A method and system for data security protection of enterprise management software

By adopting metadatabase architecture and access control mechanisms in enterprise management software, the problem of data security threats in cloud office environments is solved, and the secure storage and rapid recovery of data are achieved.

CN119939636BActive Publication Date: 2025-06-24XINJIANG CHINA ENTERPRISE DIGITAL INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510422099.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-06-24
Estimated Expiration
2045-04-07

AI Technical Summary

Technical Problem

Enterprise management software faces data security threats in cloud office environments, including phishing attacks, malware, data breaches and lack of effective access controls.

Method used

The metadatabase architecture is adopted, including the first parent database, the second parent database, the update database and the child database. Authorized access is made by formulating access conditions, and the connection is cut off when access is not authorized, and the child database data is restored through the first parent database and the second parent database.

Benefits of technology

Effectively prevent data leakage, ensure data accuracy and security, and promptly restore sub-database data to avoid data loss.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939636B_ABST
    Figure CN119939636B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for data security protection of enterprise management software, which relates to the technical field of data security. A meta database is formulated corresponding to the enterprise management software data. The meta database includes a first master database, a second master database, an update library, and a sub database. Access conditions are formulated corresponding to the meta database, and authorized access to the enterprise management software data in the sub database is performed based on the access conditions. When there is an unauthorized network accessing the sub database, the connection end between the sub database and the external network is closed, and the sub database is restored through the first master database and the second master database. The present invention can ensure the data accuracy of the sub database, can timely restore the sub database, and the used first master database and second master database can also ensure data security, and can effectively avoid data leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and in particular to a method and system for data security protection of enterprise management software. Background Art

[0002] With the rapid development of network technology, the network environment in which enterprise management software is located is becoming increasingly complex. In the process of enterprise digital transformation, the office mode has changed from the traditional mode to cloud-based office. The cloudification of applications and data has made the browser a new working platform, which has brought a series of data security problems such as phishing attacks, malware and viruses, privacy tracking and data hijacking, browser security vulnerabilities, insecure web access, internal data leakage risks, and lack of effective access control and auditing. These problems will affect the normal acquisition and use of data, and at the same time will also lead to the leakage of enterprise data. Summary of the Invention

[0003] The purpose of the present invention is to provide a method and system for data security protection of enterprise management software to solve the deficiencies in the background art.

[0004] To achieve the above purpose, the present invention provides the following technical solutions: A method for data security protection of enterprise management software, including the following steps:

[0005] Establish a meta database corresponding to the enterprise management software data, where the meta database includes a first master database, a second master database, an update library, and a sub-database;

[0006] Define access conditions corresponding to the meta database, and authorize access to the enterprise management software data in the sub-database based on the access conditions;

[0007] When there is an unauthorized network accessing the sub-database, close the connection end between the sub-database and the external network, and restore the sub-database through the first master database and the second master database.

[0008] In a preferred embodiment, the step of establishing a meta database corresponding to the enterprise management software data includes:

[0009] Establish a sub-database corresponding to the enterprise management software data in the enterprise platform;

[0010] Configure the corresponding first master database and second master database for the sub-database, and the first master database and the second master database are communicatively connected;

[0011] Set an update library corresponding to the first master database and the second master database, and communicatively connect the update library with the sub-database.

[0012] In a preferred embodiment, the corresponding sub-database configures a corresponding first master database and a second master database. The steps of communication connection between the first master database and the second master database include:

[0013] The corresponding sub-database configures a first database and a second database, and a cross-network is set in both the first database and the second database. Among them, the cross-network is composed of data grids;

[0014] A plurality of cross-points are set on the cross-network, and the plurality of cross-points are respectively connected to the intersection points of the cross-network;

[0015] The cross-network and cross-points between the first database and the second database are set in the same way, and the cross-points in the first database are corresponded to the corresponding cross-points in the second database;

[0016] The enterprise management software data is divided according to the number of cross-points to obtain a plurality of unit data, and the plurality of unit data are further divided respectively. Each unit data is divided to obtain first data and second data;

[0017] The first data and the second data are respectively stored in the corresponding cross-points in the first database and the second database;

[0018] The cross-points in the first database are swapped in position to obtain the first master database, and the cross-points in the second database are swapped in position to obtain the second master database.

[0019] In a preferred embodiment, an update library is set corresponding to the first master database and the second master database. The steps of communication connection between the update library and the sub-database include:

[0020] An integration library is set corresponding to the first master database and the second master database. Data grids are set in the integration library, and integration points are set in the data grids;

[0021] The integration points are respectively connected to the corresponding cross-points before the position swapping of the cross-points in the first master database and the second master database to obtain an update library;

[0022] The update library is communicatively connected to the sub-database.

[0023] In a preferred embodiment, the corresponding meta-database formulates access conditions, and the steps of authorizing access to the enterprise management software data in the sub-database based on the access conditions include:

[0024] Access conditions are formulated corresponding to the sub-database. Among them, the access conditions include authorized network ports and corresponding restricted access time periods;

[0025] Data access to the sub-database is performed through an authorized network port based on access conditions outside the corresponding restricted access period.

[0026] In a preferred embodiment, the step of restoring the sub-database through the first master database and the second master database includes:

[0027] Regarding a network where accessing the sub-data does not meet any of the access conditions as an unauthorized network;

[0028] When there is an unauthorized network accessing the sub-database, disconnect the connection between the unauthorized network and the sub-database, and clear the enterprise management software data in the sub-database;

[0029] Integrate the first data and the second data in the first master database and the second master database in the update library, and restore the enterprise management software data in the sub-database through the update library.

[0030] In a preferred embodiment, the step of integrating the first data and the second data in the first master database and the second master database in the update library and restoring the enterprise management software data in the sub-database through the update library includes:

[0031] Integrate and copy the first data and the second data at the corresponding intersection points between the first master database and the second master database;

[0032] Transmit the first data and the second data copied according to multiple intersection points to the corresponding integration points in the update library, and splice the multiple first data and the second data according to multiple integration points to obtain the enterprise management software data;

[0033] Transmit the enterprise management software data to the sub-database to complete data restoration.

[0034] The present invention also provides an enterprise management software data security protection system, including:

[0035] A construction module for formulating a meta-database corresponding to the enterprise management software data, where the meta-database includes a first master database, a second master database, an update library, and a sub-database;

[0036] An access module, connected to the construction module, for formulating access conditions corresponding to the meta-database and performing authorized access to the enterprise management software data in the sub-database based on the access conditions;

[0037] A restoration module, connected to the access module, for when there is an unauthorized network accessing the sub-database, closing the connection end between the sub-database and the external network, restoring the sub-database through the first master database and the second master database, and obtaining the security index of the sub-database, where the calculation formula of the security index is: , where is the security index, is the number of times the sub-database is accessed, is a constant greater than zero, is the time interval between the access times of the sub-database. It should be noted that the larger the value of the security index, the lower the security of the sub-database.

[0038] In the above technical solution, the technical effects and advantages provided by the present invention are as follows:

[0039] The present invention can copy and integrate the data in the first master database and the second master database in the update library, perform data recovery on the sub-database through the update library, which is equivalent to destroying the data in the sub-database, and perform data reconstruction on the sub-database through the update library. After the data recovery of the sub-database is completed, the data in the update library can be cleared and waiting for the next use, which can ensure the data accuracy of the sub-database, and can recover the sub-database in time, and the first master database and the second master database used can also ensure the data security and can effectively avoid data leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required to be used in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.

[0041] Figure 1 is the method flow chart of the present invention.

[0042] Figure 2 is the system block diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0043] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0044] Example 1. Please refer to Figure 1 As shown, a method for data security protection of enterprise management software in this embodiment includes the following steps:

[0045] S1. Develop a meta-database corresponding to the data of enterprise management software. Among them, the meta-database includes a first master database, a second master database, an update library, and a sub-database;

[0046] S2. Set access conditions corresponding to the meta-database, and authorize access to the enterprise management software data in the sub-database based on the access conditions;

[0047] S3. When there is an unauthorized network accessing the sub-database, close the connection end between the sub-database and the external network, and restore the sub-database through the first master database and the second master database;

[0048] As described in the above steps S1 - S3, after the data in the sub-database is restored, the data in the update library can be cleared and wait for the next use, which can ensure the data accuracy of the sub-database, and can restore the sub-database in time. Moreover, the first master database and the second master database used can also ensure data security and can effectively avoid data leakage.

[0049] In one embodiment, the step S1 of developing a meta-database corresponding to the data of enterprise management software includes:

[0050] S11. Develop a sub-database corresponding to the data of enterprise management software in the enterprise platform;

[0051] S12. Configure corresponding first and second master databases for the sub-database, and the first master database and the second master database are communicatively connected;

[0052] S13. Set an update library corresponding to the first master database and the second master database, and communicatively connect the update library with the sub-database;

[0053] In one embodiment, the step S12 of configuring corresponding first and second master databases for the sub-database, where the first master database and the second master database are communicatively connected, includes:

[0054] S121. Configure a first database and a second database for the sub-database, and set cross-nets in both the first database and the second database. Among them, the cross-net is composed of data grids;

[0055] S122. Set multiple cross-points on the cross-net, and the multiple cross-points are respectively connected to the intersection points of the cross-net;

[0056] S123. The cross-nets and cross-points between the first database and the second database are set in the same way, and the cross-points in the first database are corresponded to the corresponding cross-points in the second database;

[0057] S124. Divide the enterprise management software data according to the number of intersection points to obtain multiple unit data, and then divide the multiple unit data respectively. Each unit data is divided into first data and second data;

[0058] S125. Store the first data and the second data in the corresponding intersection points in the first database and the second database respectively;

[0059] S126. Swap the positions of the intersection points in the first database to obtain a first master database, and swap the positions of the intersection points in the second database to obtain a second master database;

[0060] In one embodiment, step S13 of setting an update library corresponding to the first master database and the second master database and communicatively connecting the update library with a sub-database includes:

[0061] S131. Set an integration library corresponding to the first master database and the second master database, set a data grid in the integration library, and set integration points in the data grid;

[0062] S132. Connect the integration points with the corresponding intersection points before the position swapping of the intersection points in the first master database and the second master database respectively to obtain an update library;

[0063] S133. Communicatively connect the update library with the sub-database;

[0064] As described in the above steps S11 - S13, a sub - database is formulated for the enterprise management software data in the enterprise platform. This sub - database is a database connected to the outside world, capable of supporting access from the external network. This sub - database is suitable for daily use in storing enterprise management software data. Among them, enterprise management software data includes: For example, basic enterprise information: including enterprise name, legal representative, registered address, contact information, etc. These information are the identifiers of the enterprise and generally exist as basic data in the software, used for various reports, documents, and communication with external institutions. Basic employee information: such as employee name, ID number, start date of employment, department, position, etc., which are the basic data for the enterprise's human resource management and are used for attendance, salary calculation, employee file management, etc. Basic information of customers and suppliers: the name, address, contact person, contact information of customers, and relevant information of suppliers, etc., which are important data for the enterprise's business transactions and are used for order management, procurement management, customer relationship maintenance, etc. Approval process settings: specify the approval links, approval personnel, approval authorities, etc. for various business processes, ensuring that all business activities of the enterprise are circulated and decision - made according to the established rules. Price system data: For sales - type enterprises, price lists, discount rules, price adjustment records, etc. of products or services are important business rule data, directly affecting the enterprise's revenue and profit. Inventory management rules: including safety inventory levels, replenishment strategies, inventory counting cycles, etc., helping the enterprise reasonably control inventory, reduce inventory costs, and ensure the smooth progress of production and sales. Software function permission settings: define the access permissions of different user roles to each function module of the enterprise management software, ensuring data security and operation standardization. Data storage and backup strategies: specify the storage location, storage format, backup period, backup storage medium, etc. of data, ensuring the secure storage and recoverability of enterprise data.Interface configuration information: If the enterprise management software is integrated with other systems, such as being connected to a financial system, an e-commerce platform, etc., the interface configuration data includes the interface address, communication protocol, data transmission format, etc., to ensure that data interaction between systems can be carried out stably and accurately. After that, in order to ensure the security of the data in the sub-database, data recovery of the sub-database is required. First, configure the corresponding first database and second database for the sub-database. Set a cross-network inside the first database and the second database. Here, the cross-network is composed of data grids. Among them, the data grid is formed by setting multiple virtual nodes in the first database and the second database, and the multiple virtual nodes are connected to each other to form a data grid for positioning the position of subsequent intersection points. A plurality of intersection points are set in both the first database and the second database. The intersection point is a virtual machine, and the intersection point is connected to the virtual node (the intersection point of the cross-network). The first database is the same as the second database. Corresponding the intersection points in the first database with the corresponding intersection points in the second database. Then, respectively swap the positions of the intersection points in the first database to obtain the first master database, and swap the positions of the intersection points in the second database to obtain the second master database. Even though the intersection points in the first master database are swapped, and the intersection points in the second master database are also swapped, the original corresponding relationship of the intersection points between the first master database and the second master database still exists. Set an integration library corresponding to the first master database and the second master database. Set a data grid in the integration library, and set an integration point in the data grid. Here, the integration point is a virtual machine without stored data, which is blank and is used to subsequently integrate the first data and the second data stored in the corresponding intersection points. There is no risk of information leakage when any one of the first master database and the second master database is obtained, because the data in the first master database and the second master database is scrambled, the intersection points have been swapped, and it is also impossible to integrate the information of the first master database and the second master database, making it difficult to restore the data. And when there is an unauthorized network access to the sub-database in the future and there is a risk of data tampering in the sub-database, the data in the first master database and the second master database can be copied and integrated into the update library, and the sub-database can be restored through the update library. It is equivalent to destroying the data in the sub-database and reconstructing the data of the sub-database through the update library. After the data recovery of the sub-database is completed, the data in the update library can be cleared and waiting for the next use, which can ensure the data accuracy of the sub-database, and can recover the sub-database in time, and the first master database and the second master database used can also ensure the data security and can effectively avoid data leakage.

[0065] In one embodiment, the step S2 of formulating access conditions for the corresponding meta-database and authorizing access to the enterprise management software data in the sub-database based on the access conditions includes:

[0066] S21. Set access conditions for the corresponding sub-database, where the access conditions include authorized network ports and corresponding restricted access time periods;

[0067] S22. Based on the access conditions, perform data access to the sub-database through the authorized network ports outside the corresponding restricted access time periods;

[0068] In one embodiment, step S3 of restoring the sub-database through the first master database and the second master database includes:

[0069] S31. Regard the network that fails to meet any access condition for accessing the sub-data as an unauthorized network;

[0070] S32. When there is an unauthorized network accessing the sub-database, cut off the connection between the unauthorized network and the sub-database, and clear the enterprise management software data in the sub-database;

[0071] S33. Integrate the first data and the second data in the first master database and the second master database in the update library, and restore the enterprise management software data in the sub-database through the update library;

[0072] In one embodiment, step S33 of integrating the first data and the second data in the first master database and the second master database in the update library and restoring the enterprise management software data in the sub-database through the update library includes:

[0073] S331. Integrate and copy the first data and the second data at the corresponding intersection points between the first master database and the second master database;

[0074] S332. Transmit the first data and the second data copied according to multiple intersection points to the corresponding integration points in the update library, and splice the multiple first data and the second data according to the multiple integration points to obtain the enterprise management software data;

[0075] S333. Transmit the enterprise management software data to the sub-database to complete data restoration.

[0076] As described in the above steps S31 - S33, the access to the corresponding sub - database is restricted. As access conditions, the access conditions include authorized network ports and corresponding restricted access time periods. Therefore, as long as there is a situation where the authorized network ports are not satisfied or / and the corresponding restricted access time periods exist, the network is regarded as an unauthorized network. When an unauthorized network accesses the sub - database, the connection between the unauthorized network and the sub - database is cut off, and the enterprise management software data in the sub - database is cleared. To ensure the accuracy of the data in the sub - database, the data in the sub - database accessed by the unauthorized network needs to be cleared. After that, the first data and the second data at the corresponding intersection points between the first master database and the second master database are integrated and copied. The integration of the first data and the second data is also the opposite operation of dividing the unit data into the first data and the second data. After integration, copying is performed. There is always a corresponding relationship between the intersection points in the first master database and the second master database. Even if the positions are deliberately disrupted, the intersection points of the first master database and the second master database are corresponding in the enterprise platform. The corresponding intersection points represent that the stored first data and second data are the same unit data in the enterprise management software data. The first data and the second data copied according to multiple intersection points are transmitted to the corresponding integration points in the update library. According to multiple integration points, multiple first data and second data are spliced to obtain the enterprise management software data. Such data splicing is the opposite operation of dividing the enterprise management software data into multiple unit data. Finally, the enterprise management software data is transmitted to the sub - database to complete the data recovery, which can ensure the normal use of the sub - database, ensure the security of the data, and obtain the security index of the sub - database. Among them, the calculation formula of the security index is: , where, is the security index, is the number of times the sub - database is accessed, is a constant greater than zero, is the time interval between the number of times the sub - database is accessed. It should be noted that the larger the value of the security index, the lower the security of the sub - database.

[0077] Embodiment 2. Please refer to Figure 2 as shown. The enterprise management software data security protection system described in this embodiment includes:

[0078] A construction module for formulating a meta - database for the enterprise management software data. Among them, the meta - database includes a first master database, a second master database, an update library, and a sub - database;

[0079] An access module, connected to the construction module, for formulating access conditions for the meta - database and performing authorized access to the enterprise management software data in the sub - database based on the access conditions;

[0080] A recovery module, connected to the access module, is used to close the connection end between the sub-database and the external network when an unauthorized network accesses the sub-database, and recover the sub-database through the first master database and the second master database.

[0081] Transmit the first data and the second data copied according to multiple intersection points to the corresponding integration points in the update library, splice the multiple first data and the second data according to the multiple integration points to obtain enterprise management software data. Such data splicing is the opposite operation of dividing the enterprise management software data into multiple unit data. Finally, transmit the enterprise management software data to the sub-database to complete data recovery, which can ensure the normal use of the sub-database and the security of the data.

[0082] As described above, it is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claimed rights.

Claims

1. A method for protecting enterprise management software data security, characterized in that: The following steps are involved: A metadata database is formulated corresponding to the enterprise management software data, wherein the metadata database includes a first parent database, a second parent database, an update database and a sub-database; The step of formulating a metadata database corresponding to the enterprise management software data includes: In the enterprise platform, a sub-database is established corresponding to the enterprise management software data; The corresponding sub-database is configured with a corresponding first mother database and a second mother database, and the first mother database and the second mother database are connected in communication; The corresponding sub-database is configured with a corresponding first mother database and a second mother database, and the steps of the first mother database and the second mother database being communicated and connected include: The first database and the second database are configured corresponding to the sub-database, and a cross network is set in the first database and the second database, wherein the cross network is composed of a data grid; A plurality of intersections are arranged on the cross network, and the plurality of intersections are respectively connected to the intersections of the cross network; The data grid is a data grid formed by setting multiple virtual nodes in the first database and the second database, and the multiple virtual nodes are connected to each other, which is used to locate the position of subsequent intersections. Multiple intersections are set in the first database and the second database, and the intersections are virtual machines, which are connected to the virtual nodes; The cross network and the cross point between the first database and the second database are set in the same way, and the cross points in the first database are matched with the corresponding cross points in the second database; Dividing the enterprise management software data according to the number of intersections to obtain a plurality of unit data, and further dividing the plurality of unit data respectively, each unit data being divided to obtain first data and second data; storing the first data and the second data in corresponding intersections of the first database and the second database respectively; The intersection points in the first database are interchanged to obtain a first mother database, and the intersection points in the second database are interchanged to obtain a second mother database; An update library is set corresponding to the first mother database and the second mother database, and the update library is communicatively connected with the child database; The step of setting an update library corresponding to the first mother database and the second mother database and connecting the update library to the sub-database for communication includes: An integration library is set corresponding to the first mother database and the second mother database, a data grid is set in the integration library, and an integration point is set in the data grid; Connecting the integration points to the corresponding intersection points in the first mother database and the second mother database before the intersection points are swapped, to obtain an updated database; Connect the update library to the sub-database for communication; Access conditions are formulated for the corresponding metadata database, and authorized access to the enterprise management software data in the sub-database is performed based on the access conditions; When an unauthorized network accesses the sub-database, the connection between the sub-database and the external network is closed, and the sub-database is restored through the first mother database and the second mother database.

2. The enterprise management software data security protection method according to claim 1, characterized in that: The step of formulating access conditions for the corresponding metadata database and authorizing access to the enterprise management software data in the sub-database based on the access conditions includes: Access conditions are formulated for the corresponding sub-database, wherein the access conditions include the authorized network port and the corresponding restricted access time period; Based on the access conditions, data access is performed on the sub-database through the authorized network port outside the corresponding restricted access period.

3. The enterprise management software data security protection method according to claim 2, characterized in that: The step of restoring the child database through the first mother database and the second mother database includes: The network that does not meet any access condition to access the sub-data is regarded as an unauthorized network; When an unauthorized network accesses the sub-database, the connection between the unauthorized network and the sub-database is cut off, and the enterprise management software data in the sub-database is cleared; The first data and the second data in the first parent database and the second parent database are integrated in the update library, and the enterprise management software data in the child database is restored through the update library.

4. The enterprise management software data security protection method according to claim 3 is characterized by: The step of integrating the first data and the second data in the first parent database and the second parent database into the update library, and restoring the enterprise management software data in the child database through the update library comprises: Integrate and copy the first data and the second data in the corresponding intersection between the first mother database and the second mother database; The first data and the second data copied according to the multiple intersection points are transmitted to the corresponding integration points in the update library, and the multiple first data and the second data are spliced ​​according to the multiple integration points to obtain the enterprise management software data; Transfer enterprise management software data to the sub-database to complete data recovery.

5. An enterprise management software data security protection system, used to implement an enterprise management software data security protection method according to any one of claims 1 to 4, characterized in that: include: A construction module is used to formulate a metadata database corresponding to the enterprise management software data, wherein the metadata database includes a first parent database, a second parent database, an update database and a sub-database; An access module, connected to the construction module, is used to formulate access conditions for the corresponding metadata database and authorize access to the enterprise management software data in the sub-database based on the access conditions; The recovery module is connected to the access module and is used to close the connection between the sub-database and the external network when an unauthorized network accesses the sub-database, and to recover the sub-database through the first mother database and the second mother database.

Citation Information

Patent Citations

  • Enterprise private cloud system

    CN108809986A

  • Enterprise management software data security protection method

    CN114580019A