Remote sensing data management system and method based on data lake
By generating index information sources and analyzing user access behavior in the data lake, and dynamically adjusting access strategies, the problem of high-risk access in remote sensing data management in the data lake is solved, thereby improving the security and controllability of remote sensing data.
Patent Information
- Application Number
- CN202511265253.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-05
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-09-05
AI Technical Summary
Existing remote sensing data management based on data lakes lacks real-time assessment of dynamic risks and in-depth analysis of access behavior, making it difficult to effectively deal with high-risk or abnormal access behavior, resulting in poor data security and controllability, especially in sensitive data and cross-departmental collaboration.
By generating an index information source when the parachain consensus of the parachain block is successful, identifying secure access nodes, analyzing user access information and risk assessment scores, and dynamically adjusting access policies, including permissions, real-time monitoring and access restrictions on remote sensing data can be achieved.
Effectively address high-risk or unusual access behaviors, enhance data security and controllability, ensure data is used only within authorized scope, reduce the risk of data leakage and misuse, and improve the flexibility and accuracy of data management.
Smart Images

Figure CN120979776A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data security management, more specifically, the present application relates to a remote sensing data management system and method based on data lake. BACKGROUND
[0003] Data security management refers to ensuring the confidentiality, integrity and availability of data in storage, processing, transmission and other aspects through a series of strategies, technologies and processes in an information system, preventing unauthorized access, leakage, tampering or destruction of data. It involves the protection of sensitive information, the control of data access, data backup and recovery, data encryption, and the security management of data transmission paths. The core goal of data security management is to reduce the risk of data leakage, data loss and data misuse, and to protect the information assets of individuals, enterprises and even countries in the digital age.
[0004] The existing remote sensing data management based on data lake is mainly a method of centralized storage, management and analysis of remote sensing data through data lake technology. Data lake is a highly scalable data storage architecture that can store large amounts of structured, semi-structured and unstructured data, suitable for processing large-scale data sets from satellites, drones and other remote sensing devices. For remote sensing data, these data usually include images, sensor data, environmental monitoring data, etc., with spatio-temporal characteristics and high-dimensional characteristics. In the data lake, remote sensing data does not need to be pre-structured for storage, but is stored in raw format for subsequent flexible query and analysis. However, in the existing remote sensing data management based on data lake, data access control usually relies on static permission settings and simple identity verification mechanisms, lacking real-time assessment of dynamic risks and in-depth analysis of access behaviors, making it difficult to effectively detect and protect high-risk or abnormal access behaviors in complex application scenarios, resulting in poor data security and controllability, especially in sensitive data and cross-departmental collaboration. Therefore, how to effectively detect and protect high-risk or abnormal access behaviors in complex application scenarios to improve the controllability of data protection in sensitive data and cross-departmental collaboration is a problem faced by the industry. SUMMARY
[0006] The present application provides a remote sensing data management system and method based on data lake, which can effectively detect and protect high-risk or abnormal access behaviors in complex application scenarios to improve the controllability of data protection in sensitive data and cross-departmental collaboration.
[0007] In a first aspect, the present application provides a remote sensing data management method based on data lake, which comprises the following steps: When the parallel chain consensus of the parallel chain block is successful, an index information source of the hydropower development basin is generated; A safe access node of remote sensing data in the hydropower development basin monitoring is determined according to the index information source, and an access identification attribute corresponding to a remote sensing monitoring target is determined through the safe access node; User access information of remote sensing data registered in a data lake under a current network security protocol is obtained, an access abnormal feature when data access is abnormal is determined according to the user access information, and then a data access strategy when the remote sensing data is accessed is determined according to the access abnormal feature and the access identification attribute; A risk judgment score of digital twin basin data under the influence of access risk is collected, a data access mode when the user accesses is determined according to the risk judgment score, and then an access request recognition of remote sensing data in the hydropower development basin is performed according to the data access mode, to obtain an identification attribute permission when access security is identified; The remote sensing data under the current network security protocol is accessed according to the data access strategy and the identification attribute permission.
[0008] In this embodiment, the index information source refers to a core information set used for quickly locating and retrieving target data.
[0009] In this embodiment, the safe access node of remote sensing data in the hydropower development basin monitoring is determined according to the index information source, and the safe access node of remote sensing data in the hydropower development basin monitoring is determined according to the index information source, and the safe access node of remote sensing data in the hydropower development basin monitoring is determined according to the index information source. An access period feature of remote sensing data in the hydropower development basin monitoring is extracted from the index information source; A safe influence value when the remote sensing data is accessed is determined; The safe access node of remote sensing data in the hydropower development basin monitoring is determined according to the access period feature and the safe influence value.
[0010] In this embodiment, the access identification attribute corresponding to the remote sensing monitoring target is determined through the safe access node, and the access identification attribute corresponding to the remote sensing monitoring target is determined through the safe access node. An access feature deviation corresponding to the remote sensing monitoring target is determined according to the safe access node; The access identification attribute corresponding to the remote sensing monitoring target is determined through the access feature deviation.
[0011] In this embodiment, the user access information refers to a collection of behaviors and related feature data generated by the user in the process of accessing a target system or a data resource (such as a data lake).
[0012] In this embodiment, the access abnormal feature when data access is abnormal is determined according to the user access information, and the access abnormal feature when data access is abnormal is determined according to the user access information. Safety evaluation data when the data is accessed is determined according to the user access information; determine access exception information when data access is abnormal; determine an access exception feature when data access is abnormal according to the security evaluation data and the access exception information.
[0013] In this embodiment, the data access strategy when accessing remote sensing data is determined according to the access exception feature and the access identification attribute, and specifically includes: determine an access attribute permission when accessing remote sensing data according to the access exception feature; determine an authentication control quantity when accessing remote sensing data according to the access identification attribute; determine a data access strategy when accessing remote sensing data according to the access attribute permission and the authentication control quantity.
[0014] In this embodiment, the risk judgment score represents the risk degree of a certain specific access request or operation to the system, data security, and overall business process.
[0015] In this embodiment, the data access mode when the user accesses is determined according to the risk judgment score, and specifically includes: determine access verification information when the user accesses through the risk judgment score; generate a data access mode when the user accesses according to the access verification information.
[0016] In a second aspect, the present application provides a remote sensing data management system based on a data lake, which is used to execute a remote sensing data management method based on a data lake. The data management system includes: An information source generation module is configured to generate an index information source of a hydropower development basin when parallel chain consensus of a parallel chain block is successful. An attribute determination module is configured to determine a secure access node of remote sensing data in hydropower development basin monitoring according to the index information source, and determine an access identification attribute corresponding to a remote sensing monitoring target through the secure access node. A strategy construction module is configured to obtain user access information of remote sensing data registered in a data lake under a current network security protocol, determine an access exception feature when data access is abnormal according to the user access information, and further determine a data access strategy when accessing remote sensing data according to the access exception feature and the access identification attribute. A permission recognition module is configured to collect a risk judgment score of digital twin basin data under the influence of access risk, determine a data access mode when the user accesses according to the risk judgment score, and further recognize an access request of remote sensing data in the hydropower development basin according to the data access mode to obtain an identification attribute permission when access security is recognized. An access restriction module is configured to restrict access to remote sensing data under the current network security protocol according to the data access strategy and the identified attribute permission.
[0017] The technical scheme provided by the embodiments disclosed in the application has the following beneficial effects: When parallel chain consensus of the parallel chain block is successful, an index information source of the hydropower development basin is generated; a secure access node of remote sensing data in hydropower development basin monitoring is determined according to the index information source, and an access identification attribute corresponding to a remote sensing monitoring target is determined through the secure access node; user access information of remote sensing data registered in a data lake under a current network security protocol is obtained, access abnormal features when data access is abnormal are determined according to the user access information, and then a data access strategy when remote sensing data is accessed is determined according to the access abnormal features and the access identification attribute; a risk judgment score of digital twin basin data under the influence of access risk is collected, a data access mode when a user accesses is determined according to the risk judgment score, and then access request recognition of remote sensing data in the hydropower development basin is performed according to the data access mode, to obtain an identified attribute permission when access security is identified; and remote sensing data under the current network security protocol is restricted according to the data access strategy and the identified attribute permission.
[0018] As can be seen, in the application, high-risk or abnormal access behaviors can be effectively detected and protected in complex application scenarios; the index information source of the hydropower development basin is generated through parallel chain consensus, which can effectively improve the query and management efficiency of data, ensure the rapid access and dynamic processing of remote sensing data, and provide a clear structure and access path for subsequent data access, thereby improving the flexibility and accuracy of data management; the secure access node is determined according to the index information source, which can ensure the security of the data access path, thereby preventing unauthorized access and data leakage and improving the security and controllability of data. This step helps to identify and prevent potential security risks in real time; by tracking the access mode, unusual behaviors can be identified and appropriate security measures can be taken in time, thereby enhancing the security protection capability of the system and improving data compliance; by analyzing user access information and determining access abnormal features, the system can realize instant detection and early warning of abnormal access. This measure helps to automatically identify potential security threats, reduces human intervention, and quickly responds to non-standard access behaviors to protect data security; access is restricted according to the data access strategy and the identified attribute permission, which can dynamically adjust the access permission of the user, ensure that data is only used within the authorized range, thereby reducing the risk of data leakage and misuse, and further strengthening the security protection and risk control of data.
[0019] In summary, the technical solution adopted in this application can effectively detect and protect against high-risk or abnormal access behaviors in complex application scenarios, thereby improving the controllability of data protection in sensitive data and cross-departmental collaboration. Attached Figure Description
[0021] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only for this embodiment of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0022] Figure 1 This is a flowchart of the remote sensing data management method based on a data lake provided in this application; Figure 2 This is a module structure diagram of the remote sensing data management system based on a data lake provided in this application. Detailed Implementation
[0024] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0025] This application provides a remote sensing data management system and method based on a data lake. The core of this system involves generating an index information source for a hydropower development basin when the parachain consensus of the parachain block is successful; determining secure access nodes for remote sensing data in the hydropower development basin monitoring based on the index information source; determining access identifier attributes corresponding to remote sensing monitoring targets through the secure access nodes; acquiring user access information for remote sensing data stored in the data lake under the current network security protocol; determining access anomaly characteristics when data access anomalies occur based on the user access information; and then determining a data access strategy for accessing remote sensing data based on the access anomaly characteristics and the access identifier attributes; collecting risk assessment scores of digital twin basin data under access risk influence; determining the data access mode when users access data based on the risk assessment scores; identifying access requests for remote sensing data in the hydropower development basin based on the data access mode; obtaining identification attribute permissions for access security identification; and restricting access to remote sensing data under the current network security protocol based on the data access strategy and the identification attribute permissions. The above solution can effectively detect and protect against high-risk or abnormal access behaviors in complex application scenarios, thereby improving the controllability of data protection in sensitive data and cross-departmental collaboration.
[0026] Example 1 To better understand the above technical solutions, a detailed explanation will be provided below with reference to the accompanying drawings and specific implementation methods. Figure 1 As shown, this figure is an exemplary flowchart of a remote sensing data management method based on a data lake according to this embodiment of the present application. The data management method includes the following steps: In step S1, when the parachain consensus of the parachain block is successful, an index information source for the hydropower development basin is generated.
[0027] In practical implementation, firstly, basic watershed data (such as geographical scope and water resource parameters) is collected and submitted to the parachain network through distributed nodes. Each node uses a distributed consensus algorithm (such as Byzantine Fault Tolerance, BFT) to verify the data, ensuring the authenticity and reliability of the submitted watershed data. After reaching a consensus, this verified watershed data is packaged into blocks and recorded in the parachain. Next, the watershed data in the blocks is processed by the index generation module. The system uses Distributed Hash Table (DHT) technology to hash the key attributes of the watershed (such as watershed number, geographical location, and resource type) to generate a unique index key. The index key is bound to the detailed data of the watershed, forming a key-value pair stored in a decentralized database. Taking the watershed number "001" as an example, the hash-generated index key Hash(001) maps to metadata such as geographical coordinates and available water resources. In other embodiments, other methods can be used to generate the index information source for hydropower development watersheds, which will not be elaborated here.
[0028] It should be noted that, in this application, the index information source refers to the core information set used for quickly locating and retrieving target data. It is generated by structuring the key attributes of the target data (such as unique identifiers, location, classification, etc.) and has identifiability and queryability.
[0029] In step S2, a secure access node for remote sensing data in hydropower development basin monitoring is determined based on the index information source, and the access identifier attribute corresponding to the remote sensing monitoring target is determined through the secure access node.
[0030] In this embodiment, determining the secure access node for remote sensing data in hydropower development basin monitoring based on the index information source can be achieved through the following steps: Extract access cycle characteristics of remote sensing data in hydropower development basin monitoring from the index information source; Determine the security implications when accessing remote sensing data; The secure access nodes for remote sensing data in hydropower development basin monitoring are determined based on the access cycle characteristics and the security impact value.
[0031] In practice, the first step is to use the index information source to contain relevant data of the hydropower development basin, including timestamps, update frequencies, and historical access records of remote sensing data. By analyzing the time characteristics of the index information source, access cycle features are extracted (e.g., high-resolution remote sensing images updated weekly and hydrological monitoring data released monthly). Using time series analysis techniques (such as time series-based decomposition models), historical access patterns are predicted to identify the time periods of high-frequency access and the intervals of low-frequency access. Then, the security impact value is used to assess the potential security threat of the access operation to the system or data. It is calculated by combining the source of the access request, data sensitivity, and the security status of the node. For example, real-time hydrological data has high sensitivity, while historical image data has lower sensitivity. A trust score is calculated based on user authentication, IP address security, and historical behavior. The security level is determined based on the node's current load, network latency, and historical security events. A weighted scoring model (e.g., Security Impact Value = 0.5 × Data Sensitivity + 0.3 × Access Source Trustworthiness + 0.2 × Node Security Status) is used to finally generate a security impact value range (e.g., 0~1, with 1 being the highest risk). For example, if an access request involves real-time remote sensing imagery, originates from a trusted node, and the node's security status is good, the overall security impact value is 0.3 (low risk). Finally, nodes that match the current access time period are prioritized. For example, when access requests occur during peak periods, the system prioritizes allocating load balancing nodes. Based on the security impact value, insecure nodes (such as high-latency nodes or nodes that have recently experienced anomalies) are excluded. Under high demand, a multi-node redundancy distribution mechanism (such as collaboration between sharded storage nodes) is adopted. The system uses a node optimization algorithm (such as AHP) to obtain the optimal list of secure access nodes. In a certain watershed monitoring, the access cycle is characterized as "every Monday morning", and the security impact value is 0.3. The system selects three nodes A, B, and C with higher security scores for access.
[0032] It should be noted that, in this application, the access cycle characteristic refers to the temporal pattern describing remote sensing data access behavior, such as access frequency, time interval, and peak periods; the security impact value is an indicator used to quantitatively assess the degree of threat that access operations pose to data or system security; and the secure access node refers to a trusted node that meets the needs of efficient access while ensuring data security.
[0033] In this embodiment, determining the access identifier attribute corresponding to the remote sensing monitoring target through the secure access node can be achieved through the following steps: The access characteristic deviation corresponding to the remote sensing monitoring target is determined based on the secure access node; The access identification attribute corresponding to the remote sensing monitoring target is determined by the access feature deviation.
[0034] In practice, each secure access node first records detailed information about received remote sensing monitoring requests, including request time, request range (geographic coordinates), and requested data type (e.g., resolution, timeliness). It uses historical access patterns as a benchmark (e.g., a node typically processes data requests for a specific area) and compares them with current access characteristics to calculate discrepancies. These discrepancies include: Geographic range discrepancy: whether the requested monitoring range exceeds the node's usual processing area; Timeliness discrepancy: whether the requested data is more real-time than the data the node typically processes; and Resolution discrepancy: whether the requested data resolution is higher or lower than the node's usual processing range. For example, assuming node A typically processes images with a resolution of 1 meter, and the current request requires an image with a resolution of 0.5 meters, the discrepancy is calculated as 50%. Next, the access identifier attribute provides a specific description of the access requirements for the remote sensing monitoring target, including: geographic range (e.g., the latitude and longitude range of the monitoring area); data type (e.g., image, vector data); and data characteristics (e.g., resolution, frequency, timeliness). Finally, the generated access identifier attribute is sent to other secure access nodes to coordinate request processing and ensure compliance with access requirements.
[0035] It should be noted that, in this application, access feature deviation refers to the difference between the actual access request features (such as scope, timeliness, and resolution) and the expected standard, and is used to analyze the particularity or anomaly of access demand; access identification attributes refer to the set of core features describing the access demand of remote sensing monitoring targets, including geographical scope, data type, resolution, and timeliness.
[0036] In step S3, user access information for remote sensing data stored in the data lake under the current network security protocol is obtained. Based on the user access information, access anomaly characteristics when data access is abnormal are determined. Then, the data access strategy for accessing remote sensing data is determined by the access anomaly characteristics and the access identifier attribute.
[0037] In practical implementation, obtaining user access information for remote sensing data hosted in the data lake under the current network security protocol can be achieved as follows: First, the user initiates a data request through a security authentication mechanism (such as OAuth 2.0 or access control based on a zero-trust architecture). The system verifies the user's identity and assigns an access token through the authentication layer provided by the protocol. Second, when receiving an access request, the system records detailed information about the request, including the user ID, request time, target data type (such as high-resolution remote sensing imagery or hydrological model data), and data lake storage path. This information is captured and stored in real time through a logging system (such as ELKStack). Subsequently, a behavior analysis module analyzes the user's access patterns to extract access information features (such as access frequency, data type, and network source IP address). By comparing these features with historical behavior (using machine learning models such as KNN or anomaly detection algorithms), potential abnormal access behaviors can be identified. Finally, the system dynamically adjusts user access permissions based on access information and network security protocols to ensure the security and efficiency of the data lake, which will not be elaborated further here.
[0038] It should be noted that, in this application, user access information refers to the collection of behavioral and related characteristic data generated by users during the process of accessing the target system or data resources (such as a data lake), which is used to record and analyze users' access patterns, permission requirements, and potential abnormal behaviors.
[0039] Additionally, it should be noted that in this application, user access information includes, but is not limited to, user identity (such as username, role), access time, target data type (such as remote sensing images, hydrological models), access method (such as reading, modifying), network source (such as IP address, geographical location), and access frequency.
[0040] In this embodiment, determining the access anomaly characteristics when data access anomalies occur based on the user access information can be achieved through the following steps: Based on the user access information, determine the security assessment data during data access; Determine the access exception information when a data access error occurs; Based on the security assessment data and the access anomaly information, determine the access anomaly characteristics when data access anomalies occur.
[0041] In practice, the system first analyzes access behavior in real time using key fields in user access information (such as user ID, access time, target data type, and source IP address). It then assesses the security of access requests using a security evaluation model (such as a risk scoring algorithm based on multi-factor analysis). The core evaluation parameters are: Legality of the behavior (similarity to the user's historical access patterns, such as access frequency and data type); Environmental credibility (credibility of the network source, such as whether the IP address is abnormal or the device fingerprint matches); and Resource sensitivity (the importance of the target data, such as whether access to sensitive remote sensing images is reasonable). Next, during the security evaluation, if the risk score exceeds a set threshold (e.g., 0.7), the system triggers abnormal access monitoring. It extracts abnormal access information through a log system, recording details of the abnormal behavior, including: Abnormal type (e.g., high-frequency access, data exceeding the scope); Abnormal triggering conditions (e.g., abnormal access time period (non-working hours), abnormal request frequency (exceeding historical average); Abnormal context (including the timing of the abnormal behavior, associated users, and nodes). The system then classifies the abnormal information using a historical anomaly database and a feature analysis model (such as the Random Forest classification algorithm). Finally, the security assessment data is combined with access anomaly information to extract key features of abnormal access: Feature extraction method: Based on data clustering algorithms (such as K-Means), abnormal behavior is divided into patterns (such as high-frequency access pattern, cross-regional access pattern); Feature selection technology (such as Lasso regression) is used to screen key indicators (such as access time, data type, source IP, etc.), and the system integrates multi-dimensional features such as access frequency, target data type, and access time to generate anomaly feature vector.
[0042] It should be noted that in this application, the security assessment data is generated based on user access information and is a quantitative indicator used to assess the risk and legitimacy of access behavior; the access anomaly information represents the specific details of the abnormal access behavior, including the anomaly type, triggering conditions and context; the access anomaly features are multi-dimensional key descriptions extracted based on the abnormal access behavior, including behavior patterns, data sensitivity and network source, etc., used to characterize the specific characteristics of abnormal access.
[0043] In this embodiment, determining the data access strategy for accessing remote sensing data based on the access anomaly characteristics and the access identifier attribute can be achieved through the following steps: Access attribute permissions for accessing remote sensing data are determined based on the aforementioned abnormal access characteristics. The authentication control level for accessing remote sensing data is determined based on the access identifier attribute. The data access strategy for accessing remote sensing data is determined based on the access attribute permissions and the authentication control parameters.
[0044] In practice, the system first dynamically adjusts user access permissions based on abnormal access characteristics, restricting the scope of data operations or enforcing higher-level security measures. Access permission adjustment rules include: restricting operation types: if abnormal access characteristics indicate high-frequency crawling behavior, restricting users to only read operations and prohibiting downloading or modification; reducing data scope: if the target geographical area exceeds the norm, the system limits users to accessing only specific areas; and enforcing security verification: for highly sensitive data access, a dual verification process (such as biometrics + one-time verification code) is added. The adjustment of access permissions is completed by the policy engine, based on a rule base or machine learning model (such as a combination of RBAC role-based access control and anomaly scoring). Then, based on a detailed description of the access identifier attributes (such as geographical scope, resolution, timeliness, etc.), the system generates the authentication control quantities required for data access. The core dimension of these authentication control quantities is: data level matching: ensuring that the user's requested target data (such as 0...). The system ensures that the access permissions match the access attributes (e.g., real-time data or historical data); time validity: the allowed access time is determined based on the time requirements in the identifier attributes; resource allocation matching: for example, multi-node storage in a watershed, the node with the optimal load is selected for allocation; the authentication control quantity is dynamically calculated by the security verification module and a unique identifier (e.g., access token) is assigned to the user's access request; finally, a data access policy is formulated, which includes: access decision rules: if the access attribute permissions match the authentication control quantity, access is allowed; if a conflict occurs (e.g., insufficient permissions or requests exceeding the scope), access is blocked or some data is returned; policy execution path: access decisions are dynamically generated using an access policy engine (e.g., based on an ABAC attribute policy model); the execution path includes data filtering (e.g., blocking out-of-scope data), permission verification, and log recording; real-time adjustment mechanism: when access anomaly characteristics continue to change (e.g., user behavior returns to normal), the system gradually relaxes policy restrictions.
[0045] It should be noted that, in this application, access attribute permissions refer to the rules limiting the range of data that a user can access, the type of operation, and the level of security verification; authentication control quantity is a set of dynamic verification parameters calculated based on access identifier attributes and used to match user requests and access permissions; data access policy is a set of control rules formulated based on access permissions and authentication control quantity, used to dynamically manage user access behavior to target data.
[0046] In step S4, the risk assessment score of the digital twin watershed data under the influence of access risk is collected. The data access mode of the user access is determined according to the risk assessment score. Then, the access request of the remote sensing data in the hydropower development watershed is identified by the data access mode to obtain the identification attribute permissions when the access security is identified.
[0047] In practical implementation, the risk assessment score for digital twin watershed data under the influence of access risks can be achieved as follows: First, the system performs an initial risk assessment based on the characteristics of the access request (such as request frequency, sensitivity of the target data, request time, and user behavior patterns). A risk assessment model (such as a multi-dimensional weighted scoring algorithm) is established to assign a risk score to each access request. Factors considered in this model include, but are not limited to, abnormal access characteristics (such as high-frequency access and cross-regional requests), data attributes (such as real-time performance and resolution), and network environment (such as IP address and access device security). Second, by integrating the watershed data characteristics from the digital twin model, the system assesses in real-time the impact of data access on the watershed simulation results, particularly whether abnormal behavior will lead to deviations in the data model or inaccuracies in the results. The risk score is calculated using weighted averages, combined with historical data and machine learning algorithms (such as decision trees and random forests), dynamically adjusting the risk assessment to form a comprehensive score. Finally, the system decides whether to allow access or take further security measures (such as mandatory multi-factor authentication and traffic restrictions) based on the risk assessment score.
[0048] It should be noted that, in this application, the risk assessment score represents the degree of risk that a specific access request or operation poses to the system, data security, and overall business processes.
[0049] In this embodiment, determining the data access pattern of a user based on the risk assessment score can be achieved through the following steps: The access verification information for users is determined based on the risk assessment score. The data access mode for user access is generated based on the access verification information.
[0050] In practice, the security level of an access request is first determined based on the user's access behavior and the risk assessment score generated by the system. A higher risk assessment score indicates potential risks in the access behavior, thus requiring more verification measures. For example: Low risk (low score): If the risk assessment score is low (e.g., 0.2), it means the user's access behavior conforms to a normal pattern, and the system only needs to perform basic authentication (such as username and password verification); Medium risk (moderate score): If the risk assessment score is in the medium range (e.g., 0.5), the system will require additional verification, such as mobile phone verification code, email confirmation, or security questions; High risk (high score): If the risk assessment score is high (e.g., above 0.8), it may involve sensitive data or abnormal behavior, and the system will require multi-factor authentication (such as facial recognition, fingerprint recognition, etc.) or adopt more security checks, such as behavioral analysis detection. Then, based on the determined access verification information, a specific user data access pattern is generated, involving the data access method, scope, and permissions. The data access pattern is dynamically generated through a policy engine (such as an ABAC-based access control model), including: Access type: such as read-only, modification, or deletion. If the verification information indicates that the access request is a low-risk behavior, the system allows the user to perform modification or deletion operations; if it is a high-risk behavior, the system only allows read-only permissions; Access scope: Based on the user's security verification information, the system restricts the range of data the user can access. For example, low-risk access may allow access to the entire dataset, while high-risk access is limited to a small range of secure data; Access timeliness: Based on the risk assessment score and the strength of the verification information, the system determines the timeliness of the user's access. For example, high-risk access may be limited to a short period of time and has an expiration time.
[0051] It should be noted that, in this application, access verification information refers to security data that verifies user identity and access permissions, including identity verification, authentication measures, and behavioral analysis information; data access mode refers to the specific behavioral norms followed by users when accessing data, including access methods, permission scope, time limits, etc.
[0052] In this embodiment, the identification of access requests for remote sensing data in the hydropower development basin based on the data access mode, and the determination of access security permissions, can be achieved through the following steps: Read remote sensing data in the hydropower development basin; Extract the access identifier node from the data access mode when the access request is initiated; The access security identification permissions are determined based on the access identifier section and the remote sensing data.
[0053] In practice, the system first reads remote sensing data of the hydropower development basin from a data lake or distributed storage. This data can include satellite imagery, climate data, river flow data, etc. The data reading process typically involves querying a database or distributed storage system and retrieving the target data based on user permissions. When reading data, the system needs to identify the data's sensitivity level; for example, high-resolution imagery may be marked as highly sensitive data, while low-resolution imagery or historical data is considered low-sensitivity data. Example: If a user requests access to basin water level monitoring data for a specific time period, the system searches for and loads the relevant data from the repository, while simultaneously recording the access operation. Then, access identification nodes can be the user's IP address, the logged-in device, user role information, or the encryption token used for access. The system needs to extract these identification nodes from the access pattern and further analyze their security attributes. For example, if the request originates from a node whose geographical location does not match the user's registration information, that node may be marked as a high-risk source, requiring additional verification measures. For example, if a user initiates an access request through their personal device, the system extracts the device's unique identifier (such as a MAC address) and compares it with the identity information in the access pattern. Finally, based on the characteristics of the extracted access identifier nodes and remote sensing data, the system dynamically calculates the identification attribute permissions. Identification attribute permissions include access levels to remote sensing data (e.g., read and write permissions), data scope (e.g., specified watershed or specific time period), and access control for specific attributes (e.g., sensitive information, detailed data). The system applies corresponding access control policies (e.g., role-based access control, attribute-based access control, etc.) based on the user's identity characteristics, access identifier nodes (e.g., IP address, device, geographical location), and data sensitivity. Low-risk scenarios: If the access request originates from a known device and the requested data is publicly available (e.g., low-resolution imagery), the system can grant the user secure access permissions. High-risk scenarios: If the request comes from an unverified external IP address and the requested data is highly sensitive (e.g., real-time monitoring data), the system may only grant read-only permissions or even deny access. Example: If a user requests high-resolution watershed data through their mobile device (identification node), the system will combine user authentication (e.g., administrator role) and data sensitivity to decide whether to allow the user to access the complete data or limit access to a simplified version.
[0054] It should be noted that, in this application, remote sensing data in hydropower development basins refers to data related to hydropower basins collected through remote sensing technology (such as satellites or drones), which is typically used for monitoring environmental changes, resource management, etc.; access identification nodes refer to features related to user identity in access requests, including device information, network identifiers, authentication tokens, etc., used to determine the legality and security of access requests; identification attribute permissions refer to the control covering data access levels, access scope, and specific attributes.
[0055] In step S5, access restrictions are imposed on remote sensing data under the current network security protocol based on the data access policy and the identification attribute permissions.
[0056] In specific implementation, restricting access to remote sensing data under the current network security protocol based on the data access policy and the identification attribute permissions can be achieved in the following ways: First, the system determines the user's access permissions based on the data access policy. These policies consider risk assessment scores, access patterns, user roles, and the required data types. For example, if a user's access request involves sensitive data and has a high risk score, the system will restrict the user's access permissions to read-only mode or only allow access to non-sensitive information. For specific data, such as real-time watershed data and high-resolution satellite images, the system may restrict access time or frequency based on the policy to prevent frequent and unauthorized access. Second, the system further strengthens access control based on identification attribute permissions. Each user's access permissions depend not only on their role and identity but are also dynamically adjusted based on access identification nodes (such as device ID and IP address). If the access request comes from an uncommon node or device, the system will trigger additional verification measures (such as multi-factor authentication or additional security audits) to restrict access to sensitive data. If the requested identification attribute permissions are insufficient, the system will automatically deny access to ensure data security. Finally, the system combines all access restriction operations with the current network security protocol to ensure that all data transmission and access behaviors comply with security standards. For example, if an encryption protocol (such as TLS or SSL) is currently being used, the system will automatically encrypt the data transmission process to avoid the risk of data leakage, which will not be elaborated here.
[0057] Therefore, this application demonstrates its ability to effectively detect and protect against high-risk or abnormal access behaviors in complex application scenarios. Specifically, generating an index information source for hydropower development basins through parallel chain consensus effectively improves data query and management efficiency, ensuring rapid access and dynamic processing of remote sensing data. It also provides a clear structure and access path for subsequent data access, thereby enhancing the flexibility and accuracy of data management. Determining secure access nodes based on the index information source ensures the security of data access paths, preventing unauthorized access and data leakage, and improving data security and controllability. This step helps to identify and prevent potential security risks in real time. Tracking access patterns allows for the identification of unusual behaviors and timely implementation of corresponding security measures, thereby enhancing the system's security capabilities and improving data compliance. By analyzing user access information and identifying abnormal access characteristics, the system can achieve immediate detection and early warning of abnormal access. This measure helps to automatically identify potential security threats, reduce human intervention, and quickly respond to irregular access behavior, thus ensuring data security. Access restrictions based on data access policies and identified attribute permissions can dynamically adjust user access permissions, ensuring data is used only within authorized scope, thereby reducing the risk of data leakage and misuse, and further strengthening data security protection and risk control. In summary, the technical solution adopted in this application can effectively detect and protect against high-risk or abnormal access behavior in complex application scenarios, thereby improving the controllability of data protection in sensitive data and cross-departmental collaboration.
[0058] Example 2 This application provides a remote sensing data management system based on a data lake, with reference to... Figure 2 As shown in the figure, this is a schematic diagram of a remote sensing data management system based on a data lake according to this embodiment of the present application. The data management system includes: The information source generation module 100 is used to generate an index information source for the hydropower development basin when the parachain consensus of the parachain block is successful. The attribute determination module 200 is used to determine the secure access node of remote sensing data in hydropower development basin monitoring based on the index information source, and to determine the access identifier attribute corresponding to the remote sensing monitoring target through the secure access node. The policy construction module 300 is used to obtain user access information of remote sensing data stored in the data lake under the current network security protocol, determine access anomaly characteristics when data access is abnormal based on the user access information, and then determine the data access policy when accessing remote sensing data based on the access anomaly characteristics and the access identifier attribute. The permission identification module 400 is used to collect the risk assessment score of digital twin watershed data under the influence of access risk, determine the data access mode when the user accesses the data based on the risk assessment score, and then identify the access request of remote sensing data in the hydropower development watershed based on the data access mode to obtain the identification attribute permission when accessing security identification. The access restriction module 500 is used to restrict access to remote sensing data under the current network security protocol according to the data access policy and the identification attribute permissions.
[0059] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0060] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, including read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-Erasable Programmable Read-Only Memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, disk storage, magnetic tape storage, or any other computer-readable medium capable of carrying or storing data.
[0061] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
Claims
1. A remote sensing data management method based on a data lake, characterized in that, The data management method includes the following steps: When the parachain consensus of the parachain block is successful, an index information source for the hydropower development basin is generated. Based on the index information source, secure access nodes for remote sensing data in hydropower development basin monitoring are determined, and access identifier attributes corresponding to remote sensing monitoring targets are determined through the secure access nodes. Obtain user access information for remote sensing data stored in the data lake under the current network security protocol, determine access anomaly characteristics when data access anomalies occur based on the user access information, and then determine the data access strategy when accessing remote sensing data based on the access anomaly characteristics and the access identifier attribute. The risk assessment score of digital twin watershed data under the influence of access risk is collected. The data access mode of the user is determined according to the risk assessment score. Then, the access request of remote sensing data in the hydropower development watershed is identified by the data access mode to obtain the identification attribute permissions when accessing security identification. Access to remote sensing data under the current network security protocol is restricted based on the data access policy and the identification attribute permissions.
2. The remote sensing data management method based on a data lake as described in claim 1, characterized in that, An index information source refers to a collection of core information used to quickly locate and retrieve target data.
3. The remote sensing data management method based on a data lake as described in claim 1, characterized in that, Based on the aforementioned index information source, the specific secure access nodes for remote sensing data in hydropower development basin monitoring include: Extract access cycle characteristics of remote sensing data in hydropower development basin monitoring from the index information source; Determine the security implications when accessing remote sensing data; The secure access nodes for remote sensing data in hydropower development basin monitoring are determined based on the access cycle characteristics and the security impact value.
4. The remote sensing data management method based on a data lake as described in claim 1, characterized in that, Determining the access identifier attribute corresponding to the remote sensing monitoring target through the secure access node specifically includes: The access characteristic deviation corresponding to the remote sensing monitoring target is determined based on the secure access node; The access identification attribute corresponding to the remote sensing monitoring target is determined by the access feature deviation.
5. The remote sensing data management method based on a data lake as described in claim 1, characterized in that, User access information refers to the collection of behavioral and related characteristic data generated by users during the process of accessing a target system or data resource (such as a data lake).
6. The remote sensing data management method based on a data lake as described in claim 1, characterized in that, The specific characteristics of access anomalies when data access occurs based on the user access information include: Based on the user access information, determine the security assessment data during data access; Determine the access exception information when a data access error occurs; Based on the security assessment data and the access anomaly information, determine the access anomaly characteristics when data access anomalies occur.
7. The remote sensing data management method based on a data lake as described in claim 1, characterized in that, The data access strategy for accessing remote sensing data, determined by the access anomaly characteristics and the access identifier attribute, specifically includes: Access attribute permissions for accessing remote sensing data are determined based on the aforementioned abnormal access characteristics. The authentication control level for accessing remote sensing data is determined based on the access identifier attribute. The data access strategy for accessing remote sensing data is determined based on the access attribute permissions and the authentication control parameters.
8. The remote sensing data management method based on a data lake as described in claim 1, characterized in that, The risk assessment score indicates the degree of risk that a specific access request or operation poses to the system, data security, and overall business processes.
9. The remote sensing data management method based on a data lake as described in claim 1, characterized in that, Determining the data access pattern for users based on the risk assessment score specifically includes: The access verification information for users is determined based on the risk assessment score. The data access mode for user access is generated based on the access verification information.
10. A remote sensing data management system based on a data lake, used to execute a remote sensing data management method based on a data lake as described in any one of claims 1 to 9, characterized in that, The data management system includes: The information source generation module is used to generate an index information source for the hydropower development basin when the parachain consensus of the parachain block is successful. The attribute determination module is used to determine the secure access node of remote sensing data in the monitoring of hydropower development basins based on the index information source, and to determine the access identifier attribute corresponding to the remote sensing monitoring target through the secure access node. The policy construction module is used to obtain user access information for remote sensing data stored in the data lake under the current network security protocol, determine access anomaly characteristics when data access anomalies occur based on the user access information, and then determine the data access policy when accessing remote sensing data based on the access anomaly characteristics and the access identifier attribute. The permission identification module is used to collect the risk assessment score of digital twin watershed data under the influence of access risk, determine the data access mode when the user accesses the data based on the risk assessment score, and then identify the access request of remote sensing data in the hydropower development watershed based on the data access mode to obtain the identification attribute permission when accessing security identification. The access restriction module is used to restrict access to remote sensing data under the current network security protocol based on the data access policy and the identification attribute permissions.
Citation Information
Patent Citations
Multi-granularity remote sensing data access method based on rules
CN103810441A
Space-time data lake management system based on multi-source remote sensing data and safety protection method thereof
CN116737854A
Secure remote sensing image data sharing system and method based on block chain and IPFS
CN117749369A
Big data security processing method based on data analysis
CN118332597A
Stereoscopic monitoring and data mining system and method for harmful lake cyanobacteria bloom
US20210293770A1