Zero-trust data security protection method and system based on data identification
By scanning and extracting data identification and collecting operational behavior data, dynamically adjusting access control policies, the lack of data hierarchical access control and continuous risk assessment in the existing technology is solved, and zero-trust data security protection and data leakage risk reduction is achieved.
Patent Information
- Application Number
- CN202510137268.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-06-24
AI Technical Summary
Existing data security technologies lack data hierarchical access control, continuous risk assessment and data access security processing, resulting in the inability to achieve fine-grained secure access and reduce the risk of data leakage.
By scanning and extracting data, performing object-based unified management, and collecting operational behavior data for monitoring and quantitative evaluation, dynamically adjusting access control policies to achieve on-demand compliance access and security risk management of data.
It realizes zero-trust data security protection, provides comprehensive, high-performance and scalable data security risk analysis, dynamically adjusts access control policies, and reduces data leakage risks.
Smart Images

Figure CN120197210A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and particularly to a zero-trust data security protection method and system based on data identification. Background Art
[0002] Existing data security access control can access corresponding data by authenticating the user identity. The main existing problems are as follows:
[0003] (1) Lack of hierarchical access control for data. Since data is not classified and graded, the sensitivity of data cannot be defined, and fine-grained security access based on data cannot be achieved.
[0004] (2) Lack of continuous risk assessment for data and users. The security risk status of data and users directly determines the data leakage risk. Continuous risk assessment of data and users will greatly reduce the data leakage risk.
[0005] (3) Lack of secure processing of accessed data. According to the security risk of data access, dynamic identification, desensitization, and leakage detection of data can better protect data security and achieve compliant access to data on demand. Summary of the Invention
[0006] The embodiments of this application provide a zero-trust data security protection method and system based on data identification. By defining the core elements of data security, the object elements of protection analysis are clarified, providing basic support for the comprehensiveness, high performance, and scalability of data security risk analysis for zero-trust security protection.
[0007] The embodiments of this application provide a zero-trust data security protection method based on data identification, including:
[0008] Performing a scan on target data to extract data identification, and uniformly managing sensitive data object by object according to the extracted data identification;
[0009] Collecting relevant operation behavior data for the sensitive data and users that are uniformly managed object by object, and monitoring and quantitatively evaluating based on the operation behavior data;
[0010] Dynamically adjusting the access control policy for the corresponding user according to the quantitative evaluation result.
[0011] Optionally, performing a data scan to extract data identification, and uniformly managing sensitive data object by object according to the extracted data identification includes:
[0012] Extracting data fingerprints through a hash algorithm and a fuzzy hash algorithm respectively, where the hash algorithm is used to describe the uniqueness of the target data, and the fuzzy hash algorithm is used to describe the similarity of data.
[0013] Using a classification and grading model pre-trained based on a classification algorithm, classify and grade the target data by inputting the key information of the target data into the classification and grading model;
[0014] Encapsulate a data identifier according to the data fingerprint and the classification and grading situation of the data. The data representation includes basic attributes, data fingerprint, category, and level information, so as to achieve objectified unified management of sensitive data through the data identifier.
[0015] Optionally, collect relevant operation behavior data for monitoring and quantitative evaluation based on the operation behavior data, including:
[0016] Collect operation behavior data and corresponding operation behavior logs, and parse the collected operation behavior logs to generate a data set, where the data set includes data elements, user elements, carrier elements, and behavior elements;
[0017] Through a clustering analysis algorithm, cluster the user data operation behavior to construct a data security risk behavior baseline for users and object data;
[0018] Analyze the collected data security elements through the data security risk behavior baseline to determine the judgment result of relevant security risk events;
[0019] Based on preset data security risk impact factors, conduct periodic impact assessments on the security risks of data and users.
[0020] Optionally, according to the quantitative evaluation results, dynamically adjust the access control strategy for the corresponding user, including:
[0021] Collect data and the corresponding operation behavior logs of the user, and parse the current operation behavior into data security elements;
[0022] According to the judgment results of historical relevant security risk events, construct a security risk analysis model with the data security elements of the current operation behavior to evaluate the security risk of the current data operation behavior;
[0023] According to the security risk of the current data operation behavior, adjust the data range with the data identifier as the core for the current data access permission, and adopt the principle of range contraction, where the number of folders accessed by file data is restricted, and the columns accessed by database files are restricted.
[0024] Optionally, it further includes the following data security processing steps:
[0025] Identify the data that the user needs to access according to security identifier management, determine the security level of the accessed data, the corresponding access control measures, and the requirements for the accessing users;
[0026] According to the current access control policy, dynamically desensitize the accessed data to desensitize the data that has no access right, and perform anti-leakage detection on the desensitized data again.
[0027] An embodiment of the present application also provides a zero-trust data security protection system based on data identification, including a processor and a memory. A computer program is stored on the memory, and when the computer program is executed by the processor, the steps of the zero-trust data security protection method based on data identification as described above are implemented.
[0028] By defining the core elements of data security in the embodiment of the present application, the element objects of protection analysis are clarified, providing a basic support for the comprehensiveness, high performance, and scalability of the data security risk analysis of zero-trust security protection.
[0029] The above description is only an overview of the technical solution of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features, and advantages of the present application more obvious and understandable, the specific embodiments of the present application are specifically exemplified below. Description of the Drawings
[0030] By reading the detailed description of the preferred embodiments below, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present application. And throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:
[0031] Figure 1 It is a schematic diagram of the basic process of the zero-trust data security protection method based on data identification;
[0032] Figure 2 It is a schematic diagram of the technical architecture of the zero-trust data security protection method based on data identification;
[0033] Figure 3 It is a schematic diagram of the working principle of the zero-trust data security protection method based on data identification. Detailed Embodiments
[0034] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.
[0035] An embodiment of the present application provides a zero-trust data security protection method based on data identification, as Figure 1As shown, it includes the following steps:
[0036] In step S101, target data is scanned to extract data identifiers, and sensitive data is uniformly managed in an objectified manner according to the extracted data identifiers. Specifically, the target data can be structured data or unstructured data. In some embodiments, scanning the data to extract data identifiers and uniformly managing sensitive data in an objectified manner according to the extracted data identifiers includes:
[0037] Data fingerprints are extracted respectively through a hash algorithm and a fuzzy hash algorithm to describe the uniqueness and similarity of the target data, facilitating subsequent accurate identification of the data, where the hash algorithm is used to describe the uniqueness of the target data, and the fuzzy hash algorithm is used to describe the similarity of the data.
[0038] Using a pre-established classification and grading model, the target data is classified and graded. By inputting the key information of the target data into the classification and grading model, such as inputting the file name, paragraph name, keywords, etc. into the classification and grading model, the target data is classified and graded, providing a basis for subsequent on-demand compliant access to the data.
[0039] A data identifier is encapsulated according to the data fingerprint and the classification and grading situation of the data. The data representation includes basic attributes, data fingerprint, category, and level information to uniformly manage sensitive data in an objectified manner through the data identifier. For example, in some specific examples, the data identifier is encapsulated to cover data fingerprint, classification and grading information, attribution information, access control information, etc., to achieve global unified management.
[0040] In some specific examples, the core carrier of data elements is the data source. In the embodiments of the present application, the data is further defined and analyzed in a finer dimension based on the data source, facilitating the development of fine-grained security audit and analysis of the data.
[0041] 1) Data fingerprint: unique identifier, physical identifier, semantic identifier, sensitive point identifier, data hash, location information;
[0042] 2) Control elements: data classification, sensitive level, access control;
[0043] 3) Extended elements: attribution party, signature information, registration party, signature information.
[0044] (2) User elements
[0045] User elements mainly refer to the subject that executes data operations, including the using institution, using user, using application, etc.
[0046] 1) Using institution: institution identifier;
[0047] 2) User involved: User identification, affiliated organization, user role, user level;
[0048] 3) Application involved: Application identification, affiliated organization, application level.
[0049] In the process of single - time data access, the user elements involved may include the using organization, the using user, and the using application simultaneously.
[0050] (3) Carrier elements
[0051] Carrier elements mainly refer to the carrier devices that perform data operations, including carrier identification, affiliated user, IP address, MAC address, and carrier level. The carrier elements involved in the process of single - time data access are two - way.
[0052] (4) Behavior elements
[0053] Behavior elements mainly refer to single - time behavior operations. Design behavior scenario elements according to the full life cycle of data and refine data operation behaviors:
[0054] 1) Collection: The operation behaviors during the process of an organization collecting data from various data sources, mainly including ① reading, ② cleaning;
[0055] 2) Transmission: The operation behaviors during the process of data transmission in different systems or networks, including ① sending, ② approval, ③ receiving;
[0056] 3) Storage: The operation behaviors during the process of data being stored in a carrier in a certain form, including ① storing, ② querying;
[0057] 4) Processing: The operation behaviors during the process of data analysis and processing, including ① adding, ② modifying, ③ calculating;
[0058] 5) Exchange: The operation behaviors of data sharing and exchanging between different systems and departments, including ① publishing, ② publishing approval, ③ subscribing, ④ subscribing approval, ⑤ exchanging;
[0059] 6) Destruction: The operation behaviors of data being securely destroyed according to relevant requirements, including ① approval, ② deletion.
[0060] In step S102, collect the relevant operation behavior data of the objectified and uniformly managed sensitive data and users, so as to conduct continuous monitoring and quantitative evaluation based on the operation behavior data.
[0061] In step S103, dynamically adjust the access control policy of the corresponding user according to the quantitative evaluation results.
[0062] In a specific example, such as Figure 2As shown in the figure, the technical architecture of the zero-trust data security protection method based on data identification in this application mainly includes three parts: a control layer, a data layer, and a support service, where:
[0063] Control layer: It is mainly composed of a data security governance service platform, which is the core of zero-trust data security protection. Through data identification management and continuous trust assessment, it realizes the dynamic adjustment of data access policies and ultimately supports the unified management of data access policies.
[0064] Data layer: It is mainly composed of an API data security gateway, which is the control point of zero-trust data security protection. During the process of a subject accessing data, it realizes the real-time processing and control of data access behaviors through API proxy, data identification, access control, and dynamic desensitization.
[0065] Support service: It mainly includes data identification, personnel identity, device identity, situation awareness, and password service applications, etc., providing pre-data fingerprint identification, personnel and device identity information, environmental situation awareness data, password management, and protection services for zero-trust data security protection.
[0066] In some embodiments, relevant operation behavior data is collected for monitoring and quantitative evaluation based on the operation behavior data, including:
[0067] Data security elements, collecting operation behavior data and corresponding operation behavior logs, and parsing the collected operation behavior logs to generate a data set, where the data set includes data elements, user elements, carrier elements, and behavior elements.
[0068] Through the clustering analysis algorithm, cluster the user data operation data behaviors to construct a data security risk behavior baseline for users and object data, which can specifically cover behavior elements such as access devices, time, data volume, and access order.
[0069] Security event analysis, analyzing the collected data security elements through the data security risk behavior baseline to determine the judgment results of relevant security risk events;
[0070] Risk level assessment, based on preset data security risk impact factors, conduct periodic impact assessments on the security risks of data and users.
[0071] Further adjustment of the data security access control policy refers to, for a single user data access behavior, dynamically adjusting the access control policy through comprehensive analysis of the quantitative evaluation levels of the current and past security risks. In some embodiments, dynamically adjusting the access control policy for the corresponding user according to the quantitative evaluation results includes:
[0072] Collect data and the operation behavior logs corresponding to users, and parse the current operation behavior into data security elements;
[0073] According to the determination results of historical relevant security risk events, construct a security risk analysis model with the data security elements of the current operation behavior to evaluate the security risk of the current data operation behavior;
[0074] According to the security risk of the current data operation behavior, adjust the data scope with the data identifier as the core for the current data access permission, and adopt the principle of scope contraction, where the number of folders accessed by file data is restricted, and the columns accessed by database files are restricted.
[0075] It also includes data security processing steps. In the embodiments of the present application, data security processing refers to performing security processing on data in combination with data access control policies to reduce data access security risks. Specifically, in some embodiments, the data security processing steps include:
[0076] In step S104, identify the data that the user needs to access according to security identity management, and determine the security level of the accessed data, the corresponding access control measures, and the requirements for the accessing users.
[0077] In step S105, perform dynamic desensitization processing on the accessed data according to the current access control policy to desensitize the data that cannot be accessed, and perform anti-leakage detection on the desensitized data again. For example, perform data replacement on the data that cannot be accessed, and perform anti-leakage detection on the desensitized data again. For example, perform anti-leakage detection on the replaced data again to ensure that no sensitive data is leaked.
[0078] The method of the present application objectifies data by performing operations such as fingerprint extraction and classification and grading on the data, providing support for subsequent data identification, security risk analysis for data, and adjustment of access control policies.
[0079] The method of the present application establishes a continuous security risk quantification assessment and analysis for specific data, and combines the security risks of the current data and the data operation behavior of the user to realize dynamic adjustment of the data access control policy, and reduces the data leakage risk through means such as dynamic desensitization and anti-leakage detection. Through data security elements, the parsing management of data security access behavior can be realized, which can efficiently support the construction and expansion of the data security risk analysis model.
[0080] The embodiments of the present application also propose a zero-trust data security protection system based on data identifiers, including a processor and a memory. A computer program is stored on the memory, and when the computer program is executed by the processor, the steps of the zero-trust data security protection method based on data identifiers as described above are realized.
[0081] It should be noted that in the embodiments of the present application, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or device including such element.
[0082] The serial numbers of the embodiments of the present application above are only for description and do not represent the superiority or inferiority of the embodiments.
[0083] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc) and includes several instructions for causing a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present application.
[0084] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims. All of these are within the protection scope of the present application.
Claims
1. A zero-trust data security protection method based on data identification, characterized in that: include: Scan the target data to extract data identifiers, and manage sensitive data in an object-oriented and unified manner based on the extracted data identifiers; For sensitive data and users that are managed in an object-oriented and unified manner, relevant operational behavior data is collected to monitor and quantify evaluation based on the operational behavior data; Based on the quantitative evaluation results, the access control policy for the corresponding users is dynamically adjusted.
2. The zero-trust data security protection method based on data identification according to claim 1, characterized in that: Scan data to extract data identifiers, and manage sensitive data in an object-oriented and unified manner based on the extracted data identifiers, including: Extracting data fingerprints by using a hash algorithm and a fuzzy hash algorithm respectively, wherein the hash algorithm is used to describe the uniqueness of target data, and the fuzzy hash algorithm is used to describe the data similarity; Using a classification and grading model pre-trained based on a classification algorithm, key information of the target data is input into the classification and grading model to classify and grade the target data; Data identification is formed by encapsulating data fingerprints and data classification and grading. The data representation includes basic attributes, data fingerprints, categories and level information, so as to achieve object-oriented and unified management of sensitive data through data identification.
3. The zero-trust data security protection method based on data identification according to claim 1, characterized in that: Collect relevant operational behavior data to monitor and quantify evaluation based on the operational behavior data, including: Collecting operation behavior data and corresponding operation behavior logs, and parsing the collected operation behavior logs to generate a data set, wherein the data set includes data elements, user elements, carrier elements, and behavior elements; Clustering analysis algorithms are used to cluster user data operation behaviors to build a data security risk behavior baseline for user and object data. Analyze the collected data security elements through the data security risk behavior baseline to determine the determination results of relevant security risk events; Based on the preset data security risk impact factors, periodic impact assessments are conducted on the security risks of data and users.
4. The zero-trust data security protection method based on data identification according to claim 3 is characterized in that: Based on the quantitative evaluation results, the access control policy for the corresponding user is dynamically adjusted, including: Collect data and the user's corresponding operation behavior logs, and analyze the operation behavior into data security factors; Based on the judgment results of historical related security risk events and the data security factors of the current operation behavior, a security risk analysis model is constructed to assess the security risks of the current data operation behavior; According to the security risks of the current data operation behavior, the data scope of this data access right is adjusted with data identification as the core, and the scope contraction principle is adopted. Among them, the file data limits the number of folders it can access, and the database file limits the columns it can access.
5. The zero-trust data security protection method based on data identification according to claim 4 is characterized in that: It also includes the following data security processing steps: Identify the data that users need to access based on security identification management, determine the security level of access data, corresponding access control measures, and requirements for access users; According to the current access control policy, the access data is dynamically desensitized to desensitize the data that is not authorized to access, and the desensitized data is again tested for leakage prevention.
6. A zero-trust data security protection system based on data identification, characterized in that: It includes a processor and a memory, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the steps of the zero-trust data security protection method based on data identification as described in any one of claims 1 to 5 are implemented.