Security protection method and electronic equipment
By determining the sensitivity level of the business module in the data platform and dynamically matching the security protection strategy, the problem that traditional security protection methods are difficult to meet the security needs of the data platform is solved, and more efficient and accurate security protection is achieved.
Patent Information
- Application Number
- CN202510429356.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-07
- Publication Date
- 2025-07-08
AI Technical Summary
Traditional security protection methods are difficult to meet the security needs of data middle platforms in complex network environments, especially in the case of explosive growth in data volume and increasing security threats, it is difficult to achieve timely and effective security protection for business modules.
By determining the sensitivity level of the business module in the data, and dynamically matching the corresponding security protection policies based on this level, including multi-level authentication and policy adaptive adjustment, adaptive security protection for business access requests is achieved.
It improves the security of each business module of the data middle platform, shortens the security protection certification time, improves protection efficiency, adapts to the real-time needs of different business scenarios, and achieves accurate security protection.
Smart Images

Figure CN120277719A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data security. Specifically, it relates to a security protection method and an electronic device. Background Art
[0002] In the wave of digital transformation, the amount of enterprise data has grown explosively. As the core hub of enterprise data, the data middle platform undertakes the processing and analysis tasks of various business data. Therefore, the security of the data middle platform is of crucial importance. Summary of the Invention
[0003] Embodiments of this application at least provide a security protection method and an electronic device, which can improve the security of data.
[0004] In a first aspect, an embodiment of this application provides a security protection method, including:
[0005] After detecting a service access request, determining a first sensitivity level of a target service module in the data middle platform corresponding to the service access request; wherein, the data middle platform includes multiple service modules, and each service module determines a corresponding sensitivity level according to the importance of the service it executes;
[0006] Determining a first security protection policy that matches based on the first sensitivity level of the target service module;
[0007] Performing security protection authentication on the service access request according to the first security protection policy, and executing the service access request when the security protection authentication passes.
[0008] In the above embodiment, by perceiving the first security protection policy of the service module through the importance of the service executed by the service module (i.e., the first sensitivity level), the adaptive perception of the security protection policy can be realized, so that a suitable security protection policy can be matched in a timely and effective manner, thereby greatly improving the security of each service module.
[0009] In an optional embodiment, after determining the first security protection policy that matches based on the first sensitivity level, the method further includes:
[0010] If it is monitored that the first sensitivity level of the target service module is updated to a second sensitivity level, determining a second security protection policy that matches the second sensitivity level;
[0011] Updating the security protection policy of the target service module to the second security protection policy.
[0012] Through the above processing method, the change of the sensitivity level can be automatically sensed, so as to automatically match the most appropriate security protection policy, and then can be timely and effectively switched to the appropriate security protection policy, further ensuring the security of the service module.
[0013] In an alternative implementation manner, the method further includes:
[0014] After updating the security protection policy of the service module to the second security protection policy, detect whether the first security protection policy is in the process of execution;
[0015] If the first security protection policy is in the process of execution, interrupt the execution of the first security protection policy, and perform security protection authentication on the service access request according to the second security protection policy.
[0016] Through the above processing method, unnecessary authentication operations can be avoided, thereby shortening the time of security protection authentication and improving the efficiency of security protection authentication.
[0017] In an alternative implementation manner, before determining that the first sensitivity level of the target service module is updated to the second sensitivity level, the method further includes:
[0018] In the case where the importance degree of the service data processed by the target service module changes, determine the sensitivity level matching the importance degree of the data to obtain the second sensitivity level;
[0019] Update the first sensitivity level to the second sensitivity level.
[0020] Through the above processing method, the sensitivity levels of the service module, service operations, and service data can be updated adaptively, and then the sensitivity levels can be updated in a timely manner, saving a large amount of manual operations.
[0021] In an alternative implementation manner, after releasing the service access request to the service module, the method further includes:
[0022] During the execution of the service operation corresponding to the service access request, identify the sensitivity level of the service operation and / or the service data corresponding to the service operation to obtain the third sensitivity level; the third sensitivity level is used to indicate the importance degree of the service operation and / or the service data;
[0023] Based on the third sensitivity level, determine the matching third security protection policy, and perform authentication on the service operation according to the third security protection policy.
[0024] Through the above processing method, the security protection policy can be automatically determined for business modules with finer granularity, so that the security protection policy can be adaptively switched from large business modules to fine-grained sensitive operations.
[0025] In an optional implementation manner, the security protection authentication of the service access request according to the first security protection policy includes:
[0026] Determine multiple authentication methods indicated by the first security protection policy, and determine the authentication order of the multiple authentication methods;
[0027] Perform multi-level security protection authentication on the service access request according to the authentication order.
[0028] Through the above processing method, the authentication order can be set according to the own requirements and real-time requirements of each business module, so as to be applicable to more business scenarios.
[0029] In an optional implementation manner, the method further includes: before detecting the service access request, evaluate the sensitivity level of the target business module to obtain a first sensitivity level; and establish an association relationship between the first sensitivity level and a preset security protection policy that matches;
[0030] The determining the first security protection policy that matches based on the first sensitivity level of the target business module includes: determining a preset security protection policy that matches the first sensitivity level based on the association relationship to obtain the first security protection policy.
[0031] In the above implementation manner, by the method of pre-customizing the security protection policy for the business module according to the sensitivity level of the business module, the determination process of the security protection policy can be shortened, thereby saving the determination time of the security protection policy, and further meeting the business scenarios with better real-time performance.
[0032] In an optional implementation manner, the determining the first security protection policy that matches based on the first sensitivity level of the target business module includes:
[0033] Obtain the module attribute information of the target business module;
[0034] Determine a target authentication method that matches the module attribute information and the first sensitivity level among multiple preset authentication methods;
[0035] Combine the target authentication methods to obtain the first security protection policy.
[0036] Through the above implementation manners, corresponding security protection policies can be customized for business modules, and then a more highly matched security protection policy can be determined for each business module, thereby achieving precise protection for each business module.
[0037] In an alternative implementation manner, determining a first security protection policy that matches based on the first sensitivity level of the target business module includes:
[0038] Determine the request sending location of the service access request;
[0039] Determine the location risk level of the request sending location;
[0040] Based on the location risk level and the first sensitivity level, determine the first security protection policy of the target business module.
[0041] Through the above processing method, the security protection policy of the business module can be determined from more dimensions, so as to determine a more matching security protection policy for the business module, and further improve the security of each business module.
[0042] In a second aspect, an embodiment of the present application further provides an electronic device, including: a processor, a memory, and a bus. The memory stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the memory through the bus. When the machine-readable instructions are executed by the processor, the steps in the first aspect, or any possible implementation manner in the first aspect are executed.
[0043] The embodiment of the present application provides a security protection method and an electronic device. In the embodiment of the present application, after detecting a service access request, the first sensitivity level of the target business module corresponding to the service access request in the data middle platform can be determined, where the data middle platform includes multiple business modules, and each business module determines the corresponding sensitivity level according to the importance of the executed service; then, based on the first sensitivity level of the target business module, a first security protection policy that matches is determined. Next, the service access request can be authenticated for security protection through the first security protection policy, and when the security protection authentication passes, the service access request is executed.
[0044] In the above implementation manner, the method of perceiving the first security protection policy of the business module through the importance of the service executed by the business module (that is, the first sensitivity level) can realize the adaptive perception of the security protection policy, so that a suitable security protection policy can be matched in a timely and effective manner, thereby improving the security of each business module.
[0045] To make the above objects, features, and advantages of the present application more apparent and understandable, the following presents preferred embodiments in conjunction with the accompanying drawings and provides a detailed description as follows. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] To more clearly illustrate the technical solutions of the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments. The accompanying drawings are incorporated into the specification and form a part of this specification. These drawings illustrate embodiments consistent with the present application and, together with the specification, are used to explain the technical solutions of the present application. It should be understood that the following drawings only illustrate certain embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0047] Figure 1 Shows a flowchart of a security protection method provided by an embodiment of the present application;
[0048] Figure 2 Shows a system architecture diagram of a security protection system provided by an embodiment of the present application;
[0049] Figure 3 Shows a structural schematic diagram of a security protection component provided by an embodiment of the present application;
[0050] Figure 4 Shows a process schematic diagram of a security protection system provided by an embodiment of the present application;
[0051] Figure 5 Shows a process schematic diagram of another security protection method provided by an embodiment of the present application;
[0052] Figure 6 Shows a schematic diagram of a security protection device provided by an embodiment of the present application;
[0053] Figure 7 Shows a schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0054] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Apparently, the described embodiments are only a part rather than all of the embodiments of this application. Components of the embodiments of this application usually described and illustrated in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely represents selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative efforts fall within the scope of protection of this application.
[0055] It should be noted that like reference numerals and letters denote like items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0056] The term "and / or" in this document merely describes an associated relationship and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the term "at least one" in this document means any one of multiple or any combination of at least two of multiple. For example, including at least one of A, B, and C may represent including any one or more elements selected from the set composed of A, B, and C.
[0057] A data middle platform refers to collecting, calculating, storing, and processing a large amount of data through data technology while unifying standards and calibers. After the data is unified in the data middle platform, standard data will be formed and then stored to form a big data asset layer, and then provide efficient services for customers.
[0058] With the complex and changeable network environment and the increasing security threats, traditional security protection means are difficult to meet the enterprise's requirements for data security. Therefore, constructing a security protection method based on the adaptability of the data middle platform is of great significance for protecting the security of enterprise data assets and improving business operation efficiency.
[0059] An embodiment of the present application provides a security protection method and an electronic device. In the embodiment of the present application, after detecting a service access request, the first sensitivity level of the target service module corresponding to the service access request in the data middle platform can be determined, where the data middle platform includes multiple service modules, and each service module determines the corresponding sensitivity level according to the importance of the service it executes; then, based on the first sensitivity level of the target service module, a matching first security protection policy is determined. Next, the service access request can be authenticated for security protection through the first security protection policy, and when the security protection authentication passes, the service access request is executed.
[0060] In the above implementation manner, the method of perceiving the first security protection policy of the service module through the importance of the service executed by the service module (i.e., the first sensitivity level) can realize the adaptive perception of the security protection policy, so that a suitable security protection policy can be matched in a timely and effective manner, thereby improving the security of each service module.
[0061] To facilitate the understanding of this embodiment, first, a security protection method disclosed in the embodiment of the present application will be introduced in detail. The execution subject of the security protection method provided in the embodiment of the present application is generally an electronic device with a certain computing ability, such as a server or a terminal, etc. In some possible implementation manners, the security protection method can be implemented by a processor calling computer-readable instructions stored in a memory.
[0062] See Figure 1 As shown, it is a flowchart of a security protection method provided by an embodiment of the present application. This security protection method is applied to a security protection component, and this security protection component can be deployed in an electronic device. The method includes steps S101 to S103, where:
[0063] S101: After detecting a service access request, determine the first sensitivity level of the service module corresponding to the service access request in the data middle platform; where the data middle platform includes multiple service modules, and each service module determines the corresponding sensitivity level according to the importance of the service it executes.
[0064] In the embodiment of the present application, the sensitivity level of the service module can be determined by the importance of the service data processed by the service module. Generally, the sensitivity level can be divided into four levels: unimportant, general, important, and particularly important.
[0065] For example, the types of business data corresponding to "specially important" include: user data, financial data, geospatial data, credit data, policy and regulation data, etc.; the types of business data corresponding to "important" include: government service data, enterprise operation data, etc.; the types of business data corresponding to "general" include: ordinary government service data, log data, etc.; the types of business data corresponding to "unimportant" include: knowledge-based data, dynamic information data, temporary data, etc.
[0066] Here, after detecting a business access request of a user for a business module, the security protection component can determine the first sensitivity level of the corresponding target business module.
[0067] S102: Determine a matching first security protection policy based on the first sensitivity level of the target business module.
[0068] In the embodiment of the present application, a first security protection policy matching the target business module can be determined based on the first sensitivity level. Among them, the first security protection policy can be a pre-set policy or a policy adaptively generated according to the first sensitivity level.
[0069] Specifically, a security protection policy matching the first sensitivity level can be determined, and then the first security protection policy can be determined according to the matching security protection policy. In addition, at least one authentication method can be screened from multiple pre-set authentication methods, and the at least one authentication method can be combined according to a preset method to obtain the first security protection policy.
[0070] For example, for the first sensitivity level "specially important", the first security protection policy can be determined as: authentication methods such as fingerprint, face recognition, dynamic token, one-time password, etc. For the first sensitivity level "important", the first security protection policy can be determined as: authentication methods such as face recognition, verification code, static password, etc. For the first sensitivity level "general", the first security protection policy can be determined as: an authentication method implementing a username and password mode, where the password length is required to be more than 8 digits, including two of uppercase and lowercase letters, numbers, and symbols, and two-factor authentication is implemented in combination with a text message verification code or a dynamic password. For the first sensitivity level "unimportant", the first security protection policy can be determined as: an authentication method of username and password, where the password complexity can be reduced.
[0071] S103: Perform security protection authentication on the business access request according to the first security protection policy, and execute the business access request when the security protection authentication is passed.
[0072] In the embodiments of the present application, after determining the first security protection policy, at least one level of security protection authentication can be performed on the service access request through at least one authentication method indicated by the first security protection policy, so as to obtain an authentication result. Among them, if the authentication result of each authentication method is authentication passed, it is determined that the security protection authentication for the service access request is passed. At this time, the security protection component releases the service access request to the target service module, thereby allowing the service access request to access the corresponding service module.
[0073] The following combines Figure 2 and Figure 3 to introduce the architecture of the security protection component. As Figure 2 shown is the system architecture diagram of the security protection system. As Figure 2 shown, the security protection system includes a data middle platform and a security protection component.
[0074] In the embodiments of the present application, as a separate component, the security protection component can be integrated into each service module of the data middle platform, so that the security protection policy can be adaptively switched from large service modules to fine-grained sensitive operations. In the technical solution of the present application, the security protection component can be easily integrated into each service module, so the integration of the service protection component has little impact on the operation of each service module.
[0075] For example, as Figure 2 shown, the service module can be an API service platform, a data desensitization platform, and a subscription and push platform in the data service system. The service module can also be data standards and label management in the data asset center. The service module can also be modules such as a data integration platform, an Internet collection platform, and a sharing and exchange platform in the data integration system.
[0076] In the embodiments of the present application, the sensitivity level of each service module can be obtained by the service importance evaluation module in the security protection component evaluating the importance degree of the service data processed by each service module, so that the security protection policy module in the security protection component gives a corresponding security protection policy according to the sensitivity level.
[0077] For example, asset management in the data asset center is mainly used to manage users' asset data. Since there is a lot of sensitive data involved in the asset data, at this time, it is determined that the importance degree of the service data processed by this asset management is relatively high. At this time, the sensitivity level can be determined as "especially important". Through this sensitivity level, multiple authentication methods can be selected from authentication methods such as fingerprints, face recognition, dynamic tokens, and one-time passwords for authentication.
[0078] For example, in the data service system, the API service platform is used to manage various API interfaces. Therefore, the confidentiality level of the API service platform is relatively high. At this time, the business data processed by the API service platform is of high importance. At this time, the sensitivity level can be determined as "particularly important". Based on this sensitivity level, multiple authentication methods can be selected for authentication, such as fingerprint, face recognition, dynamic token, one-time password, etc.
[0079] like Figure 3 The figure shows the structure diagram of the safety protection component. Figure 3 As shown, the security protection component includes: a business importance assessment module, a security protection policy module, a policy execution engine module, a log / audit module and a database DB.
[0080] The business importance assessment module is used to provide sensitivity levels for business modules, business operations and business data, and can assign sensitivity levels to each business module or business operation in the data center.
[0081] The security protection strategy module can match the appropriate security protection strategy according to the sensitivity level generated by the business importance assessment module. For example, multiple authentication methods and access control strategies can be pre-defined in the security protection strategy module, and the security protection strategy can be obtained by customizing the combination of multiple authentication methods and access control strategies.
[0082] The policy execution engine module is used to execute a specific security authentication process according to the configured security protection policy. The specific security authentication process integrates multiple authentication methods: face recognition, fingerprint, account password, U shield, SIM card, verification code, dynamic token, verification code, etc.
[0083] The log / audit module records comprehensive log records for the business importance assessment module, security protection policy module, and policy execution engine module.
[0084] The database DB is used to store data related to security protection components, such as business importance reports, log records, and security protection strategies.
[0085] The above steps will be described in detail below in conjunction with specific implementation methods.
[0086] It can be seen from the above description that after detecting a business access request, the security protection component can determine the first sensitivity level of the target business module corresponding to the business access request in the data center.
[0087] In an embodiment of the present application, a business importance assessment report of the target business module can be searched in a database, so as to determine a first sensitivity level of the target business module in the business importance assessment report; wherein, the latest sensitivity level of the target business module is recorded in the business importance assessment report, for example, the first sensitivity level.
[0088] Here, the first sensitivity level recorded in the business importance assessment report can be obtained through the following methods:
[0089] Method 1: Relevant technical personnel can determine the sensitivity level of the corresponding target business module in real time according to the actual business content of each business module and store it in the database.
[0090] Method 2: The data type of the business data processed by the target business module can be determined, and then the relative importance of the data can be determined according to the data type. For example, the importance of financial data is particularly important. At this time, the first sensitivity level of the target business module can be determined according to the data importance, for example, determined as "particularly important"; then, the business importance assessment report for recording the first sensitivity level is stored in the database.
[0091] In addition to searching for the first sensitivity level in the business importance assessment report, for scenarios with relatively low real-time requirements, after detecting a business access request, the first sensitivity level of the target business module can also be directly determined through the importance degree of the business data processed by the target business module.
[0092] Through the above processing methods, it is possible to determine the sensitivity level of the business module automatically or manually, so as to meet more business scenarios and meet more scenario requirements.
[0093] In an embodiment of the present application, after determining the first sensitivity level of the target business module, a first security protection policy matching the first sensitivity level of the target business module can be determined. Several methods for determining the first security protection policy will be introduced below.
[0094] In an alternative embodiment, the method further includes the following steps:
[0095] Before detecting the business access request, evaluate the sensitivity level of the target business module to obtain a first sensitivity level; and establish an association relationship between the first sensitivity level and a preset security protection policy that matches.
[0096] In the embodiments of the present application, the sensitivity level of the target service module can be evaluated in the manner described in the above-mentioned Method 1 and Method 2 to obtain the first sensitivity level; then, the preset security protection policies matching the first sensitivity level can be screened from the preset security protection policies; after that, the association relationship between the first sensitivity level and the preset security protection policies can be established and stored in the database.
[0097] Here, it should be noted that the sensitivity levels of each service module are not fixed and can be adjusted manually or automatically according to actual business needs. The first sensitivity level can be understood as the latest sensitivity level obtained by evaluating the target service module.
[0098] Based on this, the above steps determine the first security protection policy matching the first sensitivity level of the target service module, specifically including:
[0099] Based on the association relationship, determine the preset security protection policy matching the first sensitivity level to obtain the first security protection policy.
[0100] In the embodiments of the present application, the association relationship can be searched in the database, and then, according to the association relationship, the preset security protection policy matching the first sensitivity level can be determined, and the found preset security protection policy is determined as the first security protection policy.
[0101] In the above-mentioned implementation manner, by customizing the security protection policy for the service module in advance according to the sensitivity level of the service module, the determination process of the security protection policy can be shortened, thereby saving the determination time of the security protection policy, and further meeting the business scenarios with better real-time performance.
[0102] In another optional implementation manner, the above steps determine the first security protection policy matching the first sensitivity level of the target service module, specifically including the following steps:
[0103] First, obtain the module attribute information of the target service module;
[0104] Second, determine the target authentication method matching the module attribute information and the first sensitivity level among multiple pre-set authentication methods;
[0105] Next, combine the target authentication methods to obtain the first security protection policy.
[0106] In the embodiments of the present application, multiple authentication methods (i.e., pre-set authentication methods) can be pre-set. For example, the pre-set authentication methods include at least one of the following: face recognition, fingerprint, account password, U shield, SIM card, verification code, dynamic token, verification code, etc.
[0107] Here, the module attribute information includes: information such as the module name, module priority, and module type of the service module. For each pre-set authentication method, a corresponding attribute label can be set, and through this attribute label, the module scope of the service module applicable to the pre-set authentication method can be determined. For example, for the pre-set authentication method, the attribute labels can be set as: Label 1 and Label 2; among them, Label 1 can be the module name, and Label 2 can be the module type.
[0108] Based on this, the authentication method that matches the module attribute information can be determined according to the attribute label of each pre-set authentication method, and then, the authentication method that matches the first sensitivity level is further screened out as the target authentication method.
[0109] Next, the target authentication methods can be combined to obtain the first security protection policy for the target service module. For example, the target authentication methods can be freely combined.
[0110] Through the above implementation method, the corresponding security protection policy can be customized for the service module, and then a security protection policy with a higher matching degree can be determined for each service module, so as to achieve precise protection for each service module.
[0111] In the embodiment of the present application, the above steps of determining the first security protection policy that matches based on the first sensitivity level of the target service module specifically include the following steps:
[0112] First, determine the request sending location of the service access request;
[0113] Second, determine the location risk level of the request sending location;
[0114] Next, based on the location risk level and the first sensitivity level, determine the first security protection policy of the target service module.
[0115] In the embodiment of the present application, after determining the first sensitivity level of the target service module, the request sending location of the service access request can also be identified. Specifically, it can be identified whether the access network through which the user sends the service access request is from the trusted internal network of the enterprise or the external network; or the geographical location of the access device can be located, so as to distinguish whether the service access request comes from a high-risk area or a local normal area according to the geographical location.
[0116] After determining the request sending location, the location risk level of the request sending location can be determined. For example, the location risk level of a high-risk area is "specially important", and for another example, the location risk level of a service access request from the external network is "specially important".
[0117] Next, the security protection policies corresponding to the first sensitivity level and the location risk level can be determined respectively; then, select the security protection policy with the highest level among the two determined security protection policies as the first security protection policy. For example, when it is determined that the location risk level is higher than the first sensitivity level, determine the security protection policy matching the location risk level as the first security protection policy.
[0118] Through the above processing method, the security protection policies of the business module can be determined from more dimensions, so as to determine a more matching security protection policy for the business module, and further improve the security of each business module.
[0119] In the embodiment of the present application, after determining the first security protection policy, the security protection authentication can be performed on the service access request according to the first security protection policy, which specifically includes the following steps:
[0120] Step S11: Determine the multiple authentication methods indicated by the first security protection policy, and determine the authentication order of the multiple authentication methods;
[0121] Step S12: Perform multi-level security protection authentication on the service access request according to the authentication order.
[0122] As can be seen from the above description, the first security method policy includes multiple authentication methods. For example, it includes at least one of face recognition, fingerprint, account password, U shield, SIM card, verification code, dynamic token, and verification code.
[0123] Here, the multi-level security protection authentication can be performed on the service access request according to the multiple authentication methods indicated by the first security protection policy.
[0124] In the embodiment of the present application, the authentication order of multiple authentication methods can be determined. For example, the multiple authentication methods can be randomly sorted to obtain the authentication order; for another example, they can be sorted according to the priority of the authentication methods to obtain the authentication order; for another example, they can be sorted in a preset order to obtain the authentication order; for another example, they can be sorted according to the historical authentication pass rate of each authentication method to obtain the authentication order. For example, the authentication methods with a lower authentication pass rate can be placed in the front position.
[0125] Next, according to the authentication order, the multi-level security protection authentication can be performed on the service access request through multiple authentication methods in turn. Here, it should be noted that if the authentication of any one authentication method fails, the entire process ends and the remaining authentication methods are no longer executed.
[0126] Through the above processing method, the authentication order can be set according to the self - requirements and real - time requirements of each business module, so as to be applicable to more business scenarios. For example, for scenarios with high real - time requirements, the sorting can be carried out according to the historical authentication passing rate of each authentication method. For business access requests that cannot be released, this processing method can reduce the authentication operations and shorten the authentication time.
[0127] Here, it should be noted that during the off - peak access period, in order to reduce system resource consumption, some non - critical security controls can be appropriately relaxed, the security protection level can be reduced, and the authentication process can be simplified; while during the peak period, especially when it comes to important business and critical data processing, strengthen the security protection, automatically enable a higher - level encryption protocol to ensure the data security in a large number of concurrent accesses.
[0128] In the embodiment of the present application, when the security protection authentication is passed, the business access request is executed. Wherein, the method further includes the following steps:
[0129] S104: During the process of executing the business operation corresponding to the business access request, identify the sensitivity level of the business operation and / or the business data corresponding to the business operation, and obtain a third sensitivity level; the third sensitivity level is used to indicate the importance of the business operation and / or the business data;
[0130] S105: Based on the third sensitivity level, determine a matching third security protection policy, and authenticate the business operation according to the third security protection policy.
[0131] In the embodiment of the present application, the sensitivity level can also be set for the business operation and the business data in the business module. For example, the relevant technical personnel can pre - set the sensitivity level for the business operation and the business data in advance; or, the sensitivity level of the business operation and the business data can be set according to the data importance of the business data corresponding to the business operation. Here, the business sensitivity level of the business operation and the data sensitivity level corresponding to the business data can be the same or different.
[0132] Here, during the process of executing the business operation corresponding to the business access request, the sensitivity level of the business operation and / or the corresponding business data of the target business module can be identified, so as to obtain a third sensitivity level. Then, the business operation can be authenticated based on the third sensitivity level. Among them, if the authentication is passed, the following business operation is executed; if the authentication fails, the process ends, the next business operation is not executed, and a message of business failure is returned.
[0133] Through the above processing method, the security protection policy can be automatically determined for business modules with finer granularity, so that the security protection policy can be adaptively switched from large business modules to fine-grained sensitive operations.
[0134] In the embodiment of the present application, if the third sensitive level includes a business sensitive label and a data sensitive label, in this case, the above steps determine a matching third security protection policy based on the third sensitive level, and authenticate the business operation according to the third security protection policy, which specifically includes the following steps:
[0135] First, determine the most important sensitive label among the business sensitive label of the business operation and the data sensitive label of the business data;
[0136] Second, determine the security protection policy matching the most important sensitive label as the third security protection policy.
[0137] In the embodiment of the present application, if the third sensitive level includes both a business sensitive label and a data sensitive label at the same time, then the importance levels of the business sensitive label and the data sensitive label can be compared, and then the most important sensitive label can be determined. And determine the security protection policy matching the most important sensitive label, and then, determine the matching security protection policy as the third security protection policy; afterwards, authenticate the business operation according to the third security protection policy.
[0138] Through the above processing method, finer-grained automatic security protection can be implemented for business modules, thereby further improving the security of each business module.
[0139] In the embodiment of the present application, the sensitive levels of each business module, business operation, and business data are not fixed, but are in a state of change. If the sensitive level changes, the corresponding security protection policy also needs to be adaptively changed. Therefore, in the embodiment of the present application, it is necessary to periodically monitor the changes in the sensitive levels of each business module, business operation, and business data, so as to change the corresponding security protection policy in a timely manner.
[0140] Based on this, in the embodiment of the present application, the method further includes the following steps:
[0141] Step S21: If it is monitored that the first sensitive level of the business module is updated to the second sensitive level, determine the second security protection policy matching the second sensitive level;
[0142] Step S22: Update the security protection policy of the business module to the second security protection policy.
[0143] In the embodiments of the present application, it is possible to detect whether the sensitivity levels of business modules, business operations, and business data have changed; among them, if it is detected that a change has occurred, the sensitivity levels of the corresponding business modules, business operations, or business data in the business importance assessment report are updated, and the business importance assessment report is stored in the database. For example: for enterprise operation data, the sensitivity level of some unpublished data is important, while after these data are published, the sensitivity level will be reduced to normal.
[0144] In specific implementation, the security protection component can listen through Listen to the association relationship between business modules (or business operations, or business data) and sensitivity levels in the database, so as to automatically capture changes in business sensitivity levels according to this association relationship, and thus timely discover business modules, business operations, or business data whose sensitivity levels have changed. For the changed business module (or business operation, or business data), a business importance report can also be automatically generated, and according to this business importance report, the most suitable security protection strategy can be automatically matched for the business module (or business operation, or business data) according to the rules.
[0145] Therefore, in the embodiments of the present application, after the first sensitivity level is updated to the second sensitivity level, the second security protection strategy matching the second sensitivity level can be determined.
[0146] Through the above processing method, the change in the sensitivity level can be automatically sensed, so as to automatically match the most suitable security protection strategy, and then the appropriate security protection strategy can be switched timely and effectively, further ensuring the security of the business module.
[0147] In the embodiments of the present application, after updating the security protection strategy of the target business module to the second security protection strategy, the method further includes the following steps:
[0148] Detect whether the first security protection strategy is in the process of execution;
[0149] If the first security protection strategy is in the process of execution, interrupt the execution of the first security protection strategy, and perform security protection authentication on the business access request according to the second security protection strategy.
[0150] In the embodiments of the present application, after updating the security protection strategy of the business module from the first security protection strategy to the second security protection strategy, it is possible to detect whether the first security protection strategy is in the process of execution, and among them, if it is determined that it is, the first security protection strategy is interrupted, and security protection authentication is performed on the business access request according to the second security protection strategy.
[0151] Through the above processing method, unnecessary authentication operations can be avoided, thereby shortening the time of security protection authentication and improving the efficiency of security protection authentication.
[0152] As can be seen from the above description, the sensitivity levels of the detection service module, service operations, and service data can be changed in the following ways, specifically including:
[0153] Manual method: Update the sensitivity levels of the service module, service operations, and service data through relevant technical personnel.
[0154] Automatic method: Update the sensitivity level of the service module or service operation or service data based on the importance of the service data that has changed.
[0155] In this method, before determining that the first sensitivity level of the target service module is updated to the second sensitivity level, the method further includes the following steps:
[0156] In the case where the importance of the service data processed by the target service module changes, determine the sensitivity level matching the importance of the data to obtain the second sensitivity level;
[0157] Update the first sensitivity level to the second sensitivity level.
[0158] In an embodiment of the present application, for example, for a certain service module, the service of this service module has undergone a new and old iteration. At this time, the importance of the service data processed by this service module has changed. At this time, it is necessary to re-determine the sensitivity level for this service module. At this time, the sensitivity level matching the importance of the data can be determined as the second sensitivity level.
[0159] For another example, for a certain service module, the sensitivity levels of some unpublished service data are important. When these service data are published, at this time, it is necessary to re-determine the sensitivity level for this service module. At this time, the sensitivity level matching the importance of the data can be determined as the second sensitivity level.
[0160] Through the above processing method, the sensitivity levels of the service module, service operations, and service data can be updated adaptively, and then the sensitivity levels can be updated in a timely manner, saving a large amount of manual operations.
[0161] The following combines Figure 4 and Figure 5 to introduce the above process.
[0162] As Figure 4 shown is a schematic flowchart of an optional security protection system. As Figure 4 shown, the interaction process of each module in the security protection system includes the following processes:
[0163] S41: The business importance assessment module obtains the data importance levels of the business data processed by each business module from the data middle platform.
[0164] S42: The business importance assessment module generates a business importance assessment report based on the data importance levels and transmits it to the security protection policy module.
[0165] Specifically, the business importance assessment module assigns sensitivity levels to each business module, each business operation, and each business data in the data middle platform. For example, the sensitivity levels can be unimportant, general, important, and extremely important. After assigning the sensitivity levels, the business importance assessment module generates a business importance assessment report and transmits it to the security protection policy module.
[0166] S43: The business importance assessment module transmits the business importance assessment report to the log / audit module and the database DB.
[0167] Here, the business importance assessment module can transmit the business importance assessment report to the log / audit module for recording and to the database DB for storage.
[0168] S44: The security protection policy module matches a suitable security protection policy based on the business importance assessment report and transmits the security protection policy to the log / audit module and the database DB.
[0169] Here, the security protection policy module can transmit the security protection policy to the log / audit module for storage.
[0170] S45: In response to a business access request, the business importance assessment module determines the first sensitivity level of the business module and transmits the first sensitivity level to the security protection policy module.
[0171] Here, after detecting a business access request for the business module, the business importance assessment module can determine the first sensitivity level of the business module and transmit the first sensitivity level to the security protection policy module.
[0172] S46: The security protection policy module determines the first security protection policy based on the first sensitivity level and transmits the first security protection policy to the policy execution engine module.
[0173] S47: The policy execution engine module performs security protection authentication on the business module in the data middle platform according to the first security protection policy.
[0174] S48: The policy execution engine module transmits the authentication record to the log / audit module and the database DB.
[0175] In the above process, the entire process of the security protection component can be logged through the log / audit module. For example, the logs of the business importance assessment module, the security protection policy module, and the policy execution engine module can be recorded. At the same time, the data involved in the security protection component can be saved into the database. For example, the data involved in the business importance assessment module, the security protection policy module, and the policy execution engine module can be saved into the database.
[0176] As Figure 5 shown in the flowchart of an optional security protection method, as Figure 5 shown, the method includes the following processes:
[0177] S1: Intercept the business access request or business operation;
[0178] Here, the business access request or business operation can be intercepted through an Interceptor, and the sensitivity level of the business module or business operation corresponding to the business access request can be determined.
[0179] S2: Determine the latest security protection policy that matches the sensitivity level.
[0180] S3: Perform multi-level authentication on the business access request or business operation according to the security protection policy.
[0181] S4: Determine whether the authentication passes; among them, if it passes, execute S5; otherwise, execute S6.
[0182] S5: Release the business access request or execute the business operation.
[0183] S6: Reject the access of the business access request or stop executing the business operation.
[0184] S7: Listen for change events of the sensitivity level of the business module or business operation;
[0185] S8: Determine the latest sensitivity level of the business module or business operation based on the listened change events. Then, it can return to execute S2, that is, determine the security protection policy that matches the latest sensitivity level.
[0186] From the above description, it can be seen that the technical solution of the present application can pre-integrate the security protection component into each business module of the data middle platform. Since the security protection component is a separate component, it can be easily integrated into each business module, and at this time, the impact on the operation of each business module is relatively small. Through this security protection component, the importance (sensitivity level) of each business module can be automatically perceived, and the appropriate security protection policy can be switched in a timely and effective manner, improving the security of each business module. At the same time, the security protection component records the entire process of operation logs during the entire protection process, which is convenient for traceability and analysis.
[0187] Those skilled in the art can understand that in the above method of the specific implementation manner, the writing order of each step does not mean a strict execution order and does not impose any limitation on the implementation process. The specific execution order of each step should be determined according to its function and possible internal logic.
[0188] Based on the same inventive concept, an embodiment of the present application also provides a security protection device corresponding to the security protection method. Since the principle of solving problems by the device in the embodiment of the present application is similar to the above security protection method in the embodiment of the present application, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be elaborated.
[0189] Refer to Figure 6 As shown, it is a schematic diagram of a security protection device provided by an embodiment of the present application. Among them, the security protection device can be understood as the security protection component described in the above embodiment. The device includes: a service importance evaluation module 10, a security protection policy module 20, and a policy execution engine module 30; among them,
[0190] The service importance evaluation module 10 is configured to determine a first sensitivity level of a target service module corresponding to the service access request in the data middle platform after detecting the service access request; among them, the data middle platform includes multiple service modules, and each service module determines a corresponding sensitivity level according to the importance of the service it executes;
[0191] The security protection policy module 20 is configured to determine a first security protection policy that matches the first sensitivity level of the target service module;
[0192] The policy execution engine module 30 is configured to perform security protection authentication on the service access request according to the first security protection policy, and execute the service access request when the security protection authentication passes.
[0193] In the above implementation manner, by perceiving the first security protection policy of the service module through the importance of the service executed by the service module (that is, the first sensitivity level), the self-adaptive perception of the security protection policy can be realized, so that a suitable security protection policy can be matched in a timely and effective manner, thereby greatly improving the security of each service module.
[0194] In a possible implementation manner, the security protection policy module 20 is configured to:
[0195] If it is monitored that the first sensitivity level of the target service module is updated to a second sensitivity level, determine a second security protection policy that matches the second sensitivity level;
[0196] Update the security protection policy of the target service module to the second security protection policy.
[0197] In a possible implementation manner, the policy execution engine module 30 is further configured to:
[0198] Detect whether the first security protection policy is in the process of being executed;
[0199] If the first security protection policy is in the process of being executed, interrupt the execution of the first security protection policy, and perform security protection authentication on the service access request according to the second security protection policy.
[0200] In a possible implementation manner, the service importance evaluation module 10 is configured to:
[0201] Before determining that the first sensitivity level of the target service module is updated to the second sensitivity level, when the importance level of the service data processed by the service module changes, determine the sensitivity level matching the importance level of the data to obtain the second sensitivity level;
[0202] Update the first sensitivity level to the second sensitivity level.
[0203] In a possible implementation manner, the service importance evaluation module 10 is configured to:
[0204] During the execution of the service operation corresponding to the service access request, identify the sensitivity level of the service operation and / or the service data corresponding to the service operation to obtain a third sensitivity level; the third sensitivity level is used to indicate the importance level of the service operation and / or the service data;
[0205] The security protection policy module 20 is configured to: based on the third sensitivity level, determine a matching third security protection policy, and authenticate the service operation according to the third security protection policy.
[0206] In a possible implementation manner, the policy execution engine module 30 is further configured to:
[0207] Determine multiple authentication methods indicated by the first security protection policy, and determine the authentication order of the multiple authentication methods;
[0208] Perform multi-level security protection authentication on the service access request according to the authentication order.
[0209] In a possible implementation manner, the device is further configured to: before detecting the service access request, evaluate the sensitivity level of the target service module to obtain a first sensitivity level; and establish an association relationship between the first sensitivity level and a matching preset security protection policy;
[0210] A security protection policy module, configured to: determine a preset security protection policy that matches the first sensitivity level based on the association relationship, and obtain the first security protection policy.
[0211] In a possible implementation, the security protection policy module 20 is further configured to:
[0212] Obtain the module attribute information of the target service module;
[0213] Determine a target authentication method that matches the module attribute information and the first sensitivity level among multiple pre-set authentication methods;
[0214] Combine the target authentication methods to obtain the first security protection policy.
[0215] In a possible implementation, the security protection policy module 20 is further configured to:
[0216] Determine the request sending location of the service access request;
[0217] Determine the location risk level of the request sending location;
[0218] Based on the location risk level and the first sensitivity level, determine the first security protection policy of the target service module.
[0219] For the processing flow of each module in the device and the interaction flow between modules, reference can be made to the relevant descriptions in the above method embodiments, which will not be elaborated here.
[0220] Corresponding to Figure 1 the security protection method in, an embodiment of the present application further provides an electronic device 700, as Figure 7 shown, which is a schematic structural diagram of the electronic device 700 provided by the embodiment of the present application, including:
[0221] A processor 71, a memory 72, and a bus 73; the memory 72 is used to store execution instructions, including an internal memory 721 and an external memory 722; here, the internal memory 721 is also called the main memory, which is used to temporarily store the operation data in the processor 71 and the data exchanged with the external memory 722 such as a hard disk. The processor 71 exchanges data with the external memory 722 through the internal memory 721. When the electronic device 700 runs, the processor 71 communicates with the memory 72 through the bus 73, so that the processor 71 executes the following instructions:
[0222] After detecting a service access request, determine the first sensitivity level of the target service module in the data middle platform corresponding to the service access request; wherein, the data middle platform includes multiple service modules, and each service module determines the corresponding sensitivity level according to the importance of the service it executes;
[0223] Determine a first security protection policy that matches based on the first sensitivity level of the target service module;
[0224] Perform security protection authentication on the service access request according to the first security protection policy, and execute the service access request when the security protection authentication passes.
[0225] The embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, it executes the steps of the security protection method described in the above method embodiment. Among them, the storage medium can be a volatile or non-volatile computer-readable storage medium.
[0226] The embodiment of the present application also provides a computer program product, which carries program code. The instructions included in the program code can be used to execute the steps of the security protection method described in the above method embodiment. For details, please refer to the above method embodiment and will not be elaborated here.
[0227] Among them, the above computer program product can be specifically implemented in a way of hardware, software or a combination thereof. In an optional embodiment, the computer program product is specifically embodied as a computer storage medium. In another optional embodiment, the computer program product is specifically embodied as a software product, such as a Software Development Kit (SDK), etc.
[0228] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the above-described systems and devices can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated here. In several embodiments provided by the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed coupling or direct coupling or communication connection between each other can be through some communication interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical, mechanical or other form.
[0229] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or distributed over multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0230] In addition, in each embodiment of this application, each functional unit can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0231] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a non-volatile computer-readable storage medium executable by a processor. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of this application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs that can store program codes.
[0232] Finally, it should be noted that: the above-described embodiments are only specific implementation manners of this application, used to illustrate the technical solutions of this application, rather than limiting it. The protection scope of this application is not limited thereto. Although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed in this application can still modify the technical solutions recorded in the foregoing embodiments, or can easily think of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes, or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
Claims
1. A security protection method, characterized in that, Including: After detecting a service access request, determining a first sensitivity level of a target service module in the data middle platform corresponding to the service access request; wherein, the data middle platform includes multiple service modules, and each service module determines a corresponding sensitivity level according to the importance of the service it executes; Determining a first security protection policy that matches based on the first sensitivity level of the target service module; Performing security protection authentication on the service access request according to the first security protection policy, and executing the service access request when the security protection authentication passes.
2. The method according to claim 1, wherein The method further includes: If it is monitored that the first sensitivity level of the target service module is updated to a second sensitivity level, determining a second security protection policy that matches the second sensitivity level; Updating the security protection policy of the target service module to the second security protection policy.
3. The method according to claim 2, wherein After updating the security protection policy of the target service module to the second security protection policy, the method further includes: Detecting whether the first security protection policy is in the execution process; If the first security protection policy is in the execution process, interrupting the execution of the first security protection policy and performing security protection authentication on the service access request according to the second security protection policy.
4. The method according to claim 2, wherein Before determining that the first sensitivity level of the target service module is updated to a second sensitivity level, the method further includes: When the importance level of the service data processed by the target service module changes, determining a sensitivity level that matches the importance level of the data to obtain a second sensitivity level; Updating the first sensitivity level to the second sensitivity level.
5. The method according to claim 1, wherein The method further includes: During the execution of the service operation corresponding to the service access request, identifying the sensitivity level of the service operation and / or the service data corresponding to the service operation to obtain a third sensitivity level; the third sensitivity level is used to indicate the importance level of the service operation and / or the service data; Determining a third security protection policy that matches based on the third sensitivity level, and performing authentication on the service operation according to the third security protection policy.
6. The method according to claim 1, wherein The performing security protection authentication on the service access request according to the first security protection policy includes: Determining multiple authentication methods indicated by the first security protection policy and determining the authentication order of the multiple authentication methods; Performing multi-level security protection authentication on the service access request according to the authentication order.
7. The method according to claim 1, wherein The method further includes: before detecting the service access request, evaluating the sensitivity level of the target service module to obtain a first sensitivity level; and establishing an association relationship between the first sensitivity level and a preset security protection policy that matches; The determining a first security protection policy that matches based on the first sensitivity level of the target service module includes: determining a preset security protection policy that matches the first sensitivity level based on the association relationship to obtain the first security protection policy.
8. The method according to claim 1, characterized in that, Determining a first security protection policy that matches based on the first sensitivity level of the target service module includes: Obtaining the module attribute information of the target service module; Determining a target authentication method that matches the module attribute information and the first sensitivity level among a plurality of pre-set authentication methods; Combining the target authentication methods to obtain the first security protection policy.
9. The method according to claim 1, wherein Determining a first security protection policy that matches based on the first sensitivity level of the target service module includes: Determining the request sending location of the service access request; Determining the location risk level of the request sending location; Based on the location risk level and the first sensitivity level, determining the first security protection policy of the target service module.
10. An electronic device, characterized in that, Including: A processor, a memory, and a bus. The memory stores machine-readable instructions executable by the processor. When the electronic device runs, the processor communicates with the memory through the bus. When the machine-readable instructions are executed by the processor, the steps of the security protection method according to any one of claims 1 to 9 are executed.