Multi-level security management method for trusted data space

By employing a multi-layered security management approach for trusted data spaces, including subject access authentication, group isolation agreements, and multi-layered security verification, the problems of insufficient real-time performance and high false positive rates in existing technologies are resolved, enabling real-time risk identification and enhanced security for data interaction tasks.

CN120185887BActive Publication Date: 2026-01-02LINGSHU TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510340207.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2026-01-02
Estimated Expiration
2045-03-21

AI Technical Summary

Technical Problem

Existing technologies suffer from insufficient real-time performance, poor rule matching adaptability, and high false positive rates in anomaly detection, making it impossible to quickly and accurately identify and respond to risks in complex environments, thus affecting the security and stability of data interaction tasks.

Method used

By performing access authentication and trust rating on the entities connecting to the trusted data space, introducing a group isolation treaty based on data scenarios, setting up multi-layered security verification checkpoints, and encrypting node data on disk for core data nodes, the system implements group isolation and security verification of the entities connecting to the node data scenarios. Combined with group isolation and security verification of task cycle link nodes, the system ensures the security of the data interaction process.

Benefits of technology

This has improved the real-time risk identification capability, enhanced system adaptability, and reduced the false judgment rate of data interaction tasks, ensuring the security and stability of the data interaction process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185887B_ABST
    Figure CN120185887B_ABST
Patent Text Reader

Abstract

The application provides a multi-level security management method for a trusted data space, relates to the technical field of data security management, and comprises the following steps: performing subject access authentication and trust rating on a connection subject of the trusted data space, introducing a group isolation treaty based on a data scene; setting a multi-level security check checkpoint for the security management of the trusted data space, and performing node data disk encryption on a core data node of the trusted data space; obtaining a data interaction task, triggering the group isolation treaty for a sequence link node of a task cycle chain, implementing group isolation of a connection subject of a node data scene, and implementing security check of a checkpoint of the node data scene by matching the multi-level security check checkpoint. The application can achieve the technical target of dynamic security management based on task tracking and risk supervision, improve the real-time risk identification capability of the data interaction task, and thus ensure the safety and stability of the data interaction process.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security management, in particular to a multi-level security management method for a trusted data space. BACKGROUND

[0002] With the rapid development of information technology, data interaction plays an increasingly important role in various systems and is widely used in fields such as the Internet of Things, cloud computing, intelligent transportation, and financial payment.

[0003] Currently, existing task tracking and risk supervision technologies mainly rely on log recording, rule matching, and abnormality detection methods based on historical data, which to some extent improve the security of data interaction. However, these methods have limitations in real-time performance, adaptability, and accuracy, making it difficult to meet the data security needs in complex environments. The log recording method cannot provide immediate feedback, resulting in delayed risk response; the rule matching method relies on preset strategies and has poor adaptability to new attack methods; and the abnormality detection based on historical data is prone to misjudgment or omission, especially in cases of large data interaction and complex business logic, which affects the stability of the system.

[0004] In summary, the existing technology has the technical problem that due to insufficient real-time performance, poor adaptability of rule matching, and high misjudgment rate of abnormality detection, it is difficult to quickly and accurately identify and respond to risks in complex environments, further affecting the security and stability of data interaction tasks. SUMMARY

[0005] The purpose of the present application is to provide a multi-level security management method for a trusted data space to solve the technical problem that due to insufficient real-time performance, poor adaptability of rule matching, and high misjudgment rate of abnormality detection, it is difficult to quickly and accurately identify and respond to risks in complex environments, further affecting the security and stability of data interaction tasks.

[0006] In view of the above problems, the present application provides a multi-level security management method for a trusted data space, which includes: for the connection subject of the trusted data space, subject access authentication and trust rating are performed, and a group isolation treaty based on data scenarios is introduced; a multi-level security check checkpoint of the trusted data space security management is set, and for the core data node of the trusted data space, node data disk encryption is performed; a data interaction task is obtained, for the sequential link nodes of the task period chain, the group isolation treaty is triggered to implement node data scenario connection subject group isolation, and the multi-level security check checkpoint is matched to implement node data scenario checkpoint security check, wherein if there is a core data node, node data disk decryption is implemented.

[0007] The technical solutions provided in the application have at least the following technical effects or advantages: by achieving the technical target of dynamic security management based on task tracking and risk supervision, the real-time risk identification capability of data interaction tasks is improved, the system adaptability is enhanced, and the misjudgment rate is reduced, thereby ensuring the security and stability of the data interaction process.

[0008] The above description is only a summary of the technical solutions of the application. In order to more clearly understand the technical means of the application, the specific embodiments of the application can be implemented in accordance with the content of the specification, and in order to make the above and other purposes, characteristics and advantages of the application more obvious and easy to understand, the following specific embodiments of the application are described. It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the application, nor is it intended to limit the scope of the application. Other features of the application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0009] In order to more clearly illustrate the technical solutions in the application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are only exemplary, and for those skilled in the art, other drawings can be obtained without creative labor on the basis of the provided drawings.

[0010] Figure 1 The flowchart of the multi-level security management method for the trusted data space of the application;

[0011] Figure 2 The flowchart of the multi-level security management method for the trusted data space of the application; DETAILED DESCRIPTION

[0012] The application provides a multi-level security management method for a trusted data space, which solves the technical problems in the prior art that due to insufficient real-time performance, poor rule matching adaptability and high abnormal detection misjudgment rate, risks cannot be quickly and accurately identified and responded in a complex environment, which further affects the security and stability of data interaction tasks. The technical target of dynamic security management based on task tracking and risk supervision is achieved, the real-time risk identification capability of data interaction tasks is improved, the system adaptability is enhanced, and the misjudgment rate is reduced, thereby ensuring the security and stability of the data interaction process.

[0013] Below, the technical solutions in the present application will be described clearly and completely with reference to the drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. It should be understood that the present application is not limited by the example embodiments described herein. Based on the embodiments of the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application. In addition, it should be noted that, for the convenience of description, only parts related to the present application are shown in the drawings, not all.

[0014] Please refer to the drawings Figure 1 The present application provides a multi-level security management method for a trusted data space, which specifically includes the following steps:

[0015] S1: For the connecting subject of the trusted data space, subject access authentication and trust rating are performed, and a group isolation treaty based on data scenarios is introduced.

[0016] Specifically, subject access authentication and trust rating are performed for the connecting subject of the trusted data space. The trusted data space refers to an environment for data exchange and storage, in which all data has a certain degree of trust. The connecting subject refers to each participant in the space for data interaction or storage, such as users, devices or application programs, etc. Subject access authentication is to verify the identity of these participants to ensure that only authenticated subjects can access data. And the trust rating is to score the trust level of the subject based on its behavior history or other relevant standards, so as to distinguish the trust level of different subjects and determine their rights and responsibilities in the trusted data space.

[0017] Next, the introduction of a group isolation treaty based on data scenarios means that different subjects are grouped according to specific application scenarios during data interaction, and different security and access permissions are set for each group. For example, in the financial industry, customer data and transaction data may be grouped to ensure that different subjects access data in accordance with specific security specifications. This group isolation not only reduces the risk of data leakage, but also improves the efficiency and security of data management.

[0018] In addition, the group isolation treaty means that rules or protocols are established to determine how each subject is isolated during data interaction to avoid cross-group access and data sharing between different subjects. When a subject is considered untrusted, it can effectively isolate its interaction with other subjects to avoid causing greater data risks. For example, if a subject has a low trust rating, it will be restricted in an isolated group and cannot access the data of other subjects.

[0019] S2: Set up multiple security check checkpoints for the trusted data space security management, and perform node data disk encryption for the core data nodes of the trusted data space.

[0020] Specifically, setting up multiple security check checkpoints for the trusted data space security management means that in the process of data storage and transmission, multiple checkpoints or audit levels are set up to ensure data security. The checkpoints can set different security standards according to the sensitivity and use of data, for example, more stringent security detection can be set for high-risk data, while more relaxed standards can be set for low-risk data, which helps to gradually strengthen data protection and prevent potential security vulnerabilities.

[0021] Then, node data disk encryption is performed for the core data nodes of the trusted data space. The core data nodes of the trusted data space refer to the part of the data management system that carries the most important data, which are often critical or sensitive. Node data disk encryption means that these core data are encrypted when stored, preventing unauthorized access or tampering. Disk encryption refers to encrypting data when writing to the hard disk or other storage media, ensuring that data remains encrypted during storage.

[0022] Next, the combination of multiple security check checkpoints and node data disk encryption can form a complete data protection system. Through multiple levels of security checks, strict control can be exercised in data storage, transmission, access and other links, while encryption technology can ensure data security, especially for the protection of core data nodes, preventing data leakage or tampering.

[0023] S3: Obtain data interaction tasks, and for the order link nodes of the task cycle chain, implement node data scene group isolation by triggering the group isolation treaty, and implement node data scene checkpoint security check by matching the multiple security check checkpoints, wherein if there is a core data node, implement node data disk decryption.

[0024] Specifically, obtaining data interaction tasks means that in the entire data interaction process, the specific task content needs to be obtained from the task source, including the data involved, participants and interaction targets. Data interaction tasks include data transmission, processing and response, etc. For these tasks, the task cycle chain needs to be analyzed to identify the key nodes in each link for task tracking. The task cycle chain refers to the ordered connection of each node and step in the data interaction process.

[0025] According to the execution period of the task, the data interaction link involved in the task is analyzed in time or logical order. The task cycle chain refers to different stages experienced by the task in the entire execution process, and each stage may involve multiple link nodes, and the sequential link node is a node that performs data interaction in sequence according to the established order.

[0026] By triggering the group isolation treaty, the coupling subject group isolation of the node data scene is implemented, which means that when the data interaction involves different security levels or data sensitivity, different data interaction subjects are divided into independent security groups according to the preset isolation strategy to prevent unnecessary cross access. The group isolation treaty is a preset security rule that determines which coupling subjects need to be isolated, and the implementation process of group isolation involves dynamic adjustment of data flow.

[0027] By matching the multi-layer security check checkpoint, the checkpoint security check of the node data scene is implemented, which means that in the task execution process, according to the data environment of the current node, the appropriate security verification checkpoint is matched, and the corresponding security check is performed. The multi-layer security check checkpoint is composed of multiple security mechanisms of different levels, including identity verification, data integrity check, access control, etc. The matching process is to select the appropriate security verification step according to the risk level of the data scene. Among them, if there is a core data node, the node data disk decryption is implemented, which means that if the sequential link node involved in the task contains a core data node, the data stored in it will be decrypted to ensure that subsequent operations can proceed normally. The core data node refers to the node that stores or processes critical data, which may contain highly sensitive information such as financial records, identity information or critical business data. Data disk decryption refers to decrypting encrypted data so that it can be correctly read when needed. For example, in a blockchain transaction system, transaction records are usually stored in encrypted form, and only when verification or audit is needed, will specific transaction records be decrypted to ensure that data security and privacy protection coexist.

[0028] Further, as shown in Figure 2 , the application further comprises: S31: determining a first link node for the task cycle chain through sequential link node tracking of data interaction, wherein the first link node is a real-time link node of data interaction; S32: determining a node data scene based on the first link node, and determining whether to trigger the group isolation treaty; S33: if not triggered, performing core data node determination and security check based on the multi-layer security check checkpoint.

[0029] Specifically, by tracking the sequential link nodes of data interaction, the first link node can be determined. The first link node refers to the node that initiates the data flow transmission or processing, while the real-time link node refers to the node that is currently interacting with the data.

[0030] Then, based on the node data scenario of the first link node, the relevant data environment is identified and constructed, including task data, node characteristics, and interaction requirements. This scenario determines whether to trigger the group isolation treaty. The group isolation treaty is a security measure based on the node data scenario, aiming to improve data security by isolating different types of data groups.

[0031] Next, if the group isolation treaty is not triggered, the core data node determination is performed to determine whether the current node belongs to the core data node. The core data node refers to the node that carries critical or sensitive data in the data interaction task. Based on this determination, it is determined whether to perform security checks based on multiple security check checkpoints.

[0032] Further, the application also includes: according to the node data scenario, the coupling subject is divided into groups, and the division groups are determined, wherein the safe coupling subject and the risk coupling subject are used as the division standard; for the division groups, the communication isolation node is located; by setting the channel checkpoint, the group isolation processing based on the communication isolation node is performed, wherein the closed state of the channel checkpoint is controlled.

[0033] Specifically, in the process of data interaction, the specific data environment and task requirements of each node are analyzed. The data scenario includes the interaction content between nodes, data types, and security threats faced by the nodes. Through these data scenarios, different types of coupling subjects can be identified and grouped. Group division is to group the coupling subjects according to their roles and security requirements to improve management and security. In this process, the safe coupling subject and the risk coupling subject are the division standards. The safe coupling subject refers to the subject with high trustworthiness and low risk in data interaction, while the risk coupling subject refers to the subject with potential security risks or threats.

[0034] Then, for the division groups, according to the characteristics of different groups, the communication isolation node is further located. The communication isolation node refers to the node that isolates the data flow between certain groups in the data transmission process to enhance security. By setting the communication isolation node, the transmission of data between different groups can be effectively blocked or controlled, preventing potential risk coupling subjects from threatening safe coupling subjects.

[0035] Then, by setting a channel checkpoint, a group isolation processing based on a communication isolation node is performed. The channel checkpoint refers to a mechanism for controlling the security state of the data transmission channel. By setting the open and closed states of the checkpoint, the authority and mode of data flow can be flexibly controlled. If the channel checkpoint is closed, the data flow cannot pass through the isolation node, achieving the purpose of isolating data between different groups, thereby improving the security of the system.

[0036] Further, the application also includes: the communication isolation node is identified with a group isolation time limit; wherein the determination of the group isolation time limit comprises: determining the data operation time zone of the first link node according to the node data scene; setting the data operation time zone as the group isolation time limit.

[0037] Specifically, the communication isolation node refers to a node used to control information flow in the data transmission process, which can limit data interaction between different groups to prevent unauthorized information leakage or security risks. The communication isolation node will be identified with a group isolation time limit, i.e. a time range is set, during which the node only allows certain specific groups to interact with data, while data access of other groups will be blocked, thereby ensuring that data isolation between different groups takes effect within a reasonable time range, thereby improving the flexibility of security management.

[0038] Then, the determination of the group isolation time limit needs to be based on the analysis of the specific data scene. The data scene refers to the data flow, interaction mode and risk assessment at a certain time point or condition. By analyzing the data scene, the data operation time zone of the first link node can be determined. The first link node refers to the data transmission node that is activated or triggered first in the data interaction process, which usually undertakes the initial data processing task, so its data operation time zone is an important factor affecting the subsequent data flow. The data operation time zone refers to the time period during which the node allows data transmission and processing, only within this time period, data interaction can proceed normally.

[0039] Then, the data operation time zone is set as the group isolation time limit to ensure that the time limit of data interaction is consistent with the security policy of the system, thereby ensuring that different groups are isolated within a reasonable time range. For example, if the data operation time zone of a node is six hours out of twenty-four hours, the group isolation time limit will also be set to six hours, which means that the isolation strategy takes effect within this time period, and after this time period, new strategy adjustments may be made.

[0040] Further, the application also includes: the open state of the channel checkpoint is the normal state; if the group isolation treaty is triggered, a group division and communication isolation processing based on a link subject is performed.

[0041] Specifically, the open state of the channel checkpoint refers to the communication channel being in the default open mode, i.e. data can flow freely between different nodes without additional restrictions. In this state, each connected subject is allowed to carry out normal data exchange without the intervention of security policies. The setting of this normal state can ensure the efficiency of data transmission and maintain high communication fluency in daily operation.

[0042] Then, when the group isolation treaty is triggered, the data interaction is intervened according to the preset security policy. The group isolation treaty refers to a set of security management protocols for specific data scenarios. When potential security risks or permission requirements are detected, the treaty will take effect to restrict direct communication between different groups. The triggering conditions may include the transmission of high-risk data, the interaction request between users with different permissions, or the adjustment of security policies in specific environments. For example, in a financial transaction system, when it is detected that a user accesses data related to sensitive fund flow, an isolation policy may be automatically enabled to prevent unauthorized users from accessing critical data.

[0043] Next, after the group isolation treaty is triggered, group division based on connected subjects needs to be performed, which classifies different connected subjects according to their security level, data access permission or business requirements, so as to ensure that the data flow complies with the established security policy. The connected subject can be a user, a device or a server, and each subject will be classified into a corresponding group according to its characteristics. For example, in a medical data management system, doctors, nurses and administrative personnel belong to different connected subjects. Doctors may need to access all patient records, nurses may only be able to view nursing-related information, and administrative personnel may only be able to manage basic patient information.

[0044] In addition, communication isolation processing needs to be performed, which means that on the basis of group division, further restrictions are imposed on data transmission between different groups. Communication isolation processing can be implemented in various ways, such as limiting network connections, setting access permissions or using data encryption technology to ensure that information cannot be obtained by unauthorized subjects.

[0045] Further, the application also includes: determining whether the first link node is the core data node; if so, determining the node key by performing first-order decryption processing based on node data disk encryption; and performing second-order decryption processing on the core data node according to the node key to implement node data task processing.

[0046] Specifically, after implementing group isolation of the coupling subject group of the node data scenario, or not triggering the group isolation treaty, it is determined whether group isolation of the communication subject is required during data interaction. If group isolation has taken effect, it means that the data exchange path is blocked, thereby affecting subsequent task processing. If the group isolation treaty is not triggered, it means that all data interaction subjects can still freely access.

[0047] Then, the determination of the core data node is performed, which means that the key data storage node involved in the current task needs to be identified. The core data node refers to an important node that undertakes data storage, processing, or scheduling tasks in the entire data interaction link. These nodes usually store high-sensitivity data, and therefore require additional security measures. The determination process of the core data node needs to comprehensively analyze data flow, access rights, and security levels to ensure that data processing complies with the preset security rules. For example, in a cloud computing environment, some servers may undertake specific computing tasks, while other servers are only used for data caching, and it is necessary to first identify which servers belong to core data nodes.

[0048] Next, it is determined whether the first link node is a core data node, and it is determined whether the node that first receives data in the data interaction process belongs to a core data storage or computing node. The first link node refers to the first processing node through which data flows, which can be a normal transit node or a core data node. If the first link node is identified as a core data node, more stringent data security management is required. For example, in a distributed storage system, a server can only be a temporary data storage point, while another server stores encrypted core data, and therefore it is necessary to determine whether the current data flow passes through the core data storage area.

[0049] In addition, if the first link node is confirmed as a core data node, first-order decryption processing based on node data disk encryption needs to be performed to determine the node key. Disk encryption refers to encrypting data before storing it on the disk to prevent data from being stolen when stored statically. First-order decryption processing refers to the first layer of decryption of encrypted data to recover part of the encrypted information, thereby obtaining the data key for further decryption.

[0050] Finally, according to the node key, second-order decryption processing of the core data node is performed to implement node data task processing. This means that after obtaining the data key for decryption, a second decryption operation needs to be performed to completely recover the data and perform the corresponding task. Second-order decryption processing is usually used in advanced security scenarios, such as multi-layer encryption mechanisms, to ensure that even if the data is cracked when stored, additional decryption permissions are required to completely obtain the information. Table 1 is a record of the most recent determination of the core data node.

[0051] Table 1: Record of the last time the core data node judgment is performed

[0052]

[0053]

[0054] Further, the application also includes: traversing the multi-layer security check checkpoint for the node data scene, matching and determining the target security check checkpoint, wherein the target security check checkpoint contains at least one item; performing checkpoint security check based on the target security check checkpoint.

[0055] Specifically, after the core data node is subjected to the second-order decryption process, or the first link node is a non-core data point, the security check based on the multi-layer security check checkpoint is performed, which means that after the core data node completes the entire decryption process, or in the case of a data node that is not a core data node, further security detection is required. After the core data node completes the second-order decryption, the data has entered an operable state, and therefore the data integrity and access security need to be guaranteed, and although the non-core data node does not involve decryption, it still needs to prevent potential abnormal access through a security mechanism. In this way, regardless of the node attribute, the entire data interaction process will be subject to security control, ensuring that the data will not be illegally accessed due to security vulnerabilities.

[0056] Traversing the multi-layer security check checkpoint for the node data scene, matching and determining the target security check checkpoint, means that according to the current node data environment, all set security check checkpoints are checked in turn, and the specific security verification steps suitable for the node are screened out. The node data scene refers to the environment in which the node is in during the data interaction process, such as the type of task involved, access rights, and the sensitivity level of the data, etc. The process of traversing the multi-layer security check checkpoint is equivalent to screening the security policies that meet the conditions level by level, ensuring that each node can accept appropriate security checks. For example, if the data node involves highly sensitive data, higher level encryption and access control checkpoints will be matched, and for low sensitive data nodes, only basic identity verification is required to complete the check.

[0057] Performing checkpoint security check based on the target security check checkpoint means that the actual security verification process will be performed for the target security check checkpoint screened out to ensure that the data interaction meets the established security requirements. The target security check checkpoint contains at least one item, which means that even the lowest level of node must pass at least one security verification step. For example, a node may need to perform identity verification, access rights check, and data integrity detection, at least one of which is mandatory. Higher level data scenes may require multiple verification methods to be combined, such as parallel execution of multi-factor identity authentication and end-to-end encryption, to improve overall security.

[0058] Further, the application also includes: the group isolation treaty is periodically updated; wherein the periodic update mode comprises: setting a contract update period; according to the contract update period, calling the running flow data of the coupling subject in the periodic time zone; with the running flow data, performing a trusted rating to determine an update trusted level; based on the update trusted level, adjusting the group isolation treaty.

[0059] Specifically, the periodic update of the group isolation treaty means that the existing group isolation treaty is checked and modified at certain time intervals to ensure its adaptability to the current data interaction situation. The group isolation treaty is a security rule for dividing and isolating different data interaction groups, and the periodic update ensures that the rule will not lose its applicability due to long-term invariability. For example, in network security management, it may be necessary to re-evaluate which users or devices need to be isolated every few days, thereby adjusting access permissions to respond to new security threats or changing business needs.

[0060] Among them, the periodic update mode includes setting a contract update period, which means that the update time interval of the group isolation treaty needs to be determined in advance during runtime, so as to trigger the evaluation and adjustment process periodically. The contract update period can be flexibly set according to business needs, for example, in a financial transaction system, a security evaluation may be performed once a day, while in an industrial control system, due to slower data flow, it may be updated every few tens of days. This periodic setting can ensure that the isolation strategy neither changes too frequently to cause excessive resource consumption, nor affects security due to long-term invariability.

[0061] According to the contract update period, the running flow data of the coupling subject in the periodic time zone is called, which means that in each update period, the running state information of all coupling subjects in the current time range is collected and used as the basis for updating. The running flow data refers to the behavior data of the coupling subject during data interaction, such as access records, data transmission volume, and number of abnormal alarm times. For example, in a cloud computing environment, if a server has frequent abnormal access in the past few days, the behavior data will be recorded and considered during contract update whether to isolate or release the restrictions on the server.

[0062] With running flow data, perform trust rating, determine updated trust level, which means that according to the collected running data, each connected subject will be evaluated and assigned a trust level. The criteria for trust rating may include historical access records, data integrity, abnormal behavior detection and other factors. For example, in an enterprise network, if a user's access behavior always complies with security rules, his trust level may be raised, and if a device frequently has abnormal access, its trust level will be lowered. The adjustment of the trust level is a key step in the adjustment of the group isolation adjustment, which can effectively distinguish between safe access subjects and high-risk subjects.

[0063] Based on the updated trust level, adjust the group isolation treaty, which means that according to the latest trust rating of each connected subject, the group isolation strategy will be modified. If the trust level of a subject is high, it may be removed from the isolation group, and if the trust level of a subject decreases, it may be added to the isolation list. For example, in a bank system, if an account has not had abnormal transactions for a long time, it may be exempted from certain transaction restrictions, and if an account has a large number of suspicious transactions in a short period of time, it may be automatically added to a high-risk group, triggering stricter access control.

[0064] Further, the present application also includes: determining a multi-level security standard according to a plurality of data encryption methods and a plurality of security levels, wherein the data encryption methods include direct key encryption and sensitive processing; configuring the multi-layer security check barrier according to the multi-level security standard.

[0065] Specifically, it is determined according to a plurality of data encryption methods and a plurality of security levels. The plurality of data encryption methods refers to different encryption technologies, such as symmetric encryption and asymmetric encryption, which differ in the way data security is protected. The plurality of security levels refers to the need for data protection, which is divided into different levels according to the sensitivity of data and the use scenario, for example, high security level protection is suitable for core data, and low security level is suitable for general data. By combining these encryption methods and security levels, a more comprehensive and detailed standard for data security can be established.

[0066] Then, the multi-level security standard is determined by reasonably matching different encryption methods and security levels to provide targeted protection measures for different types of data. The multi-level security standard is a multi-level, step-by-step protection system that ensures appropriate security protection for data from storage, transmission to use at each link.

[0067] Next, according to the multi-level security standard, a multi-layer security check checkpoint is configured. The multi-layer security check checkpoint is a multi-layer inspection and verification of data according to the set security standard to ensure that potential security risks can be effectively prevented at each link. Each checkpoint will be based on different standards for strict security checks, thereby achieving all-round protection of data.

[0068] Further, the application also includes: as the data interaction task is executed, task tracking and risk supervision are synchronized; if there is an execution risk and the risk coefficient is less than or equal to the preset risk coefficient, a security alarm management is performed for the execution location; if there is an execution risk and the risk coefficient is greater than the preset risk coefficient, a security alarm is performed, and the data interaction task is interrupted and locked.

[0069] Specifically, as the data interaction task is executed, task tracking and risk supervision are synchronized, which means that the execution of the task is monitored in real time during the data interaction process, and the risks that may occur are evaluated. Data interaction task refers to the data exchange operation between different systems or devices, such as database synchronization, information transmission in the network, etc. Task tracking refers to recording and tracking the execution status of the task to ensure correct data flow and avoid data loss or delay. Risk supervision is to monitor the risks that may lead to data leakage, tampering or interruption, such as monitoring the flow of data packets in a cloud computing environment and detecting abnormal access requests, so as to take timely measures to prevent security risks.

[0070] If there is an execution risk and the risk coefficient is less than or equal to the preset risk coefficient, a security alarm management is performed for the execution location, which means that when a potential risk is found, its risk level is first calculated and compared with the preset risk threshold. If the risk level is within the acceptable range, the task will not be directly interrupted, but a security alarm will be triggered for the location where the risk occurs, so that relevant personnel or system automation mechanism can respond in time. For example, in an Internet of Things device, if the data transmission rate of a sensor is abnormal but does not exceed the acceptable range, an alarm will be triggered for the physical location of the device so that the operation and maintenance personnel can check the running status of the device, thereby avoiding small-scale faults from evolving into larger-scale system problems, reducing unnecessary task interruption and improving system stability.

[0071] If there is an execution risk and the risk coefficient is greater than the preset risk coefficient, a safety alarm is executed, and the data interaction task is interrupted and locked, indicating that when the risk level is detected to exceed the safety threshold, more stringent safety measures will be taken immediately, including issuing an alarm and forcibly interrupting task execution, while locking the task to prevent further data interaction operations. Execution risk refers to a situation that may cause data damage, loss or illegal access, while the risk coefficient is a quantitative measure of the severity of the risk. For example, in an online payment system, if it is found that a certain account has conducted a large number of abnormal transactions in a short period of time, and the risk coefficient exceeds the preset threshold, the payment function of the account will be immediately frozen, and a safety alarm will be issued to prevent further financial losses.

[0072] In summary, the multi-level security management method for trusted data space provided by the present application has the following technical effects: by achieving the technical target of dynamic security management based on task tracking and risk supervision, the real-time risk identification capability of data interaction tasks is improved, the system adaptability is enhanced, and the false positive rate is reduced, thereby ensuring the safety and stability of the data interaction process.

[0073] The above description of disclosed embodiments enables a person skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to these embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.

[0074] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the present application and its equivalents, the present application also intends to include these modifications and variations.

Claims

1. A multi-layered security management method for trusted data spaces, characterized in that: The methods include: For entities connecting to trusted data spaces, entity access authentication and trust rating are performed, and a group isolation treaty based on data scenarios is introduced. A multi-layered security verification system is established for the security management of the trusted data space, and node data encryption is performed on the core data nodes of the trusted data space. The task of acquiring data interaction is carried out. For the sequential link nodes of the task cycle chain, the connection subject group isolation of the node data scenario is implemented by triggering the group isolation treaty. The node data scenario is implemented by matching the multi-layer security verification checkpoint. If there is a core data node, the node data is written to disk and decrypted. For sequential link nodes in the task lifecycle chain, by triggering the aforementioned group isolation treaty, connection subject group isolation of the node data scenario is implemented, including: For the task cycle chain, the first link node is determined by tracing the sequential link nodes of data interaction, wherein the first link node is the real-time link node of data interaction. Determine the node data scenario based on the first link node, and then determine whether the group isolation treaty is triggered; If not triggered, perform the determination of the core data node and the security verification based on the multi-layer security verification checkpoint; If the group isolation agreement is triggered, including: Based on the node data scenario, the connected entities are divided into groups to determine the groups, with secure connected entities and risky connected entities as the dividing criteria. For the aforementioned group division, locate the communication isolation node; By setting channel barriers, group isolation processing based on the communication isolation nodes is performed, wherein control is performed by controlling the closed state of the channel barriers.

2. The multi-layered security management method for trusted data spaces as described in claim 1, characterized in that, The communication isolation node is identified by a group isolation time limit; The determination of the group isolation period includes: Based on the node data scenario, determine the data operation time zone of the first link node; Set the data operation time zone to the group isolation time limit.

3. The multi-layered security management method for trusted data spaces as described in claim 1, characterized in that, The open state of the channel gate is taken as the normal state; If the aforementioned group isolation treaty is triggered, group division and communication isolation processing based on the connected subject will be performed.

4. The multi-layered security management method for trusted data spaces as described in claim 1, characterized in that, After implementing the isolation of the connection subject group in the node data scenario, or if the group isolation treaty is not triggered, the determination of the core data node includes: Determine whether the first link node is the core data node; If so, the node key is determined by performing a first-order decryption process based on node data disk encryption; Based on the node key, the core data node is subjected to second-order decryption processing, and node data task processing is implemented.

5. The multi-layered security management method for trusted data spaces as described in claim 4, characterized in that, After performing second-order decryption on the core data node, or on a non-core data point of the first link node, perform security verification based on the multi-layered security checkpoint, including: For the node data scenario, the multi-layer security verification checkpoints are traversed, and a target security verification checkpoint is determined by matching. The target security verification checkpoint includes at least one item. Based on the target security checkpoint, perform checkpoint security verification.

6. The multi-layered security management method for trusted data spaces as described in claim 1, characterized in that, The group isolation agreement is updated periodically; The periodic update methods include: Set the contract update cycle; According to the contract update cycle, the runtime data of the connected entity within the periodic time zone is retrieved; Based on the aforementioned runtime data, a trust rating is performed to determine and update the trust level; The group isolation treaty is adjusted based on the updated trust level.

7. The multi-layered security management method for trusted data spaces as described in claim 1, characterized in that, Establish multi-layered security checkpoints for trusted data space security management, including: Based on multiple data encryption methods and multiple security levels, a multi-level security standard is determined by combining them. Among them, the data encryption methods include direct key encryption and sensitive processing. Configure the multi-layer security verification checkpoints according to the aforementioned multi-level security standards.

8. The multi-layered security management method for trusted data spaces as described in claim 1, characterized in that, The method also includes: As the data interaction task is executed, task tracking and risk monitoring are performed simultaneously. If there is an execution risk, and the risk coefficient is less than or equal to the preset risk coefficient, a safety alarm management will be implemented for the execution location; If there is an execution risk, and the risk factor is greater than the preset risk factor, a security alarm will be triggered, and the data interaction task will be interrupted and locked.

Citation Information

Patent Citations

  • Safety check method, system and storage medium

    CN108391266A

  • Field operation terminal security access protection and detection system

    CN110691064A