Data security protection method for business and financial collaborative management system
By adopting hierarchical encryption and real-time behavior evaluation methods in the business and finance collaborative management system, the problem of insufficient data security in traditional systems is solved, and refined data control and flexible access management are realized, enhancing the security and collaboration capabilities of the system.
Patent Information
- Application Number
- CN202510578814.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-08-19
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In traditional business finance collaborative management systems, data security relies on static permission allocation and basic encryption measures, making it difficult to deal with complex and changing internal collaboration needs and external threats, and lacks real-time monitoring and risk assessment of user behavior, making it difficult to detect and deal with potential security threats in a timely manner.
The encryption module is used for hierarchical management, combining user management, permission management, key generation, access audit and behavior evaluation modules, and dynamically adjust access permissions and timeliness to achieve differentiated encryption and refined control of data through real-time evaluation of user behavior.
It has achieved the security of high-sensitive data and the access efficiency of low-sensitive data, ensuring the security and flexibility of data in multi-person collaboration scenarios, timely discover abnormal access behaviors, and reducing security threats.
Smart Images

Figure CN120509047A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of security protection and authority management of business and financial systems, and in particular to a data security protection method for a business and financial collaborative management system. Background Art
[0002] With the acceleration of enterprise digital transformation, the security and compliance of financial data, as one of the core assets, have become important issues in enterprise management. In traditional business-finance collaboration management systems, data security often relies on static permission allocation and basic encryption measures, which are difficult to cope with the complex and changing internal collaboration needs and external threats. For example, sensitive data may be at risk due to permission abuse, internal leaks, or external attacks. At the same time, when collaborating across departments, how to ensure that data remains secure while being shared and avoid unauthorized access is also a problem that needs to be solved in the current system. In addition, the lack of a mechanism for real-time monitoring of user behavior and risk assessment makes it difficult to detect and address potential security threats in a timely manner.
[0003] After searching, the application scheme of Chinese patent application number CN202510343533.8 discloses a financial data security management system and method, including a data monitoring module, a vulnerability prediction module, a dynamic isolation module, a behavior analysis module, and a security response module. In the present invention, through in-depth monitoring and analysis of financial data, the ability to identify and handle abnormal operations is improved, thereby enhancing data security. By collecting financial transactions and account behavior data in real time, the frequency of capital flows and account access frequencies are carefully analyzed, and risks are effectively identified and potential security vulnerabilities are predicted. By dynamically analyzing the association between transaction nodes and risk events, the risk level is evaluated, and the data storage location and access rights are automatically adjusted according to the risk assessment. The financial data security management system in the above patent has the following deficiencies: although it has the ability to manage security, it lacks a mechanism for dynamic adjustment of users, and the management mechanism for data access is not yet perfect. Summary of the Invention
[0004] The purpose of the present invention is to solve the shortcomings of the existing technology and to propose a data security protection method for a business-finance collaborative management system.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] A data security protection method for a business-finance collaborative management system is implemented based on a data security protection system, the system comprising:
[0007] Encryption module: The encryption module manages data in different levels according to the sensitivity of the data, forming encrypted data of different levels;
[0008] Classification module, the classification module classifies the encrypted data according to the type of original data;
[0009] User management module, which is used to store user account information;
[0010] The authority management module is used to manage the authority allocation of user accounts;
[0011] The key generation module generates a corresponding key for each user account based on the user account's permissions;
[0012] Access audit module, which is used to audit the access information and key information of user accounts and determine whether to allow access based on the audit results;
[0013] Behavior assessment module: The behavior assessment module evaluates the behavior of user accounts in real time and conducts risk value assessment;
[0014] The recording module is used to store access record information.
[0015] Preferably: the encryption module manages the data in a hierarchical manner according to the sensitivity of the data, and performs corresponding encryption processing on each level of data to form encrypted data of different levels; the user management module divides each user account into corresponding levels according to preset rules; the key generation module generates an access key of the corresponding level for the user account of the corresponding level.
[0016] Preferably: the classification module divides the encrypted data into shared access data and individual access data according to the type of data. The individual access data can be accessed based on the secret key of a single user account; the shared access data can only be accessed when all user accounts within a preset user range jointly initiate an access request based on the access secret key.
[0017] Preferably, the user management module adds a category code and a group code to each user account, and the classification module adds category codes and group codes according to user accounts when classifying data, and defines a user range for access users who jointly access data.
[0018] Preferably: in the system, a user account can generate a temporary key with the same or lower authority level based on its own key authority, and each user account is saved with a time limit point. When a user account generates a temporary key, a temporary access time limit is added to the temporary key based on the time limit point. Other user accounts can access encrypted data of the corresponding level within the set temporary access time limit based on the shared temporary key; when jointly accessing data, the temporary key can temporarily replace the key of the corresponding user account, but the participation ratio of the temporary key cannot exceed the preset value.
[0019] Preferably: in the system, when a user account accesses encrypted data based on a shared temporary key, the system's behavior assessment module evaluates the access behavior of the user account in real time. When the risk value of the access behavior reaches a set warning value, the temporary access time limit is accelerated at a set rate; when the risk value reaches a warning value, the temporary access time limit is terminated.
[0020] Preferably, in the system, when a user account obtains a temporary key, it can generate a temporary subkey of a lower level based on the current temporary key, and the temporary access validity of the generated temporary subkey decreases level by level.
[0021] Preferably, in the system, when the temporary access validity period of the temporary key obtained by the user expires, the user management module adjusts the validity score of the user account that generated the temporary key according to preset rules based on the risk value assessed by the behavior assessment module.
[0022] Preferably, when performing an assessment, the behavior assessment module integrates user operation logs, device fingerprints, network environment, and time characteristics to construct a risk scoring model.
[0023] Preferably: the temporary key time attenuation coefficient is dynamically adjusted according to the risk value. When the user continuously triggers the warning value more than the set number of times within the set time, the system automatically freezes the key generation authority and triggers manual review.
[0024] The beneficial effects of the present invention are:
[0025] 1. The present invention implements hierarchical management according to the sensitivity of data through encryption modules, realizing differentiated encryption processing of data of different levels, which not only ensures the security of highly sensitive data, but also improves the access efficiency of low-sensitivity data, and realizes refined control of data protection.
[0026] 2. The user management module of the present invention is combined with the permission management module to assign an appropriate permission level to each user account, and the key generation module independently generates the corresponding access key, ensuring the precise matching and isolation of permissions; based on the temporary key generation mechanism, users are allowed to share data access rights when necessary. At the same time, through the design of time limit points and temporary access time limit, the temporariness and scope of permissions are effectively controlled, thereby enhancing the flexibility and security of data sharing.
[0027] 3. The behavior assessment module of the present invention monitors user behavior in real time and builds a risk scoring model based on multi-dimensional information such as operation logs, device fingerprints, and network environment. It can promptly detect and respond to abnormal access behavior. When the risk value of access behavior reaches the warning or alert value, the system automatically adjusts the temporary access time limit or even terminates the access, effectively reducing potential security threats.
[0028] 4. The classification module of the present invention divides encrypted data into jointly accessed data and individually accessed data. For jointly accessed data, users within a preset range are required to jointly submit access requests. Through strict review by the access review module, secure access to data in multi-person collaborative scenarios is ensured, which not only meets business needs, but also facilitates mutual supervision and avoids the risk of data leakage.
[0029] 5. This invention encourages users to use temporary keys reasonably through the design of time-based points. At the same time, the time-based points are dynamically adjusted according to the risk assessment results of user behavior. This not only encourages good behavior but also effectively punishes bad behavior, forming a positive security management cycle.
[0030] 6. The time-attenuation mechanism of the temporary key and its subkeys in the present invention, combined with the dynamic adjustment of the risk value, makes the key validity period more in line with actual security requirements, ensuring the immediate security of data while avoiding the security risks that may be caused by the long-term validity of the key. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 This is a flow chart of the timeliness adjustment in the data security protection method for the business-finance collaborative management system proposed by the present invention;
[0032] Figure 2 The present invention provides a flowchart for accessing jointly reviewed data in a data security protection method for a business-finance collaborative management system. DETAILED DESCRIPTION
[0033] The technical solution of the present invention will be further described in detail below in conjunction with specific implementation methods.
[0034] Example 1:
[0035] A data security protection method for a business-finance collaborative management system is implemented based on a data security protection system, the system comprising:
[0036] Encryption module: The encryption module manages data in different levels according to the sensitivity of the data, forming encrypted data of different levels;
[0037] Classification module, the classification module classifies the encrypted data according to the type of original data;
[0038] User management module, which is used to store user account information;
[0039] The authority management module is used to manage the authority allocation of user accounts;
[0040] The key generation module generates a corresponding key for each user account based on the user account's permissions;
[0041] Access audit module, which is used to audit the access information and key information of user accounts and determine whether to allow access based on the audit results;
[0042] Behavior assessment module: The behavior assessment module evaluates the behavior of user accounts in real time and conducts risk value assessment;
[0043] The recording module is used to store information such as access records.
[0044] Among them, the encryption module manages data in a hierarchical manner according to the sensitivity of the data, and performs corresponding encryption processing on each level of data to form encrypted data of different levels; the user management module divides each user account into corresponding levels according to preset rules; the key generation module generates the corresponding level of access key for the user account of the corresponding level.
[0045] Among them, the classification module divides the encrypted data into shared access data and individual access data according to the type of data. Individual access data can be accessed based on the secret key of a single user account; shared access data requires that all user accounts within a preset user range jointly initiate an access request based on the access secret key before the shared access data can be accessed.
[0046] Among them, the user management module adds a category code and a group code for each user account. When the classification module classifies data, it adds a category code and a group code according to the user account and defines the user range for access users who jointly access data.
[0047] In the system, a user account can generate a temporary key with the same or lower permission level based on its own key authority. Each user account stores a time limit point. When a user account generates a temporary key, a temporary access time limit is added to the temporary key based on the time limit point. Other user accounts can access encrypted data of the corresponding level within the set temporary access time limit based on the shared temporary key; when jointly accessing data, the temporary key can temporarily replace the key of the corresponding user account, but the participation ratio of the temporary key cannot exceed the preset value.
[0048] Among them, when a user account accesses encrypted data based on a shared temporary key, the system's behavior assessment module evaluates the access behavior of the user account in real time. When the risk value of the access behavior reaches the set warning value, the temporary access time limit is accelerated according to the set rate; when the risk value reaches the warning value, the temporary access time limit is terminated.
[0049] In the system, when a user account obtains a temporary secret key, it can generate a temporary subkey of a lower level based on the current temporary secret key, and the temporary access validity of the generated temporary subkey decreases step by step; for example, the levels of user accounts from low to high are Q1, Q2, Q3, ..., Q n Level, the corresponding key levels are M1, M2, M3, ..., M n Level, Q i Level user account, can generate M i 、M i-1 , ..., M1-level temporary secret key; suppose user account A generates M i The temporary key of the level is divided into time points. The temporary access time of the temporary key is S=60min. Another shared user account B obtains the temporary key and can access it based on the M i The temporary secret key of the level is generated M i-1 、M i-2 , ..., M1 level temporary sub-key, the temporary access time limit of the temporary sub-key is S / K=60 / Kmin, where K is the attenuation coefficient, for example K=2.
[0050] In the system, when the temporary access validity period of the temporary key obtained by the user expires, the user management module adjusts the validity score of the user account that generated the temporary key according to the preset rules based on the risk value assessed by the behavior assessment module.
[0051] For example, when the temporary access period of the temporary key obtained by the shared user account B expires, the assessed risk value is Z B , when Z B When it is greater than the set warning value P1, or greater than the set alert value P2, where P1 < P2, the timeliness score is reduced. If Z B When <P1, additional points will be added to the aging score, and the adjustment of the aging score shall not exceed the upper and lower limits.
[0052] In addition, if there is a shared user account C, when the temporary access period of the temporary sub-key is over, the evaluated risk value is Z C , when Z C When it is greater than the set warning value P1, or greater than the set alert value P2, where P1 < P2, the timeliness score is reduced. If Z C When <P1, the timeliness score is added. When the score is reduced or added due to the use of the temporary subkey, the magnitude of the reduction or addition is also attenuated based on the attenuation coefficient K.
[0053] Among them, when conducting an assessment, the behavior assessment module integrates user operation logs, device fingerprints, network environment (such as IP address anomalies), and time characteristics (such as non-working hours access) to build a risk scoring model.
[0054] Among them, the temporary key time attenuation coefficient (K) is dynamically adjusted according to the risk value. For example, the user who triggers the warning value (P2) is a high-risk user and is attenuated according to K=3. The user who triggers the warning value (P1) is a low-risk user and is attenuated according to K=2.
[0055] When a user continuously triggers the warning value (P2) more than the set number of times within the set time, the system automatically freezes his key generation permission and triggers manual review.
[0056] The data security protection method, when adjusting the timeliness points, includes the following steps:
[0057] S1: The user account generates a temporary key with the same or lower permission level based on its own key permissions;
[0058] S2: When generating a temporary key, a temporary access time limit is added to the temporary key based on the time limit.
[0059] S3: Other user accounts obtain the temporary key;
[0060] S4: Access the corresponding level of encrypted data within the set temporary access time based on the shared temporary key;
[0061] S5: The behavior assessment module evaluates the access behavior of the user account in real time;
[0062] S6: When the temporary access time limit expires, the user management module adjusts the time limit score of the user account that generated the temporary key according to the preset rules based on the risk value assessed by the behavior assessment module.
[0063] The data security protection method, when accessing the shared data, includes the following steps:
[0064] S11: The encryption module manages data in different levels according to its sensitivity.
[0065] S12: The classification module classifies the encrypted data according to the type of data;
[0066] S13: For the common reference data that needs to be accessed, a user account with a corresponding category code or group code submits a reference request;
[0067] S14: Other user accounts with the same category code or group code jointly submit a request for access;
[0068] S15: The access audit module audits the secret key and temporary secret key owned by the user account that submitted the request. If the audit passes, the process proceeds to step S16; otherwise, the process proceeds to step S17.
[0069] S16: Access is allowed;
[0070] S17: Request dismissed.
[0071] The above description is only a preferred specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the technical field, within the technical scope disclosed by the present invention, who makes equivalent replacements or changes based on the technical solution and inventive concept of the present invention, should be covered by the scope of protection of the present invention.
Claims
1. A data security protection method for a business-finance collaborative management system, characterized in that: It is based on a data security protection system, which includes: Encryption module: The encryption module manages data in different levels according to the sensitivity of the data, forming encrypted data of different levels; Classification module, the classification module classifies the encrypted data according to the type of original data; User management module, which is used to store user account information; The authority management module is used to manage the authority allocation of user accounts; The key generation module generates a corresponding key for each user account based on the user account's permissions; Access audit module, which is used to audit the access information and key information of user accounts and determine whether to allow access based on the audit results; Behavior assessment module: The behavior assessment module evaluates the behavior of user accounts in real time and conducts risk value assessment; The recording module is used to store access record information.
2. A data security protection method for a business-finance collaborative management system according to claim 1, characterized in that: The encryption module manages data in different levels according to the sensitivity of the data, and performs corresponding encryption processing on each level of data to form encrypted data of different levels; the user management module divides each user account into corresponding levels according to preset rules; The key generation module generates access keys of corresponding levels for user accounts of corresponding levels.
3. The data security protection method for a business-finance collaborative management system according to claim 2 is characterized in that: The classification module divides the encrypted data into shared access data and individual access data according to the type of data. Individual access data can be accessed based on the secret key of a single user account; shared access data can only be accessed when all user accounts within a preset user range jointly initiate an access request based on the access secret key.
4. A data security protection method for a business-finance collaborative management system according to claim 3, characterized in that: The user management module adds a category code and a group code to each user account. When classifying data, the classification module adds category codes and group codes according to the user accounts and defines the user range for access users who jointly access data.
5. A data security protection method for a business-finance collaborative management system according to claim 4, characterized in that: In the system, a user account can generate a temporary key with the same or lower permission level based on its own key authority. Each user account stores a time limit point. When a user account generates a temporary key, a temporary access time limit is added to the temporary key based on the time limit point. Other user accounts can access encrypted data of the corresponding level within the set temporary access time limit based on the shared temporary key; when jointly accessing data, the temporary key can temporarily replace the key of the corresponding user account, but the participation ratio of the temporary key cannot exceed the preset value.
6. A data security protection method for a business-finance collaborative management system according to claim 5, characterized in that: In the system, when a user account accesses encrypted data based on a shared temporary key, the system's behavior assessment module evaluates the access behavior of the user account in real time. When the risk value of the access behavior reaches a set warning value, the temporary access period is accelerated at a set rate; when the risk value reaches a warning value, the temporary access period is terminated.
7. A data security protection method for a business-finance collaborative management system according to claim 6, characterized in that: In the system, when a user account obtains a temporary key, it can generate a temporary subkey of a lower level based on the current temporary key, and the temporary access validity of the generated temporary subkey decreases level by level.
8. The data security protection method for a business-finance collaborative management system according to claim 7 is characterized in that: In the system, when the temporary access validity period of the temporary key obtained by the user expires, the user management module adjusts the validity score of the user account that generated the temporary key according to preset rules based on the risk value assessed by the behavior assessment module.
9. The data security protection method for a business-finance collaborative management system according to claim 6 is characterized in that: When performing an assessment, the behavior assessment module integrates user operation logs, device fingerprints, network environment, and time characteristics to construct a risk scoring model.
10. A data security protection method for a business-finance collaborative management system according to claim 8, characterized in that: The temporary key age attenuation coefficient is dynamically adjusted according to the risk value. When a user continuously triggers the warning value more than the set number of times within the set time, the system automatically freezes the key generation permission and triggers manual review.
Citation Information
Patent Citations
Financial data security management system and method thereof
CN119848882A