AI-based full-life-cycle data security management platform and method

Through the AI-based full-life cycle data security management platform, the asset data management module is used for classification and grading and strategy generation, the problem of inefficiency in traditional data security management is solved, and the safe and reliable management of the entire life cycle of data is achieved.

CN120493271AActive Publication Date: 2025-08-15盐城市大数据集团有限公司
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510431873.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-08-15
Estimated Expiration
2045-04-08

AI Technical Summary

Technical Problem

Traditional data security management lacks overall control over the entire life cycle of data, resulting in inefficiency and error-proneness, and being unable to effectively deal with complex security threats.

Method used

Adopt AI-based full-life cycle data security management platform, classify and classify the asset data management module, generate data security management policies, and implement data scenario-based component-driven to achieve security management throughout the life cycle.

Benefits of technology

It improves the efficiency and accuracy of data processing, ensures the safety and reliability of the entire life cycle of data, provides reliable basis and convenience, and realizes comprehensive and reliable management of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120493271A_ABST
    Figure CN120493271A_ABST
Patent Text Reader

Abstract

The invention provides an AI-based full life cycle data security management platform and method, and the platform comprises an asset data management module which is used for reading asset data based on AI in a data life cycle security process domain and carrying out the classification and grading of the asset data; the strategy generation module is used for generating a data security management strategy according to the classification and grading result; and the driving module is used for carrying out data scenarizing and component driving on the asset data according to the data security policy to complete safe use of the full life cycle data. According to the invention, comprehensive and reliable security management of data in each data scene is realized, the processing efficiency and processing accuracy of the data are improved, and the security and reliability of the data in the whole life cycle are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing technology, and in particular to an AI-based full-lifecycle data security management platform and method. Background Art

[0002] With the rapid development of information technology, data is increasingly generated, stored, transmitted, and used in various fields. While data brings huge value and opportunities, it also faces numerous security threats, such as data leakage, data tampering, and unauthorized access.

[0003] Traditional data security management often focuses on a specific stage or type of security threat, lacking overall control over the entire data lifecycle. Furthermore, faced with massive amounts of data and complex security threat scenarios, manual management methods are inefficient and prone to errors, significantly reducing data management effectiveness.

[0004] Therefore, in order to overcome the above-mentioned defects, the present invention provides an AI-based full-lifecycle data security management platform and method. Summary of the Invention

[0005] The present invention provides an AI-based full-life cycle data security management platform and method, which is used to read asset data based on AI in the data life cycle security process domain and classify and grade the read asset data, thereby ensuring the comprehensiveness and reliability of the read asset data, and at the same time ensuring the efficiency and accuracy of the classification of asset data. Secondly, according to the classification and grading results, corresponding data security management strategies are generated, which provides a reliable basis and convenience for the full life cycle security management of asset data. Finally, according to the obtained data security management strategies, the asset data is scenario-based and component-driven, realizing comprehensive and reliable security management of data in various data scenarios, improving the processing efficiency and accuracy of data, and ensuring the security and reliability of data throughout its life cycle.

[0006] The present invention provides an AI-based full-lifecycle data security management platform, including:

[0007] The asset data management module is used to read asset data and classify and grade asset data based on AI in the data lifecycle security process domain;

[0008] A policy generation module is used to generate data security management policies based on the classification and grading results;

[0009] The driver module is used to contextualize asset data and drive components according to data security policies, thereby ensuring the safe use of data throughout its life cycle.

[0010] Preferably, in an AI-based full life cycle data security management platform, in the asset data management module, the data life cycle security process domain includes: data collection security, data transmission security, data storage security, data processing security, data exchange security, and data destruction security.

[0011] Preferably, an AI-based full lifecycle data security management platform, asset data management module, includes:

[0012] A data object determination unit, configured to obtain a data object corresponding to the asset data;

[0013] Recognition algorithm generation unit, used for:

[0014] Locating the target traditional algorithm in the preset traditional algorithm set and the target AI algorithm in the preset AI algorithm set according to the data object;

[0015] Generate a recognition algorithm based on the target traditional algorithm and the target AI algorithm;

[0016] A data identification unit is used to identify asset data according to an identification algorithm, retrieve a preset classification and grading knowledge base, and classify and grade the identification results according to the preset classification and grading knowledge base;

[0017] The virtual asset management unit is used to perform virtual asset management on asset data based on the classification and grading results.

[0018] Preferably, an AI-based full-lifecycle data security management platform, a policy generation module, includes:

[0019] A calling unit, used to call the data security management policy pool;

[0020] The data partitioning unit is used to read the classification and grading results of the asset data and divide the asset data according to the classification and grading results to obtain the sub-asset data set under each category and each level;

[0021] Security configuration unit, used to:

[0022] Obtain the data attribute characteristics of the sub-asset dataset and determine the security management requirements of the sub-asset dataset based on the data attribute characteristics;

[0023] Retrieve the target data security management policy corresponding to the sub-asset dataset from the data security management policy pool based on security management requirements;

[0024] Configure the target security management policy in the corresponding sub-asset data set.

[0025] Preferably, an AI-based full-lifecycle data security management platform, a data identification unit, includes:

[0026] The automatic identification subunit is used to automatically identify asset data before reading it, specifically:

[0027] Build a data asset dictionary and draw a data asset map. At the same time, define sensitive data based on the data asset dictionary and data asset map;

[0028] Automatically scan sensitive data in asset data based on the defined results, and index and mark the data categories of the scanned sensitive data;

[0029] Automatically identify core data in asset data based on index tags.

[0030] Preferably, an AI-based full-lifecycle data security management platform, the driving module includes:

[0031] The scenario division unit is used to read the entire life cycle process of asset data, divide the asset data into scenarios according to the entire life cycle process of asset data, and obtain the operating characteristics of asset data in each scenario based on the division results;

[0032] A policy determination unit, configured to determine a corresponding target data security policy based on the operational characteristics of the asset data in each scenario;

[0033] A component determination unit, used to obtain the target component corresponding to each scene;

[0034] The component driving unit is used to drive components in corresponding scenarios according to the target data security policy and target components, and complete the safe use of data throughout its life cycle.

[0035] Preferably, an AI-based full-lifecycle data security management platform, the driving module includes:

[0036] Model building preparation unit for:

[0037] Obtain full-process parameters for scenario-based asset data and component-driven operations, and determine the full lifecycle management nodes of asset data based on the full-process parameters;

[0038] Obtain anomaly monitoring dimensions for the full lifecycle management node based on the management terminal, where the anomaly monitoring dimensions include data anomaly dimensions and user access behavior anomaly dimensions;

[0039] Extract the data business attributes of each period management node in the full lifecycle management node, and determine the operation mode of the asset data under each period management node and the benchmark characteristics under the operation mode based on the data business attributes;

[0040] Determine the data anomaly focus points for each periodic management node based on the operating mode and benchmark characteristics, and build data anomaly monitoring rules and anomaly level classification rules for each periodic management node based on data business attributes and data anomaly focus points;

[0041] Based on the data anomaly monitoring rules and anomaly level classification rules, a data anomaly monitoring system for each period management node is obtained, and the data anomaly monitoring system is used as the first model element;

[0042] At the same time, the data sensitivity of each periodic management node is determined based on the data service attributes of each periodic management node, and the data access rights of each periodic management node are determined based on the data sensitivity;

[0043] Determine the data usage scenarios and scenario supervision indicators under each periodic management node based on data access rights, and obtain the user access behavior anomaly monitoring system for each periodic management node based on the data usage scenarios and scenario supervision indicators, and use the user access behavior anomaly monitoring system as the second model element;

[0044] Performing a first binding on the first model element and the second model element based on the period management node, and performing a second binding on the first binding result according to the execution order of the period management node;

[0045] Anomaly monitoring model building unit, used to:

[0046] The second binding result is integrated and trained in a preset model framework to obtain a target anomaly monitoring model, and the target anomaly monitoring model is interfaced with each period management node;

[0047] Based on the interface docking results, the entire life cycle management node is monitored for abnormalities.

[0048] Preferably, an AI-based full-lifecycle data security management platform, an anomaly monitoring model building unit, includes:

[0049] Monitoring subunit, used to:

[0050] Based on the interface docking results, users' access data on asset data under different cycle management nodes is obtained in real time, and the access data is analyzed to determine the derivative data corresponding to the access data;

[0051] Determine the multi-dimensional working characteristics of the interface during the monitoring period based on the derived data, and construct an interface profile of the interface during the monitoring period based on the multi-dimensional working characteristics;

[0052] User portrait construction sub-unit is used to:

[0053] Determine the user's access behavior set for asset data under different period management nodes based on the derived data, and quantify each access behavior in the access behavior set to obtain the corresponding quantitative index value;

[0054] Determine a visualization chart for the quantitative indicator value based on the preset visualization requirements, and display the corresponding values of the quantitative indicator based on the visualization chart to obtain the corresponding user behavior portrait;

[0055] The recording subunit is used to record and store the obtained interface portrait and user behavior portrait.

[0056] Preferably, an AI-based full-lifecycle data security management platform, an anomaly monitoring model building unit, includes:

[0057] The result acquisition subunit is used to:

[0058] Obtain abnormal monitoring results for the entire lifecycle management node and lock the abnormal source when an abnormality occurs;

[0059] Analyze the locked exception source, determine the exception type and exception representation, and match the response strategy from the preset response strategy library based on the exception type and exception representation;

[0060] The exception response subunit is used to:

[0061] Provide early warning responses to abnormal types and abnormal characteristics based on response strategies.

[0062] The present invention provides an AI-based full-lifecycle data security management method, including:

[0063] Step 1: Read asset data based on AI and classify and grade the asset data in the data lifecycle security process area;

[0064] Step 2: Generate a data security management strategy based on the classification and grading results;

[0065] Step 3: Based on the data security policy, the asset data is contextualized and component-driven to ensure the safe use of data throughout its life cycle.

[0066] Compared with the prior art, the present invention has the following beneficial effects:

[0067] By reading asset data based on AI in the data lifecycle security process domain and classifying and grading the read asset data, the comprehensiveness and reliability of the read asset data are ensured, while the efficiency and accuracy of the grading of asset data are ensured. Secondly, the corresponding data security management strategy is generated according to the classification and grading results, which provides a reliable basis and convenience for the full life cycle security management of asset data. Finally, according to the obtained data security management strategy, the asset data is scenario-based and component-driven to achieve comprehensive and reliable security management of data in various data scenarios, improve the efficiency and accuracy of data processing, and ensure the security and reliability of data throughout its life cycle.

[0068] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purpose and other advantages of the present invention can be achieved and obtained through the structures specifically pointed out in this application document.

[0069] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0070] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0071] Figure 1 This is a structural diagram of an AI-based full-lifecycle data security management platform in an embodiment of the present invention;

[0072] Figure 2 Schematic diagram of the full life cycle data security management process of an AI-based full life cycle data security management platform in an embodiment of the present invention;

[0073] Figure 3 This is a flowchart of an AI-based full-lifecycle data security management method in an embodiment of the present invention. DETAILED DESCRIPTION

[0074] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.

[0075] Example 1:

[0076] This embodiment provides an AI-based full-lifecycle data security management platform, such as Figure 1 Shown, including:

[0077] The asset data management module is used to read asset data and classify and grade asset data based on AI in the data lifecycle security process domain;

[0078] A policy generation module is used to generate data security management policies based on the classification and grading results;

[0079] The driver module is used to contextualize asset data and drive components according to data security policies, thereby ensuring the safe use of data throughout its life cycle.

[0080] In this embodiment, the whole life cycle data security management process diagram is as follows: Figure 2 shown.

[0081] In this embodiment, the data assets of the core business are first sorted out and the data assets are classified and graded; secondly, for data of different types and levels, unified security policy management, issuance and execution are carried out in different usage scenarios to ensure the security of data throughout its life cycle; finally, a comprehensive audit and analysis of data usage behavior is conducted, and risks such as data leakage are promptly alerted, responded to and handled to achieve closed-loop management of data security IPDR.

[0082] In this embodiment, data classification includes: discovering rules through the sensitive data scanning module of the data security supervision system, identifying the data type and location of sensitive data in accordance with relevant classification and grading management methods, and supporting the export of reports on sensitive data classification and grading results; data classification consists of user identity and authentication information, user data, and service content information. The data classification interface displays content consisting of user identity and authentication information, user data, and service content information. By using different sensitive data identification methods to identify different types of data, sensitive data can be classified and managed.

[0083] In this embodiment, data classification includes: discovering rules through the sensitive data scanning module of the data security supervision system, identifying the sensitivity level of sensitive data, sensitive data location, etc. in accordance with relevant data classification and grading management methods, and supporting the export of reports on sensitive data classification and grading results; the sensitive data classification strategy consists of extremely sensitive level, sensitive level, relatively sensitive level, and low sensitivity level; the sensitive data classification module displays content including level, location, control rules and other information; by adopting different sensitive data identification methods, different levels of data are identified, thereby performing hierarchical management of sensitive data.

[0084] In this embodiment, the data security management policy refers to a method or policy for performing security management on data of different types and levels.

[0085] In this embodiment, data scenario includes: data collection scenario, data transmission scenario, data storage scenario, data usage scenario, data sharing scenario and data destruction scenario.

[0086] In this embodiment, component driver refers to the components or programs used in the execution process of different data scenarios.

[0087] The working principle and beneficial effects of the above technical solution are: by reading asset data based on AI in the data lifecycle security process domain and classifying and grading the read asset data, the comprehensiveness and reliability of the read asset data are ensured, while the efficiency and accuracy of the grading and classification of asset data are ensured. Secondly, the corresponding data security management strategy is generated according to the classification and grading results, which provides a reliable basis and convenience for the full life cycle security management of asset data. Finally, according to the obtained data security management strategy, the asset data is scenario-based and component-driven, realizing comprehensive and reliable security management of data in various data scenarios, improving the processing efficiency and accuracy of data, and ensuring the security and reliability of data throughout its life cycle.

[0088] Example 2:

[0089] Based on Example 1, this embodiment provides an AI-based full-life cycle data security management platform. In the asset data management module, the data life cycle security process domain includes: data collection security, data transmission security, data storage security, data processing security, data exchange security, and data destruction security.

[0090] Example 3:

[0091] Based on Example 1, this example provides an AI-based full-lifecycle data security management platform, an asset data management module, including:

[0092] A data object determination unit, configured to obtain a data object corresponding to the asset data;

[0093] Recognition algorithm generation unit, used for:

[0094] Locating the target traditional algorithm in the preset traditional algorithm set and the target AI algorithm in the preset AI algorithm set according to the data object;

[0095] Generate a recognition algorithm based on the target traditional algorithm and the target AI algorithm;

[0096] A data identification unit is used to identify asset data according to an identification algorithm, retrieve a preset classification and grading knowledge base, and classify and grade the identification results according to the preset classification and grading knowledge base;

[0097] The virtual asset management unit is used to perform virtual asset management on asset data based on the classification and grading results.

[0098] In this embodiment, the data objects include: database field name, file name, field note, file type, field content, file content, table note, file subject, table name, file summary, database name, and image identification.

[0099] In this embodiment, the preset traditional algorithm set includes: regular expressions, keywords, data dictionaries, knowledge bases, verification classes, and data volumes.

[0100] In this embodiment, the preset AI algorithm set includes: Doc2Vec+center distance calculation, KS check+linear regression, TextRank, TessERACT, NER named entity, regular automatic generation, Transformer neural network, and similarity table detection.

[0101] In this embodiment, the preset classification and grading knowledge base includes: built-in classification and grading specifications for 24 industries such as operators, finance, securities, and government affairs; supports customized data classification and grading specifications, and can customize data classification, data classification and data types; different regulatory units may have deviations in classification and grading requirements, and the system supports scanning multiple sets of specifications at the same time without authorization restrictions.

[0102] The working principle and beneficial effects of the above technical solution are: by obtaining the data objects corresponding to the asset data, it is beneficial to locate the target traditional algorithm in the preset traditional algorithm set based on the data object and to locate the target AI algorithm in the preset AI algorithm set, which is beneficial to effectively realize the classification and grading of the recognition results based on the preset classification and grading knowledge base, thereby improving the accuracy of the classification and grading.

[0103] Example 4:

[0104] Based on Example 1, this embodiment provides an AI-based full-lifecycle data security management platform, a policy generation module, including:

[0105] A calling unit, used to call the data security management policy pool;

[0106] The data partitioning unit is used to read the classification and grading results of the asset data and divide the asset data according to the classification and grading results to obtain the sub-asset data set under each category and each level;

[0107] Security configuration unit, used to:

[0108] Obtain the data attribute characteristics of the sub-asset dataset and determine the security management requirements of the sub-asset dataset based on the data attribute characteristics;

[0109] Retrieve the target data security management policy corresponding to the sub-asset dataset from the data security management policy pool based on security management requirements;

[0110] Configure the target security management policy in the corresponding sub-asset data set.

[0111] In this embodiment, data security policies are centrally managed, uniformly issued, and executed to avoid data security silos. Data security policies include, but are not limited to, sensitive data discovery policies, data access control policies, data desensitization policies, data download control policies, and API monitoring policies.

[0112] In this embodiment, the data security management pool includes several data security management policies.

[0113] In this embodiment, the data attribute characteristics include the security level and data type of the sub-asset data.

[0114] In this embodiment, relevant data security monitoring and protection capabilities are integrated and added, and through a unified API interface, centralized management, unified scheduling, and visual management of data security capabilities and data security policies are achieved.

[0115] The working principle and beneficial effects of the above technical solution are: for different types and levels of data, appropriate data security policy management is adopted to achieve targeted security protection, avoid the abuse of data security resources, and improve overall protection efficiency.

[0116] Example 5:

[0117] Based on Example 3, this embodiment provides an AI-based full-lifecycle data security management platform, a data identification unit, including:

[0118] The automatic identification subunit is used to automatically identify asset data before reading it, specifically:

[0119] Build a data asset dictionary and draw a data asset map. At the same time, define sensitive data based on the data asset dictionary and data asset map;

[0120] Automatically scan sensitive data in asset data based on the defined results, and index and mark the data categories of the scanned sensitive data;

[0121] Automatically identify core data in asset data based on index tags.

[0122] The working principle of the above technical solution is as follows: automatic data discovery and identification is based on deep content recognition based on core technologies such as word segmentation, NER, and machine learning. It is mainly composed of different components such as the management center, hierarchical classification, and sensitive data engine. These modules work together to build a discovery and identification system for sensitive data and core important data. By establishing a data asset dictionary and drawing a data asset map to define sensitive data, it provides the ability to automatically scan and discover sensitive data across the entire network. At the same time, the scanned data types are indexed and marked to automatically identify core important data. Identification methods include system built-in recognition, regular expressions, keywords, key words, field names, field types, notes, and other identification methods.

[0123] The beneficial effects of the above technical solution are: effectively defining sensitive data based on the data asset dictionary and the data asset map, thereby effectively ensuring the identification of core data and improving the accuracy and effectiveness of core data identification.

[0124] Example 6:

[0125] Based on Example 1, this embodiment provides an AI-based full-lifecycle data security management platform, the driver module includes:

[0126] The scenario division unit is used to read the entire life cycle process of asset data, divide the asset data into scenarios according to the entire life cycle process of asset data, and obtain the operating characteristics of asset data in each scenario based on the division results;

[0127] A policy determination unit, configured to determine a corresponding target data security policy based on the operational characteristics of the asset data in each scenario;

[0128] A component determination unit, used to obtain the target component corresponding to each scene;

[0129] The component driving unit is used to drive components in corresponding scenarios according to the target data security policy and target components, and complete the safe use of data throughout its life cycle.

[0130] In this embodiment, data scenarios include: a) Data collection scenarios: strategies such as classification and grading, identity authentication, access control, and sensitive data identification. b) Data transmission scenarios: strategies such as transmission encryption, access control, and data leakage prevention. c) Data storage scenarios: strategies such as storage encryption, access control, backup and recovery, and data leakage prevention. d) Data processing scenarios: strategies such as data desensitization, data encryption, and data traceability. e) Data exchange scenarios: strategies such as data auditing, data traceability, data leakage prevention, and data exchange monitoring. f) Data destruction scenarios: strategies such as media management and media destruction.

[0131] Example 7:

[0132] Based on Example 1, this embodiment provides an AI-based full-lifecycle data security management platform, the driver module includes:

[0133] Model building preparation unit for:

[0134] Obtain full-process parameters for scenario-based asset data and component-driven operations, and determine the full lifecycle management nodes of asset data based on the full-process parameters;

[0135] Obtain anomaly monitoring dimensions for the full lifecycle management node based on the management terminal, where the anomaly monitoring dimensions include data anomaly dimensions and user access behavior anomaly dimensions;

[0136] Extract the data business attributes of each period management node in the full lifecycle management node, and determine the operation mode of the asset data under each period management node and the benchmark characteristics under the operation mode based on the data business attributes;

[0137] Determine the data anomaly focus points for each periodic management node based on the operating mode and benchmark characteristics, and build data anomaly monitoring rules and anomaly level classification rules for each periodic management node based on data business attributes and data anomaly focus points;

[0138] Based on the data anomaly monitoring rules and anomaly level classification rules, a data anomaly monitoring system for each period management node is obtained, and the data anomaly monitoring system is used as the first model element;

[0139] At the same time, the data sensitivity of each periodic management node is determined based on the data service attributes of each periodic management node, and the data access rights of each periodic management node are determined based on the data sensitivity;

[0140] Determine the data usage scenarios and scenario supervision indicators under each periodic management node based on data access rights, and obtain the user access behavior anomaly monitoring system for each periodic management node based on the data usage scenarios and scenario supervision indicators, and use the user access behavior anomaly monitoring system as the second model element;

[0141] Performing a first binding on the first model element and the second model element based on the period management node, and performing a second binding on the first binding result according to the execution order of the period management node;

[0142] Anomaly monitoring model building unit, used to:

[0143] The second binding result is integrated and trained in a preset model framework to obtain a target anomaly monitoring model, and the target anomaly monitoring model is interfaced with each period management node;

[0144] Based on the interface docking results, the entire life cycle management node is monitored for abnormalities.

[0145] In this embodiment, the full process parameters refer to the processing process data of the asset data in all steps or links involved in the management of the asset data.

[0146] In this embodiment, the full lifecycle management node refers to the specific links involved in the management of asset data.

[0147] In this embodiment, the anomaly monitoring dimension refers to the type of anomaly that needs to be monitored when monitoring each periodic management node, including the data anomaly dimension and the user access behavior anomaly dimension. Among them, the data anomaly dimension refers to the monitoring object being the data itself, and the user access behavior anomaly dimension refers to the monitoring object being the user access behavior.

[0148] In this embodiment, the data service attribute refers to the type of service executed by the management node in each period, that is, the specific service situation when processing the asset data.

[0149] In this embodiment, the operation mode refers to the specific data business corresponding to the asset data when it is active under each periodic management node, including the flow of data and the business objectives that can be achieved.

[0150] In this embodiment, the baseline characteristics refer to specific features exhibited by the asset data when operating in the operating mode.

[0151] In this embodiment, the data anomaly focus refers to the abnormal situations that may occur in the asset data under the operation mode, so that the asset data can be monitored in advance with emphasis on relevant angles.

[0152] In this embodiment, the data anomaly monitoring rule refers to a specific strategy or mechanism for performing anomaly monitoring on the data of each periodic management node, which is constructed based on data service attributes and data anomaly focus points.

[0153] In this embodiment, the abnormality level classification rule refers to a specific method for classifying abnormal conditions of data in each periodic management node.

[0154] In this embodiment, the data anomaly monitoring system refers to the final data anomaly monitoring system constructed according to the data anomaly monitoring rules and the anomaly level classification rules. The directly applicable result, namely the first model element, is a component of constructing the anomaly monitoring model.

[0155] In this embodiment, data sensitivity refers to the privacy level of data under each periodic management node, thereby determining the access rights to the data under each periodic management node.

[0156] In this embodiment, the data usage scenario refers to the application scenario of the data under each periodic management node.

[0157] In this embodiment, the scenario supervision indicator refers to the standard for monitoring the value and structure of asset data in different data usage scenarios.

[0158] In this embodiment, the second model element refers to the user access behavior anomaly monitoring system of each periodic management node, which is another component of the anomaly monitoring model.

[0159] In this embodiment, the first binding refers to associating the first model element and the second model element corresponding to each periodic management node.

[0160] In this embodiment, the second binding refers to associating the first binding results according to the execution order of each period management node.

[0161] In this embodiment, the preset model framework is set in advance.

[0162] In this embodiment, the target anomaly monitoring model refers to a monitoring model that can be directly applied and is ultimately obtained.

[0163] The working principle and beneficial effects of the above technical solution are as follows: by obtaining the full-process parameters for data scenarioization and component-driven asset data, and parsing the full-process parameters, the full life cycle management nodes and corresponding anomaly monitoring dimensions are effectively determined. At the same time, the data anomaly monitoring rules and anomaly level classification rules are locked according to the data business attributes and anomaly monitoring dimensions of each period management node. Secondly, the obtained data anomaly monitoring rules and anomaly level classification rules are used as the first model element. At the same time, the data sensitivity under each period management node is determined according to the data business attributes of each period management node, and the data access rights are locked according to the sensitivity. Then, the user access behavior anomaly monitoring system is determined according to the data access rights, so as to achieve reliable acquisition of the second model element. Finally, the obtained first model element and the second model element are associated and bound to achieve accurate and effective construction of the target anomaly monitoring model, and the obtained target anomaly monitoring model is interfaced with each period management node, ultimately achieving anomaly monitoring of the full life cycle management node, improving the reliability and accuracy of asset data anomaly monitoring, and greatly improving the full life cycle management effect of asset data.

[0164] Example 8:

[0165] Based on Example 7, this embodiment provides an AI-based full-lifecycle data security management platform, and an anomaly monitoring model construction unit, including:

[0166] Monitoring subunit, used to:

[0167] Based on the interface docking results, users' access data on asset data under different cycle management nodes is obtained in real time, and the access data is analyzed to determine the derivative data corresponding to the access data;

[0168] Determine the multi-dimensional working characteristics of the interface during the monitoring period based on the derived data, and construct an interface profile of the interface during the monitoring period based on the multi-dimensional working characteristics;

[0169] User portrait construction sub-unit is used to:

[0170] Determine the user's access behavior set for asset data under different period management nodes based on the derived data, and quantify each access behavior in the access behavior set to obtain the corresponding quantitative index value;

[0171] Determine a visualization chart for the quantitative indicator value based on the preset visualization requirements, and display the corresponding values of the quantitative indicator based on the visualization chart to obtain the corresponding user behavior portrait;

[0172] The recording subunit is used to record and store the obtained interface portrait and user behavior portrait.

[0173] In this embodiment, the interface profile includes: average daily number of visits, compliant access time, average daily access data volume, average daily sensitive data volume, average daily number of sensitive data types, and average daily number of access source IPs.

[0174] In this embodiment, the user behavior profile includes: average daily data outbound transmission times, compliant working hours, compliant login times, average daily login times, average daily volume of sensitive data, average daily number of sensitive data operations, average daily number of downloads, average daily number of operations, and average daily number of peripheral device accesses.

[0175] In this embodiment, access data refers to specific access behavior data when a user accesses asset data under different period management nodes, including the data object accessed, the frequency of access, and the specific time point of access.

[0176] In this embodiment, the derived data refers to data on data access characteristics obtained after parsing the access data, including data such as specific access volume.

[0177] In this embodiment, the multi-dimensional working characteristics refer to the specific working conditions of the interface during the monitoring period, including the data flow volume and user access volume per unit time.

[0178] In this embodiment, the interface portrait refers to a report or visual display diagram that can characterize the specific working conditions of the interface during the monitoring period.

[0179] In this embodiment, the quantitative index value refers to the result obtained by quantifying each access behavior in the user access behavior set, for example, it may be the number of visits per unit time obtained by quantifying the user's access frequency.

[0180] In this embodiment, the preset visualization requirements are set in advance, including the type of visualization and the format of visualization.

[0181] The working principle and beneficial effects of the above technical solution are: by analyzing the user's access data to asset data under different cycle management nodes, the multi-dimensional working characteristics of the interface during the monitoring period can be determined, and then the interface portrait of the interface during the monitoring period can be effectively constructed, which helps to fully understand the multi-dimensional working characteristics of the interface in different monitoring periods. By constructing user behavior portraits, the user's access behavior characteristics to asset data can be effectively and clearly displayed, and data management can be traced and audited based on the interface portrait and user behavior portrait.

[0182] Example 9:

[0183] Based on Example 8, this embodiment provides an AI-based full-lifecycle data security management platform, and an anomaly monitoring model construction unit, including:

[0184] The result acquisition subunit is used to:

[0185] Obtain abnormal monitoring results for the entire lifecycle management node and lock the abnormal source when an abnormality occurs;

[0186] Analyze the locked exception source, determine the exception type and exception representation, and match the response strategy from the preset response strategy library based on the exception type and exception representation;

[0187] The exception response subunit is used to:

[0188] Provide early warning responses to abnormal types and abnormal characteristics based on response strategies.

[0189] In this embodiment, when the abnormality type is data abnormality, an early warning response is issued to the abnormal situation, and when the abnormality type is abnormal user access behavior, unauthorized personnel are prevented from illegally accessing data.

[0190] The beneficial effects of the above technical solution are: by timely determining the type of anomaly and the abnormal representation and then realizing early warning response, it effectively ensures the monitoring of user access behavior, and when an anomaly occurs, it effectively ensures the security of data by preventing unauthorized personnel from illegally accessing data.

[0191] Example 10:

[0192] This embodiment provides an AI-based full life cycle data security management method, such as Figure 3 Shown, including:

[0193] Step 1: Read asset data based on AI and classify and grade the asset data in the data lifecycle security process area;

[0194] Step 2: Generate a data security management strategy based on the classification and grading results;

[0195] Step 3: Based on the data security policy, the asset data is contextualized and component-driven to ensure the safe use of data throughout its life cycle.

[0196] The working principle and beneficial effects of the above technical solution are: by reading asset data based on AI in the data lifecycle security process domain and classifying and grading the read asset data, the comprehensiveness and reliability of the read asset data are ensured, while the efficiency and accuracy of the grading and classification of asset data are ensured. Secondly, the corresponding data security management strategy is generated according to the classification and grading results, which provides a reliable basis and convenience for the full life cycle security management of asset data. Finally, according to the obtained data security management strategy, the asset data is scenario-based and component-driven, realizing comprehensive and reliable security management of data in various data scenarios, improving the processing efficiency and accuracy of data, and ensuring the security and reliability of data throughout its life cycle.

[0197] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. An AI-based full-lifecycle data security management platform, characterized by: include: The asset data management module is used to read asset data and classify and grade asset data based on AI in the data lifecycle security process domain; A policy generation module is used to generate data security management policies based on the classification and grading results; The driver module is used to contextualize asset data and drive components according to data security policies, thereby ensuring the safe use of data throughout its life cycle.

2. The AI-based full lifecycle data security management platform according to claim 1 is characterized in that: In the asset data management module, the data lifecycle security process domain includes: data collection security, data transmission security, data storage security, data processing security, data exchange security, and data destruction security.

3. The AI-based full lifecycle data security management platform according to claim 1 is characterized in that: Asset data management module, including: A data object determination unit, configured to obtain a data object corresponding to the asset data; Recognition algorithm generation unit, used for: Locating the target traditional algorithm in the preset traditional algorithm set and the target AI algorithm in the preset AI algorithm set according to the data object; Generate a recognition algorithm based on the target traditional algorithm and the target AI algorithm; A data identification unit is used to identify asset data according to an identification algorithm, retrieve a preset classification and grading knowledge base, and classify and grade the identification results according to the preset classification and grading knowledge base; The virtual asset management unit is used to perform virtual asset management on asset data based on the classification and grading results.

4. The AI-based full lifecycle data security management platform according to claim 1 is characterized in that: Strategy generation module, including: A calling unit, used to call the data security management policy pool; The data partitioning unit is used to read the classification and grading results of the asset data and divide the asset data according to the classification and grading results to obtain the sub-asset data set under each category and each level; Security configuration unit, used to: Obtain the data attribute characteristics of the sub-asset dataset and determine the security management requirements of the sub-asset dataset based on the data attribute characteristics; Retrieve the target data security management policy corresponding to the sub-asset dataset from the data security management policy pool based on security management requirements; Configure the target security management policy in the corresponding sub-asset data set.

5. The AI-based full lifecycle data security management platform according to claim 3 is characterized in that: Data identification unit, including: The automatic identification subunit is used to automatically identify asset data before reading it, specifically: Build a data asset dictionary and draw a data asset map. At the same time, define sensitive data based on the data asset dictionary and data asset map; Automatically scan sensitive data in asset data based on the defined results, and index and mark the data categories of the scanned sensitive data; Automatically identify core data in asset data based on index tags.

6. The AI-based full lifecycle data security management platform according to claim 1 is characterized in that: Driver module, including: The scenario division unit is used to read the entire life cycle process of asset data, divide the asset data into scenarios according to the entire life cycle process of asset data, and obtain the operating characteristics of asset data in each scenario based on the division results; A policy determination unit, configured to determine a corresponding target data security policy based on the operational characteristics of the asset data in each scenario; A component determination unit, used to obtain the target component corresponding to each scene; The component driving unit is used to drive components in corresponding scenarios according to the target data security policy and target components, and complete the safe use of data throughout its life cycle.

7. The AI-based full lifecycle data security management platform according to claim 1, characterized in that: Driver module, including: Model building preparation unit for: Obtain full-process parameters for scenario-based asset data and component-driven operations, and determine the full lifecycle management nodes of asset data based on the full-process parameters; Obtain anomaly monitoring dimensions for the full lifecycle management node based on the management terminal, where the anomaly monitoring dimensions include data anomaly dimensions and user access behavior anomaly dimensions; Extract the data business attributes of each period management node in the full lifecycle management node, and determine the operation mode of the asset data under each period management node and the benchmark characteristics under the operation mode based on the data business attributes; Determine the data anomaly focus points for each periodic management node based on the operating mode and benchmark characteristics, and build data anomaly monitoring rules and anomaly level classification rules for each periodic management node based on data business attributes and data anomaly focus points; Based on the data anomaly monitoring rules and anomaly level classification rules, a data anomaly monitoring system for each period management node is obtained, and the data anomaly monitoring system is used as the first model element; At the same time, the data sensitivity of each periodic management node is determined based on the data service attributes of each periodic management node, and the data access rights of each periodic management node are determined based on the data sensitivity; Determine the data usage scenarios and scenario supervision indicators under each periodic management node based on data access rights, and obtain the user access behavior anomaly monitoring system for each periodic management node based on the data usage scenarios and scenario supervision indicators, and use the user access behavior anomaly monitoring system as the second model element; Performing a first binding on the first model element and the second model element based on the period management node, and performing a second binding on the first binding result according to the execution order of the period management node; Anomaly monitoring model building unit, used to: The second binding result is integrated and trained in a preset model framework to obtain a target anomaly monitoring model, and the target anomaly monitoring model is interfaced with each period management node; Based on the interface docking results, the entire life cycle management node is monitored for abnormalities.

8. The AI-based full lifecycle data security management platform according to claim 7, characterized in that: The abnormal monitoring model building unit includes: Monitoring subunit, used to: Based on the interface docking results, users' access data on asset data under different cycle management nodes is obtained in real time, and the access data is analyzed to determine the derivative data corresponding to the access data; Determine the multi-dimensional working characteristics of the interface during the monitoring period based on the derived data, and construct an interface profile of the interface during the monitoring period based on the multi-dimensional working characteristics; User portrait construction sub-unit is used to: Determine the user's access behavior set for asset data under different period management nodes based on the derived data, and quantify each access behavior in the access behavior set to obtain the corresponding quantitative index value; Determine a visualization chart for the quantitative indicator value based on the preset visualization requirements, and display the corresponding values of the quantitative indicator based on the visualization chart to obtain the corresponding user behavior portrait; The recording subunit is used to record and store the obtained interface portrait and user behavior portrait.

9. The AI-based full lifecycle data security management platform according to claim 8, characterized in that: The abnormal monitoring model building unit includes: The result acquisition subunit is used to: Obtain abnormal monitoring results for the entire lifecycle management node and lock the abnormal source when an abnormality occurs; Analyze the locked exception source, determine the exception type and exception representation, and match the response strategy from the preset response strategy library based on the exception type and exception representation; The exception response subunit is used to: Provide early warning responses to abnormal types and abnormal characteristics based on response strategies.

10. An AI-based full-lifecycle data security management method, characterized in that: include: Step 1: Read asset data based on AI and classify and grade the asset data in the data lifecycle security process area; Step 2: Generate a data security management strategy based on the classification and grading results; Step 3: Based on the data security policy, the asset data is contextualized and component-driven to ensure the safe use of data throughout its life cycle.

Citation Information

Patent Citations

  • Data security control method and data security control platform

    CN104796290A

  • Data asset classification modeling and grading protection method based on artificial intelligence technology

    CN113590698A

  • System and Methods for Optimizing Human Factors and Usability Engineering in Life Sciences Using Artificial Intelligence

    US20240346524A1

  • System and method for continuous and automated cybersecurity monitoring & assessment using natural language processing tools

    US20240396946A1