Data security protection system and method based on artificial intelligence

By designing a data security protection system based on artificial intelligence, the problem that existing systems cannot perform timeliness analysis and life cycle detection is solved, efficient security management of stored data is achieved, and data security and compliance are improved.

CN120145463AActive Publication Date: 2025-06-13山东九州信泰信息科技股份有限公司

Patent Information

Application Number
CN202510248063.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-04
Publication Date
2025-06-13
Estimated Expiration
2045-03-04

AI Technical Summary

Technical Problem

The existing data security protection system cannot perform timeliness analysis on stored data, cannot set the life cycle based on timeliness, cannot monitor and early warning of the storage environment, and cannot effectively control internal permissions and external data transmission, resulting in reduced data security.

Method used

Design a data security protection system based on artificial intelligence, including data timeliness analysis unit, cycle environment detection unit, internal authority control unit and external transmission control unit. Through these units, timeliness analysis, life cycle detection, authority management and outbound behavior analysis of stored data to ensure data security and compliance.

Benefits of technology

Through timeliness analysis and life cycle detection, we can improve the pertinence of data security protection and reduce the storage risk of stored data; avoid internal access abnormalities and data leakage through permission management; ensure security during data transmission through outbound behavior analysis and improve overall data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145463A_ABST
    Figure CN120145463A_ABST
Patent Text Reader

Abstract

The invention discloses a data security protection system and method based on artificial intelligence, relates to the technical field of data security protection, and solves the technical problem that in the prior art, internal permission setting and outgoing management and control cannot be performed. The method specifically comprises the following steps: an internal authority control unit performs authority control on internal access of a storage data output department, sets an authority granting department and a temporary authority department, collects authorized access data and temporary access data, and deduces whether internal authority control is normal or not according to data analysis; the external sending management and control unit analyzes and controls external sending of the storage data, constructs an external sending mode, obtains external sending node information and external sending numerical value information, and analyzes and deduces whether the external sending mode is safe or not according to the information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security protection, and particularly to an artificial intelligence-based data security protection system and method thereof. Background Art

[0002] A data security protection system is an integrated system for protecting the security, integrity, and availability of data; enterprises store a large amount of sensitive data such as business secrets, customer information, and financial data; the data security protection system can protect this data from improper access by internal employees and external network attacks.

[0003] However, in the prior art, it is impossible to perform timeliness analysis on stored data, and it is impossible to set a life cycle according to timeliness, so that it is impossible to monitor and warn the life cycle data storage environment according to the data type. In addition, it is impossible to control internal permissions and external transmissions, reducing the security of stored data.

[0004] In view of the above technical defects, a solution is proposed. Summary of the Invention

[0005] The purpose of the present invention is to solve the above-mentioned problems and propose an artificial intelligence-based data security protection system and method thereof.

[0006] The purpose of the present invention can be achieved through the following technical solutions: An artificial intelligence-based data security protection system includes a data security processing platform, which is communicatively connected to a plurality of data acquisition terminals, a data timeliness analysis unit, a periodic environment detection unit, an internal permission control unit, and an external transmission control unit; The data timeliness analysis unit performs data timeliness analysis on the stored data, divides the stored data into i sub-data, where i is a natural number greater than 1, collects data timeliness information and data expiration information, and classifies the sub-data according to information comparison; The periodic environment detection unit performs life cycle storage environment detection on the stored data, collects high-frequency environment data and continuous environment data, and infers whether the storage environment of the stored data is safe according to data analysis; The internal permission control unit controls the internal access of the department where the stored data is produced, sets the permission-granting department and the temporary permission department, collects authorized access data and temporary access data, and infers whether the internal permission control is normal according to data analysis; The external transmission control unit analyzes and controls the external transmission of the stored data, constructs an external transmission behavior model, obtains external transmission node information and external transmission value information, and infers whether the external transmission behavior model is safe according to information analysis.

[0007] As a preferred embodiment of the present invention, the data timeliness information and the data invalidation information are respectively the rising span of the floating frequency of the data values of the same category within the corresponding sub-data after the sub-data is generated and summarized and stored, and the instantaneous decrease span of the usage frequency of the current category data value of the original sub-data after the data values of the same category float; If the data timeliness information exceeds the floating frequency rising span threshold, it is marked as high-frequency data; If the data timeliness information does not exceed the floating frequency rising span threshold, it is marked as low-frequency data; If the data invalidation information exceeds the usage frequency instantaneous decrease span threshold, it is marked as transient data; If the data invalidation information does not exceed the usage frequency instantaneous decrease span threshold, it is marked as persistent data.

[0008] As a preferred embodiment of the present invention, low-frequency transient data, low-frequency persistent data, high-frequency transient data, and high-frequency persistent data are obtained by freely combining according to the data type; and according to the execution cycle of the output department where the corresponding sub-data is located and the average value of the sub-data historical data floating cycle, the cycle threshold of the corresponding sub-data is obtained through combined analysis, and different cycle threshold ratios are set according to the data type, and the order of the life cycles of the corresponding types from long to short is low-frequency persistent data, high-frequency persistent data, low-frequency transient data, and high-frequency transient data.

[0009] As a preferred embodiment of the present invention, the high-frequency environment data and the persistent environment data are respectively the maximum deviation span of the corresponding application access request quantity in the internal and external time periods of the life cycle of the high-frequency type data, and the maximum fluctuation span of the corresponding access cumulative duration in the internal and external time periods of the life cycle of the persistent type data.

[0010] As a preferred embodiment of the present invention, if the high-frequency environment data exceeds the maximum deviation span threshold, or the persistent environment data exceeds the maximum fluctuation span threshold, a high-risk signal for the storage environment is generated; if the high-frequency environment data does not exceed the maximum deviation span threshold and the persistent environment data does not exceed the maximum fluctuation span threshold, a low-risk signal for the storage environment is generated.

[0011] As a preferred embodiment of the present invention, the authority-granting department is the value output department of all categories within the sub-data in the stored data; the temporary authority department is the department affected by the stored values of all categories within the sub-data.

[0012] As a preferred embodiment of the present invention, the authorized access data and the temporary access data are respectively the rising span value of the access cumulative duration corresponding to non-identical terminal logins during the access node time period within the continuous access stage of the authority-granting department, and the floating span of the proportion of the rejected access data volume in the corresponding sub-data access request quantity during the temporary access stage of the temporary authority department; If the authorized access data exceeds the time - rise span threshold, or the temporary access data exceeds the proportion - floating span threshold, an internal - permission regulation signal is generated; if the authorized access data does not exceed the time - rise span threshold and the temporary access data does not exceed the proportion - floating span threshold, an internal - permission normal signal is generated.

[0013] As a preferred embodiment of the present invention, the external - sending behavior pattern is represented by the external - sending data - transmission time - progress nodes, cycles, and transmission speeds of the data - output department of the stored data, and the external - sending modes of each parameter component, including the external - sending execution process and the data of the execution process.

[0014] As a preferred embodiment of the present invention, the external - sending node information and the external - sending numerical information are respectively the time - span value when the buffer time between adjacent execution processes of the external - sending behavior pattern during the external - sending stage of the stored data exceeds the set range, and the maximum span of the corresponding execution values at adjacent moments of any execution process of the external - sending behavior pattern during the external - sending stage of the stored data; If the external - sending node information exceeds the time - span threshold, or the external - sending numerical information exceeds the numerical - maximum - span threshold, an external - sending regulation signal is generated; if the external - sending node information does not exceed the time - span threshold and the external - sending numerical information does not exceed the numerical - maximum - span threshold, an external - sending normal signal is generated and sent to the data - security processing platform.

[0015] An artificial - intelligence - based data - security protection method, and the data - security protection method is as follows: Data timeliness analysis: Analyze the data timeliness of the stored data, divide the stored data into i sub - data, where i is a natural number greater than 1, collect data timeliness information and data failure information, and classify the sub - data according to information comparison; Periodic environment detection: Detect the storage environment of the stored data during its life cycle, collect high - frequency environment data and continuous environment data, and infer whether the storage environment of the stored data is safe according to data analysis; Internal - permission control: Control the internal access of the data - output department of the stored data, set the permission - granting department and the temporary - permission department, collect authorized access data and temporary access data, and infer whether the internal - permission control is normal according to data analysis; External - sending control: Analyze and control the external sending of the stored data, construct an external - sending behavior pattern, obtain external - sending node information and external - sending numerical information, and infer whether the external - sending behavior pattern is safe according to information analysis.

[0016] Compared with the prior art, the beneficial effects of the present invention are: 1. In the present invention, data timeliness analysis is performed on the stored data. By analyzing the timeliness of each data, the life cycle of the data document is inferred, and based on the timeliness analysis, it is determined whether the efficiency of the current data security protection meets the requirements, so as to avoid the inability to control security vulnerabilities in a timely manner during the life cycle and perform redundant security handling operations on security vulnerabilities outside the life cycle; thereby improving the pertinence of data security protection and ensuring the data protection efficiency. Perform life cycle storage environment detection on the stored data to infer whether there are risks in the real-time storage environment of the stored data, so as to facilitate timely storage environment management and control, reduce the storage risk of the stored data, and ensure storage security.

[0017] 2. In the present invention, access rights control is performed on the internal access of the department that produces the stored data. By controlling the internal access rights, data leakage caused by abnormal internal access is avoided. At the same time, the internal data rights are controlled to improve the access efficiency of the internal department and avoid the situation where the fixed setting of rights is too serious, resulting in requests for required rights when other departments access, which reduces the accuracy of rights setting and generates unnecessary data storage risks. Analyze and control the external transmission of the stored data. By controlling the external transmission, the security of the external transmission of the stored data is ensured, and abnormal situations during the transmission of the stored data are avoided, which reduces the storage security. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] For the convenience of those skilled in the art to understand, the present invention will be further described below with reference to the accompanying drawings.

[0019] Figure 1 It is the principle block diagram of the present invention; Figure 2 It is the method flow chart of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0021] Reference to "embodiment" herein means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the present invention. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0022] Please refer to Figure 1 As shown, an artificial intelligence-based data security protection system includes a data security processing platform. The data security processing platform is communicatively connected to a number of data acquisition terminals, which are used to collect and analyze data within the current platform, such as data generation platforms like enterprises; the data security processing platform is communicatively connected to a data timeliness analysis unit, a periodic environment detection unit, an internal permission control unit, and an external sending control unit; It should be noted that all kinds of threshold parameters used in this technical solution are parameters set artificially in combination with the current operating scenario and the technical execution scenario of personnel in this field; this technical solution is based on artificial intelligence technology for intelligent data collection and processing; The data acquisition terminal sends the real-time generated data to the data security processing platform. As the data storage volume increases, the data security processing platform generates a data timeliness analysis signal and sends the data timeliness analysis signal to the data timeliness analysis unit. After receiving the data timeliness analysis signal, the data timeliness analysis unit performs data timeliness analysis on the stored data, infers the data document life cycle through the timeliness analysis of each data, and determines whether the efficiency of the current data security protection meets the requirements according to the timeliness analysis, avoiding the inability to control security vulnerabilities within the life cycle in a timely manner and performing redundant security processing operations on security vulnerabilities outside the life cycle; to improve the pertinence of data security protection and ensure the data protection efficiency; The stored data is divided into i sub-datas, where i is a natural number greater than 1. The rising span of the floating frequency of the same-category data values within the corresponding sub-data after the sub-data is generated, summarized, and stored is obtained, and the instantaneous decreasing span of the usage frequency of the current category data values of the original sub-data after the same-category data values float is obtained. The rising span of the floating frequency of the same-category data values within the corresponding sub-data after the sub-data is generated, summarized, and stored and the instantaneous decreasing span of the usage frequency of the current category data values of the original sub-data after the same-category data values float are respectively marked as data timeliness information and data invalidation information, and are respectively compared with the floating frequency rising span threshold and the usage frequency instantaneous decreasing span threshold: Among them, the same category refers to the data name in the sub-data, such as the turnover of Department A at time point X, where Department A and time point are both categories, and the turnover is the data value corresponding to the category; If the rising span of the floating frequency of the same-category data values within the corresponding sub-data after the sub-data is generated, summarized, and stored exceeds the floating frequency rising span threshold, it is inferred that there are high-frequency floating data values in the corresponding sub-data, which are marked as high-frequency data; If the rising span of the floating frequency of the same-category data values within the corresponding sub-data after the sub-data is generated, summarized, and stored does not exceed the floating frequency rising span threshold, it is inferred that there are low-frequency floating data values in the corresponding sub-data, which are marked as low-frequency data; If the instantaneous reduction span of the usage frequency of the current category data value of the original sub-data after the floating of the same-category data values exceeds the usage frequency instantaneous reduction span threshold, it is inferred that the usage rate of the original value of the corresponding sub-data's category data value drops rapidly after floating, and it is marked as transient data; If the instantaneous reduction span of the usage frequency of the current category data value of the original sub-data after the floating of the same-category data values does not exceed the usage frequency instantaneous reduction span threshold, it is inferred that the usage rate of the original value of the corresponding sub-data's category data value drops slowly after floating, and it is marked as persistent data; Free combinations are made according to the data type to obtain low-frequency transient data, low-frequency persistent data, high-frequency transient data, and high-frequency persistent data; and according to the execution cycle of the output department where the corresponding sub-data is located and the average value of the historical data floating cycle of the sub-data, the cycle threshold of the corresponding sub-data is obtained through combined analysis, and different cycle threshold ratios are set according to the types of low-frequency transient data, low-frequency persistent data, high-frequency transient data, and high-frequency persistent data. Moreover, the life cycles of the corresponding types are in the order from long to short as low-frequency persistent data, high-frequency persistent data, low-frequency transient data, and high-frequency transient data; and the corresponding life cycles and the types of the corresponding sub-data are sent to the data security processing platform together, and the data security processing platform proceeds according to the sub-data type and the corresponding life cycle; After determining the data type, a cycle environment detection signal is generated and sent to the cycle environment detection unit. After receiving the cycle environment detection signal, the cycle environment detection unit performs a life cycle storage environment detection on the stored data to infer whether there is a risk in the real-time storage environment of the stored data, so as to perform storage environment control in a timely manner, reduce the storage risk of the stored data, and ensure storage security; The maximum deviation span of the corresponding application access request quantity in the internal and external periods of the life cycle of the high-frequency type data is obtained, and at the same time, the maximum fluctuation span of the corresponding cumulative access duration in the internal and external periods of the life cycle of the persistent type data is obtained. The maximum deviation span of the corresponding application access request quantity in the internal and external periods of the high-frequency type data and the maximum fluctuation span of the corresponding cumulative access duration in the internal and external periods of the persistent type data are respectively marked as high-frequency environment data and persistent environment data, and are respectively compared with the maximum deviation span threshold and the maximum fluctuation span threshold: In this application, the high-frequency type data and the persistent type data are used as reference objects, so the low-frequency type data and the transient type data are also applicable to this system; If the maximum deviation span of the number of access requests corresponding to the high-frequency type data in the periods inside and outside the life cycle exceeds the maximum deviation span threshold, or the maximum fluctuation span of the cumulative access duration corresponding to the persistent type data in the periods inside and outside the life cycle exceeds the maximum fluctuation span threshold, it is inferred that the reduction in access demand after the end of the storage data life cycle is abnormal, a high-risk signal for the storage environment is generated and sent to the data security processing platform. After receiving the high-risk signal for the storage environment, the data security processing platform conducts a secondary screening of the access requests for the storage data during the life cycle and records the access terminals, avoiding an excessive proportion of the number of access terminals that send the first request in the access requests, which reduces the security of the storage data; If the maximum deviation span of the number of access requests corresponding to the high-frequency type data in the periods inside and outside the life cycle does not exceed the maximum deviation span threshold, and the maximum fluctuation span of the cumulative access duration corresponding to the persistent type data in the periods inside and outside the life cycle does not exceed the maximum fluctuation span threshold, it is inferred that the reduction in access demand after the end of the storage data life cycle is normal, a low-risk signal for the storage environment is generated and sent to the data security processing platform; After receiving the low-risk signal for the storage environment, the data security processing platform generates an internal permission control signal and an external sending control signal, and sends them to the internal permission control unit and the external sending control unit respectively; After receiving the internal permission control signal, the internal permission control unit conducts permission control over the internal access of the storage data output department. By controlling the internal access permissions, data leakage caused by abnormal internal access is avoided. At the same time, the internal data permissions are controlled to improve the access efficiency of the internal departments, avoiding a serious problem of fixed permission settings that cause requests for required permissions when other departments access, resulting in a decrease in the accuracy of permission settings and unnecessary data storage risks; Obtain all the numerical output departments of the sub-data within the storage data, and mark the corresponding output departments as permission-granting departments. At the same time, collect the departments that are affected by the numerical values of all categories within the sub-data, that is, if the department work progress fluctuations affect the numerical values, then mark this type of department as a temporary permission department; among them, the permission-granting departments are provided with continuous access permissions, and the temporary permission departments are provided with temporary access permissions, that is, temporary access permissions are granted when the department work progress is abnormal; Obtain the rising span value of the cumulative access duration corresponding to non - same - terminal logins during the continuous access stage of the permission - granting department for the access node time period. At the same time, obtain the floating span of the proportion of the amount of data with access denied in the corresponding sub - data access request quantity during the temporary access stage of the temporary permission department. Mark the rising span value of the cumulative access duration corresponding to non - same - terminal logins during the continuous access stage of the permission - granting department for the access node time period and the floating span of the proportion of the amount of data with access denied in the corresponding sub - data access request quantity during the temporary access stage of the temporary permission department as authorized access data and temporary access data respectively, and compare them with the duration rising span threshold and the proportion floating span threshold respectively: If the rising span value of the cumulative access duration corresponding to non - same - terminal logins during the continuous access stage of the permission - granting department for the access node time period exceeds the duration rising span threshold, or the floating span of the proportion of the amount of data with access denied in the corresponding sub - data access request quantity during the temporary access stage of the temporary permission department exceeds the proportion floating span threshold, then infer that the internal permission control analysis is abnormal, generate an internal permission regulation signal and send the internal permission regulation signal to the data security processing platform. After receiving the internal permission regulation signal, the data security processing platform re - plans the permission settings for storing data, reduces the permission access duration of the permission - granting department, and at the same time reduces the access prohibition frequency of the temporary permission department; If the rising span value of the cumulative access duration corresponding to non - same - terminal logins during the continuous access stage of the permission - granting department for the access node time period does not exceed the duration rising span threshold, and the floating span of the proportion of the amount of data with access denied in the corresponding sub - data access request quantity during the temporary access stage of the temporary permission department does not exceed the proportion floating span threshold, then infer that the internal permission control analysis is normal, generate an internal permission normal signal and send the internal permission normal signal to the data security processing platform; After receiving the external - sending control signal, the external - sending control unit analyzes and controls the external sending of the stored data, ensures the security of the external sending of the stored data through external - sending control, avoids abnormalities in the transmission of the stored data during the transmission process, and reduces the storage security; Obtain data such as the external - sending data transmission time progress node, cycle, transmission speed, etc. of the stored - data output department, and construct an external - sending behavior pattern therefrom; obtain the time - span value when the buffer time between adjacent execution processes of the external - sending behavior pattern during the external - sending stage of the stored data exceeds the set range, and mark the time - span value when the buffer time between adjacent execution processes of the external - sending behavior pattern during the external - sending stage of the stored data exceeds the set range as external - sending node information; obtain the maximum span of the execution values corresponding to adjacent moments of any execution process of the external - sending behavior pattern during the external - sending stage of the stored data, and mark the maximum span of the execution values corresponding to adjacent moments of any execution process of the external - sending behavior pattern during the external - sending stage of the stored data as external - sending value information, where the execution value represents values such as the time deviation set for the time progress node, the deviation of the set cycle, the speed deviation, etc.; Compare the external node information and the external value information with the time span threshold and the maximum value span threshold respectively: If the external node information exceeds the time span threshold or the external value information exceeds the maximum value span threshold, it is inferred that the external sending analysis is abnormal, generate an external sending control signal and send the external sending control signal to the data security processing platform. After receiving the external sending control signal, the data security processing platform makes a perfect adjustment to the external sending behavior pattern, and if the external sending behavior pattern is abnormal after the perfect adjustment, it performs external sending terminal control and cancels the permissions. If the external node information does not exceed the time span threshold and the external value information does not exceed the maximum value span threshold, it is inferred that the external sending analysis is normal, generate an external sending normal signal and send the external sending normal signal to the data security processing platform.

[0023] Please refer to Figure 2 As shown, a data security protection method based on artificial intelligence, the data security protection method is as follows: Data timeliness analysis: Perform data timeliness analysis on the stored data, divide the stored data into i sub-data, where i is a natural number greater than 1, collect data timeliness information and data invalidation information, and classify the sub-data according to information comparison; Periodic environment detection: Perform life cycle storage environment detection on the stored data, collect high-frequency environment data and continuous environment data, and infer whether the storage environment of the stored data is safe according to data analysis; Internal permission control: Control the internal access of the department that produces the stored data, set the permission-granting department and the temporary permission department, collect authorized access data and temporary access data, and infer whether the internal permission control is normal according to data analysis; External sending control: Analyze and control the external sending of the stored data, construct an external sending behavior pattern, obtain external node information and external value information, and infer whether the external sending behavior pattern is safe according to information analysis.

[0024] The preferred embodiments of the present invention disclosed above are only used to help illustrate the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the present invention to only the specific embodiments. Obviously, according to the content of this specification, many modifications and changes can be made. This specification selects and specifically describes these embodiments to better explain the principle and practical application of the present invention, so that those skilled in the art in the technical field can well understand and utilize the present invention. The present invention is only limited by the claims and their full scope and equivalents.

Claims

1. A data security protection system based on artificial intelligence, including a data security processing platform, characterized in that: The data security processing platform is connected to several data collection terminals, data timeliness analysis units, periodic environment detection units, internal authority control units, and external transmission control units; The data timeliness analysis unit performs data timeliness analysis on the stored data, divides the stored data into i sub-data, where i is a natural number greater than 1, collects data timeliness information and data expiration information, and divides the sub-data into types according to information comparison; The periodic environment detection unit performs lifecycle storage environment detection on the stored data, collects high-frequency environment data and continuous environment data, and infers whether the storage environment of the stored data is safe based on data analysis; The internal authority control unit controls the internal access of the storage data output department, sets the authority granting department and the temporary authority department, collects the authorized access data and the temporary access data, and infers whether the internal authority control is normal based on the data analysis; The outbound transmission control unit analyzes and controls the outbound transmission of stored data, constructs an outbound behavior pattern, obtains outbound node information and outbound numerical information, and infers whether the outbound behavior pattern is safe based on information analysis.

2. According to claim 1, a data security protection system based on artificial intelligence is characterized in that: The data timeliness information and data expiration information are respectively the rising span of the floating frequency of the same category data value in the corresponding sub-data after the sub-data is generated and aggregated and stored, and the instantaneous decreasing span of the usage frequency of the current category data value of the original sub-data after the same category data value fluctuates; If the data timeliness information exceeds the floating frequency rising span threshold, it is marked as high-frequency data; If the data timeliness information does not exceed the floating frequency rising span threshold, it is marked as low-frequency data; If the data failure information exceeds the usage frequency instantaneous reduction span threshold, it is marked as transient data; If the data expiration information does not exceed the instantaneous reduction span threshold of the usage frequency, it is marked as persistent data.

3. According to claim 2, the data security protection system based on artificial intelligence is characterized in that: Low-frequency short-term data, low-frequency continuous data, high-frequency short-term data and high-frequency continuous data are obtained by free combination of data types; and according to the execution cycle of the output department where the corresponding sub-data is located and the average floating cycle of the sub-data historical data, the cycle threshold of the corresponding sub-data is obtained through combined analysis, and different cycle threshold ratios are set according to the data type, and the order of the life cycle of the corresponding types from long to short is low-frequency continuous data, high-frequency continuous data, low-frequency short-term data and high-frequency short-term data.

4. According to claim 1, the data security protection system based on artificial intelligence is characterized in that: High-frequency environmental data and continuous environmental data are respectively the maximum deviation span of the number of application access requests for high-frequency type data within and outside the life cycle period, and the maximum fluctuation span of the cumulative access duration for continuous type data within and outside the life cycle period.

5. According to claim 4, the data security protection system based on artificial intelligence is characterized in that: If high-frequency environmental data exceeds the maximum deviation span threshold, or continuous environmental data exceeds the maximum fluctuation span threshold, a storage environment high-risk signal is generated; If the high-frequency environmental data does not exceed the maximum deviation span threshold, and the continuous environmental data does not exceed the maximum fluctuation span threshold, a storage environment low risk signal is generated.

6. The data security protection system based on artificial intelligence according to claim 1 is characterized in that: The authority-granting department is the department that produces the values ​​of all categories in the sub-data within the storage data; the temporary authority department is the department that is affected by the stored values ​​of all categories in the sub-data.

7. The data security protection system based on artificial intelligence according to claim 6 is characterized in that: The authorized access data and temporary access data are respectively the rising span value of the cumulative duration of access to the access node period corresponding to non-same terminal login during the continuous access phase of the authority granting department, and the floating span of the proportion of the amount of data denied access in the corresponding number of sub-data access requests during the temporary access phase of the temporary authority department; If the authorized access data exceeds the duration rising span threshold, or the temporary access data exceeds the proportion floating span threshold, an internal permission control signal is generated; if the authorized access data does not exceed the duration rising span threshold, and the temporary access data does not exceed the proportion floating span threshold, an internal permission normal signal is generated.

8. The data security protection system based on artificial intelligence according to claim 1 is characterized in that: The outbound behavior mode is represented by the outbound data transmission time schedule nodes, cycles, transmission speeds of the storage data output department, and the outbound mode of each parameter component, which includes the outbound execution process and execution process data.

9. The data security protection system based on artificial intelligence according to claim 8 is characterized in that: The outgoing node information and the outgoing value information are respectively the time span value when the buffer time of adjacent execution processes of the internal and external issuance behavior mode in the storage data outgoing phase exceeds the set range, and the maximum span of the execution value corresponding to the adjacent moments of any execution process of the internal and external issuance behavior mode in the storage data outgoing phase; If the outgoing node information exceeds the time span threshold, or the outgoing numerical information exceeds the maximum numerical span threshold, an outgoing control signal is generated; if the outgoing node information does not exceed the time span threshold, and the outgoing numerical information does not exceed the maximum numerical span threshold, an outgoing normal signal is generated and sent to the data security processing platform.

10. A data security protection method based on artificial intelligence, characterized in that: A data security protection system based on artificial intelligence is applied as described in any one of claims 1 to 9 above.

Citation Information

Patent Citations

  • Network security protection system based on artificial intelligence

    CN116112280A

  • Intelligent management system based on hospital data resources

    CN117608466A

  • Intelligent campus archive data security management system

    CN118710461A

  • Campus access safety supervision system based on smart campus

    CN118984244A

  • System and method for data access management based on environmental risk assessment

    US20240289489A1

Cited By

  • Data attack protection system based on artificial intelligence

    CN120710738A