Visual management system and method for bank internal control examination

By designing a visual management system for bank internal control assessment, the bank internal control assessment data is automatically collected, analyzed and fed back, and sensitive data is encrypted and stored, the problems of low efficiency, low security and accuracy of manual statistical investigation in the existing technology are solved, and efficient, safe and accurate internal control assessment management is achieved.

CN120067181APending Publication Date: 2025-05-30SHENZHEN BRANCH OF BANK OF COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510145349.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing technology uses manual methods to statistically check data in bank internal control assessment, resulting in low efficiency, low security and accuracy.

Method used

Design a visual management system for bank internal control assessment, including data collection module, data pre-audit module, data analysis module, data encryption storage module and visual display module to realize automated data collection, analysis and result feedback, and encrypt and store sensitive data.

Benefits of technology

It realizes the automation of the bank's internal control assessment process, shortens the statistical analysis time, ensures the accuracy and security of data, and improves the security and controllability of data use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120067181A_ABST
    Figure CN120067181A_ABST
Patent Text Reader

Abstract

The invention discloses a visual management system and a visual management method for bank internal control examination, which realize automation of a bank internal control examination process, namely, links of internal control examination and evaluation data collection, analysis, result feedback and the like can be automatically completed in the system; therefore, compared with manual processing, the statistical analysis time is greatly shortened, and the data accuracy is also ensured; meanwhile, sensitive data in the internal control examination and evaluation data are encrypted and stored, so that the data can be prevented from being tampered in the collection and transmission processes while the security in the data retention and sharing processes is ensured, and the security and controllability of data use are improved; therefore, a management system with high automation degree, high safety and high accuracy is provided for bank internal control examination and evaluation data, so that the system is very suitable for large-scale application and popularization.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data processing, and particularly relates to a visual management system and method for bank internal control assessment and evaluation. Background Art

[0002] Currently, according to the banking internal control evaluation and assessment measures, it is necessary to objectively evaluate the internal control situation of each business unit and each department every quarter. This is an investigation, testing, analysis, and evaluation activity carried out on the construction, implementation, and operation results of the bank's internal control system. In actual application, the method for checking and sorting the bank internal control evaluation and assessment data is manual checking, that is, it is necessary to manually count the summary data and detailed data of the assessment and evaluation of 60 or more business units by 17 departments, and then uniformly report the statistical checking results to the superior department for review. Among them, the above-mentioned prior art has the following deficiencies: (1) Manual review requires a large amount of time and has low efficiency; (2) The accuracy and security of the data cannot be guaranteed. Since the entire system involves a large number of tables, manual statistics cannot ensure the accuracy of the data. At the same time, the above-mentioned data is important data within the bank, and the security and encryption of manual statistical checking cannot be guaranteed throughout the entire link. Therefore, based on the above deficiencies, how to provide a visual management system for bank internal control assessment and evaluation with high efficiency, high security, and high accuracy has become an urgent problem to be solved. Summary of the Invention

[0003] The purpose of the present invention is to provide a visual management system and method for bank internal control assessment and evaluation, so as to solve the problems of low efficiency, low security, and low accuracy existing in the prior art when manually counting and checking bank internal control evaluation and assessment data.

[0004] To achieve the above purpose, the present invention adopts the following technical solutions:

[0005] In the first aspect, a visual management system for bank internal control assessment and evaluation is provided, including:

[0006] A data acquisition module, configured to obtain bank internal control evaluation and assessment data input by different departments, and send each bank internal control evaluation and assessment data to the data pre-audit module;

[0007] A data pre-audit module, configured to perform data preprocessing on each bank internal control evaluation and assessment data to obtain each preprocessed bank internal control evaluation and assessment data, and send it to the data analysis module;

[0008] A data analysis module, configured to perform data statistical analysis processing on each preprocessed bank internal control evaluation and assessment data to obtain the statistical analysis results of all bank internal control evaluation and assessment data, and perform data classification processing on each preprocessed bank internal control evaluation and assessment data to obtain a number of sensitive data and a number of non-sensitive data;

[0009] A data encryption and storage module, which is used to encrypt each sensitive data to obtain a number of encrypted data, and upload the number of encrypted data and a number of non-sensitive data to a cloud database for storage;

[0010] A visualization display module, which is used to visually display the statistical analysis results, so as to complete the visual management of bank internal control assessment after the visual display.

[0011] Based on the above disclosed content, the visual management system for bank internal control assessment provided by the present invention first obtains bank internal control evaluation and assessment data input by different departments, and then preprocesses each bank internal control evaluation and assessment data to obtain each preprocessed bank internal control evaluation and assessment data; then, the data analysis module is used to perform statistical analysis processing on the preprocessed data to obtain the statistical analysis results of all bank internal control evaluation and assessment data; then, the present invention divides each preprocessed bank internal control evaluation and assessment data into sensitive data and non-sensitive data, and uses the data encryption and storage module to encrypt the sensitive data to obtain a number of encrypted data; finally, storing the non-sensitive data and each encrypted data in a cloud database, and visually displaying the aforementioned statistical analysis results can complete the visual management of the data related to bank internal control assessment.

[0012] Through the above design, the present invention realizes the automation of the bank internal control assessment process, that is, links such as the collection, analysis and result feedback of internal control assessment and evaluation data can be automatically completed within the system; thus, compared with manual processing, not only the statistical analysis time is greatly shortened, but also the accuracy of the data is guaranteed; at the same time, the present invention also encrypts and stores the sensitive data in the internal control assessment and evaluation data. Based on this, while ensuring the security of data retention and sharing, it can prevent data from being tampered with during the collection and transmission process, thereby improving the security and controllability of data use; thus, the present invention provides a management system for bank internal control assessment and evaluation data with high automation, high security and high accuracy, so it is very suitable for large-scale application and promotion.

[0013] In a possible design, a data pre-audit module is used to sequentially perform error data correction processing and duplicate removal processing on each bank internal control evaluation and assessment data, so as to obtain each bank internal control evaluation and assessment data after duplicate removal after the duplicate removal processing;

[0014] A data pre-audit module is used to sequentially perform missing value filling processing and data integrity verification processing on each bank internal control evaluation and assessment data after duplicate removal, so as to obtain each initial bank internal control evaluation and assessment data after the data integrity verification processing;

[0015] The data pre-audit module is also used to perform format standardization processing on each initial bank internal control evaluation and assessment data, so as to obtain each preprocessed bank internal control evaluation and assessment data after the format standardization processing.

[0016] In a possible design, the data encryption and storage module is used to encrypt each sensitive data by using the symmetric key block cipher encryption algorithm to obtain a number of encrypted data.

[0017] In a possible design, the symmetric key block cipher encryption algorithm includes: exclusive-or encryption algorithm, modulo addition encryption algorithm, and left bitwise circular encryption algorithm;

[0018] Among them, for any sensitive data, the data encryption and storage module is used to divide the any sensitive data into two segments in the order from left to right to obtain a first segment of data and a second segment of data, where the lengths of the first segment of data and the second segment of data are equal;

[0019] The data encryption and storage module is also used to adopt the exclusive-or encryption algorithm, the modulo addition encryption algorithm, and the left bitwise circular encryption algorithm, and based on the Feistel network, perform multi-round encryption processing on the first segment of data and the second segment of data, so as to obtain the encrypted data corresponding to the any sensitive data after multi-round encryption processing, and after polling all sensitive data, obtain the encrypted data corresponding to each sensitive data.

[0020] In a possible design, the data encryption and storage module is used to generate a round key for the i-th round of encryption processing, and use the exclusive-or encryption algorithm and the round key to perform initial encryption processing on the second segment of data to obtain an initially encrypted second segment of data, where the initial value of i is 1;

[0021] The data encryption and storage module is used to sequentially adopt the modulo addition encryption algorithm and the left bitwise circular encryption algorithm to perform secondary encryption processing on the initially encrypted second segment of data to obtain a second segment of data after secondary encryption;

[0022] The data encryption and storage module is used to perform exclusive-or processing on the second segment of data after secondary encryption and the first segment of data, so as to obtain any sensitive data after the i-th round of encryption after the exclusive-or processing;

[0023] The data encryption and storage module is also used to increment i by 1, update the first segment of data to the second segment of data in the (i - 1)-th round, and update the second segment of data to any sensitive data after the (i - 1)-th round of encryption, and regenerate the round key for the i-th round of encryption processing until i is equal to n, so as to obtain the encrypted data corresponding to the any sensitive data. Here, n is the preset number of encryption rounds.

[0024] In a possible design, the data encryption storage module is configured to perform initial encryption processing on the second segment of data by using the following formula (1) to obtain the initially encrypted second segment of data;

[0025]

[0026] In the above formula (1), Code x represents the initially encrypted second segment of data, PT 2 represents the second segment of data, represents the round key during the i-th round of encryption processing, represents the exclusive OR operation.

[0027] In a possible design, the data encryption storage module is configured to sequentially perform secondary encryption processing on the initially encrypted second segment of data by using the following formula (2) and formula (3) to obtain the second segment of data after secondary encryption;

[0028] Code m =(Code x +key m )modY (2)

[0029] Code R =(Code m <<N)(Code m >>(8-N)) (3)

[0030] In the above formula (2), Code m represents the initially encrypted second segment of data encrypted by the modulo addition encryption algorithm, Code x represents the initially encrypted second segment of data, key m represents the modulo addition encryption key, Y represents the modulo parameter, and mod represents the modulo operation;

[0031] In the above formula (3), Code d represents the second segment of data after secondary encryption, N represents the number of bits of displacement, << represents the left shift symbol, and >> represents the right shift symbol.

[0032] In a possible design, the visualization display module is configured to perform annotation processing on the risk data in the statistical analysis result and visually display the statistical analysis result in a preset manner, where the preset manner includes a graphical manner and / or a chart manner.

[0033] In a possible design, the data encryption storage module is further configured to determine whether it has received the storage feedback information sent by the cloud, and after determining that it has received the storage feedback information, complete the data storage process, where the storage feedback information includes encrypted data storage feedback information and unencrypted data storage feedback information.

[0034] In a second aspect, there is provided a working method for the visual management system of the bank internal control assessment according to the first aspect or any one of the possible designs in the first aspect, including:

[0035] Obtain the bank internal control evaluation and assessment data entered by different departments;

[0036] Perform data preprocessing on each bank internal control evaluation and assessment data to obtain each preprocessed bank internal control evaluation and assessment data;

[0037] Perform data statistical analysis processing on each preprocessed bank internal control evaluation and assessment data to obtain the statistical analysis results of all bank internal control evaluation and assessment data, and perform data classification processing on each preprocessed bank internal control evaluation and assessment data to obtain a number of sensitive data and a number of non-sensitive data;

[0038] Encrypt each sensitive data to obtain a number of encrypted data, and upload the number of encrypted data and a number of non-sensitive data to the cloud database for storage;

[0039] Perform visual display on the statistical analysis results, so as to complete the visual management of the bank internal control assessment after the visual display.

[0040] In a third aspect, there is provided an electronic device, including a memory, a processor, and a transceiver that are communicatively connected in sequence, where the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the working method of the visual management system of the bank internal control assessment as described in the second aspect.

[0041] In a fourth aspect, there is provided a storage medium, on which instructions are stored, and when the instructions run on a computer, they execute the working method of the visual management system of the bank internal control assessment as described in the second aspect.

[0042] In a fifth aspect, there is provided a computer program product containing instructions, and when the instructions run on a computer, the computer is caused to execute the working method of the visual management system of the bank internal control assessment as described in the second aspect.

[0043] Advantageous effects:

[0044] (1) The present invention realizes the automation of the bank's internal control assessment process, that is, all links such as the collection, analysis, and result feedback of internal control assessment and evaluation data can be automatically completed within the system. Thus, compared with manual processing, it not only greatly shortens the statistical analysis time but also ensures the accuracy of the data. At the same time, the present invention also encrypts and stores sensitive data in the internal control assessment and evaluation data. Based on this, while ensuring the security of data retention and sharing, it can prevent data from being tampered with during the collection and transmission processes, thereby improving the security and controllability of data use. Therefore, the present invention provides a highly automated, secure, and accurate management system for bank internal control assessment and evaluation data, which is very suitable for large-scale application and promotion.

[0045] (2) Innovation in visual presentation methods; the present invention displays the complex indicators of bank internal control assessment through an intuitive visual interface. Among them, traditional internal control assessment data is presented in the form of long reports, and bank staff need to spend a lot of time interpreting these data. However, the present invention can clearly display assessment indicators such as risk control rate, compliance operation ratio, and the number of problems found in internal audits through charts (such as bar charts, line charts, pie charts, etc.), graphics (such as flowcharts, mind maps, etc.), or dashboards. Therefore, it improves the convenience of data analysis.

[0046] (3) Realizes encrypted shared storage of data; among them, due to the encrypted storage of sensitive data, the present invention can precisely control the sharing scope of data according to different business requirements and management requirements within the bank to ensure that the data is only accessed and used by authorized personnel. Thus, it improves the security and controllability of data sharing. Brief Description of the Drawings

[0047] Figure 1 It is a schematic structural diagram of the visual management system for bank internal control assessment provided by the embodiment of the present invention;

[0048] Figure 2 It is a step flowchart of the working method of the visual management system for bank internal control assessment provided by the embodiment of the present invention. Detailed Embodiments

[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or in the prior art, the following will briefly introduce the present invention in combination with the drawings and the description of the embodiments or the prior art. Obviously, the following description of the drawings' structures is only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings. It should be noted here that the description of these embodiment modes is used to help understand the present invention, but does not constitute a limitation to the present invention.

[0050] It should be understood that although terms such as first and second may be used herein to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, the first unit may be referred to as the second unit, and similarly, the second unit may be referred to as the first unit, without departing from the scope of the exemplary embodiments of the present invention.

[0051] It should be understood that for the term "and / or" that may appear herein, it is merely an association relationship describing associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, B exists alone, and both A and B exist simultaneously; for the term " / and" that may appear herein, it describes another association object relationship, indicating that two relationships may exist. For example, A / and B may represent: A exists alone, and both A and B exist; in addition, for the character " / " that may appear herein, it generally indicates that the associated objects before and after are in an "or" relationship.

[0052] Embodiment:

[0053] See Figure 1 As shown, the visual management system for bank internal control assessment provided in this embodiment may, but is not limited to, include a data collection module, a data pre-audit module, a data analysis module, a data encryption storage module, and a visual display module; among them, the data collection module is used to obtain bank internal control evaluation and assessment data entered by different departments and send each bank internal control evaluation and assessment data to the data pre-audit module to provide a data source for subsequent statistical summarization; in this embodiment, for example, the bank internal control evaluation and assessment data entered by each department may, but is not limited to, include data such as the internal control evaluation results of the lead line, the internal control evaluation results of the comprehensive line, the details of internal control problems in the line, the audit inspection results of the head office and branches, the external inspection results, and the rectification information form; thus, this system statistically analyzes the foregoing various data to achieve the automated management of bank internal control evaluation and assessment data.

[0054] After the collection of bank internal control evaluation and assessment data is completed, the preliminary pre-audit of the data can be carried out. Specifically, it is completed by the data pre-audit module, that is: the data pre-audit module is used to perform data preprocessing on each bank internal control evaluation and assessment data to obtain each preprocessed bank internal control evaluation and assessment data and send it to the data analysis module.

[0055] In specific implementation, the data pre-audit module is mainly used for identifying and fixing incorrectly filled data, screening and processing duplicate data, handling missing values, unifying formats, and performing data integrity checks, etc. That is: the data pre-audit module is first used to sequentially perform error data correction processing and duplicate removal processing on each bank's internal control evaluation and assessment data, so as to obtain each bank's internal control evaluation and assessment data after duplicate removal after the duplicate removal processing; then, sequentially perform missing value filling processing and data integrity verification processing on each bank's internal control evaluation and assessment data after duplicate removal, so as to obtain each initial bank's internal control evaluation and assessment data after the data integrity verification processing; finally, perform format standardization processing on each initial bank's internal control evaluation and assessment data, so as to obtain each preprocessed bank's internal control evaluation and assessment data after the format standardization processing; of course, the aforementioned error data correction, duplicate removal, missing value filling, integrity verification, and format standardization are all common techniques for data preprocessing, and their principles will not be elaborated one by one.

[0056] After the preliminary audit of the data is completed, data statistical analysis can be carried out, that is: the data analysis module is used to perform data statistical analysis processing on each preprocessed bank's internal control evaluation and assessment data to obtain the statistical analysis results of all bank's internal control evaluation and assessment data; in specific implementation, the aforementioned data analysis module is specifically used to perform statistical analysis processing on each preprocessed bank's internal control evaluation and assessment data according to preset rules to obtain the assessment data distribution result, the assessment data correlation result, and the assessment data change trend analysis result, and use the assessment data distribution result, the assessment data correlation result, and the assessment data change trend analysis result to generate the aforementioned statistical analysis result; thus, it is equivalent to calculating and displaying the data distribution, correlation, and trend of the aforementioned bank's internal control evaluation and assessment data according to the preset internal control evaluation and assessment rules. For example, horizontal and vertical comparison of similar data can be realized to obtain the trend analysis result. Another example is to perform numerical distribution statistics on the data (such as the distribution of data such as the compliance operation ratio of different bank units and the number of non-compliant operations), etc. Thus, through statistical analysis of the aforementioned data, support can be provided for subsequent data storage, retrieval, and analysis.

[0057] Furthermore, in this embodiment, to ensure data security, the data analysis module is also used to perform data classification processing on each preprocessed bank's internal control evaluation and assessment data to obtain a number of sensitive data and a number of non-sensitive data; thus, a data source can be provided for subsequent data encryption; for example, when data is entered, labels can be set for each data in the bank's internal control evaluation and assessment data (such as label 1 indicating sensitive data and label 0 indicating non-sensitive data). Based on this, sensitive data and non-sensitive data can be identified based on the labels of each data.

[0058] After the division of sensitive data and non-sensitive data is completed, the encryption process of sensitive data can be carried out. The process is as follows:

[0059] The data encryption and storage module is used to encrypt each sensitive data to obtain a number of encrypted data. After the encryption process of sensitive data is completed, the number of encrypted data and a number of non-sensitive data can be uploaded to the cloud database for storage (that is, uploaded to the cloud database of the basic subsystem of in-line data management). In this way, the data storage can be completed. At the same time, in this embodiment, after the encrypted data and non-sensitive data are stored in the cloud database, encrypted data storage feedback information and non-encrypted data storage feedback information will be obtained. Therefore, the data encryption and storage module can, based on this, determine whether the storage is completed, that is, the data encryption and storage module is also used to determine whether the storage feedback information sent by the cloud is received (the storage feedback information includes encrypted data storage feedback information and unencrypted data storage feedback information), and after determining that the storage feedback information is received, complete the data storage process. Of course, if the corresponding storage feedback information is not received, the corresponding data will be uploaded again. For example, if the encrypted data storage feedback information is not received, then the encrypted data will be uploaded again.

[0060] In this way, encrypting and storing the sensitive data in the bank's internal control evaluation and assessment data can prevent the data from being tampered with during the collection and transmission process, thereby improving the security and controllability of data use.

[0061] After the encrypted storage of the data is completed, the visual display of the statistical analysis results can be carried out, that is: the visual display module is used to visually display the statistical analysis results to complete the visual management of the bank's internal control assessment after the visual display. Among them, in this embodiment, for example, the foregoing visual display module is used to perform annotation processing on the risk data in the statistical analysis results and visually display the statistical analysis results in a preset manner.

[0062] Specifically, according to the foregoing analysis results of the change trend of the assessment data, the data with a change amount greater than the preset value can be used as risk data and annotated. In this way, the key display of risk points can be carried out. At the same time, early warning reminders can also be given to the risk points, so as to achieve the function of early warning. Further, for example, the foregoing preset manner may include, but is not limited to, graphic methods and / or chart methods. For example, the statistical analysis results are visually displayed through charts (such as bar charts, line charts, pie charts, etc.) and / or graphics (such as flowcharts, mind maps, dashboards, etc.), so as to facilitate bank staff to intuitively understand the bank's internal control evaluation and assessment data and avoid the problem of long interpretation time existing in the traditional form of presenting data in a report.

[0063] Thus, through the foregoing description, the visual management system for bank internal control assessment provided in this embodiment realizes the automated processing of the collection, analysis, and result feedback of internal control assessment and evaluation data. In this way, compared with manual processing, not only is the statistical analysis time significantly shortened, but also the data accuracy is ensured. At the same time, by encrypting and storing sensitive data in the internal control assessment and evaluation data, while ensuring the security of data retention and sharing, it can prevent data from being tampered with during the collection and transmission processes, thereby improving the security and controllability of data usage. Therefore, this system is very suitable for large-scale application and promotion.

[0064] In a possible design, the following provides the specific working process of the foregoing data encryption storage module:

[0065] Among them, in this embodiment, taking the data encryption storage module as an example, it can, but is not limited to, adopt a symmetric key block cipher encryption algorithm to encrypt each sensitive data to obtain a number of encrypted data. Among them, the foregoing symmetric key block cipher encryption algorithm can, but is not limited to, include: exclusive-or encryption algorithm, modulo addition encryption algorithm, and left bitwise circular encryption algorithm. Thus, this embodiment is based on the foregoing exclusive-or encryption algorithm, modulo addition encryption algorithm, and left bitwise circular encryption algorithm to implement the encryption of each sensitive data, thereby obtaining a number of encrypted data.

[0066] Specifically, this embodiment takes any sensitive data as an example to elaborate on the data encryption process:

[0067] In specific applications, the data encryption storage module is used to divide the any sensitive data into two segments in the order from left to right to obtain a first segment of data and a second segment of data (that is, equally divide the any sensitive data into left and right parts). Among them, for example, the lengths of the first segment of data and the second segment of data are equal and both are 64 bits. Of course, they can also be divided into data segments of different lengths according to actual use.

[0068] After completing the division of the any sensitive data, the data encryption storage module is used to adopt the exclusive-or encryption algorithm, the modulo addition encryption algorithm, and the left bitwise circular encryption algorithm, and based on the Feistel network, perform multiple rounds of encryption processing on the first segment of data and the second segment of data, so as to obtain the encrypted data corresponding to the any sensitive data after multiple rounds of encryption processing, and after polling all sensitive data, obtain the encrypted data corresponding to each sensitive data.

[0069] In specific implementation, the following discloses the detailed process of multiple rounds of encryption based on the Feistel network:

[0070] That is, the data encryption and storage module is first used to generate the round key for the i-th round of encryption processing, and uses the XOR encryption algorithm and the round key to perform initial encryption processing on the second segment of data to obtain the initially encrypted second segment of data, where the initial value of i is 1; in this embodiment, for example, 32 rounds of encryption are performed. Therefore, a 128-bit master key can be used, and then, using the 128-bit master key, 32 64-bit round keys are generated. Therefore, each round of encryption corresponds to a different round key.

[0071] Meanwhile, for example, but not limited to, the following formula (1) can be used to perform initial encryption processing on the second segment of data to obtain the initially encrypted second segment of data.

[0072]

[0073] In the above formula (1), Code x represents the initially encrypted second segment of data, PT 2 represents the second segment of data, represents the round key for the i-th round of encryption processing, represents the XOR operation.

[0074] In this way, after the initial encryption of the second segment of data is completed, the initially encrypted second segment of data can be processed by a round function, that is: the data encryption and storage module is used to sequentially use the modulo addition encryption algorithm and the left bitwise circular encryption algorithm to perform secondary encryption processing on the initially encrypted second segment of data to obtain the second segment of data after secondary encryption.

[0075] In this embodiment, for example, but not limited to, the following formula (2) and formula (3) are sequentially used to perform secondary encryption processing on the initially encrypted second segment of data to obtain the second segment of data after secondary encryption.

[0076] Code m =(Code x +key m )modY (2)

[0077] Code R =(Code m <<N)(Code m >>(8-N)) (3)

[0078] In the above formula (2), Code m represents the initially encrypted second segment of data encrypted by the modulo addition encryption algorithm, Code x represents the initially encrypted second segment of data, key m represents the modulo addition encryption key, Y represents the modulo parameter, and mod represents the modulo operation;

[0079] In the above formula (3), Code d represents the second segment of data after the secondary encryption, N represents the number of displacement bits, << represents the left shift symbol, >> represents the right shift symbol, and | represents the binary operator; in this embodiment, the modulo addition encryption key can be preset in advance, and no specific limitation is made here.

[0080] In this way, after the aforementioned modulo addition encryption and left bitwise circular encryption, the second segment of data after the secondary encryption can be obtained; then, an exclusive OR operation can be performed with the aforementioned first segment of data, thereby completing the encryption process of the i-th round, that is: a data encryption and storage module, configured to perform an exclusive OR process on the second segment of data after the secondary encryption and the first segment of data, so as to obtain any sensitive data after the i-th round of encryption after the exclusive OR process.

[0081] At the same time, after completing the encryption process of the i-th round, it is necessary to update the first segment of data and the second segment of data for subsequent next-round encryption processing. Among them, the data update process is: the data encryption and storage module is further configured to increment i by 1, update the first segment of data to the second segment of data in the (i - 1)-th round, and update the second segment of data to any sensitive data after the (i - 1)-th round of encryption, and regenerate the round key during the i-th round of encryption processing until i is equal to n, and the encrypted data corresponding to any sensitive data is obtained, where n is the preset number of encryption rounds.

[0082] In this embodiment, an example is used to illustrate the aforementioned multi-round encryption process: when i is 2, that is, when the first round of encryption ends and the second round of encryption enters, the first segment of data (i.e., the left half of the data) is updated to the second segment of data in the first round (i.e., the right half of the data during the first round of encryption), and then the second segment of data during the second round of encryption is updated to any sensitive data after the first round of encryption processing; then, encryption is performed in the aforementioned manner to complete the second round of encryption; then, based on the aforementioned principle, 32 rounds of encryption are performed until the last round of encryption is completed, and the left and right parts are merged to obtain the encrypted data corresponding to any sensitive data.

[0083] In this way, the aforementioned data encryption process can be summarized as:

[0084] The first step: Divide the plaintext data block into two equal parts, usually referred to as the left half (L) and the right half (R).

[0085] The second step: For each round (a total of 32 rounds), perform the following steps:

[0086] a. Combine the current right half with the Round Key and then process it through the RoundFunction. The RoundFunction can be any complex operation such as modular addition, cyclic shift, etc.

[0087] b. XOR with the left half: Perform an XOR operation on the output of the RoundFunction and the original left half.

[0088] c. Swap the left and right halves: Swap the left and right halves so that the original right half becomes the left half of the next round, and the result of the XOR operation becomes the right half of the next round.

[0089] Step 3: After the last round of iteration, the left and right halves are no longer swapped to ensure the reversibility of the encryption process.

[0090] Step 4: Combine the left and right halves after the last round of iteration to obtain the final ciphertext.

[0091] In this way, through the foregoing method, the encryption process of each sensitive data can be completed. Then, by storing the encrypted data in the cloud database, an encrypted data storage feedback is obtained, and by storing the non-sensitive data (i.e., data that does not need to be encrypted) in the cloud database, an unencrypted data storage feedback is obtained. In this way, the data storage can be completed.

[0092] Meanwhile, this embodiment uses a symmetric key block cipher encryption algorithm for data encryption, which has the following advantages compared with the conventional symmetric encryption algorithm:

[0093] ① Higher encryption strength: Conventional symmetric encryption algorithms usually encrypt data bit by bit or byte by byte, while the symmetric key block cipher encryption algorithm divides the plaintext data into several fixed-length blocks and then encrypts each block separately. An attacker needs to crack the encryption information of multiple blocks simultaneously, rather than just targeting a single data unit as in conventional symmetric encryption, which greatly increases the difficulty and time cost of cracking.

[0094] Key expansion enhances security: In the symmetric key block cipher encryption algorithm, multiple sub-keys can be generated from the original key through the key expansion algorithm, and each sub-key is used for different rounds or stages in the encryption process. This makes the use of the key more complex and diverse, enhancing the security of encryption. In contrast, conventional symmetric encryption algorithms usually use a single key for encryption and decryption, and the security of the key completely depends on its own confidentiality.

[0095] ② Stronger anti - attack ability, diffusion and confusion characteristics: The symmetric - key block cipher encryption algorithm is designed with good diffusion and confusion characteristics. The diffusion characteristic makes small changes in the plaintext data result in huge changes in the ciphertext, making it difficult for attackers to infer the content of the plaintext by analyzing the differences in the ciphertext. The confusion characteristic, through complex non - linear transformations, makes the relationship between the ciphertext and the key extremely complex, increasing the difficulty for attackers to determine the key by analyzing the ciphertext. Conventional symmetric encryption algorithms may be relatively weak in terms of diffusion and confusion and are vulnerable to some specific attack methods, such as differential cryptanalysis and linear cryptanalysis, etc.

[0096] Resistance to known - plaintext attacks: Since the block cipher encryption algorithm encrypts each block independently, even if an attacker obtains some plaintext - ciphertext pairs, it is difficult to use this known information to crack the encrypted content of other blocks. When facing known - plaintext attacks, conventional symmetric encryption algorithms may, due to the singularity of the key and the relative simplicity of the encryption method, make it easier for attackers to deduce the key or crack other unencrypted data by analyzing the known plaintext - ciphertext pairs.

[0097] ③ Stronger parallel computing ability

[0098] Independent block encryption is convenient for parallel processing: The block characteristic of the symmetric - key block cipher encryption algorithm makes it very suitable for parallel computing. The encryption process of each block is independent and can be encrypted simultaneously on multiple processors or computing units, thus greatly improving the encryption efficiency. Especially for the encryption of a large amount of data, the parallel computing ability can significantly shorten the encryption time required. Conventional symmetric encryption algorithms, due to their bit - by - bit or byte - by - byte encryption methods, are difficult to achieve parallel computing and are relatively inefficient when dealing with a large amount of data.

[0099] ④ Smaller error - propagation range

[0100] Block isolation limits the impact of errors: In the symmetric - key block cipher encryption algorithm, an encryption error in one block only affects the decryption result of that block and will not spread to other blocks. This means that during data transmission or storage, if an error occurs in an individual block, only the data in that block cannot be correctly decrypted, without affecting the integrity and availability of the entire data. In contrast, in a conventional symmetric encryption algorithm, an error in one data bit may cause decryption errors for all subsequent encrypted data, resulting in more serious consequences.

[0101] ⑤ More in line with modern cryptography standards and requirements

[0102] Widely recognized and applied: Many symmetric key block cipher encryption algorithms, such as AES (Advanced Encryption Standard), are standard encryption algorithms that have been widely recognized and adopted after rigorous cryptographic analysis and evaluation. These algorithms have been fully verified in terms of security, efficiency, and practicality, and can meet the high requirements for data encryption in the modern information security field.

[0103] Compatibility and interoperability: Due to the standardization and wide application of symmetric key block cipher encryption algorithms, it is easier to achieve compatibility and interoperability between different systems and devices. For example, in the fields of network communication, e-commerce, finance, etc., using the same block cipher encryption algorithm can ensure the secure transmission and sharing of data between different platforms.

[0104] Based on this, compared with storing data in traditional devices (such as hard disks, USB flash drives, etc.), in this embodiment, the sensitive-level data to be archived is encrypted and then transmitted to the cloud database for storage, which can effectively prevent improper operations or data leakage by internal personnel, thereby strengthening the internal data security management of the bank.

[0105] Furthermore, in this embodiment, for example, the system is also provided with a task initiation module, that is, to initiate the bank internal control assessment process. So that after the data collection module receives the instruction sent by the task initiation module, it sends a data entry request to the terminals of different departments, thereby collecting the bank internal control evaluation and assessment data of different departments; in this way, from the initiation of the task, task assignment to data collection, analysis, and result feedback, etc., can all be automatically completed, thereby realizing the automation of the bank internal control assessment process.

[0106] At the same time, in this embodiment, for example, the system can also be provided with a dynamic visualization function, that is, to update the progress of the internal control assessment in real time or regularly; for example, in the form of a progress bar to show the completed stages and remaining stages of a certain assessment task (such as the internal audit process), or to indicate the status of key assessment nodes (such as whether major risk points are found) through a flashing indicator light. This dynamic display method can enable the bank management to timely understand the dynamic changes of the internal control assessment, so as to make a quick response when problems occur.

[0107] In addition, the decryption key can be distributed to different authorized personnel or terminals according to different business requirements and management requirements within the bank; in this way, precisely control the scope of data sharing, ensure that the data is only accessed and used by authorized personnel, and improve the security and controllability of data sharing.

[0108] Thus, through the foregoing detailed description of the visual management system for bank internal control assessment, the present invention has the following advantages:

[0109] (1) It realizes the automation of data processing for the internal control assessment process of banks, which not only greatly improves the processing efficiency but also ensures the accuracy of data.

[0110] (2) Through charts (such as bar charts, line charts, pie charts, etc.), graphs (such as flowcharts, mind maps, etc.) or dashboards, etc., the complex indicators of bank internal control assessment can be displayed through an intuitive visual interface. In this way, the change trends and risk warnings of the annual internal control assessment of the whole bank can be intuitively and comprehensively displayed through a visual large screen, providing efficient, accurate, systematic and low-cost internal control management services, reducing the data interpretation time and improving the convenience of data interpretation.

[0111] (3) Encrypt the sensitive-level data to be archived and then transmit it to the cloud database for storage, which can effectively prevent improper operations or data leakage by internal personnel, strengthening the data security management within the bank; at the same time, it can also precisely control the data sharing scope to ensure that the data is only accessed and used by authorized personnel, improving the security and controllability of data sharing.

[0112] (4) Dynamically display the process, that is, update the progress of internal control assessment in real time or regularly. This dynamic display method allows the bank management to timely understand the dynamic changes of internal control assessment so that they can quickly respond when problems occur.

[0113] As Figure 2 shown, the second aspect of this embodiment provides a working method of the visual management system for bank internal control assessment described in the first aspect of the embodiment. Among them, the running process of this method can but is not limited to the following steps S1 to S5.

[0114] S1. Obtain the bank internal control evaluation and assessment data input by different departments.

[0115] S2. Perform data preprocessing on each bank internal control evaluation and assessment data to obtain each preprocessed bank internal control evaluation and assessment data.

[0116] S3. Perform data statistical analysis processing on each preprocessed bank internal control evaluation and assessment data to obtain the statistical analysis results of all bank internal control evaluation and assessment data, and perform data classification processing on each preprocessed bank internal control evaluation and assessment data to obtain several sensitive data and several non-sensitive data.

[0117] S4. Perform encryption processing on each sensitive data to obtain several encrypted data, and upload the several encrypted data and several non-sensitive data to the cloud database for storage.

[0118] S5. Perform visual display on the statistical analysis results to complete the visual management of bank internal control assessment after the visual display.

[0119] For the working process, working details and technical effects of this embodiment, reference can be made to the first aspect of the embodiment, which will not be elaborated here.

[0120] In the third aspect of this embodiment, an electronic device is provided, including: a memory, a processor and a transceiver that are communicatively connected in sequence. Among them, the memory is used to store computer programs, the transceiver is used to send and receive messages, and the processor is used to read the computer programs and execute the working method of the visual management system for bank internal control assessment as described in the second aspect of the embodiment.

[0121] Specifically, the memory may include, but is not limited to, random access memory (RAM), read only memory (ROM), flash memory, first input first output (FIFO) and / or first in last out (FILO), etc.; specifically, the processor may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor can be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), PLA (Programmable Logic Array). At the same time, the processor can also include a main processor and a coprocessor. The main processor is a processor used to process data in the wake state, also known as the CPU (Central Processing Unit); the coprocessor is a low-power processor used to process data in the standby state.

[0122] In some embodiments, the processor may be integrated with a GPU (Graphics Processing Unit), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. For example, the processor may not be limited to using a microprocessor of the STM32F105 series, a reduced instruction set computer (RISC) microprocessor, an X86 architecture processor, or a processor integrated with an embedded neural-network processing unit (NPU); the transceiver may be, but is not limited to, a Wi-Fi wireless transceiver, a Bluetooth wireless transceiver, a General Packet Radio Service (GPRS) wireless transceiver, a ZigBee (low-power local area network protocol based on the IEEE 802.15.4 standard) wireless transceiver, a 3G transceiver, a 4G transceiver, and / or a 5G transceiver, etc. In addition, the device may also include, but is not limited to, a power module, a display screen, and other necessary components.

[0123] For the working process, working details, and technical effects of the electronic device provided in this embodiment, reference may be made to the first aspect of the embodiment, which will not be elaborated here.

[0124] In the fourth aspect of this embodiment, a storage medium storing instructions for the working method of the visual management system for bank internal control assessment described in the second aspect of the embodiment is provided, that is, instructions are stored on the storage medium, and when the instructions run on a computer, they execute the working method of the visual management system for bank internal control assessment described in the second aspect of the embodiment.

[0125] Among them, the storage medium refers to a carrier for storing data, and may include, but is not limited to, a floppy disk, an optical disc, a hard disk, a flash memory, a USB flash drive, and / or a Memory Stick, etc. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.

[0126] For the working process, working details, and technical effects of the storage medium provided in this embodiment, reference may be made to the first aspect of the embodiment, which will not be elaborated here.

[0127] In the fifth aspect of this embodiment, a computer program product containing instructions is provided. When the instructions run on a computer, the computer is caused to execute the working method of the visual management system for bank internal control assessment described in the second aspect of the embodiment, where the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.

[0128] Finally, it should be noted that the above are only the preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A visual management system for bank internal control assessment, characterized in that: include: The data collection module is used to obtain the bank's internal control evaluation and assessment data entered by different departments, and send the internal control evaluation and assessment data of each bank to the data pre-review module; The data pre-review module is used to pre-process the internal control evaluation and assessment data of each bank, obtain the pre-processed internal control evaluation and assessment data of each bank, and send it to the data analysis module; The data analysis module is used to perform data statistical analysis on each pre-processed bank internal control evaluation and assessment data to obtain statistical analysis results of all bank internal control evaluation and assessment data, and to perform data classification on each pre-processed bank internal control evaluation and assessment data to obtain a number of sensitive data and a number of non-sensitive data; The data encryption storage module is used to encrypt various sensitive data to obtain a number of encrypted data, and upload the encrypted data and a number of non-sensitive data to the cloud database for storage; The visualization display module is used to visualize the statistical analysis results so as to complete the visualization management of the bank's internal control assessment after the visualization display.

2. A visual management system for bank internal control assessment according to claim 1, characterized in that: The data pre-review module is used to perform error data correction and deduplication processing on each bank's internal control evaluation and assessment data in turn, so as to obtain deduplicated internal control evaluation and assessment data of each bank after deduplication processing; The data pre-review module is used to perform missing value filling processing and data integrity verification processing on each deduplicated bank internal control evaluation and assessment data in turn, so as to obtain each initial bank internal control evaluation and assessment data after the data integrity verification processing; The data pre-review module is also used to perform format standardization processing on each initial bank internal control evaluation and assessment data, so as to obtain each pre-processed bank internal control evaluation and assessment data after the format standardization processing.

3. A visual management system for bank internal control assessment according to claim 1, characterized in that: The data encryption storage module is used to encrypt various sensitive data using a symmetric key block cipher encryption algorithm to obtain a number of encrypted data.

4. A visual management system for bank internal control assessment according to claim 3, characterized in that: The symmetric key block cipher encryption algorithm includes: XOR encryption algorithm, modulo addition encryption algorithm and left bitwise circular encryption algorithm; Wherein, for any sensitive data, the data encryption storage module is used to divide the any sensitive data into two segments in order from left to right to obtain a first segment of data and a second segment of data, wherein the lengths of the first segment of data and the second segment of data are equal; The data encryption storage module is also used to adopt the XOR encryption algorithm, the modulo addition encryption algorithm and the left bitwise cyclic encryption algorithm, and based on the Festel network, perform multiple rounds of encryption processing on the first segment data and the second segment data, so as to obtain the encrypted data corresponding to any sensitive data after multiple rounds of encryption processing, and obtain the encrypted data corresponding to each sensitive data after all sensitive data are polled.

5. A visual management system for bank internal control assessment according to claim 4, characterized in that: The data encryption storage module is used to generate a round key for the i-th round of encryption processing, and use an XOR encryption algorithm and the round key to perform initial encryption processing on the second segment of data to obtain an initially encrypted second segment of data, wherein the initial value of i is 1; A data encryption storage module, used to sequentially use the modulo addition encryption algorithm and the left bitwise cyclic encryption algorithm to perform secondary encryption processing on the initially encrypted second segment of data to obtain the secondary encrypted second segment of data; A data encryption storage module, used for performing an XOR process on the second segment of data after the secondary encryption and the first segment of data, so as to obtain any sensitive data after the i-th round of encryption after the XOR process; The data encryption storage module is also used to add 1 to i, update the first segment of data to the second segment of data in the i-1th round, and update the second segment of data to any sensitive data encrypted in the i-1th round, and regenerate the round key during the i-th round of encryption processing, until i is equal to n, to obtain the encrypted data corresponding to any sensitive data, wherein n is the preset number of encryption rounds.

6. A visual management system for bank internal control assessment according to claim 5, characterized in that: The data encryption storage module is used to perform initial encryption processing on the second segment of data using the following formula (1) to obtain initial encrypted second segment of data; In the above formula (1), Code x represents the first encrypted second segment of data, PT2 represents the second segment of data, represents the round key for the i-th round of encryption processing, Represents the exclusive-or operation.

7. According to the visual management system for internal control assessment of a bank as claimed in claim 5, the data encryption storage module is used to sequentially use the following formulas (2) and (3) to perform secondary encryption processing on the initially encrypted second segment data to obtain the secondary encrypted second segment data; Code m =(Code x +key m )modY (2) Code R =(Code m <<N)(Code m >>(8-N)) (3) In the above formula (2), Code m Indicates the initial encrypted second segment of data after being encrypted by the modulo addition encryption algorithm. Code x Indicates the initial encryption of the second segment of data, key m represents the modulo addition encryption key, Y represents the modulo parameter, and mod represents the modulo operation; In the above formula (3), Code d It represents the second segment of data after the secondary encryption, N represents the number of shift bits, << represents the left shift sign, and >> represents the right shift sign.

8. A visual management system for bank internal control assessment according to claim 1, characterized in that: The visualization display module is used to annotate the risk data in the statistical analysis results and to visualize the statistical analysis results in a preset manner, wherein the preset manner includes a graphical manner and / or a chart manner.

9. A visual management system for bank internal control assessment according to claim 1, characterized in that: The data encryption storage module is also used to determine whether storage feedback information sent by the cloud is received, and complete the data storage process after determining that the storage feedback information is received, wherein the storage feedback information includes encrypted data storage feedback information and unencrypted data storage feedback information.

10. A working method of a visual management system for bank internal control assessment according to any one of claims 1 to 9, characterized in that: include: Obtain bank internal control evaluation and assessment data entered by different departments; Perform data preprocessing on the internal control evaluation and assessment data of each bank to obtain the preprocessed internal control evaluation and assessment data of each bank; Performing data statistical analysis on each pre-processed bank internal control evaluation and assessment data to obtain statistical analysis results of all bank internal control evaluation and assessment data, and performing data classification on each pre-processed bank internal control evaluation and assessment data to obtain a number of sensitive data and a number of non-sensitive data; Encrypt each sensitive data to obtain a number of encrypted data, and upload the encrypted data and a number of non-sensitive data to a cloud database for storage; The statistical analysis results are visualized to complete the visual management of the bank's internal control assessment after the visual display.