A data security intelligent analysis platform and method based on data elements

By designing a data security intelligent analysis platform based on data elements, and using multi-module collaborative work for dynamic risk assessment and optimization, the problem of not being able to dynamically evaluate data risks in the existing technology is solved, and the matching of data access strategies and risk characteristics is achieved, and data security and access efficiency are improved.

CN119939669BActive Publication Date: 2025-06-20SICHUAN AOCHENG TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510424474.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-06-20
Estimated Expiration
2045-04-07

AI Technical Summary

Technical Problem

The prior art cannot conduct dynamic risk assessment based on the labels and characteristics of the data, resulting in a fixed sensitive data access strategy that does not match the dynamically changing data risk characteristics, and cannot ensure data security.

Method used

Design a data security intelligent analysis platform based on data elements, including data security assessment module, factor analysis module, risk screening module and data management module. Through the collaborative work of these modules, dynamically evaluate and optimize data risks and generate adaptive sensitive data access strategies.

Benefits of technology

Dynamic risk assessment is implemented based on data labels and characteristics, ensuring that the data access strategy matches the data risk characteristics, and improving data security and access efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939669B_ABST
    Figure CN119939669B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of data management, relates to data processing technology, and is used to solve the problem that the prior art cannot perform dynamic risk assessment based on the tags and characteristics of data. Specifically, it is a data security intelligent analysis platform and method based on data elements, including a data security assessment module, an element analysis module, a risk screening module, and a data management module connected in sequence; the data security assessment module is used to evaluate and analyze the data security status of the analysis platform: generate an evaluation period, and mark the number of data risk events occurring in the analysis platform during the evaluation period as the risk value of the evaluation period; the present invention can evaluate and analyze the data security status of the analysis platform, periodically count the occurrence frequency of data risk events to obtain a risk value, feedback the overall risk level according to the risk value, trigger element analysis when the overall risk level is abnormal, and dynamically optimize risk tags and characteristics.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of data management, relates to data processing technologies, and specifically is a data security intelligent analysis platform and method based on data elements. Background Art

[0002] Data, as a new type of production factor, is the foundation of digitalization, networking, and intelligentization, and has quickly integrated into various links such as production, distribution, circulation, consumption, and social service management, profoundly changing production methods, lifestyles, and social governance methods; data elements refer to those data resources that exist in electronic form and participate in production and business activities through computing methods and play important values.

[0003] The invention patent with the publication number CN118013502A discloses a data asset security protection method and system based on data elements. This method can solve the technical problem in the prior art that due to the association between different data, the permission level setting is inaccurate, resulting in a relatively large data security risk. It stores data in partitions according to data categories and sensitive levels and sets corresponding access policies to achieve the security protection of sensitive data access, and achieve the technical effects of improving data access efficiency and enhancing the security of sensitive data; however, this method cannot perform dynamic risk assessment based on the labels and characteristics of data, resulting in a mismatch between fixed sensitive data access policies, permission levels, and dynamically changing data risk characteristics, making data security unable to be guaranteed.

[0004] In view of the above technical problems, this application proposes a solution. Summary of the Invention

[0005] The purpose of the present invention is to provide a data security intelligent analysis platform based on data elements, which is used to solve the problem that the prior art cannot perform dynamic risk assessment based on the labels and characteristics of data;

[0006] The technical problem that the present invention needs to solve is: how to provide a data security intelligent analysis platform and method based on data elements that can perform dynamic risk assessment based on the labels and characteristics of data.

[0007] The purpose of the present invention can be achieved through the following technical solutions:

[0008] A data security intelligent analysis platform based on data elements includes a data security assessment module, an element analysis module, a risk screening module, and a data management module that are connected in sequence;

[0009] The data security assessment module is used to evaluate and analyze the data security status of the analysis platform: generate an evaluation period, mark the number of data risk events that occur in the analysis platform during the evaluation period as the risk value of the evaluation period, and determine whether the data security status of the analysis platform meets the requirements during the evaluation period based on the risk value;

[0010] The element analysis module is used to perform data element analysis on the analysis objects of the analysis platform: generate labels BQi according to the data elements of the analysis objects, where i = 1, 2,..., n, and n is a positive integer, generate features TZie through the labels BQi, where e = 1, 2,..., m, and m is a positive integer, mark the number of analysis objects whose data elements conform to the feature TZie as the event marking value SJie of the feature TZie, calculate the variance of the event marking values SJie corresponding to all features TZie of the same label BQi to obtain the element distribution coefficient YFi of the label BQi, and mark the label BQi as a concentrated label or a dispersed label through the element distribution coefficient YFi; send the concentrated label and the dispersed label to the risk screening module;

[0011] The risk screening module is used to screen and analyze the data risk characteristics of the analysis platform;

[0012] The data management module is used to perform security management analysis on the data of the analysis platform.

[0013] Further, the specific process of determining whether the data security status of the analysis platform meets the requirements during the evaluation period includes: comparing the risk value with a preset risk threshold: if the risk value is less than the risk threshold, it is determined that the data security status of the analysis platform meets the requirements during the evaluation period, generate a risk handling signal and send the risk handling signal to the mobile terminal of the management personnel; if the risk value is greater than or equal to the risk threshold, it is determined that the data security status of the analysis platform does not meet the requirements during the evaluation period, mark the data with data risk events as analysis objects, and send all the analysis objects to the element analysis module.

[0014] Further, the specific process of marking the label BQi as a concentrated label or a dispersed label includes: comparing the element distribution coefficient YFi with a preset element distribution threshold YFmax: if the element distribution coefficient YFi is less than the element distribution threshold YFmax, it is determined that the label BQi does not have a concentrated feature, and mark the corresponding label BQi as a dispersed label; if the element distribution coefficient YFi is greater than or equal to the element distribution threshold YFmax, it is determined that the label BQi has a concentrated feature, and mark the corresponding label BQi as a concentrated label.

[0015] Further, the specific process of the risk screening module for screening and analyzing the data risk characteristics of the analysis platform includes: forming a screening set with the event marking values SJie of all features TZie in the same centralized label, removing the maximum element in the screening set, then calculating the variance of the screening set to obtain a screening coefficient, marking the risk factors with the screening coefficient, freely combining all the risk factors according to the centralized label to generate several risk identification data groups, and sending the risk identification data groups to the data management module.

[0016] Further, the specific process of marking the risk factors includes: comparing the screening coefficient with the preset element distribution threshold YFmax: if the screening coefficient is greater than or equal to the element distribution threshold YFmax, then removing the maximum element in the screening set, and then recalculating the screening coefficient, and so on until the screening coefficient is less than the element distribution threshold YFmax; if the screening coefficient is less than the element distribution threshold YFmax, then marking the feature TZie corresponding to the event marking value SJie removed from the screening set as a risk factor.

[0017] Further, the specific process of the data management module for security management and analysis of the data of the analysis platform includes: marking the data with state transitions in the analysis platform as management objects, obtaining the data elements of the management objects, extracting the parameters of the centralized label in the data elements, and determining whether there is at least one data group in the risk identification data group that is exactly the same as the parameters of the centralized label of the data elements of the management object: if so, marking the management object as a first-level risk object; if not, conducting in-depth analysis on the management object.

[0018] Further, the specific process of in-depth analysis of the management object includes: marking the quantities of the corresponding centralized label and decentralized label in the data elements of the management object as the centralized value and the decentralized value respectively, marking the ratio of the centralized value to the decentralized value as the management coefficient, and comparing the management coefficient with the preset management threshold: if the management coefficient is less than the management threshold, then marking the management object as a third-level risk object; if the management coefficient is greater than or equal to the management threshold, then marking the management object as a second-level risk object.

[0019] The data security intelligent analysis method based on data elements includes the following steps:

[0020] Step 1: Evaluate and analyze the data security status of the analysis platform: generate an evaluation period, mark the number of data risk events that occur in the analysis platform during the evaluation period as the risk value of the evaluation period, and determine whether the data security status of the analysis platform during the evaluation period meets the requirements through the risk value;

[0021] Step 2: Conduct data element analysis on the analysis objects of the analysis platform, mark the centralized tags and decentralized tags, and send the centralized tags and decentralized tags to the risk screening module and the risk assessment module;

[0022] Step 3: Conduct screening analysis on the data risk characteristics of the analysis platform: The event marker values SJie of all features TZie in the same centralized tag form a screening set, and the screening set is processed to remove elements to obtain a risk identification data group;

[0023] Step 4: Conduct security management analysis on the data of the analysis platform: Mark the data with state transitions in the analysis platform as management objects, and mark the management objects as first-level risk objects, second-level risk objects or third-level risk objects.

[0024] The present invention has the following beneficial effects:

[0025] 1. Through the data security assessment module, the data security status of the analysis platform can be evaluated and analyzed, the occurrence frequency of data risk events can be periodically counted to obtain a risk value, the overall risk level can be fed back according to the risk value, and element analysis is triggered when the overall risk level is abnormal to dynamically optimize the risk tags and characteristics;

[0026] 2. Through the element analysis module, data element analysis can be conducted on the analysis objects of the analysis platform, a tag-characteristic system can be formulated based on the states of data elements in different links, centralized characteristic analysis can be conducted on the distribution state of the number of analysis objects corresponding to different characteristics under the same tag, and then the tags can be differentially marked according to the analysis results to provide data support for the screening analysis process;

[0027] 3. Through the risk screening module, the data risk characteristics of the analysis platform can be screened and analyzed, the risk elements can be marked by forming a screening set and removing elements, and a risk identification data group is generated by combining the risk elements. The risk identification data group represents the high occurrence probability characteristics of data risk events. Periodic dynamic optimization and update of the risk identification data group can balance data real-time security and call efficiency;

[0028] 4. Through the data management module, security management analysis can be conducted on the data of the analysis platform. Based on the risk identification data group and the marking results of the centralized tags, the risk levels of management objects are marked, and sensitive data access policies and permission levels are generated according to the risk levels to ensure data security. Description of the Drawings

[0029] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0030] Figure 1 It is the system block diagram of Embodiment 1 of the present invention;

[0031] Figure 2 It is the method flowchart of Embodiment 2 of the present invention. Specific implementation manners

[0032] The following will clearly and completely describe the technical solutions of the present invention in combination with the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0033] Embodiment 1: As Figure 1 shown, a data security intelligent analysis platform based on data elements includes a data security assessment module, an element analysis module, a risk screening module, and a data management module that are connected in sequence.

[0034] The data security assessment module is used to evaluate and analyze the data security status of the analysis platform: generate an evaluation period, mark the number of data risk events that occur in the analysis platform during the evaluation period as the risk value of the evaluation period. Data risk events include data leakage, data loss, and illegal tampering. Compare the risk value with a preset risk threshold: if the risk value is less than the risk threshold, it is determined that the data security status of the analysis platform during the evaluation period meets the requirements, generate a risk handling signal and send the risk handling signal to the mobile terminal of the management personnel; if the risk value is greater than or equal to the risk threshold, it is determined that the data security status of the analysis platform during the evaluation period does not meet the requirements, mark the data with data risk events as the analysis object, and send all the analysis objects to the element analysis module; evaluate and analyze the data security status of the analysis platform, periodically count the occurrence frequency of data risk events to obtain the risk value, feedback the overall risk level according to the risk value, trigger element analysis when the overall risk level is abnormal, and dynamically optimize the risk labels and features.

[0035] The element analysis module is used to perform data element analysis on the analysis objects of the analysis platform: generate tags BQi according to the data elements of the analysis objects, where i = 1, 2, …, n and n is a positive integer. The tag BQi includes sensitivity level, transmission method, storage method, usage frequency, etc. Generate features TZie through the tag BQi, where e = 1, 2, …, m and m is a positive integer. Exemplarily, when the tag BQi is the sensitivity level, the features TZie include first-level sensitivity, second-level sensitivity, third-level sensitivity, etc.; mark the number of analysis objects whose data elements conform to the feature TZie as the event marking value SJie of the feature TZie. Calculate the variance of the event marking values SJie of all features TZie corresponding to the same tag BQi to obtain the element distribution coefficient YFi of the tag BQi. Compare the element distribution coefficient YFi with the preset element distribution threshold YFmax: If the element distribution coefficient YFi is less than the element distribution threshold YFmax, it is determined that the tag BQi does not have a concentrated feature, and the corresponding tag BQi is marked as a dispersed tag; if the element distribution coefficient YFi is greater than or equal to the element distribution threshold YFmax, it is determined that the tag BQi has a concentrated feature, and the corresponding tag BQi is marked as a concentrated tag; send the concentrated tags and dispersed tags to the risk screening module and the risk assessment module; perform data element analysis on the analysis objects of the analysis platform, formulate a tag-feature system based on the states of data elements in different links, conduct concentrated feature analysis on the distribution states of the numbers of analysis objects corresponding to different features under the same tag, and then differentially mark the tags according to the analysis results to provide data support for the screening analysis process.

[0036] The risk screening module is used to perform screening analysis on the data risk characteristics of the analysis platform: form a screening set with the event marking values SJie of all features TZie in the same concentrated tag, remove the largest element in the screening set, and then calculate the variance of the screening set to obtain the screening coefficient. Compare the screening coefficient with the preset element distribution threshold YFmax: If the screening coefficient is greater than or equal to the element distribution threshold YFmax, remove the largest element in the screening set and then recalculate the screening coefficient, and so on until the screening coefficient is less than the element distribution threshold YFmax; if the screening coefficient is less than the element distribution threshold YFmax, mark the feature TZie corresponding to the event marking value SJie removed from the screening set as a risk element, freely combine all the risk elements according to the concentrated tags to generate several risk identification data groups, and send the risk identification data groups to the data management module; perform screening analysis on the data risk characteristics of the analysis platform, mark the risk elements in the way of forming a screening set and removing elements, combine according to the risk elements to generate risk identification data groups. The risk identification data groups represent the high occurrence probability characteristics of data risk events. Periodically dynamically optimize and update the risk identification data groups to balance data real-time security and call efficiency.

[0037] The data management module is used to perform security management analysis on the data of the analysis platform: mark the data with state transitions in the analysis platform as management objects, obtain the data elements of the management objects, extract the parameters of the centralized labels in the data elements, and determine whether there is at least one data group in the risk identification data group that is exactly the same as the parameters of the centralized labels of the management object data elements. If so, mark the management object as a first-level risk object. If not, perform in-depth analysis on the management object: mark the quantities of the corresponding centralized labels and decentralized labels in the data elements of the management object as the centralized value and the decentralized value respectively, mark the ratio of the centralized value to the decentralized value as the management coefficient, and compare the management coefficient with a preset management threshold. If the management coefficient is less than the management threshold, mark the management object as a third-level risk object. If the management coefficient is greater than or equal to the management threshold, mark the management object as a second-level risk object. Perform security management analysis on the data of the analysis platform, mark the risk level of the management object based on the risk identification data group and the marking results of the centralized labels, and generate sensitive data access policies and permission levels according to the risk level to ensure data security.

[0038] Embodiment 2: As Figure 2 shown, a data security intelligent analysis method based on data elements includes the following steps:

[0039] Step 1: Evaluate and analyze the data security status of the analysis platform: generate an evaluation period, mark the number of data risk events that occur in the analysis platform during the evaluation period as the risk value of the evaluation period, and determine whether the data security status of the analysis platform during the evaluation period meets the requirements through the risk value.

[0040] Step 2: Analyze the data elements of the analysis objects of the analysis platform and mark the centralized labels and decentralized labels, and send the centralized labels and decentralized labels to the risk screening module and the risk assessment module.

[0041] Step 3: Screen and analyze the data risk characteristics of the analysis platform: mark the event marking values SJie of all features TZie in the same centralized label to form a screening set, and perform elimination processing on the screening set to obtain a risk identification data group.

[0042] Step 4: Perform security management analysis on the data of the analysis platform: mark the data with state transitions in the analysis platform as management objects, and mark the management objects as first-level risk objects, second-level risk objects or third-level risk objects.

[0043] A data security intelligent analysis platform based on data elements. When working, it generates an evaluation period, marks the number of data risk events occurring in the analysis platform during the evaluation period as the risk value of the evaluation period, and determines whether the data security status of the analysis platform during the evaluation period meets the requirements through the risk value; conducts data element analysis on the analysis objects of the analysis platform and marks the centralized tags and decentralized tags, and sends the centralized tags and decentralized tags to the risk screening module and the risk assessment module; forms a screening set with the event marking values SJie of all features TZie in the same centralized tag, and performs elimination processing on the screening set to obtain a risk identification data group; marks the data with state transitions occurring in the analysis platform as management objects, and marks the management objects as first-level risk objects, second-level risk objects or third-level risk objects.

[0044] The above content is only an example and explanation of the structure of the present invention. Those skilled in the art of this technology can make various modifications or supplements to the described specific embodiments or use similar methods to replace them. As long as they do not deviate from the structure of the invention or exceed the scope defined by this claim book, they should fall within the protection scope of the present invention.

[0045] In the description of this specification, the description with reference to terms such as "one embodiment", "example", "specific example", etc. means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0046] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not elaborate on all the details, nor do they limit the invention to only the specific implementation manners. Obviously, according to the content of this specification, many modifications and changes can be made. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the present invention, so that those skilled in the art of this technology can well understand and utilize the present invention. The present invention is only limited by the claim book and its full scope and equivalents.

Claims

1. A data security intelligent analysis platform based on data elements, characterized in that: It includes a data security assessment module, a factor analysis module, a risk screening module and a data management module which are connected in sequence; The data security assessment module generates an assessment cycle, marks the number of data risk events that occur in the analysis platform during the assessment cycle as the risk value of the assessment cycle, and uses the risk value to determine whether the data security status of the analysis platform during the assessment cycle meets the requirements; The element analysis module generates a label BQi according to the data element of the analysis object, where i=1, 2, ..., n, and n is a positive integer. The feature TZie is generated through the label BQi, where e=1, 2, ..., m, and m is a positive integer. The number of analysis objects whose data elements meet the feature TZie is marked as the event marking value SJie of the feature TZie. The variance of the event marking values ​​SJie corresponding to all the features TZie of the same label BQi is calculated to obtain the element distribution coefficient YFi of the label BQi. The label BQi is marked as a concentrated label or a dispersed label through the element distribution coefficient YFi. Send the centralized labels and decentralized labels to the risk screening module; The risk screening module screens and analyzes the data risk characteristics of the analysis platform and generates a risk identification data group; The data management module performs security management analysis on the data of the analysis platform based on the risk identification data group; The specific process of the risk screening module to screen and analyze the data risk features of the analysis platform includes: forming a screening set with the event marking values ​​SJie of all features TZie in the same centralized label, removing the largest element in the screening set, and then calculating the variance of the screening set to obtain the screening coefficient, marking the risk factors through the screening coefficient, freely combining all risk factors according to the centralized label to generate several risk identification data groups, and sending the risk identification data groups to the data management module.

2. According to claim 1, a data security intelligent analysis platform based on data elements is characterized in that: The specific process of determining whether the data security status of the analysis platform during the evaluation period meets the requirements includes: comparing the risk value with the preset risk threshold: if the risk value is less than the risk threshold, it is determined that the data security status of the analysis platform during the evaluation period meets the requirements, a risk processing signal is generated and the risk processing signal is sent to the mobile phone terminal of the administrator; if the risk value is greater than or equal to the risk threshold, it is determined that the data security status of the analysis platform during the evaluation period does not meet the requirements, the data with data risk events is marked as analysis objects, and all analysis objects are sent to the feature analysis module.

3. A data security intelligent analysis platform based on data elements according to claim 2, characterized in that: The specific process of marking the label BQi as a concentrated label or a dispersed label includes: comparing the element distribution coefficient YFi with the preset element distribution threshold YFmax: if the element distribution coefficient YFi is less than the element distribution threshold YFmax, it is determined that the label BQi does not have a concentrated feature, and the corresponding label BQi is marked as a dispersed label; if the element distribution coefficient YFi is greater than or equal to the element distribution threshold YFmax, it is determined that the label BQi has a concentrated feature, and the corresponding label BQi is marked as a concentrated label.

4. A data security intelligent analysis platform based on data elements according to claim 3, characterized in that: The specific process of marking risk factors includes: comparing the screening coefficient with the preset factor distribution threshold YFmax: if the screening coefficient is greater than or equal to the factor distribution threshold YFmax, the largest element in the screening set is eliminated, and then the screening coefficient is recalculated, and so on, until the screening coefficient is less than the factor distribution threshold YFmax; if the screening coefficient is less than the factor distribution threshold YFmax, the feature TZie corresponding to the event marking value SJie eliminated from the screening set is marked as a risk factor.

5. A data security intelligent analysis platform based on data elements according to claim 4, characterized in that: The specific process of the data management module performing security management analysis on the data of the analysis platform includes: marking the data that has undergone state changes in the analysis platform as management objects, obtaining the data elements of the management objects, extracting the parameters of the centralized labels in the data elements, and determining whether there is at least one data group in the risk identification data group that is exactly the same as the parameters of the centralized labels of the management object data elements: if so, marking the management object as a first-level risk object; if not, performing an in-depth analysis of the management object.

6. A data security intelligent analysis platform based on data elements according to claim 5, characterized in that: The specific process of in-depth analysis of the management object includes: marking the number of corresponding concentrated labels and dispersed labels in the data elements of the management object as concentrated values ​​and dispersed values ​​respectively, marking the ratio of the concentrated value to the dispersed value as the management coefficient, and comparing the management coefficient with the preset management threshold: if the management coefficient is less than the management threshold, the management object is marked as a third-level risk object; if the management coefficient is greater than or equal to the management threshold, the management object is marked as a second-level risk object.

7. A data security intelligent analysis method based on data elements, applied to a data security intelligent analysis platform based on data elements as described in any one of claims 1 to 6, characterized in that: The following steps are involved: Step 1: Evaluate and analyze the data security status of the analysis platform: Generate an evaluation cycle, mark the number of data risk events that occur in the analysis platform during the evaluation cycle as the risk value of the evaluation cycle, and use the risk value to determine whether the data security status of the analysis platform during the evaluation cycle meets the requirements; Step 2: Analyze the data elements of the analysis object of the analysis platform and mark the centralized labels and decentralized labels, and send the centralized labels and decentralized labels to the risk screening module and the risk assessment module; Step 3: Screen and analyze the data risk features of the analysis platform: The event tag values ​​SJie of all features TZie in the same set of tags constitute a screening set, and the screening set is eliminated to obtain a risk identification data group; Step 4: Conduct security management analysis on the data on the analysis platform: Mark the data that has undergone state changes in the analysis platform as management objects, and mark the management objects as first-level risk objects, second-level risk objects, or third-level risk objects.

Citation Information

Patent Citations

  • Data asset security protection method and system based on data elements

    CN118013502A

  • Service data security index evaluation method and device

    CN112560046A

  • Quantitative evaluation system and method for reducing risks of production operators

    CN114266441A