Enterprise data security management method and system
By identifying and evaluating the types and value of enterprise data and implementing differentiated encryption processing, the problems of resource waste and high-value data protection in enterprise data security management are solved, and efficient and secure data management is achieved.
Patent Information
- Application Number
- CN202510627866.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2025-08-15
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, enterprises adopt unified encryption methods in data security management, resulting in wasted computing resources and storage resources, while being unable to effectively protect high-value data, which poses a risk of economic losses and reputation damage.
By identifying the target business data type, obtaining associated business data for multi-dimensional value evaluation, high-level or conventional encryption processing is implemented based on the evaluation results, accurately locate high-value data and strengthening protection to avoid wasting resources for low-value data.
Differentiated encryption processing is realized, high-value data is accurately positioned, enterprise data security management costs, improve data processing efficiency and security, and reduce resource waste.
Smart Images

Figure CN120498766A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security technology, and in particular to an enterprise data security management method and system. Background Art
[0002] As enterprises accelerate their digitalization, the volume of business data is exploding. This data, containing crucial information such as business operations, customer information, and business strategies, is a core enterprise asset. However, enterprises currently employ a unified encryption method for all data when managing data security. This approach presents numerous drawbacks. For one thing, high-strength encryption of low-value data wastes significant computing and storage resources, increasing operational costs. For another, conventional encryption of high-value data can lead to significant financial losses and reputational damage in the event of a data leak.
[0003] Therefore, how to conduct targeted security management based on the actual value of data has become an urgent issue to be solved in the field of enterprise data security. Summary of the Invention
[0004] In order to at least solve the technical problems existing in the above-mentioned background technology, the present invention provides an enterprise data security management method, system, electronic device, computer storage medium and computer program product.
[0005] A first aspect of the present invention provides an enterprise data security management method, which is applied to a data management platform and includes the following steps:
[0006] After receiving the target business data uploaded by the salesperson terminal, determining the data type of the target business data, and determining whether the target business data is regular data according to the data type;
[0007] If the target business data does not belong to regular data, then obtain a number of related business data corresponding to the target business data, and perform a multi-dimensional value assessment on the target business data based on each of the related business data;
[0008] If the assessed data value is higher than the value threshold, the target business data is encrypted at a high level; otherwise, the target business data is encrypted at a conventional level or not encrypted.
[0009] A second aspect of the present invention provides an enterprise data security management system, which is applied to a data management platform and includes a receiving module, a processing module, and a storage module; the processing module is connected to the receiving module and the storage module;
[0010] The receiving module is used to receive the target business data uploaded by the salesperson terminal and transmit it to the processing module;
[0011] The storage module is used to store executable computer program code;
[0012] The processing module is configured to execute the method as described in any of the preceding items by calling the executable computer program code in the storage module.
[0013] The third aspect of the present invention provides an electronic device, comprising: a memory storing executable program code; a processor coupled to the memory; the processor calling the executable program code stored in the memory to execute any of the methods described in the preceding items.
[0014] A fourth aspect of the present invention provides a computer storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method described in any one of the above items is executed.
[0015] A fifth aspect of the present invention provides a computer program product, which stores a computer program that can be called and executed by a processor of an electronic device, so as to implement any of the methods described above when executed.
[0016] This invention achieves differentiated encryption of business data by identifying target business data types, mining related data, and performing multi-dimensional value assessment. It can accurately locate high-value data and strengthen protection, avoid wasting encryption resources on low-value data, and effectively reduce enterprise data security management costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.
[0018] Figure 1 This is a flow chart of a method for enterprise data security management disclosed in an embodiment of the present invention;
[0019] Figure 2 is a schematic diagram of the structure of the deep belief network disclosed in an embodiment of the present invention;
[0020] Figure 3 This is a structural diagram of an enterprise data security management system disclosed in an embodiment of the present invention. DETAILED DESCRIPTION
[0021] To make the objectives, technical solutions, and advantages of the present invention more apparent, the present invention will be further described in detail below with reference to the accompanying drawings. It is apparent that the embodiments described are only some, not all, of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort are intended to fall within the scope of protection of the present invention.
[0022] The terms used in the examples of this application are for the purpose of describing specific embodiments only and are not intended to limit this application. The singular forms "a," "the," and "the" used in the examples of this application and the appended claims are also intended to include plural forms, and unless the context clearly indicates otherwise, "a plurality" generally includes at least two.
[0023] The preferred embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0024] like Figure 1 As shown, an enterprise data security management method according to an embodiment of the present invention is applied to a data management platform and includes the following steps:
[0025] S1, after receiving target business data uploaded by a salesperson terminal, determining the data type of the target business data, and determining whether the target business data is regular data according to the data type.
[0026] When the data management platform receives target business data uploaded by a salesperson's terminal, it first determines its data type. This classification can be based on various criteria, such as the data's source (customer data, production data, financial data, etc.), format (structured data, unstructured data), and purpose (operational data, analytical data, backup data, etc.). Using pre-defined rules and classification criteria, the target business data is categorized into the corresponding data type.
[0027] Next, the target business data is determined to be regular data. Regular data refers to data that is frequently generated in the company's daily operations, has a relatively fixed processing flow, and has little impact on the company's core interests, such as daily attendance records and ordinary office documents. If the data is regular data, its subsequent processing flow can adopt a relatively simple security policy or be unencrypted. If it is not regular data, it must enter the security analysis and disposal process of the present invention.
[0028] It should be noted that the data management platform can be a local area network-based platform built by the enterprise itself, or an Internet-based platform built on the cloud, so that the salesperson's terminal can transmit relevant business data back to the platform in real time via the mobile Internet. The present invention does not impose specific limitations on this.
[0029] S2: If the target business data does not belong to regular data, obtain a number of related business data corresponding to the target business data, and perform a multi-dimensional value assessment on the target business data based on each of the related business data.
[0030] For target business data that is considered non-routine data, the data management platform will acquire a number of related business data. This related business data can come from various systems or business processes within the enterprise, such as upstream and downstream business process data related to the target business data, historical data, and relevant market data. Based on this related data, the data management platform can gain a more comprehensive understanding of the context and value of the target business data.
[0031] Then, based on the relevant business data, a multi-dimensional value assessment is conducted on the target business data. This assessment includes, but is not limited to, the business importance of the data, i.e., the degree to which the data supports and impacts the company's core business; the sensitivity of the data, such as data involving customer privacy and trade secrets; the timeliness of the data, such as market dynamics data, which is highly valuable within a specific timeframe; and the scarcity of the data, such as unique or difficult-to-obtain data, which is generally more valuable. By comprehensively considering these dimensions, a quantitative assessment of the value of the target business data is conducted, providing an accurate basis for value judgment in the subsequent formulation of encryption strategies.
[0032] S3: If the assessed data value is higher than the value threshold, the target business data is encrypted at a high level; otherwise, the target business data is encrypted at a conventional level or not encrypted.
[0033] After completing the data value assessment of the target business data, the assessed data value is compared with the pre-set value threshold. The value threshold is determined by the enterprise based on factors such as its own security needs, business characteristics, and resource status.
[0034] If the assessed data value is higher than the threshold, it indicates that the target business data is highly valuable and could cause significant losses to the enterprise if leaked, so it requires high-level encryption. If the data value is lower than or equal to the threshold, the target business data is encrypted at a standard level or not encrypted.
[0035] High-level encryption can combine symmetric and asymmetric encryption algorithms to ensure data security during storage and transmission. Conventional encryption uses relatively simple, resource-efficient methods. For data of extremely low value and high public importance, encryption can be omitted based on the company's security policy, saving computing and storage resources and improving data processing efficiency.
[0036] This invention achieves differentiated encryption of business data by identifying target business data types, mining related data, and performing multi-dimensional value assessment. It can accurately locate high-value data and strengthen protection, avoid wasting encryption resources on low-value data, and effectively reduce enterprise data security management costs.
[0037] Furthermore, the receiving of target business data uploaded by the salesperson terminal includes:
[0038] After receiving the business data uploaded by the salesperson terminal, retrieving the terminal attributes of the salesperson terminal stored in the database, the terminal attributes including the salesperson level and / or the business task importance level and / or the customer importance level;
[0039] If the terminal attributes meet the preset conditions, the business data is determined as the target business data; wherein the preset conditions refer to the salesperson level being higher than the first threshold and / or the business task importance level being higher than the second threshold and / or the customer importance level being higher than the third threshold.
[0040] In enterprise data management practices, the amount of business data uploaded by salesperson terminals is huge and the value is uneven. If all data is processed indiscriminately, it will not only waste computing resources but also make it difficult to ensure the security of truly critical data.
[0041] To accurately identify high-value data, the present invention immediately retrieves multiple attributes of a salesperson terminal from the database after receiving business data uploaded by the salesperson terminal on the data management platform. These attributes include the salesperson's level, the importance of business tasks, and the importance of customers. The salesperson's level reflects their business authority and capabilities; the importance of business tasks reflects the impact of the data on the company's operations. A business task refers to the specific task assigned to the salesperson terminal by the company, with different tasks having different importance levels; and the importance of customers measures their value to the company.
[0042] Subsequently, the retrieved terminal attributes are compared with the preset thresholds. As long as the salesperson level is higher than the first threshold, the business task importance level is higher than the second threshold, and the customer importance level is higher than the third threshold, at least one preset condition is met, and the business data is determined to be the target business data, and the subsequent refined security analysis and disposal process begins; if none of the conditions are met, it is processed according to the normal process.
[0043] In this way, high-value business data can be quickly and accurately screened out, encryption and computing resources can be concentrated on processing key data, data screening efficiency can be greatly improved, system resource consumption can be reduced, and while reducing enterprise operating costs, the security protection of important data can be effectively enhanced, the risk of data leakage can be reduced, and an optimal balance between data management efficiency and security can be achieved.
[0044] Furthermore, the acquiring of a plurality of associated business data corresponding to the target business data includes:
[0045] Determine the scope of data acquisition that has a causal relationship and upstream and downstream relationship with the target business data;
[0046] Determine whether the target business data is a project attribute or an independent attribute. If it is a project attribute, set the data acquisition duration to the first duration; if it is an independent attribute, set the data acquisition duration to the second duration; the first duration is greater than the second duration;
[0047] The latest business data is acquired within a data acquisition range according to the first time period or the second time period, and is used as the associated business data.
[0048] First, based on the causal relationship between data (such as sales orders and inventory changes) and upstream and downstream relationships (such as purchase applications and production plans), the scope of data acquisition is accurately defined to ensure that all data involved have actual relevance to the target business.
[0049] Secondly, determine the attributes of the target business data. If it is a project attribute, its value realization will take a long period of time, so a longer first period (such as 6 months) is set for data collection. It is understandable that project attributes include large-scale R&D projects, long-term customer cooperation projects, etc., and projects usually include multiple customers and multiple salesmen (belonging to the same company). These multiple types of business data usually follow the same data security standards (established at the beginning of the project), which are highly referenceable for evaluating the data value of the target business data. Moreover, the synchronization of updates of these data is difficult to guarantee, so a longer first period is required to ensure that data with reference value is obtained. If it is an independent attribute (such as daily customer consultation records, single purchase orders), only recent data is needed to support the evaluation, so a shorter second period (such as 1 week) is set.
[0050] Finally, based on the set time period, the latest business data is extracted as related data within the defined scope to avoid outdated information interfering with the evaluation.
[0051] Through the above method, irrelevant data can be effectively filtered, the data processing load can be reduced, and the data screening efficiency can be improved; the acquisition time can be dynamically adjusted according to the data attributes to ensure that the value cycle of the associated data matches the target business data, making the multi-dimensional value assessment more in line with the actual business scenario, thereby providing a more accurate data basis for the formulation of encryption strategies, and ultimately achieving the dual optimization of resource utilization and security protection in data security management.
[0052] Furthermore, the multi-dimensional value assessment of the target business data based on each of the associated business data includes:
[0053] The hierarchical analysis method is used to determine the weights of the business importance dimension, sensitivity dimension, timeliness dimension and scarcity dimension; the deep belief network is used to determine the data sub-value of each related business data in a single dimension;
[0054] The data sub-value of each dimension is weightedly calculated with the corresponding weight to obtain the final data value.
[0055] In order to improve the accuracy of the assessment of the data value of target business data, this paper adopts a multi-dimensional assessment method, the assessment dimensions include but are not limited to the business importance, sensitivity, timeliness and scarcity of the data. The details are as follows:
[0056] First, the analytic hierarchy process (AHP) is used to determine the weights of each evaluation dimension, and the specific determination process will be described in detail later.
[0057] At the same time, related business data often has complex structures and rich information, and traditional methods may only be able to process superficial and simple features. As a deep learning model, DBN Figure 2 As shown, the algorithm is composed of multiple stacked restricted Boltzmann machines (RBMs), which can construct a multi-level feature representation of data. Each RBM layer learns higher-level features based on the previous layer, forming a hierarchical feature system. This multi-level feature representation can more comprehensively and meticulously characterize the essential characteristics of related business data, helping to more accurately assess the value of target business data across various dimensions. For example, when analyzing business data, it can uncover business patterns, trends, and regularities hidden in the data. These deep-level features are crucial for accurately assessing the value of target business data.
[0058] Furthermore, an enterprise's business environment and data are constantly changing, and associated business data is also dynamic. DBNs can adapt to these dynamic changes through continuous learning and training, allowing them to promptly adjust their assessments of data value. For example, as market conditions change, the value of data in dimensions like timeliness and scarcity may shift. DBNs can quickly learn these changes, ensuring the accuracy of their value assessments.
[0059] Therefore, this paper uses a deep belief network (DBN) to determine the data value of each related business data in a single dimension. The related business data is input into a trained deep belief network, which learns the underlying patterns and features in the data and outputs the data sub-value of each related business data in different dimensions.
[0060] Finally, the data sub-value of each dimension is weighted and calculated with the corresponding weight to obtain the final data value.
[0061] In this way, the importance of each evaluation dimension and the performance of related business data in each dimension are comprehensively considered, which enables a more scientific and accurate multi-dimensional value assessment of the target business data, providing a reliable value judgment basis for the subsequent formulation of encryption strategies.
[0062] Furthermore, the use of the analytic hierarchy process to determine the weights of the business importance dimension, sensitivity dimension, timeliness dimension, and scarcity dimension includes:
[0063] Construct a hierarchical model, determine the relative importance judgment matrix between each level, obtain the eigenvalue by solving the characteristic polynomial, and then obtain the eigenvector corresponding to the maximum eigenvalue;
[0064] The weight of each evaluation dimension is obtained by using the normalization formula and the characteristic vector calculation.
[0065] The present invention adopts the analytic hierarchy process (APH) to determine the weight of each dimension, as follows:
[0066] 1. Construct a hierarchical model that includes the target layer, the criteria layer, and the solution layer. The explanation of each layer is as follows:
[0067] Target layer: The clear goal is to evaluate the value of the target business data, denoted as G.
[0068] Criteria layer: Determine the evaluation dimensions, including the business importance of the data (denoted as C1), sensitivity (denoted as C2), timeliness (denoted as C3) and scarcity (denoted as C4).
[0069] Solution layer: Take the associated business data as the solution layer, denoted as D1, D2, ..., D n , where n is the number of associated business data.
[0070] 2. Determine the relative importance judgment matrix between each level:
[0071] For each criterion layer, the dimension C i , i = 1, 2, 3, 4, it is necessary to determine its relative importance to other dimensions and the target layer. This can be achieved through data analysis and other methods.
[0072] For the business importance dimension C1, we can analyze the impact of this dimension on the target business data value assessment and compare it with other dimensions to determine its relative importance. Assume that the importance of the business importance dimension C1 relative to the sensitivity dimension C2 is a 12 , relative to the importance of timeliness dimension C3 is a 13 , relative to the scarcity dimension C4, its importance is a 14 , then construct the following judgment matrix:
[0073]
[0074] Among them, a ij Represents dimension C i Relative to dimension C j The importance of a ij =1 / a ji .
[0075] 3. Calculate the eigenvector and maximum eigenvalue of the judgment matrix:
[0076] Use mathematical methods to calculate the eigenvector and maximum eigenvalue of the judgment matrix A. First, calculate the characteristic polynomial of the judgment matrix A: det(A-λI). Where λ is the eigenvalue and I is the identity matrix. Solve the above characteristic polynomial to obtain the eigenvalues λ1, λ2, ..., λ n .
[0077] Then, for each eigenvalue λ i , solve the linear equation system (A-λI)X=0 and get the corresponding eigenvector X i The maximum eigenvalue λ max The corresponding eigenvector X max It is the relative importance weight vector of each dimension.
[0078] 4. Obtain the weight of each evaluation dimension:
[0079] The calculated eigenvector X max Perform normalization to obtain the weights of each evaluation dimension ω1, ω2, ..., ω n The normalization formula is:
[0080]
[0081] Among them, X max (i) represents the eigenvector X max The i-th component of .
[0082] Through the above process, the weight of each evaluation dimension can be accurately determined, providing a reliable basis for subsequent multi-dimensional value evaluation.
[0083] It should be noted that the judgment matrix also needs to be checked for consistency to ensure the reliability of the evaluation results. This consistency check can be achieved by calculating the consistency index (CI) and the random consistency index (RI), and then calculating the consistency ratio (CR) = CI / RI. When CR < 0.1, the judgment matrix is considered to have satisfactory consistency. If the consistency does not meet the requirements, the judgment matrix needs to be readjusted.
[0084] Furthermore, a data pre-processing unit is added to the input layer of the deep belief network, and before the deep belief network is used to determine the data sub-value of each of the associated business data in a single dimension, the method further includes:
[0085] Calculating the sparsity of each of the associated business data, where the sparsity is the ratio of the number of missing values in each of the associated business data to the total amount of data;
[0086] If the sparsity degree is greater than a preset high sparsity threshold, the data preprocessing unit adopts a matrix decomposition-based method to process the sparse data; if the sparsity degree is less than or equal to a preset low sparsity threshold, the data preprocessing unit adopts a simple data normalization method to process the sparse data; if the sparsity degree is between the low sparsity threshold and the high sparsity threshold, the data preprocessing unit adopts an interpolation-based method to process the sparse data.
[0087] First, calculate the sparsity of the associated business data. The ratio of the number of missing values in the statistical data to the total data volume is recorded as the sparsity degree ρ, that is, where N missing Indicates the number of missing values, N total Indicates the total data volume.
[0088] If the calculated sparsity degree ρ is greater than the pre-set high sparsity threshold ρ high (For example, high =50%, this threshold can be adjusted according to the actual business scenario and data characteristics), then the associated business data is judged to be highly sparse. At this time, the data preprocessing unit added to the input layer of the deep belief network uses a matrix decomposition-based method to process sparse data. Specifically, the original sparse data matrix X is decomposed into the product of two low-rank matrices U and V, that is, X≈UV T , by optimizing the objective function To solve U and V, where Ω represents the index set of known data elements and λ is the regularization parameter used to prevent overfitting. In this way, sparse data is converted into a dense representation that is more suitable for deep belief network processing.
[0089] If the calculated sparsity degree ρ is less than or equal to the preset low sparsity threshold ρ low (For example, low =20%, the threshold can also be adjusted according to actual conditions), then the associated business data is determined to have low sparsity. In this case, the data preprocessing unit adopts a simple data normalization method, such as minimum-maximum normalization, to map the data to the interval [0,1].
[0090] If the sparsity level ρ is between the low sparsity threshold ρ low and a high sparsity threshold ρhigh If the value of the associated business data is between , the associated business data is determined to have medium sparsity. In this case, the data preprocessing unit uses interpolation methods, such as linear interpolation or polynomial interpolation, to fill in the missing values. For example, for a one-dimensional data sequence, if there are missing values, linear interpolation can be performed based on adjacent known data points to calculate the missing values.
[0091] By adding data preprocessing units with different functions according to the sparsity of the associated business data, the deep belief network can better process associated business data with different sparsity levels, improve the ability to mine the deep-level features of the data, and thus more accurately determine the data sub-value of each associated business data in a single dimension.
[0092] like Figure 3 As shown, an enterprise data security management system (1) according to an embodiment of the present invention is applied to a data management platform and comprises a receiving module (100), a processing module (200), and a storage module (300); the processing module (200) is connected to the receiving module (100) and the storage module (300);
[0093] The receiving module (100) is used to receive target business data uploaded by the salesperson terminal and transmit it to the processing module (200);
[0094] The storage module (300) is used to store executable computer program code;
[0095] The processing module (200) is configured to execute the method as described in any one of the preceding items by calling the executable computer program code in the storage module (300).
[0096] The specific functions of an enterprise data security management system in this embodiment refer to the above embodiments. Since the system in this embodiment adopts all the technical solutions of the above embodiments, it at least has all the beneficial effects brought by the technical solutions of the above embodiments, which will not be described one by one here.
[0097] An embodiment of the present invention further discloses an electronic device, comprising: a memory storing executable program code; a processor coupled to the memory; the processor calling the executable program code stored in the memory to execute the method as described in the above embodiment.
[0098] An embodiment of the present invention further discloses a computer storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method described in the above embodiment is executed.
[0099] An embodiment of the present invention further discloses a computer program product, which stores a computer program that can be called and executed by a processor of an electronic device, so as to implement the method described in the above embodiment when executed.
[0100] The device / system according to an embodiment of the present disclosure may include a processor, a memory for storing program data and executing the program data, a permanent memory such as a disk drive, a communication port for processing communication with an external device, and a user interface device, etc. The method is implemented as a software module or can be stored on a computer-readable recording medium as a computer-readable code or program command that can be executed by a processor. The example of a computer-readable recording medium may include a magnetic storage medium (e.g., a read-only memory (ROM), a random access memory (RAM), a floppy disk, a hard disk, etc.), an optical reading medium (e.g., a CD-ROM, a digital versatile disk (DVD), etc.), etc. The computer-readable recording medium can be distributed in a computer system connected in a network, and the computer-readable code can be stored and executed in a distributed manner. The medium can be computer-readable, stored in a memory and executed by a processor.
[0101] The embodiments of the present disclosure may be indicated as functional block components and various processing operations. Functional blocks may be implemented as various numbers of hardware and / or software components that perform specific functions. For example, the embodiments of the present disclosure may implement direct circuit components that can perform various functions under the control of one or more microprocessors or other control devices, such as memory, processing circuits, logic circuits, lookup tables, etc. The components of the present disclosure may be implemented through software programming or software components. Similarly, the embodiments of the present disclosure may include various algorithms implemented by a combination of data structures, processes, routines, or other programming components, and may be implemented by programming or scripting languages (such as C, C++, Java, assembler, etc.). Functional aspects may be implemented by algorithms executed by one or more processors. In addition, the embodiments of the present disclosure may implement related technologies for electronic environment settings, signal processing, and / or data processing. Terms such as "mechanism," "element," "unit," etc. may be used broadly and are not limited to mechanical and physical components. These terms may represent a series of software routines associated with a processor, etc.
[0102] Specific embodiments are described in this disclosure as examples, and the scope of the embodiments is not limited thereto.
[0103] Although the embodiments of the present disclosure have been described, it will be understood by those skilled in the art that various changes in form and detail may be made therein without departing from the spirit and scope of the present disclosure as defined by the appended claims. Therefore, the above-described embodiments of the present disclosure should be interpreted as examples and do not limit the embodiments in all respects. For example, each component described as a single unit may be executed in a distributed manner, and similarly, components described as distributed may be executed in a combined manner.
[0104] All examples or exemplary terms (e.g., etc.) used in the embodiments of the present disclosure are for the purpose of describing the embodiments of the present disclosure, and are not intended to limit the scope of the embodiments of the present disclosure. In addition, unless otherwise explicitly stated, expressions such as "essential," "important," etc. associated with certain components may not indicate that the components are absolutely required.
[0105] It will be understood by those skilled in the art that the embodiments of the present disclosure may be implemented in modified forms without departing from the spirit and scope of the present disclosure.
Claims
1. An enterprise data security management method, applied to a data management platform, characterized in that: The steps include: After receiving the target business data uploaded by the salesperson terminal, determining the data type of the target business data, and determining whether the target business data is regular data according to the data type; If the target business data does not belong to regular data, then obtain a number of related business data corresponding to the target business data, and perform a multi-dimensional value assessment on the target business data based on each of the related business data; If the assessed data value is higher than the value threshold, the target business data is encrypted at a high level; otherwise, the target business data is encrypted at a conventional level or not encrypted.
2. The enterprise data security management method according to claim 1, characterized in that: The target business data uploaded by the salesperson terminal is received, including: After receiving the business data uploaded by the salesperson terminal, retrieving the terminal attributes of the salesperson terminal stored in the database, the terminal attributes including the salesperson level and / or the business task importance level and / or the customer importance level; If the terminal attributes meet the preset conditions, the business data is determined as the target business data; wherein the preset conditions refer to the salesperson level being higher than the first threshold and / or the business task importance level being higher than the second threshold and / or the customer importance level being higher than the third threshold.
3. The enterprise data security management method according to claim 1, characterized in that: The acquiring of a plurality of associated business data corresponding to the target business data includes: Determine the scope of data acquisition that has a causal relationship and upstream and downstream relationship with the target business data; Determine whether the target business data is a project attribute or an independent attribute. If it is a project attribute, set the data acquisition duration to the first duration; if it is an independent attribute, set the data acquisition duration to the second duration; the first duration is greater than the second duration; The latest business data is acquired within a data acquisition range according to the first time period or the second time period, and is used as the associated business data.
4. The enterprise data security management method according to claim 3, characterized in that: The multi-dimensional value assessment of the target business data based on each of the associated business data includes: The hierarchical analysis method is used to determine the weights of the business importance dimension, sensitivity dimension, timeliness dimension and scarcity dimension; the deep belief network is used to determine the data sub-value of each related business data in a single dimension; The data sub-value of each dimension is weightedly calculated with the corresponding weight to obtain the final data value.
5. The enterprise data security management method according to claim 4, characterized in that: The use of the hierarchical analysis method to determine the weights of the business importance dimension, sensitivity dimension, timeliness dimension, and scarcity dimension includes: Construct a hierarchical model, determine the relative importance judgment matrix between each level, obtain the eigenvalue by solving the characteristic polynomial, and then obtain the eigenvector corresponding to the maximum eigenvalue; The weight of each evaluation dimension is obtained by using the normalization formula and the characteristic vector calculation.
6. The enterprise data security management method according to claim 5, characterized in that: A data pre-processing unit is added to the input layer of the deep belief network, and before the deep belief network is used to determine the data sub-value of each of the associated business data in a single dimension, the method further includes: Calculating the sparsity of each of the associated business data, where the sparsity is the ratio of the number of missing values in each of the associated business data to the total amount of data; If the sparsity degree is greater than a preset high sparsity threshold, the data preprocessing unit adopts a matrix decomposition-based method to process the sparse data; if the sparsity degree is less than or equal to a preset low sparsity threshold, the data preprocessing unit adopts a simple data normalization method to process the sparse data; if the sparsity degree is between the low sparsity threshold and the high sparsity threshold, the data preprocessing unit adopts an interpolation-based method to process the sparse data.
7. An enterprise data security management system, applied to a data management platform, comprising a receiving module, a processing module, and a storage module; the processing module is connected to the receiving module and the storage module; The receiving module is used to receive the target business data uploaded by the salesperson terminal and transmit it to the processing module; The storage module is used to store executable computer program code; Its characteristics are: The processing module is configured to execute the method according to any one of claims 1 to 6 by calling the executable computer program code in the storage module.
8. An electronic device comprising: a memory storing executable program code; A processor coupled to the memory; characterized in that: the processor calls the executable program code stored in the memory to execute the method according to any one of claims 1-6.
9. A computer storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is executed.
10. A computer program product, characterized in that: A computer program that can be called and executed by a processor of an electronic device is stored therein, so as to implement the method according to any one of claims 1 to 6 when executed.