Data full life cycle safety management method

By classifying and setting the collected data, security management of the entire life cycle of the data is achieved, solving the problem that traditional data management methods are difficult to meet the real-time adjustment of data sensitivity and overall security policy requirements, and improving data security and compliance.

CN119987650AInactive Publication Date: 2025-05-13HUANENG ZHAOCAI DIGITAL TECHNOLOGY CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202411789787.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-06
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional data management methods are difficult to meet the needs of real-time adjustment of data sensitivity and overall security strategy for the entire life cycle of data. In addition, the existing technology has insufficient integration capabilities in data classification, storage, transmission, access, audit, etc., making it difficult to achieve accurate compliance management.

Method used

By classifying and grading the collected data, determining the data label of each piece of data, storing and transmitting each piece of data, determining the access restrictions and operating range of each piece of data, generating an audit report for each piece of data, and archiving or destroying each piece of data, safe management of the entire life cycle of data is realized.

Benefits of technology

It realizes refined control of failed storage and transmission, precise setting of access and operation permissions, improves data security, compliance and management efficiency, is suitable for complex data governance scenarios, and improves data governance efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119987650A_ABST
    Figure CN119987650A_ABST
Patent Text Reader

Abstract

The invention provides a data full life cycle safety management method, which belongs to the technical field of data processing, and comprises the following steps: classifying and grading collected data, determining the subcategory and sublevel of each piece of data in the collected data, and determining the data label of each piece of data; performing data storage and data transmission on each piece of data based on the data labels of all the data; determining an access limit and an operation range of each piece of data based on the data label, the historical access data and the historical operation data of each piece of data; and generating an audit report of each piece of data, and archiving or destroying each piece of data. According to the invention, the method achieves the precise control of failure storage and transmission and the precise setting of access and operation authority, achieves the precision and automation of risk control, improves the safety, compliance and management efficiency of data, can be more suitable for a complex data management scene, and improves the data management efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to a data full life cycle security management method. Background Art

[0002] With the surge in data volume and the diversification of data types, traditional data management methods are unable to meet the refined and dynamic security needs. Data is usually classified and stored in a static manner, making it difficult to make real-time adjustments based on data sensitivity. Existing data protection measures, such as access control and encryption technology, are often isolated and applied to a single link, lacking an overall security strategy throughout the entire life cycle of data. In addition, enterprises face increasingly stringent compliance requirements, but existing technologies lack the integration capabilities in data classification, storage, transmission, access, and auditing, making it difficult to achieve accurate compliance management. At the same time, the lack of dynamic assessment of data usage status and risks leads to low data storage efficiency and increased risks.

[0003] Therefore, the present invention provides a data full life cycle security management method. Summary of the invention

[0004] The present invention provides a data life cycle security management method, which classifies and grades the collected data, determines the data label of each data, performs data storage and data transmission for each data, determines the access restriction and operation scope of each data, generates an audit report for each data, and archives or destroys each data, thereby achieving refined control of failed storage and transmission and accurate setting of access and operation permissions, achieving precise and automated risk control, improving data security, compliance and management efficiency, and being more suitable for complex data governance scenarios, thereby improving data governance efficiency.

[0005] The present invention provides a data lifecycle security management method, comprising: 101: Classify and grade the collected data, determine the subcategory and sublevel of each piece of data in the collected data, and determine the data label of each piece of data; 102: Perform data storage and data transmission for each piece of data based on data labels of all data; 103: Determine access restrictions and operation scopes for each piece of data based on the data label, historical access data, and historical operation data of each piece of data; 104: Generate an audit report for each piece of data and archive or destroy each piece of data.

[0006] According to a data lifecycle security management method provided by the present invention, the collected data is classified and graded, the subcategory and sublevel of each piece of data in the collected data are determined, and the data label of each piece of data is determined, including: Preprocess the collected data, extract features from each piece of preprocessed data, and determine the feature vector of each piece of data; Determine a subcategory of each preprocessed data based on the feature vectors of all data and the data classification standard, and determine a first category based on all subcategories; Determine the sublevel of each piece of data in each sublevel of the first category based on the feature vectors of all data in each sublevel of the first category and the data classification standard of each sublevel, and determine the first level of each sublevel based on all sublevels of each sublevel; The data label of each piece of data is determined based on the subcategory and sublevel of each piece of data.

[0007] According to a data lifecycle security management method provided by the present invention, data storage and data transmission are performed on each piece of data based on data tags of all data, including: Classify all data based on data labels and determine the label set for each data label; Extract key features related to storage requirements from the feature vectors of all data to determine the first key feature vector of each piece of data. At the same time, extract key features related to transmission requirements from the feature vectors of all data to determine the second key feature vector of each piece of data. Analyze the first key characteristic vectors of all data in the tag set of each data tag respectively to determine the fitting storage requirements of each data tag, and at the same time, analyze the second key characteristic vectors of all data in the tag set of each data tag respectively to determine the fitting transmission characteristics of each data tag; Based on the fitting storage requirements of each data tag, the storage rules of each data tag are determined, and at the same time, based on the fitting transmission characteristics of each data tag, the transmission strategy of each data tag is determined; Based on the storage rules of the data tags, each piece of data in the tag set of the data tags is stored; Data is transmitted for each piece of data in the tag set of the data tag based on the transmission strategy of the data tag.

[0008] According to a data lifecycle security management method provided by the present invention, the access restriction and operation scope of each piece of data are determined based on the data tag, historical access data and historical operation data of each piece of data, including: Extract historical access data and historical operation data of each data within multiple specified time periods; Based on the data label of each piece of data and the historical access data and historical operation records within multiple specified time periods, determine the operation risk value and access risk value of each piece of data, and determine the comprehensive risk value of each piece of data; Determine whether the comprehensive risk value of each piece of data is lower than the preset comprehensive risk threshold, and determine the data whose comprehensive risk value is not lower than the preset comprehensive risk threshold as risk data; For data whose comprehensive risk value is lower than the preset comprehensive risk threshold, the access restriction of the data is determined based on the data label and access risk value of the data. At the same time, the operation scope of the data is determined based on the data label and operation risk value of the data.

[0009] According to a data lifecycle security management method provided by the present invention, based on the data tag of each piece of data and historical access data and historical operation records within multiple specified time periods, the operation risk value and access risk value of each piece of data are determined, including: Determine the operational risk value of each piece of data based on the data label of each piece of data and historical operational data within multiple specified time periods; in, Indicates the operational risk value of the sth data. Indicates the operating frequency of the sth data in the tth specified time period, It represents the risk value of the operation type of the ith operation of the sth data in the tth specified time period. It represents the operation range risk value of the ith operation of the sth data in the tth specified time period. represents the operator risk value of operator A for the ith operation of the sth data in the tth specified time period, represents the first magnification factor of the t-th specified time period, Indicates the abnormal operation frequency of the sth data in the tth specified time period, represents the first adjustment coefficient, Indicates the number of operations on the sth data in the tth specified time period. represents the period attenuation coefficient, N2 represents the number of specified time periods, The second weight representing the comprehensive risk value; Determine the access risk value of each piece of data based on the data label of each piece of data and historical access data within multiple specified time periods; in, Indicates the access risk value of the sth data. Indicates the access frequency of the sth data in the tth specified time period, represents the visitor risk value of visitor B who visited the sth data for the jth time in the tth specified time period, represents the access behavior risk value of the jth access to the sth data in the tth specified time period, Indicates the number of times the sth data item is accessed in the tth specified time period. represents the second magnification factor of the t-th specified time period, Indicates the abnormal access frequency of the sth data in the tth specified time period, represents the second adjustment coefficient, represents the access behavior adjustment coefficient, Represents the third weight of the comprehensive risk value.

[0010] According to a data lifecycle security management method provided by the present invention, the comprehensive risk value of each piece of data is determined, including: Calculate the comprehensive risk value of each piece of data based on the data label, operation risk value, and access risk value of each piece of data; in, represents the comprehensive risk value of the sth data, represents the subcategory risk value of the data label of the s-th data, represents the sub-level risk value of the data label of the s-th data, represents the data label risk value of the s-th data, They respectively represent the first weight and the fourth weight of the comprehensive risk value.

[0011] According to a data lifecycle security management method provided by the present invention, an audit report for each piece of data is generated, including: Generate an audit report for each piece of risk data based on the operation frequency, abnormal operation frequency, access frequency, abnormal access frequency, operation risk value, access risk value and comprehensive risk value of each piece of risk data in multiple specified time periods; An audit report for each piece of data that is not risk data is generated based on the historical access data, historical operation data, operation risk value, access risk value, comprehensive risk value, access restrictions and operation scope of each piece of data that is not risk data in multiple specified time periods.

[0012] According to a data lifecycle security management method provided by the present invention, each piece of data is archived or destroyed, including: Determine whether each piece of risk data is active data. If so, mark the data that is both risk data and active data as risk active and archive the data. Otherwise, destroy the data that is both risk data and not active data. Determine whether each piece of data that is not risk data is terminated data. If so, destroy the data that is not risk data and is terminated data. Otherwise, mark the data that is neither risk data nor terminated data as non-risk and non-terminated, and archive the data.

[0013] Compared with the prior art, the present invention has the following beneficial effects: By classifying and grading the collected data, determining the data label for each piece of data, storing and transmitting each piece of data, determining the access restrictions and operating scope of each piece of data, generating an audit report for each piece of data, and archiving or destroying each piece of data, we achieve refined control of invalid storage and transmission and precise setting of access and operating permissions, achieve precise and automated risk control, improve data security, compliance and management efficiency, and can be more suitable for complex data governance scenarios, thereby improving data governance efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0015] Figure 1 It is a flow chart of a data full life cycle security management method provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0016] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0017] Embodiment 1: The present invention provides a data life cycle security management method. Figure 1 As shown, including: 101: Classify and grade the collected data, determine the subcategory and sublevel of each piece of data in the collected data, and determine the data label of each piece of data; 102: Perform data storage and data transmission for each piece of data based on data labels of all data; 103: Determine access restrictions and operation scopes for each piece of data based on the data label, historical access data, and historical operation data of each piece of data; 104: Generate an audit report for each piece of data and archive or destroy each piece of data.

[0018] In this embodiment, the full life cycle security management includes the data collection stage: classifying and grading the collected data, determining the subcategory and sublevel of each piece of data in the collected data, and determining the data label of each piece of data; the data storage and transmission stage: data storage and transmission of each piece of data based on the data labels of all data; the data usage stage: determining the access restrictions and operation scope of each piece of data based on the data label, historical access data and historical operation data of each piece of data; the post-data use stage: generating an audit report for each piece of data, and archiving or destroying each piece of data.

[0019] In this embodiment, the collected data is allocated to different subcategories according to the data type (such as sensitive data, general data, risk data, etc.).

[0020] In this embodiment, each type of data is divided into sub-levels (eg, high risk, medium risk, low risk) based on the importance or sensitivity of the data.

[0021] In this embodiment, the allowed access restrictions are set for each piece of data, and at the same time, the allowed operation permissions are set for each piece of data.

[0022] The beneficial effects of the above technical solution are as follows: by classifying and grading the collected data, determining the data label of each piece of data, storing and transmitting each piece of data, determining the access restrictions and operation scope of each piece of data, generating an audit report for each piece of data, and archiving or destroying each piece of data, refined control of invalid storage and transmission and precise setting of access and operation permissions are achieved, precise and automated risk control is achieved, data security, compliance and management efficiency are improved, and it can be more suitable for complex data governance scenarios and improve data governance efficiency.

[0023] Embodiment 2: The embodiment of the present invention provides a data lifecycle security management method, which classifies and grades the collected data, determines the subcategory and sublevel of each piece of data in the collected data, and determines the data label of each piece of data, including: Preprocess the collected data, extract features from each piece of preprocessed data, and determine the feature vector of each piece of data; Determine a subcategory of each preprocessed data based on the feature vectors of all data and the data classification standard, and determine a first category based on all subcategories; Determine the sublevel of each piece of data in each sublevel of the first category based on the feature vectors of all data in each sublevel of the first category and the data classification standard of each sublevel, and determine the first level of each sublevel based on all sublevels of each sublevel; The data label of each piece of data is determined based on the subcategory and sublevel of each piece of data.

[0024] In this embodiment, the feature vector represents the basic information of the corresponding data, including the data size characteristics, data structure characteristics, data type characteristics, data usage characteristics, data timeliness characteristics, data transmission and access characteristics, and data security characteristics of the corresponding data.

[0025] In this embodiment, the collected data is normalized, cleaned, denoised, etc. to ensure data quality and consistency.

[0026] In this embodiment, the features of the data are extracted through algorithms (such as principal component analysis, deep learning, etc.) to form a numerical feature vector for each piece of data.

[0027] In this embodiment, each piece of preprocessed data corresponds to a subcategory, and each subcategory in the first category includes at least one piece of data.

[0028] In this embodiment, each category in the first category corresponds to a first level, and each sublevel in the first level includes at least one or more pieces of data.

[0029] In this embodiment, each subcategory in the first category may be a sensitive category, a compliance category, a value category, etc.

[0030] In this embodiment, for example, the sublevels in the first level of the sensitive subcategory may be a low sensitivity level, a medium sensitivity level, and a high sensitivity level.

[0031] In this embodiment, a unique data label is generated based on the subcategory and sublevel of each piece of data, including classification and grading information.

[0032] The beneficial effects of the above technical solution are: classifying and grading the collected data, determining the subcategory and sublevel of each piece of collected data, and determining the data label of each piece of data, which can improve the standardization, flexibility and efficiency of data life cycle security management in the data collection stage, and is more suitable for large-scale and multi-dimensional scenarios.

[0033] Embodiment 3: The embodiment of the present invention provides a data lifecycle security management method, which performs data storage and data transmission for each piece of data based on data tags of all data, including: Classify all data based on data labels and determine the label set for each data label; Extract key features related to storage requirements from the feature vectors of all data to determine the first key feature vector of each piece of data. At the same time, extract key features related to transmission requirements from the feature vectors of all data to determine the second key feature vector of each piece of data. Analyze the first key characteristic vectors of all data in the tag set of each data tag respectively to determine the fitting storage requirements of each data tag, and at the same time, analyze the second key characteristic vectors of all data in the tag set of each data tag respectively to determine the fitting transmission characteristics of each data tag; Based on the fitting storage requirements of each data tag, the storage rules of each data tag are determined, and at the same time, based on the fitting transmission characteristics of each data tag, the transmission strategy of each data tag is determined; Based on the storage rules of the data tags, each piece of data in the tag set of the data tags is stored; Data is transmitted for each piece of data in the tag set of the data tag based on the transmission strategy of the data tag.

[0034] In this embodiment, storage key features of each piece of data are extracted based on storage-related factors (such as data size, frequency, sensitivity, etc.) to form a first key feature vector.

[0035] In this embodiment, based on transmission-related factors (such as transmission frequency, real-time requirements, network bandwidth requirements, etc.), transmission key features of each piece of data are extracted to form a second key feature vector.

[0036] In this embodiment, storage rules are formulated for each data tag based on the fitting storage requirements. For example, the fitting storage requirements in the data tags of sensitive subcategories and high-sensitivity sublevels are medium to large files, medium-frequency access, long-term storage, and high sensitivity, and the fitting storage rules are large-capacity storage (HDD+cold storage) and encrypted storage.

[0037] In this embodiment, a transmission strategy is formulated for each data tag based on the fitted transmission characteristics. For example, the fitted transmission characteristics of the data tags of the sensitive subcategory and the high-sensitivity sublevel are 200MB of data size, medium frequency of update frequency, medium delay, and text type. The transmission strategy is segmented transmission + medium delay, and the mode can be batch upload + verification retransmission.

[0038] In this embodiment, a storage operation is performed on each piece of data according to the storage rule to ensure that the data storage method matches the tag requirements.

[0039] In this embodiment, a transmission operation is performed on each piece of data according to the transmission strategy to ensure that the data transmission method is efficient and safe.

[0040] The beneficial effects of the above technical solution are: data storage and transmission of each piece of data based on the data tags of all data can improve the resource utilization efficiency of data security management during the data storage and transmission stages throughout the data life cycle, and enhance the security and availability of data.

[0041] Embodiment 4: The embodiment of the present invention provides a data lifecycle security management method, which determines the access restriction and operation scope of each piece of data based on the data label, historical access data and historical operation data of each piece of data, including: Extract historical access data and historical operation data of each data within multiple specified time periods; Based on the data label of each piece of data and the historical access data and historical operation records within multiple specified time periods, determine the operation risk value and access risk value of each piece of data, and determine the comprehensive risk value of each piece of data; Determine whether the comprehensive risk value of each piece of data is lower than the preset comprehensive risk threshold, and determine the data whose comprehensive risk value is not lower than the preset comprehensive risk threshold as risk data; For data whose comprehensive risk value is lower than the preset comprehensive risk threshold, the access restriction of the data is determined based on the data label and access risk value of the data. At the same time, the operation scope of the data is determined based on the data label and operation risk value of the data.

[0042] In this embodiment, the historical access data records the historical track of data access within the corresponding specified time period, including information such as access frequency, subject, and method.

[0043] In this embodiment, the historical operation data records the historical records of operations performed within a specified time period corresponding to the data, including information such as operation type, frequency, and subject.

[0044] In this embodiment, the comprehensive risk threshold represents a preset upper limit of the risk value, which is used to distinguish normal data from risky data.

[0045] In this embodiment, risk data refers to data whose comprehensive risk value is not lower than a threshold value, and normal data refers to data whose comprehensive risk value is lower than the threshold value.

[0046] In this embodiment, the access restriction is a rule for limiting the data access method, such as specifying the access subject, time period, access method, etc.

[0047] In this embodiment, the operation scope is the limiting rules for data operation behavior, such as prohibition of deletion, read-only mode, etc.

[0048] The beneficial effects of the above technical solution are as follows: by determining the access restrictions and operation scope of each piece of data based on the data label, historical access data and historical operation data of each piece of data, the data security and controllability of sensitive data in the data usage stage of the data life cycle security management can be improved, and the precision and automation of risk control can be achieved.

[0049] Embodiment 5: The embodiment of the present invention provides a data lifecycle security management method, which determines the operation risk value and access risk value of each piece of data based on the data tag of each piece of data and the historical access data and historical operation records within a plurality of specified time periods, including: Determine the operational risk value of each piece of data based on the data label of each piece of data and historical operational data within multiple specified time periods; in, Indicates the operational risk value of the sth data. Indicates the operating frequency of the sth data in the tth specified time period, It represents the risk value of the operation type of the ith operation of the sth data in the tth specified time period. It represents the operation range risk value of the ith operation of the sth data in the tth specified time period. represents the operator risk value of operator A for the ith operation of the sth data in the tth specified time period, represents the first magnification factor of the t-th specified time period, Indicates the abnormal operation frequency of the sth data in the tth specified time period, represents the first adjustment coefficient, Indicates the number of operations on the sth data in the tth specified time period. represents the period attenuation coefficient, N2 represents the number of specified time periods, The second weight representing the comprehensive risk value; Determine the access risk value of each piece of data based on the data label of each piece of data and historical access data within multiple specified time periods; in, Indicates the access risk value of the sth data. Indicates the access frequency of the sth data in the tth specified time period, represents the visitor risk value of visitor B who visited the sth data for the jth time in the tth specified time period, represents the access behavior risk value of the jth access to the sth data in the tth specified time period, Indicates the number of times the sth data item is accessed in the tth specified time period. represents the second magnification factor of the t-th specified time period, Indicates the abnormal access frequency of the sth data in the tth specified time period, represents the second adjustment coefficient, represents the access behavior adjustment coefficient, Represents the third weight of the comprehensive risk value.

[0050] In this embodiment, the first weight Represents the weight based on the risk value of the data label, the second weight Represents the weight based on the operational risk value, the third weight Represents the weight based on the access risk value, the fourth weight Represents the weight based on data label risk value, operation risk value, and access risk value.

[0051] In this embodiment, the operation may be reading, modifying, deleting, etc., and the corresponding operation type risk values ​​may be 0.5, 1, and 1.5, respectively.

[0052] In this embodiment, the operation range may be an operation on one piece of data, an operation on multiple pieces of data, or a batch operation on more than X pieces of data, and the corresponding operation range risk values ​​may be 1, 2, or 3, respectively.

[0053] In this embodiment, the operator can be a common user, a privileged user, or an administrator, and the corresponding operator risk values ​​can be 0.5, 1, or 2, respectively.

[0054] In this embodiment, the visitor can be a common user, a privileged user, or an administrator, and the corresponding visitor risk values ​​can be 0.5, 1, or 2, respectively. In this embodiment, the access behavior may be normal access, batch access, or automated access (script), and the corresponding access behavior risk values ​​may be 1, 1.5, or 2, respectively.

[0055] In this embodiment, the operational risk value is to evaluate the potential threat of the operational behavior to the data based on the historical operational data and data labels within multiple specified time periods.

[0056] In this embodiment, the access risk value is to evaluate the potential threat of access behavior to data based on historical access data and data tags within multiple specified time periods.

[0057] The beneficial effects of the above technical solution are as follows: based on the data label of each piece of data and the historical access data and historical operation records within multiple specified time periods, the operation risk value and access risk value of each piece of data are determined, which can provide a data basis for determining the comprehensive risk value of each piece of data, thereby realizing precise risk control.

[0058] Embodiment 6: The embodiment of the present invention provides a data lifecycle security management method, which determines the comprehensive risk value of each piece of data, including: Calculate the comprehensive risk value of each piece of data based on the data label, operation risk value, and access risk value of each piece of data; in, represents the comprehensive risk value of the sth data, represents the subcategory risk value of the data label of the s-th data, represents the sub-level risk value of the data label of the s-th data, represents the data label risk value of the s-th data, They respectively represent the first weight and the fourth weight of the comprehensive risk value.

[0059] In this embodiment, the comprehensive risk value combines the data tag risk value, the operation risk value and the access risk value to reflect the overall risk level of the data.

[0060] The beneficial effects of the above technical solution are: determining the comprehensive risk value of each piece of data can provide a data basis for judging whether it is risky data, determining the access restrictions and operation scope of the data, dynamically adjusting the data management strategy, and further improving the accuracy of risk control.

[0061] Embodiment 7: The embodiment of the present invention provides a data lifecycle security management method, which generates an audit report for each piece of data, including: Generate an audit report for each piece of risk data based on the operation frequency, abnormal operation frequency, access frequency, abnormal access frequency, operation risk value, access risk value and comprehensive risk value of each piece of risk data in multiple specified time periods; An audit report for each piece of data that is not risk data is generated based on the historical access data, historical operation data, operation risk value, access risk value, comprehensive risk value, access restrictions and operation scope of each piece of data that is not risk data in multiple specified time periods.

[0062] In this embodiment, the operation frequency represents the total number of operations (modification, deletion, movement, etc.) performed on data within a specified time period, and each specified time period corresponds to an operation frequency.

[0063] In this embodiment, the abnormal operation frequency represents the total number of illegal or abnormal operation behaviors occurring within a specified time period, and each specified time period corresponds to an abnormal operation frequency.

[0064] In this embodiment, the access frequency represents the total number of times data is accessed within a specified time period, and each specified time period corresponds to an access frequency.

[0065] In this embodiment, the abnormal access frequency represents the total number of abnormal access behaviors involving data within a specified time period, and each specified time period corresponds to an abnormal access frequency.

[0066] The beneficial effects of the above technical solution: Generating an audit report for each piece of data can achieve refined tracking and dynamic management of data access and operation behaviors, strengthen data security prevention and control and compliance review, and improve data governance efficiency.

[0067] Embodiment 8: The embodiment of the present invention provides a data lifecycle security management method, which archives or destroys each piece of data, including: Determine whether each piece of risk data is active data. If so, mark the data that is both risk data and active data as risk active and archive the data. Otherwise, destroy the data that is both risk data and not active data. Determine whether each piece of data that is not risk data is terminated data. If so, destroy the data that is not risk data and is terminated data. Otherwise, mark the data that is neither risk data nor terminated data as non-risk and non-terminated, and archive the data.

[0068] In this embodiment, active data means that although the data is risky data, it still has operational and access value, and therefore, it is archived.

[0069] In this embodiment, terminating data means that the data is no longer valuable and therefore is destroyed.

[0070] In this embodiment, data archiving means storing data for a long period of time for future reference or backup.

[0071] In this embodiment, data destruction means physically or logically deleting the data to ensure that it is irrecoverable.

[0072] The beneficial effects of the above technical solution are: archiving or destroying each piece of data can achieve precise control of data storage resources, optimize data security and the post-data use stage of life cycle management, and improve the intelligence and compliance level of data management.

[0073] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.

[0074] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0075] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A data life cycle security management method, characterized in that: include: 101: Classify and grade the collected data, determine the subcategory and sublevel of each piece of data in the collected data, and determine the data label of each piece of data; 102: Perform data storage and data transmission for each piece of data based on data labels of all data; 103: Determine access restrictions and operation scopes for each piece of data based on the data label, historical access data, and historical operation data of each piece of data; 104: Generate an audit report for each piece of data and archive or destroy each piece of data.

2. A data lifecycle security management method according to claim 1, characterized in that: Classify and grade the collected data, determine the subcategory and sublevel of each piece of collected data, and determine the data label of each piece of data, including: Preprocess the collected data, extract features from each piece of preprocessed data, and determine the feature vector of each piece of data; Determine a subcategory of each preprocessed data based on the feature vectors of all data and the data classification standard, and determine a first category based on all subcategories; Determine the sublevel of each piece of data in each sublevel of the first category based on the feature vectors of all data in each sublevel of the first category and the data classification standard of each sublevel, and determine the first level of each sublevel based on all sublevels of each sublevel; The data label of each piece of data is determined based on the subcategory and sublevel of each piece of data.

3. A data lifecycle security management method according to claim 2, characterized in that: Data storage and data transmission for each piece of data are performed based on the data labels of all data, including: Classify all data based on data labels and determine the label set for each data label; Extract key features related to storage requirements from the feature vectors of all data to determine the first key feature vector of each piece of data. At the same time, extract key features related to transmission requirements from the feature vectors of all data to determine the second key feature vector of each piece of data. Analyze the first key characteristic vectors of all data in the tag set of each data tag respectively to determine the fitting storage requirements of each data tag, and at the same time, analyze the second key characteristic vectors of all data in the tag set of each data tag respectively to determine the fitting transmission characteristics of each data tag; Based on the fitting storage requirements of each data tag, the storage rules of each data tag are determined, and at the same time, based on the fitting transmission characteristics of each data tag, the transmission strategy of each data tag is determined; Based on the storage rules of the data tags, each piece of data in the tag set of the data tags is stored; Data is transmitted for each piece of data in the tag set of the data tag based on the transmission strategy of the data tag.

4. A data lifecycle security management method according to claim 1, characterized in that: Determine the access restrictions and operation scope of each piece of data based on the data label, historical access data, and historical operation data of each piece of data, including: Extract historical access data and historical operation data of each data within multiple specified time periods; Based on the data label of each piece of data and the historical access data and historical operation records within multiple specified time periods, determine the operation risk value and access risk value of each piece of data, and determine the comprehensive risk value of each piece of data; Determine whether the comprehensive risk value of each piece of data is lower than the preset comprehensive risk threshold, and determine the data whose comprehensive risk value is not lower than the preset comprehensive risk threshold as risk data; For data whose comprehensive risk value is lower than the preset comprehensive risk threshold, the access restriction of the data is determined based on the data label and access risk value of the data. At the same time, the operation scope of the data is determined based on the data label and operation risk value of the data.

5. A data lifecycle security management method according to claim 4, characterized in that: Based on the data label of each piece of data and the historical access data and historical operation records within multiple specified time periods, the operation risk value and access risk value of each piece of data are determined, including: Determine the operational risk value of each piece of data based on the data label of each piece of data and the historical operational data within multiple specified time periods; in, Indicates the operational risk value of the sth data. Indicates the operating frequency of the sth data in the tth specified time period, It represents the risk value of the operation type of the ith operation of the sth data in the tth specified time period. It represents the operation range risk value of the ith operation of the sth data in the tth specified time period. represents the operator risk value of operator A for the ith operation of the sth data in the tth specified time period, represents the first magnification factor of the t-th specified time period, Indicates the abnormal operation frequency of the sth data in the tth specified time period, represents the first adjustment coefficient, Indicates the number of operations on the sth data in the tth specified time period. represents the period attenuation coefficient, N2 represents the number of specified time periods, The second weight representing the comprehensive risk value; Determine the access risk value of each piece of data based on the data label of each piece of data and historical access data within multiple specified time periods; in, Indicates the access risk value of the sth data. Indicates the access frequency of the sth data in the tth specified time period, represents the visitor risk value of visitor B who visited the sth data for the jth time in the tth specified time period, represents the access behavior risk value of the jth access to the sth data in the tth specified time period, Indicates the number of times the sth data item is accessed in the tth specified time period. represents the second magnification factor of the t-th specified time period, Indicates the abnormal access frequency of the sth data in the tth specified time period, represents the second adjustment coefficient, represents the access behavior adjustment coefficient, Represents the third weight of the comprehensive risk value.

6. A data lifecycle security management method according to claim 5, characterized in that: Determine the comprehensive risk value of each piece of data, including: Calculate the comprehensive risk value of each piece of data based on the data label, operation risk value, and access risk value of each piece of data; in, represents the comprehensive risk value of the sth data, represents the subcategory risk value of the data label of the s-th data, represents the sub-level risk value of the data label of the s-th data, represents the data label risk value of the s-th data, They respectively represent the first weight and the fourth weight of the comprehensive risk value.

7. A data lifecycle security management method according to claim 1, characterized in that: Generate an audit report for each piece of data, including: Generate an audit report for each piece of risk data based on the operation frequency, abnormal operation frequency, access frequency, abnormal access frequency, operation risk value, access risk value and comprehensive risk value of each piece of risk data in multiple specified time periods; An audit report is generated for each piece of data that is not risk data based on historical access data, historical operation data, operation risk value, access risk value, comprehensive risk value, access restrictions and operation scope over multiple specified time periods for each piece of data that is not risk data.

8. A data lifecycle security management method according to claim 7, characterized in that: Archive or destroy each piece of data, including: Determine whether each piece of risk data is active data. If so, mark the data that is both risk data and active data as risk active and archive the data. Otherwise, destroy the data that is both risk data and not active data. Determine whether each piece of data that is not risk data is terminated data. If so, destroy the data that is not risk data and is terminated data. Otherwise, mark the data that is neither risk data nor terminated data as non-risk and non-terminated, and archive the data.

Citation Information

Patent Citations

  • Data security control method and data security control platform

    CN104796290A

  • Data security control method and system based on data classification and grading

    CN106682527A

  • Medical data system based on risk and UCON access control model

    CN114861224A

  • Hierarchical management data anti-leakage management method and system and storage medium

    CN117951716A

  • Network data security protection method and system based on big data

    CN118631577A