Database-based digital asset development management system
By designing a database-based digital asset management system, using the coordinated work of asset analysis, internal monitoring, external monitoring, fuzzy judgment and permission management modules, the existing system has insufficient response speed and flexibility in the face of security threats, and has achieved dynamic monitoring and real-time permission adjustment of digital assets, improving security.
Patent Information
- Application Number
- CN202510137406.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-05-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
When facing internal and external security threats, the existing digital asset management system has poor response speed and flexibility, and the static authority allocation mechanism cannot be dynamically adjusted according to environmental and risk changes, which increases the risk of asset leakage.
Design a database-based digital asset development and management system, including asset analysis module, internal monitoring module, external monitoring module, fuzzy judgment module and permission management module. Through the collaborative work of these modules, the status and external access behavior of digital assets are monitored in real time, and users’ access rights to digital assets are dynamically adjusted.
It realizes dynamic monitoring and real-time permission adjustment of digital assets, improves the system's response speed and flexibility when facing security threats, reduces the risk of data leakage, and improves the security of digital assets.
Smart Images

Figure CN120046168A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of digital asset management, and more specifically, to a digital asset development and management system based on a database. Background Art
[0002] With the rapid development of informatization, enterprises and organizations have accumulated a large number of digital assets, which play a vital role in the operation, management and decision-making of enterprises. However, with the rapid growth in the types and quantity of digital assets, how to effectively manage and protect these assets has become an urgent problem to be solved. Traditional digital asset management systems usually only provide simple storage and retrieval functions, but the dynamic management capabilities of the importance, sensitivity, security and other aspects of assets are relatively insufficient. Especially when facing internal and external security threats, the response speed and flexibility of existing systems are poor.
[0003] In addition, the security management of digital assets in existing technologies often relies on a static permission allocation mechanism, which cannot be dynamically adjusted according to changes in the environment and risks. For example, when the behavior patterns of external users are abnormal or risks occur within the system, the system cannot dynamically adjust access rights based on these anomalies, increasing the risk of asset leakage. Therefore, developing a management system that can dynamically monitor the status of digital assets and adjust access rights in real time has become an important topic in the current information security field. Summary of the invention
[0004] To achieve the above object, the present invention provides the following technical solutions:
[0005] A digital asset development and management system based on a database, including a database, an asset analysis module, an internal monitoring module, an external monitoring module, a fuzzy judgment module, and a permission management module;
[0006] The database contains all the information of digital assets;
[0007] The asset analysis module extracts the asset metadata of the digital assets in the database, and performs classification operations according to the preset classification standards, performs asset analysis based on the results of the classification operations, and generates the comprehensive asset value of the target digital assets;
[0008] The internal monitoring module monitors the safety operation information within the system, performs internal environmental analysis, and generates an internal disorder coefficient.
[0009] The external monitoring module collects the request verification information of external users, performs external environment analysis, and generates an external disorder coefficient.
[0010] The fuzzy logic judgment module uses fuzzy logic rules based on the comprehensive value of the asset, the internal disorder coefficient and the external disorder coefficient to judge whether the digital asset is allowed to be viewed, edited or downloaded;
[0011] The authority management module dynamically allocates user authority over digital assets in the database based on the output of the fuzzy logic judgment module.
[0012] In a preferred embodiment, a database-based digital asset development and management system further includes a data backup module for periodically backing up all digital assets.
[0013] In a preferred embodiment, the classification operation refers to:
[0014] According to the category to which the target asset metadata belongs, an asset type and a role type are assigned to it according to the preset classification standards. Each role type corresponds to an importance value, and each asset type corresponds to a classification value. All importance values and classification values range from 0 to 1, and the sum of the classification values corresponding to all asset types is one.
[0015] In a preferred embodiment, performing asset analysis based on the results of the classification operation to generate the comprehensive asset value of the target digital asset refers to:
[0016] Obtain the importance value corresponding to the target digital asset and mark it as I, and the sensitivity value corresponding to the target digital asset and mark it as C. Then, in the preset time window, count the historical usage records of the target digital asset in the system to determine its usage frequency score F. The usage frequency score F is calculated by dividing the number of times used in the preset time window by the number of times all digital assets are used in the preset time window. The output result is obtained from the pre-trained feature extraction model and marked as privacy sensitivity S. Finally, the historical number of leaks of the target digital asset is obtained and marked as L, and then substituted into the following calculation formula:
[0017] As=C*(w1*I+w2*F+w3*S 2 +w4*L); w1, w2, w3 and w4 are all preset influence coefficients and are not zero, and As represents the comprehensive asset value of the target digital asset.
[0018] In a preferred embodiment, the steps of using the feature extraction model are:
[0019] Step 1: Perform word segmentation, text feature extraction, and vocabulary matching on text assets, and use image or video recognition technology to perform object detection or content recognition on non-text assets;
[0020] Step 2: Input all processed assets into the pre-trained deep learning model to obtain their respective sensitivity scores;
[0021] Step 3: Perform weighted summation of all sensitivity scores to obtain the privacy sensitivity S, where the weight value of each depends on the content type corresponding to the sensitivity score.
[0022] In a preferred embodiment, the logic for obtaining the internal turbulence coefficient is:
[0023] In the set time window T, obtain the number of abnormal events N detected by the system in the time window T, the number of abnormalities in the log operation Elog, the current system load value Lcurr, the current communication delay value Rlater, and the system device health status value Hdevice, and then substitute them into the calculation formula:
[0024] Etotal represents the total number of log operations within the time window T, Lmax represents the maximum load value allowed by the system, Rmax represents the maximum communication delay value allowed by the system, Hmax represents the maximum health status value when the system equipment is configured, and Dint represents the internal disorder coefficient of the system.
[0025] In a preferred embodiment, the logic for obtaining the external turbulence coefficient is:
[0026] Obtaining a behavior parameter combination corresponding to the current behavior pattern of the external user, and obtaining a behavior parameter combination corresponding to the historical behavior pattern of the external user, calculating the cosine similarity of the maximum value between the behavior parameter combination corresponding to the current behavior pattern and the behavior parameter combination corresponding to the historical behavior pattern, and then calculating the user activity pattern anomaly based on the cosine similarity of the maximum value, the sum of the cosine similarity of the user activity pattern anomaly and the maximum value is one;
[0027] Obtain the number of network address changes when external users access the system in the time window T, and then calculate the ratio of the number of network address changes to the preset standard allowed change threshold to obtain the network jump ratio value;
[0028] Use the external turbulence coefficient calculation formula:
[0029] Dout=ln(1+YC*WT); YC is the abnormal value of the user activity pattern, WT is the network jump ratio value, and Dout is the external disorder coefficient.
[0030] In a preferred embodiment, the working process of the fuzzy logic judgment module is:
[0031] The comprehensive asset value, internal disorder coefficient and external disorder coefficient of the target digital asset are taken as input variables, and the access mode of the target digital asset is taken as the output variable. The input variables are fuzzified and the values of the input variables are converted into fuzzy sets. The output variables are fuzzified and the output variables are converted into fuzzy sets. Fuzzy rules are formulated to describe the access security under different data type combinations. The fuzzified input variables are inferred through fuzzy rules to obtain the access mode of the target digital asset.
[0032] Technical effects and advantages of the present invention:
[0033] Through the fuzzy logic judgment module, the present invention can adjust the user's access rights to digital assets in real time based on the comprehensive value of assets, internal disorder coefficient and external disorder coefficient. This dynamic management mechanism enables the system to respond flexibly to different security risks, effectively prevent data leakage, and improve the security of digital assets.
[0034] Through the asset analysis module, internal monitoring module and external monitoring module, the system can monitor the use of digital assets and external access behavior in real time, and generate a comprehensive risk assessment based on the internal status of the system. This allows the system to respond to potential threats in a timely manner, thereby ensuring the security of digital assets and the stability of the system.
[0035] The present invention classifies digital assets, combines the business attributes and importance of each asset, and assigns appropriate classification values and importance values to each asset, thereby achieving refined management of different assets. This classification mechanism not only improves the efficiency of system management, but also provides a more accurate basis for judgment in authority allocation and security control.
[0036] Through the joint work of internal and external monitoring modules, the system can identify and handle potential internal and external security threats. It uses the behavior analysis of external users and the monitoring of internal system status to generate corresponding disorder coefficients for risk assessment, thereby improving the system's ability to perceive and handle potential threats. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to facilitate understanding by those skilled in the art, the present invention is further described below in conjunction with the accompanying drawings;
[0038] Figure 1 This is a schematic diagram of a database-based digital asset development and management system in Example 1 of the present invention.
[0039] Figure 2 This is a schematic diagram of a database-based digital asset development and management system in Example 2 of the present invention.
[0040] Figure 3This is a flowchart of the use of a database-based digital asset development and management system in Example 1 of the present invention.
[0041] Figure 4 This is a flowchart of the steps for using the feature extraction model in Example 1 of the present invention.
[0042] Figure 5 This is a schematic diagram of the feature extraction model in Example 1 of the present invention. DETAILED DESCRIPTION
[0043] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0044] Reference Figure 1-5 The following embodiments are obtained:
[0045] Embodiment 1: A digital asset development management system based on a database, comprising a database, an asset analysis module, an internal monitoring module, an external monitoring module, a fuzzy judgment module, and a rights management module;
[0046] The database contains all the information of digital assets; an example is:
[0047] Creation Time: The timestamp of when the asset was first stored.
[0048] Last access time: The time when the digital asset was last accessed.
[0049] Expiration or deletion time: Some assets may have a lifecycle management mechanism that specifies expiration time or automatic deletion time to help the system manage storage resources effectively.
[0050] Storage location: The physical storage location of the asset (e.g. local storage, cloud storage).
[0051] Number of visits: records the total number of times the asset has been visited.
[0052] Download count: records the number of times the asset has been downloaded.
[0053] Frequency of use: The frequency of use of the asset can be calculated through the number of visits and downloads.
[0054] Basic asset information: Asset ID: A unique identifier for each digital asset (usually a system-generated unique ID), used to identify each asset in the database. Asset Name: The name of the digital asset, used to describe the content of the asset for easy user identification. Asset Type: Specifies the type of digital asset, such as text, image, video, audio, etc., to help with classification and management.
[0055] Metadata: Creation time: The timestamp when the digital asset was created, recording the time when the asset was first stored. Modification time: Records the latest modification time of the asset, which helps manage version control. Creator: Records the creator or owner of the asset, which may be a user ID or username. File size: The storage size of the digital asset, usually recorded in bytes. Format: The format type of the file, such as PDF, JPEG, MP4, DOCX, TXT, etc., used to identify and process different types of files.
[0056] The asset analysis module extracts the asset metadata of the digital assets in the database, and performs classification operations according to the preset classification standards, performs asset analysis based on the results of the classification operations, and generates the comprehensive asset value of the target digital assets;
[0057] The internal monitoring module monitors the safety operation information within the system, performs internal environmental analysis, and generates an internal disorder coefficient.
[0058] The external monitoring module collects the request verification information of external users, performs external environment analysis, and generates an external disorder coefficient.
[0059] The fuzzy logic judgment module uses fuzzy logic rules based on the comprehensive value of the asset, the internal disorder coefficient and the external disorder coefficient to judge whether the digital asset is allowed to be viewed, edited or downloaded;
[0060] The authority management module dynamically allocates user authority over digital assets in the database based on the output of the fuzzy logic judgment module.
[0061] The classification operation means: according to the category to which the target asset metadata belongs, an asset type and a role type are assigned to it according to the preset classification standard. Each role type corresponds to an importance value, and each asset type corresponds to a classification value. All importance values and classification values range from 0 to 1. The sum of the classification values corresponding to all asset types is one. Specifically:
[0062] The core concepts of classification operations: Asset type: classified according to the business attributes or functions of assets. Common asset types include: Business data: data information related to the company's core business, such as financial statements, sales records, customer orders, etc. User information: relevant information of individual users, such as user name, password, email, address, contact information, etc. Internal documents: non-public documents used within the company, such as internal policies, rules and regulations, internal emails, etc.
[0063] Role type: The role an asset plays in the system or its purpose usually determines the priority of the asset. For example: Core business data: assets that are critical to the company's operations. Supporting data: supports the company's business but is not core, such as analytical reports. Non-critical data: general information with low relevance to the business.
[0064] Importance value: Each role type corresponds to an importance value ranging from 0 to 1. The higher the value, the greater the importance of the asset.
[0065] Category value: Each asset type has a category value ranging from 0 to 1, indicating the relative importance of the asset in its category. The sum of all category values is 1.
[0066] Take an example to illustrate the classification operation: suppose there are three assets, and their basic information is as follows: Asset A: financial statements; asset type: business data; function type: core business data; Asset B: user registration information; asset type: user information; function type: core business data; Asset C: internal meeting minutes; asset type: internal documents; function type: non-critical data.
[0067] Assign asset types based on their functions: Asset A is information related to the company's finances and belongs to the business data type. Asset B contains user registration information and belongs to the user information type. Asset C is a document used within the company and belongs to the internal document type.
[0068] Assign role types: Asset A has a role type of core business data because it is critical to the company's financial operations. Asset B also has a role type of core business data because user information is equally important to the company's business foundation. Asset C has a role type of non-critical data because internal meeting records have no direct impact on the company's core business.
[0069] Assign importance values and classification values: For role types, assign importance values to each type: core business data: 0.9 (high importance); supporting data: 0.5 (medium importance); non-critical data: 0.2 (low importance); for asset types, assign classification values: business data: 0.4; user information: 0.3; internal documents: 0.3.
[0070] Based on the results of the classification operation, asset analysis is performed to generate the comprehensive asset value of the target digital asset, which refers to:
[0071] Obtain the importance value corresponding to the target digital asset and mark it as I, indicating the criticality of the asset in the business. The sensitivity value corresponding to the target digital asset is marked as C, indicating the weight of the category to which the asset belongs. Then, in the preset time window, count the historical usage records of the target digital asset in the system to determine its usage frequency score F. The usage frequency score F is calculated by dividing the number of times used in the preset time window by the number of times all digital assets are used in the preset time window. The output result is obtained from the pre-trained feature extraction model and marked as privacy sensitivity S, reflecting the level of sensitive information (such as privacy, confidentiality) involved in the asset. Finally, obtain the historical leakage number of the target digital asset and mark it as L, indicating whether the asset has ever had a history of security accidents or leakages, and then substitute them into the following calculation formula:
[0072] As=C*(w1*I+w2*F+w3*S 2 +w4*L); w1, w2, w3 and w4 are all preset influence coefficients and are not zero. They are used to balance the impact of various factors on the final comprehensive value. As represents the comprehensive value of the target digital asset. The square of the sensitivity S means that the sensitivity of the asset is amplified, that is, assets with higher sensitivity will have a greater impact on the comprehensive value. The larger the comprehensive value, the higher the importance, frequency of use, sensitivity and historical leakage risk of the asset. Specifically: a high comprehensive value means that the asset is very critical to the business, frequently used, highly sensitive to privacy and may have a history of leakage, so higher protection measures are required. A low comprehensive value means that the asset is less important, less frequently used, less sensitive, and has a lower risk.
[0073] The steps for using the feature extraction model are:
[0074] Step 1: Perform word segmentation, text feature extraction, and vocabulary matching on text assets, and use image or video recognition technology to perform object detection or content recognition on non-text assets;
[0075] Step 2: Input all processed assets into the pre-trained deep learning model to obtain their respective sensitivity scores;
[0076] Step 3: Perform weighted summation of all sensitivity scores to obtain the privacy sensitivity S, where the weight value of each depends on the content type corresponding to the sensitivity score.
[0077] Use a pre-trained feature extraction model (such as a deep learning model) to process different types of assets. This model can extract features for different types of assets (text, image video, audio, etc.) through a large amount of training data and output privacy-related sensitivity scores.
[0078] The main functions of this feature extraction model are: for text data, extract keywords, context information, content classification, etc., and evaluate its sensitivity. For non-text data, extract sensitive objects in the content (such as faces, ID cards, logos, etc.), and output sensitive information through content detection.
[0079] The output results are uniformly expressed as a privacy sensitivity score S, where a larger value indicates a higher sensitivity.
[0080] Data preprocessing: For text-type assets and non-text-type assets, data preprocessing is performed first: Text data: Word segmentation, part-of-speech tagging, and semantic analysis are performed on the text to prepare for input into the feature extraction model. Non-text data: Data standardization is performed on images, videos, audio, etc., or relevant input data is generated through object detection and feature extraction technology.
[0081] Use of feature extraction model: The preprocessed text and non-text data are input into the pre-trained feature extraction model, which outputs the sensitivity score of the asset.
[0082] Take text assets as an example: Assuming that text assets are used, sensitive features are extracted through keyword matching:
[0083] Keyword library: Establish a keyword library K = {k1, k2, ..., kn} of sensitive words. These keywords may include "privacy", "confidential", "credit card number", etc. Keyword extraction: Perform text analysis on the asset, extract the vocabulary set Q = {q1, q2, ..., qn} in the asset that matches the sensitive word library, and assign different weights to different sensitive keywords or features. For example, "confidential" may have a higher sensitivity than "privacy", and each extracted sensitive word can be assigned a sensitivity weight mi;
[0084] δ(ki) indicates whether the asset contains the ith keyword. If so, it takes 1, and if not, it takes 0. P1 represents the sensitivity score corresponding to the text asset.
[0085] Take a non-text asset as an example: images and videos can be unified as one category, and sensitivity can be achieved through image recognition and object detection technology. Through image or video recognition technology, that is, computer vision technology, sensitive content in images or videos, such as faces, ID cards, bank card numbers, trademarks, etc., is extracted. Object detection: Use a pre-trained neural network model to detect objects contained in images or videos. The extracted set of sensitive objects is represented as O = {o1, o2, ..., on}, sensitive object weight library: assign a weight gi to each possible sensitive object, and these weights reflect the sensitivity of the object. For example, objects such as faces and ID information have a large weight, while ordinary scenes have a small weight.
[0086] The sensitivity score of the image or video is calculated by extracting the sensitive object O and the predefined weight gi. Assume that n objects are detected in the image or video;
[0087] P2 represents the sensitivity score corresponding to the image and video classes in non-text assets, δ(Oi) means that if the image or video contains the object oi, the value is 1, otherwise it is 0;
[0088] By analogy, the sensitivity score corresponding to audio assets is P3. Because an asset may involve multiple types of sensitivity scores, all sensitivity scores are weighted and summed to obtain the privacy sensitivity S. The weight values of each sensitivity score depend on the content type corresponding to the sensitivity score (such as text, image video, audio, etc.). The weighted summation formula can be: ri is the preset weight coefficient of content type i corresponding to the sensitivity score, and Pi is the sensitivity score corresponding to content type i.
[0089] The logic for obtaining the internal turbulence coefficient is:
[0090] In the set time window T, obtain the number of abnormal events N detected by the system in the time window T, the number of abnormalities in the log operation Elog, the current system load value Lcurr, the current communication delay value Rlater, and the system device health status value Hdevice, and then substitute them into the calculation formula:
[0091] Etotal represents the total number of log operations within the time window T, Lmax represents the maximum load value allowed by the system, Rmax represents the maximum communication delay value allowed by the system, Hmax represents the maximum health status value when the system equipment is configured, and Dint represents the internal disorder coefficient of the system.
[0092] Anomaly Detection Ratio Indicates the number of abnormal events N detected by the system within the time window T, indicating the abnormal density of the system; log abnormality ratio Indicates the proportion of abnormal events in the system log, which is used to reflect abnormal operations and security risks that may exist during the operation process; load ratio Indicates the ratio of the current system load to the maximum load, indicating the load status of the system. When the load is close to the maximum value, the risk increases; communication delay ratio Indicates the ratio of the current communication delay to the maximum allowed communication delay, which is used to reflect the network communication quality of the system. When the delay increases, the system risk increases; device health ratio Indicates the ratio of the device's health status to its maximum health status. To represent the reverse impact of the equipment health status, that is, the healthier the equipment, the smaller the system disorder coefficient; the unhealthier the equipment, the larger the disorder coefficient.
[0093] If the number of anomaly detections N or the proportion of log anomalies increases, the internal disorder coefficient of the system will increase linearly, because these factors independently increase the instability of the system. When the system load ratio is close to 1, the system operation pressure increases, which may cause more problems and cause the disorder coefficient to rise sharply. The increase in communication delay will reduce the efficiency of data transmission, which will indirectly affect the stability of the system, thereby further amplifying the disorder coefficient through multiplication in the formula. The health status of the device directly affects the operation of the system. When the health status of the device decreases, the disorder coefficient in the formula The term will be amplified and increase the internal turbulence coefficient.
[0094] It should be noted that in order to avoid confusion, the following explanation is given: the number of abnormal events N and the log abnormality ratio Elog are both indicators that reflect abnormal conditions in the system, but their sources and focuses are different. They are used to reflect external threats and internal stability issues of the system respectively:
[0095] The number of abnormal events N is the total number of abnormal events detected in the system. These abnormal events are usually detected by specialized security systems or monitoring systems, such as firewalls, intrusion detection systems (IDS), network security scanning tools, etc. These events may include security events such as network attacks, malware intrusions, abnormal logins, illegal access attempts, etc. The data of N comes from specialized security monitoring tools or anomaly detection systems, such as: Network attack detection: such as DDoS attacks, port scanning, etc. Intrusion detection: such as unauthorized access attempts, user account hijacking, etc. System firewall: records access anomalies and security threats. Host anomalies: hardware or software errors, overloads, process crashes, etc. in the system. Function: The number of abnormal events N directly reflects the intensity of external or internal security threats faced by the system. The increase in the number of such events means that the system is under higher threats or attacks.
[0096] The log exception ratio reflects the proportion of abnormal events in the system operation log. The operation log is a record generated during the operation of the system, containing every detail of the system operation. Log exceptions refer to exceptions or errors that occur during these routine operations. For example, the system log may record file access failures, insufficient permissions, process errors, connection interruptions, etc. The source of log exceptions is the system's daily operation logs, which include records of almost all activities in the system, involving: File system operations: such as file read and write failures. User operations: such as login failures, unauthorized operations, etc. System resource usage: such as CPU overload, insufficient memory, etc. Application exceptions: such as process crashes, abnormal terminations, etc. The log exception ratio mainly reflects the stability issues of the system during daily operations. An increase in operation log exceptions may indicate potential errors or instability within the system, such as frequent file access failures.
[0097] The logic for obtaining the external disorder coefficient is as follows: obtain the behavior parameter combination corresponding to the current behavior pattern of the external user, and at the same time obtain the behavior parameter combination corresponding to the historical behavior pattern of the external user, calculate the cosine similarity of the maximum value between the behavior parameter combination corresponding to the current behavior pattern and the behavior parameter combination corresponding to the historical behavior pattern, and then calculate the user activity pattern anomaly based on the cosine similarity of the maximum value. The sum of the cosine similarity of the user activity pattern anomaly and the maximum value is one; the user activity pattern anomaly indicates the degree of deviation between the user's current behavior and historical behavior. The higher the value, the greater the deviation between the current behavior and the user's regular behavior, and the higher the external risk of the system.
[0098] Get the number of network address changes when external users access the system in the time window T, then calculate the ratio of the number of network address changes to the preset standard allowed change threshold to get the network jump ratio value; the network jump ratio value represents the number of IP address changes (network jumps) when users access the system in a short period of time. The more jumps, it means that the user uses covert means (such as VPN, proxy, etc.), and the greater the external risk of the system.
[0099] Use the external turbulence coefficient calculation formula:
[0100] Dout=ln(1+YC*WT; YC is the user activity pattern anomaly, WT is the network jump ratio, and Dout is the external disorder coefficient. Both the deviation of user behavior and network jump are indicators that reflect external threats, but they reflect different angles. In order to better capture the incremental and cumulative impact of risks, the product and logarithmic transformation are used to combine the impact of the two. By multiplying the user activity pattern anomaly with the network jump ratio, the interaction between the two is captured. Both activity pattern anomalies and network jumps represent potential external risks. The product amplifies the risk when the two occur at the same time. If any one value is higher, the product result will also be larger, reflecting that the external risks faced by the system have increased significantly.
[0101] Logarithmic transformation helps to smooth the data and avoid using the product directly, which may result in a large result. The introduction of logarithms can make the impact of small abnormal behaviors on system risks relatively mild, while serious deviations and multiple jumps will significantly amplify external risks. The 1 in the logarithm is to avoid negative values when the product of the user activity pattern abnormal value and the network jump ratio value is 0, and to ensure that the formula still has basic numerical output even when there is no abnormality.
[0102] Using logarithmic transformation can smooth out the impact of some smaller abnormal behaviors and avoid directly causing large risk values when user behavior or network jump times are small. This is because the logarithmic function grows very slowly when it is close to 1, and grows rapidly when the value is large, which can better capture serious risks. The logarithmic smoothing effect reduces the excessive amplification of the external disorder coefficient when a single factor is high but another factor is low. For example, a simple abnormal user activity pattern or a simple network jump may be sporadic behavior, but the logarithmic transformation reduces the risk accumulation effect when they appear separately.
[0103] Practical application scenario description: When the user's activity pattern is abnormal (such as suddenly logging in from different locations or devices) and the number of network jumps is large (IP addresses change frequently), this formula can be used to capture the rapid increase in external risks. Logarithmic smoothing can ensure that small-scale jumps or anomalies do not lead to an overestimation of system risks. When the system calculates a high external turbulence coefficient value, additional security measures may be triggered, such as the subsequent fuzzy logic judgment module may restrict access rights.
[0104] The working process of the fuzzy logic judgment module is:
[0105] The comprehensive asset value, internal disorder coefficient and external disorder coefficient of the target digital asset are taken as input variables, and the access mode of the target digital asset is taken as the output variable. The input variables are fuzzified and the values of the input variables are converted into fuzzy sets. The output variables are fuzzified and the output variables are converted into fuzzy sets. Fuzzy rules are formulated to describe the access security under different data type combinations. The fuzzified input variables are inferred through fuzzy rules to obtain the access mode of the target digital asset.
[0106] The workflow of the fuzzy logic judgment module is as follows:
[0107] Fuzzification of input variables: The module first takes the comprehensive asset value, internal disorder coefficient and external disorder coefficient of the target digital asset as input variables. Because these values are usually precise values, but fuzzy logic needs to convert these precise values into fuzzy sets. For example, the comprehensive asset value may be between 0 and 1, which can be fuzzified into fuzzy levels such as "low, medium, high", and the internal and external disorder coefficients can also be fuzzified into "stable, unstable" according to the corresponding range.
[0108] Output variable fuzzification: The output variable is the access mode of the target digital asset, which can be fuzzified into several types of operations, such as "allow viewing", "allow editing", "allow downloading", "forbid viewing", "forbid editing", etc. The definition of these access modes is determined based on different combinations of input variables.
[0109] Formulate fuzzy rules: In fuzzy logic reasoning, the system needs fuzzy rules to describe the relationship between input variables and output variables. Each combination of input variables corresponds to a different access mode. For example: If the comprehensive value of assets is "high", the internal disorder coefficient is "stable", and the external disorder coefficient is "low", then "view, edit, and download" are allowed. If the comprehensive value of assets is "low", the internal disorder coefficient is "unstable", and the external disorder coefficient is "high", then "viewing is prohibited". If the comprehensive value of assets is "medium", the internal disorder coefficient is "unstable", and the external disorder coefficient is "medium", then "viewing is allowed, editing and downloading are prohibited". These fuzzy rules are used to describe the access security under different input data combinations.
[0110] Fuzzy reasoning: The fuzzified input variables are reasoned through the formulated fuzzy rules. Through the combination of fuzzy rules, the system will derive the access mode corresponding to the target digital asset and determine the user's authority in the system.
[0111] Defuzzification: Finally, the obtained fuzzy access pattern is defuzzified and converted into clear access rights, such as "allow viewing", "allow editing" or "forbid downloading".
[0112] Fuzzy logic can handle imprecise or ambiguous data information very well, which is different from the precise value judgment of traditional logic. Through fuzzy logic, the system can flexibly adjust the access rights to digital assets according to complex conditions. By comprehensively considering the sensitivity, internal and external risks of assets, the system can dynamically adjust permissions to ensure that access to important data is reduced in high-risk environments and reduce the possibility of data leakage. Fuzzy logic can handle complex multi-input condition combinations very well, especially when multiple influencing factors are involved. It is more comprehensive than simple conditional judgments. The system can fine-tune user access rights based on the attributes, risks and other factors of different digital assets, reduce unnecessary permission exposure, and ensure the overall security and rationality of the system.
[0113] Here is an example of the access mode of the target digital asset:
[0114] Assume that there is a financial statement as the target digital asset, and its variables are as follows: Asset comprehensive value: 0.85, indicating that the asset is very important. Internal chaos coefficient: 0.2, indicating that the internal risk of the system is low. External chaos coefficient: 0.7, indicating that there are certain risks in the external environment, such as potential threats to user access to the device. Based on these values, the system fuzzifies each variable: the asset comprehensive value is fuzzified to "high", the internal chaos coefficient is fuzzified to "stable", and the external chaos coefficient is fuzzified to "medium". According to the fuzzy rules, if the asset comprehensive value is "high", the internal chaos coefficient is "stable", and the external chaos coefficient is "medium", the system will infer that the asset allows "viewing", but prohibits "editing" and "downloading" to ensure data security. Therefore, the access mode of the financial statement will be set to: allow viewing, prohibit editing and downloading.
[0115] The permission management module dynamically adjusts the user's access rights to digital assets based on the output of the fuzzy logic judgment module. This dynamic adjustment mechanism flexibly assigns users whether they can view, edit or download specific digital assets based on the comprehensive risk assessment of digital assets. The purpose of this is to provide the most appropriate permission level while ensuring system security.
[0116] The specific working process of the permission management module: receiving the output of fuzzy logic judgment: the fuzzy logic judgment module obtains the decision result of whether the asset can be viewed, edited or downloaded based on the input asset comprehensive value, internal disorder coefficient and external disorder coefficient after fuzzification processing. The permission management module dynamically adjusts the user's permissions based on this decision result. The permission management module determines the user's operation permissions for specific assets based on the output of the fuzzy logic judgment module. The user's access rights may be different for different assets or the same asset under different risk conditions.
[0117] View permissions: Allow users to view the content of a digital asset, but not edit or download it.
[0118] Edit permissions: Allow users to make modifications to digital assets, but may restrict downloading.
[0119] Download permission: Allows users to download digital assets to their local computer.
[0120] When the system detects changes in the environment (such as an increase in external access risk or a decrease in internal system stability), the fuzzy logic judgment module will recalculate the risk, and the permission management module will automatically adjust the permissions based on the new judgment results. For example, a user originally had edit and download permissions for an asset, but when external risks increase, the permission management module will adjust the user's permissions to view only, or even completely prohibit access.
[0121] Example: Example 1: Assume that there is a company financial report in the system, which is a sensitive asset with high importance, stable internal environment and medium risk of external user access. Asset comprehensive value: 0.9 (the asset is very important); internal disorder coefficient: 0.2 (the system internal environment is relatively stable); external disorder coefficient: 0.6 (the external user access risk is high); after fuzzy logic judgment, the system decides to allow the user to view the financial report because the asset is of high importance and the system is stable internally. Due to the high external risk, the user is prohibited from editing the asset and downloading the asset to prevent sensitive data leakage.
[0122] Example 2: Assume there is an internal meeting record with low importance, stable system internal environment, and high external user risk. Asset comprehensive value: 0.3 (low asset importance), internal disorder coefficient: 0.1 (very stable system internal environment), external disorder coefficient: 0.8 (high external user risk). After fuzzy logic judgment, the system decides to allow viewing of the record, prohibit editing, and prohibit downloading of the record due to high external risk.
[0123] Embodiment 2: A digital asset management system based on a database also includes a data backup module for periodically backing up all digital assets. The main functions of the data backup module are:
[0124] Automatic regular backup: The system will automatically back up all digital assets in the database according to the preset time interval. The backup can be daily, weekly or monthly, and the specific time interval can be configured according to business needs.
[0125] Incremental backup and full backup: Incremental backup: only back up the data that has changed since the last backup, reducing storage space and speeding up backup.
[0126] Full backup: Perform a full backup regularly to save a complete copy of all digital assets.
[0127] Backup and recovery mechanism: Once data corruption, loss or other system failures occur, the data backup module can support rapid data recovery and restore digital assets to the most recent backup status.
[0128] Data backup process: Data scanning: The system regularly scans digital assets in the database to find recently changed or newly added assets. Data backup execution: According to the preset strategy (full or incremental), the system backs up the data to a secure storage location (such as cloud storage or local backup server). Backup status report: After the backup is completed, the system will generate a backup log to record the status, time and success of the backup.
[0129] Regular backup ensures that even when the system encounters an unexpected situation (such as hardware failure or network attack), data can be restored through backup to reduce losses. After a failure, data can be quickly restored from backup to ensure business continuity.
[0130] When the present invention is used, all the information of digital assets is stored in a database, the asset analysis module is used to extract the asset metadata of the digital assets in the database, and a classification operation is performed according to a preset classification standard, and an asset analysis is performed based on the result of the classification operation to generate the asset comprehensive value of the target digital asset;
[0131] Use the internal monitoring module to monitor the security operation information within the system, perform internal environment analysis, and generate an internal disorder coefficient; at the same time, use the external monitoring module to collect request verification information from external users, perform external environment analysis, and generate an external disorder coefficient;
[0132] Based on the comprehensive value of assets, internal disorder coefficient and external disorder coefficient, the fuzzy logic judgment module uses fuzzy logic rules to determine whether digital assets are allowed to be viewed, edited or downloaded. Finally, based on the output of the fuzzy logic judgment module, the permission management module is used to dynamically allocate users' permissions to digital assets in the database.
[0133] The above formulas are all dimensionless and numerical calculations. The formula is a formula for the most recent real situation obtained by collecting a large amount of data and performing software simulation. The preset parameters in the formula are set by technicians in this field according to actual conditions.
[0134] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0135] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0136] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0137] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A digital asset development and management system based on a database, characterized in that: Including database, asset analysis module, internal monitoring module, external monitoring module, fuzzy judgment module, and authority management module; The database contains all the information of digital assets; The asset analysis module extracts the asset metadata of the digital assets in the database, and performs classification operations according to the preset classification standards, performs asset analysis based on the results of the classification operations, and generates the comprehensive asset value of the target digital assets; The internal monitoring module monitors the safety operation information inside the system, performs internal environment analysis, and generates an internal disorder coefficient; The external monitoring module collects the request verification information of external users, analyzes the external environment, and generates the external disorder coefficient; The fuzzy logic judgment module uses fuzzy logic rules based on the comprehensive value of the asset, the internal disorder coefficient and the external disorder coefficient to judge whether the digital asset is allowed to be viewed, edited or downloaded; The authority management module dynamically allocates user authority over digital assets in the database based on the output of the fuzzy logic judgment module.
2. A database-based digital asset development and management system according to claim 1, characterized in that: It also includes a data backup module for regularly backing up all digital assets.
3. A database-based digital asset development and management system according to claim 2, characterized in that: Classification operations refer to: According to the category to which the target asset metadata belongs, an asset type and a role type are assigned to it according to the preset classification standards. Each role type corresponds to an importance value, and each asset type corresponds to a classification value. All importance values and classification values range from 0 to 1, and the sum of the classification values corresponding to all asset types is one.
4. A database-based digital asset development and management system according to claim 3, characterized in that: Based on the results of the classification operation, asset analysis is performed to generate the comprehensive asset value of the target digital asset, which refers to: Obtain the importance value corresponding to the target digital asset and mark it as I, and the sensitivity value corresponding to the target digital asset and mark it as C. Then, in the preset time window, count the historical usage records of the target digital asset in the system to determine its usage frequency score F. The usage frequency score F is calculated by dividing the number of times used in the preset time window by the number of times all digital assets are used in the preset time window. The output result is obtained from the pre-trained feature extraction model and marked as privacy sensitivity S. Finally, the historical number of leaks of the target digital asset is obtained and marked as L, and then substituted into the following calculation formula: As=C*(w1*I+w2*F+w3*S 2 +w4*L); w1, w2, w3 and w4 are all preset influence coefficients and are not zero, and As represents the comprehensive asset value of the target digital asset.
5. A database-based digital asset development and management system according to claim 4, characterized in that: The steps for using the feature extraction model are: Step 1: Perform word segmentation, text feature extraction, and vocabulary matching on text assets, and use image or video recognition technology to perform object detection or content recognition on non-text assets; Step 2: Input all processed assets into the pre-trained deep learning model to obtain their respective sensitivity scores; Step 3: Perform weighted summation of all sensitivity scores to obtain the privacy sensitivity S, where the weight value of each depends on the content type corresponding to the sensitivity score.
6. A database-based digital asset development and management system according to claim 5, characterized in that: The logic for obtaining the internal turbulence coefficient is: In the set time window T, obtain the number of abnormal events N detected by the system in the time window T, the number of abnormalities in the log operation Elog, the current system load value Lcurr, the current communication delay value Rlater, and the system device health status value Hdevice, and then substitute them into the calculation formula: Etotal represents the total number of log operations within the time window T, Lmax represents the maximum load value allowed by the system, Rmax represents the maximum communication delay value allowed by the system, Hmax represents the maximum health status value when the system equipment is configured, and Dint represents the internal disorder coefficient of the system.
7. A database-based digital asset development and management system according to claim 6, characterized in that: The logic for obtaining the external turbulence coefficient is: Obtaining a behavior parameter combination corresponding to the current behavior pattern of the external user, and obtaining a behavior parameter combination corresponding to the historical behavior pattern of the external user, calculating the cosine similarity of the maximum value between the behavior parameter combination corresponding to the current behavior pattern and the behavior parameter combination corresponding to the historical behavior pattern, and then calculating the user activity pattern anomaly based on the cosine similarity of the maximum value, the sum of the cosine similarity of the user activity pattern anomaly and the maximum value is one; Obtain the number of network address changes when external users access the system in the time window T, and then calculate the ratio of the number of network address changes to the preset standard allowed change threshold to obtain the network jump ratio value; Use the external turbulence coefficient calculation formula: Dout=ln(1+YC*WT); YC is the abnormal value of the user activity pattern, WT is the network jump ratio value, and Dout is the external disorder coefficient.
8. A database-based digital asset development and management system according to claim 7, characterized in that: The working process of the fuzzy logic judgment module is: The comprehensive asset value, internal disorder coefficient and external disorder coefficient of the target digital asset are taken as input variables, and the access mode of the target digital asset is taken as the output variable. The input variables are fuzzified and the values of the input variables are converted into fuzzy sets. The output variables are fuzzified and the output variables are converted into fuzzy sets. Fuzzy rules are formulated to describe the access security under different data type combinations. The fuzzified input variables are inferred through fuzzy rules to obtain the access mode of the target digital asset.