Security management method, system and storage medium for data governance
By setting protection levels and generating authentication password combinations in data governance, combined with dynamic encryption and load balancing mechanisms, the problem of insufficient data sensitivity in existing technologies is solved, and refined security management and efficient secure transmission of data are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ZHENGZHOU BIG DATA DEV CO LTD
- Filing Date
- 2025-07-30
- Publication Date
- 2026-05-19
AI Technical Summary
Existing data governance technologies are insufficient for providing precise protection based on the importance of the data, leading to the risk of sensitive data being leaked.
Protection levels are set by analyzing the importance of each piece of target data on the target server, generating authentication password combinations, and performing differentiated encryption and access control based on user identity and access permission levels. Target passwords and forwarders are updated in real time, and data transmission is optimized by combining load balancing mechanisms.
It enables differentiated protection for different types of data, improves the security and control of data access, avoids resource waste and potential security risks, and ensures the secure transmission and reasonable access of data in complex network environments.
Smart Images

Figure CN120896742B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, and in particular to security management methods, systems and storage media for data governance. Background Technology
[0002] With the rapid development of information technology, data has become a core asset of enterprises and society, and its importance is increasingly prominent. However, existing data governance technologies have many shortcomings in terms of security. In enterprise data management, servers store a large amount of data with varying degrees of sensitivity, ranging from public documents to core financial data. However, existing methods are difficult to provide fine-grained protection based on the importance of the data, and usually adopt a uniform security strategy, leading to the risk of sensitive data leakage. A similar existing technology is Chinese Patent CN120217438A, which proposes an enterprise risk data security management system and method, involving the field of enterprise data security management technology. The method includes the following steps: based on the internal data of the enterprise platform, the risk level of the internal data is classified through administrator accounts; employee information is collected and an employee database is established; different levels of employee data access permissions are granted; for the risk data stored in the enterprise platform, the access behavior of different users with access rights to the risk data is collected, and combined with the access habits of different users, a comprehensive judgment is made on whether the current risk data is at risk of leakage, and the risk level is marked; based on the risk level of the current risk data, data protection is implemented for the current risk data, including temporary blocking and access blocking, and anomalies are reported to the administrator account. This patent combines enterprise data access records with employee access behavior habits to comprehensively manage and protect internal enterprise data. A similar prior art is Chinese patent CN119089507B, which proposes a collaborative office security system to prevent information leakage. This system addresses the problem of information leakage caused by human error in failing to encrypt important files. It includes a collaborative tool selection module, a real-time collaboration module, a sensitive information identification module, and a file management module. The system selects collaborative tools based on the project content and enterprise requirements, uses the selected tools for real-time collaboration, calculates the sensitivity index of files, identifies sensitive files exceeding a threshold, and encrypts them. The system manages encrypted files based on a calculated security risk index, effectively preventing information leakage due to human error and improving the efficiency and security of collaborative work. While these two patents address the security issues of internal enterprise data, existing methods struggle to provide fine-grained protection based on data importance, often employing a uniform security strategy, which leaves sensitive data at risk of leakage. Summary of the Invention
[0003] This application provides a security management method, system, and storage medium for data governance. By combining multiple technologies such as data protection, authentication management, encrypted transmission, and load balancing, this invention effectively improves the security and reliability of data governance, ensuring secure data transmission and legitimate access in complex network environments. The method includes:
[0004] The importance of each target data in the target server is analyzed to set the protection level. An authentication password combination is generated based on the user's identity information and corresponding access permission level. The target password corresponding to the user in the authentication password combination is sent to the user terminal.
[0005] When a user accesses the target data through a user terminal by authenticating with an account and the target password, the user selects the target forwarder corresponding to the target data and connects to the target server through the target forwarder.
[0006] The target server selects the corresponding encryption method according to the protection level of the target data to encrypt the target data, and sends the encrypted target data to the corresponding user terminal through the repeater;
[0007] The system collects data in real time and, based on the protection level and user risk information of each target data, re-acquires the new target password and updates the target repeater corresponding to the target data.
[0008] The user terminal receives and parses the encrypted target data, and when the protection level of the target data or the user's risk information changes, it controls the user terminal to parse and receive the target data according to the user's access permission level and the protection level of the currently transmitted target data.
[0009] As a preferred embodiment of the present invention, the generation of the authentication password combination includes:
[0010] The importance of each piece of target data in the target server is analyzed and a corresponding protection level is set according to the classification criteria. The access permission level is obtained based on the identity information of each user and the highest protection level allowed to access the target data. The authentication password set is generated according to the password complexity standard corresponding to the access permission level and the password generator. The authentication password set includes the target password and the corresponding backup password when the user's identity information or access permission level changes within a set range.
[0011] As a preferred embodiment of the present invention, selecting the target data corresponding to the target repeater includes:
[0012] The target data is sorted according to the corresponding protection level from smallest to largest, and the N target data of different levels are divided into the same group according to the sorting. The same forwarder is assigned to each group. When the user terminal accesses the target data through the authentication of the account and the target password, the forwarder corresponding to the group where the target data is located is used as the target forwarder of the target data, and the connection is made to the target server through the target forwarder.
[0013] As a preferred embodiment of the present invention, re-acquiring the target forwarder corresponding to the target data whose target password and protection level have changed includes:
[0014] When the user enters their account and target password for authentication through the user terminal, the number of times the user enters the target password incorrectly within a first preset time period is recorded. After successful authentication, the number of times the user attempts to access the target data that is not within the user's corresponding permission range within a second preset time period is recorded. The first number and the second number are weighted to obtain user risk information. When the user risk information is greater than a set threshold, the access permission level corresponding to the user's identity information is reduced; otherwise, it remains unchanged.
[0015] Simultaneously, the changes in the protection level and user identity information of each target data are collected in real time. Based on the changed protection level of the target data, the user's identity information, and the access permission level, a new target password is selected from the prepared passwords of the authentication password combination. When the user's risk information is less than or equal to the set threshold, the user's access permission level and the corresponding target password are restored. After the protection level of the target data changes, the corresponding target forwarder is reacquired.
[0016] As a preferred embodiment of the present invention, the control of the user terminal for parsing and receiving the target data includes:
[0017] When the protection level of the target data or the user's permission level changes, the protection level of the currently transmitted target data is compared. If the user's permission level is lower than the protection level of the target data, a blocking command is sent to the target repeater and the user terminal to stop forwarding and receiving. The user terminal is also stopped from parsing the encrypted target data, and the parsed or unparsed target data is deleted.
[0018] As a preferred technical solution of the present invention, when selecting the target repeater corresponding to the target data, the data forwarding delay of the target repeater corresponding to the group where the target data is located is also considered. When the delay exceeds a set delay time, the repeater with the smallest forwarding data volume is used as the backup repeater for the target data. The original target data corresponding to the backup repeater is forwarded through the repeater corresponding to other target data with the closest corresponding protection level.
[0019] As a preferred embodiment of the present invention, the repeater is a distributed forwarding server.
[0020] As a preferred embodiment of the present invention, the target server includes a variety of target data.
[0021] The present invention also provides a security management system for data governance, for implementing the method described above, the system comprising:
[0022] The generation unit is used to analyze the importance of each target data in the target server, set the protection level, generate an authentication password combination based on the user's identity information and corresponding access permission level, and send the target password corresponding to the user in the authentication password combination to the user terminal.
[0023] The forwarding unit is used to select the target forwarder corresponding to the target data when a user accesses the target data through a user terminal based on an account and the target password, and connect to the target server through the target forwarder.
[0024] The target server is used to select the corresponding encryption method according to the protection level of the target data to encrypt the target data, and send the encrypted target data to the corresponding user terminal through the repeater;
[0025] The update unit is used to collect data in real time and, based on the protection level and user risk information of each target data, re-acquire the new target password and update the target repeater corresponding to the target data;
[0026] The user terminal is used to receive and parse the encrypted target data;
[0027] The control unit is used to control the user terminal to parse and receive the target data according to the user's access permission level and the protection level of the target data currently being transmitted, when the protection level of the target data or the user's risk information changes.
[0028] The present invention also provides a computer-readable storage medium storing instructions that, when executed by a processor, implement the above-described method.
[0029] Effect
[0030] The security management method, system, and storage medium for data governance provided by this invention significantly improve the security and control of data access through refined security management. First, this method analyzes the importance of each piece of target data on the target server and sets protection levels based on its sensitivity, thereby achieving differentiated protection for different types of data. This hierarchical management based on protection levels allows highly sensitive data to receive stronger encryption protection, while less sensitive data can be protected with lighter measures, avoiding resource waste. Second, this invention generates authentication password combinations by combining user identity information and access permission levels, ensuring that only authorized users can access data within their authorized scope. The authentication password combination includes not only the target password but also a backup password. When user identity information or access permission levels change, the system can automatically switch passwords, ensuring the flexibility and security of password management. This method effectively avoids security risks caused by changes in permissions or password leaks. Furthermore, the dynamic encryption mechanism of this invention selects an appropriate encryption method based on the protection level of the target data, ensuring data security during transmission. Encrypted data is transmitted to the user terminal via a target repeater. During transmission, the protection level of the target data and the user's risk information are collected and analyzed in real time. When changes occur, the target password and authentication password combination are updated promptly, thereby reducing potential security risks. Furthermore, by controlling the user terminal's parsing and reception of target data, this invention can promptly prevent unauthorized access when user permissions change or the protection level of the target data is upgraded, preventing sensitive data leakage. Even in high-risk environments, the system can effectively protect data security through password updates and permission adjustments. Finally, the repeater load balancing mechanism in the system dynamically distributes data transmission tasks among multiple repeaters, avoiding transmission delays or failures caused by excessive load on a single repeater, thus ensuring the stability and efficiency of the system under high concurrency. Through the synergy of the above technical solutions, the security and reliability of data governance are effectively improved, ensuring secure data transmission and legitimate access in complex network environments. Attached Figure Description
[0031] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0032] Figure 1 This is a flowchart of a security management method for data governance in an embodiment of this application;
[0033] Figure 2 This is a flowchart illustrating the method for generating authentication password combinations in this application embodiment;
[0034] Figure 3 This is a flowchart illustrating the method for re-acquiring the target password and the target repeater corresponding to the target data whose protection level has changed, as described in this application embodiment.
[0035] Figure 4 This is a structural diagram of a security management system for data governance in an embodiment of this application. Detailed Implementation
[0036] This application provides a security management method, system, and storage medium for data governance. The terms "first," "second," "third," "fourth," etc. (if present) in the specification, claims, and accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in a sequence other than that illustrated or described herein. Furthermore, the terms "comprising" or "having" and any variations thereof are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0037] For ease of understanding, the specific process of the embodiments of this application is described below, such as... Figure 1 As shown in the embodiment of this application, a security management method for data governance includes:
[0038] Step S1: Analyze the importance of each target data in the target server, set the protection level, generate an authentication password combination based on the user's identity information and corresponding access permission level, and send the target password corresponding to the user in the authentication password combination to the user terminal;
[0039] Specifically, the importance of various types of data on the target server is first analyzed, such as sensitivity and business value. Protection levels are then categorized according to preset standards, ranging from L1 (public documents) to L3 (financial data). Based on user identity (e.g., position, department) and the highest accessible protection level, corresponding access permission levels are generated. Subsequently, password complexity rules are matched according to the permission level (e.g., Level 3 requires 12 characters including special characters). An authentication password combination is created using a password generator, containing the currently used target password and a backup password. The backup password is pre-generated based on permission change scenarios, such as user promotion or data security level adjustment, and stored in the authentication password combination. This technical solution enforces complex passwords for high-privilege accounts, preventing low-strength credentials from accessing sensitive data. For low-privilege users, password rules are simplified, improving operability. When user permissions or data security levels change within a preset range, the backup password is directly called to update the target password, eliminating the need for real-time password generation and significantly reducing computational resource consumption (e.g., avoiding frequent calls to the password generator). The backup password mechanism achieves "zero-latency" response to permission changes, while also reducing operational burden and laying the foundation for subsequent access control.
[0040] Step S2: When a user accesses the target data through a user terminal using their account and the target password, they select the target forwarder corresponding to the target data and connect to the target server through the target forwarder.
[0041] Specifically, the target data is sorted in ascending order of protection level, such as L1→L3. N data of adjacent levels are divided into the same group, such as Group A containing L1-L3. Each group is bound to a dedicated forwarder, such as target forwarder F1. When a user accesses specific data, the system locates the group to which it belongs. For example, L2 data belongs to Group A, and the system automatically selects the target forwarder F1 within the group to establish a "user terminal→F1→target server" link. The above technical solution ensures physical isolation between high-security data and low-security data through group design. Even if a forwarder is compromised, the attacker can only obtain a limited range of data within the group. Based on data grouping rather than fixed paths, high-value data is avoided from being exposed to general transmission channels, increasing the difficulty for attackers to locate the data.
[0042] Step S3: The target server selects the corresponding encryption method according to the protection level of the target data to encrypt the target data, and sends the encrypted target data to the corresponding user terminal through the repeater;
[0043] Specifically, the target server dynamically selects the encryption method based on the data protection level. For example, L3 data uses AES-256, and L1 data uses DES. The encrypted data is then transmitted to the user terminal via the repeater selected in step S2. Simultaneously, the system collects data protection level changes and user behavior in real time, such as the number of incorrect password attempts and unauthorized access attempts, generating user risk information. This technical solution ensures security through strong encryption of highly sensitive data, improves transmission efficiency through lightweight encryption of low-sensitivity data, and provides real-time monitoring to support the dynamic password adjustment in step S4, forming a closed loop for data security governance.
[0044] Step S4: Collect data in real time and, based on the protection level and user risk information of each target data, re-acquire the new target password and update the target repeater corresponding to the target data;
[0045] Specifically, by recording the number of incorrect password attempts within a preset time period (e.g., 3 incorrect attempts within 10 minutes) and the number of unauthorized access attempts after authentication (e.g., 2 consecutive attempts to access L3 data within 20 minutes), a weighted risk value is calculated. For example, an error weight of 0.6 + an unauthorized access weight of 0.4 = a risk value of 2.6. If the risk value exceeds a threshold (e.g., 2.0), the user's access privileges are immediately reduced (e.g., from Level 3 to Level 2). A new target password is selected from the prepared passwords, and the original privileges and password are automatically restored when the risk value falls back below the threshold. This technical solution quantifies abnormal behavior through risk values, triggering a reduction in privileges in the early stages of password cracking or unauthorized access attempts, blocking potential attacks, and automatically restoring privileges after the risk is eliminated. This avoids permanent access interruption due to accidental operations, balancing security and user experience.
[0046] Step S5: The user terminal receives and parses the encrypted target data, and when the protection level of the target data or the user risk information changes, it controls the user terminal to parse and receive the target data according to the user's access permission level and the protection level of the currently transmitted target data.
[0047] Specifically, when the data protection level or user permissions change (e.g., financial data is upgraded from L2 to L3, or user permissions are downgraded from Level 3 to Level 2), the protection level of the currently transmitted data is compared with the user permissions in real time. If the permissions are lower than the data security level (e.g., a Level 2 user accessing L3 data), a blocking command is sent to the repeater to stop data forwarding; a cleanup command is sent to the user terminal to terminate data parsing and delete the received encrypted / decrypted data. This technical solution solves the data leakage risk caused by "delayed permission changes" in traditional systems, ensures strict synchronization between permissions and data access, forcibly clears unparsed / partially parsed data, prevents highly sensitive information from remaining on the terminal, such as financial statements in temporary cache, meets compliance requirements, and thus improves data security.
[0048] Furthermore, the generation of the authentication password combination, such as Figure 2 As shown, it includes:
[0049] The importance of each piece of target data in the target server is analyzed and a corresponding protection level is set according to the classification criteria. The access permission level is obtained based on the identity information of each user and the highest protection level allowed to access the target data. The authentication password set is generated according to the password complexity standard corresponding to the access permission level and the password generator. The authentication password set includes the target password and the backup password corresponding to the change of the protection level of the user's identity information or the highest level of target data allowed to be accessed by the user within a set range.
[0050] Specifically, the target server stores confidential and regular data of varying sensitivity or importance to the enterprise. The importance of each piece of target data on the target server is analyzed, such as sensitivity, business value, or confidentiality level. Based on preset classification standards, corresponding protection levels are set for the data. For example, financial data might be classified as the highest protection level L3, while public documents are set to the lowest level L1. Based on the user's identity information, such as position, department, and the highest protection level of the target data they are allowed to access, the user's access permission level is automatically generated. For example, financial personnel can access L3 data, and their permission level is marked "Level 3"; ordinary employees can only access L1 data, with a permission level of "Level 1". A password generator is invoked, and an authentication password set is generated based on the password complexity standard corresponding to the access permission level. This authentication password set includes not only the target password but also backup passwords. The generation of the target password includes, for example, high-privilege users, such as Level... 3. A strong password rule must be met, such as a 12-character password containing special characters. For Level 1 users with low privileges, a simpler rule applies, such as an 8-character alphanumeric combination. This generates a target password suitable for the user. The user's identity information and the highest level of protection for the target data allowed to the user are used as the access permission settings. Because when accessing large amounts of data, changes in the user's access permission settings—for example, a user promotion, or an increase or decrease in the protection level of the highest-level target data—are necessary due to limited computing resources and the requirement for timely updates to the target password. Furthermore, since the access permission settings generally do not change significantly, therefore… To reduce computational resource consumption and ensure timely updates of the target password when the aforementioned permission settings change within the defined range, this technical solution involves pre-setting the changed permission settings and obtaining a backup password based on the password generator. This strict matching of permissions and password strength prevents low-privilege credentials from accessing high-security data. It also facilitates password memorization and operation for low-privilege users. The backup password not only saves computational resources but also ensures automated password management and enables zero-latency switching during permission changes, significantly reducing operational burden and laying the foundation for improved access security for the target data.
[0051] Further, selecting the target repeater corresponding to the target data includes:
[0052] The target data is sorted according to the corresponding protection level from smallest to largest, and the N target data of different levels are divided into the same group according to the sorting. The same forwarder is assigned to each group. When the user terminal accesses the target data through the authentication of the account and the target password, the forwarder corresponding to the group where the target data is located is used as the target forwarder of the target data, and the connection is made to the target server through the target forwarder.
[0053] Specifically, the target data on the target server is sorted by its protection level from lowest to highest, such as L1 public documents → L3 financial data. According to preset rules, N target data of different protection levels are grouped into the same group, for example, L1, L2, and L3 data are merged into Group A. A unique forwarder is assigned to each group, such as Group A being bound to forwarder F1. The grouping is designed based on the continuity of protection levels; for example, adjacent levels of data are merged, with L1-L3 forming a group. By grouping target data with similar protection levels, the need for users to access multi-level data is met while preventing the exposure of highly sensitive data. Even if an attacker infiltrates a forwarder, they can only obtain a limited range of data within the group and cannot directly locate all high-value data on the server. When a user terminal logs in and accesses a page using an account and target password authentication to access specific target data, the group to which the data belongs is located; for example, if the target data is at level L2, it belongs to Group F1. Group A automatically binds the forwarder F1 to the target forwarder, establishing a dedicated link from "user terminal → target forwarder F1 → target server". Each group is assigned a unique forwarder, such as Group A binding forwarder F1. This technical solution, by grouping target data at different protection levels, not only saves communication resources but also prevents the leakage of target data at high protection levels, thereby improving data transmission security.
[0054] Furthermore, re-acquire the target repeater corresponding to the target password and the target data whose protection level has changed, such as... Figure 3 As shown, it includes:
[0055] When a user authenticates by entering their account and target password through the user terminal, the number of times the user enters the target password incorrectly within a first preset time period is recorded. After successful authentication, the number of times the user attempts to access the target data outside the user's corresponding permission range within a second preset time period is recorded. The first and second attempts are weighted to obtain user risk information. At the same time, the changes in the protection level of each target data and the user's identity information are collected in real time. When the user risk information is greater than a set threshold, the access permission level corresponding to the user's identity information is reduced. When the user risk information is less than or equal to the set threshold, the access permission level remains unchanged.
[0056] Based on the protection level corresponding to the changed target data, the user identity information, and the access permission level, a new target password is selected from the prepared passwords of the authentication password combination. When the user risk information is less than or equal to the set threshold, the user's access permission level and the corresponding target password are restored. After the protection level corresponding to the target data changes, the corresponding target forwarder is reacquired.
[0057] Specifically, when a user authenticates by entering their account and target password through a user terminal, the system records the number of times the user incorrectly enters the target password within a first preset time period, such as 10 minutes (the first count). After the above incorrect authentication is successful, within a second preset time period, such as 20 consecutive minutes, the system monitors the number of times the user attempts to access target data beyond their authorized scope (the second count). For example, a regular employee attempting to access financial data, which is L3 level target data. Both the first and second counts reflect attacks and malicious operations on the user's account. Therefore, the first and second counts are weighted according to preset weights, such as 0.6 for incorrect counts and 0.4 for unauthorized access counts, to generate a quantified user risk information value. For example: 3 incorrect counts × 0.6 + 2 unauthorized access counts × 0.4 = risk value 2.6. If the user risk information value is greater than a set threshold, such as threshold 2.0, it indicates that the user's password is at risk of being stolen or attacked. Therefore, the user's access permission level is immediately reduced, such as from Level 3 to Level 4. 2. Temporarily restrict access to the highest protection level of data, such as prohibiting access to L3 data. Based on the new access permission level, user identity information, and the current protection level of the target data, automatically select a new target password from the pre-generated authentication password combination. When the user's risk information recovers to less than or equal to the set threshold, restore the access permission level corresponding to the user identity information. Otherwise, maintain the original access permission level and target password. When the protection level of the target data changes, repeat step S2 to reacquire the target forwarder corresponding to the target data. The above technical solution can not only identify potential malicious operations of users in advance and intercept probing attacks in a timely manner by strengthening the target password, but also restore user permissions in a timely manner after the probing attack ends, thereby improving data security.
[0058] Furthermore, the control of the user terminal over the parsing and receiving of the target data includes:
[0059] When the protection level of the target data or the user's permission level changes, the protection level of the currently transmitted target data is compared. If the user's permission level is lower than the protection level of the target data, a blocking command is sent to the target repeater and the user terminal to stop forwarding and receiving. The user terminal is also stopped from parsing the encrypted target data, and the parsed or unparsed target data is deleted.
[0060] Specifically, when the protection level of the target data changes, such as financial data rising from L2 to L3, and the user's access privilege level changes, such as an employee being downgraded from Level 3 to Level 2, when either of the above two events occurs, the control process is immediately initiated. Since the above events may cause a change in the user's current access privilege to the target data, therefore, by extracting the protection level of the target data in the current transmission, such as the financial data being transmitted is L3, and obtaining the user's latest access privilege level, such as being Level 2 after downgrading, if the user privilege level is lower than the data protection level, such as Level 2 < L3, the blocking mechanism is triggered. First, a stop command is sent to the target forwarder to interrupt the forwarding link to the user terminal. Then, a stop command is sent to the user terminal to stop receiving the data stream, forcefully terminate the parsing process of the encrypted target data by the user terminal, and completely delete the parsed plaintext data in the terminal, such as partially decrypted financial statements. The encrypted data cache that has not been parsed, such as encrypted data packets in transmission, is synchronously cleared. The above technical solution can prevent the leakage of target data when the user's position changes or the protection level of the target data changes, thereby improving data security.
[0061] Furthermore, when selecting the corresponding target forwarder for the target data, the data forwarding delay of the target forwarder corresponding to the group where the target data is located is also considered. When the delay exceeds the set delay time, the forwarder with the smallest data forwarding volume is selected as the standby forwarder for the target data, and the original target data corresponding to the standby forwarder is forwarded through the target forwarder corresponding to other target data with the closest protection level.
[0062] Specifically, by continuously collecting the data forwarding delays of each group of forwarders, such as the delay time of the target forwarder F1 processing GroupA data, when the delay exceeds the set delay time, such as the 200ms threshold, it is determined that the forwarder is in an overloaded state. The node with the smallest current data forwarding volume is selected from all available forwarders, such as the load of forwarder F3 is only 20%, and it is designated as the standby forwarder. The original target data responsible for the overloaded forwarder (F1), such as the L2 sales report in Group A, is migrated to the standby forwarder (F3). When migrating, it is necessary to ensure the consistency of the data protection level. By matching the group where other target data with the closest protection level is located, such as GroupB contains L2 - L4 data, and its corresponding forwarder (F2) is used as a temporary channel. After the migration is completed, when the user accesses the data subsequently, it is directly routed to the standby forwarder (F3), forming a new path of "user terminal → F3 → target server". The original forwarder (F1) enters the cooling state until the load is normal. The above technical solution, by balancing the load of the above target forwarders, not only improves the data transmission security but also improves the forwarding efficiency of the target data.
[0063] Furthermore, N takes the value of a positive integer greater than or equal to 1.
[0064] Furthermore, the target server includes various types of target data, and the forwarder is a distributed forwarding server.
[0065] This invention also provides a security management system for data governance, used to implement the above-described method, such as... Figure 4 As shown, the system includes:
[0066] The generation unit is used to analyze the importance of each target data in the target server, set the protection level, generate an authentication password combination based on the user's identity information and corresponding access permission level, and send the target password corresponding to the user in the authentication password combination to the user terminal.
[0067] The forwarding unit is used to select the target forwarder corresponding to the target data when a user accesses the target data through a user terminal based on an account and the target password, and connect to the target server through the target forwarder.
[0068] The target server is used to select the corresponding encryption method according to the protection level of the target data to encrypt the target data, and send the encrypted target data to the corresponding user terminal through the repeater;
[0069] The update unit is used to collect data in real time and re-acquire the target password and the target repeater corresponding to the target data based on the protection level and user risk information of each target data.
[0070] The user terminal is used to receive and parse the encrypted target data;
[0071] The control unit is used to control the user terminal to parse and receive the target data according to the user's access permission level and the protection level of the target data currently being transmitted, when the protection level of the target data or the user's risk information changes.
[0072] The present invention also provides a computer-readable storage medium storing instructions, wherein the instructions, when executed by a processor, implement the method as described in any one of claims 1-8.
[0073] In summary, this invention achieves differentiated protection for different types of data by analyzing the importance of each piece of target data on the target server and setting protection levels based on their sensitivity. This hierarchical management based on protection levels allows highly sensitive data to receive stronger encryption protection, while less sensitive data can be protected with lighter measures, avoiding waste of resources. Secondly, this invention generates authentication password combinations by combining user identity information and access permission levels, ensuring that only authorized users can access data within their authorized scope. The authentication password combination includes not only the target password but also a backup password. When user identity information or access permission levels change, the system can automatically switch passwords, ensuring the flexibility and security of password management. This method effectively avoids security risks caused by changes in permissions or password leaks. Furthermore, the dynamic encryption mechanism of this invention selects an appropriate encryption method based on the protection level of the target data, ensuring data security during transmission. Encrypted data is transmitted to the user terminal via a target repeater. During transmission, the protection level of the target data and the user's risk information are collected and analyzed in real time. When changes occur, the target password and authentication password combination are updated promptly, thereby reducing potential security risks. Furthermore, by controlling the user terminal's parsing and reception of target data, this invention can promptly prevent unauthorized access when user permissions change or the protection level of the target data is upgraded, preventing sensitive data leakage. Even in high-risk environments, the system can effectively protect data security through password updates and permission adjustments. Finally, the repeater load balancing mechanism in the system dynamically distributes data transmission tasks among multiple repeaters, avoiding transmission delays or failures caused by excessive load on a single repeater, thus ensuring the stability and efficiency of the system under high concurrency. Through the synergy of the above technical solutions, the security and reliability of data governance are effectively improved, ensuring secure data transmission and legitimate access in complex network environments.
[0074] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0075] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0076] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A security management method for data governance, characterized in that, The method includes: S1. Analyze the importance of each target data in the target server and set a protection level. Generate an authentication password combination based on the user's identity information and corresponding access permission level, and send the target password corresponding to the user in the authentication password combination to the user terminal. The generation of the authentication password combination includes generating the authentication password set according to the password complexity standard corresponding to the access permission level and a password generator. The authentication password set includes the target password and a backup password corresponding to the change in the protection level of the user's identity information or the highest level of target data that the user is allowed to access within a set range. When the user's permissions or data security level change within a preset range, the backup password is directly called to update the target password without the need to generate a new password in real time. S2. Sort the target data in ascending order of protection level, divide N data of adjacent levels into the same group, bind a dedicated forwarder to each group, when a user accesses specific data, the system locates the group to which the specific data belongs and automatically selects the target forwarder in the group to establish a link, and connects to the target server through the target forwarder. S3. The target server selects the corresponding encryption method according to the protection level of the target data to encrypt the target data, and sends the encrypted target data to the corresponding user terminal through the repeater; S4. Record the number of incorrect password attempts and the number of unauthorized access attempts after authentication within a preset time and calculate the risk value by weighting them. If the risk value exceeds the threshold, immediately reduce the user's access permissions and select a new target password from the prepared passwords. When the risk value falls back below the threshold, automatically restore the original permissions and password. S5. When the data protection level or user permissions change, the protection level of the currently transmitted data is compared with the user permissions in real time. If the user permissions are lower than the data security level, a blocking command is sent to the repeater to stop data forwarding, and a cleanup command is sent to the user terminal to terminate data parsing and delete the received encrypted / decrypted data. The change in data protection level or user permissions includes upgrading, or the protection level of the highest level target data being raised or lowered. Among them, the data forwarding delay of each packet repeater is continuously collected. When the delay time of the target repeater in processing packet data exceeds the set delay time, the repeater with the smallest forwarding data volume is used as the backup repeater for the target data. The original target data corresponding to the backup repeater is forwarded through the repeater corresponding to other target data with the closest protection level.
2. The method according to claim 1, characterized in that, The generation of the authentication password combination includes: The importance of each piece of target data in the target server is analyzed and a corresponding protection level is set according to the classification criteria. The access permission level is obtained based on the identity information of each user and the highest protection level allowed to access the target data. The authentication password set is generated according to the password complexity standard corresponding to the access permission level and the password generator. The authentication password set includes the target password and the corresponding backup password when the user's identity information or access permission level changes within a set range.
3. The method according to claim 1, characterized in that, The control of the user terminal over the parsing and receiving of the target data includes: When the protection level of the target data or the user's permission level changes, the protection level of the currently transmitted target data is compared. If the user's permission level is lower than the protection level of the target data, a blocking command is sent to the target repeater and the user terminal to stop forwarding and receiving. The user terminal is also stopped from parsing the encrypted target data, and the parsed or unparsed target data is deleted.
4. The method according to claim 1, characterized in that, The repeater is a distributed forwarding server.
5. The method according to claim 1, characterized in that, The target server includes various types of target data.
6. A security management system for data governance, used to implement the method as described in any one of claims 1-5, characterized in that, The system includes: The generation unit is used to analyze the importance of each target data in the target server, set the protection level, generate an authentication password combination based on the user's identity information and corresponding access permission level, and send the target password corresponding to the user in the authentication password combination to the user terminal. The forwarding unit is used to select the target forwarder corresponding to the target data when a user accesses the target data through a user terminal based on an account and the target password, and connect to the target server through the target forwarder. The target server is used to select the corresponding encryption method according to the protection level of the target data to encrypt the target data, and send the encrypted target data to the corresponding user terminal through the repeater; The update unit is used to collect data in real time and, based on the protection level and user risk information of each target data, re-acquire the new target password and update the target repeater corresponding to the target data; The user terminal is used to receive and parse the encrypted target data; The control unit is used to control the user terminal to parse and receive the target data according to the user's access permission level and the protection level of the target data currently being transmitted, when the protection level of the target data or the user's risk information changes.
7. A computer-readable storage medium storing instructions thereon, characterized in that, When the instructions are executed by the processor, they implement the method as described in any one of claims 1-5.