Secure service method and system for enterprise-level ledgers

By employing a hierarchical encryption, distributed storage, and zero-trust architecture access control model, combined with real-time anomaly detection and microservice architecture, the security and flexibility issues in ledger data management are resolved, thereby improving data protection and enterprise operational efficiency.

CN120012131BActive Publication Date: 2026-04-21STATE GRID SHANDONG ELECTRIC POWER CO TAOXIAN POWER SUPPLY CO
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
STATE GRID SHANDONG ELECTRIC POWER CO TAOXIAN POWER SUPPLY CO
Filing Date
2025-01-22
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing ledger data management methods face challenges such as centralized data storage making it an easy target for attacks, traditional access control being unable to cope with dynamic threats, and a lack of real-time monitoring and intelligent analysis, resulting in low data security and low enterprise operational efficiency.

Method used

By employing hierarchical encryption and distributed storage, a zero-trust architecture access control model is constructed, which dynamically assigns the least privilege. Through real-time anomaly detection and intelligent auditing, combined with microservice architecture and service mesh deployment, flexible data protection and efficient management are achieved.

Benefits of technology

It improves data security and reliability, enhances access control flexibility and audit efficiency, optimizes service architecture, reduces maintenance costs, and adapts to the management needs of enterprises of different types and sizes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012131B_ABST
    Figure CN120012131B_ABST
Patent Text Reader

Abstract

This invention relates to the field of ledger security service technology, and more particularly to a security service method and system for enterprise-level ledgers. The method includes the following steps: collecting ledger data from a target enterprise to obtain an original ledger dataset; performing hierarchical encryption on the original ledger dataset to obtain an encrypted ledger dataset; distributing the encrypted ledger dataset to obtain a distributed encrypted ledger dataset; constructing a zero-trust architecture access control model on the distributed encrypted ledger dataset to obtain a zero-trust access control model; and dynamically allocating the least privilege to the distributed encrypted ledger dataset according to the zero-trust access control model to obtain a permission-controlled ledger dataset. This invention significantly improves the security of ledger data and the flexibility of access control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of ledger security service technology, and in particular to a security service method and system for enterprise-level ledgers. Background Technology

[0002] In today's business environment, the security and integrity of ledger data are paramount. Ledger data not only contains critical business information such as financial, tax, and human resources data, but also involves multiple aspects of the business, such as compliance, assets, and information technology. However, with the continuous increase in data volume and the complexity of the network environment, traditional ledger data management methods face numerous challenges.

[0003] First, centralized data storage makes data vulnerable to attacks, potentially leading to the leakage of large amounts of sensitive data. Second, traditional access control mechanisms, often based on static permission allocation, struggle to handle dynamically changing access needs and security threats. Furthermore, enterprises often lack effective real-time monitoring and intelligent analysis tools when conducting data audits and risk assessments, making it difficult to promptly detect and respond to abnormal behavior.

[0004] Against this backdrop, existing methods for securing ledger data have several significant limitations. For example, data encryption and storage methods are relatively simplistic, lacking flexibility and scalability. Furthermore, access control models often rely on traditional trust systems, making them ill-suited for zero-trust architectures. In addition, anomaly detection and intelligent auditing functions for user behavior are inadequate, failing to effectively identify and prevent potential security risks. These problems not only impact enterprise data security but also hinder the efficiency and reliability of enterprise operations. Summary of the Invention

[0005] Therefore, it is necessary for the present invention to provide a security service method and system for enterprise-level ledgers to solve at least one of the above-mentioned technical problems.

[0006] To achieve the above objectives, a security service method for enterprise-level ledgers includes the following steps:

[0007] Step S1: Collect ledger data from the target enterprise to obtain the original ledger dataset; perform hierarchical encryption on the original ledger dataset to obtain the encrypted ledger dataset; and distribute the encrypted ledger dataset for distributed storage to obtain the distributed encrypted ledger dataset.

[0008] Step S2: Construct a zero-trust architecture access control model for the distributed encrypted ledger dataset to obtain the zero-trust access control model; Perform dynamic least privilege allocation on the distributed encrypted ledger dataset according to the zero-trust access control model to obtain the access-controlled ledger dataset.

[0009] Step S3: Obtain the access behavior baseline model; use the access behavior baseline model to perform real-time anomaly detection and intelligent auditing on the access-controlled ledger dataset to obtain audit anomaly detection result data; perform risk assessment and data hardening on the access-controlled ledger dataset based on the audit anomaly detection result data to obtain the risk-hardened ledger dataset;

[0010] Step S4: Perform service function decoupling analysis on the risk hardening ledger dataset to obtain ledger service decoupling mapping data; construct an elastic microservice architecture for the risk hardening ledger dataset based on the ledger service decoupling mapping data to obtain the ledger microservice architecture blueprint; and implement stateless design and service mesh deployment for the risk hardening ledger dataset based on the ledger microservice architecture blueprint to obtain the elastic mesh ledger dataset.

[0011] This invention ensures data protection at different security levels and reduces the risk of data leakage through hierarchical encryption and distributed storage. The zero-trust architecture access control model makes permission allocation more dynamic and flexible, adapting to constantly changing security threats and access requirements. Real-time anomaly detection and intelligent auditing improve the accuracy and efficiency of auditing, further enhancing data security and reliability. Decoupling analysis of service functions and the construction of a microservice architecture not only improve system maintainability and scalability but also enhance system resilience and stability through stateless design and service mesh deployment. Furthermore, this invention is highly adaptable, meeting the management needs of enterprises of different types and sizes while reducing maintenance costs. In summary, this invention significantly improves the security of ledger data, the flexibility of access control, and the efficiency of auditing and risk assessment, while optimizing the service architecture and enhancing enterprise operational efficiency and compliance.

[0012] Preferably, the present invention also provides a security service system for enterprise-level ledgers, used to execute the security service method for enterprise-level ledgers as described above, the security service system for enterprise-level ledgers comprising:

[0013] The encrypted storage module is used to collect ledger data from the target enterprise to obtain the original ledger dataset; to perform hierarchical encryption on the original ledger dataset to obtain the encrypted ledger dataset; and to perform distributed storage on the encrypted ledger dataset to obtain the distributed encrypted ledger dataset.

[0014] The access control module is used to construct a zero-trust architecture access control model for the distributed encrypted ledger dataset, resulting in a zero-trust access control model; and to dynamically allocate the least privileges to the distributed encrypted ledger dataset based on the zero-trust access control model, resulting in a permission-controlled ledger dataset.

[0015] The behavior auditing and risk assessment module is used to obtain an access behavior baseline model; to perform real-time anomaly detection and intelligent auditing on the access-controlled ledger dataset using the access behavior baseline model, and to obtain audit anomaly detection result data; and to perform risk assessment and data hardening on the access-controlled ledger dataset based on the audit anomaly detection result data, and to obtain a risk-hardened ledger dataset.

[0016] The microservice architecture construction module is used to perform service function decoupling analysis on the risk hardening ledger dataset to obtain ledger service decoupling mapping data; based on the ledger service decoupling mapping data, the risk hardening ledger dataset is used to construct an elastic microservice architecture to obtain the ledger microservice architecture blueprint; based on the ledger microservice architecture blueprint, the risk hardening ledger dataset is used to perform stateless design and implementation and service mesh deployment to obtain the elastic mesh ledger dataset.

[0017] This invention achieves significant improvements in data security, dynamic access control, real-time behavior auditing and risk assessment, service function decoupling, and microservice architecture construction through encrypted storage modules, access control modules, behavior auditing and risk assessment modules, and microservice architecture construction, thereby effectively improving enterprise operational efficiency. The system's multi-layered security measures and zero-trust architecture ensure data confidentiality and access security, while real-time monitoring and intelligent analysis mechanisms improve response speed and processing capabilities for security incidents. Furthermore, the system's modular design and microservice architecture not only reduce maintenance costs but also enhance maintainability and scalability, possessing strong adaptability to meet the ledger data management needs of enterprises of different types and sizes, ensuring the security of critical enterprise information and the efficiency of enterprise operations. Attached Figure Description

[0018] Other features, objects, and advantages of the invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings:

[0019] Figure 1 A flowchart illustrating the steps of a security service method for enterprise-level ledgers according to an embodiment is shown.

[0020] Figure 2 A detailed flowchart of step S3 of one embodiment is shown.

[0021] Figure 3 A detailed flowchart of step S37 of one embodiment is shown. Detailed Implementation

[0022] The technical method of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.

[0023] Furthermore, the accompanying drawings are merely illustrative of the invention and are not necessarily drawn to scale. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor methods and / or microcontroller methods.

[0024] It should be understood that although the terms "first," "second," etc., may be used herein to describe various units, these units should not be limited by these terms. These terms are used merely to distinguish one unit from another. For example, without departing from the scope of the exemplary embodiments, a first unit may be referred to as a second unit, and similarly, a second unit may be referred to as a first unit. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0025] To achieve the above objectives, please refer to Figures 1 to 3 This invention provides a security service method for enterprise-level ledgers, comprising the following steps:

[0026] Step S1: Collect ledger data from the target enterprise to obtain the original ledger dataset; perform hierarchical encryption on the original ledger dataset to obtain the encrypted ledger dataset; and distribute the encrypted ledger dataset for distributed storage to obtain the distributed encrypted ledger dataset.

[0027] Step S2: Construct a zero-trust architecture access control model for the distributed encrypted ledger dataset to obtain the zero-trust access control model; Perform dynamic least privilege allocation on the distributed encrypted ledger dataset according to the zero-trust access control model to obtain the access-controlled ledger dataset.

[0028] Step S3: Obtain the access behavior baseline model; use the access behavior baseline model to perform real-time anomaly detection and intelligent auditing on the access-controlled ledger dataset to obtain audit anomaly detection result data; perform risk assessment and data hardening on the access-controlled ledger dataset based on the audit anomaly detection result data to obtain the risk-hardened ledger dataset;

[0029] Step S4: Perform service function decoupling analysis on the risk hardening ledger dataset to obtain ledger service decoupling mapping data; construct an elastic microservice architecture for the risk hardening ledger dataset based on the ledger service decoupling mapping data to obtain the ledger microservice architecture blueprint; and implement stateless design and service mesh deployment for the risk hardening ledger dataset based on the ledger microservice architecture blueprint to obtain the elastic mesh ledger dataset.

[0030] This invention ensures data protection at different security levels and reduces the risk of data leakage through hierarchical encryption and distributed storage. The zero-trust architecture access control model makes permission allocation more dynamic and flexible, adapting to constantly changing security threats and access requirements. Real-time anomaly detection and intelligent auditing improve the accuracy and efficiency of auditing, further enhancing data security and reliability. Decoupling analysis of service functions and the construction of a microservice architecture not only improve system maintainability and scalability but also enhance system resilience and stability through stateless design and service mesh deployment. Furthermore, this invention is highly adaptable, meeting the management needs of enterprises of different types and sizes while reducing maintenance costs. In summary, this invention significantly improves the security of ledger data, the flexibility of access control, and the efficiency of auditing and risk assessment, while optimizing the service architecture and enhancing enterprise operational efficiency and compliance.

[0031] In this embodiment, firstly, data acquisition tools such as web crawlers or database export functions are used to collect ledger data from the target enterprise, forming an original ledger dataset. Next, encryption software such as GnuPG or BitLocker is used to perform hierarchical encryption on this data, generating an encrypted ledger dataset. This encrypted dataset is then distributed and stored using a distributed file system such as Hadoop HDFS or a cloud storage service such as Amazon S3, forming a distributed encrypted ledger dataset. Then, a zero-trust access control model is constructed, using access control tools such as Microsoft Active Directory combined with policy-as-code tools such as HashiCorpVault to dynamically assign least privileges to the distributed encrypted ledger dataset, forming a controlled-access ledger dataset. Further, an access behavior baseline model is developed or obtained, and machine learning tools such as scikit-learn are used to perform real-time anomaly detection and intelligent auditing on the controlled-access ledger dataset, generating audit anomaly detection results data. Based on these audit results, a risk assessment is conducted, and data hardening techniques such as data anonymization or security policy updates are applied to obtain a risk-hardened ledger dataset. Next, service function decoupling analysis was performed on the risk-hardened ledger dataset. Using architecture design tools such as ArchiMate or modeling tools such as Enterprise Architect, decoupling mapping data for the ledger services was obtained. Based on this mapping data, a microservice architecture blueprint for the ledger was constructed using microservice development frameworks such as Spring Boot and container technologies such as Docker. Finally, using service mesh technologies such as Istio and container orchestration tools such as Kubernetes, a stateless design and service mesh deployment were implemented for the risk-hardened ledger dataset, forming a resilient mesh ledger dataset.

[0032] Preferably, step S1 includes the following steps:

[0033] Step S11: Obtain the enterprise terminal device identifier list;

[0034] Specifically, the types and quantities of all endpoint devices in the enterprise network environment can be determined. This is achieved using network scanning tools, such as Nmap or Ping Sweep, to scan the enterprise's internal network and identify all online devices. This information is then used to generate a list containing all endpoint device identifiers, ultimately yielding the enterprise endpoint device identifier list.

[0035] Step S12: Collect ledger data from terminal devices according to the enterprise terminal device identification list to obtain the original ledger dataset;

[0036] Specifically, automated scripts or data acquisition software can be used to collect ledger data from each terminal device. For example, a script can be developed to run on the enterprise's server, connecting to each terminal device via SSH or Remote Desktop Protocol (RDP) to execute data acquisition commands. These commands include, but are not limited to, listing file system directories, retrieving system logs, and collecting application configurations. The collected data is then transmitted back to a central server and stored in a predefined database or data warehouse, ultimately yielding the raw ledger dataset.

[0037] Step S13: Perform data structure recognition on the original ledger dataset to obtain the ledger data structure mapping set;

[0038] Specifically, a data model can be defined that describes the fields and types that the ledger data should include, such as date, amount, and transaction type. Then, data parsing tools such as Python's Pandas library or Java's JDBC tools are used to parse and clean the collected raw data. These tools can identify patterns and structures in the data and map it to a predefined data model. In this way, the raw, unstructured data is transformed into a structured ledger dataset, ultimately resulting in a ledger data structure mapping set.

[0039] Step S14: Group the original ledger dataset according to the same data structure based on the ledger data structure mapping set to obtain several groups of structured ledger data;

[0040] Specifically, SQL queries or the aggregation capabilities of NoSQL databases can be used to identify records with the same data structure in the ledger data structure mapping set. For example, in relational databases, the GROUP BY statement can be used to group records with similar fields and data types. These grouping operations can be based on field names, data types, or predefined ranges of field values. The grouped data will be stored in different collections or tables, each collection representing a specific data structure type, ultimately resulting in several sets of structured ledger data.

[0041] Step S15: Identify the data categories of each group of structured ledger data to obtain a ledger type dataset;

[0042] Specifically, a set of predefined category labels can be defined, such as finance, taxation, and human resources. Then, text mining and natural language processing (NLP) tools, such as Python's NLTK library or Java's OpenNLP library, are used to analyze the text content in each set of structured ledger data, extracting keywords and concepts. These keywords and concepts are then matched against the predefined category labels, thereby classifying the data. For example, data records containing the words "salary" and "bonus" would be labeled as belonging to the human resources category. Furthermore, supervised learning algorithms, such as support vector machines (SVM) or random forests, can be used to train a classification model that automatically assigns new ledger data records to the appropriate categories. The classification results are stored in a database, forming a ledger type dataset.

[0043] Step S16: Encrypt several sets of structured ledger data according to the ledger type dataset to obtain an encrypted ledger dataset, and then distribute the encrypted ledger dataset to obtain a distributed encrypted ledger dataset.

[0044] Specifically, please refer to the sub-step of step S16 for the specific implementation process of this embodiment.

[0045] This invention ensures the comprehensiveness and accuracy of data collection by obtaining a list of enterprise terminal device identifiers and using this list for data acquisition. Secondly, it optimizes data structure management and improves data readability and operability by performing structure identification and mapping on the original ledger data. Furthermore, grouping data according to the same structure enhances data retrieval, facilitating quick access and processing of specific data types. Encrypting data based on ledger data categories enhances the level of data protection, effectively preventing data leakage and misuse. Simultaneously, distributing the encrypted ledger data reduces the risk of data loss and improves the system's resistance to attacks.

[0046] Preferably, step S16 includes the following steps:

[0047] Step S161: Use the ledger type dataset to perform association mapping on several groups of structured ledger data to obtain a type-related ledger data table;

[0048] Specifically, this association can be achieved using an SQL database by creating views or stored procedures. For example, by writing an SQL query to associate financial type ledger data with financial category labels and storing the correspondence in a new table, a type-associative ledger data table can be obtained. This query uses a JOIN operation to join several sets of structured ledger data and ledger type datasets.

[0049] Step S162: Extract the corresponding ledger type from a set of structured ledger data based on the type-related ledger data table to obtain ledger type data;

[0050] Specifically, an SQL query can be used to filter the type-related ledger data table using a specified WHERE clause to select the ledger type corresponding to a set of structured ledger data, such as financial ledger or tax ledger, thereby obtaining the ledger type data.

[0051] Step S163: If the ledger type data is any one of financial ledger, tax ledger, or compliance ledger, then the corresponding group of structured ledger data is marked with the highest level of security to obtain ledger security level marked data.

[0052] Specifically, if the ledger data is any of the following types: financial, tax, or compliance, a data tagging tool can be used to apply the highest level of security tags to the financial, tax, or compliance-type ledger data, ultimately resulting in ledger security level tagged data. Furthermore, scripting languages ​​such as PowerShell or Bash can be used to automate the tagging process. The script reads the ledger type data and applies security tags to the corresponding data records according to predefined rules.

[0053] Step S164: If the ledger type data is any one of human resources type ledger, customer type ledger and supplier type ledger, then perform high-level security marking on the corresponding group of structured ledger data to obtain ledger security level marking data.

[0054] Specifically, if the ledger data is of any of the following types: human resources, customer, or supplier, similar data tagging tools can be used to apply high-level security tags to the human resources, customer, and supplier ledger data, ultimately resulting in ledger security level tagged data. Data tagging software such as Microsoft SQL Server Data Masking can be used to define and apply security tags. By defining data masking rules, high-level security tags can be automatically applied to data records containing sensitive personnel or customer information.

[0055] Step S165: If the ledger type data is any one of asset type ledger, information technology type ledger, inventory type ledger and project type ledger, then perform general level security marking on the corresponding group of structured ledger data to obtain ledger security level marking data.

[0056] Specifically, if the ledger type data is any one of asset-type ledger, information technology-type ledger, inventory-type ledger, or project-type ledger, a data classification tool can be used to apply a general level of security labeling to the asset, information technology, inventory, and project-type ledger data, ultimately resulting in ledger security level labeled data. Data management software such as SAP Data Services can be used to apply the corresponding security labels.

[0057] Step S166: If the ledger security level marker data is the highest security level, then homomorphic encryption is performed on the corresponding group of structured ledger data to obtain encrypted ledger data. If the ledger security level marker data is a relatively high security level, then attribute-based encryption is performed on the corresponding group of structured ledger data to obtain encrypted ledger data. If the ledger security level marker data is a general security level, then lightweight symmetric encryption is performed on the corresponding group of structured ledger data to obtain encrypted ledger data.

[0058] Specifically, encryption software and libraries can be used to homomorphically encrypt the structured ledger data corresponding to the highest security level, ultimately obtaining encrypted ledger data. Open-source encryption libraries such as LibHOMOMORPH can be used to implement homomorphic encryption, which supports computation on encrypted data without decryption. For data with higher security levels, attribute-based encryption (ABE) can be used, while for data with general security levels, lightweight symmetric encryption techniques such as AES (Advanced Encryption Standard) can be used.

[0059] Step S167: Perform steps S162-S166 on each group of structured ledger data to obtain several ledger security level marker data and several encrypted ledger data. Record the several encrypted ledger data as the encrypted ledger dataset.

[0060] Specifically, steps S162-S166 can be performed on each set of structured ledger data to obtain several ledger security level marker data and several encrypted ledger data. The several encrypted ledger data are then merged and recorded as an encrypted ledger dataset.

[0061] Step S168: Divide the encrypted ledger dataset into data fragments of the same level according to several ledger security level marker data to obtain fragmented encrypted ledger datasets, and store the fragmented encrypted ledger datasets in a distributed manner to obtain distributed encrypted ledger datasets.

[0062] Specifically, data sharding and storage management tools can be used to process encrypted ledger datasets. First, using database management tools such as Oracle SQL Developer, the encrypted ledger dataset is queried, and the data is grouped according to security level labels. Then, data sharding technology is used to divide the data for each security level into smaller data blocks. These data blocks can be evenly distributed using specific sharding algorithms, such as consistent hashing or range sharding. The sharded data blocks are then labeled with the same security level. Data storage and backup solutions, such as NetApp or EMC, are used to distribute the sharded encrypted ledger dataset. This can be achieved by configuring storage policies to store data blocks in different physical locations or cloud storage services. Furthermore, data replication and backup tools, such as Rsync or Veritas, can be used to periodically back up the distributed data.

[0063] This invention enhances the relevance and manageability of structured ledger data across different groups through association mapping. By implementing corresponding levels of security labeling and encryption based on different ledger types, hierarchical data protection is achieved, ensuring a higher level of security for critical data. Data storage is optimized through fragmented encryption and distributed storage, improving storage flexibility and reliability while reducing the risk of data loss. This method also improves data access efficiency, enabling rapid location and access to specific types of ledger data. The use of homomorphic encryption, attribute-based encryption, and lightweight symmetric encryption technologies enhances attack resistance, effectively mitigating data attacks. Furthermore, different levels of security labeling and encryption promote compliant data management and reduce compliance risks.

[0064] Preferably, step S2 includes the following steps:

[0065] Step S21: Obtain the ledger access history data;

[0066] Specifically, log management tools and database query technology can be used to collect the access history of the ledger system, thereby obtaining the ledger access history data.

[0067] Step S22: Extract and remove abnormal access data from the ledger access history data to obtain abnormal ledger access history data and normal ledger access history data.

[0068] Specifically, data analysis and machine learning techniques can be used to identify and remove anomalous access data. Statistical analysis software such as R or Python's Pandas library can be used to analyze access history data in the access log to identify access patterns that significantly deviate from normal behavior. For example, statistical indicators such as access frequency and access time distribution can be calculated to identify abnormally high access frequencies or access during non-normal working hours. Then, machine learning algorithms such as Isolation Forest or One-Class SVM can be used to further identify anomalous access behavior. These algorithms can automatically learn normal access patterns and identify anomalous accesses that deviate from the normal pattern. The identified anomalous access data will be labeled and removed from the original dataset, ultimately resulting in anomalous access history data and normal access history data in the access log.

[0069] Step S23: Perform abnormal access pattern identification on the abnormal ledger access history data to obtain abnormal access pattern data, and perform normal access pattern identification on the normal ledger access history data to obtain normal access pattern data.

[0070] Specifically, data visualization tools such as Tableau or Power BI can be used to visually display patterns and trends of anomalous access. These tools allow observation of information about anomalous access, such as time distribution, frequency variations, and access paths. Furthermore, by combining business knowledge and security policies, it can be determined whether these anomalous accesses represent actual security threats, such as unauthorized access, data breach attempts, or system abuse. Identified anomalous access patterns are recorded and categorized, ultimately yielding anomalous access pattern data. For normal access history data, statistical analysis software such as R or Python's Pandas library can be used to calculate baseline characteristics of normal access, such as average access frequency, typical access time windows, and common access paths. These baseline characteristics define the range of normal access patterns. Machine learning algorithms, such as K-Means clustering or Gaussian Mixture Models (GMMs), are used to perform pattern recognition on the access data, categorizing access behavior into several typical normal access patterns, ultimately yielding normal access pattern data.

[0071] Step S24: Construct an access behavior baseline model based on abnormal ledger access history data, normal ledger access history data, abnormal access pattern data, and normal access pattern data to obtain the access behavior baseline model;

[0072] Specifically, data preprocessing tools such as Python's Scikit-learn library can be used to prepare abnormal access history data, normal access history data, abnormal access pattern data, and normal access pattern data, including cleaning, standardization, and feature selection. Then, appropriate machine learning algorithms, such as decision trees, random forests, or neural networks, are selected to train the model. These algorithms can learn patterns of access behavior from normal and abnormal access history records and identify the boundaries between normal and abnormal access. Finally, a baseline model of access behavior is constructed.

[0073] Step S25: Capture real-time access data of the distributed encrypted ledger dataset to obtain real-time access data of the ledger, and extract the access user trust level from the real-time access data of the ledger to obtain access user trust level data.

[0074] Specifically, network monitoring tools such as Wireshark or tcpdump can be used to capture real-time network traffic accessing the distributed encrypted ledger dataset and analyze access requests. Application performance management (APM) tools such as New Relic or Dynatrace can be used to monitor application-level access behavior and performance metrics, ultimately obtaining real-time ledger access data. From this real-time access data, the identity information of the currently accessing user can be extracted, and based on this information, the corresponding trust level can be extracted from the enterprise user management database, thus obtaining the user trust level data.

[0075] Step S26: Use the access behavior baseline model to perform dynamic deviation analysis on the real-time access data of the ledger to obtain access behavior deviation assessment data;

[0076] Specifically, machine learning platforms such as Python's scikit-learn library or the R language can be used to load a baseline model of access behavior and perform prediction and deviation analysis on real-time access data from the ledger. The baseline model of access behavior will assess whether access behavior conforms to normal patterns and calculate a deviation score. For example, if a user suddenly starts accessing resources they don't usually access, or if their access frequency increases significantly, this will generate a high deviation score. The final result is the access behavior deviation assessment data. By setting a dynamic deviation threshold, access behaviors that significantly deviate from normal patterns can be automatically identified.

[0077] Step S27: If the access behavior deviation assessment data is greater than the preset dynamic deviation threshold, the access user trust data is downgraded to obtain the adjusted trust data; otherwise, the access user trust data is maintained to obtain the adjusted trust data.

[0078] Specifically, if the access behavior deviation assessment data exceeds a preset dynamic deviation threshold, the credit score of the relevant user will be automatically lowered, and they will be marked as an object requiring further review. This downgrade can be implemented through an automated script, which reads the deviation assessment results and adjusts the trust score according to predefined rules. If the deviation assessment data does not exceed the threshold, the user's existing trust score will be maintained. All adjusted trust data will be recorded in the database, resulting in the final adjusted trust data.

[0079] Step S28: Based on the access behavior baseline model, construct a zero-trust access control model according to the access behavior deviation assessment data and the adjusted trust level data to obtain the zero-trust access control model, and perform dynamic minimum permission allocation on the distributed encrypted ledger dataset according to the zero-trust access control model to obtain the permission-controlled ledger dataset.

[0080] Specifically, please refer to the sub-steps of step S28 for the detailed implementation process of this embodiment.

[0081] This invention enhances the accuracy of access behavior analysis by acquiring and analyzing historical access records to distinguish between abnormal and normal access patterns. Secondly, by utilizing an access behavior baseline model to perform dynamic deviation analysis on real-time access data, it improves the dynamism of access control, ensuring real-time adjustment of access permissions and increasing system responsiveness and flexibility. Furthermore, by capturing logbook access data in real time and extracting user trust levels, it strengthens trust management, enhancing its dynamism and adaptability. When access behavior deviations exceed preset thresholds, it automatically lowers user trust levels, responding promptly to potential security threats and reducing the risk of unauthorized access and data leakage. Based on a zero-trust access control model, it implements dynamic least privilege allocation, ensuring users only access the minimum dataset required for their business, reducing the possibility of privilege abuse. By constructing an access behavior baseline model and a zero-trust access control model, it promotes refined access control management, improving the accuracy and effectiveness of access control.

[0082] Preferably, step S28 includes the following steps:

[0083] Step S281: Perform feature fusion on the access behavior baseline model, access behavior deviation assessment data, and adjusted trust level data to obtain the access control feature vector;

[0084] Specifically, Python's Pandas library can be used to process and integrate the access behavior baseline model, access behavior bias assessment data, and adjusted trust data. Feature engineering can extract key features such as access frequency, access time, user identity, and behavior bias scores. Next, machine learning libraries like scikit-learn are used for feature selection and extraction to determine the most predictive features. These features are then combined into a feature vector, ultimately yielding the access control feature vector.

[0085] Step S282: Adaptive access control rule generation is performed on the access control feature vector to obtain an initial access control rule set, and reinforcement learning is performed on the initial access control rule set to obtain an access control rule generator;

[0086] Specifically, deep learning frameworks, such as TensorFlow or PyTorch in Python, can be used to design a model that learns the relationship between access control feature vectors and access permissions. Using a training dataset, the model can identify which feature combinations correspond to high-risk or low-risk access behaviors. An initial set of access control rules is generated based on these learned patterns. Further, reinforcement learning techniques, such as Q-Learning or Deep Q-Network (DQN), are used to optimize the initial set of access control rules. By continuously adjusting the rules through interaction with the environment to maximize security performance, an access control rule generator is ultimately obtained. The access control rule generator continuously learns and updates the rule set.

[0087] Step S283: Use the access control rule generator to perform fine-grained access rule inference on the distributed encrypted ledger dataset to obtain the initial dynamic access control rule set;

[0088] Specifically, access control rule generators can be used to generate fine-grained access rules for decentralized encrypted ledger datasets. Using an access control rule generator, specific access permissions and conditions can be defined for each data item or dataset. For example, stricter access control rules can be defined for financial data, while relatively lenient rules can be defined for inventory data. These rules are inferred based on access control feature vectors and previously generated access control rule sets, ultimately resulting in an initial dynamic access control rule set. These access rules can be automatically managed and enforced using rule engines such as Drools or Jess.

[0089] Step S284: Perform fuzzy logic optimization on the initial dynamic access control rule set to obtain an optimized dynamic access control rule set;

[0090] Specifically, fuzzy logic can be used to optimize the initial dynamic access control rule set. Fuzzy logic is a mathematical method for handling uncertainty and fuzziness. By defining fuzzy sets and fuzzy rules, access requests can be handled more flexibly. For example, fuzzy concepts such as "high user trust" and "normal access time" can be defined, and corresponding weights can be assigned to these concepts. Using fuzzy logic tools such as MATLAB's Fuzzy Logic Toolbox or Python's scikit-fuzzy library, fuzzy logic models can be built, and these models can be applied to adjust and optimize access control rules, ultimately resulting in an optimized dynamic access control rule set.

[0091] Step S285: Perform correlation analysis and coordination on the optimized dynamic access control rule set to obtain a coordinated dynamic access control rule set;

[0092] Specifically, association rule mining algorithms such as Apriori or FP-Growth can be used to analyze and optimize the relationships between different access control rules in a dynamic access control rule set. These algorithms can help identify which rules are frequently triggered together, thereby optimizing the execution order and logic of the rules. These association analyses can be performed using data mining software such as R or Python's MLxtend library. Next, a coordination mechanism ensures consistency and complementarity among the rules. This can be implemented using expert systems or decision support systems such as IBM i2 Analyst's Notebook, which defines the coordination logic and priorities between rules. Finally, a coordinated dynamic access control rule set is generated.

[0093] Step S286: Construct an adaptive policy execution engine based on the coordinated dynamic access control rule set to obtain a zero-trust access control model;

[0094] Specifically, an adaptive policy enforcement engine can be built, which implements a zero-trust access control model based on a harmonized dynamic access control rule set. Workflow management tools such as BPMN (Business Process Model and Symbol) or automation tools such as Microsoft Power Automate can be used to design and implement the execution flow of access control policies. These tools allow for defining the logic, conditions, and actions of policy enforcement. By integrating machine learning models and rule engines such as Drools, the engine can evaluate access requests in real time and make decisions based on the harmonized dynamic access control rule set. The adaptive policy enforcement engine will continuously learn and adjust policies to adapt to changing access patterns and security threats, thereby building a zero-trust access control model.

[0095] Step S287: Use the zero-trust access control model to dynamically evaluate and allocate access permissions to the decentralized encrypted ledger dataset to obtain a preliminary access allocation scheme;

[0096] Specifically, access management tools such as Microsoft Identity Manager or Oracle Access Manager can be used to define and implement fine-grained access control policies. These tools allow for dynamic adjustment of access permissions based on user attributes, environmental factors, and behavioral patterns. By integrating an adaptive policy enforcement engine, access requests can be evaluated in real time, and an initial permission allocation plan can be generated. Data analysis and reporting tools such as Tableau or Power BI can be used to visualize the effects of the permission allocation, ultimately resulting in the initial permission allocation plan.

[0097] Step S288: Adjust the data access edge nodes in real time according to the preliminary permission allocation scheme to obtain the adjusted permission allocation scheme;

[0098] Specifically, network access control (NAC) systems such as Cisco ISE or ForeScout CounterACT can be used to monitor and control account data access. Access policies are configured within the NAC system, defining policies based on user identity, device type, access time, and location factors. An integrated adaptive policy enforcement engine dynamically updates access control lists (ACLs) in response to adjustments in the initial permission allocation scheme. For example, if a user is excluded from specific data access permissions, the NAC system automatically updates the policy to block their access request. Simultaneously, identity and access management (IAM) tools such as Microsoft Active Directory or Okta are used to further manage and audit user permissions. Furthermore, automated scripts or configuration management tools such as Ansible or Puppet can be used to automate the permission adjustment process, deploying changes to all edge nodes, reducing manual intervention and mitigating the risk of errors.

[0099] Step S289: Embed permissions into the distributed encrypted ledger dataset according to the adjusted permission allocation scheme to obtain a permission-controlled ledger dataset.

[0100] Specifically, data encryption and access control software such as Symantec Encryption Desktop or Microsoft Azure Information Protection can be used to define and enforce access control policies for each data item or dataset, depending on the adjusted permission allocation scheme. These tools allow access permissions to be embedded directly into the data, ensuring that only authorized users can decrypt and access the data, ultimately resulting in a permission-controlled ledger dataset. By integrating an adaptive policy enforcement engine, it can be ensured that access control policies remain consistent with the latest permission allocation scheme. Data management platforms such as Hadoop or Amazon S3 can be used to store and manage the permission-controlled ledger dataset.

[0101] This invention utilizes feature fusion technology to more intelligently identify and respond to access behaviors, enhancing the accuracy and effectiveness of access control. The use of an adaptive access control rule generator dynamically generates access control rules based on real-time data, improving system flexibility and adaptability. Fine-grained access rule inference ensures rigorous authentication and permission checks on distributed encrypted ledger datasets, thereby improving data security. Fuzzy logic optimization reduces rule conflicts and misjudgments, improving the accuracy and reliability of access control. Correlation analysis and coordination ensure consistency and coordination among access control rule sets, enhancing system stability and predictability. The construction of an adaptive policy execution engine realizes a zero-trust access control model, improving the execution efficiency and response speed of access control policies. Dynamic access permission evaluation and allocation ensures that users can only access the minimum dataset required for their business, reducing the risk of permission abuse. Real-time adjustment of data access edge nodes improves the real-time nature and effectiveness of data access. Finally, permission embedding ensures strict control and recording of access permissions, comprehensively enhancing the security and reliability of enterprise data management.

[0102] Preferably, step S3 includes the following steps:

[0103] Step S31: Obtain the baseline model of access behavior;

[0104] Specifically, the baseline model of access behavior can be obtained directly from the previously built model library.

[0105] Step S32: Capture the access behavior stream in real time on the access-controlled ledger dataset to obtain the user access behavior data stream;

[0106] Specifically, network monitoring tools such as Wireshark or tcpdump can be used to capture network traffic and analyze access requests. Furthermore, application performance management (APM) tools such as New Relic or Dynatrace can be used to monitor application-level access behavior and performance metrics. These tools can collect access data in real time, including but not limited to access time, visitor identity, accessed resources, and operation type information. By integrating this data into a central monitoring system, such as using Apache Kafka or RabbitMQ message queues, a real-time access behavior data stream can be built.

[0107] Step S33: Use the access behavior baseline model to perform user behavior deviation analysis on the user access behavior data stream to obtain preliminary access anomaly detection results data;

[0108] Specifically, machine learning platforms such as Python's scikit-learn library or the R language can be used to load a baseline model of access behavior and perform prediction and deviation analysis on user access behavior data streams. The baseline model assesses whether access behavior conforms to normal patterns and calculates a deviation score. For example, if a user suddenly starts accessing resources they don't usually access, or if their access frequency increases significantly, this will result in a high deviation score. By setting dynamic deviation thresholds, access behaviors that significantly deviate from normal patterns can be automatically identified. This ultimately yields preliminary access anomaly detection results.

[0109] Step S34: Evaluate the confidence level of the preliminary access anomaly detection results data and weight them to obtain weighted access anomaly detection results data;

[0110] Specifically, the initial access anomaly detection data can be processed using Python's Pandas library or the R language to calculate the confidence level for each anomaly detection. This can be done using statistical tests such as the chi-square test or t-test to determine the significance of the anomaly detection. Next, based on the confidence level assessment, a weight is assigned to each anomaly detection. The weights can be calculated using a predefined weighting function that considers confidence level, anomaly severity, and potential influencing factors, ultimately resulting in weighted access anomaly detection data. Decision support systems such as IBM SPSS or SAS can help automate this weighting process.

[0111] Step S35: Perform contextual correlation analysis on the weighted access anomaly detection result data based on the user access behavior data stream to obtain contextual anomaly detection result data;

[0112] Specifically, association rule mining algorithms such as Apriori or FP-Growth can be used to analyze the patterns and correlations in the weighted access anomaly detection results data within the user access behavior data stream. These algorithms can help identify which behavioral features frequently co-occur with anomalous access behaviors. Next, a machine learning platform such as scikit-learn or TensorFlow is used to train a model to identify context-dependent anomalous access patterns. The model will consider multiple dimensions of user access behavior, such as time, location, device type, and access path, to identify the contextual features of anomalous access. Finally, based on these analysis results, contextual anomaly detection result data will be generated.

[0113] Step S36: Generate an intelligent audit report based on the context anomaly detection result data to obtain the audit anomaly detection result data;

[0114] Specifically, report templates can be created using Python's Jupyter Notebook or R Markdown, containing charts and text to display anomaly detection results. Then, automated scripts such as Python or R scripts are used to extract key information from the contextual anomaly detection data and populate the report templates. This ultimately yields the audit anomaly detection results data.

[0115] Step S37: Based on the audit anomaly detection results, perform risk assessment and data hardening on the access-controlled ledger dataset to obtain the risk-hardened ledger dataset.

[0116] Specifically, please refer to the sub-step of step S37 for the specific implementation process of this embodiment.

[0117] This invention improves the accuracy of behavior monitoring by acquiring a baseline model of access behavior. By capturing user access behavior data streams in real time and performing deviation analysis, the timeliness of anomaly detection is enhanced, enabling rapid discovery and response to potential security threats. Confidence assessment and weighting of preliminary anomaly detection results further improve the reliability of anomaly detection, reducing the probability of false positives and false negatives. The application of contextual correlation analysis allows for a more comprehensive understanding of the background and impact of abnormal behavior, improving the depth and breadth of anomaly detection. Automatically generated intelligent audit reports provide detailed descriptions and analyses of abnormal behavior, facilitating rapid understanding and action. Comprehensive risk assessment based on audit anomaly detection results and the implementation of data hardening measures strengthen data security and attack resistance. Real-time monitoring and rapid response mechanisms improve the system's response speed to security incidents, reducing business interruptions and data loss. Automatic adjustment of monitoring strategies and anomaly detection models based on changes in user behavior enhances adaptability, accommodating different business scenarios and security requirements.

[0118] Preferably, step S37 includes the following steps:

[0119] Step S371: Classify the audit anomaly detection result data into anomaly behavior categories to obtain an anomaly behavior type dataset. The anomaly behavior type dataset contains several anomaly behavior type data, and each anomaly behavior type data corresponds to an anomaly behavior type.

[0120] Specifically, the Pandas library in Python can be used to clean and preprocess the audit anomaly detection results data. Then, NLP tools such as NLTK or spaCy are used to extract key features and behavioral patterns. Supervised learning algorithms, such as Support Vector Machines (SVM) or Random Forests, can be used to train a classification model to identify different types of abnormal behavior. For example, abnormal behavior records, access violation records, transaction anomaly records, and system violation operations can be used as different category labels. Machine learning platforms such as scikit-learn or TensorFlow can be used to train this classification model. After the model is trained, it will be used to classify the audit anomaly detection results data, resulting in an anomaly behavior type dataset. This dataset will contain several anomaly behavior type data, each corresponding to a specific anomaly behavior type.

[0121] Step S372: Determine the risk level of each abnormal behavior type in the abnormal behavior type dataset according to the preset abnormal behavior-risk level mapping table to obtain the abnormal behavior risk level dataset.

[0122] Specifically, an abnormal behavior-risk level mapping table can be defined, associating different abnormal behavior types with corresponding risk levels. For example, unauthorized access is mapped to high risk, while frequent login attempts are mapped to medium risk. Using a decision support system such as IBM SPSS or SAS, a risk level can be automatically assigned to each abnormal behavior type based on the pre-defined abnormal behavior-risk level mapping table. Ultimately, the risk level determination results will form an abnormal behavior risk level dataset.

[0123] Step S373: Based on the access-controlled ledger dataset, predict the impact range of each abnormal behavior type in the abnormal behavior type dataset according to the abnormal behavior risk level dataset, and obtain the impact range prediction result set;

[0124] Specifically, Python's Pandas library or the R language can be used to analyze access-controlled ledger datasets to identify key data assets and access permissions. Next, combined with anomaly risk level datasets, statistical analysis and predictive models are used to assess the potential impact range of each anomaly. For example, logistic regression or decision tree models can be used to predict the potential impact of high-risk anomalies on data assets. Furthermore, data visualization tools such as Tableau or Power BI can be used to visually represent the impact range prediction results. In this way, the potential impact of anomalies on ledger data can be identified and assessed. Finally, the impact range prediction results will be organized into an impact range prediction result set.

[0125] Step S374: Based on the impact range prediction result set, identify vulnerable areas in the access-controlled ledger dataset to obtain ledger vulnerable area mapping data;

[0126] Specifically, data analysis software such as Python's Pandas library can be used to process the impact range prediction result set, extracting key indicators such as access frequency, data sensitivity, and historical security incidents. Next, risk assessment tools such as Nessus or OpenVAS are used to perform a security scan on the ledger dataset to identify potential security vulnerabilities and weaknesses. By integrating these tools, the prediction results can be automatically compared with actual security scan data to identify vulnerable areas. Finally, this information will be integrated into ledger vulnerability area mapping data.

[0127] Step S375: Based on the preset multi-level reinforcement strategy library, select reinforcement strategies for the access-controlled ledger dataset according to the impact range prediction result set and the ledger vulnerability area mapping data, and obtain the ledger data reinforcement strategy;

[0128] Specifically, a multi-level hardening strategy library can be defined, containing different levels of hardening measures, such as data encryption, enhanced access control, and improved security auditing. Using decision support systems such as IBM i2 Analyst's Notebook or SAS, combined with impact range prediction result sets and ledger vulnerability area mapping data, the effectiveness and cost-effectiveness of each hardening measure can be evaluated. A rule engine such as Drools can automatically select the optimal hardening strategy based on predefined rules. Furthermore, a policy management platform such as Microsoft Identity Manager or Okta can be used to manage and deploy the selected hardening strategies. Finally, based on the evaluation results and the strategy library, a ledger data hardening strategy is generated.

[0129] Step S376: Perform comprehensive reinforcement of the access-controlled ledger dataset according to the ledger data reinforcement strategy to obtain the risk-reinforced ledger dataset.

[0130] Specifically, based on the ledger data hardening strategy, access permissions can be reconfigured using Identity and Access Management (IAM) systems such as Microsoft Active Directory or Okta to ensure that only authenticated and authorized users can access sensitive data. Simultaneously, a Security Information and Event Management (SIEM) system, such as Splunk or IBM QRadar, should be deployed or upgraded to enhance monitoring and logging of ledger data access and operations. Based on the ledger's vulnerability area mapping data, vulnerability scanning tools such as Nessus or Qualys should be used to scan the system, identify, and remediate security vulnerabilities. Furthermore, security policies and response processes should be updated based on the latest security threat intelligence. Automation tools such as Ansible or Puppet can be used to automate the hardening process, automatically deploying encryption measures, updating access control lists, and configuring the SIEM system. The final result is a risk-hardened ledger dataset.

[0131] This invention classifies anomalous behaviors to more accurately identify and label different types of anomalous actions. By utilizing an anomalous behavior-risk level mapping table, it can accurately determine the risk level of each anomalous behavior, ensuring consistent assessments. Through impact range prediction, it can predict the potential impact range of anomalous behaviors based on a risk level dataset. By identifying vulnerable areas in ledger data and selecting the most suitable hardening strategy from a multi-level hardening strategy library, it improves the effectiveness of data protection. The implementation of a comprehensive hardening strategy enhances data security and resistance to attacks. By dynamically adjusting hardening strategies based on real-time audit anomaly detection results, it adapts to constantly evolving security threats. Automated anomaly detection and hardening processes reduce manual intervention, improving the efficiency and reliability of enterprise data management. These comprehensive measures work together to enhance the overall effectiveness and compliance of enterprise data management.

[0132] Preferably, step S4 includes the following steps:

[0133] Step S41: Perform service function semantic analysis on the risk reinforcement ledger dataset to obtain the ledger data function semantic vector set, and graph the ledger data function semantic vector set to obtain the ledger service function semantic graph.

[0134] Specifically, Python's NLTK or spaCy libraries can be used to parse the text content in the risk reinforcement ledger dataset, extracting keywords and concepts. Next, a machine learning platform such as scikit-learn or TensorFlow is used to train a model to identify and classify different service functions. In this way, the service functions in the dataset can be transformed into a series of semantic vectors, each representing a specific service function. Then, graph analysis tools such as Neo4j or Apache Jena are used to graph these semantic vectors, constructing a semantic graph of ledger service functions. In this graph, nodes represent service functions, and edges represent relationships between functions.

[0135] Step S42: Perform service boundary division and function clustering on the semantic graph of ledger service functions to obtain a preliminary decoupling scheme for ledger services;

[0136] Specifically, graph analysis tools such as Neo4j can be used to analyze the nodes (service functions) and edges (functional relationships) in the semantic graph of ledger service functions, identifying the degree of closeness and dependencies between service functions. Next, clustering algorithms such as K-means or hierarchical clustering are applied to group similar or closely related service functions together, forming different functional clusters. This can be achieved using machine learning platforms such as scikit-learn, which automatically determines the optimal number and method of clusters. Then, based on the clustering results, service boundaries are defined, clarifying the responsibilities and scope of each service function cluster. Finally, this information will be integrated into a preliminary ledger service decoupling scheme.

[0137] Step S43: Conduct a reliability assessment of the initial decoupling scheme for the ledger service and perform iterative optimization to obtain the ledger service decoupling mapping data;

[0138] Specifically, please refer to the sub-step of step S43 for the specific implementation process of this embodiment.

[0139] Step S44: Based on the decoupling mapping data of the ledger service, design the risk-reinforced ledger dataset according to the service domain-driven principle to obtain the ledger service domain model architecture;

[0140] Specifically, modeling tools such as Enterprise Architect or Visual Paradigm can be used to create conceptual models, defining the relationships between business domains and entities. Ledger services are used to decouple and map data, identifying key business entities, services, and data models. A clear business domain model is constructed using the concepts of aggregate roots, entities, value objects, and domain services from Domain-Driven Design. Then, UML (Unified Modeling Language) is used to describe the attributes, methods, and interactions of these entities in detail. Finally, the ledger service domain model architecture is formed.

[0141] Step S45: Construct a microservice architecture for the ledger service domain model architecture to obtain the ledger microservice architecture blueprint;

[0142] Specifically, based on the entities and business logic in the domain model architecture of the ledger service, the service can be broken down into independent microservice components. Each microservice will be responsible for handling specific business functions and communicating with other services through well-defined APIs. API design tools such as Swagger or Postman are used to design and test these APIs. Furthermore, containerization technologies such as Docker and Kubernetes are leveraged to provide a deployment and runtime environment for the microservices. Ultimately, a ledger microservice architecture blueprint is formed, clearly defining the function, dependencies, and deployment method of each microservice.

[0143] Step S46: Based on the ledger microservice architecture blueprint, perform stateless transformation on each microservice in the risk hardening ledger dataset to obtain a set of stateless ledger microservices;

[0144] Specifically, microservice development frameworks such as Spring Cloud or Netflix OSS can be used to ensure that each microservice in the ledger microservice architecture blueprint is stateless and does not depend on any local storage or session state. By storing state information in an external persistent storage system, such as a distributed cache or database, microservices can be restarted or scaled anytime, anywhere without losing state. Continuous integration / continuous deployment (CI / CD) tools such as Jenkins or GitLab CI are used to automate the building, testing, and deployment processes of microservices. This ensures that each microservice can be deployed and updated independently without affecting other services. Ultimately, this forms a stateless collection of ledger microservices.

[0145] Step S47: Deploy the stateless ledger microservice set in a grid to obtain the elastic grid ledger dataset.

[0146] Specifically, service mesh platforms such as Istio or Linkerd can be used to provide microservices with functionalities such as traffic management, service discovery, and load balancing. Service meshes allow for more flexible and reliable communication between microservices, supporting dynamic service routing and failover. Container orchestration tools like Kubernetes are used to deploy microservices into clusters, enabling automatic scaling and self-healing. By defining service mesh policies and rules, fine-grained control over communication and security policies between services can be achieved. Monitoring and logging tools such as Prometheus and Grafana are used to monitor the status and performance of the service mesh in real time. Ultimately, this results in a resilient mesh ledger dataset.

[0147] This invention enhances the understandability of service functions by performing service function semantic analysis on a ledger dataset. By utilizing a service function semantic graph, service boundaries are clearly defined and functions are clustered. Through reliability assessment and iterative optimization, the service decoupling scheme is continuously optimized, improving the reliability of the service architecture. Based on the service decoupling mapping data, a service domain model architecture conforming to the service domain-driven principle is designed, realizing the modeling of the service domain and improving the clarity and maintainability of the service architecture. The construction of a microservice architecture decomposes complex service functions into independent microservices, improving the system's flexibility and scalability. Stateless transformation enables services to be expanded and deployed more flexibly, enhancing the system's scalability and resilience. Mesh deployment optimizes service deployment, improving service availability and fault tolerance. The independence and isolation of each service in the microservice architecture enhances system security and reduces the impact of a single service failure on the overall system.

[0148] Preferably, step S43 includes the following steps:

[0149] Step S431: Construct a ledger service decoupling evaluation model, and use the ledger service decoupling evaluation model to conduct a multi-dimensional evaluation of the preliminary ledger service decoupling scheme, and obtain a set of ledger service decoupling evaluation indicators;

[0150] Specifically, the Pandas library in Python can be used to process and analyze ledger data to identify key indicators of service decoupling, such as service independence, data consistency, and system complexity. Next, statistical analysis software such as R or JMP is used to build a multi-dimensional evaluation model that comprehensively considers these key indicators. A predictive model can be trained using a machine learning platform such as scikit-learn to evaluate the effectiveness of the initial ledger service decoupling scheme. Using decision tree or random forest algorithms, the decoupling scheme can be automatically evaluated, and a set of ledger service decoupling evaluation indicators can be generated.

[0151] Step S432: Based on the decoupling evaluation index set of ledger service, perform reliability simulation on the preliminary decoupling scheme of ledger service to obtain the reliability simulation data of ledger service decoupling;

[0152] Specifically, simulation software such as MATLAB Simulink or AnyLogic can be used to build a simulation model based on a set of evaluation metrics for decoupling the ledger service. This model will simulate the system behavior after service decoupling, including service interaction, data flow, and system response. By setting different simulation scenarios and parameters, the performance of the decoupling scheme under different conditions can be tested. Using simulation analysis tools such as Simulink Design Optimization or AnyLogic Optimization, parameter optimization and sensitivity analysis can be performed to determine the key influencing factors of the decoupling scheme. Finally, the simulation results will generate reliability simulation data for the ledger service decoupling.

[0153] Step S433: Identify potential risk points in the reliability simulation data of the ledger service decoupling to obtain the risk point data of the ledger service decoupling;

[0154] Specifically, risk management software such as Hazard Analysis or System Theoretic Process Analysis (STPA) can be used to analyze the reliability simulation data of the ledger service decoupling to identify factors leading to system failures or performance degradation. By defining a risk matrix, the severity and probability of occurrence of each potential risk point can be assessed. Data visualization tools such as Tableau or Power BI can help to visually display the distribution and impact of risk points. Next, Fault Tree Analysis (FTA) or Event Tree Analysis (ETA) methods are used to further analyze the causes and propagation paths of the risk points. Finally, the identified potential risk points will be recorded in the ledger service decoupling risk point dataset.

[0155] Step S434: Generate a comprehensive risk assessment report based on the set of assessment indicators for decoupling ledger services and the risk point data for decoupling ledger services, and obtain the service decoupling risk assessment report;

[0156] Specifically, Excel or professional data analysis software such as Tableau can be used to organize and analyze the set of assessment indicators and risk points related to the decoupling of ledger services. These tools enable the calculation of risk scores, identification of key risk factors, and assessment of their potential impact on the service decoupling solution. Next, risk management software such as Axiom or Oracle Risk Analytics is used to integrate this data into a comprehensive risk assessment report. The report will detail the severity, probability of occurrence, and potential impact on business operations for each risk point, ultimately resulting in a service decoupling risk assessment report.

[0157] Step S435: Based on the service decoupling risk assessment report, optimize the initial service decoupling scheme of the ledger using a genetic algorithm to obtain a set of optimized service decoupling schemes for the ledger.

[0158] Specifically, genetic algorithm toolboxes such as Python's DEAP library or MATLAB's Global Optimization Toolbox can be used to define the optimization problem, including the objective function, constraints, and initial population. The objective function will be designed based on the risk score and business requirements in the service decoupling risk assessment report to minimize risk and maximize the effect of service decoupling. Next, a genetic algorithm is run to iteratively improve the decoupling scheme, generating a new population through operations such as selection, crossover, and mutation. This process can be automated using algorithm optimization software such as MATLAB or Python's SciPy library to find the optimal or near-optimal decoupling scheme. Finally, the algorithm will output an optimized set of ledger service decoupling schemes.

[0159] Step S436: Obtain the set of optimization trade-off indicators for ledger targets, and filter the set of decoupling optimization schemes for ledger services based on the set of optimization trade-off indicators to obtain ledger service decoupling mapping data.

[0160] Specifically, decision support systems such as IBM i2 Analyst's Notebook or SAS can be used to define and quantify trade-off metrics, such as cost-effectiveness, performance, maintainability, and security, ultimately resulting in a set of trade-off metrics for optimizing ledger objectives. Next, multi-criteria decision analysis (MCDM) methods, such as the Analytic Hierarchy Process (AHP) or the Technology Evaluation and Selection Solution (TOPSIS), are used to evaluate and compare the various options in the set of trade-off metrics for optimizing ledger objectives. This evaluation process can be automated using MCDM software or custom analysis tools. Finally, based on the evaluation results, the option with the highest score is selected as the final ledger service decoupling mapping data.

[0161] This invention significantly improves the quality and implementation effectiveness of enterprise-level ledger service decoupling solutions by constructing a ledger service decoupling evaluation model and applying advanced optimization techniques. It enables comprehensive evaluation of preliminary decoupling solutions from multiple dimensions, enhancing the accuracy and comprehensiveness of the assessment. By utilizing a set of evaluation indicators for reliability simulation, the actual performance of the decoupling solution is predicted and verified, improving its reliability and identifying potential problems early. In-depth analysis of simulation data identifies potential risk points in the decoupling solution. A comprehensive risk assessment report is generated by combining the evaluation indicator set and risk point data, providing comprehensive risk information and recommendations. A genetic algorithm is applied to optimize the preliminary decoupling solution, resulting in a more efficient and reliable set of optimized service decoupling solutions. By acquiring and applying a set of ledger target optimization trade-off indicators, the decoupling solution that best meets the enterprise's goals and needs is selected, achieving a balance between optimization objectives. Furthermore, the optimized service decoupling solution accelerates the enterprise's response speed to market changes and business needs, improving its competitiveness and market adaptability.

[0162] Preferably, the present invention also provides a security service system for enterprise-level ledgers, used to execute the security service method for enterprise-level ledgers as described above, the security service system for enterprise-level ledgers comprising:

[0163] The encrypted storage module is used to collect ledger data from the target enterprise to obtain the original ledger dataset; to perform hierarchical encryption on the original ledger dataset to obtain the encrypted ledger dataset; and to perform distributed storage on the encrypted ledger dataset to obtain the distributed encrypted ledger dataset.

[0164] The access control module is used to construct a zero-trust architecture access control model for the distributed encrypted ledger dataset, resulting in a zero-trust access control model; and to dynamically allocate the least privileges to the distributed encrypted ledger dataset based on the zero-trust access control model, resulting in a permission-controlled ledger dataset.

[0165] The behavior auditing and risk assessment module is used to obtain an access behavior baseline model; to perform real-time anomaly detection and intelligent auditing on the access-controlled ledger dataset using the access behavior baseline model, and to obtain audit anomaly detection result data; and to perform risk assessment and data hardening on the access-controlled ledger dataset based on the audit anomaly detection result data, and to obtain a risk-hardened ledger dataset.

[0166] The microservice architecture construction module is used to perform service function decoupling analysis on the risk hardening ledger dataset to obtain ledger service decoupling mapping data; based on the ledger service decoupling mapping data, the risk hardening ledger dataset is used to construct an elastic microservice architecture to obtain the ledger microservice architecture blueprint; based on the ledger microservice architecture blueprint, the risk hardening ledger dataset is used to perform stateless design and implementation and service mesh deployment to obtain the elastic mesh ledger dataset.

[0167] This invention achieves significant improvements in data security, dynamic access control, real-time behavior auditing and risk assessment, service function decoupling, and microservice architecture construction through encrypted storage modules, access control modules, behavior auditing and risk assessment modules, and microservice architecture construction, thereby effectively improving enterprise operational efficiency. The system's multi-layered security measures and zero-trust architecture ensure data confidentiality and access security, while real-time monitoring and intelligent analysis mechanisms improve response speed and processing capabilities for security incidents. Furthermore, the system's modular design and microservice architecture not only reduce maintenance costs but also enhance maintainability and scalability, possessing strong adaptability to meet the ledger data management needs of enterprises of different types and sizes, ensuring the security of critical enterprise information and the efficiency of enterprise operations.

[0168] Therefore, the embodiments should be considered as exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, it is intended that all variations falling within the meaning and scope of the equivalents of the application be incorporated into the invention.

[0169] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features of the invention herein.

Claims

1. A security service method for enterprise-level ledgers, characterized in that, Includes the following steps: Step S1: Collect ledger data from the target company to obtain the original ledger dataset; The original ledger dataset is hierarchically encrypted to obtain an encrypted ledger dataset; the encrypted ledger dataset is then distributed and stored to obtain a distributed encrypted ledger dataset. Step S2: Construct a zero-trust architecture access control model for the distributed encrypted ledger dataset to obtain the zero-trust access control model; Perform dynamic least privilege allocation on the distributed encrypted ledger dataset according to the zero-trust access control model to obtain the access-controlled ledger dataset. Step S3: Obtain the access behavior baseline model; use the access behavior baseline model to perform real-time anomaly detection and intelligent auditing on the access-controlled ledger dataset to obtain audit anomaly detection results data; Based on the audit anomaly detection results, a risk assessment and data hardening are performed on the access-controlled ledger dataset to obtain a risk-hardened ledger dataset; wherein, step S3 includes the following steps: Step S31: Obtain the baseline model of access behavior; Step S32: Capture the access behavior stream in real time on the access-controlled ledger dataset to obtain the user access behavior data stream; Step S33: Use the access behavior baseline model to perform user behavior deviation analysis on the user access behavior data stream to obtain preliminary access anomaly detection results data; Step S34: Evaluate the confidence level of the preliminary access anomaly detection results data and weight them to obtain weighted access anomaly detection results data; Step S35: Perform contextual correlation analysis on the weighted access anomaly detection result data based on the user access behavior data stream to obtain contextual anomaly detection result data; Step S36: Generate an intelligent audit report based on the context anomaly detection result data to obtain the audit anomaly detection result data; Step S37: Based on the audit anomaly detection results, perform risk assessment and data hardening on the access-controlled ledger dataset to obtain a risk-hardened ledger dataset; Step S37 includes the following steps: Step S371: Classify the audit anomaly detection result data into anomaly behavior categories to obtain an anomaly behavior type dataset. The anomaly behavior type dataset contains several anomaly behavior type data, and each anomaly behavior type data corresponds to an anomaly behavior type. Step S372: Determine the risk level of each abnormal behavior type in the abnormal behavior type dataset according to the preset abnormal behavior-risk level mapping table to obtain the abnormal behavior risk level dataset. Step S373: Based on the access-controlled ledger dataset, predict the impact range of each abnormal behavior type in the abnormal behavior type dataset according to the abnormal behavior risk level dataset, and obtain the impact range prediction result set; Step S374: Based on the impact range prediction result set, identify vulnerable areas in the access-controlled ledger dataset to obtain ledger vulnerable area mapping data; Step S375: Based on the preset multi-level reinforcement strategy library, select reinforcement strategies for the access-controlled ledger dataset according to the impact range prediction result set and the ledger vulnerability area mapping data, and obtain the ledger data reinforcement strategy; Step S376: Perform comprehensive reinforcement on the access-controlled ledger dataset according to the ledger data reinforcement strategy to obtain the risk-reinforced ledger dataset; Step S4: Perform service function decoupling analysis on the risk hardening ledger dataset to obtain ledger service decoupling mapping data; construct an elastic microservice architecture for the risk hardening ledger dataset based on the ledger service decoupling mapping data to obtain the ledger microservice architecture blueprint; and implement stateless design and service mesh deployment for the risk hardening ledger dataset based on the ledger microservice architecture blueprint to obtain the elastic mesh ledger dataset.

2. The security service method for enterprise-level ledgers according to claim 1, characterized in that, Step S1 includes the following steps: Step S11: Obtain the enterprise terminal device identifier list; Step S12: Collect ledger data from terminal devices according to the enterprise terminal device identification list to obtain the original ledger dataset; Step S13: Perform data structure recognition on the original ledger dataset to obtain the ledger data structure mapping set; Step S14: Group the original ledger dataset according to the same data structure based on the ledger data structure mapping set to obtain several groups of structured ledger data; Step S15: Identify the data categories of each group of structured ledger data to obtain a ledger type dataset; Step S16: Encrypt several sets of structured ledger data according to the ledger type dataset to obtain an encrypted ledger dataset, and then distribute the encrypted ledger dataset to obtain a distributed encrypted ledger dataset.

3. The security service method for enterprise-level ledgers according to claim 2, characterized in that, Step S16 includes the following steps: Step S161: Use the ledger type dataset to perform association mapping on several groups of structured ledger data to obtain a type-related ledger data table; Step S162: Extract the corresponding ledger type from a set of structured ledger data based on the type-related ledger data table to obtain ledger type data; Step S163: If the ledger type data is any one of financial ledger, tax ledger, or compliance ledger, then the corresponding group of structured ledger data is marked with the highest level of security to obtain ledger security level marked data. Step S164: If the ledger type data is any one of human resources type ledger, customer type ledger and supplier type ledger, then perform high-level security marking on the corresponding group of structured ledger data to obtain ledger security level marking data. Step S165: If the ledger type data is any one of asset type ledger, information technology type ledger, inventory type ledger and project type ledger, then perform general level security marking on the corresponding group of structured ledger data to obtain ledger security level marking data. Step S166: If the ledger security level marker data is the highest security level, then homomorphic encryption is performed on the corresponding group of structured ledger data to obtain encrypted ledger data. If the ledger security level marker data is a relatively high security level, then attribute-based encryption is performed on the corresponding group of structured ledger data to obtain encrypted ledger data. If the ledger security level marker data is a general security level, then lightweight symmetric encryption is performed on the corresponding group of structured ledger data to obtain encrypted ledger data. Step S167: Perform steps S162-S166 on each group of structured ledger data to obtain several ledger security level marker data and several encrypted ledger data. Record the several encrypted ledger data as the encrypted ledger dataset. Step S168: Divide the encrypted ledger dataset into data fragments of the same level according to several ledger security level marker data to obtain fragmented encrypted ledger datasets, and store the fragmented encrypted ledger datasets in a distributed manner to obtain distributed encrypted ledger datasets.

4. The security service method for enterprise-level ledgers according to claim 1, characterized in that, Step S2 includes the following steps: Step S21: Obtain the ledger access history data; Step S22: Extract and remove abnormal access data from the ledger access history data to obtain abnormal ledger access history data and normal ledger access history data. Step S23: Perform abnormal access pattern identification on the abnormal ledger access history data to obtain abnormal access pattern data, and perform normal access pattern identification on the normal ledger access history data to obtain normal access pattern data. Step S24: Construct an access behavior baseline model based on abnormal ledger access history data, normal ledger access history data, abnormal access pattern data, and normal access pattern data to obtain the access behavior baseline model; Step S25: Capture real-time access data of the distributed encrypted ledger dataset to obtain real-time access data of the ledger, and extract the access user trust level from the real-time access data of the ledger to obtain access user trust level data. Step S26: Use the access behavior baseline model to perform dynamic deviation analysis on the real-time access data of the ledger to obtain access behavior deviation assessment data; Step S27: If the access behavior deviation assessment data is greater than the preset dynamic deviation threshold, the access user trust data is downgraded to obtain the adjusted trust data; otherwise, the access user trust data is maintained to obtain the adjusted trust data. Step S28: Based on the access behavior baseline model, construct a zero-trust access control model according to the access behavior deviation assessment data and the adjusted trust level data to obtain the zero-trust access control model, and perform dynamic minimum permission allocation on the distributed encrypted ledger dataset according to the zero-trust access control model to obtain the permission-controlled ledger dataset.

5. The security service method for enterprise-level ledgers according to claim 4, characterized in that, Step S28 includes the following steps: Step S281: Perform feature fusion on the access behavior baseline model, access behavior deviation assessment data, and adjusted trust level data to obtain the access control feature vector; Step S282: Adaptive access control rule generation is performed on the access control feature vector to obtain an initial access control rule set, and reinforcement learning is performed on the initial access control rule set to obtain an access control rule generator; Step S283: Use the access control rule generator to perform fine-grained access rule inference on the distributed encrypted ledger dataset to obtain the initial dynamic access control rule set; Step S284: Perform fuzzy logic optimization on the initial dynamic access control rule set to obtain an optimized dynamic access control rule set; Step S285: Perform correlation analysis and coordination on the optimized dynamic access control rule set to obtain a coordinated dynamic access control rule set; Step S286: Construct an adaptive policy execution engine based on the coordinated dynamic access control rule set to obtain a zero-trust access control model; Step S287: Use the zero-trust access control model to dynamically evaluate and allocate access permissions to the decentralized encrypted ledger dataset to obtain a preliminary access allocation scheme; Step S288: Adjust the data access edge nodes in real time according to the preliminary permission allocation scheme to obtain the adjusted permission allocation scheme; Step S289: Embed permissions into the distributed encrypted ledger dataset according to the adjusted permission allocation scheme to obtain a permission-controlled ledger dataset.

6. The security service method for enterprise-level ledgers according to claim 1, characterized in that, Step S4 includes the following steps: Step S41: Perform service function semantic analysis on the risk reinforcement ledger dataset to obtain the ledger data function semantic vector set, and graph the ledger data function semantic vector set to obtain the ledger service function semantic graph. Step S42: Perform service boundary division and function clustering on the semantic graph of ledger service functions to obtain a preliminary decoupling scheme for ledger services; Step S43: Conduct a reliability assessment of the initial decoupling scheme for the ledger service and perform iterative optimization to obtain the ledger service decoupling mapping data; Step S44: Based on the decoupling mapping data of the ledger service, design the risk-reinforced ledger dataset according to the service domain-driven principle to obtain the ledger service domain model architecture; Step S45: Construct a microservice architecture for the ledger service domain model architecture to obtain the ledger microservice architecture blueprint; Step S46: Based on the ledger microservice architecture blueprint, perform stateless transformation on each microservice in the risk hardening ledger dataset to obtain a set of stateless ledger microservices; Step S47: Deploy the stateless ledger microservice set in a grid to obtain the elastic grid ledger dataset.

7. The security service method for enterprise-level ledgers according to claim 6, characterized in that, Step S43 includes the following steps: Step S431: Construct a ledger service decoupling evaluation model, and use the ledger service decoupling evaluation model to conduct a multi-dimensional evaluation of the preliminary ledger service decoupling scheme, and obtain a set of ledger service decoupling evaluation indicators; Step S432: Based on the decoupling evaluation index set of ledger service, perform reliability simulation on the preliminary decoupling scheme of ledger service to obtain the reliability simulation data of ledger service decoupling; Step S433: Identify potential risk points in the reliability simulation data of the ledger service decoupling to obtain the risk point data of the ledger service decoupling; Step S434: Generate a comprehensive risk assessment report based on the set of assessment indicators for decoupling ledger services and the risk point data for decoupling ledger services, and obtain the service decoupling risk assessment report; Step S435: Based on the service decoupling risk assessment report, optimize the initial service decoupling scheme of the ledger using a genetic algorithm to obtain a set of optimized service decoupling schemes for the ledger. Step S436: Obtain the set of optimization trade-off indicators for ledger targets, and filter the set of decoupling optimization schemes for ledger services based on the set of optimization trade-off indicators to obtain ledger service decoupling mapping data.

8. A security service system for enterprise-level ledgers, characterized in that, For executing the security service method for enterprise-level ledgers as described in claim 1, the security service system for enterprise-level ledgers includes: The encrypted storage module is used to collect ledger data from the target enterprise to obtain the original ledger dataset; to perform hierarchical encryption on the original ledger dataset to obtain the encrypted ledger dataset; and to perform distributed storage on the encrypted ledger dataset to obtain the distributed encrypted ledger dataset. The access control module is used to construct a zero-trust architecture access control model for the distributed encrypted ledger dataset, resulting in a zero-trust access control model; and to dynamically allocate the least privileges to the distributed encrypted ledger dataset based on the zero-trust access control model, resulting in a permission-controlled ledger dataset. The behavior auditing and risk assessment module is used to obtain an access behavior baseline model; to perform real-time anomaly detection and intelligent auditing on the access-controlled ledger dataset using the access behavior baseline model, and to obtain audit anomaly detection result data; and to perform risk assessment and data hardening on the access-controlled ledger dataset based on the audit anomaly detection result data, and to obtain a risk-hardened ledger dataset. The microservice architecture construction module is used to perform service function decoupling analysis on the risk hardening ledger dataset to obtain ledger service decoupling mapping data; based on the ledger service decoupling mapping data, the risk hardening ledger dataset is used to construct an elastic microservice architecture to obtain the ledger microservice architecture blueprint; based on the ledger microservice architecture blueprint, the risk hardening ledger dataset is used to perform stateless design and implementation and service mesh deployment to obtain the elastic mesh ledger dataset.