Computing power resource data control method and device of intelligent computing center

Through identity authentication and permission hierarchy, dynamic auditing and intelligent desensitization mechanisms, the problem of insufficient data security in a high concurrency environment is solved, and the security and efficiency of data operations are achieved.

CN120337280APending Publication Date: 2025-07-18DATACANVAS LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510392615.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

Existing intelligent computing centers are difficult to effectively prevent unauthorized data access or operations under high concurrency processing capabilities, resulting in insufficient data security.

Method used

Through the triple mechanism of identity authentication and permission hierarchy, dynamic audit and intelligent desensitization, the access rights of the user terminal are determined, the overridden operations are identified, sensitive fields are dynamically identified and desensitized, and data security is ensured.

Benefits of technology

Improves the data security and compliance of the smart computing center, ensuring that data operations are within the scope of authorization, taking into account high concurrency processing capabilities and privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337280A_ABST
    Figure CN120337280A_ABST
Patent Text Reader

Abstract

The invention provides a computing power resource data control method and device of an intelligent computing center, and relates to the technical field of intelligent computing centers, intelligent computing centers and computing power infrastructure, and the method comprises the steps: S1, when a request of a user terminal for logging in the intelligent computing center is received, determining the access authority of the user terminal according to the identity information of the user terminal; s2, receiving an access request of a user terminal to a target database pre-established in the intelligent computing center; s3, when the access request does not exceed the database access permission, identifying a first SQL statement edited by the user terminal in the target database and first context information of the first SQL statement according to the SQL statement editing permission; s4, when the SQL statement editing authority is not exceeded, sensitive field identification and desensitization processing are carried out on the first SQL statement and the first context information according to a preset desensitization rule, and a second SQL statement and second context information are obtained; and S5, executing the second SQL statement and the second context information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the technical fields of intelligent computing centers, intelligent computing centers, and computing power infrastructure, and specifically relate to a method and device for controlling computing power resource data of an intelligent computing center. Background Art

[0002] With the rapid development of artificial intelligence technology, "intelligent computing centers" and "intelligent computing centers" have emerged as the times require.

[0003] An "intelligent computing center" refers to a facility that uses large-scale heterogeneous computing power resources, including general computing power and intelligent computing power, and mainly provides the required computing power, data, and algorithms for artificial intelligence applications (such as scenarios of artificial intelligence deep learning model development, model training, and model inference). An intelligent computing center covers facilities, hardware, and software, and can provide full-stack capabilities from underlying computing power to top-level application enabling.

[0004] An "intelligent computing center" includes, but is not limited to, an "intelligent computing center".

[0005] An "intelligent computing center", that is, an artificial intelligence computing center, is a type of computing power infrastructure that is based on artificial intelligence theory, adopts an artificial intelligence computing architecture, and provides computing power services, data services, and algorithm services required for artificial intelligence applications.

[0006] "Computing power" is the core of "intelligent computing centers" and "intelligent computing centers". It is the ability of computer devices or computing / data centers to process information, the ability of computer hardware and software to cooperate to jointly execute a certain computing requirement, the computing ability to achieve the output of the target result by processing information data, and a new type of productive force that integrates information computing power, network carrying capacity, and data storage capacity. It mainly provides services to society through computing power infrastructure.

[0007] Data storage and processing in intelligent computing centers usually rely on a distributed cluster architecture and usually require storing, managing, and analyzing a large amount of sensitive information. To ensure information security, related technologies usually rely on coarse-grained access control lists or role-based access control to restrict users' operations on resources through predefined roles and permissions. However, in the face of a complex intelligent computing environment, simply relying on static rules is difficult to effectively prevent unauthorized data access or operations. Therefore, there is an urgent need for a technical solution that can both guarantee the high-concurrency processing ability of intelligent computing centers and ensure the security of cluster resources and data. Summary of the Invention

[0008] The present invention provides a method and device for controlling computing power resource data of an intelligent computing center, which can improve the security of cluster resources and data while guaranteeing the high-concurrency processing ability of the intelligent computing center.

[0009] To solve the above technical problems, the present invention is implemented as follows:

[0010] In a first aspect, the present invention provides a method for controlling computing power resource data of an intelligent computing center, including:

[0011] Step S1: When receiving a request from a user terminal to log in to the intelligent computing center, determine the access permission of the user terminal according to the identity information of the user terminal, where the access permission includes database access permission and unstructured data SQL statement editing permission;

[0012] Step S2: Receive an access request from the user terminal to a target database pre-established in the intelligent computing center;

[0013] Step S3: When the access request does not exceed the database access permission, identify the first SQL statement edited by the user terminal in the target database and the first context information of the first SQL statement according to the SQL statement editing permission;

[0014] Step S4: When the first SQL statement and the first context information do not exceed the SQL statement editing permission, perform sensitive field identification and desensitization processing on the first SQL statement and the first context information according to a pre-set desensitization rule to obtain a second SQL statement and second context information;

[0015] Step S5: Execute the second SQL statement and the second context information.

[0016] In one embodiment, step S1 includes:

[0017] Step S11: Determine the access permission based on the identity information and a preset minimum permission range;

[0018] Step S12: According to the business scenario that needs to be associated when the user terminal logs in to the intelligent computing center, determine the database access permission, the SQL statement editing permission, and the data operation audit permission from the access permission;

[0019] Wherein, the identity information includes at least one of the project department affiliation relationship of the user terminal, the terminal level, the terminal device status, the user role identifier, the geographical location information, the historical behavior data, and the temporary authorization status.

[0020] In one embodiment, step S3 includes:

[0021] Step S31: When the access request does not exceed the database access permission, identify the first SQL statement according to the SQL statement editing permission;

[0022] Step S32: When the first SQL statement exceeds the SQL statement editing permission and at least one field in the first SQL statement conforms to a preset field, intercept the first SQL statement and record an interception log;

[0023] Among them, the interception processing includes at least one of intercepting cross-table association over-authorization, blocking high-risk function calls, limiting the execution speed of SQL statements, and controlling resource quotas.

[0024] In one embodiment, the step S4 includes:

[0025] Step S41: Determine the desensitization rule according to the user level of the user terminal and the data level of the first context information;

[0026] Step S42: Identify the first sensitive field in the first SQL statement and / or the second sensitive field in the first context information according to the data characteristics configured in the desensitization rule;

[0027] Step S43: Perform a desensitization processing operation on the first sensitive field in the first SQL statement and / or the second sensitive field in the first context information to obtain a second SQL statement and second context information;

[0028] Among them, the desensitization processing operation includes at least one of masking, encrypting, deleting, and replacing sensitive information.

[0029] In one embodiment, the method further includes:

[0030] Step S6: Obtain the operation behavior data of the user terminal, where the operation behavior data includes at least one operation behavior, and the behavior result, behavior type, behavior time, and behavior object of each operation behavior;

[0031] Step S7: Identify the operation behavior data and evaluate the behavior risk level of each operation behavior in the operation behavior data;

[0032] Step S8: Generate an approval suggestion corresponding to the operation behavior data based on the behavior risk level of each operation behavior, and the approval suggestion is classified according to at least one of the time sequence, user group, and operation behavior type.

[0033] In one embodiment, the method further includes any one of the following:

[0034] Step S9: When the first SQL statement edited by the user terminal is obtained, predict the subsequent information of the first SQL statement based on the first SQL statement, and send the subsequent information to the user terminal;

[0035] Step S10: When at least one target field in the first SQL statement edited by the user terminal is obtained, send a permission conflict prompt to the user terminal, where the permission conflict prompt is generated based on the target field and the SQL statement editing permission;

[0036] Step S11: When the first SQL statement edited by the user terminal is obtained, convert the first SQL statement into a SQL statement in a standardized format.

[0037] In a second aspect, the present invention provides a computing power resource data control device for an intelligent computing center, including:

[0038] A permission determination module, configured to determine the access permission of the user terminal according to the identity information of the user terminal when a request for the user terminal to log in to the intelligent computing center is received, where the access permission includes database access permission and unstructured data SQL statement editing permission;

[0039] A request receiving module, configured to receive an access request from the user terminal to a target database pre-established in the intelligent computing center;

[0040] A statement recognition module, configured to recognize the first SQL statement edited by the user terminal in the target database and the first context information of the first SQL statement according to the SQL statement editing permission when the access request does not exceed the database access permission;

[0041] A desensitization processing module, configured to perform sensitive field recognition and desensitization processing on the first SQL statement and the first context information according to a pre-set desensitization rule to obtain a second SQL statement and a second context information when the first SQL statement and the first context information do not exceed the SQL statement editing permission;

[0042] A statement execution module, configured to execute the second SQL statement and the second context information.

[0043] In a third aspect, the present invention provides a server, including: a processor, a memory, and a program stored on the memory and executable on the processor, where when the program is executed by the processor, the steps of the computing power resource data control method for the intelligent computing center described in the first aspect above are implemented.

[0044] Fourthly, the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the computing power resource data control method of the intelligent computing center as described in the first aspect above are implemented.

[0045] Fifthly, the present invention provides a computer program product, including computer instructions. When the computer instructions are executed by a processor, the steps of the computing power resource data control method of the intelligent computing center as described in the first aspect above are implemented.

[0046] In the present invention, the computing power resource data control method running in the intelligent computing center effectively improves the data security and compliance of the computing power resources through three mechanisms: permission grading, dynamic auditing, and intelligent desensitization. First, the principle of least privilege is realized through identity authentication and permission stratification, reducing the risk of unauthorized operations. Secondly, the dual auditing mechanism for SQL statements combined with context semantics can accurately identify abnormal operation patterns. Finally, dynamic desensitization processing meets the privacy protection requirements while maintaining data availability. In this way, the three-stage protection system in the present invention enables the data operation to maintain a complete business process within the authorized scope of the intelligent computing center, taking into account both security and computing efficiency, and improving the security performance. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] By reading the following detailed description of the preferred embodiments, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0048] Figure 1 is a schematic flowchart of a computing power resource data control method for an intelligent computing center in the present invention;

[0049] Figure 2 is a schematic diagram of a user terminal management page in the present invention;

[0050] Figure 3 is a schematic diagram of a data desensitization page in the present invention;

[0051] Figure 4 is a schematic diagram of a data operation page in the present invention;

[0052] Figure 5 is a schematic diagram of an audit analysis page in the present invention;

[0053] Figure 6 is a schematic structural diagram of a computing power resource data control device for an intelligent computing center in the present invention;

[0054] Figure 7It is a schematic structural diagram of an electronic device in the present invention. Detailed implementation manners

[0055] Next, the technical solutions in the present invention will be clearly and completely described in conjunction with the accompanying drawings in the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without creative efforts shall fall within the protection scope of the present invention.

[0056] First, the technical terms related to the present invention will be briefly described below.

[0057] The "computing power" referred to in the present invention means: the ability of a computer device or a computing / data center to process information, the ability of computer hardware and software to cooperate to jointly execute a certain computing requirement, the computing ability to achieve the output of a target result by processing information data, a new type of productive force integrating information computing power, network carrying capacity, and data storage capacity, and mainly providing services to society through computing power infrastructure.

[0058] The "computational power" (Computational Power, CP) referred to in the present invention means: the ability of a data center server to process data and achieve the output of results, a comprehensive index to measure the computing ability of a data center, including general computing ability, supercomputing ability, and intelligent computing ability. The commonly used measurement unit is the number of floating-point operations per second (FLOPS, 1EFLOPS = 10^18 FLOPS), and the larger the value, the stronger the comprehensive computing ability. It is estimated that 1EFLOPS is approximately the computing power output of 5 Tianhe 2A or 500,000 mainstream server CPUs or 2 million mainstream laptops. The calculation formula is: CP = CP 通用 +CP 智能 +CP 超级 .

[0059] The "carrying capacity" (Network Power, NP) referred to in the present invention means: the performance of the data transmission ability of computing power facilities, a comprehensive ability including network architecture, network bandwidth, transmission delay, intelligent management and scheduling, etc., involving network transmission inside and between data centers, and a comprehensive index to measure the network transmission scheduling ability.

[0060] The "Storage Power" (SP) described in the present invention refers to the comprehensive ability of a data center in four aspects: data storage capacity, performance, security and reliability, and green and low-carbon. It is a comprehensive indicator for measuring the data storage capacity of a data center and includes external storage devices such as storage arrays and server-internal storage devices. The common measurement unit for storage capacity is the exabyte (EB, 1EB = 2^60 bytes), the common measurement unit for performance is the number of read / write operations per second per unit capacity (IOPS / TB, Input / Output Operations Per Second / TB), and the disaster recovery ratio is an important manifestation of security and reliability.

[0061] The "computing power infrastructure" described in the present invention refers to a new type of information infrastructure that integrates information computing power, network carrying capacity, and data storage power, and can realize the centralized computing, storage, transmission, and application of information.

[0062] The "new type of information infrastructure" described in the present invention mainly includes network infrastructures such as 5G networks, fiber broadband networks, backbone networks, international communication networks, and satellite Internet, computing power infrastructures such as data centers, general computing power centers, intelligent computing centers, and supercomputing centers, and new technology facilities such as artificial intelligence, blockchain, and quantum computing.

[0063] The "computing power" described in the present invention includes: general computing power, intelligent computing power, and super computing power.

[0064] The "general computing power" described in the present invention refers to the computing power provided by servers based on CPU (Central Processing Unit) chips, which is used to support basic general computing such as cloud computing and edge computing.

[0065] The "intelligent computing power" described in the present invention refers to a computing platform that is scaled for various artificial intelligence innovation applications and is based on dedicated chips such as GPU (Graphics Processing Unit), FPGA (Field Programmable Gate Array), and ASIC (Application Specific Integrated Circuit), such as natural language processing and machine vision.

[0066] The "super computing power" described in the present invention mainly refers to the computing power provided by high-performance computing clusters such as supercomputers. It utilizes the centralized computing resources of multiple computer systems working in parallel and processes extremely complex or data-intensive problems through a dedicated operating system, and is mainly used for computing in cutting-edge scientific fields, such as planetary simulation, drug molecule design, and gene analysis.

[0067] The "Intelligent Computing Center" as described in the present invention refers to a facility that uses large-scale heterogeneous computing power resources, including general computing power (CPU) and intelligent computing power (GPU, FPGA, ASIC, etc.), and mainly provides the required computing power, data, and algorithms for artificial intelligence applications (such as scenarios like artificial intelligence deep learning model development, model training, and model inference). The intelligent computing center covers facilities, hardware, and software, and can provide full-stack capabilities from underlying computing power to top-level application enabling.

[0068] The "Intelligent Computing Center" as described in the present invention includes but is not limited to the "Intelligent Computing Center".

[0069] The "Intelligent Computing Center" as described in the present invention, namely the artificial intelligence computing center, is a type of computing power infrastructure based on artificial intelligence theory, adopting an artificial intelligence computing architecture, and providing computing power services, data services, and algorithm services required for artificial intelligence applications.

[0070] The "Computing Power Center" as described in the present invention refers to a facility mainly composed of infrastructure such as wind, fire, water, and electricity and IT software and hardware devices, and having computing power, carrying capacity, and storage capacity, including general data centers, intelligent computing centers, supercomputing centers, etc.

[0071] The "Supercomputing Center" as described in the present invention, namely the supercomputing data center, is a data center based on supercomputers or large-scale computing clusters, capable of providing functions such as large-scale computing, storage, and network services, and is widely used in application scenarios such as aerospace, national defense, oil exploration, climate modeling, and genome sequencing.

[0072] The "Computing Power Resources" as described in the present invention refers to technologies and facilities required for the development of the digital society and having information computing, transmission, storage, and application capabilities, including but not limited to computing resources such as CPU and GPU, network resources such as switches and routers, storage resources such as storage arrays and distributed storage, security resources such as firewalls and intrusion detection systems, and support and guarantee resources such as wind, fire, water, and electricity.

[0073] The "Large Language Model" as described in the present invention refers to a large language model (LLM), which is a language model with a relatively large number of parameters, aiming to understand and generate human language, trained through a large amount of text data, and can perform a wide range of tasks including text summarization, translation, sentiment analysis, etc.

[0074] The "Multimodal Large Models" as described in the present invention refers to models that jointly train multimodal information such as text, images, videos, and audio, including but not limited to multimodal large language models.

[0075] Specifically, please refer to Figure 1 ,Figure 1 is a flow chart of a computing resource data control method for an intelligent computing center provided by an embodiment of the present invention, such as Figure 1 As shown, the following steps are included:

[0076] Step S1: upon receiving a request from a user terminal to log into an intelligent computing center, determining the access rights of the user terminal according to the identity information of the user terminal, wherein the access rights include database access rights and unstructured data SQL statement editing rights.

[0077] Among them, the above-mentioned user terminal can be a device that initiates an access request (such as a PC, server), and it is necessary to access the intelligent computing center through identity authentication. The above-mentioned identity information can be used to verify the credentials of the legitimacy of the user, such as account password, biometrics, digital certificates, etc. The above-mentioned access rights can be the scope of operations granted to the user, which specifically includes three categories: database access rights: a list of databases allowed to be accessed (such as only allowing access to the "user portrait library"); unstructured data SQL statement editing permissions: permissions to perform SQL operations on unstructured data (such as pictures, log files), such as allowing selection (SELECT) but prohibiting deletion (DELETE). In addition, the permission to record user operation logs can also be used. For example, auditors can view operation records, and ordinary users do not have this permission.

[0078] In applications, such as Figure 2 As shown, Figure 2 Schematic diagram of the page for user terminal management. Among them, the top is the four parts of data operation, data desensitization, data change and audit analysis involved in the embodiment of this application. For user terminal management operations, management can be carried out for different departments, or user terminal classification can be managed, specifically involving the user name, login account, department, user role, CQ / domain, audit scope and status of the user terminal.

[0079] In the above steps, the user terminal submits identity information through an encrypted protocol (such as HTTPS), and the system calls an authentication service (such as LDAP, OAuth) to verify the legitimacy. For example, user A enters his account and password, and the system binds his role to "data analyst" after passing the verification.

[0080] Specifically, preset rules can be matched from the permission policy library according to user roles or attributes. For example, the "data analyst" role has the "customer database" selection (SELECT) permission by default, but is prohibited from performing high-risk operations such as DROP TABLE. Subsequently, the matching permissions can be dynamically loaded into the user session to generate an access token (Token). For example, after user A logs in, the list of databases that he can access (such as "customer library" and "log library") is marked in the token, and his SQL operation types are restricted.

[0081] In this way, the intelligent computing center can adopt a role-based access control model and ensure the minimum allocation of permissions through a three-layer mapping of "user-role-permission". For example, the operation and maintenance role has the permission to audit data operations, while ordinary users only have basic query permissions.

[0082] Step S2: Receive an access request from the user terminal to a target database pre-established in the intelligent computing center.

[0083] It should be noted that the above access request can be an operation instruction sent by the user terminal to the intelligent computing center, including the target database name, operation type (such as query, write), and user credentials (such as Token). The target database can be a specific database instance requested by the user to access (such as the "user behavior analysis library"), which needs to be within the permission range and have completed metadata registration in advance.

[0084] In a specific embodiment, the user terminal submits identity information (such as account password, fingerprint), and the system verifies the identity through an authentication service (such as LDAP, OAuth). For example, user B logs in using a digital certificate, and after the system verifies the validity of the certificate, binds their role as "auditor". Preset rules can be extracted from the permission policy library according to the role or user attributes. For example, the role of "auditor" by default has "read-only" permissions for all databases and is allowed to call the audit log interface. Finally, the permissions can be encapsulated into an access token (Token) to limit the scope of subsequent user operations. For example, user B's Token marks that they can access all databases, but are prohibited from executing update (UPDATE) or DELETE statements.

[0085] In the above steps, dynamic permission control can be achieved through a role-based access control (RBAC) model. For example, the role of operation and maintenance personnel may include "permission to audit data operations", allowing them to view the operation logs of all users, while the role of ordinary developers only opens read and write permissions for specific databases and prohibits high-risk operations (such as DROP).

[0086] Step S3: In the case where the access request does not exceed the database access permission, identify the first SQL statement edited by the user terminal in the target database and the first context information of the first SQL statement according to the SQL statement editing permission.

[0087] It is worth mentioning that the database access permission can be the scope of database operations granted to the user in step S1 (such as only allowing access to the "order database"). The SQL statement editing permission is the restriction rule for the user to perform SQL operations on unstructured data (such as allowing SELECT but prohibiting INSERT). The above first SQL statement represents the specific SQL command actually input by the user. For example, SELECT * FROM user_logs WHERE date = '2025-04-01'. The first context information can represent the environmental parameters when executing SQL, such as the user IP address, operation time, and historical behavior records.

[0088] Abnormal operation mode: The operation characteristics that violate the security policy (such as high-frequency batch queries, cross-database association queries).

[0089] In the embodiment of the present application, the user terminal submits identity information (such as account password, biometric features), and the system completes the verification through an authentication service (such as Kerberos or JWT). For example, user C logs in using fingerprints, and after the system verification, assigns his role as "report generation member". Specifically, corresponding rules can be extracted from the permission policy library according to the user role or attributes. For example, the "report generation member" role is only allowed to access the "sales statistics database", and the SQL operations are limited to a maximum of 10 SELECTs per day. Encrypt the permission information and write it into the access token (Token), and associate it with the user session. For example, in the Token of user C, mark the database he can access as the "sales statistics database", and prohibit the execution of ALTER or TRUNCATE commands.

[0090] In this way, the above steps adopt dynamic permission policy loading. For example, supplement the RBAC model through Attribute-Based Access Control (ABAC). When the user logs in from an unusual IP, even if the role is legal, his high-risk operation permissions may be temporarily restricted.

[0091] Step S4: When the first SQL statement and the first context information do not exceed the SQL statement editing permission, according to the preset desensitization rules, perform sensitive field identification and desensitization processing on the first SQL statement and the first context information to obtain a second SQL statement and a second context information.

[0092] It is understandable that the desensitization rule can be a strategy for transforming or masking sensitive data (such as ID numbers and mobile phone numbers). For example, part of the field can be replaced with * or the original value can be replaced with a hash value. The sensitive fields can be data columns that need to be protected in the database (such as user_phone and credit_card), which are usually marked through a predefined rule library. The desensitization process can be to modify the sensitive content in the SQL statement according to the rule. For example, changing SELECT phone FROM users to SELECT mask(phone)FROM users.

[0093] Furthermore, the second SQL statement can represent the secure SQL statement after desensitization to ensure that the execution result does not disclose sensitive data. The second context information can indicate the operation environment data after desensitization (such as hiding the last three digits of the user's real IP).

[0094] In the application, as Figure 3 shown, for the executed or to-be-executed desensitization tasks in the intelligent computing center, they can be represented one by one, including the task name, task type, domain, target, status, start time, update time, creator, and specific operations of each desensitization task. This application does not make specific restrictions on this.

[0095] In the above steps, the user terminal submits a credential (such as an OAuth token), and the system verifies its validity and associates the user role. For example, user D logs in by scanning the code with enterprise WeChat, and the system confirms that their role is "customer service support". In the permission matching, the permission rules can be loaded from the permission policy library according to the role, including the accessible databases and the allowed types of SQL operations. For example, the "customer service support" role can only access the "customer service library" and only allows SELECT operations. For permission binding, the permission can be encapsulated into a Token and additional dynamic restrictions (such as an operation time window) can be attached. For example, it is stipulated in user D's Token that they can only execute 20 queries per day and are prohibited from accessing the salary field.

[0096] In this way, the above steps combine static permissions (role preset) with dynamic policies (such as real-time risk detection). For example, when a user attempts to access from an overseas IP, even if the role is legitimate, the system can still temporarily prohibit the access permission to the desensitized field.

[0097] Step S5: Execute the second SQL statement and the second context information.

[0098] In the embodiment of the present application, the whole process control of data operation is realized through hierarchical permission control and dynamic security strategy: First, the permission is initialized. When the user logs in, the system verifies the identity based on the identity information (such as account password, digital certificate) and matches the preset role (such as "data analyst" and "auditor"). The permissions are bound through the RBAC model, for example, the "customer service support" role is restricted to access only the customer service library and high-risk SQL operations are prohibited. Secondly, the access control process, that is, after the user initiates an access request, the system verifies the database access rights in its Token (such as prohibiting access to the financial library), and analyzes the SQL statements and contexts (such as operation frequency, IP ownership) entered by the user in real time. For example, a risk warning is triggered when a high-frequency SELECT* query is detected. Finally, dynamic desensitization can automatically identify sensitive fields (such as mobile phone numbers, ID card numbers) and desensitize them according to the rules for SQL statements that have passed the review. For example, rewrite SELECT phone FROM users to SELECT mask (phone) FROM users to ensure that the number displayed in the returned result is 123****5678.

[0099] In this way, the embodiments of the present application can reduce the risk of unauthorized operations and injection attacks through permission stratification and double SQL auditing. For example, prohibiting ordinary users from executing DELETE statements can prevent accidental deletion of data, and context analysis can intercept cross-database association query attacks. Among them, dynamic desensitization can ensure that sensitive data is not leaked and meet the requirements of regulations such as GDPR. For example, the last four digits of the ID number are automatically hidden when the customer service staff views the user information. Dynamic binding of permissions (such as Token time control) and intelligent desensitization (such as retaining the readability of some fields) take into account business needs and security, and avoid the decrease in data availability caused by traditional static desensitization. Therefore, the three-stage protection system in this application enables data operations to maintain a complete business process within the authorization scope of the intelligent computing center, taking into account security and computing efficiency, and improving security performance.

[0100] In one embodiment, step S1 includes:

[0101] Step S11: Determine the access rights based on the identity information and the preset minimum permission range;

[0102] Step S12: according to the business scenario that needs to be associated when the user terminal logs into the intelligent computing center, determining the database access permission, the SQL statement editing permission and the data operation audit permission from the access permission;

[0103] The identity information includes at least one of the project department affiliation, terminal grade, terminal device status, user role identification, geographic location information, historical behavior data and temporary authorization status of the user terminal.

[0104] In some embodiments, the multi-dimensional identity information of the user terminal can be integrated, such as the project department belonging to the "Finance Department", the terminal level being "ordinary", and the device status being "security patch installed", to perform permission calculation, and an initial permission set can be generated according to a preset minimum permission rule library. Exemplarily, when the user role is "Financial Analyst" and belongs to the "Finance Department", only the SELECT permission for the "Financial Database" is opened, and cross-departmental database access is prohibited. Finally, dynamic adjustment is performed to correct the permissions in combination with real-time parameters (such as the status of the terminal device and the geographical location). For example, if the device does not have a patch installed or the logged-in IP is an overseas address, access to sensitive tables (such as salary) is temporarily prohibited.

[0105] For step 12 above, the permissions can be refined according to the business scenario. According to the business scenario (such as "Data Statistics", "Troubleshooting") declared when the user logs in, applicable rules can be filtered from the initial permissions. For example, when the "Troubleshooting" scenario is selected, the SELECT permission for the log library is opened, but the number of records returned by each query is restricted to no more than 1000.

[0106] In addition, the permissions can be split. The permissions are split into three categories according to functions: Database access permission: The specific library tables allowed to be accessed (such as the "System Monitoring Library" can be accessed in the "Operation and Maintenance Personnel" scenario). SQL statement editing permission: Restrict the types of operations that can be executed (such as only the aggregation functions COUNT / SUM are allowed in the "Data Statistics" scenario). Data operation audit permission: Control the log viewing scope according to the role (such as the "Auditor" scenario can export all operation logs).

[0107] In this way, the above embodiments of the present application minimize risk exposure: dynamically shrink permissions through multi-dimensional identity information (such as terminal level, historical behavior) to avoid over-authorization. For example, if there are abnormal query records in a user's historical behavior, even if the role is legitimate, the SQL operation frequency of its new session will be restricted to 50% of the normal value. Scenario-based precise control can also be performed. The association of business scenarios ensures that the permissions strictly match the requirements, reducing the possibility of permission abuse. When the same user selects the "Daily Report Generation" scenario, only the aggregated view can be accessed, while when the "Data Cleaning" scenario is selected, the UPDATE permission can be temporarily opened (subject to secondary approval). In this way, adjusting permissions in combination with real-time parameters such as the status of the terminal device and the geographical location enhances the defense ability against abnormal access.

[0108] In one embodiment, step S3 includes:

[0109] Step S31: When the access request does not exceed the database access permission, identify the first SQL statement according to the SQL statement editing permission;

[0110] Step S32: When the first SQL statement exceeds the SQL statement editing permission and at least one field in the first SQL statement conforms to the preset field, intercept the first SQL statement and record the interception log;

[0111] Among them, the interception processing includes at least one of intercepting cross-table association over-authorization, blocking high-risk function calls, limiting the execution speed of SQL statements, and controlling resource quotas.

[0112] In the above embodiment, for the process of permission verification and SQL parsing, based on the database access permission in the user Token, it can be verified whether the target library table requested to be accessed is within the authorized range. Exemplarily, if a user has the access permission to the "order library" but attempts to access the "finance library", it is directly rejected. For SQL structure parsing, the SQL statement input by the user can be parsed grammatically to extract the operation type (SELECT / DELETE), target table, fields, and association conditions. For example, parsing SELECT user_id,phone FROM orders JOIN users ON orders.user_id = users.id, it can identify the cross-table association query involving the "orders" and "users" tables.

[0113] In some specific embodiments, interception and dynamic control can be performed through unauthorized operations. Whether it exceeds the permission or triggers a high-risk operation can be detected according to the SQL statement editing permission rule library. Cross-table association over-authorization can also be performed to prohibit unauthorized table associations (such as an ordinary user attempting to associate the "user table" with the "payment record table"). High-risk function blocking can also be performed, that is, intercepting sensitive function calls (such as LOAD_FILE() to read local files or EXEC to execute system commands). Speed limit and quota control can also be performed, that is, limiting the number of SQL executions or resource consumption within a unit time (such as a single user can execute at most 10 queries per minute).

[0114] In addition, interception and logging can also be performed to block illegal operations in real time and record the operation details (such as SQL content, user IP, timestamp). Exemplarily, as Figure 4 shown, when a user attempts to execute DELETE FROM logs on database 1, it is intercepted due to the lack of DELETE permission and a log is generated marked as "high-risk operation".

[0115] In this way, the above embodiments of the present application can accurately intercept unauthorized operations (such as cross-table association attacks) through SQL structure parsing and rule matching, reducing the risk of lateral penetration. The embodiments of the present application can also reduce the risk of misoperations, implement speed limit and quota control (such as restricting the return of 100,000 data records per single query), and avoid system overload caused by code defects or human errors. In addition, it realizes the traceability of attack features, records the details of high-risk operations through intercepted logs, and provides a basis for security audits.

[0116] In one embodiment, step S4 includes:

[0117] Step S41: Determine the desensitization rule according to the user level of the user terminal and the data level of the first context information;

[0118] Step S42: Identify the first sensitive field in the first SQL statement and / or the second sensitive field in the first context information according to the data characteristics configured in the desensitization rule;

[0119] Step S43: Perform a desensitization operation on the first sensitive field in the first SQL statement and / or the second sensitive field in the first context information to obtain a second SQL statement and a second context information;

[0120] Among them, the desensitization operation includes at least one of masking, encrypting, deleting, and replacing sensitive information.

[0121] The above input parameters can combine the user level (such as identity levels like "ordinary user", "administrator", etc.) and the data level of the context information (such as "public", "confidential", etc.) to select an applicable desensitization strategy from the rule library. Exemplarily, when the user level is "customer service" and the accessed data is marked as "personal privacy", the rule of masking the last four digits of the mobile phone number is adopted.

[0122] In some embodiments, if there are conflicting rules, for example, the user level allows partial desensitization but the data level requires full encryption, decisions can be made according to the priority, such as giving priority to the data level. It is also possible to accurately identify sensitive fields, including using SQL statement scanning, that is, through regular expressions or a predefined sensitive field library (such as field names containing phone, id_card) to identify sensitive fields in SQL. For example, in SELECT name,id_card FROM employees, id_card can be marked as the first sensitive field. Context information filtering is to extract sensitive content (such as the user's IP address, device serial number) from the operation environment data and mark it as the second sensitive field. For example, when recording operation logs, the user's real IP 192.168.1.100 is desensitized to 192.168.*.*.

[0123] Furthermore, differential desensitization can be performed for masking. Partial replacement can be carried out on the data that needs to retain some visible parts (such as mobile phone numbers). For example, SELECT phone FROM users can be rewritten as SELECT SUBSTR(phone,1,3)+'****'FROM users. The above encryption and deletion can encrypt and store or directly filter highly sensitive fields (such as bank card numbers). For example, when querying credit_card, a null value or a hash value (a1b2c3...) is returned.

[0124] In this way, the embodiments of the present application can achieve hierarchical data protection, dynamically adjust the desensitization intensity according to the user level and data sensitivity, and balance security and business requirements. It can also accurately identify with low misjudgment, identify multi-dimensionally by combining field names, data patterns (such as ID card number verification rules) and context, and reduce the mis-desensitization rate. At the same time, ensure the compliance of operation logs, desensitize context information (such as IP, device number) synchronously, and ensure that audit records comply with privacy regulations.

[0125] In one embodiment, the method further includes:

[0126] Step S6: Obtain the operation behavior data of the user terminal, where the operation behavior data includes at least one operation behavior, and the behavior result, behavior type, behavior time, and behavior object of each operation behavior;

[0127] Step S7: Identify the operation behavior data and evaluate the behavior risk level of each operation behavior in the operation behavior data;

[0128] Step S8: Generate an approval suggestion corresponding to the operation behavior data based on the behavior risk level of each operation behavior, and the approval suggestion is classified according to at least one of the time sequence, user group, and operation behavior type.

[0129] In some embodiments, the operation logs of the user terminal can be captured in real time, including behavior type (such as SELECT / UPDATE), behavior object (target table name), behavior result (success / failure), timestamp, etc. Exemplarily, when the user executes DELETE FROM logs WHERE id=100, the behavior type is recorded as "delete", the object is "logs table", the result is "success", and the time is "2025-4-01 14:3". By using context association and attaching environmental information (such as session ID, device fingerprint), a complete operation link is formed.

[0130] Furthermore, risk dynamic assessment can be carried out based on a preset rule library, such as "frequent deletion operations" and "sensitive table access", to determine the risk level (low / medium / high). For example, user A executes 10 DELETE operations continuously within 1 minute, triggering a "high risk" flag. Or risk dynamic assessment is assisted by machine learning: detecting abnormal patterns through the historical behavior model, such as accessing the core table during non-working hours. Exemplarily, user B usually queries sales data from 9:00 to 18:00. If the salary table is suddenly accessed at 2 am, it is determined as "medium risk". Thus, the generation of intelligent approval suggestions can be realized. Specifically, an approval list can be generated according to dimensions such as risk level, user group, and operation type to achieve classification and aggregation. In the application, all "high risk" deletion operations can be sorted by time and pushed to the security team for review preferentially. In addition, recommended processing methods can be adopted in combination with the business scenario, such as immediate blocking and manual review.

[0131] In this way, through full-scale behavior collection and hierarchical assessment, the above embodiments can quickly locate abnormal operations (such as unauthorized batch data export during non-authorization periods), and can also perform automated responses. When high-risk operations occur (such as overclocking queries), interception or secondary verification can be automatically triggered to reduce manual intervention delay.

[0132] It is worth mentioning that in the embodiments of the present application, each operation in the intelligent computing center is audited and analyzed, and the audit and analysis results can be as Figure 5 shown, including content related to user operations, as well as the number of SQL executions, average execution duration, etc., which can intuitively display the situation of each operation in the intelligent computing center, facilitate the timely management of data operations, and improve operation security.

[0133] In one embodiment, the method further includes any one of the following:

[0134] Step S9: When the first SQL statement edited by the user terminal is obtained, predict the subsequent information of the first SQL statement based on the first SQL statement, and send the subsequent information to the user terminal;

[0135] Step S10: When at least one target field in the first SQL statement edited by the user terminal is obtained, send a permission conflict prompt to the user terminal, and the permission conflict prompt is generated based on the target field and the SQL statement editing permission;

[0136] Step S11: When the first SQL statement edited by the user terminal is obtained, convert the first SQL statement into a SQL statement in a standardized format.

[0137] In some embodiments, the SQL fragment currently input by the user is parsed through a natural language processing (NLP) model or a historical query pattern library. At the same time, possible subsequent operations can be recommended based on semantic relevance. For example, it is recommended to complete the condition user_id = 100 or the sorting clause ORDER BY create_time. Active pushing can also be performed, that is, the prediction results are displayed to the user terminal in the form of a prompt box or a completion list. For example, when the user inputs SELECT product_name,SUM(sales)FROM, the system recommends completing GROUP BY product_name and prompts available aggregation functions. In this way, the SQL intelligent prediction in step S9 can reduce manual input errors, accelerate the writing of complex SQL, and avoid unauthorized operations by the user due to accidental touch by recommending compliant fields or conditions.

[0138] In the above step S10, the SQL statement input by the user can be parsed in real time to extract target fields (such as salary, phone). And permission verification is performed to compare the fields with the user's SQL statement editing permissions to detect conflicts (such as the user having no permission to access the salary field). Finally, dynamic feedback is given, and a warning (such as "No permission to access the salary field, please contact the administrator") is immediately popped up on the user terminal, and the conflict location is marked. For example, when the user tries to execute SELECT phone,credit_cardFROM users, if the credit_card field exceeds the permission, the system highlights the field and blocks the submission. In this way, through this step, the user can be prevented from repeatedly attempting unauthorized operations and invalid queries can be reduced. It can also achieve permission transparency, clearly prompt the permission boundary, and enhance the user's compliance awareness.

[0139] In the above step S11, the non-standard SQL (such as mixed case and chaotic indentation) input by the user is converted into a unified format by using an SQL parser (such as ANTLR). The query logic is rewritten (such as changing implicit JOIN to explicit INNER JOIN), and the keywords are standardized (such as unifying the AS alias syntax). Finally, feedback is output, that is, the standardized SQL can be returned for the user to confirm or automatically executed. Thus, the embodiments of the present application reduce the parsing risk and avoid execution errors caused by syntax ambiguity through a unified format. It also realizes audit optimization, and standardizing SQL facilitates log analysis.

[0140] In some other embodiments, such as Figure 5As shown, developers can manage different data sources in the same interface, with the same design and the same operation style of the data control platform (CloudQuery) in the intelligent computing center. The data control platform supports functions such as keyword highlighting, syntax hinting, SQL beautification, and viewing execution plans. In addition, the platform will perform SQL parsing on the written SQL statements, intercept SQL over-authorization operations, and prevent unauthorized users from accessing database information.

[0141] Please refer to Figure 6 , Figure 6 is the structural diagram of a computing power priority scheduling device and a computing power resource data control device of an intelligent computing center provided by an embodiment of the present invention. As Figure 6 shown, the computing power resource data control device 20 of the intelligent computing center includes:

[0142] A permission determination module 21, configured to determine the access permission of the user terminal according to the identity information of the user terminal when receiving a request for the user terminal to log in to the intelligent computing center, where the access permission includes database access permission and unstructured data SQL statement editing permission;

[0143] A request receiving module 22, configured to receive an access request of the user terminal for a target database pre-established in the intelligent computing center;

[0144] A statement recognition module 23, configured to recognize a first SQL statement edited by the user terminal in the target database and first context information of the first SQL statement according to the SQL statement editing permission when the access request does not exceed the database access permission;

[0145] A desensitization processing module 24, configured to perform sensitive field recognition and desensitization processing on the first SQL statement and the first context information according to a pre-set desensitization rule to obtain a second SQL statement and second context information when the first SQL statement and the first context information do not exceed the SQL statement editing permission;

[0146] A statement execution module 25, configured to execute the second SQL statement and the second context information.

[0147] In one embodiment, the permission determination module 21 is specifically configured to:

[0148] Determine the access permission based on the identity information and a preset minimum permission range;

[0149] When the user terminal logs in to the intelligent computing center, the database access permission, the SQL statement editing permission, and the data operation auditing permission are determined from the access permissions according to the associated business scenario.

[0150] Wherein, the identity information includes at least one of the project department affiliation of the user terminal, the terminal level, the terminal device status, the user role identifier, the geographical location information, the historical behavior data, and the temporary authorization status.

[0151] In one embodiment, the statement recognition module 23 is specifically configured to:

[0152] When the access request does not exceed the database access permission, the first SQL statement is recognized according to the SQL statement editing permission.

[0153] When the first SQL statement exceeds the SQL statement editing permission and at least one field in the first SQL statement conforms to a preset field, the first SQL statement is intercepted and an interception log is recorded.

[0154] Wherein, the interception processing includes at least one of intercepting cross-table association over-authorization, blocking high-risk function calls, limiting the execution speed of SQL statements, and controlling resource quotas.

[0155] In one embodiment, the desensitization processing module 24 is specifically configured to:

[0156] Determine the desensitization rule according to the user level of the user terminal and the data level of the first context information.

[0157] Identify the first sensitive field in the first SQL statement and / or the second sensitive field in the first context information according to the data characteristics configured in the desensitization rule.

[0158] Perform a desensitization processing operation on the first sensitive field in the first SQL statement and / or the second sensitive field in the first context information to obtain a second SQL statement and a second context information.

[0159] Wherein, the desensitization processing operation includes at least one of masking, encrypting, deleting, and replacing sensitive information.

[0160] In one embodiment, the computing power resource data control device 20 of the intelligent computing center is further configured to:

[0161] Obtain the operation behavior data of the user terminal, where the operation behavior data includes at least one operation behavior, and the behavior result, behavior type, behavior time, and behavior object of each operation behavior.

[0162] Identify the operation behavior data and evaluate the behavior risk level of each operation behavior in the operation behavior data;

[0163] Based on the behavior risk level of each operation behavior, generate an approval suggestion corresponding to the operation behavior data, and the approval suggestion is classified according to at least one of the time sequence, the group to which the user belongs, and the operation behavior type.

[0164] In one embodiment, the computing power resource data control device 20 of the intelligent computing center is further configured to perform any one of the following:

[0165] When the first SQL statement edited by the user terminal is obtained, predict the subsequent information of the first SQL statement based on the first SQL statement, and send the subsequent information to the user terminal;

[0166] When at least one target field in the first SQL statement edited by the user terminal is obtained, send a permission conflict prompt to the user terminal, and the permission conflict prompt is generated based on the target field and the SQL statement editing permission;

[0167] When the first SQL statement edited by the user terminal is obtained, convert the first SQL statement into a SQL statement in a standardized format.

[0168] The computing power resource data control device 20 of the intelligent computing center provided by the embodiments of the present invention can implement each process of the above-mentioned embodiments of the computing power resource data control method of the intelligent computing center, and the technical features correspond one by one and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0169] It should be noted that the computing power resource data control device 200 in the embodiments of the present invention can be a device, or a component, an integrated circuit, or a chip in an electronic device.

[0170] The embodiments of the present invention further provide an electronic device. Refer to Figure 7 , Figure 7 is a schematic structural diagram of an electronic device provided by the embodiments of the present invention. The electronic device includes a memory 31, a processor 32, and a program or instruction running on the memory 31. When the program or instruction is executed by the processor 32, it can implement Figure 1 any step in the corresponding embodiment of the computing power resource data control method of the intelligent computing center and achieve the same beneficial effects, which will not be elaborated here.

[0171] Among them, the processor 32 can be a CPU, an ASIC, an FPGA, or a GPU.

[0172] Those of ordinary skill in the art can understand that all or part of the steps for implementing the embodiments of the computing power resource data control method of the above-mentioned intelligent computing center can be completed by hardware related to program instructions, and the program can be stored in a readable medium.

[0173] An embodiment of the present invention further provides a readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it can implement any of the steps in the above-mentioned Figure 1 corresponding embodiments of the computing power resource data control method of the intelligent computing center, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here. The storage medium includes, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc, etc.

[0174] An embodiment of the present application further provides a computer program product, including computer instructions. When the computer instructions are executed by a processor, they implement each process of the above-mentioned Figure 1 embodiments of the computing power resource data control method of the intelligent computing center shown, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.

[0175] It should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or device including the element.

[0176] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, in essence, or the part that makes a contribution to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc), and includes several instructions for causing a terminal (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in various embodiments of the present invention.

[0177] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative rather than restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can also make many forms without departing from the spirit of the present invention and the scope protected by the claims, and all of them fall within the protection scope of the present invention.

Claims

1. A method for controlling computing power resource data of an intelligent computing center, characterized in that, Including: Step S1: When receiving a request from a user terminal to log in to the intelligent computing center, determine the access permission of the user terminal according to the identity information of the user terminal, where the access permission includes database access permission and unstructured data SQL statement editing permission; Step S2: Receive an access request from the user terminal to the target database pre-established in the intelligent computing center; Step S3: When the access request does not exceed the database access permission, according to the SQL statement editing permission, identify the first SQL statement edited by the user terminal in the target database and the first context information of the first SQL statement; Step S4: When the first SQL statement and the first context information do not exceed the SQL statement editing permission, according to the pre-set desensitization rules, perform sensitive field identification and desensitization processing on the first SQL statement and the first context information to obtain a second SQL statement and second context information; Step S5: Execute the second SQL statement and the second context information.

2. The method according to claim 1, wherein The step S1 includes: Step S11: Determine the access permission based on the identity information and the preset minimum permission range; Step S12: According to the business scenario that needs to be associated when the user terminal logs in to the intelligent computing center, determine the database access permission, the SQL statement editing permission, and the data operation audit permission from the access permission; Among them, the identity information includes at least one of the project department affiliation, terminal level, terminal device status, user role identifier, geographical location information, historical behavior data, and temporary authorization status of the user terminal.

3. The method according to claim 1, wherein The step S3 includes: Step S31: When the access request does not exceed the database access permission, identify the first SQL statement according to the SQL statement editing permission; Step S32: When the first SQL statement exceeds the SQL statement editing permission and at least one field in the first SQL statement meets the preset field, perform an interception process on the first SQL statement and record an interception log; Among them, the interception process includes at least one of intercepting cross-table association over-authorization, blocking high-risk function calls, limiting the execution speed of SQL statements, and resource quota control.

4. The method according to claim 1, wherein The step S4 includes: Step S41: Determine the desensitization rule according to the user level of the user terminal and the data level of the first context information; Step S42: Identify the first sensitive field in the first SQL statement and / or the second sensitive field in the first context information according to the data characteristics configured in the desensitization rule; Step S43: Perform a desensitization processing operation on the first sensitive field in the first SQL statement and / or the second sensitive field in the first context information to obtain a second SQL statement and second context information; Among them, the desensitization processing operation includes at least one of masking, encrypting, deleting, and replacing sensitive information.

5. The method according to any one of claims 1 to 4, characterized in that, The method further includes: Step S6: Obtain the operation behavior data of the user terminal, where the operation behavior data includes at least one operation behavior, as well as the behavior result, behavior type, behavior time, and behavior object of each operation behavior; Step S7: Identify the operation behavior data and evaluate the behavior risk level of each operation behavior in the operation behavior data; Step S8: Based on the behavior risk level of each operation behavior, generate an approval suggestion corresponding to the operation behavior data, and the approval suggestion is classified according to at least one of the time sequence, the group to which the user belongs, and the operation behavior type.

6. The method according to claim 5, wherein The method further includes any one of the following: Step S9: When the first SQL statement edited by the user terminal is obtained, predict the subsequent information of the first SQL statement based on the first SQL statement and send the subsequent information to the user terminal; Step S10: When at least one target field in the first SQL statement edited by the user terminal is obtained, send a permission conflict prompt to the user terminal, and the permission conflict prompt is generated based on the target field and the SQL statement editing permission; Step S11: When the first SQL statement edited by the user terminal is obtained, convert the first SQL statement into a SQL statement in a standardized format.

7. A computing power resource data control device for an intelligent computing center, characterized in that, Comprising: A permission determination module, configured to determine the access permission of the user terminal according to the identity information of the user terminal when receiving a request from the user terminal to log in to the intelligent computing center, where the access permission includes database access permission and unstructured data SQL statement editing permission; A request receiving module, configured to receive an access request from the user terminal to a target database pre-established in the intelligent computing center; A statement recognition module, configured to recognize the first SQL statement edited by the user terminal in the target database and the first context information of the first SQL statement according to the SQL statement editing permission when the access request does not exceed the database access permission; A desensitization processing module, configured to perform sensitive field identification and desensitization processing on the first SQL statement and the first context information according to a pre-set desensitization rule to obtain a second SQL statement and second context information when the first SQL statement and the first context information do not exceed the SQL statement editing permission; A statement execution module, configured to execute the second SQL statement and the second context information.

8. A server, characterized in that, Comprising: A processor, a memory, and a program stored on the memory and executable on the processor, and when the program is executed by the processor, the steps of the method for controlling the computing power resource data of the intelligent computing center according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the method for controlling the computing power resource data of the intelligent computing center according to any one of claims 1 to 6 are implemented.

10. A computer program product, characterized in that, Including computer instructions, when the computer instructions are executed by a processor, the steps of the computing power resource data control method of the intelligent computing center described in any one of claims 1 to 6 are implemented.