Dynamic transaction auditing system and method oriented to industrial application software heterogeneous environment

By building a dynamic transaction audit system in a heterogeneous environment of industrial application software, the problems of insufficient information security protection and high system coupling in traditional audit solutions are solved, cross-store transaction tracking and flexible configuration are realized, and data security and reliability are ensured.

CN120337211AActive Publication Date: 2025-07-18BEIJING CSSCA TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510775761.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-11
Publication Date
2025-07-18
Estimated Expiration
2045-06-11

AI Technical Summary

Technical Problem

Traditional industrial application software has problems such as low level of information security protection, high level of system coupling, poor integration, and single audit strategy model in terms of security audits. It is difficult to achieve cross-store transaction audit tracking and flexible configuration in the heterogeneous business database environment.

Method used

It provides a dynamic transaction audit system for industrial application software heterogeneous environments, including audit databases, audit servers, audit management tools and application servers. It manages audits through dynamic configuration policies, supports multiple database environments, achieves cross-system compatibility, and encrypts transmission and storage of sensitive data.

Benefits of technology

It realizes efficient and secure audit data storage and management in a heterogeneous environment, ensures the integrity and traceability of audit data, reduces labor costs, and improves abnormal detection efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337211A_ABST
    Figure CN120337211A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a dynamic transaction auditing system and method oriented to an industrial application software heterogeneous environment. The system comprises an audit database, an audit server, an audit management tool and an application server. The audit database is used for storing audit management files. And the auditing server is used for communicating with the transaction auditing service in the application server, and creating and maintaining the auditing management file stored in the auditing database. And the auditing management tool is used for providing a user interface of the dynamic transaction auditing system, interacting with a user and realizing configuration management and auditing management in a dynamic transaction auditing process. And the application server is used for communicating with the auditing server and providing transaction auditing service. In this way, audit management can be carried out based on the dynamic configuration strategy, and the requirements of industrial application software in the aspect of system security are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of computer technology, and in particular to a dynamic transaction auditing system and method for heterogeneous environments of industrial application software. Background Art

[0002] The audit management function of industrial application software (such as Enterprise Resource Planning (ERP), Supply Chain Management (SCM), etc.) is the core mechanism to ensure the security and compliance operation of the whole process data of enterprise production, procurement, sales, etc. However, there are many problems in the security audit of traditional industrial application software. First, the traditional solution stores audit records in log files or business databases, and some plaintext storage forms are prone to the risk of leakage and tampering of sensitive business information. Second, the existing solutions have poor support for heterogeneous business databases, and it is difficult to support cross-database transaction audit tracking in a mixed database environment, unable to meet complex deployment requirements. In addition, the audit strategy modes and implementation technical methods of some industrial application software are too single, unable to perform audit tracking and flexible configuration at the database field level according to the enterprise organizational structure for complex transaction processing, with low abnormal detection efficiency and high labor costs.

[0003] Therefore, there is a need for a dynamic transaction auditing method for heterogeneous environments of industrial application software to solve the problems such as low information security protection level, high system coupling degree, poor integration, and single audit strategy mode existing in the existing audit management. Summary of the Invention

[0004] According to the embodiments of the present application, a dynamic transaction auditing solution for heterogeneous environments of industrial application software is provided, which can perform audit management based on dynamic configuration strategies and meet the requirements of industrial application software in terms of system security.

[0005] In the first aspect of the present application, a dynamic transaction auditing system for heterogeneous environments of industrial application software is provided. The system includes an audit database, an audit server, an audit management tool, and an application server; The audit database is used to store audit management files; The audit server is used to communicate with the transaction audit service in the application server, create and maintain the audit management files stored in the audit database; The audit management tool is used to provide a user interface for the dynamic transaction auditing system, interact with users, and implement configuration management and audit management during the dynamic transaction auditing process; The application server is used to communicate with the audit server and provide transaction audit services.

[0006] In a possible implementation, the audit management file includes a sequence file, an information file, an audit specification file, an audit definition file, and an overflow file.

[0007] In a possible implementation, the sequence file is used to store transaction audit data; The information file is used to store control information data related to the transaction audit data in the sequence file; The audit specification file is used to store audit specification data corresponding to the audit business table and the enterprise organization code; The audit definition file is used to store the storage location data of the sequence file and the information file; The overflow file is used to store transaction audit data that cannot be stored in the memory buffer because the memory buffer of the audit server is full.

[0008] In a possible implementation, the process of the audit server writing transaction audit data into the audit database includes: Initializing and allocating an audit processor; Querying whether the information file related to the transaction audit data exists. If it exists, reading and locking the header information of the information file related to the transaction audit data. If it does not exist, creating an information file and initializing it with default values; Querying the sequence file related to the transaction audit data, and respectively reading and comparing the sequence header files in the sequence file and the information file; If the sequence header files in the sequence file and the information file do not match, recording an error log and terminating the write operation; If the sequence header files in the sequence file and the information file match, writing the transaction audit data through the audit processor, updating the information file and the sequence file, and storing the write record in the two-phase dump file.

[0009] In a possible implementation, the process of the audit management tool performing audit configuration includes: Performing audit tracking attribute configuration on the enterprise organization and business tables that need to participate in the audit; Allocating the business tables to the corresponding business databases according to the business areas and audit requirements of the audit configuration; Maintaining the metadata definition of the business tables and performing audit tracking attribute configuration on the fields for dynamic transaction audit; Configuring the storage path of the audit management file; Maintaining the audit information file and the audit specification file according to the security access rights and operation options set by the system administrator for the audit users.

[0010] In a possible implementation, the audit management function of the audit management tool includes displaying the audit sequence, maintaining the audit information file, cleaning up the audit files, managing user audit security, checking the integrity of the audit files, and retrieving the content of the audit files.

[0011] In a possible implementation, the communication process between the audit server and the application server includes: The application server sends a start instruction to the audit server; The audit server establishes a communication connection with the process communication service of the application server through the connection service; The application server starts the session service of the audit server through the task scheduling service; Data query and audit management in the dynamic transaction audit process are implemented through the data access service in the application server and the cursor service in the audit server; The transaction audit service in the application server transfers the audit transactions to be processed to the transaction audit service in the audit server, and the audit server stores the audit records of the dynamic transaction audit in the audit database; When ending the dynamic transaction audit, the application server closes the session service of the audit server through the task scheduling service.

[0012] Optionally, the communication process further includes: When there is sensitive data in the audit data of the dynamic transaction audit, the sensitive data is encrypted through a key derivation function and an encryption algorithm.

[0013] In a possible implementation, the system further includes: Monitoring the transaction audit data through a transaction audit monitoring model; When an abnormal transaction occurs in the dynamic transaction audit, a warning signal is sent.

[0014] In the second aspect of the present application, a dynamic transaction audit method for an industrial application software heterogeneous environment is provided. This method can be executed according to any one of the first aspects of the present application.

[0015] The dynamic transaction auditing system for the heterogeneous environment of industrial application software provided by the embodiments of the present application includes an auditing database, an auditing server, an auditing management tool, and an application server. The auditing database is used to store auditing management files. The auditing server is used to communicate with the transaction auditing service in the application server to create and maintain the auditing management files stored in the auditing database. The auditing management tool is used to provide a user interface for the dynamic transaction auditing system, interact with users, and implement configuration management and auditing management during the dynamic transaction auditing process. The application server is used to communicate with the auditing server and provide transaction auditing services. By flexibly configuring tools and designing rigorous processes, the complexity of auditing management for industrial application software is reduced, the integrity and traceability of auditing data are ensured, and different software platforms and databases in the industrial field are effectively compatible. At the same time, sensitive data is encrypted during transmission and storage and fine-grained permission control is performed, effectively avoiding security risks.

[0016] It should be understood that the content described in the summary of the invention section is not intended to limit the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understood through the following description. Brief Description of the Drawings

[0017] Combined with the drawings and referring to the following detailed description, the above and other features, advantages, and aspects of the embodiments of the present application will become more obvious. In the drawings, the same or similar reference numerals represent the same or similar elements, where: Figure 1 It is a schematic diagram of the dynamic transaction auditing system for the heterogeneous environment of industrial application software provided by the embodiments of the present application; Figure 2 It is a schematic diagram of the structure of the auditing management file according to the embodiments of the present application; Figure 3 It is a schematic diagram of the process of writing transaction auditing data into the auditing database according to the embodiments of the present application; Figure 4 It is a schematic diagram of the auditing configuration by the auditing management tool according to the embodiments of the present application; Figure 5 It is a schematic diagram of the communication structure between the auditing server and the application server according to the embodiments of the present application; Figure 6 It is a schematic diagram of the process of encrypted communication of sensitive data according to the embodiments of the present application. Detailed Description of the Embodiments

[0018] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Apparently, the described embodiments are some, but not all, of the embodiments of the present disclosure. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present disclosure without creative efforts shall fall within the scope of protection of the present disclosure.

[0019] In addition, the term "and / or" in this article is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.

[0020] Figure 1 The schematic diagram of the dynamic transaction auditing system provided by the embodiments of the present application for the heterogeneous environment of industrial application software is as Figure 1 shown: The system includes an auditing database, an auditing server, an auditing management tool, and an application server; The auditing database is used to store auditing management files; The auditing server is used to communicate with the transaction auditing service in the application server, and create and maintain the auditing management files stored in the auditing database; The auditing management tool is used to provide a user interface for the dynamic transaction auditing system, interact with users, and implement configuration management and auditing management in the dynamic transaction auditing process; The application server is used to communicate with the auditing server and provide transaction auditing services.

[0021] In addition, the business application program is a single business interface for auditors to perform dynamic transaction auditing and management. The system management database is a database directly called and managed by the application server. The business database is used to store the auditing data in the business application program. The system management database and the business database include, but are not limited to, relational databases (such as Oracle, DB2, SQL Server, MySQL, etc.), non-relational databases, and distributed databases.

[0022] In this embodiment, the dynamic transaction auditing system can dynamically configure and manage the auditing requirements of industrial software on different platforms and databases, achieving cross-system compatibility. At the same time, it provides reliable full-process auditing transaction records, traceable auditing data storage, and a unified security management interface.

[0023] Optionally, the auditing management files include sequence files, information files, auditing specification files, auditing definition files, and overflow files.

[0024] Figure 2 A schematic structural diagram of an audit management file according to an embodiment of the present application is as Figure 2 shown.

[0025] In the present application, the audit database serves as the storage engine for audit management and is a collection of all audit management files, containing all the audit data required to be managed during the dynamic transaction audit. During the storage process of audit data, regardless of the type of business database selected for the dynamic transaction audit or the simultaneous use of multiple heterogeneous databases, the creation and management methods of the audit database for audit management files always remain consistent, not only ensuring the standardization and systematicness of the storage of audit data but also providing convenient conditions for subsequent audit data analysis and management based on different organizational structures.

[0026] Optionally, the sequence file is used to store transaction audit data; The information file is used to store control information data related to the transaction audit data in the sequence file; The audit specification file is used to store audit specification data corresponding to the audit business table and the enterprise organization code; The audit definition file is used to store the storage location data of the sequence file and the information file; The overflow file is used to store transaction audit data that cannot be stored in the memory buffer because the memory buffer of the audit server is full.

[0027] In some embodiments, the sequence file is used to store transaction audit data. Each sequence file contains multiple pieces of audit data in the dynamic transaction audit, that is, various operations performed by the application on different databases during the dynamic transaction audit. Inside the sequence file, it includes but is not limited to the table name of the business table and the enterprise organization number. On this basis, the naming format of the sequence file is: a <mmmnnn><Enterprise Organization Code>.<Sequence File Number>, where "a" is the audit file identifier, used to clarify that the file belongs to the audit category; "mmm" is the name of the module being audited, through which the module to which the audit data belongs can be quickly located by a concise identifier; "nnn" is the number of the business table being audited, facilitating the accurate identification of business table information; "Enterprise Organization Code" is the enterprise organization code of the enterprise being audited, which can clearly define the organizational level of the data source; the value range of "Sequence File Number" is 000 - 999, used to distinguish different sequence files under the same type of audit data. For example, in a sequence file 002, which contains the business table itm001 to be dynamically audited and the enterprise organization 812, and the sequence file number is 002, then the name of this sequence file is aitm001812.002. In addition, a sequence header is set at the starting position of each sequence file, and the content recorded in the sequence header includes but is not limited to the creation situation of the sequence file, the current status, and the information contained in the sequence file. Specifically, the data structure of the sequence header in the sequence file is shown in Table 1: Table 1 Data Structure of the Sequence Header in the Sequence File

[0028] Among them, "Length" is the data length range of the whole sequence; "Sequence Number" is the unique number identifier of this sequence file in the entire audit data system; the formats of "Start Time" and "End Time" are "YYYYMMDDHHMMSS", used to record the time points of the start record and the end record of the audit data in the sequence file; "Status" indicates the current status of this sequence file, such as whether it is being written, completed, etc.; "Transaction Quantity" is the specific quantity of the dynamic audit transactions contained in the sequence file; "Application Information 1 - 4" is used to store specific information related to the application, providing more dimensional data support for subsequent analysis; "Audit Field Quantity" is the total number of audit fields in the sequence file; "Primary Key Field Quantity" is the total number of primary key fields in the sequence file; "Reserved Space" facilitates future possible function expansion or audit data supplementation. A transaction header is also set in each sequence file. For each dynamic audit transaction recorded in the sequence file, a transaction header and one to several rows of transaction data (i.e., audit rows) are configured. Specifically, the data structure of the transaction header in the sequence file is shown in Table 2: Table 2 Data Structure of the Transaction Header in the Sequence File

[0029] Among them, the user identifier is a unique identifier for the user identity executing the dynamic audit transaction; the system username is the username information recorded for operations executed at the system level; the audit date is the date and time when the dynamic transaction audit occurs recorded in a specific format; the session name is the session name used to mark the session when the dynamic audit transaction is executed; the transaction status is used to reflect the current status of the transaction, such as success, failure, or in progress, etc.; the number of audit rows is used to display the number of audit rows corresponding to the dynamic audit transaction; the number of bytes updated by the transaction is the number of bytes occupied by the audit data update during the audit execution of the dynamic audit transaction.

[0030] In some embodiments, the information file is used to store control information data related to the transaction audit data in the sequence file, and is mainly composed of an information header and a copy of the sequence header specifying the combination of the business table and the enterprise organizational structure code. The naming format of the information file is: a <mmmnnn><Enterprise Organization Code>.inf, where "a" is the audit file identifier, used to clarify that the file belongs to the audit category; "mmm" is the name of the module being audited, and through this concise identifier, the module to which the audit data belongs can be quickly located; "nnn" is the number of the business table being audited, facilitating the accurate identification of business table information; "Enterprise Organization Code" is the enterprise organization code of the entity being audited, enabling a clear definition of the organizational level of the data source; "inf" is the specific identifier of the information file, facilitating quick identification from among numerous file types. For example, an information file containing business table itm001 and enterprise organization code 812 can be named aitm001812.inf. Additionally, each information file has an information header that contains control parameter information related to the transaction audit data in the sequence file. Specifically, the data structure of the information header in the information file is shown in Table 3: Table 3 Data Structure of the Information Header in the Information File

[0031] Among them, the version number is the version followed by the information file, facilitating version management and compatibility judgment during system upgrades or maintenance; the table name is the name of the business table associated with the information file, ensuring an accurate correspondence between the data and the business table; the enterprise organization code is the enterprise organizational level corresponding to the information file, providing a clear data attribution identifier for audit management at different levels of the enterprise; the status is the current status of the information file, such as normal, abnormal, pending processing, etc., facilitating system operation and maintenance personnel to quickly understand the file status; the start sequence is the sequence number marking the starting position of the sequence file, providing a key index for data traceability and continuity management; the target sequence is the target sequence number expected to be reached under specific business logic or audit requirements, assisting the system in task planning and progress monitoring; the end sequence is the sequence number at the end position of the sequence file, helping the system accurately define the data scope; the maximum sequence byte count is used to set the maximum number of bytes that a single sequence file can accommodate; the security permission flag is the identifier of the security permission, used to clarify the access and operation permissions of different users or roles to this information file, ensuring data security and confidentiality; the current sequence is the sequence number currently being processed or associated, facilitating the system to track the current processing progress and position; the current offset is the offset position in the current sequence file, helping to more accurately locate and read the data; the reserved space is provided to facilitate future possible function expansion or audit data supplementation.

[0032] In some embodiments, the audit specification file is used to store audit specification data corresponding to the audit business table and the enterprise organization code, including but not limited to the definition of the scope of the sequence file, the setting of the maximum capacity of the sequence file, and the allocation of user permissions. The entry structure of the audit specification file is: :<enterprise organization code>: <reuse> : <range> <size> <sec>, where the table is one or more business tables to be audited; the enterprise organization code is the enterprise organization number to be audited; reuse is an optional override function identifier; range is used to set the quantity range of sequence files for auditing transaction records for a specific "business table / organization number" combination, and this range can cover up to 999 sequence files at most; size is the maximum capacity that a single sequence file can accommodate; sec is the security permission granted to the user. The maintenance methods of the audit specification file include but are not limited to automated audit configuration tools and manual editing and modification.

[0033] In some embodiments, the audit definition file is used to store the storage location data of sequence files and information files. During the setup process, it can contain a single entry, specifying a unified directory for all business tables of all enterprise organizations, or it can contain multiple entries to specify different directories for different "business table / enterprise organization" combinations respectively. Further, under each specified directory, there are multiple subdirectories, which are used to update the subdirectories corresponding to each module of the business table / enterprise organization to be audited. If the audit location file contains a single entry and only specifies one directory for all tables of all enterprise organizations, then each subdirectory will contain the audit files of several business table / enterprise organization combinations. If the audit location file contains multiple entries and specifies different directories for different business table / enterprise organization combinations, then each module subdirectory only contains the audit files of the specified business table / enterprise organization combination. The structure of the audit definition file is: :<enterprise organization>:<directory>, where the table is the entry table to be placed in the specified directory; the enterprise organization is the enterprise organization to be placed in the specified directory; the directory is the directory location where the combination of a specific "business table / enterprise organization" is located, and it is the specified path for storing the corresponding audit files.

[0034] In some embodiments, the overflow file is used to store transaction audit data that cannot be stored in the memory buffer because the memory buffer of the audit server is full. Specifically, each overflow file buffers data for all tables associated with a single session. Since the audit management mechanism allows multiple sessions to exist simultaneously on each audit server, multiple overflow files may be generated during actual operation. However, the overflow files are created in a temporary directory. When the relevant dynamic transaction audit work is completed, the system will automatically perform a cleanup operation to free up storage space and ensure the efficient operation of the system. The naming format of the overflow file is: aoflow.<session ID>.<process ID of the audit server>, where aoflow is the specific identification character of the overflow file; the session ID is the session identification name generated when the application is running, corresponding to a specific application session; and the process ID of the audit server is the process number assigned by the operating system to the audit server, which is used to uniquely identify the audit server process at the operating system level.

[0035] Figure 3 Schematic diagram of the process of writing transaction audit data to the audit database according to an embodiment of the present application, as Figure 3 shown.

[0036] The process of the audit server writing transaction audit data to the audit database includes: S301. Initialize and allocate an audit processor; S302. Query whether the information file related to the transaction audit data exists. If it exists, read and lock the header information of the information file related to the transaction audit data. If it does not exist, create an information file and initialize it with default values; S303. Query the sequence file related to the transaction audit data, and read and compare the sequence header files in the sequence file and the information file respectively; S304. If the sequence header files in the sequence file and the information file do not match, record an error log and terminate the write operation; S305. If the sequence header files in the sequence file and the information file match, write the transaction audit data through the audit processor, update the information file and the sequence file, and store the write record in the two-phase dump file.

[0037] In some embodiments, when the audit server performs a write operation for a dynamic audit transaction, it first needs to initialize and allocate an audit processor. The audit processor uses a data structure with a doubly linked list, and the specific structure is shown in Table 4: Table 4 Doubly linked list data structure in the audit processor

[0038] Among them, the sequence file descriptor is used to identify and operate on sequence files; the information file descriptor is used to identify and operate on information files; the audit processor status characterizes the working status of the audit processor; the audit metadata dictionary is used to store metadata related to audit data; the audit processing doubly linked list is used to manage multiple audit transactions, and with the characteristics of fast insertion and deletion, it dynamically processes audit tasks. For example, in a multi-transaction concurrent scenario, a new audit transaction can be quickly inserted into the doubly linked list for processing, and the processed audit transaction can be quickly deleted from the doubly linked list. Then, check whether the information file exists. If it does not exist, further check the audit directory. If the audit directory does not exist either, create the audit directory and the information file and initialize them with default values. After querying the information file, read and lock the information header in the information file to prevent other processes from modifying it. Then query and compare the sequence file to judge the existence, consistency, and availability of the sequence file. If the sequence file exists, read the sequence header information from the sequence file and the information file respectively and compare them. If they match, the sequence files are consistent. If they do not match, it is a serious error, record the error log and terminate the operation. In addition, the availability of the sequence file can be judged by checking the sequence file size, security level, and the metadata dictionary definition of the table. If the size of the sequence file does not meet the requirements and it is necessary, the current sequence file needs to be extended to the maximum allowed capacity. After judging the existence, consistency, and availability of the sequence file, write the sequence file status information to the sequence file and the information file to ensure that the two states are consistent. And after writing is completed, close the current sequence file, set the next sequence file as the current sequence file, and at the same time update the information file header, refresh the current sequence file information and offset. Finally, store the written records in the two-phase dump file for subsequent transaction recovery and audit tracking.

[0039] In this embodiment, through multi-level query and comparison, the correct update of the information file and the sequence file during the process of writing transaction audit data is ensured, and the secure storage of audit records is achieved.

[0040] Figure 4 A schematic diagram for auditing configuration of the audit management tool according to an embodiment of the present application is as Figure 4 shown.

[0041] The process of auditing configuration by the audit management tool includes: S401. Configure audit tracking attributes for enterprise organizational structures and business tables that need to participate in auditing; S402. According to the business areas and audit requirements of the audit configuration, allocate business tables to the corresponding business databases; S403. Maintain the metadata definition of business tables and configure audit tracking attributes for fields undergoing dynamic transaction auditing; S404. Configure the storage path of the audit management file; S405. Maintain the audit information file and the audit specification file according to the security access rights and operation options set by the system administrator for the audit user.

[0042] In this application, in order to track the operations in various heterogeneous databases such as business tables, audit databases, and business databases during the dynamic transaction audit process in real time, during the audit configuration, each operation or command executed in various databases will be recorded as a transaction in the audit database. Among them, the operations or commands executed in the database include, but are not limited to, creating tables, deleting tables, emptying tables, inserting rows, deleting rows, and updating rows. Further, specific instructions are set for characters in the audit database, specifically: C = create table; R = delete table; L = empty table; I = insert row; D = delete row; U = update row.

[0043] In this embodiment, the dynamic audit transaction is configured and managed through the audit management tool, realizing data tracking at the field level during the dynamic transaction audit process, and providing a basis for subsequent intelligent dynamic transaction audit.

[0044] Optionally, the audit management functions of the audit management tool include displaying the audit sequence, maintaining the audit information file, cleaning the audit file, managing user audit security, checking the integrity of the audit file, and retrieving the content of the audit file.

[0045] Among them, displaying the audit sequence is used to clearly and intuitively present the audit sequence, including but not limited to the audit process or data records arranged in a specific order; maintaining the audit information file is used to provide users with a comprehensive maintenance interface for the audit information file, including but not limited to creation, update, and backup operations; cleaning the audit file is used to clean the audit file regularly or on demand, release storage space, and optimize system performance; managing user audit security ensures that only authorized users can access and operate relevant audit data by setting strict access rights, authentication mechanisms, etc., thereby effectively preventing data leakage and illegal tampering; checking the integrity of the audit file verifies whether there are problems such as data loss and damage in the file through specific algorithms and verification mechanisms; retrieving the content of the audit file is used to retrieve the content of the audit file to different extents, and the retrieval conditions include but are not limited to keywords, time ranges, and data types.

[0046] In this embodiment, the audit management tool provides different audit management functions, enhancing the convenience and flexibility of users for specific management of audit data.

[0047] Optionally, the communication process between the audit server and the application server includes: The application server sends a start instruction to the audit server; The audit server establishes a communication connection with the process communication service of the application server through the connection service; The application server starts the session service of the audit server through the task scheduling service; Data query and audit management in the dynamic transaction audit process are realized through the data access service in the application server and the cursor service in the audit server; The transaction audit service in the application server transmits the audit transactions to be processed to the transaction audit service in the audit server, and the audit server stores the audit records of the dynamic transaction audit in the audit database; When ending the dynamic transaction audit, the application server closes the session service of the audit server through the task scheduling service.

[0048] Figure 5 FIG. is a schematic diagram of the communication structure between the audit server and the application server according to an embodiment of the present application, as Figure 5 shown.

[0049] The audit server includes a connection service, a session service, a cursor service, and a transaction audit service. Among them, the connection service is used to receive the start instruction or shutdown instruction sent by the application server, establish or disconnect the communication connection with the application server. The session service is used to start or close the session with the application server. The cursor service is used to open, move, and close the cursor according to the dynamic audit transaction operation in the application server, complete the browsing, addition, deletion, and update of the audit data, traverse the current audit data, and locate the record position. The transaction audit service is used to receive the audit transactions to be processed sent by the transaction audit service of the application server, and create and store the audit records. The application server includes a process communication service, a task scheduling service, a data access service, and a transaction audit service. Among them, the process communication service is used to send the start instruction or shutdown instruction to the audit server, establish or disconnect the communication connection with the audit server. The task scheduling service is used to start or close the session with the audit server. The data access service is used to guide the cursor service in the audit server to open, move, and close the cursor, complete the browsing, addition, deletion, and update of the audit data, traverse the current audit data, and locate the record position. The transaction audit service is used to execute commit transaction operations such as adding, deleting, and updating audit records or creating and deleting audit databases, send the transactions to be processed to the audit server, and realize the creation and storage of audit records.

[0050] Among them, the communication method between the audit server and the application server includes but is not limited to pipes, sockets (Socket), and HTTP / HTTPS communication.

[0051] In this embodiment, through modular design, the audit server and the application server achieve efficient connection, storage recording, and flexible configuration of audit data during dynamic transaction auditing, improving the integration of the dynamic audit transaction system.

[0052] Optionally, the communication process further includes: When there is sensitive data in the audit data during dynamic transaction auditing, the sensitive data is encrypted through a key derivation function and an encryption algorithm.

[0053] Among them, the key derivation function (KDF, Key derivation function) can securely convert and expand an initial secret value (such as a shared key or password) into one or more encryption keys with specific lengths and attributes, ensuring that the generated key material has strong randomness and security, meeting the security requirements of subsequent cryptographic operations (such as symmetric encryption or message authentication). The symmetric encryption algorithm includes but is not limited to the SM2 encryption algorithm and the SM4 encryption algorithm. Among them, the SM2 encryption algorithm is an asymmetric encryption algorithm, based on elliptic curve cryptography, with high security strength and fast encryption speed. The SM4 encryption algorithm is a symmetric encryption algorithm, which is a block cipher that uses 128-bit blocks and 128 / 192 / 256-bit keys for efficient data encryption and decryption.

[0054] Figure 6 It is a schematic flow diagram of sensitive data encrypted communication according to an embodiment of the present application, as Figure 6 shown: S601. The application server generates a temporary SM2 encryption master key according to the SM2 encryption algorithm, encrypts it with the public key of the audit server, and sends it to the audit server. The audit server decrypts it with the private key to obtain the symmetric temporary SM2 encryption master key; S602. The application server converts the SM2 encryption master key into an SM4 encryption master key according to the key derivation function and a random number; S603. Send the random number, the encrypted sensitive data encrypted with the SM4 encryption master key, and the integrity verification code to the audit server; S604. The audit server decrypts and verifies the encrypted sensitive data according to the received random number, the encrypted sensitive data encrypted with the SM4 encryption master key, the integrity verification code, and the key derivation function to obtain the sensitive data.

[0055] In addition, after the transmission of sensitive data ends, the audit server and the application server end the session. At the same time, the SM4 symmetric encryption master key generated through the key derivation function is erased, thereby minimizing the risk of key leakage. Even if the system is partially invaded, the historical session key cannot be restored.

[0056] In this embodiment, the sensitive data is encrypted through a key derivation function and a symmetric encryption algorithm, realizing the secure transmission of sensitive data in the dynamic transaction auditing process and enhancing the security of the system.

[0057] Optionally, the system further includes: Monitoring the transaction audit data through a transaction audit monitoring model; When an abnormal transaction occurs in the dynamic transaction audit, sending a warning signal.

[0058] In this application, the transaction audit monitoring model can automatically collect various types of audit data, perform preprocessing operations such as cleaning and conversion on the audit data according to specific criteria, and then perform real-time analysis on the dynamic transaction audit data to promptly capture any abnormal signs to ensure that problems can be discovered in the first time. Then, in accordance with the preset compliance rules, strictly review the dynamic audit transactions to ensure that all business operations comply with the requirements of relevant policies and regulations, and automatically generate an audit report with detailed content and standardized format based on the audit analysis results, greatly improving the efficiency and accuracy of report generation. In addition, the transaction monitoring model includes, but is not limited to, mechanism models.

[0059] In some embodiments, the transaction audit monitoring model can comprehensively analyze many complex factors such as industrial order priority, equipment production capacity, and personnel allocation, and deeply judge whether the production scheduling realizes the optimal resource utilization and the shortest life cycle. Once unreasonable points in the audit data are found, it can give a warning in time and provide targeted optimization suggestions.

[0060] In some embodiments, the transaction audit monitoring model can analyze information in many aspects such as historical sales data, market trends, and customer behavior. Further, through a demand forecasting model, it can conduct comprehensive audits and optimizations to help enterprises better respond to market changes. Among them, the demand forecasting model includes, but is not limited to, time series models and causal models.

[0061] In some embodiments, the transaction audit monitoring model can automatically start the sales order audit process, check the integrity and accuracy of the order information, prevent abnormal orders or incorrect order information from flowing into the production link, and thus ensure the smooth progress of industrial production activities.

[0062] In some embodiments, the transaction audit monitoring model can strictly review the purchase orders according to the preset enterprise purchase policies and processes, promptly discover violations, and quickly issue a warning to effectively prevent purchase risks and safeguard the interests of the enterprise.

[0063] In some embodiments, the transaction audit monitoring model can audit the expense reimbursement vouchers to verify their authenticity, compliance, and accuracy to ensure the financial health of the enterprise.

[0064] In some embodiments, the transaction audit monitoring model can automatically complete the inventory count work, improving the accuracy and efficiency of the count. At the same time, it can promptly detect inventory differences and potential management problems, providing strong support for enterprise inventory management.

[0065] In this embodiment, an automated dynamic transaction audit is realized in combination with the transaction audit monitoring model, saving human resources and improving the accuracy and automation of the audit.

[0066] According to the embodiments of the present disclosure, the following technical effects are achieved: 1) By flexibly configuring the dynamic transaction audit data in different industrial software environments through the audit management tool, the system heterogeneity problem in industrial application scenarios is effectively solved; 2) By strictly writing and storing the audit records of dynamic audit transactions through the audit server, it is ensured that the transaction audit data is accurately and persistently stored, providing a solid and reliable data basis for subsequent audit tracking; 3) For sensitive audit data, the key derivation function and symmetric encryption algorithm are used for end-to-end encrypted transmission and storage, effectively controlling the access to sensitive audit information and preventing the potential risk of unauthorized disclosure of audit data.

[0067] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.

[0068] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the described modules can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated here.

[0069] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0070] The units or modules involved in the embodiments described in the present application can be implemented in software or in hardware. The described units or modules can also be provided in a processor. Among them, the names of these units or modules do not, in some cases, constitute a limitation on the units or modules themselves.

[0071] The above description is only a preferred embodiment of the present application and an explanation of the technical principles applied. Those skilled in the art should understand that the scope of the application involved in the present application is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above application concept. For example, the technical solutions formed by mutually replacing the above features with (but not limited to) technical features having similar functions in the present application.< / sec> < / size> < / range> < / reuse> < / mmmnnn> < / mmmnnn>

Claims

1. A dynamic transaction auditing system for heterogeneous environments of industrial application software, characterized in that It includes an audit database, an audit server, an audit management tool, and an application server; The audit database is used to store audit management files; The audit server is used to communicate with the transaction audit service in the application server, and create and maintain the audit management files stored in the audit database; The audit management tool is used to provide a user interface for the dynamic transaction audit system, interact with users, and implement configuration management and audit management during the dynamic transaction audit process; The application server is used to communicate with the audit server and provide transaction audit services.

2. The dynamic transaction auditing system for heterogeneous environments of industrial application software according to claim 1, characterized in that The audit management files include sequence files, information files, audit specification files, audit definition files, and overflow files.

3. The dynamic transaction auditing system for heterogeneous environments of industrial application software according to claim 2, characterized in that, The sequence files are used to store transaction audit data; The information files are used to store control information data related to the transaction audit data in the sequence files; The audit specification files are used to store audit specification data corresponding to audit business tables and enterprise organization codes; The audit definition files are used to store the storage location data of the sequence files and the information files; The overflow files are used to store transaction audit data that cannot be stored in the memory buffer because the memory buffer of the audit server is full.

4. The dynamic transaction auditing system for heterogeneous environments of industrial application software according to claim 3, characterized in that, The process by which the audit server writes the transaction audit data into the audit database includes: Initializing and allocating audit processors; Querying whether an information file related to the transaction audit data exists. If it exists, reading and locking the header information of the information file related to the transaction audit data. If it does not exist, creating the information file and initializing it with default values; Querying the sequence file related to the transaction audit data, and respectively reading and comparing the sequence header files in the sequence file and the information file; If the sequence header files in the sequence file and the information file do not match, recording an error log and terminating the write operation; If the sequence header files in the sequence file and the information file match, writing the transaction audit data through the audit processor, updating the information file and the sequence file, and storing the write record in a two-phase dump file.

5. The dynamic transaction auditing system for heterogeneous environments of industrial application software according to claim 3, wherein The process by which the audit management tool performs audit configuration includes: Performing audit tracking attribute configuration on the enterprise organizations and business tables that need to participate in the audit; Allocating the business tables to the corresponding business databases according to the business areas and audit requirements of the audit configuration; Maintaining the metadata definition of the business tables, and performing audit tracking attribute configuration on the fields for which the dynamic transaction audit is performed; Configuring the storage path of the audit management files; Maintaining the audit information files and the audit specification files according to the security access permissions and operation options set by the system administrator for audit users.

6. The dynamic transaction auditing system for heterogeneous environments of industrial application software according to claim 1, characterized in that The audit management functions of the audit management tool include displaying audit sequences, maintaining audit information files, cleaning audit files, managing user audit security, checking the integrity of audit files, and retrieving the content of audit files.

7. The dynamic transaction auditing system for heterogeneous environments of industrial application software according to claim 1, characterized in that The communication process between the audit server and the application server includes: The application server sends a start instruction to the audit server; The audit server establishes a communication connection with the process communication service of the application server through the connection service; The application server enables the session service of the audit server through the task scheduling service; Data query and audit management in the dynamic transaction audit process are realized through the data access service in the application server and the cursor service in the audit server; The transaction audit service in the application server transmits the audit transactions to be processed to the transaction audit service in the audit server, and the audit server stores the audit records of the dynamic transaction audit in the audit database; When ending the dynamic transaction audit, the application server closes the session service of the audit server through the task scheduling service.

8. The dynamic transaction auditing system for heterogeneous environments of industrial application software according to claim 7, wherein The communication process further includes: When there is sensitive data in the audit data of the dynamic transaction audit, the sensitive data is encrypted through a key derivation function and an encryption algorithm.

9. The dynamic transaction auditing system for heterogeneous environments of industrial application software according to claim 3, characterized in that The system further includes: Monitoring the transaction audit data through a transaction audit monitoring model; When an abnormal transaction occurs in the dynamic transaction audit is detected, a warning signal is sent.

10. A dynamic transaction auditing method for the heterogeneous environment of industrial application software, characterized in that, The method is executed based on the dynamic transaction audit system for heterogeneous environments of industrial application software according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • System and method for integrating transactional middleware platform with centralized audit framework

    CN108475220A

  • Block chain-based auditing data de-duplication method

    CN114666037A

  • Power grid service intelligent auditing method and system based on AI enhancement

    CN119599821A

  • Methods and apparatus for creating an audit trail

    US20100185693A1

  • Method and apparatus for agent-less auditing of server

    US8024296B1