Data security system based on data classification and grading

By introducing data classification and grading and dynamic security policy processing in the data security system, the problem that traditional encryption methods cannot perform differentiated processing based on data sensitivity and importance is solved, and the effects of high data security, higher system flexibility and efficiency are achieved.

CN120046184APending Publication Date: 2025-05-27CHINACCS INFORMATION IND
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510088049.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

Traditional encryption methods adopt a unified encryption strategy and cannot be differentiated according to the sensitivity and importance of data, making it difficult to ensure data security while taking into account the efficiency and flexibility of the system.

Method used

Provide a data security system based on data classification and grading, including system security components, static data security components, dynamic data security components, data transmission security components and data security governance components. Through the collaborative work of these components, dynamic encryption, decryption and desensitization are carried out according to data classification and grading and security policies.

Benefits of technology

It improves the security of data during storage and transmission, enhances the flexibility and processing efficiency of the system, effectively prevents external network attacks and data leakage, and reduces the waste of computing resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046184A_ABST
    Figure CN120046184A_ABST
Patent Text Reader

Abstract

The invention provides a data security system based on data classification and grading, which relates to the technical field of data security and comprises a system security component, a static data security component, a dynamic data security component, a data transmission security component and a data security governance component, the system security component is used for checking and filtering network requests and defending external network attacks; the static data security component is used for configuring entity and field security policies and performing security processing on data; the dynamic data security component is used for performing security processing on the data according to the classification level configured by the data security governance component and a corresponding security policy; the data transmission security component is used for performing security processing on the data according to the transmission strategy configured by the data security governance component; and the data security governance component is used for classifying and grading the data according to the classification and grading strategy and configuring a security strategy and a transmission strategy. The method has the beneficial effects that the security of data during storage and transmission is improved, the system flexibility is high, and the efficiency is high.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and particularly to a data security system based on data classification and grading. Background Art

[0002] With the rapid development of information technology, data has become the core asset of enterprises and organizations. However, data leakage and illegal access have become serious data security threats. Traditional encryption methods often adopt a unified encryption strategy, which cannot perform differential processing according to the sensitivity and importance of data, making it difficult to balance the efficiency and flexibility of the system while ensuring data security.

[0003] How to solve the above technical problems is the subject faced by the present invention. Summary of the Invention

[0004] In order to solve the deficiencies of the prior art, the present invention provides a data security system based on data classification and grading, which improves the security of data during storage and transmission, and has high system flexibility and efficiency.

[0005] The technical solution adopted by the present invention to solve its technical problems is: the present invention provides a data security system based on data classification and grading, including a system security component, a static data security component, a dynamic data security component, a data transmission security component, and a data security governance component;

[0006] The system security component is used to check and filter all network requests entering the system to defend against external network attacks;

[0007] The static data security component is used to configure security policies for entities and entity fields, and perform security processing on data according to the security policies when saving or updating in the database and reading data from the database;

[0008] The dynamic data security component is used to perform security processing on data according to the classification and grading configured by the data security governance component and the corresponding security policies when saving or updating in the database and reading data from the database;

[0009] The data transmission security component includes a client data transmission security component and a server data transmission security component, and is used to perform security processing on the transmitted data according to the transmission policy configured by the data security governance component;

[0010] The data security governance component includes a data classification and grading module, a basic configuration module, and a transmission policy module, and is used to classify and grade data and configure security policies and transmission policies.

[0011] Preferably, the system security component is used to check and filter all network requests entering the system to defend against external network attacks. Specifically, the system security component first intercepts all network requests entering the system through a filter mechanism and parses the request content, including the URL, request header, and request body; then, according to preset security rules, the request content is matched and checked, and when attack features are detected, corresponding defense strategies are adopted according to the attack type.

[0012] Preferably, the attack types include injection attacks, CSRF cross-site request forgery attacks, XSS cross-site scripting attacks, and cross-site file inclusion (XFI) attacks;

[0013] The defense strategy for the attack type specifically includes anti-injection attack: strict verification and filtering of user input to ensure the legitimacy and security of input data;

[0014] Prevent CSRF (cross-site request forgery) attacks: Check the Referer field in the request header to ensure the legitimacy of the request source;

[0015] Anti-XSS cross-site scripting attack: HTML entity encoding or JavaScript escape of user input to prevent the execution of malicious scripts;

[0016] Prevent cross-site file inclusion (XFI) attacks: strictly limit the paths and types of files included to avoid including malicious files.

[0017] Preferably, when the static data security component saves or updates the database, the security processing of the data specifically includes the following steps:

[0018] S1. Before a database entity is saved or updated to the database, a monitoring mechanism is set up to pre-process the entity to be operated;

[0019] S2. For the entity instance captured by the monitoring script, the system will traverse the entity and all its parent structures to check whether they carry the @EncryptBeanAnno annotation;

[0020] S3. After checking, if the entity and all its parent structures do not carry the @EncryptBeanAnno annotation, it means that the entity does not need to be encrypted and can directly perform normal database storage or update operations; if the entity or its parent structure carries the @EncryptBeanAnno annotation, further in-depth processing will be carried out. The system will traverse the fields of the entity and all its parent structures, and check whether these fields carry the @EncryptPropertyAnno annotation one by one;

[0021] S4. For fields without the @EncryptPropertyAnno annotation, the system will keep their data as it is without any encryption. For fields with the @EncryptPropertyAnno annotation, the system will perform corresponding encryption on the data values in the fields according to the encryption algorithm specified in the annotation and in combination with the preset key information in the configuration file.

[0022] When the static data security component reads data from the database, the security processing of the data specifically includes the following steps:

[0023] S1. After reading the database entity, set up a listening mechanism to preprocess the entity to be operated on.

[0024] S2. For the database entity captured by the listening script, the system will traverse the entity and all its parent structures to check whether they carry the @EncryptBeanAnno annotation or the @MaskBeanAnno annotation.

[0025] S3. After inspection, if neither the entity nor all its parent structures carry the @EncryptBeanAnno annotation or the @MaskBeanAnno annotation, it indicates that the entity does not require data decryption or desensitization processing.

[0026] S4. If the entity or its parent carries the @EncryptBeanAnno annotation, further in-depth processing will be carried out. The system will traverse the fields in the entity itself and all its parents and check one by one whether these fields carry the @EncryptPropertyAnno annotation.

[0027] S5. For fields without the @EncryptPropertyAnno annotation, the system will keep their data as it is without any decryption. For fields with the @EncryptPropertyAnno annotation, the system will perform corresponding decryption on the data values in the fields according to the decryption algorithm specified in the annotation and in combination with the preset key information in the configuration file.

[0028] S6. If the entity or its parent carries the @MaskBeanAnno annotation, further in-depth processing will be carried out. The system will traverse the fields in the entity itself and all its parents and check one by one whether these fields carry the @DataMasking annotation.

[0029] S7. For fields without the @DataMasking annotation, the system will keep their data unchanged without any desensitization processing; for fields with the @DataMasking annotation, the system will perform corresponding desensitization processing on the data values in the fields according to the decryption rules specified in the annotation.

[0030] Preferably, when the dynamic data security component saves or updates data in the database, the security processing of the data specifically includes the following steps:

[0031] S1. Cache the database classification and grading and the corresponding security policies;

[0032] S2. Before the data is stored in the database, traverse all fields, search for the database, tables, and fields, and check whether the fields are configured with classification and grading and the corresponding security policies;

[0033] S3. If the fields are not configured with classification and grading and the corresponding security policies, no encryption processing will be performed on the data; if the fields are configured with classification and grading and the corresponding security policies, the data will be encrypted according to the encryption algorithm and key information specified in the corresponding security policies.

[0034] When the dynamic data security component reads data from the database, the security processing of the data specifically includes the following steps:

[0035] S1. Cache the database classification and grading and the corresponding security policies;

[0036] S2. After retrieving the data from the database, traverse all fields, search for the database, tables, and fields, and check whether the fields are configured with classification and grading and the corresponding security policies;

[0037] S3. If the fields are not configured with classification and grading and the corresponding security policies, no decryption or desensitization processing will be performed on the data; if the fields are configured with classification and grading and the corresponding security policies, the data will be decrypted and desensitized according to the decryption algorithm, key information, and desensitization rules specified in the corresponding security policies.

[0038] Preferably, the specific process of the data transmission security component for security processing of transmitted data is as follows: For each request data of the client, it needs to pass through the client data transmission security component. The client data transmission security component reads the transmission policy from the server and decides whether to encrypt and sign the requested data according to the transmission policy;

[0039] The server data transmission security component reads the transmission policy from the data security governance system. When the requested data arrives at the server, the server data transmission security component determines whether to decrypt and verify the signature of the data according to the transmission policy, and then delivers the requested data to the server for response.

[0040] Preferably, the data classification and grading module includes a data source management module and a field classification and grading module. The data source management module loads different database drivers according to the data source type and configures the relevant parameter information of the data source to achieve connection with the database. The field classification and grading module is used to query databases, tables, and fields under the data source and classify and grade the fields according to the classification and grading strategy. The user sets a suitable classification and grading strategy by referring to the national standard of data classification and grading rules and combining with the actual business requirements.

[0041] Preferably, the basic configuration module includes an algorithm configuration module, a key management module, and a desensitization module. The algorithm configuration module is used to manage and configure various algorithms used in the system. The key management module is responsible for the generation, storage, and distribution of keys. The desensitization module is responsible for converting sensitive data into non-sensitive data and formulating a suitable desensitization strategy according to the data type and sensitivity level.

[0042] Preferably, the transmission strategy specifically includes the encryption method of transmission encryption and decryption, the encryption method of digital envelopes, information digest, and signature mechanism.

[0043] Preferably, the data security control system provides dynamic configuration of classification and grading, security policies, and transmission policies for multiple dynamic data security components and data transmission security components. After the business system integrates the server-side data transmission security component and the dynamic data security component, it obtains the configuration information through these two components.

[0044] The beneficial effects of the present invention are as follows: The data has high security during storage and transmission. The system can select appropriate security components for security processing according to business requirements, with higher flexibility and processing efficiency, and can effectively save computing resources. The system security components are set up. By means of the filter mechanism, network requests are inspected, filtered and combined with defense strategies, which can effectively prevent external network attacks, improve the security of the system, and reduce the risk of data leakage. The static data security component and the dynamic data security component are set up. The static data security component directly writes the security policy into the code, which is simple to access and convenient to deploy, reducing the time for reading the security policy from the configuration file additionally, effectively reducing latency and improving system efficiency. The dynamic data security component can dynamically adjust the security policy according to real-time situations, improving the flexibility of the system. The basic configuration module is set up to centrally manage encryption algorithms, key management and desensitization strategies, simplifying the complex security policy configuration process. At the same time, the data is classified and graded, and corresponding security policies are configured according to the classification and grading results, enabling enterprises to reasonably adjust security policies according to their own business requirements, etc., so as to utilize computing resources more efficiently and reduce waste of computing resources. The signature mechanism is set in the transmission policy, so that when the client and the server perform data transmission, the corresponding configuration can be dynamically obtained, effectively preventing the data from being tampered with or stolen during transmission, and enhancing the security of the data. In addition, the data security governance component of the present invention can provide dynamic configuration of classification and grading, security policies and transmission policies for multiple dynamic data security components and data transmission security components, enabling various business systems to share security resources on the same platform, improving the efficiency of system integration, and also allowing each business system to perform personalized configuration according to its own characteristics, enhancing the adaptability of the overall system. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 is the system architecture diagram of the present invention.

[0046] Figure 2 is the security processing flow chart when the static data security component of the present invention saves or updates in the database.

[0047] Figure 3 is the security processing flow chart when the static data security component of the present invention reads data from the database.

[0048] Figure 4 is the security processing flow chart when the dynamic data security component of the present invention saves or updates in the database.

[0049] Figure 5 is the security processing flow chart when the dynamic data security component of the present invention reads data from the database. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0050] To clearly illustrate the technical features of this solution, the following will elaborate on this solution through specific implementation manners.

[0051] See Figures 1 to 5 As shown, this embodiment is a data security system based on data classification and grading, including a system security component, a static data security component, a dynamic data security component, a data transmission security component, and a data security governance component;

[0052] The system security component is used to check and filter all network requests entering the system to defend against external network attacks. Specifically: The system security component first intercepts all network requests entering the system through a filter mechanism, parses the request content, including the URL, request headers, and request body; then, according to preset security rules, it performs a matching check on the request content. When an attack feature is detected, corresponding defense strategies are adopted according to the attack type.

[0053] The attack types include injection attacks, CSRF cross-site request forgery attacks, XSS cross-site scripting attacks, and cross-site file inclusion (XFI) attacks;

[0054] The defense strategies for the attack types specifically include anti-injection attack: strictly verifying and filtering user input to ensure the legality and security of the input data;

[0055] Anti-CSRF cross-site request forgery attack: checking the Referer field in the request headers to ensure the legality of the request source;

[0056] Anti-XSS cross-site scripting attack: performing HTML entity encoding or JavaScript escaping on user input to prevent the execution of malicious scripts;

[0057] Anti-cross-site file inclusion (XFI) attack: strictly restricting the paths and types of file inclusions to avoid including malicious files.

[0058] The static data security component is used for configuring entity and entity field security policies, and when saving or updating in the database and reading database data, it performs security processing on the data according to the security policies;

[0059] When the static data security component saves or updates in the database, the security processing of the data specifically includes the following steps:

[0060] S1. Before saving or updating the database entity to the database, set up a listening mechanism to preprocess the entity to be operated on;

[0061] S2. For the entity instance captured by the listening script, the system will traverse the entity and all its parent structures to check whether they carry the @EncryptBeanAnno annotation;

[0062] S3. After inspection, if the entity and all its parent structures do not carry the @EncryptBeanAnno annotation, it indicates that the entity does not need to perform data encryption, and the normal database storage or update operation is directly executed; if the entity or its parent structure carries the @EncryptBeanAnno annotation, further in-depth processing is required. The system will traverse the fields in the entity itself and all its parent structures, and check one by one whether these fields carry the @EncryptPropertyAnno annotation;

[0063] S4. For fields that do not carry the @EncryptPropertyAnno annotation, the system will keep their data unchanged and not perform any encryption processing; for fields that carry the @EncryptPropertyAnno annotation, the system will perform corresponding encryption processing on the data values in the fields according to the encryption algorithm specified in the annotation and in combination with the preset key information in the configuration file;

[0064] When the static data security component reads the database data, the security processing of the data specifically includes the following steps:

[0065] S1. After reading the database entity, set a listening mechanism to preprocess the entity to be operated on;

[0066] S2. For the database entity captured by the listening script, the system will traverse the entity and all its parent structures to check whether they carry the @EncryptBeanAnno annotation or the @MaskBeanAnno annotation;

[0067] S3. After inspection, if the entity and all its parent structures do not carry the @EncryptBeanAnno annotation or the @MaskBeanAnno annotation, it indicates that the entity does not need to perform data decryption or desensitization processing;

[0068] S4. If the entity or its parent carries the @EncryptBeanAnno annotation, further in-depth processing is required. The system will traverse the fields in the entity itself and all its parents, and check one by one whether these fields carry the @EncryptPropertyAnno annotation;

[0069] S5. For fields that do not carry the @EncryptPropertyAnno annotation, the system will keep their data unchanged and not perform any decryption processing; for fields that carry the @EncryptPropertyAnno annotation, the system will perform corresponding decryption processing on the data values in the fields according to the decryption algorithm specified in the annotation and in combination with the preset key information in the configuration file;

[0070] S6. If the entity or its parent carries the @MaskBeanAnno annotation, further in-depth processing will be carried out. The system will traverse the fields in this entity level and all its parents, and check one by one whether these fields carry the @DataMasking annotation;

[0071] S7. For fields that do not carry the @DataMasking annotation, the system will keep their data as it is without any desensitization processing; for fields that carry the @DataMasking annotation, the system will perform corresponding desensitization processing on the data values in the fields according to the decryption rules specified in this annotation.

[0072] The dynamic data security component is used to perform security processing on data according to the classification and grading configured by the data security governance component and the corresponding security policies when saving or updating the database and reading database data;

[0073] When the dynamic data security component saves or updates the database, the specific steps for performing security processing on the data are as follows:

[0074] S1. Cache the database classification and grading and the corresponding security policies;

[0075] S2. Before the database entry, traverse all fields, search for the database, table, and fields, and check whether the fields are configured with classification and grading and the corresponding security policies;

[0076] S3. If the fields are not configured with classification and grading and the corresponding security policies, no encryption processing will be performed on the data; if the fields are configured with classification and grading and the corresponding security policies, the data will be encrypted according to the encryption algorithm and key information specified in the corresponding security policies.

[0077] When the dynamic data security component reads database data, the specific steps for performing security processing on the data are as follows:

[0078] S1. Cache the database classification and grading and the corresponding security policies;

[0079] S2. After retrieving the data from the database, traverse all fields, search for the database, table, and fields, and check whether the fields are configured with classification and grading and the corresponding security policies;

[0080] S3. If the fields are not configured with classification and grading and the corresponding security policies, no decryption or desensitization processing will be performed on the data; if the fields are configured with classification and grading and the corresponding security policies, the data will be decrypted and desensitized according to the decryption algorithm, key information, and desensitization rules specified in the corresponding security policies.

[0081] The data transmission security component includes a client - side data transmission security component and a server - side data transmission security component, which are used to perform security processing on the transmitted data according to the transmission policies configured by the data security governance component;

[0082] The specific process of the data transmission security component for performing security processing on the transmitted data is as follows: For each piece of data requested by the client, it needs to pass through the client - side data transmission security component. The client - side data transmission security component reads the transmission policy from the server and decides whether to encrypt and sign the requested data according to the transmission policy;

[0083] The server - side data transmission security component reads the transmission policy from the data security governance system. When the requested data arrives at the server, the server - side data transmission security component determines whether to decrypt and verify the signature of the data according to the transmission policy, and then delivers the requested data to the server for response.

[0084] The data security governance component includes a data classification and grading module, a basic configuration module, and a transmission policy module, which are used to classify and grade data and configure security policies and transmission policies.

[0085] The data classification and grading module includes a data source management module and a field classification and grading module. The data source management module loads different database drivers according to the data source type and configures relevant parameter information of the data source to achieve connection with the database; The field classification and grading module is used to query databases, tables, and fields under the data source and classify and grade the fields according to the classification and grading policy. Users refer to the national standard of data classification and grading rules and set appropriate classification and grading policies in combination with the actual business requirements.

[0086] The basic configuration module includes an algorithm configuration module, a key management module, and a data masking module. The algorithm configuration module is used to manage and configure various algorithms used in the system; The key management module is responsible for key generation, storage, and distribution; The data masking module is responsible for converting sensitive data into non - sensitive data and formulating appropriate data masking strategies according to the data type and sensitivity level.

[0087] The transmission policy specifically includes the encryption method of transmission encryption and decryption, the encryption method of digital envelopes, message digest, and signature mechanism.

[0088] The data security governance component provides dynamic configuration of classification and grading, security policies, and transmission policies for multiple dynamic data security components and data transmission security components. After the business system integrates the server - side data transmission security component and the dynamic data security component, it obtains the configuration information through these two components.

[0089] The technical features not described in the present invention can be achieved by or adopted from the prior art, and will not be elaborated herein. Of course, the above description is not a limitation of the present invention, and the present invention is not limited to the above examples. Changes, modifications, additions or substitutions made by those of ordinary skill in the art within the scope of the essence of the present invention should also fall within the protection scope of the present invention.

Claims

1. A data security system based on data classification and grading, characterized in that: Including system security components, static data security components, dynamic data security components, data transmission security components and data security governance components; The system security component is used to check and filter all network requests entering the system to defend against external network attacks; The static data security component is used to configure the security policy of entities and entity fields, and to perform security processing on the data according to the security policy when saving, updating or reading database data in the database; When the dynamic data security component is used to save or update or read database data, the data is securely processed according to the classification and grading configured by the data security governance component and the corresponding security policy; The data transmission security component includes a client data transmission security component and a server data transmission security component, which are used to perform security processing on the transmission data according to the transmission policy configured by the data security governance component; The data security governance component includes a data classification and grading module, a basic configuration module and a transmission policy module, which are used to classify and grade data and configure security policies and transmission policies.

2. The data security system based on data classification and grading according to claim 1 is characterized in that: The system security component is used to check and filter all network requests entering the system to defend against external network attacks. Specifically, the system security component first intercepts all network requests entering the system through a filter mechanism and parses the request content, including the URL, request header, and request body; then, according to preset security rules, the request content is matched and checked. When attack features are detected, corresponding defense strategies are adopted according to the attack type.

3. The data security system based on data classification and grading according to claim 2 is characterized in that: The attack types include injection attacks, CSRF cross-site request forgery attacks, XSS cross-site scripting attacks, and cross-site file inclusion (XFI) attacks; The defense strategy for the attack type specifically includes anti-injection attack: strict verification and filtering of user input to ensure the legitimacy and security of input data; Prevent CSRF (cross-site request forgery) attacks: Check the Referer field in the request header to ensure the legitimacy of the request source; Anti-XSS cross-site scripting attack: HTML entity encoding or JavaScript escape of user input to prevent the execution of malicious scripts; Prevent cross-site file inclusion (XFI) attacks: strictly limit the paths and types of files included to avoid including malicious files.

4. The data security system based on data classification and grading according to claim 1 is characterized in that: When the static data security component saves or updates the database, the security processing of the data specifically includes the following steps: S1. Before a database entity is saved or updated to the database, a monitoring mechanism is set up to pre-process the entity to be operated; S2. For the entity instance captured by the monitoring script, the system will traverse the entity and all its parent structures to check whether they carry the @EncryptBeanAnno annotation; S3. After checking, if the entity and all its parent structures do not carry the @EncryptBeanAnno annotation, it means that the entity does not need to be encrypted and can directly perform normal database storage or update operations; if the entity or its parent structure carries the @EncryptBeanAnno annotation, further in-depth processing will be carried out. The system will traverse the fields of the entity and all its parent structures, and check whether these fields carry the @EncryptPropertyAnno annotation one by one; S4. For fields without @EncryptPropertyAnno annotation, the system will keep the data as it is without any encryption processing; for fields with @EncryptPropertyAnno annotation, the system will perform corresponding encryption processing on the data value in the field according to the encryption algorithm specified in the annotation and the key information preset in the configuration file; When the static data security component reads the database data, the data security processing specifically includes the following steps: S1. After reading the database entity, set up a monitoring mechanism to pre-process the entity to be operated; S2. For the database entity captured by the monitoring script, the system will traverse the entity and all its parent structures to check whether they carry the @EncryptBeanAnno annotation or the @MaskBeanAnno annotation; S3. Upon inspection, if the entity and all its parent structures do not carry the @EncryptBeanAnno annotation or the @MaskBeanAnno annotation, it indicates that the entity does not need data decryption or desensitization processing; S4. If the entity or its parent carries the @EncryptBeanAnno annotation, the system will further process the fields of the entity and all its parents, and check whether these fields carry the @EncryptPropertyAnno annotation one by one; S5. For fields without @EncryptPropertyAnno annotation, the system will keep the data as it is without any decryption processing; for fields with @EncryptPropertyAnno annotation, the system will perform corresponding decryption processing on the data value in the field according to the decryption algorithm specified in the annotation and the key information preset in the configuration file; S6. If the entity or its parent carries the @MaskBeanAnno annotation, the system will further process the fields of the entity and all its parents, and check whether these fields carry the @DataMasking annotation one by one; S7. For fields without the @DataMasking annotation, the system will keep the data as it is without any desensitization processing; for fields with the @DataMasking annotation, the system will perform corresponding desensitization processing on the data value in the field according to the desensitization rules specified in the annotation.

5. The data security system based on data classification and grading according to claim 1 is characterized in that: When the dynamic data security component is saved or updated in the database, the security processing of the data specifically includes the following steps: S1. Classification and grading of cache databases and corresponding security policies; S2. Before the database is stored, all fields are traversed to find the database, table, and field to check whether the fields are configured with classification and corresponding security policies; S3. If the field is not configured with classification and grading and the corresponding security policy, the data will not be encrypted; if the field is configured with classification and grading and the corresponding security policy, the data will be encrypted according to the encryption algorithm and key information specified in the corresponding security policy; When the dynamic data security component reads the database data, the data security processing specifically includes the following steps: S1. Classification and grading of cache databases and corresponding security policies; S2. After retrieving data from the database, traverse all fields, search for databases, tables, and fields, and check whether the fields are configured with classification and corresponding security policies; S3. If the field is not configured with classification and grading and the corresponding security policy, the data will not be decrypted or desensitized; if the field is configured with classification and grading and the corresponding security policy, the data will be decrypted and desensitized according to the decryption algorithm, key information and desensitization rules specified in the corresponding security policy.

6. The data security system based on data classification and grading according to claim 1 is characterized in that: The specific process of the data transmission security component for securely processing the transmitted data is as follows: each time the data requested by the client needs to pass through the client data transmission security component, the client data transmission security component reads the transmission policy from the server, and decides whether to encrypt and sign the requested data according to the transmission policy; The server-side data transmission security component reads the transmission policy from the data security management system. When the requested data reaches the server, the server-side data transmission security component determines whether the data needs to be decrypted and signed based on the transmission policy, and then hands the requested data to the server for response.

7. The data security system based on data classification and grading according to claim 1 is characterized in that: The data classification and grading module includes a data source management module and a field classification and grading module. The data source management module loads different database drivers according to the data source type, and configures the data source related parameter information to achieve connection with the database; the field classification and grading module is used to query the database, table, and field under the data source, and classify and grade the fields according to the classification and grading strategy.

8. The data security system based on data classification and grading according to claim 1 is characterized in that: The basic configuration module includes an algorithm configuration module, a key management module and a desensitization module. The algorithm configuration module is used to manage and configure various algorithms used in the system; the key management module is responsible for the generation, storage and distribution of keys; The desensitization module is responsible for converting sensitive data into non-sensitive data and formulating appropriate desensitization strategies based on the data type and sensitivity.

9. The data security system based on data classification and grading according to claim 1 is characterized in that: The transmission strategy specifically includes the encryption method of transmission encryption and decryption, the encryption method of the digital envelope, the information summary and the signature mechanism.

10. The data security system based on data classification and grading according to claim 1, characterized in that: The data security governance component provides classification and grading, dynamic configuration of security policies and transmission policies for multiple dynamic data security components and data transmission security components. After the business system integrates the server-side data transmission security component and the dynamic data security component, it obtains configuration information through these two components.