Data security protection method and system based on big data

By combining data access historical big data, the degree of access threat of data units is analyzed and the importance of data units is sorted, and data splitting and interactive storage is performed, the problem of high cost of existing data security protection measures is solved, and the effect of effectively protecting data without increasing significant costs is achieved.

CN120046201AActive Publication Date: 2025-05-27BEIJING CHINASOFT LINKAGE TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510123377.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-26
Publication Date
2025-05-27
Estimated Expiration
2045-01-26

AI Technical Summary

Technical Problem

Existing data security protection measures are costly and it is difficult to effectively protect data without significantly increasing costs, especially when establishing a security protection network in depth.

Method used

By combining historical big data accessed by data, comprehensively analyze the access threat level of different data units, determine their importance, and perform data splitting and interactive storage according to their importance to reduce the risk of data loss and corruption.

Benefits of technology

Without significantly increasing costs, this method effectively avoids overall data loss and corruption after data units are threatened by access, ensures data stability, and fully ensures storage security and stability after data interaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046201A_ABST
    Figure CN120046201A_ABST
Patent Text Reader

Abstract

The invention provides a data security protection method and system based on big data, and relates to the technical field of data security protection. The method comprises the following steps: acquiring historical access data of different data units, and performing security level analysis of access threats to form data access security level information; performing interaction matching of the data units according to the data access security level information to form data interaction matching information; and according to the data interaction matching information, performing splitting matching processing on the data unit to form interaction matching data. According to the method, the data is reasonably split and interactively stored, so that the safety protection of the data can be simply, conveniently and quickly realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security protection, and in particular, to a data security protection method and system based on big data. Background Art

[0002] With the progress of science, the degree of social informatization is getting higher and higher. Along with this, a large amount of data information needs to be reasonably processed, analyzed, stored, etc., and at the same time, data needs to be transmitted and interacted. In the process of performing these series of operations on data, considering that the information carried by the data is targeted, it is necessary to reasonably protect the data.

[0003] Currently, data security has attracted more and more attention from people, and many methods have been proposed for the protection measures taken for data security. Basically, security barriers such as firewalls are established for the access that poses a threat to the data. This method improves the security of data application to a certain extent, but the cost generated by taking these measures is relatively large, especially when deeply establishing a security protection network. If it is possible to perform a certain degree of security protection processing on the data itself while establishing a certain degree of security protection, it can effectively protect the data without significantly increasing the cost.

[0004] Therefore, designing a data security protection method and system based on big data, which can simply and quickly achieve data security protection by reasonably splitting and interactively storing the data itself, is an urgent problem to be solved at present. Summary of the Invention

[0005] The purpose of the present invention is to provide a data security protection method based on big data. By comprehensively analyzing the degree of access threat of different data units in combination with the historical big data of data access, the importance degree of different data units is determined, and then the data units are reasonably split and interacted according to the importance degree. This not only avoids the loss and damage of the overall data after the data unit is threatened by access, ensures the stability of the data to a certain extent, but also can move some data to the data unit with less access threat for storage, greatly reducing the situation of loss and damage of the interacted data. At the same time, because the interaction is based on the importance degree and interacts with unimportant data, the storage security and stability after data interaction can be fully ensured. This method, combined with a certain degree of protection measures, can achieve better results than simply establishing protection measures for security protection without significantly increasing the cost.

[0006] The object of the present invention is also to provide a data security protection system based on big data. The system can collect the historical access big data of data units and perform importance ranking analysis based on access threats, so as to realize reasonable data interaction storage for data units to improve the overall data security. It is an important material basis for realizing data security protection and greatly improves the security of data protection.

[0007] In a first aspect, the present invention provides a data security protection method based on big data, including: obtaining historical access data of different data units, and performing security level analysis of access threats to form data access security level information; according to the data access security level information, performing interactive matching of data units to form data interaction matching information; according to the data interaction matching information, performing split matching processing on the data units to form interactive matching data.

[0008] In the present invention, the method comprehensively analyzes the degree of access threats to different data units by combining the historical big data of data access to determine the importance of different data units, and then reasonably splits and interacts the data units according to the importance. This not only avoids the loss and damage of the overall data after the data unit is threatened by access, ensures the stability of the data to a certain extent, but also can move some data to data units with fewer access threats for storage, greatly reducing the situation of loss and damage of the interactive data. At the same time, since the interaction is based on importance and interacts with unimportant data, the storage security and stability after data interaction can be fully ensured. This method, combined with certain protection measures, can achieve better results than establishing protection measures alone for security protection without significantly increasing the cost.

[0009] As a possible implementation, obtaining historical access data of different data units and performing security level analysis of access threats to form data access security level information includes: performing quantitative statistical analysis based on access threats according to the historical access data of different data units to form quantitative access threat data corresponding to different data units; performing importance analysis on different data units according to the quantitative access threat data to form data importance ranking information.

[0010] In the present invention, the analysis of the historical access data of data units is mainly to determine the degree of access threats to the data units. After all, when using the form of data interaction to protect data security, the best way is to transfer important data that is often threatened by access to objects or storage spaces with fewer access threats. Therefore, when performing security level analysis based on access threats, it is necessary to use big data for data statistics to determine the importance information of different data units through reasonable data extraction and analysis.

[0011] As a possible implementation, based on the historical access data of different data units, perform quantitative statistical analysis of access threats to form quantitative access threat data corresponding to different data units, including: setting a threat statistics period, for different data units, extracting the number of access threats in the historical access data during the threat statistics period to form the total unit access threat number U corresponding to the data unit n , where n represents the number of different data units; for different data units, extracting the types of access threats in the historical access data during the threat statistics period to form the unit access threat types V corresponding to the data unit n ; according to the total unit access threat number U corresponding to the data unit n and the unit access threat types V n , perform comprehensive threat degree analysis to form the unit quantitative access threat degree D corresponding to different data units n .

[0012] In the present invention, it should be noted that the measurement of the importance of data units is mainly reflected by the access threat indicators that the data units have received in the historical big data. The more important the data unit is, the more times it will be accessed threateningly, and the types and forms of access threats will also be more diverse. Therefore, when this application uses the big data of data units to measure importance, it mainly considers these two parameters of access threat in terms of access quantity and access threat types. Of course, in order to ensure the comparability of the importance measurement of different data units, it is necessary to set a unified threat statistics period, and the threat statistics period can be determined according to actual needs, or a representative time period can be obtained based on the feature analysis of big data for analysis.

[0013] As a possible implementation, according to the total unit access threat number U corresponding to the data unit n and the unit access threat types V n , perform comprehensive threat degree analysis to form the unit quantitative access threat degree L corresponding to different data units n , including: for different data units, according to the threat statistics duration T of the threat statistics period and the corresponding total unit access threat number U n , determine the unit access threat density D corresponding to the data unit n , where According to the total unit access threat number U corresponding to the data unit n and the unit access threat types V n , determine the unit access threat type accommodation rate A corresponding to the data unit n , where According to the unit access threat density D corresponding to the data unit n and the unit access threat type accommodation rate An to determine the unit quantization access threat degree L corresponding to the data unit n , where: L n = α 1 * D n + α 2 * A n , α 1 represents the density contribution factor, and α 2 represents the accommodation rate contribution factor.

[0014] In the present invention, of course, for the access threat data and types of access threats of the collected data units during a specific period, it is only a display of the access volume. To measure the importance of the data units, further processing of the data is required. The importance of the data units is more reasonably characterized by the density of access and the proportion of the types of access threats in the total number of accesses. The density contribution factor and the accommodation rate contribution factor can be determined according to the actual situation or based on big data analysis.

[0015] As a possible implementation manner, according to the quantization access threat data, importance analysis is performed on different data units to form data importance ranking information, including: according to the unit quantization access threat degree L corresponding to different data units n , different data units are arranged in descending order according to the unit quantization access threat degree L n to form data importance ranking information.

[0016] In the present invention, after obtaining the unit quantization access threat degree information for measuring the importance of the data units, reasonable sorting of the data units can be performed based on the unit quantization access threat degree. It should be noted that the purpose of sorting the data units by importance is to establish a reasonable security protection level for the data units, and then provide a reference for subsequent data interaction matching, ensuring that the interacted data, especially the data with high importance, can be stored in a location with few access threats, achieving the effect of security protection.

[0017] As a possible implementation manner, according to the data access security level information, data unit interaction matching is performed to form data interaction matching information, including: according to the data importance ranking information, the following method of interaction matching is performed on different data units to form data interaction matching information: if the total number of data units shown in the data importance ranking information is even, one data unit is extracted from each end of the sorting order of the data units provided by the data importance ranking information each time for matching to form data interaction matching groups until all data units are matched, and all data interaction matching groups are aggregated to form data interaction matching information; if the total number of data units shown in the data importance ranking information is odd, after excluding the unit quantization access threat degree Ln After the smallest data units, one data unit is extracted from each end of the sorting order of the data units provided by the data importance sorting information each time for matching to form a data interaction matching group until the matching between all data units is completed, and all data interaction matching groups are aggregated to form data interaction matching information.

[0018] In the present invention, the data interaction matching of data units based on the importance sorting information is mainly to provide unit objects with fewer access threats for some data exchange and storage for data units with high importance, in exchange for the protection of important data units and to avoid the complete acquisition or destruction of the data of data units by access threats. Based on this, the first thing to do in interactive matching is to perform importance-based matching on different data units. Here, the data importance sorting information is utilized to achieve symmetric matching in order considering the total number of data units.

[0019] As a possible implementation manner, according to the data interaction matching information, split matching processing is performed on the data units to form interactive matching data, including: performing an interactive amount analysis based on the storage amount on different data interaction matching groups in the data interaction matching information to determine the corresponding interactive storage amount of the data interaction matching group; splitting the data of different data units in the corresponding data interaction matching group according to the interactive storage amount to extract interactive sub-unit data; performing interactive storage on the two interactive sub-unit data in the data interaction matching group, and performing number encryption calibration processing on the interactive sub-unit data corresponding to the data unit after interaction; obtaining all data units that have completed interactive matching to form interactive matching data.

[0020] In the present invention, after determining the interactive matching objects of different data units, partial data interactive storage can be performed on the data units. Here, interactive matching considers two aspects. One is the size of the data amount that can achieve interactive matching, which can be determined according to the respective data storage amounts of the two data units being matched. The other is that after interactive matching, a non-direct corresponding relationship is established for the data that has interacted, so reasonable guidance is needed to determine the data unit to which the interacted data originally belongs. Of course, in order to avoid access threats from obtaining this corresponding relationship, encryption needs to be performed for protection.

[0021] As a possible implementation manner, performing an interactive amount analysis based on the storage amount on different data interaction matching groups in the data interaction matching information to determine the corresponding interactive storage amount of the data interaction matching group includes: for different data interaction matching groups, determining the allowable interactive data amount of different data units in the data interaction matching group; according to the smallest allowable interactive data amount in the data interaction matching group, respectively extracting the interactive matching data of two data units to form corresponding interactive sub-unit data.

[0022] In the present invention, considering that different data units have different amounts of data information, and thus their corresponding storage spaces are different. In order to ensure the smooth realization of data interaction matching, it is considered to determine the sub-unit data with a smaller storage capacity in the interaction matching group, and then extract the sub-unit data under another data unit based on the size of this sub-unit data, so as to achieve equal interaction matching.

[0023] As a possible implementation manner, the interactive storage is performed on the two interactive sub-unit data in the data interaction matching group, and the calibration process of numbering and encrypting the interactive sub-unit data corresponding to the data unit after interaction is carried out, including: performing interactive storage on the interactive sub-unit data in different unit data in the data interaction matching group, and respectively calibrating the range of the storage space of the interactive sub-unit data corresponding to the unit data after interactive storage; setting the interactive encryption function F enc , and performing numbering encryption on the interactive sub-unit data corresponding to the unit data after interactive storage in the following manner: obtaining the sorting number of the data unit corresponding to the interactive sub-unit data before interactive storage in the data importance sorting information, and determining it as the initial number corresponding to the interactive sub-unit data; through the interactive encryption function F enc processing the initial number corresponding to the interactive sub-unit data to form the interactive number corresponding to the interactive sub-unit data; associating the interactive number corresponding to the interactive sub-unit data with the sorting number of the unit data corresponding to the interactive sub-unit data after interactive storage in the data importance sorting information to form an interactive association sequence number; using the interactive association sequence number to calibrate the data unit formed after interactive storage.

[0024] In the present invention, for the numbering and encryption calibration of the interactive part, the original data unit corresponding to the interactive part is numbered by setting an interactive encryption function. The encryption function can ensure that the formed encrypted information is more secure, and can also reversely determine the initial corresponding data unit, which not only ensures the security of the data unit, but also avoids the defect that the source cannot be identified.

[0025] In a second aspect, the present invention provides a data security protection system based on big data, which is configured to: obtain the historical access data of different data units, and perform a security level analysis of access threats to form data access security level information; perform interactive matching of data units according to the data access security level information to form data interaction matching information; perform split matching processing on the data units according to the data interaction matching information to form interactive matching data.

[0026] In the present invention, the system is configured to collect the historical access big data of data units and perform importance ranking analysis based on access threats, so as to achieve reasonable data interaction storage of data units to improve the overall data security. It is an important material basis for realizing data security protection and greatly enhances the security of data protection.

[0027] The beneficial effects of a data security protection method and system based on big data provided by the present invention are as follows:

[0028] This method comprehensively analyzes the degree of access threats to different data units by combining the historical big data of data access to determine the importance of different data units, and then reasonably splits and interacts the data units according to the importance. This not only avoids the loss and damage of the overall data after the data unit is threatened by access, ensures the stability of the data to a certain extent, but also can move some data to data units with fewer access threats for storage, greatly reducing the situation of loss and damage of the interacted data. At the same time, since the interaction is based on importance and interacts with unimportant data, the storage security and stability after data interaction can be fully ensured. This method, combined with a certain degree of protection measures, can achieve better results than establishing protection measures alone for security protection without significantly increasing the cost.

[0029] The system is configured to collect the historical access big data of data units and perform importance ranking analysis based on access threats, so as to achieve reasonable data interaction storage of data units to improve the overall data security. It is an important material basis for realizing data security protection and greatly enhances the security of data protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required to be used in the embodiments of the present invention will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0031] Figure 1 It is a step diagram of a data security protection method based on big data provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0032] The technical solutions in the embodiments of the present invention will be described below with reference to the drawings in the embodiments of the present invention.

[0033] With the progress of science, the degree of social informatization is getting higher and higher. Along with it, a large amount of data information needs to be reasonably processed, analyzed, stored and other operations. At the same time, data transmission and interaction are also required. In the process of these series of operations on data, considering that the information carried by the data is targeted, it is necessary to reasonably protect the data security.

[0034] Currently, data security has attracted more and more attention from people, and many methods have been proposed for the protection measures taken for data security. Basically, security barriers such as firewalls are established for the access that poses a threat to the data. This method improves the security of data application to a certain extent, but the cost generated by taking these measures is relatively large, especially when deeply establishing a security protection network. If it is possible to perform a certain degree of security protection processing on the data itself while establishing a certain degree of security protection, it can effectively protect the data without significantly increasing the cost.

[0035] Reference Figure 1 , an embodiment of the present invention provides a data security protection method based on big data. This method comprehensively analyzes the degree of access threat of different data units by combining the historical big data of data access to determine the importance degree of different data units, and then reasonably splits and interacts the data units according to the importance degree. It not only avoids the loss and damage of the overall data after the data unit is threatened by access, ensures the stability of the data to a certain extent, but also can move some data to the data unit with less access threat for storage, greatly reducing the situation of loss and damage of the interactive data. At the same time, because the interaction is based on the importance degree and interacts with unimportant data, the storage security and stability after data interaction can be fully ensured. This method, combined with a certain degree of protection measures, can achieve better results than simply establishing protection measures for security protection without significantly increasing the cost.

[0036] The data security protection method based on big data specifically includes the following steps:

[0037] S1: Obtain the historical access data of different data units, and perform a security level analysis of the access threat to form data access security level information.

[0038] Obtain the historical access data of different data units, and perform a security level analysis of the access threat to form data access security level information, including: based on the historical access data of different data units, perform a quantitative statistical analysis of the access threat to form quantitative access threat data corresponding to different data units; according to the quantitative access threat data, perform an importance analysis of different data units to form data importance ranking information.

[0039] Analyze the historical access data of data units, mainly to determine the degree of access threats to the data units. After all, when protecting data security in the form of data interaction, the best way is to transfer the data units that are frequently threatened by access to objects or storage spaces with fewer access threats. Therefore, when conducting a security level analysis based on access threats, it is necessary to use big data for data statistics to determine the importance information of different data units through reasonable data extraction and analysis.

[0040] Based on the historical access data of different data units, conduct a quantitative statistical analysis of access threats to form quantitative access threat data corresponding to different data units, including: setting a threat statistics period, for different data units, extract the number of access threats in the threat statistics period from the corresponding historical access data to form the total unit access threat U corresponding to the data unit n , where n represents the numbers of different data units; for different data units, extract the types of access threats in the threat statistics period from the corresponding historical access data to form the unit access threat types V corresponding to the data unit n ; According to the total unit access threat U n and the unit access threat types V n , conduct a comprehensive threat degree analysis to form the unit quantitative access threat degree D corresponding to different data units n .

[0041] It should be noted that the measurement of the importance of data units is mainly reflected by the access threat indicators that the data units receive in historical big data. The more important the data unit, the more times it will be threatened by access, and the more diverse the types and forms of access threats will be. Therefore, when this application uses big data of data units to measure importance, it mainly considers these two parameters of access threat in terms of access quantity and access threat types. Of course, in order to ensure the comparability of the importance measurement of different data units, it is necessary to set a unified threat statistics period, which can be determined according to actual needs, or a representative time period can be obtained based on the feature analysis of big data for analysis.

[0042] According to the total unit access threat U n and the unit access threat types V n , conduct a comprehensive threat degree analysis to form the unit quantitative access threat degree L corresponding to different data units n , including: for different data units, according to the threat statistics duration T of the threat statistics period and the corresponding total unit access threat U n , determine the unit access threat density D corresponding to the data unit n , where According to the total number of unit access threats U corresponding to the data unit n and the types of unit access threats V n , determine the accommodation rate A of the types of unit access threats corresponding to the data unit n , where According to the unit access threat density D corresponding to the data unit n and the accommodation rate A of the types of unit access threats n , determine the unit quantified access threat degree L corresponding to the data unit n , where: L n = α 1 * D n + α 2 * A n , α 1 represents the density contribution factor, and α 2 represents the accommodation rate contribution factor.

[0043] Of course, for the access threat data and types of access threats of the collected data units during a specific period, they are only manifestations of the access volume. To measure the importance of the data units, further processing of the data is required. The importance of the data units is more reasonably characterized by the density of access and the proportion of the types of access threats in the total number of accesses. The density contribution factor and the accommodation rate contribution factor can be determined according to the actual situation or based on big data analysis.

[0044] According to the quantified access threat data, perform importance analysis on different data units to form data importance ranking information, including: according to the unit quantified access threat degree L corresponding to different data units n , arrange different data units in descending order according to the unit quantified access threat degree L n to form data importance ranking information.

[0045] After obtaining the unit quantified access threat degree information for measuring the importance of the data units, reasonable sorting of the data units can be performed based on the unit quantified access threat degree. It should be noted that the purpose of sorting the data units by importance is to establish a reasonable security protection level for the data units, and then provide a reference for subsequent data interaction matching, ensuring that the interacted data, especially the data with high importance, can be stored in locations with few access threats, achieving the effect of security protection.

[0046] S2: According to the data access security level information, perform data unit interaction matching to form data interaction matching information.

[0047] According to the data access security level information, perform interactive matching of data units to form data interactive matching information, including: According to the data importance ranking information, perform interactive matching of different data units in the following ways to form data interactive matching information: If the data importance ranking information shows that the total number of data units is even, then extract one data unit from each end of the sorting order of the data units provided by the data importance ranking information each time to form a data interactive matching group until all data units are matched. Aggregate all data interactive matching groups to form data interactive matching information; If the data importance ranking information shows that the total number of data units is odd, then after excluding the data unit with the smallest unit quantization access threat degree L n the smallest data unit, extract one data unit from each end of the sorting order of the data units provided by the data importance ranking information each time to form a data interactive matching group until all data units are matched. Aggregate all data interactive matching groups to form data interactive matching information.

[0048] The data interactive matching of data units based on the importance ranking information is mainly to provide unit objects with less access threat for data units with high importance for partial data exchange and storage, in exchange for the protection of important data units and to avoid the complete acquisition or destruction of the data of data units by access threats. Based on this, the first thing to do in interactive matching is to perform importance-based matching of different data units. Here, the data importance ranking information is used to achieve symmetric matching in order considering the total number of data units.

[0049] S3: According to the data interactive matching information, perform split matching processing on the data units to form interactive matching data.

[0050] According to the data interactive matching information, perform split matching processing on the data units to form interactive matching data, including: Perform an interactive volume analysis based on the storage volume on different data interactive matching groups in the data interactive matching information to determine the corresponding interactive storage volume of the data interactive matching group; Split the different data units in the corresponding data interactive matching group according to the interactive storage volume to extract interactive subunit data; Perform interactive storage on the two interactive subunit data in the data interactive matching group, and perform number encryption calibration processing on the interactive subunit data corresponding to the data unit after interaction; Obtain all data units that have completed interactive matching to form interactive matching data.

[0051] After determining the interactive matching objects of different data units, partial data interactive storage of the data units can be performed. Here, interactive matching considers two aspects. One is the size of the data volume that can achieve interactive matching, which can be determined according to the respective data storage volumes of the two data units being matched. The other is that after interactive matching, an indirect corresponding relationship is established for the interacted data. Therefore, reasonable guidance is needed to determine the data unit to which the interacted data part originally belongs. Of course, in order to avoid access threats and obtain this corresponding relationship, encryption needs to be carried out for protection.

[0052] Perform an analysis of the interactive volume based on the storage volume for different data interactive matching groups in the data interactive matching information, and determine the interactive storage volume corresponding to the data interactive matching group, including: for different data interactive matching groups, determine the allowable interactive data volume of different data units within the data interactive matching group; according to the smallest allowable interactive data volume in the data interactive matching group, extract the interactive matching data of the two data units respectively to form the corresponding interactive sub-unit data.

[0053] Considering that different data units have different amounts of data information, and thus their corresponding storage spaces are different. To ensure the smooth realization of data interactive matching, consider determining the sub-unit data with a smaller storage volume in the interactive matching group, and then extract the sub-unit data under another data unit based on the size of this sub-unit data, so as to achieve equal interactive matching.

[0054] Perform interactive storage on the two interactive sub-unit data in the data interactive matching group, and perform a calibration process of number encryption on the interactive sub-unit data corresponding to the data unit after interaction, including: perform interactive storage on the interactive sub-unit data in different unit data in the data interactive matching group, and respectively calibrate the range of the storage space of the interactive sub-unit data corresponding to the unit data after interactive storage; set the interactive encryption function F enc , perform number encryption on the interactive sub-unit data corresponding to the unit data after interactive storage in the following way: obtain the sorting number of the data unit corresponding to the interactive sub-unit data before interactive storage in the data importance sorting information, and determine it as the initial number corresponding to the interactive sub-unit data; through the interactive encryption function F enc process the initial number corresponding to the interactive sub-unit data to form the interactive number corresponding to the interactive sub-unit data; associate the interactive number corresponding to the interactive sub-unit data with the sorting number of the unit data corresponding to the interactive sub-unit data after interactive storage in the data importance sorting information to form an interactive association sequence number; use the interactive association sequence number to calibrate the data unit formed after interactive storage.

[0055] Number and encrypt the interaction part, number the original data unit corresponding to the interaction part by setting an interaction encryption function. The encryption function can ensure that the formed encrypted information is more secure and can also reversely determine the initial corresponding data unit, which not only ensures the security of the data unit but also avoids the defect of inability to identify the source.

[0056] The present invention also provides a data security protection system based on big data. The system is configured to: obtain the historical access data of different data units, perform a security level analysis of access threats, and form data access security level information; according to the data access security level information, perform an interactive matching of data units to form data interaction matching information; according to the data interaction matching information, perform a split matching process on the data units to form interactive matching data.

[0057] By being configured to collect the historical access big data of data units and perform an importance ranking analysis based on access threats, the system realizes reasonable data interaction storage of data units to improve the overall data security. It is an important material basis for realizing data security protection and also greatly improves the security of data protection.

[0058] In summary, the beneficial effects of the data security protection method and system based on big data provided by the embodiments of the present invention are as follows:

[0059] This method comprehensively analyzes the degree of access threats to different data units by combining the historical big data of data access to determine the importance of different data units, and then reasonably splits and interacts the data units according to the importance. This not only avoids the loss and damage of the overall data after the data unit is threatened by access, ensures the stability of the data to a certain extent, but also can move some data to data units with fewer access threats for storage, greatly reducing the situation of loss and damage of the interacted data. At the same time, since the interaction is based on importance and interacts with unimportant data, it can fully ensure the storage security and stability after data interaction. This method, combined with certain protection measures, can achieve better results than establishing protection measures alone for security protection without significantly increasing the cost.

[0060] By being configured to collect the historical access big data of data units and perform an importance ranking analysis based on access threats, the system realizes reasonable data interaction storage of data units to improve the overall data security. It is an important material basis for realizing data security protection and also greatly improves the security of data protection.

[0061] In the embodiments of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. If the information indicated by a certain piece of information is called the information to be indicated, then in the specific implementation process, there are many ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated, etc. It is also possible to indirectly indicate the information to be indicated by indicating other information, where there is an association relationship between the other information and the information to be indicated. It is also possible to only indicate a part of the information to be indicated, while the other parts of the information to be indicated are known or pre-agreed. For example, it is also possible to use the arrangement order of each piece of information pre-agreed (such as stipulated in the protocol) to realize the indication of specific information, thereby reducing the indication overhead to a certain extent. At the same time, it is also possible to identify the common parts of each piece of information and indicate them uniformly to reduce the indication overhead caused by separately indicating the same information.

[0062] In addition, the specific indication method can also be various existing indication methods. For example, but not limited to, the above indication methods and their various combinations, etc. The specific details of various indication methods can refer to the prior art and will not be elaborated herein. As can be seen from the above, for example, when it is necessary to indicate multiple pieces of information of the same type, there may be a situation where the indication methods of different pieces of information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiments of the present application do not limit the selected indication method. In this way, the indication methods involved in the embodiments of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0063] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending periods and / or sending times of these sub-information can be the same or different. The specific sending method is not limited in the embodiments of the present application. Among them, the sending periods and / or sending times of these sub-information can be predefined, such as predefined according to the protocol, or can be configured by the sending device by sending configuration information to the receiving device.

[0064] "Predefined" or "pre-configured" can be realized by pre-saving the corresponding codes, tables or other ways that can be used to indicate relevant information in the device. The embodiments of the present application do not limit its specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be separately provided, or can be integrated in the encoder or decoder, processor, or communication device. The one or more memories can also be partly separately provided and partly integrated in the decoder, processor, or communication device. The type of the memory can be any form of storage medium, which is not limited in the embodiments of the present application.

[0065] The "protocol" involved in the embodiments of this application may refer to a protocol family in the communication field, a standard protocol with a frame structure similar to that of a protocol family, or a related protocol applied to future communication systems. The embodiments of this application do not make specific limitations in this regard.

[0066] In the embodiments of this application, descriptions such as "when...", "in the case of...", "if", and "when" all refer to the situation where the device will perform corresponding processing under certain objective circumstances, rather than limiting time. It does not require the device to have a judgment action when implemented, nor does it mean the existence of other limitations.

[0067] In the description of the embodiments of this application, unless otherwise specified, " / " indicates that the objects associated before and after are in an "or" relationship. For example, A / B may represent A or B. The "and / or" in the embodiments of this application is only a description of the association relationship of the associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Also, in the description of the embodiments of this application, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of single items (items) or plural items (items). For example, at least one (item) of a, b, or c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple. Additionally, for the convenience of clearly describing the technical solutions of the embodiments of this application, in the embodiments of this application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and roles. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and "first", "second", etc. do not necessarily mean different. At the same time, in the embodiments of this application, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" aims to present relevant concepts in a specific way for easy understanding.

[0068] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0069] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0070] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more collections of available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, or magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0071] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood by referring to the context.

[0072] In the present application, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or a similar expression means any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or plural.

[0073] It should be understood that in various embodiments of the present application, the magnitude of the sequence numbers of the above processes does not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0074] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0075] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0076] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of devices or units can be electrical, mechanical, or other forms.

[0077] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0078] In addition, the functional units in each embodiment of this application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0079] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0080] The above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. A data security protection method based on big data, characterized in that: include: Obtain historical access data of different data units, and perform security level analysis of access threats to form data access security level information; According to the data access security level information, interactive matching of data units is performed to form data interactive matching information; According to the data interactive matching information, the data unit is split and matched to form interactive matching data.

2. The data security protection method based on big data according to claim 1 is characterized in that: The acquisition of historical access data of different data units and the analysis of the security level of access threats to form data access security level information include: According to the historical access data of different data units, performing access threat-based quantitative statistical analysis to form quantitative access threat data corresponding to different data units; According to the quantified access threat data, importance analysis is performed on different data units to form data importance ranking information.

3. The data security protection method based on big data according to claim 2 is characterized in that: The performing access threat-based quantitative statistical analysis according to the historical access data of different data units to form quantitative access threat data corresponding to different data units includes: Set a threat statistics period, extract the number of access threats in the corresponding historical access data in the threat statistics period for different data units, and form the total number of unit access threats U corresponding to the data unit n , n represents the serial number of different data units; For different data units, the access threat types in the corresponding historical access data in the threat statistics period are extracted to form the unit access threat type U corresponding to the data unit. n ; The total number of unit access threats U corresponding to the data unit n and the unit access threat category V n , conduct a comprehensive threat level analysis to form a unit quantified access threat level D corresponding to different data units n .

4. The data security protection method based on big data according to claim 3 is characterized in that: The total number of unit access threats U corresponding to the data unit n and the unit access threat category V n , conduct a comprehensive threat level analysis to form a unit quantified access threat level L corresponding to different data units n ,include: For different data units, according to the threat statistics duration T of the threat statistics period and the corresponding total number of unit access threats U n , determine the unit access threat density D corresponding to the data unit n ,in, The total number of unit access threats U corresponding to the data unit n and the unit access threat category V n , determine the unit access threat type tolerance rate A corresponding to the data unit n ,in, According to the unit access threat density D corresponding to the data unit n and the unit access threat type containment rate A n , determine the unit quantized access threat level L corresponding to the data unit n ,in: L n =α1*D n +α2*A n , α1 represents the density contribution factor, and α2 represents the capacity contribution factor.

5. The data security protection method based on big data according to claim 4 is characterized in that: The step of performing importance analysis on different data units according to the quantified access threat data to form data importance ranking information includes: Quantify the access threat level L according to the unit corresponding to different data units n , quantify the access threat level L of different data units according to the units n Arrange them in descending order to form the data importance ranking information.

6. The data security protection method based on big data according to claim 5 is characterized in that: The interactive matching of data units according to the data access security level information to form data interactive matching information includes: According to the data importance ranking information, different data units are interactively matched in the following manner to form data interactive matching information: If the data importance sorting information shows that the total number of the data units is an even number, then extract one data unit at a time from both ends of the sorting order of the data units provided by the data importance sorting information for matching to form a data interaction matching group, until the matching between all the data units is completed, and gather all the data interaction matching groups to form the data interaction matching information; If the data importance ranking information shows that the total number of the data units is an odd number, then the quantified access threat level L of the unit is excluded. n After the smallest data unit, one data unit is extracted each time from both ends of the sorting order of the data units provided by the data importance sorting information for matching to form a data interaction matching group until the matching between all the data units is completed, and all the data interaction matching groups are gathered to form the data interaction matching information.

7. The data security protection method based on big data according to claim 6 is characterized in that: The step of performing splitting and matching processing on the data unit according to the data interactive matching information to form interactive matching data includes: Performing storage-based interaction volume analysis on different data interaction matching groups in the data interaction matching information to determine the interaction storage volume corresponding to the data interaction matching group; According to the interactive storage amount, data of different data units in the corresponding data interactive matching group are split to extract interactive sub-unit data; Interactively storing the two interactive sub-unit data in the data interactive matching group, and performing numbering and encryption calibration processing on the interactive sub-unit data corresponding to the interactive data unit; All the data units that have completed interactive matching are acquired to form the interactive matching data.

8. The data security protection method based on big data according to claim 7 is characterized in that: The performing storage-based interaction volume analysis on different data interaction matching groups in the data interaction matching information to determine the interaction storage volume corresponding to the data interaction matching group includes: For different data interaction matching groups, determining the allowed interactive data amounts of different data units in the data interaction matching groups; According to the minimum allowed interactive data amount in the data interactive matching group, the interactive matching data of the two data units are respectively extracted to form the corresponding interactive sub-unit data.

9. The data security protection method based on big data according to claim 8 is characterized in that: The interactive storage of the two interactive sub-unit data in the data interactive matching group and the numbering and encryption of the interactive sub-unit data corresponding to the interactive data unit after the interaction include: Interactively storing the interactive sub-unit data in different unit data in the data interactive matching group, and respectively calibrating the range of storage space for the interactive sub-unit data corresponding to the unit data after interactive storage; Set the interactive encryption function F enc , the interactive sub-unit data corresponding to the unit data after interactive storage is numbered and encrypted in the following manner: Obtaining the sorting number of the data unit corresponding to the interactive sub-unit data before interactive storage in the data importance sorting information, and determining it as the initial number corresponding to the interactive sub-unit data; Through the interactive encryption function F enc Processing the initial number corresponding to the interaction sub-unit data to form an interaction number corresponding to the interaction sub-unit data; Associating the interaction number corresponding to the interaction sub-unit data with the sorting number of the unit data corresponding to the interaction sub-unit data after the interaction sub-unit data is interactively stored in the data importance sorting information to form an interaction association sequence number; The data units formed after interactive storage are calibrated using the interactive association sequence numbers.

10. A data security protection system based on big data, characterized in that: Configured as: Obtain historical access data of different data units, and perform security level analysis of access threats to form data access security level information; According to the data access security level information, interactive matching of data units is performed to form data interactive matching information; According to the data interactive matching information, the data unit is split and matched to form interactive matching data.

Citation Information

Patent Citations

  • Power system data interaction security threat information analysis method

    CN116956148A

  • Network data security protection method and system based on big data

    CN118631577A

  • Cybersecurity quantitative analysis software as a service

    US20210201229A1