Enterprise management software data security protection method and system

By establishing a multi-level metadatabase and access control mechanism in enterprise management software, the data security problem of enterprise management software in cloud office environments is solved, data accuracy and security are achieved, and timely recovery and leakage are prevented.

CN119939636AActive Publication Date: 2025-05-06XINJIANG CHINA ENTERPRISE DIGITAL INFORMATION TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510422099.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-05-06
Estimated Expiration
2045-04-07

AI Technical Summary

Technical Problem

Enterprise management software faces data security issues in cloud office environments, such as phishing attacks, data breaches and unauthorized access, which affects data acquisition and use.

Method used

Using a multi-level data security protection method, a metadatabase is formulated in enterprise management software, including the first parent database, the second parent database, the update database and the child database, and authorized access based on access conditions. When unauthorized network access is detected, the connection between the child database and the external network is closed, and the child database is restored through the first parent database and the second parent database.

Benefits of technology

It effectively avoids data leakage, ensures the accuracy and security of sub-database data, recovers data in a timely manner, and prevents the risks brought by unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939636A_ABST
    Figure CN119939636A_ABST
Patent Text Reader

Abstract

The invention discloses an enterprise management software data security protection method and system, and relates to the technical field of data security, a metadatabase is formulated corresponding to enterprise management software data, and the metadatabase comprises a first mother database, a second mother database, an update library and a sub-database; formulating an access condition corresponding to the metadatabase, and performing authorized access on the enterprise management software data in the sub-database based on the access condition; and when the unauthorized network accesses the sub-database, closing the connection end of the sub-database and the external network, and recovering the sub-database through the first mother database and the second mother database. According to the method, the data accuracy of the sub-database can be ensured, the sub-database can be recovered in time, the security of the data can also be ensured by using the first mother database and the second mother database, and data leakage can be effectively avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a method and system for protecting enterprise management software data security. Background Art

[0002] With the rapid development of network technology, the network environment of enterprise management software is becoming increasingly complex. In the process of enterprise digital transformation, the office mode has shifted from the traditional mode to the cloud office. The cloudification of applications and data has made the browser a new work platform. This has brought about a series of data security issues such as phishing attacks, malware and viruses, privacy tracking and data hijacking, browser security vulnerabilities, insecure web access, internal data leakage risks, and lack of effective access control and auditing, which will affect the normal acquisition and use of data, and will also lead to the leakage of enterprise data. Summary of the invention

[0003] The purpose of the present invention is to provide a method and system for protecting enterprise management software data security to address the deficiencies in the background technology.

[0004] In order to achieve the above object, the present invention provides the following technical solution: a method for protecting enterprise management software data security, comprising the following steps: A metadata database is formulated corresponding to the enterprise management software data, wherein the metadata database includes a first parent database, a second parent database, an update database and a sub-database; The corresponding metadata database sets access conditions, and based on the access conditions, authorizes access to the enterprise management software data in the sub-database; When an unauthorized network accesses the sub-database, the connection between the sub-database and the external network is closed, and the sub-database is restored through the first mother database and the second mother database.

[0005] In a preferred embodiment, the step of formulating a metadata library corresponding to the enterprise management software data includes: In the enterprise platform, a sub-database is established corresponding to the enterprise management software data; The corresponding sub-database is configured with a corresponding first mother database and a second mother database, and the first mother database and the second mother database are connected in communication; An update library is set corresponding to the first mother database and the second mother database, and the update library is communicatively connected with the child database.

[0006] In a preferred embodiment, the corresponding sub-database is configured with a corresponding first mother database and a second mother database, and the step of establishing a communication connection between the first mother database and the second mother database includes: The first database and the second database are configured corresponding to the sub-database, and a cross network is set in the first database and the second database, wherein the cross network is composed of a data grid; A plurality of intersections are arranged on the cross network, and the plurality of intersections are respectively connected to the intersections of the cross network; The cross network and the cross point between the first database and the second database are set in the same way, and the cross points in the first database are matched with the corresponding cross points in the second database; Dividing the enterprise management software data according to the number of intersections to obtain a plurality of unit data, and further dividing the plurality of unit data respectively, each unit data being divided to obtain first data and second data; storing the first data and the second data in corresponding intersections of the first database and the second database respectively; The intersection points in the first database are interchanged to obtain a first mother database, and the intersection points in the second database are interchanged to obtain a second mother database.

[0007] In a preferred embodiment, the step of setting up an update library corresponding to the first mother database and the second mother database and connecting the update library to the sub-database for communication includes: An integration library is set corresponding to the first mother database and the second mother database, a data grid is set in the integration library, and an integration point is set in the data grid; Connecting the integration points to the corresponding intersection points in the first mother database and the second mother database before the intersection points are swapped, to obtain an updated database; Connect the update repository to the sub-database.

[0008] In a preferred embodiment, the corresponding metadata database formulates access conditions, and the step of authorizing access to the enterprise management software data in the sub-database based on the access conditions includes: Access conditions are formulated for the corresponding sub-database, wherein the access conditions include the authorized network port and the corresponding restricted access time period; Based on the access conditions, data access is performed on the sub-database through the authorized network port outside the corresponding restricted access period.

[0009] In a preferred embodiment, the step of restoring the child database through the first mother database and the second mother database includes: The network that does not meet any access condition to access the sub-data is regarded as an unauthorized network; When an unauthorized network accesses the sub-database, the connection between the unauthorized network and the sub-database is cut off, and the enterprise management software data in the sub-database is cleared; The first data and the second data in the first parent database and the second parent database are integrated in the update library, and the enterprise management software data in the child database is restored through the update library.

[0010] In a preferred embodiment, the step of integrating the first data and the second data in the first parent database and the second parent database into an update library, and restoring the enterprise management software data in the child database through the update library includes: Integrate and copy the first data and the second data in the corresponding intersection between the first mother database and the second mother database; The first data and the second data copied according to the multiple intersection points are transmitted to the corresponding integration points in the update library, and the multiple first data and the second data are spliced ​​according to the multiple integration points to obtain the enterprise management software data; Transfer enterprise management software data to the sub-database to complete data recovery.

[0011] The present invention also provides an enterprise management software data security protection system, comprising: A construction module is used to formulate a metadata database corresponding to the enterprise management software data, wherein the metadata database includes a first parent database, a second parent database, an update database and a sub-database; An access module, connected to the construction module, is used to formulate access conditions for the corresponding metadata database and authorize access to the enterprise management software data in the sub-database based on the access conditions; The recovery module is connected to the access module and is used to close the connection between the sub-database and the external network when an unauthorized network accesses the sub-database, recover the sub-database through the first mother database and the second mother database, and obtain the security index of the sub-database, wherein the calculation formula of the security index is: ,in, is the safety index, is the number of times the sub-database is accessed, is a constant greater than zero, It is the interval time between the number of times the sub-database is accessed. It should be noted that the larger the value of the security index is, the lower the security of the sub-database is.

[0012] In the above technical solution, the technical effects and advantages provided by the present invention are: The present invention can integrate the data of the first mother database and the second mother database in the update library, and restore the data of the child database through the update library, which is equivalent to destroying the data in the child database. The data of the child database is rebuilt through the update library. After the child database completes the data recovery, the data in the update library can be cleared and wait for the next use. The data accuracy of the child database can be guaranteed, and the child database can be restored in time. The first mother database and the second mother database used can also ensure the security of the data, and can effectively avoid data leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.

[0014] Figure 1 The figure is a flow chart of the method of the present invention.

[0015] Figure 2 It is a system block diagram of the present invention. DETAILED DESCRIPTION

[0016] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0017] Example 1, please refer to Figure 1 As shown, the enterprise management software data security protection method described in this embodiment includes the following steps: S1. Formulate a metadata database corresponding to the enterprise management software data, wherein the metadata database includes a first parent database, a second parent database, an update database, and a sub-database; S2. formulate access conditions for the corresponding metadata database, and authorize access to the enterprise management software data in the sub-database based on the access conditions; S3. When an unauthorized network accesses the sub-database, the connection between the sub-database and the external network is closed, and the sub-database is restored through the first mother database and the second mother database; As described in the above steps S1-S3, after the sub-database completes the data recovery, the data in the update library can be cleared and wait for the next use. This can ensure the data accuracy of the sub-database and can restore the sub-database in time. The first mother database and the second mother database used can also ensure the security of the data and effectively avoid data leakage.

[0018] In one embodiment, the step S1 of formulating a metadata library corresponding to the enterprise management software data includes: S11. Establish a sub-database corresponding to the enterprise management software data in the enterprise platform; S12, the corresponding sub-database is configured with a corresponding first mother database and a corresponding second mother database, and the first mother database is connected to the second mother database for communication; S13, setting an update library corresponding to the first mother database and the second mother database, and connecting the update library to the sub-database for communication; In one embodiment, the corresponding sub-database is configured with a corresponding first mother database and a second mother database, and step S12 of communication connection between the first mother database and the second mother database includes: S121, configuring a first database and a second database corresponding to the sub-database, and setting a cross network in both the first database and the second database, wherein the cross network is composed of a data grid; S122, setting a plurality of intersections on the cross network, wherein the plurality of intersections are respectively connected to the intersections of the cross network; S123, the intersection network and the intersection point between the first database and the second database are set to be the same, and the intersection point in the first database is matched with the corresponding intersection point in the second database; S124, dividing the enterprise management software data according to the number of intersections to obtain a plurality of unit data, and further dividing the plurality of unit data respectively, each unit data being divided to obtain first data and second data; S125, storing the first data and the second data in corresponding intersections of the first database and the second database respectively; S126, swapping the positions of the intersection points in the first database to obtain a first mother database, and swapping the positions of the intersection points in the second database to obtain a second mother database; In one embodiment, the step S13 of setting an update library corresponding to the first mother database and the second mother database and connecting the update library to the sub-database for communication includes: S131, setting an integration library corresponding to the first mother database and the second mother database, setting a data grid in the integration library, and setting an integration point in the data grid; S132, connecting the integration points to the corresponding intersection points in the first mother database and the second mother database before the intersection points are swapped, to obtain an update database; S133, connecting the update library to the sub-database for communication; As described in the above steps S11-S13, a sub-database is formulated in the enterprise platform corresponding to the enterprise management software data. The sub-database is a database connected to the outside world and can support access to the external network. The sub-database is suitable for daily use to store enterprise management software data, wherein the enterprise management software data includes: for example, basic information of the enterprise: including the name of the enterprise, legal representative, registered address, contact information, etc., which are the identification of the enterprise, generally exist as basic data in the software, and are used for various reports, documents and communication with external organizations. Basic information of employees: such as employee name, ID number, entry time, department, position, etc., are the basic data for the enterprise to carry out human resource management, used for attendance, salary calculation, employee file management, etc. Basic information of customers and suppliers: the name, address, contact person, contact information of the customer, and relevant information of the supplier, etc., are important data for the enterprise to conduct business transactions, used for order management, procurement management, customer relationship maintenance, etc. Approval process settings: stipulates the approval links, approval personnel, approval authority, etc. of various business processes, to ensure that the various business activities of the enterprise are circulated and decided according to the established rules. Price system data: For sales-oriented enterprises, the price list, discount rules, price adjustment records, etc. of products or services are important business rule data, which directly affect the income and profit of the enterprise. Inventory management rules: including safety stock level, replenishment strategy, inventory counting cycle, etc., help enterprises to reasonably control inventory, reduce inventory costs, and ensure the smooth progress of production and sales. Software function permission setting: defines the access rights of different user roles to various functional modules of enterprise management software to ensure data security and standardization of operations. Data storage and backup strategy: specifies the location, storage format, backup cycle, backup storage medium, etc. of data storage to ensure the safe storage and recoverability of enterprise data.Interface configuration information: If the enterprise management software is integrated with other systems, such as financial systems, e-commerce platforms, etc., the interface configuration data includes interface address, communication protocol, data transmission format, etc., to ensure that the data interaction between systems can be carried out stably and accurately. Later, in order to ensure the security of the sub-database data, the sub-database needs to be restored. First, the corresponding first database and second database are configured for the sub-database, and a cross network is set inside the first database and the second database. The cross network here is composed of a data grid, wherein the data grid is a data grid formed by setting multiple virtual nodes in the first database and the second database, and multiple virtual nodes are connected to each other to locate the position of subsequent intersections. Multiple intersections are set in the first database and the second database. The intersection is a virtual machine, and the intersection is connected to the virtual node (the intersection of the cross network). The first database is the same as the second database. The intersection in the first database is matched with the intersection in the corresponding second database. Then, the intersection in the first database is exchanged to obtain the first parent database, and the intersection in the second database is exchanged to obtain the second parent database. Even if the intersection in the first parent database is exchanged, and the intersection in the second parent database is also exchanged, the first parent database and the second parent database are still the same. The correspondence between the original intersections between the libraries still exists. An integrated library is set up corresponding to the first mother database and the second mother database, a data grid is set up in the integrated library, and an integration point is set up in the data grid. The integration point here is a virtual machine that does not store data and is blank. It is used to subsequently integrate the first data and the second data stored in the corresponding intersection. There is no risk of information leakage even if either the first mother database or the second mother database is obtained, because the data in the first mother database and the second mother database are disordered, the intersections have been swapped, and it is impossible to integrate the information of the first mother database and the second mother database, making it difficult to restore the data. And when there is unauthorized network access to the sub-database in the future and there is a risk of data tampering in the sub-database, the data in the first mother database and the second mother database can be copied and integrated in the update library, and the data of the sub-database can be restored through the update library, which is equivalent to destroying the data in the sub-database. The data of the sub-database can be rebuilt through the update library. After the sub-database completes the data recovery, the data in the update library can be cleared and wait for the next use. The data accuracy of the sub-database can be guaranteed, and the sub-database can be restored in time. The first mother database and the second mother database used can also ensure the security of the data and effectively avoid data leakage.

[0019] In one embodiment, the corresponding metadata database formulates access conditions, and the step S2 of authorizing access to the enterprise management software data in the sub-database based on the access conditions includes: S21, formulate access conditions for the corresponding sub-database, wherein the access conditions include the authorized network port and the corresponding restricted access time period; S22, accessing data to the sub-database outside the corresponding restricted access period through the authorized network port based on the access conditions; In one embodiment, the step S3 of restoring the child database through the first mother database and the second mother database includes: S31, treating a network that does not meet any access condition for accessing the sub-data as an unauthorized network; S32. When an unauthorized network accesses the sub-database, the connection between the unauthorized network and the sub-database is cut off, and the enterprise management software data in the sub-database is cleared; S33, integrating the first data and the second data in the first parent database and the second parent database into the update library, and restoring the enterprise management software data in the child database through the update library; In one embodiment, the step S33 of integrating the first data and the second data in the first parent database and the second parent database into the update library and restoring the enterprise management software data in the child database through the update library includes: S331, integrating and copying the first data and the second data in the corresponding intersection between the first mother database and the second mother database; S332, transmitting the first data and the second data copied according to the multiple intersection points to the corresponding integration points in the update library, and splicing the multiple first data and the second data according to the multiple integration points to obtain the enterprise management software data; S333. Transfer the enterprise management software data to the sub-database to complete data recovery.

[0020] As described in the above steps S31-S33, access to the corresponding sub-database is restricted as an access condition, and the access condition includes an authorized network port and a corresponding restricted access period. Therefore, as long as there is a situation where the authorized network port or / and the corresponding restricted access period are not satisfied, the network is regarded as an unauthorized network. When an unauthorized network accesses the sub-database, the connection between the unauthorized network and the sub-database is cut off, and the enterprise management software data in the sub-database is cleared. In order to ensure the accuracy of the data in the sub-database, it is necessary to clear the data in the sub-database that has been accessed by the unauthorized network, and then the first data and the second data in the corresponding intersection between the first mother database and the second mother database are integrated and copied. The integration of the first data and the second data is also the opposite operation of dividing the unit data into the first data and the second data. After the integration The first mother database and the second mother database are copied. There is always a corresponding relationship between the intersections in the first mother database and the second mother database. Even if the positions are deliberately disrupted, the intersections between the first mother database and the second mother database are corresponding in the enterprise platform. The corresponding intersections represent that the stored first data and the second data are the same unit data in the enterprise management software data. The first data and the second data copied according to the multiple intersections are transmitted to the corresponding integration points in the update library. The multiple first data and the second data are spliced ​​according to the multiple integration points to obtain the enterprise management software data. Such data splicing is the opposite operation of dividing the enterprise management software data to obtain multiple unit data. Finally, the enterprise management software data is transmitted to the sub-database to complete the data recovery, which can ensure the normal use of the sub-database, ensure the security of the data, and obtain the security index of the sub-database. The calculation formula of the security index is: ,in, is the safety index, is the number of times the sub-database is accessed, is a constant greater than zero, It is the interval time between the number of times the sub-database is accessed. It should be noted that the larger the value of the security index is, the lower the security of the sub-database is.

[0021] Example 2, please refer to Figure 2 As shown, the enterprise management software data security protection system described in this embodiment includes: A construction module is used to formulate a metadata database corresponding to the enterprise management software data, wherein the metadata database includes a first parent database, a second parent database, an update database and a sub-database; An access module, connected to the construction module, is used to formulate access conditions for the corresponding metadata database and authorize access to the enterprise management software data in the sub-database based on the access conditions; The recovery module is connected to the access module and is used to close the connection between the sub-database and the external network when an unauthorized network accesses the sub-database, and to recover the sub-database through the first mother database and the second mother database.

[0022] The first data and the second data copied according to multiple intersection points are transmitted to the corresponding integration points in the update library, and the multiple first data and the second data are spliced ​​according to the multiple integration points to obtain the enterprise management software data. Such data splicing is the opposite operation of dividing the enterprise management software data to obtain multiple unit data. Finally, the enterprise management software data is transmitted to the sub-database to complete the data recovery, which can ensure the normal use of the sub-database and the security of the data.

[0023] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. A method for protecting enterprise management software data security, characterized in that: The following steps are involved: A metadata database is formulated corresponding to the enterprise management software data, wherein the metadata database includes a first parent database, a second parent database, an update database and a sub-database; Access conditions are formulated for the corresponding metadata database, and authorized access to the enterprise management software data in the sub-database is performed based on the access conditions; When an unauthorized network accesses the sub-database, the connection between the sub-database and the external network is closed, and the sub-database is restored through the first mother database and the second mother database.

2. The enterprise management software data security protection method according to claim 1, characterized in that: The step of formulating a metadata database corresponding to the enterprise management software data includes: In the enterprise platform, a sub-database is established corresponding to the enterprise management software data; The corresponding sub-database is configured with a corresponding first mother database and a second mother database, and the first mother database and the second mother database are connected in communication; An update library is set corresponding to the first mother database and the second mother database, and the update library is communicatively connected with the child database.

3. The enterprise management software data security protection method according to claim 2, characterized in that: The corresponding sub-database is configured with a corresponding first mother database and a second mother database, and the steps of the first mother database and the second mother database being communicated and connected include: The first database and the second database are configured corresponding to the sub-database, and a cross network is set in the first database and the second database, wherein the cross network is composed of a data grid; A plurality of intersections are arranged on the cross network, and the plurality of intersections are respectively connected to the intersections of the cross network; The cross network and the cross point between the first database and the second database are set in the same way, and the cross points in the first database are matched with the corresponding cross points in the second database; Dividing the enterprise management software data according to the number of intersections to obtain a plurality of unit data, and further dividing the plurality of unit data respectively, each unit data being divided to obtain first data and second data; storing the first data and the second data in corresponding intersections of the first database and the second database respectively; The intersection points in the first database are interchanged to obtain a first mother database, and the intersection points in the second database are interchanged to obtain a second mother database.

4. The enterprise management software data security protection method according to claim 3 is characterized by: The step of setting an update library corresponding to the first mother database and the second mother database and connecting the update library to the sub-database for communication includes: An integration library is set corresponding to the first mother database and the second mother database, a data grid is set in the integration library, and an integration point is set in the data grid; Connecting the integration points to the corresponding intersection points in the first mother database and the second mother database before the intersection points are swapped, to obtain an updated database; Connect the update repository to the sub-database.

5. The enterprise management software data security protection method according to claim 4, characterized in that: The step of formulating access conditions for the corresponding metadata database and authorizing access to the enterprise management software data in the sub-database based on the access conditions includes: Access conditions are formulated for the corresponding sub-database, wherein the access conditions include the authorized network port and the corresponding restricted access time period; Based on the access conditions, data access is performed on the sub-database through the authorized network port outside the corresponding restricted access period.

6. The enterprise management software data security protection method according to claim 5, characterized in that: The step of restoring the child database through the first mother database and the second mother database includes: The network that does not meet any access condition to access the sub-data is regarded as an unauthorized network; When an unauthorized network accesses the sub-database, the connection between the unauthorized network and the sub-database is cut off, and the enterprise management software data in the sub-database is cleared; The first data and the second data in the first parent database and the second parent database are integrated in the update library, and the enterprise management software data in the child database is restored through the update library.

7. The enterprise management software data security protection method according to claim 6, characterized in that: The step of integrating the first data and the second data in the first parent database and the second parent database into the update library, and restoring the enterprise management software data in the child database through the update library comprises: Integrate and copy the first data and the second data in the corresponding intersection between the first mother database and the second mother database; The first data and the second data copied according to the multiple intersection points are transmitted to the corresponding integration points in the update library, and the multiple first data and the second data are spliced ​​according to the multiple integration points to obtain the enterprise management software data; Transfer enterprise management software data to the sub-database to complete data recovery.

8. An enterprise management software data security protection system, used to implement an enterprise management software data security protection method according to any one of claims 1 to 7, characterized in that: include: A construction module is used to formulate a metadata database corresponding to the enterprise management software data, wherein the metadata database includes a first parent database, a second parent database, an update database and a sub-database; An access module, connected to the construction module, is used to formulate access conditions for the corresponding metadata database and authorize access to the enterprise management software data in the sub-database based on the access conditions; The recovery module is connected to the access module and is used to close the connection between the sub-database and the external network when an unauthorized network accesses the sub-database, and to recover the sub-database through the first mother database and the second mother database.

Citation Information

Patent Citations

  • Data security protection method of enterprise management software

    CN101923678A

  • Enterprise private cloud system

    CN108809986A

  • Enterprise management software data security protection method

    CN114580019A

  • Network security policy management method based on network slices

    CN116886409A

  • Database sensitive data risk avoidance method, storage medium and equipment

    CN117668917A

Cited By

  • A system for digitizing and 3D modeling of geological records of a tunnel survey

    CN122597695A