User database information leakage protection system and equipment based on big data
By acquiring and analyzing the importance of the data to be transmitted in the user database and the key historical update status, dynamically adjusting the key update time, solving the problem of periodic risk of key updates in the prior art, and improving information security.
Patent Information
- Application Number
- CN202510669408.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2045-05-23
AI Technical Summary
In the prior art, the key update time point is based on a set time period, and there is a risk of eavesdropping and cracking, resulting in poor security of user database information.
The data to be transmitted is obtained through the data acquisition module. The importance analysis module determines the importance of the data, and calculates the necessity of key update based on the key history update moment, and performs key updates when the necessity is greater than the threshold.
It avoids the risk of eavesdropping and cracking of key updates under set time periods, and improves information security.
Smart Images

Figure CN120223434B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a user database information leakage protection system and equipment based on big data. Background Art
[0002] Currently, data encryption transmission is used to protect the information security of user databases. During the data encryption transmission process, the key is often updated to ensure the security and reliability of data transmission.
[0003] However, currently, the time point for updating the key is often selected based on a set time period. The set period has the risk of being eavesdropped and cracked, which increases the risk factor of the user database during data transmission and poor information security. Summary of the Invention
[0004] The embodiments of the present invention provide a user database information anti-leakage protection system and device based on big data, which can improve information security.
[0005] According to a first aspect of an embodiment of the present invention, a user database information leakage protection device based on big data is provided, comprising:
[0006] Data acquisition module, used to obtain the current data to be transmitted;
[0007] The importance analysis module is used to determine the data importance of the data to be transmitted according to the current data type of the data to be transmitted;
[0008] Necessity analysis module, used to determine the necessity of key update for the current data to be transmitted based on the importance of the data and the historical update time of each key;
[0009] The key updating module is used to update the key of the data to be transmitted when the key updating necessity is greater than a preset necessity threshold.
[0010] In some possible implementations, the importance analysis module specifically includes the following units:
[0011] A first type importance determination unit is configured to determine a target type importance corresponding to a current data type of the data to be transmitted based on a target matching relationship, wherein the target matching relationship is used to characterize a matching relationship between various data types and corresponding type importances;
[0012] an element acquisition unit, configured to acquire a first transmission data volume of the current data to be transmitted, and a type difference between the current data to be transmitted and the first historical transmission data within the corresponding historical time window, the type difference being used to characterize the difference between the current data type and the first historical data type of the first historical transmission data within the historical time window;
[0013] The data importance determination unit is used to determine the data importance of the current data to be transmitted by using the target type importance, the first transmission data volume and the type difference.
[0014] In some possible implementations, the importance analysis module further includes the following units:
[0015] A data acquisition unit, configured to acquire second historical transmission data within a target historical time period;
[0016] A second type importance determination unit is configured to determine the type importance corresponding to the second historical data type of each batch of second historical transmission data based on the second historical transmission data within the target historical time period;
[0017] The relationship generating unit is used to generate a target matching relationship based on the type importance corresponding to each second historical data type.
[0018] In some possible implementations, the second-type importance determination unit specifically includes the following subunits:
[0019] a transmission performance determination subunit, configured to determine the transmission performance of each second historical data type according to the start transmission time and the end transmission time of each batch of second historical transmission data within the target historical time period;
[0020] The type importance determination sub-unit is used to perform, for each second historical data type, respectively: determine the type importance of the target historical data type based on the transmission performance of the target historical data type, and the single transmission duration and second transmission data volume of the target second historical transmission data, the target historical data type is any second historical data type, and the target second historical transmission data is each batch of second historical transmission data corresponding to the target historical data type.
[0021] In some possible implementations, the transmission performance determination subunit is specifically configured to:
[0022] Determine the total data transmission duration of the target historical data type and the transmission interval duration between adjacent target second historical transmission data according to the start transmission time and the end transmission time of each batch of second historical transmission data within the target historical time period;
[0023] The transmission performance of the target historical data type is determined by using the total data transmission duration of the target historical data type, the transmission interval durations between adjacent target second historical transmission data, and the total historical duration of the target historical time period.
[0024] In some possible implementations, the type importance determination subunit is specifically configured to:
[0025] Determining a call frequency of the target historical data type according to a single transmission duration of the target second historical transmission data and a second transmission data volume;
[0026] The type importance of the target historical data type is determined by using the transmission performance and call frequency of the target historical data type.
[0027] In some possible implementations, the necessity analysis module specifically includes the following units:
[0028] An interval duration determination unit, configured to determine an average interval duration for key updates based on each key historical update moment;
[0029] The necessity determination unit is used to determine the necessity of key update for the current data to be transmitted based on the data importance, the current interval duration of the current data to be transmitted and the average interval duration, where the current interval duration is the interval duration between the current moment and the moment when the key was last updated.
[0030] In some possible implementations, the interval duration determining unit is specifically configured to:
[0031] For each key update time period, respectively performing: determining a duration weight of the key update time period based on the third transmission data volume within the key update time period and the type importance of each data type within the key update time period, where the key update time period is a time period between adjacent key historical update moments;
[0032] The average interval duration of key updates is determined by using the time period duration of each key update time period and the corresponding time period weight.
[0033] In some possible implementations, the necessity determination unit is specifically configured to:
[0034] Determine the necessity weight of the data to be transmitted according to the relationship between the current interval duration of the data to be transmitted and the average interval duration;
[0035] The necessity of rekeying the data to be transmitted is determined by using the data importance, necessity weight, and the proportion of abnormal data between the current time and the time of the last key update.
[0036] A second aspect of an embodiment of the present invention provides a user database information leakage protection system based on big data, comprising:
[0037] Data encryption subsystem, used to encrypt the data to be transmitted in the user database;
[0038] Behavior detection subsystem, used to detect the health and abnormality of data transmission behavior in the user database;
[0039] The authority control subsystem is used to manage the access rights to the data to be transmitted in the user database;
[0040] The user database information anti-leakage protection device based on big data provided by any of the above aspects communicates with the data encryption subsystem, the behavior detection subsystem and the authority control subsystem respectively.
[0041] The beneficial effects of the present invention are as follows:
[0042] In the user database information leakage protection device based on big data provided by an embodiment of the present invention, the data importance of the data to be transmitted is analyzed according to the current data type of the data to be transmitted. Then, the necessity of updating the key of the data to be transmitted is determined according to the transmission importance of the data to be transmitted and each historical key update moment. In the case where the necessity of key update is greater than the preset necessity threshold, the key of the data to be transmitted is updated. In this way, the present invention determines the transmission importance of the data to be transmitted according to the current data type of the data to be transmitted, and analyzes the necessity of key update at the current moment in combination with the interval length of key update under historical circumstances, thereby determining whether to update the key according to the necessity of key update. In this way, the risk of eavesdropping and the risk of cracking when updating the key within a set time period can be avoided, thereby improving information security. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the technical solutions and advantages of the embodiments of the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0044] Figure 1 A schematic diagram of the structure of a user database information anti-leakage protection device based on big data provided by one embodiment of the present invention;
[0045] Figure 2 A schematic diagram of the structure of a necessity analysis module provided by one embodiment of the present invention;
[0046] Figure 3 A schematic diagram of the structure of a user database information anti-leakage protection system based on big data provided by one embodiment of the present invention. DETAILED DESCRIPTION
[0047] To further illustrate the technical means and effectiveness of the present invention to achieve its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, describes in detail the specific implementation, structure, features, and effectiveness of a user database information leakage protection system and device based on big data proposed by the present invention. In the following description, different references to "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics of one or more embodiments may be combined in any suitable manner.
[0048] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.
[0049] It should be noted that the acquisition, storage, use, and processing of data in the technical solution of the present invention comply with the relevant provisions of laws and regulations.
[0050] Current mainstream solutions focus on building a data protection barrier through encrypted transmission. Key management, a critical component of this system, has a direct impact on its effectiveness through its update mechanism. While traditional periodic key update strategies offer ease of implementation, the fixed time window nature of these updates creates a predictable security rhythm. This deterministic model provides attackers with a potential vulnerability: through long-term monitoring and pattern analysis, attackers can launch precise attacks just before key expiration, creating periodic windows of vulnerability within the protection system and significantly increasing the risk of data breaches.
[0051] The purpose of the present invention is to provide a user database information anti-leakage protection system and device based on big data. In the user database information anti-leakage protection device based on big data provided by the embodiment of the present invention, the data importance of the current data to be transmitted is analyzed according to the current data type of the current data to be transmitted. Then, the necessity of key update of the current data to be transmitted is determined according to the transmission importance of the current data to be transmitted and each historical key update time. In the case where the necessity of key update is greater than the preset necessity threshold, the key of the current data to be transmitted is updated. In this way, the present invention determines the transmission importance of the current data to be transmitted according to the current data type of the current data to be transmitted, and analyzes the necessity of key update at the current moment in combination with the interval length of key update under historical circumstances, thereby determining whether to update the key according to the necessity of key update. In this way, the risk of eavesdropping and the risk of cracking when updating the key within a set time period can be avoided, thereby improving information security.
[0052] The following describes a specific embodiment of a user database information anti-leakage protection system and device based on big data provided by an embodiment of the present invention.
[0053] like Figure 1 1 , a schematic diagram of a user database information leakage protection device based on big data is provided. The user database information leakage protection device based on big data 100 includes a data acquisition module 110 , an importance analysis module 120 , a necessity analysis module 130 and a key update module 140 .
[0054] The data acquisition module 110 is used to acquire the data to be transmitted.
[0055] In this embodiment, the data to be transmitted can come from various sources, such as environmental data collected by sensors (such as temperature, humidity, pressure, etc.), business data generated by business systems (such as transaction records, customer information, etc.), file data uploaded by users, etc.
[0056] The data to be transmitted can be acquired in real-time, periodically, or through event-triggered collection. Real-time acquisition: For data with high real-time requirements, such as equipment operating status data in industrial production, the data acquisition module 110 collects data in real time through sensors. Periodically: For periodically generated data, such as daily sales data, the data acquisition module 110 can set a scheduled task to collect data at a specific time. Event-triggered collection: When a specific event occurs, the data acquisition module 110 is triggered to collect data. For example, after a user completes a transaction, the system automatically collects the relevant data of the transaction.
[0057] The data to be transmitted acquired by the data acquisition module 110 is usually first stored in a temporary buffer or data queue, waiting for subsequent processing. The buffer can be a data structure in memory or a temporary table in a database.
[0058] The importance analysis module 120 is configured to determine the data importance of the data to be transmitted according to the current data type of the data to be transmitted.
[0059] In this embodiment, the current data type is used to indicate the type of data to be transmitted. For example, data types may include sensitive data types, general business data types, and non-critical data types. Sensitive data types may include personal identity information (name, ID number, bank card number, etc.), medical data, and core confidential corporate data (business plans, R&D results, etc.). Leakage of this data could cause serious losses to individuals or businesses. General business data types may include ordinary business reports and daily operation records. These data have certain reference value to the business but have a relatively low risk of leakage. Non-critical data types may include temporary data used for testing, or log data with minimal business impact.
[0060] Data importance is used to represent the importance of data. For example, the importance analysis module 120 can pre-set corresponding importance levels based on various data types. For example, the data importance of sensitive data types can be set to 3 (the highest level), the data importance of general business data types to 2, and the data importance of non-critical data types to 1.
[0061] Therefore, after the data acquisition module 110 acquires the current data to be transmitted, the importance analysis module 120 can directly determine the data importance of the current data to be transmitted according to the current data type of the current data to be transmitted and in accordance with a preset matching relationship.
[0062] The necessity analysis module 130 is used to determine the necessity of key update of the data to be transmitted according to the importance of the data and the historical update time of each key.
[0063] In this embodiment, the key historical update time is used to represent the time when the key is updated in the historical process, and the key update necessity is used to represent the necessity degree of updating the key corresponding to the current data to be transmitted.
[0064] As an example, the necessity analysis module 130 calculates the average interval between key updates based on each historical key update time. It then divides the interval between the current time and the last key update time by the average interval to obtain a target ratio. A weighted sum of this target ratio and the data importance is then used to calculate a quantitative value for the key update necessity.
[0065] The key updating module 140 is configured to update the key of the data to be transmitted when the degree of necessity for key updating is greater than a preset degree of necessity threshold.
[0066] In this embodiment, the key update module 140 pre-sets a threshold for the necessity of key update based on security requirements, service characteristics, etc. For example, the threshold is set to 0.7, and when the calculated key update necessity is greater than 0.7, a key update operation is triggered.
[0067] Specifically, a new key is first generated using a secure key generation algorithm, such as one based on a random number generator or cryptographic hash function. The new key should possess sufficient randomness and complexity to ensure its security. The new key is then securely distributed to the data sender and receiver. This distribution process can employ technologies such as encrypted channels and digital certificate authentication to ensure the confidentiality and integrity of the key during transmission. After the data sender and receiver successfully obtain the new key, the old key is replaced with the new one. For data currently being transmitted, a smooth key transition mechanism can be implemented to ensure continuous data transmission. For example, decryption can be performed using both the old and new keys for a period of time, gradually transitioning to using only the new key. Finally, after confirming that the new key is functioning properly and the old key is no longer needed, the old key is securely destroyed to prevent malicious use. This destruction can occur through physical destruction of the storage medium (such as the hardware security module containing the old key) or through software-level overwriting or clearing to ensure that the old key cannot be recovered.
[0068] As an optional embodiment, the importance analysis module 120 specifically includes the following units:
[0069] A first type importance determination unit is configured to determine a target type importance corresponding to a current data type of the data to be transmitted based on a target matching relationship, wherein the target matching relationship is used to characterize a matching relationship between various data types and corresponding type importances;
[0070] an element acquisition unit, configured to acquire a first transmission data volume of the current data to be transmitted, and a type difference between the current data to be transmitted and the first historical transmission data within the corresponding historical time window, the type difference being used to characterize the difference between the current data type and the first historical data type of the first historical transmission data within the historical time window;
[0071] The data importance determination unit is used to determine the data importance of the current data to be transmitted by using the target type importance, the first transmission data volume and the type difference.
[0072] In this embodiment, the target matching relationship is to describe the matching relationship between various data types and corresponding type importances. For example, the data types and corresponding type importances can be stored using a hash table structure, where the key is the data type and the value is the corresponding type importance.
[0073] The first transmission data volume is used to represent the total amount of data in the user database that needs to be transmitted this time, that is, the total amount of data included in the data to be transmitted currently.
[0074] The first historical transmission data is used to represent the historical transmission data within the historical time window, and the first historical data type is used to represent the data type corresponding to the first historical transmission data.
[0075] The type difference is the difference between the current data type of the current data to be transmitted and the first historical data type of the first historical transmission data in the corresponding historical time window. For example, the size of the historical time window can be 5 batches of data to be transmitted before the current data to be transmitted.
[0076] As an example, the first type importance determination unit uses the constructed target matching relationship and the current data type as a key to search for the corresponding value in the hash table, thereby determining the target type importance.
[0077] Then, the element acquisition unit counts the first transmission data volume of the current data to be transmitted in the user database through a database query statement; at the same time, obtains 5 batches of data to be transmitted before the current data to be transmitted (i.e., the first historical transmission data) from the user database, and then determines the number of overlapping types in the data types of these 5 batches of data to be transmitted (i.e., the first historical data type) that are the same as the current data type of the current data to be transmitted, and finally divides 5 by the number of overlapping types to obtain the type difference between the current data to be transmitted and the first historical transmission data in the historical time window.
[0078] Finally, the data importance determination unit determines the data importance of the current data to be transmitted using the target type importance, the first transmission data amount, and the type difference through the following formula 1:
[0079] Formula 1
[0080] In formula 1, Used to characterize the importance of the jth batch of data to be transmitted, Used to characterize the type importance of the jth batch of data to be transmitted, The first transmission data volume used to characterize the jth batch of data to be transmitted, Used to characterize the type difference between the jth batch of data to be transmitted and the first historical transmission data in the corresponding historical time window.
[0081] Formula 1 primarily uses the importance of the type of data currently being transmitted in the user database, combined with the first transmission volume of the currently being transmitted data and whether data of this type was transmitted immediately before the currently being transmitted data, to comprehensively determine the data importance of the currently being transmitted data. The greater the importance of the type of data currently being transmitted, the greater the first transmission volume of the currently being transmitted data, or the less data of this type was transmitted immediately before the currently being transmitted data, the greater the data importance of the currently being transmitted data.
[0082] Through this embodiment, the data importance of the current data to be transmitted is comprehensively determined by combining the first transmission data volume of the current data to be transmitted, the type difference between the current data to be transmitted and the first historical transmission data in the corresponding historical time window, and the target type importance corresponding to the current data type. This can improve the accuracy of the data importance of the current data to be transmitted, thereby improving information security.
[0083] As an optional embodiment, the importance analysis module 120 further includes the following units:
[0084] A data acquisition unit, configured to acquire second historical transmission data within a target historical time period;
[0085] A second type importance determination unit is configured to determine the type importance corresponding to the second historical data type of each batch of second historical transmission data based on the second historical transmission data within the target historical time period;
[0086] The relationship generating unit is used to generate a target matching relationship based on the type importance corresponding to each second historical data type.
[0087] In this embodiment, the target historical time period can be determined based on business needs, data feature analysis, or relevant rules. For example, if you want to analyze the reference significance of recent data transmission patterns for current data processing, you can set the target historical time period to the past month; if you are interested in long-term trends, you can set it to the past year.
[0088] The second historical transmission data is used to represent the historical transmission data within the target historical time period, and the second historical data type is used to represent the data type corresponding to the second historical transmission data.
[0089] As an example, the data acquisition unit acquires the second historical transmission data from the user database using a corresponding query statement or a data extraction tool according to the target historical time period.
[0090] The second-type importance determination unit then analyzes each batch of second historical transmission data to identify its data type. Specifically, this may involve data parsing. For example, for structured data (such as tabular data in a database), the data type can be determined by reviewing field definitions and data content. For unstructured data (such as text, images, and audio), specific algorithms or tools may be used for feature extraction and classification, such as using natural language processing technology to identify the topic type of text data or image recognition technology to determine the category of image data.
[0091] The second type importance determination unit then assigns type importance to different data types based on business requirements and importance assessment criteria. For example, in a medical data transmission scenario, the importance of a patient's medical record data type might be set to 9 (out of 10), while the importance of general health promotional materials data type might be set to 3.
[0092] Finally, the relationship generation unit selects an appropriate data structure to store the target matching relationship, thereby storing each second historical data type and its corresponding type importance in the selected data structure. Specifically, common data structures may include a hash table, a dictionary, or a table in a relational database.
[0093] This embodiment obtains the second historical transmission data within the target historical time period, determines the type importance of each data type, and generates a target matching relationship that characterizes the matching relationship between the data type and the type importance. This allows the target type importance corresponding to the current data type of the data to be transmitted to be determined directly based on the target matching relationship, thereby improving the efficiency of determining the target type importance.
[0094] As an optional embodiment, the second type importance determination unit specifically includes the following subunits:
[0095] a transmission performance determination subunit, configured to determine the transmission performance of each second historical data type according to the start transmission time and the end transmission time of each batch of second historical transmission data within the target historical time period;
[0096] The type importance determination sub-unit is used to perform, for each second historical data type, respectively: determine the type importance of the target historical data type based on the transmission performance of the target historical data type, and the single transmission duration and second transmission data volume of the target second historical transmission data, the target historical data type is any second historical data type, and the target second historical transmission data is each batch of second historical transmission data corresponding to the target historical data type.
[0097] In this embodiment, the transmission performance metric is used to characterize the overall transmission performance of the second historical data type within the target historical time period. For example, the transmission performance metric can comprehensively consider factors such as transmission stability and timeliness. For example, the transmission performance metric can be defined as the ratio of the standard deviation of transmission duration to the average transmission duration to measure transmission stability, while timeliness can be assessed by considering whether the transmission is completed within the specified time.
[0098] The single data transmission duration is used to represent the duration required to transmit a batch of target second historical transmission data, and the second transmission data volume is used to represent the total amount of data included in the target second historical transmission data.
[0099] As an example, the transmission performance determination subunit first obtains the start transmission time and the end transmission time of each batch of second historical transmission data within the target historical time period, and calculates the transmission duration of each batch of second historical transmission data.
[0100] Then, the average transmission duration and standard deviation of all second historical transmission data of the same data type within the target historical time period are calculated. Based on the defined indicators, the transmission performance of the corresponding second historical data type is calculated using the average transmission duration and standard deviation of the second historical transmission data of the same data type.
[0101] Then, the type importance determination sub-unit obtains the corresponding single data transmission duration of each batch of target second historical transmission data for the target historical data type, and calculates the average single data transmission duration; and obtains the corresponding second transmission data volume of each batch of target second historical transmission data, and calculates the average second transmission data volume.
[0102] Finally, based on the transmission performance of the target historical data type, the average single data transmission duration, and the average second transmission data volume, the type importance of the target historical data type is calculated through weighted summation.
[0103] This embodiment accurately determines the type importance of a target historical data type based on the transmission performance of the target historical data type, as well as the single transmission duration and second transmission data volume of the target second historical transmission data. This allows accurate calculation of the type importance of each data type, further improving information security.
[0104] As an optional embodiment, the transmission performance determination subunit is specifically configured to:
[0105] Determine the total data transmission duration of the target historical data type and the transmission interval duration between adjacent target second historical transmission data according to the start transmission time and the end transmission time of each batch of second historical transmission data within the target historical time period;
[0106] The transmission performance of the target historical data type is determined by using the total data transmission duration of the target historical data type, the transmission interval durations between adjacent target second historical transmission data, and the total historical duration of the target historical time period.
[0107] In this embodiment, the total data transmission duration is used to represent the sum of the transmission durations of each batch of target second historical transmission data of the target historical data type, and the total historical duration is used to represent the length of the target historical time period.
[0108] The transmission interval duration is used to represent the duration between adjacent target second historical transmission data. For example, the transmission interval duration between the a+1th batch of target second historical transmission data and the a+1th batch of target second historical transmission data is calculated by subtracting the end transmission time of the ath batch of target second historical transmission data from the start transmission time of the ath batch of target second historical transmission data.
[0109] As an example, the transmission performance of the target historical data type may be determined by the following formula 2:
[0110] Formula 2
[0111] In formula 2, It is used to characterize the transmission performance of the data type corresponding to the jth batch of data to be transmitted. It is used to represent the total transmission time of the data corresponding to the data type of the jth batch of data to be transmitted. Used to represent the total historical duration of the target historical time period, It is used to represent the average value of the transmission interval durations between the second historical transmission data of adjacent targets corresponding to the data type of the j-th batch of data to be transmitted.
[0112] in, It is used to characterize the ratio of the total transmission time of the data type corresponding to the jth batch of data to be transmitted to the total historical transmission time. The larger the ratio, or the shorter the time interval between each data transmission of the same data type, the more frequently this type of data is called in the user database, that is, the greater the corresponding transmission performance.
[0113] Through this embodiment, the transmission performance of the target historical data type can be accurately determined by utilizing the total data transmission time of the target historical data type, the transmission interval time between each adjacent target second historical transmission data, and the total historical time of the target historical time period, thereby improving the calculation accuracy of the type importance.
[0114] As an optional embodiment, the type importance determination subunit is specifically configured to:
[0115] Determining a call frequency of the target historical data type according to a single transmission duration of the target second historical transmission data and a second transmission data volume;
[0116] The type importance of the target historical data type is determined by using the transmission performance and call frequency of the target historical data type.
[0117] In this embodiment, the type importance of the target historical data type can be determined specifically by the following formula 3:
[0118] Formula 3
[0119] In formula 3, It is used to characterize the type importance of the data type corresponding to the jth batch of data to be transmitted. Used to characterize the transmission performance of the data type corresponding to the jth batch of data to be transmitted. The batch number of the target second historical transmission data used to characterize the data type corresponding to the jth batch of data to be transmitted, It is used to characterize the single transmission duration of the second historical transmission data of the i-th batch of target data corresponding to the data type of the j-th batch of data to be transmitted. The second transmission data volume of the i-th batch of target second historical transmission data is used to represent the data type corresponding to the j-th batch of data to be transmitted.
[0120] in, This is used to characterize the call frequency of the data type corresponding to the jth batch of data to be transmitted. Specifically, if a data type is transmitted multiple times during the transmission process, and each transmission takes a long time and involves a large amount of data, this indicates that the data type is frequently called. The greater the call frequency, or the greater the transmission performance, the greater the type's importance.
[0121] Through this embodiment, the transmission performance of the target historical data type and the calling frequency of the target historical data type can be used to accurately determine the type importance of the target historical data type, thereby improving the calculation accuracy of the type importance and further improving information security.
[0122] As an optional embodiment, Figure 2 As shown, the necessity analysis module 130 specifically includes the following units:
[0123] The interval duration determining unit 131 is used to determine the average interval duration of key updates based on each key historical update moment;
[0124] The necessity determination unit 132 is used to determine the necessity of key update for the current data to be transmitted based on the data importance, the current interval duration of the current data to be transmitted, and the average interval duration, where the current interval duration is the interval duration between the current moment and the moment when the key was last updated.
[0125] In this embodiment, the average interval duration is used to represent the average interval duration between adjacent key update moments during the historical key update process; the current interval duration is used to represent the interval duration between the current moment and the moment of the last key update.
[0126] As an example, the interval duration determining unit 131 obtains historical update time information of the key from the log record, organizes the collected historical update time information, and arranges it in chronological order for subsequent calculation.
[0127] Then, we traverse the collected historical update time information and calculate the time interval between each two updates. We then add up the time intervals between all two updates and divide it by the number of intervals to get the average time interval between key updates.
[0128] Then, the necessity determination unit 132 obtains the current interval duration of the data to be transmitted, compares the current interval duration with the average interval duration, and determines the calculation rule of the key update necessity based on the relationship between the current interval duration and the average interval duration.
[0129] Finally, according to the calculation rule of the key update necessity, the data importance of the data to be transmitted is used to determine the key update necessity of the data to be transmitted.
[0130] This embodiment utilizes the importance of the data currently being transmitted, combined with the relationship between the current interval duration and the average interval duration of the data currently being transmitted, to accurately calculate the degree of re-keying necessity for the data currently being transmitted. This improves the accuracy of calculating the degree of re-keying necessity for the data currently being transmitted, thereby facilitating subsequent accurate determination of whether to update the key based on the degree of re-keying necessity, thereby improving information security.
[0131] As an optional embodiment, the interval duration determining unit 131 is specifically configured to:
[0132] For each key update time period, respectively performing: determining a duration weight of the key update time period based on the third transmission data volume within the key update time period and the type importance of each data type within the key update time period, where the key update time period is a time period between adjacent key historical update moments;
[0133] The average interval duration of key updates is determined by using the time period length of each key update time period and the corresponding time period weight.
[0134] In this embodiment, the third transmission data volume is used to represent the total amount of data transmitted during the key update period, that is, the total amount of data included in the key update period.
[0135] The key update period is a period between adjacent key history update moments. The duration of the key update period is the next key history update moment corresponding to the key update period minus the previous key history update moment.
[0136] As an example, the duration weight of the key update period may be determined by the following formula 4:
[0137] Formula 4
[0138] In formula 4, The duration weight used to characterize the cth key update period, Used to represent the third transmission data volume in the cth key update time period, It is used to characterize the type importance of the data type corresponding to the jth batch of data to be transmitted. Used to represent the number of data types in the cth key update time period.
[0139] The greater the amount of data transmitted during the rekeying period, or the greater the average importance of the types within the rekeying period, the greater the weight of the rekeying period. Specifically, the greater the amount of data transmitted during the rekeying period, or the greater the importance of the types within the rekeying period, the greater the weight assigned to the rekeying period.
[0140] Furthermore, the average interval duration for key updates can be determined specifically by the following formula 5:
[0141] Formula 5
[0142] In formula 5, It is used to represent the average interval between key updates. The duration of the cth key update period. The duration weight used to characterize the cth key update period, Used to represent the number of key update time periods, It is used to represent the accumulation of the duration weights of each key update period. That is, the duration weight representing the cth key update period accounts for the cumulative duration weights of all key update periods. This embodiment uses the duration of each key update period and its corresponding duration weight to determine the average interval between key updates. This approach, using the scale of data transmission and the importance of the data type in each key update period as weights, allows for more accurate determination of the average interval between key updates, thereby improving the accuracy of the necessity of subsequent key updates.
[0143] As an optional embodiment, the necessity determination unit 132 is specifically configured to:
[0144] Determine the necessity weight of the data to be transmitted according to the relationship between the current interval duration of the data to be transmitted and the average interval duration;
[0145] The necessity of rekeying the data to be transmitted is determined by using the data importance, necessity weight, and the proportion of abnormal data between the current time and the time of the last key update.
[0146] In this embodiment, the abnormal data ratio is used to represent the proportion of abnormal data to the total transmitted data in the time period between the current time and the time of the last key update. The abnormal data is data that has abnormal phenomena such as data theft.
[0147] As an example, the necessity weight of the data to be transmitted can be determined by the following formula 6:
[0148] Formula 6
[0149] In formula 6, Used to characterize the necessity weight of the data to be transmitted. Used to represent the current interval duration of the data to be transmitted. This parameter represents the average interval between key updates. s is a preset constant parameter to prevent the denominator from being zero.
[0150] Among them, when the current interval duration is greater than the average interval duration, the necessity weight of the current data to be transmitted is set to the difference between the current interval duration and the average interval duration; when the current interval duration is less than or equal to the average interval duration, the necessity weight of the current data to be transmitted is set to the reciprocal of the sum of the absolute value of the difference between the current interval duration and the average interval duration and the preset constant parameter.
[0151] Specifically, the necessity of key update for the data to be transmitted can be determined by the following formula 7:
[0152] Formula 7
[0153] In formula 7, It is used to characterize the necessity of key update for the data to be transmitted. Used to characterize the importance of the data to be transmitted. It is used to represent the necessary weight of the data to be transmitted, and norm is used to represent the normalization operation. It is used to represent the amount of abnormal data between the current time and the time when the key was last updated. It is used to represent the total amount of data transmitted between the current time and the time when the key was last updated. It is used to characterize the proportion of abnormal data between the current moment and the moment when the key was last updated. It should be noted that, in order to ensure that the calculation results are meaningful, when performing fractional operations in the embodiment of the present invention, when the denominator is 0, a parameter adjustment factor greater than 0 needs to be added to the denominator to prevent the denominator from being 0. The value of the parameter adjustment factor is set by the implementer according to the actual situation, and this application does not impose any special restrictions.
[0154] This embodiment utilizes data importance, necessity weight, and the proportion of abnormal data between the current time and the last key update to accurately determine the necessity of a key update for the data currently being transmitted. This allows the decision to determine whether to perform a key update based on the necessity. This reduces the risk of eavesdropping and cracking associated with key updates performed within a set time period, improving information security.
[0155] According to the big data-based user database information anti-leakage protection device provided by the present invention, the present invention also provides a specific embodiment of the big data-based user database information anti-leakage protection system.
[0156] like Figure 3 As shown, a schematic diagram of the structure of a user database information leakage protection system based on big data is provided. The user database information leakage protection system based on big data includes:
[0157] The data encryption subsystem 310 is used to encrypt the data to be transmitted in the user database;
[0158] The behavior detection subsystem 320 is used to detect the health and abnormality of the data transmission behavior of the user database;
[0159] The authority control subsystem 330 is used to manage the access rights to the data to be transmitted in the user database;
[0160] The user database information anti-leakage protection device 100 based on big data provided in any of the above aspects communicates with the data encryption subsystem 310, the behavior detection subsystem 320 and the authority control subsystem 330 respectively.
[0161] In this embodiment, the data encryption subsystem 310 uses an advanced encryption algorithm to encrypt sensitive data in the user database. The selection of the encryption algorithm should be based on the importance of the data, transmission requirements, and availability of computing resources.
[0162] The behavior detection subsystem 320 uses big data analysis and machine learning technology to monitor the data transmission behavior of the user database, including the time and frequency of data transmission.
[0163] The permission control subsystem 330 assigns specific roles to different users or user groups. Each role has different data access permissions, enabling fine-grained control of data access, such as read-only, write, and delete permissions, ensuring that only authorized users can perform specific operations. Furthermore, user permissions can be dynamically adjusted based on business needs, user behavior analysis results, or changes in security policies.
[0164] The user database information anti-leakage protection device 100 based on big data serves as a central control node, and communicates with the data encryption subsystem 310, the behavior detection subsystem 320 and the authority control subsystem 330 through a secure and efficient communication protocol to execute the user database information anti-leakage protection process in the user database information anti-leakage protection device 100 based on big data provided by any of the above aspects.
[0165] In the user database information leakage protection system based on big data provided by an embodiment of the present invention, the data importance of the data to be transmitted is analyzed according to the current data type of the data to be transmitted. Then, the necessity of updating the key of the data to be transmitted is determined according to the transmission importance of the data to be transmitted and each historical key update time. In the case where the necessity of key update is greater than the preset necessity threshold, the key of the data to be transmitted is updated. In this way, the present invention determines the transmission importance of the data to be transmitted according to the current data type of the data to be transmitted, and analyzes the necessity of key update at the current moment in combination with the interval length of key update under historical circumstances, thereby determining whether to update the key according to the necessity of key update. In this way, the risk of eavesdropping and the risk of cracking when updating the key within a set time period can be avoided, thereby improving information security.
[0166] It should be understood that the present invention is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, a detailed description of known methods is omitted. In the above embodiments, several specific steps are described and illustrated as examples. However, the method of the present invention is not limited to the specific steps described and illustrated. Those skilled in the art may make various changes, modifications, and additions, or change the order of the steps after understanding the spirit of the present invention.
Claims
1. A user database information anti-leakage protection device based on big data, characterized in that: The device comprises: Data acquisition module, used to obtain the current data to be transmitted; an importance analysis module, configured to determine the data importance of the data to be transmitted according to the current data type of the data to be transmitted, where the data types include sensitive data types, general business data types, and non-critical data types, where the data importance of the sensitive data types is higher than that of the general business data types, and the data importance of the general business data types is higher than that of the non-critical data types; a necessity analysis module, configured to determine the necessity of updating the key of the data to be transmitted based on the importance of the data and each historical key update time, wherein the key update necessity is used to represent the degree of necessity of updating the key of the data to be transmitted; A key updating module, configured to update the key of the data to be transmitted when the key update necessity is greater than a preset necessity threshold; The key update necessity satisfies the following formula: in, Indicates the degree of necessity for key update, Indicates the importance of the data to be transmitted. Indicates the necessity weight of the data to be transmitted. represents the normalization operation, Indicates the amount of abnormal data between the current time and the time when the key was last updated. Indicates the total amount of data transmitted between the current time and the time when the key was last updated. Indicates the percentage of abnormal data between the current time and the time when the key was last updated.
2. The user database information anti-leakage protection device based on big data according to claim 1 is characterized in that: The importance analysis module specifically includes the following units: A first type importance determination unit is configured to determine a target type importance corresponding to a current data type of the data to be transmitted based on a target matching relationship, wherein the target matching relationship is used to characterize a matching relationship between various data types and corresponding type importances; an element acquisition unit, configured to acquire a first transmission data volume of the current data to be transmitted, and a type difference between the current data to be transmitted and the first historical transmission data within the corresponding historical time window, the type difference being used to characterize the difference between the current data type and the first historical data type of the first historical transmission data within the historical time window; A data importance determination unit is used to determine the data importance of the data to be transmitted currently by using the target type importance, the first transmission data volume and the type difference.
3. The user database information anti-leakage protection device based on big data according to claim 2 is characterized in that: The importance analysis module further includes the following units: A data acquisition unit, configured to acquire second historical transmission data within a target historical time period; a second type importance determining unit, configured to determine, based on the second historical transmission data within the target historical time period, a type importance corresponding to the second historical data type of each batch of the second historical transmission data; The relationship generating unit is configured to generate the target matching relationship based on the type importance corresponding to each of the second historical data types.
4. The user database information anti-leakage protection device based on big data according to claim 3 is characterized in that: The second-type importance determination unit specifically includes the following subunits: a transmission performance determination subunit, configured to determine a transmission performance of each type of the second historical data according to a start transmission time and an end transmission time of each batch of the second historical transmission data within the target historical time period; The type importance determination sub-unit is used to perform, for each second historical data type, respectively: determine the type importance of the target historical data type based on the transmission performance of the target historical data type, and the single transmission duration and second transmission data volume of the target second historical transmission data, the target historical data type is any one of the second historical data types, and the target second historical transmission data is each batch of the second historical transmission data corresponding to the target historical data type.
5. The user database information anti-leakage protection device based on big data according to claim 4 is characterized in that: The transmission performance determination subunit is specifically configured to: Determine, based on the start transmission time and the end transmission time of each batch of the second historical transmission data within the target historical time period, the total transmission duration of the data of the target historical data type and the transmission interval duration between adjacent target second historical transmission data; The transmission performance of the target historical data type is determined by using the total data transmission duration of the target historical data type, the transmission interval durations between adjacent target second historical transmission data, and the total historical duration of the target historical time period.
6. The user database information anti-leakage protection device based on big data according to claim 4 is characterized in that: The type importance determination subunit is specifically used to: determining a call frequency of the target historical data type according to the single data transmission duration of the target second historical transmission data and the second transmission data volume; The type importance of the target historical data type is determined by utilizing the transmission performance of the target historical data type and the call frequency.
7. The user database information anti-leakage protection device based on big data according to claim 1 is characterized in that: The necessity analysis module specifically includes the following units: an interval duration determining unit, configured to determine an average interval duration for updating the key according to each historical update moment of the key; The necessity determination unit is used to determine the necessity of updating the key of the data to be transmitted according to the importance of the data, the current interval duration of the data to be transmitted and the average interval duration, where the current interval duration is the interval duration between the current moment and the moment when the key was last updated.
8. The user database information anti-leakage protection device based on big data according to claim 7 is characterized in that: The interval duration determining unit is specifically configured to: For each key update time period, respectively performing: determining a duration weight of the key update time period based on a third amount of transmitted data within the key update time period and a type importance of each of the data types within the key update time period, wherein the key update time period is a time period formed between adjacent key historical update moments; The average interval duration of the key update is determined by using the time period duration of each key update time period and the corresponding time period weight.
9. The user database information anti-leakage protection device based on big data according to claim 7, characterized in that: The necessity determination unit is specifically configured to: Determining a necessity weight of the data to be transmitted currently based on a relationship between a current interval duration of the data to be transmitted currently and the average interval duration; The necessity of updating the key of the data to be transmitted is determined by using the data importance, the necessity weight, and the proportion of abnormal data between the current moment and the moment when the key was last updated.
10. A user database information anti-leakage protection system based on big data, characterized in that: The system comprises: Data encryption subsystem, used to encrypt the data to be transmitted in the user database; A behavior detection subsystem, used to detect the health and abnormality of the data transmission behavior of the user database; The authority control subsystem is used to manage the access rights to the data to be transmitted in the user database; The big data-based user database information anti-leakage protection device as described in any one of claims 1 to 9, wherein the big data-based user database information anti-leakage protection device communicates with the data encryption subsystem, the behavior detection subsystem and the authority control subsystem respectively.
Citation Information
Patent Citations
Power distribution room intelligent operation and maintenance information system based on quantum encryption
CN119853907A