Information security protection system and method applied to data center and storage medium

By setting up information relay and risk assessment modules in the data center, the problem of delay in detecting data transmission anomalies was solved, thereby improving the security and economy of data transmission.

CN121098628BActive Publication Date: 2026-03-24SHANGHAI DIPU XINCHENG INTELLIGENT TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-07
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

In the current technology for information transmission in data centers, abnormal behavior is usually detected by feedback alerts, which means that the abnormal data transmission is only discovered after it has occurred, which can easily lead to losses. Furthermore, the step-by-step verification increases the network load and affects economic efficiency.

Method used

By setting up information relays, access requests and information storage are isolated, security risk assessments and risk control management are carried out, risk control signals are generated, and the security of the relay area is ensured. This includes the collaborative work of the core data storage module, the information relay sending and receiving module, the external network connection module, the security verification and assessment module, and the relay risk control module.

Benefits of technology

It improves the security of data relay transmission, avoids data leakage, reduces network load, and enhances the economy and security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121098628B_ABST
    Figure CN121098628B_ABST
Patent Text Reader

Abstract

The application relates to the field of information security and aims to solve the problems of lag in data transmission risk discovery and high verification cost when a large amount of data is faced, and specifically relates to an information security protection system and method applied to a data center and a storage medium, mainly comprising a core data storage module, an information relay transceiving module, a security verification and evaluation module, a transmission accumulation module and a relay risk control module; in the information transmission process of the data center, the isolation of access requests and information storage is realized through the setting of information relay, the safety of data storage in the data center is improved, after receiving a data access request, the data access request is counted, relevant security risk evaluation and security risk accumulation are carried out according to the data access request, corresponding risk control signals are generated, intelligent risk control actions are executed on the relay area, high-risk residues in the relay area are avoided, and the safety in the data relay transmission process is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security, specifically to information security protection systems, methods, and storage media applied to data centers. Background Technology

[0002] Data centers are the "heart" and "brain" of the modern digital world. They are not only storage warehouses for massive amounts of data, but also computing and exchange hubs for core business applications, critical services, and digital processes. Data centers support core business systems in finance, energy, transportation, government affairs, and healthcare. Once they are damaged or data is leaked, it may lead to widespread service paralysis, directly affecting the normal operation of society and public safety.

[0003] As cyberattack methods continue to evolve, threats are everywhere, from external advanced persistent threats and zero-day exploits to internal malicious employees and unintentional misoperations. Data centers, as high-value targets, are the first choice for hackers. A robust security protection system is the only way to defend against these threats. Data needs to be protected throughout its entire lifecycle, from creation, storage, use, sharing, archiving to destruction. Data center security protection covers multiple levels, including physical security, network security, application security, and data security, to ensure that data is properly protected in any state and in any location.

[0004] Therefore, many data center security solutions have been proposed in the existing technology. For example, patent application CN114884745B achieves secure data forwarding by adding and verifying dynamic tags at each level. This method effectively improves the confidentiality and integrity of data transmission, prevents the path from being predicted or tampered with, and has the ability to flexibly adjust the security level and quickly locate faulty nodes. However, the detection in this solution is a feedback reminder, that is, the discovery and location of anomalies occur after the data transmission anomaly has occurred, which can easily cause losses. At the same time, for the massive data transmission demand of data centers, step-by-step verification will significantly increase the network load and affect the economics of data transmission. Therefore, a solution is proposed here. Summary of the Invention

[0005] In the information transmission process of a data center, information relays are set up to isolate access requests and information storage, thereby improving the security of data storage in the data center. After receiving a data access request, the data access request is statistically analyzed, and relevant security risk assessments and accumulations are performed based on the data access request. Corresponding risk control signals are generated, thereby enabling intelligent risk control actions to be executed in the relay area to ensure that there are no high-risk residues in the relay area, thus improving the security of data relay transmission and solving the technical defects mentioned in the background technology.

[0006] The objective of this invention can be achieved through the following technical solution: an information security protection system applied to a data center, comprising a core data storage module, an information relay transceiver module, an external network connection module, a security verification and assessment module, a transmission accumulation module, and a relay risk control module; the core data storage module manages the information stored within the data center and extracts fragments from the stored information to obtain information identification features; the external network connection module connects to an external network, receives information access requests from the external network, and can also send and receive feedback on the received core data; the information relay transceiver module stores and parses information access requests and forwards them to the core data storage module; the information relay transceiver module can also... The core data storage module acquires the information that needs to be accessed and sends it to the external network connection module. The security verification and evaluation module can acquire information access requests through the information relay transceiver module, perform security verification on the information access requests, generate access security samples, and send the access security samples to the relay risk control module. The transmission accumulation module acquires access security samples through the security verification and evaluation module, quantifies and accumulates the access security samples, generates accumulated risk samples, and sends the accumulated risk samples to the relay risk control module. The relay risk control module performs continuity verification through access security samples, performs quantitative evaluation through accumulated risk samples, obtains risk control signals based on the verification and evaluation results, and performs risk control management on the information relay transceiver module based on the risk control signals.

[0007] In a preferred embodiment of the present invention, the access request obtained by the external network connection module includes access identity, access time, data identity, and data volume, wherein the data identity is the information identification feature stored in the data center; the external network connection module verifies the access identity, and if the access identity verification is successful, the entire access request is sent to the information relay transceiver module; if the access identity verification fails, the external network connection module only sends the access identity and access time in the access request to the information relay transceiver module.

[0008] In a preferred embodiment of the present invention, after obtaining an access request, the information relay transceiver module sends the data identity in the access request to the core data storage module. The core data storage module compares the data identity with the information identification features of the data center and sends the corresponding data to the information relay transceiver module. After obtaining the corresponding data, the information relay transceiver module sends the data to the external network connection module.

[0009] In a preferred embodiment of the present invention, after the security verification and evaluation module obtains the access request, it calculates the abnormal access characteristics in the access request and compares the abnormal access characteristics with the minimum value of the set abnormal risk range. If the abnormal access characteristics are less than the minimum value of the set abnormal risk range, the access request is classified as a normal access request. If the abnormal access characteristics are within the set abnormal risk range, the access request is classified as an abnormal access request. If the abnormal access characteristics are greater than the maximum value of the set abnormal risk range, the access request is classified as a high-risk access request. The security verification and evaluation module records the classification results of the access request as an access security sample.

[0010] In a preferred embodiment of the present invention, the method for the security verification and evaluation module to calculate abnormal access characteristics is as follows: the security verification and evaluation module records the access time and access identity in the access request, obtains all access times of the same access identity from the database, calculates the high-frequency access interval of the access identity, and records the access frequency of the high-frequency access interval as the focus frequency; the security verification and evaluation module obtains the data identity and data volume in the access request, and marks the privacy level of each data identity; the security verification and evaluation module generates corresponding weights based on the privacy level, and performs weighted calculation based on the data volume to obtain the data volume statistics result; the security verification and evaluation module generates abnormal access characteristics by weighted average of the data volume statistics result and the focus frequency.

[0011] In a preferred embodiment of the present invention, the method for the security verification module to obtain the high-frequency access interval is as follows: the security verification module selects a sampler of a set time length, moves the sampler on the time axis, counts the number of accesses for each access identity within the interval where the sampler is located, and records the interval with the highest number of accesses as the high-frequency access interval.

[0012] In a preferred embodiment of the present invention, after acquiring an access security sample each time, the transmission accumulation module assigns different weights to different access security samples and performs double accumulation on the number of samples and time to obtain a cumulative risk sample; the relay risk control module performs threshold judgment on the cumulative risk sample and obtains a relay high-risk signal, a relay low-risk signal, and a relay normal signal based on the judgment result; the relay risk control module acquires access security samples through the security verification module and comprehensively corrects the threshold judgment results of the access security samples and the cumulative risk samples to obtain a relay high-risk signal, a relay low-risk signal, and a relay normal signal; after acquiring the relay high-risk signal, the relay risk control module performs formatting processing on the information relay transceiver module.

[0013] The information security protection method applied to data centers adopts the aforementioned information security protection system applied to data centers, including the following steps: Step 1: Information access request verification; Step 2: Information relay access; Step 3: Information access request security verification; Step 4: Security risk assessment; Step 5: Relay module risk control execution.

[0014] A computer-readable storage medium storing a computer program thereon, wherein when the computer program is executed by a processor, the above-described information security protection method applied to a data center is implemented.

[0015] Compared with the prior art, the beneficial effects of the present invention are as follows: In the information transmission process of the data center, by setting up information relays, access requests and information storage are isolated, and information access requests are parsed in the relay area. Based on the parsing results, the data is scheduled to the relay area for information access, thereby avoiding a large amount of data leakage in the data center and improving the security of data storage in the data center.

[0016] In this invention, after receiving a data access request, the data access requests are statistically analyzed, and a relevant security risk assessment is conducted based on the access frequency, access identity, and the amount and identity of the data to be accessed. The security risk assessment results are recorded, and the security risks are accumulated based on the recorded results to generate corresponding risk control signals. The risk control signals are then evaluated, thereby enabling intelligent risk control actions to be executed in the relay area to ensure that there are no high-risk remnants in the relay area and improve the security of data relay transmission. Attached Figure Description

[0017] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to the accompanying drawings.

[0018] Figure 1 This is a system block diagram of the present invention; Figure 2 This is a system flowchart of the present invention. Detailed Implementation

[0019] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.

[0020] Example 1: Please refer to Figure 1 - Figure 2As shown, the information security protection system applied to the data center includes a core data storage module, an information relay transceiver module, an external network connection module, a security verification and assessment module, a transmission accumulation module, and a relay risk control module. The core data storage module manages the information stored within the data center and extracts fragments of this information to obtain information identification features, such as information titles. The external network connection module connects to the external network and, based on information access requests received from the external network, can also send and deliver the received core data accordingly. The access requests obtained by the external network connection module include access identity, access time, data identity, and data volume, where data identity is the information identification feature stored in the data center. The external network connection module verifies the access identity; if the access authentication is successful, the entire access request is sent to the information relay transceiver module. If the access authentication fails, the external network connection module only sends the access identity and access time from the access request to the information relay transceiver module.

[0021] The information relay transceiver module can store and parse information access requests, obtain the data identity in the access request, and forward it to the core data storage module. The core data storage module compares the data identity with the information identification characteristics of the data center and sends the corresponding data to the information relay transceiver module. After obtaining the required information from the core data storage module, the information relay transceiver module sends a successful acquisition message to the external network connection module and sends the data to the external network connection module. The security verification and evaluation module can obtain information access requests from the information relay transceiver module, perform security verification on the information access requests, and generate access security samples. The process is as follows: After obtaining an access request, the security verification and assessment module calculates the abnormal access characteristics in the request and compares these characteristics with a set minimum value for the abnormal risk range. If the abnormal access characteristics are less than the minimum value, the access request is classified as a normal access request; if they are within the set abnormal risk range, the access request is classified as an abnormal access request; if they are greater than the maximum value, the access request is classified as a high-risk access request. The security verification and assessment module records the classification results as an access security sample and sends the access security sample to... The relay risk control module; among which, the security verification and assessment module calculates abnormal access characteristics as follows: the security verification and assessment module records the access time and access identity in the access request, and obtains all access times of the same access identity from the database. The security verification module selects a sampler of a set time length, and moves the sampler on the time axis to count the number of accesses for each access identity within the interval in which the sampler is located. The interval with the highest number of accesses is recorded as the high-frequency access interval, and the access frequency of the high-frequency access interval is recorded as the focus frequency. The security verification and assessment module obtains the data identity and data volume in the access request, and assigns a privacy level to each data identity. The security verification and evaluation module generates corresponding weights based on privacy levels. The higher the privacy level of the data identity, the greater the weight assigned. A weighted calculation is performed based on the data volume to obtain the product of the weight and the data volume, which is recorded as the data volume statistics. When performing the product calculation, the data volume uses the number of data bytes and the number of data units as indicators. The number of data bytes is in MB, and the number of data units is in bytes, i.e., L = q × n × s, where L is the data volume statistics, q is the weight, n is the number of data units, and S is the number of data bytes. The security verification and evaluation module generates abnormal access characteristics by weighted averaging the data volume statistics and focus frequency.

[0022] The transmission accumulation module acquires access security samples through the security verification and evaluation module, assigns different weights to different access security samples, and performs a double accumulation of the sample quantity and time to obtain a cumulative risk sample. This cumulative risk sample is then sent to the relay risk control module. The double accumulation process of sample quantity and time is as follows: the time accumulation result is the period from the last formatting to the current time. Each time an access security sample is acquired, if it is a high-risk access request, it is assigned a value A1; if it is a low-risk access request, it is assigned a value A2; and if it is a normal access request, it is assigned a value A3. The sum of A1, A2, and A3 is used as the cumulative sample quantity result. The time accumulation result and the sample quantity accumulation result are then combined to form the cumulative risk sample. The relay risk control module performs threshold judgment on the cumulative risk sample. Based on the judgment result, it obtains relay high-risk signals, relay low-risk signals, and relay normal signals. Specifically, in the judgment, the time accumulation result or the sample quantity accumulation result... If any one of the criteria reaches a set threshold, a high-risk relay signal is generated. If no high-risk relay signal is generated, but the proportion of high-risk access requests in the accumulated sample count is greater than the set threshold, a low-risk relay signal is generated; otherwise, a normal relay signal is generated. The relay risk control module obtains access security samples through the security verification module and comprehensively corrects the threshold judgment results of the access security samples and the accumulated risk samples. That is, after obtaining the threshold judgment results of the accumulated risk samples, the number of consecutive occurrences of high-risk access requests in the access security samples is recorded. If the number of consecutive occurrences of high-risk access requests is greater than the set threshold, the threshold judgment result of the original accumulated risk samples is changed to a high-risk relay signal; otherwise, the high-risk relay signal, low-risk relay signal, or normal relay signal in the threshold judgment result of the original accumulated risk samples is maintained. After obtaining the high-risk relay signal, the relay risk control module performs formatting processing on the information relay transceiver module.

[0023] Example 2: Please refer to Figure 1 - Figure 2 As shown, the information security protection method applied to the data center includes the following steps: Step 1: Obtain information access requests through an external network connection module, verify the information access requests, and obtain access identity, access time, data identity, and data volume; Step 2: Retrieve data through the data center and relay the retrieved data through an information relay transceiver module; Step 3: Perform security verification on the information access requests during the information access process, and classify the information access requests into high-risk, low-risk, and normal requests; Step 4: Conduct a cumulative security risk assessment on the information access requests based on time and quantity, and perform risk control on the information relay transceiver module according to the assessment results; Step 5: Execute risk control on the information relay transceiver module to ensure the security of the information relay transceiver module.

[0024] Example 3: Please refer to Figure 1 - Figure 2As shown, a computer-readable storage medium stores a computer program thereon, which, when executed by a processor, implements the aforementioned information security protection method applied to a data center.

[0025] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods.

[0026] Any references to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory.

[0027] For illustrative purposes and not as a limitation, RAM is available in various forms, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Dual Data Rate SDRAM (DDRSDRAM), Enhanced SDRAM (ESDRAM), Synchlink DRAM (SLDRAM), Rambus Direct RAM (RDRAM), Direct Memory Bus Dynamic RAM (DRDRAM), and Memory Bus Dynamic RAM (RDRAM). Thresholds, preset values, and preset ranges are set for result comparison and analysis to determine good or bad. The magnitude of these values ​​is determined by a combination of large-scale model analysis of sample data and human experience, and can also be adjusted appropriately based on seasonal or common-sense influence conditions. Similarly, the weighting ratio coefficients and influence factors are assigned specific values ​​based on the magnitude of each parameter's influence on the result, ultimately reflecting the impact on the result. These values ​​are also determined by a combination of large-scale model analysis of sample data and human experience, and can also be adjusted appropriately based on seasonal or common-sense influence conditions.

[0028] Obviously, many modifications and variations can be made based on the content of this specification. These embodiments have been selected and specifically described in this specification to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.

Claims

1. An information security protection system applied to a data center, characterized in that, The system includes a core data storage module, an information relay transceiver module, an external network connection module, a security verification and evaluation module, a transmission accumulation module, and a relay risk control module. The core data storage module manages information stored within the data center and extracts fragments from this information to obtain information identification features. The external network connection module connects to external networks, receives information access requests from the external network, and sends and provides feedback on the received core data. The information relay transceiver module stores and parses information access requests and forwards them to the core data storage module. It also retrieves the required information from the core data storage module and sends it to the external network connection module. The security verification and evaluation module retrieves information access requests from the information relay transceiver module, verifies the security of the requests, generates an access security sample, and sends the access security sample to the relay risk control module. The transmission accumulation module obtains access security samples through the security verification and evaluation module, quantifies and accumulates the access security samples to generate accumulated risk samples, and sends the accumulated risk samples to the relay risk control module. The relay risk control module performs continuity verification through the access security samples, performs quantitative evaluation through the accumulated risk samples, obtains risk control signals based on the verification and evaluation results, and performs risk control management on the information relay transceiver module based on the risk control signals.

2. The information security system applied to a data center according to claim 1, wherein, The access request obtained by the external network connection module includes access identity, access time, data identity, and data volume, where data identity is the information identification feature stored in the data center; the external network connection module verifies the access identity, and if the access identity verification is successful, the entire access request is sent to the information relay transceiver module; if the access identity verification fails, the external network connection module only sends the access identity and access time in the access request to the information relay transceiver module.

3. The information security system applied to a data center according to claim 1, wherein, After receiving an access request, the information relay transceiver module sends the data identity in the access request to the core data storage module. The core data storage module compares the data identity with the information identification features of the data center and sends the corresponding data to the information relay transceiver module. After receiving the corresponding data, the information relay transceiver module sends the data to the external network connection module.

4. The information security system applied to a data center according to claim 1, wherein, After obtaining the access request, the security verification and evaluation module calculates the abnormal access characteristics in the access request and compares the abnormal access characteristics with the set minimum value of the abnormal risk range. If the abnormal access characteristics are less than the set minimum value of the abnormal risk range, the access request is classified as a normal access request. If the abnormal access characteristics are within the set abnormal risk range, the access request is classified as an abnormal access request. If the abnormal access characteristics are greater than the set maximum value of the abnormal risk range, the access request is classified as a high-risk access request. The security verification and evaluation module records the classification results of the access request as an access security sample.

5. The information security system applied to a data center according to claim 4, wherein, The method for calculating abnormal access characteristics by the security verification and evaluation module is as follows: The security verification and evaluation module records the access time and access identity in the access request, obtains all access times of the same access identity from the database, calculates the high-frequency access interval of the access identity, and records the access frequency of the high-frequency access interval as the focus frequency; The security verification and evaluation module obtains the data identity and data volume in the access request, and marks the privacy level of each data identity; The security verification and evaluation module generates corresponding weights based on the privacy level, and performs weighted calculation based on the data volume to obtain the data volume statistics result; The security verification and evaluation module generates abnormal access characteristics by weighted average of the data volume statistics result and the focus frequency.

6. The information security system applied to a data center according to claim 5, wherein, The security verification and evaluation module obtains the high-frequency access interval by selecting a sampler with a set time length and moving the sampler on the time axis to count the number of accesses for each access identity within the interval where the sampler is located, and recording the interval with the highest number of accesses as the high-frequency access interval.

7. The information security system applied to a data center according to claim 1, wherein, Each time the transmission accumulation module acquires an access security sample, it assigns different weights to different access security samples and performs a double accumulation of the sample quantity and time to obtain a cumulative risk sample. The relay risk control module performs threshold judgment on the cumulative risk sample and obtains relay high-risk signals, relay low-risk signals, and relay normal signals based on the judgment results. The relay risk control module acquires access security samples through the security verification module and comprehensively corrects the threshold judgment results of the access security samples and the cumulative risk samples to obtain relay high-risk signals, relay low-risk signals, and relay normal signals. After acquiring the relay high-risk signal, the relay risk control module performs formatting processing on the information relay transceiver module.

8. An information security protection method applied to a data center, employing the information security protection system for data centers as described in any one of claims 1-7, characterized in that, Includes the following steps: Step 1: Information access request verification; Step 2: Information relay access; Step 3: Information access request security verification; Step 4: Security risk assessment; Step 5: Relay module risk control execution.

9. A computer-readable storage medium, characterized in that, It stores a computer program, which, when executed by a processor, implements the information security protection method for data centers as described in claim 8.

Citation Information

Patent Citations

  • A method and system for information security protection in data centers

    CN114884745B

  • Computer information security supervision system based on artificial intelligence

    CN116579019A

  • Zero-trust dynamic access control method and device and computer equipment

    CN119046910A