Human resource data security guarantee method and device, medium and equipment

Through the combination of multi-dimensional sensitivity classification and dynamic encryption algorithms, real-time monitoring and multi-factor authentication, the problem of inefficient authorization under dynamic access requirements is solved, and the balance between security and efficiency of human resource data is achieved.

CN120277689APending Publication Date: 2025-07-08CHONGQING SHENGLERONG TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510348180.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-24
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

Traditional encryption methods are difficult to cope with dynamic access requirements, and sensitive data classification is coarse, resulting in low authorization efficiency and difficult to achieve differentiated protection.

Method used

Multi-dimensional sensitivity classification is used to generate classification tags, combine dynamic encryption algorithms and key management, and data traffic is monitored in real time through network probes, abnormal access behavior is detected in real time, and multi-factor authentication and environmental risk assessment models are adopted.

Benefits of technology

It achieves a balance between data security and processing efficiency, responds to security risks dynamically, and realizes differentiated protection of sensitive data and intercepting abnormal access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120277689A_ABST
    Figure CN120277689A_ABST
Patent Text Reader

Abstract

The invention discloses a human resource data safety guarantee method and device, a medium and equipment, and the method comprises the steps: 1, carrying out the multi-dimensional sensitivity classification of human resource data, generating a classification label, enabling the sensitivity classification to comprise the data type, post level, performance evaluation and behavior data, and enabling the classification label to be a classification label; wherein the performance evaluation comprises an assessment record, a promotion material and a reward and punishment record, and the behavior data comprises an attendance record, a system operation log and a training record; step 2, dynamically selecting an encryption algorithm according to the classification labels to perform hierarchical encryption; 3, monitoring and analyzing transmission data in real time by using a network probe, capturing data traffic through a mirror image port or an optical splitter, forming an original data packet, and providing a basis for subsequent analysis; 4, abnormal access behaviors are detected in real time; the invention relates to the technical field of information security, and particularly provides a human resource data security guarantee method and device, a medium and equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and specifically to a method, device, medium and equipment for ensuring the security of human resource data. Background Art

[0002] With the rapid development of information technology, the difficulty of confidentiality work has increased, and more challenges have been encountered. The communication data volume between nodes in network information transmission is huge, which further increases the technical difficulty of data security assurance.

[0003] Human resource data is important data of an enterprise. The human resource management system stores a large amount of sensitive data (such as employee identity information, salary, performance appraisal, etc.). Traditional encryption methods have the problems that static encryption is difficult to meet dynamic access requirements, resulting in low authorization efficiency, coarse classification granularity of sensitive data, and difficulty in achieving differential protection. Summary of the Invention

[0004] The technical problem to be solved by the present invention is that traditional encryption methods are difficult to meet dynamic access requirements with static encryption, and the classification granularity of sensitive data is coarse.

[0005] To solve the above technical problems, the present invention provides the following technical solutions: A method for ensuring the security of human resource data provided by this solution includes:

[0006] Step 1: Classify human resource data with multi-dimensional sensitivity to generate classification labels. The sensitivity classification includes: data type, job level, performance evaluation, and behavior data. Among them, performance evaluation includes assessment records, promotion materials, reward and punishment records, and behavior data includes attendance records, system operation logs, and training records;

[0007] Step 2: Dynamically select an encryption algorithm for hierarchical encryption according to the classification label;

[0008] Step 3: Use a network probe to monitor and analyze transmission data in real time, capture data traffic through a mirror port or a splitter to form original data packets, providing a basis for subsequent analysis;

[0009] Step 4: Detect abnormal access behaviors in real time.

[0010] Preferred Technical Solution 1: The dynamic encryption includes adopting a session key mechanism for highly sensitive data, generating a unique key for each communication, and the key generation depends on a random number seed or a dynamic factor.

[0011] Preferred Technical Solution 2: The dynamic encryption includes adopting an encryption algorithm switchable mechanism for highly sensitive data, dynamically selecting an algorithm according to a security policy to avoid the risk of a single algorithm being attacked for a long time.

[0012] A device for ensuring the security of human resource data includes

[0013] Data classification module, used for data classification, sensitivity analysis and generation of classification labels;

[0014] The encryption module uses a dynamic encryption engine to achieve real-time protection of data during transmission and processing through dynamic keys and algorithm switching mechanisms, and dynamic key timeliness control;

[0015] Monitoring and data analysis module, which captures and analyzes network traffic in real time and extracts key information for security analysis or performance optimization;

[0016] The access control module ensures the legitimacy of data access and minimizes authorization, while dynamically responding to security risks and adopting multi-factor authentication, including biometrics, hardware tokens and behavioral characteristics.

[0017] Furthermore, the access control module can work in conjunction with the encryption module and the monitoring and data analysis module to update the access policy.

[0018] Furthermore, when the authentication strength of the access control module reaches a threshold, it is necessary to simultaneously complete triple verification of biometrics, hardware tokens, and behavioral feature analysis, where the behavioral features include keyboard input frequency.

[0019] Furthermore, the access control module also adds an environmental risk assessment model, and the model dimensions include device credibility; network location; and operation time.

[0020] The present disclosure also includes a storage medium storing program instructions, which implement the above method when executed by a processor.

[0021] The present disclosure also includes an electronic device, which includes: a storage medium, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-described method when executing the program.

[0022] The present invention proposes a method, device, medium and equipment for ensuring the security of human resources data. The beneficial effects achieved by adopting the above structure are as follows:

[0023] (1) Through the dynamic hierarchical encryption mechanism based on data sensitivity, the encryption algorithm and key management strategy are dynamically selected in combination with the data classification results to achieve a balance between security and processing efficiency;

[0024] (2) Build a monitoring and data analysis module to monitor and analyze transmission data in real time through network probes, and combine multi-factor authentication and environmental risk assessment models to intercept and warn of abnormal access. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] The accompanying drawings are used to provide a further understanding of the present invention and form a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention. In the accompanying drawings:

[0026] Figure 1 It is a flowchart of a method for ensuring the security of human resource data proposed by the present invention. Detailed implementation manners

[0027] The following will clearly and completely describe the technical invention in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments; based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0028] Embodiment 1

[0029] As Figure 1 shown, the technical invention adopted by the present invention is as follows: A method for ensuring the security of human resource data, including:

[0030] Step 1: Classify the human resource data in multiple dimensions to generate classification labels, so as to obtain different categories of human resource data. The sensitivity classification includes: data type, position level, performance evaluation, and behavior data. Among them, the performance evaluation includes assessment records, promotion materials, rewards and punishments records, and the behavior data includes attendance records, system operation logs, and training records. The classification model adopts a hybrid decision-making mechanism combining a rule engine and machine learning;

[0031] Step 2: Dynamically select an encryption algorithm for hierarchical encryption according to the classification labels. The dynamic encryption includes adopting a session key mechanism for highly sensitive data, generating a unique key for each communication, blocking the risk of historical key leakage, and the key generation depends on a random number seed (such as a hardware true random number generator) or dynamic factors such as a time stamp and device status parameters;

[0032] Step 3: Use a network probe to monitor and analyze the transmitted data in real time, capture the data traffic through a mirror port or an optical splitter to form an original data packet, providing a basis for subsequent analysis;

[0033] Step 4: Detect abnormal access behaviors in real time.

[0034] Preferred technical solution 2:

[0035] A device for ensuring the security of human resource data, including

[0036] a data classification module, used for classifying data, sensitivity analysis, and generating classification labels;

[0037] The encryption module uses a dynamic encryption engine to achieve real-time protection of data during transmission and processing through dynamic keys and algorithm switching mechanisms. It also controls the timeliness of dynamic keys and generates a temporary token for each access, the validity period of which is bound to the operation type.

[0038] Monitoring and data analysis module, which captures and analyzes network traffic in real time and extracts key information for security analysis or performance optimization;

[0039] The access control module ensures the legitimacy of data access and minimizes authorization, while dynamically responding to security risks and adopting multi-factor authentication, including biometrics, hardware tokens and behavioral characteristics; the access control module can work with the encryption module and the monitoring and data analysis module to update the access policy. When the authentication strength of the access control module reaches the threshold, it must complete triple verification of biometrics, hardware tokens and behavioral characteristic analysis at the same time, where behavioral characteristics include keyboard input frequency.

[0040] Furthermore, the access control module also adds an environmental risk assessment model, which includes device credibility (whether the enterprise security client is installed); network location (enterprise intranet / IP whitelist / external public WiFi); and operation time (9:00-18:00 on weekdays).

[0041] The present disclosure also includes a storage medium storing program instructions, which implement the above method when the instructions are executed by a processor.

[0042] The present disclosure also includes an electronic device, which includes: a storage medium, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-described method when executing the program.

[0043] Embodiment 2

[0044] Based on Example 1, a method for ensuring the security of human resources data is provided. The dynamic encryption includes a switchable encryption algorithm mechanism for highly sensitive data. Algorithm switching is triggered in real time based on the three dimensions of data sensitivity, system load, and compliance requirements. Layered encryption includes the use of a national secret algorithm at the base layer, ChaCha20 at the transport layer, and AES-256 at the application layer, to avoid the risk of a single algorithm being attacked for a long time.

[0045] A human resources data security protection device, wherein the access control module also adds an environmental risk assessment model, and the model dimensions include device credibility (whether the enterprise security client is installed); network environment (enterprise intranet / IP whitelist / external public WiFi); operation time (9:00-18:00 on weekdays).

[0046] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, material or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, material or device.

[0047] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A method for ensuring the security of human resource data, characterized in that, include Step 1: Perform multi-dimensional sensitivity classification on human resource data and generate classification labels. The sensitivity classification includes: data type, job level, performance evaluation and behavioral data. Performance evaluation includes assessment records, promotion materials, reward and punishment records, and behavioral data includes attendance records, system operation logs, and training records. Step 2: Dynamically select encryption algorithms based on classification labels for hierarchical encryption; Step 3: Use network probes to monitor and analyze transmission data in real time, capture data traffic through mirror ports or splitters, and form original data packets to provide a basis for subsequent analysis; Step 4: Detect abnormal access behavior in real time.

2. The method for ensuring the security of human resource data according to claim 1, characterized in that The dynamic encryption includes using a session key mechanism for highly sensitive data, generating a unique key for each communication, and the key generation relies on a random number seed or a dynamic factor.

3. The method for ensuring the security of human resource data according to claim 1, characterized in that, The dynamic encryption includes using a switchable encryption algorithm mechanism for highly sensitive data.

4. A human resource data security protection device, characterized in that include: Data classification module, used for data classification, sensitivity analysis and generation of classification labels; The encryption module uses a dynamic encryption engine to achieve real-time protection of data during transmission and processing through dynamic keys and algorithm switching mechanisms, and dynamic key timeliness control; Monitoring and data analysis module, which captures and analyzes network traffic in real time and extracts key information for security analysis or performance optimization; The access control module ensures the legitimacy of data access and minimizes authorization, while dynamically responding to security risks and adopting multi-factor authentication, including biometrics, hardware tokens and behavioral characteristics.

5. The human resource data security protection device according to claim 4, characterized in that The access control module can work with the encryption module and the monitoring and data analysis module to update the access policy.

6. The human resource data security protection device according to claim 4, characterized in that, When the authentication strength of the access control module reaches the threshold, it is necessary to complete triple verification of biometrics, hardware token and behavioral feature analysis at the same time. The behavioral features include keyboard input frequency.

7. An apparatus for ensuring the security of human resource data according to any one of claims 4 to 6, characterized in that, The access control module also adds an environmental risk assessment model, the model dimensions of which include device credibility; network location; and operation time.

8. A storage medium storing program instructions, wherein the instructions, when executed by a processor, implement the method according to any one of claims 1 to 3.

9. An electronic device, the electronic device comprising: A storage medium, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1 to 3 when executing the program.