Data security transmission method in cloud platform salary management system

Through dynamic segmented encryption and two-dimensional verification watermark technology based on job permission matrix and environmental security scores, the security and reliability problems in the transmission of compensation data on cloud platform are solved, and the secure classification storage, dynamic encryption transmission and precise traceability control of data are realized, which improves the overall security and data transmission efficiency of the compensation management system of cloud platform.

CN120498768APending Publication Date: 2025-08-15JIANGSU SUYING INFORMATION TECH CO LTD
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202510634449.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-16
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

The existing cloud platform salary data security transmission methods have technical defects in permission management, dynamic encryption, environment perception and data control, and it is difficult to meet the high requirements of modern enterprises for salary data transmission security and intelligence. Especially when facing complex and changeable network environments, they lack differentiated protection and real-time monitoring capabilities.

Method used

Using dynamic segmentation encryption based on the job permission matrix, intelligent verification mechanism of environmental security scores, and multi-level data control technology for two-dimensional verification watermarks, we can realize secure classification storage, dynamic encryption transmission and precise traceability control of compensation data by generating job permission matrix, differentiated segmentation encryption rules, environmental security scores and two-dimensional verification watermarks.

Benefits of technology

It significantly improves the security and reliability of salary data transmission, realizes differentiated data protection, real-time monitoring and multi-level protection, and can quickly adjust protection strategies according to actual risk levels to ensure the security and traceability of data throughout the entire life cycle of transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498768A_ABST
    Figure CN120498768A_ABST
Patent Text Reader

Abstract

The invention discloses a secure data transmission method in a cloud platform salary management system, which belongs to the technical field of cloud platform data transmission, and comprises the following steps: acquiring user post attributes and authority levels to generate a post authority matrix, and generating a segmentation encryption rule to dynamically segment salary data to generate an encrypted data segment group; generating an environment security score based on the characteristics of the current network transmission path, and verifying the environment security score with the encrypted data segment group; after data transmission is completed, implanting a two-dimensional verification watermark into the encrypted data segment group to generate a controlled data packet; and generating a protection intensity grade and a gradient response instruction based on the current operation step and the environmental safety score, and executing a dynamic data protection operation. According to the method, the security classified storage, the dynamic encryption transmission and the accurate tracing control of the salary data can be realized by adopting the intelligent verification mechanism based on the dynamic segmentation encryption of the post permission matrix and the environmental security score and the multi-level data control technology of the two-dimensional verification watermark.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cloud platform data transmission, and in particular to a method for secure data transmission in a cloud platform salary management system. Background Art

[0002] Cloud platforms, as a crucial pillar of modern enterprise informatization, provide an efficient and flexible infrastructure for business operations and data management. With the widespread adoption of cloud computing technology, payroll management systems are gradually migrating to cloud platforms. However, due to the high sensitivity of payroll data, the secure transmission of payroll data on cloud platforms is becoming increasingly problematic. Leaks of payroll data can not only cause financial losses to businesses, but can also trigger a crisis of employee trust and even disrupt normal business operations.

[0003] Traditional solutions for secure payroll data transmission primarily rely on unified encryption technology and physical isolation measures, achieving protection through static encryption of the entire data packet. However, this single encryption approach has significant limitations in complex and volatile network environments, particularly in addressing practical requirements for categorized storage of payroll data, dynamic sharding encryption, and environmental adaptability during transmission. Furthermore, traditional solutions also lack data verification and post-transmission control mechanisms, making them ineffective in addressing the data security challenges of distributed network environments.

[0004] Currently, traditional encryption schemes lack the ability to classify salary data fields, making it difficult to provide differentiated protection based on data sensitivity and job permissions. This can lead to over- or under-protection of some highly sensitive data during transmission. Second, existing schemes lack real-time perception of the transmission environment and are unable to dynamically adjust encryption strength and protection strategies based on the security of the network environment, reducing the security of data transmission. Furthermore, existing technical solutions have limitations in data verification and post-transmission control, making it difficult to accurately trace data sources and transmission paths. Furthermore, they lack the ability to monitor and respond to abnormal operations in real time, limiting the breadth and depth of their application in cloud platform environments.

[0005] In summary, existing cloud platform payroll data security transmission methods have technical deficiencies in areas such as permission management, dynamic encryption, environmental awareness, and data control, making them unable to meet the high security and intelligent requirements of modern enterprises for payroll data transmission. A multi-dimensional technical solution is urgently needed that combines job permissions, dynamic encryption, environmental security scoring, and data verification to provide comprehensive, flexible, and intelligent data security transmission for cloud platform payroll management systems. Summary of the Invention

[0006] To solve the above problems, the present invention provides a method for secure data transmission in a cloud platform salary management system. It adopts dynamic segmented encryption based on the job authority matrix, an intelligent verification mechanism of environmental security scoring, and multi-level data control technology with two-dimensional verification watermarks. It can realize the secure classified storage, dynamic encrypted transmission and precise traceability control of salary data.

[0007] The above objectives can be achieved through the following solutions:

[0008] A method for secure data transmission in a cloud platform salary management system comprises: obtaining user job attributes and authority levels to generate a job authority matrix, wherein the job attributes include job hierarchy and department association parameters; generating differentiated segmentation encryption rules according to the job authority matrix, and using the segmentation encryption rules to dynamically segment salary data to generate encrypted data segment groups; obtaining current network transmission path characteristics based on a preset environmental security assessment model to generate an environmental security score; using the environmental security score and the encrypted data segment group for verification; implanting a two-dimensional verification watermark into the encrypted data segment group after data transmission is completed to generate a controlled data packet, wherein the two-dimensional verification watermark includes a metadata fingerprint layer and an operation track record layer; generating a protection strength level based on the current operation steps and the environmental security score, and generating a gradient response instruction according to the protection strength level to execute dynamic data protection operations.

[0009] Optionally, obtaining user job attributes and authority levels to generate a job authority matrix includes: extracting a preset department isolation coefficient and performing a weighted operation with the job level to generate an initial authority parameter; comparing the initial authority parameter with a preset salary visibility range threshold to generate an authority correction parameter; and generating a job authority matrix based on the product operation result of the authority correction parameter and the department association parameter.

[0010] Optionally, the generation of differentiated segmented encryption rules based on the position authority matrix includes: inputting the position authority matrix into a preset encryption policy allocation model to obtain a basic encryption mode; detecting the salary data field type and performing similarity matching with the basic encryption mode, and determining the segmented nodes based on the matching results; generating a node key distribution scheme based on the segmented nodes, the node key distribution scheme including a key generation algorithm and a key update cycle parameter; and constructing segmented encryption rules based on the node key distribution schemes of each segmented node.

[0011] Optionally, the use of the segmented encryption rule to dynamically segment the salary data to generate an encrypted data segment group includes: splitting the salary data into a basic salary segment and a performance salary segment according to the segmentation node; calling the basic encryption mode to perform dual-key rotation encryption on the basic salary segment to generate a first encrypted segment; using the pre-acquired employee ID to perform obfuscation encoding on the performance salary segment to generate a second encrypted segment; and combining the first encrypted segment and the second encrypted segment into an encrypted data segment group according to a preset arrangement rule.

[0012] Optionally, the verification using the environmental security score and the encrypted data segment group includes: when the environmental security score is lower than a preset first threshold, generating a verification serial number; dividing the encrypted data segment group corresponding to different employees into multiple ciphertext segments and storing them in different verification nodes in a preset verification node group; the verification nodes in the verification node group return corresponding ciphertext segments according to the verification serial number; arranging and combining the ciphertext segments returned by each verification node according to preset reorganization rules to obtain a standard sequence; comparing and matching the standard sequence with a preset template, and when the matching result meets the preset requirements, generating an access authorization token and updating the segmented encryption rules.

[0013] Optionally, updating the segmented encryption rule includes: extracting the location characteristics of the verification node to generate a dynamic key obfuscation parameter; superimposing the dynamic key obfuscation parameter into the key distribution scheme of the segmented encryption rule to generate a new segmented encryption rule including timestamp verification.

[0014] Optionally, the step of implanting a two-dimensional verification watermark into the encrypted data segment group after data transmission is completed to generate a controlled data packet includes: extracting the hardware fingerprint of the current operating terminal to generate a metadata fingerprint layer; recording the hash value of the operation steps during the data transmission process to generate an operation track record layer; and alternately embedding the metadata fingerprint layer and the operation track record layer into the encrypted data segment group to generate a controlled data packet.

[0015] Optionally, the method further includes: when a large-scale data export operation is monitored, enhancing the embedding depth of the operation track record layer; adding a department identification code to the metadata fingerprint layer to generate a traceability feature group; and synchronously updating the modified two-dimensional verification watermark to all associated controlled data packets.

[0016] Optionally, the protection strength level is generated based on the current operation steps and the environmental safety score, and a gradient response instruction is generated according to the protection strength level. The execution of dynamic data protection operations includes: extracting a normal operation sequence that matches the job authority matrix from the historical operation log to generate a baseline operation portrait; comparing the deviation value between the current operation steps and the baseline operation portrait in real time to generate a risk level parameter; selecting a protection strength level according to the correlation between the risk level parameter and the environmental safety score, the protection strength level including level one protection, level two protection and level three protection; calling a preset response plan based on the protection strength level to generate a gradient response instruction.

[0017] Optionally, calling a preset response plan based on the protection strength level and generating a gradient response instruction include: when the protection strength level is level one, activating the operation track mirror recording function and limiting the data transmission rate; when the protection strength level is level two, creating a virtual data copy for suspicious operation calls while blocking access to the original data; when the protection strength level is level three, triggering a preset sensitive field self-destruction program and generating an offline audit report.

[0018] Compared with the prior art, the present invention has the following advantages:

[0019] 1. This invention significantly improves the security and reliability of payroll data transmission through the comprehensive application of multiple technical means. This method implements data classification storage and dynamic encryption based on the position authority matrix, and can provide differentiated security protection based on different position authorities and data sensitivity, effectively reducing the risk of data leakage.

[0020] 2. This invention introduces an environmental security scoring and dynamic verification mechanism, combined with distributed node verification and watermark embedding technology, to achieve real-time monitoring and multi-level protection during data transmission. Furthermore, through gradient response instructions and dynamic protection operations, this method can quickly adjust protection strategies based on actual risk levels, forming an intelligent and dynamic security protection system, significantly improving the overall security and data transmission efficiency of the cloud platform payroll management system.

[0021] 3. The present invention can also achieve traceability and controllability of data transmission. By embedding a two-dimensional verification watermark into the transmitted data, it can accurately locate the data source and transmission path, thereby improving data tracking capabilities.

[0022] 4. The present invention can effectively respond to different security threat scenarios and ensure the security of data throughout the entire transmission life cycle through the dynamic update of segmented encryption rules and the key management mechanism. In addition, the method can also trigger the hierarchical protection mechanism in time when abnormal operations occur through real-time monitoring of operation steps and environmental security scores, thereby avoiding the spread of potential security threats and providing a complete data security transmission solution for the cloud platform salary management system.

[0023] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0025] Figure 1 It is a flow chart of a method for secure data transmission in a cloud platform salary management system according to an embodiment of the present invention.

[0026] Figure 2 Schematic diagram of the relationship between the environmental security score and encryption strength according to an embodiment of the present invention.

[0027] Figure 3 It is a schematic diagram of the encryption strength of the segmented encryption rule according to an embodiment of the present invention. DETAILED DESCRIPTION

[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0029] Reference Figure 1 One embodiment of the present invention proposes a method for secure data transmission in a cloud platform salary management system. It adopts dynamic segmented encryption based on a job authority matrix, an intelligent verification mechanism based on environmental security scoring, and a multi-level data control technology with a two-dimensional verification watermark. It can achieve secure classified storage, dynamic encrypted transmission, and precise traceability control of salary data.

[0030] The method of this embodiment specifically includes:

[0031] Obtaining user job attributes and authority levels to generate a job authority matrix, wherein the job attributes include job level and department association parameters;

[0032] Generate differentiated segmented encryption rules based on the position authority matrix, and use the segmented encryption rules to dynamically segment the salary data to generate encrypted data segment groups;

[0033] Obtaining current network transmission path characteristics based on a preset environmental security assessment model to generate an environmental security score; and verifying the environmental security score with the encrypted data segment group;

[0034] Specifically, the connection attributes of the current network transmission path are monitored in real time. The connection attributes include the access terminal device model, the number of network routing nodes, and the access time record. The connection attributes are input into the environmental security assessment model for multi-dimensional feature extraction. The environmental security assessment model is a pre-trained machine learning model that outputs an environmental security score between 0 and 100. The relationship between the environmental security score and the encryption strength is as follows: Figure 2 shown.

[0035] After data transmission is completed, a two-dimensional verification watermark is implanted into the encrypted data segment group to generate a controlled data packet, wherein the two-dimensional verification watermark includes a metadata fingerprint layer and an operation track record layer;

[0036] A protection strength level is generated based on the current operation steps and the environmental security score, and a gradient response instruction is generated according to the protection strength level to perform dynamic data protection operations.

[0037] Specifically, a position permission matrix is first generated based on user role attributes (such as job level and department-related parameters) and permission levels, ensuring that only users with the appropriate permissions can access specific salary data. Based on this position permission matrix, differentiated segmented encryption rules are generated. Users in different roles may use different encryption methods and strengths when accessing salary data, ensuring data protection tailored to its sensitivity. Based on these segmented encryption rules, salary data is dynamically split into multiple segments, such as base salary segments and performance-based salary segments, and each segment is encrypted separately to further enhance data security. The security of the current network environment is assessed in real time, including network connection attributes such as terminal device model, number of routing nodes, and access time records. A pre-defined environmental security assessment model is used to generate an environmental security score, which is used to dynamically adjust subsequent authentication and encryption strategies. When the environmental security score falls below a preset threshold, a more secure authentication mechanism is triggered. This involves generating a verification sequence number, dividing the data into ciphertext segments, and storing them on different authentication nodes. The authentication nodes return the ciphertext segments based on the sequence number, and then reassembling the data according to pre-defined reassembly rules for comparison to ensure the data has not been tampered with. After data transmission is completed, a two-dimensional verification watermark is embedded in the encrypted data segment group, including a metadata fingerprint layer and an operation track record layer. This not only enhances the data's traceability, but also improves the data's resistance to tampering. Based on the current operation steps and environmental security score, a protection strength level is generated, and gradient response instructions are generated according to the level to execute dynamic data protection operations. Protection strategies can be flexibly adjusted according to real-time security threat situations to effectively respond to security threats at different levels. Through multi-level data verification and dynamic adjustment mechanisms, the integrity, confidentiality, and availability of data during transmission are ensured. Each step is embedded with a corresponding security mechanism, which together constitutes a comprehensive and intelligent verification system that can monitor and respond to potential security threats in real time and ensure the secure transmission of payroll data.

[0038] Optionally, obtaining user job attributes and authority levels to generate a job authority matrix includes:

[0039] Extracting the preset department isolation coefficient and performing weighted calculation on it with the position level to generate the initial authority parameter;

[0040] Comparing the initial authority parameter with a preset salary visibility range threshold to generate an authority modification parameter;

[0041] A position authority matrix is generated according to the product operation result of the authority modification parameter and the department association parameter.

[0042] Specifically, the preset position hierarchy parameters and department association parameters are obtained, wherein the position hierarchy parameters are divided into numerical levels according to the position levels set in the organizational structure, and the department association parameters reflect the data interaction authority relationship between the target department and the current operating department; the department isolation coefficient pre-stored in the system configuration table is extracted, and the coefficient is set by the network security management department according to the confidentiality level and business collaboration needs of each department; the position hierarchy parameters and the department isolation coefficient are weighted, and the initial authority parameter P is used. initial ,have:

[0043] P initial =α·L+(1-α)·S,

[0044] Where L is the normalized value of the position hierarchy parameter, S is the normalized value of the department isolation coefficient, and α is the preset weight adjustment factor with a value range of 0.6-0.8. The calculated initial authority parameter is compared with the preset salary visibility range threshold. The salary visibility range threshold is divided into three levels according to job functions: basic salary threshold, performance salary threshold, and annual bonus threshold. When the initial authority parameter exceeds the corresponding threshold, the authority correction parameter ΔP is generated:

[0045]

[0046] Where, T k is the salary visibility range threshold corresponding to the current job category, and β is the correction coefficient; finally, the authority correction parameter and the department association parameter are multiplied to generate the job authority matrix, whose dimension is determined by the number of departments and the number of job levels.

[0047] For example, taking the salary management system of a technology company as an example, the position level parameter L of the financial director position is set to 0.9, and the department isolation coefficient S of the R&D department is set to 0.7. The R&D department has high isolation requirements. Take the weight adjustment factor α = 0.7 and calculate the initial authority parameter P initial =0.7×0.9+0.3×0.7=0.84. When the salary range threshold T corresponding to the financial position is visible k= 0.8, correction coefficient β = 0.2, and calculated permission correction parameter ΔP = (0.84 - 0.8) / 0.8 × 1.2 = 0.06. Based on the associated permission parameters of the Finance department and other departments, for example, the parameter associated with the R&D department is 0.4, the generated permission matrix element M = 0.06 × 0.4 = 0.024. The final permission value after normalization is mapped to the second-level data access permission. By dynamically calculating the position authority matrix, while ensuring the necessary data access rights of the financial director, the risk of sensitive salary information leakage across departments, especially in the R&D department, can be effectively limited. The authority correction mechanism can automatically adapt to the authority change requirements after the organizational structure is adjusted. The generation process of the position authority matrix integrates the dual factors of position characteristics and department security policies. Compared with the traditional static authority allocation method, the precision of data access can be adjusted according to the actual business scenario. Specifically, when the departmental collaboration relationship changes, the access rights of all relevant positions can be automatically updated by adjusting the department-related parameters, avoiding the inefficient operation of manual adjustment one by one. At the same time, because the generation process of the authority matrix includes multi-level threshold proofreading, it can avoid the system-level authority risk caused by a single parameter setting error.

[0048] Optionally, generating differentiated segmented encryption rules according to the position authority matrix includes:

[0049] Input the position authority matrix into a preset encryption strategy allocation model to obtain a basic encryption mode;

[0050] Detecting the salary data field type and performing similarity matching on the basic encryption mode, and determining the segmentation node based on the matching result;

[0051] generating a node key distribution scheme according to the segment nodes, wherein the node key distribution scheme includes a key generation algorithm and a key update period parameter;

[0052] According to the node key distribution scheme of each segment node, a segment encryption rule is formed.

[0053] Specifically, the position authority matrix is input into the encryption strategy allocation model. The encryption strategy allocation model is a preset computing network with a three-layer neural structure. The input layer receives the parameters of each dimension of the position authority matrix, the hidden layer performs feature fusion operations, and the output layer generates a parameter set containing the encryption strength level and key type. The basic encryption mode identifier in the parameter set is extracted. The identifier corresponds to a specific encryption algorithm combination. The types of the currently transmitted salary data fields are detected, including the basic salary field, performance bonus field, and equity incentive field. The metadata features of each field are matched with the basic encryption mode for similarity. The similarity matching formula is:

[0054]

[0055] Among them, M i Represents the similarity value, W j represents the jth feature weight in the basic encryption mode, F ij Represents the jth metadata feature value of the i-th salary field; when the similarity exceeds the preset matching threshold, the start offset and end offset of the corresponding field are marked as segment nodes; based on the position distribution of all segment nodes, a key distribution scheme is generated. The scheme includes a key generation algorithm and key update cycle parameters independently configured for each data segment, ultimately forming a segmented encryption rule.

[0056] For example, taking the salary transmission scenario of a financial institution as an example, the R&D director position authority matrix [0.85, 0.6, 0.3] is input into the encryption strategy allocation model, and the encryption parameter set {AES-256, dual key rotation, 24-hour update} is output after the model operation. The transmission data is detected to contain a basic salary field (type code 01), a performance bonus field (type code 03) and an equity incentive field (type code 05). The similarity of the basic salary field is calculated as M1=0.92, the performance bonus field M2=0.76, and the equity incentive field M3=0.58, with a preset threshold of 0.7. The basic salary field and the performance bonus field are determined to be valid segment nodes, located at bytes 128-512 and bytes 1024-2048 of the data packet respectively. AES-256 dual key rotation encryption is configured for the basic salary segment, RSA-2048 encryption is configured for the performance bonus segment and is bound to the employee's work number, and the equity incentive segment remains transmitted in the original text. The encryption strength of the segment position is as follows: Figure 3 As shown. The generated segmented encryption rule file contains the above-mentioned segmentation location, encryption algorithm and key management strategy. By combining the dual analysis of job authority characteristics and data field types, adaptive encryption strategies are formulated according to the sensitivity of salary data, especially focusing on the protection of highly sensitive basic salary and performance data, while appropriately reducing the protection intensity of low-risk equity incentive data, optimizing system resource consumption while ensuring security. The deep involvement of the job authority matrix makes the encryption strategy strictly correspond to the corporate organizational structure. For example, since the R&D director has cross-departmental management authority, his encryption rules take into account the risk of internal unauthorized use while preventing external attacks. Compared with the traditional unified encryption method, this method can effectively limit the scope of impact when encountering local data leaks. Even if the attacker cracks the encryption of a single data segment, he cannot obtain complete salary information.

[0057] Optionally, the dynamically segmenting the salary data using the segment encryption rule to generate encrypted data segment groups includes:

[0058] Splitting the salary data into basic salary segments and performance salary segments according to the segmentation nodes;

[0059] Calling the basic encryption mode to perform dual-key rotation encryption on the basic salary segment to generate a first encrypted segment;

[0060] Using the pre-acquired employee ID, the performance salary segment is subjected to obfuscated encoding processing to generate a second encrypted segment;

[0061] The first encrypted segment and the second encrypted segment are combined into an encrypted data segment group according to a preset arrangement rule.

[0062] Specifically, the original salary data stream is binary parsed according to the segmentation node, and the segmentation node contains the starting offset and data segment length parameters; the preset byte splitting algorithm is used to divide the salary data into basic salary segments and performance salary segments, where the basic salary segment contains fixed salary and statutory welfare data, and the performance salary segment contains performance appraisal bonus and project commission data; the dual-key rotation encryption method defined in the basic encryption mode is called, and the method encrypts the basic salary segment by alternating between two sets of independently generated AES keys, and the key rotation time interval is determined by the key update cycle parameter output by the encryption strategy allocation model; the employee number obfuscation algorithm is executed on the performance salary segment, and the algorithm converts the employee number into an eight-bit binary sequence and performs an XOR operation with the original data to generate an intermediate obfuscation code, and then inputs the intermediate obfuscation code into the RSA encryption module to generate the encrypted performance data segment; the encrypted basic salary segment and performance salary segment are combined according to the preset arrangement rule, and the arrangement rule uses an alternating substitution method to insert a check code at the end of each encrypted data segment, and finally forms an encrypted data segment group with a complete structure.

[0063] For example, for a multinational company's payroll data transmission, the original payroll data packet (total length 4096 bytes) was split. Based on the segment node definition, bytes 0-1023 were assigned to the base pay segment (including basic salary and social security data), while bytes 1024-4095 were assigned to the performance pay segment (including quarterly bonuses and project share). Dual-key rotation encryption was enabled for the base pay segment: AES-256 keys K1 = 0x3f7d... and K2 = 0x9a2b... were generated. Odd-numbered blocks (512 bytes each) were encrypted using K1, while even-numbered blocks were encrypted using K2. The K1 / K2 combination was automatically updated every 24 hours via the key management system. Employee ID obfuscation encryption is performed on the performance-based salary segment: The employee ID (210035) is converted to binary 001000010000001100110101; the binary code is then bit-by-bit XORed with the first 24 bytes of the performance data; the XOR result is input into the RSA-2048 encryption module (public key modulus N = 0xabcd...) to generate the final ciphertext. When assembling the encrypted data segments, the CRC32 checksum 0x78d54e3a is added to the end of the basic salary segment, and the SHA-256 digest value 0xb5a2... is added to the end of the performance-based salary segment, forming a 4128-byte encrypted data segment. By implementing a differentiated encryption strategy, the basic salary data utilizes a dynamically rotating dual-key mechanism, effectively preventing the risk of brute-force attacks caused by long-term key fixation. Furthermore, performance data is encrypted using identity obfuscation based on employee characteristics, ensuring that even bonus payment records of the same amount will produce completely different ciphertext forms depending on the employee ID, significantly enhancing the data's resistance to analysis. The verification information added during segment combination provides a technical basis for subsequent data transmission integrity verification. The protection measures of different encryption segments form multiple security barriers, making it difficult for attackers to obtain complete salary information through a single cracking method. Especially when dealing with the complex salary structure of multinational companies, this technical solution can adaptively adjust the encryption granularity to strike a balance between security protection and system performance.

[0064] Optionally, the verifying using the environmental security score and the encrypted data segment group includes:

[0065] When the environmental safety score is lower than a preset first threshold, generating a verification serial number;

[0066] Dividing the encrypted data segment group corresponding to different employees into multiple ciphertext segments and storing them in different verification nodes in a preset verification node group; the verification nodes in the verification node group return corresponding ciphertext segments according to the verification sequence number;

[0067] Arrange and combine the ciphertext fragments returned by each verification node according to the preset recombination rules to obtain a standard sequence;

[0068] The standard sequence is compared and matched with a preset template. When the matching result meets the preset requirements, an access authorization token is generated and the segment encryption rule is updated.

[0069] Specifically, when it is detected that the environmental security score is lower than a preset first threshold, an activation instruction is sent to the distributed verification node management system, which includes more than three verification servers deployed in different geographical areas; three nodes are randomly selected from the activated verification node group to generate a verification serial number, and each node stores a pre-divided ciphertext fragment, which is a redundant encryption block generated during the salary data encryption process and has a unique location identifier; a challenge request data packet containing the verification serial number is constructed, and a data retrieval instruction is sent to the selected verification node; after receiving the ciphertext fragments returned by each node, they are arranged and combined according to the preset reorganization rules, and the reorganization rules require that the ciphertext fragments be arranged in ascending order according to the hash value of the position identifier; if the combined data block matches the pre-stored standard verification template and meets the set requirements, an access authorization token is generated and the key parameters of the segmented encryption rule are updated.

[0070] For example, when a company employee attempts to access the payroll system from an external network, he or she uses a home network (with 8 routing nodes) at 22:35. The calculated environmental security score is 62 points (the first threshold is 65 points). The three verification nodes located in Beijing, Shanghai, and Guangzhou are activated, generating the verification sequence number BJ-SH-GZ-0822. The Beijing node returns a ciphertext fragment with the location identifier 0xA1 (length 128 bytes), the Shanghai node returns a fragment 0xB3 (96 bytes), and the Guangzhou node returns a fragment 0xC5 (64 bytes). According to the hash value sorting rule, 0xA1 (1865), 0xB3 (2543), and 0xC5 (3921) are combined into a standard sequence. The combined 288 bytes of data are compared with the preset template. When the match reaches 92%, an access token with a validity period of 30 minutes is generated. The key parameters of the segmented encryption rule are updated based on the verification characteristics of this time, such as updating the RSA key length of the performance segment to 3072 bits. By triggering a distributed verification mechanism in a low-security environment, it effectively resists the attempts of man-in-the-middle attackers to forge a single node. This requires attackers to simultaneously compromise multiple geographically distributed verification nodes in order to obtain complete verification information, significantly increasing the cost of the attack. The decentralized storage of ciphertext fragments, combined with dynamic reorganization rules, makes the challenge content generated by each verification request unpredictable, effectively preventing replay attacks. The encryption rule update mechanism after successful verification can dynamically adjust the protection strength based on real-time risks, forming a continuously evolving security protection system. In particular, when responding to external access by employees during non-normal working hours, the system can not only protect the urgent business needs of legitimate users, but also promptly curb potential risks through dynamically upgraded protection strategies.

[0071] Optionally, updating the segment encryption rule includes:

[0072] Extracting the position feature of the verification node to generate a dynamic key obfuscation parameter;

[0073] The dynamic key obfuscation parameter is superimposed on the key distribution scheme of the segmented encryption rule to generate a new segmented encryption rule including timestamp verification.

[0074] Specifically, location feature parameters are extracted from each verification node. The parameters may include the geographic location of the node, the geographic location information of the IP address, the network identifier, etc. For example, one verification node may be located in Beijing with a location feature code of "BJ123456", and another may be located in Shanghai with a feature code of "SH678901". The extracted location feature parameters are processed by a preset algorithm to generate dynamic key obfuscation parameters. For example, a hash function (such as SHA-256) is used to calculate the location feature code to generate a segment of obfuscation parameters. Assuming that the extracted location feature parameters are "BJ123456" and "SH678901", the obfuscation parameters obtained by hash calculation are "0xabcdef12" and "0x34567890". The generated dynamic key obfuscation parameters are combined with the original key distribution scheme, for example, by performing an exclusive OR operation (XOR) on the original key. For example, assuming the original base key is "0x1234abcd," the dynamic key obfuscation parameter "0xabcdef12" is used in an XOR operation to generate the new key "0x1234abcdXOR0xabcdef12." A new key distribution scheme is generated for each segment node, and an enhanced timestamp verification mechanism is embedded within it. For example, a timestamp verification field is added to the original encryption policy to ensure that data packets have not been tampered with or delayed during transmission. New segment encryption rules are generated and replaced with the old ones.

[0075] By triggering encryption rule updates when the environment's security score is low, it effectively addresses potential threats in low-security environments. Dynamically extracting verification node location features, combined with generated obfuscation parameters, significantly increases the diversity of encryption rules, making it difficult for attackers to obtain all data using a single key. Furthermore, an enhanced timestamp verification mechanism ensures data integrity during transmission, reducing the risk of data tampering. The entire update process is efficient and automated, ensuring the system's real-time security protection capabilities and safeguarding the secure transmission of payroll data.

[0076] Optionally, the step of implanting a two-dimensional verification watermark into the encrypted data segment group to generate a controlled data packet after the data transmission is completed includes:

[0077] Extract the hardware fingerprint of the current operating terminal to generate a metadata fingerprint layer;

[0078] Record the operation steps in the data transmission process and generate the operation trace record layer by hash value;

[0079] The metadata fingerprint layer and the operation trace record layer are alternately embedded in the encrypted data segment group to generate a controlled data packet.

[0080] Specifically, a hardware fingerprint set is generated by reading the motherboard serial number and MAC address of the current operating terminal. The hardware fingerprint set is processed through a preset hash algorithm to generate a 32-bit hexadecimal metadata fingerprint layer. During the data transmission process, the timestamp and operation type code of each operation step are recorded, and the continuous operation step records are input into the SHA-1 hash function to generate an operation trace record layer. A three-dimensional embedding template is constructed, with the first dimension of the template marked as the metadata fingerprint layer distribution area, the second dimension set as the operation trace record layer distribution area, and the third dimension reserved as the extended check area. The metadata fingerprint layer and the operation trace record layer are alternately written into the embedding template using an interleaved nesting algorithm, where the alternation pattern is determined by a preset prime number sequence. The first prime number of the prime number sequence determines the metadata writing starting position, and subsequent prime numbers determine the alternation interval. For the byte stream of each encrypted data segment group, the second, seventh, and fifteenth bytes of every 16 bytes are selected as watermark carrier bits according to the high-order first principle, and the watermark information in the embedded template is replaced with the carrier bits through a bit masking operation. After the replacement is completed, a redundant check code is calculated for the data packet, and the check code is written into the extended check area to form the final controlled data packet.

[0081] For example, during the watermarking process for a payroll data export operation, the operator extracted the terminal's motherboard serial number (SN = GMLC9X2KJ) and MAC address (00-1B-63-84-45-E6). The hardware information was then combined to generate the input string "GMLC9X2KJ_001B638445E6." This string was then hashed using MD5 to obtain the metadata fingerprint layer: e5d4a7503d9f41cd890d0a7b9f8c3b20. The recorded operation trace was {2023-08-22 14:30 query, 14:32 filter, 14:35 export}, generating the following operation trace hash value: sha1("1430_QRY|1432_FLT|1435_EXP") = a108f3…. The prime number sequence was set to [5, 3, 7], with the metadata starting at the fifth byte and alternating between 3 and 7 bytes. The metadata fingerprint layer character 'e5' is written into the 5th byte, the first character 'a1' of the operation trace hash is written into the 8th (5+3) byte, and subsequent characters are written into the 15th (8+7), 18th (15+3), 25th (18+7) bytes, etc. Watermark information is embedded in the lower 4 bits of the 2nd, 7th, and 15th bytes of each 16-byte unit. The CRC32 checksum 0x8A3D5F is calculated and written into the extended checksum area to complete the controlled data packet assembly. Through the dual marking mechanism of hardware characteristics and operation traces, any illegal copying or tampering of data will destroy the integrity of the watermark structure. Taking the financial director's illegal export of R&D department salary data as an example, during the audit, the terminal characteristics and specific operation time series can be quickly located by analyzing the watermark. Even if the attacker deletes or modifies part of the data content, the watermark information embedded in the dispersed carrier position can still retain key tracking clues. At the same time, the alternating embedding mode of the two-dimensional watermark increases concealment, preventing conventional data scanning tools from detecting the existence of the watermark. In addition, the embedding interval mechanism driven by prime number sequences makes the watermark distribution of different data packets different, effectively resisting tampering attacks targeting specific locations.

[0082] Optionally, the method further includes:

[0083] When a large-scale data export operation is detected, increasing the embedding depth of the operation trace recording layer;

[0084] Adding a department identification code to the metadata fingerprint layer to generate a traceability feature group;

[0085] The modified two-dimensional verification watermark is synchronously updated to all associated controlled data packets.

[0086] Specifically, the recording parameters of the data export operation are monitored in real time. The recording parameters include the data volume value and operation duration of a single export. When it is detected that the data volume value exceeds the preset batch processing threshold and the duration is shorter than the normal operation benchmark, the watermark enhancement instruction is triggered. The embedding depth parameter of the operation track recording layer is adjusted. The embedding depth parameter controls the number of bits occupied by the watermark information in each 16-byte unit, and the original 4-bit embedding depth is extended to 6 bits. The department association parameter in the current controlled data packet is extracted. The department association parameter is dynamically generated by the security relationship between the data creation department and the access department. The department association parameter and the preset organizational code are input into the hash function to generate the department identifier. The code is encoded, and the hash function uses two SHA-224 operations and takes the middle 32 bits as the output; the department identification code is split into four groups of two's complement sequences by byte and then inserted into the header area of the metadata fingerprint layer; the three-dimensional structure of the embedded template is recalculated, and a new time reference mark is appended to the extended check area. The time reference mark contains the compressed encoding of the latest operation timestamp; the updated two-dimensional verification watermark parameters are distributed to all associated controlled data packets through an asynchronous data synchronization protocol. The protocol uses a difference comparison algorithm to transmit only the changed parts to reduce network load; when performing the watermark rewrite operation on each associated data packet, an atomic transaction mechanism is used to ensure data integrity and version consistency.

[0087] For example, in a cross-departmental data audit scenario at a financial institution, monitoring an R&D administrator exporting 520MB of payroll data within 10 seconds (preset threshold: 500MB / 30 seconds) triggers watermark enhancement mode, expanding the embedded bits from 4 to 6 per 16 bytes, adding the third and ninth bytes as embedded bits. The data center department's associated parameter, 0.86, and the organization code, ORG-2023-FIN, are extracted to generate a department identification code: SHA224 (SHA224("0.86_ORG-2023-FIN")), with the middle 32 bits being 0x5f8d3a... The department identification code is then split into [5f,8d,3a,ec] and inserted into the metadata fingerprint layer header to form a new structure. The timestamp 0825T1425Z (UTC time compressed to 6 bytes) is written in the extended checksum area. Only the 5KB difference data is transmitted via an asynchronous protocol to the nine associated data packet nodes. A two-phase commit protocol is used to ensure that transactions are committed only after all nodes have successfully updated their watermarks. The three nodes that have not completed the update will automatically roll back to the last valid version and record the exception log. By dynamically increasing the watermark embedding depth, the marking strength of abnormal export operations is effectively improved to ensure that complete traceability information can still be extracted in the event of a large-scale data leak. The combination of department identification codes and time stamps can accurately distinguish between normal business collaboration and illegal data transfer. For example, when exported data is circulated between non-collaborative departments, the identification code will show the mismatch between the source department and the actual holding department. The asynchronous synchronization mechanism reduces network resource consumption while ensuring watermark consistency. The atomic transaction design avoids data version confusion caused by the failure of some nodes to update. This design is particularly suitable for multi-data center scenarios of multinational enterprises and can reliably implement security policy updates among globally distributed nodes.

[0088] Optionally, generating a protection strength level based on the current operation step and the environmental security score, and generating a gradient response instruction according to the protection strength level, and performing the dynamic data protection operation includes:

[0089] Extracting normal operation sequences that match the position authority matrix from historical operation logs to generate a baseline operation profile;

[0090] Comparing the deviation value between the current operation step and the benchmark operation profile in real time to generate risk level parameters;

[0091] Selecting a protection strength level based on the correlation between the risk level parameter and the environmental safety score, the protection strength level including level one protection, level two protection, and level three protection;

[0092] A preset response plan is called based on the protection strength level to generate a gradient response instruction.

[0093] Specifically, historical operation records within a preset time range are extracted from the system audit database. The historical operation records include operation type codes, operation time series, and data access parameters. The historical operation records are screened using the job authority matrix, and operation sequences with matching authority levels are retained to form a training data set. The training data set is input into a preset time series analysis model. The time series analysis model can use the hidden Markov algorithm to establish a normal operation mode and generate a baseline operation portrait vector group. The vector group dimension is determined by the operation type and time interval characteristics. The current user's operation step sequence is captured in real time, and the operation type code and time interval of each step are converted into an observation vector. The deviation value between the observation vector and the baseline operation portrait vector group is calculated to obtain the risk level parameter D. The deviation value calculation method uses the multi-dimensional space Euclidean distance formula:

[0094]

[0095] Among them, V obs,i Represents the current observation vector of the i-th dimension, V base,i Represents the baseline portrait vector of the i-th dimension, and n is the number of vector dimensions; obtain the environmental security score in real time and establish a protection strength selection matrix:

[0096]

[0097] Among them, L1 represents the first level of protection, L2 represents the second level of protection, L3 represents the third level of protection, T1 and T2 are deviation thresholds, E is the environmental safety score, and E h 、E m It is the scoring threshold; based on the protection strength level, the preset response plan is called to generate a gradient response instruction.

[0098] For example, a company's payroll system was subjected to internal unauthorized access. A total of 1527 normal operation records of the financial director in the past 90 days were extracted, and the hidden Markov model was trained to generate a baseline portrait vector [0.87, 0.12, 0.01], which respectively represents the frequency ratio of query, modification, and export operations; it was detected that the current user performed [query (32 times), export (8 times)] operations within half an hour, and generated an observation vector [0.80, 0.20, 0.00]. The calculated deviation value D = 0.114 is greater than the deviation threshold T2 = 0.1. The current environmental security score is 58, which is lower than E m= 60, entering L3 protection level based on the selection matrix match; invoking the sensitive field self-destruction routine to erase the performance salary data segment, generating an offline audit log file, and sending the alert code ERR_2035 to the administrator console, forcibly terminating the current session. Dynamic analysis of the temporal characteristics of operational behavior significantly improves the accuracy of identifying internal unauthorized operations. The continuous update mechanism of the baseline operation profile enables the system to adapt to changes in operating patterns caused by employee position changes. When abnormally high-frequency export operations are detected, a dual verification mechanism combined with environmental scoring effectively distinguishes between work errors and malicious operations. While ensuring the continuity of normal business processes, the gradient response mechanism implements tiered control based on risk level to avoid excessive protection from disrupting business operations. For sudden high-risk threats, the offline audit function ensures the complete preservation of key evidence, providing a reliable basis for subsequent security incident investigations.

[0099] Optionally, calling a preset response scheme based on the protection strength level to generate a gradient response instruction includes:

[0100] When the protection strength level is level one, the operation track mirror recording function is activated and the data transmission rate is limited;

[0101] When the protection strength level is level 2, a virtual data copy is created for suspicious operations to call while blocking access to the original data;

[0102] When the protection strength level is level three, the preset sensitive field self-destruction program is triggered and an offline audit report is generated.

[0103] Specifically, when the protection strength level is detected as level one, the operation trajectory mirror recording function is activated. This function creates an independent log thread to fully record the screenshot data, keyboard input events, and network packet characteristics of the current operation terminal. At the same time, the bandwidth rate of the data transmission channel is reduced to a preset safety value, which is determined by multiplying the average data processing speed of the baseline operation profile by an adjustment coefficient of 0.3. When the protection strength level is level two, the virtual data copy generation program is triggered. The program extracts non-sensitive test data from a preset simulation database to replace key fields in the original salary data to form a virtual copy. Special marking fields are attached to the virtual copy and an access behavior analysis queue is established to continuously track the execution path of suspicious operations in the virtual environment. If the protection strength level is detected as level three, the sensitive field self-destruction program is immediately activated. The program identifies the basic salary segment, bonus calculation segment, and other additional benefit segments in the salary data based on data classification characteristics. A segment-by-segment erasure algorithm is used to perform physical overwrite operations on each data segment. The number of overwrite rounds is positively correlated with the percentage of deviation values exceeding the threshold. After the overwrite is completed, an offline audit report containing the erasure time stamp, residual data characteristics, and operation terminal information is generated and transmitted to the preset secure storage node via an encrypted channel.

[0104] For example, during a certain internal violation, it was detected that the query operation frequency of the payroll specialist was abnormal, the protection strength level was level one, the mirror recording function was activated, the screen image was captured every second and the keyboard input was recorded, and the data download rate was limited to 50KB / s (the original rate was 1.5MB / s); it was subsequently discovered that the user tried to export the department manager's salary data, the deviation value increased, the protection strength level was changed to level two, a virtual copy was generated, the real employee name was replaced with a simulated name, the basic salary field was set to a uniform value, and the virtual data packet marker feature code 0xDEADBEEF was used for behavior tracking; the user continued to try to crack the virtual data export restriction, the deviation value increased again, the protection strength level was upgraded to level three, the self-destruct program was triggered, the basic salary segment was covered 3 times, the performance data segment was covered 5 times, an offline audit report was generated, the erasure time 2023-09-15T14:22:35 and the terminal device code were recorded, and the report was encrypted and transmitted to the Beijing data center storage node via the TLS1.3 protocol. The stepped design of the three-level response mechanism achieves a balance between security protection and evidence retention. Bandwidth limitation in the initial stage increases the attacker's time cost without interrupting normal business. The deployment of virtual copies effectively misleads illegal operators and collects evidence of attack methods. Physical erasure in the final stage ensures that sensitive information is irrecoverable. The independent storage mechanism of offline audit reports prevents attackers from destroying local logs. For malicious personnel with internal system knowledge, this solution forms an effective deterrent through step-by-step protection measures and completes emergency response without interrupting the overall system operation.

[0105] It should be noted that the formulas appearing above can translate physical quantities of different properties into unitless standard values or superimposable parameters of the same dimension through the principle of dimensional consistency and mathematical standardization means (such as normalization, dimensionless parameter conversion or unit system unification), thereby eliminating the interference of different dimensions on the operation logic, so that the formulas have mathematical operation rationality and objective law adaptability while retaining the distribution characteristics of the original data. It is a conventional technical means and will not be elaborated here. The electrical connection between the above-mentioned units does not necessarily mean a direct connection of the circuit. The indirect connection method can be applied to the embodiments of the present invention as long as the purpose of the present invention is achieved. The above is only an exemplary embodiment of the present invention and the scope of the present invention cannot be limited thereto.

[0106] That is, any equivalent changes and modifications made according to the teachings of the present invention are still within the scope of the present invention. Those skilled in the art will readily conceive of other embodiments of the present invention after considering the disclosure of the specification and practice. This application is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of the present invention and include common knowledge or customary techniques in the art not described herein.

Claims

1. A method for secure data transmission in a cloud platform salary management system, characterized in that: The method comprises: Obtaining user job attributes and authority levels to generate a job authority matrix, wherein the job attributes include job level and department association parameters; Generating differentiated segmented encryption rules according to the position authority matrix, and using the segmented encryption rules to dynamically segment the salary data to generate encrypted data segment groups; Obtaining current network transmission path characteristics based on a preset environmental security assessment model to generate an environmental security score; and verifying the environmental security score with the encrypted data segment group; After data transmission is completed, a two-dimensional verification watermark is implanted into the encrypted data segment group to generate a controlled data packet, wherein the two-dimensional verification watermark includes a metadata fingerprint layer and an operation track record layer; A protection strength level is generated based on the current operation steps and the environmental security score, and a gradient response instruction is generated according to the protection strength level to perform dynamic data protection operations.

2. A method for secure data transmission in a cloud platform salary management system according to claim 1, characterized in that: The step of obtaining user job attributes and authority levels to generate a job authority matrix includes: Extracting the preset department isolation coefficient and performing weighted calculation on it with the position level to generate the initial authority parameter; Comparing the initial authority parameter with a preset salary visibility range threshold to generate an authority modification parameter; A position authority matrix is generated according to the product operation result of the authority modification parameter and the department association parameter.

3. A method for secure data transmission in a cloud platform salary management system according to claim 1, characterized in that: The generating of differentiated segmented encryption rules according to the position authority matrix includes: Input the position authority matrix into a preset encryption strategy allocation model to obtain a basic encryption mode; Detecting the salary data field type and performing similarity matching on the basic encryption mode, and determining the segmentation node based on the matching result; generating a node key distribution scheme according to the segment nodes, wherein the node key distribution scheme includes a key generation algorithm and a key update period parameter; According to the node key distribution scheme of each segment node, a segment encryption rule is formed.

4. A method for secure data transmission in a cloud platform salary management system according to claim 3, characterized in that: The dynamically slicing the salary data using the segment encryption rule to generate encrypted data segment groups includes: Splitting the salary data into basic salary segments and performance salary segments according to the segmentation nodes; Calling the basic encryption mode to perform dual-key rotation encryption on the basic salary segment to generate a first encrypted segment; Using the pre-acquired employee ID, the performance salary segment is subjected to obfuscated encoding processing to generate a second encrypted segment; The first encrypted segment and the second encrypted segment are combined into an encrypted data segment group according to a preset arrangement rule.

5. The method for secure data transmission in a cloud platform salary management system according to claim 1, characterized in that: The verification using the environmental security score and the encrypted data segment group includes: When the environmental safety score is lower than a preset first threshold, generating a verification serial number; Dividing the encrypted data segment group corresponding to different employees into multiple ciphertext segments and storing them in different verification nodes in a preset verification node group; the verification nodes in the verification node group return corresponding ciphertext segments according to the verification sequence number; Arrange and combine the ciphertext fragments returned by each verification node according to the preset recombination rules to obtain a standard sequence; The standard sequence is compared and matched with a preset template. When the matching result meets the preset requirements, an access authorization token is generated and the segment encryption rule is updated.

6. A method for secure data transmission in a cloud platform salary management system according to claim 5, characterized in that: Said updating of said segment encryption rule comprises: Extracting the position feature of the verification node to generate a dynamic key obfuscation parameter; The dynamic key obfuscation parameter is superimposed on the key distribution scheme of the segmented encryption rule to generate a new segmented encryption rule including timestamp verification.

7. The method for secure data transmission in a cloud platform salary management system according to claim 1, characterized in that: The step of implanting a two-dimensional verification watermark into the encrypted data segment group to generate a controlled data packet after data transmission is completed comprises: Extract the hardware fingerprint of the current operating terminal to generate a metadata fingerprint layer; Record the operation steps in the data transmission process and generate the operation trace record layer by hash value; The metadata fingerprint layer and the operation trace record layer are alternately embedded in the encrypted data segment group to generate a controlled data packet.

8. A method for secure data transmission in a cloud platform salary management system according to claim 7, characterized in that: The method further comprises: When a large-scale data export operation is detected, increasing the embedding depth of the operation trace recording layer; Adding a department identification code to the metadata fingerprint layer to generate a traceability feature group; The modified two-dimensional verification watermark is synchronously updated to all associated controlled data packets.

9. The method for secure data transmission in a cloud platform salary management system according to claim 1, characterized in that: Generating a protection strength level based on the current operation step and the environmental security score, and generating a gradient response instruction according to the protection strength level, and performing a dynamic data protection operation include: Extracting normal operation sequences that match the position authority matrix from historical operation logs to generate a baseline operation profile; Comparing the deviation value between the current operation step and the benchmark operation profile in real time to generate risk level parameters; Selecting a protection strength level based on the correlation between the risk level parameter and the environmental safety score, the protection strength level including level one protection, level two protection, and level three protection; A preset response plan is called based on the protection strength level to generate a gradient response instruction.

10. A method for secure data transmission in a cloud platform salary management system according to claim 9, characterized in that: The calling of a preset response scheme based on the protection strength level to generate a gradient response instruction includes: When the protection strength level is level one, the operation track mirror recording function is activated and the data transmission rate is limited; When the protection strength level is level 2, a virtual data copy is created for suspicious operations to call while blocking access to the original data; When the protection strength level is level three, the preset sensitive field self-destruction program is triggered and an offline audit report is generated.

Citation Information

Cited By

  • Data security transmission method based on digital archive multi-protection

    CN120880802A

  • A data security transmission method based on digital archive multi-protection

    CN120880802B

  • Data access management method and system based on block chain

    CN121077791A

  • Power grid network data security management system

    CN121261918A