Data security management method and device, equipment and storage medium
Through the multi-store point architecture and consensus algorithm of the blockchain system, the problems of data security and privacy protection in centralized databases and single blockchain storage methods are solved, and data security management and transparent sharing among enterprises are realized.
Patent Information
- Application Number
- CN202510362824.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-07-11
AI Technical Summary
Traditional centralized databases lack transparent verification mechanisms to store data, and data authenticity is difficult to guarantee. A single blockchain storage method lacks privacy protection and regulatory mechanisms, which poses a risk of sensitive data being tampered with.
The multi-store point architecture of regulatory blockchain and enterprise blockchain in the blockchain system is adopted, and enterprise blockchain is used to verify enterprise data and upload key information to the regulatory blockchain, and the data is securely managed in combination with consensus algorithms.
It improves the credibility of data security management, ensures data security and reliability, and realizes transparent data sharing and real-time risk response among enterprises.
Smart Images

Figure CN120296801A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain technology, and in particular, to a data security management method, device, equipment and storage medium. Background Art
[0002] With the rapid development of big data technology, the normal operation of each enterprise involves a large amount of data. And with the collaborative development among enterprises, while ensuring the data security, certain data sharing is required among enterprises. Therefore, while ensuring the data security of its own enterprise, it is the current requirement for the collaborative development of enterprises to ensure that the locally shared data is not tampered with.
[0003] The traditional method of storing data using a centralized database relies on manual review and process approval, lacks a transparent verification mechanism, it is difficult to guarantee the authenticity of data, and the data credibility is low; manual operation is time-consuming and cannot meet the real-time requirements of high-risk scenarios. The existing method of storing data using a single blockchain, due to the lack of privacy protection and supervision mechanism, the single storage point becomes the target of attack, and once it is invaded, there is a risk of sensitive data being tampered with. Summary of the Invention
[0004] The present invention provides a data security management method to achieve the security management of data.
[0005] According to the first aspect of the present invention, there is provided a data security management method, including: each enterprise blockchain in the blockchain system respectively receives enterprise data uploaded by an associated enterprise security management platform, wherein, the blockchain system includes a regulatory blockchain and a plurality of enterprise blockchains respectively connected to the regulatory blockchain;
[0006] The enterprise blockchain verifies the received enterprise data to obtain verification information, and uploads the verification information to the regulatory blockchain, wherein the verification information includes key information of enterprise data or early warning signals;
[0007] The regulatory blockchain conducts security management on the verification information.
[0008] Optionally, before each enterprise blockchain in the blockchain system respectively receives enterprise data uploaded by an associated enterprise security management platform, it further includes:
[0009] Receiving a management instruction for the enterprise blockchain, wherein the management instruction includes the number of enterprises;
[0010] Creating the enterprise blockchain in the blockchain system according to the management instruction, wherein the number of enterprise blockchains is the same as the number of enterprises.
[0011] Optionally, the enterprise data includes alarm metadata and the original hash value corresponding to the alarm metadata.
[0012] Optionally, verifying the enterprise data received through the enterprise blockchain to obtain verification information includes:
[0013] Calculating a calculated hash value for the enterprise data received through the enterprise blockchain;
[0014] Verifying the original hash value based on the calculated hash value to obtain the verification information.
[0015] Optionally, verifying the original hash value based on the calculated hash value to obtain the verification information includes:
[0016] Determining whether the calculated hash value is the same as the original hash value. If so, it is determined that the verification is passed, and the key information extracted from the enterprise data is used as the verification information.
[0017] Otherwise, it is determined that the verification fails, and the generated warning signal is used as the verification information.
[0018] Optionally, after using the generated warning signal as the verification information, it further includes:
[0019] Triggering the start of the email alarm component;
[0020] Sending the warning signal to the administrator email of the blockchain system through the email alarm component.
[0021] Optionally, uploading the verification information to the regulatory blockchain includes:
[0022] Determining a data synchronization mode, where the data synchronization mode includes scheduled synchronization or real-time synchronization;
[0023] Based on the data synchronization mode, uploading the verification information to the regulatory blockchain using a consensus algorithm, where the consensus algorithm includes a proof-of-stake algorithm or a delegated proof-of-stake algorithm.
[0024] According to another aspect of the present invention, a data security management device is provided, including: an enterprise data receiving module for each enterprise blockchain in the blockchain system to respectively receive enterprise data uploaded by an associated enterprise security management platform, where the blockchain system includes a regulatory blockchain and a plurality of enterprise blockchains respectively connected to the regulatory blockchain;
[0025] An enterprise data verification module is used to verify the received enterprise data through the enterprise blockchain to obtain verification information, and upload the verification information to the supervision blockchain, where the verification information includes key information of enterprise data or warning signals;
[0026] A security management module is used to perform security management on the verification information through the supervision blockchain.
[0027] According to another aspect of the present invention, an electronic device is provided, and the electronic device includes:
[0028] At least one processor; and
[0029] A memory communicatively connected to the at least one processor; wherein,
[0030] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the method according to any embodiment of the present invention.
[0031] According to another aspect of the present invention, a computer-readable storage medium is provided, and the computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the method according to any embodiment of the present invention when executed by a processor.
[0032] The technical solution of the embodiment of the present invention is through a blockchain system including a supervision blockchain and an enterprise blockchain. Adopt a multi-storage point method for multi-level data storage. Through each enterprise blockchain, all data of the associated enterprises are stored. After each enterprise blockchain verifies the enterprise data, the key information is uploaded to the supervision blockchain for storage, thereby improving the credibility of data security management and ensuring the security of data.
[0033] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. Description of the Drawings
[0034] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0035] Figure 1 It is a flowchart of a data security management method provided according to Embodiment 1 of the present invention;
[0036] Figure 2 It is a schematic structural diagram of a blockchain system provided in Embodiment 1 of the present invention;
[0037] Figure 3 It is a flowchart of a data security management method provided in Embodiment 2 of the present invention;
[0038] Figure 4 It is a schematic structural diagram of a data security management device provided in Embodiment 3 of the present invention;
[0039] Figure 5 It is a schematic structural diagram of an electronic device provided in Embodiment 4 of the present invention. Detailed implementation manners
[0040] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0041] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order different from those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0042] Embodiment 1
[0043] Figure 1 This embodiment provides a flowchart of a data security management method for the first embodiment of the present invention. This embodiment is applicable to the situation of data security management. This method can be executed by a database instance synchronization device, and this device can be implemented in the form of hardware and / or software. As Figure 1 shown, this method includes:
[0044] Step S101, each enterprise blockchain in the blockchain system respectively receives enterprise data uploaded by the associated enterprise security management platform.
[0045] Optionally, before each enterprise blockchain in the blockchain system receives the enterprise data uploaded by the associated enterprise security management platform, it further includes: receiving a management instruction for the enterprise blockchain, where the management instruction includes the number of enterprises; creating an enterprise blockchain in the blockchain system according to the management instruction, where the number of enterprise blockchains is the same as the number of enterprises.
[0046] Among them, as Figure 2 shown is the structural schematic diagram of the blockchain system of this embodiment. As Figure 2 shown, the blockchain system includes a regulatory blockchain and multiple enterprise blockchains respectively connected to the regulatory blockchain. And before data security management, it will receive the management instruction of the enterprise blockchain, and the management instruction includes the number of enterprises. Therefore, when creating the blockchain system, the number of enterprise blockchains can be adjusted according to the number of enterprises to enhance the scalability of the system and ensure efficient data collection and processing in enterprises of different scales. Therefore Figure 2 only six enterprise blockchains are taken as an example, and the number of enterprise blockchains included in the blockchain system is not limited. Each enterprise blockchain in this embodiment corresponds to an enterprise and is used to store the enterprise data of that enterprise.
[0047] Specifically, in this embodiment, an enterprise security management platform is configured for each enterprise. The enterprise security management platform collects industrial enterprise terminal and network data through probes such as industrial firewalls, industrial control security audits, and industrial control host guards, and then processes the collected data through a normalization parsing model, performs operations such as eliminating and complementing abnormal data, and finally generates alarm metadata with a unified format. Among them, the alarm metadata includes five-tuples, alarm names, timestamps, etc. In this embodiment, the specific content included in the alarm metadata is not limited. Each enterprise security management platform collects data comprehensively and in real time through a distributed probe method, and ensures data security quality and consistency through generalization parsing, providing a reliable basis for subsequent blockchain evidence storage. And after each enterprise management platform processes the collected enterprise data to obtain alarm metadata, it will convert the alarm metadata into a json string, generate a hash value according to the json string, and then upload the hash value and the alarm metadata to the corresponding enterprise blockchain as enterprise data.
[0048] It is worth mentioning that all relevant data collected by the enterprise is stored in the enterprise blockchain associated with each enterprise security management platform, and the data in each enterprise blockchain can be shared within the enterprise. And by adopting the form of blockchain for internal enterprise management, data tampering within the enterprise can be avoided, thus ensuring the security of enterprise internal data.
[0049] Step S102: Verify the received enterprise data through the enterprise blockchain to obtain verification information, and upload the verification information to the regulatory blockchain.
[0050] Optionally, verifying the received enterprise data through the enterprise blockchain to obtain verification information includes calculating a computed hash value for the enterprise data received through the enterprise blockchain; verifying the original hash value based on the computed hash value to obtain verification information.
[0051] Optionally, verifying the original hash value based on the computed hash value to obtain verification information includes: determining whether the computed hash value is the same as the original hash value. If so, it is determined that the verification passes, and the key information extracted from the enterprise data is used as the verification information. Otherwise, it is determined that the verification fails, and the generated warning signal is used as the verification information.
[0052] Specifically, in this embodiment, after the enterprise blockchain obtains the enterprise data, it will use a preset smart contract to verify the enterprise data and upload the obtained verification information to the regulatory blockchain. When performing the verification, specifically, the warning metadata in the enterprise data to be uploaded to the blockchain is calculated to obtain a computed hash value. Since the enterprise data itself contains an original hash value, the currently obtained computed hash value is compared with the original hash value to determine whether they are the same. When they are the same, it indicates that the verification passes, that is, the warning metadata has not been tampered with within the enterprise. At this time, the key information is extracted from the enterprise data, and the key information is used as the verification information to be uploaded to the regulatory blockchain. The key information at this time can be pre-specified field information. As long as the key information is non-confidential and non-sensitive data within the enterprise, it is within the scope of protection of this application. The specific content of the key information is not limited in this embodiment. Therefore, in the case of passing the verification, by uploading the key information of non-confidential and non-sensitive data to the regulatory blockchain, while ensuring the security of enterprise internal data, data sharing between different enterprises is achieved through the regulatory blockchain. In addition, when the computed hash value is different from the original hash value, it indicates that the verification fails, that is, the warning metadata has been tampered with within the enterprise. At this time, a warning signal will be generated and the warning signal will be used as the verification information to be uploaded to the regulatory blockchain. At the same time, the email warning component will be triggered to send the warning signal to the administrator email of the blockchain system, so as to facilitate the administrator to take corresponding security protection measures in a timely manner for the security management of enterprise data within the enterprise.
[0053] It is worth mentioning that in this embodiment, the enterprise blockchain ensures the immutability of data through distributed storage and hash values, and the regulatory blockchain synchronizes key information to enhance security and regulatory capabilities. This design provides a reliable data foundation for enterprise data security management, and the connection between the enterprise blockchain and the regulatory blockchain reflects a regulatory mechanism for double-layer protection of data, thus ensuring the security of enterprise data management.
[0054] Optionally, uploading the verification information to the regulatory blockchain includes: determining a data synchronization mode, where the data synchronization mode includes scheduled synchronization or real-time synchronization; and uploading the verification information to the regulatory blockchain using a consensus algorithm based on the data synchronization mode, where the consensus algorithm includes a proof-of-stake algorithm or a delegated proof-of-stake algorithm.
[0055] Specifically, in this embodiment, when uploading the verification information to the regulatory blockchain, it is necessary to determine the data synchronization mode. The data synchronization mode configured in the preset smart contract includes scheduled synchronization or real-time synchronization. Among them, the scheduled synchronization can be executed weekly, daily, or monthly to report local enterprise data to the superior regulatory blockchain. In this embodiment, the specific type of the data synchronization mode is not limited. The smart contract of this embodiment automatically executes verification and response, reducing human interference and improving system efficiency. The real-time synchronization mechanism ensures that the regulatory blockchain can grasp enterprise security data in real time, and the regulatory blockchain (as the main chain) realizes real-time synchronization and supervision of data by connecting with the enterprise blockchain (as the side chain). And from the perspective of superior supervision, creating a regulatory blockchain and the enterprise blockchain using a smart contract to regularly synchronize data to the regulatory blockchain can ensure data consistency.
[0056] In addition, in this embodiment, after determining the data synchronization mode, when uploading the verification information to the regulatory blockchain based on the data synchronization mode, specifically, a consensus algorithm is used to implement communication between the enterprise blockchain and the regulatory blockchain. Among them, the consensus algorithm includes a proof-of-stake algorithm or a delegated proof-of-stake algorithm. Using the above formula algorithm can effectively reduce the communication delay between the enterprise blockchain and the regulatory blockchain, thereby accelerating data synchronization and improving the real-time performance of the blockchain system. Of course, in this real-time mode, only the consensus algorithm is used as an example for illustration, and the communication method between the regulatory blockchain and the enterprise blockchain is not limited. As long as it can reduce the communication delay, it is within the protection scope of this application.
[0057] It should be noted that the preset smart contract adopted in this embodiment is an automated program on the enterprise blockchain, which provides transparency and immutability for data storage. Smart contracts are applicable to scenarios that require high trust and data transparency. And in this embodiment, both the enterprise blockchain and the regulatory blockchain can adopt a decentralized file storage method. Decentralized file storage means splitting a file into small pieces and dispersing them for storage on different nodes of the blockchain, achieving data security and privacy protection. This method effectively prevents the risk of data being controlled or tampered with by a single entity because an attacker needs to control multiple nodes simultaneously to cause substantial damage to the file. Among them, the reason for adopting the form of blockchain for data storage in this embodiment is that blockchain is a data structure in which blocks are linked together in a specific way. This chain structure makes it almost impossible to tamper with data once it is written because any modification will affect the hash values of all subsequent blocks and thus be recognized by other nodes in the network. Therefore, this structure significantly enhances the traceability of data. And this embodiment adopts a multi-level blockchain storage method of enterprise blockchain and regulatory blockchain, which ensures the security of enterprise internal data while also ensuring the security of data between enterprises.
[0058] Step S103, perform security management on the verification information through the regulatory blockchain.
[0059] Among them, the verification information includes key enterprise data information or warning signals. Therefore, the relevant data collected by each enterprise is saved on the regulatory blockchain, and the key information can be the data of specified fields in the enterprise data, thus significantly reducing the storage pressure on the regulatory blockchain while synchronizing data. In addition, the key information is required to be non-confidential and non-sensitive enterprise data, thus ensuring the data security of each enterprise while meeting the information sharing between enterprises to ensure the normal execution of business.
[0060] It should be noted that although the data on the regulatory blockchain are non-confidential and non-sensitive data of each enterprise, they are also very important information for each enterprise. Although they can be used by enterprises to conduct business, in order to ensure the security of the data, they are stored in a decentralized manner in the form of blockchain, and any operation and modification of the data will be reflected in the regulatory blockchain, thus ensuring the security of the data in the regulatory blockchain. Therefore, in this embodiment, through the innovative main chain (enterprise blockchain)-side chain (regulatory blockchain) architecture, combined with distributed data collection, intelligent contract automated response, and multi-level data storage, the data credibility, collaboration efficiency, and response speed of industrial security management are significantly improved. This application has significant advantages in terms of decentralization, automation, and security. The expansion suggestions further improve the scalability and intelligence level of the system, providing an efficient and reliable solution for industrial security management. Therefore, the trusted security management platform based on blockchain in this embodiment solves problems such as the credibility of data storage evidence, multi-party collaboration efficiency, and real-time risk response based on blockchain technology. Through intelligent contracts, automated security management is achieved, reducing the risk of human intervention and improving the real-time performance and accuracy of industrial security management.
[0061] It is worth mentioning that in this embodiment, when using blockchain to manage data security, it mainly relies on its unique characteristics such as decentralization, immutability, transparency, and encryption technology. Among them, decentralized storage and distributed consensus mean that blockchain adopts distributed ledger technology to store data dispersedly on multiple nodes in the network. Each node has a complete or partial copy of the data, avoiding the risks of single-point failure and data loss. Through the consensus mechanism, the nodes in the network jointly verify and confirm the validity of the data, ensuring the consistency and security of the data. The immutability of data means that the chain structure of blockchain makes the data unable to be modified or deleted once written. Each block contains the hash value of the previous block, and any tampering with the data will destroy the chain structure and be recognized and rejected by other nodes in the network. Encryption technology and privacy protection mean that blockchain uses advanced encryption algorithms, such as hash functions or asymmetric encryption, to protect data. Each block contains encrypted information, and only users with the corresponding private key can decrypt and access the data, ensuring the confidentiality and privacy of the data. In addition, blockchain also supports privacy protection technologies such as zero-knowledge proof, further enhancing the security of the data.
[0062] In the embodiment of this application, through a blockchain system including a regulatory blockchain and an enterprise blockchain. A multi-storage point method is adopted for multi-level data storage. All data of the associated enterprises are stored through each enterprise blockchain. After each enterprise blockchain verifies the enterprise data, the key information is uploaded to the regulatory blockchain for storage, thus improving the credibility of data security management and ensuring the security of the data.
[0063] Embodiment 2
[0064] Figure 3 A flowchart of a data security management method provided in Embodiment 2 of the present invention. This embodiment is based on the above embodiment. Before verifying the enterprise data received through the enterprise blockchain to obtain verification information and uploading the verification information to the supervision blockchain, it further includes: detecting the communication between the enterprise blockchain and the supervision blockchain to determine that the communication connection is normal. As Figure 3 shown, the method includes:
[0065] Step S201, each enterprise blockchain in the blockchain system respectively receives enterprise data uploaded by the associated enterprise security management platform.
[0066] Optionally, before each enterprise blockchain in the blockchain system respectively receives enterprise data uploaded by the associated enterprise security management platform, it further includes: receiving a management instruction for the enterprise blockchain, where the management instruction includes the number of enterprises; creating enterprise blockchains in the blockchain system according to the management instruction, where the number of enterprise blockchains is the same as the number of enterprises.
[0067] Step S202, detect the communication between the enterprise blockchain and the supervision blockchain to determine that the communication connection is normal.
[0068] Specifically, in this embodiment, after creating the blockchain system and before the enterprise blockchain performs data transmission with the supervision blockchain, the communication between each enterprise blockchain and the supervision blockchain will be detected first to determine whether the communication is normal. When it is determined through the detection that the communication between each enterprise blockchain and the supervision blockchain is normal, a communication detection passed prompt will be generated and sent to each enterprise blockchain. When each enterprise blockchain receives the communication detection passed prompt, it will perform subsequent data transmission. When it is determined that the communication detection fails, data transmission will not be performed, thereby avoiding the occupation of transmission resources caused by invalid data transmission. And when the communication detection fails, a communication failure alarm message will be generated and sent to the system administrator to facilitate the system administrator to promptly repair and restore the communication.
[0069] It should be noted that each enterprise blockchain has a corresponding number, and the communication failure alarm information also includes the numbers of the enterprise blockchains that have lost communication with the regulatory blockchain. After the system administrator views the numbers in the failure alarm information, if it is determined through query that the enterprise corresponding to the enterprise blockchain with communication failure is a deregistered enterprise, then it will directly instruct not to restore the communication between the enterprise blockchain with communication failure and the regulatory blockchain. For example, when it is confirmed that the enterprise blockchains with communication failure are enterprise blockchain 1 and enterprise blockchain 2, and enterprise blockchain 1 corresponds to enterprise A, enterprise blockchain 2 corresponds to enterprise B, and it is found through querying the registered enterprise list that enterprise A has been deregistered, but enterprise B is a registered enterprise, then only the communication between enterprise blockchain 2 and the regulatory blockchain needs to be repaired. Of course, this embodiment is only an example and does not limit the specific number of enterprise blockchains with communication failure.
[0070] It is worth mentioning that in this embodiment, when detecting whether the communication between blockchains is normal, methods such as node verification, public key verification, network verification, IBC protocol detection, and cross-chain communication protocol detection can be used for detection. The specific detection method in this embodiment is not limited, as long as effective detection of communication can be performed, it is within the protection scope of this application.
[0071] Step S203: Verify the enterprise data received through the enterprise blockchain to obtain verification information, and upload the verification information to the regulatory blockchain.
[0072] Optionally, verifying the enterprise data received through the enterprise blockchain to obtain verification information includes calculating a calculated hash value for the enterprise data received through the enterprise blockchain; verifying the original hash value based on the calculated hash value to obtain verification information.
[0073] Optionally, verifying the original hash value based on the calculated hash value to obtain verification information includes: determining whether the calculated hash value is the same as the original hash value. If so, it is determined that the verification passes, and the key information extracted from the enterprise data is used as the verification information. Otherwise, it is determined that the verification fails, and the generated warning signal is used as the verification information.
[0074] Optionally, uploading the verification information to the regulatory blockchain includes: determining the data synchronization mode, where the data synchronization mode includes scheduled synchronization or real-time synchronization; uploading the verification information to the regulatory blockchain using a consensus algorithm based on the data synchronization mode, where the consensus algorithm includes the proof-of-stake algorithm or the delegated proof-of-stake algorithm.
[0075] Step S204: Perform security management on the verification information through the regulatory blockchain.
[0076] In the embodiments of the present application, a blockchain system including a regulatory blockchain and enterprise blockchains is adopted. A multi-storage-point method is used for multi-level data storage. Each enterprise blockchain stores all the data of the associated enterprise. After each enterprise blockchain verifies the enterprise data, key information is uploaded to the regulatory blockchain for storage, thereby enhancing the credibility of data security management and ensuring the security of the data.
[0077] Embodiment III
[0078] Figure 4 The structural schematic diagram of a data security management device provided in Embodiment III of the present invention. As Figure 4 shown, the device includes: an enterprise data receiving module 310, an enterprise data verification module 320, and a security management module 330.
[0079] Among them, the enterprise data receiving module 310 is used for each enterprise blockchain in the blockchain system to respectively receive the enterprise data uploaded by the associated enterprise security management platform. Among them, the blockchain system includes a regulatory blockchain and multiple enterprise blockchains respectively connected to the regulatory blockchain;
[0080] The enterprise data verification module 320 is used to verify the received enterprise data through the enterprise blockchain to obtain verification information, and upload the verification information to the regulatory blockchain, where the verification information includes enterprise data key information or warning signals;
[0081] The security management module 330 is used to perform security management on the verification information through the regulatory blockchain.
[0082] Optionally, the device further includes an enterprise blockchain creation module, which is used to receive a management instruction for the enterprise blockchain, where the management instruction includes the number of enterprises;
[0083] Create an enterprise blockchain in the blockchain system according to the management instruction, where the number of enterprise blockchains is the same as the number of enterprises.
[0084] Optionally, the enterprise data includes alarm metadata and an original hash value corresponding to the alarm metadata.
[0085] Optionally, the enterprise data verification module includes: a hash value calculation unit, which is used to calculate a calculated hash value for the received enterprise data through the enterprise blockchain;
[0086] A verification unit, which is used to verify the original hash value according to the calculated hash value to obtain verification information.
[0087] Optionally, the verification unit is used to determine whether the calculated hash value is the same as the original hash value. If so, it is determined that the verification is passed, and the key information extracted from the enterprise data is used as the verification information.
[0088] Otherwise, determine that the verification fails and use the generated warning signal as the verification information.
[0089] Optionally, the device further includes a warning signal sending module for triggering the start of the email alert component;
[0090] Send the warning signal to the administrator email of the blockchain system through the email alert component.
[0091] Optionally, the enterprise data verification module further includes a verification information uploading unit for determining the data synchronization mode, where the data synchronization mode includes scheduled synchronization or real-time synchronization;
[0092] Upload the verification information to the regulatory blockchain using a consensus algorithm based on the data synchronization mode, where the consensus algorithm includes the proof-of-stake algorithm or the delegated proof-of-stake algorithm.
[0093] The data security management device provided by the embodiments of the present invention can execute the data security management method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0094] Embodiment 4
[0095] Figure 5 The structural schematic diagram of the electronic device 10 that can be used to implement the embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0096] Such as Figure 5As shown, the electronic device 10 includes at least one processor 11 and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. Among them, the memory stores a computer program executable by the at least one processor. The processor 11 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0097] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0098] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the data security management method.
[0099] In some embodiments, the data security management method can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the data security management method described above can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute the data security management method in any other appropriate manner (e.g., by means of firmware).
[0100] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), systems on chip (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.
[0101] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0102] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain, or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0103] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0104] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0105] A computing system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0106] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and this is not limited herein.
[0107] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A data security management method, characterized in that Including: Each enterprise blockchain in the blockchain system respectively receives enterprise data uploaded by the associated enterprise security management platform. Among them, the blockchain system includes a regulatory blockchain and multiple enterprise blockchains respectively connected to the regulatory blockchain; The enterprise blockchain verifies the received enterprise data to obtain verification information and uploads the verification information to the regulatory blockchain. Among them, the verification information includes key information of enterprise data or warning signals; The regulatory blockchain performs security management on the verification information.
2. The method according to claim 1, wherein Before each enterprise blockchain in the blockchain system respectively receives enterprise data uploaded by the associated enterprise security management platform, it further includes: Receiving a management instruction for the enterprise blockchain, where the management instruction includes the number of enterprises; Creating the enterprise blockchain in the blockchain system according to the management instruction, where the number of enterprise blockchains is the same as the number of enterprises.
3. The method according to claim 1, characterized in that, The enterprise data includes alarm metadata and the original hash value corresponding to the alarm metadata.
4. The method according to claim 3, characterized in that The step of the enterprise blockchain verifying the received enterprise data to obtain verification information includes: Calculating a calculated hash value for the received enterprise data through the enterprise blockchain; Verifying the original hash value according to the calculated hash value to obtain the verification information.
5. The method according to claim 4, characterized in that The step of verifying the original hash value according to the calculated hash value to obtain the verification information includes: Judging whether the calculated hash value is the same as the original hash value. If so, it is determined that the verification passes, and the key information extracted from the enterprise data is used as the verification information. Otherwise, it is determined that the verification fails, and the generated warning signal is used as the verification information.
6. The method according to claim 5, characterized in that, After using the generated warning signal as the verification information, it further includes: Triggering and starting the email alarm component; Sending the warning signal to the administrator email of the blockchain system through the email alarm component.
7. The method according to claim 1, wherein The step of uploading the verification information to the regulatory blockchain includes: Determining a data synchronization mode, where the data synchronization mode includes scheduled synchronization or real-time synchronization; Based on the data synchronization mode, uploading the verification information to the regulatory blockchain using a consensus algorithm, where the consensus algorithm includes a proof-of-stake algorithm or a delegated proof-of-stake algorithm.
8. A data security management device, characterized in that, Including: An enterprise data receiving module, configured to enable each enterprise blockchain in the blockchain system to respectively receive enterprise data uploaded by the associated enterprise security management platform. Among them, the blockchain system includes a regulatory blockchain and multiple enterprise blockchains respectively connected to the regulatory blockchain; An enterprise data verification module, configured to verify the received enterprise data through the enterprise blockchain to obtain verification information and upload the verification information to the regulatory blockchain. Among them, the verification information includes key information of enterprise data or warning signals; A security management module, configured to perform security management on the verification information through the regulatory blockchain.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, the memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, enables the at least one processor to execute the method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a processor to implement the method according to any one of claims 1-7 when executed.