Intrinsic security protection methods, systems and media for data-driven decision-making systems

By constructing a full-stack intrinsic security governance architecture, embedding it into each level of the data-driven decision-making system, and combining it with a trusted execution environment, the fragmentation problem of security protection in existing technologies is solved, realizing system-level proactive defense and risk closed-loop governance, and improving data security protection capabilities and system stability.

CN120768683BActive Publication Date: 2025-11-14HUBEI PROVINCIAL SCI & TECH INFORMATION RES INST (HUBEI PROVINCIAL SCI & TECH INFORMATION BUREAU HUBEI PROVINCIAL SCI & TECH NEWSPAPER & PERIODICALS MANAGEMENT OFFICE)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511276697.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-08
Publication Date
2025-11-14
Estimated Expiration
2045-09-08

AI Technical Summary

Technical Problem

Existing security protection methods for data-driven decision-making systems mainly rely on external security measures, resulting in fragmented and static security protection that is difficult to cover the entire system lifecycle and dynamic threat evolution, and thus cannot achieve system-level proactive defense and closed-loop risk management.

Method used

We construct a full-stack intrinsic security governance architecture, encompassing hardware, software, data, algorithms, and application layers. By embedding security mechanisms within a trusted execution environment, we generate proactive defense strategies and achieve end-to-end risk control and collaborative governance feedback.

Benefits of technology

It enhances the data security protection capabilities of the data-driven decision-making system, achieves system-level defense-in-depth and risk isolation, possesses adaptive and sustainable dynamic protection capabilities, and improves the system's security consistency and stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768683B_ABST
    Figure CN120768683B_ABST
Patent Text Reader

Abstract

This application provides an intrinsic security protection method, system, and medium for data-driven decision-making systems, relating to the field of data security technology. The method includes: constructing a multi-layered, full-stack intrinsic security governance architecture to implement layered defense for the data-driven decision-making system and establish security mechanisms; embedding the security mechanisms into the entire lifecycle of the data-driven decision-making system for intrinsic security protection based on a trusted execution environment; generating and executing proactive defense strategies to manage risks throughout the entire process of the data-driven decision-making system; determining system collaborative governance feedback information and implementing security protection; and achieving intrinsic security protection for data-driven decision-making systems. This application solves the technical problem of fragmented and static data security protection capabilities caused by the lack of deep integration of security mechanisms with the system architecture in existing technologies, achieving the technical effect of enhancing data security protection capabilities and realizing system-level proactive defense and closed-loop risk governance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security technology, specifically to intrinsic security protection methods, systems, and media for data-driven decision-making systems. Background Technology

[0002] With the widespread application of technologies such as artificial intelligence, big data, and the Internet of Things, data-driven decision-making systems are playing an increasingly important role in key areas such as intelligent manufacturing and administrative management. However, due to the large amount of sensitive data flow and complex logical reasoning processes involved in their operation, data security issues are becoming increasingly prominent. Existing security protection methods for data-driven decision-making systems mainly rely on peripheral security measures or post-analysis mechanisms, including firewalls, intrusion detection systems, access control modules, and rule-based anomaly detection. These protection methods are deployed externally at the system periphery or some key nodes, exhibiting point-like deployment and isolated operation characteristics. This makes it difficult to form a unified and secure governance perspective for the entire system, resulting in security blind spots at uncontrolled levels. Furthermore, current security protection lacks deep coupling with system business processes, making it impossible to obtain real-time system status changes or governance results. The protection mechanism is disconnected from the actual operating status, making it difficult to meet the high requirements of new intelligent systems for security, reliability, and dynamic protection. Summary of the Invention

[0003] This application provides an intrinsic security protection method, system, and medium for data-driven decision-making systems. It solves the technical problem that existing technologies, due to the lack of deep integration of security mechanisms with the system architecture, result in fragmented and static data security protection capabilities, making it difficult to cover the entire system lifecycle and dynamic threat evolution. It achieves the technical effect of enhancing the data security protection capabilities of data-driven decision-making systems and realizing system-level proactive defense and risk closed-loop governance.

[0004] In view of the above problems, firstly, this application provides an intrinsic security protection method for data-driven decision-making systems. The method includes: constructing a full-stack intrinsic security governance architecture, which comprises multiple layers, including hardware, software, data, algorithm, and application layers; performing layered defense on the data-driven decision-making system based on these multiple layers to establish a security mechanism; embedding the security mechanism into the entire lifecycle of the data-driven decision-making system for intrinsic security protection based on a trusted execution environment, generating an active defense strategy; executing the active defense strategy to perform full-process risk management of the data-driven decision-making system, determining system collaborative governance feedback information, and performing security protection based on the system collaborative governance feedback information, thereby achieving intrinsic security protection for data-driven decision-making systems.

[0005] Preferably, a full-stack intrinsic security governance architecture is constructed, comprising multiple layers, including a hardware layer, a software layer, a data layer, an algorithm layer, and an application layer. The method includes: constructing a hardware layer based on a heterogeneous computing architecture using a trusted execution environment; integrating a secure development framework with a containerized isolation mechanism to construct a software layer for real-time monitoring and capturing of real-time threat parameters of the data-driven decision-making system; employing federated learning for blockchain traceability to construct a data layer for data privacy protection of parameters within the data-driven decision-making system and generating end-to-end data traceability tags; constructing an algorithm layer based on interpretable components and verification tools for decision attribution analysis and dynamic adjustment of defense strategies; constructing an application layer based on a scenario-based risk management mechanism for scenario simulation; and integrating the hardware, software, data, algorithm, and application layers to construct the full-stack intrinsic security governance architecture.

[0006] Preferably, a layered defense mechanism is established for the data-driven decision-making system based on the multiple layers, comprising the following methods: optimizing the computing power of the data-driven decision-making system at the hardware layer, dynamically allocating resources based on the optimization results, identifying multiple security-sensitive tasks for physical isolation and storage, and generating a first defense parameter; detecting operational anomalies in the data-driven decision-making system at the software layer, logically isolating real-time operational threat parameters, and generating a second defense parameter; performing distributed training on the data-driven decision-making system using federated learning at the data layer, generating a data privacy protection scheme, mapping the data privacy protection scheme to the blockchain for recording, and generating a third defense parameter by combining data end-to-end traceability tags; and utilizing the algorithm layer... The interpretable component performs visual attribution analysis on the data-driven decision-making system, generates attribution results, and performs dynamic adversarial testing on the attribution results using the verification tool to generate a fourth defense parameter. Based on the application layer, it simulates fault attack scenarios through the scenario-based risk management mechanism, automatically responds to the data-driven decision-making system based on the simulated fault attack scenarios, generates anomaly blocking parameters, and adds the anomaly blocking parameters to the fifth defense parameter. The first defense parameter, the second defense parameter, the third defense parameter, the fourth defense parameter, and the fifth defense parameter are linked at multiple levels according to the hardware layer, the software layer, the data layer, the algorithm layer, and the application layer to construct the security mechanism.

[0007] Preferably, the security mechanism is constructed by linking the first, second, third, fourth, and fifth defense parameters at multiple levels: hardware, software, data, algorithm, and application. The method includes: identifying suspicious data based on the first, second, third, fourth, and fifth defense parameters; integrating data according to the identification results to obtain a shared threat dataset; performing security defense analysis based on the hardware, software, data, algorithm, and application levels to construct a security log containing security rules; conducting collaborative analysis of the multiple levels based on the security rules to construct a cross-level collaborative strategy; and linking the security log with the shared threat dataset according to the cross-level collaborative strategy to construct the security mechanism.

[0008] Preferably, based on a trusted execution environment, the security mechanism is embedded into the entire lifecycle of the data-driven decision-making system for intrinsic security protection, generating an active defense strategy. The method includes: performing integrity verification on key datasets of the data-driven decision-making system based on the trusted execution environment deployed at the hardware layer; encrypting the key datasets in memory according to the verification results and the first defense parameter to generate an encrypted dataset; performing encryption gradient exchange on the encrypted dataset based on the data layer according to the trusted execution environment and the second defense parameter to obtain encrypted data protection information; generating runtime security logs for defense optimization based on the algorithm layer according to the trusted execution environment and the fourth defense parameter to generate active defense rules; performing trajectory extrapolation on the encrypted data protection information according to the active defense rules based on the trusted execution environment and the fifth defense parameter at the application layer to generate system elastic recovery capability parameters for the data-driven decision-making system; and performing intrinsic security protection on the entire lifecycle of the data-driven decision-making system based on the encrypted dataset, the encrypted data protection information, the active defense rules, and the system elastic recovery capability parameters to generate the active defense strategy.

[0009] Preferably, the active defense strategy is implemented to perform full-process risk management of the data-driven decision-making system, determine system collaborative governance feedback information, and perform security protection based on the system collaborative governance feedback information to achieve intrinsic security protection for the data-driven decision-making system. The method includes: continuously monitoring the data-driven decision-making system to obtain real-time threat intelligence; retrieving the operational status information of the data-driven decision-making system, performing multi-level collaborative risk analysis based on the real-time threat intelligence and the operational status information to obtain a full-process risk parameter set; performing collaborative governance on the multiple levels of the data-driven decision-making system according to the full-process risk parameter set to generate system collaborative governance feedback information; dynamically adjusting the active defense strategy according to the system collaborative governance feedback information to generate an active defense optimization strategy, and performing dynamic intrinsic security protection for the data-driven decision-making system according to the active defense optimization strategy.

[0010] Preferably, the method for collaboratively governing the multiple levels of the data-driven decision-making system according to the full-process risk parameter set and generating system collaborative governance feedback information includes: real-time collection of multiple levels of the data-driven decision-making system based on the cross-level collaborative strategy to obtain multiple levels of security event data; traversing the operational status information to extract multiple levels of operational status data; performing collaborative governance of the multiple levels according to the full-process risk parameter set combined with the multiple levels of operational status data to generate initial collaborative governance information; and performing reverse verification of the initial collaborative governance information based on the multiple levels of security event data to generate the collaborative governance feedback information.

[0011] Preferably, the method for dynamically adjusting the proactive defense strategy according to the system collaborative governance feedback information to generate a proactive defense optimization strategy, and for providing dynamic protection for the data-driven decision-making system with intrinsic security according to the proactive defense optimization strategy, includes: traversing the multiple levels to decompose the system collaborative governance feedback information to obtain multiple collaborative feedback information; traversing the multiple levels to decompose the proactive defense strategy to obtain multiple proactive defense parameters; matching and aligning the multiple collaborative feedback information and the multiple proactive defense parameters according to the multiple levels to construct a data adjustment list; dynamically optimizing the multiple proactive defense parameters based on the data adjustment list according to the multiple collaborative feedback information to generate multiple defense optimization parameters; and performing intrinsic security deduction on the multiple defense optimization parameters according to the multiple levels to generate the proactive defense optimization strategy.

[0012] Secondly, this application also provides an intrinsic security protection system for data-driven decision-making systems. The system includes: an architecture building module for constructing a full-stack intrinsic security governance architecture, which comprises multiple layers, including hardware, software, data, algorithm, and application layers; a layered defense module for performing layered defense on the data-driven decision-making system based on the multiple layers, establishing a security mechanism; a protection deployment module for embedding the security mechanism into the entire lifecycle of the data-driven decision-making system for intrinsic security protection based on a trusted execution environment, generating an active defense strategy; and an intrinsic security protection module for executing the active defense strategy to perform full-process risk management of the data-driven decision-making system, determining system collaborative governance feedback information, and performing security protection based on the system collaborative governance feedback information, thereby achieving intrinsic security protection for data-driven decision-making systems.

[0013] Thirdly, this application also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps in the above-described intrinsic security protection method for data-driven decision systems.

[0014] One or more technical solutions provided in this application have at least the following beneficial effects:

[0015] By constructing a full-stack intrinsic security governance architecture, security capabilities are embedded into multiple layers of the system, including perception, transmission, processing, decision-making, and feedback. This makes security mechanisms an integral part of the system, fundamentally solving the fragmentation and externalization of security protection in existing technologies, and significantly improving the overall security consistency and stability of the system. Based on this governance architecture, differentiated security policies and mechanisms are deployed for different system layers, targeting their functional characteristics and risk types. This achieves defense-in-depth and risk isolation, enhancing the overall system's security resilience. Leveraging the isolation and encrypted computing capabilities provided by the trusted execution environment, security mechanisms are embedded into the entire lifecycle of the data-driven decision-making system for intrinsic security protection, generating proactive defense strategies. These strategies can identify, analyze, and respond to security threats in real time when facing abnormal behavior or potential attacks, achieving a leap from static rules to dynamic policies. By constructing an information collection and analysis mechanism based on system collaborative governance feedback, protection strategies can be dynamically adjusted according to operational results, achieving strategy optimization and security capability evolution, thereby achieving adaptive and continuously optimized data security protection goals.

[0016] In summary, this application constructs a multi-layered, evolvable, full-stack intrinsic security governance architecture, which natively embeds security mechanisms into the structure and lifecycle of the data-driven decision-making system. It combines a trusted execution environment to ensure the trustworthiness of key links, and drives dynamic risk management and collaborative feedback optimization throughout the entire process through proactive defense strategies. This enables the system to have in-depth defense capabilities from the architecture layer to the operation layer, and ultimately achieves dynamic data security protection for the entire lifecycle and process of the data-driven decision-making system.

[0017] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description

[0018] Figure 1 This is a flowchart illustrating the intrinsic security protection method for data-driven decision-making systems provided in this application embodiment.

[0019] Figure 2 A schematic diagram of the structure of the intrinsic security protection system for data-driven decision-making systems provided in this application embodiment.

[0020] Figure labeling: Architecture building module 10, layered defense module 20, protection deployment module 30, intrinsic security protection module 40. Detailed Implementation

[0021] This application provides an intrinsic security protection method, system, and medium for data-driven decision-making systems. It solves the technical problem that existing technologies suffer from fragmented and static data security protection capabilities due to the lack of deep integration of security mechanisms with the system architecture. This makes it difficult to cover the entire system lifecycle and dynamic threat evolution. The application achieves the technical effect of enhancing the data security protection capabilities of data-driven decision-making systems and realizing system-level proactive defense and risk closed-loop governance.

[0022] Example 1, as Figure 1 As shown in the embodiments of this application, an intrinsic security protection method for data-driven decision-making systems is provided, the method comprising:

[0023] Step S100: Construct a full-stack intrinsic security governance architecture, which includes multiple layers, including hardware layer, software layer, data layer, algorithm layer, and application layer.

[0024] Furthermore, step S100 includes:

[0025] Step S110: Based on the trusted execution environment, a heterogeneous computing architecture is constructed to build a hardware layer, which is used for the secure storage of parameters and dynamic allocation of sensitive tasks within the data-driven decision system.

[0026] Step S120: Integrate the security development framework with the containerization isolation mechanism to build a software layer, which is used to monitor and capture real-time threat parameters of the data-driven decision-making system in real time.

[0027] Step S130: Federated learning is used to construct a data hierarchy for blockchain traceability. The data hierarchy is used to protect the data privacy of parameters within the data-driven decision-making system and generate full-link data traceability tags.

[0028] Step S140: Construct an algorithm hierarchy based on interpretable components and verification tools, the algorithm hierarchy being used for decision attribution analysis and dynamic adjustment of defense strategies.

[0029] Step S150: Construct an application layer based on a scenario-based risk management mechanism, wherein the application layer is used for scenario simulation.

[0030] Step S160: Integrate and associate the hardware layer, the software layer, the data layer, the algorithm layer, and the application layer to construct the full-stack intrinsic security governance architecture.

[0031] Specifically, a full-stack intrinsic security governance architecture refers to a security architecture system that covers multiple layers of a data-driven decision-making system, from the underlying hardware to the upper-level applications, and spans the entire system lifecycle. These multiple layers include hardware, software, data, algorithm, and application layers.

[0032] The hardware layer is the underlying foundation of a data-driven decision-making system, primarily comprising physical devices (such as servers, storage devices, and network devices) and hardware-related firmware and drivers. Heterogeneous computing architecture refers to an architecture where multiple types of processors (such as CPUs, GPUs, FPGAs, and TPUs) collaborate to complete computational tasks. When constructing the hardware layer, a security module built on a trusted execution environment (TEA) is embedded into different types of computing units to achieve a heterogeneous computing architecture. This ensures that key parameters in the data-driven decision-making system (such as algorithm model weights and privacy data) are stored in a trusted space and enables dynamic scheduling of sensitive tasks. The task scheduler dynamically allocates sensitive tasks to trusted processing nodes based on task characteristics (such as privacy level and computational complexity) and the load of each computing unit. The TEA kernel provides encryption / decryption, integrity verification, and authentication interfaces to ensure the security of the computation process.

[0033] The software layer primarily refers to the operating system, middleware, applications, and other software environments of a data-driven decision-making system, along with their related configurations and management. When building the software layer, a secure development framework is integrated with containerization isolation mechanisms. First, a secure development framework is used for software development. A secure development framework is a toolset used to integrate functions such as code auditing, vulnerability detection, and security dependency management during the software development process, providing guiding principles such as code security standards and vulnerability prevention. Following these guiding principles when writing software code can reduce the occurrence of security vulnerabilities. During the software deployment phase, containerization technologies (such as Docker and Kubernetes) are used to package the software application and its dependencies into container images, and the containers run on the host machine. Through containerization isolation mechanisms, different software services or modules are isolated in their respective containers, preventing mutual interference and attacks between services. To monitor the data-driven decision-making system in real time and capture real-time threat parameters, a security monitoring agent is deployed on the host machine and in containers to collect the system's operational status information, including CPU utilization, memory usage, network traffic, process status, etc., and security monitoring rules (such as threshold-based alarm rules or machine learning-based anomaly detection rules) are configured. When the real-time monitoring data meets specific threat conditions, an alarm is triggered and relevant real-time threat parameters are recorded, including but not limited to abnormal CPU usage, abnormal network connections, process creation frequency, system call patterns, etc.

[0034] The data hierarchy primarily involves the management, storage, processing, and analysis of data in data-driven decision-making systems. When constructing the data hierarchy, federated learning is employed for blockchain traceability to protect data privacy and generate end-to-end data traceability tags. First, a federated learning client is configured for each participant in the data-driven decision-making system. This client is responsible for processing data and training models locally, and sending encrypted model updates (such as encrypted gradient information) to the federated learning server. Upon receiving the encrypted model updates from each client, the federated learning server decrypts and aggregates them to generate a new global model, which is then encrypted and distributed to each federated learning client for the next round of training. Throughout this process, the original data remains locally and is not transmitted or leaked to other participants, thus protecting data privacy. Simultaneously, to achieve blockchain traceability, a blockchain network is constructed, with participants acting as nodes. In each training step of the federated learning process, metadata and parameter update records generated during training are written into the blockchain network via smart contracts and bound to corresponding hash identifiers, forming unique end-to-end data traceability tags to record the complete path information of data from generation, storage, use, to modification. This end-to-end data traceability label spans the entire lifecycle of data within the data-driven decision-making system, supporting traceability verification and security auditing.

[0035] The algorithm hierarchy involves the design, development, evaluation, and optimization of algorithms in data-driven decision-making systems. When constructing the algorithm hierarchy, interpretable components and validation tools are combined to achieve decision attribution analysis and dynamically adjust defense strategies. Interpretable components reveal the decision-making basis of the machine learning model, while validation tools test the consistency and security of the algorithm's logic, behavior, and input / output. First, appropriate interpretable components are selected and integrated into the algorithm model. When the model generates decision results, the decision-making basis and key influencing factors are analyzed to pinpoint the regions that play a crucial role in the decision, helping users understand why the model focuses on certain parts of the input data. Simultaneously, validation tools are used to evaluate and validate the model during algorithm development. Based on this, and according to the results of decision attribution analysis and the problems discovered by the validation tools, model parameter updates or strategy adjustment logic are triggered to dynamically adjust the defense strategy, achieving an automated closed-loop strategy optimization.

[0036] The application layer primarily involves the specific business applications and user interactions of the data-driven decision-making system. When constructing the application layer, scenario simulation is conducted based on a scenario-based risk management mechanism. This mechanism is a method for developing targeted risk assessment and control strategies based on the characteristics and risk features of specific business scenarios. Different business scenarios face varying security risks; the scenario-based risk management mechanism fully considers the specificities of each scenario, enabling refined risk management and improving the accuracy and effectiveness of risk control. A scenario library is built for typical use cases (such as high-concurrency access, model-misleading input, and offline edge devices). A scenario simulation environment is constructed using digital twin technology or a simulation platform. Within this environment, various potential risks in real-world scenarios are reproduced. This allows for verification of the responsiveness and control effectiveness of current defense strategies based on the simulated risk characteristics, and the simulation feedback is used to update strategy weights or trigger control logic.

[0037] When constructing a full-stack intrinsic security governance architecture, it is necessary to integrate and correlate the hardware, software, data, algorithm, and application layers, establishing communication interfaces and protocols between each layer to ensure smooth information transmission across different layers, thus forming a full-stack intrinsic security governance architecture. The hardware layer provides the basic hardware support for the software layer's operation. The software layer interacts with the data layer, responsible for manipulating, processing, and transmitting data, while the data layer provides data resources to the software and ensures data privacy and traceability. The algorithm layer relies on data provided by the data layer for algorithmic calculations, and the decision results from the algorithm layer are fed back to the software layer for execution. The application layer builds upon the hardware, software, data, and algorithm layers to construct practical application scenarios, and the needs of the application layer in turn influence the optimization direction of other layers.

[0038] Step S200: Based on the multiple levels, implement layered defense for the data-driven decision-making system and establish a security mechanism.

[0039] Furthermore, step S200 includes:

[0040] Step S210: Optimize the computing power of the data-driven decision system based on the hardware level, dynamically allocate resources according to the optimization results, determine multiple security-sensitive tasks for physical isolation and storage, and generate the first defense parameters.

[0041] Step S220: Based on the software layer, perform operational anomaly detection on the data-driven decision system, logically isolate the real-time operational threat parameters, and generate second defense parameters.

[0042] Step S230: Based on the data hierarchy, federated learning is used to perform distributed training on the data-driven decision-making system to generate a data privacy protection scheme. The data privacy protection scheme is mapped to the blockchain for recording, and a third defense parameter is generated by combining the data end-to-end traceability tag.

[0043] Step S240: Based on the algorithm level, use the interpretable component to perform visual attribution analysis on the data-driven decision system, generate attribution results, and perform dynamic adversarial testing on the attribution results according to the verification tool to generate a fourth defense parameter.

[0044] Step S250: Based on the application layer, simulate the fault attack scenario through the scenario-based risk management mechanism, automatically respond to the data-driven decision system according to the simulated fault attack scenario, generate abnormal blocking parameters, and add the abnormal blocking parameters to the fifth defense parameters.

[0045] Step S260: The first defense parameter, the second defense parameter, the third defense parameter, the fourth defense parameter, and the fifth defense parameter are linked in a multi-level manner according to the hardware level, the software level, the data level, the algorithm level, and the application level to construct the security mechanism.

[0046] Specifically, security mechanisms refer to a series of technologies, measures, and processes designed and implemented to ensure the security of data-driven decision-making systems. These encompass multiple aspects such as access control, encryption, intrusion detection, and security auditing, providing corresponding security guarantees for different levels of security needs. At the hardware level, the computing resources within the data-driven decision-making system are first subjected to load analysis. For different tasks, computing power is optimized and configured according to their computing power requirements and priorities. Tasks with high security sensitivity levels (such as encryption key processing and user privacy analysis) are allocated independent trusted execution environments or dedicated encrypted storage modules to ensure that their operation and storage environment are not interfered with by ordinary tasks. Finally, based on task allocation and isolation configuration, first-level defense parameters are generated, such as a "sensitive task ID-isolation unit binding table" and a "computing resource encryption scheduling table."

[0047] A security monitoring agent deployed at the software level continuously monitors the operational status of each component of the data-driven decision-making system, identifying threat indicators such as API abuse, abnormal access frequency, and module crashes. Tagged abnormal components or data flows are immediately logically isolated, and their impact is limited through measures such as least privilege control and sandbox execution. Isolation policies and configurations are recorded as secondary defense parameters for reference by other defense mechanisms.

[0048] Data privacy protection schemes are strategic combinations that specifically define methods for processing user data, such as anonymization, encryption, and minimal exposure. At the data level, each node (participant) in the data-driven decision-making system participates in model training through federated learning to prevent the leakage of raw data. Each node locally executes a data privacy protection scheme (such as differential privacy or encrypted computation) to generate parameter summaries. These data privacy protection schemes are mapped to the blockchain in hash form and bound to a data end-to-end traceability tag. The data-driven decision-making system thus constructs a data link protection graph and combines the generated parameter summaries, execution logs, and data end-to-end traceability tags to form a third defense parameter.

[0049] At the algorithm level, interpretable components are used to visualize the model output and analyze the contribution of important features. For example, in a deep learning model used for disease diagnosis, Shapleyga and the interpretable value method are used as interpretable components to calculate the contribution of each input feature (such as patient symptoms, examination indicators, medical history, etc.) to the disease diagnosis result, and the importance ranking of these features is visualized in the form of a heatmap. After obtaining the attribution results, feature perturbation scenarios are automatically constructed using validation tools to verify the model's adversarial robustness. Based on the adversarial validation results, a fourth defense parameter is generated, including the adversarial test success rate (i.e., the proportion of misdiagnosis caused by adversarial samples), the difference measure of the attribution results between adversarial samples and original samples (such as the rate of change of feature contribution values), and the adjustment parameters of the model's defense strategy (such as the noise intensity added during adversarial training and the number of training epochs).

[0050] At the application level, scenario-based risk management mechanisms are used to simulate fault attack scenarios. For example, in a data-driven decision-making system of an e-commerce platform, a scenario where a hacker attack leads to the theft of user account passwords is simulated. Under the simulated fault attack scenario, the simulated fault attack scenario is responded to according to predefined automated response strategies of the scenario-based risk management mechanism, such as automatically freezing suspicious accounts and restricting abnormal login IPs. By monitoring and evaluating the automated response process, anomaly blocking parameters are generated, including the identifier of the frozen account, the range of restricted login IPs, and the triggering conditions for the automated response. This anomaly blocking parameter is added to the fifth defense parameter, which can also include other information related to application-level security, such as the normal operating scope of the application scenario and risk thresholds.

[0051] Establish a unified security management platform. This platform is responsible for collecting, integrating, and managing defense parameters from different levels, and for real-time monitoring and analysis of the overall security status of the data-driven decision-making system. It enables multi-layered linkage control and constructs a security mechanism that covers all levels of hardware, software, data, algorithms, and applications, so that security protection measures at each level complement each other and work together to defend.

[0052] Furthermore, step S260 includes:

[0053] Step S261: Based on the first defense parameter, the second defense parameter, the third defense parameter, the fourth defense parameter, and the fifth defense parameter, suspicious data is identified, and data is integrated according to the identification results to obtain a shared threat dataset.

[0054] Step S262: Perform security defense analysis based on the hardware layer, the software layer, the data layer, the algorithm layer, and the application layer, and construct a security log, which contains security rules.

[0055] Step S263: Perform collaborative analysis on the multiple levels based on the security rules to construct a cross-level collaborative strategy.

[0056] Step S264: Link the security logs with the shared threat dataset according to the cross-level collaboration strategy to construct the security mechanism.

[0057] Specifically, the suspicious data identifier is the data content, behavior pattern, or access path in the data-driven decision-making system that poses potential threats or abnormal behaviors. Parse and cross-compare the five types of defense parameters, and identify data such as logs, model inputs, and network requests with potential risks through information such as abnormal behavior tags, access timestamps, and task ownership. Subsequently, classify and integrate the identified data into a standard format (such as STIX, JSON, Graph format) to form a shared threat dataset.

[0058] At the hardware level, analyze the security functions of hardware devices, the impact of computing power allocation on security, the effectiveness of physical isolation storage, etc. At the software level, study the software operation anomaly detection mechanism, logical isolation measures, the impact of software updates on security, etc. For the data level, consider data privacy protection schemes, data security in the process of federated learning, the accuracy of data full-link tracing, etc. At the algorithm level, analyze the visualization of attribution analysis results, the improvement of algorithm security by dynamic adversarial testing, etc. At the application level, pay attention to the simulation of fault attack scenarios under the scenario-based risk control mechanism, the effectiveness of automated responses, etc. Construct security logs based on these analysis results. The security logs contain security rules. For example, at the hardware level, specific device access permissions are specified; at the software level, the start and stop conditions of software processes are specified; at the data level, the permissions and processes for data sharing are specified; at the algorithm level, the input and output ranges of algorithms are specified; at the application level, user operation permissions in different scenarios are specified.

[0059] Read the rules and event chains in the security logs, and identify the trigger logic and dependency paths between different levels. With the help of a graph database or a causal network, construct an event propagation chain, and inject policy hooks at multiple levels to achieve top-down or bottom-up linkage control. For example, data layer events can trigger the freezing of algorithm layer parameters, and software layer anomalies can request resource clearing from the hardware layer. Finally, form a set of dynamic cross-layer execution rule sets to constitute a cross-level collaborative strategy. This cross-level collaborative strategy describes the scheduling control logic for coordinating the execution of defense actions across multiple levels.

[0060] Automatically invoke the response paths in the security logs according to the cross-level collaborative strategy, and combine the current risk situation in the shared threat dataset to issue linkage instructions to multiple levels, including operations such as model replacement, resource isolation, and access blocking. At the same time, update the status of the security logs and the shared threat dataset to achieve dynamic learning and self-repair capabilities. Finally, construct a security mechanism with adaptive and self-evolving capabilities.

[0061] Step S300: Based on the trusted execution environment, embed the security mechanism into the entire life cycle of the data-driven decision-making system for in-depth security protection, and generate an active defense strategy.

[0062] Furthermore, step S300 includes:

[0063] Step S310: Based on the trusted execution environment deployed at the hardware layer, perform integrity verification on the key dataset of the data-driven decision system, and encrypt the key dataset in memory according to the verification result and the first defense parameter to generate an encrypted dataset.

[0064] Step S320: Based on the data layer, perform encryption gradient exchange on the encrypted dataset according to the trusted execution environment and the second defense parameters to obtain encrypted data protection information.

[0065] Step S330: Based on the algorithm layer, generate runtime security logs according to the trusted execution environment and the fourth defense parameters to optimize defense and generate proactive defense rules.

[0066] Step S340: Based on the application layer, the encrypted data protection information is simulated according to the active defense rules through the trusted execution environment and the fifth defense parameter to generate the system elastic recovery capability parameters of the data-driven decision system.

[0067] Step S350: Based on the encrypted dataset, the encrypted data protection information, the proactive defense rules, and the system elastic recovery capability parameters, perform intrinsic security protection on the entire lifecycle of the data-driven decision-making system, and generate the proactive defense strategy.

[0068] Specifically, a Trusted Execution Environment (TEE) refers to a secure computing area within a data-driven decision-making system, defined through hardware isolation and encryption technologies, ensuring the confidentiality and integrity of code and data within it. The entire lifecycle refers to the entire process of a data-driven decision-making system from creation, deployment, operation, maintenance to decommissioning. During this process, the system will experience different stages, each with its specific security requirements and risks. Proactive defense strategies refer to real-time dynamic protection measures automatically generated and applied by the data-driven decision-making system based on threat detection and feedback mechanisms.

[0069] By leveraging a trusted execution environment within the hardware layer, hash verification and digital signature comparison are performed on key datasets (such as user behavior data and model parameters) in the data-driven decision-making system to achieve integrity verification. If the verification passes, the sensitive data residing in physical memory is dynamically encrypted using encryption algorithms such as AES and SM4 according to the sensitivity level indicated by the first defense parameter to prevent memory scanning and man-in-the-middle attacks, and the encryption result is encapsulated and stored as an encrypted dataset.

[0070] Based on the data layer structure, encryption gradient calculations are performed on the encrypted dataset in a fragmented and perturbation manner within a trusted execution environment, and the gradient exchange process is completed between different nodes. Combining secondary defense parameters (such as logical isolation policies, threat label weights, etc.), the exchange path and mask strength are dynamically selected, and finally, encrypted data protection information containing timestamps, source and target identifiers, and data weights is generated.

[0071] Within the algorithm layer, the current model's running status and security posture are monitored. Combined with the fourth defense parameters (including attribution analysis results and adversarial test feedback), detailed operational security logs are generated, covering changes in model input, execution branches, and parameter fluctuations. Within a trusted execution environment, the operational security log data is stored reliably, and the rule engine is invoked to generate proactive defense rules, specifying defensive actions such as model annealing, risk isolation, and adaptive switching.

[0072] The application layer invokes the trajectory modeling engine within the trusted execution environment, using proactive defense rules as evolutionary conditions and combining them with fifth defense parameters (such as attack simulation data and scenario response records) to simulate various attack paths or failure scenarios. For each scenario, it evaluates metrics such as response time, recovery path, and resource consumption, outputting a set of system resilience parameters to quantify the data-driven decision-making system's recovery speed, integrity, and stability after being attacked or experiencing a failure.

[0073] By leveraging encrypted datasets, encrypted data protection information, proactive defense rules, and system resilience parameters, intrinsic security protection is implemented throughout the entire lifecycle of a data-driven decision-making system (including all stages of data generation, storage, processing, transmission, and application). In the data generation stage, encrypted datasets ensure initial data security; in the storage stage, secure storage is achieved based on encrypted datasets and encrypted data protection information; in the processing stage, proactive defense rules ensure the security of algorithm processing; in the transmission stage, encrypted data protection information guarantees secure data transmission; and in the application stage, system resilience parameters ensure the stability and resilience of the data-driven decision-making system during application. Through this lifecycle-wide security protection, a proactive defense strategy is generated, encompassing measures and rules for data security management, algorithm security maintenance, and application security assurance. This proactive defense strategy possesses dynamic adjustment and continuous evolution capabilities, allowing for updates or reconstruction based on actual operational conditions.

[0074] Step S400: Execute the proactive defense strategy to manage the risks of the data-driven decision-making system throughout the entire process, determine the system collaborative governance feedback information, and carry out security protection based on the system collaborative governance feedback information to achieve intrinsic security protection for the data-driven decision-making system.

[0075] Furthermore, step S400 includes:

[0076] Step S410: Continuously monitor the data-driven decision-making system to execute the proactive defense strategy and obtain real-time threat intelligence.

[0077] Step S420: Retrieve the operational status information of the data-driven decision-making system, and conduct multi-level collaborative risk analysis based on the real-time threat intelligence and the operational status information to obtain a full-process risk parameter set.

[0078] Step S430: Perform collaborative governance on the multiple levels of the data-driven decision-making system according to the full-process risk parameter set, and generate system collaborative governance feedback information.

[0079] Step S440: Dynamically adjust the proactive defense strategy according to the system collaborative governance feedback information to generate a proactive defense optimization strategy, and perform dynamic protection of the data-driven decision system for intrinsic security according to the proactive defense optimization strategy.

[0080] Specifically, full-process risk management refers to continuous risk monitoring, assessment, and control at all stages of the data-driven decision-making system, including perception, analysis, decision-making, and execution. System collaborative governance feedback information refers to the risk perception and strategy adjustment data exchanged, verified, and generated between different levels during the operation of the data-driven decision-making system. Intrinsic security protection refers to deeply integrating security mechanisms into the internal structure of the data-driven decision-making system, making them an integral part of the system itself, thereby achieving self-protection and self-repair capabilities.

[0081] During the operation of the data-driven decision-making system, the execution of proactive defense strategies is continuously monitored through monitoring mechanisms at various levels. For example, network data traffic is monitored for abnormal traffic patterns, which may indicate malicious attacks or data breaches. Simultaneously, system logs are analyzed to check for operations or events that do not conform to the proactive defense strategy settings. Through these monitoring activities, information about potential threats is collected, resulting in real-time threat intelligence.

[0082] The system retrieves operational status information from the data-driven decision-making system, including hardware-level data such as device temperature and memory usage; software-level data such as process status and software version information; data-level data volume and update frequency; algorithm-level data such as algorithm execution efficiency and convergence; and application-level data such as user activity and business operation success rate. Then, combined with real-time threat intelligence, collaborative risk analysis is performed at multiple levels. Potential risk nodes and attack paths are identified, generating a full-lifecycle risk parameter set covering resource bottlenecks, potential failure points, and predictive offsets.

[0083] Based on the extracted full-process risk parameter set, dynamic adjustments and repairs are made to the hardware-level computing power scheduling, software-level container isolation, data-level data tracing, algorithm-level defense rules, and application-level response mechanisms. During the governance process, response results from each sub-layer are collected, and unified system collaborative governance feedback information is generated to reflect the overall security operation status of the current data-driven decision-making system and the adaptability of various strategies.

[0084] Based on feedback information from system collaborative governance, the system analyzes the failure points or redundant parts of the current defense strategy, calls the strategy optimization engine to fine-tune rules, update response paths, and reconfigure resources, generating a set of proactive defense optimization strategies adapted to the current threat landscape. These proactive defense optimization strategies will cover multiple stages of the system's entire lifecycle, enabling dynamic insertion and gradual activation, and then redeployment to all levels of the data-driven decision-making system to achieve dynamic, intrinsic security protection.

[0085] Furthermore, step S430 includes:

[0086] Step S431: Based on the cross-level collaborative strategy, collect data on the multiple levels of the data-driven decision-making system in real time to obtain security event data at multiple levels.

[0087] Step S432: Traverse the running status information to extract running status data at multiple levels, and perform collaborative governance on the multiple levels according to the full-process risk parameter set and the running status data at multiple levels to generate initial collaborative governance information.

[0088] Step S433: Perform reverse verification on the initial collaborative governance information based on the multiple levels of security event data to generate the collaborative governance feedback information.

[0089] Specifically, based on a cross-level collaborative strategy, real-time data is collected across multiple levels of the data-driven decision-making system. At the hardware level, physical security monitoring systems and hardware status monitoring tools collect parameters such as temperature and voltage of hardware devices, as well as abnormal operational events (such as unauthorized plugging and unplugging of devices). At the software level, software logs record events such as software runtime errors and unauthorized access attempts. At the data level, database auditing systems and data access monitoring tools collect information such as the number of database connections, query counts, data change records, and backup status in real time. At the algorithm level, abnormal outputs during algorithm execution and events such as algorithm attacks and interference are collected. At the application level, attention is paid to abnormal user operations and application crashes. This data related to security events collected from different levels constitutes multi-level security event data.

[0090] The current operational status information is traversed layer by layer to extract operational status data for each level. Then, based on the full-process risk parameter set and these multi-level operational status data, collaborative governance is performed on each level. For example, if the full-process risk parameter set indicates that the hardware level has an excessively high load rate and poses a risk, and this is combined with information such as memory usage in the hardware level operational status data, governance measures such as increasing hardware resources and optimizing hardware configuration are taken. For the software level, based on the risk parameter set and software operational status data, measures such as optimizing software code and updating software versions are taken. After collaborative governance of each level in this way, initial collaborative governance information is generated. This initial collaborative governance information includes the governance measures taken at each level and the expected effects after governance.

[0091] The initial collaborative governance information is verified using security event data from multiple levels. For example, if the initial collaborative governance information suggests increasing hardware resources to reduce load, the hardware-level data from multiple security event levels is examined to check if the hardware load has actually decreased and whether other hardware-related security events have occurred (e.g., whether the hardware still exhibits abnormal temperature increases). For the software level, if the governance measure is to optimize software code to shorten response time, the software response time in the software-level security event data is checked to see if it has indeed been shortened and whether there are still software runtime errors. In this way, the governance measures and expected effects at each level are verified. Based on the verification results, collaborative governance feedback information is generated. This feedback information, generated during the reverse verification process, includes the effectiveness of the initial collaborative governance information and directions for improvement.

[0092] Furthermore, step S440 includes:

[0093] Step S441: Traverse the multiple levels to break down the system collaborative governance feedback information and obtain multiple collaborative feedback information.

[0094] Step S442: Traverse the multiple layers to break down the active defense strategy and obtain multiple active defense parameters.

[0095] Step S443: Match and align the multiple collaborative feedback information and the multiple active defense parameters according to the multiple levels to construct a data adjustment list.

[0096] Step S444: Based on the data adjustment list, dynamically optimize the multiple active defense parameters according to the multiple collaborative feedback information to generate multiple defense optimization parameters.

[0097] Step S445: Perform intrinsic security deduction on the multiple defense optimization parameters according to the multiple levels to generate the active defense optimization strategy.

[0098] Specifically, for the hardware, software, data, algorithm, and application layers of the data-driven decision-making system, the corresponding sub-items in the system's collaborative governance feedback information are extracted and traversed to form multiple collaborative feedback information messages that correspond one-to-one with each layer, serving as the basis for optimization input. Based on the system's hierarchical structure, the currently applied proactive defense strategy is deconstructed into multiple executable sub-strategies, and proactive defense parameters related to security control at each layer are extracted to ensure that each layer's strategy has independent update capabilities.

[0099] Based on hierarchical labels, collaborative feedback information and active defense parameters are mapped and compared one-to-one. A dynamic matching algorithm is used to generate adjustment suggestions, outputting a unified data adjustment list containing parameter names, current values, suggested adjustment values, and adjustment basis. Combining the state change trends of the data-driven decision-making system with collaborative feedback information at each level, operations such as weight adjustment, strategy refinement, and resource reallocation are performed on the original active defense parameters to dynamically generate multiple defense optimization parameters. Joint simulation and scenario extrapolation are conducted on the defense optimization parameters at each level to evaluate the impact of multiple defense optimization parameters on the stability, security, and performance of the overall data-driven decision-making system. Finally, a new active defense optimization strategy is integrated to replace the original strategy for security execution in the next cycle.

[0100] In summary, the intrinsic security protection method for data-driven decision-making systems provided in this application has the following beneficial effects:

[0101] By constructing a full-stack intrinsic security governance architecture, security capabilities are embedded into multiple layers of the system, including perception, transmission, processing, decision-making, and feedback. This makes security mechanisms an integral part of the system, fundamentally solving the fragmentation and externalization of security protection in existing technologies, and significantly improving the overall security consistency and stability of the system. Based on this governance architecture, differentiated security policies and mechanisms are deployed for different system layers, targeting their functional characteristics and risk types. This achieves defense-in-depth and risk isolation, enhancing the overall system's security resilience. Leveraging the isolation and encrypted computing capabilities provided by the trusted execution environment, security mechanisms are embedded into the entire lifecycle of the data-driven decision-making system for intrinsic security protection, generating proactive defense strategies. These strategies can identify, analyze, and respond to security threats in real time when facing abnormal behavior or potential attacks, achieving a leap from static rules to dynamic policies. By constructing an information collection and analysis mechanism based on system collaborative governance feedback, protection strategies can be dynamically adjusted according to operational results, achieving strategy optimization and security capability evolution, thereby achieving adaptive and continuously optimized data security protection goals.

[0102] Overall, the embodiments of this application construct a multi-layered, evolvable, full-stack intrinsic security governance architecture, which natively embeds security mechanisms into the structure and lifecycle of the data-driven decision-making system. Combined with a trusted execution environment to ensure the trustworthiness of key links, and driven by proactive defense strategies to drive dynamic risk management and collaborative feedback optimization throughout the entire process, the data-driven decision-making system has in-depth defense capabilities from the architecture layer to the operation layer, and ultimately achieves dynamic data security protection for the entire lifecycle and process of the data-driven decision-making system.

[0103] Example 2, as Figure 2 As shown, based on the same inventive concept as in Embodiment 1 above, this application provides an intrinsic security protection system for data-driven decision-making systems, the system comprising:

[0104] Architecture building module 10 is used to build a full-stack intrinsic security governance architecture. The full-stack intrinsic security governance architecture includes multiple layers, including hardware layer, software layer, data layer, algorithm layer, and application layer.

[0105] The layered defense module 20 is used to perform layered defense on the data-driven decision-making system based on the multiple layers and establish a security mechanism.

[0106] The protection deployment module 30 is used to embed the security mechanism into the entire lifecycle of the data-driven decision system based on a trusted execution environment for intrinsic security protection and to generate proactive defense strategies.

[0107] The intrinsic security protection module 40 is used to execute the active defense strategy to perform full-process risk management of the data-driven decision-making system, determine the system collaborative governance feedback information, and perform security protection based on the system collaborative governance feedback information, thereby realizing intrinsic security protection for the data-driven decision-making system.

[0108] Furthermore, the architecture building module 10 in this embodiment is also used to perform the following steps:

[0109] A heterogeneous computing architecture based on a trusted execution environment is constructed, including a hardware layer for secure storage of parameters and dynamic allocation of sensitive tasks within the data-driven decision-making system; a software layer integrating a secure development framework and containerized isolation mechanisms for real-time monitoring and capture of real-time threat parameters of the data-driven decision-making system; a data layer using federated learning for blockchain traceability for data privacy protection of parameters within the data-driven decision-making system and generation of end-to-end data traceability tags; an algorithm layer based on interpretable components and verification tools for decision attribution analysis and dynamic adjustment of defense strategies; and an application layer based on a scenario-based risk management mechanism for scenario simulation. Finally, the hardware, software, data, algorithm, and application layers are integrated to construct the full-stack intrinsic security governance architecture.

[0110] Furthermore, in this embodiment of the application, the layered defense module 20 is also used to perform the following steps:

[0111] Based on the hardware level, the computing power of the data-driven decision-making system is optimized, dynamically allocated according to the optimization results, and multiple security-sensitive tasks are physically isolated and stored to generate the first defense parameter. Based on the software level, the data-driven decision-making system is subjected to operational anomaly detection, and real-time operational threat parameters are logically isolated to generate the second defense parameter. Based on the data level, federated learning is used to perform distributed training on the data-driven decision-making system to generate a data privacy protection scheme, which is mapped to the blockchain for recording and combined with data end-to-end traceability tags to generate the third defense parameter. Based on the algorithm level, the interpretable component is used to visualize the data-driven decision-making system. The system performs attribution analysis to generate attribution results. It then conducts dynamic adversarial testing on these results using the verification tool to generate a fourth defense parameter. Based on the application layer, it simulates fault attack scenarios using the scenario-based risk management mechanism. The system then automatically responds to the simulated fault attack scenarios, generating anomaly blocking parameters, which are added to the fifth defense parameter. Finally, it links the first, second, third, fourth, and fifth defense parameters at multiple levels—hardware, software, data, algorithm, and application—to construct the security mechanism.

[0112] Furthermore, in this embodiment of the application, the layered defense module 20 is also used to perform the following steps:

[0113] Suspicious data is identified based on the first, second, third, fourth, and fifth defense parameters. Data is integrated according to the identification results to obtain a shared threat dataset. Security defense analysis is performed based on the hardware, software, data, algorithm, and application layers to construct a security log containing security rules. Collaborative analysis is performed on the multiple layers based on the security rules to construct a cross-level collaborative strategy. The security log is linked with the shared threat dataset according to the cross-level collaborative strategy to construct the security mechanism.

[0114] Furthermore, in this embodiment of the application, the protection deployment module 30 is also used to perform the following steps:

[0115] Based on the trusted execution environment deployed at the hardware layer, the integrity of the key dataset of the data-driven decision-making system is verified. According to the verification results and the first defense parameter, the key dataset is encrypted in memory to generate an encrypted dataset. Based on the data layer, the encrypted dataset is subjected to encryption gradient exchange according to the trusted execution environment and the second defense parameter to obtain encrypted data protection information. Based on the algorithm layer, the encrypted execution environment and the fourth defense parameter are used to generate runtime security logs for defense optimization, generating proactive defense rules. Based on the application layer, the encrypted data protection information is subjected to trajectory extrapolation according to the proactive defense rules using the trusted execution environment and the fifth defense parameter, generating system resilience parameters for the data-driven decision-making system. Based on the encrypted dataset, the encrypted data protection information, the proactive defense rules, and the system resilience parameters, intrinsic security protection is implemented throughout the entire lifecycle of the data-driven decision-making system, generating the proactive defense strategy.

[0116] Furthermore, in this embodiment, the intrinsic security protection module 40 is also used to perform the following steps:

[0117] The system continuously monitors the data-driven decision-making system to execute the proactive defense strategy, obtaining real-time threat intelligence. It retrieves the operational status information of the data-driven decision-making system and performs multi-level collaborative risk analysis based on the real-time threat intelligence and operational status information to obtain a full-process risk parameter set. It then performs collaborative governance of the multiple levels of the data-driven decision-making system according to the full-process risk parameter set, generating system collaborative governance feedback information. Finally, it dynamically adjusts the proactive defense strategy based on the system collaborative governance feedback information, generating an proactive defense optimization strategy, and provides dynamic protection for the data-driven decision-making system's intrinsic security according to the proactive defense optimization strategy.

[0118] Furthermore, in this embodiment, the intrinsic security protection module 40 is also used to perform the following steps:

[0119] Based on the cross-level collaborative strategy, the data-driven decision-making system collects data in real time across multiple levels to obtain security event data at multiple levels; it traverses the operational status information to extract operational status data at multiple levels, and performs collaborative governance on the multiple levels in accordance with the full-process risk parameter set and the operational status data at multiple levels to generate initial collaborative governance information; it then performs reverse verification on the initial collaborative governance information based on the security event data at multiple levels to generate collaborative governance feedback information.

[0120] Furthermore, in this embodiment, the intrinsic security protection module 40 is also used to perform the following steps:

[0121] The system collaborative governance feedback information is broken down into multiple collaborative feedback information by traversing the multiple levels; the proactive defense strategy is broken down into multiple proactive defense parameters by traversing the multiple levels; the multiple collaborative feedback information and the multiple proactive defense parameters are matched and aligned according to the multiple levels to construct a data adjustment list; based on the data adjustment list, the multiple proactive defense parameters are dynamically optimized according to the multiple collaborative feedback information to generate multiple defense optimization parameters; the multiple defense optimization parameters are subjected to intrinsic security deduction according to the multiple levels to generate the proactive defense optimization strategy.

[0122] Through the foregoing detailed description of the intrinsic security protection method for data-driven decision-making systems, those skilled in the art can clearly understand that the intrinsic security protection system for data-driven decision-making systems in this embodiment, as corresponding to the method disclosed in Embodiment 2, has corresponding functional modules and beneficial effects. For relevant details, please refer to the method section.

[0123] Furthermore, based on the same inventive concept as the aforementioned Embodiment 1, this application also provides a computer-readable storage medium storing a computer program thereon. When the computer program is executed by a processor, it implements the various processes of the above-described embodiment of the intrinsic security protection method for data-driven decision-making systems and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0124] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. An intrinsic security protection method for data-driven decision-making systems, characterized in that, The method includes: A full-stack intrinsic security governance architecture is constructed, which includes multiple layers, including a hardware layer based on a heterogeneous computing architecture using a trusted execution environment, a software layer that integrates a security development framework with a containerized isolation mechanism, a data layer constructed using federated learning for blockchain traceability, an algorithm layer constructed based on interpretable components and verification tools, and an application layer constructed based on a scenario-based risk management mechanism. Based on the aforementioned multiple levels, a layered defense system for data-driven decision-making is implemented to establish a security mechanism. Based on a trusted execution environment, the security mechanism is embedded into the entire lifecycle of the data-driven decision-making system for intrinsic security protection, generating proactive defense strategies. The active defense strategy is implemented to manage the risk of the data-driven decision-making system throughout the entire process, determine the system collaborative governance feedback information, and carry out security protection based on the system collaborative governance feedback information, thereby achieving intrinsic security protection for the data-driven decision-making system. Based on the hardware layer, the computing power of the data-driven decision-making system is optimized, and dynamic allocation is performed according to the optimization results. Multiple security-sensitive tasks are physically isolated and stored to generate the first defense parameters. Based on the software hierarchy, the data-driven decision-making system is subjected to operational anomaly detection, and real-time operational threat parameters are logically isolated to generate second defense parameters. Based on the data hierarchy, federated learning is used to perform distributed training on the data-driven decision-making system to generate a data privacy protection scheme. The data privacy protection scheme is mapped to the blockchain for recording and combined with the data end-to-end traceability tag to generate a third defense parameter. Based on the algorithm hierarchy, the interpretable component is used to perform visual attribution analysis on the data-driven decision system to generate attribution results. The attribution results are then subjected to dynamic adversarial testing using the verification tool to generate a fourth defense parameter. Based on the application layer, the scenario-based risk management mechanism is used to simulate fault attack scenarios. The data-driven decision system is automatically responded to according to the simulated fault attack scenarios, and abnormal blocking parameters are generated and added to the fifth defense parameters. The first defense parameter, the second defense parameter, the third defense parameter, the fourth defense parameter, and the fifth defense parameter are linked in a multi-level manner according to the hardware level, the software level, the data level, the algorithm level, and the application level to construct the security mechanism.

2. The intrinsic security protection method for data-driven decision-making systems as described in claim 1, characterized in that, A full-stack intrinsic security governance architecture is constructed, comprising multiple layers including hardware, software, data, algorithm, and application layers. The method includes: The hardware layer is used for the secure storage of parameters and the dynamic allocation of sensitive tasks within the data-driven decision-making system. The software layer is used to monitor and capture real-time threat parameters of the data-driven decision-making system in real time. The data hierarchy is used to protect the data privacy of parameters within the data-driven decision-making system and generate data traceability tags across the entire data chain. The algorithm hierarchy is used to perform decision attribution analysis and dynamically adjust defense strategies; The application layer is used for scenario simulation; The hardware layer, software layer, data layer, algorithm layer, and application layer are interconnected and integrated to construct the full-stack intrinsic security governance architecture.

3. The intrinsic security protection method for data-driven decision-making systems as described in claim 1, characterized in that, The security mechanism is constructed by linking the first, second, third, fourth, and fifth defense parameters at multiple levels: hardware, software, data, algorithm, and application. The method includes: Suspicious data is identified based on the first defense parameter, the second defense parameter, the third defense parameter, the fourth defense parameter, and the fifth defense parameter. Data is then integrated according to the identification results to obtain a shared threat dataset. Security defense analysis is performed based on the hardware layer, the software layer, the data layer, the algorithm layer, and the application layer to construct a security log, which contains security rules. Based on the security rules, collaborative analysis is performed on the multiple levels to construct a cross-level collaborative strategy; The security logs are linked with the shared threat dataset according to the cross-level collaboration strategy to construct the security mechanism.

4. The intrinsic security protection method for data-driven decision-making systems as described in claim 1, characterized in that, Based on a trusted execution environment, the security mechanism is embedded into the entire lifecycle of the data-driven decision-making system for intrinsic security protection, generating a proactive defense strategy. The method includes: The trusted execution environment deployed at the hardware level performs integrity verification on the key datasets of the data-driven decision-making system. Based on the verification results and the first defense parameter, the key datasets are encrypted in memory to generate encrypted datasets. Based on the data hierarchy, the encrypted dataset is subjected to encryption gradient exchange according to the trusted execution environment and the second defense parameters to obtain encrypted data protection information. Based on the algorithm level, the trusted execution environment is combined with the fourth defense parameter to generate runtime security logs for defense optimization, and proactive defense rules are generated. Based on the application layer, the encrypted data protection information is simulated according to the active defense rules through the trusted execution environment and the fifth defense parameter, thereby generating the system elastic recovery capability parameters of the data-driven decision-making system. Based on the encrypted dataset, the encrypted data protection information, the proactive defense rules, and the system elastic recovery capability parameters, intrinsic security protection is provided for the entire lifecycle of the data-driven decision-making system, and the proactive defense strategy is generated.

5. The intrinsic security protection method for data-driven decision-making systems as described in claim 3, characterized in that, The proactive defense strategy is implemented to manage risks throughout the entire process of the data-driven decision-making system, determine system collaborative governance feedback information, and perform security protection based on the system collaborative governance feedback information, thereby achieving intrinsic security protection for the data-driven decision-making system. The method includes: The data-driven decision-making system continuously monitors the implementation of the proactive defense strategy to obtain real-time threat intelligence. Retrieve the operational status information of the data-driven decision-making system, and conduct multi-level collaborative risk analysis based on the real-time threat intelligence and the operational status information to obtain a full-process risk parameter set; The data-driven decision-making system is collaboratively governed at multiple levels according to the full-process risk parameter set, and system collaborative governance feedback information is generated. The proactive defense strategy is dynamically adjusted based on the feedback information from the system's collaborative governance, generating an optimized proactive defense strategy. The data-driven decision-making system is then dynamically protected for inherent security based on this optimized proactive defense strategy.

6. The intrinsic security protection method for data-driven decision-making systems as described in claim 5, characterized in that, The method involves collaborative governance of the multiple levels of the data-driven decision-making system based on the aforementioned full-process risk parameter set, generating system collaborative governance feedback information, including: Based on the cross-level collaboration strategy, the data-driven decision-making system collects data in real time from multiple levels to obtain security event data from multiple levels. The operation status information is traversed to extract operation status data at multiple levels. The multiple levels are then collaboratively governed according to the full-process risk parameter set and the operation status data at multiple levels to generate initial collaborative governance information. Based on the security event data from the multiple levels, the initial collaborative governance information is reverse-verified to generate the collaborative governance feedback information.

7. The intrinsic security protection method for data-driven decision-making systems as described in claim 5, characterized in that, The method of dynamically adjusting the proactive defense strategy according to the system collaborative governance feedback information to generate a proactive defense optimization strategy, and then providing dynamic protection for the intrinsic security of the data-driven decision-making system according to the proactive defense optimization strategy, includes: The system collaborative governance feedback information is broken down by traversing the multiple levels to obtain multiple collaborative feedback information. The active defense strategy is broken down by traversing the multiple levels to obtain multiple active defense parameters; The multiple collaborative feedback information and the multiple active defense parameters are matched and aligned according to the multiple levels to construct a data adjustment list; Based on the data adjustment list, the multiple active defense parameters are dynamically optimized according to the multiple collaborative feedback information to generate multiple defense optimization parameters; The active defense optimization strategy is generated by performing intrinsic security deduction on the multiple defense optimization parameters according to the multiple levels.

8. An intrinsic security protection system for data-driven decision-making systems, characterized in that: The system is used to execute the intrinsic security protection method for data-driven decision-making systems according to any one of claims 1-7, including: The architecture building module is used to construct a full-stack intrinsic security governance architecture, which includes multiple layers, including hardware layer, software layer, data layer, algorithm layer, and application layer. The layered defense module is used to perform layered defense on the data-driven decision-making system based on the multiple layers, and to establish a security mechanism. The protection deployment module is used to embed the security mechanism into the entire lifecycle of the data-driven decision system based on a trusted execution environment for intrinsic security protection and to generate proactive defense strategies. The intrinsic security protection module is used to execute the proactive defense strategy to perform full-process risk management of the data-driven decision-making system, determine the system collaborative governance feedback information, and perform security protection based on the system collaborative governance feedback information, thereby realizing intrinsic security protection for the data-driven decision-making system.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps in the intrinsic security protection method for data-driven decision systems as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Distributed photovoltaic energy intelligent group dispatching and group control system based on machine learning

    CN118554625A

  • Network security system construction method and system

    CN118890208A