Public data storage management system based on artificial intelligence
By introducing a public data storage management system based on artificial intelligence into the public information management system, using technical means such as microservice architecture, containerized storage technology and security detection models, the problems of false information and malicious virus data in the public information management system are solved, data security management and isolation are realized, and information security is improved.
Patent Information
- Application Number
- CN202510171982.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-06-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
There is a large amount of false information and malicious virus data in the existing public information management system, resulting in data breaches and information security threats.
The public data storage management system based on artificial intelligence is adopted, including an automated data management platform, network isolation module, storage and deployment module, container planning module, log management module, etc., and data security management and isolation are achieved through technical means such as microservice architecture, containerized storage technology, security detection model and network isolation firewall.
Through the combination of network isolation and security detection models, we ensure the security of data during transmission, avoid the spread of false information and malicious virus data, and improve the security and reliability of public data.
Smart Images

Figure CN120105474A_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of public information management technology, and specifically, relates to a public data storage and management system based on artificial intelligence. Background Art
[0002] The concept of smart city originated from the field of media. It refers to the use of various information technologies or innovative concepts to connect and integrate the city's systems and services in order to improve the efficiency of resource utilization, optimize urban management and services, and improve the quality of life of citizens. Smart city is an advanced form of urban informatization based on the next generation of innovation in the knowledge society that makes full use of the new generation of information technology in all walks of life in the city, realizing the deep integration of informatization, industrialization and urbanization, which will help alleviate the "big city disease", improve urban management effectiveness and improve the quality of life of citizens.
[0003] At present, more and more attention is paid to the public security of the society, and the collection and organization of public information is imperative. Many enterprises or units use computers to manage the collection, processing, handling and transmission of public information. However, due to the insufficiency of existing technology, there is a large amount of false information in the existing public information. Some malicious virus data is hidden in the public data and collected together in the public storage management computer, which may cause data leakage and threaten the public information security. Summary of the invention
[0004] In order to solve the above problems and technical defects, the present application adopts the following technical solution, a public data storage and management system based on artificial intelligence, characterized in that it includes:
[0005] Automated data management platform, which is used to establish a module management platform using microservice architecture to deploy, configure and manage various functional modules in the system;
[0006] The network isolation module is used to establish a network isolation firewall to isolate the system from the external network and perform security checks on data when the external network transmits data;
[0007] The storage deployment module is used to containerize the system database using containerized storage technology and store data in different storage containers according to needs;
[0008] The container planning module is used to detect and evaluate the system's containers, and to plan and optimize the capacity of storage containers based on the detection and evaluation data;
[0009] The log management module is used to record the system's operation records and operation logs, and to manage and review the record logs.
[0010] Preferably, the network isolation module includes: a one-way data receiving module, a one-way data output module and a security detection module;
[0011] A one-way data receiving module is used to transmit data from the external network to the system in one direction;
[0012] The data unidirectional output module is used to transmit the system data unidirectionally to the external network;
[0013] The security detection module is used to establish a security detection model and perform security detection on the data transmitted by the data unidirectional receiving module and the data unidirectional output module.
[0014] Furthermore, the safety detection process of the safety detection model is as follows:
[0015] Obtain security standard data, deploy IDS / IPS system, use IDS / IPS system to perform standard analysis on security standard data, obtain standard analysis results, and generate security detection standard range according to standard analysis results;
[0016] Use the IDS / IPS system to perform security analysis on the data transmitted by the data unidirectional receiving module and the data unidirectional output module, obtain the security analysis results, and compare the security analysis results with the security detection standard range to obtain the security detection results.
[0017] Furthermore, the process of judging and comparing is as follows:
[0018] Two safety thresholds are preset, the two safety thresholds are respectively a first safety threshold and a second safety threshold, wherein the first safety threshold is greater than the second safety threshold;
[0019] Calculate the safety deviation value between the safety analysis result and the safety detection standard range, and compare the safety deviation value with the first safety threshold and the second safety threshold;
[0020] When the safety deviation value is greater than or equal to the first safety threshold, the transmitted data is judged to be risky data;
[0021] When the safety deviation value is less than or equal to the second safety threshold, the transmitted data is determined to be safe data;
[0022] Otherwise, use YARA rules to match risk data features. If there are no risk data features, the transmitted data is judged to be safe data.
[0023] Furthermore, the data transmitted by the data unidirectional receiving module and the data unidirectional output module need to be encrypted and protected using the IPsec encryption protocol.
[0024] Preferably, the storage deployment module uses Block Storage technology to containerize the system database, first deploys and expands the container process, packages data of different types and users into the corresponding container process, and then caches, shards and load balances according to the storage usage of each container process.
[0025] Preferably, it also includes an interface control module, which is used to generate a log report based on the recorded logs in the log management module, generate a visual chart based on the security detection results of the network isolation module and the detection and evaluation results of the container planning module, and check the system status, so that the administrator can configure and manage the system based on the log report and the visual chart.
[0026] Furthermore, it also includes an authentication management module, which is used to perform identity authentication, identity marking and identity management on the data sending end of the external network, and authenticate the identity by generating a token and returning it to the data sending end. When the identity authentication of the data sending end is not compliant, a system warning is issued, and the data sending end is marked. Data from the data sending end with an identity mark is not received, and data is not sent to the data sending end with an identity mark. The administrator performs manual identity management and removes the identity mark.
[0027] An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the content of a public data storage management system based on artificial intelligence as described above is implemented.
[0028] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the content of a public data storage management system based on artificial intelligence as described above.
[0029] Compared with the prior art, the beneficial effects of this application are:
[0030] (1) This application establishes a network isolation firewall through a network isolation module to isolate the system from the external network. When the external network transmits data, the data is security checked, and the data is received and transmitted in one direction through a data unidirectional receiving module and a data unidirectional output module. Then, the system database is containerized using containerized storage technology in combination with the storage deployment module, so that the data will not interfere with each other, thereby improving the security of public data;
[0031] (2) The present application establishes a security detection model to perform security detection on the transmitted data, deploys an IDS / IPS system, uses the IDS / IPS system to perform standard analysis on the security standard data, obtains the standard analysis results, and generates a security detection standard range. The IDS / IPS system is used to perform security analysis on the data transmitted by the data unidirectional receiving module and the data unidirectional output module, obtains the security analysis results, and compares the security analysis results with the security detection standard range to obtain the security detection results, thereby accurately judging whether the target transmitted data is safe and avoiding the risk of risk data causing security risks to other data. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In the attached picture:
[0033] Figure 1 A schematic diagram of the system structure of an embodiment of the present application;
[0034] Figure 2 This is a schematic diagram of the device structure of an embodiment of the present application. DETAILED DESCRIPTION
[0035] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Generally, the components of the embodiments of the present application described and shown in the drawings here can be arranged and designed in various different configurations.
[0036] Example 1
[0037] like Figure 1 As shown, a public data storage management system based on artificial intelligence includes:
[0038] Automated data management platform, which is used to establish a module management platform using microservice architecture to deploy, configure and manage various functional modules in the system;
[0039] The network isolation module is used to establish a network isolation firewall to isolate the system from the external network and perform security checks on data when the external network transmits data;
[0040] The network isolation module includes: a one-way data receiving module, a one-way data output module and a security detection module;
[0041] A one-way data receiving module is used to transmit data from the external network to the system in one direction;
[0042] The data unidirectional output module is used to transmit the system data unidirectionally to the external network;
[0043] The security detection module is used to establish a security detection model and perform security detection on the data transmitted by the data unidirectional receiving module and the data unidirectional output module.
[0044] The safety detection process of the safety detection model is as follows:
[0045] Obtain security standard data, deploy IDS / IPS system, use IDS / IPS system to perform standard analysis on security standard data, obtain standard analysis results, and generate security detection standard range according to standard analysis results;
[0046] Use the IDS / IPS system to perform security analysis on the data transmitted by the data unidirectional receiving module and the data unidirectional output module, obtain the security analysis results, and compare the security analysis results with the security detection standard range to obtain the security detection results.
[0047] The judgment and comparison process is as follows:
[0048] Two safety thresholds are preset, the two safety thresholds are respectively a first safety threshold and a second safety threshold, wherein the first safety threshold is greater than the second safety threshold;
[0049] Calculate the safety deviation value between the safety analysis result and the safety detection standard range, and compare the safety deviation value with the first safety threshold and the second safety threshold;
[0050] When the safety deviation value is greater than or equal to the first safety threshold, the transmitted data is judged to be risky data;
[0051] When the safety deviation value is less than or equal to the second safety threshold, the transmitted data is determined to be safe data;
[0052] Otherwise, use YARA rules to match risk data features. If there are no risk data features, the transmitted data is judged to be safe data.
[0053] The data transmitted by the data unidirectional receiving module and the data unidirectional output module needs to be encrypted and protected using the IPsec encryption protocol.
[0054] The storage deployment module is used to containerize the system database using containerized storage technology and store data in different storage containers according to needs;
[0055] The container planning module is used to detect and evaluate the system's containers, and to plan and optimize the capacity of storage containers based on the detection and evaluation data;
[0056] The storage deployment module uses Block Storage technology to containerize the system database. It first deploys and expands the container process, packages data of different types and users into the corresponding container process, and then caches, shards, and load balances data based on the storage usage of each container process.
[0057] The log management module is used to record the system's operation records and operation logs, and to manage and review the record logs.
[0058] It also includes an interface control module, which is used to generate log reports based on the recorded logs in the log management module, generate visual charts based on the security detection results of the network isolation module and the detection and evaluation results of the container planning module, and view the system status, so that the administrator can configure and manage the system based on the log reports and visual charts.
[0059] It also includes an authentication management module, which is used to perform identity authentication, identity tagging and identity management on the data sending end of the external network. The identity is authenticated by generating a token and returning it to the data sending end. When the identity authentication of the data sending end is not compliant, a system warning is issued, and the data sending end is marked. Data from the data sending end with an identity tag is not received, and data is not sent to the data sending end with an identity tag. The administrator performs manual identity management and removes the identity tag.
[0060] Embodiment 2:
[0061] like Figure 2 As shown, from a hardware level, the present application provides an embodiment of an electronic device that implements all or part of the contents of a public data storage management system based on artificial intelligence, wherein the electronic device includes a service processor and a distributed memory, wherein the service processor is connected to the memory, wherein the distributed memory stores a service self-management program configured to store machine-readable instructions, and wherein the service processor executes the service self-management program, and when the instructions are executed by the processor, a public data storage management system based on artificial intelligence as described above is implemented.
[0062] From the hardware level, in order to effectively improve the flexibility, versatility and efficiency of data collection, the present application provides an embodiment of an electronic device that implements all or part of the contents of a public data storage and management system based on artificial intelligence, and the electronic device specifically includes the following contents:
[0063] Processor, memory, communication interface and bus; wherein the processor, memory and communication interface communicate with each other through the bus; the communication interface is used to realize information transmission between the data acquisition device based on the distributed model and the core business system, user terminal and related database and other related equipment; the logic controller can be a desktop computer, a tablet computer and a mobile terminal, etc., but the present embodiment is not limited thereto. In the present embodiment, the logic controller can be implemented with reference to an embodiment of a public data storage management system based on artificial intelligence and an embodiment of a data acquisition device based on a distributed model, and the contents thereof are incorporated herein and repeated parts are not repeated.
[0064] It is understandable that the user terminal may include a smart phone, a tablet electronic device, a network set-top box, a portable computer, a desktop computer, a personal digital assistant (PDA), a vehicle-mounted device, a smart wearable device, etc. Among them, the smart wearable device may include smart glasses, a smart watch, a smart bracelet, etc.
[0065] In practical applications, the academic opinion annotation and analysis method can be performed on the electronic device side as described above, or all operations can be completed in the client device. The specific selection can be based on the processing capability of the client device and the limitations of the user's usage scenario, etc. This application does not limit this. If all operations are completed in the client device, the client device may also include a processor.
[0066] The above-mentioned client device may have a communication module (i.e., a communication unit), which can communicate with a remote server to realize data transmission with the server. The server may include a server on the task scheduling center side, and other implementation scenarios may also include a server on an intermediate platform, such as a server on a third-party server platform that has a communication link with the task scheduling center server. The server may include a single computer device, or a server cluster consisting of multiple servers, or a server structure of a distributed device.
[0067] Example 3
[0068] The embodiments of the present application also provide a computer-readable storage medium that can implement all the contents of a public data storage and management system based on artificial intelligence in the above embodiments, in which the execution subject is a server or a client. The computer-readable storage medium stores a computer program, which, when executed by a processor, implements all the contents of a public data storage and management system based on artificial intelligence in the above embodiments, in which the execution subject is a server or a client.
[0069] The embodiments of the present application may be provided as methods, devices, or computer program products, and therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0070] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (apparatus), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0071] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0072] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0073] The above-mentioned embodiments only express the preferred implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for ordinary technicians in this field, several modifications, improvements and substitutions can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application.
Claims
1. A public data storage and management system based on artificial intelligence, characterized in that: include: Automated data management platform, which is used to establish a module management platform using microservice architecture to deploy, configure and manage various functional modules in the system; The network isolation module is used to establish a network isolation firewall to isolate the system from the external network and perform security checks on data when the external network transmits data; The storage deployment module is used to containerize the system database using containerized storage technology and store data in different storage containers according to needs; The container planning module is used to detect and evaluate the system's containers, and to plan and optimize the capacity of storage containers based on the detection and evaluation data; The log management module is used to record the system's operation records and operation logs, and to manage and review the record logs.
2. The public data storage and management system based on artificial intelligence according to claim 1 is characterized in that: The network isolation module includes: a one-way data receiving module, a one-way data output module and a security detection module; A one-way data receiving module is used to transmit data from the external network to the system in one direction; The data unidirectional output module is used to transmit the system data unidirectionally to the external network; The security detection module is used to establish a security detection model and perform security detection on the data transmitted by the data unidirectional receiving module and the data unidirectional output module.
3. The public data storage and management system based on artificial intelligence according to claim 2 is characterized in that: The safety detection process of the safety detection model is as follows: Obtain security standard data, deploy IDS / IPS system, use IDS / IPS system to perform standard analysis on security standard data, obtain standard analysis results, and generate security detection standard range according to standard analysis results; Use the IDS / IPS system to perform security analysis on the data transmitted by the data unidirectional receiving module and the data unidirectional output module, obtain the security analysis results, and compare the security analysis results with the security detection standard range to obtain the security detection results.
4. The public data storage and management system based on artificial intelligence according to claim 3 is characterized in that: The judgment and comparison process is as follows: Two safety thresholds are preset, the two safety thresholds are respectively a first safety threshold and a second safety threshold, wherein the first safety threshold is greater than the second safety threshold; Calculate the safety deviation value between the safety analysis result and the safety detection standard range, and compare the safety deviation value with the first safety threshold and the second safety threshold; When the safety deviation value is greater than or equal to the first safety threshold, the transmitted data is judged to be risky data; When the safety deviation value is less than or equal to the second safety threshold, the transmitted data is determined to be safe data; Otherwise, use YARA rules to match risk data features. If there are no risk data features, the transmitted data is judged to be safe data.
5. The public data storage and management system based on artificial intelligence according to claim 2 is characterized in that: The data transmitted by the one-way data receiving module and the one-way data output module need to be encrypted and protected using the IPsec encryption protocol.
6. The public data storage and management system based on artificial intelligence according to claim 1 is characterized in that: The storage deployment module uses Block Storage technology to containerize the system database. It first deploys and expands the container process, packages data of different types and users into the corresponding container process, and then caches, segments and load balances according to the storage usage of each container process.
7. The public data storage and management system based on artificial intelligence according to claim 1 is characterized in that: It also includes an interface control module, which is used to generate log reports based on the recorded logs in the log management module, generate visual charts based on the security detection results of the network isolation module and the detection and evaluation results of the container planning module, and view the system status, so that the administrator can configure and manage the system based on the log reports and visual charts.
8. The public data storage and management system based on artificial intelligence according to claim 1 is characterized in that: It also includes an authentication management module, which is used to perform identity authentication, identity marking and identity management on the data sending end of the external network. The identity is authenticated by generating a token and returning it to the data sending end. When the identity authentication of the data sending end is not compliant, a system warning is issued, and the data sending end is marked. Data from the data sending end with an identity mark is not received, and data is not sent to the data sending end with an identity mark. The administrator performs manual identity management and removes the identity mark.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the content of the public data storage management system based on artificial intelligence described in claim 1 is implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the content of the public data storage management system based on artificial intelligence described in claim 1 is realized.
Citation Information
Patent Citations
Data isolation method under SAAS platform
CN117879902A
College resource deployment and service system based on AI intelligence
CN118642846A
Cloud platform rapid deployment system and method
CN119396422A
Security deployment and management mechanism for software container
US11416587B1