Business data management system based on data medium station

By adopting a combination solution of enterprise data middle platform, cloud platform and data management terminal in the data middle platform system, the problem of data leakage in multi-dimensional complex data processing is solved, and efficient business data management and strong data security are achieved.

CN120180455APending Publication Date: 2025-06-20NANJING LIANDI INFORMATION SYST CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202311752468.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-19
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

When processing multi-dimensional complex data, it is difficult to sort and encrypt, resulting in some useless data or data leakage that should not be seen, affecting the security and privacy of the data.

Method used

The business data management system based on the data middle platform is adopted to collect and classify data through the enterprise data middle platform, encrypt data using the cloud platform, and data flow and permission management are carried out through the data management terminal to ensure the security and privacy of the data during transmission and storage.

Benefits of technology

It improves the system's business processing capabilities and efficiency, enhances the confidentiality and security of data, prevents unauthorized users from accessing and processing sensitive data, and protects the integrity and privacy of enterprise data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180455A_ABST
    Figure CN120180455A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data processing, in particular to a business data management system based on a data medium station, which comprises an enterprise data medium station, a cloud platform and a data management terminal, and is characterized in that the enterprise data medium station is used for collecting and storing enterprise data information, and the cloud platform is used for providing examples and data encryption for the enterprise data medium station; the data management terminal is used for collecting and sorting data transmitted by the enterprise data middle station through the cloud platform, and the enterprise data middle station is used for collecting enterprise data, judging the enterprise data, sorting the enterprise data and circulating the enterprise data. The enterprise data flow comprises enterprise business data flow, enterprise management data flow and enterprise encrypted data flow. The method is used for business data management, the business processing capability of the data management system can be improved, the business processing efficiency of the data management system is improved, and the data reliability and safety of the data management system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and particularly relates to a business data management system based on a data middle platform. Background Art

[0002] With the development of Internet technology, business processing scenarios have become more diverse and complex, and it is necessary to ensure the integrity and security of data. How to design an efficient, fast, and secure business data management method and system is extremely important for the effective and accurate management of enterprises. The so-called middle platform is relative to the front desk and the back desk. The front desk usually refers to the market, sales, and service departments or systems facing customers, while the back desk is the support departments or systems such as technical support, R & D, finance, human resources, and internal audit. For the front desk, it is its basic responsibility to quickly respond to customer needs. In the traditional architecture, the front desk needs to obtain instructions from the back desk, including business and data guidance, but the feedback speed of the back desk is often very slow and cannot meet the needs of customers, resulting in a very poor customer experience; the back-end system is a relatively complete system with standardized processes and strict management systems, and it cannot be completely changed for the needs of the front desk, while the business of the front desk changes too fast to make timely analysis and judgment. The value of middle platform construction lies in helping enterprises build a new IT architecture that is more suitable for enterprise digital transformation. Or rather, the middle platform architecture itself is the core content and backbone system of the enterprise's new IT architecture, making the enterprise's IT operation smoother and helping the enterprise to try new business models to achieve the purpose of strategic transformation.

[0003] Currently, Chinese Patent with the authorization announcement number of CN105516344A discloses a data management system and a business processing method. The present invention discloses that the method includes: receiving updated business information sent by a client, where the updated business information at least includes updated content; writing the updated content into a data persistence layer and a cache according to the updated business information, and obtaining the writing result; generating an updated business processing result according to the result and returning it to the client. The present invention also discloses a database management system. The present invention realizes that in the case of a large amount of data, the data management system can quickly respond to a large number of requests, process business requests in a timely manner, and at the same time ensure the reliability of business processing and the consistency of business data.

[0004] The above-mentioned existing technical solutions have the following defects: multi-dimensional complex data are mixed together, and they cannot be sorted, classified, and encrypted, which easily causes some useless data or data that should not be seen to be leaked, and even seen and processed by users without permission, thus affecting the security and privacy of the data and causing losses to users. Summary of the Invention

[0005] The purpose of the present invention is to provide a business data management system based on a data middle platform to solve the problems existing in the above-mentioned prior art.

[0006] The above technical object of the present invention is achieved through the following technical solutions:

[0007] A business data management system based on a data middle platform includes an enterprise data middle platform, a cloud platform, and a data management terminal. The enterprise data middle platform is used to collect and store enterprise data information. The cloud platform is used to provide calculation examples and data encryption for the enterprise data middle platform. The data management terminal is used to collect and organize the data transmitted by the enterprise data middle platform through the cloud platform.

[0008] By adopting the above technical solutions, the business processing ability of the system is improved, and the efficiency of business processing of the system is improved.

[0009] In a further embodiment, the enterprise data middle platform is used to collect enterprise data, judge enterprise data, organize enterprise data, and transfer enterprise data. The enterprise data transfer includes enterprise business data transfer, enterprise management data transfer, and enterprise encrypted data transfer.

[0010] By adopting the above technical solutions, the privacy and security of the system are improved. In the present invention, a private cloud is used. The difference between a public cloud and a private cloud is that for a public cloud, third-party providers' users can use the cloud, and a public cloud can generally be used through the Internet. For a private cloud, it refers to the cloud used by an enterprise itself, and all its services are not for others to use, but for its own internal personnel or branches. Because of the characteristics of the private cloud, it needs to be improved to suit the enterprise. Therefore, the present invention has made some improvements to the private cloud and established an external dedicated operation and maintenance data channel. Since the private cloud requires the enterprise itself to provide operation and maintenance, in order to avoid increasing a large expense for the enterprise, an external dedicated interface is added to the hardware part of the private cloud in the present invention. The external dedicated interface needs to obtain authorization before each access, and is allowed to access after authorization. And when authorizing, the permissions are classified. According to the actual situation, it can be divided into multiple levels. The permissions corresponding to each level open the database according to the actual situation, and the data in the database cannot be downloaded through the dedicated channel. After obtaining the permission in the dedicated channel, it is necessary to code the accessed data page and mark the watermark indicating the prohibited disclosure of data information.

[0011] In a further embodiment, the data management method of the enterprise data middle platform is as follows:

[0012] Step S310: Collect data, collect and classify enterprise data;

[0013] Step S320: Convert the format, convert the format and protocol of enterprise data to make the enterprise data format and protocol unified;

[0014] Step S330: Weight the data and perform weighted processing on the converted data to avoid full disclosure of information.

[0015] Step S340: Set the login administrator permission through the cloud platform, and the cloud platform identifies the administrator permission to select whether the data is open.

[0016] By adopting the above technical solution, after collecting and classifying enterprise data and then weighting it, the confidentiality and security of the system data are improved.

[0017] In a further embodiment, in step S410, identify whether there is a permission mark in the data. If so, use the permission in the data as the standard. If not, proceed to the next step.

[0018] Step S420: Identify the data generation source and set the permission for the data source.

[0019] Step S430: Identify the data receiver information and set the permission for the data receiver.

[0020] Step S440: Identify external factors, judge whether there are external risks. If there are, identify the temporary permission increase instruction. If not, mark and transmit the weighted data.

[0021] By adopting the above technical solution, the confidentiality and security of the system data are ensured.

[0022] In a further embodiment, the enterprise data classification method is as follows:

[0023] Step S510: Unify the data naming format. One of the file naming formats is: time - department - project - matter - confidentiality level, e.g., May 20, 2023 - First Group of the Technology Department - Enterprise Data Middle Platform Management System - Nth Iteration - File Content Public.

[0024] Step S520: Classify according to time and data type. The data is classified into process category, application category, confidentiality category, technology category, and other category.

[0025] Step S530: For the technology category, summarize and store according to the technology project list and the number of technology iterations.

[0026] By adopting the above technical solution, after classifying the system data, it is convenient for storage and reading, reduces the system operation load, and improves the data processing efficiency.

[0027] In a further embodiment, the cloud platform is used to encrypt and store the data of the enterprise data middle platform in the data management terminal, and the cloud platform is used to provide management permissions for enterprise managers and access all the data in the data management terminal.

[0028] By adopting the above technical solution, the confidentiality and security of system data are improved.

[0029] In a further embodiment, the data encryption method is encryption by a symmetric encryption algorithm, and the private key in the symmetric encryption algorithm is updated regularly.

[0030] By adopting the above technical solution, the confidentiality and security of system data are improved. Another advantage of public key encryption is that it can provide non-repudiable digital signatures. Authentication through a secret key system requires both parties to share a key and sometimes to trust a third party. As a result, the sender may deny having sent a message after sending it, claiming that the shared key was eavesdropped and someone else impersonated his identity. For example, in the Kerberos secret key authentication system, there is a central database containing the secret keys of all users. If this database is attacked, a large number of identity forgeries will occur. The public key encryption method does not have this problem and is non-repudiable. Each user is responsible for protecting his own private key. This feature of the public key encryption method is usually called the non-repudiation feature. However, since the system uses a private cloud and the usage scenario is for the enterprise itself, using a private key is a more secure method to ensure enterprise data security, avoiding the data transfer of the key and reducing the possibility of leakage. Only by strengthening the management specification of the key can the purpose of keeping enterprise data confidential be well achieved.

[0031] In a further embodiment, the enterprise data middle platform is further provided with a data supplement module, and the data supplement module is used to supplement data when the data is defective.

[0032] By adopting the above technical solution, the integrity of system data is ensured.

[0033] In a further embodiment, the data supplement module includes a data detection unit, a data temporary storage unit, and a data filling unit. The data detection unit is used to detect the integrity of the data, the data temporary storage unit is used to temporarily store enterprise data within a certain period of time, and the data filling unit is used to retrieve the data in the temporary storage unit to fill the data when the enterprise data is defective.

[0034] By adopting the above technical solution, the integrity of system data is ensured, and the reliability of the system is improved.

[0035] In summary, the present invention has the following beneficial effects:

[0036] 1. By collecting enterprise data, judging enterprise data, sorting enterprise data, and transferring enterprise data through the enterprise data middle platform, the effect of improving the system business processing ability and improving the data processing efficiency can be achieved;

[0037] 2. By collecting and classifying enterprise data and then weighting it, the data in the enterprise data center is encrypted and stored in the data management terminal, which can improve the confidentiality and security of system data.

[0038] 3. The present invention also labels the data. Data labeling is a key link for the effective operation of most artificial intelligence algorithms. Artificial intelligence algorithms are data-driven algorithms. That is to say, if you want to realize artificial intelligence, you first need to teach computers the ability of humans to understand and judge things, so that computers can learn this recognition ability. The process of data labeling is to provide samples for machine systems to learn through manual labeling. Data labeling is to label data that needs to be recognized and distinguished by machines, and then let the computer continuously learn the characteristics of these data, and finally realize that the computer can recognize it autonomously. Labeling is a process of continuously optimizing the robot algorithm of this system, so this system will iterate in sequence during use. With long-term use, the difficulty of using this system can be further reduced and the reliability of this system can be increased. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 It is a block diagram of the data management method of the enterprise data middle platform of the present invention;

[0040] Figure 2 It is a block diagram of the data weighting method of the present invention;

[0041] Figure 3 It is a framework diagram of the invented enterprise data classification method. DETAILED DESCRIPTION

[0042] The present invention is further described in detail below in conjunction with the accompanying drawings.

[0043] The same parts are denoted by the same reference numerals. It should be noted that the words "front", "rear", "left", "right", "upper" and "lower" used in the following description refer to the attached Figure 1 In the description of this specification, the words "bottom" and "top", "inside" and "outside" refer to directions toward or away from a particular component geometry, respectively. In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Therefore, features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of this specification, the meaning of "multiple" is two or more, unless otherwise clearly and specifically defined.

[0044] Embodiment 1:

[0045] like Figures 1-3As shown, a business data management system based on a data middle platform includes an enterprise data middle platform, a cloud platform and a data management terminal. The enterprise data middle platform is used to collect and store enterprise data information, the cloud platform is used to provide examples and data encryption for the enterprise data middle platform, and the cloud platform is used to encrypt and store the data of the enterprise data middle platform in the data management terminal. The data middle platform breaks down data barriers and builds data assets through multi-dimensional and three-dimensional online and offline data collection tools and methods. At the same time, it helps enterprises to process, process, analyze and model data to maximize the value of data. The data middle platform is a further sedimentation of enterprise business and data. The data middle platform can be used to connect marketing, sales, service, after-sales, repeat purchases and other links, comprehensively manage multi-source data, and then create an efficient user management system to help enterprises manage users, improve user experience, and promote digital marketing. Therefore, in the actual process, the management of the enterprise data business middle platform involves all aspects. Making good use of the enterprise data business middle platform can greatly increase the management and business capabilities of the enterprise and accelerate the flow of enterprise data. The cloud platform is used to provide enterprise managers with management authority and access to all data in the data management terminal. The data encryption method is symmetric encryption algorithm encryption. The private key in the symmetric encryption algorithm is updated regularly. The data management terminal is used to collect and organize the enterprise data. The middle platform passes through the cloud platform The enterprise data middle platform is also provided with a data supplement module, and the data supplement module is used to supplement the data when the data is missing. The data supplement module includes a data detection unit, a data temporary storage unit and a data filling unit. The data detection unit is used to detect the integrity of the data, and the temporary storage unit is used to temporarily store the enterprise data within a certain period of time. The data filling unit is used to retrieve the data of the temporary storage unit to fill the data when the enterprise data is missing. A good enterprise data business middle platform can increase user satisfaction, optimize the enterprise from the data level, and enable the enterprise to enter a good progress cycle. Through the enterprise data middle platform, a series of processes can be realized, including discovering problems, solving problems, recording solutions, and using big data to count the causes of problems and tracing the sources of problems.

[0046] like Figure 1 As shown, the enterprise data middle station is used to collect enterprise data, judge enterprise data, organize enterprise data and transfer enterprise data. The enterprise data transfer includes enterprise business data transfer, enterprise management data transfer and enterprise encrypted data transfer. The data management method of the enterprise data middle station is:

[0047] Step S310 collects data, collects and classifies enterprise data, and the enterprise data classification method is as follows: Step S510, unifies the data naming format, and one of the file naming formats is: time-department-project-matter-confidentiality level, such as: May 20, 2023-The first group of the technical department-enterprise data middle platform management system-Nth iteration-file content disclosure; Step S520, classifies according to time and data type, and classifies data into process, application, confidentiality, technology and other categories; Step S530, the technical category is summarized and stored according to the list of technical projects and the number of technical iterations. At the same time, in order to better collect enterprise data and avoid the problem of data loss leading to subsequent traceability and other links that cannot be prosecuted due to data loss, the enterprise is generally partitioned and stored in the memory during actual use, that is, the storage area in the server is partitioned and isolated when used, and at least one area of ​​data does not generate any data interaction and only collects enterprise data for backup, crawls the enterprise data through crawlers, and closes the access interface after crawling, classifies the data in the storage area, and summarizes the data;

[0048] Step S320 converts the format, performs format and protocol conversion on the enterprise's data, and unifies the enterprise's data format and protocol. In the present invention, a private cloud is used. The difference between a public cloud and a private cloud is that a public cloud is a cloud that can be used by users of a third-party provider. A public cloud can generally be used through the Internet. A private cloud refers to a cloud used by an enterprise itself. All of its services are not for use by others, but for use by its own internal personnel or branches. Because the characteristics of a private cloud require improvement and enterprise-specific features, the present invention has made some improvements to the private cloud and established an external dedicated operation and maintenance data channel. Because the private cloud requires the enterprise itself to provide operation and maintenance, in order to avoid increasing the enterprise's large expenses, the hardware part of the private cloud of the present invention has added an external dedicated interface. The external dedicated interface needs to be authorized before each access, and access is allowed after authorization. At the time of authorization, the authority is graded and can be divided into multiple levels according to the actual situation. The authority corresponding to each level is opened to the database according to the actual situation, and the data in the database cannot be downloaded through a dedicated channel. After obtaining the authority through the dedicated channel, the data page to be accessed needs to be coded and marked with a watermark prohibiting the leakage of data information.

[0049] Step S330 weights the data and performs weighted processing on the converted data to avoid full disclosure of information. The data weighting method is as follows: Step S410 identifies whether there is a permission mark in the data. Data labeling is a key link for most artificial intelligence algorithms to operate effectively. Artificial intelligence algorithms are data-driven algorithms. In other words, if you want to achieve artificial intelligence, you first need to teach computers the ability of humans to understand and judge things, so that computers can learn this recognition ability. The process of data labeling is to provide samples for machine systems to learn through manual labeling. Data labeling is to label the data that needs to be machine-recognized and distinguished, and then let the computer continuously learn the characteristics of this data, and finally realize that the computer can autonomously identify it. If there is, the authority in the data shall prevail. If not, proceed to the next step; step S420, identify the source of data generation and set the authority for the data source; step S430, identify the data receiving end information and set the authority for the data receiving end; step S440, identify external factors and determine whether there is external risk. If there is, identify the temporary authority increase instruction. If not, mark and transmit the weighted data. In the enterprise data flow, the weighted level according to the responsibility level is from high to low, namely, secretarial department-technology department-process department-business department-production department-other departments, among which technology department The weighted level of the file sent by the department and received by the secretarial department is the highest. In order to facilitate identification, the weights are assigned: the secretarial department, technical department, process department, business department, production department, and other departments are 10, 8, 6, 4, 3, and 2 respectively. According to the weighted assignment of the issuing department and the receiving department, the weighted calculation model is weight = (issuing department + receiving department) * number of circulation departments. Specifically, the maximum weight of the enterprise is 600, and the final file sent from the technical department and circulated by all departments is collected by the technical department for encrypted storage. The files with the weight in this state must be approved before they can be circulated by all departments, and the viewing personnel of the circulated department must make permission restrictions. Ordinary employees without permission do not have access rights, and the business middle platform does not push notifications like unauthorized personnel;

[0050] Step S340 sets the login administrator permission through the cloud platform. The cloud platform identifies the administrator permission and selects whether to open the data. Only one highest-level permission is issued by the cloud platform. The private key of the cloud platform is updated at intervals according to the enterprise risk level and confidentiality level. Another advantage of the public-key encryption method is that it can provide non-repudiable digital signatures. Authentication through the secret-key system requires both parties to share the key and sometimes trust a third party. As a result, after sending the message, the sender may deny having sent such a message, claiming that the shared key was eavesdropped and someone else impersonated his identity. For example, in the Kerberos secret-key authentication system, there is a central database containing the secret keys of all users. If this database is attacked, a large number of identity forgeries will occur. The public-key encryption method does not have this problem and is non-repudiable. Each user is responsible for protecting his own private key. This feature of the public-key encryption method is usually called the non-repudiation feature. However, since this system uses a private cloud and the usage scenario is for the enterprise itself, using the private key is a more secure method to ensure enterprise data security, avoiding the data transfer of the key and reducing the possibility of leakage. Only by strengthening the management specification of the key can the purpose of keeping enterprise data confidential be achieved well.

[0051] Since the present invention involves a large amount of data sorting and induction, the method for classifying and sorting the data adopted by the present invention is as follows: The present invention mainly adopts the tree diagram classification method for classification and sorting. First, a framework based on the number of departments is established. In addition, special event branches and warning time branches need to be established on this basis. Each branch under each department is based on the time scale. When something happens at a certain time in a department for the first time, it is listed in the corresponding position. When something happens at a certain time in a department multiple times, it is listed at the time point of the first occurrence, and its occurrence frequency is retrieved. If the frequency exceeds ten times per month, it is listed again in the special event branch. Some special precautions are listed in the warning branch, and the classification method of the warning branch is classified according to events and listed in chronological order under the event. The previous mark of the list indicates the number of modifications and the reasons. For better data traceability, timestamps are marked for the data during the listing and induction of the data. In addition, it should be noted that the recommended key algorithms in the present invention are one of the DES algorithm, the Lucifer algorithm, the Khufu and Khafre algorithms. These algorithms are relatively mature and have effective management methods that can be customized according to the enterprise's own needs.

[0052] In summary, the objective of the present invention is to establish a data management system for public enterprises, which can ensure data security under the condition of a perfect enterprise management system. Therefore, the actual technology used in the present invention is quite different from the prior art. By setting up multiple aspects of the cloud, computing end, data transfer channel, and access rights, the enterprise data is not easily leaked, which is more suitable for enterprise use without strong technical means.

[0053] In the embodiments disclosed in the present invention, terms such as "installation", "connection", "linkage", "fixation", etc. should be understood in a broad sense. For example, "connection" can be a fixed connection, a detachable connection, or an integral connection; "linkage" can be a direct linkage or an indirect linkage through an intermediate medium. For those of ordinary skill in the art, the specific meanings of the above terms in the embodiments disclosed in the present invention can be understood according to specific circumstances.

[0054] This specific embodiment is only an interpretation of the present invention and not a limitation thereof. After reading this specification, those skilled in the art can make modifications to this embodiment without creative contributions as needed, but as long as it is within the scope of the claims of the present invention, it is protected by the patent law.

Claims

1. A business data management system based on a data middle platform, characterized in that: It includes an enterprise data center, a cloud platform, and a data management terminal. The enterprise data center is used to collect and store enterprise data information. The cloud platform is used to provide calculation examples and data encryption for the enterprise data center. The data management terminal is used to collect and organize the data transmitted by the enterprise data center through the cloud platform.

2. The business data management system based on a data middle platform according to claim 1, characterized in that: The enterprise data center is used to collect, judge, organize, and transfer enterprise data. The enterprise data transfer includes enterprise business data transfer, enterprise management data transfer, and enterprise encrypted data transfer.

3. The business data management system based on a data middle platform according to claim 1, characterized in that, The data management method of the enterprise data center is as follows: Step S310: Collect data, collect and classify enterprise data. Step S320: Convert formats, convert the formats and protocols of enterprise data to make the enterprise data formats and protocols unified. Step S330: Weight the data, perform weighted processing on the converted data to avoid full disclosure of information. Step S340: Set login administrator permissions through the cloud platform, and the cloud platform identifies the administrator permissions to select whether the data is open.

4. The business data management system based on a data middle platform according to claim 3, characterized in that, The data weighting method is as follows: Step S410: Identify whether there is a permission mark in the data. If so, use the permission in the data as the standard. If not, proceed to the next step. Step S420: Identify the data generation source and set permissions for the data source. Step S430: Identify the data receiver information and set permissions for the data receiver. Step S440: Identify external factors, judge whether there are external risks. If there are, identify the temporary permission increase instruction. If not, mark and transfer the weighted data.

5. The business data management system based on a data middle platform according to claim 3, characterized in that, The enterprise data classification method is as follows: Step S510: Unify the data naming format. Step S520: Classify according to time and data type. The data is classified into process type, application type, confidential type, technology type, and other types. Step S530: For the technology type, summarize and store according to the technology project list and the number of technology iterations.

6. The business data management system based on a data middle platform according to claim 1, characterized in that: The cloud platform is used to encrypt and store the data of the enterprise data center in the data management terminal. The cloud platform is used to provide management permissions for enterprise managers and access all the data in the data management terminal.

7. The business data management system based on a data middle platform according to claim 6, characterized in that: The data encryption method is encryption using the symmetric encryption algorithm, and the private key in the symmetric encryption algorithm is updated regularly.

8. The business data management system based on a data middle platform according to claim 1, characterized in that: The enterprise data center is also provided with a data supplement module, which is used to supplement data when the data is missing.

9. The business data management system based on a data middle platform according to claim 8, characterized in that: The data supplement module includes a data detection unit, a data temporary storage unit, and a data filling unit. The data detection unit is used to detect the integrity of the data. The data temporary storage unit is used to temporarily store enterprise data for a certain period of time. The data filling unit is used to retrieve the data in the temporary storage unit to fill the data when the enterprise data is missing.

Citation Information

Patent Citations

  • Data management system and service-processing method

    CN105516344A