Procurement data structured processing method and system

Through the combination of dynamic maze storage structure and bait data nodes, the regularity of traditional centralized storage is broken, and through dynamic path reconstruction, the security problem caused by excessive centralization of procurement data storage is solved, significantly improving the security of data and difficulty in illegal access.

CN119903062BActive Publication Date: 2025-05-23STATE GRID ZHEJIANG ELECTRIC POWER CO LTD JINHUA POWER SUPPLY CO +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510379010.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-28
Publication Date
2025-05-23
Estimated Expiration
2045-03-28

AI Technical Summary

Technical Problem

In the prior art, the storage of procurement data is too concentrated, resulting in poor security. Illegal visitors are prone to finding the corresponding supplier or procurement system data through data storage rules, making it less difficult to obtain information.

Method used

Using a dynamic maze storage structure, the procurement data is scattered and mapped to virtual nodes, breaking the regularity of traditional centralized storage, and forming an active defense layer by setting up bait data associated with the topology of real nodes, misleading attackers and consuming their resources. At the same time, dynamic path reconstruction is carried out according to external access situations to ensure the difference in each access.

Benefits of technology

It significantly improves the security of procurement data and increases the difficulty of illegal visitors to locate data. Through the triple mechanism of storage decentralization, path randomization, and data obfuscation, it makes it difficult for attackers to obtain effective information through regular analysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119903062B_ABST
    Figure CN119903062B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of data processing, and discloses a procurement data structured processing method and system, the method comprising: pre-processing the original procurement data through a sandbox environment to generate structured intermediate data with metadata tags; constructing a dynamic maze storage structure in a memory, dividing the structured intermediate data into data fragments and mapping them to maze path nodes to form real data nodes; setting up decoy data nodes to form a topological association with real data nodes; realizing dynamic changes in storage paths through a data jump controller, and verifying visitor permissions and reconstructing paths when responding to external access requests. The present invention maps procurement data to virtual nodes in a dispersed manner through a dynamic maze storage structure, breaking the regularity of traditional centralized storage, forming an active defense layer through decoy data, and dynamically reconstructing paths according to external access conditions, ensuring the difference of each access, increasing the difficulty of illegal visitors to locate data, and improving data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing, and in particular to a procurement data structured processing method and system. Background Art

[0002] The procurement data of an enterprise usually comes from multiple different data sources, including suppliers, procurement systems, and the enterprise's internal ERP system. For the convenience of management, the data of the same supplier or procurement system is usually stored in a centralized manner. However, since this storage method is too regular and the data is too centralized, it is easy for illegal visitors to find the data of the corresponding supplier or procurement system through the data storage regularity and obtain a large amount of valid information in a short time. It can be seen that the security protection measures for the entire procurement data are too fragile in this case.

[0003] Therefore, how to improve the security of procurement data through unique security measures based on the characteristics of procurement data to increase the difficulty for illegal visitors to obtain information is a problem that has not been solved yet. Summary of the invention

[0004] In view of the problem that the procurement data storage in the prior art is too centralized, resulting in poor security, the present invention provides a procurement data structured processing method and system, which maps the procurement data to virtual nodes in a dispersed manner through a dynamic maze storage structure, breaking the regularity of traditional centralized storage and increasing the difficulty of locating illegal access. At the same time, by setting bait data associated with the real node topology, an active defense layer is formed to mislead attackers and consume their resources, and dynamic path reconstruction is performed according to external access conditions to ensure the difference of each access, further increasing the difficulty of illegal visitors to locate data, and solving the security problems existing in the prior art.

[0005] The following is the technical solution of the present invention.

[0006] The method for processing procurement data structure includes the following steps:

[0007] S1: Preprocess the original procurement data through the sandbox environment to generate structured intermediate data with metadata tags;

[0008] S2: Build a dynamic maze storage structure in memory, split the structured intermediate data into data segments and map them to maze path nodes to form real data nodes;

[0009] S3: Set up decoy data nodes to form a topological association with real data nodes;

[0010] S4: The data jump controller is used to dynamically change the storage path, verify the accessor's permissions and reconstruct the path in response to external access requests.

[0011] The present invention pre-processes the procurement data in a sandbox environment, generates metadata tags, realizes strict isolation and standardization of the data input stage, effectively filters the risks of non-standard protocols, and uses a dynamic maze storage structure to disperse and map the data to virtual nodes, breaking the regularity of traditional centralized storage and increasing the difficulty of locating illegal access. At the same time, by setting bait data associated with the real node topology, an active defense layer is formed to mislead attackers and consume their resources, and dynamically reconstructs the path according to the external access situation to ensure the difference of each access, further increasing the difficulty of illegal visitors to locate the data. The overall solution of the present invention uses the triple mechanisms of storage decentralization, path randomization, and data obfuscation to make it difficult for attackers to obtain effective information through regularity analysis.

[0012] Preferably, the S1: preprocessing the original purchase data in a sandbox environment to generate structured intermediate data with metadata tags includes:

[0013] Create a virtualized isolation environment based on QEMU-KVM and configure a dedicated network card to implement physical layer isolation;

[0014] Deploy a two-way traffic mirroring system, set the capacity of the input / output buffer, load predefined security policy templates, and restrict non-standard protocol transmission;

[0015] A three-layer tag tree is constructed, in which the root node marks the data source type, the secondary node marks the data version, and the leaf node stores the operation traces. Metadata tags are dynamically generated and bound to the original content to obtain structured intermediate data.

[0016] Preferably, the S2: constructing a dynamic maze storage structure in the memory, dividing the structured intermediate data into data segments and mapping them to maze path nodes, comprises:

[0017] The logical storage space is divided based on the three-dimensional Cartesian coordinate system, and each coordinate point corresponds to a virtual storage node;

[0018] Define three basic connection relationships: horizontal connection represents cross-supplier, vertical connection represents cross-category, and deep connection represents cross-time, forming a three-dimensional grid.

[0019] Based on the remaining capacity ratio and access frequency coefficient, each node is assigned a dynamic weight value. High-weight nodes are given priority in path construction to form a dynamic maze storage structure.

[0020] According to metadata tags, structured intermediate data is divided into logical blocks according to business dimensions, the entropy value of the data block is calculated, and adaptive sharding is performed based on the high entropy value-fine granularity principle. A timestamp and logical coordinate tag are added to each shard to form a data fingerprint.

[0021] Several routing decision factors and constraints are constructed, and path selection is modeled as an energy minimization problem. The node state corresponds to the energy value. The network is converged to a stable state through iterative calculation, and the optimal path that satisfies multiple factor constraints is output. Virtual coordinates are assigned to each data shard, which are dynamically bound to the physical storage node coordinates through a hash function to achieve decoupling of the logical layer and the storage layer and complete path mapping to form real data nodes.

[0022] Preferably, the step S3: setting a decoy data node to form a topological association with the real data node includes:

[0023] Copy the real data fragment, replace the field, and add fixed marks to obtain the bait data;

[0024] The decoy data of the same supplier is stored in the maze path nodes adjacent to the corresponding real data nodes, forming a topological association between the decoy data nodes and the real data nodes.

[0025] Preferably, the S4: dynamically changing the storage path through the data jump controller, verifying the accessor's authority and reconstructing the path in response to an external access request, includes:

[0026] Extract visitor device fingerprint, access time, and request data type to generate a temporary token;

[0027] Determine the permissions of the temporary token based on the visitor's device fingerprint. If the permissions match the requested data type, extract the path of the real data node from the maze storage structure, otherwise extract the path of the decoy data node;

[0028] After the visit, reconstruct the path.

[0029] Preferably, the reconstruction path includes:

[0030] Extract the associated nodes from the maze storage structure according to the data request type, and randomly select other branch nodes and associated nodes to form a path;

[0031] When reconstructing a path, other branch nodes are replaced to form a new path.

[0032] Preferably, a fuse mechanism is also included: if the path access frequency is greater than a preset frequency or the node response delay is greater than a preset delay, the current path is frozen and a backup path is built.

[0033] The present invention also provides a procurement data structured processing system for executing a procurement data structured processing method, comprising:

[0034] Tagging module: used to pre-process the original procurement data through the sandbox environment and generate structured intermediate data with metadata tags;

[0035] Dynamic storage module: used to build a dynamic maze storage structure in memory, split the structured intermediate data into data segments and map them to maze path nodes to form real data nodes;

[0036] Decoy module: used to set up decoy data nodes and form topological associations with real data nodes;

[0037] Path reconstruction module: used to realize dynamic change of storage path through data jump controller, verify visitor authority and reconstruct path when responding to external access request.

[0038] The present invention also provides an electronic device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the above-mentioned procurement data structured processing method when calling the computer program in the memory.

[0039] The present invention also provides a storage medium, in which computer executable instructions are stored. When the computer executable instructions are loaded and executed by a processor, the steps of the above-mentioned procurement data structured processing method are implemented.

[0040] The substantial effects of the present invention include:

[0041] In the preprocessing stage, a sandbox environment is used to generate structured intermediate data with metadata tags, which realizes strict isolation and normalization of data. By constructing a dynamic maze storage structure, the regularity of traditional centralized storage of procurement data is effectively broken, and the security of data is significantly improved. The bait data nodes are set to form a topological association with the real data nodes, forming an active defense layer, which further enhances the ability to resist illegal access. At the same time, the present invention can dynamically reconstruct the storage path according to the external access situation, ensure the difference of each access, and avoid the security risks brought by fixed paths. In addition, a fuse mechanism is introduced to ensure safe operation under high access frequency or abnormal delay. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 is a flow chart of an embodiment of the present invention. DETAILED DESCRIPTION

[0043] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution will be clearly and completely described below in combination with the embodiments. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0044] It should be understood that in various embodiments of the present invention, the size of the sequence number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0045] It should be understood that in the present invention, "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or apparatus comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to these processes, methods, products or apparatuses.

[0046] It should be understood that in the present invention, "plurality" refers to two or more than two. "And / or" is merely a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the objects associated before and after are in an "or" relationship. "Contains A, B and C", "Contains A, B, C" means that A, B, and C are all included, "Contains A, B or C" means that one of A, B, and C is included, and "Contains A, B and / or C" means that any one, any two, or any three of A, B, and C are included.

[0047] The technical solution of the present invention is described in detail with specific embodiments below. The embodiments may be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments. Example

[0048] Procurement data structured processing methods, such as Figure 1 As shown, the following steps are included:

[0049] S1: Preprocess the original procurement data through the sandbox environment to generate structured intermediate data with metadata tags.

[0050] include:

[0051] S11: Create a virtualized isolation environment based on QEMU-KVM and configure a dedicated network card to implement physical layer isolation.

[0052] Among them, QEMU-KVM is an open source virtualization technology that can run multiple virtual machines on a physical machine. Each virtual machine has its own independent operating system and resources. At the same time, each virtual machine in this embodiment has its own independent network interface, and communication with the external network is strictly controlled to prevent data leakage or tampering.

[0053] S12: Deploy a bidirectional traffic mirroring system, set the capacity of the input / output buffer (set to 1GB / 512MB respectively), load the predefined security policy template (including HTTP / HTTPS protocol whitelist), and limit non-standard protocol transmission.

[0054] S13: Construct a three-layer tag tree, in which the root node marks the data source type (such as supplier API, ERP system), the secondary node marks the data version (such as V1.0-V3.0), and the leaf node stores operation traces (such as operator ID, timestamp). Metadata tags are dynamically generated through the HMAC-SHA256 algorithm, and the metadata tags are bound to the original content to obtain structured intermediate data.

[0055] In this embodiment, if there is a batch of procurement data from supplier A, the version is V1.0. In the preprocessing stage, the system will first put this data into a virtualized isolation environment created based on QEMU-KVM. Then, a two-way traffic mirroring system is deployed to monitor and record the data transmission process between virtual machines. Then, a three-layer label tree is constructed, in which the root node is marked as "supplier A", the secondary node is marked as "V1.0", and the leaf node records various operations of the data during the preprocessing process, such as removing duplicates, filling missing values, etc. Finally, metadata tags are dynamically generated based on this information, and these tags are bound to the original data to generate structured intermediate data.

[0056] S2: Build a dynamic maze storage structure in memory, split the structured intermediate data into data segments and map them to maze path nodes to form real data nodes.

[0057] include:

[0058] S21: Divide the logical storage space based on a three-dimensional Cartesian coordinate system, where each coordinate point corresponds to a virtual storage node.

[0059] In this embodiment, the X-axis of the three-dimensional Cartesian coordinate system: supplier level, divided by supplier cooperation level (0~N level, N is the total number of suppliers), each level corresponds to a logical segment. Y-axis: category depth, divided by the commodity category tree level (such as root category = 0, first-level category = 1, and last-level category = K), the depth is K+1 layer. Z-axis: time axis, based on the timestamp, segmented by the procurement cycle (day / month / year), for example, each day corresponds to a scale unit. Each coordinate point is mapped to a virtual storage node.

[0060] S22: Define three basic connection relationships, with horizontal connection representing cross-supplier, vertical connection representing cross-category, and deep connection representing cross-time, to form a three-dimensional grid.

[0061] Among them, horizontal connections allow jumping across supplier nodes, and the maximum span is set in sequence. Vertical connections only allow jumping between adjacent levels, and deep connections only require one-way connections in chronological order.

[0062] S23: A dynamic weight value is assigned to each node based on the remaining capacity ratio and the access frequency coefficient. High-weight nodes are preferentially involved in path construction to form a dynamic maze storage structure.

[0063] ;

[0064] in, W is the dynamic weight value, C 剩余 is the remaining capacity of the node, C 总 is the total capacity of the node, F is the access frequency, R is the risk level (0-1), a, b, c are the capacity coefficient, frequency coefficient, and risk coefficient respectively.

[0065] S24: Based on the metadata tags, the structured intermediate data is divided into logical blocks according to the business dimension, the entropy value of the data block is calculated, and the sharding is adaptively performed based on the high entropy value-fine granularity principle. A timestamp and logical coordinate tag are attached to each shard to form a data fingerprint.

[0066] The entropy calculation formula of this embodiment is:

[0067] ;

[0068] Among them, H is the entropy value, M is the total number of feature fields, is the probability of occurrence of the kth characteristic field value in the data block. In this embodiment, when H is greater than or equal to 6, the data is fragmented at a granularity of 1KB, corresponding to high-complexity data (such as contract text); when H is less than or equal to 3, the data is fragmented at a granularity of 10KB, corresponding to low-complexity data (such as supplier ID list); the rest are fragmented at a granularity of 5KB, corresponding to medium-complexity data.

[0069] S25: Construct several routing decision factors and constraints, model the path selection as an energy minimization problem, the node state corresponds to the energy value, and the network converges to a stable state through iterative calculation. The optimal path that satisfies the multi-factor constraints is output, and virtual coordinates are assigned to each data shard. The virtual coordinates are dynamically bound to the physical storage node coordinates through a hash function to achieve decoupling of the logical layer and the storage layer and complete the path mapping to form a real data node.

[0070] In this embodiment, the routing decision factors are mainly the risk level R of the node, the path length, etc., and the constraint conditions include security level ≥ access permission threshold (such as risk level needs R ≤0.2), path hop count ≤5 (to prevent delays caused by too long paths), etc.

[0071] The energy value is calculated using the Hopfield network, and the energy function is:

[0072] ;

[0073] in, is the connection weight from node i to j (given by the dynamic weight , calculate), , , indicating whether node i or j is selected, N is the total number of nodes, and θ is the path length penalty coefficient (the default setting is 0.7). The simulated annealing algorithm is used for optimization until the energy function is stable (ΔE<0.01), the iterative convergence is completed, and the activated nodes are arranged in the connection order to generate the path.

[0074] The virtual coordinates (X, Y, Z) of the data shard are directly mapped by its metadata tag (e.g., vendor ID=1001 maps to X=5). The virtual coordinates are calculated using a hash function, and the result is modulo mapped to the actual physical node address to decouple the logic layer from the storage layer and complete the path mapping. After decoupling, the business layer only perceives the virtual coordinates, such as (5,2,20231105), without paying attention to the physical storage location.

[0075] For example, for the data block: 2023-11-05 (coordinate Z=20231105) order data of supplier A (coordinate X=5), the entropy value H=7.2, then the shard granularity is 1KB. After the above steps, the path selection is: starting point (5,0,20231105) through node 3 (W=0.8), node 7 (W=0.9) to the end point (5,2,20231105), with a total weight = 1.7.

[0076] S3: Set up decoy data nodes to form a topological association with real data nodes.

[0077] include:

[0078] S31: Copy the real data fragment, replace the field, and add fixed tags to obtain bait data.

[0079] S32: Storing the decoy data of the same supplier in the maze path nodes adjacent to the corresponding real data nodes, so as to form a topological association between the decoy data nodes and the real data nodes.

[0080] For example, the last two digits of the amount are randomized, the timestamp is offset by ±3 hours, and an invisible mark is added (such as a binary watermark: the CRC checksum is stored in the last 2 bits of every 8th byte), and the storage address of the decoy node is offset by 256KB from the real node.

[0081] S4: The data jump controller is used to dynamically change the storage path, verify the accessor's permissions and reconstruct the path in response to external access requests.

[0082] include:

[0083] S41: Extract the visitor's device fingerprint, access time, and request data type to generate a temporary token.

[0084] S42: Determine the authority of the temporary token according to the visitor device fingerprint, and if the authority matches the requested data type, extract the path of the real data node from the maze storage structure, otherwise extract the path of the decoy data node.

[0085] S43: After the access is completed, the associated nodes are extracted from the maze storage structure according to the data request type, and other branch nodes and associated nodes are randomly selected to form a path.

[0086] S44: When reconstructing the path, other branch nodes are replaced to form a new path.

[0087] For example, extracting device fingerprint (IP+MAC hash) and request type generates a temporary token valid for 45 seconds. Based on the device fingerprint, its access rights can be determined. If the request type includes access requests that exceed the permissions, the path to the decoy data node is extracted. If not, the path to the real data node is extracted.

[0088] This embodiment reconstructs the path after each access to avoid security issues caused by fixed paths.

[0089] This embodiment also includes a fuse mechanism: if the path access frequency is greater than a preset frequency or the node response delay is greater than a preset delay, the current path is frozen and a backup path is built.

[0090] In general, this embodiment pre-processes the procurement data in a sandbox environment, generates metadata tags, achieves strict isolation and standardization of the data input stage, effectively filters non-standard protocol risks, and uses a dynamic maze storage structure to disperse and map data to virtual nodes, breaking the regularity of traditional centralized storage and increasing the difficulty of locating illegal access. At the same time, by setting bait data associated with the real node topology, an active defense layer is formed to mislead attackers and consume their resources, and dynamically reconstructs the path according to the external access situation to ensure the difference of each access, further increasing the difficulty of illegal visitors to locate data. The overall solution of the present invention uses the triple mechanisms of storage decentralization, path randomization, and data obfuscation to make it difficult for attackers to obtain effective information through regularity analysis.

[0091] This embodiment also provides a procurement data structured processing system, which is used to execute the procurement data structured processing method, including:

[0092] Tagging module: used to pre-process the original procurement data through the sandbox environment and generate structured intermediate data with metadata tags;

[0093] Dynamic storage module: used to build a dynamic maze storage structure in memory, split the structured intermediate data into data segments and map them to maze path nodes to form real data nodes;

[0094] Decoy module: used to set up decoy data nodes and form topological associations with real data nodes;

[0095] Path reconstruction module: used to realize dynamic changes of storage paths through data jump controllers, verify visitor permissions and reconstruct paths when responding to external access requests.

[0096] This embodiment also provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the above-mentioned procurement data structured processing method when calling the computer program in the memory.

[0097] This embodiment also provides a storage medium, in which computer executable instructions are stored. When the computer executable instructions are loaded and executed by a processor, the steps of the above-mentioned procurement data structured processing method are implemented.

[0098] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be assigned to different functional modules as needed, that is, the internal structure of the specific device can be divided into different functional modules to complete all or part of the functions described above.

[0099] In the embodiments provided in the present application, it should be understood that the disclosed structures and methods can be implemented in other ways. For example, the embodiments of the structure described above are only schematic. For example, the division of modules or units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another structure, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, structures or units, which can be electrical, mechanical or other forms.

[0100] The units described as separate components may or may not be physically separated, and the components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple different places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0101] In addition, each functional unit in the embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0102] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium, including several instructions to enable a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) to perform all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program code.

[0103] The above contents are only specific implementation methods of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A method for processing procurement data structure, characterized in that: The following steps are involved: S1: Preprocess the original procurement data through the sandbox environment to generate structured intermediate data with metadata tags; S2: Build a dynamic maze storage structure in memory, split the structured intermediate data into data segments and map them to maze path nodes to form real data nodes; S3: Set up decoy data nodes to form a topological association with real data nodes; S4: Dynamically change the storage path through the data jump controller, verify the accessor's permissions and reconstruct the path when responding to external access requests; S2: constructing a dynamic maze storage structure in memory, dividing the structured intermediate data into data segments and mapping them to maze path nodes, including: The logical storage space is divided based on the three-dimensional Cartesian coordinate system, and each coordinate point corresponds to a virtual storage node; Define three basic connection relationships: horizontal connection represents cross-supplier, vertical connection represents cross-category, and deep connection represents cross-time, forming a three-dimensional grid. Based on the remaining capacity ratio and access frequency coefficient, each node is assigned a dynamic weight value. High-weight nodes are given priority in path construction to form a dynamic maze storage structure. According to metadata tags, structured intermediate data is divided into logical blocks according to business dimensions, the entropy value of the data block is calculated, and adaptive sharding is performed based on the high entropy value-fine granularity principle. A timestamp and logical coordinate tag are added to each shard to form a data fingerprint. Construct several routing decision factors and constraints, model the path selection as an energy minimization problem, the node state corresponds to the energy value, and the network converges to a stable state through iterative calculation. Output the optimal path that satisfies the multi-factor constraints, assign virtual coordinates to each data shard, and dynamically bind them to the physical storage node coordinates through a hash function to achieve decoupling of the logic layer and the storage layer and complete path mapping to form a real data node; S4: dynamically changing the storage path through the data jump controller, verifying the accessor's authority and reconstructing the path in response to an external access request, including: Extract visitor device fingerprint, access time, and request data type to generate a temporary token; Determine the permissions of the temporary token based on the visitor's device fingerprint. If the permissions match the requested data type, extract the path of the real data node from the maze storage structure, otherwise extract the path of the decoy data node; After the visit, reconstruct the path.

2. The method for structuring procurement data according to claim 1, characterized in that: S1: Preprocessing the original procurement data in the sandbox environment to generate structured intermediate data with metadata tags, including: Create a virtualized isolation environment based on QEMU-KVM and configure a dedicated network card to implement physical layer isolation; Deploy a two-way traffic mirroring system, set the capacity of the input / output buffer, load predefined security policy templates, and restrict non-standard protocol transmission; A three-layer tag tree is constructed, in which the root node marks the data source type, the secondary node marks the data version, and the leaf node stores the operation traces. Metadata tags are dynamically generated and bound to the original content to obtain structured intermediate data.

3. The method for structuring procurement data according to claim 1, characterized in that: S3: Setting up decoy data nodes to form a topological association with real data nodes, including: Copy the real data fragment, replace the field, and add fixed marks to obtain the bait data; The decoy data of the same supplier is stored in the maze path nodes adjacent to the corresponding real data nodes, forming a topological association between the decoy data nodes and the real data nodes.

4. The method for structuring procurement data according to claim 1, characterized in that: The reconstruction path includes: Extract the associated nodes from the maze storage structure according to the data request type, and randomly select other branch nodes and associated nodes to form a path; When reconstructing a path, other branch nodes are replaced to form a new path.

5. The procurement data structured processing method according to claim 1 or 4, characterized in that: It also includes a fuse mechanism: if the path access frequency is greater than the preset frequency or the node response delay is greater than the preset delay, the current path is frozen and a backup path is built.

6. A procurement data structuring processing system, configured to execute the procurement data structuring processing method according to any one of claims 1 to 5, characterized in that: include: Tagging module: used to pre-process the original procurement data through the sandbox environment and generate structured intermediate data with metadata tags; Dynamic storage module: used to build a dynamic maze storage structure in memory, split the structured intermediate data into data segments and map them to maze path nodes to form real data nodes; Decoy module: used to set up decoy data nodes and form topological associations with real data nodes; Path reconstruction module: used to realize dynamic change of storage path through data jump controller, verify visitor authority and reconstruct path when responding to external access request.

7. An electronic device, characterized in that: It comprises a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the procurement data structured processing method as described in any one of claims 1 to 5 when calling the computer program in the memory.

8. A storage medium, characterized in that: The storage medium stores computer executable instructions, which, when loaded and executed by a processor, implement the steps of the procurement data structuring processing method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • IP spoofing DDoS attack defense method based on active IP record

    CN101383812A

  • Data construction variation algorithm based on node clone

    CN104168161A