Intelligent data security management system based on digital twinning
By adopting dynamic anonymous privacy protection method and generalization tree division strategy in the digital twin data security management system, the problem of privacy leakage and data utilization balance during transmission and use of digital twin data is solved, and efficient data security and privacy protection is achieved, while maximizing the availability of data.
Patent Information
- Application Number
- CN202510690435.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-06-24
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Current digital twin data is prone to serious privacy leakage problems due to incorrect operation or improper management during transmission and use, and existing security protection methods are difficult to ensure the high availability of data, its security and privacy at the same time.
Dynamic anonymous privacy protection methods are adopted to protect sensitive information, reduce the risk of privacy leakage through multi-level decision-making and generalization processing, and enhance data security by adding noise data to boundary areas. At the same time, the twin data is classified, the generalization tree is built based on attributes, the data is divided into spaces of different granularity, dynamically divided into three regions, and appropriate generalization and suppression operations are performed.
It effectively reduces the risk of privacy leakage, enhances data security and privacy protection levels, while maximizing the availability of data, solving the shortcomings of traditional security protection measures in balancing data protection and utilization.
Smart Images

Figure CN120197225A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and particularly to an intelligent data security management system based on digital twins. Background Art
[0002] With the rapid development of digital twin technology, the security and privacy protection of its data have become particularly important. However, there are still many deficiencies in the current digital twin data security field; such data often contains a large amount of highly sensitive information, including but not limited to key information such as personal identity, health status, and geographical location. During the data transmission and usage process, once there are incorrect operations or improper management, it is very likely to cause serious privacy leakage problems; the current security protection means are insufficient in ensuring the effective utilization of these valuable data resources and are difficult to simultaneously ensure the high availability, security, and privacy of the data. Summary of the Invention
[0003] In view of the above situation, to overcome the defects of the prior art, the present invention provides an intelligent data security management system based on digital twins. For the problem that once there are incorrect operations or improper management during the data transmission and usage process, it is very likely to cause serious privacy leakage problems, this solution uses a dynamic anonymous privacy protection method to protect sensitive information. By implementing multi-level decision-making and generalization processing, the risk of privacy leakage is reduced, and the data security is further enhanced by adding noise data to the boundary area; for the problem that the current security protection means are insufficient in ensuring the effective utilization of these valuable data resources and are difficult to simultaneously ensure the high availability, security, and privacy of the data, this solution classifies the twin data, constructs a generalization tree based on attributes, and divides it into spaces with different granularities. According to the different characteristics of these granularity spaces, the data is dynamically divided into three regions, and appropriate generalization, suppression, etc. operations are performed for each region. This strategy not only realizes a more detailed division of different degrees of sensitive information, but also maximally retains the availability of the data while ensuring that the privacy protection requirements are met, successfully overcoming the deficiencies of traditional security protection measures in balancing data protection and utilization.
[0004] An intelligent data security management system based on digital twins provided by the present invention includes a data twin modeling module, a real-time data monitoring module, an intelligent analysis and decision-making module, a dynamic protection execution module, and a visualization linkage response module;
[0005] The data twin modeling module constructs a high-fidelity digital twin model based on enterprise data assets. The digital twin model includes mapping data storage locations, access paths, and permission relationships, simulates the paths and states of data during transmission, processing, and sharing, and constructs common threat scenarios and attack patterns;
[0006] The real-time data monitoring module obtains the data flow status, behavior data, and environmental data in real time through sensors, probes, and log collection tools, and transmits them to the digital twin model. The data flow status includes data access frequency, transmission path, and storage location; the behavior data includes the login behavior, operation permissions, and abnormal access patterns of users and devices; the environmental data includes network traffic, system logs, and vulnerability scan results;
[0007] The intelligent analysis and decision-making module combines the digital twin model with real-time data for multi-dimensional security analysis, including threat detection, risk prediction, and adaptive policy generation;
[0008] The dynamic protection execution module anonymizes the data using the method of dynamic anonymous privacy protection, refines the data using the three-way decision method, and uses the digital twin model to roll back the damaged data and automatically repair the vulnerabilities;
[0009] The visualization linkage response module displays the data asset distribution, threat situation, and protection strategies through a 3D visualization interface, and links with the enterprise's existing security systems to achieve threat intelligence sharing and collaborative response.
[0010] Furthermore, the dynamic protection execution module anonymizes the twin data using the method of dynamic anonymous privacy protection and refines the twin data using the three-way decision method, which specifically includes the following steps:
[0011] Step S1: Data preprocessing, obtaining the twin data in the digital twin model, and dividing the twin data into identification attributes, quasi-identifier attributes, and sensitive attributes;
[0012] Step S2: Generalization tree construction, constructing an attribute generalization tree based on the quasi-identifier attributes, and the attribute generalization tree is divided into different generalization levels;
[0013] Step S3: Three-way decision-making, using the three-way decision-making division method to dynamically divide the data area to obtain the positive area, boundary area, and negative area, and gradually refine the granularity;
[0014] Step S4: Generate a multi-level decision table, and generate a decision table for each generalization level of all twin data according to the three-way decision-making division method;
[0015] Step S5: Add noise, use the Laplace method to add noise data to the data in the boundary area to obtain anonymous data;
[0016] Step S6: Data publishing, storing the anonymized data added with noise in a secure data set, and transmitting it to the digital twin model for publishing and use;
[0017] Furthermore, in step S2, the generalization tree construction specifically includes the following steps:
[0018] Step S21: Define a generalization tree. For each quasi-identifier attribute, construct a generalization tree with m levels. The attribute generalization tree is refined successively from top to bottom. The data in the attribute generalization tree includes identification attributes and sensitive attributes;
[0019] Step S22: Determine the maximum generalization level. The maximum value of the heights of the generalization trees of all attributes is ;
[0020] Step S23: Complete the generalization tree. If the height of an attribute generalization tree is less than , then fill the remaining levels with the value of the highest level of this attribute generalization tree;
[0021] Furthermore, in step S3, the three-way decision partitioning method specifically includes the following steps:
[0022] Step S31: Granularity space partitioning. According to the number of quasi-identifier attributes, divide the twin data into n granularity spaces, and each granularity space contains levels of hierarchy;
[0023] Step S32: In each granularity space, use the l-th level quasi-identifier attribute to divide the twin data into s equivalent groups, and set an anonymity threshold H and L, where H is the high anonymity threshold and L is the low anonymity threshold;
[0024] Step S33: Data partitioning. According to the set anonymity threshold, divide each equivalent group into a positive region, a boundary region, and a negative region;
[0025] Step S34: Generalization and suppression. Suppress the data in the negative region and do not enter the next granularity space. Generalize the data in the boundary region to a higher level and reclassify it. If the requirements of the anonymity threshold still cannot be met after generalization to the highest level, then suppress this data;
[0026] Step S35: Data transfer. The data in the positive region and the boundary region enter the next granularity space and continue to perform the operations in step S34;
[0027] Step S36: Anonymization stage. Anonymize the data in the positive region to make the data in the positive region meet the anonymity requirements of the high anonymity threshold, and suppress the data in the negative region.
[0028] The beneficial effects achieved by the present invention using the above solution are as follows:
[0029] (1) In the process of data transmission and use, once there are incorrect operations or improper management, it is very likely to cause serious privacy leakage problems. This solution uses a dynamic anonymous privacy protection method to protect sensitive information. By implementing multi-level decision-making and generalization processing, the risk of privacy leakage is reduced, and the data security is further enhanced by adding noise data to the boundary area;
[0030] (2) Regarding the current security protection means being unable to effectively utilize these valuable data resources, and it is difficult to ensure both the high availability of data and its security and privacy at the same time. This method classifies twin data, constructs a generalization tree based on attributes, and divides it into spaces with different granularities. Subsequently, according to the different characteristics of these granularity spaces, the data is dynamically divided into three regions, and appropriate generalization, suppression, etc. operations are performed for each region. This strategy not only realizes a more detailed division of different levels of sensitive information, but also maximally retains the availability of data while ensuring compliance with privacy protection requirements. Therefore, this method not only strengthens the data security and privacy protection level, but also improves the utilization value of data, successfully overcoming the deficiencies of traditional security protection measures in balancing data protection and utilization. Even in the face of complex data environments, it can effectively ensure the security and efficient utilization of data resources. Brief Description of the Drawings
[0031] Figure 1 It is a schematic diagram of an intelligent data security management system based on digital twins proposed by the present invention;
[0032] Figure 2 It is a schematic diagram of the process of anonymizing twin data;
[0033] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention. Detailed Embodiments
[0034] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments; based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0035] Embodiment 1, refer to Figure 1 , an intelligent data security management system based on digital twins provided by the present invention, which includes a data twin modeling module, a real-time data monitoring module, an intelligent analysis and decision-making module, a dynamic protection execution module, and a visualization linkage response module;
[0036] The data twin modeling module constructs a high-fidelity digital twin model based on enterprise data assets. The digital twin model includes mapping data storage locations, access paths, and permission relationships, simulates the paths and states of data during transmission, processing, and sharing, and constructs common threat scenarios and attack patterns.
[0037] The real-time data monitoring module obtains the data flow status, behavior data, and environmental data in real time through sensors, probes, and log collection tools, and transmits them to the digital twin model. The data flow status includes data access frequency, transmission path, and storage location; the behavior data includes login behaviors, operation permissions, and abnormal access patterns of users and devices; the environmental data includes network traffic, system logs, and vulnerability scan results.
[0038] The intelligent analysis and decision-making module combines the digital twin model with real-time data for multi-dimensional security analysis, including threat detection, risk prediction, and adaptive policy generation. The real-time data is the data flow status, behavior data, and environmental data of the real-time data monitoring module.
[0039] The dynamic protection execution module anonymizes the twin data using the method of dynamic anonymous privacy protection, refines the twin data using the three-way decision method, and uses the digital twin model to roll back damaged data and automatically repair vulnerabilities.
[0040] The visualization linkage response module displays the data asset distribution, threat situation, and protection policies through a 3D visualization interface, and links with the enterprise's existing security systems to achieve threat intelligence sharing and collaborative response.
[0041] Embodiment 2. This embodiment is based on the above embodiment. The permission relationship of the data twin modeling module includes the digital representation of information such as user roles, access levels, and operation permissions. A role-based access control mechanism. By defining different roles, including but not limited to administrators, ordinary employees, and external partners, and assigning corresponding permission sets to each role, the model can strictly limit the user's ability to operate data according to the scope of their responsibilities. For example, an administrator may have full access rights, while an ordinary employee can only view part of the data or perform limited operations.
[0042] Dynamic permission verification, real-time monitoring of users' access behaviors, and combining context information, including time, location, and device type, for dynamic permission verification. If a user attempts to access sensitive data from an abnormal geographical location or an unauthorized device, the system will automatically trigger an alarm or reject the access request. This dynamic verification mechanism effectively prevents security risks caused by permission abuse or account leakage.
[0043] Embodiment 3. Refer to Figure 1 and Figure 2, this embodiment is based on the above embodiment. The dynamic protection execution module anonymizes the twin data using the method of dynamic anonymous privacy protection and refines the twin data using the three-way decision method, which specifically includes the following steps:
[0044] Step S1: Data preprocessing. Obtain the twin data in the digital twin model and divide the twin data into identification attributes, quasi-identifier attributes, and sensitive attributes. Identification attributes are used to uniquely identify assets or records. Quasi-identifier attributes may identify assets when combined with other information, while sensitive attributes contain sensitive information that requires special protection;
[0045] The identification attributes can be user IDs, device IDs, and the IDs of physical assets. The quasi-identifier attributes are asset categories, geographical locations, device types and models, manufacturing dates, sensor data related to assets, and asset status. The sensitive attributes include test results of devices, deviation details, simulation results, software details, and material safety data sheets;
[0046] Step S2: Generalization tree construction. Build an attribute generalization tree based on the quasi-identifier attributes. The attribute generalization tree is divided into different generalization levels;
[0047] Step S3: Three-way decision. Dynamically divide the data region using the three-way decision partitioning method to obtain the positive region, boundary region, and negative region, and gradually refine the granularity;
[0048] Step S4: Generate multi-level decision tables. Generate decision tables for each generalization level of all twin data according to the three-way decision partitioning method. The generation of the decision table is as follows: ;
[0049] Among them, represents the set of all records at the th generalization level, represents the set of quasi-identifier attributes at the th generalization level, represents the set of sensitive attributes at the th generalization level, is the decision table at the th generalization level;
[0050] Step S5: Add noise. Use the Laplace method to add noise data to the data in the boundary region to obtain anonymized data;
[0051] Step S6: Data publishing. Store the anonymized data with added noise in a secure dataset and transfer it to the digital twin model for publishing and use.
[0052] Embodiment 4. This embodiment is based on the above embodiment. In step S2, the construction of the generalization tree specifically includes the following steps:
[0053] Step S21: Define the generalization tree. Build an m-level generalization tree for each quasi-identifier attribute. The attribute generalization tree is refined sequentially from top to bottom. The data in the attribute generalization tree includes identification attributes and sensitive attributes. The attribute generalization tree of the asset category can be divided into assets from top to bottom. Assets are divided into financial assets, physical assets, and virtual assets. Financial assets are divided into stocks and bonds. The last layer is the specific name and number of the assets. The attribute generalization tree of the geographical location is graded according to country, province / state, city, township, and community / group.
[0054] Step S22: Determine the maximum generalization level. The maximum value of the heights of the generalization trees of all attributes is ;
[0055] Step S23: Complete the generalization tree. If the height of an attribute generalization tree is less than , then fill the remaining levels with the value of the highest level of the attribute generalization tree. For example, the above asset category is divided into four levels, and the geographical location is divided into five levels. Then the fifth level of the asset is filled with assets.
[0056] By performing the above operations, in the process of data transmission and use, once an error operation or improper management occurs, it is very likely to cause serious privacy leakage problems. This solution uses a dynamic anonymous privacy protection method to protect sensitive information. By implementing multi-level decision-making and generalization processing, the risk of privacy leakage is reduced, and the data security is further enhanced by adding noise data to the boundary area.
[0057] Embodiment 5. Refer to Figure 2 , this embodiment is based on the above embodiment. In step S3, the three-way decision partitioning method specifically includes the following steps:
[0058] Step S31: Granularity space partitioning. Divide the twin data into n granularity spaces according to the number of quasi-identifier attributes. Each granularity space contains levels of hierarchy.
[0059] Step S32: In each granularity space, use the l-level quasi-identifier attribute to divide the twin data into s equivalent groups, and set the anonymity thresholds H and L, where H is the high anonymity threshold and L is the low anonymity threshold.
[0060] Step S33: Data partitioning. According to the set anonymity thresholds, divide each equivalent group into a positive region, a boundary region, and a negative region.
[0061] Step S34: Generalization and suppression. Suppress the data in the negative region and prevent it from entering the next granularity space. Generalize the data in the boundary region to a higher level and reclassify it. If the generalization to the highest level still fails to meet the requirements of the anonymity threshold, suppress this data.
[0062] Step S35: Data transfer. The data in the positive region and the boundary region enter the next granularity space and continue with the operations in Step S34.
[0063] Step S36: Anonymization phase. Anonymize the data in the positive region to make the data in the positive region meet the anonymity requirements of the high anonymity threshold, and suppress the data in the negative region.
[0064] Example 6. This example is based on the above example. In Step S33, the data division of the positive region, the boundary region, and the negative region specifically includes the following: ; ; ;
[0065] where represents the dataset divided by the quasi-identifier attributes at the th generalization level in the th granularity space, represents the data in , represents the size of the equivalence group where the record is located, is the high anonymity threshold, indicating the minimum anonymity requirement that the data must meet in the positive region, is the low anonymity threshold, indicating the minimum anonymity requirement that the data must meet in the boundary region, is the positive region, is the boundary region, is the negative region.
[0066] By performing the described operations, the current security protection measures are unable to effectively utilize these valuable data resources, and it is difficult to ensure both the high availability of data and its security and privacy at the same time. This method classifies the twin data, constructs a generalization tree based on attributes, and divides it into spaces with different granularities. Subsequently, according to the different characteristics of these granularity spaces, the data is dynamically divided into three regions, and appropriate generalization, suppression, and other operations are performed on each region. This strategy not only achieves a more detailed division of sensitive information at different levels, but also maximally retains the availability of the data while ensuring compliance with privacy protection requirements. Therefore, this method not only strengthens the security and privacy protection level of the data, but also enhances the utilization value of the data, successfully overcoming the deficiencies of traditional security protection measures in balancing data protection and utilization. Even in the face of a complex data environment, it can effectively ensure the security and efficient utilization of data resources.
[0067] It should be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device.
[0068] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
[0069] The above describes the present invention and its implementation manners. This description is not restrictive, and only one of the implementation manners of the present invention is shown in the drawings. The actual structure is not limited thereto. Generally speaking, if those of ordinary skill in the art are inspired by it and design similar structural manners and embodiments without creative efforts without departing from the purpose of the present invention, they shall fall within the protection scope of the present invention.
Claims
1. An intelligent data security management system based on digital twin, characterized in that: The system includes a data twin modeling module, a real-time data monitoring module, an intelligent analysis and decision-making module, a dynamic protection execution module, and a visualization linkage response module; The data twin modeling module constructs a high-fidelity digital twin model based on enterprise data assets. The digital twin model includes mapping data storage locations, access paths, and permission relationships, simulates the paths and states of data during transmission, processing, and sharing, and constructs common threat scenarios and attack patterns; The real-time data monitoring module obtains the data flow status, behavior data, and environmental data in real time through sensors, probes, and log collection tools, and transmits them to the digital twin model; The intelligent analysis and decision-making module combines the digital twin model and real-time data to perform multi-dimensional security analysis, including threat detection, risk prediction, and adaptive policy generation; The dynamic protection execution module anonymizes the twin data using the method of dynamic anonymous privacy protection, refines the twin data using the three-way decision method, and uses the digital twin model to roll back damaged data and automatically repair vulnerabilities; The visualization linkage response module displays the data asset distribution, threat situation, and protection policies through a 3D visualization interface, and links with the enterprise's existing security systems to achieve threat intelligence sharing and collaborative response.
2. The intelligent data security management system based on digital twin according to claim 1, wherein: The dynamic protection execution module anonymizes the twin data using the method of dynamic anonymous privacy protection and refines the twin data using the three-way decision method, which specifically includes the following steps: Step S1: Data preprocessing, obtaining the twin data in the digital twin model, and dividing the twin data into identification attributes, quasi-identifier attributes, and sensitive attributes; Step S2: Generalization tree construction, constructing an attribute generalization tree based on the quasi-identifier attributes, and the attribute generalization tree is divided into different generalization levels; Step S3: Three-way decision-making, using the three-way decision-making division method to dynamically divide the data area to obtain a positive area, a boundary area, and a negative area, and gradually refine the granularity; Step S4: Generate a multi-level decision table, and generate a decision table for each generalization level of all twin data according to the three-way decision-making division method; Step S5: Add noise, use the Laplace method to add noise data to the data in the boundary area to obtain anonymous data; Step S6: Data publishing, storing the anonymized data after adding noise in a secure dataset, and transmitting it to the digital twin model for publishing and use.
3. The intelligent data security management system based on digital twin according to claim 2, characterized in that: In step S3, the three-way decision-making division method specifically includes the following steps: Step S31: Granularity space division. According to the number of quasi-identifier attributes, the twin data is divided into n granularity spaces, and each granularity space contains levels; Step S32: In each granularity space, use the l-th level quasi-identifier attribute to divide the twin data into s equivalent groups, and set the anonymous thresholds H and L, where H is the high anonymous threshold and L is the low anonymous threshold; Step S33: Data division, dividing each equivalent group into a positive area, a boundary area, and a negative area according to the set anonymous thresholds; Step S34: Generalization and suppression, suppressing the data in the negative area and not allowing it to enter the next granularity space, generalizing the data in the boundary area to a higher level and reclassifying it. If the requirements of the anonymous threshold cannot be met even after generalization to the highest level, suppress this data; Step S35: Data transfer. The data in the positive region and the boundary region enter the next granularity space and continue with the operations in Step S34. Step S36: Anonymization phase. Anonymize the data in the positive region so that the data in the positive region meets the anonymity requirements of the high anonymity threshold, and suppress the data in the negative region.
Citation Information
Patent Citations
Data security protection system based on block chain
CN118827140A