Data security management method and system for cross-domain interaction and electronic equipment

By deploying data perception nodes and building cross-domain trust chains in cross-domain interactions, positioning multi-level information confrontation point sets, and setting up cross-domain dual protection mechanisms, the problem of lack of dynamic protection in cross-domain interactions is solved, and dynamic perception and precise positioning of cross-domain data security is achieved.

CN120354448APending Publication Date: 2025-07-22LINGSHU TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510429080.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The existing technology lacks cross-domain adaptability and dynamic protection mechanisms in cross-domain interactions, affecting attack protection capabilities and being unable to effectively respond to complex cross-domain security challenges.

Method used

Deploy data-aware nodes, build a cross-domain trust chain, introduce upper and lower critical interactive nodes, adopt multiple data conversion methods, locate multi-level information adversarial point sets, and combine multi-level access control rules to set up a cross-domain dual protection mechanism.

Benefits of technology

It realizes dynamic perception and precise positioning, ensures data security for cross-domain interactions, and improves the security and adaptability of cross-domain interactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120354448A_ABST
    Figure CN120354448A_ABST
Patent Text Reader

Abstract

The invention discloses a data security management method and system for cross-domain interaction and electronic equipment, and relates to the technical field of data security, and the method comprises the steps: deploying data sensing nodes according to cross-domain interaction task requirements, collecting structural features, authority labels and privacy sensitivity identifiers of multi-domain interaction data streams, and constructing a cross-domain trust chain. Introducing an upper critical interaction node of a cross-domain transfer node, and positioning a first multi-level information confrontation point set in a task interaction process by adopting a plurality of data conversion modes; meanwhile, a lower critical interaction node is introduced, and a second multi-level information confrontation point set is positioned. And setting a cross-domain dual-protection mechanism according with a cross-domain compliance protection standard on the basis of the first and second multi-level information confrontation point sets in combination with a multi-level access control rule. And in a cross-domain interaction task execution process, realizing data security management by utilizing the dual protection mechanism. Therefore, the technical effects of dynamic sensing, accurate positioning and data security of cross-domain interaction are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and particularly to a data security management method, system, and electronic device for cross-domain interaction. Background Art

[0002] Cross-domain interaction faces many security challenges, such as inconsistent security policies caused by domain barriers, data being easily stolen or tampered with during transmission, and the lack of trust mechanisms between different domains. In the prior art, traditional security measures, such as firewalls and intrusion detection systems, are mainly used to ensure the security of data interaction. Although these technologies have improved security to a certain extent, they are mostly designed based on the security requirements of a single domain and are difficult to adapt to the complex environment of cross-domain interaction. They cannot be dynamically adjusted flexibly according to the specific situation of cross-domain interaction and lack the ability to protect against cross-domain attacks. Summary of the Invention

[0003] The present invention provides a data security management method, system, and electronic device for cross-domain interaction to solve the technical problem in the prior art that the lack of cross-domain adaptability and dynamic protection mechanism affects the attack protection ability, and to achieve the technical effect of dynamically perceiving and accurately positioning to ensure the data security of cross-domain interaction.

[0004] In a first aspect, the present invention provides a data security management method for cross-domain interaction, wherein the data security management method for cross-domain interaction includes:

[0005] Deploy data perception nodes according to cross-domain interaction tasks, obtain structured features, permission labels, and privacy sensitivity identifiers corresponding to multi-domain interaction data streams, and construct a cross-domain trust chain.

[0006] Introduce the upper critical interaction nodes of the cross-domain transfer nodes, and use various data conversion methods in data interaction in the cross-domain trust chain to locate the first multi-level information confrontation point set in the execution of task interaction.

[0007] Introduce the lower critical interaction nodes of the cross-domain transfer nodes, and use various data conversion methods in data interaction in the cross-domain trust chain to locate the second multi-level information confrontation point set in the execution of task interaction.

[0008] Based on the first multi-level information confrontation point set and the second multi-level information confrontation point set, combine multi-level access control rules to set a cross-domain dual protection mechanism, and the cross-domain dual protection mechanism complies with cross-domain compliance protection standards.

[0009] Use the cross-domain dual protection mechanism to perform data security management during the execution of the cross-domain interaction task.

[0010] In a feasible implementation, various data conversion methods in data interaction are adopted in the cross-domain trust chain to locate the first multi-level information confrontation point set in task interaction execution, including:

[0011] Configure the user behavior baseline based on historical normal interaction data.

[0012] Introduce the upper critical interaction node of the cross-domain transfer node, and evaluate the behavior deviation degree D with reference to the user behavior baseline.

[0013] In the cross-domain trust chain, adopt various data conversion methods in data interaction, filter adversarial samples with the behavior deviation degree D, and obtain the first multi-level information confrontation point set in task interaction execution.

[0014] In a feasible implementation, introduce the upper critical interaction node of the cross-domain transfer node, and evaluate the behavior deviation degree D with reference to the user behavior baseline, including:

[0015] Model the user behavior baseline, and define the user behavior baseline model B = {μ req , σ req , T interval}, where μ req is the mean of the number of requests, σ req is the standard deviation of the number of requests, and T interval is the average time of the request interval.

[0016] The behavior deviation degree where z is the current number of requests and t is the current request interval time.

[0017] In a feasible implementation, after constructing the cross-domain trust chain, it further includes:

[0018] In the cross-domain trust chain, extract the PageRank security weight corresponding to cross-domain interaction, and construct a directed acyclic graph trust network.

[0019] Based on the directed acyclic graph trust network, configure link state routing, and the link state routing is associated with key trust nodes.

[0020] At the same time, when the key trust node fails, trigger the distributed consensus reorganization of the directed acyclic graph trust network.

[0021] In a feasible implementation, based on the directed acyclic graph trust network, configuring link state routing includes:

[0022] Based on the directed acyclic graph trust network, establish a routing table.

[0023] Perform dynamic refresh using the routing table based on the key trust nodes and the node weight update frequency.

[0024] In a feasible implementation, performing dynamic refresh using the routing table includes:

[0025] Define a quantum entanglement key pool, where the key distribution rate and key distribution distance of the quantum entanglement key pool meet the interaction requirements.

[0026] Configure a privacy computing container at the edge computing node to perform homomorphic encryption hybrid operations. If the quantum channel bit error rate is greater than the preset bit error rate and the key trust node fails, extract a backup key from the quantum entanglement key pool.

[0027] Meanwhile, use a timestamp blockchain to store interaction credential metadata.

[0028] In a feasible implementation, during the execution of the cross-domain interaction task, data security management includes:

[0029] Determine the first cross-domain data outflow segment based on the upper critical interaction node of the cross-domain transfer node.

[0030] Deploy a lightweight traffic probe in the first cross-domain data outflow segment.

[0031] Based on the lightweight traffic probe, calculate the entropy value H = -∑p(x i )log2p(x i ) of the data flow within the segment in real time, and perform traffic anomaly monitoring.

[0032] where x i is the i-th type of event or the i-th type of symbol in the multi-domain interaction data flow, and p(x i ) refers to the probability of the i-th type of event or the i-th type of symbol appearing in the multi-domain interaction data flow.

[0033] In a feasible implementation, during the execution of the cross-domain interaction task, data security management further includes:

[0034] Determine the second cross-domain data outflow segment based on the lower critical interaction node of the cross-domain transfer node.

[0035] Deploy a random number generator in the second cross-domain data outflow segment to generate a random traffic confusion sequence.

[0036] When an external attack is received, activate the mimic defense mode, which is used to perform service port hopping according to the random traffic confusion sequence.

[0037] Second aspect, the present invention also provides a data security management system for cross-domain interaction. Among them, the data security management system for cross-domain interaction includes:

[0038] A trust chain construction module, configured to deploy data perception nodes according to cross-domain interaction tasks, obtain structured features, permission tags, and privacy sensitivity identifiers corresponding to multi-domain interaction data streams, and construct a cross-domain trust chain.

[0039] A first positioning module, configured to introduce the upper critical interaction node of the cross-domain transfer node, and adopt various data conversion methods in data interaction in the cross-domain trust chain to locate the first multi-level information confrontation point set in the execution of task interaction.

[0040] A second positioning module, configured to introduce the lower critical interaction node of the cross-domain transfer node, and adopt various data conversion methods in data interaction in the cross-domain trust chain to locate the second multi-level information confrontation point set in the execution of task interaction.

[0041] A protection mechanism configuration module, configured to set a cross-domain dual protection mechanism based on the first multi-level information confrontation point set and the second multi-level information confrontation point set, in combination with multi-level access control rules, and the cross-domain dual protection mechanism complies with the cross-domain compliance protection standard.

[0042] A security management execution module, configured to perform data security management during the execution of the cross-domain interaction task with the cross-domain dual protection mechanism.

[0043] Third aspect, the present invention also provides an electronic device, including: a memory for storing executable instructions; a processor, when executing the executable instructions stored in the memory, implements the data security management method for cross-domain interaction provided by the present invention.

[0044] The present invention discloses a data security management method, system and electronic device for cross-domain interaction, including: deploying data perception nodes according to the requirements of cross-domain interaction tasks, collecting the structured features, permission tags and privacy sensitivity identifiers of multi-domain interaction data streams, and constructing a cross-domain trust chain. Introduce the upper critical interaction nodes of the cross-domain transfer nodes, adopt various data conversion methods to locate the first multi-level information confrontation point set in the task interaction process; at the same time, introduce the lower critical interaction nodes to locate the second multi-level information confrontation point set. Based on the first and second multi-level information confrontation point sets, combined with multi-level access control rules, set a cross-domain dual protection mechanism that meets the cross-domain compliance protection standard. During the execution of the cross-domain interaction task, use the dual protection mechanism to implement data security management. The data security management method, system and electronic device for cross-domain interaction disclosed by the present invention solve the technical problems of lack of cross-domain adaptability and dynamic protection mechanism, which affect the attack protection ability, and achieve the technical effects of dynamic perception and accurate positioning, ensuring the data security of cross-domain interaction. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 It is a schematic flowchart of the data security management method for cross-domain interaction of the present invention.

[0046] Figure 2 It is a schematic structural diagram of the data security management system for cross-domain interaction of the present invention.

[0047] Figure 3 It is a schematic structural diagram of an exemplary electronic device of the present invention.

[0048] Description of the reference numerals: Trust chain construction module 11, First positioning module 12, Second positioning module 13, Protection mechanism configuration module 14, Security management execution module 15, Processor 31, Memory 32, Input device 33, Output device 34. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0049] The following will describe the above technical solutions in detail in combination with the accompanying drawings of the specification and specific embodiments to better understand the above technical solutions. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments of the present invention. It should be understood that the present invention is not limited to the exemplary embodiments for explaining the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention. In addition, it should be noted that, for the sake of description, only the parts related to the present invention are shown in the drawings rather than all.

[0050] Embodiment 1, as Figure 1 It is a schematic flowchart of the data security management method for cross-domain interaction of the present invention, wherein the data security management method for cross-domain interaction includes:

[0051] S100: Deploy data perception nodes according to cross - domain interaction tasks, obtain the structured features, permission tags, and privacy sensitivity identifiers corresponding to the multi - domain interaction data stream, and construct a cross - domain trust chain.

[0052] Specifically, the data perception node refers to a monitoring unit deployed on the access side of each data stream or the interaction path, which has the capabilities of real - time data stream acquisition, parsing, and attribute marking. By deploying data perception nodes at key nodes of the cross - domain interaction system (such as the data source side, data exchange platform, receiving terminal side) as the basic perception carriers, the whole - process monitoring of the data stream can be realized, ensuring the reliability of the original data source for subsequent feature extraction and trust evaluation.

[0053] Specifically, obtain the structured features, permission tags, and privacy sensitivity identifiers of the multi - domain interaction data stream. Among them, the structured features refer to the organizational form and attributes of the data, that is, the information such as the data types, formats, and field distributions that can be clearly extracted from the data stream; the permission tags identify the access permissions or ownership rights of the data stream (such as the source department, data owner, access level); the privacy sensitivity identifier is a sensitivity level set according to the privacy degree involved in the data content (such as high - sensitivity, medium - sensitivity, low - sensitivity).

[0054] Exemplarily, through the data perception node, the received interaction data stream is parsed in real - time: extract information such as data types and field structures in the data to form structured features; mark the corresponding permission tags according to the data source, protocol authentication information, etc.; combine the preset sensitive word library and data content features to identify whether the data contains privacy information and generate sensitivity identifiers.

[0055] Specifically, through the above - mentioned structured features, permission tags, and privacy sensitivity identifiers, a cross - domain trust chain can be constructed. The cross - domain trust chain refers to a dynamic trust evaluation link established based on the data stream structure features, permission tags, and privacy sensitivity as the core basis, which is used to ensure the security and credibility of cross - domain data interaction. Among them, each node of the trust chain represents a trust relationship (recording the corresponding data attributes and trust scores), thus ensuring the credibility of data transmission between different domains.

[0056] Through the deployment of data perception nodes and the construction of a cross - domain trust chain, the characteristics of the data stream can be dynamically perceived, providing a basis for subsequent protection mechanisms. It helps to improve the adaptability to different interaction scenarios and the security of cross - domain interactions.

[0057] S200: Introduce the upper - critical interaction node of the cross - domain transfer node, and adopt various data conversion methods in the data interaction in the cross - domain trust chain to locate the first multi - level information confrontation point set in the task interaction execution.

[0058] Specifically, a cross - domain transfer node refers to an intermediate node during data interaction between different domains, which is used to coordinate and manage data transmission and conversion. An upper - critical interaction node refers to a node in a data interaction topology where data flows frequently, has a large interaction volume, or has a significant boundary of information interaction permissions, and belongs to a potential security bottleneck or a "critical loop" of the trust chain.

[0059] Specifically, during the data interaction process, in order to meet the security requirements of different domains, various data - processing methods need to be adopted, such as encryption, format conversion, access control, etc. A multi - level information confrontation point set refers to nodes that combine various data - conversion methods during the data interaction process and identify phenomena such as abnormal changes in access permissions, failure of sensitive - information desensitization, and abnormal restructuring of data structures, that is, high - risk confrontation - behavior nodes, which are used as the decision basis for subsequent trust - chain correction, enhanced access control, and risk warning.

[0060] In some embodiments, in the cross - domain trust chain, various data - conversion methods in data interaction are adopted to locate the first multi - level information confrontation point set in task - interaction execution, including:

[0061] Based on historical normal interaction data, configure a user - behavior baseline; introduce the upper - critical interaction nodes of the cross - domain transfer nodes, and evaluate the behavior deviation degree D with reference to the user - behavior baseline; in the cross - domain trust chain, adopt various data - conversion methods in data interaction, and filter adversarial samples with the behavior deviation degree D to obtain the first multi - level information confrontation point set in task - interaction execution.

[0062] Specifically, a user - behavior baseline refers to a behavior model established based on historical normal interaction data, which is used to evaluate whether the behavior of the current data flow is abnormal. The behavior deviation degree D is a quantitative index used to measure the degree of difference between the current behavior and the user - behavior baseline. Adversarial - sample filtering is a technique used to identify and filter possible attack samples. A multi - level information confrontation point set refers to multiple risk points that may occur during the data - interaction process, and these risk points may involve the privacy, integrity, and availability of data.

[0063] Specifically, first, obtain the historical normal interaction data in the cross - domain data - interaction system, count the interaction - behavior characteristics of users under different domains, different data types, and different access permissions, and establish a user - behavior baseline as a reference standard for subsequent behavior - deviation evaluation. Exemplarily, the user - behavior baseline includes but is not limited to: interaction - frequency distribution; data - access - path pattern; typical data - conversion method; permission - label change rule, etc.

[0064] Specifically, then, for the upper critical interaction nodes in the cross-domain trust chain, the interaction behavior data is collected in real time and compared with the user behavior baseline for feature comparison to evaluate the deviation degree D of the current interaction behavior. Among them, the behavior deviation degree D can be calculated based on indicators such as access path anomaly degree, data structure change degree, permission label offset, and interaction frequency anomaly amplitude.

[0065] Specifically, then, based on the behavior deviation degree D of each interaction node in the cross-domain trust chain, combined with the data interaction conversion methods adopted by the nodes (including data structure conversion, permission label reconstruction, privacy sensitivity adjustment, etc.), further adversarial feature recognition and filtering are performed on the interaction samples whose behavior deviation degree exceeds the preset threshold, so as to screen out multi-level information confrontation points with potential risks of data tampering, permission violation, or privacy leakage.

[0066] Through the above method, the first set of multi-level information confrontation points with adversarial risk characteristics in the task interaction execution process can be obtained, thus providing a support basis for subsequent trust chain security policy adjustment and risk warning.

[0067] In some embodiments, for the upper critical interaction nodes introducing cross-domain transfer nodes, the behavior deviation degree D is evaluated with reference to the user behavior baseline, including:

[0068] Model the user behavior baseline, and define the user behavior baseline model B = {μ req , σ req , T interval}, where μ req is the mean of the request times, σ req is the standard deviation of the request times, and T interval is the average time between requests; the behavior deviation degree where z is the current request times and t is the current request interval time.

[0069] Specifically, based on historical normal interaction data, statistical analysis is performed on user behavior characteristics to establish a user behavior baseline model B, and this baseline model B is used to characterize the feature parameters of user normal behavior.

[0070] Specifically, the user behavior baseline model B includes: μ req , representing the mean of the user request times per unit time, σ req , representing the standard deviation of the user request times, used to reflect the volatility of the request times, and T interval , representing the average time interval between two consecutive requests of the user.

[0071] Further, for the upper critical interaction nodes of cross-domain transfer nodes, the current interaction behavior data is collected in real time, the current request count z and the current request interval time t are obtained, and based on the user behavior baseline model B, the behavior deviation degree D is calculated in combination with the behavior deviation evaluation formula. The behavior deviation degree D is used to quantify the deviation degree between the current interaction behavior and the normal behavior baseline. The larger the D value, the more abnormal the current behavior is.

[0072] By calculating the behavior deviation degree D, abnormal behaviors in the current data stream can be identified. When D exceeds the preset threshold, the current data stream is marked as a potential risk, and the multi-level information confrontation point set in the task interaction execution is further analyzed and located.

[0073] In some embodiments, after constructing the cross-domain trust chain, it further includes:

[0074] In the cross-domain trust chain, the PageRank security weight corresponding to the cross-domain interaction is extracted to construct a directed acyclic graph trust network; based on the directed acyclic graph trust network, the link state routing is configured, and the link state routing is associated with the key trust nodes; at the same time, when the key trust node fails, the distributed consensus reorganization of the directed acyclic graph trust network is triggered.

[0075] Specifically, for the multi-node data stream in the cross-domain interaction process, the node behaviors and interaction patterns in the cross-domain interaction are analyzed, and the PageRank security weight corresponding to each cross-domain interaction is extracted to reflect the trust influence and interaction importance of each interaction node in the overall interaction process. Furthermore, based on the PageRank security weight, a directed acyclic graph (DAG) trust network is constructed. Each node in the directed acyclic graph trust network corresponds to a cross-domain interaction node, and the directionality of the edge represents the data interaction flow direction; the weight of the edge is associated with the PageRank security weight. Through this trust network, the trust transfer path and node trust level in the cross-domain interaction can be comprehensively characterized.

[0076] Further, based on the directed acyclic graph trust network, the link state routing protocol is adopted to configure the link state routing in the cross-domain data interaction to ensure the safe and efficient transfer of the data interaction path in the trust chain. Among them, the link state routing is bound to the key trust nodes and is used to dynamically select the optimal path; the key trust nodes are the nodes whose PageRank security weight exceeds the preset trust threshold.

[0077] Meanwhile, when a critical trust node fails (such as communication anomaly, permission revocation, or detection of abnormal behavior), a distributed consensus reorganization mechanism of the directed acyclic graph trust network is automatically triggered, including recalculating the PageRank security weights of affected nodes; updating the DAG trust network structure; reconfiguring the link state routing to ensure the integrity, coherence, and fault tolerance of data interaction in the cross-domain trust chain.

[0078] Through the above-mentioned directed acyclic graph trust network constructed based on PageRank security weights, and by introducing link state routing and a distributed consensus reorganization mechanism, the adaptive construction and maintenance of a dynamic trusted network in the cross-domain trust chain can be realized, effectively enhancing the security, controllability, and anti-attack ability of the multi-domain data interaction process.

[0079] In some embodiments, based on the directed acyclic graph trust network, configuring link state routing includes:

[0080] Based on the directed acyclic graph trust network, a routing table is established; through the critical trust nodes and the node weight update frequency, the routing table is dynamically refreshed.

[0081] Optionally, first, based on the PageRank security weights of each node in the directed acyclic graph trust network and the directed connection relationship between nodes, a corresponding cross-domain link state routing table is established. Exemplarily, the routing table includes the identification information of each cross-domain interaction node, the current security weight value of the node, the downstream interaction nodes it points to and their weights, the identification and priority information of critical trust nodes, etc., which is used to guide the selection of data forwarding paths in the cross-domain data interaction process.

[0082] Optionally, the routing table is configured with a dynamic refresh mechanism, that is, based on the critical trust nodes recorded in the routing table and their weight update frequency, the routing table is dynamically refreshed regularly or on demand. Exemplarily, it includes:

[0083] When it is detected that the change in the PageRank security weight of a critical trust node exceeds a preset threshold, the routing weight of the corresponding node is updated; when a new node joins or an existing node fails, the routing table structure is dynamically adjusted; according to the weight update frequency, an incremental update mechanism is set to reduce the routing table synchronization overhead and improve the system response efficiency.

[0084] By establishing a routing table based on a directed acyclic graph trust network and combining the weight changes of key trust nodes to achieve dynamic refresh, it can effectively improve the routing decision accuracy and system robustness in the process of cross-domain data interaction, and achieve real-time adaptive adjustment of the trust chain link state. For example, in the cross-domain interaction between the Internet of Things and cloud computing, by dynamically refreshing the routing table, it can ensure that data is always transmitted through the safest and most efficient path, thereby improving the performance and security of the entire system. This dynamic path optimization and security enhancement ability enables the system to provide a higher level of data transmission guarantee in a complex cross-domain environment.

[0085] In some embodiments, using the routing table for dynamic refresh includes:

[0086] Define a quantum entanglement key pool, where the key distribution rate and key distribution distance of the quantum entanglement key pool meet the interaction requirements; configure a privacy computing container at the edge computing node for homomorphic encryption hybrid operation. If the quantum channel bit error rate is greater than the preset bit error rate and the key trust node fails, extract a backup key from the quantum entanglement key pool; at the same time, use a timestamp blockchain to store the interaction credential metadata.

[0087] Optionally, for dynamic refresh of the routing table, first, define a quantum entanglement key pool that pre-stores data encryption key pairs for cross-domain interaction, and the key pool has the following characteristics: the key distribution rate meets the real-time requirements of cross-domain data interaction, the key distribution distance covers the spatial distribution range of cross-domain interaction nodes, and the key entanglement degree and error correction ability reach the cross-domain trust chain security standard, thus providing a basis for subsequent data encryption.

[0088] Then, configure a privacy computing container at the edge computing node in the directed acyclic graph trust network. This container has the ability of homomorphic encryption hybrid operation and is used for trusted computing in the encrypted state of the interaction data to prevent the leakage of sensitive data.

[0089] Optionally, during the cross-domain data interaction process, if it is detected that the quantum channel bit error rate exceeds the preset bit error rate threshold or the key trust node fails, dynamically extract a backup key from the quantum entanglement key pool to ensure the security and continuity of cross-domain data interaction; at the same time, store the credential metadata in the cross-domain data interaction process using a timestamp blockchain. Exemplarily, it specifically includes: interaction initiation timestamp, the quantum key identifier used, routing node information and link state, anomaly detection and fault tolerance processing records.

[0090] By introducing a quantum entanglement key pool, edge privacy computing containers, and a blockchain evidence storage mechanism, in the process of dynamic routing update of the cross-domain trust chain, the anti-attack ability, key fault tolerance ability, and data traceability of the interaction link are effectively improved, realizing high security and controllability of cross-domain data interaction.

[0091] S300: Introduce the lower critical interaction node of the cross-domain transfer node, adopt various data conversion methods in data interaction in the cross-domain trust chain, and locate the second multi-level information confrontation point set in the task interaction execution.

[0092] Specifically, the lower critical interaction node of the cross-domain transfer node refers to the key node when data flows out, which is used to monitor and process the security of the outflow data. By introducing the lower critical interaction node recognition mechanism, effective monitoring of potential hidden confrontation behaviors at the end of data interaction is realized in the cross-domain trust chain system, the multi-level information confrontation detection ability in the cross-domain interaction process is improved, and the integrity and controllability of cross-domain data interaction are ensured.

[0093] Specifically, the second multi-level information confrontation point set is constructed using the same method principle as the above first multi-level information confrontation point set. It should be understood that for the sake of simplicity of the specification, no further elaboration is made here.

[0094] In some embodiments, during the execution of the cross-domain interaction task, data security management further includes:

[0095] Based on the lower critical interaction node of the cross-domain transfer node, determine the second cross-domain data outflow segment; deploy a random number generator in the second cross-domain data outflow segment to generate an irregular traffic confusion sequence; when an external attack is received, activate the mimic defense mode, and the mimic defense mode is used to perform service port hopping according to the irregular traffic confusion sequence.

[0096] Specifically, first, based on the lower critical interaction node, determine the second cross-domain data outflow segment, that is, the outlet data flow area starting from the lower critical node. This segment is used as the key protection area, and all data flows passing through here will be uniformly monitored and processed. Then, within the second cross-domain data outflow segment, deploy a high-performance random number generator. The output of the random number generator is used to generate an irregular traffic confusion sequence, which is used to insert random perturbation information during the data flow transmission process, thereby disrupting the true traffic characteristics of the data packets and reducing the risk of attackers targeting and attacking based on traffic patterns.

[0097] Furthermore, monitor the cross-domain data flow in real time. When an external attack (such as abnormal access, port scanning, replay attack, etc.) is detected, trigger a preset security policy to activate the mimic defense mode, and dynamically adjust the data transmission path and service port configuration according to the information of the confusion sequence in the signal to achieve service port hopping, that is, switch the current service port within a short time, making it difficult for attackers to lock the target.

[0098] By deploying random number generators in segments at the exit to generate a confusion sequence, the characteristics of the data stream can be effectively disrupted, increasing the difficulty for attackers to locate, and then quickly dispersing or transferring the attack load when an attack is detected, ensuring the stable operation of the system and enhancing the overall protection effect.

[0099] S400: Based on the first multi-level information confrontation point set and the second multi-level information confrontation point set, combined with multi-level access control rules, a cross-domain dual protection mechanism is set up, and the cross-domain dual protection mechanism complies with the cross-domain compliance protection standard.

[0100] Specifically, the multi-level access control rules are preset or dynamically generated by the policy administrator in the platform, supporting multi-level control dimensions: subject dimension, based on user identity, organizational role, authentication method, etc.; object dimension, based on data resource classification, sensitivity level, access scope, etc.; environment dimension, based on access time, geographical location, network environment, etc., and behavior dimension: based on access type (read, write, update, delete), request frequency, etc. Preferably, the access control rules are organized in the form of a policy tree or a rule graph, supporting policy merging, priority control, and conflict resolution.

[0101] Optionally, the cross-domain dual protection mechanism meets multiple cross-domain security compliance requirements. Exemplarily, it includes: the principle of data minimization, only allowing access to the minimum required data set; the principle of controllable access, dynamically authorizing and real-time controlling access permissions; the principle of auditable behavior, completely recording access behaviors, supporting auditing and accountability; the principle of risk perception, having the ability to real-time identify and respond to abnormal behaviors.

[0102] S500: Using the cross-domain dual protection mechanism, data security management is carried out during the execution of the cross-domain interaction task.

[0103] Optionally, the collaborative process of the cross-domain dual protection mechanism includes: when an external system initiates a cross-domain data access request, it first undergoes preliminary detection and identification by the first confrontation point set; if the request passes the first-stage verification, it is forwarded to the target domain; the second confrontation point set in the target domain conducts in-depth analysis and content-level access control on the request; the protection engine makes a decision based on the access control rules to generate an access response result. The cross-domain dual protection mechanism forms a dual protection closed loop of the source domain + target domain, thus further ensuring the security and compliance of cross-domain access.

[0104] In some embodiments, carrying out data security management during the execution of the cross-domain interaction task includes:

[0105] Based on the upper critical interaction node of the cross-domain transfer node, determine the first cross-domain data outflow segment; in the first cross-domain data outflow segment, deploy a lightweight traffic probe; based on the lightweight traffic probe, calculate the entropy value H of the data stream within the segment in real-time, where H = -∑p(xi ) log2p(x i ), and perform traffic anomaly monitoring; where x i is the i-th type of event or the i-th type of symbol in the multi-domain interaction data stream, and p(x i ) refers to the probability that the i-th type of event or the i-th type of symbol appears in the multi-domain interaction data stream.

[0106] Specifically, first, based on the upper critical interaction node of the cross-domain transfer node, determine the first cross-domain data outflow segment. This segment is the logical section that first leaves the control range of the source domain during the process of data flowing from the source domain to the target domain, and is a key monitoring point for cross-domain data outflow behavior. It is usually located at the source domain egress gateway, API gateway, or service mesh boundary node, cross-domain transfer service proxy node (such as reverse proxy, edge computing node), etc. Then, in the first cross-domain data outflow segment, deploy a lightweight traffic probe module. The traffic probe performs symbolic abstraction processing on the data stream, mapping data packets, request events, content fragments, etc. to a series of discrete events or symbols x i for subsequent statistical analysis. This lightweight traffic probe module has the characteristics of low resource occupancy, strong protocol independence, strong real-time performance, and non-intrusive deployment.

[0107] Furthermore, the lightweight traffic probe calculates the information entropy value H of the data stream in this segment in real time based on the collected data stream symbol sequence. This entropy value reflects the complexity and uncertainty of the current data stream, and can be used to identify sudden high-entropy traffic (possibly data leakage or illegal bulk export), low-entropy high-frequency repeated traffic (possibly automated attacks, abnormal scans, etc.), and sharp changes in entropy values (possibly system intrusion or configuration tampering).

[0108] In summary, the cross-domain interaction data security management method provided by the present invention has the following technical effects:

[0109] By deploying data perception nodes according to cross-domain interaction task requirements, collecting the structured features, permission labels, and privacy sensitivity identifiers of the multi-domain interaction data stream, and constructing a cross-domain trust chain. Introducing the upper critical interaction node of the cross-domain transfer node, using multiple data conversion methods to locate the first multi-level information confrontation point set in the task interaction process; at the same time introducing the lower critical interaction node to locate the second multi-level information confrontation point set. Based on the first and second multi-level information confrontation point sets, combined with multi-level access control rules, set up a cross-domain dual protection mechanism that meets the cross-domain compliance protection standard. During the execution of the cross-domain interaction task, use the dual protection mechanism to achieve data security management, thereby achieving the technical effects of dynamic perception and precise positioning to ensure the data security of cross-domain interaction.

[0110] Example 2, as Figure 2It is a schematic structural diagram of the data security management system for cross - domain interaction of the present invention. For example, Figure 1 In the present invention, the schematic flow diagram of the data security management method for cross - domain interaction can be implemented through a structure as shown in Figure 2 the following.

[0111] Based on the same concept as the data security management method for cross - domain interaction in the above - mentioned embodiment, the data security management system for cross - domain interaction provided by the present invention further includes:

[0112] A trust chain construction module 11, configured to deploy data perception nodes according to cross - domain interaction tasks, obtain structured features, permission tags, and privacy sensitivity identifiers corresponding to multi - domain interaction data streams, and construct a cross - domain trust chain.

[0113] A first positioning module 12, configured to introduce the upper critical interaction node of the cross - domain transfer node, and adopt various data conversion methods in data interaction in the cross - domain trust chain to locate the first multi - level information confrontation point set in task interaction execution.

[0114] A second positioning module 13, configured to introduce the lower critical interaction node of the cross - domain transfer node, and adopt various data conversion methods in data interaction in the cross - domain trust chain to locate the second multi - level information confrontation point set in task interaction execution.

[0115] A protection mechanism configuration module 14, configured to set a cross - domain dual - protection mechanism based on the first multi - level information confrontation point set and the second multi - level information confrontation point set, in combination with multi - level access control rules, and the cross - domain dual - protection mechanism complies with the cross - domain compliance protection standard.

[0116] A security management execution module 15, configured to perform data security management in the process of executing the cross - domain interaction task with the cross - domain dual - protection mechanism.

[0117] In some embodiments, the first positioning module 12 includes:

[0118] A user behavior baseline configuration unit, configured to configure a user behavior baseline based on historical normal interaction data.

[0119] A behavior deviation degree evaluation unit, configured to introduce the upper critical interaction node of the cross - domain transfer node, and evaluate the behavior deviation degree D with reference to the user behavior baseline.

[0120] A first multi - level information confrontation point set acquisition unit, configured to adopt various data conversion methods in data interaction in the cross - domain trust chain, filter adversarial samples with the behavior deviation degree D, and obtain the first multi - level information confrontation point set in task interaction execution.

[0121] In some embodiments, the first positioning module 12 further includes:

[0122] A user behavior baseline modeling unit, which is used to model the user behavior baseline and define the user behavior baseline model B = {μ req , σ req , T interval}, where μ req is the mean of the request times, σ req is the standard deviation of the request times, and T interval is the average time of the request interval.

[0123] A behavior deviation calculation unit, which is used for the behavior deviation where z is the current request times and t is the current request interval time.

[0124] In some embodiments, the first positioning module 12 further includes:

[0125] A directed acyclic graph trust network construction unit, which is used to extract the PageRank security weights corresponding to cross-domain interactions in the cross-domain trust chain and construct a directed acyclic graph trust network.

[0126] A link state routing configuration unit, which is used to configure link state routing based on the directed acyclic graph trust network, and the link state routing is associated with key trust nodes.

[0127] A distributed consensus reorganization trigger unit, which is used to trigger the distributed consensus reorganization of the directed acyclic graph trust network when the key trust node fails.

[0128] In some embodiments, the first positioning module 12 further includes:

[0129] A routing table establishment unit, which is used to establish a routing table based on the directed acyclic graph trust network.

[0130] A routing table dynamic refresh unit, which is used to perform dynamic refresh of the routing table through the key trust node and the node weight update frequency.

[0131] In some embodiments, the first positioning module 12 further includes:

[0132] A quantum entanglement key pool definition unit, which is used to define a quantum entanglement key pool, and the key distribution rate and key distribution distance of the quantum entanglement key pool meet the interaction requirements.

[0133] A privacy computing container configuration unit, which is used to configure a privacy computing container at an edge computing node to perform homomorphic encryption hybrid operations, and extract a backup key from the quantum entanglement key pool when the quantum channel bit error rate is greater than a preset bit error rate and the key trust node fails.

[0134] An interaction credential metadata storage unit for storing interaction credential metadata using a timestamp blockchain.

[0135] In some embodiments, it includes:

[0136] A first cross-domain data outflow segment determination unit for determining a first cross-domain data outflow segment based on the upper critical interaction node of the cross-domain transfer node.

[0137] A lightweight traffic probe deployment unit for deploying a lightweight traffic probe in the first cross-domain data outflow segment.

[0138] A traffic anomaly monitoring unit for calculating the entropy value H = -∑p(x i )log2p(x i ) of the data flow within the segment in real time based on the lightweight traffic probe and performing traffic anomaly monitoring. Where x i is the i-th type of event or the i-th type of symbol of the multi-domain interaction data flow, and p(x i ) refers to the probability of the i-th type of event or the i-th type of symbol appearing in the multi-domain interaction data flow.

[0139] In some implementation manners, the second positioning module 13 includes:

[0140] A second cross-domain data outflow segment determination unit for determining a second cross-domain data outflow segment based on the lower critical interaction node of the cross-domain transfer node.

[0141] A random number generator deployment unit for deploying a random number generator in the second cross-domain data outflow segment to generate an irregular traffic confusion sequence.

[0142] A mimic defense mode activation unit for activating the mimic defense mode when receiving an external attack, and the mimic defense mode is used to perform service port hopping according to the irregular traffic confusion sequence.

[0143] It should be understood that the embodiments mentioned in this specification focus on their differences from other embodiments. The specific embodiments in the foregoing Embodiment 1 are equally applicable to the cross-domain interaction data security management system described in Embodiment 2. For the sake of brevity of the specification, no further elaboration is made here.

[0144] Embodiment 3, as Figure 3 is a schematic structural diagram of an exemplary electronic device provided by the present invention, showing a block diagram of an exemplary electronic device suitable for implementing the embodiments of the present invention. Figure 3 The displayed electronic device is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present invention. As Figure 3As shown, the electronic device includes a processor 31, a memory 32, an input device 33, and an output device 34; the number of processors 31 in the electronic device can be one or more. Figure 3 Taking one processor 31 as an example, the processor 31, the memory 32, the input device 33, and the output device 34 in the electronic device can be connected through a bus or other means. Figure 3 Taking connection through a bus as an example.

[0145] The memory 32, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the cross-domain interaction data security management method in the embodiments of the present invention. The processor 31 executes various functional applications and data processing of the computer device by running the software programs, instructions, and modules stored in the memory 32, that is, implements the above-mentioned cross-domain interaction data security management method.

[0146] It should be understood that the disclosed embodiments of the present invention and the above descriptions can enable those skilled in the art to implement the present invention using the present invention. At the same time, the present invention is not limited to the above-mentioned part of the embodiments. It should be understood that those of ordinary skill in the art can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.

Claims

1. A data security management method for cross-domain interaction, characterized in that Including: According to the cross - domain interaction task, deploy data - aware nodes, obtain the structured features, permission tags, and privacy sensitivity identifiers corresponding to the multi - domain interaction data stream, and construct a cross - domain trust chain; Introduce the upper - critical interaction nodes of the cross - domain transfer nodes, and use various data conversion methods in data interaction in the cross - domain trust chain to locate the first multi - level information confrontation point set in the task interaction execution; Introduce the lower - critical interaction nodes of the cross - domain transfer nodes, and use various data conversion methods in data interaction in the cross - domain trust chain to locate the second multi - level information confrontation point set in the task interaction execution; Based on the first multi - level information confrontation point set and the second multi - level information confrontation point set, combined with multi - level access control rules, set up a cross - domain dual - protection mechanism, and the cross - domain dual - protection mechanism complies with the cross - domain compliance protection standard; With the cross - domain dual - protection mechanism, perform data security management during the execution of the cross - domain interaction task.

2. The cross-domain interaction data security management method according to claim 1, wherein, Using various data conversion methods in data interaction in the cross - domain trust chain to locate the first multi - level information confrontation point set in the task interaction execution includes: Configure the user behavior baseline based on historical normal interaction data; Introduce the upper - critical interaction nodes of the cross - domain transfer nodes, and evaluate the behavior deviation degree D against the user behavior baseline; Using various data conversion methods in data interaction in the cross - domain trust chain, filter adversarial samples with the behavior deviation degree D to obtain the first multi - level information confrontation point set in the task interaction execution.

3. The cross-domain interaction data security management method according to claim 2, wherein Introduce the upper - critical interaction nodes of the cross - domain transfer nodes, and evaluate the behavior deviation degree D against the user behavior baseline, including: Model the user behavior baseline and define the user behavior baseline model B = {μ req , σ req , T interval}, where μ req is the mean of the number of requests, σ req is the standard deviation of the number of requests, and T interval is the average time between requests; The deviation of the behavior z is the current number of requests, and t is the current request interval time.

4. The cross-domain interaction data security management method according to claim 1, wherein After constructing the cross - domain trust chain, it further includes: In the cross - domain trust chain, extract the PageRank security weight corresponding to the cross - domain interaction, and construct a directed acyclic graph trust network; Based on the directed acyclic graph trust network, configure the link - state routing, and the link - state routing is associated with the key trust nodes; Meanwhile, when the key trust nodes fail, trigger the distributed consensus reorganization of the directed acyclic graph trust network.

5. The cross-domain interaction data security management method according to claim 4, characterized in that Based on the directed acyclic graph trust network, configuring the link - state routing includes: Based on the directed acyclic graph trust network, establish a routing table; Through the key trust nodes and the node weight update frequency, use the routing table for dynamic refreshing.

6. The cross-domain interaction data security management method according to claim 5, wherein Using the routing table for dynamic refreshing includes: Define a quantum entanglement key pool, and the key distribution rate and key distribution distance of the quantum entanglement key pool meet the interaction requirements; Configure privacy - computing containers at the edge - computing nodes to perform homomorphic encryption hybrid operations. If the quantum - channel bit - error rate is greater than the preset bit - error rate and the key trust nodes fail, extract backup keys from the quantum entanglement key pool; Meanwhile, use timestamp blockchain to store the interaction credential metadata.

7. The cross-domain interaction data security management method according to claim 1, characterized in that, Performing data security management during the execution of the cross - domain interaction task includes: Based on the upper - critical interaction nodes of the cross - domain transfer nodes, determine the first cross - domain data outflow segment; Deploy lightweight traffic probes in the first cross - domain data outflow segment; Based on the lightweight traffic probe, the entropy value H of the data stream within the segment is calculated in real time, where H = -∑p(x i ) log2p(x i ), and traffic anomaly monitoring is performed; where x i is the i-th type of event or the i-th type of symbol in the multi-domain interaction data stream, and p(x i ) refers to the probability of the i-th type of event or the i-th type of symbol occurring in the multi-domain interaction data stream.

8. The cross-domain interaction data security management method according to claim 7, characterized in that, Performing data security management during the execution of the cross - domain interaction task further includes: Based on the lower critical interaction node of the cross-domain transfer node, determine the second cross-domain data outflow segment; Deploy a random number generator in the second cross-domain data outflow segment to generate an irregular traffic confusion sequence; When an external attack is received, activate the mimic defense mode, which is used to perform service port hopping according to the irregular traffic confusion sequence.

9. A data security management system for cross-domain interaction, characterized in that, A data security management method for cross-domain interaction according to any one of claims 1-8, comprising: A trust chain construction module, configured to deploy data perception nodes according to cross-domain interaction tasks, obtain structured features, permission labels, and privacy sensitivity identifiers corresponding to multi-domain interaction data streams, and construct a cross-domain trust chain; A first positioning module, configured to introduce the upper critical interaction node of the cross-domain transfer node, and adopt various data conversion methods in data interaction in the cross-domain trust chain to locate the first multi-level information confrontation point set in task interaction execution; A second positioning module, configured to introduce the lower critical interaction node of the cross-domain transfer node, and adopt various data conversion methods in data interaction in the cross-domain trust chain to locate the second multi-level information confrontation point set in task interaction execution; A protection mechanism configuration module, configured to set a cross-domain dual protection mechanism based on the first multi-level information confrontation point set and the second multi-level information confrontation point set, in combination with multi-level access control rules, and the cross-domain dual protection mechanism complies with cross-domain compliance protection standards; A security management execution module, configured to perform data security management during the execution of the cross-domain interaction task with the cross-domain dual protection mechanism.

10. An electronic device, characterized in that, The electronic device includes: A memory for storing executable instructions; A processor, configured to implement the data security management method for cross-domain interaction according to any one of claims 1 to 8 when executing the executable instructions stored in the memory.