Data Flow Method, Device and Fiscal and Tax Integration Platform of an Integrated Platform

Through the integrated platform's data flow method, RPA, CL, iPaaS and data security monitoring modules are integrated, which solves the problems of inefficiency and insecure data flow in traditional financial processing, realizes cross-system secure data flow and intelligent processing, and improves financial management efficiency and security.

CN120013262BActive Publication Date: 2025-07-18WUHAN FEIYU YIKE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510502860.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-07-18
Estimated Expiration
2045-04-22

AI Technical Summary

Technical Problem

The traditional financial processing model relies on manual operation inefficiency, is prone to errors, and lacks a unified secure flow mechanism for cross-system data flow, resulting in reduced information island problems and financial management efficiency.

Method used

It adopts an integrated platform, integrates RPA module, CL module, iPaaS module and data security monitoring module, and realizes secure data flow across systems through data structure, risk data and key data identification and processing strategies generation.

Benefits of technology

It improves financial management efficiency, realizes seamless data exchange and collaborative work between multiple business processing systems, reduces the risk of human error, enhances data security, and realizes the full process automation and intelligence of financial data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120013262B_ABST
    Figure CN120013262B_ABST
Patent Text Reader

Abstract

The present application discloses a data flow method, device, and financial and tax integration platform for an integrated platform. The method includes: the RPA module converts multi-source data into structured data and identifies financial information in the structured data; the RPA module classifies and sorts the financial information to determine the processing order of the classified and sorted financial information; the CL module analyzes the financial information according to the processing order, determines the risk data and key data of the financial information, and generates a first processing strategy and a second processing strategy; the iPaaS module receives the risk data and key data, and transfers the risk data and key data to the data security monitoring module; the data security monitoring module uses the first processing strategy to conduct a risk investigation on the risk data, encrypts the key data using the second processing strategy, and transfers the risk data and the encrypted key data to the corresponding business processing platform. The present application can effectively improve the financial management efficiency and achieve secure data flow between systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of data transmission, and in particular, to a data flow method, device, and financial and tax integration platform for an integrated platform. Background Art

[0002] With the rapid development of the digital economy, enterprise financial management is undergoing unprecedented changes. The traditional financial processing mode relies on a large number of manual operations, which is not only inefficient but also prone to human errors. In the context of the global digital wave, financial process automation has become a key factor for enterprises to enhance their core competitiveness. Especially in a complex and ever-changing economic environment, enterprises need to process financial data more accurately and efficiently to support the strategic planning and business development of the decision-making level.

[0003] Financial data is characterized by multi-source, complexity, and sensitivity. The financial data generated in the daily operation of enterprises comes from a wide range of sources, including but not limited to multiple channels such as ERP systems, CRM systems, electronic invoice platforms, bank statements, and supplier systems. These data have different formats, including both structured data and semi-structured and unstructured data, such as PDF invoices, scanned documents, and emails. In addition, financial data usually contains sensitive information, such as bank accounts, tax numbers, and customer information, and data security issues are particularly prominent.

[0004] In recent years, robotic process automation (RPA) technology has been widely used in the financial field to help enterprises achieve partial process automation. By simulating human operations, RPA can perform tasks with high repetition and clear rules, such as data entry and report generation. However, enterprises usually have multiple business processing systems, and the data flow between these systems often relies on manual intervention or simple interface calls, lacking a unified data security flow mechanism, resulting in prominent information island problems. Therefore, although a single RPA technology can achieve the automation of basic processes, it is relatively limited in realizing cross-system data security flow, leading to a significant reduction in financial management efficiency. Summary of the Invention

[0005] Embodiments of the present application provide a data flow method, device, and financial and tax integration platform for an integrated platform, which are used to effectively improve financial management efficiency and achieve secure data flow between systems.

[0006] To achieve the above object, the embodiments of the present application adopt the following technical solutions:

[0007] In a first aspect, a data flow method for an integrated platform is provided, which is applied to a financial and tax integration platform. The financial and tax integration platform is obtained by integrating n business processing platforms, and the financial and tax integration platform includes an RPA module, a CL module, an iPaaS module, and a data security monitoring module. The method includes:

[0008] In response to a multi-source data entry instruction, the RPA module converts multi-source data into structured data and identifies financial information in the structured data;

[0009] The RPA module classifies and sorts the financial information and determines the processing order of the classified and sorted financial information;

[0010] The CL module analyzes the financial information according to the processing order, determines the risk data and key data of the financial information, and generates a first processing strategy and a second processing strategy;

[0011] The iPaaS module receives the risk data and key data and transfers the risk data and key data to the data security monitoring module;

[0012] The data security monitoring module conducts risk investigation on the risk data using the first processing strategy and encrypts the key data using the second processing strategy; and

[0013] The data security monitoring module transfers the risk data and the encrypted key data to the corresponding business processing platforms.

[0014] In a possible implementation manner of the first aspect, the CL module generates the first processing strategy and the second processing strategy, including:

[0015] The CL module extracts the context features of the financial information and obtains historical data;

[0016] The CL module dynamically generates the first processing strategy and the second processing strategy based on the context features and historical data;

[0017] Among them, the first processing strategy includes a risk data grading mechanism, a risk assessment model, an abnormal data identification rule, and a risk data traceability mechanism. The risk data grading mechanism is used to determine the risk level of the risk data. The risk assessment model is used to determine the risk probability of the risk data according to the risk level of the risk data. The abnormal data identification rule is used to determine the abnormal data in the risk data according to the risk probability. The risk data traceability mechanism is used to record the processing process of the risk data;

[0018] The second processing strategy includes a hierarchical encryption strategy, a dynamic key management mechanism, an access permission control strategy, and a data masking processing rule. The hierarchical encryption strategy is used to determine the sensitivity of the key data and determine the corresponding encryption algorithm based on the sensitivity. The dynamic key management mechanism is used to update the encryption key and store the encryption key in a decentralized manner. The access permission control strategy is used to set data access permissions; the data masking processing rule is used to mask or replace sensitive fields in the key data.

[0019] In another possible implementation of the first aspect, the CL module dynamically generates a first processing strategy and a second processing strategy based on context features and historical data, including:

[0020] The CL module takes data features and context features as input parameters and inputs them into a pre-built machine learning model to analyze and obtain the historical processing records of risk data and the historical encryption records of key data;

[0021] The CL module determines the parameters and conditions of the first processing strategy according to the historical processing records, and applies the parameters and conditions of the first processing strategy to the first processing strategy. Among them, the parameters and conditions of the first processing strategy include the threshold parameters of the risk data grading mechanism, the evaluation factors of the risk assessment model, the determination conditions of the abnormal data identification rule, and the record items of the risk data traceability mechanism;

[0022] The CL module determines the parameters and conditions of the second processing strategy according to the historical encryption records, and applies the parameters and conditions of the second processing strategy to the second processing strategy. Among them, the parameters and conditions of the second processing strategy include the encryption intensity of the hierarchical encryption strategy, the key update period of the dynamic key management mechanism, the permission matrix of the access control strategy, and the data desensitization method of the data desensitization processing rule.

[0023] In another possible implementation of the first aspect, the RPA module classifies and sorts financial information and determines the processing order of the classified and sorted financial information, including:

[0024] The RPA module divides financial information based on preset data categories to obtain at least one financial data set;

[0025] The RPA module determines the correlation degree between each financial data set and other financial data sets, and merges the financial data sets with a correlation degree higher than the preset correlation degree to obtain at least one associated financial data set;

[0026] For any associated financial data set, the RPA module uses a preset scoring rule to determine its time sensitivity score and data value score, and calculates the total score of each associated financial data set. Among them, the total score is the sum of the time sensitivity score and the data value score, and the order from high to low of the total score is used as the processing order of the associated financial data sets.

[0027] In another possible implementation of the first aspect, the CL module includes a basic data layer, a business logic layer, and a risk control layer. The CL module determines the risk data and key data of financial information, including:

[0028] For each associated financial data set, in the basic data layer, the CL module validates the format of the associated financial data set, and uses the data that fails the format validation in the associated financial data set as risk data;

[0029] In the business logic layer, the CL module performs business logic consistency verification on the associated financial data set, and takes the data in the associated financial data set that fails the business logic consistency verification as risk data;

[0030] In the risk control layer, the CL module performs data sensitivity verification on the associated financial data set, and takes the data in the associated financial data set that fails the data sensitivity verification as critical data.

[0031] In another possible implementation of the first aspect, after the iPaaS module receives the risk data and the critical data, it further includes:

[0032] The iPaaS module extracts the first feature of the risk data and the second feature of the critical data, and determines the optimal data transfer path based on the first feature and the second feature;

[0033] The iPaaS module monitors the efficiency and quality of the optimal data transfer path in real time;

[0034] The iPaaS module dynamically adjusts the data transmission compression ratio and encryption strength of the optimal data transfer path according to the efficiency and quality of the optimal data transfer path, so as to balance the data security and transmission efficiency of the optimal data transfer path.

[0035] In another possible implementation of the first aspect, the efficiency of the optimal data transfer path is characterized by network latency and bandwidth occupancy rate, and the quality of the optimal data transfer path is characterized by packet loss rate. The iPaaS module dynamically adjusts the data transmission compression ratio and encryption strength of the optimal data transfer path according to the efficiency and quality of the optimal data transfer path, so as to balance the data security and transmission efficiency of the optimal data transfer path, including:

[0036] The iPaaS module calculates the combination of the best data transmission compression ratio and the best encryption strength based on the network latency, bandwidth occupancy rate and packet loss rate through a pre-built adaptive adjustment model, so as to balance the data security and transmission efficiency of the optimal data transfer path.

[0037] In another possible implementation of the first aspect, the method further includes:

[0038] The data security monitoring module uploads the risk data and the encrypted critical data to the blockchain network, and the blockchain network is used to verify the integrity and compliance of the risk data and the critical data based on the smart contract.

[0039] In a second aspect, the present application provides an electronic device, including:

[0040] A memory configured to store instructions; and

[0041] A processor, configured to call the instructions from the memory and capable of implementing the data flow method of the integrated platform as described above when executing the instructions.

[0042] In a third aspect, the present application provides a finance and tax integrated platform, which is deployed in the above-mentioned electronic device and is used to execute the operation steps of the data flow method of the integrated platform.

[0043] Through the above technical solutions, it is possible to respond to multi-source data entry instructions, uniformly convert heterogeneous data from multiple channels such as ERP systems, CRM systems, electronic invoice platforms, bank statements, and supplier systems, including structured data, semi-structured, and unstructured data, into structured data, and identify the financial information therein, solving the problem of difficult integration of multi-source heterogeneous data in traditional financial processing; the CL module analyzes the financial information according to the determined processing sequence, identifies risk data and key data, and dynamically generates targeted first and second processing strategies according to the data characteristics, enhancing the intelligent processing ability of complex financial data; the iPaaS module, as an integration platform, receives risk data and key data and securely transfers them to the data security monitoring module, effectively solving the limitations of data transfer between traditional systems relying on manual intervention or simple interface calls and eliminating the information island problem; the data security monitoring module respectively uses the first processing strategy to conduct risk investigation on risk data and the second processing strategy to encrypt key data, providing security protection for sensitive information in financial data; the data security monitoring module transfers the risk data after risk investigation and the encrypted key data to the corresponding business processing platforms, realizing cross-system secure data transfer. Through the collaborative workflow, not only the limitations of a single RPA technology in processing complex financial data are overcome, but also an end-to-end data security transfer mechanism is constructed through the introduction of the iPaaS module and the data security monitoring module, enabling enterprises to achieve seamless data exchange and collaborative work between multiple business processing systems on the premise of ensuring data security, significantly improving the financial processing efficiency, reducing the risk of human errors, enhancing data security. Compared with traditional solutions relying on manual operations or single RPA technology, the present technical solution realizes the full-process automation and intelligence of financial data from entry, analysis, transfer to secure processing through the collaborative work of multiple modules.

[0044] Other features and advantages of the embodiments of the present application will be described in detail in the subsequent specific implementation part. Description of the Drawings

[0045] Figure 1 It is a schematic flowchart of a data flow method of an integrated platform provided by an embodiment of the present application;

[0046] Figure 2Schematic diagram of a financial and tax integration platform provided by an embodiment of the present application;

[0047] Figure 3 Schematic diagram of data processing of an RPA module provided by an embodiment of the present application;

[0048] Figure 4 Schematic diagram of risk analysis of a CL module provided by an embodiment of the present application;

[0049] Figure 5 Schematic diagram of module interaction timing provided by an embodiment of the present application;

[0050] Figure 6 Schematic diagram of a risk assessment model provided by an embodiment of the present application;

[0051] Figure 7 Flowchart of dynamic key management provided by an embodiment of the present application. Detailed implementation manners

[0052] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. It should be understood that the specific implementation manners described herein are only for explaining and interpreting the embodiments of the present application, and are not used to limit the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0053] It should be noted that if there are directional indications (such as up, down, left, right, front, back,...) involved in the embodiments of the present application, the directional indications are only used to explain the relative positional relationship and movement conditions between components in a specific posture (as shown in the drawings). If the specific posture changes, the directional indications will also change accordingly.

[0054] In addition, if descriptions such as "first" and "second" are involved in the embodiments of the present application, the descriptions of "first", "second", etc. are only for descriptive purposes and cannot be understood as indicating or implying their relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In addition, the technical solutions between various embodiments can be combined with each other, but it must be based on the fact that those of ordinary skill in the art can implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present application.

[0055] Figure 1The flowchart schematically shows a data flow method of an integrated platform according to an embodiment of the present application. As Figure 1 shown, an embodiment of the present application provides a data flow method of an integrated platform, which is applied to a financial and tax integrated platform. The financial and tax integrated platform is integrated from n business processing platforms. The financial and tax integrated platform includes an RPA module, a CL module, an iPaaS module, and a data security monitoring module. The method may include the following steps.

[0056] S110. The RPA module responds to a multi-source data entry instruction, converts all multi-source data into structured data, and identifies financial information in the structured data;

[0057] S120. The RPA module classifies and sorts the financial information, and determines the processing order of the classified and sorted financial information;

[0058] S130. The CL module analyzes the financial information according to the processing order, determines the risk data and key data of the financial information, and generates a first processing strategy and a second processing strategy;

[0059] S140. The iPaaS module receives the risk data and key data, and transfers the risk data and key data to the data security monitoring module;

[0060] S150. The data security monitoring module performs risk investigation on the risk data by using the first processing strategy, and encrypts the key data by using the second processing strategy; and

[0061] S160. The data security monitoring module transfers the risk data and the encrypted key data to the corresponding business processing platforms.

[0062] Figure 2 shows a schematic structural diagram of a financial and tax integrated platform provided by an embodiment of the present application. As Figure 2 shown, in the data flow process of the financial and tax integrated platform, first, the RPA (Robotic Process Automation) module responds to a multi-source data entry instruction to realize the standardized conversion of data and the identification of financial information. Multi-source data refers to various financial-related data from different business systems and channels, including but not limited to Excel reports exported from ERP systems, customer transaction records in CRM systems, electronic invoices in PDF format, scanned images of paper documents, bank statements, settlement documents in supplier systems, and financial attachments in emails, etc. Multi-source data includes structured database records, semi-structured Excel tables, as well as unstructured PDF documents and image files.

[0063] The data entry instruction can be a scheduled task, manually triggered by a user, or an API call from another system. After receiving the instruction, the RPA module will call the corresponding data collection components according to the data source type, such as database connectors, file readers, OCR (Optical Character Recognition) engines, etc. For structured data such as database records or standard format Excel spreadsheets, the RPA module directly extracts the data through field mapping; for semi-structured data such as non-standard Excel spreadsheets or XML files, the valid information is extracted through template matching and rule parsing; for unstructured data such as PDF documents or scanned images, the OCR technology is used to digitize the text content, and then the key information is extracted through natural language processing technology.

[0064] To facilitate understanding of the chronological order and collaboration relationship of the RPA module, CL module, iPaaS module, and data security monitoring module in the data flow, please refer to Figure 5 , such as Figure 5 shown, during the data conversion process, the RPA module first unifies the format of the original data, such as standardizing the date format, numerical format, and text format. The text format standardization can be removing extra spaces, special characters, etc. Then, data quality checks can be further performed, including null value detection, outlier identification, logical consistency verification, etc., to mark or automatically correct the problematic data. Finally, the cleaned data is converted into a unified structured format such as JSON or XML to ensure the consistency and integrity of the data structure.

[0065] After completing the data structuring conversion, the RPA module further identifies the financial information in the structured data. The financial information identification adopts a method combining a rule engine and machine learning. The rule engine performs preliminary identification based on predefined financial field features (such as keywords like "amount", "tax rate", "invoice number", etc.) and format features (such as the numerical format of the amount, the character pattern of the invoice number). The machine learning model can identify more complex financial information patterns through learning historical data, such as the structural features of different types of invoices, the organizational logic of various financial statements, etc. In addition, in this embodiment, for specific industries and business scenarios, the RPA module also integrates a professional vocabulary library and a business rule library to further improve the accuracy and integrity of financial information identification.

[0066] After completing the structured transformation of multi-source data and the identification of financial information, the RPA module classifies and sorts the financial information. In the classification and sorting process, first, according to the preset financial information classification system, the identified financial information is divided into different categories. The financial information classification system usually includes but is not limited to the following dimensions: classification by business type (such as sales business, procurement business, expense reimbursement, asset management, etc.); classification by document type (such as invoices, contracts, bank statements, reports, etc.); classification by amount level (such as significant amount, general amount, small amount, etc.); classification by timeliness (such as urgent processing, regular processing, periodic processing, etc.); preliminary classification by risk level (such as high risk, medium risk, low risk).

[0067] The classification process can adopt a multi-level classification algorithm. Specifically, first, preliminary classification is carried out through keyword matching and pattern recognition, and then refined classification is carried out in combination with context information and business rules. For example, for a financial record, first identify whether it contains keywords such as "invoice" and "receipt" to determine the document type, then determine the amount level according to the amount value, at the same time analyze the date information in the record to judge the timeliness, and finally comprehensively consider information such as the counterparty and business description to preliminarily evaluate the risk level.

[0068] After completing the basic classification, the RPA module further analyzes the correlation between financial information and identifies related financial data sets. The correlation analysis can be based on the following factors: business correlation (such as different links of the same business); time correlation (such as related transactions within the same time period); counterparty correlation (such as multiple transactions with the same customer or supplier); amount correlation (such as records with the same amount or a clear calculation relationship); document correlation (such as the correlation between invoices and corresponding contracts and orders). The correlation degree calculation uses a weighted scoring model, assigns different weights to different correlation factors, and calculates the correlation strength between financial information. When the correlation strength exceeds the preset threshold, these financial information are combined into a processing unit to ensure that related financial data can be processed together and avoid business logic errors caused by fragmented processing.

[0069] After determining the classification and correlation of financial information, the RPA module calculates the processing priority of each group of financial information according to the preset scoring rules, so as to determine the final processing order. The scoring rules can consider one or more of the following factors: timeliness factors (such as deadline, legal reporting deadline, etc.); importance factors (such as amount size, business importance, etc.); risk factors (such as preliminary risk rating, abnormal indicators, etc.); resource consumption factors (such as processing complexity, required approval levels, etc.); dependency factors (such as whether there are preprocessing requirements).

[0070] In this embodiment, the determination of the processing order can also follow the principles of system load balancing and maximizing processing efficiency. The RPA module can dynamically monitor the system resource occupancy. While ensuring the timely processing of high-priority tasks, it reasonably arranges the execution time of medium- and low-priority tasks to avoid uneven peaks and valleys in system resources. In addition, for financial information with similar processing flows, the RPA module is arranged to process continuously, reducing the additional overhead caused by switching processing modes and improving the overall processing efficiency.

[0071] After the RPA module completes the classification and sorting of financial information and determines the processing order, the CL (Cognitive Learning) module takes over the subsequent financial information analysis work. The CL module is the core intelligent analysis component of the fiscal and tax integration platform, responsible for deeply analyzing financial information, identifying risk data and key data therein, and generating corresponding processing strategies accordingly. The CL module strictly analyzes financial information one by one according to the processing order determined by the RPA module to ensure that high-priority financial data is processed in a timely manner.

[0072] The financial information analysis adopts a multi-level verification architecture and conducts comprehensive verification at the basic data layer, business logic layer, and risk control layer respectively. The verification at the basic data layer mainly checks the integrity, consistency, and accuracy of the data, such as whether the required fields are complete, whether the values are within a reasonable range, and whether the date format is correct. The verification at the business logic layer focuses on whether the financial data conforms to business rules and process requirements, such as whether the purchase order matches the invoice amount, whether the expense reimbursement conforms to the budget limit, and whether the payment and receipt information is consistent with the contract terms. The verification at the risk control layer evaluates from the perspectives of compliance and risk prevention and control, such as whether the transaction complies with tax laws, whether there are abnormal transaction patterns, and whether it involves sensitive counter-parties.

[0073] On the basis of multi-level verification, the risk data identification adopts a method combining a rule engine and a machine learning model. The rule engine conducts a preliminary screening based on preset risk identification rules, such as abnormal amount (beyond the historical transaction range), abnormal time (transaction during non-working hours), abnormal frequency (frequent transactions in a short period), and abnormal counter-party (new or sensitive counter-party). The machine learning model establishes a benchmark model of normal transaction patterns through learning historical transaction data, and any transaction deviating from this benchmark is marked as a potential risk. In addition, the CL module can also integrate external data sources, such as enterprise credit databases, tax exception lists, and industry risk warning information, to further improve the accuracy and comprehensiveness of risk identification.

[0074] Meanwhile, the CL module can also identify key data in financial information, namely data that has an important impact on the enterprise's financial situation, tax compliance, and business operations. The identification of key data is based on a data sensitivity assessment model, which comprehensively considers factors such as the business importance of the data (such as core financial indicators, key performance indicators, etc.), compliance importance (such as data required for tax declarations, data of concern in audits, etc.), security sensitivity (such as bank accounts, tax numbers, customer information, etc.), and data integrity requirements (such as data that needs to maintain a complete audit trail). Through the sensitivity scoring mechanism, the system marks data with scores exceeding the preset threshold as key data, which requires special protection and processing.

[0075] Based on the identification results of risk data and key data, the CL module further generates corresponding processing strategies. The first processing strategy targets risk data and mainly includes a risk data grading mechanism, a risk assessment model, abnormal situation identification rules, and a risk traceability mechanism. The risk data grading divides risk data into three levels: high, medium, and low, and different levels adopt different processing procedures and approval authorities. The risk assessment model calculates the risk score based on the weights of risk factors and gives risk treatment suggestions. The abnormal situation identification rules define the judgment criteria and processing procedures for various abnormal situations. The risk traceability mechanism ensures that each risk treatment decision has a complete record and a responsibility traceability chain.

[0076] The second processing strategy targets key data and mainly includes a hierarchical encryption mechanism, dynamic key management, access control, and data masking rules. The hierarchical encryption mechanism uses encryption algorithms of different strengths according to the data sensitivity to ensure that the encryption strength matches the data importance. The dynamic key management defines the full life cycle management rules for key generation, distribution, update, and destruction. The access control is based on the "least privilege principle" and strictly restricts the access scope of key data. The data masking rules define how to appropriately mask sensitive information in different usage scenarios, protecting data security while not affecting business processing.

[0077] When generating processing strategies, the CL module extracts the context features of financial information and historical processing data, and dynamically optimizes the strategy parameters through machine learning models. For example, by analyzing historical risk treatment records, the risk grading threshold is adjusted; by analyzing data access patterns, the encryption strength and key update cycle are optimized; by monitoring the data flow efficiency, the relationship between security control and processing efficiency is balanced, so as to ensure the adaptability and effectiveness of the processing strategy, which can be automatically adjusted as the business environment and risk situation change.

[0078] After the CL module completes the financial information analysis and determines the risk data and key data, the iPaaS (Integration Platform as a Service) module, as the data integration and transfer hub of the financial and tax integration platform, first receives the risk data and key data from the CL module through standardized API interfaces. The receiving process uses a secure transmission protocol (such as HTTPS) to ensure the security of the data transmission process. The data reception adopts an asynchronous message queue mechanism to avoid data loss or processing delay caused by large data volume or network fluctuations. The received data contains complete metadata tags, including data source, generation time, risk level, sensitivity level, processing strategy identifier, etc.

[0079] After the iPaaS module receives the data, it first performs data integrity verification, using technical means such as checksums and digital signatures to ensure that the received data has not been tampered with. At the same time, it performs data format verification to ensure that the data structure conforms to the predefined data exchange standard, such as the format specifications defined by JSON Schema or XML DTD. For data that fails the verification, the iPaaS module will generate an exception report and trigger a retransmission mechanism to ensure the integrity and accuracy of the data. The data that passes the verification will be temporarily stored in the secure data buffer of the iPaaS module, which uses in-memory encryption technology to ensure that the data is also encrypted in memory and prevent memory theft attacks.

[0080] Before data transfer, the iPaaS module preprocesses the data, including data format conversion, data compression, and preliminary data masking. Data format conversion is used to ensure that the data meets the input requirements of the data security monitoring module, such as converting JSON format to XML format, etc. Data compression uses lossless compression algorithms to reduce the data transmission volume and improve the transmission efficiency. Preliminary data masking is to temporarily replace or mask some sensitive information according to the security level of the data transfer path, reducing the exposure risk of the data during the transfer process.

[0081] In this embodiment, the iPaaS module uses an intelligent routing mechanism to determine the data transfer path. The intelligent routing makes decisions based on multiple factors: data type (risk data or key data), data priority, the load status of the data security monitoring module, network status, etc. The routing algorithm dynamically evaluates multiple possible transmission paths and selects the optimal path for data transmission. For high-priority data, the system reserves a dedicated channel to ensure the transmission speed; for large-volume data, a sharding transmission strategy is adopted, dividing the data into multiple small pieces and transmitting them in parallel to improve the transmission efficiency.

[0082] During the data flow process, the iPaaS module implements full - process monitoring and logging through its built - in monitoring system and logging system. Specifically, the monitoring system tracks the transmission status of each data packet in real - time, including indicators such as sending time, receipt confirmation, and transmission rate. The logging system records the complete data flow trajectory, including information such as data identifiers, transmission timestamps, transmission paths, and processing nodes.

[0083] The communication between the iPaaS module and the data security monitoring module uses the two - way authentication TLS protocol to ensure the authenticity of the identities of both communication parties. Data transmission uses end - to - end encryption. Even if the data is intercepted during transmission, the original data cannot be obtained without the correct decryption key. In addition, the communication protocol also includes a replay attack prevention mechanism. Each data packet contains a unique timestamp and random number to prevent attackers from deceiving by replaying historical data packets. The communication channel also supports an automatic recovery mechanism, which can automatically reconnect and continue the unfinished data transmission task after a network interruption, ensuring the continuity and reliability of data flow.

[0084] Through the efficient data flow of the iPaaS module, risk data and key data can be safely and quickly transferred from the CL module to the data security monitoring module, laying a foundation for subsequent risk investigation and data encryption processing. The introduction of the iPaaS module significantly improves the data integration efficiency between components of the financial and tax integration platform, reduces the system integration complexity, and at the same time provides flexibility and compatibility for future platform expansion and upgrade through standardized data exchange interfaces.

[0085] After receiving the risk data and key data transmitted by the iPaaS module, the data security monitoring module executes the first processing strategy and the second processing strategy generated by the CL module to ensure the security and compliance of data during the flow process. The data security monitoring module first performs a shunt processing on the received data, importing risk data and key data into different processing pipelines respectively to achieve parallel processing to improve efficiency. The shunt process is based on the metadata tags in the data packet to accurately identify the data type and apply the corresponding processing strategy.

[0086] For risk data, the data security monitoring module strictly conducts risk investigation according to the first processing strategy. Specifically, first, basic security checks are carried out, including malicious code scanning, sensitive information leakage detection, and format verification. Malicious code scanning uses the latest virus signature library and heuristic analysis algorithms to detect whether the data contains potential malicious code or scripts. Sensitive information leakage detection identifies possible unauthorized sensitive information in the data, such as personal identity information and bank account numbers, through regular expression matching and semantic analysis. Format verification ensures that the data conforms to the predefined security format specifications to prevent security vulnerabilities caused by format anomalies.

[0087] After the basic inspection, in-depth risk analysis is started. Specifically, a method combining rules and machine learning is adopted to comprehensively evaluate the risk data. Rule-based analysis can apply preset risk identification rules, such as rules for abnormal transaction amounts, abnormal transaction frequencies, abnormal trading counterparts, etc., to identify obvious risk patterns. Machine learning analysis, on the other hand, identifies hidden risk patterns through a trained anomaly detection model. The anomaly detection model is trained based on historical transaction data and can identify abnormal behaviors that deviate from the normal business model. In-depth risk analysis also combines external threat intelligence, such as a database of known fraud patterns, a list of abnormal high-risk trading counterparts, etc., to further improve the accuracy of risk identification.

[0088] The results of the risk investigation are divided into three levels: high, medium, and low according to the risk level, and a detailed risk report is generated. High-risk data will trigger real-time alarms and notify relevant responsible persons through preset notification channels (such as internal system messages, emails, text messages, etc.). Medium-risk data will be marked and recorded in the risk log for manual review. Low-risk data is allowed to continue to flow, but a risk mark will be attached for reference in subsequent processes. The risk report contains detailed information such as risk type, risk level, risk description, triggering rules, and recommended handling methods, providing a basis for subsequent decision-making.

[0089] At the same time, for critical data, the data security monitoring module strictly implements the second processing strategy for encryption protection. The encryption process first selects appropriate encryption algorithms and key strengths according to the data sensitivity level. High-sensitivity data uses high-strength encryption algorithms (such as AES-256, RSA-2048, etc.), medium-sensitivity data uses standard-strength encryption algorithms (such as AES-128, etc.), and low-sensitivity data may only be subject to lightweight encryption or hashing. Encryption key management uses a distributed key management system to support the full life cycle management of key generation, distribution, rotation, and revocation. Key storage is protected by a hardware security module (HSM) to ensure the security of the keys themselves. Specifically, the dynamic key management mechanism is as Figure 7 shown, which shows the full life cycle management process of key generation, distribution, update, and destruction. First, key generation is the responsibility of the key management system, using high-strength encryption algorithms to ensure the randomness and security of the keys; then, key distribution is completed by the key distribution module through a secure channel (such as TLS) to ensure the security of the key transmission process; then, key update is regularly executed by the key management module according to the security policy to address potential security threats. During the use of the key, if the key becomes invalid, the key destruction module uses secure erasure technology to completely destroy the key to ensure that it cannot be recovered; if it is not invalid, the key continues to be used.

[0090] The encryption process supports two modes: field-level encryption and file-level encryption. Field-level encryption selectively encrypts sensitive fields in structured data (such as ID numbers, bank account numbers, etc.), protecting sensitive information while preserving the data structure. File-level encryption encrypts the entire document or data packet and is suitable for highly sensitive complete documents. Encryption also supports format-preserving encryption technology, which preserves the format characteristics of the original data (such as length, character type, etc.) while encrypting the data, facilitating data processing and verification without decryption.

[0091] After encryption is completed, encrypted metadata is generated, recording information such as the encryption algorithm, key identifier, encryption timestamp, etc., and these metadata are encapsulated together with the encrypted data. The encapsulation process uses digital signature technology to ensure the integrity and non-repudiation of the encrypted data. The digital signature is generated using an asymmetric encryption algorithm, which can verify whether the data has been tampered with during transmission and storage, and can also confirm the authenticity of the data source.

[0092] The data security monitoring module also implements a full-process audit record, recording detailed information about all risk investigations and encryption operations, including the operation time, operation type, operation result, operator (or system component), etc. The audit log uses an immutable storage mechanism, such as blockchain technology or write-once-read-many (WORM) storage, to ensure the authenticity and integrity of the audit record.

[0093] After completing the risk investigation and data encryption, the data security monitoring module accurately transfers the processed risk data and encrypted key data to the corresponding business processing platforms. Before data transfer, the data security monitoring module first performs target platform identification and routing decision-making. Target platform identification is based on the business attributes, processing requirements, and security levels of the data to accurately locate the target platform to which the data should flow among the n business processing platforms integrated with the fiscal and tax integration platform. Routing decision-making considers factors such as network conditions, platform load, data priority, etc., and selects the optimal transmission path and transmission timing for each batch of data.

[0094] Data transfer uses an intelligent scheduling mechanism to dynamically adjust the data transmission rate and batch size according to the processing capabilities and current load conditions of the business processing platforms. For platforms with strong processing capabilities and low load, increase the data batch size and transmission frequency; for platforms with limited processing capabilities or high current load, reduce the data batch size and transmission frequency to avoid performance bottlenecks on the target platform due to sudden data increases. At the same time, ensure that high-priority data (such as tax data related to the legal reporting deadline) can be transmitted and processed preferentially, ensuring the timely processing of key businesses even under high system load.

[0095] The data transmission process adopts secure channel technology to ensure the security of data during network transmission. The secure channel is established based on the TLS / SSL protocol and supports two-way authentication to ensure the authenticity of the identities of both communication parties.

[0096] After the data arrives at the target business processing platform, the data security monitoring module will execute the data delivery confirmation process. The delivery confirmation adopts a reliable message passing mechanism, requiring the target platform to return a confirmation message after successfully receiving and verifying the data. The confirmation message includes information such as data identification, reception timestamp, and data integrity verification result. If the confirmation message is not received within the predetermined time, or the confirmation message indicates abnormal data reception, the retransmission mechanism is automatically started to ensure the reliable delivery of the data.

[0097] For the encrypted critical data, the data security monitoring module also needs to coordinate key distribution to ensure that the target platform can correctly decrypt and process the data. The key distribution adopts a secure key exchange protocol, such as the PKI-based key distribution mechanism. The key distribution and data transmission are carried out in different secure channels to avoid security risks caused by single-point failures. The key usage permissions are strictly controlled, and only authorized business processing platforms can obtain the corresponding decryption keys.

[0098] The entire data flow process implements full-process monitoring and audit records. The monitoring system real-time tracks the data flow status, including transmission progress, target platform response, abnormal events, etc. The monitoring data is presented through a visual dashboard to facilitate managers to understand the data flow situation in real time. The audit system records the complete data flow trajectory, including information such as data identification, flow time, source platform, target platform, and transmission status.

[0099] Through the precise data flow of the data security monitoring module, the finance and tax integration platform realizes the safe and efficient distribution of risk data and critical data, ensuring that each business processing platform can obtain the required data in a timely manner and perform corresponding processing, significantly improving the processing efficiency and security of enterprise finance and tax data, and providing solid technical support for enterprise finance and tax management. At the same time, the complete monitoring and audit mechanism also ensures the traceability and compliance of the data flow process, effectively preventing security risks such as data leakage and data abuse, and providing all-round protection for enterprise finance and tax data security.

[0100] In another embodiment, the RPA module includes a data processing rule library. After the data security monitoring module transfers the risk data and encrypted critical data to the corresponding business processing platforms, it further includes:

[0101] S1. The data security monitoring module generates a feedback report and sends it to the CL module. The feedback report includes the risk data processing effect, risk probability distribution, critical data encryption effect, and key usage record;

[0102] S2. Based on the feedback report, the CL module optimizes the first processing strategy and the second processing strategy, and updates the data processing rules of the RPA module;

[0103] Among them, based on the feedback report, the CL module optimizes the first processing strategy and the second processing strategy, and updates the data processing rules of the RPA module, including:

[0104] S21. According to the risk data processing effect in the feedback report, adjust the risk data grading mechanism in the first processing strategy;

[0105] S22. Based on the risk probability distribution in the feedback report, adjust the parameters of the risk assessment model in the first processing strategy;

[0106] S23. According to the critical data encryption effect in the feedback report, adjust the encryption algorithm selection strategy for critical data in the second processing strategy;

[0107] S24. Based on the key usage records in the feedback report, update the dynamic key management mechanism in the second processing strategy.

[0108] After the risk data and the encrypted critical data are transferred to the corresponding business processing platforms, the data security monitoring module generates a feedback report to evaluate the data processing effect and provide a basis for strategy optimization. The content of the feedback report includes the risk data processing effect, the risk probability distribution, the critical data encryption effect, and the key usage records. The risk data processing effect refers to the results of the risk data being identified, graded, and processed during the transfer process, such as the processing success rate of high-risk data and the processing efficiency of medium-risk data. The risk probability distribution refers to the distribution of data with different risk levels during the processing process, such as the proportion of high-risk data and the proportion of low-risk data. The critical data encryption effect refers to the security and integrity of the encrypted critical data during the transfer process, such as the decryption success rate of encrypted data and the strength of the encryption algorithm. The key usage records refer to the usage of keys during the encryption and decryption processes, such as the generation time of keys, the usage frequency, and the update period. The process of generating the feedback report first extracts relevant indicators by collecting and analyzing the transferred data. Statistical analysis tools can be used to calculate the risk data processing effect, data visualization tools can be used to display the risk probability distribution, encryption performance testing tools can be used to evaluate the critical data encryption effect, and log analysis tools can be used to extract the key usage records.

[0109] After receiving the feedback report, the CL module optimizes the first processing strategy and the second processing strategy based on the report content and updates the data processing rules of the RPA module. The first processing strategy mainly targets risk data, including a risk data grading mechanism, a risk assessment model, an abnormal data identification rule, and a risk data traceability mechanism. The second processing strategy mainly targets critical data, including a hierarchical encryption strategy, a dynamic key management mechanism, an access permission control strategy, and a data desensitization processing rule. The process of optimizing the strategy first determines the parameters and conditions that need to be adjusted by analyzing the feedback report. For example, according to the processing effect of risk data, the threshold parameter of the risk data grading mechanism is adjusted; according to the risk probability distribution, the evaluation factors of the risk assessment model are adjusted; according to the encryption effect of critical data, the selection strategy of the encryption algorithm is adjusted; according to the key usage record, the key update period of the dynamic key management mechanism is updated. The process of updating the data processing rules of the RPA module ensures that the RPA module can apply the latest strategy when processing data by writing the optimized strategy parameters and conditions into the rule library. By optimizing the strategy and updating the rules, the efficiency and security of data processing can be improved, and the stability and reliability of data flow can be ensured.

[0110] In the process of optimizing the first processing strategy, the risk data grading mechanism classifies the data into high-risk, medium-risk, and low-risk according to the risk level of the data. The process of adjusting the grading mechanism first determines the threshold parameters that need to be adjusted by analyzing the processing effect of the risk data in the feedback report. If the processing success rate of high-risk data is low, the threshold of high-risk data needs to be reduced to mark more data as high-risk; if the processing efficiency of low-risk data is high, the threshold of low-risk data needs to be increased to mark more data as low-risk. The process of adjusting the threshold parameters can be achieved through statistical analysis, such as using regression analysis to determine the optimal threshold. By adjusting the risk data grading mechanism, the accuracy and efficiency of risk data processing can be improved, ensuring that high-risk data is processed in a timely manner and low-risk data is processed efficiently.

[0111] In the process of optimizing the first processing strategy, the risk assessment model predicts the risk probability based on the characteristics of the data. The process of adjusting the model parameters first determines the evaluation factors that need to be adjusted by analyzing the risk probability distribution in the feedback report. For example, if the proportion of high-risk data is high, the weights of features such as amount and transaction frequency need to be increased; if the proportion of low-risk data is high, the weights of these features need to be reduced. The process of adjusting the evaluation factors is achieved through machine learning methods, such as using the gradient descent method to optimize the model parameters. By adjusting the parameters of the risk assessment model, the accuracy of risk prediction can be improved, ensuring that risk data is processed reasonably.

[0112] During the process of optimizing the second processing strategy, the encryption algorithm selection strategy selects different encryption algorithms according to the sensitivity of critical data. The process of adjusting the selection strategy first determines the encryption strength that needs to be adjusted by analyzing the encryption effect of critical data in the feedback report. If the decryption success rate of the encrypted data is low, it is necessary to reduce the encryption strength and select a more efficient encryption algorithm to reduce the complexity or failure rate during the decryption process; if the security of the encrypted data is insufficient (for example, the decryption success rate is too high or there are security vulnerabilities), it may be necessary to increase the encryption strength and select a more secure encryption algorithm to enhance the data protection ability.

[0113] During the process of optimizing the second processing strategy, the dynamic key management mechanism regularly updates and dispersedly stores keys according to the usage of keys. The process of updating the management mechanism first determines the key update period that needs to be adjusted by analyzing the key usage records in the feedback report. For example, if the usage frequency of the key is high, it may be necessary to shorten the update period to improve the security of the key; if the usage frequency of the key is low, it may be necessary to extend the update period to improve the key management efficiency. By updating the dynamic key management mechanism, the security and management efficiency of the key can be improved, ensuring the effective protection of encrypted data.

[0114] In this embodiment, by responding to the multi-source data entry instruction, heterogeneous data from multiple channels such as the ERP system, CRM system, electronic invoice platform, bank statement, and supplier system, including structured data, semi-structured and unstructured data, are uniformly converted into structured data, and the financial information therein is identified, solving the problem of difficult integration of multi-source heterogeneous data in traditional financial processing; the CL module analyzes the financial information according to the determined processing sequence, identifies risk data and key data, and dynamically generates targeted first and second processing strategies according to the data characteristics, enhancing the intelligent processing ability of complex financial data; the iPaaS module, as an integration platform, receives risk data and key data and securely transfers them to the data security monitoring module, effectively solving the limitations of traditional data transfer between systems relying on manual intervention or simple interface calls and eliminating the information island problem; the data security monitoring module respectively uses the first processing strategy to conduct risk investigation on risk data and the second processing strategy to encrypt key data, providing security protection for sensitive information in financial data; the data security monitoring module transfers the risk data after risk investigation and the encrypted key data to the corresponding business processing platform, realizing cross-system secure data transfer. Through the collaborative workflow, not only the limitations of single RPA technology in processing complex financial data are overcome, but also an end-to-end data security transfer mechanism is constructed by introducing the iPaaS module and the data security monitoring module, enabling enterprises to achieve seamless data exchange and collaborative work between multiple business processing systems on the premise of ensuring data security, significantly improving financial processing efficiency, reducing the risk of human errors, enhancing data security. Compared with traditional solutions relying on manual operations or single RPA technology, this technical solution realizes the full-process automation and intelligence of financial data from entry, analysis, transfer to secure processing through the collaborative work of multiple modules.

[0115] In one implementation manner of this embodiment, the CL module generates the first and second processing strategies, including the following steps:

[0116] S210. The CL module extracts the context features of the financial information and obtains historical data;

[0117] S220. The CL module dynamically generates the first and second processing strategies based on the context features and historical data;

[0118] The first processing strategy includes a risk data classification mechanism, a risk assessment model, an abnormal data identification rule and a risk data tracing mechanism. The risk data classification mechanism is used to determine the risk level of risk data. The risk assessment model is used to determine the risk probability of risk data according to the risk level of risk data. The abnormal data identification rule is used to determine the abnormal data in risk data according to the risk probability. The risk data tracing mechanism is used to record the processing flow of risk data.

[0119] The second processing strategy includes a hierarchical encryption strategy, a dynamic key management mechanism, an access permission control strategy and data desensitization processing rules. The hierarchical encryption strategy is used to determine the sensitivity of key data and determine the corresponding encryption algorithm based on the sensitivity. The dynamic key management mechanism is used to update the encryption key and store the encryption key in a dispersed manner. The access permission control strategy is used to set data access permissions. The data desensitization processing rules are used to mask or replace sensitive fields in key data.

[0120] In the data flow process of the integrated finance and taxation platform, the CL module first needs to extract the contextual features of financial information and obtain relevant historical data, which is the basis for generating effective processing strategies. Contextual feature extraction adopts a multi-dimensional analysis method to extract features from multiple dimensions such as the content, source, time, and association of financial information. Feature extraction in the content dimension focuses on the attribute characteristics of the financial data itself, including but not limited to core financial elements such as transaction amount, transaction type, transaction frequency, counterparty, and accounting subjects. Natural language processing technology is used to perform semantic analysis on unstructured financial descriptions, extract keywords, entities, and semantic relationships, and convert them into quantifiable feature vectors. For structured data, numerical features, category features, and time series features are directly extracted to construct a multi-dimensional feature space.

[0121] Feature extraction from the source dimension focuses on the generation channels and transmission paths of financial information, including data source systems, input methods, transmission protocols, etc. A credibility scoring mechanism can be established for data from different sources, and different credibility weights can be assigned to each data source based on factors such as historical data quality, system security level, and data consistency. For example, data from the core financial system of an enterprise that has undergone multiple audits usually has a higher credibility score than data imported from outside or entered manually.

[0122] The feature extraction of the time dimension focuses on the time attributes of financial information, including the time when the data is generated, the accounting period, the reporting period, etc. It can analyze the time series characteristics of the data and identify seasonal patterns, cyclical changes, and abnormal time points. Through time dimension analysis, abnormal transactions that do not conform to the normal business cycle can be found, such as large capital flows during non-working hours and abnormal accounting adjustments near the reporting date.

[0123] The feature extraction of the association relationship dimension focuses on the internal connections between financial information and constructs a data association network. Graph analysis techniques can be used to construct a financial relationship map with financial entities (such as accounts, transactions, customers, suppliers, etc.) as nodes and the relationships between them (such as fund flows, ownership, business dealings, etc.) as edges. Through map analysis, hidden association relationships can be discovered, such as potential risk points like circular transactions and related-party transactions. Association analysis also includes cross-system data consistency checks to verify whether the records of the same financial matters in different business systems are consistent.

[0124] After the context feature extraction is completed, the CL module further obtains historical data related to the current financial information. The historical data acquisition adopts an intelligent retrieval mechanism. Based on the feature vector of the current financial information, similar cases are retrieved from the historical database. The retrieval uses vector similarity calculation methods, such as cosine similarity and Euclidean distance, to find the historical records closest in the feature space.

[0125] After the context feature extraction and historical data acquisition of the financial information are completed, the CL module dynamically generates the first processing strategy and the second processing strategy. The generation of the first processing strategy focuses on the control of risk data, including a risk data grading mechanism, a risk assessment model, an abnormal data identification rule, and a risk data traceability mechanism. The risk data grading mechanism divides risk data into multiple levels based on the risk index, such as extremely high risk, high risk, medium risk, and low risk. The grading criteria consider industry characteristics and the enterprise's risk preference and can be adjusted by configuring parameters.

[0126] The risk assessment model adopts a multi-model fusion method, combining a rule engine and machine learning algorithms to calculate the risk probability of risk data. The rule engine contains deterministic rules encoded with expert knowledge, such as clear risk signals like "the amount of a single transaction exceeds the authorized limit" and "large fund outflows at unconventional times". Machine learning algorithms include anomaly detection models (such as isolation forest and autoencoder) and classification models (such as gradient boosting tree and neural network), which can capture complex risk patterns. The model fusion adopts weighted voting or stacking ensemble methods to synthesize the prediction results of multiple models and improve the accuracy and stability of risk assessment. Among them, the flowchart of the risk assessment model can refer to Figure 6 , first, the risk factors extracted from the financial information are used as the input for risk assessment. Weights are assigned to each risk factor, and the weight reflects the degree of influence of the factor on the overall risk. Then, based on the risk factors and their weights, the comprehensive risk score is calculated. According to the risk score, the risk is divided into three levels: high, medium, and low.

[0127] The abnormal data recognition rule determines the abnormal data that needs special attention based on the risk probability threshold and business rules. The recognition rule not only considers the risk probability of a single piece of data, but also considers the correlation and temporal pattern between data, and can discover collaborative anomalies scattered in multiple records. For example, it can identify scattered transactions with a small single amount but abnormal frequency, or discover the fund circulation across multiple accounts.

[0128] The risk data traceability mechanism is designed to record the complete processing history of risk data, ensuring the auditability and compliance of the risk handling process. The traceability mechanism can adopt blockchain or tamper-proof log technology to record each link of data processing, including information such as the risk identification time, assessment results, processing decisions, execution operations, and responsible persons. The trace records use timestamp and digital signature technologies to ensure authenticity, and support multi-dimensional query and visual display, facilitating post-event audit and risk review.

[0129] The second processing strategy includes a hierarchical encryption strategy, a dynamic key management mechanism, an access permission control strategy, and data desensitization processing rules. The hierarchical encryption strategy selects appropriate encryption algorithms and parameters for data with different sensitivity levels based on the sensitivity index. High-sensitivity data may use stronger encryption algorithms and more complex encryption modes, while medium- and low-sensitivity data may use lightweight encryption or hash protection.

[0130] The dynamic key management mechanism is responsible for the full life cycle management of key generation, distribution, update, and destruction. The key update adopts a combination of time-triggered and event-triggered methods, regularly rotating keys and immediately updating them when potential security threats are detected. The key decentralized storage adopts secret sharing technology, splitting the master key into multiple shares and storing them in different security domains respectively. Only when enough shares are collected can the original key be reconstructed, effectively preventing the risk of single-point leakage.

[0131] The access permission control strategy adopts a hybrid access control model based on roles and attributes to finely manage data access permissions. Permission control not only considers user roles, but also considers context factors such as data attributes, access time, and access location to achieve dynamic and context-aware access control. For example, the same user may be granted different levels of data access permissions at different times or in different network environments. The permission policy supports the principle of least privilege and the principle of separation of duties, ensuring that users can only access the minimum data set required to perform their duties, and preventing the abuse of power through the separation of duties.

[0132] Data desensitization rules provide field-level protection measures for data that needs to be transferred over a wide range but contains sensitive fields. According to the field type and sensitivity level, appropriate desensitization techniques are selected, such as masking (e.g., displaying a credit card number as "**** **** **** 1234"), data replacement (replacing real data with fictional but consistent-format data), and ranging (replacing exact values with range values). Desensitization processing preserves the business value and statistical characteristics of the data while effectively protecting personal privacy and business secrets.

[0133] In actual implementation, dynamic policy generation relies on machine learning models and rule engines. For example, using a random forest model or a neural network model, based on context features and historical data, the risk level and sensitivity of the data are predicted. The rule engine then generates specific processing policies according to preset business rules.

[0134] The first processing policy and the second processing policy dynamically generated in this embodiment are respectively targeted at risk data and critical data, realizing risk classification, encryption protection, and permission control of the data. By combining machine learning models and rule engines, dynamic policy generation can adapt to complex and changing financial data environments, improving the efficiency and security of data processing. Ultimately, this technical solution not only solves the problem of difficult integration of multi-source heterogeneous data in traditional financial processing but also significantly improves the automation level and security of financial data processing through an intelligent policy generation mechanism, realizing the full-process intelligent processing of financial data from context feature extraction to dynamic policy generation.

[0135] In one implementation of this embodiment, the CL module dynamically generates the first processing policy and the second processing policy based on context features and historical data, including the following steps:

[0136] S310. The CL module inputs the data features and context features as input parameters into a pre-constructed machine learning model to analyze and obtain the historical processing records of risk data and the historical encryption records of critical data;

[0137] S320. The CL module determines the parameters and conditions of the first processing policy according to the historical processing records and applies the parameters and conditions of the first processing policy to the first processing policy, where the parameters and conditions of the first processing policy include the threshold parameters of the risk data classification mechanism, the evaluation factors of the risk assessment model, the determination conditions of the abnormal data identification rule, and the record items of the risk data traceability mechanism;

[0138] S330. The CL module determines the parameters and conditions of the second processing strategy based on historical encryption records, and applies the parameters and conditions of the second processing strategy to the second processing strategy. Among them, the parameters and conditions of the second processing strategy include the encryption strength of the hierarchical encryption strategy, the key update period of the dynamic key management mechanism, the permission matrix of the access control strategy, and the desensitization method of the data desensitization processing rule.

[0139] Data features refer to the attributes of financial data itself, such as amount, transaction type, timestamp, etc. Context features include environmental information such as data source, operator, and business scenario. These features together serve as input parameters for the machine learning model. Pre-built machine learning models usually adopt supervised learning or unsupervised learning methods, such as random forest, support vector machine, or neural network. The machine learning model learns the correlation between data features and processing results by training historical data. For example, the model can learn that certain specific types of transactions (such as large transfers) are more likely to be marked as high-risk, or that transactions processed by certain operators (such as new employees) are more likely to be abnormal. By inputting the data features and context features of the current data, the machine learning model can predict its risk level and sensitivity, and generate corresponding processing strategies with reference to historical processing records and encryption records.

[0140] In actual implementation, the extraction of data features and context features can be achieved through data preprocessing techniques. For example, for structured data, the field values are directly extracted as data features; for unstructured data, natural language processing (NLP) techniques are used to extract key information. Context features are generated by analyzing metadata and business rules. By inputting data features and context features into the model, the historical processing records of risk data and the historical encryption records of key data can be analyzed.

[0141] After obtaining the historical processing records of risk data, determine the parameters and conditions of the first processing strategy. Specifically, such as Figure 4As shown, the first processing strategy includes a risk data grading mechanism, a risk assessment model, an abnormal data identification rule, and a risk data traceability mechanism. The threshold parameters of the risk data grading mechanism are determined according to the risk level distribution in the historical processing records. For example, if the historical data shows that the risk levels of a certain type of transaction are mainly concentrated in "medium risk" and "high risk", the threshold parameters can be set to the critical value that distinguishes these two risk levels. The evaluation factors of the risk assessment model are determined according to the risk probability distribution in the historical data. For example, when using a logistic regression model, the evaluation factors can be the weights of features such as transaction amount and transaction frequency. The judgment conditions of the abnormal data identification rule are determined according to the characteristics of abnormal data in the historical processing records. For example, if the historical data shows that a certain type of transaction is usually abnormal when the risk probability exceeds 0.8, the judgment condition is set to the risk probability being greater than 0.8. The record items of the risk data traceability mechanism are determined according to the audit requirements in the historical processing records. For example, the record items can include data source, processing personnel, processing time, etc.

[0142] In actual implementation, the determination of parameters and conditions is usually achieved through statistical analysis or machine learning methods. For example, clustering analysis is used to determine the threshold parameters of the risk data grading mechanism, and regression analysis is used to determine the evaluation factors of the risk assessment model. By applying the determined parameters and conditions to the first processing strategy, the dynamic and personalized nature of the strategy can be realized, improving the accuracy and efficiency of risk data processing.

[0143] After obtaining the historical encryption records of the key data, the parameters and conditions of the second processing strategy are determined. Specifically, the second processing strategy includes a hierarchical encryption strategy, a dynamic key management mechanism, an access permission control strategy, and a data desensitization processing rule. The encryption intensity of the hierarchical encryption strategy is determined according to the sensitivity distribution in the historical encryption records. For example, if the historical data shows that the sensitivity levels of a certain type of data are mainly concentrated in "high sensitivity" and "medium sensitivity", the encryption intensity can be set to AES-256 and AES-128. The key update period of the dynamic key management mechanism is determined according to the key usage frequency in the historical encryption records. For example, if the historical data shows that the usage frequency of a certain type of key is high, the update period can be set to a shorter time interval. The permission matrix of the access permission control strategy is determined according to the user roles and permissions distribution in the historical encryption records. For example, the permission matrix can include the access scopes of roles such as financial manager and ordinary employee. The desensitization method of the data desensitization processing rule is determined according to the desensitization requirements in the historical encryption records. For example, the desensitization method can include masking, replacement, etc.

[0144] In specific implementation, clustering analysis can be used to determine the encryption strength of the hierarchical encryption strategy, and regression analysis can be used to determine the key update period of the dynamic key management mechanism. By applying the determined parameters and conditions to the second processing strategy, the dynamic and personalized nature of the strategy can be achieved, improving the accuracy and efficiency of critical data processing.

[0145] In this embodiment, the input of data features and context features provides comprehensive input information for the analysis of the machine learning model, ensuring the pertinence and effectiveness of the strategy. The parameters and conditions determined based on historical processing records and encryption records achieve the dynamic and personalized nature of the first processing strategy and the second processing strategy. By combining statistical analysis or machine learning methods, the determination of parameters and conditions can adapt to the complex and changeable financial data environment, improving the efficiency and security of data processing. Finally, this technical solution not only solves the problem of difficult integration of multi-source heterogeneous data in traditional financial processing, but also significantly improves the automation level and security of financial data processing through an intelligent strategy parameter determination mechanism.

[0146] In one implementation of this embodiment, the RPA module classifies and sorts financial information and determines the processing order of the classified and sorted financial information, including the following steps:

[0147] S410. The RPA module divides the financial information based on preset data categories to obtain at least one financial data set;

[0148] S420. The RPA module determines the correlation degree between each financial data set and other financial data sets, and merges the financial data sets with a correlation degree higher than the preset correlation degree to obtain at least one associated financial data set;

[0149] S430. For any one of the associated financial data sets, the RPA module uses a preset scoring rule to determine its time sensitivity score and data value score, and calculates the total score of each associated financial data set, where the total score is the sum of the time sensitivity score and the data value score, and the order from high to low of the total scores is used as the processing order of the associated financial data sets.

[0150] Figure 3 Shows a schematic diagram of data processing by the RPA module provided in the embodiment of the present application, as Figure 3As shown, during the financial information processing, the RPA module classifies financial information through preset data categories, categorizing multi-source financial data into several financial data sets. The preset data categories usually include invoice data, contract data, accounting data, statement data, etc. These categories are defined according to the actual needs and business processes of enterprise financial management. For example, invoice data includes electronic invoices, scanned copies of paper invoices, etc.; contract data includes supplier contracts, customer contracts, etc.; accounting data includes bank statements, accounts receivable, etc.; statement data includes financial statements, tax statements, etc. The classification process first determines the category to which the financial data belongs by analyzing its metadata and content characteristics. For example, for an electronic invoice, by identifying key fields such as invoice number, amount, date, etc., it is classified as invoice data; for a bank statement, by identifying key fields such as account information, transaction records, etc., it is classified as accounting data. In actual implementation, data classification can be achieved through a rule engine. The rule engine matches data characteristics through preset rules. For example, if the data contains the "invoice number" field, it is classified as invoice data.

[0151] On the basis of financial information classification, determining the degree of association between data sets is a key step in achieving data integration and efficient processing. The degree of association refers to the correlation between different data sets in terms of business logic or data processing flow. For example, invoice data and accounting data usually have a high degree of association because invoice information needs to be reconciled with accounting records; contract data and statement data may also have a high degree of association because contract information needs to be reflected in financial statements. The process of determining the degree of association first calculates their similarity or correlation by analyzing the content characteristics and business rules of the data sets. For example, the cosine similarity or Jaccard similarity is used to calculate the similarity between data sets. For invoice data and accounting data, if both contain the same transaction number or amount information, their degree of association is high. In actual implementation, the calculation of the degree of association can be achieved through statistical analysis or machine learning methods. For example, clustering analysis is used to classify data sets with similar characteristics into the same group, or association rule mining techniques (such as the Apriori algorithm) are used to discover the association relationships between data sets. By merging data sets with a degree of association higher than the preset threshold, several associated financial data sets can be obtained. For example, invoice data and accounting data are merged into one associated data set, and contract data and statement data are merged into another associated data set. Through the construction of associated data sets, data integration and collaborative processing can be achieved, improving the efficiency and accuracy of data processing.

[0152] After obtaining the associated financial data set, the determination of the processing order is based on the time sensitivity score and the data value score. The time sensitivity score refers to the urgency of the data set in terms of processing time. For example, some data needs to be processed within a specific time; otherwise, it will affect the business process. The data value score refers to the importance of the data set in business decision-making or financial analysis. For example, some data has an important impact on the accuracy of financial statements or the compliance of tax declarations. The scoring rules are usually defined according to business requirements and historical data. For example, the time sensitivity score can be determined based on the deadline or processing cycle of the data, and the data value score can be determined based on the amount, business type, or impact scope of the data. For each associated data set, first calculate its time sensitivity score and data value score, and then add the two to obtain the total score. For example, for the associated data set of invoice data and accounting data, if its deadline is approaching and the amount is large, then its time sensitivity score and data value score are both high, and the total score is also high. In actual implementation, the scoring rules can be achieved through weighted summation. By sorting the total scores from high to low, the processing order of the associated data sets is determined. For example, the data set with the highest total score is processed first, and the data set with the lowest total score is processed last. Through scoring and sorting, the priority management of data processing can be realized, ensuring that key data is processed in a timely manner and improving the efficiency and accuracy of financial management.

[0153] This embodiment classifies financial information based on preset data categories, ensuring the structured management and orderly processing of data. By determining the correlation degree between data sets and merging high-correlation data sets, the integration and collaborative processing of data are achieved. By using scoring rules to determine the time sensitivity score and data value score and calculating the total score, the priority management of the data processing order is realized. Finally, this technical solution not only solves the problems of difficult data classification and priority management in traditional financial processing but also significantly improves the efficiency and accuracy of financial data processing through an intelligent scoring and sorting mechanism.

[0154] In one implementation of this embodiment, the CL module includes a basic data layer, a business logic layer, and a risk control layer. The CL module determines the risk data and key data of financial information, including the following steps:

[0155] S510. For each associated financial data set, in the basic data layer, the CL module verifies the format of the associated financial data set and regards the data that fails the format verification in the associated financial data set as risk data;

[0156] S520. In the business logic layer, the CL module verifies the business logic consistency of the associated financial data set and regards the data that fails the business logic consistency verification in the associated financial data set as risk data;

[0157] S530. At the risk control layer, the CL module conducts data sensitivity verification on the associated financial data set, and takes the data in the associated financial data set that fails the data sensitivity verification as key data. (Involving enterprise core financial indicators, key information for tax declaration, and sensitive business data)

[0158] In the process of financial data processing, format verification is the first step to ensure data integrity and accuracy. The basic data layer is responsible for performing format verification on the associated financial data set to identify data that does not meet the preset format requirements. Format verification includes multiple aspects such as data type, field length, numerical range, date format, etc. For example, for invoice data, the verification fields include invoice number (must be a number and have a fixed length), amount (must be a numerical value and greater than zero), date (must conform to the YYYY-MM-DD format), etc. For accounting data, the verification fields include account number (must be an alphanumeric combination and have a fixed length), transaction amount (must be a numerical value and not empty), transaction date (must conform to a specific format), etc. The process of format verification first parses the data fields to extract their types and values, and then compares them with the preset format rules. For example, regular expressions are used to verify the date format, and numerical range checks are used to verify the amount range. For data that fails the format verification, it is marked as risk data, and its error type and location are recorded. For example, if the amount field of a certain transaction is empty or negative, it is marked as risk data. In actual implementation, format verification can be achieved through a rule engine. For example, a rule engine (such as Drools) is used to define verification rules.

[0159] Based on format verification, the business logic layer is responsible for performing business logic consistency verification on the associated financial data set to identify data that does not conform to business rules. Business logic consistency verification includes multiple aspects such as data correlation, business rule compliance, logical consistency, etc. For example, for invoice data, its consistency with accounting data is verified to ensure that the invoice amount is consistent with the amount in the accounting records; for contract data, its consistency with statement data is verified to ensure that the contract amount is consistent with the amount in the financial statements. The process of business logic consistency verification first analyzes the association relationships between data fields to determine its consistency rules. For example, SQL queries are used to verify the consistency between invoice data and accounting data, or a business rule engine is used to verify the consistency between contract data and statement data. For data that fails the business logic consistency verification, it is marked as risk data, and its error type and location are recorded. For example, if the amount of a certain invoice is inconsistent with the amount in the accounting records, it is marked as risk data. In actual implementation, business logic consistency verification can be achieved through database triggers. For example, database triggers are used to automatically verify data consistency.

[0160] Based on the verification of business logic consistency, the risk control layer is responsible for performing data sensitivity verification on associated financial data sets to identify data containing sensitive information. Data sensitivity verification includes multiple aspects such as sensitive field identification, sensitive data detection, and compliance checking. For example, for invoice data, sensitive fields to be identified include bank account numbers, tax numbers, etc.; for accounting data, sensitive fields to be identified include customer information, transaction amounts, etc. The process of data sensitivity verification first analyzes data fields to identify their sensitivity levels. For example, regular expressions are used to identify sensitive fields such as bank account numbers and tax numbers. Data that fails the data sensitivity verification is marked as critical data, and its sensitive type and location are recorded. For example, if a transaction contains bank account information, it is marked as critical data. In actual implementation, Drools can be used to define sensitive field identification rules. Through data sensitivity verification, the security and compliance of data can be ensured.

[0161] In this embodiment, the format verification of the basic data layer ensures the integrity and accuracy of the data, providing a reliable basis for subsequent business logic verification and risk control. The business logic consistency verification of the business logic layer ensures that the data conforms to business processes and rules, providing a reliable basis for subsequent risk control. The data sensitivity verification of the risk control layer ensures the security and compliance of the data, providing a reliable basis for subsequent encryption processing and permission control, effectively solving the problems of difficult data verification and risk control in traditional financial processing. Through an intelligent verification mechanism, the efficiency and security of financial data processing are significantly improved.

[0162] In one implementation of this embodiment, after the iPaaS module receives risk data and critical data, the following steps are included:

[0163] S610. The iPaaS module extracts the first feature of the risk data and the second feature of the critical data, and determines the optimal data transfer path based on the first feature and the second feature;

[0164] S620. The iPaaS module monitors the efficiency and quality of the optimal data transfer path in real time;

[0165] S630. The iPaaS module dynamically adjusts the data transmission compression ratio and encryption strength of the optimal data transfer path according to the efficiency and quality of the optimal data transfer path to balance the data security and transmission efficiency of the optimal data transfer path.

[0166] After receiving risk data and critical data, the iPaaS module first extracts the first feature of the risk data and the second feature of the critical data to determine the optimal data transfer path. The first feature refers to the attributes of the risk data, such as risk level, data volume, processing priority, etc.; the second feature refers to the attributes of the critical data, such as sensitivity level, encryption requirement, access privilege, etc. The process of extracting features is achieved by analyzing the metadata and content information of the data. For example, for risk data, its risk level (such as high risk, medium risk, low risk) and data volume (such as file size, number of records) are extracted; for critical data, its sensitivity level (such as highly sensitive, moderately sensitive) and encryption requirement (such as whether AES-256 encryption is required) are extracted. Based on the above features, the iPaaS module can determine the optimal data transfer path. The selection of the optimal path is usually based on multiple factors, including network bandwidth, transmission latency, data security requirements, etc. For example, for risk data with high risk and large data volume, a path with high bandwidth and low latency is selected; for highly sensitive critical data, a path with high encryption strength and strong security is selected.

[0167] After determining the optimal data transfer path, real-time monitoring of the path's efficiency and quality is a crucial step in ensuring the stability and reliability of data transmission. The efficiency of the path is characterized by network latency and bandwidth occupancy rate, and the quality of the path is characterized by packet loss rate. The process of real-time monitoring first deploys monitoring tools or sensors to collect the network performance data of the path. For example, the Ping command is used to measure network latency, a bandwidth monitoring tool is used to measure bandwidth occupancy rate, and a packet analysis tool is used to measure packet loss rate. The collected data is analyzed in real time to generate a monitoring report. For example, if the network latency of a certain path exceeds the preset threshold, it is marked as an inefficient path; if the packet loss rate exceeds the preset threshold, it is marked as a low-quality path. In actual implementation, real-time monitoring can be achieved through a network monitoring system, such as Nagios.

[0168] Based on real-time monitoring, dynamically adjusting the data transmission compression ratio and encryption strength can optimize the path performance. The data transmission compression ratio refers to the proportion of data compressed during transmission, and the encryption strength refers to the level of data encryption during transmission. The process of dynamic adjustment first determines the adjustment strategy by analyzing the efficiency and quality of the path. For example, if the network latency of the path is high, the compression ratio is reduced to reduce processing time; if the bandwidth occupancy rate of the path is low, the compression ratio is increased to reduce the data volume. For encryption strength, if the security of the path is strong, the encryption strength is reduced to improve transmission efficiency; if the security of the path is weak, the encryption strength is increased to enhance data security. In actual implementation, dynamic adjustment can be achieved through an adaptive algorithm, such as an adjustment algorithm based on feedback control. Through dynamic adjustment, the transmission efficiency of the path can be optimized while ensuring data security, achieving the best performance of data transfer.

[0169] This embodiment extracts features and determines the optimal path, ensuring both efficiency and security during data transmission. It monitors the efficiency and quality of the path in real time, promptly discovers and solves performance problems. Dynamically adjusts the data transmission compression ratio and encryption intensity, optimizes the path performance, and achieves the best balance of data flow. Ultimately, it not only solves the problem that it is difficult to balance efficiency and security in traditional data flow, but also significantly improves the efficiency and security of data flow through an intelligent monitoring and adjustment mechanism, realizing the full-process intelligent management of risk data and critical data from feature extraction to path optimization.

[0170] In one implementation of this embodiment, the efficiency of the optimal data flow path is characterized by network latency and bandwidth occupancy rate, and the quality of the optimal data flow path is characterized by the packet loss rate. The iPaaS module dynamically adjusts the data transmission compression ratio and encryption intensity of the optimal data flow path according to the efficiency and quality of the optimal data flow path to balance the data security and transmission efficiency of the optimal data flow path, including the following steps:

[0171] S710. The iPaaS module calculates the combination of the optimal data transmission compression ratio and the optimal encryption intensity based on network latency, bandwidth occupancy rate, and packet loss rate through a pre-constructed adaptive adjustment model to balance the data security and transmission efficiency of the optimal data flow path.

[0172] During the data flow process, network latency, bandwidth occupancy rate, and packet loss rate are key indicators for measuring the path efficiency and quality. Network latency refers to the time required for data to travel from the sender to the receiver, usually measured in milliseconds (ms); bandwidth occupancy rate refers to the proportion of the current network bandwidth used, usually expressed as a percentage (%); packet loss rate refers to the proportion of lost packets in the total number of packets during transmission, usually expressed as a percentage (%). These indicators jointly determine the performance of the data flow path. To achieve the best balance between data security and transmission efficiency, the iPaaS module dynamically calculates the combination of the optimal data transmission compression ratio and the optimal encryption intensity through a pre-constructed adaptive adjustment model. The adaptive adjustment model is an intelligent algorithm based on machine learning that can automatically adjust parameters according to real-time monitoring data to optimize system performance. The input parameters of the model include network latency, bandwidth occupancy rate, and packet loss rate, and the output parameters are the optimal data transmission compression ratio and the optimal encryption intensity.

[0173] The construction process of the adaptive adjustment model first requires collecting a large amount of historical data, including latency, bandwidth occupancy rate, packet loss rate under different network conditions, as well as the corresponding data transmission compression rate and encryption strength. This data is used to train the model so that it can learn the correlation between input parameters and output parameters. For example, when the network latency is high, the model tends to reduce the compression rate to reduce processing time; when the bandwidth occupancy rate is low, the model tends to increase the compression rate to reduce the amount of data; when the packet loss rate is high, the model tends to increase the encryption strength to enhance data security. The training of the model usually adopts supervised learning methods, such as regression analysis or neural networks. Through training, the model can predict the optimal combination of data transmission compression rate and encryption strength based on real-time monitoring data.

[0174] In practical applications, the adaptive adjustment model dynamically calculates the optimal parameter combination by collecting real-time data on network latency, bandwidth occupancy rate, and packet loss rate. For example, if the current network latency is 100ms, the bandwidth occupancy rate is 70%, and the packet loss rate is 5%, the model finally calculates that the optimal compression rate is 60% and the optimal encryption strength is AES-128. This combination can maximize the transmission efficiency while ensuring data security. The dynamic adjustment process of the model is achieved through a feedback control mechanism, that is, further optimizing the parameters according to the performance after adjustment. For example, if the adjusted network latency is still high, the model may further reduce the compression rate or encryption strength to optimize the transmission efficiency.

[0175] The adaptive adjustment model can automatically adjust parameters according to different network conditions and business requirements to achieve the best performance of the data flow path. For example, during peak periods when network bandwidth is tight, the model may tend to increase the compression rate to reduce the amount of data; during off-peak periods when network bandwidth is sufficient, the model may tend to reduce the compression rate to increase the transmission speed. For the encryption strength, the model can dynamically adjust the encryption level according to the data sensitivity and network security. For example, for highly sensitive data, the model may choose AES-256 encryption; for moderately sensitive data, the model may choose AES-128 encryption. Through the adaptive adjustment model, the iPaaS module can achieve intelligent management of the data flow path in a complex and changing network environment, ensuring the best balance between data security and transmission efficiency.

[0176] The adaptive adjustment model in this embodiment dynamically calculates the optimal combination of data transmission compression rate and encryption strength based on network latency, bandwidth occupancy rate, and packet loss rate, ensuring the best balance between the security and transmission efficiency of the data flow path. The construction and training process of the model are realized through machine learning methods, enabling it to automatically adjust parameters according to real-time monitoring data and optimize system performance. In practical applications, the model can flexibly adjust the compression rate and encryption strength according to different network conditions and business requirements, realizing the intelligent management of the data flow path. It not only solves the problem that it is difficult to balance security and efficiency in traditional data flow, but also significantly improves the efficiency and security of data flow through an intelligent adaptive adjustment mechanism.

[0177] In one implementation manner of this embodiment, the following steps are further included:

[0178] S810. The data security monitoring module uploads the risk data and the encrypted key data to the blockchain network, and the blockchain network is used to verify the integrity and compliance of the risk data and the key data based on the smart contract.

[0179] In the process of data flow and storage, ensuring the integrity and compliance of data is crucial. Blockchain technology, with its characteristics of decentralization, immutability, and transparency and traceability, can securely verify data integrity and compliance. The data security monitoring module uploads the risk data and the encrypted key data to the blockchain network, and uses the smart contract mechanism of the blockchain to verify and record the data. The blockchain network consists of multiple nodes, and each node stores a complete copy of the data. Any modification of the data requires the consensus of the majority of nodes, thus ensuring the immutability of the data. A smart contract is a program code running on the blockchain that can automatically execute predefined rules and logics. Through the smart contract, the blockchain network can automatically verify the integrity and compliance of the uploaded data and record the verification results.

[0180] The process of uploading the risk data and the encrypted key data first packages the data into a blockchain transaction through the data security monitoring module. Each transaction contains metadata such as the hash value, timestamp, and uploader information of the data. The hash value is a fixed-length string calculated through a hash function (such as SHA-256) and can uniquely identify the data content. The timestamp is used to record the time of data upload, and the uploader information is used to identify the data source. The packaged transaction is broadcast through the nodes of the blockchain network and waits for verification and confirmation. The nodes of the blockchain network verify the transaction through a consensus mechanism (such as PoW or PoS) to ensure the authenticity and integrity of the data. After the verification passes, the transaction is packaged into a block and added to the blockchain, becoming an immutable record.

[0181] Smart contracts automatically verify the integrity and compliance of uploaded data through predefined rules and logic. For example, for risk data, the smart contract can verify whether its risk level meets the preset standards and whether the data content is complete; for encrypted critical data, the smart contract can verify whether its encryption method meets the security requirements and whether the data content is compliant. The verification process first parses the transaction data to extract metadata such as its hash value, timestamp, uploader information, etc. Then, the smart contract verifies the data according to the predefined rules. For example, it recalculates the hash value of the data using a hash function and compares it with the hash value in the transaction to ensure that the data content has not been tampered with; checks whether the timestamp is within the valid range to ensure that the data upload time meets the requirements; and verifies whether the uploader information is legal to ensure that the data source is trustworthy. The verification result is recorded in the blockchain by the smart contract, becoming an immutable proof.

[0182] In actual implementation, public blockchains, consortium blockchains, and private blockchains are three common types of blockchains. Public blockchains are open to all users and have the highest degree of decentralization, but lower performance and privacy; consortium blockchains are jointly maintained by multiple organizations, have a relatively high degree of decentralization and good performance, and are suitable for data sharing between enterprises; private blockchains are maintained by a single organization, have the highest performance and privacy, and are suitable for enterprise internal data management. The appropriate type of blockchain can be selected according to specific needs. For example, for cross-enterprise data sharing, a consortium blockchain can be selected; for enterprise internal data management, a private blockchain can be selected.

[0183] In this embodiment, by uploading risk data and encrypted critical data to the blockchain network and using smart contracts for verification, the integrity and compliance of the data can be ensured. The immutability and transparent traceability of the blockchain make any modification to the data be recorded and discovered, thus enhancing the security of the data. The automatic execution and predefined rules of the smart contract make the data verification process efficient and reliable, reducing human intervention and errors. It not only solves the problem that it is difficult to guarantee the integrity and compliance of data in traditional data management, but also significantly improves the security and credibility of the data through the introduction of blockchain and smart contracts.

[0184] This application embodiment also provides an electronic device, including:

[0185] A memory configured to store instructions; and

[0186] A processor configured to call instructions from the memory and be able to implement the data flow method of the above integrated platform when executing the instructions.

[0187] In this embodiment, the electronic device may be a tablet computer, a desktop computer, a laptop computer, a handheld computer, a wearable device, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, or other devices with a processor. Of course, the electronic device may also be a server. The specific form of the electronic device in the embodiments of the present application is not particularly limited.

[0188] The embodiments of the present application also provide a finance and tax integration platform, which is deployed in the above-mentioned electronic device and is used to execute the operation steps of the data flow method of the integration platform.

[0189] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0190] This application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0191] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implement the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0192] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide means for implementing the functions in the process Figure 1One or more processes and / or blocks Figure 1 Steps of the functions specified in one or more blocks

[0193] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0194] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0195] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can store information accessible by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.

[0196] It should also be noted that the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, commodity or device including the element.

[0197] The above are only embodiments of the present application and are not used to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A data flow method for an integrated platform, characterized in that, Applied to the finance and tax integration platform, which is integrated by n business processing platforms. The finance and tax integration platform includes an RPA module, a CL module, an iPaaS module, and a data security monitoring module. The method includes: The RPA module responds to the multi-source data entry instruction, converts the multi-source data into structured data, and identifies the financial information in the structured data; The RPA module classifies and sorts the financial information and determines the processing order of the classified and sorted financial information; The CL module analyzes the financial information according to the processing order, determines the risk data and key data of the financial information, and generates a first processing strategy and a second processing strategy; The iPaaS module receives the risk data and key data and transfers the risk data and key data to the data security monitoring module; The iPaaS module extracts the first feature of the risk data and the second feature of the key data and determines the optimal data transfer path based on the first feature and the second feature; The iPaaS module monitors the efficiency and quality of the optimal data transfer path in real time; The iPaaS module dynamically adjusts the data transmission compression ratio and encryption strength of the optimal data transfer path according to the efficiency and quality of the optimal data transfer path to balance the data security and transmission efficiency of the optimal data transfer path; The data security monitoring module uses the first processing strategy to conduct risk investigation on the risk data and uses the second processing strategy to encrypt the key data; and The data security monitoring module transfers the risk data and the encrypted key data to the corresponding business processing platform.

2. The method according to claim 1, wherein The CL module generates the first processing strategy and the second processing strategy, including: The CL module extracts the context features of the financial information and obtains historical data; The CL module dynamically generates the first processing strategy and the second processing strategy based on the context features and historical data; Among them, the first processing strategy includes a risk data grading mechanism, a risk assessment model, an abnormal data identification rule, and a risk data traceability mechanism. The risk data grading mechanism is used to determine the risk level of the risk data. The risk assessment model is used to determine the risk probability of the risk data according to the risk level of the risk data. The abnormal data identification rule is used to determine the abnormal data in the risk data according to the risk probability. The risk data traceability mechanism is used to record the processing process of the risk data; The second processing strategy includes a grading encryption strategy, a dynamic key management mechanism, an access permission control strategy, and a data masking processing rule. The grading encryption strategy is used to determine the sensitivity level of the key data and determine the corresponding encryption algorithm based on the sensitivity level. The dynamic key management mechanism is used to update the encryption key and store the encryption key in a distributed manner. The access permission control strategy is used to set data access permissions; the data masking processing rule is used to mask or replace the sensitive fields in the key data.

3. The method according to claim 2, wherein The CL module dynamically generates the first processing strategy and the second processing strategy based on the context features and historical data, including: The CL module takes the data features and context features as input parameters and inputs them into a pre-built machine learning model to analyze and obtain the historical processing records of the risk data and the historical encryption records of the key data; The CL module determines the parameters and conditions of the first processing strategy based on historical processing records, and applies the parameters and conditions of the first processing strategy to the first processing strategy. Among them, the parameters and conditions of the first processing strategy include the threshold parameters of the risk data grading mechanism, the evaluation factors of the risk assessment model, the determination conditions of the abnormal data identification rule, and the record items of the risk data traceability mechanism; The CL module determines the parameters and conditions of the second processing strategy based on historical encryption records, and applies the parameters and conditions of the second processing strategy to the second processing strategy. Among them, the parameters and conditions of the second processing strategy include the encryption strength of the hierarchical encryption strategy, the key update period of the dynamic key management mechanism, the permission matrix of the access permission control strategy, and the desensitization method of the data desensitization processing rule.

4. The method according to claim 1, wherein The RPA module classifies and sorts financial information, and determines the processing order of the classified and sorted financial information, including: The RPA module divides financial information based on preset data categories to obtain at least one financial data set; The RPA module determines the correlation degree between each financial data set and other financial data sets, and merges the financial data sets with a correlation degree higher than the preset correlation degree to obtain at least one associated financial data set; For any associated financial data set, the RPA module uses a preset scoring rule to determine its time sensitivity score and data value score, and calculates the total score of each associated financial data set. Among them, the total score is the sum of the time sensitivity score and the data value score, and the order from high to low of the total score is used as the processing order of the associated financial data sets.

5. The method according to claim 4, wherein The CL module includes a basic data layer, a business logic layer, and a risk control layer. The CL module determines the risk data and key data of financial information, including: For each associated financial data set, in the basic data layer, the CL module validates the format of the associated financial data set, and uses the data that fails the format validation in the associated financial data set as risk data; In the business logic layer, the CL module validates the business logic consistency of the associated financial data set, and uses the data that fails the business logic consistency validation in the associated financial data set as risk data; In the risk control layer, the CL module validates the data sensitivity of the associated financial data set, and uses the data that fails the data sensitivity validation in the associated financial data set as key data.

6. The method according to claim 1, wherein The efficiency of the optimal data transfer path is characterized by network latency and bandwidth occupancy rate, and the quality of the optimal data transfer path is characterized by the packet loss rate. The iPaaS module dynamically adjusts the data transmission compression rate and encryption strength of the optimal data transfer path according to the efficiency and quality of the optimal data transfer path to balance the data security and transmission efficiency of the optimal data transfer path, including: The iPaaS module calculates the combination of the best data transmission compression rate and the best encryption strength based on network latency, bandwidth occupancy rate, and packet loss rate through a pre-built adaptive adjustment model to balance the data security and transmission efficiency of the optimal data transfer path.

7. The method according to claim 1, characterized in that, The method further includes: The data security monitoring module uploads risk data and encrypted key data to the blockchain network, which is used to verify the integrity and compliance of the risk data and key data based on smart contracts.

8. An electronic device, characterized in that, Including: A memory configured to store instructions; And A processor configured to call the instructions from the memory and, when executing the instructions, be capable of implementing the data flow method of the integrated platform according to any one of claims 1 to 7.

9. A fiscal and tax integration platform, characterized in that, The fiscal and tax integration platform is deployed in the electronic device according to claim 8 and is used to execute the operation steps of the method according to any one of claims 1 to 7 above.

Citation Information

Patent Citations

  • Automatic early warning method and system for enterprise financial data

    CN117522136A

  • Enterprise financial document integrated digital management system based on artificial intelligence

    CN118863814A