A system for secure interactive analysis and processing of cross-departmental regulatory collaboration data

By constructing a secure interactive analysis and processing system for cross-departmental regulatory collaboration data, the problems of unclear data sharing boundaries and untraceable results in cross-departmental regulatory collaboration have been solved. This system has achieved data access security and result consistency and traceability, thereby improving data security and accounting consistency in cross-departmental regulatory collaboration.

CN121309005BActive Publication Date: 2026-02-13YIWU NEW SMART CITY OPERATION CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511862256.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-11
Publication Date
2026-02-13
Estimated Expiration
2045-12-11

AI Technical Summary

Technical Problem

The lack of a unified access control and security verification mechanism in cross-departmental regulatory collaboration leads to unclear data sharing boundaries, inconsistent collaborative accounting, and untraceable results.

Method used

Construct a secure interactive analysis and processing system for cross-departmental regulatory collaborative data, including a policy fingerprint generation module, an access authorization issuance module, a data compliance encapsulation module, a security verification loading module, a joint accounting analysis module, and a result output auditing module. These modules enable closed-loop management of data access control, security verification, joint accounting, and result output.

Benefits of technology

This ensures that the entire process of data access and output is subject to policy constraints, guarantees the security and verifiability of data transmission and access, achieves consistency and traceability of data results across multiple departments, and improves data security, accounting consistency, and accountability traceability in cross-departmental regulatory collaboration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121309005B_ABST
    Figure CN121309005B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of data security processing, and discloses a safe interaction analysis processing system for cross-department supervision collaborative data, which comprises a strategy fingerprint generation module, an access authorization issuing module, a data compliance packaging module, a security verification loading module, a joint accounting analysis module and a result output auditing module.The strategy fingerprint generation module is used for generating a strategy fingerprint based on task information; the access authorization issuing module is used for performing attribute authorization and issuing a bill according to the strategy fingerprint and a user identity; the data compliance packaging module is used for generating a compliance view according to the strategy fingerprint and performing deterministic desensitization and encryption packaging; the security verification loading module is used for verifying the consistency of a packaging bag and loading the packaging bag into a temporary session library to generate a session fingerprint; the joint accounting analysis module is used for performing deterministic joint accounting and early warning determination; and the result output auditing module is used for clipping an accounting result and generating an auditable proof bag.The early warning distribution monitoring module is used for pushing early warning information and monitoring a task execution state.The application realizes trusted interaction, compliance analysis and traceable management of cross-department supervision data under the condition of scattered storage.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of data security processing, and particularly relates to a safe interaction analysis processing system for cross-department supervision collaborative data. BACKGROUND

[0002] With the continuous deepening of supervision informatization work, cross-department supervision collaboration has become an important means to improve the comprehensive supervision ability and supervision efficiency. A large amount of scattered business data is formed in the process of different departments performing their duties. These data have differences in data structure, storage standard, access permission and security level, etc., and it is difficult to realize unified management and collaborative application. The existing cross-department collaboration method mainly depends on manual data export, offline transmission or point-to-point sharing, and the process is complex and inefficient. In the process of data transmission and aggregation, data leakage, unauthorized access, statistical duplication and inconsistent accounting standards may occur, which seriously affects the accuracy and timeliness of joint supervision.

[0003] At present, cross-department data collaboration mainly faces two problems: first, there is a lack of unified task strategy and access boundary control mechanism, which cannot realize on-demand access and dynamic authorization under the premise of ensuring data security; second, there is a lack of reliable data interaction and accounting mechanism, and the collaborative data between departments lack consistent security verification and responsibility tracking means in the process of transmission, processing and accounting, which makes it difficult to ensure reliable data source, complete content and traceable results. SUMMARY

[0004] The application provides a safe interaction analysis processing system for cross-department supervision collaborative data, which solves the technical problem that in the related art, there is a lack of unified access control and security verification mechanism in the cross-department supervision data collaboration process, resulting in unclear data sharing boundary, inconsistent collaborative accounting and untraceable results.

[0005] The application provides a safe interaction analysis processing system for cross-department supervision collaborative data, which includes:

[0006] A strategy fingerprint generation module is configured to select preset rules and indexes and determine a business scope based on task information in a task registration interface, and generate a strategy fingerprint.

[0007] An access authorization issuing module is configured to complete attribute-based access control authorization and issue a one-time capability ticket according to the strategy fingerprint, task information, user identity and ticket validity period.

[0008] A data compliance packaging module is configured to generate a compliance view from original data of each department according to the strategy fingerprint, execute deterministic desensitization on key fields of the supervision object, and encrypt and package the compliance view, the strategy fingerprint, the one-time capability ticket and the rule code hash value, and sign by the department to obtain an encrypted package.

[0009] A security verification loading module is configured to verify the consistency of the department signature, the one-time capability ticket and the policy fingerprint and the task information of the encrypted package in the controlled execution domain, and load the verified package as a temporary session library and generate a session fingerprint after verification;

[0010] A joint accounting analysis module is configured to perform deterministic joint accounting and early warning determination based on preset rules and indexes of the temporary session library and the policy fingerprint, and output joint accounting results and early warning trigger information;

[0011] A result auditing module is configured to clip the joint accounting results according to the number field and the aggregation granularity of the policy fingerprint, obtain minimized output data, and generate an auditable proof package combined with the task information, the policy fingerprint, the rule code hash value and the session fingerprint, and write the auditable proof package into a log;

[0012] An early warning distribution monitoring module is configured to push the early warning trigger information to the responsible person's account according to the distribution rules, and monitor and display the task status.

[0013] Further, the policy fingerprint includes: task purpose, time range and supervision object range, allowed field, join key, drillable level, data retention period and aggregation granularity.

[0014] Further, the generation process of the policy fingerprint includes:

[0015] Step 11, receiving a task information object from a task registration interface, and extracting a task number, a task initiating department, a task belonging business field, a task creation time and a task intention, determining a corresponding rule set and an index set according to the task intention, and obtaining task structured information; the index set includes: planned inspection rate, double random proportion, cross-department supervision rate and supervision correction rate; the rule set includes: repeated inspection, coordination inefficiency, result contradiction and expiration without processing;

[0016] Step 12, determining a business range based on the task structured information, including a time range, a supervision area, a supervision object set and a participating department set; extracting a required field set, a join key set and a drillable level according to the rule set and the index set, and setting a data retention period, a number field and an aggregation granularity;

[0017] Step 13, assembling the task purpose, the business range, the field set, the join key set, the drillable level, the data retention period, the number field, the aggregation granularity and the preset distribution rules to form a policy fingerprint object, calculating a policy fingerprint integrity hash value, and binding the policy fingerprint object and its identification number and the task number bidirectionally, and then registering into the library.

[0018] Further, the attribute-based access control authorization is completed and a one-time capability ticket is issued, including:

[0019] Step 21, obtain the user identity object, extract the user unique identifier, the department to which the user belongs, the role type, the security level, and the digital identity certificate, verify the validity of the digital identity certificate, construct an access request object based on the task information, the policy fingerprint, and the verified user identity attributes, the access request object including the task number, the policy fingerprint identifier, the user identity attributes, and the access request time;

[0020] Step 22, match the access request object according to the pre-defined access control rule set in the policy fingerprint; when the user department, role, and security level in the access request object all meet the range constraints of the policy fingerprint, generate an access authorization decision as allowed;

[0021] Step 23, when the access authorization decision is allowed, splice the policy fingerprint identifier, the task number, the user unique identifier, and the ticket validity period in a fixed order to form a digest original string, calculate the policy fingerprint digest through an anti-collision hash function, and digitally sign the policy fingerprint digest by the policy decision point private key to generate a one-time capability ticket.

[0022] Further, generate a compliance view from the original data of each department according to the policy fingerprint, and perform deterministic desensitization on the key fields of the regulated objects, including:

[0023] Step 31, load the data to be processed from the original data set of the department, and filter the data according to the time range and the scope of the regulated objects in the policy fingerprint to obtain a data subset that meets the task boundary;

[0024] Step 32, perform field projection on the filtered results according to the allowed fields in the policy fingerprint to generate a compliance view containing only necessary fields;

[0025] Step 33, perform deterministic desensitization processing on the join key fields specified in the policy fingerprint in the compliance view, hash the original join key values based on the shared key to obtain desensitized join key values.

[0026] Further, encrypt and encapsulate the compliance view, the policy fingerprint, the one-time capability ticket, and the rule code hash value, and sign them by the department to obtain an encrypted encapsulation package, including:

[0027] Step 41, read the policy fingerprint identifier, the task number, the one-time capability ticket, and the rule code hash value, combine them with the compliance view to form an encapsulation payload to be encrypted;

[0028] Step 42, encrypt the encapsulation payload to be encrypted using the public key of the controlled execution domain, and digitally sign the hash value of the encryption result using the private key of the department to generate an encrypted data body and a department signature;

[0029] Step 43, assemble the encrypted data body, department signature and department certificate into an encrypted package, and send the encrypted package to the controlled execution domain.

[0030] Further, the security verification loading module specifically comprises:

[0031] Step 51, receive the encrypted package from each department, verify the integrity of the encrypted data body, department signature and certificate structure in the encrypted package, and verify the department signature using the department public key certificate carried by the encrypted package; when the signature verification is passed, it is confirmed that the package is real and has not been tampered with;

[0032] Step 52, decrypt the encrypted data body using the private key of the controlled execution domain to obtain the encapsulated load, which includes the compliance view, policy fingerprint identifier, task number, one-time capability ticket and rule code hash value; verify the signature of the one-time capability ticket based on the public key of the policy decision point, and compare the policy fingerprint identifier, task number and user identifier to confirm the consistency and validity period of the ticket and the task context;

[0033] Step 53, according to the decrypted load information, check the matching relationship of the task number and the policy fingerprint identifier in the controlled execution domain task registration library and the policy fingerprint registration library, and load the encapsulated load into the temporary session library under the condition that all verifications are passed;

[0034] Step 54, based on the unique session number, task number, policy fingerprint identifier and loading time of the temporary session library, form a session original string in a fixed order, and calculate the session fingerprint through an anti-collision hash function.

[0035] Further, the process of performing deterministic joint accounting and early warning determination comprises:

[0036] Step 61, obtain the index set, rule set, aggregation granularity and drillable level, and align and time window cut the multi-department data in the temporary session library with the joint key in the policy fingerprint to obtain a data set that meets the task boundary;

[0037] Step 62, according to the index set, perform deterministic index calculation on the data set according to the aggregation granularity to generate an index result table, in which the plan inspection rate is obtained by the ratio of the number of inspections included in the plan to the actual number of inspections, the double random proportion is obtained by the ratio of the number of double random inspection checks to the total number of checks, the cross-department supervision rate is obtained by the ratio of the number of checks of a unified object in the time window by at least two departments to the total number of checks, and the supervision correction rate is obtained by the ratio of the number of corrected problems to the total number of discovered problems;

[0038] Step 63, check the indicator result table and the original record according to the condition judgment logic in the rule set, identify repeated checks, coordination inefficiency, conflicting results, and overdue events, and form a set of early warning events;

[0039] Step 64, integrate the set of early warning events according to the rule priority, generate a joint accounting result, and bind it with the corresponding session fingerprint to obtain an accounting record;

[0040] Step 65, according to the aggregation granularity and drillable level in the strategy fingerprint, perform pruning on the joint accounting result to obtain a minimized output view consistent with the strategy fingerprint, and form the final joint accounting result and early warning trigger information.

[0041] Further, the process of pruning the joint accounting result according to the output field and aggregation granularity of the strategy fingerprint to generate the minimized output data and form the auditable proof package includes:

[0042] Step 71, obtain the set of output fields, aggregation granularity, and data retention period, and perform field filtering and hierarchical aggregation on the joint accounting result with the join key in the strategy fingerprint to obtain an aggregated result table consistent with the output caliber;

[0043] Step 72, based on the aggregated result table and the set of early warning events, constrain the data items directly associated with the indicators according to the output field to generate a minimized output data set; and concatenate the task information, strategy fingerprint identifier, rule code hash value, and session fingerprint, and calculate a structured digest through an anti-collision hash function;

[0044] Step 73, digitally sign the structured digest with a controlled execution domain private key to generate an auditable proof package containing the data payload and signature information, and write it to the log.

[0045] Further, the early warning distribution monitoring module specifically includes:

[0046] Step 81, extract the task number, responsible department, and responsible person account from the early warning trigger information, and establish an early warning distribution mapping relationship according to the distribution rules in the strategy fingerprint to generate a responsibility assignment table;

[0047] Step 82, based on the responsibility assignment table, load the corresponding task template from the task template library, automatically configure the work requirements, completion time limit, and carbon copy objects, instantiate the task object and push it to the responsible person account, and realize task assignment and signing;

[0048] Step 83, receive the task status and processing time reported by the responsible person during task execution, calculate the time deviation amount according to the task completion time limit and the specified completion time limit, and monitor and display the task status.

[0049] The application has the beneficial effects that: the application forms a safe interactive analysis processing system of cross-departmental regulatory collaborative data by constructing strategy fingerprint, access authorization, data compliance packaging, security verification, joint calculation, result output and early warning closed loop and other modules. The strategy fingerprint defines the task boundary and field granularity, ensures that the data access and output process are subject to strategy constraints; through the one-time capability ticket and encryption packaging mechanism, the security and verifiability of data transmission and access process are ensured; through deterministic joint calculation and early warning judgment, the consistency and traceability of multi-department data results are realized; through result clipping and audit-proof proof package generation, the minimization and tamper resistance of result output are ensured; through early warning distribution and task monitoring mechanism, a closed loop system of risk discovery, distribution and disposal is built. Overall, the application improves the data security, calculation consistency and responsibility traceability of cross-departmental regulatory collaboration. BRIEF DESCRIPTION OF DRAWINGS

[0050] Figure 1 is a module schematic diagram of a safe interactive analysis processing system of cross-departmental regulatory collaborative data of the application. DETAILED DESCRIPTION

[0051] The subject matter described herein will now be discussed with reference to example implementations. It should be understood that the discussion of these implementations is merely meant to provide a better understanding of the subject matter described herein and can include changes to the function and arrangement of elements discussed without departing from the scope of the content of this specification. Various examples can omit, substitute, or add various procedures or components as desired. In addition, features described with respect to some examples can be combined in other examples.

[0052] As shown in Figure 1 , a safe interactive analysis processing system of cross-departmental regulatory collaborative data includes:

[0053] A strategy fingerprint generation module 1 is configured to select preset rules and indicators and determine a business scope based on task information in a task registration interface, and generate a strategy fingerprint.

[0054] An access authorization issuing module 2 is configured to complete attribute-based access control authorization according to the strategy fingerprint, task information, user identity and ticket validity period, and issue a one-time capability ticket.

[0055] A data compliance packaging module 3 is configured to generate a compliance view from original data of each department according to the strategy fingerprint, perform deterministic desensitization on key fields of the regulatory object, and encrypt and package the compliance view, the strategy fingerprint, the one-time capability ticket and the rule code hash value and sign by the department to obtain an encrypted package.

[0056] The security verification loading module 4 is configured to verify the consistency of the department signature, the one-time capability ticket and the policy fingerprint and the task information of the encrypted package in the controlled execution domain, and load the temporary session library and generate the session fingerprint after the verification is passed.

[0057] The joint accounting analysis module 5 is configured to perform the deterministic joint accounting and early warning determination based on preset rules and indexes of the temporary session library and the policy fingerprint, and output the joint accounting result and the early warning trigger information.

[0058] The result auditing module 6 is configured to cut the joint accounting result according to the output field and the aggregation granularity of the policy fingerprint, obtain the minimized output data, and generate the auditable proof package combined with the task information, the policy fingerprint, the rule code hash value and the session fingerprint and write the auditable proof package into the log.

[0059] The early warning distribution monitoring module 7 is configured to push the early warning trigger information to the responsible person account according to the distribution rule, and monitor and display the task state.

[0060] In an embodiment of the present application, the policy fingerprint is a structured data object for identifying the task execution boundary and the data use constraint, and includes a task purpose, a time range and a regulatory object range, an allowed field, a join key, a drillable level, a data retention period and an aggregation granularity.

[0061] Specifically, the time range is configured to limit the time window suitable for the task, such as a regulatory inspection period of a quarter or a year; the regulatory object range is configured to limit the subject category involved by the data, such as a specific industry, a region or a regulated unit; the allowed field refers to a set of data fields allowed to be accessed and used by the system when generating the compliance view and performing the accounting; the join key set is a set of unique association fields for cross-department data comparison, and an irreversible association identifier is generated by a deterministic de-identification method, which is used to realize the accurate matching of data between multiple departments on the premise of ensuring data privacy; the drillable level is configured to describe the dimension level of the data after aggregation, so as to ensure that the accounting result can be queried in a controlled range; and the aggregation granularity is configured to limit the data aggregation level.

[0062] In an embodiment of the present application, the generation process of the policy fingerprint includes:

[0063] Step 11, receiving a task information object from a task registration interface, and extracting a task number, a task initiating department, a task belonging business field, a task creation time and a task intention, determining a corresponding rule set and an index set according to the task intention, and obtaining task structured information; the index set includes: a plan inspection rate, a double random proportion, a cross-department supervision rate, and a supervision correction rate; the rule set is used for subsequent abnormality identification and early warning determination, including: repeated inspection, low efficiency of cooperation, contradictory results, and expiration without processing; wherein, the repeated inspection is used for detecting a situation that a same supervision object is repeatedly inspected within a time window; the low efficiency of cooperation is used for identifying a situation that a joint task execution time is too long; the contradictory results are used for detecting a situation that different departments have inconsistent inspection conclusions on a same object; and the expiration without processing is used for judging a situation that a planned task or an inspection result is not completed within a specified period of time.

[0064] Step 12, determining a business scope based on the task structured information, including a time range, a supervision region, a supervision object set and a participating department set; the supervision region is used for restricting a region of task execution; the supervision object set is a set of object entities participating in task supervision; the participating department set refers to data providing and accounting departments participating in the supervision task; according to the rule set and the index set, a required field set, a junction key set and a drillable level are extracted, and a data retention period, an output field and an aggregation granularity are set; the output field is used to determine a data range that can be publicly disclosed by each department in task cooperation.

[0065] Step 13, assembling the task purpose, the business scope, the field set, the junction key set, the drillable level, the data retention period, the output field, the aggregation granularity and a preset distribution rule to form a strategy fingerprint object, and calculating a strategy fingerprint integrity hash value, and then registering the strategy fingerprint object and its identification number and the task number into a database in a bidirectional binding manner. The strategy fingerprint integrity hash value is used to uniquely identify a version state of the strategy fingerprint, and prevents the strategy from being tampered after registration.

[0066] The strategy fingerprint generated by the above steps in the embodiment enables the system to strictly control the task execution boundary, data access permission, field granularity and output dimension in the cross-department supervision cooperation process, so as to ensure that different departments complete data processing and accounting under unified strategy constraints. The mechanism realizes cross-department data sharing while avoiding the problems of unauthorized reading and repeated statistics caused by inconsistent access boundaries, and ensures the safety, traceability and consistency of data processing.

[0067] In an embodiment of the present application, the strategy fingerprint further includes an access control rule set, which is used to limit the department range, role type and security level constraints of the task participating user, so as to realize attribute-based access determination in the authorization stage. The attribute-based access control authorization is completed and a one-time capability ticket is issued, including:

[0068] Step 21, obtain a user identity object, extract a user unique identifier, a department to which the user belongs, a role type, a security level, and a digital identity credential, wherein the digital identity credential is an encryption certificate or a token issued by a unified identity authentication agency, validity of the digital identity credential is verified to confirm whether the credential is within a valid period, whether the issuing agency is trustworthy, and whether the signature is complete, an access request object is constructed based on task information, a policy fingerprint, and verified user identity attributes, the access request object includes a task number, a policy fingerprint identifier, user identity attributes, and an access request time, the policy fingerprint identifier is used to indicate a policy version and rule constraints applicable to the current task, and the access request object is used to represent a data access request initiated by the user in a specific task context;

[0069] Step 22, the access request object is matched and determined according to a set of access control rules in the policy fingerprint; when the user department, role, and security level in the access request object all meet the range constraints of the policy fingerprint, an access authorization decision is generated as allowed, otherwise the access authorization decision is generated as refused; specifically, the set of access control rules is an access constraint model corresponding to the task policy one by one, and is used to define department range, role type, and security level conditions allowed to access the task;

[0070] Step 23, when the access authorization decision is allowed, a digest original string is formed by splicing in a fixed order based on the policy fingerprint identifier, the task number, the user unique identifier, and the ticket validity period, and a one-way operation is performed on the digest original string by using an anti-collision hash function, a policy fingerprint digest is calculated, and the policy fingerprint digest is digitally signed by a policy decision point private key to generate a one-time capability ticket, which is used to authorize the user to perform a specific task operation within a limited time and within a limited range. The policy fingerprint digest is a unique identifier of the current authorized context, and is used to ensure integrity and tamper resistance of the authorization result.

[0071] The embodiment dynamically matches the user department, role, and security level with the task policy through the rule set in the policy fingerprint, realizes fine-grained access control, generates the policy fingerprint digest by using the anti-collision hash function, forms the one-time capability ticket by using the private key digital signature, ensures that the authorization credential cannot be counterfeited, and improves data security and accuracy of access management in a cross-department supervision and collaboration environment.

[0072] In an embodiment of the present application, a compliance view is generated from original data of each department according to a policy fingerprint, and deterministic desensitization is performed on key fields of a supervision object, including:

[0073] Step 31, load the to-be-processed data from the original data set of the department, and perform data screening according to the time range and the regulatory object range in the policy fingerprint, to obtain a data subset conforming to the task boundary, so as to avoid out-of-bound use or redundant loading; the original data set is structured record data accumulated by the department in daily business, such as inspection records, penalty information, and spot check results.

[0074] Step 32, perform field projection on the screening result according to the allowed field in the policy fingerprint, to generate a compliance view containing only necessary fields; specifically, field projection refers to a process of selecting part of fields from an original data table to form a new data view, to control the range of accessible fields; through the field projection operation, the system automatically removes unauthorized fields when generating the compliance view, to ensure data minimization use and privacy compliance from the source.

[0075] Step 33, since the original data of different departments may contain identification information of the same object, and such information usually belongs to sensitive fields and cannot be directly exposed or exchanged, deterministic de-sensitization is required. Perform deterministic de-sensitization processing on the join key field specified in the policy fingerprint in the compliance view, and perform hash calculation on the original join key value based on a shared key to obtain a de-sensitized join key value. The deterministic de-sensitization refers to an irreversible encryption processing mode that always generates the same output value for the same input value, so as to ensure that the data remains consistent after independent de-sensitization in different departments. In this embodiment, the system performs calculation on the original join key based on a shared key through an anti-collision hash function to generate an irreversible de-sensitized join key value.

[0076] This embodiment realizes task-level boundary control of data screening through time range and regulatory object range constraints, to ensure that only data related to the task is processed; through the allowed field and field projection mechanism, it is ensured that the compliance view contains only necessary fields, to reduce the data leakage risk from the source; through the irreversible transformation of the shared key and the anti-collision hash function, it is prevented that any party restores the original identification information alone, to improve the privacy security of data interaction, and to realize safe collaborative preprocessing of cross-department data without centralized original data.

[0077] In an embodiment of the present application, the compliance view, the policy fingerprint, the one-time capability ticket, and the rule code hash value are encrypted and packaged by the department, to obtain an encrypted package, including:

[0078] Step 41, read the policy fingerprint identifier, task number, one-time capability ticket and rule code hash value, combine them with the compliance view to form an encapsulated load to be encrypted; the rule code hash value is an anti-collision hash digest calculated by the accounting and rule script adopted in the task execution process, used to identify the integrity status of the current accounting logic. The encapsulated load contains not only the task data content, but also the complete policy, security and rule context information, ensuring that the subsequent controlled execution domain can verify the task identity, policy scope and execution environment when receiving the data.

[0079] Step 42, encrypt the encapsulated load to be encrypted using the public key of the controlled execution domain, and use the private key of the department to digitally sign the hash value of the encryption result, generating encrypted data and department signature; wherein the controlled execution domain refers to a cross-department data processing execution space deployed in a secure computing environment, with independent key system and access isolation mechanism, and can only receive encrypted data through the preset public key. The encryption algorithm of this step is preferably RSA public key encryption algorithm. The department signature is implemented by using an asymmetric encryption algorithm, which can prove that the data indeed comes from the signing department, and ensures that the encapsulated content has not been modified after signing.

[0080] Step 43, assemble the encrypted data, department signature and department certificate into an encrypted encapsulation package, and send the encrypted encapsulation package to the controlled execution domain. The encrypted encapsulation package includes: data content encrypted by the public key of the controlled execution domain; signature data generated by the private key of the department; department digital certificate identifying the signing subject.

[0081] In this embodiment, the encapsulated load is encrypted by the public key of the controlled execution domain, so that it cannot be read by unauthorized third parties during transmission; through the department private key signature and digital certificate verification mechanism, it ensures that the receiver can verify the authenticity of the data source, prevents forgery or impersonation, and realizes full-link encryption and signature verification from data generation, transmission to reception in the cross-department regulatory collaboration environment.

[0082] In an embodiment of the present application, the security verification loading module specifically includes:

[0083] Step 51, receive the encrypted encapsulation package from each department, verify the integrity of the encrypted data, department signature and certificate structure in the encrypted encapsulation package, verify whether the encrypted data, department signature and certificate structure are complete and meet the predetermined format requirements, and verify the department signature using the department public key certificate carried by the encrypted encapsulation package; when the signature verification is passed, it is confirmed that the encapsulation package is real and has not been tampered with; the signature verification process ensures that each data encapsulation package has a verifiable source identity, thereby preventing fake data or malicious injection.

[0084] Step 52, the encrypted data body is decrypted using the private key of the controlled execution domain to obtain an encapsulated load, wherein the encapsulated load includes a compliance view, a policy fingerprint identifier, a task number, a one-time capability ticket and a rule code hash value; the signature of the one-time capability ticket is verified based on the public key of the policy decision point, and the policy fingerprint identifier, the task number and the user identifier are compared to confirm the consistency and validity period of the ticket and the task context; through the verification step, the system can ensure that the current decrypted data indeed corresponds to a legal task request and is within the authorized time window, thereby preventing fake tickets or repeated access behaviors.

[0085] Step 53, according to the load information after decryption, the matching relationship of the task number and the policy fingerprint identifier is checked in the controlled execution domain task registration library and the policy fingerprint registration library, and in the case that all verifications are passed, the encapsulated load is loaded as a temporary session library; wherein the task registration library is used to store the number, creation time and state information of all registered tasks in the system; the policy fingerprint registration library is used to store the policy fingerprint object and the version number corresponding to each task. The system confirms that the encapsulated load is consistent with the task instance and the policy version recorded in the registration library through bidirectional matching, ensures that the data belongs to a legal task and the policy version is not replaced. When all verifications are passed, the system formally loads the encapsulated load as a temporary session library. The temporary session library is an isolated data container inside the controlled execution domain, which is used to store the temporary data set and context information of the current task, and supports computing and analysis in the security domain.

[0086] Step 54, a session original string is spliced in a fixed order based on the unique session number, the task number, the policy fingerprint identifier and the loading time of the temporary session library, and a session fingerprint is calculated through an anti-collision hash function. The session fingerprint is used to uniquely identify the execution state of this session.

[0087] The embodiment ensures that the encrypted encapsulation package is real and cannot be forged through the department signature and digital certificate double verification mechanism; the encrypted body and the encapsulated load are verified through hashing and signature before and after data decryption to prevent data from being tampered with in the transmission or storage process; the embodiment establishes a trusted execution chain from encapsulation verification to controlled loading for cross-department regulatory collaborative data, and realizes the unity of data transmission security, execution controllability and result traceability.

[0088] In an embodiment of the present application, the process of performing deterministic joint accounting and early warning determination includes:

[0089] Step 61, obtain the indicator set, rule set, aggregation granularity, and drillable level, and align the multi-department data in the temporary session library with the join key in the strategy fingerprint, and perform time window clipping to obtain a data set that meets the task boundary; specifically, the system first clips the data window according to the time range defined by the strategy fingerprint, to ensure that the analysis object only contains valid records within the task period; then align the data of different departments with the join key as the connection field, to achieve cross-department object-level matching and time consistency control, thereby forming a data set that meets the task boundary.

[0090] Step 62, perform deterministic indicator calculation on the data set according to the indicator set and the aggregation granularity, to generate an indicator result table; in the indicator result table, the plan inspection rate is obtained by the ratio of the number of inspections included in the plan to the actual number of inspections, the double-random proportion is obtained by the ratio of the number of double-random inspection checks to the total number of inspections, the cross-department supervision rate is obtained by the ratio of the number of inspections of a unified object within the time window by at least two departments to the total number of inspections, and the supervision correction rate is obtained by the ratio of the number of corrected problems to the total number of discovered problems;

[0091] Step 63, perform verification on the indicator result table and the original records according to the condition judgment logic in the rule set, to identify repeated inspections, coordination inefficiency, contradictory results, and expired unprocessed events, and form a pre-warning event set for identifying possible abnormal task behaviors or results;

[0092] Step 64, integrate the pre-warning event set according to the rule priority, to generate a joint accounting result, and bind it with the corresponding session fingerprint, to obtain an accounting record corresponding to a session; wherein the rule priority is set according to the risk level defined in the task strategy;

[0093] Step 65, perform clipping on the joint accounting result according to the aggregation granularity and the drillable level in the strategy fingerprint, to obtain a minimized output view consistent with the strategy fingerprint, and form the final joint accounting result and pre-warning trigger information. The minimized output view only retains the data fields and summary results directly related to the task target, and eliminates intermediate calculations and auxiliary fields, to ensure that the result meets the minimum available principle in information disclosure.

[0094] The embodiment completes the alignment and consistency accounting of different department data in a controlled execution domain by the join key and the aggregation granularity in the strategy fingerprint, and eliminates the difference in caliber; the fixed indicator formula and the standard parameter set are used to realize verifiable calculation logic and traceable results; the embodiment realizes deterministic accounting and automatic pre-warning of cross-department supervision tasks under the premise of ensuring data security and access compliance.

[0095] In an embodiment of the present application, the process of generating minimized output data and forming an auditable proof package by jointing the number of fields of the policy fingerprint with the aggregation granularity clipping result, includes:

[0096] Step 71, obtain the set of number of fields, aggregation granularity and data retention period, and perform field filtering and hierarchical aggregation on the jointing result in the policy fingerprint with the joint key to obtain an aggregated result table within the scope of policy authorization and meeting the number of field criteria, to prevent out-of-scope disclosure;

[0097] Step 72, based on the aggregated result table and the set of early warning events, retain the data items directly associated with the indicators according to the number of fields to generate a minimized output data set; and splice the task information, policy fingerprint identifier, rule code hash value and session fingerprint, and calculate a structured digest through an anti-collision hash function; the structured digest is used to identify the integrity and consistency of the minimized output data set, to verify the tamper resistance of the output data load in the transmission and storage process;

[0098] Step 73, digitally sign the structured digest through a controlled execution domain private key to generate an auditable proof package containing the data load and signature information, and write it into a log. The data load contains the minimized output data set and the structured digest.

[0099] The embodiment defines the number of fields and the aggregation granularity through the policy fingerprint, and the system can accurately control the disclosed fields and the aggregation level at the number stage to prevent unauthorized disclosure; the minimized output data set only retains the fields directly related to the task target, which can reduce the transmission and storage of sensitive data; the embodiment makes the processing result of the cross-department regulatory collaborative data still have verifiable integrity and credibility at the number stage.

[0100] In an embodiment of the present application, after completing jointing and early warning determination, to realize the responsibility implementation and closed-loop management of risk events, based on the pre-defined distribution rules in the policy fingerprint, the early warning trigger information is automatically pushed to the corresponding responsible person account, and the whole process of execution monitoring and progress display is performed. The early warning distribution monitoring module specifically includes:

[0101] Step 81, extract the task number, responsible department and responsible person account from the early warning trigger information, and establish an early warning distribution mapping relationship according to the distribution rules in the policy fingerprint to generate a responsibility assignment table; the distribution rules are used to describe the responsibility attribution logic and information transmission path of the risk event, including: mapping conditions according to department type, task level or regulatory object category. The responsibility assignment table records the responsible department, responsible person account and carbon copy object information corresponding to each early warning event.

[0102] Step 82, based on the responsibility assignment table, load the corresponding task template from the task template library, automatically configure the work requirements, completion time limit and carbon copy object, instantiate the task object and push it to the responsible person account, realize the task assignment and signing; the task template library is used to define the processing requirements, completion time limit, collaboration mode and reporting mode of different types of risk events.

[0103] Step 83, receive the task status and processing time reported by the responsible person during the task execution process, calculate the time deviation amount according to the task completion time limit and the specified completion time limit, monitor and display the task status, and write the status change and timestamp into the log. Specifically, the task status includes: processing, completed and overdue; the time deviation amount is obtained by calculating the difference between the actual completion time of the task and the specified completion time limit, which is used to measure the timeliness of task execution; when the time deviation amount exceeds the set deviation threshold, the system prompts the state on the board interface through red, yellow and green lights, where red represents overdue, yellow represents approaching deadline, and green represents on-time completion.

[0104] The embodiment automatically generates a responsibility assignment table through the distribution rule in the strategy fingerprint, ensures that the risk information is accurately delivered to the corresponding responsible person; through the task template library, the embodiment realizes the rapid configuration and reuse of different risk types, improves the task assignment efficiency; the embodiment makes the supervision collaboration system not only able to discover risks, but also able to realize accurate task assignment, dynamic tracking and whole-process traceable supervision, ensuring the safety and timeliness of cross-departmental supervision information collaboration.

[0105] It should be noted that the setting of the interval and the threshold size is for easy comparison, and the size of the threshold depends on the number of sample data and the base number set by the person skilled in the art for each group of sample data, as long as it does not affect the proportional relationship of the parameters and the quantized values. And the above formula is a dimensionless calculation of the value, and the formula is obtained by software simulation of a large amount of data to obtain a formula of the nearest real situation, and the preset parameters in the formula are set by the person skilled in the art according to the actual situation.

[0106] The data involved in the present application are all obtained with full authorization, and the collection, use and processing of relevant information need to comply with relevant laws, regulations and standards of relevant countries and regions.

[0107] The embodiments of the present application are described above, but the present application is not limited to the above specific embodiments, the above specific embodiments are only illustrative, not limiting, and those skilled in the art can make many forms under the inspiration of the present embodiment, which are all within the protection of the present embodiment.

Claims

1. A secure interactive analytics processing system for cross-departmental regulatory collaboration data, characterized in that, Comprise: A policy fingerprint generation module for selecting preset rules and indicators on a task registration interface based on task information and determining a business scope to generate a policy fingerprint; An access authorization issuing module for completing attribute-based access control authorization and issuing a one-time capability ticket according to the policy fingerprint, the task information, the user identity and the ticket validity period; A data compliance packaging module for generating a compliance view from original data of each department according to the policy fingerprint, performing deterministic desensitization on key fields of a supervised object, and encrypting and packaging the compliance view, the policy fingerprint, the one-time capability ticket and a rule code hash value and signing by the department to obtain an encrypted package; A security verification loading module for verifying the consistency of the department signature, the one-time capability ticket and the policy fingerprint and the task information in the controlled execution domain, and loading as a temporary session library and generating a session fingerprint after verification; A joint accounting analysis module for performing deterministic joint accounting and early warning judgment based on the preset rules and indicators of the temporary session library and the policy fingerprint, and outputting joint accounting results and early warning trigger information; A result auditing module for cropping the joint accounting results according to the output field and the aggregation granularity of the policy fingerprint to obtain minimized output data, and generating an auditable proof package combined with the task information, the policy fingerprint, the rule code hash value and the session fingerprint and writing into a log; An early warning distribution monitoring module for pushing the early warning trigger information to the responsible person's account according to the distribution rules, and monitoring and displaying the task status.

2. The system for secure interactive analysis processing of cross-department supervisory collaborative data according to claim 1, wherein, The policy fingerprint comprises: task purpose, time range and supervision object range, allowed field, join key, drillable level, data retention period and aggregation granularity.

3. The secure interactive analytics processing system of cross-departmental regulated collaborative data of claim 2, wherein, The generation process of the policy fingerprint comprises: Step 11, receiving a task information object from the task registration interface, and extracting a task number, a task initiating department, a task belonging business field, a task creation time and a task intention, determining a corresponding rule set and an indicator set according to the task intention to obtain task structured information; the indicator set comprises: planned inspection rate, double random proportion, cross-department supervision rate and supervision correction rate; the rule set comprises: repeated inspection, coordination inefficiency, result contradiction and expiration without processing; Step 12, determining a business scope based on the task structured information, including a time range, a supervision area, a supervision object set and a participating department set; extracting a required field set, a join key set and a drillable level according to the rule set and the indicator set, and setting a data retention period, an output field and an aggregation granularity; Step 13, assembling the task purpose, the business scope, the field set, the join key set, the drillable level, the data retention period, the output field, the aggregation granularity and the preset distribution rules to form a policy fingerprint object, and calculating a policy fingerprint integrity hash value, and binding the policy fingerprint object and its identification number and the task number bidirectionally and registering into the database.

4. The system for secure interactive analysis processing of cross-department governed collaborative data according to claim 1, wherein, Complete attribute-based access control authorization and issue a one-time capability ticket, comprising: Step 21, obtain the user identity object, extract the user unique identifier, the department to which the user belongs, the role type, the security level, and the digital identity certificate, verify the validity of the digital identity certificate, construct an access request object based on the task information, the policy fingerprint, and the verified user identity attributes, the access request object including the task number, the policy fingerprint identifier, the user identity attributes, and the access request time; Step 22, match the access request object according to the pre-defined access control rule set in the policy fingerprint; when the user department, role, and security level in the access request object all meet the range constraints of the policy fingerprint, generate an access authorization decision as allowed; Step 23, when the access authorization decision is allowed, splice the policy fingerprint identifier, the task number, the user unique identifier, and the ticket validity period in a fixed order to form a digest original string, calculate the policy fingerprint digest through an anti-collision hash function, and digitally sign the policy fingerprint digest with the policy decision point private key to generate a one-time capability ticket.

5. The secure interactive analytics processing system of cross-departmental regulated collaborative data of claim 2, wherein, Generate a compliance view from the original data of each department according to the policy fingerprint, and perform deterministic desensitization on the key fields of the regulated objects, including: Step 31, load the data to be processed from the original data set of the department, and filter the data according to the time range and the scope of the regulated objects in the policy fingerprint to obtain a data subset that meets the task boundary; Step 32, perform field projection on the filtered results according to the allowed fields in the policy fingerprint to generate a compliance view containing only necessary fields; Step 33, perform deterministic desensitization processing on the join key fields specified in the policy fingerprint in the compliance view, hash the original join key values based on the shared key to obtain desensitized join key values.

6. The secure interactive analytics processing system that facilitates cross-departmental regulatory collaboration of data, as claimed in claim 1, wherein, Encapsulate the compliance view, the policy fingerprint, the one-time capability ticket, and the rule code hash value, and sign them with the department to obtain an encrypted encapsulation package, including: Step 41, read the policy fingerprint identifier, the task number, the one-time capability ticket, and the rule code hash value, combine them with the compliance view to form an encapsulation payload to be encrypted; Step 42, encrypt the encapsulation payload to be encrypted using the public key of the controlled execution domain, and digitally sign the hash value of the encryption result using the private key of the department to generate an encrypted data body and a department signature; Step 43, assemble the encrypted data body, the department signature, and the department certificate into an encrypted encapsulation package, and send the encrypted encapsulation package to the controlled execution domain.

7. The system of claim 1, wherein, The security verification loading module specifically includes: Step 51, receive the encrypted encapsulation package from each department, verify the integrity of the encrypted data body, the department signature, and the certificate structure in the encrypted encapsulation package, and verify the department signature using the department public key certificate carried by the encrypted encapsulation package; when the signature verification is passed, confirm that the encapsulation package is genuine and has not been tampered with; Step 52, decrypt the encrypted data body using the private key of the controlled execution domain to obtain the encapsulated payload, which includes the compliance view, policy fingerprint identification, task number, one-time capability ticket, and rule code hash value; verify the signature of the one-time capability ticket based on the public key of the policy decision point, and compare the policy fingerprint identification, task number, and user identification to confirm the consistency and validity period of the ticket and task context; Step 53, according to the decrypted payload information, check the matching relationship of the task number and policy fingerprint identification in the controlled execution domain task registration library and policy fingerprint registration library, and load the encapsulated payload as a temporary session library under the condition that all verifications are passed; Step 54, based on the unique session number, task number, policy fingerprint identification, and loading time of the temporary session library, form a session original string in a fixed order, and calculate the session fingerprint through an anti-collision hash function.

8. The system for secure interactive analysis processing of cross-department governed collaborative data according to claim 1, wherein, The process of performing deterministic joint accounting and early warning determination includes: Step 61, obtain the index set, rule set, aggregation granularity, and drillable level, and align and time window cut the multi-department data in the temporary session library based on the join key in the policy fingerprint to obtain a data set that meets the task boundary; Step 62, according to the index set, perform deterministic index calculation on the data set according to the aggregation granularity to generate an index result table. In the index result table, the plan inspection rate is obtained by the ratio of the number of inspections included in the plan to the actual number of inspections, the double-random proportion is obtained by the ratio of the number of double-random inspection to the total number of inspections, the cross-department supervision rate is obtained by the ratio of the number of inspections of a unified object within a time window by at least two departments to the total number of inspections, and the supervision correction rate is obtained by the ratio of the number of corrected problems to the total number of discovered problems; Step 63, according to the condition determination logic in the rule set, check the index result table and the original record to identify repeated inspections, coordination inefficiency, contradictory results, and expired unprocessed events, and form an early warning event set; Step 64, integrate the early warning event set according to the rule priority to generate joint accounting results, and bind them with the corresponding session fingerprint to obtain accounting records; Step 65, according to the aggregation granularity and drillable level in the policy fingerprint, cut the joint accounting results to obtain a minimized output view consistent with the policy fingerprint range, and form the final joint accounting results and early warning trigger information.

9. The system of claim 1, wherein, The process of cutting the joint accounting results according to the output field of the policy fingerprint and the aggregation granularity to generate the minimized output data and form the auditable proof package includes: Step 71, obtain the output field set, aggregation granularity, and data retention period, and perform field filtering and level aggregation on the joint accounting results based on the join key in the policy fingerprint to obtain an aggregated result table that meets the output range; Step 72, based on the aggregated result table and the early warning event set, retain the data items directly associated with the indicators according to the output field constraints to generate a minimized output data set; and concatenate the task information, policy fingerprint identification, rule code hash value, and session fingerprint, and calculate a structured digest through an anti-collision hash function. Step 73, the structured abstract is digitally signed by the controlled execution domain private key, an auditable proof package containing the data payload and signature information is generated, and written into the log.

10. The system of claim 1, wherein, The early warning distribution monitoring module specifically comprises: Step 81, the task number, the responsible department and the responsible person account are extracted from the early warning trigger information, and the early warning distribution mapping relationship is established according to the distribution rule in the strategy fingerprint, and the responsibility assignment table is generated; Step 82, based on the responsibility assignment table, the corresponding task template is loaded from the task template library, the work requirement, the completion time limit and the carbon copy object are automatically configured, the task object is instantiated and pushed to the responsible person account, the task assignment and signing are realized; Step 83, the task state and processing time reported by the responsible person in the task execution process are received, the time deviation amount is calculated according to the task completion time limit and the specified completion time limit, and the task state is monitored and displayed.

Citation Information

Patent Citations

  • Jumping key digital communication encryption system and method based on national secret algorithm

    CN114915396A

  • Safety monitoring method and system for financial information service platform

    CN120372642A