Finance and tax data intelligent management method and system based on encrypted storage
Through the multi-feature fusion sensitivity evaluation model and dynamic encryption strategy, the differentiation and compliance issues of fiscal and tax data protection are solved, intelligent security management and rapid retrieval of data are realized, and the security and credibility of data are improved.
Patent Information
- Application Number
- CN202510769439.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-10
AI Technical Summary
The existing fiscal and taxation data protection technology lacks differentiated protection capabilities. Traditional systems have shortcomings in key management, dynamic updates, ciphertext retrieval and compliance audits, and it is difficult to meet the needs of complex and changeable business scenarios, resulting in data leakage, encryption failure and audit traceability difficulties.
The multi-feature fusion sensitivity evaluation model is adopted, and the encryption algorithm and key generation method are dynamically selected. Combined with composite chaotic mapping and grid-based key generation, the fine-grained classification and differentiated protection of data is realized, and ciphertext retrieval and dynamic key rotation are supported to ensure the security and compliance of the data throughout the life cycle.
It realizes intelligent security protection and continuous compliance management of fiscal and tax data, improves data security and credibility, supports rapid retrieval and dynamic response to multi-scenario needs, and reduces the risk of data leakage.
Smart Images

Figure CN120277699A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of enterprise finance and tax management, and particularly to an intelligent management method and system for finance and tax data based on encrypted storage. Background Art
[0002] With the continuous acceleration of the enterprise digitalization and tax e - filing processes, finance and tax data, as an important information asset for enterprise operation management and compliance supervision, has seen a continuous increase in its data volume, data complexity, and sensitivity. The demand for the security protection of finance and tax data has become increasingly stringent, and relevant laws and regulations have also put forward higher requirements for the collection, storage, use, and transfer of sensitive data.
[0003] Existing finance and tax data protection technologies mainly rely on static unified encryption methods and lack the ability to differentially protect data with different sensitivities. At the same time, traditional systems have deficiencies in key management, dynamic update, ciphertext retrieval, and compliance auditing, making it difficult to meet the requirements of complex and changeable business scenarios and prone to problems such as data leakage, encryption failure, and difficulties in audit traceability.
[0004] In view of the above problems, the present invention proposes an intelligent management method and system for finance and tax data based on encrypted storage. Through multi - feature fusion sensitivity assessment, dynamic encryption strategy decision - making, composite chaotic mapping and lattice - based key generation, ciphertext retrieval access and dynamic key rotation mechanism, it realizes the intelligent security protection and continuous compliance management of the entire life cycle of finance and tax data, effectively making up for the deficiencies of the existing technology. Summary of the Invention
[0005] The present invention aims at the above problems and provides an intelligent management method and system for finance and tax data based on encrypted storage to solve the problems of static and rigid finance and tax data protection means, insufficient flexibility, and inability to dynamically respond to multi - scenario requirements in the existing technology.
[0006] To solve the above - mentioned technical problems, the present invention provides the following technical solutions: An intelligent management method for finance and tax data based on encrypted storage, comprising the following steps:
[0007] Step S1, collect financial and tax - related data from multiple channels through a data acquisition module, evaluate the sensitivity of the data, and divide the sensitivity levels.
[0008] In step S1, the following sub - steps are further included:
[0009] S1 - 1, connect to the external sources of the enterprise financial system and tax system through a data interface unit based on preset data acquisition rules and interface protocols, and extract structured finance and tax data, where the finance and tax data includes accounts and declaration records.
[0010] S1-2. Using the OCR recognition algorithm through the data recognition unit, scan and recognize the unstructured financial and tax data of bills and invoices, extract the key fields and convert them into a structured data format, as shown in the following formula:
[0011]
[0012]
[0013] Among them, I is the image input space, and T is the text output space. is the OCR recognition mapping function; D is the unstructured data set generated after OCR recognition. represents the j-th text data entry extracted from the image.
[0014] S1-3. Invoke the data preprocessing unit to clean and standardize the collected raw data, filter out abnormal information and redundant information, fill in the missing data, and unify the data format model, and output the standardized financial and tax data.
[0015] S1-4. Based on the preset sensitivity assessment model, analyze and calculate the preprocessed data to obtain the sensitivity index value of the data. The sensitivity assessment model comprehensively considers various influencing factors, including the degree of private information contained in the data, the financial value level of the data, and the intensity of compliance requirements involved in the data. Let the input data be denoted as D, then the sensitivity index is calculated according to the weighted model, as shown in the following formula:
[0016]
[0017] Among them, represents the privacy sensitivity factor of data D. represents the value sensitivity factor of data D. represents other relevant sensitivity factors. , ,..., are the weight coefficients of the corresponding factors.
[0018] S1-5. Sensitivity level classification. Compare the sensitivity index S(D) calculated in step S1-4 with the preset sensitivity level threshold to determine the sensitivity level category to which the data belongs. The specific classification criteria are as follows:
[0019] The sensitivity score range is [0.8, 1.0], and the sensitivity level is top secret. The data contains management-level and enterprise core financial and tax information, and leakage will cause significant losses.
[0020] The sensitivity score range is [0.6, 0.8), and the sensitivity level is confidential. The data contains large transaction data and important tax declaration information, and leakage will cause relatively large losses.
[0021] The sensitivity score range is [0.4, 0.6), the sensitivity level is sensitive, the data includes small and medium-sized financial bills and general tax-related data, and there is a medium risk of leakage;
[0022] The sensitivity score range is [0.2, 0.4), the sensitivity level is internal, the data includes the enterprise's internal regular financial and tax information, and the impact of leakage is small;
[0023] The sensitivity score range is [0.0, 0.2), the sensitivity level is public, the data includes publicly available or data without sensitivity requirements, and no special encryption is required.
[0024] Step S2, key generation and encryption policy setting. Based on the data sensitivity level, dynamically determine the appropriate encryption algorithm type and encryption parameters, and generate the corresponding key;
[0025] In step S2, the following sub-steps are also included:
[0026] S2-1. According to the data sensitivity level determined in S1-5, combined with the preset encryption protection standard, select the matching encryption algorithm type and key parameters to achieve the dynamic balance between the security and system performance of data with different sensitivity levels. The specific matching relationships are as follows:
[0027] Data of top-secret level: Adopt NTRU quantum-resistant encryption combined with ABE attribute-based encryption. The NTRU key length is not less than 1024 bits, and the ABE policy supports fine-grained access control;
[0028] Data of confidential and sensitive levels: Adopt Paillier homomorphic encryption. The public key length is not less than 2048 bits, and it supports data calculation and processing under ciphertext;
[0029] Data of internal and public levels: Adopt AES-256 symmetric encryption. The key length is 256 bits, taking into account both efficiency and security;
[0030] S2-2. Invoke the key generation mechanism of the key management unit to generate the encryption key K according to the selected algorithm and parameters. The key generation adopts a cryptographically secure random number algorithm;
[0031] In the case of symmetric encryption, use a secure random number generator to generate a key that meets the length requirements of step S2-1; in the case of asymmetric encryption, generate the corresponding public and private key pairs. The generated keys should meet the security strength requirements and match the data sensitivity level;
[0032] S2-3. Securely save the generated key K to the key library of the key management module, and establish a mapping relationship between the key identifier and the data sensitivity level. During the key storage process, perform secondary encryption on the key, and record the key generation time, applicable data range, and expiration metadata.
[0033] Step S3. Data encryption and storage. Use the obtained key and encryption policy to encrypt the fiscal and tax data, and securely store the ciphertext.
[0034] In step S3, the following sub-steps are also included:
[0035] S3-1. Call the encryption algorithm module, and use the key K generated in step S2 to perform an encryption operation on the fiscal and tax data classified in step S1 to obtain the corresponding ciphertext data C. During the encryption process, strictly execute according to the algorithm and parameters set in step S2 to ensure that the encryption strength meets the requirements.
[0036] For the case of a large amount of data, adopt technologies such as block encryption to ensure the efficiency of the encryption process. However, the final encryption result should completely cover the original data. After encryption, package the ciphertext data C and related metadata, where the related metadata includes data identifier, sensitivity level, and key identifier, and send them to the storage unit.
[0037] S3-2. Receive the ciphertext data C from the encryption unit, and write it into a secure data storage medium. During the storage process, perform hierarchical management in combination with the sensitivity level of the data, as follows:
[0038] For data of top-secret level, store it in a highly secure storage medium with physical isolation capabilities, that is, the trusted execution environment memory and hardware encrypted disk.
[0039] For data of confidential level, store it in an encrypted independent partition or a dedicated encrypted disk volume, and adopt an independent access control policy.
[0040] For data of sensitive level, store it in a secure partition with standard data encryption enabled, that is, an AES encrypted disk.
[0041] For data of internal level, store it in a standard storage medium protected by conventional security measures, and restrict access through access control.
[0042] For data of public level, it can be stored in a common storage space without special encryption processing, but access logs are still recorded.
[0043] S3-3. Record the meta-information corresponding to the ciphertext data, including data identifier, sensitivity level, key identifier used for encryption, and encryption timestamp. Establish an index in the storage medium and associate and save the above meta-information with the ciphertext data for subsequent retrieval, decryption, and key update management. This meta-information record ensures that the system can quickly locate the key based on the data identifier and perform decryption.
[0044] Step S4. Data access and dynamic encryption maintenance. Provide a controlled encrypted data access service and perform dynamic security maintenance on the stored data according to a predetermined policy.
[0045] In step S4, the following sub-steps are also included:
[0046] S4-1. The system verifies whether the identity credentials provided by the requester are legal and valid. Adopt username / password verification and combine it with a multi-factor authentication mechanism to improve the authentication strength. Only the subject that passes the identity authentication can enter the subsequent authorization check process.
[0047] S4-2. Perform permission verification on the access request that has passed the authentication. Check whether the requester has the access permission corresponding to the sensitivity level of the requested data. The system compares the permission level of the requester with the sensitivity level of the target data according to the pre-set permission policy. If the permission level meets the requirements, decrypt and access are allowed; otherwise, the request is rejected and the illegal access attempt is recorded.
[0048] S4-3. For the request that has passed the authorization, extract the corresponding ciphertext data C and its meta-information from the data storage medium. The system determines the data key for decryption according to the meta-information, and then calls the decryption algorithm module to perform a decryption operation on C using the correct key to restore the original plaintext data D. During the decryption process, verify the data integrity and correctness to ensure that the decryption result is the same as before encryption.
[0049] S4-4. Provide the decrypted plaintext data to the requester for use, and record and audit this data access. The recorded content includes the identity of the visitor, the data identifier accessed, the sensitivity level, the access time, and the key identifier used for decryption for security audit and future traceability.
[0050] S4-5. The system continuously monitors the encryption status of the stored data. According to the key validity period and usage times policy set in step S2, trigger the key update process under specific conditions. When the key update condition is reached, perform the following operations on the corresponding data:
[0051] First, the key management module generates a new encryption key K', that is, it re-executes a process similar to step S2-2, but generates a new key; then it decrypts the existing ciphertext data C using the old key K to obtain the plaintext data D; next, it re-encrypts D using the new key K' according to step S3-1 to obtain a new ciphertext C'; finally, it replaces the originally stored C with C', and updates the key identifier and encryption time in the meta-information; during the update process, the new key K' and its metadata are synchronously stored in the key library, and the old key K is marked as invalid and cannot be used again.
[0052] An intelligent management system for fiscal and tax data based on encrypted storage, comprising:
[0053] A data classification module, a key management and encryption policy module, a data encryption storage module, and a data access and dynamic encryption maintenance module;
[0054] The data classification module is used to perform sensitivity analysis and classification on fiscal and tax data. This module includes: a data acquisition unit, a sensitivity analysis unit, and a classification unit;
[0055] The data acquisition unit is used to collect original fiscal and tax data and input the collected data into the data classification module for processing; the sensitivity analysis unit is used to calculate the sensitivity index of the fiscal and tax data according to a preset sensitivity assessment model; the classification unit is used to divide the fiscal and tax data into corresponding sensitivity levels according to the sensitivity index and provide the classification result to subsequent modules;
[0056] The key management and encryption policy module is used to generate an encryption key and formulate an encryption policy according to the data sensitivity level. This module includes: a key generation unit, a policy setting unit, and a key storage unit;
[0057] The key generation unit is used to generate an encryption key according to the selected algorithm type and parameters, ensuring that the key meets the security strength requirements; the policy setting unit is used to determine parameters such as the encryption algorithm type, key length, and key update policy of the data; the key storage unit is used to securely store the generated key and maintain the mapping relationship between the key and the data sensitivity level as well as the key life cycle information;
[0058] The data encryption storage module is used to perform encryption operations on fiscal and tax data and manage the storage of the encrypted data. This module includes: an encryption execution unit and a data storage unit;
[0059] The encryption execution unit is used to call the selected encryption algorithm to encrypt the fiscal and tax data to generate corresponding ciphertext data; the data storage unit is used to store the encrypted ciphertext data and save the meta-information associated with the ciphertext data to support subsequent data retrieval, decryption, and key update operations;
[0060] Data access and dynamic encryption maintenance module, which is used to control the access and decryption of encrypted data and perform dynamic encryption maintenance. This module includes: identity authentication unit, permission control unit, data extraction unit, data decryption unit, dynamic maintenance unit and audit unit;
[0061] The identity authentication unit is used to authenticate the data access requester to ensure that it is a legitimate user; the permission control unit is used to verify whether the requester who has passed the identity authentication has the access permission corresponding to the sensitivity level of the target data; the data extraction unit is used to retrieve the ciphertext of the requested fiscal and tax data and its related meta-information from the storage medium; the data decryption unit is used to call the decryption algorithm to decrypt the retrieved ciphertext data with the correct key to restore the original plaintext data; the dynamic maintenance unit is used to monitor the key usage status according to the predetermined encryption policy and regularly trigger key updates and perform data re-encryption operations; the audit unit is used to record and monitor the key events during the data access process, including information such as the identity of the visitor, access time, access data identifier, and operation result, to support security audits and anomaly tracing.
[0062] Compared with the prior art, the beneficial effects of the present invention are:
[0063] By introducing a sensitivity evaluation model based on the fusion of amount features, sensitive field features, business scenario features and context semantic features, the present invention can perform fine-grained sensitivity intelligent classification on fiscal and tax data. Different from the traditional static encryption method of unified processing, it realizes the differentiation and intelligence of data protection strategies.
[0064] The present invention dynamically selects the optimal encryption algorithm according to the data sensitivity level and matches the corresponding key generation method. Anti-quantum encryption combined with attribute-based encryption mechanism is used for high-sensitivity data, and symmetric encryption is used for internal and public data. The symmetric key is generated through compound chaotic mapping, which enhances the randomness and unpredictability of the key.
[0065] During the data storage process, the present invention combines a data integrity hash check mechanism to ensure that the stored ciphertext data is not tampered with during transmission and long-term storage, improving the data credibility; at the same time, it introduces searchable encryption technology. Through the encrypted index and Bloom filter protection mechanism, it supports fast retrieval of sensitive fields such as invoice numbers and amount ranges in the encrypted state, effectively solving the problem that traditional encrypted data cannot be retrieved, and taking into account both security and business availability. Description of the Drawings
[0066] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0067] Figure 1 is the flowchart of the method of the present invention;
[0068] Figure 2 is the system architecture diagram of the present invention. Specific Embodiments
[0069] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention. Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the claimed present invention, but is merely for the selected embodiments of the present invention.
[0070] Please refer to Figure 1 and Figure 2 , Figure 1 is the flowchart of an intelligent management method for fiscal and tax data based on encrypted storage provided by an embodiment of the present invention, Figure 2 is the system architecture diagram of an intelligent management system for fiscal and tax data based on encrypted storage provided by an embodiment of the present invention, including the following steps:
[0071] Step S1, collect financial and tax-related data from multiple channels through a data acquisition module, evaluate the sensitivity of the data, and divide the sensitivity levels;
[0072] S1-1, structured data acquisition. Connect external sources such as the enterprise financial system and tax system through a data interface unit based on preset data acquisition rules and interface protocols, and extract structured fiscal and tax data. The fiscal and tax data includes accounts and declaration records;
[0073] S1-2, unstructured data acquisition. Use an OCR recognition algorithm through a data recognition unit to scan and recognize unstructured fiscal and tax data such as bills and invoices, extract key fields, and convert them into a structured data format, specifically as shown in the formula:
[0074]
[0075]
[0076] Among them, I is the image input space, and T is the text output space. is the OCR recognition mapping function, and the output includes keyword fields such as invoice number, amount, and invoicing party; D is the unstructured data set generated after OCR recognition. represents the j-th text data entry extracted from the image.
[0077] S1-3, data preprocessing, call the data preprocessing unit to clean and standardize the collected raw data, filter out abnormal information and redundant information, fill in missing data, and unify the data format model, and output the normalized fiscal and tax data to ensure the integrity and consistency of the data.
[0078] S1-4, sensitivity index calculation, based on the preset sensitivity assessment model, analyze and calculate the preprocessed data to obtain the sensitivity index value of the data. The sensitivity assessment model comprehensively considers various influencing factors, including the degree of private information contained in the data, the financial value level of the data, and the strength of compliance requirements involved in the data, etc. Let the input data be denoted as D, then the sensitivity index is calculated according to the weighted model, specifically as shown in the formula:
[0079]
[0080] Among them, is the sensitivity index. represents the privacy sensitivity factor of data D. represents the value sensitivity factor of data D. represents other relevant sensitivity factors. , ,..., are the weight coefficients of the corresponding factors.
[0081] S1-5, sensitivity level classification, compare the sensitivity index S(D) calculated in step S1-4 with the preset sensitivity level threshold to determine the sensitivity level category to which the data belongs. The specific classification criteria are as follows:
[0082] The sensitivity score range is [0.8, 1.0], and the sensitivity level is top secret. The data contains supervisor-level and enterprise core fiscal and tax information, and leakage will cause major losses.
[0083] The sensitivity score range is [0.6, 0.8), and the sensitivity level is confidential. The data contains large transaction data and important tax declaration information, and leakage will cause relatively large losses.
[0084] The sensitivity score range is [0.4, 0.6), the sensitivity level is sensitive, the data includes small and medium-sized financial bills and general tax-related data, and there is a medium risk of leakage;
[0085] The sensitivity score range is [0.2, 0.4), the sensitivity level is internal, the data includes the regular financial and tax information within the enterprise, and the impact of leakage is small;
[0086] The sensitivity score range is [0.0, 0.2), the sensitivity level is public, the data includes publicly available data or data without sensitivity requirements, and no special encryption processing is required;
[0087] When S(D) falls into the corresponding interval, the data is respectively marked as top secret, confidential, sensitive, internal or public level, and the sensitivity level label is associated and stored in the metadata of the data. The sensitivity level classification result will be used as an important basis for formulating the dynamic encryption policy and configuring the key management in the subsequent step S2.
[0088] Step S2, key generation and encryption policy setting, based on the data sensitivity level, dynamically determine the appropriate encryption algorithm type and encryption parameters, and generate the corresponding key.
[0089] S2-1, according to the data sensitivity level determined in S1-5, combined with the preset encryption protection standard, select the matching encryption algorithm type and key parameters to achieve the dynamic balance between the security of data with different sensitivity levels and the system performance. The specific matching relationship is as follows:
[0090] Top secret level data: Adopt the combination of NTRU quantum-resistant encryption and attribute-based encryption (ABE). The NTRU key length is not less than 1024 bits, and the ABE strategy supports fine-grained access control;
[0091] Confidential and sensitive level data: Adopt Paillier homomorphic encryption, the public key length is not less than 2048 bits, and support data calculation and processing under ciphertext;
[0092] Internal and public level data: Adopt AES-256 symmetric encryption, the key length is 256 bits, taking into account both efficiency and security.
[0093] To support dynamic encryption and long-term compliance requirements, at the same time, preset the key update policy parameters corresponding to each sensitivity level, including the key expiration date and the maximum number of uses. Specifically:
[0094] The key of top secret level data is valid for 30 days or used no more than 100 times;
[0095] The key of confidential level data is valid for 90 days or used no more than 500 times;
[0096] The validity period of sensitive data keys is 180 days or they may be used no more than 1,000 times;
[0097] Internal-level data keys are valid for 365 days or may be used no more than 3,000 times;
[0098] The public level data can flexibly set the key update strategy according to needs.
[0099] S2-2, key generation, calling the key generation mechanism of the key management unit, generating the encryption key K according to the selected algorithm and parameters, and using a cryptographically secure random number algorithm to ensure the randomness and uniqueness of the key;
[0100] In the case of symmetric encryption, a secure random number generator is used to generate a key of the required length in step S2-1; in the case of asymmetric encryption, a public key and a private key pair of corresponding strength are generated. The generated key should meet the security strength requirements and match the data sensitivity level.
[0101] S2-3, key storage, securely saves the generated key K in the key library of the key management module, and establishes a mapping relationship between the key identifier and the data sensitivity level. During the key storage process, the key is re-encrypted or assisted by a hardware security module to prevent key leakage. The key generation time, applicable data range, validity period and other metadata are recorded to provide support for subsequent dynamic updates.
[0102] The formulated encryption strategy and key information are output and passed to the encryption storage module. The encryption strategy includes the selected algorithm type, key identifier, key validity period strategy, etc., providing a basis for subsequent data encryption execution.
[0103] Step S3, data encryption and storage, uses the obtained key and encryption strategy to encrypt the financial and tax data and store the ciphertext securely.
[0104] S3-1, call the encryption algorithm module, use the key K generated in step S2 to perform encryption operation on the financial and tax data classified in step S1, and obtain the corresponding ciphertext data C. The encryption process is strictly executed in accordance with the algorithm and parameters set in step S2 to ensure that the encryption strength meets the requirements;
[0105] For large amounts of data, block encryption and other technologies are used to ensure the efficiency of the encryption process, but the final encryption result should completely cover the original data. After the encryption is completed, the ciphertext data C and related metadata, including data identification, sensitivity level and key identification, are packaged and sent to the storage unit.
[0106] S3-2. Receive the ciphertext data C from the encryption unit and write it into a secure data storage medium. During the storage process, hierarchical management is carried out in combination with the sensitivity level of the data, as follows:
[0107] For data at the top-secret level, store it in a highly secure storage medium with physical isolation capabilities, namely, the memory of the trusted execution environment and the hardware encryption disk;
[0108] For data at the confidential level, store it in an encrypted independent partition or a dedicated encrypted disk volume, and adopt an independent access control policy;
[0109] For data at the sensitive level, store it in a secure partition with standard data encryption enabled, namely, the AES encrypted disk;
[0110] For data at the internal level, store it in a standard storage medium protected by conventional security measures and restrict access through access control;
[0111] For data at the public level, it can be stored in ordinary storage space without special encryption processing, but access logs are still recorded.
[0112] Through the above hierarchical storage strategy, different security measures are taken according to the data sensitivity level at the physical storage level, thereby further enhancing the overall security and protection intensity of the data in the static storage state.
[0113] S3-3. Record the meta-information corresponding to the ciphertext data, including data identification, sensitivity level, key identification (or public key identification) used for encryption, and encryption timestamp, etc. Establish an index or mapping table in the storage medium, and associate and save the above meta-information with the ciphertext data to facilitate subsequent retrieval, decryption, and key update management. This meta-information record ensures that the system can quickly locate the key according to the data identification and perform decryption or re-encryption operations.
[0114] Verify the integrity and availability of the ciphertext data in the storage medium to ensure that the data is successfully written and can be retrieved.
[0115] Step S4. Data access and dynamic encryption maintenance. Provide a controlled encrypted data access service and perform dynamic security maintenance on the stored data according to a predetermined policy.
[0116] S4-1. The system verifies whether the identity credentials provided by the requester are legal and valid. Adopt username / password verification and combine multi-factor authentication mechanisms to improve the authentication strength. Only the principal who passes the identity authentication can enter the subsequent authorization check process.
[0117] It should be noted that the multi-factor authentication mechanisms include: time-based one-time password (TOTP) authentication, hardware encryption key authentication (such as tax UKey), biometric authentication (such as fingerprint, face recognition), etc.
[0118] S4-2. Perform permission verification on the authenticated access request to verify whether the requester has the access permission corresponding to the sensitivity level of the requested data. The system compares the requester's permission level with the sensitivity level of the target data according to the pre-set permission policy. If the permission level meets the requirements, decrypted access is allowed; otherwise, the request is rejected and the illegal access attempt is recorded.
[0119] S4-3. For the requests authorized to pass, extract the corresponding ciphertext data C and its meta-information from the data storage medium. The system determines the data key (or the corresponding private key) for decryption according to the meta-information, and then calls the decryption algorithm module to perform a decryption operation on C using the correct key to recover the original plaintext data D. During the decryption process, verify the data integrity and correctness to ensure that the decryption result is consistent with that before encryption.
[0120] S4-4. Provide the decrypted plaintext data to the requester for use, and record and audit this data access. The recorded content includes the visitor's identity, the access data identifier, the sensitivity level, the access time, and the key identifier used for decryption, etc., for security audit and future traceability.
[0121] S4-5. The system continuously monitors the encryption status of the stored data, and triggers the key update process regularly or under specific conditions according to the key validity period or usage times policy set in step S2. When the key update condition is reached, perform the following operations on the corresponding data: First, the key management module generates a new encryption key K', that is, re-execute a process similar to step S2-2, but generate a new key; then use the old key K to decrypt the existing ciphertext data C to obtain the plaintext data D; then use the new key K' to re-encrypt D according to step S3-1 to obtain a new ciphertext C'; finally, replace the original stored C with C', and update the key identifier and encryption time in the meta-information. During the update process, the new key K' and its metadata are synchronously stored in the key library, and the old key K is marked as invalid and cannot be used again. Through the above dynamic key update mechanism, ensure that the data stored for a long time continuously meets the security requirements and reduce the risk of key leakage.
[0122] The present invention also provides an intelligent management system for financial and tax data based on encrypted storage, including:
[0123] A data classification module, a key management and encryption policy module, a data encrypted storage module, and a data access and dynamic encryption maintenance module.
[0124] The data classification module is used to perform sensitivity analysis and classification on financial and tax data, and this module includes: a data acquisition unit, a sensitivity analysis unit, and a classification unit;
[0125] A data acquisition unit, which is used to collect original fiscal and tax data and input the collected data into a data classification module for processing; a sensitivity analysis unit, which is used to calculate the sensitivity index of the fiscal and tax data according to a preset sensitivity evaluation model; a classification unit, which is used to divide the fiscal and tax data into corresponding sensitivity levels according to the sensitivity index and provide the classification result to subsequent modules.
[0126] A key management and encryption policy module, which is used to generate encryption keys and formulate encryption policies according to the data sensitivity level. This module includes: a key generation unit, a policy setting unit, and a key storage unit;
[0127] The key generation unit is used to generate encryption keys according to the selected algorithm type and parameters to ensure that the keys meet the security strength requirements; the policy setting unit is used to determine parameters such as the encryption algorithm type, key length, and key update policy of the data; the key storage unit is used to securely store the generated keys and maintain the mapping relationship between the keys and the data sensitivity level as well as the key life cycle information.
[0128] A data encryption storage module, which is used to perform encryption operations on fiscal and tax data and manage the storage of the encrypted data. This module includes: an encryption execution unit and a data storage unit;
[0129] The encryption execution unit is used to call the selected encryption algorithm to encrypt the fiscal and tax data and generate corresponding ciphertext data; the data storage unit is used to store the encrypted ciphertext data and save the meta-information associated with the ciphertext data to support subsequent data retrieval, decryption, and key update operations.
[0130] A data access and dynamic encryption maintenance module, which is used to control the access and decryption of encrypted data and perform dynamic encryption maintenance. This module includes: an identity authentication unit, a permission control unit, a data extraction unit, a data decryption unit, a dynamic maintenance unit, and an audit unit;
[0131] The identity authentication unit is used to authenticate the data access requester to ensure that it is a legitimate user; the permission control unit is used to verify whether the requester who has passed the identity authentication has the access permission corresponding to the sensitivity level of the target data; the data extraction unit is used to retrieve the ciphertext of the requested fiscal and tax data and its related meta-information from the storage medium; the data decryption unit is used to call the decryption algorithm to decrypt the retrieved ciphertext data with the correct key to restore the original plaintext data; the dynamic maintenance unit is used to monitor the key usage status according to the predetermined encryption policy and regularly trigger key updates and perform data re-encryption operations; the audit unit is used to record and monitor key events during the data access process, including information such as the visitor's identity, access time, accessed data identifier, and operation results, to support security audits and anomaly tracing.
[0132] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, various modifications and variations can be made to the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. An intelligent management method for fiscal and tax data based on encrypted storage, characterized in that, It includes the following steps: Step S1: Collect financial and tax-related data from multiple channels through a data acquisition module, evaluate the sensitivity of the data, and divide the sensitivity levels. Step S2: Generate keys and set encryption policies. Based on the data sensitivity levels, dynamically determine the appropriate encryption algorithm type and encryption parameters, and generate corresponding keys. Step S3: Encrypt and store the data. Use the obtained keys and encryption policies to encrypt the financial and tax data, and securely store the ciphertext. Step S4: Data access and dynamic encryption maintenance. Provide a controlled encrypted data access service, and perform dynamic security maintenance on the stored data according to predetermined policies.
2. A method for intelligent management of financial and tax data based on encrypted storage according to claim 1, characterized in that: In step S1, it further includes the following sub-steps: S1-1: Connect to the external sources of the enterprise financial system and tax system through a data interface unit based on preset data collection rules and interface protocols, and extract structured financial and tax data, where the financial and tax data includes accounts and declaration records. S1-2: Use an OCR recognition algorithm through a data recognition unit to scan and recognize the unstructured financial and tax data of bills and invoices, extract key fields and convert them into a structured data format, specifically as shown in the formula: ; ; Among them, I is the image input space, and T is the text output space. is the OCR recognition mapping function; D is the unstructured data set generated after OCR recognition. represents the j-th text data entry extracted from the image. S1-3: Invoke a data preprocessing unit to clean and standardize the collected raw data, filter out abnormal information and redundant information, fill in missing data, and unify the data format model, and output standardized financial and tax data. S1-4: Based on a preset sensitivity evaluation model, analyze and calculate the preprocessed data to obtain the sensitivity index value of the data. The sensitivity evaluation model comprehensively considers various influencing factors, including the degree of private information contained in the data, the financial value level of the data, and the intensity of compliance requirements involved in the data. Let the input data be denoted as D, then the sensitivity index is calculated according to the weighted model, specifically as shown in the formula: ; Among them, represents the privacy sensitivity factor of data D, represents the value sensitivity factor of data D, represents other relevant sensitivity factors, , ,..., are the weight coefficients of the corresponding factors; S1-5: Sensitivity level division. Compare the sensitivity index S(D) calculated in step S1-4 with the preset sensitivity level threshold to determine the sensitivity level category to which the data belongs. The specific division criteria are as follows: The sensitivity score range is [0.8, 1.0], and the sensitivity level is top secret. The data contains supervisor-level and enterprise core financial and tax information, and leakage will cause significant losses. The sensitivity score range is [0.6, 0.8), and the sensitivity level is confidential. The data contains large transaction data and important tax declaration information, and leakage will cause relatively large losses. The sensitivity score range is [0.4, 0.6), and the sensitivity level is sensitive. The data contains small and medium-sized financial bills and general tax-related data, and there is a medium risk of leakage. The sensitivity score range is [0.2, 0.4), and the sensitivity level is internal. The data contains regular financial and tax information within the enterprise, and leakage has little impact. The sensitivity score range is [0.0, 0.2), and the sensitivity level is public. The data contains publicly available or data without sensitivity requirements, and no special encryption processing is required.
3. A method for intelligent management of financial and tax data based on encrypted storage according to claim 1, characterized in that: In step S2, the following sub-steps are further included: S2-1. According to the data sensitivity level determined in S1-5 and in combination with the preset encryption protection standard, select a matching encryption algorithm type and key parameters to achieve a dynamic balance between the security and system performance of data with different sensitivity levels. The specific matching relationships are as follows: For data at the top-secret level, use NTRU quantum-resistant encryption combined with ABE attribute-based encryption. The NTRU key length is not less than 1024 bits, and the ABE policy supports fine-grained access control; For data at the confidential and sensitive levels, use Paillier homomorphic encryption. The public key length is not less than 2048 bits, and it supports data calculation and processing under ciphertext; For internal and public-level data, use AES-256 symmetric encryption. The key length is 256 bits, taking into account both efficiency and security; S2-2. Invoke the key generation mechanism of the key management unit to generate an encryption key K according to the selected algorithm and parameters. The key generation uses a cryptographically secure random number algorithm; In the case of symmetric encryption, use a secure random number generator to generate a key that meets the length requirements of step S2-1; in the case of asymmetric encryption, generate a public and private key pair of corresponding strength. The generated key should meet the security strength requirements and match the data sensitivity level; S2-3. Securely store the generated key K in the key library of the key management module, and establish a mapping relationship between the key identifier and the data sensitivity level. During the key storage process, the key is encrypted twice, and metadata such as the key generation time, applicable data range, and expiration date are recorded.
4. A method for intelligent management of fiscal and tax data based on encrypted storage according to claim 1, characterized in that: In step S3, the following sub-steps are further included: S3-1. Invoke the encryption algorithm module to perform an encryption operation on the fiscal and tax data classified in step S1 using the key K generated in step S2 to obtain the corresponding ciphertext data C. During the encryption process, strictly execute according to the algorithm and parameters set in step S2 to ensure that the encryption strength meets the requirements; For the case of a large amount of data, use technologies such as block encryption to ensure the efficiency of the encryption process, but the final encryption result should completely cover the original data. After encryption, package the ciphertext data C and related metadata, where the related metadata includes data identifiers, sensitivity levels, and key identifiers, and send them to the storage unit; S3-2. Receive the ciphertext data C from the encryption unit and write it into a secure data storage medium. During the storage process, perform hierarchical management in combination with the sensitivity level of the data, as follows: For data at the top-secret level, store it in a highly secure storage medium with physical isolation capabilities, namely, the memory of a trusted execution environment and a hardware encrypted disk; For data at the confidential level, store it in an encrypted independent partition or a dedicated encrypted disk volume, and adopt an independent access control policy; For data at the sensitive level, store it in a secure partition with standard data encryption enabled, namely, an AES encrypted disk; For data at the internal level, store it in a standard storage medium protected by conventional security measures and restrict access through access control; For publicly graded data, it can be stored in ordinary storage space without special encryption, but access logs are still recorded; S3-3. Record the meta-information corresponding to the ciphertext data, including data identification, sensitivity level, key identification used for encryption, and encryption timestamp. Establish an index in the storage medium and associate and save the above meta-information with the ciphertext data for subsequent retrieval, decryption, and key update management. This meta-information record ensures that the system can quickly locate the key based on the data identification and perform decryption.
5. The intelligent management method for fiscal and tax data based on encrypted storage according to claim 1, characterized in that: In step S4, the following sub-steps are further included: S4-1. The system verifies whether the identity credentials provided by the requester are legal and valid, uses username / password verification combined with a multi-factor authentication mechanism to improve the authentication strength, and only the subject that passes the identity authentication can enter the subsequent authorization check process; S4-2. Perform permission verification on the access request that has passed the authentication, and check whether the requester has the access permission corresponding to the sensitivity level of the requested data. The system compares the permission level of the requester with the sensitivity level of the target data according to the pre-set permission policy; If the permission level meets the requirements, decrypt and access are allowed; otherwise, the request is rejected and the illegal access attempt is recorded; S4-3. For the request that has passed the authorization, extract the corresponding ciphertext data C and its meta-information from the data storage medium. The system determines the data key used for decryption according to the meta-information, then calls the decryption algorithm module, and uses the correct key to perform decryption operation on C to restore the original plaintext data D; during the decryption process, verify the data integrity and correctness to ensure that the decryption result is the same as before encryption; S4-4. Provide the decrypted plaintext data to the requester for use, and record and audit the current data access. The recorded content includes the visitor's identity, accessed data identification, sensitivity level, access time, and key identification used for decryption for security audit and future traceability; S4-5. The system continuously monitors the encryption status of the stored data. According to the key validity period and usage times policy set in step S2, trigger the key update process under specific conditions. When the key update condition is reached, perform the following operations on the corresponding data: First, the key management module generates a new encryption key K', that is, re-execute a process similar to step S2-2, but generate a new key; then use the old key K to decrypt the existing ciphertext data C to obtain the plaintext data D; then use the new key K' to re-encrypt D according to step S3-1 to obtain a new ciphertext C'; finally, replace the original stored C with C', and update the key identification and encryption time in the meta-information; during the update process, the new key K' and its metadata are synchronously stored in the key library, and the old key K is marked as invalid and cannot be used again.
6. An intelligent management system for fiscal and tax data based on encrypted storage, which is applied to an intelligent management method for fiscal and tax data based on encrypted storage according to any one of claims 1-5, characterized in that Including: Data classification module, key management and encryption policy module, data encrypted storage module, data access and dynamic encryption maintenance module; The data classification module is used to perform sensitivity analysis and classification on fiscal and tax data. This module includes: data acquisition unit, sensitivity analysis unit, and classification unit; A data acquisition unit for collecting original fiscal and tax data and inputting the collected data into a data classification module for processing; a sensitivity analysis unit for calculating the sensitivity index of the fiscal and tax data according to a preset sensitivity evaluation model; a classification unit for classifying the fiscal and tax data into corresponding sensitivity levels according to the sensitivity index and providing the classification result to subsequent modules; A key management and encryption policy module for generating encryption keys and formulating encryption policies according to the data sensitivity level. This module includes: a key generation unit, a policy setting unit, and a key storage unit; The key generation unit is used to generate encryption keys based on the selected algorithm type and parameters to ensure that the keys meet the security strength requirements; the policy setting unit is used to determine parameters such as the encryption algorithm type, key length, and key update policy of the data; the key storage unit is used to securely store the generated keys and maintain the mapping relationship between the keys and the data sensitivity level as well as the key lifecycle information; A data encryption storage module for performing encryption operations on fiscal and tax data and storing and managing the encrypted data. This module includes: an encryption execution unit and a data storage unit; The encryption execution unit is used to call the selected encryption algorithm to encrypt the fiscal and tax data to generate corresponding ciphertext data; the data storage unit is used to store the encrypted ciphertext data and save the meta-information associated with the ciphertext data to support subsequent data retrieval, decryption, and key update operations; A data access and dynamic encryption maintenance module for controlling the access and decryption of encrypted data and performing dynamic encryption maintenance. This module includes: an identity authentication unit, a permission control unit, a data extraction unit, a data decryption unit, a dynamic maintenance unit, and an audit unit; The identity authentication unit is used to authenticate the data access requester to ensure that it is a legitimate user; the permission control unit is used to verify whether the requester who has passed the identity authentication has the access permission corresponding to the sensitivity level of the target data; the data extraction unit is used to retrieve the ciphertext of the requested fiscal and tax data and its related meta-information from the storage medium; the data decryption unit is used to call the decryption algorithm to decrypt the retrieved ciphertext data with the correct key to restore the original plaintext data; the dynamic maintenance unit is used to monitor the key usage status according to the predetermined encryption policy and periodically trigger key updates and perform data re-encryption operations; the audit unit is used to record and monitor key events during the data access process, including information such as the identity of the visitor, access time, accessed data identifier, and operation results, to support security audits and anomaly tracing.
Citation Information
Patent Citations
Data encryption management system and data encryption method
CN118153081A
Information encryption system and method based on cloud computing
CN118400166A
Accounting file data management method and system and storage medium
CN119989403A
Attribute-based encryption for selective document content protection
EP4557144A1
A system that verifies user access to the central authorization server and manages access to internal resources
KR102690046B1
Cited By
Multi-storage financial image centralized management method, device, equipment and medium
CN120873216A
Method and device for processing medical health care data
CN120951353A
Sensitive data processing method and device, equipment and storage medium
CN120951391A
Intelligent ERP financial system data security management and authentication method
CN121167793A
Data management method and device, storage medium and terminal
CN121615190A