Commercial secret data classification and access control method and device
By building a hierarchical trade secret level tree and creating a dynamic permission engine, combining data association and differentiated circuit breaker strategies, the problems of static classification lag, cross-level access risks and multi-system collaboration bottlenecks of trade secret data management in the existing technology are solved, and efficient and secure trade secret data management and access control are achieved.
Patent Information
- Application Number
- CN202510281984.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-11
- Publication Date
- 2025-06-17
AI Technical Summary
The existing Shangxin data management technology has static classification lag, cross-level access risks and multi-system collaboration bottlenecks, making it difficult to dynamically adapt to changes in the enterprise organizational structure and data flow paths, resulting in low permission management efficiency and insufficient data security.
By building a hierarchical trade secret level tree, creating a dynamic permission engine, dynamically adjusting access permissions based on the depth of the access path and personnel trust coefficient, and permission adjustment and synchronization are performed through data association, and differentiated circuit breaking strategies are set.
It realizes high-precision cross-level correlation control, real-time dynamic update capabilities, fine-grained traceability countermeasures, reduce management costs and risks, enhance data access security and improve enterprise operation efficiency.
Smart Images

Figure CN120162701A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular, to a method and device for classifying and accessing commercial secret data. Background Art
[0002] With the acceleration of the digital transformation of enterprises, the management and protection of commercial secret (biz secret) data have become a key link in enterprise information security. In the existing technology, the classification and access control of biz secret data mainly rely on static permission management models, which have many defects and deficiencies in practical applications and are difficult to adapt to the dynamic business needs and organizational structure adjustments of enterprises.
[0003] The existing biz secret data control technologies have the following core defects: 1. Static classification lag defect: The traditional biz secret data classification method is based on static rules and cannot dynamically adapt to changes in the internal organizational structure of an enterprise, such as department mergers, employee rank adjustments, etc. This results in more than 70% of permission changes requiring manual intervention, and the permission synchronization delay can reach more than 8 hours, seriously affecting enterprise operation efficiency and data security.
[0004] 2. Cross-level access risk vulnerability: Traditional encryption technologies only verify the legality of a single operation and cannot track the transmission path of data between enterprise levels (such as grass-roots → middle-level → senior-level). This technical defect leads to an increased risk of cross-level leakage, especially when data is transferred between different levels, it is difficult to ensure the confidentiality and integrity of the data.
[0005] 3. Multi-system collaboration bottleneck: Systems such as ERP (Enterprise Resource Planning), OA (Office Automation), and CRM (Customer Relationship Management) within an enterprise usually manage biz secret policies independently. When an employee changes positions or job roles, conflicts are likely to occur in the permission configurations between different systems and need to be manually synchronized, increasing management costs and the probability of errors.
[0006] Therefore, how to provide a method for classifying and accessing biz secret data that can be dynamically adjusted, has fine-grained control, and has cross-system collaboration capabilities to meet the high requirements for information security in enterprise digital transformation has become a technical problem to be solved urgently. Summary of the Invention
[0007] In view of this, in order to overcome the deficiencies of the existing technology, this application aims to provide a method and device for classifying and accessing biz secret data.
[0008] According to the first aspect of this application, a method for classifying and accessing biz secret data is provided, and the method includes: Step S101: Classify biz secret data by constructing a hierarchical biz secret level tree; Step S102: Create a dynamic permission engine to dynamically adjust access permissions based on the depth of the access path and the personnel trust coefficient; Step S103: Perform permission adjustment synchronization through data association and set a differential fusing strategy.
[0009] Optionally, in the commercial secret data classification and access control method of the present application, in step S101, a commercial secret level tree is constructed based on the IPC hierarchical extension model, and commercial secret data is hierarchically divided according to the confidentiality level.
[0010] Optionally, in the commercial secret data classification and access control method of the present application, step S101 further includes: dynamically adjusting the confidentiality level of commercial secret data according to the usage scenario of the commercial secret data, and dynamically adjusting the hierarchy of the commercial secret data according to the adjusted confidentiality level.
[0011] Optionally, in the commercial secret data classification and access control method of the present application, in step S102: constrain the access path gradient through a hierarchical message passing algorithm, and dynamically adjust the access permission according to the constrained access path gradient.
[0012] Optionally, in the commercial secret data classification and access control method of the present application, step S102 includes: calculating the access path depth threshold through a hierarchical message passing algorithm, and triggering a fusing mechanism when the level of the access path depth is greater than the access path depth threshold and the access frequency exceeds a preset trigger threshold.
[0013] Optionally, in the commercial secret data classification and access control method of the present application, step S102 further includes: dynamically adjusting the access permission according to the personnel trust coefficient, and the personnel trust coefficient is composed of a position sensitivity weight, a compliance record weight, an employment years attenuation factor, and a dynamic behavior weight factor.
[0014] Optionally, in the commercial secret data classification and access control method of the present application, the dynamic behavior weight factor is generated according to the analysis of the operation compliance rate of the employee in the recent 30 days and is dynamically adjusted every day.
[0015] Optionally, in the commercial secret data classification and access control method of the present application, step S103 includes: performing cross-system synchronization on commercial secret data through semantic tags, synchronizing personnel change events to the main database in real time, and dynamically adjusting the access permissions of personnel.
[0016] Optionally, in the commercial secret data classification and access control method of the present application, step S103 further includes: setting a trust score range for the personnel trust coefficient, and setting a corresponding access level and key validity period for each trust score range.
[0017] According to the second aspect of the present application, there is provided a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the method described in the first aspect of the present application is implemented.
[0018] The commercial secret data classification and access control method and device of the present application have the following beneficial technical effects: 1. High-precision cross-level association control: By introducing the hierarchical classification principle and multitasking processing capabilities, the hierarchical structure of commercial secret data is optimized, and dynamic matching between data confidentiality levels and personnel permissions is achieved. It can accurately identify the implicit associations between data confidentiality levels and personnel permissions in multi-dimensional scenarios, effectively solving the leakage risks caused by data flow between levels in the prior art. For example, through the calculation of semantic proximity between levels, non-linear association rules between data confidentiality levels and personnel permissions are defined to ensure the security and compliance of cross-level access.
[0019] 2. Real-time dynamic update ability: A dynamic permission engine is designed. Based on the hierarchical message passing mechanism, it can update data classification labels and personnel permissions in real time. It avoids the timeliness loopholes caused by manual permission adjustment, significantly improving the flexibility and response speed of permission management. For example, when an employee's position changes, the system can automatically synchronize the permission changes to ensure the timeliness and accuracy of permission configuration without manual intervention.
[0020] 3. Fine-grained traceability and countermeasure: Combining log data with hierarchical access path tracking technology, it can monitor the data flow path in fine-grained manner. When detecting the outflow of illegal data, the system can accurately locate the level where the leakage node is located, realizing precise traceability and countermeasure against data leakage. For example, the system can trace the conversion node of data from T1 (core commercial secret) to T2 (departmental secret), quickly locate the key derivation vulnerability, thereby effectively preventing the spread of data leakage.
[0021] 4. Reducing management costs and risks: Through the automated and dynamic permission management mechanism, the need for manual intervention is greatly reduced, and the risks caused by manual configuration errors are reduced. At the same time, the cross-system automatic synchronization function can adjust employees' permissions in real time, avoiding the problem of permission configuration conflicts between multiple systems, and significantly improving the collaboration and management efficiency of enterprise internal information systems.
[0022] 5. Enhancing data access security: The differential fusing strategy dynamically adjusts access permissions according to the personnel trust coefficient, ensuring that high-risk operations can be identified and restricted in a timely manner, thereby effectively protecting the enterprise's core commercial secret data.
[0023] 6. Improve enterprise operation efficiency: Through automated privilege adjustment and dynamic access control mechanisms, business interruptions caused by untimely privilege management are reduced. At the same time, the fine-grained traceability and countermeasure capabilities can quickly locate problems and reduce the impact of data leakage on enterprise operations. These technological improvements have significantly enhanced the operation efficiency and data management capabilities of enterprises during the digital transformation process. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] To more clearly illustrate the technical solutions of the embodiments of the present application, the accompanying drawings required for use in the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0025] Figure 1 It is a flowchart of the steps of a commercial secret data classification and access control method according to an embodiment of the present application; Figure 2 It is an example diagram of the execution process of a commercial secret data classification and access control method according to an embodiment of the present application; Figure 3 It is a schematic structural diagram of the device provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0026] The embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0027] It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other; and, based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present disclosure.
[0028] It should be noted that the following describes various aspects of the embodiments within the scope of the appended claims. It should be obvious that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on the present disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement the device and / or practice the method. Additionally, this device and / or method can be implemented using other structures and / or functionality in addition to one or more of the aspects described herein.
[0029] Figure 1 It is a flowchart of the steps of a commercial secret data classification and access control method according to an embodiment of the present application. Figure 2This is an example flowchart of the execution process of a commercial secret data classification and access control method according to an embodiment of the present application. As Figure 1 and Figure 2 shown, the commercial secret data classification and access control method includes the following steps: Step S101: Classify commercial secret data by constructing a hierarchical commercial secret level tree.
[0030] As an optional example, in this embodiment, a commercial secret level tree is constructed based on the IPC hierarchical extension model, and commercial secret data is hierarchically divided according to the confidentiality level. In this embodiment, the confidentiality level of commercial secret data is also dynamically adjusted according to the usage scenario of the commercial secret data, and the hierarchy of the commercial secret data is dynamically adjusted according to the adjusted confidentiality level. In this embodiment, the IPC hierarchical extension model is a hierarchical data classification architecture model used to decompose a complex information system into multiple levels, and each level is responsible for specific functions or data classifications.
[0031] For example, in this embodiment, the IPC hierarchical extension model can be used to divide commercial secret data into the following four levels: T1 (core commercial secret): Confidential data at the highest level involving the enterprise's core competitiveness, strategic planning, etc.
[0032] T2a (departmental secret): Sensitive information related to a specific department, such as financial statements, human resources data, etc.
[0033] T2b (project secret): Confidential information related to cross-departmental collaboration projects.
[0034] T3 (restricted disclosure): Data that can be publicly disclosed within a certain range within the enterprise but still requires restricted access.
[0035] Step S102: Create a dynamic permission engine to dynamically adjust access permissions according to the depth of the access path and the personnel trust coefficient.
[0036] In practical applications, when a file is marked as T2a and associated with a cross-departmental collaboration scenario, the system automatically downgrades its confidentiality level to T2b. For example, when the budget file (T2a) of a company's finance department needs to be shared with the project management department, its confidentiality level is automatically adjusted to T2b to meet the needs of cross-departmental collaboration.
[0037] As an optional example, in this embodiment, the access path gradient is constrained by a hierarchical message passing algorithm, and the access permission is dynamically adjusted according to the constrained access path gradient. Specifically, the access path depth threshold is calculated by the hierarchical message passing algorithm. When the level of the access path depth is greater than the access path depth threshold and the access frequency exceeds the preset trigger threshold, the fusing mechanism is triggered. For example, in this embodiment, the access path depth threshold θ is defined, and its value range is [0.6, 0.75]. The access path depth Δ level is calculated in real time by the hierarchical message passing algorithm. When the Δ level is greater than θ and the access frequency exceeds the preset threshold, the fusing mechanism is triggered to limit the access permission. For example, when an employee at level P3 requests to access a file at level T1 more than 3 times within a single day, the system determines that the access frequency is too high, triggers the fusing mechanism, revokes the dynamic key, and prohibits further access.
[0038] As an optional example, in this embodiment, the access permission is dynamically adjusted according to the personnel trust coefficient, which is composed of the post sensitivity weight, the compliance record weight, the employment years attenuation factor, and the dynamic behavior weight factor. Among them, the dynamic behavior weight factor is generated based on the analysis of the operation compliance rate of the employee in the past 30 days and is dynamically adjusted every day.
[0039] For example, in this embodiment, the following factors constitute the personnel trust coefficient (PTS): Post sensitivity weight (α): The weight assigned according to the importance and sensitivity of the employee's post.
[0040] Compliance record weight (β): The weight assigned based on the employee's historical compliance records.
[0041] Employment years attenuation factor (γ): The attenuation factor adjusted according to the employee's employment years.
[0042] Dynamic behavior weight factor (δ(t)): Generated based on the operation compliance rate of the employee in the past 30 days and dynamically adjusted every day.
[0043] The personnel trust coefficient is calculated according to the following formula: PTS(t)=[Σ(αi×βj)+δ(t)] / (1 + γ).
[0044] For example, an employee's post sensitivity weight is 0.8, the compliance record weight is 0.9, the employment years attenuation factor is 0.1, and the operation compliance rate in the past 30 days is 95% (the dynamic behavior weight factor is 0.95). According to the above formula, the trust coefficient of this employee is 0.85.
[0045] Step S103: Perform permission adjustment synchronization through data association and set a differential fusing strategy.
[0046] As an optional example, in this embodiment, commercial secret data is synchronously across systems through semantic tags, and personnel change events are synchronously to the main database in real time to dynamically adjust the access rights of personnel. For example, when an employee transfers or changes positions, the system automatically updates their permission configuration through interfaces of systems such as ERP, OA, and CRM to ensure the real-time and accuracy of permission adjustment. This process requires no manual intervention, significantly improving the efficiency of multi-system collaborative management.
[0047] As an optional example, this embodiment sets the trust score range of the personnel trust coefficient, and sets corresponding access levels and key validity periods for each trust score range.
[0048] For example, this embodiment can set the following differentiated fusing strategies according to the trust score range: PTS interval [0.9, 1.0]: Allows cross-level access at two levels, and the key validity period is 48 hours.
[0049] PTS interval [0.7, 0.9): Only allows same-level access, and the key validity period is 24 hours.
[0050] PTS < 0.7: Triggers access locking and requires manual review.
[0051] For example, when a P3-level employee accesses T1-level data, the system dynamically adjusts the access rights according to the calculation results of their trust coefficient and access path depth. If the real-time PTS value is lower than the set threshold (such as 0.36), access is denied and an alarm mechanism is triggered.
[0052] In practical applications, dynamic context key technology can also be introduced to perform secondary encryption according to operation scenarios (such as cross-level review, outsourcing collaboration) by attaching parameters such as timestamps and data fences, further enhancing the security of data access.
[0053] The commercial secret data classification and access control method according to the embodiment of the present application has the following remarkable beneficial technical effects: 1. High-precision cross-level association control: By introducing the hierarchical classification principle and multi-task processing capabilities, the hierarchical structure of commercial secret data is optimized, and dynamic matching between data confidentiality levels and personnel permissions is achieved. It can accurately identify the implicit association between data confidentiality levels and personnel permissions in multi-dimensional scenarios, effectively solving the leakage risk caused by data transfer between levels in the prior art. For example, through the calculation of semantic proximity between levels, non-linear association rules between data confidentiality levels and personnel permissions are defined to ensure the security and compliance of cross-level access.
[0054] 2. Real-time dynamic update ability: A dynamic permission engine is designed. Based on the hierarchical message passing mechanism, it can update data classification tags and personnel permissions in real time. This avoids the timeliness loopholes caused by manual permission adjustment, and significantly improves the flexibility and response speed of permission management. For example, when an employee's position changes, the system can automatically synchronize the permission changes to ensure the real-time and accuracy of permission configuration without manual intervention.
[0055] 3. Fine-grained traceability and countermeasure: By combining log data with hierarchical access path tracing technology, it can monitor the data flow path in fine-grained manner. When detecting the outflow of illegal data, the system can accurately locate the level where the leakage node is located, realizing precise traceability and countermeasure against data leakage. For example, the system can trace the conversion node of data from T1 (core commercial secret) to T2 (departmental secret), quickly locate the key derivation vulnerability, and thus effectively prevent the spread of data leakage.
[0056] 4. Reduce management costs and risks: Through the automated and dynamic permission management mechanism, the need for manual intervention is greatly reduced, and the risks caused by manual configuration errors are lowered. At the same time, the cross-system automatic synchronization function can adjust employees' permissions in real time, avoiding the problem of permission configuration conflicts between multiple systems, and significantly improving the coordination and management efficiency of enterprise internal information systems.
[0057] 5. Enhance data access security: The differential fusing strategy dynamically adjusts access permissions according to the personnel trust coefficient to ensure that high-risk operations can be identified and restricted in a timely manner, thus effectively protecting the enterprise's core commercial secret data.
[0058] 6. Improve enterprise operation efficiency: Through the automated permission adjustment and dynamic access control mechanism, the business interruption caused by untimely permission management is reduced. At the same time, the fine-grained traceability and countermeasure ability can quickly locate problems and reduce the impact of data leakage on enterprise operations. These technical improvements have significantly improved the operation efficiency and data management ability of enterprises in the process of digital transformation.
[0059] This application solves the problems of static classification lag, cross-level access risk, and multi-system collaboration bottleneck existing in the prior art through the dynamically adjusted commercial secret data classification and access control method. It not only improves the security and management efficiency of enterprise commercial secret data, but also provides reliable technical support for the digital transformation of enterprises, with significant economic and social benefits.
[0060] Such as Figure 3As shown in the figure, the present application also provides a device, including a processor 210, a communication interface 220, a memory 230 for storing computer programs executable by the processor, and a communication bus 240. Among them, the processor 210, the communication interface 220, and the memory 230 complete communication with each other through the communication bus 240. The processor 210 realizes the above-mentioned commercial secret data classification and access control method by running the executable computer program.
[0061] Among them, when the computer program in the memory 230 can be implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present application. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs, etc., which can store program codes.
[0062] The system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected based on actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.
[0063] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the technical solution, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disks, optical discs, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods of various embodiments or some parts of the embodiments.
[0064] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present application should be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
Claims
1. A commercial secret data classification and access control method, characterized in that: The method comprises: Step S101: classify the commercial secret data by constructing a hierarchical commercial secret level tree; Step S102: Create a dynamic permission engine to dynamically adjust access rights based on access path depth and personnel trust coefficient; Step S103: Perform permission adjustment synchronization through data association and set differentiated fuse strategies.
2. The commercial secret data classification and access control method according to claim 1, characterized in that: In step S101, a commercial secret level tree is constructed based on the IPC hierarchical extension model, and the commercial secret data is hierarchically divided according to the confidentiality level.
3. The commercial secret data classification and access control method according to claim 1, characterized in that: Step S101 also includes: dynamically adjusting the confidentiality level of the commercial secret data according to the usage scenario of the commercial secret data, and dynamically adjusting the hierarchy of the commercial secret data according to the adjusted confidentiality level.
4. The commercial secret data classification and access control method according to claim 1, characterized in that: In step S102: the access path gradient is constrained by a hierarchical message passing algorithm, and the access rights are dynamically adjusted according to the constrained access path gradient.
5. The commercial secret data classification and access control method according to claim 4, characterized in that: Step S102 includes: calculating an access path depth threshold through a hierarchical message passing algorithm, and triggering a fuse mechanism when the level of the access path depth is greater than the access path depth threshold and the access frequency exceeds a preset trigger threshold.
6. The commercial secret data classification and access control method according to claim 1, characterized in that: Step S102 also includes: dynamically adjusting access rights according to the personnel trust coefficient, where the personnel trust coefficient is composed of a job sensitivity weight, a compliance record weight, a tenure decay factor, and a dynamic behavior weight factor.
7. The commercial secret data classification and access control method according to claim 6, characterized in that: The dynamic behavior weight factor is generated based on analyzing the employee's operational compliance rate in the past 30 days and is dynamically adjusted every day.
8. The commercial secret data classification and access control method according to claim 1, characterized in that: Step S103 includes: synchronizing commercial secret data across systems through semantic tags, synchronizing personnel change events to the main database in real time, and dynamically adjusting personnel access rights.
9. The commercial secret data classification and access control method according to claim 1, characterized in that: Step S103 also includes: setting trust zones of personnel trust coefficients, and setting corresponding access levels and key validity periods for each trust zone.
10. A computer device, characterized in that: The computer device comprises a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor implements the steps of the method according to any one of claims 1 to 9 when executing the program.