Enterprise digital management system of economic model
The enterprise digital management system using economic models quantifies the economic impact of data security incidents in real time and dynamically generates security resource allocation schemes. This solves the risk problem caused by the simplification of security measures in the enterprise digital management system, realizes closed-loop optimization of security strategies and economic models, and improves protection capabilities and operational efficiency.
Patent Information
- Application Number
- CN202511710229.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-20
- Publication Date
- 2026-03-03
AI Technical Summary
Existing enterprise digital management systems often rely on a complacent approach to cost control and simplified security measures, leading to direct impacts on core business activities when data is lost or leaked, and lacking effective risk protection mechanisms.
The enterprise digital management system, which adopts an economic model, includes an economic indicator analysis engine, a security management center, a policy mapping module, a dynamic access control module, and a value assessment feedback module. It generates security resource configuration plans by calculating key economic indicators in real time, manages user permissions in real time, and continuously collects execution effect data to optimize security policies.
It enables precise configuration of security protection level and backup frequency, avoids short-sighted behavior in cost control, enhances the system's adaptive protection capability against data leakage and business interruption, and significantly improves operational efficiency and risk control capabilities.
Smart Images

Figure CN121599535A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of enterprise management, and particularly to an enterprise digital management system with an economic model. Background Art
[0002] An enterprise digital management system refers to a comprehensive platform that integrates internal and external resources of an enterprise through information technology means, and systematically manages business processes, data assets and operation decisions. Its core goal is to improve operation efficiency, optimize resource allocation and strengthen risk control capabilities, and it is the infrastructure for modern enterprises to achieve digital transformation.
[0003] Enterprise digital management systems in the prior art usually adopt a modular architecture, control user access behaviors through preset security policies and permission rules, and rely on a data backup mechanism to ensure business continuity. Each module of the system executes data monitoring, permission verification and risk warning functions according to established logic, forming a relatively static protection system.
[0004] However, the existing enterprise digital management systems have obvious defects in actual applications: in actual construction, enterprises may simplify security measures to control costs, such as using free antivirus software and not performing off-site data backup, etc. This kind of fluke mentality will lay serious security risks, and once data loss or leakage occurs, it will directly impact the core business activities of the enterprise. Therefore, there is an urgent need to provide an enterprise digital management system with an economic model to solve the above problems. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to overcome the above-mentioned defects of the prior art and provide an enterprise digital management system with an economic model.
[0006] To solve the above technical problem, a technical solution adopted by the present invention is: to provide an enterprise digital management system with an economic model, including an economic indicator analysis engine, a security management center, a policy mapping module, a dynamic permission control module and a value evaluation feedback module; The economic indicator analysis engine is used to calculate and output in real time the key economic indicators of the enterprise's core business activities; The security management center receives the key economic indicators and generates a security resource allocation plan based on them; the security management center is built-in with an active defense unit and an intelligent backup unit, and the security resource allocation plan includes the security protection level set by the active defense unit and the data backup frequency set by the intelligent backup unit; The policy mapping module is used to convert the security resource allocation plan into data access rules and control rules; The dynamic access control module manages user access permissions to the enterprise's core business activities based on the data access rules and the control rules, and performs real-time generation or revocation of the access permissions. The value assessment feedback module is used to continuously collect the efficiency of business data flow and the occurrence of data security incidents in the core business activities of the enterprise after the permission adjustment as execution effect data, and feed the execution effect data back to the economic indicator analysis engine.
[0007] The present invention is further configured such that: the key economic indicators in the economic indicator analysis engine include the average estimated loss of a single data security incident and the expected input-output ratio of the data backup strategy; The economic indicator analysis engine is specifically a risk quantification economic model built on historical data security incidents and losses from interruptions in core business activities of enterprises. The method for constructing the risk quantification economic model is as follows: S1. Establish a sample library of historical data security events of core business activities of enterprises. By extracting features from the data processing flow of various core business activities of enterprises in the sample library, a business value flow map is formed. The business value flow map includes the value contribution parameters of data input nodes, data processing nodes and data output nodes of core business activities of enterprises. S2. Based on the value contribution parameter, historical data security events are mapped to the data input nodes, data processing nodes, and data output nodes of the enterprise's core business activities. By analyzing the degree of value loss caused by historical data security events to the data input nodes, data processing nodes, and data output nodes of the enterprise's core business activities, a security event impact chain model is established. The transmission loss of a single data security event in the business value stream graph is quantified through the security event impact chain model. S3. Based on the aforementioned transmission loss, and combined with the recovery time parameters of the data input nodes, data processing nodes, and data output nodes of the enterprise's core business activities, an average estimated loss calculation framework for a single data security incident is constructed. The average estimated loss calculation framework generates a loss prediction result by accumulating the direct losses and indirect related losses of the data security incident in each enterprise's core business activities. S4. Based on the average estimated loss calculation framework for a single data security incident, an input-output evaluation model for data backup strategies is established for the implementation cost and data recovery time required for different data backup strategies. The input-output evaluation model outputs the expected input-output ratio of the data backup strategy by comparing the ratio between the implementation cost of the data backup strategy and the expected loss reduction value. S5. By monitoring the latest data flow of the enterprise's core business activities in real time, dynamically update the value contribution parameter in the business value stream map, and optimize the data backup strategy using the input-output evaluation model to form a risk quantification economic model.
[0008] The present invention is further configured such that the method for forming the business value stream map in step S1 is as follows: S101. Extract multi-dimensional business feature vectors of the enterprise's core business activities from the sample library. The multi-dimensional business feature vectors include data throughput, processing time, and related business scope indicators of the data processing process. Analyze the enterprise's core business activities based on the multi-dimensional business feature vectors to generate a business activity cluster. Construct an initial business value stream graph framework based on the business activity cluster. S102. Analyze each of the business activity clusters in the initial business value stream graph framework. By calculating the topological centrality and business critical path dependency of each business activity cluster in the data processing flow, determine the positional attributes of the data input node, data processing node, and data output node, and assign preset initial value contribution parameters to the data input node, data processing node, and data output node to complete the construction of the business value stream graph.
[0009] The present invention is further configured such that: the specific content of determining the location attributes of data input nodes, data processing nodes, and data output nodes by calculating the topological centrality and business critical path dependency relationship of each of the business activity clusters in the data processing flow in step S102 is as follows: S1021. Using the business activity cluster as nodes, the data flow between the business activity clusters as connection edges, and assigning a connection weight based on a preset data traffic and transmission frequency to each connection edge, a weighted data processing network topology is formed. S1022. Based on the weighted data processing network topology, the topology centrality quantification result is generated by calculating the in-degree centrality, out-degree centrality, and betweenness centrality indices of each business activity cluster node. Simultaneously, the frequency of occurrence and dependence strength of each business activity cluster node on the critical path are analyzed by identifying the critical path of data flow in the data processing network topology, forming a business critical path dependency quantification result. Finally, the topology centrality quantification result and the business critical path dependency quantification result are merged to determine the location attribute distribution of data input nodes, data processing nodes, and data output nodes.
[0010] The present invention is further configured such that: the security protection level and the data backup frequency in the security management center are jointly determined by the average estimated loss of a single data security incident and the expected return on investment of the data backup strategy, as follows: Q1. Establish a decision matrix based on the average estimated loss of the single data security incident and the expected input-output ratio of the data backup strategy. The decision matrix uses the average estimated loss as the horizontal axis dimension parameter and the expected input-output ratio as the vertical axis dimension parameter. Divide the decision matrix plane into three decision regions: high-value protection zone, economic balance zone, and basic protection zone. And preset an initial security strategy configuration set for each decision region. Q2. Based on the coordinate position of the average estimated loss and the expected input-output ratio in the decision matrix obtained in real time, determine the target decision area, extract the protection level parameters and backup frequency parameters of the target decision area from the initial security policy configuration set, and generate a primary security resource configuration scheme. Q3. Introduce a preset real-time load coefficient and a preset data sensitivity correction factor in the core business activities of the enterprise to adjust the protection level parameter and the backup frequency parameter in the primary security resource configuration scheme, thereby forming an optimized security resource configuration scheme. Q4. The optimized security resource configuration scheme is sent to the active defense unit and the intelligent backup unit for execution. At the same time, the execution effect data of the security resource configuration scheme in the actual operating environment is recorded, and the execution effect data is fed back to the decision matrix for adaptive calibration of the boundary parameters of the decision region.
[0011] The present invention is further configured such that the specific steps in the policy mapping module for converting the security resource configuration scheme into data access rules and control rules are as follows: W1. Parse the protection level parameter and the backup frequency parameter in the security resource configuration scheme, and generate access permission classification rules based on the protection level parameter. The access permission classification rules include user authentication strength requirements, data access scope restrictions, and operation time window constraints. At the same time, generate data operation permission constraint rules based on the backup frequency parameter. The data operation permission constraint rules include data modification approval process strength, data export frequency restrictions, and data persistence protection requirements. W2. The access permission classification rules and the data operation permission constraint rules are integrated to generate a dynamic access control list and a data operation permission matrix. The dynamic access control list contains the mapping relationship between users and data resources and the corresponding access strength parameters. The data operation permission matrix contains the correspondence between data operation types and permission levels and operation audit requirements. The generated dynamic access control list and the data operation permission matrix are then sent to the dynamic permission control module.
[0012] The present invention is further configured such that the specific content of the dynamic permission control module is as follows: H1. Receive the dynamic access control list and the data operation permission matrix. By parsing the user-data resource mapping relationship and access strength parameter in the dynamic access control list, and combining the data operation type and permission level correspondence in the data operation permission matrix, establish a real-time permission status table indexed by user identity, and set a timestamp-based permission effective range and operation behavior counter for each user permission entry in the real-time permission status table. H2. Based on the permission effective range in the real-time permission status table and the operation behavior counter, perform real-time permission verification on external user requests. When it is detected that the user's operation behavior exceeds the permission level specified by the data operation permission matrix or the operation behavior counter reaches a preset threshold, automatically trigger the preset permission status update mechanism, generate new permission constraint rules in real time or revoke abnormal operation permissions, and synchronize the permission execution log to the value assessment feedback module.
[0013] The present invention is further configured such that the step of establishing the real-time permission status table in step H1 is as follows: H11. Parse the dynamic access control list and the data operation permission matrix, extract the user identity identifier, data resource identifier, access strength parameter, operation type and permission level mapping relationship, generate an initial permission entry set containing permission subject, permission object, operation permission scope and constraint conditions, and temporarily store the initial permission entry set in the preset permission entry temporary storage area. H12. Logical verification and conflict detection are performed on the initial permission entries in the permission entry temporary storage area. Based on the operation audit requirements in the data operation permission matrix, a timestamp label and an initial value of the operation behavior counter are added to each initial permission entry to generate standardized permission records. Finally, the standardized permission records that have passed the verification are organized into a real-time permission status table according to the user identity index rules.
[0014] The present invention is further configured such that: the specific content of the value assessment feedback module is as follows: by collecting the permission execution log of the dynamic permission control module, extracting user operation behavior data and system resource access records therein, and combining them with the data flow of the enterprise's core business activities monitored in real time, generating a data flow efficiency quantification index and a security risk assessment index; calculating the change rate of business processing timeliness before and after permission adjustment based on the data flow efficiency quantification index, and simultaneously statistically analyzing the frequency and impact range of security incidents according to the security risk assessment index; performing correlation analysis between the change rate of business processing timeliness and the frequency and impact range of data security incidents to form an execution effect data report; and feeding the execution effect data report back to the economic indicator analysis engine.
[0015] The beneficial effects of this invention are as follows: 1. This invention uses an economic indicator analysis engine to quantify in real time the average estimated loss of a single data security incident and the expected input-output ratio of data backup strategies, so that the configuration decisions of security protection level and backup frequency are based on economic value analysis. This fundamentally avoids the short-sighted behavior of enterprises simplifying security measures to control costs, and ensures that critical business data obtains protection resources that match its value. 2. This invention continuously collects business data flow efficiency and security event data after permission adjustments through a value assessment feedback module, generates an execution effect data report, and feeds it back to the economic indicator analysis engine. This achieves closed-loop optimization of security strategies and economic models, significantly improving the system's adaptive protection capabilities against risks such as data leakage and business interruption. Attached Figure Description
[0016] Figure 1 This is a system flowchart of the present invention; Figure 2 This is a flowchart illustrating the method for constructing the risk quantification economic model of the present invention. Figure 3 This is a flowchart illustrating the specific content of the dynamic permission control module of the present invention. Detailed Implementation
[0017] The preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, so that the advantages and features of the present invention can be more easily understood by those skilled in the art, thereby providing a clearer and more explicit definition of the scope of protection of the present invention.
[0018] Please see Figures 1-3 A digital management system for enterprises based on an economic model, comprising an economic indicator analysis engine, a security management center, a strategy mapping module, a dynamic access control module, and a value assessment feedback module; An economic indicator analysis engine is used to calculate and output key economic indicators of a company’s core business activities in real time. The security management center receives key economic indicators and generates security resource allocation plans accordingly. The security management center has built-in active defense units and intelligent backup units. The security resource allocation plan includes the security protection level set by the active defense unit and the data backup frequency set by the intelligent backup unit. The policy mapping module is used to transform security resource configuration schemes into data access rules and control rules. The dynamic access control module manages user access permissions to the company's core business activities based on data access rules and control rules, and performs real-time generation or revocation of access permissions. The value assessment feedback module is used to continuously collect data on the efficiency of business data flow and the occurrence of data security incidents in the core business activities of the enterprise after the permission adjustment, as execution effect data, and feed the execution effect data back to the economic indicator analysis engine to optimize the calculation of key economic indicators in the next round.
[0019] The beneficial effects of this system are that it accurately links security measures with economic value through an economic indicator analysis engine, transforming security investment from a cost center into a quantifiable investment; the security management center dynamically adjusts protection levels and backup frequencies accordingly; the policy mapping module transforms these into executable rules; the dynamic access control module enables real-time access control; and the value assessment feedback module forms a closed loop from decision-making to optimization, ultimately improving operational efficiency, reducing security risks, and maximizing the benefits of security resource allocation.
[0020] One embodiment of the present invention is as follows: the key economic indicators in the economic indicator analysis engine include the average estimated loss of a single data security incident and the expected input-output ratio of the data backup strategy; The economic indicator analysis engine is specifically a risk-quantifying economic model built on historical data security incidents and losses from disruptions to core business activities of enterprises; The method for constructing a risk quantification economic model is as follows: S1. Establish a sample library of historical data security incidents of core business activities of enterprises. By extracting features from the data processing flow of various core business activities of enterprises in the sample library, a business value flow map is formed. The business value flow map includes the value contribution parameters of data input nodes, data processing nodes and data output nodes of core business activities of enterprises. S2. Based on the value contribution parameter, historical data security events are mapped to the data input nodes, data processing nodes, and data output nodes of the enterprise's core business activities. By analyzing the degree of value loss caused by historical data security events to the data input nodes, data processing nodes, and data output nodes of the enterprise's core business activities, a security event impact chain model is established. The transmission loss of a single data security event in the business value stream graph is quantified through the security event impact chain model. The steps for establishing a security incident impact chain model are as follows: Based on the value contribution parameters in the business value stream graph, historical data security incidents are mapped to corresponding data input nodes, data processing nodes, and data output nodes. By analyzing the degree of value loss of each node affected by the data security incident, an event impact sequence with nodes as units is constructed. According to the data dependencies between nodes in the event impact sequence, the transmission path of the data security incident in the business value stream is identified, forming a complete security incident impact chain model. The security incident impact chain model can describe the cascading impact process of a security incident from the initial node to the final node. The steps for generating transmission loss are as follows: Using the security event impact chain model, extract the value loss data for each affected node. Combine this with the topological position of the nodes in the business value flow graph to calculate the loss transmission coefficient between adjacent nodes (the formula for calculating the loss transmission coefficient is: Loss transmission coefficient = Upstream node value loss / Downstream node value contribution × Dependence strength between nodes, where the upstream node value loss comes from the node value loss data in the security event impact chain model, the downstream node value contribution comes from the value contribution parameter in the business value flow graph, and the dependency strength between nodes is based on the dependency strength parameter in the quantification result of the business critical path dependency relationship). By accumulating the product of the loss transmission coefficient and the node value loss data, quantify the total transmission loss of the data security event in the entire impact chain, and use this transmission loss as a quantitative indicator to assess the overall impact of the event. S3. Based on the transmission loss, and combined with the recovery time parameters of the data input nodes, data processing nodes and data output nodes of the enterprise's core business activities, construct an average estimated loss calculation framework for a single data security incident. The average estimated loss calculation framework generates a loss prediction result by accumulating the direct losses and indirect related losses of the data security incident in each enterprise's core business activities. The construction steps of the average estimated loss calculation framework for a single data security incident are as follows: Based on the transmission loss data, the recovery time parameters of each node in the core business activities of the enterprise are introduced to establish the correlation function between node loss and recovery time; based on the correlation function, the transmission loss is decomposed into direct node loss and indirect related loss caused by recovery delay, and a hierarchical calculation framework is constructed. The hierarchical calculation framework integrates the calculation logic of direct loss and indirect related loss to form the average estimated loss calculation model for a single data security incident. The steps for generating the loss prediction result are as follows: Apply the average estimated loss calculation framework for a single data security incident, input the impact data of the data security incident collected in real time and the node recovery time parameters, and accumulate the direct loss and indirect associated loss of each node layer by layer through the hierarchical calculation logic within the average estimated loss calculation framework; normalize the accumulated result with historical benchmark loss data to generate a standardized loss prediction result, which is used to quantify the potential impact of a single data security incident on the economic value of the enterprise. S4. Based on the average estimated loss calculation framework for a single data security incident, an input-output evaluation model for data backup strategies is established to address the implementation costs and data recovery time required for different data backup strategies. The input-output evaluation model outputs the expected input-output ratio of the data backup strategy by comparing the ratio between the implementation cost of the data backup strategy and the expected loss reduction value. The steps for establishing the input-output evaluation model for data backup strategies are as follows: Based on the average estimated loss calculation framework for a single data security incident, extract the implementation cost parameters and data recovery time parameters corresponding to different data backup strategies, and construct a mapping relationship; By comparing the implementation cost parameters with the expected reduction in loss after the application of the data backup strategy, establish the cost-benefit ratio calculation logic, and form an input-output evaluation model. The input-output evaluation model can output the relative benefit index of different data backup strategies. The steps for outputting the expected input-output ratio are as follows: Using the input-output evaluation model, input the implementation cost parameters of the current data backup strategy and historical loss reduction value samples. Through the cost-benefit ratio calculation logic within the input-output evaluation model, generate the initial input-output ratio of the data backup strategy. Introduce real-time business environment variables to dynamically correct the initial input-output ratio: calculate the dynamic correction factor based on the real-time business environment variables; perform weighted fusion processing on the dynamic correction factor and the initial input-output ratio; output the calibrated expected input-output ratio after weighted fusion processing, and use the expected input-output ratio as the decision-making basis for the security management center to optimize the backup strategy. The specific value of the real-time business environment variable is the weighted product of the abnormal fluctuation rate of the business data flow efficiency collected by the value assessment feedback module and the sensitivity parameter in the data operation permission constraint rules generated by the strategy mapping module. The formula for calculating the dynamic correction factor is: Environmental correction factor = Abnormal fluctuation rate of business data flow efficiency × Sensitivity parameter in data operation permission constraint rules.
[0021] Among them, the abnormal fluctuation rate of business data flow efficiency comes from the quantitative fluctuation value of "business data flow efficiency" collected by the value assessment feedback module, and the sensitivity parameter in the data operation permission constraint rules comes from the sensitivity measurement implicit in the "data operation permission constraint rules" generated by the strategy mapping module.
[0022] S5. By monitoring the latest data flow of the enterprise's core business activities in real time, dynamically update the value contribution parameters in the business value stream map, and optimize the data backup strategy using the input-output evaluation model to form a risk quantification economic model.
[0023] The beneficial effects of steps S1-S5 are that the economic impact of security incidents is quantified through the economic indicator analysis engine, key economic indicators are dynamically generated based on the risk quantification economic model, and security strategies can be automatically adjusted according to real-time economic data; the transmission loss is accurately assessed through the security incident impact chain model, and the backup plan is optimized by combining the input-output evaluation model of the data backup strategy, so as to maximize the cost-effectiveness of security resource allocation; the value assessment feedback module forms a closed-loop optimization mechanism to continuously improve the system's security protection efficiency and business continuity.
[0024] Specifically, the method for forming the business value stream map in step S1 is as follows: S101. Extract multi-dimensional business feature vectors of core business activities from the sample library. The multi-dimensional business feature vectors include data throughput, processing time, and related business scope indicators of the data processing process. Analyze the core business activities of the enterprise based on the multi-dimensional business feature vectors to generate business activity clusters. Construct an initial business value stream graph framework based on the business activity clusters. S102. Perform node importance analysis on each business activity cluster in the initial business value stream graph framework. By calculating the topological centrality and business critical path dependency of each business activity cluster in the data processing flow, determine the location attributes of data input nodes, data processing nodes, and data output nodes, and assign preset initial value contribution parameters to data input nodes, data processing nodes, and data output nodes to complete the construction of the business value stream graph.
[0025] Preset initial value contribution parameter: The specific value range of the preset initial value contribution parameter is based on the historical performance data and business criticality assessment of the business activity cluster in the data processing flow. Through normalization processing, the value contribution parameter is limited to a continuous range of 0 to 1, where 0 represents the minimum value contribution and 1 represents the maximum value contribution. The value range is dynamically adjusted according to the topological centrality and critical path dependency of the business activity cluster to ensure that the parameter matches the actual business value. Specifically, the details of determining the location attributes of data input nodes, data processing nodes, and data output nodes by calculating the topological centrality and critical path dependency of each business activity cluster in the data processing flow in step S102 are as follows: S1021. Using business activity clusters as nodes and data flow between business activity clusters as connection edges, and assigning connection weights to each connection edge based on preset data traffic and transmission frequency, a weighted data processing network topology is formed. Preset connection weights for data traffic and transmission frequency: The preset connection weights for data traffic and transmission frequency are based on historical data flow monitoring results and the interaction frequency between business activity clusters. By quantifying the size of data traffic and the speed of transmission frequency, the connection weights are set to a scale value between 0.1 and 10. The data traffic is based on the number of data packets processed per second, and the transmission frequency is based on the number of transmissions per second. The final connection weight is calculated by weighted average to reflect the intensity of data interaction between business activity clusters. S1022. Based on the weighted data processing network topology, the topology centrality quantification result is generated by calculating the in-degree centrality, out-degree centrality, and betweenness centrality indices of each business activity cluster node. Simultaneously, by identifying the critical paths of data flow in the data processing network topology, the frequency of occurrence and dependence strength of each business activity cluster node on the critical path are analyzed to form the business critical path dependency quantification result. Finally, the topology centrality quantification result and the business critical path dependency quantification result are integrated to determine the location attribute distribution of data input nodes, data processing nodes, and data output nodes.
[0026] The in-degree centrality, out-degree centrality, and betweenness centrality indices of business activity cluster nodes are calculated as follows: the in-degree centrality index of a business activity cluster node is determined by calculating the ratio of the number of connected edges pointing to that node to the total number of connected edges; the out-degree centrality index is determined by calculating the ratio of the number of connected edges from that node to other nodes to the total number of connected edges; and the betweenness centrality index is determined by calculating the ratio of the frequency of that node appearing in all shortest paths to the total number of shortest paths. This generates standardized centrality indices for topology centrality measurement. The steps for analyzing the frequency of occurrence and dependency strength of each business activity cluster node on the critical path are as follows: The frequency of occurrence of each business activity cluster node on the critical path is calculated by statistically analyzing the ratio of the number of times the node appears in the critical path set to the total number of nodes on the critical path. The dependency strength is obtained by weighting the data traffic and transmission frequency between the node and other nodes on the critical path. Finally, quantitative values of occurrence frequency and dependency strength are formed to generate the quantitative results of business critical path dependency relationship.
[0027] This method constructs an accurate business value stream map by extracting multi-dimensional business features and analyzing business activity clusters. It uses topological centrality and critical path dependency calculations to ensure the accurate determination of data node location attributes and the dynamic adjustment of value contribution parameters, thereby improving the system's ability to quantitatively evaluate business value and the efficiency of resource allocation.
[0028] One embodiment of the present invention is as follows: the security protection level and data backup frequency in the security management center are jointly determined by the average estimated loss of a single data security incident and the expected return on investment of the data backup strategy, as follows: Q1. Establish a decision matrix based on the average estimated loss of a single data security incident and the expected input-output ratio of data backup strategies. The decision matrix uses the average estimated loss as the horizontal axis dimension parameter and the expected input-output ratio as the vertical axis dimension parameter. Divide the decision matrix plane into three decision regions: high-value protection zone, economic balance zone, and basic protection zone. Preset an initial security strategy configuration set for each decision region. Preset initial security policy configuration set: Based on the security requirement characteristics of the three decision areas—high-value protection zone, economic balance zone, and basic protection zone—corresponding protection level parameter value range and backup frequency parameter baseline value are configured for each decision area, forming an initial security policy configuration set containing multiple sets of security policy parameters. This initial security policy configuration set serves as the basic template for generating a primary security resource configuration scheme. Q2. Based on the coordinates of the average estimated loss and expected input-output ratio obtained in real time in the decision matrix, determine the target decision area, extract the protection level parameters and backup frequency parameters of the target decision area from the initial security policy configuration set, and generate a primary security resource configuration scheme. Q3. Introduce a preset real-time load factor and a preset data sensitivity correction factor in the core business activities of the enterprise to adjust the protection level parameters and backup frequency parameters in the primary security resource configuration scheme. The real-time load factor is used to adjust the security protection level to avoid system performance overload, and the data sensitivity correction factor is used to adjust the data backup frequency to ensure compliance requirements, thus forming an optimized security resource configuration scheme. Preset real-time load factor and preset data sensitivity correction factor: The preset real-time load factor is dynamically calculated by monitoring the system resource utilization rate of the enterprise's core business activities and is used to flexibly adjust the protection level parameters in the primary security resource configuration scheme; the preset data sensitivity correction factor is generated based on the sensitivity parameters in the data operation permission constraint rules and historical compliance requirements, and is used to calibrate the backup frequency parameters for compliance, ultimately forming a combination of real-time load factor and data sensitivity correction factor that can adapt to the actual business environment; Q4. The optimized security resource configuration scheme is delivered to the active defense unit and intelligent backup unit for execution. At the same time, the execution effect data of the security resource configuration scheme in the actual operating environment is recorded, and the execution effect data is fed back to the decision matrix for adaptive calibration of the boundary parameters of the decision area, thus completing the closed-loop optimization of the security policy.
[0029] Specifically, the "execution effect data" in step Q3 and the "execution effect data" in the value assessment feedback module refer to the same data, only mentioned in different places. In step Q3, the "execution effect data" is the object that is "recorded"; in the value assessment feedback module, the "execution effect data" is the object that is "produced". The business data flow efficiency and security event occurrence continuously collected by the value assessment feedback module are collectively referred to as execution effect data. This execution effect data is fed back to the economic indicator analysis engine for model optimization, and is also recorded and referenced by the security management center for adaptive calibration of its internal decision matrix.
[0030] The beneficial effect of this embodiment is that it realizes intelligent partition management of security policies through decision matrix, dynamically optimizes resource allocation by using real-time load coefficient and data sensitivity correction factor, and forms a closed-loop self-adjustment mechanism from policy generation to execution feedback, which significantly improves the accuracy of system protection and resource utilization efficiency.
[0031] One embodiment of the present invention is as follows: the specific steps in the policy mapping module for converting security resource configuration schemes into data access rules and control rules are as follows: W1. Analyze the protection level parameters and backup frequency parameters in the security resource configuration scheme, and generate access permission classification rules based on the protection level parameters. The access permission classification rules include user authentication strength requirements, data access scope restrictions, and operation time window constraints. At the same time, generate data operation permission constraint rules based on the backup frequency parameters. The data operation permission constraint rules include the strength of the data modification approval process, data export frequency restrictions, and data persistence protection requirements. W2. The access permission level rules and data operation permission constraint rules are integrated to generate a (system-executable) dynamic access control list and data operation permission matrix. The dynamic access control list contains the mapping relationship between users and data resources and the corresponding access strength parameters. The data operation permission matrix contains the correspondence between data operation types and permission levels and operation audit requirements. The generated dynamic access control list and data operation permission matrix are then sent to the dynamic permission control module (to perform real-time permission management).
[0032] Preferably, based on the three constraint dimensions of data modification approval process intensity, data export frequency limit, and data persistence protection requirements in the data operation permission constraint rules, the intensity quantification value of each dimension is extracted as the initial sensitivity benchmark parameter; then, the initial sensitivity benchmark parameters of the three dimensions are weighted and fused to generate a comprehensive sensitivity index; finally, the comprehensive sensitivity index is dynamically corrected according to the correspondence between the permission level in the data operation permission matrix, and the sensitivity parameter of the data operation permission constraint rules is output.
[0033] The beneficial effects of this embodiment are that the policy mapping module transforms the abstract security resource configuration scheme into executable data access rules and control rules, realizing the precise conversion from security policy to access control; the generated dynamic access control list and data operation permission matrix provide the system with fine-grained access control capabilities, and combined with the dynamic correction mechanism of sensitivity parameters, significantly improves the adaptability and accuracy of access control, ultimately enhancing the real-time performance and effectiveness of the overall system security protection.
[0034] One embodiment of the present invention is as follows: The specific contents of the dynamic permission control module are as follows: H1. Receive the dynamic access control list and data operation permission matrix. By parsing the user-data resource mapping relationship and access strength parameters in the dynamic access control list, and combining the data operation type and permission level correspondence in the data operation permission matrix, establish a real-time permission status table indexed by user identity, and set a timestamp-based permission effective range and operation behavior counter for each user permission entry in the real-time permission status table. Preferably, the steps for establishing the real-time permission status table in step H1 are as follows: H11. Parse the dynamic access control list and data operation permission matrix, extract the user identity identifier, data resource identifier, access strength parameter, operation type and permission level mapping relationship, generate an initial permission entry set containing permission subject, permission object, operation permission scope and constraints, and temporarily store the initial permission entry set in the preset permission entry temporary storage area. H12. Logical verification and conflict detection are performed on the initial permission entries in the permission entry temporary storage area. Based on the operation audit requirements in the data operation permission matrix, a timestamp tag and the initial value of the operation behavior counter are added to each initial permission entry to generate standardized permission records with temporal attributes and behavior monitoring capabilities. Finally, the standardized permission records that have passed the verification are organized into a real-time permission status table according to the user identity index rules. H2. Based on the permission effective range and operation behavior counter in the real-time permission status table, perform real-time permission verification on external user requests. When it is detected that the user's operation behavior exceeds the permission level specified by the data operation permission matrix or the operation behavior counter reaches the preset threshold, the preset permission status update mechanism is automatically triggered to generate new permission constraint rules or revoke abnormal operation permissions in real time, and the permission execution log is synchronized to the value assessment feedback module to generate execution effect data.
[0035] Preferably, the specific content of the preset permission status update mechanism in step H2 is as follows: when the operation behavior counter reaches a preset threshold or when the user's operation behavior is detected to exceed the permission level, a preset permission anomaly detection trigger is immediately triggered. The permission anomaly detection trigger generates a real-time threat assessment level based on the type and risk level of the abnormal operation behavior, and starts the corresponding permission adjustment response strategy based on the real-time threat assessment level. The permission adjustment response strategy includes three handling methods: immediately revoking the current operation permission, temporarily freezing the user account access function, and generating new permission constraint rules. The system updates the permission effective range and operation behavior counter parameters in the real-time permission status table in real time according to the execution result of the permission adjustment response strategy, and synchronously sends all operation logs of this permission status update event to the value assessment feedback module for generating execution effect data.
[0036] The beneficial effect of this embodiment is that it realizes dynamic permission control through a real-time permission status table, performs accurate permission verification by combining the permission effective range and operation behavior counter, and automatically triggers the permission status update mechanism to adjust the permission rules in real time when abnormal operation is detected, forming a closed-loop permission management cycle, which effectively improves the real-time performance and adaptability of system security protection.
[0037] One embodiment of the present invention is as follows: The specific content of the value assessment feedback module is as follows: By collecting the permission execution logs of the dynamic permission control module, user operation behavior data and system resource access records are extracted, and combined with the data flow of the enterprise's core business activities monitored in real time, a data flow efficiency quantification index and a security risk assessment index are generated; based on the data flow efficiency quantification index, the change rate of business processing timeliness before and after permission adjustment is calculated, and at the same time, the frequency and impact range of security incidents are statistically analyzed according to the security risk assessment index; the change rate of business processing timeliness is correlated with the frequency and impact range of data security incidents to form a comprehensive execution effect data report; and the execution effect data report is fed back to the economic indicator analysis engine to optimize the value contribution parameter and security incident impact chain model in the risk quantification economic model.
[0038] The beneficial effect of this embodiment is that the value assessment feedback module generates data flow efficiency and security risk assessment indicators by collecting permission execution logs and real-time business data, and calculates the change rate of business processing timeliness and security event statistics. Through correlation analysis, it forms an execution effect data report and feeds it back to the economic indicator analysis engine, thereby realizing the continuous optimization of the value contribution parameter and the security event impact chain model in the risk quantification economic model, and improving the system's adaptability and decision accuracy.
[0039] The above description is merely an embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. A digital management system for an economic model enterprise, characterized in that: It includes an economic indicator analysis engine, a security management center, a policy mapping module, a dynamic access control module, and a value assessment feedback module; An economic indicator analysis engine is used to calculate and output key economic indicators of a company’s core business activities in real time. The security management center receives the key economic indicators and generates a security resource allocation plan accordingly. The security management center has a built-in active defense unit and an intelligent backup unit. The security resource configuration scheme includes the security protection level set by the active defense unit and the data backup frequency set by the intelligent backup unit. The policy mapping module is used to convert the security resource configuration scheme into data access rules and control rules; The dynamic access control module manages user access permissions to the enterprise's core business activities based on the data access rules and the control rules, and performs real-time generation or revocation of the access permissions. The value assessment feedback module is used to continuously collect the efficiency of business data flow and the occurrence of data security incidents in the core business activities of the enterprise after the permission adjustment as execution effect data, and feed the execution effect data back to the economic indicator analysis engine.
2. The enterprise digital management system for an economic model according to claim 1, characterized in that: The key economic indicators in the economic indicator analysis engine include the average estimated loss of a single data security incident and the expected return on investment of the data backup strategy. The economic indicator analysis engine is specifically a risk quantification economic model built on historical data security incidents and losses from interruptions in core business activities of enterprises. The method for constructing the risk quantification economic model is as follows: S1. Establish a sample library of historical data security events of core business activities of enterprises. By extracting features from the data processing flow of various core business activities of enterprises in the sample library, a business value flow map is formed. The business value flow map includes the value contribution parameters of data input nodes, data processing nodes and data output nodes of core business activities of enterprises. S2. Based on the value contribution parameter, historical data security events are mapped to the data input nodes, data processing nodes, and data output nodes of the enterprise's core business activities. By analyzing the degree of value loss caused by historical data security events to the data input nodes, data processing nodes, and data output nodes of the enterprise's core business activities, a security event impact chain model is established. The transmission loss of a single data security event in the business value stream graph is quantified through the security event impact chain model. S3. Based on the aforementioned transmission loss, and combined with the recovery time parameters of the data input nodes, data processing nodes, and data output nodes of the enterprise's core business activities, an average estimated loss calculation framework for a single data security incident is constructed. The average estimated loss calculation framework generates a loss prediction result by accumulating the direct losses and indirect related losses of the data security incident in each enterprise's core business activities. S4. Based on the average estimated loss calculation framework for a single data security incident, an input-output evaluation model for data backup strategies is established for the implementation cost and data recovery time required for different data backup strategies. The input-output evaluation model outputs the expected input-output ratio of the data backup strategy by comparing the ratio between the implementation cost of the data backup strategy and the expected loss reduction value. S5. By monitoring the latest data flow of the enterprise's core business activities in real time, dynamically update the value contribution parameter in the business value stream map, and optimize the data backup strategy using the input-output evaluation model to form a risk quantification economic model.
3. The enterprise digital management system for an economic model according to claim 2, characterized in that: The method for forming the business value stream map in step S1 is as follows: S101. Extract multi-dimensional business feature vectors of the enterprise's core business activities from the sample library. The multi-dimensional business feature vectors include data throughput, processing time, and related business scope indicators of the data processing process. Analyze the enterprise's core business activities based on the multi-dimensional business feature vectors to generate a business activity cluster. Construct an initial business value stream graph framework based on the business activity cluster. S102. Analyze each of the business activity clusters in the initial business value stream graph framework. By calculating the topological centrality and business critical path dependency of each business activity cluster in the data processing flow, determine the positional attributes of the data input node, data processing node, and data output node, and assign preset initial value contribution parameters to the data input node, data processing node, and data output node to complete the construction of the business value stream graph.
4. The enterprise digital management system for an economic model according to claim 3, characterized in that: The specific content of determining the location attributes of data input nodes, data processing nodes, and data output nodes by calculating the topological centrality and critical path dependency of each business activity cluster in the data processing flow in step S102 is as follows: S1021. Using the business activity cluster as nodes, the data flow between the business activity clusters as connection edges, and assigning a connection weight based on a preset data traffic and transmission frequency to each connection edge, a weighted data processing network topology is formed. S1022. Based on the weighted data processing network topology, the topology centrality quantification result is generated by calculating the in-degree centrality, out-degree centrality, and betweenness centrality indices of each business activity cluster node. Simultaneously, the frequency of occurrence and dependence strength of each business activity cluster node on the critical path are analyzed by identifying the critical path of data flow in the data processing network topology, forming a business critical path dependency quantification result. Finally, the topology centrality quantification result and the business critical path dependency quantification result are merged to determine the location attribute distribution of data input nodes, data processing nodes, and data output nodes.
5. The enterprise digital management system for an economic model according to claim 4, characterized in that: The security protection level and data backup frequency in the security management center are jointly determined by the average estimated loss of a single data security incident and the expected return on investment of the data backup strategy, as follows: Q1. Establish a decision matrix based on the average estimated loss of the single data security incident and the expected input-output ratio of the data backup strategy. The decision matrix uses the average estimated loss as the horizontal axis dimension parameter and the expected input-output ratio as the vertical axis dimension parameter. Divide the decision matrix plane into three decision regions: high-value protection zone, economic balance zone, and basic protection zone. And preset an initial security strategy configuration set for each decision region. Q2. Based on the coordinate position of the average estimated loss and the expected input-output ratio in the decision matrix obtained in real time, determine the target decision area, extract the protection level parameters and backup frequency parameters of the target decision area from the initial security policy configuration set, and generate a primary security resource configuration scheme. Q3. Introduce a preset real-time load coefficient and a preset data sensitivity correction factor in the core business activities of the enterprise to adjust the protection level parameter and the backup frequency parameter in the primary security resource configuration scheme, thereby forming an optimized security resource configuration scheme. Q4. The optimized security resource configuration scheme is sent to the active defense unit and the intelligent backup unit for execution. At the same time, the execution effect data of the security resource configuration scheme in the actual operating environment is recorded, and the execution effect data is fed back to the decision matrix for adaptive calibration of the boundary parameters of the decision region.
6. The enterprise digital management system for an economic model according to claim 5, characterized in that: The specific steps in the policy mapping module to convert the security resource configuration scheme into data access rules and control rules are as follows: W1. Parse the protection level parameter and the backup frequency parameter in the security resource configuration scheme, and generate access permission classification rules based on the protection level parameter. The access permission classification rules include user authentication strength requirements, data access scope restrictions, and operation time window constraints. At the same time, generate data operation permission constraint rules based on the backup frequency parameter. The data operation permission constraint rules include data modification approval process strength, data export frequency restrictions, and data persistence protection requirements. W2. The access permission classification rules and the data operation permission constraint rules are integrated to generate a dynamic access control list and a data operation permission matrix. The dynamic access control list contains the mapping relationship between users and data resources and the corresponding access strength parameters. The data operation permission matrix contains the correspondence between data operation types and permission levels and operation audit requirements. The generated dynamic access control list and the data operation permission matrix are then sent to the dynamic permission control module.
7. The enterprise digital management system for an economic model according to claim 6, characterized in that: The specific contents of the dynamic permission control module are as follows: H1. Receive the dynamic access control list and the data operation permission matrix. By parsing the user-data resource mapping relationship and access strength parameter in the dynamic access control list, and combining the data operation type and permission level correspondence in the data operation permission matrix, establish a real-time permission status table indexed by user identity, and set a timestamp-based permission effective range and operation behavior counter for each user permission entry in the real-time permission status table. H2. Based on the permission effective range in the real-time permission status table and the operation behavior counter, perform real-time permission verification on external user requests. When it is detected that the user's operation behavior exceeds the permission level specified by the data operation permission matrix or the operation behavior counter reaches a preset threshold, automatically trigger the preset permission status update mechanism, generate new permission constraint rules in real time or revoke abnormal operation permissions, and synchronize the permission execution log to the value assessment feedback module.
8. The enterprise digital management system for an economic model according to claim 7, characterized in that: The steps for establishing the real-time permission status table in step H1 are as follows: H11. Parse the dynamic access control list and the data operation permission matrix, extract the user identity identifier, data resource identifier, access strength parameter, operation type and permission level mapping relationship, generate an initial permission entry set containing permission subject, permission object, operation permission scope and constraint conditions, and temporarily store the initial permission entry set in the preset permission entry temporary storage area. H12. Logical verification and conflict detection are performed on the initial permission entries in the permission entry temporary storage area. Based on the operation audit requirements in the data operation permission matrix, a timestamp label and an initial value of the operation behavior counter are added to each initial permission entry to generate standardized permission records. Finally, the standardized permission records that have passed the verification are organized into a real-time permission status table according to the user identity index rules.
9. The enterprise digital management system for an economic model according to claim 8, characterized in that: The specific content of the value assessment feedback module is as follows: by collecting the permission execution log of the dynamic permission control module, extracting user operation behavior data and system resource access records, and combining them with the data flow of the enterprise's core business activities monitored in real time, a quantitative indicator of data flow efficiency and a security risk assessment indicator are generated. Based on the data flow efficiency quantification index, calculate the change rate of business processing time before and after permission adjustment, and at the same time, based on the security risk assessment index, calculate the frequency and scope of security incidents; perform correlation analysis between the change rate of business processing time and the frequency and scope of data security incidents to form an execution effect data report. The execution effect data report is then fed back to the economic indicator analysis engine.