Integrated data management method and system based on cloud native
By analyzing, evaluating and sorting the security level of enterprise data and using encryption mechanisms for management, the security management problems of enterprise data on the cloud platform are solved, and the comprehensive protection and management of data is achieved, improving the data security and privacy protection effect.
Patent Information
- Application Number
- CN202510122069.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-24
- Publication Date
- 2025-05-16
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
With the growth of enterprise data scale and the intensification of data breaches, it is difficult for existing technologies to effectively manage and protect enterprise data, especially on cloud platforms.
By obtaining integrated data from the enterprise database, analyzing and dividing it into data blocks, determining the value characteristic factors and sensitive characteristic factors of each data block, the importance evaluation and security level division are carried out based on these factors, and finally determining the corresponding encryption mechanism from the cloud-native platform for data management.
It significantly improves the security of data, ensures that even if the data is stolen, sensitive information will not be leaked, helps enterprises better understand the importance of data, and take corresponding security measures to reduce the risk of data breaches and improve compliance.
Smart Images

Figure CN120011343A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data management technology, and in particular to a cloud-native based integrated data management method and system. Background Art
[0002] With the continuous development and popularization of cloud computing technology, more and more enterprises are beginning to migrate their businesses and data to cloud platforms. As a modern application development and deployment method, cloud native technology provides enterprises with more flexible, scalable and efficient cloud computing solutions. In this context, integrated data management methods have emerged based on cloud native technology to help enterprises better manage and protect their data assets.
[0003] However, as the scale of enterprise data continues to grow and the risk of data leakage becomes increasingly severe, the security management of enterprise data has become crucial. Against this background, an integrated data security management method based on cloud native has emerged, which can provide enterprises with comprehensive data protection and security management solutions. Summary of the invention
[0004] In order to solve the above technical problems, the present invention provides an integrated data management method and system based on cloud native, including: Obtaining integrated data from an enterprise database, determining content information corresponding to all data in the integrated data, and dividing the integrated data into a number of data blocks based on the content information; Analyze the content information corresponding to all the data in each data block to determine the value characteristic factors and sensitive characteristic factors in the content information corresponding to all the data in each data block; Analyze and evaluate the importance of each data block based on the value characteristic factor and the sensitive characteristic factor to obtain the importance evaluation value of each data block; Classify each data block into security levels according to the importance assessment value and determine the security level of each data block; Determine the storage and transmission encryption mechanism corresponding to the security level from the cloud native platform, and encrypt and manage each data block according to the corresponding storage and transmission encryption mechanism.
[0005] Furthermore, the step of acquiring the integrated data from the enterprise database, determining the content information corresponding to all the data in the integrated data, and dividing the integrated data into a plurality of data blocks based on the content information includes: Obtain integrated data from the enterprise database and determine the data content corresponding to all data in the integrated data; Extract keywords from the data content and use the keywords as the content information corresponding to each data in the integrated data; The correlation between the content information corresponding to the data is analyzed, and the data with close correlation between the content information are grouped together to obtain several data blocks, that is, the integrated data is divided into several data blocks based on the content information.
[0006] Furthermore, the analysis data corresponds to the correlation between the content information, and the data with close correlation between the content information are grouped together to obtain a number of data blocks, including: Obtain the semantic meaning of the content information corresponding to each data, and convert each data into a vector based on the semantic meaning; The cosine similarity between all vectors is calculated, and the cosine similarity greater than a preset threshold is used as a condition for close association. The data corresponding to the vectors with cosine similarity greater than the preset threshold are collected to obtain several data blocks.
[0007] Furthermore, the analyzing of the content information corresponding to all the data in each data block to determine the value characteristic factor and the sensitive characteristic factor in the content information corresponding to all the data in each data block includes: Obtaining a number of content information corresponding to each data in the data block, and determining the semantic meaning of each content information; Calculate the relevance between the semantic meaning of each content information and its value and sensitivity respectively, and obtain the value relevance value and sensitivity relevance value of each content information respectively; The content information with the highest value association value among the plurality of content information is determined as the value characteristic factor corresponding to each data, and the content information with the highest sensitivity association value among the plurality of content information is determined as the sensitive characteristic factor corresponding to each data.
[0008] Furthermore, the importance of each data block is analyzed and evaluated based on the value feature factor and the sensitive feature factor to obtain the importance evaluation value of each data block, including: Obtain the value association value of the value characteristic factor and the sensitivity association value of the sensitive characteristic factor corresponding to each data, and obtain the preset standard value association value and the preset standard sensitivity association value; Calculate the difference between the value association value of the value characteristic factor corresponding to each data and the preset standard value association value to obtain a first difference, and calculate the difference between the sensitivity association value of the sensitive characteristic factor corresponding to each data and the preset standard sensitivity association value to obtain a second difference; The first difference and the second difference are evaluated and valued respectively, and the value difference evaluation value of the value characteristic factor and the sensitivity difference evaluation value of the sensitive characteristic factor of each data are obtained respectively; The preset first weight of the value feature factor and the preset second weight of the sensitive association value are obtained, and the importance evaluation value of the data block is determined based on the preset first weight of the value feature factor and the value difference evaluation value corresponding to each data in the data block and the preset second weight of the sensitive feature factor and the sensitivity difference evaluation value, wherein the calculation formula of the importance evaluation value of the data block is: , Among them, S is the importance evaluation value of the data block, α is the preset first weight of the value feature factor, Pi is the value difference evaluation value of the value feature factor corresponding to each data, β is the preset second weight of the sensitive feature factor, Qi is the sensitivity difference evaluation value of the sensitive feature factor corresponding to each data, and n is the number of data in the data block.
[0009] Furthermore, the security level of each data block is divided according to the importance evaluation value to determine the security level of each data block, including: Two security levels and a security level-importance evaluation value interval correspondence relationship are pre-set, wherein the security level-importance evaluation value interval correspondence relationship is associated with a corresponding security level for each importance evaluation value interval; The importance evaluation value of each data block is obtained, and based on the mapping relationship between the importance evaluation value interval to which the importance evaluation value belongs and the security level corresponding to the importance evaluation value interval is selected as the corresponding security level of each data block.
[0010] Furthermore, determining the storage and transmission encryption mechanism corresponding to the security level on the cloud native platform, and performing encryption management on each data block according to the corresponding storage and transmission encryption mechanism, includes: Pre-set storage and transmission encryption mechanisms corresponding to two security levels on the cloud native platform; If the security level is level 1, the cloud native platform determines that the encryption method using the symmetric encryption algorithm is used to store and encrypt the data blocks, and the encryption method using the TLS / SSL encryption communication protocol is used to encrypt the data blocks during transmission; If the security level is level 2, the cloud native platform determines that a combination of symmetric and asymmetric encryption algorithms is used to encrypt and manage the storage of data blocks, and the VPN security channel encryption method is used to encrypt and manage the transmission of data blocks.
[0011] The present invention also provides an integrated data management system based on cloud native, including: An acquisition module is used to acquire integrated data from an enterprise database, determine content information contained in all data in the integrated data, and divide the integrated data into a number of data blocks according to the content information; An analysis module, used to analyze the content information contained in each data block, and determine the value characteristic factors and sensitive characteristic factors in the content information contained in each data block; An evaluation module is used to analyze and evaluate the importance of each data block based on the value feature factor and the sensitive feature factor to obtain an importance evaluation value of each data block; A determination module, used to classify the security level of each data block according to the importance evaluation value, and determine the security level of each data block; The management module is used to determine the storage and transmission encryption mechanism corresponding to the security level from the cloud native platform, and encrypt and manage each data block according to the corresponding storage and transmission encryption mechanism.
[0012] Compared with the prior art, the cloud-native integrated data management method and system according to the embodiment of the present invention have the following beneficial effects: The present invention can significantly improve the security of data by analyzing, evaluating and classifying data into security levels, and managing data using an encryption mechanism. Data encryption can ensure that even if the data is stolen, sensitive information will not be leaked; The present invention can help enterprises better understand the importance of data by evaluating the value characteristic factors of data blocks and classifying data blocks into different security levels, so as to help enterprises take corresponding security measures according to different levels of data, prevent valuable and sensitive data from being leaked, improve compliance and reduce the risk of data leakage; In general, the present invention achieves all-round protection and management of enterprise data by comprehensively applying technical means such as data analysis, security assessment and encryption management, thereby improving the technical effects of data security and privacy protection, helping enterprises to better manage and protect their data assets and improve the security of data management. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 It is a schematic diagram of the process structure of the cloud-native integrated data management method in an embodiment of the present invention; Figure 2 It is a schematic diagram of the composition of an integrated data management system based on cloud native in an embodiment of the present invention. DETAILED DESCRIPTION
[0014] The specific implementation methods of the present application are further described in detail below in conjunction with the accompanying drawings and examples. The following examples are used to illustrate the present invention, but are not intended to limit the scope of the present invention.
[0015] In the description of the present application, it should be understood that the terms "center", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating orientations or positional relationships, are based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the platform or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as a limitation on the present application.
[0016] The terms "second" and "second" are used for descriptive purposes only and should not be understood as indicating or implying a relative degree of importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined with "second" or "second" may explicitly or implicitly include one or more of the features. In the description of this application, unless otherwise specified, "multiple" means two or more.
[0017] In the description of this application, it should be noted that, unless otherwise clearly specified and limited, the terms "installed", "connected", and "connected" should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two components. For ordinary technical personnel in this field, the specific meanings of the above terms in this application can be understood according to specific circumstances.
[0018] like Figure 1 As shown, in an embodiment of the present application, a cloud-native integrated data management method is provided, including: S100: obtaining integrated data from an enterprise database, determining content information corresponding to all data in the integrated data, and dividing the integrated data into a number of data blocks based on the content information; S200: analyzing the content information corresponding to all data in each data block, and determining the value characteristic factors and sensitive characteristic factors in the content information corresponding to all data in each data block; S300: analyzing and evaluating the importance of each data block based on the value characteristic factors and the sensitive characteristic factors, and obtaining an importance evaluation value for each data block; S400: classifying each data block into a security level according to the importance evaluation value, and determining the security level of each data block; S500: determining the storage and transmission encryption mechanism corresponding to the security level from the cloud-native platform, and encrypting and managing each data block according to the corresponding storage and transmission encryption mechanism.
[0019] Furthermore, the present invention can significantly improve data security by analyzing, evaluating and classifying data into security levels, and managing data with an encryption mechanism. Data encryption can ensure that even if the data is stolen, sensitive information will not be leaked. The present invention can help enterprises better understand the importance of data by evaluating the value characteristic factors of data blocks and classifying data blocks into different security levels, which helps enterprises take corresponding security measures according to data of different levels to prevent valuable and sensitive data from being leaked, improve compliance and reduce the risk of data leakage. In general, the present invention achieves all-round protection and management of enterprise data through the comprehensive application of technical means such as data analysis, security assessment and encryption management, thereby improving the technical effects of data security and privacy protection, helping enterprises to better manage and protect their data assets and improve the security of data management.
[0020] In an embodiment of the present application, a cloud-native integrated data management method is provided, wherein the integrated data is obtained from an enterprise database, content information corresponding to all data in the integrated data is determined, and the integrated data is divided into a number of data blocks based on the content information, including: obtaining the integrated data from the enterprise database, and determining the data content corresponding to all data in the integrated data; extracting keywords from the data content, and using the keywords as the content information corresponding to each data in the integrated data; analyzing the correlation between the content information corresponding to the data, and grouping the data with closely correlated content information to obtain a number of data blocks, thereby completing the division of the integrated data into a number of data blocks based on the content information.
[0021] Specifically, data is extracted from the enterprise database, and then the data content corresponding to each data is determined. The data content may include text, pictures, videos or other forms of information; each data content is analyzed to extract keywords or key phrases. Keywords are words or phrases that describe the theme or characteristics of the data content and are used to represent the main content of the data; the extracted keywords are used as the content information corresponding to each data. Keywords can be used to describe and identify the data content, which is convenient for subsequent association analysis and data segmentation; by analyzing the association relationship between keywords in the content information corresponding to different data, the correlation and connection between the data can be discovered, and it can be determined which data are closely related and can be classified as the same data block; according to the association relationship between keywords, closely related data are classified as the same data block, achieving the goal of segmenting integrated data into several data blocks based on content information. This step can achieve fine-grained management of data content and better understand and utilize data through keyword extraction and association analysis; by analyzing the associations between keywords, potential connections between data can be discovered, which helps to explore the correlations between data and improve the effectiveness of data analysis and application; dividing data into data blocks can better organize and manage data, which helps to manage and protect data security; data segmentation methods based on content information can achieve personalized data processing and application based on the characteristics and associations of data content, providing enterprises with more customized data management solutions. In summary, this integrated data segmentation method based on content information achieves fine management and optimized segmentation of data by utilizing keywords and associations, improves data correlation and personalized processing effects, and provides a more intelligent and efficient solution for enterprise data management.
[0022] In an embodiment of the present application, a cloud-native integrated data management method is provided, wherein the correlation between content information corresponding to the analysis data is analyzed, and data with close correlation between the content information are grouped to obtain a number of data blocks, including: obtaining the semantic meaning of the content information corresponding to each data, and converting each data into a vector based on the semantic meaning; calculating the cosine similarity between each pair of vectors in all vectors, and taking the cosine similarity greater than a preset threshold as a condition for close correlation, and grouping the data corresponding to the vectors with cosine similarity greater than the preset threshold to obtain a number of data blocks.
[0023] Specifically, semantic analysis is performed on the content information corresponding to each data to extract its semantic meaning, and these semantic meanings are converted into vector representations. Word embeddings or other vectorization methods are used to convert semantic information into numerical vectors. The converted vectors of all data are calculated, and the cosine similarity between every two vectors is calculated. Cosine similarity is a commonly used method to measure the similarity between vectors, which can reflect the directional relationship between vectors and has a value range of -1 to 1. A preset cosine similarity threshold is set in advance. When the cosine similarity between two vectors is greater than the threshold, they are considered to have a close association and can be classified into the same group. According to the vector pairs whose cosine similarity is greater than the preset threshold, these data are classified as the same data block, thereby achieving the goal of grouping data into several data blocks based on semantic meaning. This step converts the data content into a vector representation, which can quantify and compare the semantic meaning of the data, thereby better analyzing the correlation between the data; the cosine similarity calculation can quantify the similarity between the data, which helps to more accurately determine the correlation between the data and improve the accuracy of data grouping; the correlation relationship determination based on cosine similarity can realize the automated data grouping process, reduce manual intervention, and improve data processing efficiency; grouping data into data blocks can better manage and organize data and improve data security management and protection slope. In summary, the data grouping method based on semantic meaning and cosine similarity can realize the intelligent association and grouping of data, improve the efficiency and accuracy of data security management and processing, and provide a more intelligent and efficient solution for enterprise data management.
[0024] In an embodiment of the present application, a cloud-native integrated data management method is provided, wherein the content information corresponding to all data in each data block is analyzed to determine the value characteristic factors and sensitive characteristic factors in the content information corresponding to all data in each data block, including: obtaining a number of content information corresponding to each data in the data block, and determining the semantic meaning of each content information; respectively calculating the correlation between the semantic meaning of each content information and the value and sensitivity, and respectively obtaining a value correlation value and a sensitivity correlation value of each content information; determining the content information with the highest value correlation value among the several content information as the value characteristic factor corresponding to each data, and determining the content information with the highest sensitivity correlation value among the several content information as the sensitive characteristic factor corresponding to each data.
[0025] Specifically, several content information corresponding to each data block is obtained from each data block, and semantic analysis is performed on these content information to determine their semantic meanings, including understanding and interpreting the content in the form of text, image, video and other data; for each content information, its correlation value with value and sensitivity is calculated respectively, and the correlation value here can evaluate the correlation degree between content information and value and sensitivity by means of semantic similarity; the content information with the highest value correlation value is selected from several content information as the value feature factor corresponding to each data, and the content information with the highest sensitivity correlation value is selected as the sensitive feature factor corresponding to each data. This step can realize personalized feature extraction of each data by calculating the value and sensitivity correlation of content information, so as to better describe and understand the characteristics of the data; selecting the content information with the highest value and sensitivity correlation value as the feature factor can more accurately capture the important features of the data, which is helpful for subsequent data analysis and application; by determining the sensitive feature factor, the potential risks in the data can be better identified and managed, and by determining the value feature factor, the potential value in the data can be better mined to provide support for enterprise decision-making. In summary, the data feature factor extraction method based on content information can help enterprises better understand and utilize data and realize personalized data management and analysis. It also helps with risk management and value mining, and provides more intelligent and efficient management solutions for enterprise data processing.
[0026] In an embodiment of the present application, a cloud-native integrated data management method is provided, wherein the importance of each data block is analyzed and evaluated based on the value feature factor and the sensitive feature factor to obtain an importance evaluation value of each data block, including: obtaining a value correlation value of the value feature factor corresponding to each data and a sensitivity correlation value of the sensitive feature factor, and obtaining a preset standard value correlation value and a preset standard sensitivity correlation value; calculating the difference between the value correlation value of the value feature factor corresponding to each data and the preset standard value correlation value to obtain a first difference, and calculating the difference between the sensitivity correlation value of the sensitive feature factor corresponding to each data and the preset standard sensitivity correlation value to obtain a second difference; evaluating and valuing the first difference and the second difference respectively, and obtaining a value difference evaluation value of the value feature factor of each data and a sensitivity difference evaluation value of the sensitive feature factor; obtaining a preset first weight of the value feature factor and a preset second weight of the sensitivity correlation value, and determining the importance evaluation value of the data block based on the preset first weight and the value difference evaluation value of the value feature factor corresponding to each data in the data block and the preset second weight and the sensitivity difference evaluation value of the sensitive feature factor, wherein the calculation formula of the importance evaluation value of the data block is: , Among them, S is the importance evaluation value of the data block, α is the preset first weight of the value feature factor, Pi is the value difference evaluation value of the value feature factor corresponding to each data, β is the preset second weight of the sensitive feature factor, Qi is the sensitivity difference evaluation value of the sensitive feature factor corresponding to each data, and n is the number of data in the data block.
[0027] Specifically, for each data, the value relevance value of the corresponding value feature factor and the sensitivity relevance value of the sensitive feature factor are obtained, and a preset standard value relevance value and a preset standard sensitivity relevance value are set; the difference (first difference) between the value relevance value of the value feature factor corresponding to each data and the preset standard value relevance value, as well as the difference (second difference) between the sensitivity relevance value of the sensitive feature factor and the preset standard sensitivity relevance value are calculated respectively; the first difference and the second difference are evaluated and valued to obtain the value difference evaluation value of the value feature factor and the sensitivity difference evaluation value of the sensitive feature factor of each data; the importance evaluation value of the data block is determined according to the preset first weight of the value feature factor and the preset second weight of the sensitivity relevance value, combined with the value difference evaluation value and the sensitivity difference evaluation value. This step can achieve personalized importance assessment for each data based on the correlation value and difference evaluation value of the value characteristic factor and the sensitive characteristic factor, and more accurately identify the value and sensitivity of the data; through the combination of preset weights and evaluation values, it can achieve flexible regulation of the importance of data blocks and adjust the processing and management priorities of data according to actual conditions; based on the importance evaluation value, it can provide support for enterprise data decision-making, help enterprises better understand and use data, and achieve data-driven decision-making and operations. In summary, the importance assessment method based on value characteristic factors and sensitive characteristic factors can help enterprises better manage and use data, achieve personalized data importance assessment and risk management, and provide more intelligent and efficient solutions for enterprise data governance and decision-making.
[0028] In an embodiment of the present application, a cloud-native integrated data management method is provided, wherein each data block is divided into a security level according to an importance assessment value to determine the security level of each data block, including: pre-setting two security levels, and a security level-importance assessment value interval correspondence relationship, wherein the security level-importance assessment value interval correspondence relationship is associated with a corresponding security level for each importance assessment value interval; obtaining the importance assessment value of each data block, and based on a mapping relationship between the importance assessment value interval to which the importance assessment value belongs within the security level-importance assessment value interval correspondence relationship, selecting the security level corresponding to the importance assessment value interval as the corresponding security level of each data block.
[0029] Specifically, two security levels are pre-set, and the corresponding relationship between the security level and the importance assessment value interval is determined. This corresponding relationship is set according to actual needs and is used to guide data security management and decision-making; each data block is evaluated for importance, and the corresponding importance assessment value is obtained. According to the importance assessment value interval to which the importance assessment value belongs, the corresponding security level is found in the security level-importance assessment value interval correspondence, and the security level is selected as the corresponding security level of each data block. This step realizes the automatic allocation of the security level of each data block through the mapping relationship between the importance assessment value and the security level, reduces the workload of manual adjustment, and improves efficiency; classifying and managing data blocks according to security levels helps to achieve security control and protection of data, and ensure that sensitive data is properly processed and kept confidential; by mapping data blocks to corresponding security levels, the risk level of data can be better identified, and corresponding security protection and risk response measures can be taken in a targeted manner. In summary, the mapping relationship method based on importance assessment values and security levels can help enterprises better manage and protect data, realize automatic classification and management of data security levels, and provide more intelligent and efficient solutions for enterprise data security and risk management.
[0030] In an embodiment of the present application, a cloud-native integrated data management method is provided, wherein a storage and transmission encryption mechanism corresponding to a security level is determined from a cloud-native platform, and each data block is encrypted and managed according to the corresponding storage and transmission encryption mechanism, including: pre-setting storage and transmission encryption mechanisms corresponding to two security levels on the cloud-native platform; if the security level is a first-level security level, determining from the cloud-native platform an encryption method using a symmetric encryption algorithm to perform storage encryption management on the data block, and using an encryption method using a TLS / SSL encryption communication protocol to perform transmission encryption management on the data block; if the security level is a second-level security level, determining from the cloud-native platform an encryption method combining symmetric encryption and asymmetric encryption algorithms to perform storage encryption management on the data block, and using an encryption method using a VPN security channel to perform transmission encryption management on the data block.
[0031] Specifically, storage and transmission encryption mechanisms corresponding to the first-level security level and the second-level security level are pre-set on the cloud native platform; if the security level of the data block is level one, the data block is stored and encrypted using a symmetric encryption algorithm, which means that the data will be encrypted using a symmetric encryption algorithm when stored to protect the confidentiality of the data. At the same time, the TLS / SSL encrypted communication protocol is used to encrypt the data block for transmission to ensure the security of the data during transmission; if the security level of the data block is level two, the data block is stored and encrypted using an encryption method that combines symmetric encryption and asymmetric encryption algorithms, which means that symmetric encryption and asymmetric encryption algorithms will be applied simultaneously when the data is stored, which improves the encryption strength and security of the data. At the same time, the VPN secure channel encryption method is used to encrypt the data block for transmission, and the security of data transmission is ensured by establishing a secure virtual private network channel. This step uses different encryption mechanisms to store and transmit encrypted data according to the data security level, effectively protecting the confidentiality and integrity of the data and reducing the risk of data leakage; different encryption methods are selected according to different security levels, making the encryption mechanism more flexible and scalable, and adapting to data management scenarios with different security requirements; by using encrypted communication protocols and VPN secure channels to transmit encrypted data, it can effectively prevent data from being stolen or tampered with during transmission, thereby improving the security of data transmission. In summary, based on the setting of different security levels and the corresponding encryption mechanisms, targeted data encryption management can be implemented on the cloud native platform, improving data security and protection levels, and providing more reliable and efficient protection for enterprise data security.
[0032] like Figure 2 As shown, in an embodiment of the present application, an integrated data management system based on cloud native is provided, including: an acquisition module, used to acquire integrated data from an enterprise database, determine the content information contained in all data in the integrated data, and divide the integrated data into a number of data blocks according to the content information; an analysis module, used to analyze the content information contained in each data block, and determine the value characteristic factors and sensitive characteristic factors in the content information contained in each data block; an evaluation module, used to analyze and evaluate the importance of each data block based on the value characteristic factors and sensitive characteristic factors, and obtain an importance evaluation value of each data block; a determination module, used to classify each data block into a security level according to the importance evaluation value, and determine the security level of each data block; a management module, used to determine the storage and transmission encryption mechanism corresponding to the security level from the cloud native platform, and encrypt and manage each data block according to the corresponding storage and transmission encryption mechanism.
[0033] In summary, the embodiment of the present invention provides an integrated data management method and system based on cloud native, which includes: determining the content information corresponding to all data in the integrated data in the enterprise database, and dividing the integrated data into several data blocks based on it; analyzing the content information corresponding to all data in each data block to determine the value characteristic factor and the sensitive characteristic factor; analyzing and evaluating the importance of each data block based on the value characteristic factor and the sensitive characteristic factor to obtain an importance evaluation value; dividing each data block into a security level according to the importance evaluation value to determine the security level; determining the storage and transmission encryption mechanism corresponding to the security level from the cloud native platform, and encrypting and managing each data block accordingly. The present invention realizes all-round protection and management of enterprise data by comprehensively applying the technical means of data analysis, security assessment and encryption management, thereby improving the technical effects of data security and privacy protection.
[0034] Finally, it should be noted that: Obviously, a person skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the present invention and its equivalent technology, the present invention is also intended to include these modifications and variations.
[0035] The above is only an example of implementation of the present invention, but it cannot be used to limit the scope of the present invention. Any structural changes made according to the present invention, as long as they do not lose the essence of the present invention, should be regarded as falling within the scope of protection of the present invention and being restricted. Technical personnel in the relevant technical field can clearly understand that for the convenience and simplicity of description, the specific working process and related instructions of the platform described above can refer to the corresponding process in the aforementioned platform embodiment, and will not be repeated here.
[0036] The term "comprises" or any other similar term is intended to cover a non-exclusive inclusion such that a process, platform, article, or apparatus / platform that includes a list of elements includes not only those elements but also other elements not expressly listed or inherent to such process, platform, article, or apparatus / platform.
[0037] So far, the technical solutions of the present invention have been described in conjunction with the further embodiments shown in the accompanying drawings. However, it is easy for a person skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, a person skilled in the art can make equivalent changes or substitutions to closely related technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.
[0038] The above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention.
Claims
1. A cloud-native integrated data management method, characterized in that: include: Obtaining integrated data from an enterprise database, determining content information corresponding to all data in the integrated data, and dividing the integrated data into a number of data blocks based on the content information; Analyze the content information corresponding to all the data in each data block to determine the value characteristic factors and sensitive characteristic factors in the content information corresponding to all the data in each data block; Analyze and evaluate the importance of each data block based on the value characteristic factor and the sensitive characteristic factor to obtain the importance evaluation value of each data block; Classify each data block into security levels according to the importance assessment value and determine the security level of each data block; Determine the storage and transmission encryption mechanism corresponding to the security level from the cloud native platform, and encrypt and manage each data block according to the corresponding storage and transmission encryption mechanism.
2. A cloud-native integrated data management method according to claim condition 1, characterized in that: The step of obtaining the integrated data from the enterprise database, determining the content information corresponding to all the data in the integrated data, and dividing the integrated data into a plurality of data blocks based on the content information includes: Obtain integrated data from the enterprise database and determine the data content corresponding to all data in the integrated data; Extract keywords from the data content and use the keywords as the content information corresponding to each data in the integrated data; The correlation between the content information corresponding to the data is analyzed, and the data with close correlation between the content information are grouped together to obtain several data blocks, that is, the integrated data is divided into several data blocks based on the content information.
3. A cloud-native integrated data management method according to claim condition 2, characterized in that: The analysis data corresponds to the association relationship between the content information, and the data with close association relationship between the content information are collected to obtain several data blocks, including: Obtain the semantic meaning of the content information corresponding to each data, and convert each data into a vector based on the semantic meaning; The cosine similarity between all vectors is calculated, and the cosine similarity greater than a preset threshold is used as a condition for close association. The data corresponding to the vectors with cosine similarity greater than the preset threshold are collected to obtain several data blocks.
4. A cloud-native integrated data management method according to claim condition 2, characterized in that: The analyzing the content information corresponding to all the data in each data block to determine the value characteristic factors and sensitive characteristic factors in the content information corresponding to all the data in each data block includes: Obtaining a number of content information corresponding to each data in the data block, and determining the semantic meaning of each content information; Calculate the relevance between the semantic meaning of each content information and its value and sensitivity respectively, and obtain the value relevance value and sensitivity relevance value of each content information respectively; The content information with the highest value association value among the plurality of content information is determined as the value characteristic factor corresponding to each data, and the content information with the highest sensitivity association value among the plurality of content information is determined as the sensitive characteristic factor corresponding to each data.
5. A cloud-native integrated data management method according to claim condition 4, characterized in that: The importance of each data block is analyzed and evaluated based on the value feature factor and the sensitive feature factor to obtain the importance evaluation value of each data block, including: Obtain the value association value of the value characteristic factor and the sensitivity association value of the sensitive characteristic factor corresponding to each data, and obtain the preset standard value association value and the preset standard sensitivity association value; Calculate the difference between the value correlation value of the value characteristic factor corresponding to each data and the preset standard value correlation value to obtain a first difference, and calculate the difference between the sensitivity correlation value of the sensitive characteristic factor corresponding to each data and the preset standard sensitivity correlation value to obtain a second difference; The first difference and the second difference are evaluated and valued respectively, and the value difference evaluation value of the value characteristic factor and the sensitivity difference evaluation value of the sensitive characteristic factor of each data are obtained respectively; The preset first weight of the value feature factor and the preset second weight of the sensitive association value are obtained, and the importance evaluation value of the data block is determined based on the preset first weight of the value feature factor and the value difference evaluation value corresponding to each data in the data block and the preset second weight of the sensitive feature factor and the sensitivity difference evaluation value, wherein the calculation formula of the importance evaluation value of the data block is: , Among them, S is the importance evaluation value of the data block, α is the preset first weight of the value feature factor, Pi is the value difference evaluation value of the value feature factor corresponding to each data, β is the preset second weight of the sensitive feature factor, Qi is the sensitivity difference evaluation value of the sensitive feature factor corresponding to each data, and n is the number of data in the data block.
6. A cloud-native integrated data management method according to claim condition 5, characterized in that: The step of classifying each data block into a security level according to the importance evaluation value and determining the security level of each data block includes: Two security levels and a security level-importance evaluation value interval correspondence relationship are pre-set, wherein the security level-importance evaluation value interval correspondence relationship is associated with a corresponding security level for each importance evaluation value interval; The importance evaluation value of each data block is obtained, and based on the mapping relationship between the importance evaluation value interval to which the importance evaluation value belongs and the security level corresponding to the importance evaluation value interval is selected as the corresponding security level of each data block.
7. A cloud-native integrated data management method according to claim condition 6, characterized in that: Determining the storage and transmission encryption mechanism corresponding to the security level on the cloud native platform, and performing encryption management on each data block according to the corresponding storage and transmission encryption mechanism, includes: Pre-set storage and transmission encryption mechanisms corresponding to two security levels on the cloud native platform; If the security level is level 1, the cloud native platform determines that the encryption method using the symmetric encryption algorithm is used to store and encrypt the data blocks, and the encryption method using the TLS / SSL encryption communication protocol is used to encrypt the data blocks during transmission; If the security level is level 2, the cloud native platform determines that a combination of symmetric and asymmetric encryption algorithms is used to encrypt and manage the storage of data blocks, and the VPN security channel encryption method is used to encrypt and manage the transmission of data blocks.
8. An integrated data management system based on cloud native, characterized in that: include: An acquisition module is used to acquire integrated data from an enterprise database, determine content information contained in all data in the integrated data, and divide the integrated data into a number of data blocks according to the content information; An analysis module, used to analyze the content information contained in each data block, and determine the value characteristic factors and sensitive characteristic factors in the content information contained in each data block; An evaluation module is used to analyze and evaluate the importance of each data block based on the value feature factor and the sensitive feature factor to obtain an importance evaluation value of each data block; A determination module, used to classify the security level of each data block according to the importance evaluation value, and determine the security level of each data block; The management module is used to determine the storage and transmission encryption mechanism corresponding to the security level from the cloud native platform, and encrypt and manage each data block according to the corresponding storage and transmission encryption mechanism.
Citation Information
Patent Citations
Cloud native application health detection method and device, computer equipment and storage medium
CN114153696A
Data management method and system in cloud native environment and storage medium
CN117874141A
Information encryption system and method based on cloud computing
CN118400166A
Encrypted information management system based on big data
CN119004494A
A system for encrypting and decrypting health data using machine learning on a cloud-based SaaS platform
DE202024104730U1
Cited By
Dynamic data privacy protection evaluation method and system based on big data analysis
CN120930170A