Government affair data security management system of e-government affair platform
Through edge computing, blockchain and other technical means, an e-government platform's government data security management system has been built, which solves the shortcomings in the security, sharing and management efficiency of government data, and realizes the full life cycle protection and efficient management of government data.
Patent Information
- Application Number
- CN202510277133.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-06-27
AI Technical Summary
The existing e-government platform has shortcomings in terms of security, sharing and management efficiency of government data, and faces problems such as data leakage, tampering, imperfect access rights management and insufficient data transmission security.
Through the comprehensive use of technical means such as edge computing, blockchain, encrypted storage, and access control, a government data security management system is built to achieve the full life cycle protection of data. Specifically, it includes modules such as data collection and integration, blockchain network, data encryption, access control, log audit, data backup and recovery, and data transmission security.
It realizes the full life cycle protection of government data, improves data security, sharing and management efficiency, and effectively responds to various challenges in data security management in e-government platforms.
Smart Images

Figure CN120217409A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of government data security management, and particularly to a government data security management system for an e-government platform. Background Art
[0002] With the rapid development of information technology, e-government platforms have become important tools for government departments to improve administrative efficiency and optimize public services. However, the security issues of government data have become increasingly prominent, mainly reflected in the following aspects:
[0003] Data leakage risk: Government data involves a large amount of sensitive information, such as citizens' personal information, government internal documents, etc. Once leaked, it will cause serious consequences.
[0004] Data tampering risk: Unauthorized personnel may tamper with government data, resulting in decision-making errors or public service interruptions.
[0005] Insufficient data access permission management: In existing systems, the data access permission management mechanism is not perfect enough, which may lead to unauthorized access or illegal operations.
[0006] Insufficient data transmission security: During the cross-department and cross-platform transmission of government data, there may be risks of data being stolen or tampered with.
[0007] Therefore, designing an efficient and secure government data security management system that can achieve the full life cycle protection of data has become a key requirement in the construction of e-government platforms. Summary of the Invention
[0008] In order to overcome the deficiencies of the prior art, the purpose of the present invention is to provide a government data security management system for an e-government platform, which realizes the full life cycle protection of government data through the comprehensive application of technologies such as edge computing, blockchain, encrypted storage, and access control, and improves data security, sharing, and management efficiency.
[0009] To achieve the above purpose, the present invention provides the following solutions:
[0010] A government data security management system for an e-government platform, comprising:
[0011] A data collection and integration module, which is used to perform real-time data collection, processing, and transmission on each link of the e-government platform by using edge computing to obtain a government data set;
[0012] A blockchain network module for constructing a private blockchain network, uploading and storing the government affairs data set based on the private blockchain network, and developing smart contracts for automatically executing business processes in the private blockchain network to achieve trusted sharing, automated execution, and multi-party collaboration of government affairs data;
[0013] A data encryption module for encrypting and storing the government affairs data set to ensure the security of the government affairs data set in both static and dynamic states;
[0014] An access control module for setting access permissions for the government affairs data set based on role-based access control and fine-grained privilege management methods;
[0015] A log auditing module for recording all data operation behaviors on the government affairs data set and supporting real-time monitoring and post-event tracing;
[0016] A data backup and recovery module for regularly backing up the government affairs data set and supporting recovery in case of data loss or damage;
[0017] A data transmission security module for ensuring the confidentiality and integrity of the government affairs data set during transmission through security protocols.
[0018] Preferably, the data collection and integration module includes:
[0019] A node setting unit for setting each edge computing node in the topology network structure at each link of the e-government platform;
[0020] A decision-making generation unit for periodically obtaining the communication status information of each edge computing node in the topology network structure and the edge computing nodes within a preset distance range around it, and inputting the obtained communication status information into a pre-established node connection decision model to obtain a real-time decision result;
[0021] A topology network generation unit for dynamically adjusting the connection relationships between each edge computing node in the topology network structure and the edge computing nodes within a preset distance range around it in real time based on the real-time decision result to form an adaptive topology network structure;
[0022] A communication module for transmitting data with each edge computing node based on the adaptive topology network structure;
[0023] An edge computing unit for filtering and aggregating the collected data set using the adaptive topology network structure to complete local processing, and uploading key data in the original data set to the cloud and caching it locally to obtain the government affairs data set.
[0024] Preferably, the communication status information includes at least one of signal strength, data transmission rate, packet loss rate, latency, energy consumption, moving speed, and historical connection quality.
[0025] Preferably, the decision-making unit includes:
[0026] A model construction subunit, configured to construct a node connection decision model;
[0027] A node processing subunit, configured to input the periodically obtained communication status information into the node connection decision model and output the real-time decision result; the real-time decision result includes the edge computing nodes that each edge computing node in the topology network structure needs to connect to and the edge computing nodes that need to be disconnected.
[0028] Preferably, the topology network generation unit includes:
[0029] An adjustment subunit, configured to dynamically adjust in real time the connection between each edge computing node in the topology network structure and the edge computing nodes to be connected, and dynamically adjust in real time the disconnection between each edge computing node in the topology network structure and the edge computing nodes to be disconnected, so as to form an adaptive topology network structure; the edge computing nodes to be connected and the edge computing nodes to be disconnected are determined from the edge computing nodes within a preset distance range around each edge computing node.
[0030] Preferably, the data encryption module includes:
[0031] A database encryption unit, configured to encrypt and store the government affairs data set using a symmetric encryption algorithm to ensure the security of the data in the database;
[0032] A data transmission encryption unit, configured to encrypt the transmission key using an asymmetric encryption algorithm during the transmission process of the government affairs data set, and encrypt and transmit the government affairs data set in combination with a symmetric encryption algorithm;
[0033] A key encryption unit, configured to generate a unique encryption key for each data file in the government affairs data set and store the key in a secure key management system.
[0034] Preferably, the access control module includes:
[0035] An access control unit, configured to assign roles to each user; different roles have different permissions;
[0036] A fine-grained permission management unit, configured to refine the user's access permission to the data to the field level or record level;
[0037] A dynamic permission adjustment unit, configured to dynamically adjust permissions according to the user's behavior and context;
[0038] A verification mechanism unit for verifying in real time whether the user's permissions are legal when the user accesses data.
[0039] Preferably, the log audit module includes:
[0040] A data recording unit for recording the operation behaviors of all government affairs data sets; the operation behaviors include the creation, reading, modification, and deletion of data;
[0041] A log acquisition unit for recording the log content of the government affairs data set; the log content includes the operation time, the operating user, the operation type, and the operation data;
[0042] A real-time monitoring unit for detecting abnormal operation behaviors in the log content in real time through big data analysis technology, and providing log query and analysis tools to support post-event traceability and auditing.
[0043] Preferably, the security protocol is the SSL / TLS protocol.
[0044] According to the specific embodiments provided by the present invention, the following technical effects are disclosed by the present invention:
[0045] The present invention provides a government affairs data security management system for an e-government platform, including: a data collection and integration module for using edge computing to perform real-time data collection, processing, and transmission on each link of the e-government platform to obtain a government affairs data set; a blockchain network module for constructing a private blockchain network, and based on the private blockchain network, performing data on-chain and data storage on the government affairs data set, and developing a smart contract for automatically executing business processes in the private blockchain network to complete the trusted sharing, automated execution, and multi-party collaboration of government affairs data; a data encryption module for encrypting and storing the government affairs data set to ensure the security of the government affairs data set in both static and dynamic states; an access control module for setting access permissions for the government affairs data set based on role-based access control and fine-grained permission management methods; a log audit module for recording all data operation behaviors on the government affairs data set, and supporting real-time monitoring and post-event traceability; a data backup and recovery module for regularly backing up the government affairs data set, and supporting recovery in case of data loss or damage; a data transmission security module for ensuring the confidentiality and integrity of the government affairs data set during the transmission process through a security protocol. By comprehensively applying technical means such as edge computing, blockchain, encrypted storage, and access control, the present invention realizes the full life cycle protection of government affairs data, improves data security, sharing, and management efficiency, and can effectively cope with various challenges in data security management of the e-government platform, having significant technical advantages and application value. Description of the Drawings
[0046] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required for use in the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0047] Figure 1 It is a schematic diagram of the system structure provided by the embodiment of the present invention. Specific embodiments
[0048] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0049] The purpose of the present invention is to provide a government affairs data security management system for an e-government platform. Through the comprehensive application of technologies such as edge computing, blockchain, encrypted storage, and access control, the full life cycle protection of government affairs data is achieved, the data security, sharing, and management efficiency are improved, and various challenges in data security management in the e-government platform can be effectively addressed, having significant technical advantages and application values.
[0050] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0051] Figure 1 It is a schematic diagram of the system structure provided by the embodiment of the present invention. As Figure 1 shown, the present invention provides a government affairs data security management system for an e-government platform, including:
[0052] A data collection and integration module, used to perform real-time data collection, processing, and transmission on each link of the e-government platform by using edge computing to obtain a government affairs data set;
[0053] A blockchain network module, used to build a private blockchain network, and based on the private blockchain network, perform data uploading and data storage on the government affairs data set, and develop smart contracts for automatically executing business processes in the private blockchain network to complete the trusted sharing, automated execution, and multi-party collaboration of government affairs data;
[0054] A data encryption module, used to encrypt and store the government affairs data set to ensure the security of the government affairs data set in both static and dynamic states;
[0055] An access control module for setting access permissions for the government affairs data set based on role-based access control and fine-grained permission management methods;
[0056] A log audit module for recording all data operation behaviors on the government affairs data set and supporting real-time monitoring and post-event traceability;
[0057] A data backup and recovery module for regularly backing up the government affairs data set and supporting recovery in case of data loss or damage;
[0058] A data transmission security module for ensuring the confidentiality and integrity of the government affairs data set during transmission through a security protocol.
[0059] Preferably, the data collection and integration module includes:
[0060] A node setting unit for setting each edge computing node in the topological network structure at each link of the e-government platform;
[0061] A decision-making generation unit for periodically obtaining communication status information of each edge computing node in the topological network structure and edge computing nodes within a preset distance range around it, and inputting the obtained communication status information into a pre-established node connection decision model to obtain a real-time decision result;
[0062] A topological network generation unit for dynamically adjusting the connection relationship between each edge computing node in the topological network structure and edge computing nodes within a preset distance range around it in real time based on the real-time decision result to form an adaptive topological network structure;
[0063] A communication module for data transmission with each edge computing node based on the adaptive topological network structure;
[0064] An edge computing unit for filtering and aggregating the collected data set using the adaptive topological network structure to complete local processing, and uploading key data in the original data set to the cloud and caching it locally to obtain the government affairs data set.
[0065] Preferably, the communication status information includes at least one of signal strength, data transmission rate, packet loss rate, latency, energy consumption, moving speed, and historical connection quality.
[0066] Specifically, the specific implementation process of the data collection and integration module in this embodiment includes:
[0067] 1. Node setting and topological network initialization:
[0068] In each link of the e-government platform, edge computing nodes are deployed, and an initial topological network structure is constructed. Each edge computing node is configured as a node in the network according to its physical location and task requirements, forming a data collection network covering the entire government affairs platform. The node setting unit is responsible for recording the basic attributes of each node (such as location, device capabilities, etc.) and initializing the connection relationship with surrounding nodes.
[0069] 2. Communication Status Information Collection and Decision Generation:
[0070] The decision-making unit periodically collects communication status information from each edge computing node in the topological network, including parameters such as signal strength, data transmission rate, packet loss rate, latency, energy consumption, moving speed, and historical connection quality. These parameters are input into a pre-trained node connection decision model, which is based on machine learning or optimization algorithms and generates real-time decision results in combination with the communication status information to determine which nodes need to adjust the connection relationship to optimize network performance.
[0071] 3. Adaptive Topological Network Structure Generation:
[0072] The topological network generation unit dynamically adjusts the connection relationship between edge computing nodes according to the real-time decision results, forming an adaptive topological network structure. This process can ensure that the network still operates efficiently and stably when the communication status changes (such as node movement or signal fluctuation). The adjusted network structure improves data transmission efficiency through optimal path selection and reduces latency and energy consumption.
[0073] 4. Edge Computing and Data Processing:
[0074] Under the adaptive topological network structure, the communication module conducts efficient data transmission with each edge computing node. The edge computing unit filters and aggregates the collected raw data, eliminating redundant information and only retaining valid data. Key data will be uploaded to the cloud for further processing and storage, while other data is cached locally to support quick response. Finally, the processed data forms a government affairs data set, ensuring the real-time, integrity, and efficiency of data collection.
[0075] Preferably, the decision-making unit includes:
[0076] A model construction subunit for constructing a node connection decision model;
[0077] A node processing subunit for inputting the periodically obtained communication status information into the node connection decision model and outputting the real-time decision results; the real-time decision results include the edge computing nodes that each edge computing node in the topological network structure needs to connect to and the edge computing nodes that need to be disconnected.
[0078] Preferably, the topology network generation unit includes:
[0079] An adjustment subunit, configured to dynamically adjust in real time the connection between each edge computing node and the edge computing nodes to be connected in the topology network structure, and dynamically adjust in real time the disconnection between each edge computing node and the edge computing nodes to be disconnected in the topology network structure, so as to form an adaptive topology network structure; the edge computing nodes to be connected and the edge computing nodes to be disconnected are determined from the edge computing nodes within a preset distance range around each edge computing node.
[0080] Specifically, the model construction subunit collects a large amount of historical communication status information (such as signal strength, data transmission rate, packet loss rate, latency, energy consumption, moving speed, and historical connection quality, etc.) and the corresponding optimal connection relationships, and uses machine learning algorithms (such as decision trees, random forests, or deep learning models) to train a node connection decision model. This model can predict the optimal connection scheme for each edge computing node according to the input communication status information, including the nodes to be connected and the nodes to be disconnected, so as to provide a decision basis for dynamically adjusting the topology network. The node processing subunit periodically collects communication status information from each edge computing node in the topology network and inputs this information into the node connection decision model. The model outputs real-time decision results according to the current communication status information, including the edge computing nodes that each edge computing node needs to connect and the edge computing nodes that need to be disconnected. The decision results will give priority to the edge computing nodes within a preset distance range around the node to ensure the local optimization and overall stability of the network. The adjustment subunit dynamically adjusts the topology network structure according to the real-time decision results. Specifically, for the edge computing nodes to be connected, the adjustment subunit realizes the connection by establishing a new communication link; for the edge computing nodes to be disconnected, the adjustment subunit realizes the disconnection by closing the communication link. This process can quickly adjust the network structure when the network state changes (such as node movement or communication quality degradation) to ensure the efficiency and stability of the network. During the adjustment process, the adjustment subunit always takes the edge computing nodes within a preset distance range around the node as the basis to dynamically optimize the connection relationship and avoid the connection of nodes that are too far away resulting in high latency or high energy consumption. By adjusting the connection and disconnection relationships in real time, an adaptive topology network structure is formed, enabling the network to self-optimize according to the actual communication state, improving data transmission efficiency, reducing energy consumption, and ensuring the efficient and reliable cooperation between edge computing nodes.
[0081] Optionally, the specific implementation process of the blockchain network module in this embodiment is as follows:
[0082] 1. Construction of a private blockchain network:
[0083] First, based on the security and privacy requirements of government affairs data, select a suitable blockchain framework (such as Hyperledger Fabric or Quorum) to build a private blockchain network. The private blockchain network consists of multiple nodes, each of which is operated by relevant departments or institutions of the government affairs platform to ensure the distributed storage and management of data. By setting up a permission control mechanism, restrict the access rights of the blockchain network, and only allow authorized nodes to participate in network operations, thus ensuring the security and privacy of government affairs data.
[0084] 2. Data uploading and storage of government affairs data sets:
[0085] After the government affairs data set is generated, the data is uploaded and stored through the blockchain network module. Specifically, the key information of government affairs data (such as metadata, digest information) generates a unique identifier through a hash algorithm and is stored in the blockchain to ensure the immutability and traceability of the data. For large-scale government affairs data sets, an off-chain storage method is adopted to store the complete data in an external database or a distributed storage system (such as IPFS), and record its storage location and verification information in the blockchain to achieve efficient storage combining on-chain and off-chain.
[0086] 3. Development and deployment of smart contracts:
[0087] Develop smart contracts in the private blockchain network for automatically executing government affairs business processes. Smart contracts are pre-defined program codes that contain business rules and logics, such as data sharing approval, cross-departmental collaboration processes, etc. Once deployed to the blockchain network, smart contracts can be automatically executed when the trigger conditions are met without manual intervention, thus improving the efficiency and transparency of business processes. The development of smart contracts needs to combine the requirements of government affairs scenarios to ensure the accuracy and security of their logics.
[0088] 4. Trusted sharing and multi-party collaboration of government affairs data:
[0089] Based on the distributed ledger characteristics of the blockchain, the sharing and collaboration of government affairs data become more trustworthy. Through smart contracts, relevant departments or institutions can automatically obtain the required data under preset conditions without relying on third-party intermediaries, thus realizing efficient multi-party collaboration. At the same time, every data operation in the blockchain network will be recorded on the chain, forming an immutable operation log to ensure the transparency and traceability of the data sharing process, and further enhancing the credibility and security of government affairs data collaboration.
[0090] Preferably, the data encryption module includes:
[0091] A database encryption unit for encrypting and storing the government affairs data set using a symmetric encryption algorithm to ensure the security of the data in the database;
[0092] A data transmission encryption unit, which is used to encrypt the transmission key by using an asymmetric encryption algorithm during the transmission process of the government affairs data set, and encrypt the government affairs data set by combining a symmetric encryption algorithm for encrypted transmission;
[0093] A key encryption unit, which is used to generate a unique encryption key for each data file in the government affairs data set and store the key in a secure key management system.
[0094] Optionally, the specific implementation process of the data encryption module in this embodiment is as follows:
[0095] 1. Implementation of the database encryption unit:
[0096] The database encryption unit encrypts and stores the government affairs data set by using a symmetric encryption algorithm (such as AES). Before writing data into the database, the system encrypts the data by using a preset encryption key to ensure that the data is stored in the database in ciphertext form. When reading data, the system restores the ciphertext to plaintext through a decryption operation for legitimate users to use. The encryption key is uniformly managed by the key management system to avoid the risk of key leakage, thereby ensuring the security of data in a static state.
[0097] 2. Implementation of the data transmission encryption unit:
[0098] During the transmission process of the government affairs data set, the data transmission encryption unit encrypts the transmission key by using an asymmetric encryption algorithm (such as RSA) to ensure the security of the key during the transmission process. Subsequently, it combines a symmetric encryption algorithm (such as AES) to encrypt the actually transmitted data. Specifically, the sending end uses the symmetric encryption algorithm to encrypt the data and encrypts the symmetric key by using the asymmetric encryption algorithm; the receiving end decrypts the key by using the asymmetric encryption algorithm and then decrypts the data by using the decrypted symmetric key, thereby realizing the confidentiality and integrity of the data during the dynamic transmission process.
[0099] 3. Implementation of the key encryption unit:
[0100] The key encryption unit generates a unique encryption key for each government affairs data file to ensure that the encryption keys of different files are different from each other and improve data security. The generated key will be stored in a secure key management system (such as a hardware security module HSM or a cloud key management service KMS-based one), and the key management system supports operations such as key generation, distribution, storage, and destruction. Through strict permission control and access auditing, the security and controllability of the key are ensured, thereby providing reliable key support for the encrypted storage and transmission of the government affairs data set.
[0101] Preferably, the access control module includes:
[0102] An access control unit for assigning roles to each user; different roles have different permissions;
[0103] A fine-grained permission management unit for refining a user's access permission to data to the field level or record level;
[0104] A dynamic permission adjustment unit for dynamically adjusting permissions according to a user's behavior and context;
[0105] An authentication mechanism unit for verifying in real time whether a user's permission is legal when the user accesses data.
[0106] Specifically, the specific implementation process of the access control module in this embodiment is as follows:
[0107] 1. Implementation of the access control unit:
[0108] The access control unit adopts the role-based access control (RBAC) method to assign roles to each user, and different roles correspond to different permission sets. For example, system administrators, department heads, and ordinary users have different access permissions respectively. After a user logs in to the system, the system automatically loads the corresponding permission set according to their role, ensuring that the user can only access data and functions related to their role. The definition of roles and the assignment of permissions are uniformly managed by the system administrator, supporting flexible configuration and expansion.
[0109] 2. Implementation of the fine-grained permission management unit:
[0110] The fine-grained permission management unit refines a user's access permission to data to the field level or record level. For example, a certain user can access some fields (such as name and department) in the government affairs dataset, but cannot access sensitive fields (such as ID number or salary information); or a certain user can only view records related to their department and cannot access data from other departments. By introducing a permission filtering mechanism at the database query level, the system dynamically generates query conditions according to the user's permission configuration, ensuring that the user can only access the authorized data range.
[0111] 3. Implementation of the dynamic permission adjustment unit:
[0112] The dynamic permission adjustment unit dynamically adjusts permissions according to a user's behavior and context (such as time, location, device, etc.). For example, when a user attempts to log in from an unauthorized device or an abnormal location, the system can restrict their access to sensitive data or require additional authentication (such as multi-factor authentication). Dynamic permission adjustment combines artificial intelligence technology to analyze the user's behavior pattern, identify abnormal behaviors, and adjust permissions in real time, further enhancing the security and flexibility of the system.
[0113] 4. Implementation of the authentication mechanism unit:
[0114] When the user accesses data, the verification mechanism unit verifies in real time whether the user's permissions are legal. Specifically, when the user initiates a data access request, the system checks whether the user has the permission to access the target data according to the user's role, fine-grained permission configuration, and dynamic permission adjustment results. If the verification passes, the system allows access; otherwise, access is denied and the relevant operation logs are recorded. Through real-time permission verification, the verification mechanism ensures the compliance and security of data access, and provides an audit basis for abnormal operations at the same time.
[0115] Preferably, the log audit module includes:
[0116] A data recording unit for recording the operation behaviors of all government affairs data sets; the operation behaviors include the creation, reading, modification, and deletion of data; exemplarily, the data recording unit is responsible for capturing and recording all operation behaviors of government affairs data sets, including the creation, reading, modification, and deletion of data. Each time a user operates, the system automatically triggers the log recording function and encapsulates the operation behavior into a standardized log entry. The log entry contains the basic information of the operation (such as the operation type, operation target) and detailed information (such as the data values before and after modification). These log data are stored in a dedicated log database, and technologies that cannot be tampered with (such as blockchain or digital signature) are used to ensure the authenticity and integrity of the logs.
[0117] A log acquisition unit for recording the log content of the government affairs data set; the log content includes the operation time, the operating user, the operation type, and the operation data; specifically, while recording the operation behavior, the log acquisition unit details the log content, including information such as the operation time, the operating user, the operation type, and the operation data. Each log content will be bound to the identity information of the operating user, and the specific time and target data of the operation will be marked. Through a unified log format and indexing mechanism, the system can quickly retrieve and extract the operation logs of a specified time period, user, or data, providing efficient support for retrospective and audit after the event.
[0118] A real-time monitoring unit for detecting abnormal operation behaviors in the log content in real time through big data analysis technology, and providing log query and analysis tools to support retrospective and audit after the event. Optionally, the real-time monitoring unit uses big data analysis technology and anomaly detection algorithms to perform real-time analysis on the operation behaviors in the log content, and identify potential abnormal operation behaviors (such as frequently reading sensitive data or unauthorized users attempting to access). When an abnormal behavior is detected, the system will trigger an alarm and mark the abnormal log as high priority for the administrator to review. In addition, the system provides log query and analysis tools, supports multi-dimensional queries by user, time, operation type, etc., and generates a visual audit report to help the administrator quickly locate problems and take corresponding measures.
[0119] Furthermore, the data backup and recovery module in this embodiment performs full backups and incremental backups on the government affairs data set through a regular backup mechanism. The full backup regularly copies the entire government affairs data set to a secure backup storage system (such as a local storage device or a cloud storage service), while the incremental backup only records the data that has changed since the last backup, reducing storage space occupancy and backup time. The backup data is stored in an encrypted manner (such as AES encryption) to ensure the security of the backup files. At the same time, the data disaster tolerance ability is enhanced through multi-copy storage and off-site backup strategies. In case of data loss or damage, the system quickly restores the government affairs data set through a data recovery mechanism. During the recovery process, the backup files are loaded in sequence according to the backup type (full backup or incremental backup), and the integrity and consistency of the restored data are ensured through a verification mechanism (such as hash verification). The system supports the point-in-time recovery function, and the administrator can select the backup data at a specific time point for recovery to ensure that the business system can quickly resume normal operation and reduce business interruptions caused by data loss.
[0120] Preferably, the security protocol is the SSL / TLS protocol.
[0121] Optionally, the data transmission security module in this embodiment guarantees the confidentiality and integrity of the government affairs data set during the transmission process through the SSL / TLS protocol. Before data transmission, the client and the server perform mutual authentication through the SSL / TLS protocol to establish an encrypted communication channel. During the transmission process, the data is encrypted by a symmetric encryption algorithm (such as AES) to ensure that the data content cannot be eavesdropped or tampered with. At the same time, the message integrity verification function (such as HMAC) of the SSL / TLS protocol can detect and prevent data from being tampered with during the transmission process, ensuring the security and reliability of data transmission.
[0122] The beneficial effects of the present invention are as follows:
[0123] (1) The present invention utilizes edge computing technology to realize real-time data collection, processing, and transmission of each link in the e-government platform in the data collection and integration module, which can significantly improve the efficiency and accuracy of data collection, reduce data latency, and meet the requirements of government affairs scenarios for real-time and high efficiency.
[0124] (2) The present invention constructs a private blockchain network through the blockchain network module, stores the government affairs data set on the chain, and ensures the immutability and traceability of the data. At the same time, based on smart contracts, it realizes the execution of automated business processes and multi-party collaboration, improves the credibility and efficiency of government affairs data sharing, and solves the trust problem in cross-departmental collaboration.
[0125] (3) The data encryption module of the present invention ensures the effective protection of data during both static storage and dynamic transmission by encrypting and storing government affairs data sets, preventing data leakage or unauthorized access, and enhancing data security.
[0126] (4) The access control module of the present invention adopts role-based access control (RBAC) and fine-grained permission management methods, which can flexibly set the access permissions of different users or roles, prevent unauthorized operations, and ensure the compliance and security of data access.
[0127] (5) The log auditing module of the present invention records all data operation behaviors on government affairs data sets. Combining with the real-time monitoring function, it can promptly detect abnormal operation behaviors, provide basis for retrospective and auditing after the event, and effectively respond to security incidents such as data leakage or tampering.
[0128] (6) The data backup and recovery module of the present invention ensures rapid recovery in case of data loss or damage by regularly backing up government affairs data sets, guaranteeing the high availability of data and the disaster tolerance ability of the system, and avoiding business interruption caused by data loss.
[0129] (7) The data transmission security module of the present invention ensures the confidentiality and integrity of government affairs data sets during transmission by adopting security protocols (such as SSL / TLS), preventing data from being stolen or tampered with during transmission.
[0130] (8) By combining multiple technical means such as blockchain technology, smart contracts, edge computing, and fine-grained permission management, the present invention not only enhances data security, but also improves the automation and intelligence levels of government affairs data management, reducing the risk of manual intervention.
[0131] (9) The system of the present invention supports the trustworthy sharing and collaboration of government affairs data across departments and platforms, solves the problems of data islands and low collaboration efficiency in traditional government affairs systems, and provides technical support for the efficient operation of e-government platforms.
[0132] (10) Through the immutability of blockchain technology and the full-process recording of the log auditing module, the present invention enhances the transparency and credibility of government affairs data, improving the public's trust and satisfaction with government affairs services.
[0133] In this specification, each embodiment is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other.
[0134] In this article, specific examples are used to illustrate the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A government data security management system for an e-government platform, characterized in that: include: The data collection and integration module is used to use edge computing to collect, process and transmit data in real time at each link of the e-government platform to obtain government data sets; A blockchain network module is used to build a private blockchain network, upload the government data set to the blockchain and store the data based on the private blockchain network, and develop smart contracts that automatically execute business processes in the private blockchain network to achieve trusted sharing, automated execution and multi-party collaboration of government data; A data encryption module, used for encrypting and storing the government data set to ensure the security of the government data set in static and dynamic states; An access control module, used to set access rights to the government data set based on role-based access control and fine-grained authority management methods; The log audit module is used to record all data operations on the government data set and support real-time monitoring and post-event tracing; A data backup and recovery module, used to regularly back up the government data set and support recovery when the data is lost or damaged; The data transmission security module ensures the confidentiality and integrity of the government data set during transmission through security protocols.
2. The government data security management system of the electronic government platform according to claim 1 is characterized in that: The data acquisition and integration module includes: A node setting unit, used to set each edge computing node in the topological network structure at each link of the e-government platform; A decision generating unit is used to periodically obtain the communication status information of each edge computing node in the topological network structure and the edge computing nodes within a preset distance range around it, and input the obtained communication status information into a pre-established node connection decision model to obtain a real-time decision result; A topology network generation unit, configured to dynamically adjust the connection relationship between each edge computing node in the topology network structure and the surrounding edge computing nodes within a preset distance range in real time based on the real-time decision result, so as to form an adaptive topology network structure; A communication module, used for data transmission with each edge computing node based on an adaptive topology network structure; The edge computing unit is used to use the adaptive topology network structure to filter and aggregate the collected data set, complete local processing, and upload key data in the original data set to the cloud and cache it locally to obtain the government data set.
3. The government data security management system of the electronic government platform according to claim 2 is characterized in that: The communication status information includes at least one of signal strength, data transmission rate, packet loss rate, delay, energy consumption, moving speed and historical connection quality.
4. The government data security management system of the electronic government platform according to claim 3 is characterized in that: The decision making unit comprises: A model building subunit, used to build a node connection decision model; The node processing subunit is used to input the communication status information periodically obtained into the node connection decision model and output the real-time decision result; the real-time decision result includes the edge computing nodes that each edge computing node in the topological network structure needs to connect to and the edge computing nodes that need to be disconnected.
5. The government data security management system of the electronic government platform according to claim 4 is characterized in that: The topology network generating unit comprises: The regulating subunit is used to dynamically adjust the connection between each edge computing node in the topological network structure and the edge computing nodes that need to be connected, and to dynamically adjust the disconnection between each edge computing node in the topological network structure and the edge computing nodes that need to be disconnected, so as to form an adaptive topological network structure; the edge computing nodes that need to be connected and the edge computing nodes that need to be disconnected are determined from the edge computing nodes within a preset distance range around each edge computing node.
6. The government data security management system of the electronic government platform according to claim 1 is characterized in that: The data encryption module comprises: A database encryption unit, used to encrypt and store the government data set using a symmetric encryption algorithm to ensure the security of the data in the database; A data transmission encryption unit, used to encrypt the transmission key using an asymmetric encryption algorithm during the transmission of the government data set, and to encrypt and transmit the government data set in combination with a symmetric encryption algorithm; The key encryption unit is used to generate a unique encryption key for each data file in the government data set and store the key in a secure key management system.
7. The government data security management system of the electronic government platform according to claim 1 is characterized in that: The access control module comprises: Access control unit, used to assign roles to each user; different roles have different permissions; Fine-grained permission management unit, used to refine user access rights to data to the field level or record level; Dynamic permission adjustment unit, used to dynamically adjust permissions based on user behavior and context; The verification mechanism unit is used to verify in real time whether the user's authority is legal when the user accesses data.
8. The government data security management system of the electronic government platform according to claim 1 is characterized in that: The log audit module includes: A data recording unit is used to record the operation behaviors of all government data sets; the operation behaviors include creation, reading, modification and deletion of data; A log acquisition unit, used to record the log content of the government data set; the log content includes operation time, operation user, operation type and operation data; The real-time monitoring unit is used to detect abnormal operation behaviors in the log content in real time through big data analysis technology, and provide log query and analysis tools to support post-event tracing and auditing.
9. The government data security management system of the electronic government platform according to claim 1, characterized in that: The security protocol is the SSL / TLS protocol.
Citation Information
Cited By
Government affair platform security control method and device based on computer and medium
CN121391190A
A computer-based government affair platform security management and control method, device and medium
CN121391190B
Salary payment system and method based on data security management
CN121746104A