in an online state, performing consistency verification on the analyzed label identifier, and in the case where the consistency verification is passed, performing compliance verification on the network data according to the label identifier; In the case where the regulatory gateway is in an offline state, performing compliance analysis on the network data and the label identifier based on big data.
3. The method of claim 1, wherein, The method further comprises the following steps: Capturing traffic data of the network data in the transmission process through a regulatory probe; Obtaining the label identifier of the traffic data; Performing transmission reliability verification on the network data according to the label identifier of the traffic data and the label identifier of the network data.
4. A network data management apparatus characterized by comprising: The device comprises the following: The receiving module is used for receiving network data transmitted by a client; the network data carries a label identifier, the label identifier includes a data label identifier and a network label identifier, the data label identifier is used for representing source information of the network data, and the network label identifier is used for representing network service information of the network data; the data label identifier includes data source coding, data content coding and supervision identification; the data source coding is obtained according to identity information of a data sender; the data content coding is obtained by identifying the network data by combining a large model and a small model; the supervision identification is determined according to sensitive information in the network data; the label identifier is obtained by sequentially performing label marking of an authorized supervision layer, label marking of an application layer, label marking of a network layer and identifier network encapsulation; the network label identifier includes service identification and transmission identification; the service identification is obtained according to a resource demand degree of the network data; the transmission identification is obtained by performing consistency marking on the data content coding and the supervision identification in the network layer; The checking module is used for analyzing the network data, and performing compliance checking on the network data according to the label identifier obtained by analysis; The transmission module is used for, in the case that the compliance checking is passed, performing routing addressing according to the network label identifier in the label identifier, and transmitting the network data after label removal to a next hop routing according to an addressing result. The management module is used for generating a management code according to the label identifier, and reporting the management code to a supervision platform, so as to instruct the supervision platform to manage a circulation path of the network data according to all management codes reported by the network data in a transmission process; the management code includes upstream and downstream gateway information of a current supervision gateway. 5.A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the computer device is configured to perform the method according to any one of claims 1-4 when the computer program is executed by the processor. The processor executes the computer program to realize the steps of the method in any one of claims 1 to 3.
6. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to realize the steps of the method in any one of claims 1 to 3.
7. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to realize the steps of the method in any one of claims 1 to 3.
Citation Information
Patent Citations
Material equipment management method and device based on block chain and identification analysis technology
CN117034359A
Mining product identification traceability system and method based on block chain
CN117853132A