An ai-based full-lifecycle data security management platform and method

By using an AI-based full lifecycle data security management platform, the problem of low efficiency in traditional data security management has been solved, enabling secure and reliable management of data throughout its entire lifecycle and improving processing efficiency and accuracy.

CN120493271BActive Publication Date: 2026-03-31盐城市大数据集团有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Traditional data security management lacks overall control over the entire data lifecycle, is inefficient and prone to errors, and struggles to cope with complex security threats.

Method used

An AI-based full lifecycle data security management platform is adopted. The asset data management module classifies and grades the data, generates data security management strategies, and drives data scenario-based components to achieve full lifecycle security management.

Benefits of technology

It improves the efficiency and accuracy of data processing, ensures the security and reliability of data throughout its entire lifecycle, provides reliable evidence and convenience, and achieves comprehensive, reliable and secure data management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120493271B_ABST
    Figure CN120493271B_ABST
Patent Text Reader

Abstract

The application provides an AI-based whole life cycle data security management platform and method, which comprises: an asset data management module for reading asset data and classifying and grading the asset data based on AI in the data life cycle security process domain; a strategy generation module for generating a data security management strategy according to the classification and grading results; and a driving module for performing data sceneization on the asset data and component driving according to the data security strategy, thereby completing the safe use of whole life cycle data. Comprehensive and reliable security management of data in various data scenes is achieved, the processing efficiency and accuracy of data are improved, and the safety and reliability of the whole life cycle of data are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, in particular to an AI-based full life cycle data security management platform and method. BACKGROUND

[0002] With the rapid development of information technology, data is increasingly generated, stored, transmitted and used in various fields, at the same time, data faces many security threats such as data leakage, data tampering, unauthorized access, etc. while bringing great value and opportunities;

[0003] Traditional data security management often focuses on a certain specific stage or a specific type of security threat, lacks overall control of the data full life cycle, and at the same time, in the face of massive data and complex security threat scenarios, manual management is inefficient and prone to errors, greatly reducing the management effect of data;

[0004] Therefore, in order to overcome the above defects, the present application provides an AI-based full life cycle data security management platform and method. SUMMARY

[0005] The present application provides an AI-based full life cycle data security management platform and method, which reads asset data based on AI in the data life cycle security process domain, and classifies the read asset data, ensuring the comprehensiveness and reliability of the read asset data, and ensuring the efficiency and accuracy of the classification of asset data, secondly, according to the classification result, the corresponding data security management strategy is generated, which provides a reliable basis and convenience for the full life cycle security management of asset data, finally, according to the obtained data security management strategy, the asset data is data-scene and component-driven, realizing the comprehensive and reliable security management of data in each data scene, improving the processing efficiency and accuracy of data, and ensuring the safety and reliability of the full life cycle of data.

[0006] The present application provides an AI-based full life cycle data security management platform, comprising:

[0007] An asset data management module for reading asset data based on AI in the data life cycle security process domain and classifying the asset data;

[0008] A strategy generation module for generating a data security management strategy according to the classification result;

[0009] A driving module for data-scene and component-driven asset data according to the data security strategy, completing the safe use of full life cycle data.

[0010] Preferably, an AI-based full life cycle data security management platform, in the asset data management module, the data life cycle security process domain includes: data collection security, data transmission security, data storage security, data processing security, data exchange security and data destruction security.

[0011] Preferably, an AI-based full life cycle data security management platform, the asset data management module includes:

[0012] The data object determination unit is configured to obtain a data object corresponding to the asset data.

[0013] The recognition algorithm generation unit is configured to:

[0014] Locate a target traditional algorithm in a preset traditional algorithm set and a target AI algorithm in a preset AI algorithm set according to the data object.

[0015] Generate a recognition algorithm according to the target traditional algorithm and the target AI algorithm.

[0016] The data recognition unit is configured to recognize the asset data according to the recognition algorithm, call a preset classification and grading knowledge base, and classify and grade the recognition result according to the preset classification and grading knowledge base.

[0017] The virtual asset management unit is configured to manage the asset data according to the classification and grading result.

[0018] Preferably, an AI-based full life cycle data security management platform, the strategy generation module includes:

[0019] The calling unit is configured to call a data security management strategy pool.

[0020] The data division unit is configured to read the classification and grading result of the asset data, and divide the asset data according to the classification and grading result to obtain a sub-asset data set under each category and each level.

[0021] The security configuration unit is configured to:

[0022] Obtain data attribute features of the sub-asset data set, and determine a security management requirement of the sub-asset data set according to the data attribute features.

[0023] Call a target data security management strategy corresponding to the sub-asset data set in the data security management strategy pool according to the security management requirement.

[0024] Perform security configuration on the target security management strategy in the corresponding sub-asset data set.

[0025] Preferably, an AI-based full life cycle data security management platform, the data recognition unit includes:

[0026] The automatic identification sub-unit is used to automatically identify asset data before reading it, specifically as follows:

[0027] Construct a data asset dictionary and draw a data asset map. At the same time, define sensitive data based on the data asset dictionary and the data asset map.

[0028] Based on the defined results, the system automatically scans for sensitive data in the asset data and indexes and marks the data categories of the scanned sensitive data.

[0029] The core data in the asset data is automatically identified based on index tags.

[0030] Preferably, an AI-based full lifecycle data security management platform includes a driver module comprising:

[0031] The scenario segmentation unit is used to read the entire lifecycle of asset data, segment the asset data into scenarios based on the entire lifecycle of asset data, and obtain the operational characteristics of asset data in each scenario based on the segmentation results.

[0032] The strategy determination unit is used to determine the corresponding target data security strategy based on the operational characteristics of asset data in each scenario.

[0033] The component determination unit is used to obtain the target component corresponding to each scene;

[0034] The component-driven unit is used to drive the component according to the target data security policy and the target component in the corresponding scenario, so as to complete the secure use of data throughout the entire life cycle.

[0035] Preferably, an AI-based full lifecycle data security management platform includes a driver module comprising:

[0036] Model building preparation unit, used for:

[0037] Acquire full-process parameters for contextualizing asset data and driving component processing, and determine the full lifecycle management nodes of asset data based on these full-process parameters;

[0038] Based on the management terminal, the anomaly monitoring dimensions of the entire lifecycle management nodes are obtained. Among them, the anomaly monitoring dimensions include data anomaly dimensions and user access behavior anomaly dimensions.

[0039] Extract the data business attributes of each cycle management node in the full life cycle management node, and determine the operation mode of asset data under each cycle management node and the benchmark characteristics under the operation mode based on the data business attributes;

[0040] Based on the operating mode and baseline characteristics, the data anomaly concerns of each cycle management node are determined, and data anomaly monitoring rules and anomaly level classification rules are constructed for each cycle management node based on data business attributes and data anomaly concerns.

[0041] Based on the data anomaly monitoring rules and anomaly level classification rules, a data anomaly monitoring system for each period management node is obtained, and the data anomaly monitoring system is used as the first model element.

[0042] At the same time, the data sensitivity of each management node is determined based on the data service attributes of each management node in each cycle, and the data access permissions of each management node in each cycle are determined based on the data sensitivity.

[0043] Based on data access permissions, determine the data usage scenarios and scenario supervision indicators under each period management node, and obtain the user access behavior anomaly monitoring system for each period management node based on the data usage scenarios and scenario supervision indicators, and use the user access behavior anomaly monitoring system as the second model element.

[0044] Based on the cycle management node, the first model element and the second model element are bound together in the first binding, and the first binding result is bound together in the second binding according to the execution order of the cycle management node;

[0045] Anomaly monitoring model building unit, used for:

[0046] The second binding result is integrated and trained in the preset model framework to obtain the target anomaly monitoring model, and the target anomaly monitoring model is interfaced with the management nodes of each cycle.

[0047] Based on the interface connection results, perform anomaly monitoring on the full lifecycle management nodes.

[0048] Preferably, an AI-based full lifecycle data security management platform includes an anomaly monitoring model construction unit, comprising:

[0049] The monitoring subunit is used for:

[0050] Based on the interface connection results, the system obtains user access data for asset data under different period management nodes in real time, parses the access data, and determines the corresponding derived data.

[0051] Based on the derived data, determine the multi-dimensional working characteristics of the interface during the monitoring period, and construct an interface profile of the interface during the monitoring period based on the multi-dimensional working characteristics.

[0052] The user profile building subunit is used for:

[0053] Based on derived data, determine the set of user access behaviors for asset data under different period management nodes, and quantify each access behavior in the set of access behaviors to obtain the corresponding quantitative indicator value.

[0054] Based on the preset visualization requirements, determine the visualization charts for the quantitative indicator values, and display the corresponding values ​​of the quantitative indicator values ​​based on the visualization charts to obtain the corresponding user behavior profiles.

[0055] The recording subunit is used to record and store the obtained interface profiles and user behavior profiles.

[0056] Preferably, an AI-based full lifecycle data security management platform includes an anomaly monitoring model construction unit, comprising:

[0057] The result acquisition subunit is used for:

[0058] Obtain anomaly monitoring results for all lifecycle management nodes, and pinpoint the source of the anomaly when one is detected.

[0059] The locked anomaly source is analyzed to determine the anomaly type and anomaly characteristics, and a response strategy is matched from the preset response strategy library based on the anomaly type and anomaly characteristics.

[0060] Anomaly response subunit, used for:

[0061] Early warning responses are generated based on the anomaly type and anomaly characteristics according to the response strategy.

[0062] This invention provides an AI-based full lifecycle data security management method, including:

[0063] Step 1: In the data lifecycle security process domain, use AI to read asset data and classify and grade the asset data;

[0064] Step 2: Generate a data security management strategy based on the classification and grading results;

[0065] Step 3: Based on the data security policy, contextualize the asset data and implement component-driven processing to achieve secure use of data throughout its entire lifecycle.

[0066] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0067] By using AI to read asset data within the data lifecycle security process domain and classifying and grading the read asset data, the comprehensiveness and reliability of the read asset data are ensured, as well as the efficiency and accuracy of the classification and grading of asset data. Secondly, corresponding data security management strategies are generated based on the classification and grading results, providing a reliable basis and convenience for the full lifecycle security management of asset data. Finally, based on the obtained data security management strategies, asset data is scenario-based and component-driven, realizing comprehensive and reliable security management of data in various data scenarios, improving the efficiency and accuracy of data processing, and ensuring the security and reliability of data throughout its entire lifecycle.

[0068] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in this application.

[0069] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0070] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:

[0071] Figure 1 This is a structural diagram of an AI-based full lifecycle data security management platform according to an embodiment of the present invention;

[0072] Figure 2 This is a schematic diagram of the full lifecycle data security management process of an AI-based full lifecycle data security management platform according to an embodiment of the present invention;

[0073] Figure 3 This is a flowchart of an AI-based full lifecycle data security management method according to an embodiment of the present invention. Detailed Implementation

[0074] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0075] Example 1:

[0076] This embodiment provides an AI-based full lifecycle data security management platform, such as... Figure 1 As shown, it includes:

[0077] The asset data management module is used to read asset data based on AI and classify and grade the asset data in the data lifecycle security process domain;

[0078] The strategy generation module is used to generate data security management strategies based on the classification and grading results;

[0079] The driver module is used to contextualize asset data according to data security policies and drive components to enable secure use of data throughout its entire lifecycle.

[0080] In this embodiment, a schematic diagram of the full lifecycle data security management process is shown below. Figure 2 As shown.

[0081] In this embodiment, the core business data assets are first sorted out and classified and graded. Secondly, for different types and levels of data, unified security policies are managed, distributed and executed in different usage scenarios to ensure data security throughout its entire lifecycle. Finally, a comprehensive audit and analysis of data usage behavior is conducted, and risks such as data leakage are promptly alerted, responded to and dealt with to achieve closed-loop management of data security IPDR.

[0082] In this embodiment, data classification includes: identifying sensitive data types and locations through the sensitive data scanning module of the data security supervision system, in accordance with relevant hierarchical classification management methods, and supporting the export of reports showing the results of sensitive data classification and grading; data classification consists of user identity and authentication information, user data, and service content information. The data classification interface displays content including user identity and authentication information, user data, and service content information. By employing different sensitive data identification methods, different types of data are identified, thereby enabling the classification and management of sensitive data.

[0083] In this embodiment, data classification includes: discovering rules through the sensitive data scanning module of the data security supervision system, identifying the sensitivity level and location of sensitive data according to relevant data classification and management methods, and supporting the export of reports of sensitive data classification and grading results; the sensitive data grading strategy consists of extremely sensitive, sensitive, moderately sensitive, and low sensitive levels; the sensitive data grading module displays information including level, location, and control rules; and different levels of data are identified by using different sensitive data identification methods, thereby enabling the graded management of sensitive data.

[0084] In this embodiment, the data security management strategy refers to the methods or strategies for security management of different types and levels of data.

[0085] In this embodiment, data contextualization includes: data acquisition scenario, data transmission scenario, data storage scenario, data usage scenario, data sharing scenario, and data destruction scenario.

[0086] In this embodiment, component-driven refers to the components or programs used in the execution process of different data scenarios.

[0087] The working principle and beneficial effects of the above technical solution are as follows: By reading asset data based on AI in the data lifecycle security process domain and classifying and grading the read asset data, the comprehensiveness and reliability of the read asset data are ensured, while the efficiency and accuracy of the classification and grading of asset data are also ensured. Secondly, corresponding data security management strategies are generated based on the classification and grading results, providing a reliable basis and convenience for the full lifecycle security management of asset data. Finally, based on the obtained data security management strategies, asset data is scenario-based and component-driven, realizing comprehensive and reliable security management of data in various data scenarios, improving the efficiency and accuracy of data processing, and ensuring the security and reliability of data throughout its entire lifecycle.

[0088] Example 2:

[0089] Based on Example 1, this example provides an AI-based full lifecycle data security management platform. In the asset data management module, the data lifecycle security process domain includes: data acquisition security, data transmission security, data storage security, data processing security, data exchange security, and data destruction security.

[0090] Example 3:

[0091] Based on Example 1, this example provides an AI-based full lifecycle data security management platform, including an asset data management module, comprising:

[0092] The data object determination unit is used to obtain the data object corresponding to the asset data;

[0093] The recognition algorithm generation unit is used for:

[0094] Based on the data object, the target traditional algorithm is located in the preset traditional algorithm set, and the target AI algorithm is located in the preset AI algorithm set;

[0095] A recognition algorithm is generated based on the target's traditional algorithm and target AI algorithm;

[0096] The data recognition unit is used to identify asset data according to the recognition algorithm, retrieve a preset classification and grading knowledge base, and classify and grade the recognition results according to the preset classification and grading knowledge base;

[0097] The virtual asset management unit is used to manage virtual assets based on the classification and grading results.

[0098] In this embodiment, the data objects include: database field name, file name, field remarks, file type, field content, file content, table remarks, file topic, table name, file summary, database name, and image recognition.

[0099] In this embodiment, the preset set of traditional algorithms includes: regular expressions, keywords, data dictionaries, knowledge bases, validation classes, and data volume.

[0100] In this embodiment, the preset AI algorithm set includes: Doc2Vec + center distance calculation, KS verification + linear regression, TextRank, TessERACT, NER named entity, automatic regular expression generation, Transformer neural network, and similarity table detection.

[0101] In this embodiment, the preset classification and grading knowledge base includes: built-in classification and grading standards for 24 industries such as operators, finance, securities, and government affairs; it supports custom data classification and grading standards, allowing customization of data classification, data grading, and data types; different regulatory units may have different requirements for classification and grading, and the system supports scanning multiple sets of standards simultaneously without authorization restrictions.

[0102] The working principle and beneficial effects of the above technical solution are as follows: by acquiring the data objects corresponding to the asset data, it is easier to locate the target traditional algorithm in the preset traditional algorithm set and the target AI algorithm in the preset AI algorithm set based on the data objects. In turn, it is easier to effectively classify and grade the recognition results based on the preset classification and grading knowledge base, thereby improving the accuracy of classification and grading.

[0103] Example 4:

[0104] Based on Example 1, this example provides an AI-based full lifecycle data security management platform, including a policy generation module:

[0105] The retrieval unit is used to retrieve the data security management policy pool.

[0106] The data partitioning unit is used to read the classification and grading results of asset data and divide the asset data according to the classification and grading results to obtain the sub-asset datasets under each category and level.

[0107] The security configuration unit is used for:

[0108] Obtain the data attribute characteristics of the sub-asset dataset, and determine the security management requirements of the sub-asset dataset based on the data attribute characteristics;

[0109] Based on security management requirements, retrieve the target data security management policy corresponding to the sub-asset dataset from the data security management policy pool;

[0110] Configure the target security management policy in the corresponding sub-asset dataset.

[0111] In this embodiment, data security policies are centrally managed, uniformly distributed, and executed to avoid creating data security silos. Data security policies include, but are not limited to: sensitive data discovery policies, data access control policies, data anonymization policies, data download control policies, API monitoring policies, etc.

[0112] In this embodiment, the data security management pool includes several data security management strategies.

[0113] In this embodiment, the data attribute characteristics include the security level and data type of the sub-asset data.

[0114] In this embodiment, relevant data security monitoring and protection capabilities are integrated and added. Through a unified API interface, centralized management and unified scheduling of data security capabilities, as well as visualized management of data security policies, are achieved.

[0115] The working principle and beneficial effects of the above technical solution are as follows: appropriate data security strategies are adopted to manage different types and levels of data, thereby achieving targeted security protection, avoiding the abuse of data security resources, and improving overall protection efficiency.

[0116] Example 5:

[0117] Based on Example 3, this example provides an AI-based full lifecycle data security management platform, including a data identification unit:

[0118] The automatic identification sub-unit is used to automatically identify asset data before reading it, specifically as follows:

[0119] Construct a data asset dictionary and draw a data asset map. At the same time, define sensitive data based on the data asset dictionary and the data asset map.

[0120] Based on the defined results, the system automatically scans for sensitive data in the asset data and indexes and marks the data categories of the scanned sensitive data.

[0121] The core data in the asset data is automatically identified based on index tags.

[0122] The working principle of the above technical solution is as follows: Automatic data discovery and identification utilizes deep content recognition technologies such as word segmentation, NER (Network Errata), and machine learning. It mainly consists of different components including a management center, hierarchical classification, and a sensitive data engine. These modules work together to build a system for discovering and identifying sensitive and core important data. By establishing a data asset dictionary and drawing a data asset map, sensitive data is defined, providing the ability to automatically scan and discover sensitive data across the entire network. Simultaneously, the scanned data types are indexed and marked, automatically identifying core important data, including recognition methods such as built-in system identifiers, regular expressions, keywords, field names, field types, and comments.

[0123] The beneficial effects of the above technical solution are: it effectively defines sensitive data based on the data asset dictionary and data asset graph, thereby effectively ensuring the identification of core data and improving the accuracy and effectiveness of core data identification.

[0124] Example 6:

[0125] Based on Example 1, this example provides an AI-based full lifecycle data security management platform, including a driver module comprising:

[0126] The scenario segmentation unit is used to read the entire lifecycle of asset data, segment the asset data into scenarios based on the entire lifecycle of asset data, and obtain the operational characteristics of asset data in each scenario based on the segmentation results.

[0127] The strategy determination unit is used to determine the corresponding target data security strategy based on the operational characteristics of asset data in each scenario.

[0128] The component determination unit is used to obtain the target component corresponding to each scene;

[0129] The component-driven unit is used to drive the component according to the target data security policy and the target component in the corresponding scenario, so as to complete the secure use of data throughout the entire life cycle.

[0130] In this embodiment, the data scenarios include: a) Data acquisition scenarios: strategies such as classification and grading, identity authentication, access control, and sensitive data identification. b) Data transmission scenarios: strategies such as transmission encryption, access control, and data leakage prevention. c) Data storage scenarios: strategies such as storage encryption, access control, backup and recovery, and data leakage prevention. d) Data processing scenarios: strategies such as data anonymization, data encryption, and data traceability. e) Data exchange scenarios: strategies such as data auditing, data traceability, data leakage prevention, and data exchange monitoring. f) Data destruction scenarios: strategies such as media management and media destruction.

[0131] Example 7:

[0132] Based on Example 1, this example provides an AI-based full lifecycle data security management platform, including a driver module comprising:

[0133] Model building preparation unit, used for:

[0134] Acquire full-process parameters for contextualizing asset data and driving component processing, and determine the full lifecycle management nodes of asset data based on these full-process parameters;

[0135] Based on the management terminal, the anomaly monitoring dimensions of the entire lifecycle management nodes are obtained. Among them, the anomaly monitoring dimensions include data anomaly dimensions and user access behavior anomaly dimensions.

[0136] Extract the data business attributes of each cycle management node in the full life cycle management node, and determine the operation mode of asset data under each cycle management node and the benchmark characteristics under the operation mode based on the data business attributes;

[0137] Based on the operating mode and baseline characteristics, the data anomaly concerns of each cycle management node are determined, and data anomaly monitoring rules and anomaly level classification rules are constructed for each cycle management node based on data business attributes and data anomaly concerns.

[0138] Based on the data anomaly monitoring rules and anomaly level classification rules, a data anomaly monitoring system for each period management node is obtained, and the data anomaly monitoring system is used as the first model element.

[0139] At the same time, the data sensitivity of each management node is determined based on the data service attributes of each management node in each cycle, and the data access permissions of each management node in each cycle are determined based on the data sensitivity.

[0140] Based on data access permissions, determine the data usage scenarios and scenario supervision indicators under each period management node, and obtain the user access behavior anomaly monitoring system for each period management node based on the data usage scenarios and scenario supervision indicators, and use the user access behavior anomaly monitoring system as the second model element.

[0141] Based on the cycle management node, the first model element and the second model element are bound together in the first binding, and the first binding result is bound together in the second binding according to the execution order of the cycle management node;

[0142] Anomaly monitoring model building unit, used for:

[0143] The second binding result is integrated and trained in the preset model framework to obtain the target anomaly monitoring model, and the target anomaly monitoring model is interfaced with the management nodes of each cycle.

[0144] Based on the interface connection results, perform anomaly monitoring on the full lifecycle management nodes.

[0145] In this embodiment, the full-process parameters refer to the processing flow data of all steps or stages involved in the management of asset data.

[0146] In this embodiment, the full lifecycle management node refers to the specific steps involved in managing asset data.

[0147] In this embodiment, the anomaly monitoring dimension refers to the type of anomalies that need to be monitored when monitoring each periodic management node, including data anomaly dimension and user access behavior anomaly dimension. The data anomaly dimension refers to monitoring data itself, while the user access behavior anomaly dimension refers to monitoring user access behavior.

[0148] In this embodiment, the data service attribute refers to the type of service executed by the management node in each cycle, that is, the specific business situation when processing asset data.

[0149] In this embodiment, the operating mode refers to the specific data business corresponding to the activity of asset data under each periodic management node, including the flow of data and the business objectives that can be achieved.

[0150] In this embodiment, the baseline feature refers to the specific characteristics that asset data exhibits when operating in the operating mode.

[0151] In this embodiment, data anomaly concerns refer to abnormal situations that may occur in asset data during operation, thereby enabling early monitoring of asset data from relevant perspectives.

[0152] In this embodiment, the data anomaly monitoring rule refers to a specific strategy or mechanism for monitoring the data of each management node in each cycle, based on the data business attributes and data anomaly concerns.

[0153] In this embodiment, the anomaly level classification rule refers to the specific method for classifying the anomalies in the data of each periodic management node.

[0154] In this embodiment, the data anomaly monitoring system refers to the final data anomaly monitoring system constructed based on data anomaly monitoring rules and anomaly level classification rules. The directly applicable result, namely the first model element, is a component of the anomaly monitoring model.

[0155] In this embodiment, data sensitivity refers to the degree of privacy of the data under each period management node, thereby enabling the determination of data access permissions under each period management node.

[0156] In this embodiment, the data usage scenario refers to the application scenario of the data under each periodic management node.

[0157] In this embodiment, scenario monitoring indicators refer to the standards for monitoring the value and structure of asset data under different data usage scenarios.

[0158] In this embodiment, the second model element refers to the user access behavior anomaly monitoring system of each period management node, which is another component of the anomaly monitoring model.

[0159] In this embodiment, the first binding refers to associating the first model element and the second model element corresponding to each periodic management node.

[0160] In this embodiment, the second binding refers to associating the first binding result according to the execution order of each periodic management node.

[0161] In this embodiment, the preset model framework is pre-defined.

[0162] In this embodiment, the target anomaly monitoring model refers to the monitoring model that can be directly applied and is ultimately obtained.

[0163] The working principle and beneficial effects of the above technical solution are as follows: By acquiring and contextualizing asset data and implementing component-driven full-process parameters, and parsing these parameters, the full lifecycle management nodes and corresponding anomaly monitoring dimensions are effectively determined. Simultaneously, data anomaly monitoring rules and anomaly level classification rules are locked based on the data business attributes and anomaly monitoring dimensions of each management node. Next, the obtained data anomaly monitoring rules and anomaly level classification rules are used as the first model element. Furthermore, the data sensitivity of each management node is determined based on its data business attributes, enabling the locking of data access permissions based on sensitivity. This, in turn, determines the user access behavior anomaly monitoring system based on data access permissions, thereby reliably acquiring the second model element. Finally, the obtained first and second model elements are associated and bound to accurately and effectively construct the target anomaly monitoring model. The obtained target anomaly monitoring model is then interfaced with each management node, ultimately achieving anomaly monitoring of the full lifecycle management nodes. This improves the reliability and accuracy of asset data anomaly monitoring and significantly enhances the full lifecycle management effect of asset data.

[0164] Example 8:

[0165] Building upon Example 7, this example provides an AI-based full lifecycle data security management platform, including an anomaly monitoring model construction unit:

[0166] The monitoring subunit is used for:

[0167] Based on the interface connection results, the system obtains user access data for asset data under different period management nodes in real time, parses the access data, and determines the corresponding derived data.

[0168] Based on the derived data, determine the multi-dimensional working characteristics of the interface during the monitoring period, and construct an interface profile of the interface during the monitoring period based on the multi-dimensional working characteristics.

[0169] The user profile building subunit is used for:

[0170] Based on derived data, determine the set of user access behaviors for asset data under different period management nodes, and quantify each access behavior in the set of access behaviors to obtain the corresponding quantitative indicator value.

[0171] Based on the preset visualization requirements, determine the visualization charts for the quantitative indicator values, and display the corresponding values ​​of the quantitative indicator values ​​based on the visualization charts to obtain the corresponding user behavior profiles.

[0172] The recording subunit is used to record and store the obtained interface profiles and user behavior profiles.

[0173] In this embodiment, the interface profile includes: average daily number of accesses, compliant access time, average daily access data volume, average daily sensitive data volume, average daily number of sensitive data types, and average daily number of access source IPs.

[0174] In this embodiment, the user behavior profile includes: average daily number of data outgoings, compliant working hours, compliant login hours, average daily number of logins, average daily amount of sensitive data, average daily number of sensitive data operations, average daily number of downloads, average daily number of operations, and average daily number of peripheral device accesses.

[0175] In this embodiment, access data refers to the specific access behavior data of a user when accessing asset data under different periodic management nodes, including the data object accessed, the frequency of access, and the specific time point of access.

[0176] In this embodiment, derived data refers to data about data access characteristics obtained after parsing access data, including specific access volume and other data.

[0177] In this embodiment, multi-dimensional working characteristics refer to the specific working status of the interface during the monitoring period, including the amount of data flow per unit time and the number of user accesses.

[0178] In this embodiment, the interface profile refers to a report or visualization that can characterize the specific working status of the interface during the monitoring period.

[0179] In this embodiment, the quantification index value refers to the result obtained by quantifying each access behavior in the user access behavior set. For example, it can be the quantification of the user's access frequency, which is the number of accesses per unit time.

[0180] In this embodiment, the preset visualization requirements are set in advance, including the type of visualization and the format of visualization.

[0181] The working principle and beneficial effects of the above technical solution are as follows: By parsing the user's access data to asset data under different periodic management nodes, the multi-dimensional working characteristics of the interface during the monitoring period can be determined, thereby enabling the effective construction of the interface profile during the monitoring period. This helps to fully understand the multi-dimensional working characteristics of the interface in different monitoring periods. By constructing user behavior profiles, the user's access behavior characteristics to asset data can be effectively and clearly displayed, and data management can be traced and audited based on the interface profile and user behavior profile.

[0182] Example 9:

[0183] Building upon Example 8, this example provides an AI-based full lifecycle data security management platform, including an anomaly monitoring model construction unit:

[0184] The result acquisition subunit is used for:

[0185] Obtain anomaly monitoring results for all lifecycle management nodes, and pinpoint the source of the anomaly when one is detected.

[0186] The locked anomaly source is analyzed to determine the anomaly type and anomaly characteristics, and a response strategy is matched from the preset response strategy library based on the anomaly type and anomaly characteristics.

[0187] Anomaly response subunit, used for:

[0188] Early warning responses are generated based on the anomaly type and anomaly characteristics according to the response strategy.

[0189] In this embodiment, when the anomaly type is data anomaly, an early warning response is issued for the anomaly situation; when the anomaly type is user access behavior anomaly, unauthorized personnel are prevented from accessing the data in violation of regulations.

[0190] The beneficial effects of the above technical solution are: by timely identifying the type and characteristics of anomalies, an early warning response can be achieved, effectively ensuring the monitoring of user access behavior; and when anomalies occur, by preventing unauthorized personnel from accessing the data, data security can be effectively guaranteed.

[0191] Example 10:

[0192] This embodiment provides an AI-based full lifecycle data security management method, such as... Figure 3 As shown, it includes:

[0193] Step 1: In the data lifecycle security process domain, use AI to read asset data and classify and grade the asset data;

[0194] Step 2: Generate a data security management strategy based on the classification and grading results;

[0195] Step 3: Based on the data security policy, contextualize the asset data and implement component-driven processing to achieve secure use of data throughout its entire lifecycle.

[0196] The working principle and beneficial effects of the above technical solution are as follows: By reading asset data based on AI in the data lifecycle security process domain and classifying and grading the read asset data, the comprehensiveness and reliability of the read asset data are ensured, while the efficiency and accuracy of the classification and grading of asset data are also ensured. Secondly, corresponding data security management strategies are generated based on the classification and grading results, providing a reliable basis and convenience for the full lifecycle security management of asset data. Finally, based on the obtained data security management strategies, asset data is scenario-based and component-driven, realizing comprehensive and reliable security management of data in various data scenarios, improving the efficiency and accuracy of data processing, and ensuring the security and reliability of data throughout its entire lifecycle.

[0197] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.

Claims

1. An AI-based full life cycle data security management platform, characterized in that, The application comprises: An asset data management module for reading asset data based on AI and classifying asset data in a data life cycle security process domain; A strategy generation module for generating a data security management strategy according to the classification and grading results; A driving module for data scene setting and component driving of asset data according to the data security strategy, completing the safe use of life cycle data; The driving module comprises: A model construction preparation unit for: Obtaining full-process parameters for data scene setting and component driving of asset data, and determining life cycle management nodes of asset data based on the full-process parameters; Obtaining abnormal monitoring dimensions of the life cycle management nodes based on a management terminal, wherein the abnormal monitoring dimensions include data abnormality dimensions and user access behavior abnormality dimensions; Extracting data business attributes of each cycle management node in the life cycle management nodes, and determining the operation mode of asset data under each cycle management node and the benchmark characteristics in the operation mode based on the data business attributes; Determining data abnormality attention points of each cycle management node based on the operation mode and the benchmark characteristics, and constructing data abnormality monitoring rules and abnormal level grading rules for each cycle management node based on the data business attributes and the data abnormality attention points; Obtaining a data abnormality monitoring system for each cycle management node based on the data abnormality monitoring rules and the abnormal level grading rules, and taking the data abnormality monitoring system as a first model element; At the same time, determining the data sensitivity under each cycle management node based on the data business attributes of each cycle management node, and determining the data access authority of each cycle management node based on the data sensitivity; Determining the data use scene and scene supervision index under each cycle management node based on the data access authority, and obtaining a user access behavior abnormality monitoring system for each cycle management node based on the data use scene and the scene supervision index, and taking the user access behavior abnormality monitoring system as a second model element; Firstly, binding the first model element and the second model element based on the cycle management nodes, and secondly, binding the first binding result according to the execution order of the cycle management nodes; An abnormality monitoring model construction unit for: Integrating and training the second binding result in a preset model framework to obtain a target abnormality monitoring model, and interfacing the target abnormality monitoring model with each cycle management node; Abnormality monitoring of the life cycle management nodes based on the interface connection result.

2. The AI-based full life cycle data security management platform of claim 1, wherein, In the asset data management module, the data life cycle security process domain includes data collection security, data transmission security, data storage security, data processing security, data exchange security, and data destruction security.

3. The AI-based full life cycle data security management platform of claim 1, wherein, The asset data management module comprises: A data object determination unit for obtaining a data object corresponding to asset data; An identification algorithm generation unit for: Locating a target traditional algorithm in a preset traditional algorithm set and a target AI algorithm in a preset AI algorithm set according to the data object; Generating an identification algorithm according to the target traditional algorithm and the target AI algorithm; The data recognition unit is configured to recognize the asset data according to a recognition algorithm, call a preset classification and grading knowledge base, and classify and grade the recognition result according to the preset classification and grading knowledge base. The virtual asset management unit is configured to manage the asset data as virtual assets according to the classification and grading result.

4. The AI-based full life cycle data security management platform of claim 1, wherein, The policy generation module comprises: The calling unit is configured to call a data security management policy pool. The data division unit is configured to read the classification and grading result of the asset data, divide the asset data according to the classification and grading result, and obtain a sub-asset data set under each category and each level. The security configuration unit is configured to: Obtain data attribute features of the sub-asset data set, and determine security management requirements of the sub-asset data set according to the data attribute features; Call a target data security management policy corresponding to the sub-asset data set in the data security management policy pool according to the security management requirements; Perform security configuration on the target security management policy in the corresponding sub-asset data set.

5. The AI-based full life cycle data security management platform of claim 3, wherein, The data recognition unit comprises: The automatic recognition sub-unit is configured to automatically recognize the asset data before reading the asset data, specifically: Construct a data asset dictionary and draw a data asset graph, and at the same time, define sensitive data according to the data asset dictionary and the data asset graph; Automatically scan the sensitive data in the asset data according to the definition result, and index mark the data category of the scanned sensitive data; Automatically identify the core data in the asset data according to the index mark.

6. The AI-based full life cycle data security management platform of claim 1, wherein, The driving module comprises: The scene division unit is configured to read a whole life cycle process of the asset data, divide the asset data according to the whole life cycle process of the asset data, and obtain running features of the asset data in each scene according to the division result; The policy determination unit is configured to determine a corresponding target data security policy according to the running features of the asset data in each scene; The component determination unit is configured to obtain a target component corresponding to each scene; The component driving unit is configured to drive the target component in the corresponding scene according to the target data security policy and the target component, and complete the safe use of the whole life cycle data.

7. The AI-based full-life cycle data security management platform of claim 1, wherein, The abnormality monitoring model construction unit comprises: The monitoring sub-unit is configured to: Obtain access data of the asset data under different cycle management nodes by a user in real time based on an interface connection result, analyze the access data, and determine derived data corresponding to the access data; Determine multi-dimensional working features of the interface in a monitoring period based on the derived data, and construct an interface portrait of the interface in the monitoring period based on the multi-dimensional working features; The user portrait construction sub-unit is configured to: Determine a set of access behaviors of the asset data under different cycle management nodes by the user based on the derived data, quantify each access behavior in the set of access behaviors, and obtain corresponding quantitative index values; Determine a visualization display chart of the quantitative index values based on a preset visualization requirement, perform corresponding value display of the quantitative index values based on the visualization display chart, and obtain a corresponding user behavior portrait; The recording sub-unit is configured to record and store the obtained interface portrait and user behavior portrait.

8. The AI-based full life cycle data security management platform of claim 7, wherein, The abnormality monitoring model construction unit comprises: The result obtaining sub-unit is configured to: Obtain the abnormal monitoring result of the full life cycle management node, and lock the abnormal source when there is an abnormality; Analyze the locked abnormal source, determine the abnormal type and abnormal characterization, and match the response strategy from the preset response strategy library based on the abnormal type and abnormal characterization; The abnormal response subunit is used for: Based on the response strategy, the abnormal type and abnormal characterization are prewarned.

9. An AI-based full-life-cycle data security management method, characterized by, It includes: Step 1: Based on AI, read asset data in the data life cycle security process domain and classify and grade asset data; Step 2: Generate data security management strategy according to classification and grading results; Step 3: According to the data security strategy, the asset data is data-scene and component-driven, and the safe use of the full life cycle data is completed; Step 3, including: Obtain the full process parameters of the asset data data-scene and component-driven, and determine the full life cycle management node of the asset data based on the full process parameters; Based on the management terminal, obtain the abnormal monitoring dimension of the full life cycle management node, wherein the abnormal monitoring dimension includes data abnormality dimension and user access behavior abnormality dimension; Extract the data business attributes of each cycle management node in the full life cycle management node, and determine the running mode of the asset data under each cycle management node and the benchmark characteristics under the running mode based on the data business attributes; Determine the data abnormality focus of each cycle management node based on the running mode and the benchmark characteristics, and construct the data abnormality monitoring rule and the abnormal level classification rule of each cycle management node based on the data business attributes and the data abnormality focus; Based on the data abnormality monitoring rule and the abnormal level classification rule, obtain the data abnormality monitoring system of each cycle management node, and take the data abnormality monitoring system as the first model element; At the same time, determine the data sensitivity of each cycle management node based on the data business attributes of each cycle management node, and determine the data access authority of each cycle management node based on the data sensitivity; Determine the data use scene and scene supervision index of each cycle management node based on the data access authority, and obtain the user access behavior abnormality monitoring system of each cycle management node based on the data use scene and scene supervision index, and take the user access behavior abnormality monitoring system as the second model element; Based on the cycle management node, the first model element and the second model element are first bound, and the first binding result is second bound according to the execution order of the cycle management node; Integrate and train the second binding result in the preset model framework to obtain the target abnormal monitoring model, and interface the target abnormal monitoring model with each cycle management node; Based on the interface docking result, the full life cycle management node is monitored for the full life cycle management node.

Citation Information

Patent Citations

  • Data security control method and data security control platform

    CN104796290A

  • Data asset classification modeling and grading protection method based on artificial intelligence technology

    CN113590698A