Digital economic risk management assessment method and system
By building a data management platform and repository in the digital economy, identifying device signature codes and refining permission management, the problems of broad permission management and difficult identification of abnormal risks in the existing technology have been solved, and higher data security and credibility have been achieved.
Patent Information
- Application Number
- CN202510495875.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-21
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-04-21
AI Technical Summary
The existing technology has a relatively broad authority management method in the digital economy, making it difficult to refine authority allocation and timely identify abnormal risks, resulting in data leakage risks and abuse of permissions.
By building a repository that stores digital economic data and building a data management platform, identifying the software and hardware characteristics of the access device, generating device signature codes and management numbers, establishing a correspondence between permission types and device signature codes, reading the call log and generating a comparison code, and determining whether the call log meets the target permissions. If otherwise, it is marked as an exception log.
It realizes the binding of permissions and specific devices, precise control of access rights, improves data security, realizes quantitative management and comprehensive monitoring of access devices, refines permission management, and improves the credibility and security of the digital economy.
Smart Images

Figure CN120031389A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of risk management assessment, and in particular to a digital economy risk management assessment method and system. Background Art
[0002] Digital economy refers to an economic form that takes data as the key production factor, digital technology as the core driving force, and modern information networks as important carriers. The digital economy relies on technologies such as the Internet, cloud computing, big data, artificial intelligence, and blockchain, and uses information technology to improve resource allocation efficiency, promote the transformation and upgrading of traditional industries, and at the same time give birth to new industries and new business models, such as e-commerce, online education, digital finance, and smart manufacturing.
[0003] Permission management is a core link in the digital economy. It involves multiple aspects such as data access, use, storage and sharing. Through permission management, it can ensure that different subjects (users and enterprises, etc.) can obtain and use data within a reasonable range. The existing permission management methods are generally broad; for example, sales personnel have the permission to review, modify and report sales data, but it is impossible to assign permissions specifically to each person and each data, which can easily lead to data leakage risks and permission abuse.
[0004] Therefore, “how to refine authority allocation and identify abnormal risks in a timely manner” is the technical problem that the present invention needs to solve. Summary of the invention
[0005] The purpose of the present invention is to provide a digital economy risk management assessment method and system to solve the problem of "how to refine authority allocation and identify abnormal risks in a timely manner" raised in the above background technology.
[0006] To achieve the above object, the present invention provides the following technical solutions: A digital economy risk management assessment method, the method comprising: Build a repository for storing digital economic data, set up a data management platform, receive call requests uploaded by users, identify access devices, and read out the software and hardware features of access devices, where the software and hardware features at least include: processor identifier, hard disk serial number, browser information, administrator name and device IP; Configure the splicing order, and splice the software and hardware features to obtain a device feature code, obtain a management number composed of several arrays, traverse the characters corresponding to each array in the device feature code, and integrate to obtain an identification code, determine whether there is an identical identification code, and if so, insert an additional group into the management number; Establishing a correspondence between the management number, the device feature code and the identification code, and setting the permission type of the storage repository, wherein the permission type at least includes: access, edit, approve, delete and share, and each permission type corresponds to a management number; Through the data management platform, the call log of the digital economic data is read, the source device corresponding to the call log is traced back, and a comparison code is generated to determine whether there is an identification code that is the same as the comparison code; If yes, define the permission type corresponding to the comparison code as the target permission, determine whether the call log meets the target permission, and if not, define the call log as an abnormal log and send it to the preset terminal; If not, the call log is directly marked as an abnormal log.
[0007] Furthermore, the steps of constructing a repository for storing digital economic data and building a data management platform include: Dividing the storage repository into a plurality of partitions, wherein the partitions include at least: a hot zone and a cold zone; The usage frequency of the digital economic data is calculated, and when the usage frequency is greater than a threshold, the corresponding digital economic data is migrated to a hot zone.
[0008] Furthermore, the steps of receiving the call request uploaded by the user, identifying the access device, and reading the software and hardware characteristics of the access device include: Configuring the usage scenario of the access device and obtaining historical login data of the access device; Determine whether the usage scenario has abnormal features. If so, define the usage scenario as an abnormal scenario and trigger a pre-built secondary verification mechanism.
[0009] Furthermore, the step of inserting an additional group into the management number includes: Traversing the administrator account of the data management platform, and sending a query pop-up window to the administrator account; The feedback information of the administrator account is obtained, an additional group is determined, and the identifier is updated.
[0010] Furthermore, the step of establishing a correspondence between the management number, the device feature code and the identification code and setting the permission type of the storage library includes: Creating a root node, synchronizing the device feature code to the root node, calculating the number of the permission types, and defining it as the total number of permissions; Create the same number of parent nodes as the total number of permissions, and upload the corresponding permission types to the parent nodes; Mount the parent node to the root node, mount child nodes to each parent node, integrate the identification codes corresponding to all access devices, obtain an index set, and upload the index set to the corresponding child nodes; The root node, parent node and child node are integrated to generate a rights management tree.
[0011] Furthermore, the step of reading the call log of the digital economic data via the data management platform, tracing back the source device corresponding to the call log, and generating a comparison code includes: Read the accessed data and the corresponding permission type from the call log, and define the corresponding child node as the target node; The rights management tree is traversed to determine whether the comparison code is stored in the target node.
[0012] Furthermore, the method further comprises: Configure the risk level corresponding to each permission type and create emergency handling rules corresponding to the risk level; Integrate the risk levels, exception logs and emergency handling rules, generate a management assessment report, and send it to a preset terminal.
[0013] Furthermore, the system comprises: A construction module is used to build a repository for storing digital economic data, build a data management platform, receive call requests uploaded by users, identify access devices, and read out the software and hardware features of access devices, where the software and hardware features at least include: processor identifier, hard disk serial number, browser information, administrator name, and device IP; An insertion module is used to configure a splicing order, and to splice the software and hardware features to obtain a device feature code, obtain a management number composed of a plurality of arrays, traverse the characters corresponding to each array in the device feature code, and integrate to obtain an identification code, and determine whether there is an identical identification code. If so, insert an additional group into the management number; An establishment module is used to establish a correspondence between the management number, the device feature code and the identification code, and set the permission type of the storage library, wherein the permission type at least includes: access, edit, approve, delete and share, and each permission type corresponds to a management number; A definition module is used to read the call log of digital economic data through the data management platform, trace back the source device corresponding to the call log, and generate a comparison code to determine whether there is an identification code identical to the comparison code. If so, the permission type corresponding to the comparison code is defined as the target permission, and whether the call log complies with the target permission. If not, the call log is defined as an abnormal log and sent to a preset terminal. If not, the call log is directly marked as an abnormal log.
[0014] Furthermore, the building blocks include: A partitioning unit, used to partition the storage repository into a plurality of partitions, wherein the partitions at least include: a hot zone and a cold zone; A migration unit, used to calculate the usage frequency of digital economic data, and when the usage frequency is greater than a threshold, migrate the corresponding digital economic data to a hot zone; An access unit, used to configure a usage scenario of the access device and obtain historical login data of the access device; The judging unit is used to judge whether the usage scenario has abnormal features. If so, the usage scenario is defined as an abnormal scenario and a pre-built secondary verification mechanism is triggered.
[0015] Furthermore, the insertion module includes: An inquiry unit, used to traverse the administrator account of the data management platform and send an inquiry pop-up window to the administrator account; The updating unit is used to obtain feedback information of the administrator account, determine the additional group, and update the identifier.
[0016] Compared with the prior art, the present invention has the following beneficial effects: By building a data management platform, permissions can be bound to specific devices to ensure that only specific devices can access certain resources, thereby accurately controlling access rights and greatly improving data security. By determining identifiers, access devices can be quantitatively managed while achieving comprehensive monitoring of all access devices to further improve data security. By determining permission types, permissions for the digital economy can be refined to achieve more detailed permission management. By determining target permissions and exception logs, risk assessments can be conducted on the calling process of digital economy data to ensure the security of data calls, greatly improving the credibility and security of the digital economy. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 A flowchart of a digital economy risk management assessment method provided by an embodiment of the present invention; Figure 2 A first sub-process flowchart of the digital economy risk management assessment method provided by an embodiment of the present invention; Figure 3 A second sub-process flowchart of the digital economy risk management assessment method provided by an embodiment of the present invention; Figure 4 A third sub-process flowchart of the digital economy risk management assessment method provided by an embodiment of the present invention; Figure 5A fourth sub-process flowchart of the digital economy risk management assessment method provided by an embodiment of the present invention; Figure 6 A block diagram of the digital economy risk management and assessment system provided by an embodiment of the present invention; Figure 7 A block diagram of the components of the building blocks in the digital economy risk management and assessment system provided by an embodiment of the present invention; Figure 8 A block diagram of the components of the insertion module in the digital economy risk management and assessment system provided by an embodiment of the present invention; Fig. 9 A block diagram of the components of the establishment module in the digital economy risk management and assessment system provided by an embodiment of the present invention; Fig.10 A block diagram of the composition of the definition modules in the digital economy risk management and assessment system provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0018] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0019] In Example 1, Figure 1 The implementation process of the digital economy risk management assessment method provided by the embodiment of the present invention is shown and described in detail below: S100: Build a repository for storing digital economic data, set up a data management platform, receive call requests uploaded by users, identify access devices, and read out the software and hardware features of the access devices, where the software and hardware features include at least: processor identifier, hard disk serial number, browser information, administrator name and device IP.
[0020] Create a database system for storing, managing and retrieving digital economic data, i.e., a repository, build a data management platform, realize the classification, indexing, access control and processing of digital economic data, and parse the device identification information in the request, such as MAC address, IMEI and IP address, after receiving the call request uploaded by the user; determine the user's access device and read the software and hardware features of the access device; the digital economic data can be enterprise operation data, user behavior data and financial transaction data, etc.; in the data management platform, open the registration mechanism, and after the user verification is completed, determine the role and corresponding permissions of each user, where the permissions should be specific to the basic data, i.e., a picture, a file or a chart, etc.
[0021] S200: configure the splicing order, and splice the software and hardware features to obtain the device feature code, obtain the management number composed of several arrays, traverse the characters corresponding to each array in the device feature code, and integrate them to obtain the identification code, determine whether the same identification code exists, and if so, insert an additional group into the management number.
[0022] After determining the characteristics of software and hardware, the acquired characteristic information is standardized, all data is converted into a unified coding format, and the software and hardware characteristics are spliced in a preset splicing order, such as in the order of "processor identifier-hard disk serial number-browser information-administrator name-device IP"; the specific splicing order is determined by the data management platform administrator, and the specific values of the software and hardware characteristics obtained after splicing are defined as the device characteristic code; the management number is determined, and the management number is also determined by the data management platform administrator. The management number is composed of several arrays. In the device characteristic code, the characters corresponding to each array are found, and the corresponding characters are integrated to obtain the identifier.
[0023] For example, the software and hardware features of access device X are sorted in the order of "processor identifier-hard disk serial number-browser information-administrator name-device IP". Assume that the obtained device feature code is: Intel_i7-10700K-SN-XYZ987654321-Chrome_120.0.6099.199_Win10-xiaoming-192.168.1.100; there are four arrays 02, 05, 16 and 11 (management number is 02051621), then find the 2nd, 5th, 16th and 11th characters from the device feature code to obtain the identifier nlN-7 (excluding the separator); in other words, when managing digital economic data, nlN-7 is used to characterize the access device.
[0024] If there are two identical access devices, more arrays are inserted into the management number, where the inserted arrays are additional groups. It should be noted that the division of the arrays is determined by the management personnel. In the management number, the arrays do not have to be arranged in order from small to large, and the additional group can be inserted at any position in the management number.
[0025] S300: Establishing a correspondence between the management number, the device feature code and the identification code, and setting the permission type of the storage repository, wherein the permission type at least includes: access, edit, approve, delete and share, and each permission type corresponds to a management number.
[0026] Establish a correspondence between the management number, device feature code and identification code, and store this correspondence in the data management platform; it should be noted that each access device corresponds to at least one permission type.
[0027] In this application, an example is given for the prior art. Assume that the repository stores A: monthly sales report of a certain online store, B: behavior data form of a certain user in the online store, C: quality inspection report of defective products of a certain factory, and D: financial payment data of a certain user; further, the common device of user A in the data management platform (assuming the identifier is nlN-7) can view and modify data A, B and D, and the common device of user B (assuming the identifier is 3-l-6-1) can view, approve, delete and share data C. If the permission type corresponding to the management number is set to view, then when the management number is 02051621, the identification compliance set shown in Table 1 below is obtained.
[0028] Table 1:
[0029] Set a management number again (such as 0214152342), and the corresponding permission type is modification, and obtain the identification compliance set shown in Table 2 below.
[0030] Table 2:
[0031] Among them, Table 1 is the identification set corresponding to A, B, C and D when the management number is: 02051621 and the permission type is view; Table 2 is the identification set corresponding to A, B, C and D when the management number is: 0214152342 and the permission type is modify.
[0032] It can be seen that by setting multiple groups of management numbers and integrating the identifiers of all access devices, an identification compliance set is obtained (each permission type corresponds to an identification compliance set). When accessing data, the management number is queried to calculate the identifier of the current device, and it is determined whether this identifier is in the identification compliance set of the corresponding permission. If so, it means that the user has the authority to use the corresponding permission type to process the required access data.
[0033] Assume that by querying the management number, the identifier of the current device is TL-8-I, which is neither in Table 1 nor in Table 2. This means that the current device has no authority to view and modify A, B, C, and D.
[0034] S400: Read the call log of the digital economic data through the data management platform, trace back the source device corresponding to the call log, and generate a comparison code to determine whether there is an identification code that is the same as the comparison code; if so, define the permission type corresponding to the comparison code as the target permission, and determine whether the call log complies with the target permission. If not, define the call log as an exception log and send it to the preset terminal. If not, directly mark the call log as an exception log.
[0035] Extract key information from the call log of digital economic data, such as the call time, the IP address of the calling device, the call data and the specific operation; determine the source device based on the IP address, and calculate the comparison code of the source device in the manner of S200; determine whether the corresponding identification is in compliance with the set according to the permission type (target permission) in the specific operation, and whether there is an identifier identical to the comparison code; if so, it means that this data call and device behavior meet the permission management requirements; if not, define the call log as an exception log, and send the exception log to the preset terminal, where the preset terminal is the data management platform administrator terminal.
[0036] In this application, by constructing an identification code set and storing it in the form of a single text, it is possible to manage different permission types for different devices. At this time, if the user has multiple devices, different permission types should be configured for each device.
[0037] In Example 2, Figure 2 The implementation process of the digital economy risk management assessment method provided by the embodiment of the present invention is shown. The steps of constructing a repository for storing digital economy data and building a data management platform are described in detail as follows: S101: Divide the storage repository into a plurality of partitions, wherein the partitions include at least a hot zone and a cold zone.
[0038] In the data management platform, the repository is divided into several partitions, including at least hot and cold zones. The hot zone is mainly used to store frequently accessed and updated digital economic data, and is usually deployed on high-performance storage media, such as solid-state drives; the cold zone is mainly used to store infrequently accessed digital economic data, which has a low access frequency, and is usually deployed on traditional hard drives with larger capacity.
[0039] S102: Calculate the usage frequency of digital economic data, and when the usage frequency is greater than a threshold, migrate the corresponding digital economic data to a hot zone.
[0040] The usage frequency of each digital economic data is calculated. If the usage frequency is greater than the threshold, the corresponding digital economic data will be synchronized to the hot zone. Otherwise, it will be placed in the cold zone.
[0041] In Embodiment 3, Figure 2 The implementation process of the digital economy risk management assessment method provided by the embodiments of the present invention is shown. The following details the steps of receiving a call request uploaded by a user, identifying an access device, and reading the software and hardware characteristics of the access device, as follows: S103: Configure the usage scenario of the access device and obtain the historical login data of the access device.
[0042] According to the correspondence between the identifier and the access device, determine the user's usage scenario, where the usage scenario is divided into: common scenario and non-common scenario; obtain the historical login data of the access device, and the historical login data includes: login time, IP address at login, operating system version of the login device, browser information, etc. These historical login data can help users identify abnormal or frequent login behaviors of the access device.
[0043] S104: Determine whether the usage scenario has abnormal characteristics. If so, define the usage scenario as an abnormal scenario and trigger a pre-constructed secondary verification mechanism.
[0044] Determine whether there are abnormal characteristics in the user's usage scenario and login data. If so, start the secondary verification mechanism to verify the user's identity again; the specific verification method is not limited.
[0045] In Embodiment 4, Figure 3 The implementation process of the digital economy risk management assessment method provided by the embodiments of the present invention is shown. The following details the steps of inserting an additional group into the management number, as follows: S201: Traverse the administrator accounts of the data management platform and send an inquiry pop-up window to the administrator accounts.
[0046] Determine the administrator according to the role of each user, push an inquiry pop-up window to the administrator account, and receive the additional group input by the administrator in the inquiry pop-up window.
[0047] S202: Obtain the feedback information of the administrator account, determine the additional group, and update the identifier.
[0048] Extract the additional group from the feedback information and update the identifier, where the additional group can be inserted into any position in the identifier.
[0049] In Embodiment 5, Figure 4 The implementation process of the digital economy risk management assessment method provided by the embodiments of the present invention is shown. The following details the steps of establishing the correspondence between the management number, the device feature code, and the identification code, and setting the permission type of the repository, as follows: S301: Create a root node, synchronize the device feature code to the root node, calculate the number of the permission types, and define it as the total number of permissions.
[0050] Create a root node and synchronize the device feature code to the root node, calculate the number of permission types, and get the total number of permissions. The root node is the basic structure for storing data and is mainly used to characterize access devices. If the permission types are: access, edit, approve, and delete, the corresponding total number of permissions is 4.
[0051] S302: Create the same number of parent nodes as the total number of permissions, and upload the corresponding permission types to the parent nodes.
[0052] A parent node corresponding to each permission type is created, where the parent node has the same data structure as the root node, and is mainly used to display the permission type possessed by each access device.
[0053] S303: Mount the parent node to the root node, mount child nodes to each parent node, integrate identification codes corresponding to all access devices, obtain an index set, and upload the index set to the corresponding child nodes.
[0054] Mount the parent node to the root node, create a child node, where the child node also has the same data structure as the root node, and mount the child node to the parent node. It should be noted that there are multiple parent nodes mounted under each root node, and each parent node has only one child node mounted under it.
[0055] S304: Integrate the root node, parent node and child node to generate a rights management tree.
[0056] A permission management tree is generated using the root node, parent node and child node, where the permission management tree is similar to a binary tree and can quickly perform permission verification.
[0057] In Example 6, Figure 5 The implementation process of the digital economy risk management assessment method provided by an embodiment of the present invention is shown. The following is a detailed description of the steps of reading the call log of digital economy data through the data management platform, tracing back the source device corresponding to the call log, and generating a comparison code, as follows: S401: Read the accessed data and the corresponding permission type from the call log, and define the corresponding child node as the target node.
[0058] When verifying the call log, find out the accessed data and the corresponding permission type corresponding to the call log, and locate the corresponding root node according to the source device.
[0059] S402: traverse the rights management tree to determine whether the comparison code is stored in the target node.
[0060] Define the child node under the found root node as the target node, and determine whether the comparison code is stored in the target node. If so, continue to determine whether the permission type corresponding to the child node is the same as the permission type corresponding to the accessed data. If they are the same, it means that this data call and device behavior meet the permission management requirements.
[0061] In Example 7, different from Example 1, in this embodiment of the present invention, the method further includes: Configure the risk level corresponding to each permission type and create emergency handling rules corresponding to the risk level; Integrate the risk levels, exception logs and emergency handling rules, generate a management assessment report, and send it to a preset terminal.
[0062] Each permission type corresponds to a risk level, and each risk level corresponds to an emergency response rule. The emergency response rules are formulated by the data management platform administrator. The risk level, exception log and emergency response rules are written into the preset template, and a management assessment report is generated and sent to the preset terminal, which is the data management platform administrator terminal.
[0063] For example, continuing to elaborate on the example in S300, assuming that the risk level corresponding to C is high, the emergency response rule is: when a data leak occurs, report the data leak incident to the relevant department in a timely manner.
[0064] Figure 6 The digital economy risk management and evaluation system provided by an embodiment of the present invention is shown in a structural block diagram. The digital economy risk management and evaluation system 1 includes: Construction module 11 is used to build a repository for storing digital economic data, build a data management platform, receive call requests uploaded by users, identify access devices, and read out software and hardware features of access devices, wherein the software and hardware features at least include: processor identifier, hard disk serial number, browser information, administrator name and device IP; Insertion module 12, used to configure the splicing order, and splice the software and hardware features to obtain a device feature code, obtain a management number composed of several arrays, traverse the characters corresponding to each array in the device feature code, and integrate to obtain an identification code, determine whether there is an identical identification code, and if so, insert an additional group into the management number; Establishing module 13, used to establish the corresponding relationship between the management number, the device feature code and the identification code, and set the permission type of the storage library, wherein the permission type at least includes: access, edit, approve, delete and share, and each permission type corresponds to a management number; The definition module 14 is used to read the call log of the digital economic data through the data management platform, trace back the source device corresponding to the call log, and generate a comparison code to determine whether there is an identification code that is the same as the comparison code. If so, the permission type corresponding to the comparison code is defined as the target permission, and whether the call log complies with the target permission. If not, the call log is defined as an abnormal log and sent to a preset terminal. If not, the call log is directly marked as an abnormal log.
[0065] Figure 7 The structure diagram of the digital economy risk management and assessment system provided by the embodiment of the present invention is shown, and the building block 11 includes: A partitioning unit 111 is used to partition the storage repository into a plurality of partitions, wherein the partitions at least include: a hot zone and a cold zone; A migration unit 112, configured to calculate the usage frequency of the digital economic data, and when the usage frequency is greater than a threshold, migrate the corresponding digital economic data to a hot zone; An access unit 113 is used to configure a usage scenario of the access device and obtain historical login data of the access device; The judging unit 114 is used to judge whether the usage scenario has abnormal features. If so, the usage scenario is defined as an abnormal scenario and a pre-built secondary verification mechanism is triggered.
[0066] Figure 8 The structure diagram of the digital economy risk management and assessment system provided by the embodiment of the present invention is shown, and the insertion module 12 includes: An inquiry unit 121 is used to traverse the administrator account of the data management platform and send an inquiry pop-up window to the administrator account; The updating unit 122 is used to obtain feedback information of the administrator account, determine the additional group, sort the array and the additional group in order from small to large, and update the identifier according to the sorting result.
[0067] Fig. 9 The structure diagram of the digital economy risk management and assessment system provided by the embodiment of the present invention is shown, and the establishment module 13 includes: The calculation unit 131 is used to create a root node, synchronize the device feature code to the root node, calculate the number of the permission types, and define it as the total number of permissions; An uploading unit 132 is used to create the same number of parent nodes as the total number of permissions, and upload the corresponding permission types to the parent nodes; The obtaining unit 133 is used to mount the parent node to the root node, mount a child node to each parent node, integrate the identification codes corresponding to all access devices, obtain an index set, and upload the index set to the corresponding child node; The integration unit 134 is used to integrate the root node, the parent node and the child node to generate a rights management tree.
[0068] Fig.10 The structure diagram of the digital economy risk management and assessment system provided by the embodiment of the present invention is shown, and the definition module 14 includes: A reading unit 141 is used to read the accessed data and the corresponding permission type from the call log, and define the corresponding child node as a target node; The traversal unit 142 is used to traverse the permission management tree to determine whether the comparison code is stored in the target node.
[0069] The construction module 11 is mainly used to complete step S100, the insertion module 12 is mainly used to complete step S200, the establishment module 13 is mainly used to complete step S300, and the definition module 14 is mainly used to complete step S400; The segmentation unit 111 is mainly used to complete step S101, the migration unit 112 is mainly used to complete step S102, the access unit 113 is mainly used to complete step S103, and the determination unit 114 is mainly used to complete step S104; The query unit 121 is mainly used to complete step S201, and the update unit 122 is mainly used to complete step S202; The calculation unit 131 is mainly used to complete step S301, the uploading unit 132 is mainly used to complete step S302, the obtaining unit 133 is mainly used to complete step S303, and the integration unit 134 is mainly used to complete step S304; The reading unit 141 is mainly used to complete step S401, and the traversal unit 142 is mainly used to complete step S402.
[0070] The technical features of the above-described embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0071] The above-mentioned embodiments only express several implementation methods of the present invention, and the description thereof is relatively specific and detailed, but it cannot be understood as limiting the scope of the patent of the present invention. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the attached claims.
[0072] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A digital economy risk management assessment method, characterized in that: The method comprises: Build a repository for storing digital economic data, set up a data management platform, receive call requests uploaded by users, identify access devices, and read out the software and hardware features of access devices, where the software and hardware features at least include: processor identifier, hard disk serial number, browser information, administrator name and device IP; Configure the splicing order, and splice the software and hardware features to obtain a device feature code, obtain a management number composed of several arrays, traverse the characters corresponding to each array in the device feature code, and integrate to obtain an identification code, determine whether there is an identical identification code, and if so, insert an additional group into the management number; Establishing a correspondence between the management number, the device feature code and the identification code, and setting the permission type of the storage repository, wherein the permission type at least includes: access, edit, approve, delete and share, and each permission type corresponds to a management number; Through the data management platform, the call log of the digital economic data is read, the source device corresponding to the call log is traced back, and a comparison code is generated to determine whether there is an identification code that is the same as the comparison code; If yes, define the permission type corresponding to the comparison code as the target permission, determine whether the call log meets the target permission, and if not, define the call log as an abnormal log and send it to the preset terminal; If not, the call log is directly marked as an abnormal log.
2. The digital economy risk management assessment method according to claim 1 is characterized in that: The steps of constructing a repository for storing digital economic data and building a data management platform include: Dividing the storage repository into a plurality of partitions, wherein the partitions include at least: a hot zone and a cold zone; The usage frequency of the digital economic data is calculated, and when the usage frequency is greater than a threshold, the corresponding digital economic data is migrated to a hot zone.
3. The digital economy risk management assessment method according to claim 1 is characterized in that: The steps of receiving a call request uploaded by a user, identifying an access device, and reading software and hardware features of the access device include: Configuring the usage scenario of the access device and obtaining historical login data of the access device; Determine whether the usage scenario has abnormal features. If so, define the usage scenario as an abnormal scenario and trigger a pre-built secondary verification mechanism.
4. The digital economy risk management assessment method according to claim 1 is characterized in that: The step of inserting an additional group into the management number comprises: Traversing the administrator account of the data management platform, and sending a query pop-up window to the administrator account; The feedback information of the administrator account is obtained, an additional group is determined, and the identifier is updated.
5. The digital economy risk management assessment method according to claim 1 is characterized in that: The step of establishing a correspondence between the management number, the device feature code and the identification code, and setting the permission type of the storage library comprises: Creating a root node, synchronizing the device feature code to the root node, calculating the number of the permission types, and defining it as the total number of permissions; Create the same number of parent nodes as the total number of permissions, and upload the corresponding permission types to the parent nodes; Mount the parent node to the root node, mount child nodes to each parent node, integrate the identification codes corresponding to all access devices, obtain an index set, and upload the index set to the corresponding child nodes; The root node, parent node and child node are integrated to generate a rights management tree.
6. The digital economy risk management assessment method according to claim 5 is characterized in that: The step of reading the call log of digital economic data via the data management platform, tracing back the source device corresponding to the call log, and generating a comparison code includes: Read the accessed data and the corresponding permission type from the call log, and define the corresponding child node as the target node; The rights management tree is traversed to determine whether the comparison code is stored in the target node.
7. The digital economy risk management assessment method according to claim 6 is characterized in that: The method further comprises: Configure the risk level corresponding to each permission type and create emergency handling rules corresponding to the risk level; Integrate the risk levels, exception logs and emergency handling rules, generate a management assessment report, and send it to a preset terminal.
8. A digital economy risk management and assessment system, characterized in that: The system comprises: A construction module is used to build a repository for storing digital economic data, build a data management platform, receive call requests uploaded by users, identify access devices, and read out the software and hardware features of access devices, where the software and hardware features at least include: processor identifier, hard disk serial number, browser information, administrator name, and device IP; An insertion module is used to configure a splicing order, and to splice the software and hardware features to obtain a device feature code, obtain a management number composed of a plurality of arrays, traverse the characters corresponding to each array in the device feature code, and integrate to obtain an identification code, and determine whether there is an identical identification code. If so, insert an additional group into the management number; An establishment module is used to establish a correspondence between the management number, the device feature code and the identification code, and set the permission type of the storage library, wherein the permission type at least includes: access, edit, approve, delete and share, and each permission type corresponds to a management number; A definition module is used to read the call log of digital economic data through the data management platform, trace back the source device corresponding to the call log, and generate a comparison code to determine whether there is an identification code identical to the comparison code. If so, the permission type corresponding to the comparison code is defined as the target permission, and whether the call log complies with the target permission. If not, the call log is defined as an abnormal log and sent to a preset terminal. If not, the call log is directly marked as an abnormal log.
9. The digital economy risk management and assessment system according to claim 8, characterized in that: The building blocks include: A partitioning unit, used to partition the storage repository into a plurality of partitions, wherein the partitions at least include: a hot zone and a cold zone; A migration unit, used to calculate the usage frequency of digital economic data, and when the usage frequency is greater than a threshold, migrate the corresponding digital economic data to a hot zone; An access unit, used to configure a usage scenario of the access device and obtain historical login data of the access device; The judging unit is used to judge whether the usage scenario has abnormal features. If so, the usage scenario is defined as an abnormal scenario and a pre-built secondary verification mechanism is triggered.
10. The digital economy risk management and assessment system according to claim 8, characterized in that: The insertion module comprises: An inquiry unit, used to traverse the administrator account of the data management platform and send an inquiry pop-up window to the administrator account; The updating unit is used to obtain feedback information of the administrator account, determine the additional group, and update the identifier.
Citation Information
Patent Citations
Data management method and device, electronic equipment and computer readable storage medium
CN111666578A
IT operation and maintenance configuration resource management system
CN114510390A
Equipment management method and system based on tree structure, equipment and medium
CN117560222A
User authority management method and device, storage medium and electronic device
CN117914535A
Zero-trust dynamic access control method and device and computer equipment
CN119046910A