Multi-level security management method for trusted data space
Through a multi-level security management method for trusted data space, the shortcomings of risk identification and response in complex environments in the prior art are solved, and real-time risk identification and system stability of data interaction tasks are realized.
Patent Information
- Application Number
- CN202510340207.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-21
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2045-03-21
AI Technical Summary
In complex environments, the prior art cannot quickly and accurately identify and respond to risks due to insufficient real-time, poor adaptability of rule matching and high misjudgment rate of abnormal detection, which affects the security and stability of data interaction tasks.
A multi-level security management method for trusted data space is adopted, including subject access authentication and trustworthy rating, group isolation treaty based on data scenarios, multi-layer security verification levels and node data roll-off encryption, real-time risk identification and response are achieved through dynamic security management.
It improves the real-time risk identification capabilities of data interaction tasks, enhances system adaptability and reduces the misjudgment rate, and ensures the security and stability of the data interaction process.
Smart Images

Figure CN120185887A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data security management, and particularly to a multi-level security management method for a trusted data space. Background Art
[0002] With the rapid development of information technology, data interaction has become increasingly prominent in various systems and is widely used in fields such as the Internet of Things, cloud computing, intelligent transportation, and financial payment.
[0003] Currently, existing task tracking and risk supervision technologies mainly rely on logging, rule matching, and anomaly detection methods based on historical data, which have improved the security of data interaction to a certain extent. However, these methods have limitations in terms of real-time performance, adaptability, and accuracy, and are difficult to meet the data security requirements in complex environments. The logging method is difficult to provide immediate feedback, resulting in a lag in risk response; the rule matching method relies on preset policies and has poor adaptability in the face of new attack methods; anomaly detection based on historical data is prone to false positives or false negatives, especially in the case of large amounts of data interaction and complex business logic, which affects the stability of the system.
[0004] In summary, there are technical problems in the prior art that due to insufficient real-time performance, poor adaptability of rule matching, and high false positive rate of anomaly detection, risks cannot be quickly and accurately identified and responded to in complex environments, further affecting the security and stability of data interaction tasks. Summary of the Invention
[0005] The purpose of this application is to provide a multi-level security management method for a trusted data space to solve the technical problems in the prior art that due to insufficient real-time performance, poor adaptability of rule matching, and high false positive rate of anomaly detection, risks cannot be quickly and accurately identified and responded to in complex environments, further affecting the security and stability of data interaction tasks.
[0006] In view of the above problems, this application provides a multi-level security management method for a trusted data space, including: performing entity access authentication and trusted rating for the connection entities of the trusted data space, and introducing a group isolation treaty based on data scenarios; setting up multiple security verification checkpoints for the security management of the trusted data space, and performing node data disk encryption for the core data nodes of the trusted data space; obtaining a data interaction task, and for the sequential link nodes of the task cycle chain, implementing group isolation of the connection entity groups of the node data scenarios by triggering the group isolation treaty, and implementing checkpoint security verification of the node data scenarios by matching the multiple security verification checkpoints, where if there are core data nodes, implementing node data disk decryption.
[0007] The technical solutions provided in this application have at least the following technical effects or advantages: By achieving the technical goal of dynamic security management based on task tracking and risk supervision, the real-time risk identification ability of data interaction tasks is improved, the system adaptability is enhanced, and the misjudgment rate is reduced, thereby ensuring the security and stability of the data interaction process.
[0008] The above description is only an overview of the technical solutions of this application. In order to be able to understand the technical means of this application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of this application more obvious and easy to understand, the specific embodiments of this application are specifically given below. It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of this application, nor is it used to limit the scope of this application. Other features of this application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] In order to more clearly illustrate the technical solutions in this application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only exemplary, and for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0010] Figure 1 It is a schematic flowchart of the multi-level security management method for the trusted data space of this application;
[0011] Figure 2 It is a schematic flowchart of isolating the connection subject group of the implementation node data scenario in the multi-level security management method for the trusted data space of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0012] By providing a multi-level security management method for the trusted data space, this application solves the technical problems existing in the prior art, such as insufficient real-time performance, poor adaptability of rule matching, and high misjudgment rate of anomaly detection, resulting in the inability to quickly and accurately identify and respond to risks in complex environments, further affecting the security and stability of data interaction tasks. The technical goal of dynamic security management based on task tracking and risk supervision is achieved, and the technical effects of improving the real-time risk identification ability of data interaction tasks, enhancing system adaptability, and reducing the misjudgment rate are achieved, thereby ensuring the security and stability of the data interaction process.
[0013] Next, the technical solutions in this application will be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments of this application. It should be understood that this application is not limited by the example embodiments described herein. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of this application without creative efforts shall fall within the scope of protection of this application. Additionally, it should be noted that for the sake of description, only the parts related to this application are shown in the drawings rather than all of them.
[0014] Please refer to the attached Figure 1 , this application provides a multi-level security management method for a trusted data space, specifically including the following steps:
[0015] S1: For the connection entities of the trusted data space, perform entity access authentication and trusted rating, and introduce a group isolation treaty based on the data scenario.
[0016] Specifically, for the connection entities of the trusted data space, perform entity access authentication and trusted rating. The trusted data space refers to an environment for data exchange and storage, in which all data has a certain degree of trust. The connection entities refer to the various participants who perform data interaction or storage in this space, such as users, devices, or application programs, etc. Entity access authentication is to verify the identities of these participants to ensure that only the verified entities can access the data. And the trusted rating is, on the basis of authentication, to give a credibility score to them according to the entity's behavior history or other relevant criteria, so as to distinguish the trust levels of different entities and determine their permissions and responsibilities in the trusted data space.
[0017] Next, introducing a group isolation treaty based on the data scenario means that during the data interaction process, different entities are grouped according to the specific application scenario, and different security and access permissions are set for each group. For example, in the financial industry, customer data and transaction data may be divided into different groups to ensure that the access of different entities to the data complies with specific security specifications. This group isolation can not only reduce the risk of data leakage but also improve the efficiency and security of data management.
[0018] In addition, the group isolation treaty means that by formulating rules or agreements, it is stipulated how each entity should be isolated during the data interaction process to avoid cross-group access and data sharing between different entities. It is ensured that when an entity is considered untrusted, its interaction with other entities can be effectively isolated to avoid causing a larger range of data risks. For example, if an entity has a low trusted rating, it will be restricted to an isolated group and cannot access the data of other entities.
[0019] S2: Set up multiple security verification checkpoints for the security management of the trusted data space, and perform node data disk encryption for the core data nodes of the trusted data space.
[0020] Specifically, setting up multiple security verification checkpoints for the security management of the trusted data space means that during data storage and transmission, in order to ensure data security, multiple checkpoints or audit levels are established. The checkpoints can set different security standards according to the sensitivity and usage of the data. For example, more stringent security detections can be set for high-risk data, while more relaxed standards can be set for low-risk data, which helps to gradually strengthen data protection and prevent potential security vulnerabilities.
[0021] Then, perform node data disk encryption for the core data nodes of the trusted data space. The core data nodes of the trusted data space refer to the parts in the data management system that carry the most important data, and these data are often critical or sensitive. Node data disk encryption means encrypting these core data during storage to prevent unauthorized access or tampering. Disk encryption refers to encrypting the data when it is written to the hard disk or other storage media to ensure that the data remains encrypted during storage.
[0022] Next, combining the setting of multiple security verification checkpoints and node data disk encryption can form a complete data protection system. Through multi-level security verification, strict control can be carried out in multiple links such as data storage, transmission, and access. At the same time, through encryption technology, data security can be guaranteed, especially for the protection of core data nodes, preventing data leakage or tampering.
[0023] S3: Obtain a data interaction task. For the sequential link nodes of the task cycle chain, trigger the group isolation treaty to implement group isolation of the connection entities in the node data scenario, and implement checkpoint security verification of the node data scenario by matching the multiple security verification checkpoints. Among them, if there are core data nodes, perform node data disk decryption.
[0024] Specifically, obtaining a data interaction task means that during the entire data interaction process, specific task content needs to be obtained from the task source, including the data involved, participants, and interaction goals. Data interaction tasks include links such as data transmission, processing, and response. For these tasks, it is necessary to analyze the task cycle chain to identify key nodes in each link and track the tasks. The task cycle chain refers to the orderly connection of each node and step during data interaction.
[0025] Analyze the data interaction link involved in the task according to the execution period of the task, in chronological or logical order. The task cycle chain refers to the different stages that the task goes through during the entire execution process. Each stage may involve multiple link nodes, and the sequential link nodes are the nodes that perform data interaction in a predefined order.
[0026] By triggering the group isolation treaty, implement the group isolation of the connection subject for the node data scenario, which means that when data interaction involves different security levels or data sensitivities, different data interaction subjects are divided into independent security groups according to the preset isolation policy to prevent unnecessary cross-access. The group isolation treaty is a preset security rule that determines which connection subjects need to be isolated, and the implementation process of group isolation involves dynamic adjustment of the data flow.
[0027] By matching multiple levels of security verification checkpoints, implement the checkpoint security verification for the node data scenario, which means that during the task execution process, according to the data environment of the current node, match the appropriate security verification checkpoint and perform the corresponding security check. The multiple levels of security verification checkpoints are composed of multiple security mechanisms at different levels, including authentication, data integrity check, access permission control, etc. The matching process is to select the appropriate security verification steps according to the risk level of the data scenario. Among them, if there is a core data node, implement the decryption of the node data when it is stored on disk, which means that if the sequential link nodes involved in the task include core data nodes, the data stored on them will be decrypted to ensure that subsequent operations can proceed normally. A core data node refers to a node that stores or processes critical data and may contain highly sensitive information such as financial records, identity information, or key business data. Decryption of data when it is stored on disk means decrypting the encrypted stored data so that it can be correctly read when needed. For example, in a blockchain trading system, transaction records are usually encrypted and stored, and only when verification or auditing is required, specific transaction records will be decrypted to ensure both data security and privacy protection.
[0028] Furthermore, as Figure 2 shown, this application also includes: S31: For the task cycle chain, determine the first link node by tracing the sequential link nodes that perform data interaction, where the first link node is the real-time link node for data interaction; S32: Determine the node data scenario based on the first link node and determine whether to trigger the group isolation treaty; S33: If not triggered, perform the determination of the core data node and the security verification based on the multiple levels of security verification checkpoints.
[0029] Specifically, by tracing the sequential link nodes for data interaction, the first link node can be determined. The first link node refers to the link that serves as the starting node in the data interaction process and is responsible for initiating the transmission or processing of the entire data stream, while the real-time link node refers to the node where data interaction is currently taking place.
[0030] Then, the node data scenario based on the first link node means that after the first link node is traced, the relevant data environment is identified and constructed, including the task data involved, node characteristics, and interaction requirements, etc. The judgment of this scenario determines whether the group isolation treaty needs to be triggered. The group isolation treaty is a security measure based on the node data scenario, aiming to improve data security by isolating different types of data groups.
[0031] Next, if the group isolation treaty is not triggered, the determination of the core data node will be executed to judge whether the current node belongs to the core data node. The core data node refers to the node that bears key or sensitive data in the data interaction task. Based on this determination, it is decided whether to perform security verification based on multiple layers of security verification checkpoints.
[0032] Furthermore, this application also includes: according to the node data scenario, dividing the connection entities into groups to determine the divided groups, where the security connection entity and the risk connection entity are used as the division criteria; for the divided groups, locating the communication isolation nodes; and performing group isolation processing based on the communication isolation nodes by setting channel checkpoints, where the control is performed based on the closed state of the channel checkpoints.
[0033] Specifically, during the data interaction process, analyze the specific data environment and task requirements of each node. The data scenario includes the interaction content between nodes, data types, and security threats faced by the nodes. Through these data scenarios, different types of connection entities can be identified and grouped. Grouping is to group the connection entities according to their roles and security requirements to improve management and security. In this process, the security connection entity and the risk connection entity are the division criteria. The security connection entity refers to the entity with a high level of trust and low risk in data interaction, while the risk connection entity refers to the entity with potential security risks or threats.
[0034] Then, for the divided groups, according to the characteristics of different groups, further locate the communication isolation nodes. The communication isolation node refers to the node that isolates the data flow between certain groups specifically during the data transmission process to enhance security. By setting the communication isolation nodes, the transmission of data between different groups can be effectively blocked or controlled, preventing potential risk connection entities from threatening the security connection entities.
[0035] Next, by setting channel checkpoints, group isolation processing based on communication isolation nodes is performed. A channel checkpoint refers to a mechanism that controls the security state of a data transmission channel. By setting the open / closed state of the checkpoint, the permissions and methods of data flow can be flexibly controlled. If the channel checkpoint is closed, the data stream cannot pass through the isolation node, achieving the purpose of isolating data between different groups and thus improving the security of the system.
[0036] Furthermore, this application also includes: the communication isolation node is marked with a group isolation time limit; wherein, the determination of the group isolation time limit includes: according to the node data scenario, determining the data operation time zone of the first link node; setting the data operation time zone as the group isolation time limit.
[0037] Specifically, a communication isolation node refers to a node used to control the information flow direction during data transmission, which can restrict data interaction between different groups to prevent unauthorized information leakage or security risks. This communication isolation node will be marked with a group isolation time limit, that is, a time range is set. During this period, only certain specific groups are allowed to perform data interaction through this node, while data access by other groups will be blocked, thereby ensuring that data isolation between different groups takes effect within a reasonable time range and improving the flexibility of security management.
[0038] Then, the determination of the group isolation time limit needs to be analyzed based on the specific data scenario. A data scenario refers to the data flow, interaction mode, and risk assessment at a certain specific time point or under certain conditions. By analyzing the data scenario, the data operation time zone of the first link node can be determined. The first link node refers to the data transmission node that is first activated or triggered during the data interaction process. It usually undertakes the initial data processing task, so its data operation time zone is an important factor affecting subsequent data transfer. The data operation time zone refers to the time period during which this node is allowed to perform data transmission and processing. Only within this time period can data interaction proceed normally.
[0039] Next, set the data operation time zone as the group isolation time limit to ensure that the time limit for data interaction is consistent with the security policy of the system, thereby ensuring that different groups are isolated within a reasonable time range. For example, if the data operation time zone of a certain node is six hours out of twenty-four hours, then the group isolation time limit will also be set to six hours, which means that within this time period, the isolation policy takes effect, and after this time period, new policy adjustments may be made.
[0040] Furthermore, this application also includes: taking the open state of the channel checkpoint as the normal state; if the group isolation treaty is triggered, perform group division and communication isolation processing based on the connection entity.
[0041] Specifically, the open state of the channel checkpoint refers to the communication channel being in the default open mode, that is, data can flow freely between different nodes without additional restrictions. In this state, each connection entity is allowed to perform normal data exchange without being intervened by security policies. This setting of the normal state can ensure the efficiency of data transmission and maintain a high communication fluency during daily operation.
[0042] Then, when the group isolation treaty is triggered, the data interaction is intervened according to the preset security policy. The group isolation treaty refers to a set of security management protocols for specific data scenarios. When potential security risks or permission requirements are detected, this treaty will come into effect and restrict the direct communication between different groups. The triggering conditions may include the transmission of high-risk data, interaction requests between users with different permissions, or security policy adjustments in specific environments. For example, in a financial trading system, when it is detected that a user accesses data involving sensitive fund flows, the isolation policy may be automatically enabled to prevent unauthorized users from accessing critical data.
[0043] Next, after the group isolation treaty is triggered, it is necessary to perform group division based on the connection entities, classifying different connection entities according to their security levels, data access permissions, or business requirements, so as to ensure that the data flow conforms to the established security policy. The connection entities can be users, devices, or servers, and each entity will be classified into the corresponding group according to its characteristics. For example, in a medical data management system, doctors, nurses, and administrative staff belong to different connection entities. Doctors may need to access all medical records of patients, while nurses may only be able to view nursing-related information, and administrative staff can only manage basic patient information.
[0044] In addition, communication isolation processing needs to be performed, which means that on the basis of group division, the data transmission between different groups is further restricted. Communication isolation processing can be carried out in various ways, such as restricting network connections, setting access permissions, or ensuring that information cannot be obtained by unauthorized entities through data encryption technology.
[0045] Furthermore, this application also includes: determining whether the first link node is the core data node; if so, determining the node key by performing first-order decryption processing based on node data disk encryption; and performing second-order decryption processing on the core data node according to the node key to implement node data task processing.
[0046] Specifically, after implementing the connection entity group isolation for the node data scenario, or if the group isolation treaty is not triggered, it means that during the data interaction process, it will first be determined whether group isolation needs to be performed on the entities participating in the communication. If the group isolation has taken effect, it means that the data exchange path is blocked, thus affecting subsequent task processing. If the group isolation treaty is not triggered, it means that all data interaction entities can still access freely.
[0047] Then, the determination of the core data node is executed, which means identifying the key data storage nodes involved in the current task. The core data node refers to an important node that undertakes data storage, processing, or scheduling tasks in the entire data interaction link. These nodes usually store highly sensitive data, so additional security measures need to be taken. The determination process of the core data node needs to comprehensively analyze data flow, access rights, and security levels to ensure that data processing complies with the preset security rules. For example, in a cloud computing environment, some servers may undertake specific computing tasks, while other servers are only used for data caching. It is necessary to first identify which servers belong to the core data nodes.
[0048] Next, it is determined whether the first link node is a core data node, that is, whether the node that first receives data during the data interaction process belongs to a core data storage or computing node. The first link node refers to the first processing node through which the data stream passes. It may be an ordinary transit node or a core data node. If the first link node is identified as a core data node, more stringent data security management is required. For example, in a distributed storage system, a certain server may only be a temporary storage point for data, while another server stores encrypted core data. Therefore, it is necessary to determine whether the current data flow passes through the core data storage area.
[0049] In addition, if the first link node is confirmed as a core data node, a first-order decryption process based on node data disk encryption needs to be executed to determine the node key. Disk encryption means encrypting the data before storing it on the disk to prevent the data from being stolen during static storage. The first-order decryption process refers to the first layer of decryption of the encrypted data to restore some encrypted information, so as to obtain the data key for further decryption.
[0050] Finally, based on the node key, a second-order decryption process is performed on the core data node to implement node data task processing. This means that after obtaining the data key for decryption, a second decryption operation needs to be performed to fully restore the data and execute the corresponding tasks. The second-order decryption process is usually used in advanced security scenarios, such as multi-layer encryption mechanisms, to ensure that even if the data is cracked during storage, additional decryption permissions are required to fully obtain the information. Table 1 shows the determination record of the core data node for the most recent execution.
[0051] Table 1: Records of the most recent execution of core data node determination
[0052]
[0053]
[0054] Furthermore, this application also includes: for the node data scenario, traversing the multi - layer security verification levels, matching and determining the target security verification level, where the target security verification level includes at least one item; based on the target security verification level, performing level security verification.
[0055] Specifically, after performing second - order decryption processing on the core data node, or for non - core data points of the first - link node, performing security verification based on multi - layer security verification levels means that after the core data node completes all decryption processes, or when the data node is not a core data node, further security detection is required. After the core data node completes second - order decryption, the data has entered an operable state, so it is necessary to ensure data integrity and access security. Although non - core data nodes are not involved in decryption, they still need to prevent potential abnormal access through a security mechanism. In this way, regardless of the node attributes, the entire data interaction process will be under security control to ensure that data is not illegally accessed due to security vulnerabilities.
[0056] Traversing the multi - layer security verification levels and matching and determining the target security verification level for the node data scenario means that according to the data environment of the current node, all set security verification levels are checked in sequence, and the specific security verification steps applicable to this node are screened out. The node data scenario refers to the environment in which the node is located during the data interaction process, such as the task type involved, access permissions, and the sensitivity level of the data, etc. The process of traversing the multi - layer security verification levels is equivalent to gradually screening out eligible security policies to ensure that each node can receive appropriate security checks. For example, if a data node involves highly sensitive data, higher - level encryption and access control levels will be matched, while for low - sensitivity data nodes, only basic identity verification is required to complete the verification.
[0057] Performing level security verification based on the target security verification level means that for the screened - out target security verification level, the security verification process will be actually executed to ensure that the data interaction meets the established security requirements. The target security verification level includes at least one item, which means that even the node with the lowest security level must pass at least one security verification step. For example, a certain node may need to perform identity verification, access permission verification, and data integrity detection, and at least one of them is mandatory. Higher - level data scenarios may require a combination of multiple verification methods, such as multi - factor identity authentication and end - to - end encryption being executed in parallel to improve overall security.
[0058] Furthermore, this application also includes: the group isolation treaty is updated periodically; wherein, the periodic update method includes: setting a contract update period; according to the contract update period, invoking the operation flow data of the connection entities within the periodic time zone; using the operation flow data to conduct a trust rating and determine the updated trust level; based on the updated trust level, adjusting the group isolation treaty.
[0059] Specifically, the periodic update of the group isolation treaty means that at regular time intervals, the existing group isolation treaty is inspected and modified to ensure its suitability for the current data interaction situation. The group isolation treaty is a security rule used to divide and isolate different data interaction groups, and the periodic update ensures that the rule does not become inapplicable due to long-term immutability. For example, in network security management, it may be necessary to re-evaluate which users or devices need to be isolated every few days, thereby adjusting access permissions to address new security threats or changing business requirements.
[0060] Among them, the periodic update method includes setting a contract update period, which means that during operation, it is necessary to determine in advance the update time interval of the group isolation treaty in order to trigger the evaluation and adjustment process regularly. The contract update period can be flexibly set according to business requirements. For example, in a financial trading system, a security assessment may be performed once a day, while in an industrial control system, due to slower data flow, it may be updated only every dozens of days. This periodic setting can ensure that the isolation policy does not change too frequently, resulting in excessive resource consumption, nor will it affect security due to long-term immutability.
[0061] According to the contract update period, invoking the operation flow data of the connection entities within the periodic time zone means that within each update period, the operation status information of all connection entities within the current time range is collected and used as the basis for the update. The operation flow data refers to the behavior data of the connection entities during the data interaction process, such as access records, data transfer volumes, and the number of exception alerts. For example, in a cloud computing environment, if a certain server has frequent abnormal accesses in the past few days, these behavior data will be recorded, and when the contract is updated, it will be considered whether to isolate or lift the restrictions on this server.
[0062] Run the flow data to conduct a trust rating and determine the updated trust level, indicating that based on the collected operation data, each connected entity will be evaluated and assigned a trust level. The criteria for trust rating may include factors such as historical access records, data integrity, and detection of abnormal behaviors. For example, in an enterprise network, if a user's access behavior always complies with security rules, their trust level may increase, while if a device frequently exhibits abnormal accesses, its trust level will decrease. The adjustment of the trust level is a key step in group isolation adjustment, which can effectively distinguish between secure access entities and high-risk entities.
[0063] Based on the updated trust level, adjust the group isolation treaty, indicating that according to the latest trust ratings of each connected entity, the group isolation policy will be modified. If an entity has a high trust level, it may be removed from the isolation group, while if an entity's trust level decreases, it may be added to the isolation list. For example, in a banking system, an account may have certain transaction restrictions lifted if there have been no abnormal transactions for a long time, while if an account conducts a large number of suspicious transactions in a short period, it may be automatically added to a high-risk group, triggering more stringent access controls.
[0064] Furthermore, this application also includes: determining a multi-level security standard by combining multiple data encryption methods and multiple security levels, where the data encryption methods include direct key encryption types and sensitive processing types; configuring the multi-layer security verification checkpoints according to the multi-level security standard.
[0065] Specifically, determine based on multiple data encryption methods and multiple security levels. Multiple data encryption methods refer to different encryption techniques, such as symmetric encryption and asymmetric encryption, which differ in the way they protect data security. Multiple security levels refer to the different levels of data protection requirements according to the sensitivity of the data and the usage scenarios. For example, high-security-level protection is applicable to core data, while low-security-level protection is applicable to general data. By combining these encryption methods and security levels, a more comprehensive and detailed standard for data security can be established.
[0066] Then, combine to determine the multi-level security standard, reasonably match different encryption methods and security levels in order to provide targeted protection measures for different types of data. The multi-level security standard is a multi-level and step-by-step protection system to ensure that each link from data storage, transmission to usage has appropriate security protection.
[0067] Next, according to the multi-level security standard, configure multiple layers of security verification checkpoints. The multiple layers of security verification checkpoints sequentially perform multiple inspections and verifications on the data according to the set security standards to ensure that potential security risks can be effectively prevented at each link. Each checkpoint will conduct strict security checks based on different standards, thereby achieving all-round protection of the data.
[0068] Furthermore, this application also includes: as the data interaction task is executed, task tracking and risk supervision are synchronously carried out; if there is an execution risk and the risk coefficient is less than or equal to the preset risk coefficient, security alarm management is performed for the execution location; if there is an execution risk and the risk coefficient is greater than the preset risk coefficient, a security alarm is executed, and the data interaction task is interrupted and locked.
[0069] Specifically, as the data interaction task is executed, synchronously carrying out task tracking and risk supervision means that during the data interaction process, the execution status of the task is monitored in real time, and the possible risks are evaluated. The data interaction task refers to the data exchange operation between different systems or devices, such as database synchronization, information transmission in the network, etc. Task tracking refers to recording and tracking the execution status of the task to ensure the correct flow of data and avoid data loss or delay. Risk supervision is to monitor the risks that may cause data leakage, tampering or interruption. For example, in a cloud computing environment, monitor the flow of data packets and detect whether there are abnormal access requests, so as to take measures in time to prevent security hazards.
[0070] If there is an execution risk and the risk coefficient is less than or equal to the preset risk coefficient, performing security alarm management for the execution location means that when a potential risk is discovered, first calculate its risk level and compare it with the preset risk threshold. If the risk level is within the acceptable range, the task will not be directly interrupted, but a security alarm will be issued for the location where the risk occurs, so that relevant personnel or system automation mechanisms can respond in time. For example, in an Internet of Things device, if the data transmission rate of a certain sensor is abnormal but within the acceptable range, an alarm will be triggered for the physical location of the device, so that the operation and maintenance personnel can check the running status of the device, thereby avoiding small-scale failures from evolving into larger-scale system problems and reducing unnecessary task interruptions, improving the stability of the system.
[0071] If there is an execution risk and the risk coefficient is greater than the preset risk coefficient, execute a security alarm and interrupt and lock the data interaction task, which means that when the detected risk level exceeds the security threshold, stricter security measures will be immediately taken, including issuing an alarm, forcibly interrupting the task execution, and locking the task to prevent further data interaction operations. The execution risk refers to the situation that may cause data corruption, loss, or illegal access, and the risk coefficient is a quantification of the severity of the risk. For example, in an online payment system, if it is found that a certain account has conducted a large number of abnormal transactions in a short period of time and the risk coefficient exceeds the preset threshold, the payment function of the account will be immediately frozen and a security alarm will be issued to prevent further financial losses.
[0072] In summary, the multi-level security management method for a trusted data space provided by this application has the following technical effects: By achieving the technical goal of dynamic security management based on task tracking and risk supervision, the technical effects of improving the real-time risk identification ability of data interaction tasks, enhancing system adaptability, and reducing the misjudgment rate are achieved, thereby ensuring the security and stability of the data interaction process.
[0073] The above description of the disclosed embodiments enables those skilled in the art to implement or use this application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application will not be limited to these embodiments shown herein, but rather will be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0074] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of this application and its equivalent technologies, this application is also intended to include these changes and modifications.
Claims
1. A multi-level security management method for trusted data space, characterized in that: Methods include: For the connection subjects of the trusted data space, subject access authentication and trust rating are carried out, and group isolation agreements based on data scenarios are introduced; Set up multi-layer security verification checkpoints for the security management of the trusted data space, and encrypt the node data on the core data nodes of the trusted data space; Acquire data interaction tasks, for sequential link nodes of the task cycle chain, implement connection subject group isolation of the node data scenario by triggering the group isolation treaty, implement level security verification of the node data scenario by matching the multi-layer security verification level, wherein, if there is a core data node, implement node data disk decryption.
2. The multi-level security management method for trusted data space according to claim 1, characterized in that: For the sequential link nodes of the task cycle chain, by triggering the group isolation agreement, the connection subject group isolation of the node data scenario is implemented, including: For the task cycle chain, a first link node is determined by tracking the sequential link nodes of data interaction, wherein the first link node is a real-time link node of data interaction; Determine a node data scenario based on the first link node to determine whether to trigger the group isolation protocol; If not triggered, the determination of the core data node and the security check based on the multi-layer security checkpoints are executed.
3. The multi-level security management method for trusted data space as claimed in claim 2, characterized in that: If the group isolation agreement is triggered, it includes: According to the node data scenario, the connection subjects are divided into groups to determine the division groups, wherein the division criteria are safe connection subjects and risky connection subjects; For the divided groups, locate the communication isolation nodes; By setting a channel checkpoint, group isolation processing based on the communication isolation node is performed, wherein control is performed in a closed state of the channel checkpoint.
4. The multi-level security management method for trusted data space as claimed in claim 3, characterized in that: The communication isolation node identifier has a group isolation time limit; The determination of the group isolation time limit includes: Determining a data operation time zone of the first link node according to the node data scenario; The data operation time zone is set as the group isolation time limit.
5. The multi-level security management method for trusted data space as claimed in claim 3, characterized in that: The open state of the channel checkpoint is regarded as the normal state; If the group isolation protocol is triggered, group division and communication isolation processing based on the connection subject is performed.
6. The multi-level security management method for trusted data space as claimed in claim 3, characterized in that: After the connection subject group isolation of the node data scenario is implemented, or the group isolation protocol is not triggered, the determination of the core data node is performed, including: Determining whether the first link node is the core data node; If yes, determine the node key by performing a first-order decryption process based on the node data encryption on disk; According to the node key, the core data node is subjected to second-order decryption processing, and the node data task processing is implemented.
7. The multi-level security management method for trusted data space according to claim 6, characterized in that: After the core data node is subjected to the second-order decryption processing, or the first link node non-core data point, a security check based on the multi-layer security checkpoint is performed, including: For the node data scenario, traverse the multiple layers of security verification levels, match and determine a target security verification level, wherein the target security verification level includes at least one item; Based on the target security check level, a level security check is performed.
8. The multi-level security management method for trusted data space as claimed in claim 1, characterized in that: The group isolation agreement is periodically updated; The periodic update methods include: Set contract renewal cycle; According to the contract update cycle, calling the operation flow data of the connection subject in the periodic time zone; Using the running flow data, a trust rating is performed to determine an updated trust level; Based on the updated confidence level, the group isolation protocol is adjusted.
9. The multi-level security management method for trusted data space according to claim 1, characterized in that: Set up multi-layer security verification levels for trusted data space security management, including: Determine the multi-level security standards based on multiple types of data encryption methods and multiple security levels, where the data encryption methods include direct key encryption and sensitive processing; The multi-layer security checkpoints are configured according to the multi-level security standards.
10. The multi-level security management method for trusted data space according to claim 1, characterized in that: The method also includes: As the data interaction tasks are executed, task tracking and risk supervision are performed simultaneously; If there is an execution risk, and the risk factor is less than or equal to the preset risk factor, security alarm management is performed for the execution location; If there is an execution risk, and the risk factor is greater than the preset risk factor, a security alarm is executed, and the data interaction task is interrupted and locked.
Citation Information
Patent Citations
Safety check method, system and storage medium
CN108391266A
Field operation terminal security access protection and detection system
CN110691064A
Access control method, device and equipment and computer storage medium
CN118740405A
Device for secure data exchange in financial transactions using blockchain
DE202024106186U1
System for secure data processing and data protection-compliant analytics
DE202025100530U1
Cited By
Credit investigation management method and device
CN121414483A