Data security tracing method and system based on graph database

By using a graph database-based method in data security tracking and traceability, a graphical relationship network of data is built, and problems such as low data traceability efficiency and data redundancy in the existing technology are solved, and efficient and accurate data operation history traceability and data security improvement are achieved.

CN120217330APending Publication Date: 2025-06-27NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510235046.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

When existing data security traceability and traceability technology processes a large number of associated data, the performance bottleneck of relational databases leads to low traceability efficiency, while document databases have shortcomings such as data redundancy, query restrictions, and security issues.

Method used

Using the data security tracking and traceability method based on the graph database, we use the graphical relationship network of data, record data operation information, and add nodes and relationships to the graph database to achieve efficient and accurate data operation history traceability.

Benefits of technology

It improves data security and problem traceability capabilities, simplifies the query process, improves query efficiency, and reduces time and resource consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217330A_ABST
    Figure CN120217330A_ABST
Patent Text Reader

Abstract

The invention discloses a data security tracing method and system based on a graph database, and relates to a data security tracing technology, and the method comprises the steps: defining related nodes and relationships in the graph database in advance; and under the condition that data operation occurs to the data to be traced, recording operation information, and adding the recorded operation information as a new node and relationship to the graph database so as to realize data traceability of the data to be traced according to the tracked data operation history. According to the method, efficient and accurate data operation history tracing is realized by constructing the graphical relationship network of the data, so that the data security and the problem tracing capability are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to data security traceability technology, and in particular to a data security tracking and tracing method and system based on a graph database. Background Art

[0002] With the rapid development of information technology, data has become an important asset in modern society. However, with the explosion of data volume and the increase in data complexity, data security issues have become increasingly prominent. To ensure the security and integrity of data, tracing the source and flow of data has become an important issue. Existing data security tracking and tracing mainly realizes the visualization chain presentation of the entire life cycle by comprehensively analyzing data transfer log records. The relevant analysis methods mainly include the following:

[0003] 1) Data security tracking and tracing technology based on relational databases. The data security tracking and tracing technology based on relational databases stores data association relationships in relational databases. Relational databases adopt a two-dimensional table data model, and the processing efficiency for multi-dimensional data is relatively low. In the process of data security traceability, a large amount of associated data often needs to be processed. Relational databases may face performance bottlenecks when processing such data, and there is a disadvantage of low traceability efficiency.

[0004] 2) Data security tracking and tracing technology based on document databases. The data security tracking and tracing technology based on document databases stores data association relationships in document databases. Although document databases have advantages such as high flexibility and easy expansion, they also have disadvantages such as data redundancy, query limitations, weak data constraints, cross-document query limitations, security issues, traceability technology limitations, and performance issues. Summary of the Invention

[0005] The embodiments of this application provide a data security tracking and tracing method and system based on a graph database, which realizes efficient and accurate tracing of the data operation history by constructing a graphical relationship network of data, thereby enhancing data security and problem tracing capabilities.

[0006] The embodiments of this application provide a data security tracking and tracing method based on a graph database, including:

[0007] Define relevant nodes and relationships in the graph database in advance;

[0008] In the case where data operations occur on the data to be traced, record the operation information, and add the recorded operation information as new nodes and relationships to the graph database to realize data traceability of the data to be traced according to the traced data operation history.

[0009] Optionally, defining relevant nodes and relationships in the graph database in advance includes:

[0010] According to the data type, personnel, equipment, and data assets are used as nodes in the graph database, and node attributes are configured;

[0011] Based on the association relationships existing among personnel, equipment, and data assets, edges are constructed on the corresponding nodes, and edge attributes are configured.

[0012] Optionally, the configured node attributes include:

[0013] Personnel attributes: person's name, personnel classification, personnel number;

[0014] Equipment attributes: equipment IP, equipment level, equipment type, equipment status, equipment physical location;

[0015] Data asset attributes: asset fingerprint, asset meta-information, asset classification information, asset categorization information.

[0016] Optionally, based on the association relationships existing among personnel, equipment, and data assets, edges are constructed on the corresponding nodes, and the configured edge attributes include:

[0017] The personnel-equipment association information is used as an edge, and the edge attributes include: the most recent usage time;

[0018] The equipment and the data asset are used as an edge through the subordination relationship, and the edge attributes include: the creation time;

[0019] The asset and the data asset are used as an edge through similarity, and the edge attributes include: the similarity percentage;

[0020] Between the personnel and the data asset, the operation log is used as an edge, and the table attributes include: the operation time, the operation type;

[0021] Between the equipment and the data asset, the operation log is used as an edge, and the edge attributes include: the operation time, the operation type.

[0022] Optionally, in the case where data operations occur on the data to be traced, operation information is recorded, and the recorded operation information is added as new nodes and relationships to the graph database, including:

[0023] Through the personnel attributes, query in the graph database to obtain the attribution of the complete personnel, the operations on the data, and the relationships of similar data;

[0024] Through the equipment attributes, query in the graph database to obtain the operator corresponding to the equipment, the data information of the operation, and the operation log information;

[0025] Through the data asset attributes, query in the graph database to obtain the equipment where the asset is located, similar data, the equipment where the similar data is located, and the operation log of the data.

[0026] Optionally, in the case where data operations occur on the data to be traced, recording operation information and adding the recorded operation information as new nodes and relationships to the graph database includes:

[0027] Obtaining the data information of the data to be traced, creating personnel nodes, device nodes, data asset nodes according to the relevant definitions of the graph database, establishing the relationship between personnel and devices, and establishing the relationship between devices and data assets;

[0028] Performing similarity calculation on the data assets of the data to be traced, and establishing the relationship between data assets according to the relevant definitions of the graph database;

[0029] Obtaining the data asset operation behavior logs generated in the controlled environment of the data to be traced, and establishing the relationship between personnel and data assets, and establishing the relationship between devices and data assets according to the relevant definitions of the graph database.

[0030] Optionally, in the case where data operations occur on the data to be traced, recording operation information and adding the recorded operation information as new nodes and relationships to the graph database further includes:

[0031] For the data to be traced, querying in the established graph database through personnel attributes to obtain relevant device nodes, relevant data asset nodes, operation data asset nodes, similar data asset nodes, and similar relationships;

[0032] For the data to be traced, querying in the established graph database through device attributes to obtain the affiliated personnel nodes, relevant data asset nodes, operation data asset nodes, asset transfer device nodes, asset transfer device relationships, and similar data asset nodes;

[0033] For the data to be traced, querying in the established graph database through data asset attributes to obtain the affiliated personnel nodes, affiliated device nodes, operation device nodes, operator nodes, and similar asset data nodes.

[0034] The embodiment of the present application also proposes a data security tracking and tracing system based on a graph database, including a processor and a memory, where a computer program is stored on the memory, and when the computer program is executed by the processor, the steps of the data security tracking and tracing method based on the graph database as described above are implemented.

[0035] The embodiment of the present application realizes efficient and accurate tracing of data operation history by constructing a graphical relationship network of data, thereby enhancing data security and problem tracing ability.

[0036] The above description is only an overview of the technical solution of the present application. In order to better understand the technical means of the present application, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the specific embodiments of the present application are specifically given below. Brief Description of the Drawings

[0037] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present application. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0038] Figure 1 It is a schematic diagram of the traceability architecture of the data security traceability method based on the graph database of the present application. Detailed Embodiments

[0039] Hereinafter, exemplary embodiments of the present disclosure will be described in more detail with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.

[0040] In the process of traceability of traditional relational databases, due to reasons such as scattered data distribution and complex table structures, multi-table joins are required for queries, which affects query efficiency. In the process of traceability of traditional relational databases, due to decentralized storage, the main body and relationships are stored in separate tables, and the data is fragmented. Multiple tables need to be constructed and complex query statements need to be written, increasing the query cost and consuming a large amount of time and space resources. The embodiments of the present application provide a data security traceability method based on a graph database, including the following steps:

[0041] In step S101, relevant nodes and relationships are predefined in the graph database;

[0042] In step S102, when a data operation occurs on the data to be traced, the operation information is recorded, and the recorded operation information is added to the graph database as new nodes and relationships, so as to realize the data traceability of the data to be traced according to the traced data operation history. In a specific example, when a data operation occurs, the operation information is recorded, including the operation type, operation time, operation object, etc., and this information is added to the graph database as new nodes and relationships. According to the traced data operation history, the source, flow and usage of the data are traced backwards.

[0043] Embodiments of the present application realize efficient and accurate traceability of data operation history by constructing a graphical relationship network of data, thereby enhancing data security and the ability to trace problems.

[0044] In some embodiments, the predefined relevant nodes and relationships in the graph database include:

[0045] According to the data type, personnel, devices, and data assets are used as nodes in the graph database, and node attributes are configured;

[0046] According to the association relationships existing among personnel, devices, and data assets, edges are constructed on the corresponding nodes, and edge attributes are configured.

[0047] In a specific example, configuring node attributes includes:

[0048] Personnel attributes: personnel name, personnel classification, personnel number;

[0049] Device attributes: device IP, device level, device type, device status, device physical location;

[0050] Data asset attributes: asset fingerprint, asset meta-information, asset classification information, asset categorization information.

[0051] In some embodiments, according to the association relationships existing among personnel, devices, and data assets, edges are constructed on the corresponding nodes, and configuring edge attributes includes:

[0052] Taking the personnel-device association information as an edge, and the edge attributes include: most recent use time;

[0053] Devices and data assets are connected by a subordination relationship as an edge, and the edge attributes include: creation time;

[0054] Assets and data assets are connected by similarity as an edge, and the edge attributes include: similarity percentage;

[0055] Between personnel and data assets, an operation log is used as an edge, and the table attributes include: operation time, operation type;

[0056] Between devices and data assets, an operation log is used as an edge, and the edge attributes include: operation time, operation type.

[0057] In some embodiments, in the case where data operation occurs on the data to be traced, operation information is recorded, and the recorded operation information is added as new nodes and relationships to the graph database, including:

[0058] Through personnel attributes, query is performed in the graph database to obtain the affiliation of the complete personnel, operations on data, and relationships of similar data;

[0059] Query in the graph database through device attributes to obtain the operator corresponding to the device, the data information operated on, and the operation log information.

[0060] Query in the graph database through data asset attributes to obtain the device where the asset is located, similar data, the device where the similar data is located, and the operation log of the data.

[0061] In some embodiments, in the case where data operations occur on the data to be traced, record the operation information, and add the recorded operation information as new nodes and relationships to the graph database, including:

[0062] Obtain the data information of the data to be traced, and according to the relevant definitions of the graph database, create person nodes, device nodes, data asset nodes, establish the relationship between persons and devices, and establish the relationship between devices and data assets;

[0063] Perform a similarity calculation on the data assets of the data to be traced, and according to the relevant definitions of the graph database, establish the relationship between data assets;

[0064] Obtain the operation behavior log of the data assets generated in the controlled environment of the data to be traced, and according to the relevant definitions of the graph database, establish the relationship between persons and data assets, and establish the relationship between devices and data assets.

[0065] In some embodiments, in the case where data operations occur on the data to be traced, record the operation information, and adding the recorded operation information as new nodes and relationships to the graph database further includes:

[0066] For the data to be traced, query in the established graph database through person attributes to obtain relevant device nodes, relevant data asset nodes, operation data asset nodes, similar data asset nodes, and similar relationships;

[0067] For the data to be traced, query in the established graph database through device attributes to obtain the person nodes to which it belongs, relevant data asset nodes, operation data asset nodes, asset transfer device nodes, asset transfer device relationships, and similar data asset nodes;

[0068] For the data to be traced, query in the established graph database through data asset attributes to obtain the person nodes to which it belongs, the device nodes to which it belongs, operation device nodes, operator nodes, and similar asset data nodes.

[0069] The method of the present application uses a graph database to construct a relationship network between data, which can more intuitively display the association between data, thereby improving the efficiency of tracking data operation history (such as data update, insertion, deletion, etc.). The nodes and edges in the graph database can represent different data entities and the relationships between them, making the data tracing process more intuitive and accurate.

[0070] Traditional relational databases have poor performance when processing highly correlated and fragmented data. They need to build multiple tables and write complex query statements, which consumes a lot of time and resources. The graph database-based tracking and tracing technology of this application can display the relationship between data in a graphical way, simplify the query process, and improve query efficiency.

[0071] This application can significantly improve query efficiency and reduce query time by decomposing and optimizing the query method of the graph database and combining it with the joint query technology of multiple platforms. This is of great significance for the tracing and source tracking of large-scale data and can greatly improve the efficiency of data processing and analysis.

[0072] An embodiment of the present application also proposes a data security tracking and tracing system based on a graph database, including a processor and a memory, wherein a computer program is stored on the memory, and when the computer program is executed by the processor, the steps of the data security tracking and tracing method based on the graph database as described above are implemented.

[0073] It should be noted that in the various embodiments of the present application, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "includes a ..." does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0074] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0075] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described example methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present application.

[0076] The embodiments of the present application have been described above in conjunction with the accompanying drawings. However, the present application is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present application, those of ordinary skill in the art can also make many forms without departing from the purpose of the present application and the scope protected by the claims. All of these are within the protection scope of the present application.

Claims

1. A data security tracing method based on a graph database, characterized in that: include: Predefine the relevant nodes and relationships in the graph database; When data operations occur on the data to be traced, the operation information is recorded and added to the graph database as new nodes and relationships, so as to achieve data tracing of the data to be traced based on the tracked data operation history.

2. The data security tracking and tracing method based on the graph database according to claim 1 is characterized in that: The relevant nodes and relationships pre-defined in the graph database include: According to the data type, personnel, equipment, and data assets are used as nodes of the graph database, and node properties are configured; According to the relationship between personnel, equipment, and data assets, edges are built at corresponding nodes and edge attributes are configured.

3. The data security tracking and tracing method based on the graph database according to claim 2 is characterized in that: Configuration node properties include: Personnel attributes: personnel name, personnel grade, personnel number; Device attributes: device IP, device level, device type, device status, device physical location; Data asset attributes: asset fingerprint, asset meta information, asset classification information, and asset classification information.

4. The data security tracking and tracing method based on the graph database according to claim 3 is characterized in that: According to the relationship between personnel, equipment, and data assets, edges are built at corresponding nodes, and edge attributes are configured, including: The personnel-equipment association information is used as the edge, and the edge attributes include: the most recent use time; Devices and data assets are used as edges through subordinate relationships, and edge attributes include: creation time; Assets and data assets are represented by similarity as edges, and edge attributes include: similarity percentage; The operation log is used as an edge between personnel and data assets. The table attributes include: operation time and operation type; The operation logs are used as edges between devices and data assets, and the edge attributes include: operation time and operation type.

5. The data security tracking and tracing method based on the graph database according to claim 4 is characterized in that: When data operation occurs on the data to be traced, recording the operation information and adding the recorded operation information as new nodes and relationships to the graph database includes: Query the graph database through personnel attributes to obtain complete personnel attributes, data operations, and relationships between similar data; Through device attributes, query the graph database to obtain the corresponding operator of the device, operation data information, and operation log information; Through the data asset attributes, queries are performed in the graph database to obtain the device where the asset is located, similar data, the device where similar data is located, and the operation log of the data.

6. The data security tracking and tracing method based on the graph database according to claim 5 is characterized in that: When data operation occurs on the data to be traced, recording the operation information and adding the recorded operation information as new nodes and relationships to the graph database includes: Obtain the data information of the data to be traced, create personnel nodes, equipment nodes, data asset nodes according to the relevant definitions of the graph database, establish the relationship between personnel and equipment, and establish the relationship between equipment and data assets; Calculate the similarity of the data assets of the traceable data and establish the relationship between data assets according to the relevant definitions of the graph database; Obtain the data asset operation behavior logs generated in the controlled environment of the data to be traced, and establish the relationship between personnel and data assets, as well as the relationship between equipment and data assets based on the relevant definitions of the graph database.

7. The data security tracking and tracing method based on the graph database according to claim 6 is characterized in that: In the case where data operation occurs on the data to be traced, recording the operation information, and adding the recorded operation information as new nodes and relationships to the graph database further includes: For traceability data, query the established graph database through personnel attributes to obtain relevant equipment nodes, relevant data asset nodes, operation data asset nodes, similar data asset nodes, and similar relationships; For traceability data, query the established graph database through device attributes to obtain the personnel nodes, related data asset nodes, operation data asset nodes, asset circulation device nodes, asset circulation device relationships, and similar data asset nodes; For traceability data, queries are performed in the established graph database through data asset attributes to obtain the personnel node, equipment node, operating equipment node, operator node, and similar asset data node.

8. A data security tracking and tracing system based on a graph database, characterized in that: It includes a processor and a memory, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the steps of the data security tracking and tracing method based on the graph database as described in any one of claims 1 to 7 are implemented.