Data management platform construction method based on data encryption algorithm
The data governance platform uses advanced encryption and secure key management to address key management vulnerabilities and resource inefficiencies, ensuring enhanced data security and performance through precise data categorization and dynamic resource allocation.
Patent Information
- Application Number
- CN202510229150.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-07-15
AI Technical Summary
The existing data governance platform has insufficient security in key management. The key generation, storage, distribution, update and destruction cannot be effectively guaranteed based on complexity and sensitivity, and encryption and decryption operations consume computing resources, resulting in system performance degradation.
Neural network technology is used to accurately divide data types, combine AES, RSA and DES algorithms to design key generation, storage, distribution and destruction mechanisms, build a data governance platform architecture, use hardware security modules to store keys, monitor data flow security in real time, optimize computing resource allocation, and introduce a variety of encryption technologies and artificial intelligence for data protection.
It realizes accurate determination and secure encryption of data types, ensures the security of key management, optimizes computing resource allocation, and improves the operation efficiency and intelligence of the data governance platform.
Smart Images

Figure CN120316786A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of information security and data processing, and particularly to a method for constructing a data governance platform based on a data encryption algorithm. Background Art
[0002] In today's digital age, enterprise data assets have grown rapidly, but data governance platforms face many severe challenges. On the one hand, data security is insufficient. Frequent data leakage incidents seriously threaten the survival and development of enterprises. With the increasingly complex network attack means, traditional protection measures are difficult to resist, and sensitive data may be illegally obtained at any time. On the other hand, the compliance risk is high. Enterprises have difficulty meeting the increasingly strict regulatory requirements. At the same time, technical limitations also restrict the development of the platform and affect its ability to protect sensitive data. To address these issues, data encryption technology has become the key. It can ensure security during data storage, transmission, and processing, and promote compliance management. Based on this, a method for constructing a data governance platform based on a data encryption algorithm has emerged. This method integrates advanced encryption technologies such as AES and RSA, and implements encryption in each link of the platform, providing effective protection for data security and providing technical support for the dilemmas faced by existing data governance platforms.
[0003] Although there have been great progresses in an existing method for constructing a data governance platform based on a data encryption algorithm, there are still some problems to be optimized. In terms of key management, the generation, storage, distribution, update, and destruction of keys are directly related to the overall security of the data encryption system. Existing technologies cannot ensure the security of keys according to the complexity and sensitivity of each link. Once there is a loophole in key management, it will pose a serious threat to the security of the entire data encryption system. In terms of performance, although data encryption provides protection for data security, encryption and decryption operations will inevitably consume additional computing resources. When the allocation of computing resources is not reasonably optimized, it may lead to a decline in system performance and affect the timeliness of business response, which has a certain hindrance to the efficient operation of the data governance platform. Summary of the Invention
[0004] To achieve the above objectives, the present invention is realized through the following technical solutions: A method for constructing a data governance platform based on a data encryption algorithm includes the following steps:
[0005] Step 1: Identify the data types protected by the data governance platform, including top-secret data, confidential data, and secret data, and select a suitable encryption algorithm according to the data types, providing data support for the subsequent process of designing the data governance platform;
[0006] Step 2: Design a key generation, storage, distribution, update, and destruction mechanism according to the data types protected by the data governance platform;
[0007] Step 3: Select the granularity encryption form, granularity encryption mode, encryption tool, and encryption library according to the data types protected by the data governance platform;
[0008] Step 4: Design the system architecture of the data governance platform, determine the interfaces between the data encryption module and other system architecture layers, and formulate a data flow security control plan;
[0009] Step 5: Divide modules for the overall code structure according to the system architecture design, and match the code to implement the data encryption function;
[0010] Step 6: Test the encryption function, including unit testing, integration testing, and performance testing, to ensure that the error of the data governance platform is within the controllable range;
[0011] Step 7: Have the data governance platform reviewed by security experts, and deploy the data governance platform that has completed testing and review to the production environment to improve the reliability of the data governance platform;
[0012] Step 8: Conduct security monitoring and performance evaluation on the data governance platform.
[0013] A further improvement in the technical solution of the present invention lies in that: in the above Step 1, the process of clarifying the data types protected by the data governance platform and selecting a suitable encryption algorithm includes:
[0014] Use text processing software to establish a sensitive keyword library, set the mode for identifying sensitive data formats, and use NLP for semantic analysis to obtain the sensitivity of the data;
[0015] Count all the resources invested in the process of obtaining the data, evaluate the benefits brought by the data from multiple perspectives, and check the scarcity of the data in the industry to obtain the value score of the data;
[0016] Draw a data storage architecture diagram to obtain the relationships between different data storage systems, review the association relationships between database tables, and combine data mining techniques to discover the potential associations between the data to obtain the correlation of the data;
[0017] According to the sensitivity of vocabulary and semantics, divide the data sensitivity into three levels: high, medium, and low; according to the level of the value score, divide the data value into three levels: high, medium, and low; according to the association relationship between the data, divide the data correlation into three levels: high, medium, and low.
[0018] Build a neural network architecture using a multi-layer perceptron structure. The input layer represents the levels of data sensitivity, value, and relevance. The output layer represents the data types protected by the data governance platform, and the number of output nodes is set to 3, namely top-secret data, confidential data, and secret data. Use the input layer data to train the model to obtain the relationship between the levels of data sensitivity, value, and relevance and the corresponding data types protected by the data governance platform.
[0019] Evaluate the performance of the neural network model, adjust the parameters to optimize the neural network model, obtain a data type classification model, and then input the levels of data sensitivity, value, and relevance into the model to obtain the data types protected by the data governance platform.
[0020] For top-secret data, select the AES algorithm; for confidential data, select the RSA algorithm; for secret data, select the DES algorithm. Among them, the AES algorithm and the DES algorithm are symmetric algorithms, and the RSA algorithm is an asymmetric algorithm.
[0021] A further improvement of the technical solution of the present invention is that in the second step, the process of designing the key generation, storage, distribution, update, and destruction mechanism includes:
[0022] Use a cryptographically secure pseudo-random number generator to generate keys. During the key generation process, set a seed value, which is derived from the entropy source of the Windows system, initialize the pseudo-random number generator, and determine the length and format of the keys according to the requirements of the encryption algorithm and security needs.
[0023] Use a hardware security module to store keys. Store the generated keys in the internal key storage area of the HSM. Only authorized users can interact with the HSM. Here, the hardware security module is the HSM.
[0024] Use the SSL / TLS protocol to distribute keys. On the sender side, send the keys to the receiver through a secure channel; on the receiver side, decrypt the received keys using the decryption key.
[0025] According to the data types protected by the data governance platform, formulate a strategy for regularly updating keys. For the encryption keys of top-secret data, set to update once a month; for the encryption keys of confidential data, set to update once a quarter; for the encryption keys of secret data, set to update once every six months.
[0026] Adopt secure deletion technology. Destroy the keys that are no longer used in the HSM through the method of multiple overwrite writes, and establish a key destruction record mechanism to record each key destruction operation.
[0027] A further improvement of the technical solution of the present invention lies in: in the third step, the process of selecting the granularity encryption form, granularity encryption mode, encryption tool, and encryption library includes:
[0028] Select the granularity encryption form as file-level encryption and field-level encryption. Among them, file-level encryption is used to encrypt the entire file, and field-level encryption is used to encrypt specific fields;
[0029] Select the granularity encryption modes including CBC mode, CTR mode, and ECB mode. For top-secret data, select the CBC mode. After performing an exclusive OR operation on the ciphertext block and the current plaintext block, encrypt the plaintext block. For confidential data, select the CTR mode. After encrypting the value of the counter with the key, perform encryption through an exclusive OR operation with the plaintext. For secret data, select the ECB mode. Divide the plaintext into plaintext blocks of a fixed size and encrypt each plaintext block independently;
[0030] Select the encryption tool as the OpenSSL tool. The OpenSSL tool combines with the AES algorithm, RSA algorithm, and DES algorithm for encryption, which are respectively applicable to the encryption processes of top-secret data, confidential data, and secret data.
[0031] The encryption library is the Bouncy Castle library. The Bouncy Castle library provides the AES algorithm, RSA algorithm, and DES algorithm, which are respectively applicable to the encryption processes of top-secret data, confidential data, and secret data.
[0032] A further improvement of the technical solution of the present invention lies in: in the fourth step, the process of designing the system architecture of the data governance platform, determining the interfaces between the data encryption module and other system architecture layers, and formulating a data flow security control plan includes:
[0033] Construct the data governance platform architecture, which is divided into a data source layer, a data collection layer, a data transmission layer, a data storage layer, a data processing layer, a data service layer, a user access layer, and a data encryption module;
[0034] Use a real-time adaptive encryption trigger interface between the data encryption module and the data collection layer. When the data collected by the data collection layer is obtained, the real-time adaptive encryption trigger interface performs multi-dimensional analysis on the data and dynamically selects a matching encryption algorithm and encryption parameters based on the analysis results;
[0035] Use a hybrid encryption transmission adaptation interface between the data encryption module and the data transmission layer. This hybrid encryption transmission adaptation interface integrates multiple encryption technologies. In a conventional network environment, an encryption algorithm based on elliptic curve cryptography is used for encryption; in a network environment with potential security threats, quantum key distribution technology is used to generate a temporary key to perform secondary encryption on the data;
[0036] A dynamic storage encryption policy interface is used between the data encryption module and the data storage layer to monitor various indicators of data storage in real time and adjust the data encryption algorithm and encryption mode. Among them, the various indicators of data storage are the CPU usage rate, memory usage rate of the server, and disk I / O read and write rate;
[0037] A secure computing resource scheduling interface is used between the data encryption module and the data processing layer. This secure computing resource scheduling interface is used for encryption and decryption operations during data processing, and schedules computing resources according to the priority and resource requirements of data processing tasks;
[0038] An encryption interface based on user intent is used between the data encryption module and the data service layer. When the data service layer receives a user's data request, the encryption interface based on user intent deeply understands the user's intent and performs corresponding encryption and decryption operations;
[0039] The links of the data flow security policy include data collection, data transmission, data storage, data processing, and data service. Among them, in the data collection link, artificial intelligence is used to evaluate the risk of data sources and perform hardware protection; in the data transmission link, adaptive network slicing technology is introduced for data adaptive encryption, and blockchain technology is used to verify data integrity; in the data transmission link, biometric recognition is combined with encryption operations; in the data processing link, trusted execution environment technology and secure multi-party computing technology are integrated to build a secure data processing environment, and artificial intelligence is used for anomaly monitoring; in the data service link, encryption watermark technology is introduced to protect data.
[0040] A further improvement of the technical solution of the present invention lies in: in step five, according to the system architecture design, modules are divided for the overall code structure, and the process of matching code to implement the data encryption function includes:
[0041] The data encryption function includes the integration of data encryption algorithms, the implementation of a key management system, and the application of data encryption policies;
[0042] The overall code is divided into three modules, including a data encryption algorithm integration module, a key management system module, and a data encryption policy application module, and code is matched for the data encryption algorithm integration module, the key management system module, and the data encryption policy application module to implement encryption;
[0043] For the data encryption algorithm integration module, the cryptography library in Python is selected, and an encryption algorithm call interface function is created. This encryption algorithm call interface function is used to call the interface between the data encryption module and other system architecture layers;
[0044] The key management system module has a key management process that includes key generation, key storage, key retrieval, key update, and key deletion. It adopts an object-oriented programming approach. During the key generation process, a byte sequence key of a specified length is generated using a secure pseudo-random number generator inside a function. During the key storage process, a key class is created to represent the key object, and the SQLite database is used to persist the key object information. The generated key class object is stored in the database using the store_key function. During the key retrieval process, the get_key function is used to query and obtain the corresponding key class object from the database based on the incoming key ID, and a decryption operation is performed to restore the original key content, which is then sent to the caller. During the key update process, the key attributes are updated according to specific modifications through the update_key function. During the key deletion process, the corresponding key record is deleted from the database based on the incoming key ID through the delete_key function.
[0045] The data encryption policy application module creates a configuration file and divides the policy blocks according to data types. Each policy block includes a data identifier, an encryption algorithm name, and a key usage rule. The encrypt_data function is configured to find the encryption policy based on the data identifier and call the encrypt_aes encryption function for encryption operations. The decrypt_data function is configured to find the decryption policy based on the data identifier and call the decrypt_aes encryption function for decryption operations.
[0046] A further improvement of the technical solution of the present invention is that in step six, the process of unit testing includes:
[0047] The unit testing is divided into symmetric encryption algorithm testing, asymmetric encryption algorithm testing, key management system testing, and data encryption policy testing;
[0048] In unit testing, for symmetric encryption algorithm testing, plaintext data of different lengths and contents are prepared, and the symmetric encryption algorithm is tested by detecting the consistency between the key after encryption by the AES algorithm and the DES algorithm and the original plaintext.
[0049] For asymmetric encryption algorithm testing, plaintext data of different lengths and contents are prepared, and the asymmetric encryption algorithm is tested by detecting the consistency between the key after encryption by the RSA algorithm and the original plaintext.
[0050] Key management system testing includes the processes of key generation, storage, retrieval, update, and deletion. The key generation process is tested by the length and format specifications of the generated key.
[0051] Test the key storage process by checking the encryption process of the stored key; test the key retrieval process by verifying the consistency between the retrieved key and the content of the key before storage;
[0052] Test the key update process by checking the triggering of the update mechanism;
[0053] Test the key deletion process by checking the residues of key deletion and cleaning;
[0054] Test the data encryption policy by determining the matching situation between the representation of the test data and the encryption policy.
[0055] A further improvement of the technical solution of the present invention lies in that: in step six, the processes of integration testing and performance testing include:
[0056] The integration testing is divided into the integration testing of the encryption algorithm and the key management system, the integration testing of the encryption algorithm and the data encryption policy, and the integration testing of the key management system and the data encryption policy; the performance testing is divided into the encryption speed test, the decryption speed test, and the resource occupancy test;
[0057] In the integration testing, test the integration testing of the encryption algorithm and the key management system according to the encryption situation of obtaining the key from the key management system during the encryption process; test the integration of the encryption algorithm and the data encryption policy through the consistency between the decryption result obtained by the encryption algorithm and the decryption result obtained by the data encryption policy; utilize the consistency between the decryption result obtained through the key management system and the decryption result obtained through the data encryption policy to test the integration testing of the key management system and the data encryption policy;
[0058] In the performance testing, test the encryption speed by comparing the time for the symmetric encryption algorithm and the asymmetric encryption algorithm to encrypt data of the same length; test the decryption speed by comparing the decryption time for different data; test the peak and average occupancy of resources for encryption and decryption under different algorithms and different data volumes, evaluate the degree of resource consumption, and test the resource occupancy during the data encryption and decryption processes.
[0059] A further improvement of the technical solution of the present invention lies in that: in step seven, the process of the security expert reviewing the data governance platform and deploying the data governance platform that has completed testing and review to the production environment includes:
[0060] Prepare the corresponding review materials based on top-secret data, confidential data, and secret data. The security expert reviews the data governance platform according to the regulations. The review content includes the implementation of the data encryption policy, the security of the key management mechanism, the selection and configuration of encryption tools, and then deploy the data governance platform that has completed testing and review to the production environment.
[0061] A further improvement of the technical solution of the present invention lies in: In step eight, the process of performing security monitoring and performance evaluation on the data governance platform includes:
[0062] Establish a security monitoring system, deploy network traffic monitoring tools, and analyze the network traffic entering and leaving the data governance platform in real time; collect and manage the logs of each component of the data governance platform, and perform real-time parsing and correlation analysis on the logs; for the data encryption process, monitor the running status of the encryption algorithm, the usage of keys, and the integrity of the encrypted data in real time; regularly scan the data governance platform through vulnerability scanning tools, and monitor and handle the vulnerability situation of the data governance platform in real time;
[0063] Monitor the CPU usage rate, memory usage rate, and disk I / O read and write rate of the server used by the data governance platform in real time, set thresholds, and issue an alarm when the indicators exceed the thresholds. Then, use an automated resource allocation tool to perform resource allocation according to the resource usage of the data processing platform; monitor the data processing performance of the data governance platform, and evaluate the impact of the encryption and decryption processes on the data governance platform.
[0064] Due to the adoption of the above technical solution, the technical progress achieved by the present invention compared with the prior art is as follows: A method for constructing a data governance platform based on a data encryption algorithm in the present invention, compared with the traditional method for constructing a data governance platform based on a data encryption algorithm, the natural language processing (NLP) technology, neural network technology and modern information technology in the method of the present invention are closely combined to accurately capture the sensitivity, value and relevance data of the data, obtain accurate data type classification results, and achieve real-time and comprehensive determination of the data security level. By selecting a suitable encryption algorithm, designing a secure key management mechanism, and determining an appropriate encryption form, mode, tool and library accordingly, the problem that in the aspect of key management, the prior art cannot guarantee the security of the key according to the complexity and sensitivity of the link is solved. Once a loophole appears in key management, it will pose a serious threat to the security of the entire data encryption system; in terms of performance, although data encryption provides guarantee for data security, the encryption and decryption operations will inevitably consume additional computing resources. When the computing resource allocation fails to be reasonably optimized, it may lead to a decline in system performance and affect the timeliness of business response, which has a certain obstacle to the efficient operation of the data governance platform. The method of the present invention can refine the dynamic monitoring standard of a method for constructing a data governance platform based on a data encryption algorithm within a more accurate range, making the monitored data become more accurate indicators under the same conditions. The research and application of this method significantly enhance the degree of intelligence in the construction and operation process of the data governance platform. Description of the Drawings
[0065] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.
[0066] Figure 1 It is a flowchart of a method for constructing a data governance platform based on a data encryption algorithm of the present invention. Specific embodiments
[0067] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the protection scope of the present invention.
[0068] As Figure 1 shown, the present invention provides a method for constructing a data governance platform based on a data encryption algorithm, which consists of the following steps:
[0069] Step 1: Identify the data types protected by the data governance platform, including top-secret data, confidential data, and secret data, and select a suitable encryption algorithm according to the data types, providing data support for the subsequent process of designing the data governance platform;
[0070] Step 2: Design mechanisms for key generation, storage, distribution, update, and destruction according to the data types protected by the data governance platform;
[0071] Step 3: Select the granularity encryption form, granularity encryption mode, encryption tool, and encryption library according to the data types protected by the data governance platform;
[0072] Step 4: Design the system architecture of the data governance platform, determine the interfaces between the data encryption module and other system architecture layers, and formulate a data flow security control plan;
[0073] Step 5: Divide modules for the overall code structure according to the system architecture design, and match the code to implement the data encryption function;
[0074] Step 6: Test the encryption function, including unit testing, integration testing, and performance testing, to ensure that the errors of the data governance platform are within a controllable range;
[0075] Step 7: Have the data governance platform reviewed by security experts, and deploy the data governance platform that has completed testing and review to the production environment to improve the reliability of the data governance platform;
[0076] Step Eight: Conduct security monitoring and performance evaluation on the data governance platform.
[0077] In Step One, the process of clarifying the data types protected by the data governance platform and selecting a suitable encryption algorithm includes:
[0078] Use text processing software to establish a sensitive keyword library, set a pattern for identifying sensitive data formats, and use NLP for semantic analysis to obtain the sensitivity of the data;
[0079] Statistically obtain all the resources invested in the data acquisition process, evaluate the benefits brought by the data from multiple perspectives, and check the scarcity of the data in the industry to obtain the value score of the data;
[0080] Draw a data storage architecture diagram, obtain the relationships between different data storage systems, review the association relationships between database tables, and combine data mining techniques to discover the potential associations between data to obtain the relevance of the data;
[0081] According to the sensitivity of vocabulary and semantics, divide the data sensitivity into three levels: high, medium, and low; according to the level of the value score, divide the data value into three levels: high, medium, and low; according to the association relationship between data, divide the data relevance into three levels: high, medium, and low;
[0082] Build a neural network architecture, adopt a multi-layer perceptron structure, the input layer is the levels of data sensitivity, value, and relevance. Among them, the output layer is the data types protected by the data governance platform, and the number of output nodes is set to 3, namely top-secret data, confidential data, and secret data. Use the input layer data to train the model to obtain the relationship between the levels of data sensitivity, value, and relevance and the corresponding data types protected by the data governance platform;
[0083] Conduct performance evaluation on the neural network model, adjust the parameters to optimize the neural network model, obtain the data type classification model, and then input the levels of data sensitivity, value, and relevance into the model to obtain the data types protected by the data governance platform;
[0084] For top-secret data, select the AES algorithm; for confidential data, select the RSA algorithm; for secret data, select the DES algorithm. Among them, the AES algorithm and the DES algorithm are symmetric algorithms, and the RSA algorithm is an asymmetric algorithm.
[0085] In Step Two, the process of designing key generation, storage, distribution, update, and destruction mechanisms includes:
[0086] Generate a key using a cryptographically secure pseudorandom number generator. During the key generation process, set a seed value that originates from the entropy source of the Windows system, initialize the pseudorandom number generator, and determine the length and format of the key according to the requirements of the encryption algorithm and security needs.
[0087] Use a hardware security module to store the key. Store the generated key in the internal key storage area of the HSM. Only authorized users can interact with the HSM, where the hardware security module is the HSM.
[0088] Use the SSL / TLS protocol to distribute the key. On the sender side, send the key to the receiver through a secure channel. On the receiver side, use the decryption key to decrypt the received key.
[0089] According to the data types protected by the data governance platform, formulate a strategy for regularly updating the key. For the encryption key of top-secret data, set to update once a month; for the encryption key of confidential data, set to update once a quarter; for the encryption key of secret data, set to update once every six months.
[0090] Adopt secure deletion technology. Destroy the keys no longer used in the HSM through the method of multiple overwrite writes, and establish a key destruction record mechanism to record each key destruction operation.
[0091] In step three, the process of selecting the granularity encryption form, granularity encryption mode, encryption tool, and encryption library includes:
[0092] Select the granularity encryption form as file-level encryption and field-level encryption. Among them, file-level encryption is used to encrypt the entire file, and field-level encryption is used to encrypt specific fields.
[0093] Select the granularity encryption modes including CBC mode, CTR mode, and ECB mode. For top-secret data, select the CBC mode. After performing an exclusive OR operation on the ciphertext block and the current plaintext block, encrypt the plaintext block. For confidential data, select the CTR mode. After encrypting the value of the counter with the key, perform encryption through an exclusive OR operation with the plaintext. For secret data, select the ECB mode. Divide the plaintext into plaintext blocks of a fixed size and encrypt each plaintext block independently.
[0094] Select the encryption tool as the OpenSSL tool. The OpenSSL tool combines with the AES algorithm, RSA algorithm, and DES algorithm for encryption, which are respectively applicable to the encryption processes of top-secret data, confidential data, and secret data.
[0095] The encryption library is the Bouncy Castle library, which provides AES algorithm, RSA algorithm and DES algorithm, applicable to the encryption processes of top-secret data, confidential data and secret data respectively.
[0096] In Step 4, the process of designing the system architecture of the data governance platform, determining the interfaces between the data encryption module and other system architecture layers, and formulating the data flow security control plan includes:
[0097] Construct the data governance platform architecture, which is divided into a data source layer, a data collection layer, a data transmission layer, a data storage layer, a data processing layer, a data service layer, a user access layer and a data encryption module;
[0098] A real-time adaptive encryption trigger interface is used between the data encryption module and the data collection layer. When the data collected by the data collection layer arrives, the real-time adaptive encryption trigger interface conducts multi-dimensional analysis on the data and dynamically selects a matching encryption algorithm and encryption parameters based on the analysis results;
[0099] A hybrid encryption transmission adaptation interface is used between the data encryption module and the data transmission layer. This hybrid encryption transmission adaptation interface integrates multiple encryption technologies. In a conventional network environment, an encryption algorithm based on elliptic curve cryptography is used for encryption; in a network environment with potential security threats, quantum key distribution technology is utilized to generate a temporary key to perform secondary encryption on the data;
[0100] A dynamic storage encryption policy interface is used between the data encryption module and the data storage layer to monitor various indicators of data storage in real time and adjust the data encryption algorithm and encryption mode. Among them, the various indicators of data storage are the CPU usage rate, memory usage rate of the server and the disk I / O read and write rate;
[0101] A secure computing resource scheduling interface is used between the data encryption module and the data processing layer. This secure computing resource scheduling interface is used for encryption and decryption operations during the data processing process, and schedules computing resources according to the data processing task priority and resource requirements;
[0102] An encryption interface based on user intent is used between the data encryption module and the data service layer. When the data service layer receives a user's data request, the encryption interface based on user intent deeply understands the user's intent and performs corresponding encryption and decryption operations;
[0103] The links of the data flow security policy include data collection, data transmission, data storage, data processing, and data services. Among them, in the data collection link, artificial intelligence is used to evaluate the risk of data sources and hardware protection is carried out; in the data transmission link, adaptive network slicing technology is introduced for data adaptive encryption, and blockchain technology is used to verify data integrity; in the data transmission link, biometric recognition is combined with encryption operations; in the data processing link, trusted execution environment technology and secure multi-party computing technology are integrated to build a secure data processing environment, and artificial intelligence is used for anomaly monitoring; in the data service link, encrypted watermark technology is introduced to protect data.
[0104] In step five, according to the system architecture design, the process of dividing the overall code structure into modules and matching the code to implement the data encryption function includes:
[0105] The data encryption function includes the integration of data encryption algorithms, the implementation of a key management system, and the application of data encryption policies;
[0106] The overall code is divided into three modules, including a data encryption algorithm integration module, a key management system module, and a data encryption policy application module, and the code is matched for the data encryption algorithm integration module, the key management system module, and the data encryption policy application module to achieve encryption;
[0107] For the data encryption algorithm integration module, the cryptography library in Python is selected, and an encryption algorithm call interface function is created. This encryption algorithm call interface function is used to call the interface between the data encryption module and other system architecture layers;
[0108] For the key management system module, the key management process includes key generation, key storage, key retrieval, key update, and key deletion. An object-oriented programming method is adopted. In the key generation process, a byte sequence key of a specified length is generated using a secure pseudo-random number generator inside the function; in the key storage process, a key class is created to represent the key object, and the SQLite database is used to persist the key object information. The generated key class object is stored in the database using the store_key function; in the key retrieval process, the get_key function is used to query and obtain the corresponding key class object from the database according to the incoming key ID, and a decryption operation is performed to restore the original key content and send it to the caller; in the key update process, the key attributes are updated according to specific modifications through the update_key function; in the key deletion process, the corresponding key record is deleted from the database according to the incoming key ID through the delete_key function;
[0109] The data encryption policy application module creates a configuration file, divides policy blocks according to data types. Each policy block includes a data identifier, an encryption algorithm name, and a key usage rule. Configure the encrypt_data function to find the encryption policy according to the data identifier and call the encrypt_aes encryption function for encryption operations; configure the decrypt_data function to find the decryption policy according to the data identifier and call the decrypt_aes encryption function for decryption operations.
[0110] In step six, the process of unit testing includes:
[0111] The unit testing is divided into symmetric encryption algorithm testing, asymmetric encryption algorithm testing, key management system testing, and data encryption policy testing;
[0112] In unit testing, for symmetric encryption algorithm testing, prepare plaintext data of different lengths and contents, and test the symmetric encryption algorithm by detecting the consistency between the key after encrypting with the AES algorithm and the DES algorithm and the original plaintext;
[0113] For asymmetric encryption algorithm testing, prepare plaintext data of different lengths and contents, and test the asymmetric encryption algorithm by detecting the consistency between the key after encrypting with the RSA algorithm and the original plaintext;
[0114] For key management system testing, it includes key generation, storage, retrieval, update, and deletion processes. Test the key generation process by the length and format specifications of the generated key;
[0115] Test the key storage process by checking the encryption processing of the stored key; test the key retrieval process by verifying the consistency between the retrieved key and the key content before storage;
[0116] Test the key update process by checking the situation of triggering the update mechanism;
[0117] Test the key deletion process by checking the remaining situation of key deletion and cleaning;
[0118] For data encryption policy testing, determine the matching situation between the representation of the test data and the encryption policy to test the data encryption policy.
[0119] In step six, the processes of integration testing and performance testing include:
[0120] The integration testing is divided into integration testing of encryption algorithms and key management systems, integration testing of encryption algorithms and data encryption policies, and integration testing of key management systems and data encryption policies; the performance testing is divided into encryption speed testing, decryption speed testing, and resource occupancy testing;
[0121] In the integration test, the integration test of the encryption algorithm and the key management system is carried out according to the encryption situation of obtaining the key from the key management system during the encryption process; the integration of the encryption algorithm and the data encryption policy is tested through the consistency between the decryption result obtained by the encryption algorithm and the decryption result obtained by the data encryption policy; the integration test of the key management system and the data encryption policy is carried out by using the consistency between the decryption result obtained through the key management system and the decryption result obtained through the data encryption policy.
[0122] In the performance test, the encryption speed is tested by comparing the time taken by the symmetric encryption algorithm and the asymmetric encryption algorithm to encrypt data of the same length; the decryption speed is tested by comparing the decryption times for different data; the peak and average occupancy of resources during encryption and decryption under different algorithms and different data volumes are tested to evaluate the degree of resource consumption, and the resource occupancy during the data encryption and decryption processes is tested.
[0123] Step Seven, the process of having a security expert review the data governance platform and deploying the data governance platform that has completed testing and review to the production environment includes:
[0124] Prepare the corresponding review materials based on top-secret data, confidential data, and secret data. The security expert reviews the data governance platform according to regulations. The review content includes the implementation of the data encryption policy, the security of the key management mechanism, and the selection and configuration of encryption tools. Then, the data governance platform that has completed testing and review is deployed to the production environment.
[0125] Step Eight, the process of performing security monitoring and performance evaluation on the data governance platform includes:
[0126] Establish a security monitoring system, deploy network traffic monitoring tools, and analyze the network traffic entering and leaving the data governance platform in real time; collect and manage the logs of each component of the data governance platform, and perform real-time parsing and correlation analysis on the logs; for the data encryption process, monitor the running status of the encryption algorithm, the usage of keys, and the integrity of the encrypted data in real time; regularly scan the data governance platform with a vulnerability scanning tool, monitor the vulnerability situation of the data governance platform in real time and perform corresponding processing;
[0127] Monitor the CPU usage rate, memory usage rate, and disk I / O read and write rate of the server used by the data governance platform in real time, set thresholds, and issue an alarm when the metrics exceed the thresholds. Then, use an automated resource allocation tool to perform resource allocation according to the resource usage of the data processing platform; monitor the data processing performance of the data governance platform and evaluate the impact of the encryption and decryption processes on the data governance platform.
[0128] As described above, it is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claimed rights.
Claims
1. A method for constructing a data governance platform based on a data encryption algorithm, characterized in that: Including the following steps: Step 1: Identify the data types protected by the data governance platform, including top-secret data, confidential data, and secret data, and select an encryption algorithm according to the data types; Step 2: Design mechanisms for key generation, storage, distribution, update, and destruction according to the data types protected by the data governance platform; Step 3: Select the granularity encryption form, granularity encryption mode, encryption tool, and encryption library according to the data types protected by the data governance platform; Step 4: Design the system architecture of the data governance platform and formulate a data flow security control plan; Step 5: Divide modules for the overall code structure according to the system architecture design, and match the code to implement the data encryption function; Step 6: Test the encryption function, including unit testing, integration testing, and performance testing; Step 7: Review the data governance platform and deploy the data governance platform that has completed testing and review to the production environment; Step 8: Conduct security monitoring and performance evaluation on the data governance platform.
2. A method for constructing a data governance platform based on a data encryption algorithm according to claim 1, characterized in that: In the above Step 1, the process of identifying the data types protected by the data governance platform and selecting an encryption algorithm includes: Using text processing software, establish a sensitive keyword library, set the mode for identifying sensitive data formats, and use NLP for semantic analysis to obtain the sensitivity of the data; Statistically analyze all resources invested in the process of obtaining data, evaluate the benefits brought by the data from multiple perspectives, and check the scarcity of the data in the industry to obtain the value score of the data; Draw a data storage architecture diagram, obtain the relationships between different data storage systems, review the association relationships between database tables, and combine data mining techniques to discover potential associations between data to obtain the relevance of the data; According to the sensitivity of vocabulary and semantics, divide the data sensitivity into three levels: high, medium, and low; according to the high and low value scores, divide the data value into three levels: high, medium, and low; according to the association relationships between data, divide the data relevance into three levels: high, medium, and low; Construct a neural network architecture, adopt a multi-layer perceptron structure, with the input layer being the levels of data sensitivity, value, and relevance. Among them, the output layer is the data types protected by the data governance platform, and the number of output nodes is set to 3, namely top-secret data, confidential data, and secret data. Use the input layer data to train the model to obtain the relationship between the levels of data sensitivity, value, and relevance and the corresponding data types protected by the data governance platform; Conduct performance evaluation on the neural network model, adjust the parameters to optimize the neural network model, obtain the data type classification model, and then input the levels of data sensitivity, value, and relevance into the model to obtain the data types protected by the data governance platform; For top-secret data, select the AES algorithm; for confidential data, select the RSA algorithm; for secret data, select the DES algorithm. Among them, the AES algorithm and the DES algorithm are symmetric algorithms, and the RSA algorithm is an asymmetric algorithm.
3. A method for constructing a data governance platform based on a data encryption algorithm according to claim 2, characterized in that: In the above Step 2, the process of designing mechanisms for key generation, storage, distribution, update, and destruction includes: Generate a key using a cryptographically secure pseudo-random number generator. During the key generation process, set a seed value that is sourced from the entropy source of the Windows system, initialize the pseudo-random number generator, and determine the length and format of the key according to the requirements of the encryption algorithm and security needs. Store the key using a hardware security module. Store the generated key in the internal key storage area of the HSM. Only authorized users can interact with the HSM. Here, the hardware security module is the HSM. Distribute the key using the SSL / TLS protocol. On the sender side, send the key to the receiver through a secure channel. On the receiver side, decrypt the received key using the decryption key. Based on the data types protected by the data governance platform, formulate a strategy for regularly updating the key. For the encryption key of top-secret data, set to update it once a month. For the encryption key of confidential data, set to update it once a quarter. For the encryption key of secret data, set to update it once every six months. Adopt secure deletion technology. Destroy the keys that are no longer used in the HSM through the method of multiple overwrite writes, and establish a key destruction record mechanism to record each key destruction operation.
4. A method for constructing a data governance platform based on a data encryption algorithm according to claim 3, characterized in that: In step three, the process of selecting the granularity encryption form, granularity encryption mode, encryption tool, and encryption library includes: Select the granularity encryption form as file-level encryption and field-level encryption. Among them, file-level encryption is used to encrypt the entire file, and field-level encryption is used to encrypt specific fields. Select the granularity encryption modes including CBC mode, CTR mode, and ECB mode. For top-secret data, select the CBC mode. After performing an exclusive OR operation on the ciphertext block and the current plaintext block, encrypt the plaintext block. For confidential data, select the CTR mode. After encrypting the value of the counter with the key, perform an exclusive OR operation with the plaintext for encryption. For secret data, select the ECB mode. Divide the plaintext into plaintext blocks of a fixed size and encrypt each plaintext block independently. Select the encryption tool as the OpenSSL tool. The OpenSSL tool is combined with the AES algorithm, RSA algorithm, and DES algorithm for encryption, which are respectively applicable to the encryption processes of top-secret data, confidential data, and secret data. The encryption library is the Bouncy Castle library. The Bouncy Castle library provides the AES algorithm, RSA algorithm, and DES algorithm, which are respectively applicable to the encryption processes of top-secret data, confidential data, and secret data.
5. A method for constructing a data governance platform based on a data encryption algorithm as claimed in claim 4, characterized in that: In step four, the process of designing the system architecture of the data governance platform and formulating a data flow security control plan includes: Construct the data governance platform architecture, which is divided into a data source layer, a data collection layer, a data transmission layer, a data storage layer, a data processing layer, a data service layer, a user access layer, and a data encryption module. Use a real-time adaptive encryption trigger interface between the data encryption module and the data collection layer. When the data collection layer collects data, the real-time adaptive encryption trigger interface performs multi-dimensional analysis on the data and dynamically selects a matching encryption algorithm and encryption parameters based on the analysis results. A hybrid encryption transmission adaptation interface is used between the data encryption module and the data transmission layer. This hybrid encryption transmission adaptation interface integrates multiple encryption technologies. In a conventional network environment, an encryption algorithm based on elliptic curve cryptography is used for encryption; in a network environment with potential security threats, the quantum key distribution technology is utilized to generate temporary keys for secondary encryption of the data. A dynamic storage encryption policy interface is used between the data encryption module and the data storage layer to monitor various indicators of data storage in real time and adjust the data encryption algorithm and encryption mode. Among them, the various indicators of data storage are the CPU usage rate, memory usage rate, and disk I / O read and write rate of the server. A secure computing resource scheduling interface is used between the data encryption module and the data processing layer. This secure computing resource scheduling interface is used for encryption and decryption operations during the data processing process, and schedules computing resources according to the data processing task priority and resource requirements. An encryption interface based on user intent is used between the data encryption module and the data service layer. When the data service layer receives a user's data request, the encryption interface based on user intent deeply understands the user's intent and performs corresponding encryption and decryption operations. The links of the data flow security policy include data collection, data transmission, data storage, data processing, and data service. Among them, in the data collection link, artificial intelligence is used to evaluate the risk of data sources and perform hardware protection; in the data transmission link, the adaptive network slicing technology is introduced for adaptive data encryption, and the blockchain technology is used to verify the data integrity; in the data transmission link, biometric recognition is combined with encryption operations; in the data processing link, the trusted execution environment technology and the secure multi-party computing technology are integrated to build a secure data processing environment, and artificial intelligence is used for anomaly monitoring; in the data service link, the encryption watermark technology is introduced to protect the data.
6. A method for constructing a data governance platform based on a data encryption algorithm according to claim 5, characterized in that: In step five, according to the system architecture design, the process of dividing the overall code structure into modules and matching the code to implement the data encryption function includes: The data encryption function includes the integration of data encryption algorithms, the implementation of the key management system, and the application of data encryption policies. The overall code is divided into three modules, including the data encryption algorithm integration module, the key management system module, and the data encryption policy application module, and the code is matched to the data encryption algorithm integration module, the key management system module, and the data encryption policy application module to implement encryption. For the data encryption algorithm integration module, the cryptography library in Python is selected, and an encryption algorithm call interface function is created. This encryption algorithm call interface function is used to call the interface between the data encryption module and other system architecture layers. The key management system module has a key management process that includes key generation, key storage, key retrieval, key update, and key deletion. It adopts an object-oriented programming approach. During the key generation process, a byte sequence key of a specified length is generated using a secure pseudo-random number generator inside a function. During the key storage process, a key class is created to represent the key object, and the SQLite database is used to persist the key object information. The generated key class object is stored in the database using the store_key function. During the key retrieval process, the get_key function is used to query and obtain the corresponding key class object from the database based on the incoming key ID, and then a decryption operation is performed to restore the original key content, which is sent to the caller. During the key update process, the key attributes are updated according to specific modifications through the update_key function. During the key deletion process, the corresponding key record is deleted from the database based on the incoming key ID through the delete_key function. The data encryption policy application module creates a configuration file, divides the policy blocks according to data types, and each policy block includes a data identifier, an encryption algorithm name, and a key usage rule. The encrypt_data function is configured to find the encryption policy according to the data identifier and call the encrypt_aes encryption function for encryption operations. The decrypt_data function is configured to find the decryption policy according to the data identifier and call the decrypt_aes encryption function for decryption operations.
7. A method for constructing a data governance platform based on a data encryption algorithm according to claim 6, characterized in that: In step six, the process of unit testing includes: The unit testing is divided into symmetric encryption algorithm testing, asymmetric encryption algorithm testing, key management system testing, and data encryption policy testing; In unit testing, for symmetric encryption algorithm testing, plaintext data of different lengths and contents are prepared, and the symmetric encryption algorithm is tested by detecting the consistency between the key after encryption by the AES algorithm and DES algorithm and the original plaintext. For asymmetric encryption algorithm testing, plaintext data of different lengths and contents are prepared, and the asymmetric encryption algorithm is tested by detecting the consistency between the key after encryption by the RSA algorithm and the original plaintext. For key management system testing, it includes the key generation, storage, retrieval, update, and deletion links. The key generation process is tested by the length and format specifications of the generated key. The key storage process is tested by checking the encryption processing of the stored key. The key retrieval process is tested by verifying the consistency between the retrieved key and the key content before storage. The key update process is tested by checking the situation of triggering the update mechanism. The key deletion process is tested by checking the remaining situation of key deletion and cleaning. For data encryption policy testing, the data encryption policy is tested by determining the matching situation between the representation of the test data and the encryption policy.
8. A method for constructing a data governance platform based on a data encryption algorithm according to claim 7, characterized in that: In step six, the process of integration testing and performance testing includes: The integration tests include the integration test of the encryption algorithm and the key management system, the integration test of the encryption algorithm and the data encryption policy, and the integration test of the key management system and the data encryption policy; the performance tests include the encryption speed test, the decryption speed test, and the resource occupancy test; In the integration tests, the integration test of the encryption algorithm and the key management system is tested according to the encryption situation of obtaining keys from the key management system during the encryption process; the integration of the encryption algorithm and the data encryption policy is tested through the consistency between the decryption results obtained by the encryption algorithm and the decryption results obtained by the data encryption policy; the integration test of the key management system and the data encryption policy is carried out by using the consistency between the decryption results obtained through the key management system and the decryption results obtained through the data encryption policy; In the performance tests, the encryption speed is tested by comparing the time taken by the symmetric encryption algorithm and the asymmetric encryption algorithm to encrypt data of the same length; the decryption speed is tested by comparing the decryption times for different data; the peak and average occupancy of resources during encryption and decryption under different algorithms and different data volumes are tested to evaluate the degree of resource consumption, and the resource occupancy during the data encryption and decryption processes is tested.
9. A method for constructing a data governance platform based on a data encryption algorithm according to claim 8, characterized in that: The process of step seven, where a security expert reviews the data governance platform and deploys the data governance platform that has completed testing and review to the production environment, includes: According to top-secret data, confidential data, and secret data, prepare the corresponding review materials to review the data governance platform. The review content includes the implementation of the data encryption policy, the security of the key management mechanism, and the selection and configuration of encryption tools. Then, deploy the data governance platform that has completed testing and review to the production environment.
10. A method for constructing a data governance platform based on a data encryption algorithm according to claim 9, characterized in that: The process of step eight, where security monitoring and performance evaluation of the data governance platform are carried out, includes: Establish a security monitoring system, deploy network traffic monitoring tools, and analyze the network traffic entering and leaving the data governance platform in real time; collect and manage the logs of each component of the data governance platform, and perform real-time parsing and correlation analysis on the logs; for the data encryption process, monitor the running status of the encryption algorithm, the usage of keys, and the integrity of encrypted data in real time; regularly scan the data governance platform with a vulnerability scanning tool, and monitor and handle the vulnerability situation of the data governance platform in real time; Monitor the CPU usage rate, memory usage rate, and disk I / O read and write rate of the server used by the data governance platform in real time, set thresholds, and issue an alarm when the metrics exceed the thresholds. Then, use an automated resource allocation tool to perform resource allocation according to the resource usage of the data processing platform; monitor the data processing performance of the data governance platform and evaluate the impact of the encryption and decryption processes on the data governance platform.