Data security intelligent analysis platform and method based on data elements
By designing a data security intelligent analysis platform based on data elements, the problem of not being able to dynamically evaluate data risks in the existing technology is solved, and the matching of data access strategies and data risk characteristics is achieved, effectively ensuring data security.
Patent Information
- Application Number
- CN202510424474.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-07
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-04-07
AI Technical Summary
The prior art cannot conduct dynamic risk assessment based on the labels and characteristics of the data, resulting in a fixed sensitive data access strategy that does not match the dynamically changing data risk characteristics, and cannot ensure data security.
Design a data security intelligent analysis platform based on data elements, including data security assessment module, factor analysis module, risk screening module and data management module. Through the collaborative work of these modules, data risks can be evaluated dynamically, risk tags and characteristics can be optimized, and adaptive sensitive data access strategies can be generated.
Dynamic risk assessment is implemented based on data labels and characteristics, ensuring that the data access strategy matches the data risk characteristics, and effectively ensuring data security.
Smart Images

Figure CN119939669A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of data management and relates to data processing technology, specifically a data security intelligent analysis platform and method based on data elements. Background Art
[0002] Data, as a new type of production factor, is the foundation of digitalization, networking, and intelligence. It has been rapidly integrated into various links such as production, distribution, circulation, consumption, and social service management, profoundly changing the mode of production, lifestyle, and social governance. Data elements refer to data resources that exist in electronic form, participate in production and operation activities through computing, and play an important role.
[0003] The invention patent with announcement number CN118013502A discloses a data asset security protection method and system based on data elements. This method can solve the technical problem in the prior art that the authority level setting is inaccurate due to the association between different data, which in turn leads to a large data security risk. It partitions and stores data according to data categories and sensitivity levels and sets corresponding access policies to achieve security protection for sensitive data access, thereby achieving the technical effect of improving data access efficiency and improving the security of sensitive data; however, this method cannot perform dynamic risk assessment based on data labels and features, resulting in a mismatch between fixed sensitive data access policies and authority levels and dynamically changing data risk features, making it impossible to ensure data security.
[0004] In view of the above technical problems, this application proposes a solution. Summary of the invention
[0005] The purpose of the present invention is to provide a data security intelligent analysis platform based on data elements, which is used to solve the problem that the existing technology cannot perform dynamic risk assessment based on the labels and features of the data; The technical problem to be solved by the present invention is: how to provide a data security intelligent analysis platform and method based on data elements that can perform dynamic risk assessment based on the labels and features of the data.
[0006] The purpose of the present invention can be achieved through the following technical solutions: A data security intelligent analysis platform based on data elements, comprising a data security assessment module, an element analysis module, a risk screening module and a data management module connected in sequence; The data security assessment module is used to assess and analyze the data security status of the analysis platform: generate an assessment cycle, mark the number of data risk events that occur in the analysis platform during the assessment cycle as the risk value of the assessment cycle, and determine whether the data security status of the analysis platform during the assessment cycle meets the requirements based on the risk value; The element analysis module is used to perform data element analysis on the analysis object of the analysis platform: generate a label BQi according to the data element of the analysis object, i=1, 2, ..., n, n is a positive integer, generate a feature TZie through the label BQi, e=1, 2, ..., m, m is a positive integer, mark the number of analysis objects whose data elements meet the feature TZie as the event marking value SJie of the feature TZie, calculate the variance of the event marking values SJie corresponding to all features TZie of the same label BQi to obtain the element distribution coefficient YFi of the label BQi, mark the label BQi as a concentrated label or a dispersed label through the element distribution coefficient YFi; send the concentrated label and the dispersed label to the risk screening module; The risk screening module is used to screen and analyze the data risk characteristics of the analysis platform; The data management module is used to perform security management and analysis on the data of the analysis platform.
[0007] Furthermore, the specific process of determining whether the data security status of the analysis platform during the evaluation period meets the requirements includes: comparing the risk value with the preset risk threshold: if the risk value is less than the risk threshold, it is determined that the data security status of the analysis platform during the evaluation period meets the requirements, a risk processing signal is generated and the risk processing signal is sent to the mobile phone terminal of the administrator; if the risk value is greater than or equal to the risk threshold, it is determined that the data security status of the analysis platform during the evaluation period does not meet the requirements, the data with data risk events is marked as analysis objects, and all analysis objects are sent to the factor analysis module.
[0008] Furthermore, the specific process of marking the label BQi as a concentrated label or a dispersed label includes: comparing the element distribution coefficient YFi with the preset element distribution threshold YFmax: if the element distribution coefficient YFi is less than the element distribution threshold YFmax, it is determined that the label BQi does not have a concentrated feature, and the corresponding label BQi is marked as a dispersed label; if the element distribution coefficient YFi is greater than or equal to the element distribution threshold YFmax, it is determined that the label BQi has a concentrated feature, and the corresponding label BQi is marked as a concentrated label.
[0009] Furthermore, the specific process of the risk screening module for screening and analyzing the data risk features of the analysis platform includes: forming a screening set from the event marking values SJie of all features TZie in the same centralized label, eliminating the largest element in the screening set, and then performing variance calculation on the screening set to obtain a screening coefficient, marking the risk factors through the screening coefficient, freely combining all risk factors according to the centralized label to generate several risk identification data groups, and sending the risk identification data groups to the data management module.
[0010] Furthermore, the specific process of marking risk factors includes: comparing the screening coefficient with the preset factor distribution threshold YFmax: if the screening coefficient is greater than or equal to the factor distribution threshold YFmax, the largest element in the screening set is eliminated, and then the screening coefficient is recalculated, and so on, until the screening coefficient is less than the factor distribution threshold YFmax; if the screening coefficient is less than the factor distribution threshold YFmax, the feature TZie corresponding to the event marking value SJie eliminated from the screening set is marked as a risk factor.
[0011] Furthermore, the specific process of the data management module performing security management analysis on the data of the analysis platform includes: marking the data that has undergone state changes in the analysis platform as management objects, obtaining the data elements of the management objects, extracting the parameters of the centralized labels in the data elements, and determining whether there is at least one data group in the risk identification data group that is completely identical to the parameters of the centralized labels of the management object data elements: if so, marking the management object as a first-level risk object; if not, performing an in-depth analysis of the management object.
[0012] Furthermore, the specific process of conducting in-depth analysis of the management object includes: marking the number of corresponding concentrated labels and dispersed labels in the data elements of the management object as concentrated values and dispersed values respectively, marking the ratio of the concentrated value to the dispersed value as a management coefficient, and comparing the management coefficient with a preset management threshold: if the management coefficient is less than the management threshold, the management object is marked as a third-level risk object; if the management coefficient is greater than or equal to the management threshold, the management object is marked as a second-level risk object.
[0013] The data security intelligent analysis method based on data elements includes the following steps: Step 1: Evaluate and analyze the data security status of the analysis platform: Generate an evaluation cycle, mark the number of data risk events that occur in the analysis platform during the evaluation cycle as the risk value of the evaluation cycle, and use the risk value to determine whether the data security status of the analysis platform during the evaluation cycle meets the requirements; Step 2: Analyze the data elements of the analysis object of the analysis platform and mark the centralized labels and decentralized labels, and send the centralized labels and decentralized labels to the risk screening module and the risk assessment module; Step 3: Screen and analyze the data risk features of the analysis platform: The event tag values SJie of all features TZie in the same set of tags constitute a screening set, and the screening set is eliminated to obtain a risk identification data group; Step 4: Conduct security management analysis on the data on the analysis platform: Mark the data that has undergone state changes in the analysis platform as management objects, and mark the management objects as first-level risk objects, second-level risk objects, or third-level risk objects.
[0014] The present invention has the following beneficial effects: 1. The data security assessment module can be used to assess and analyze the data security status of the analysis platform, periodically collect statistics on the frequency of data risk events to obtain risk values, and provide feedback on the overall risk level based on the risk value. When the overall risk level is abnormal, factor analysis is triggered to dynamically optimize risk labels and features. 2. The element analysis module can be used to analyze the data elements of the analysis objects of the analysis platform. A label-feature system can be formulated based on the status of data elements in different links. The distribution status of the number of analysis objects corresponding to different features under the same label can be analyzed centrally. Then, the labels can be marked differently according to the analysis results to provide data support for the screening and analysis process. 3. The risk screening module can be used to screen and analyze the data risk characteristics of the analysis platform, mark the risk factors by forming a screening set and eliminating elements, and generate a risk identification data group based on the risk factors. The risk identification data group represents the high probability characteristics of data risk events. The risk identification data group is periodically dynamically optimized and updated, which can take into account both real-time data security and call efficiency; 4. The data management module can be used to conduct security management analysis on the data of the analysis platform, and the risk level of the management objects can be marked based on the risk identification data group and the marking results of the centralized tags. Sensitive data access policies and permission levels can be generated according to the risk level to ensure data security. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0016] Figure 1 is a system block diagram of Embodiment 1 of the present invention; Figure 2 This is a flow chart of the method of Embodiment 2 of the present invention. DETAILED DESCRIPTION
[0017] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0018] Embodiment 1: Figure 1As shown, a data security intelligent analysis platform based on data elements includes a data security assessment module, an element analysis module, a risk screening module and a data management module which are connected in sequence.
[0019] The data security assessment module is used to evaluate and analyze the data security status of the analysis platform: generate an assessment cycle, mark the number of data risk events that occur in the analysis platform during the assessment cycle as the risk value of the assessment cycle, data risk events include data leakage, data loss, and illegal tampering, and compare the risk value with the preset risk threshold: if the risk value is less than the risk threshold, it is determined that the data security status of the analysis platform during the assessment cycle meets the requirements, and a risk processing signal is generated and sent to the manager's mobile terminal; if the risk value is greater than or equal to the risk threshold, it is determined that the data security status of the analysis platform during the assessment cycle does not meet the requirements, and the data where the data risk event occurs is marked as an analysis object, and all analysis objects are sent to the feature analysis module; evaluate and analyze the data security status of the analysis platform, periodically count the frequency of data risk events to obtain the risk value, feedback the overall risk level based on the risk value, trigger feature analysis when the overall risk level is abnormal, and dynamically optimize risk labels and features.
[0020] The element analysis module is used to perform data element analysis on the analysis object of the analysis platform: generate a label BQi according to the data element of the analysis object, i=1, 2, ..., n, n is a positive integer, the label BQi includes sensitivity level, transmission method, storage method and frequency of use, etc., generate a feature TZie through the label BQi, e=1, 2, ..., m, m is a positive integer, illustratively, when the label BQi is the sensitivity level, the feature TZie includes primary sensitivity, secondary sensitivity, tertiary sensitivity, etc.; mark the number of analysis objects whose data elements meet the feature TZie as the event marking value SJie of the feature TZie, calculate the variance of the event marking values SJie corresponding to all the features TZie of the same label BQi to obtain the element distribution coefficient YFi of the label BQi, and convert the element distribution coefficient Y Fi is compared with the preset element distribution threshold YFmax: if the element distribution coefficient YFi is less than the element distribution threshold YFmax, it is determined that the label BQi does not have a concentrated feature, and the corresponding label BQi is marked as a dispersed label; if the element distribution coefficient YFi is greater than or equal to the element distribution threshold YFmax, it is determined that the label BQi has a concentrated feature, and the corresponding label BQi is marked as a concentrated label; the concentrated label and the dispersed label are sent to the risk screening module and the risk assessment module; data element analysis is performed on the analysis object of the analysis platform, and a label-feature system is formulated based on the status of data elements in different links. The distribution status of the number of analysis objects corresponding to different features under the same label is analyzed through concentrated features, and then the labels are differentiated according to the analysis results to provide data support for the screening analysis process.
[0021] The risk screening module is used to screen and analyze the data risk features of the analysis platform: the event tag values SJie of all features TZie in the same set of tags constitute a screening set, the maximum element in the screening set is eliminated, and then the variance of the screening set is calculated to obtain the screening coefficient, and the screening coefficient is compared with the preset element distribution threshold YFmax: if the screening coefficient is greater than or equal to the element distribution threshold YFmax, the maximum element in the screening set is eliminated, and then the screening coefficient is recalculated, and so on, until the screening coefficient is less than the element distribution threshold YFmax; if the screening coefficient is less than the element distribution threshold YFmax , then the feature TZie corresponding to the event mark value SJie eliminated by the screening set is marked as a risk factor, all risk factors are freely combined according to the centralized label to generate several risk identification data groups, and the risk identification data groups are sent to the data management module; the data risk characteristics of the analysis platform are screened and analyzed, and the risk factors are marked by forming a screening set and eliminating elements. The risk identification data group is generated by combining the risk factors. The risk identification data group represents the high probability characteristics of data risk events. The risk identification data group is periodically dynamically optimized and updated, which can take into account both real-time data security and call efficiency.
[0022] The data management module is used to perform security management analysis on the data of the analysis platform: mark the data that has undergone state changes in the analysis platform as management objects, obtain the data elements of the management objects, extract the parameters of the centralized labels in the data elements, and determine whether there is at least one data group in the risk identification data group that is exactly the same as the parameters of the centralized labels of the management object data elements: if so, mark the management object as a first-level risk object; if not, perform an in-depth analysis on the management object: mark the number of corresponding centralized labels and decentralized labels in the data elements of the management object as centralized values and decentralized values respectively, mark the ratio of the centralized value to the decentralized value as the management coefficient, and compare the management coefficient with the preset management threshold: if the management coefficient is less than the management threshold, mark the management object as a third-level risk object; if the management coefficient is greater than or equal to the management threshold, mark the management object as a second-level risk object; perform security management analysis on the data of the analysis platform, mark the risk level of the management object based on the marking results of the risk identification data group and the centralized label, generate sensitive data access policies and permission levels according to the risk level, and ensure data security.
[0023] Embodiment 2: Figure 2 As shown, a data security intelligent analysis method based on data elements includes the following steps: Step 1: Evaluate and analyze the data security status of the analysis platform: Generate an evaluation cycle, mark the number of data risk events that occur in the analysis platform during the evaluation cycle as the risk value of the evaluation cycle, and use the risk value to determine whether the data security status of the analysis platform during the evaluation cycle meets the requirements; Step 2: Analyze the data elements of the analysis object of the analysis platform and mark the centralized labels and decentralized labels, and send the centralized labels and decentralized labels to the risk screening module and the risk assessment module; Step 3: Screen and analyze the data risk features of the analysis platform: The event tag values SJie of all features TZie in the same set of tags constitute a screening set, and the screening set is eliminated to obtain a risk identification data group; Step 4: Conduct security management analysis on the data on the analysis platform: Mark the data that has undergone state changes in the analysis platform as management objects, and mark the management objects as first-level risk objects, second-level risk objects, or third-level risk objects.
[0024] A data security intelligent analysis platform based on data elements generates an evaluation cycle when working, marks the number of data risk events that occur in the analysis platform during the evaluation cycle as the risk value of the evaluation cycle, and determines whether the data security status of the analysis platform during the evaluation cycle meets the requirements through the risk value; performs data element analysis on the analysis object of the analysis platform and marks the centralized label and the decentralized label, and sends the centralized label and the decentralized label to the risk screening module and the risk assessment module; forms a screening set with the event marking values SJie of all features TZie in the same centralized label, and eliminates the screening set to obtain a risk identification data group; marks the data with state changes in the analysis platform as management objects, and marks the management objects as primary risk objects, secondary risk objects or tertiary risk objects.
[0025] The above contents are merely examples and explanations of the structure of the present invention. The technicians in this technical field may make various modifications or additions to the specific embodiments described or replace them in a similar manner. As long as they do not deviate from the structure of the invention or exceed the scope defined by the claims, they should all fall within the protection scope of the present invention.
[0026] In the description of this specification, the description with reference to the terms "one embodiment", "example", "specific example", etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.
[0027] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to only specific implementation methods. Obviously, many modifications and changes can be made according to the content of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can understand and use the present invention well. The present invention is limited only by the claims and their full scope and equivalents.
Claims
1. A data security intelligent analysis platform based on data elements, characterized in that: It includes a data security assessment module, a factor analysis module, a risk screening module and a data management module which are connected in sequence; The data security assessment module generates an assessment cycle, marks the number of data risk events that occur in the analysis platform during the assessment cycle as the risk value of the assessment cycle, and uses the risk value to determine whether the data security status of the analysis platform during the assessment cycle meets the requirements; The element analysis module generates a label BQi according to the data element of the analysis object, where i=1, 2, ..., n, and n is a positive integer. The feature TZie is generated through the label BQi, where e=1, 2, ..., m, and m is a positive integer. The number of analysis objects whose data elements meet the feature TZie is marked as the event marking value SJie of the feature TZie. The variance of the event marking values SJie corresponding to all the features TZie of the same label BQi is calculated to obtain the element distribution coefficient YFi of the label BQi. The label BQi is marked as a concentrated label or a dispersed label through the element distribution coefficient YFi. Send the centralized labels and decentralized labels to the risk screening module; The risk screening module screens and analyzes the data risk characteristics of the analysis platform and generates a risk identification data group; The data management module performs security management analysis on the data of the analysis platform based on the risk identification data group.
2. According to claim 1, a data security intelligent analysis platform based on data elements is characterized in that: The specific process of determining whether the data security status of the analysis platform during the evaluation period meets the requirements includes: comparing the risk value with the preset risk threshold: if the risk value is less than the risk threshold, it is determined that the data security status of the analysis platform during the evaluation period meets the requirements, a risk processing signal is generated and the risk processing signal is sent to the mobile phone terminal of the administrator; if the risk value is greater than or equal to the risk threshold, it is determined that the data security status of the analysis platform during the evaluation period does not meet the requirements, the data with data risk events is marked as analysis objects, and all analysis objects are sent to the feature analysis module.
3. A data security intelligent analysis platform based on data elements according to claim 2, characterized in that: The specific process of marking the label BQi as a concentrated label or a dispersed label includes: comparing the element distribution coefficient YFi with the preset element distribution threshold YFmax: if the element distribution coefficient YFi is less than the element distribution threshold YFmax, it is determined that the label BQi does not have a concentrated feature, and the corresponding label BQi is marked as a dispersed label; if the element distribution coefficient YFi is greater than or equal to the element distribution threshold YFmax, it is determined that the label BQi has a concentrated feature, and the corresponding label BQi is marked as a concentrated label.
4. A data security intelligent analysis platform based on data elements according to claim 3, characterized in that: The specific process of the risk screening module to screen and analyze the data risk features of the analysis platform includes: forming a screening set with the event marking values SJie of all features TZie in the same centralized label, removing the largest element in the screening set, and then calculating the variance of the screening set to obtain the screening coefficient, marking the risk factors through the screening coefficient, freely combining all risk factors according to the centralized label to generate several risk identification data groups, and sending the risk identification data groups to the data management module.
5. A data security intelligent analysis platform based on data elements according to claim 4, characterized in that: The specific process of marking risk factors includes: comparing the screening coefficient with the preset factor distribution threshold YFmax: if the screening coefficient is greater than or equal to the factor distribution threshold YFmax, the largest element in the screening set is eliminated, and then the screening coefficient is recalculated, and so on, until the screening coefficient is less than the factor distribution threshold YFmax; if the screening coefficient is less than the factor distribution threshold YFmax, the feature TZie corresponding to the event marking value SJie eliminated from the screening set is marked as a risk factor.
6. A data security intelligent analysis platform based on data elements according to claim 5, characterized in that: The specific process of the data management module performing security management analysis on the data of the analysis platform includes: marking the data that has undergone state changes in the analysis platform as management objects, obtaining the data elements of the management objects, extracting the parameters of the centralized labels in the data elements, and determining whether there is at least one data group in the risk identification data group that is exactly the same as the parameters of the centralized labels of the management object data elements: if so, marking the management object as a first-level risk object; if not, performing an in-depth analysis of the management object.
7. The data security intelligent analysis platform based on data elements according to claim 6 is characterized in that: The specific process of in-depth analysis of the management object includes: marking the number of corresponding concentrated labels and dispersed labels in the data elements of the management object as concentrated values and dispersed values respectively, marking the ratio of the concentrated value to the dispersed value as the management coefficient, and comparing the management coefficient with the preset management threshold: if the management coefficient is less than the management threshold, the management object is marked as a third-level risk object; if the management coefficient is greater than or equal to the management threshold, the management object is marked as a second-level risk object.
8. A data security intelligent analysis method based on data elements, applied to a data security intelligent analysis platform based on data elements as described in any one of claims 1 to 7, characterized in that: The following steps are involved: Step 1: Evaluate and analyze the data security status of the analysis platform: Generate an evaluation cycle, mark the number of data risk events that occur in the analysis platform during the evaluation cycle as the risk value of the evaluation cycle, and use the risk value to determine whether the data security status of the analysis platform during the evaluation cycle meets the requirements; Step 2: Analyze the data elements of the analysis object of the analysis platform and mark the centralized labels and decentralized labels, and send the centralized labels and decentralized labels to the risk screening module and the risk assessment module; Step 3: Screen and analyze the data risk features of the analysis platform: The event tag values SJie of all features TZie in the same set of tags constitute a screening set, and the screening set is eliminated to obtain a risk identification data group; Step 4: Conduct security management analysis on the data on the analysis platform: Mark the data that has undergone state changes in the analysis platform as management objects, and mark the management objects as first-level risk objects, second-level risk objects, or third-level risk objects.
Citation Information
Patent Citations
Data asset security protection method and system based on data elements
CN118013502A
Shallow-water lake algal bloom risk analysis early-warning system and analysis early-warning method
CN106990216A
Service data security index evaluation method and device
CN112560046A
Quantitative evaluation system and method for reducing risks of production operators
CN114266441A
Project execution risk assessment system based on data analysis
CN115983625A