A method for securing pharmaceutical sales data

By analyzing the generation process and transmission architecture of pharmaceutical sales data, a targeted protection sequence is constructed, and the encryption strategy is dynamically adjusted. This solves the problem of the lack of targeted protection strategies in existing technologies and achieves efficient security protection and resource optimization.

CN121682897BActive Publication Date: 2026-04-28HUNAN SPACE FOLDING INTERNET TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUNAN SPACE FOLDING INTERNET TECH CO LTD
Filing Date
2026-02-06
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing methods for protecting pharmaceutical sales data security do not fully consider the differences in the generation process of different types of sales data and the changes in the dynamic transmission environment, resulting in a lack of targeted protection strategies. Some high-risk data is not adequately protected, while low-risk data is overprotected, leading to a waste of resources.

Method used

By acquiring the event set and dynamic transmission architecture of pharmaceutical sales data, analyzing global and local event factors, constructing targeted protection sequences, matching and scientifically integrating appropriate encryption algorithms, and dynamically adjusting security protection strategies.

Benefits of technology

It achieves strong protection for high-risk data and resource conservation for low-risk data, while also possessing camouflage protection capabilities, thereby improving the security level and anti-attack ability of pharmaceutical sales data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121682897B_ABST
    Figure CN121682897B_ABST
Patent Text Reader

Abstract

The application provides a security protection method for medical sales data, and belongs to the technical field of data security protection. The method comprises the following steps: obtaining a generation process event set of medical sales data, a dynamic transmission architecture and a historical security baseline; analyzing the event set to divide global and local event factors, determining a real protection level and other components to form a first protection sequence; matching and adapting an encryption algorithm based on the performance of a service port; constructing a second protection sequence through the overlapping proportion with the historical baseline; and integrating the two sequences and the encryption algorithm to complete security protection. The method realizes dynamic adaptation of protection strategies and data characteristics and transmission environment, takes into account the protection strength of high-risk data and the resource utilization rate of low-risk data, and improves the data security protection level and attack resistance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security protection technology, and in particular to a method for protecting pharmaceutical sales data. Background Technology

[0002] Pharmaceutical sales data, as core and sensitive data in the pharmaceutical industry, encompasses key information such as drug distribution volume, sales prices, channel information, and customer information. Its security is directly related to the protection of corporate trade secrets, the stability of market order, and the privacy of patients. With the accelerated digital transformation of the pharmaceutical industry, the scale of sales data generation, transmission, and storage continues to expand, and the number of data flow links increases, leading to increasingly prominent security risks, such as frequent data theft, tampering, and leakage.

[0003] Existing methods for protecting pharmaceutical sales data security mostly employ fixed encryption algorithms or uniform protection strategies, failing to fully consider the differences in the generation process of different types of sales data and the changes in the dynamic transmission environment. This results in a lack of targeted protection strategies, insufficient protection of some high-risk data, and excessive protection of low-risk data, leading to a waste of resources.

[0004] To address the aforementioned technical problems, this invention provides a method for the secure protection of pharmaceutical sales data. Summary of the Invention

[0005] This invention provides a method for the security protection of pharmaceutical sales data, in order to solve the aforementioned technical problems.

[0006] This invention provides a method for the security protection of pharmaceutical sales data, comprising:

[0007] Step 1: Obtain the event set of the generation process for each type of sales data in the newly generated pharmaceutical sales data and the dynamic transmission architecture for each generation process event. At the same time, obtain the historical security baseline for each type of sales data. The historical security baseline includes the historical reference security level range composed of security parameter groups for each historical collection time. The dynamic transmission architecture is based on multiple service ports involved in the corresponding generation process event.

[0008] Step 2: Analyze the event set of the data generation process for each sales type, determine the global event factor group and the local event factor group, and determine the true protection level, the protection level after adding interference, and the range of disguise level for the corresponding sales type data to form the first protection sequence;

[0009] Step 3: Based on the performance changes of the dynamic verification set consisting of all service ports involved in the dynamic transmission architecture, determine the adaptability index of each service port and perform functional perturbation transformation analysis to obtain the adaptability feedback vector, so as to match several encryption algorithms that match the adaptability feedback vector from the security protection pool.

[0010] Step 4: Obtain the overlap ratio between the actual protection level, the protection level after adding interference, and the spoofing level range of the corresponding sales type data and the historical security baseline of the same type, and form the second protection sequence;

[0011] Step 5: Integrate the first protection sequence, the second protection sequence, and several encryption algorithms under the corresponding sales type data, and perform security protection processing on the corresponding sales type data.

[0012] Preferably, the analysis includes the event set of the data generation process for each sales type, including:

[0013] Obtain the first purpose before the generation process event and the second purpose after the generation process event, and analyze the dual-change timeline of the first purpose and the second purpose throughout the entire generation process event, wherein the first purpose and the second purpose are the same or different.

[0014] Based on the first time point of the non-zero change in the dual-change timeline and the combination of factors that cause the non-zero change at the corresponding first time point, and based on the first maximum continuous value of the continuous non-zero change and the second maximum continuous value of the zero change in the dual-change timeline, the main factors are calibrated for each time point in the dual-change timeline to obtain the initial calibration line for the corresponding process event.

[0015] Time alignment is performed on the initial calibration lines of all generation process events in the generation process event set of the corresponding sales type data to determine the global event factor group and the local event factor group.

[0016] Preferably, determining the global event factor group and the local event factor group includes:

[0017] Obtain the initial calibration line between the i-th and j-th generation process events in the generation process event set, construct an event-factor bipartite graph, and calculate the correlation strength weight between every two factor nodes in the bipartite graph;

[0018] Based on the association strength weight, community discovery is performed on all factor nodes to divide them into K factor communities, and the original calibration time points corresponding to each factor node contained in each factor community are extracted to form a time point set for the corresponding community.

[0019] For each factor community's time point set, multi-scale sliding window density clustering is performed. In the first scale window, high-density time point clusters are identified as anchor points for the core business stages of the corresponding community. In the second scale window, micro-density fluctuation points are identified in the neighborhood of each core business stage anchor point as local perturbation markers.

[0020] For any event that generates a process, the corresponding initial calibration line is mapped to each factor community. Based on whether the factor calibration falls into the core business stage anchor point or local disturbance mark of the corresponding community, a multi-community alignment feature vector for the event that generates a process is generated.

[0021] Cluster analysis is performed based on the multi-community aligned feature vectors of all events. Common event factors that always appear at the core business stage anchor points of all factor communities and have stable features are grouped into the global event factor group. Event-specific factors that only appear in local disturbance markers in specific factor communities or only appear at the core business stage anchor points of some events are grouped into the local event factor group.

[0022] Preferably, the association strength weight is determined based on the number of event nodes jointly connected by the two factor nodes and the temporal proximity of the time points corresponding to the edges connecting these event nodes in their respective dual-variable timelines.

[0023] Preferably, the first protection sequence is formed by determining the true protection level, the protection level after adding interference, and the range of disguise levels for the corresponding sales type data, including:

[0024] Calculate the composite weight value of the global event factor group :

[0025] ,in, The attenuation coefficient; Current time and global event factors Normalized time difference of most recent active time; Global event factor The inherent risk intensity; This represents the total number of factors in the global event factor group.

[0026] Calculate the maximum weight value of the local event factor group. :

[0027] ,in, For current time and local event factors Normalized time difference of most recent active time; This represents the total number of factors in the local event factor group. Local event factor The inherent risk intensity;

[0028] Determine the basic protection level ,in, , These are weighting coefficients, and ; It is the sigmoid normalization function;

[0029] Calculate the true protection level ,in, This is the emergency adjustment coefficient; This represents the system resource sufficiency coefficient.

[0030] Calculate the protection level after adding interference. :

[0031] ;

[0032] ;

[0033] ;

[0034] in, For threat response functions; Estimating the probability of an insider attacker; For response sensitivity coefficient; For unconventional utility values ​​of internal access streams; This is the interference increment;

[0035] Determine the range of camouflage levels ,in, , Lower limit level, upper limit level;

[0036] ;

[0037] ;

[0038] ;

[0039] ;

[0040] in, The moving average of the protection level as a historical safety baseline; This represents the average alignment of global event factors. This is the alignment adjustment factor; The average attribution confidence of the current event set; The confidence level affects the curvature parameter; The disturbance period is t; t is the current time. The amplitude of the periodic disturbance;

[0041] Will , , The data is combined in sequence to form the first protection sequence for the corresponding sales type data.

[0042] Preferably, the adaptation index for each service port is determined and a functional perturbation transformation analysis is performed to obtain the adaptation feedback vector, including:

[0043] A set of standardized test data perturbation sequences is injected into the dynamic verification set, and each service port is simultaneously observed during the observation period. The chain response within the time frame generates a corresponding observation vector, wherein the observation vector contains a response observation basis at several uniform sampling time points and a response amplitude based on each response observation basis;

[0044] Several baseline response templates are extracted based on historical secure transmission records, and the single matching degree between each observation vector and each baseline response template is determined to obtain the native adaptability index of the corresponding service port. Each baseline response template is a vector with the same dimension as the observation vector.

[0045] The native compatibility metrics of all service ports are used to construct an initial vector A, which is then divided into G1 disjoint subgroups. The number of ports contained in each subgroup may vary;

[0046] Based on the average adaptability index of ports within the subgroup, the subgroup is divided into L levels, and all subgroups contained in each level are encrypted.

[0047] The encrypted data is subjected to inter-level cross-obfuscation and noise that satisfies differential privacy is added, where the noise scale is related to the level.

[0048] The ciphertext with added noise is decrypted using the private key corresponding to each level to obtain the perturbed subgroup data, and all subgroup data are reassembled in the original order to obtain the fitness feedback vector.

[0049] Preferred options also include:

[0050] Adjust the size of the dynamic verification set consisting of all service ports involved in the dynamic transport architecture. :

[0051] ;

[0052] in, , These are the preset minimum validation set size and maximum validation set size, respectively; To adjust the slope coefficient; The information sensitivity index at the current moment is calculated based on the protection level, data volume, and historical abnormal access frequency of the pharmaceutical sales data to be transmitted. This is the floor symbol.

[0053] Preferably, the first protection sequence, the second protection sequence, and several encryption algorithms under the corresponding sales type data are integrated, including:

[0054] Based on the first protection sequence True protection level in Calculate the ranking weight ;

[0055] in, To set the slope coefficient; The protection level threshold;

[0056] when When the weight exceeds the preset weight, the first protection sequence will be... Treat it as a sub-ordered sequence; otherwise, treat the first protected sequence. Each element in the sequence is randomly shuffled and sorted, and then treated as a random sorted sequence.

[0057] Select the two elements with the highest overlap from the second protection sequence as core ordered elements, and use the remaining elements as auxiliary random elements;

[0058] Two core ordered elements are used as fixed anchor points and placed at the beginning and golden section points of the blank sequence, respectively.

[0059] Based on the remaining positions Assign ordered gap number With random gap number ,in, , ,in, The total length of the blank sequence is given by where is the security situation index based on the current system. Determine the maximum number of consecutive random elements allowed during the randomization process. ,in, Use a base random number; For the maximum increment; For smoothing parameters;

[0060] First, insert the sorted elements from the sub-ordered sequence sequentially after the starting position, until the number of insertions is equal to the number of elements in the sub-ordered sequence. Consistent, where if there are not enough elements, they are used in a loop;

[0061] Then insert sequentially before the golden ratio point. The elements are sorted from a random sequence and an auxiliary random element combination until the number of insertions is equal to the number of elements in the sequence. Consistent; if there are not enough elements, they are used in a circular manner.

[0062] If, after the insertion is completed, there are blank positions in the position segment formed by the starting position and the golden section point position, then 0 and 1 are used to randomly insert into each blank position. If there are no blank positions, then no insertion is required. At this time, the insertion sequence is obtained based on the final insertion result, and then the integration algorithm is obtained by randomly sorting several encryption algorithms.

[0063] Compared with the prior art, the beneficial effects of this application are as follows:

[0064] By dynamically capturing the generation process, transmission architecture, and historical security baseline of sales data, accurately distinguishing global and local event factors, constructing targeted protection sequences, matching and scientifically integrating appropriate encryption algorithms, the system achieves dynamic adaptation of security protection strategies to data characteristics and transmission environment. This ensures the protection strength of high-risk data while avoiding resource waste of low-risk data. It is also compatible with historical security strategies and has camouflage protection capabilities, effectively improving the security protection level and anti-attack capability of pharmaceutical sales data.

[0065] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description and the accompanying drawings.

[0066] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0067] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:

[0068] Figure 1 This is a flowchart of a method for protecting pharmaceutical sales data in an embodiment of the present invention. Detailed Implementation

[0069] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0070] This invention provides a method for the security protection of pharmaceutical sales data, such as... Figure 1 As shown, it includes:

[0071] Step 1: Obtain the event set of the generation process for each type of sales data in the newly generated pharmaceutical sales data and the dynamic transmission architecture for each generation process event. At the same time, obtain the historical security baseline for each type of sales data. The historical security baseline includes the historical reference security level range composed of security parameter groups for each historical collection time. The dynamic transmission architecture is based on multiple service ports involved in the corresponding generation process event.

[0072] Step 2: Analyze the event set of the data generation process for each sales type, determine the global event factor group and the local event factor group, and determine the true protection level, the protection level after adding interference, and the range of disguise level for the corresponding sales type data to form the first protection sequence;

[0073] Step 3: Based on the performance changes of the dynamic verification set consisting of all service ports involved in the dynamic transmission architecture, determine the adaptability index of each service port and perform functional perturbation transformation analysis to obtain the adaptability feedback vector, so as to match several encryption algorithms that match the adaptability feedback vector from the security protection pool.

[0074] Step 4: Obtain the overlap ratio between the actual protection level, the protection level after adding interference, and the spoofing level range of the corresponding sales type data and the historical security baseline of the same type, and form the second protection sequence;

[0075] Step 5: Integrate the first protection sequence, the second protection sequence, and several encryption algorithms under the corresponding sales type data, and perform security protection processing on the corresponding sales type data.

[0076] In this embodiment, sales type data refers to specific categories of data classified according to the sales model, channel, or product type of pharmaceutical products, such as prescription drug wholesale data, over-the-counter drug retail data, medical device sales data, and vaccine-specific sales data.

[0077] The event set for the generation process refers to the collection of all independent events related to the generation, processing, and flow of a certain type of sales data throughout the entire process from initial generation to completion of transmission. For example, for wholesale data of antibiotic prescription drugs, the event set for the generation process includes hospital purchase order submission events, pharmaceutical company order review events, inventory verification events, logistics scheduling events, drug delivery record generation events, invoice issuance events, payment receipt confirmation events, and data synchronization to the enterprise management system events.

[0078] A dynamic transmission architecture refers to a transmission architecture that dynamically adjusts the activation status of multiple service ports involved in the generation of a certain type of sales data according to data transmission needs. For example, the service ports involved in the above prescription drug wholesale data transmission include the order system port (port number 8080), the inventory system port (port number 9001), the logistics scheduling port (port number 6003), the financial settlement port (port number 7002), and the data storage port (port number 5005). These ports are dynamically activated according to the data transmission stage. For example, only port 8080 is activated during the order submission stage, while ports 9001 and 6003 are activated during the logistics scheduling stage, thus forming a dynamic transmission architecture.

[0079] Historical security baseline refers to the set of security parameters corresponding to each historical collection point of a certain type of sales data. All historical security parameter sets together constitute the range of historical reference security levels. Among them, the security parameter sets include core security parameters such as data encryption strength, access permission level, transmission verification frequency, and data backup cycle.

[0080] A global event factor group refers to a set of common event factors that appear consistently in the core business stages of all events that generate a certain type of sales data and have a general impact on data security.

[0081] Local event factor groups refer to a set of specific event factors that only occur in specific events during the generation of a certain type of sales data or in a specific business stage, and that have an impact on the security of certain data links.

[0082] The actual protection level refers to a quantitative level that reflects the actual data security protection needs, determined based on the weights of the global event factor group and the local event factor group, combined with adjustments for system resource adequacy. The value range is 0.1-1.0.

[0083] The protection level with added interference refers to the protection level formed by adding interference mechanisms on the basis of the real protection level, taking into account factors such as the probability of internal attackers and the unconventional utility of internal access flows. It is used to improve the anti-attack capability of data protection, and the value range does not exceed 1.0.

[0084] The spoofing level range refers to a false security protection level range set to confuse potential attackers, making it impossible for attackers to accurately judge the true protection strength of the data. The lower limit of the range is not lower than 0, and the upper limit is not higher than 1.0.

[0085] First protection sequence: {True protection level, protection level after adding interference, camouflage level range}.

[0086] The dynamic verification set refers to the set of all currently enabled service ports in the dynamic transmission architecture. It is used to monitor port transmission performance and security response status, and to provide a basis for matching encryption algorithms. For example, when transmitting prescription drug wholesale data, the currently enabled ports 8080, 9001, 6003, and 7002 constitute the dynamic verification set.

[0087] The adaptability index is a quantitative indicator that measures the degree to which the transmission performance, security response capability and current data security protection requirements of a single service port are adapted. The value ranges from 0 to 1, with a larger value indicating better adaptability, 0 indicating no adaptability and 1 indicating complete adaptability.

[0088] The adaptability feedback vector refers to the vector formed by recombining the adaptability indicators of all service ports in the dynamic verification set in port order after processing such as functional perturbation transformation, encryption and obfuscation, noise addition and decryption.

[0089] The security protection pool refers to a pre-established database that stores various encryption algorithms and their corresponding adaptation conditions, as shown in Table 1:

[0090] Table 1. Partial contents of the safety protection pool

[0091]

[0092] The overlap ratio refers to the proportion of overlap between the actual protection level, the protection level after adding interference, and the security level range of the historical security baseline, respectively, as well as the proportion of overlap between the spoofing level range and the security level range of the historical security baseline. The value range is 0-1. For example, if the quantized range of encryption strength corresponding to the protection level range of the historical security baseline is 0.6-0.9 (assuming encryption strength AES-128 corresponds to 0.6 and AES-256 corresponds to 0.9), and the quantized value of encryption strength corresponding to the current actual protection level is 0.8, then the overlap ratio is 1.0; the quantized value of encryption strength corresponding to the protection level after adding interference is 0.95, and the overlap ratio is 0.5 (only 0.9-0.95 overlaps with the historical range of 0.6-0.9, the length of the overlapping part is 0.05, the length of the historical range is 0.3, 0.05 / 0.3≈0.17, this is just an example logic); the spoofing level range is 0.4-0.5, which does not overlap with the historical range, so the overlap ratio is 0.

[0093] Second protection sequence: {overlap ratio between the actual protection level and the historical security baseline, overlap ratio between the protection level after adding interference and the historical security baseline, overlap ratio between the camouflage level range and the historical security baseline}.

[0094] The beneficial effects of the above technical solution are as follows: by dynamically capturing the generation process, transmission architecture, and historical security baseline of sales data, accurately distinguishing global and local event factors, constructing targeted protection sequences, matching and scientifically integrating appropriate encryption algorithms, the solution achieves dynamic adaptation of security protection strategies to data characteristics and transmission environment. This ensures the protection strength of high-risk data while avoiding resource waste of low-risk data. It is also compatible with historical security strategies and has the ability to disguise protection, effectively improving the security protection level and anti-attack capability of pharmaceutical sales data.

[0095] This invention provides a method for the security protection of pharmaceutical sales data, which analyzes the event set of the generation process for each type of sales data, including:

[0096] Obtain the first purpose before the generation process event and the second purpose after the generation process event, and analyze the dual-change timeline of the first purpose and the second purpose throughout the entire generation process event, wherein the first purpose and the second purpose are the same or different.

[0097] Based on the first time point of the non-zero change in the dual-change timeline and the combination of factors that cause the non-zero change at the corresponding first time point, and based on the first maximum continuous value of the continuous non-zero change and the second maximum continuous value of the zero change in the dual-change timeline, the main factors are calibrated for each time point in the dual-change timeline to obtain the initial calibration line for the corresponding process event.

[0098] Time alignment is performed on the initial calibration lines of all generation process events in the generation process event set of the corresponding sales type data to determine the global event factor group and the local event factor group.

[0099] In this embodiment, the first purpose refers to the core objective or use that is preset before a certain event is initiated or executed, that is, the initial intention of the event. For example, the first purpose of an inventory check event is to confirm whether the current inventory of antibiotic prescription drugs of pharmaceutical companies meets the needs of hospital purchase orders.

[0100] The second objective refers to the core goal actually achieved or the subsequent use generated after a certain process event is completed. It may be the same as or different from the first objective. For example, after the inventory verification event is completed, not only is the inventory quantity confirmed (consistent with the first objective), but it is also found that some drugs are close to their expiration date. Therefore, the second objective is to confirm that the inventory meets the order requirements and to mark the drugs nearing their expiration date.

[0101] A dual-change timeline refers to two parallel timelines constructed with time (in seconds) on the horizontal axis and the changes in the first and second objectives on the vertical axis (a change of 0 indicates no change in the objective, while a non-zero change indicates an adjustment, addition, or modification of the objective). For example, if the execution time of an inventory check event is t0-t10 (10 seconds in total), from t0 to t3 (the first 3 seconds), both the first and second objectives are to confirm the inventory quantity, and the change is 0. At t3, near-expiry drugs are discovered, and the second objective adds the near-expiry drug to the list, changing the change to 1. From t3 to t10, the change in the second objective remains 1, while the change in the first objective remains 0, thus constructing a dual-change timeline.

[0102] The first time point of a non-zero change refers to the first time point in the double change timeline where the change of the first or second objective changes from 0 to non-zero, that is, the time point when the objective first changes. For example, in the double change timeline of the inventory check event mentioned above, t3 seconds is the first time point when the change of the second objective changes from 0 to 1, and this time point is the first time point.

[0103] The combination of factors that causes a non-zero change at the first time point refers to the set of all relevant factors that cause a change in the first or second objective at the first time point. For example, the combination of factors that causes a change in the second objective at t3 seconds above includes the completion of inventory quantity verification (triggering condition factor), the activation of the drug expiration date query function (functional factor), and the detection of 3 batches of amoxicillin nearing their expiration date (data factor).

[0104] The first maximum continuous value of continuous non-zero change refers to the longest duration (in seconds) during which the change of the first or second objective remains non-zero in the dual change timeline. For example, in the dual change timeline of the inventory check event mentioned above, the second objective maintains a non-zero change from t3 to t10 seconds, a duration of 7 seconds, which is the first maximum continuous value of 7.

[0105] The second maximum continuous value of zero variation refers to the longest duration (in seconds) during which the variation of both the first and second objectives in the dual variation timeline remains at 0.

[0106] For example, in the inventory verification event mentioned above, the period from t0 to t2 is in a state of 0 change and within the second maximum continuous value range, with the main factor marked as inventory quantity query initialization; the period from t3 is the first time point, with the main factor marked as near-expiry drug detection trigger; and the period from t4 to t10 is in a state of non-zero change and within the first maximum continuous value range, with the main factor marked as near-expiry drug information recording.

[0107] The initial calibration line refers to the linear data sequence containing time points, change states, and main factors formed after the main factors are calibrated for all time points in the double change timeline of a single generating process event. For example, the initial calibration line for the inventory check event is [(t0, 0 change, inventory quantity query initialization), (t1, 0 ​​change, inventory quantity query initialization), (t2, 0 change, inventory quantity query initialization), (t3, non-zero change, near-expiry drug detection trigger), (t4, non-zero change, near-expiry drug information record), ..., (t10, non-zero change, near-expiry drug information record)].

[0108] Time alignment refers to uniformly calibrating the initial calibration lines of all events in the event set of a certain type of sales data generation process according to the time axis. Taking the start time of the first event as the benchmark, the time coordinates of other events are adjusted to ensure that the time dimension of all events is consistent. For example, if the event set of the generation process includes order submission events (t0-t8 seconds), inventory verification events (t2-t12 seconds), and logistics scheduling events (t5-t15 seconds), taking the start time t0 of the order submission event as the benchmark, the time coordinates of the inventory verification events are adjusted to t0-t10 seconds (the original t2 corresponds to the new t0, and the original t12 corresponds to the new t10), and the time coordinates of the logistics scheduling events are adjusted to t3-t18 seconds (the original t5 corresponds to the new t3, and the original t15 corresponds to the new t18), thus completing the time alignment.

[0109] The beneficial effects of the above technical solution are: by constructing a dual-change timeline and identifying the main factors, it is possible to accurately capture the dynamic changes of the purpose and key influencing factors during the execution of the event. Time alignment processing ensures the comparability between different events, providing reliable basic data support for the accurate division of global and local event factor groups, and improving the scientificity and accuracy of event factor analysis.

[0110] This invention provides a method for security protection of pharmaceutical sales data, which determines global event factor groups and local event factor groups, including:

[0111] Obtain the initial calibration line between the i-th and j-th generation process events in the generation process event set, construct an event-factor bipartite graph, and calculate the correlation strength weight between every two factor nodes in the bipartite graph;

[0112] Based on the association strength weight, community discovery is performed on all factor nodes to divide them into K factor communities, and the original calibration time points corresponding to each factor node contained in each factor community are extracted to form a time point set for the corresponding community.

[0113] For each factor community's time point set, multi-scale sliding window density clustering is performed. In the first scale window, high-density time point clusters are identified as anchor points for the core business stages of the corresponding community. In the second scale window, micro-density fluctuation points are identified in the neighborhood of each core business stage anchor point as local perturbation markers.

[0114] For any event that generates a process, the corresponding initial calibration line is mapped to each factor community. Based on whether the factor calibration falls into the core business stage anchor point or local disturbance mark of the corresponding community, a multi-community alignment feature vector for the event that generates a process is generated.

[0115] Cluster analysis is performed based on the multi-community aligned feature vectors of all events. Common event factors that always appear at the core business stage anchor points of all factor communities and have stable features are grouped into the global event factor group. Event-specific factors that only appear in local disturbance markers in specific factor communities or only appear at the core business stage anchor points of some events are grouped into the local event factor group.

[0116] Preferably, the association strength weight is determined based on the number of event nodes jointly connected by the two factor nodes and the temporal proximity of the time points corresponding to the edges connecting these event nodes in their respective dual-variable timelines.

[0117] In this embodiment, the event-factor bipartite graph refers to a bipartite graph structure formed by using events in the event set of the generation process as one type of node (event node) and the main factors in all initial calibration lines as another type of node (factor node). Event nodes and factor nodes that have a relationship (a factor is the main factor of a certain event) are connected by undirected edges. For example, event nodes include order submission event (E1), inventory verification event (E2), and logistics scheduling event (E3), while factor nodes include procurement demand entry (F1), inventory quantity query initialization (F2), near-expiry drug testing trigger (F3), and transportation route planning (F4). E1 is connected to F1, E2 is connected to F2, E2 is connected to F3, and E3 is connected to F4, thus forming the event-factor bipartite graph.

[0118] Association strength weight = 0.6 × (number of co-connected events / total number of events) + 0.4 × (1 - |tr1 - tr2| / tmax), where tr1 and tr2 are the calibration time points of the two factor nodes in the corresponding events; tmax is the total duration of the data generation process for this sales type.

[0119] Clustering algorithms (such as the Louvain algorithm) are used to divide all factor nodes into several relatively independent communities (factor communities). For example, through community discovery algorithms, factor nodes F1, F2, and F3 are divided into community C1 (related to order processing and inventory verification), and F4 and F5 (logistics node verification) are divided into community C2 (related to logistics scheduling), forming two factor communities. At this time, if the time point corresponding to F1 in community C1 is t0-t1, the time point corresponding to F2 is t0-t2, and the time point corresponding to F3 is t3-t10, the integrated time point set is {t0,t1,t2,t3,t4,...,t10}.

[0120] In this embodiment, the first scale window (core business stage identification) has the following parameters: window size = 5 seconds, density threshold = 0.7 (time point number / window size ≥ 0.7 is considered a high-density cluster).

[0121] Second-scale window (local disturbance identification): window size = 1 second, density fluctuation threshold = 0.3 (a window whose density is ≥0.3 higher than that of the adjacent window is considered a micro fluctuation point).

[0122] The core business stage anchor point refers to the high-density time point cluster identified by density clustering under the first-scale window. It corresponds to the core business execution stage of the factor community and is the time interval in which factor nodes within the community exert their concentrated influence. For example, in community C1, the time point set {t0-t10} uses a 5-second first-scale window sliding. The time point density is 0.8 (number of time points / window size) in the first t0-t5 seconds and 0.6 in the second t5-t10 seconds. The high-density time point cluster is in the second t0-t5 seconds. This interval is the core business stage anchor point.

[0123] Local disturbance markers refer to micro-density fluctuation points identified within the neighborhood of the core business stage anchor point (e.g., 1 second before and after the anchor point) under the second scale window. These correspond to the disturbance of local factors in the core business stage. For example, if the core business stage anchor point of community C1 is t0-t5 seconds, and a 1-second second scale window is used for sliding, the time point density of the window at t3 seconds is 0.3 higher than that of the adjacent windows. This t3 seconds is the local disturbance marker.

[0124] For example, the initial calibration line of event E2 (inventory verification event) is mapped to communities C1 (core anchor t0-t5 seconds, local marker t3 seconds) and C2 (core anchor t3-t8 seconds). Its main factors fall into the core anchor and local marker in C1, but not in C2. Therefore, the multi-community alignment feature vector is [1,2,0], where it is assumed that C1 corresponds to two dimensions and C2 corresponds to one dimension.

[0125] The common factor of an event refers to the factor that, in the multi-community aligned feature vector of all event-generating processes, falls within the core business stage anchor point of all factor communities and has a stable feature value (e.g., all are 1). For example, in the multi-community aligned feature vectors of events E1 (order submission event), E2 (inventory verification event), and E3 (logistics scheduling event), there is a data integrity verification factor whose feature value is 1 in all community core anchor points; this factor is the common factor of the event.

[0126] Event-specific factors refer to factors that fall into a specific factor community or the core business stage anchor point of a certain community only in the multi-community aligned feature vector of some generating process events. For example, the triggering factor for near-expiry drug testing only falls into the local perturbation marker of community C1 in the feature vector of event E2, and does not appear in the feature vectors of E1 and E3. This factor is an event-specific factor.

[0127] The beneficial effects of the above technical solution are as follows: by constructing an event-factor bipartite graph, community discovery, and multi-scale cluster analysis, the global event factors and local event factors are accurately distinguished. The division of event factors takes into account both the correlation between factors and the business stage and time characteristics, providing a scientific basis for the accurate calculation of subsequent protection levels and further improving the pertinence of security protection strategies.

[0128] This invention provides a method for security protection of pharmaceutical sales data, which determines the true protection level, the protection level after adding interference, and the range of disguise levels for data of the corresponding sales type, and constitutes a first protection sequence, including:

[0129] Calculate the composite weight value of the global event factor group :

[0130] ,in, The attenuation coefficient; Current time and global event factors Normalized time difference of most recent active time; Global event factor The inherent risk intensity; This represents the total number of factors in the global event factor group.

[0131] Calculate the maximum weight value of the local event factor group. :

[0132] ,in, For current time and local event factors Normalized time difference of most recent active time; This represents the total number of factors in the local event factor group. Local event factor The inherent risk intensity;

[0133] Determine the basic protection level ,in, , These are weighting coefficients, and ; It is the sigmoid normalization function;

[0134] Calculate the true protection level ,in, This is the emergency adjustment coefficient; This represents the system resource sufficiency coefficient.

[0135] Calculate the protection level after adding interference. :

[0136] ;

[0137] ;

[0138] ;

[0139] in, For threat response functions; Estimating the probability of an insider attacker; For response sensitivity coefficient; For unconventional utility values ​​of internal access streams; This is the interference increment;

[0140] Determine the range of camouflage levels ,in, , Lower limit level, upper limit level;

[0141] ;

[0142] ;

[0143] ;

[0144] ;

[0145] in, The moving average of the protection level as a historical safety baseline; This represents the average alignment of global event factors. This is the alignment adjustment factor; The average attribution confidence of the current event set; The confidence level affects the curvature parameter; The disturbance period is t; t is the current time. The amplitude of the periodic disturbance;

[0146] Will , , The data is combined in sequence to form the first protection sequence for the corresponding sales type data.

[0147] In this embodiment, The value ranges from 0.3 to 0.7, and is used to adjust the decay effect of time difference on weights. The larger the value, the more significant the impact of the time lag, especially in prescription drug wholesale / vaccine sales (highly sensitive scenarios): Over-the-counter drug retail (moderately sensitive scenarios): Sales of medical device accessories (low-sensitivity scenarios): .

[0148] , and The calculation method is similar and will not be repeated here; The value range is 0-1, preset according to the degree of influence of the factor on data security, such as the data integrity verification factor. =0.9, access authentication factor =0.85; The value range is 0-1, such as the encryption factor of the transportation route. =0.75, encryption factor for repayment amount =0.8.

[0149] In this embodiment, The value range is 0.6-0.8, with priority given to the influence of global event factors; Values ​​range from 0.2 to 0.4; data involving patient privacy (such as prescription drug sales): Data that does not involve privacy (such as the sale of ordinary consumables): .

[0150] Based on the current security risk level setting, when the risk is low... =0.05, medium risk =0.15, high risk =0.25.

[0151] Pa = (Number of abnormal internal accesses in the past 30 days / Total number of accesses in the past 30 days) × 0.8 + (Number of internal attack incidents in the past year / Number of maximum attack incidents in the past 3 years) × 0.2.

[0152] The value range is 2-5. The larger, The more significant the impact on the threat response function, the stricter the internal access control scenario: Scenarios with lax internal access control: 2.

[0153] Calculations are based on the deviations of internal access frequency, permissions, and data access volume from normal conditions. For example, if the normal access frequency is 10 times / hour, the current frequency is 25 times / hour. =1.5.

[0154] Rcamou: refers to the false protection level range consisting of the lower limit level Low and the upper limit level Lhigh, used to confuse attackers.

[0155] This is the average of the historical protection levels over the past 6 months. To determine the alignment between global event factors and the current business process, this is calculated by statistically analyzing the frequency of occurrence of global event factors within the current business process. =Attribution confidence of all individual events and / Total number of events, and the attribution confidence of individual events is based on the accuracy assessment of factor calibration, with a value range of [0,1], which is automatically calculated by the system based on historical calibration accuracy (default 0.85, 0.7 when there is no historical data).

[0156] In this embodiment, >0.5 =0.2, <0.5 =-0.2, =0.5 =-0.

[0157] The value range is 7-30 days, used to control the periodic fluctuations of the disguise level range. For high-frequency updated data (such as daily sales data): w=7; for low-frequency updated data (such as monthly summary data): w=30.

[0158] In this embodiment, a high-risk attack scenario is: Low-risk attack scenarios: .

[0159] The beneficial effects of the above technical solution are: by quantitatively calculating the weights of global and local event factors, and combining multiple dimensions such as system resources, internal attack risks, and historical baselines, the range of the true protection level, the protection level after adding interference, and the spoofing level can be accurately determined. This ensures that the protection level not only fully reflects the actual security needs of the data, but also has the ability to resist attacks and confuse attackers, thereby improving the accuracy and comprehensiveness of security protection.

[0160] This invention provides a method for security protection of pharmaceutical sales data, which determines the adaptability index of each service port and performs functional perturbation transformation analysis to obtain an adaptability feedback vector, including:

[0161] A set of standardized test data perturbation sequences is injected into the dynamic verification set, and each service port is simultaneously observed during the observation period. The chain response within the time frame generates a corresponding observation vector, wherein the observation vector contains a response observation basis at several uniform sampling time points and a response amplitude based on each response observation basis;

[0162] Several baseline response templates are extracted based on historical secure transmission records, and the single matching degree between each observation vector and each baseline response template is determined to obtain the native adaptability index of the corresponding service port. Each baseline response template is a vector with the same dimension as the observation vector.

[0163] The native compatibility metrics of all service ports are used to construct an initial vector A, which is then divided into G1 disjoint subgroups. The number of ports contained in each subgroup may vary;

[0164] Based on the average adaptability index of ports within the subgroup, the subgroup is divided into L levels, and all subgroups contained in each level are encrypted.

[0165] The encrypted data is subjected to inter-level cross-obfuscation and noise that satisfies differential privacy is added, where the noise scale is related to the level.

[0166] The ciphertext with added noise is decrypted using the private key corresponding to each level to obtain the perturbed subgroup data, and all subgroup data are reassembled in the original order to obtain the fitness feedback vector.

[0167] In this embodiment, the standardized test data perturbation sequence refers to a set of standardized data that is pre-set for testing the response performance and security stability of the service port. It includes perturbation items in dimensions such as data volume, transmission rate, and access permissions. For example, the test data perturbation sequence includes data volume perturbation (basic data volume 100MB, fluctuation ±10%), transmission rate perturbation (basic rate 10Mbps, fluctuation ±15%), access permission perturbation (simulating three types of access permissions: ordinary user, administrator user, and illegal user), and data format perturbation (adding a small number of invalid data fields).

[0168] The observation period refers to the time interval during which the response of the service port is continuously observed, denoted as . ,in, The observation start time, The observation duration (range 30-60 seconds, to ensure that the complete response of the port can be captured).

[0169] An observation vector is a vector formed by sampling at uniform time intervals (e.g., every 5 seconds) within an observation period, recording the response observation basis and response amplitude at each sampling point. The response observation basis includes transmission delay, transmission accuracy, security check pass rate, number of error codes, etc., and the response amplitude is the specific value of the observation basis. For example, if the observation period is 60 seconds, and sampling is performed once every 5 seconds, for a total of 12 sampling points, the observation vector would be [(transmission delay 20ms, amplitude 20), (transmission delay 22ms, amplitude 22), ..., (transmission delay 23ms, amplitude 23), (transmission accuracy 99.9%, amplitude 99.9), ..., (security check pass rate 100%, amplitude 100)] (the vector dimension is consistent with the number of observation basis points × the number of sampling times).

[0170] The baseline response template refers to a representative standard response vector extracted from historical secure transmission records. Each template corresponds to a normal transmission scenario, and the dimension is consistent with the observation vector. For example, 10 sets of response data under normal transmission scenarios are extracted from the historical secure transmission records of the past 3 months, and after processing, 10 baseline response templates are formed. For example, template 1 corresponds to a low load and no attack scenario, and template 2 corresponds to a medium load and slight interference scenario.

[0171] The single matching degree refers to the quantitative index of similarity between a single observation vector and a single baseline response template. It is obtained by calculating the cosine similarity between vectors and has a value range of 0-1.

[0172] The native fit metric refers to the maximum single match between the observation vector of a certain service port and all baseline response templates.

[0173] The initial vector A refers to the vector formed by arranging the native adaptability indices of all service ports in the dynamic verification set in order of port number. For example, if the dynamic verification set contains 4 service ports with native adaptability indices of 0.88, 0.92, 0.85, and 0.90 respectively, the initial vector A = [0.88, 0.92, 0.85, 0.90].

[0174] Subgrouping refers to dividing the initial vector A into G1 disjoint subgroups according to a preset grouping rule (such as based on the numerical range of the fitness index). Each subgroup contains the native fitness index of at least one port. For example, if the initial vector A=[0.88,0.92,0.85,0.90], it can be divided into G1 subgroups based on fitness index ≥0.9 and <0.9: C1=[0.92,0.90] and C2=[0.88,0.85].

[0175] Hierarchical division refers to dividing all subgroups into L levels (L ranges from 2 to 3, such as high, medium, and low levels) based on the average adaptability index of the ports within each subgroup. The higher the average adaptability index, the higher the level. For example, if the average adaptability index of subgroup C1 is (0.92+0.90) / 2=0.91 and the average adaptability index of subgroup C2 is (0.88+0.85) / 2=0.865, it is divided into L=2 levels. Level 1 (high adaptability level) includes C1, and level 2 (medium adaptability level) includes C2.

[0176] Inter-level cross-obfuscation refers to cross-mixing encrypted subgroups of data from different levels according to a preset ratio (e.g., the ratio of level 1 to level 2 is 1:1) to disrupt the original grouping relationship of the data and improve the confidentiality of the data. For example, if the encrypted subgroup data of level 1 is [E(0.92), E(0.90)] and the encrypted subgroup data of level 2 is [E(0.88), E(0.85)] (E() represents encryption processing), the cross-obfuscated data is [E(0.92), E(0.88), E(0.90), E(0.85)].

[0177] Noise that satisfies differential privacy refers to random noise added to protect the privacy of subgroup data in accordance with the differential privacy model.

[0178] In this embodiment, all perturbed subgroup data are reassembled according to the port order of the initial vector A to form a fitness feedback vector. For example, after perturbing subgroup C1, it is [0.91, 0.89], and after perturbing subgroup C2, it is [0.87, 0.84]. The reassembled fitness feedback vector is [0.91, 0.89, 0.87, 0.84].

[0179] The beneficial effects of the above technical solution are as follows: by injecting standardized test data perturbation sequences to obtain port responses, and combining them with benchmark templates to calculate the fit index, the resulting fit feedback vector, after subgrouping, hierarchical encryption, cross-obfuscation, and differential privacy noise processing, accurately reflects the fit between the service port and security protection requirements, while ensuring the confidentiality and privacy of the data. This provides a reliable basis for the accurate matching of subsequent encryption algorithms and avoids the risk of fit data being stolen or tampered with.

[0180] This invention provides a method for the security protection of pharmaceutical sales data, and further includes:

[0181] Adjust the size of the dynamic verification set consisting of all service ports involved in the dynamic transport architecture. :

[0182] ;

[0183] in, , These are the preset minimum validation set size and maximum validation set size, respectively; To adjust the slope coefficient; This represents the information sensitivity index at the current moment. This is the floor symbol.

[0184] In this embodiment, 0.4 × Actual protection level + 0.3 × Normalized value of data volume + 0.3 × Normalized value of historical abnormal access frequency.

[0185] In this embodiment, the minimum verification set size refers to the minimum number of ports allowed by the preset dynamic verification set, ensuring that basic transmission performance and security verification requirements are met. This size is set according to the enterprise's business scale and data transmission needs, such as for prescription drug / vaccine sales. 5; Sales of over-the-counter drugs / common consumables: The value is 3.

[0186] In this embodiment, the maximum verification set size refers to the maximum number of ports allowed by the preset dynamic verification set, avoiding resource waste or transmission delays caused by too many ports. This size is set according to the system's carrying capacity, such as... The value is 8.

[0187] In this embodiment, the adjustment slope coefficient refers to the parameter that adjusts the degree of influence of the information sensitivity index on the size of the validation set. The value range is 1-3. The larger h1 is, the more significant the adjustment effect of the information sensitivity index on the size of the validation set is (e.g., h1=2).

[0188] The information sensitivity index is calculated by averaging the quantitative values ​​of data protection level, data volume, and historical abnormal access frequency.

[0189] The beneficial effects of the above technical solution are: by dynamically adjusting the size of the dynamic verification set according to the information sensitivity index, the size of the verification set is adapted to the data sensitivity and system resource status. When the data sensitivity is high, more ports are enabled to improve transmission security and stability, and when the data sensitivity is low, the number of ports is reduced to reduce resource consumption, thus achieving a balance between security and resource utilization.

[0190] This invention provides a security protection method for pharmaceutical sales data, which integrates a first protection sequence, a second protection sequence, and several encryption algorithms for corresponding sales type data, including:

[0191] Based on the first protection sequence True protection level in Calculate the ranking weight ;

[0192] in, To set the slope coefficient; The protection level threshold;

[0193] when When the weight exceeds the preset weight, the first protection sequence will be... Treat it as a sub-ordered sequence; otherwise, treat the first protected sequence. Each element in the sequence is randomly shuffled and sorted, and then treated as a random sorted sequence.

[0194] Select the two elements with the highest overlap from the second protection sequence as core ordered elements, and use the remaining elements as auxiliary random elements;

[0195] Two core ordered elements are used as fixed anchor points and placed at the beginning and golden section points of the blank sequence, respectively.

[0196] Based on the remaining positions Assign ordered gap number With random gap number ,in, , ,in, The total length of the blank sequence is given by where is the security situation index based on the current system. Determine the maximum number of consecutive random elements allowed during the randomization process. ,in, Use a base random number; For the maximum increment; For smoothing parameters;

[0197] First, insert the sorted elements from the sub-ordered sequence sequentially after the starting position, until the number of insertions is equal to the number of elements in the sub-ordered sequence. Consistent, where if there are not enough elements, they are used in a loop;

[0198] Then insert sequentially before the golden ratio point. The elements are sorted from a random sequence and an auxiliary random element combination until the number of insertions is equal to the number of elements in the sequence. Consistent; if there are not enough elements, they are used in a circular manner.

[0199] If, after the insertion is completed, there are blank positions in the position segment formed by the starting position and the golden section point position, then 0 and 1 are used to randomly insert into each blank position. If there are no blank positions, then no insertion is required. At this time, the insertion sequence is obtained based on the final insertion result, and then the integration algorithm is obtained by randomly sorting several encryption algorithms.

[0200] In this embodiment, the preset weight threshold is 0.6, which is pre-set based on the expert group.

[0201] In this embodiment, if If the number of values ​​is 2 and the number of intermediate positions based on the starting position and the golden section point is greater than 2, then insert the elements in the order from the starting position to the golden section point. And so on;

[0202] If the golden ratio point is located at... There are 5 positions between the last element after insertion, and The value is 4. At this point, insert the parts sequentially from the golden section point to the starting position. And so on. It should be noted that the random sorting sequence is: And the middle blank position is randomly selected based on rand(0,1) and a value is inserted again.

[0203] In this embodiment, The value range is 2-5, such as =3; The value range is 0.5-0.7, such as... =0.6.

[0204] A blank sequence refers to a pre-constructed empty sequence used to carry the core ordered element, the first guard sequence element, and the auxiliary random element, with a total length of [length missing]. Configure according to data security requirements, such as =10.

[0205] The golden section point refers to the position in the blank sequence determined according to the golden ratio (approximately 0.618), which is used to place the second core ordered element. For example, if the length of the blank sequence is 10, the golden section point is 10 × 0.618 ≈ 6 (rounded down to the integer 6), that is, the 6th position is the golden section point.

[0206] The value range is 2-4, such as =3, The value range is 1-2, such as =2; The value ranges from 0 to 1, and is calculated from system security logs and attack detection results, such as... =0.8; The value range is 0.5-1, such as =0.8.

[0207] An integrated algorithm refers to the final set of security protection algorithms formed by randomly sorting and combining the inserted sequence with the matching encryption algorithm.

[0208] In this embodiment, the data security protection scenario for wholesale antibiotic prescription drugs is as follows:

[0209] Basic parameter settings: =0.7, =0.8, =0.2, =0.25, =5, =14 days =0.3;

[0210] Dynamic validation set adjustment:

[0211] Data protection level =0.9, data size 1000MB, 4 abnormal accesses in the past 30 days: =0.78;

[0212] Validation set size = 7;

[0213] Encryption algorithm matching: Fit feedback vector = [0.92, 0.89, 0.91, 0.88, 0.93, 0.87, 0.90], matching AES-256 (similarity 0.93), RSA-4096 (similarity 0.92), SHA-256 (similarity 0.91);

[0214] Protective sequence integration: The first protected sequence is a sub-ordered sequence;

[0215] Core ordered elements (highest overlap): actual protection level overlap is 0.95%, protection level overlap after adding interference is 0.8%;

[0216] Number of ordered gaps =4, number of random intervals =2;

[0217] Subordered sequence: The combined random sorted sequence: { Auxiliary random elements};

[0218] Final integration algorithm: [True protection level overlap ratio 0.95, , , After adding interference, the overlap ratio of protection levels is 0.8 (AES-256+RSA-4096+SHA-256).

[0219] The beneficial effects of the above technical solution are as follows: by dynamically determining the sequence sorting method based on the actual protection level, taking the core ordered element as the anchor point, reasonably allocating the ordered and random gaps, and integrating the first and second protection sequences and the adapted encryption algorithm, the integrated algorithm not only ensures the orderliness and targeting of the core protection strategy, but also improves the anti-attack capability through randomization processing, while being compatible with historical security strategies, making the security protection method more flexible and comprehensive, and able to accurately deal with different types of security risks.

[0220] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.

Claims

1. A method for secure protection of pharmaceutical sales data, characterized in that, include: Step 1: Obtain the event set of the generation process for each type of sales data in the newly generated pharmaceutical sales data and the dynamic transmission architecture for each generation process event. At the same time, obtain the historical security baseline for each type of sales data. The historical security baseline includes the historical reference security level range composed of security parameter groups for each historical collection time. The dynamic transmission architecture is based on multiple service ports involved in the corresponding generation process event. Step 2: Analyze the event set of the data generation process for each sales type, determine the global event factor group and the local event factor group, and determine the true protection level, the protection level after adding interference, and the range of disguise level for the corresponding sales type data to form the first protection sequence; Step 3: Based on the performance changes of the dynamic verification set consisting of all service ports involved in the dynamic transmission architecture, determine the adaptability index of each service port and perform functional perturbation transformation analysis to obtain the adaptability feedback vector, so as to match several encryption algorithms that match the adaptability feedback vector from the security protection pool. Step 4: Obtain the overlap ratio between the actual protection level, the protection level after adding interference, and the spoofing level range of the corresponding sales type data and the historical security baseline of the same type, and form the second protection sequence; Step 5: Integrate the first protection sequence, the second protection sequence, and several encryption algorithms under the corresponding sales type data, and perform security protection processing on the corresponding sales type data; The analysis includes the event set of the data generation process for each sales type, including: Obtain the first purpose before the generation process event and the second purpose after the generation process event, and analyze the dual-change timeline of the first purpose and the second purpose throughout the entire generation process event, wherein the first purpose and the second purpose are the same or different; Based on the first time point of the non-zero change in the dual-change timeline and the combination of factors that cause the non-zero change at the corresponding first time point, and based on the first maximum continuous value of the continuous non-zero change and the second maximum continuous value of the zero change in the dual-change timeline, the main factors are calibrated for each time point in the dual-change timeline to obtain the initial calibration line for the corresponding process event. Time alignment is performed on the initial calibration lines of all generation process events in the generation process event set of the corresponding sales type data to determine the global event factor group and the local event factor group; The determination of global event factor groups and local event factor groups includes: Obtain the initial calibration line between the i-th and j-th generation process events in the generation process event set, construct an event-factor bipartite graph, and calculate the correlation strength weight between every two factor nodes in the bipartite graph; Based on the association strength weight, community discovery is performed on all factor nodes to divide them into K factor communities, and the original calibration time points corresponding to each factor node contained in each factor community are extracted to form a time point set for the corresponding community. For each factor community's time point set, multi-scale sliding window density clustering is performed. In the first scale window, high-density time point clusters are identified as anchor points for the core business stages of the corresponding community. In the second scale window, micro-density fluctuation points are identified in the neighborhood of each core business stage anchor point as local perturbation markers. For any event that generates a process, the corresponding initial calibration line is mapped to each factor community. Based on whether the factor calibration falls into the core business stage anchor point or local disturbance mark of the corresponding community, a multi-community alignment feature vector for the event that generates a process is generated. Cluster analysis is performed based on the multi-community aligned feature vectors of all events. Common event factors that always appear at the core business stage anchor points of all factor communities and have stable features are classified into the global event factor group. Event-specific factors that only appear in local perturbation markers in specific factor communities or only appear at the core business stage anchor points of some events are classified into the local event factor group. The first protection sequence is formed by determining the true protection level, the protection level after adding interference, and the range of spoofing levels for the corresponding sales type data, including: Calculate the composite weight value of the global event factor group : ,in, The attenuation coefficient; Current time and global event factors Normalized time difference of most recent active time; Global event factor The inherent risk intensity; This represents the total number of factors in the global event factor group. Calculate the maximum weight value of the local event factor group. : ,in, For current time and local event factors Normalized time difference of most recent active time; This represents the total number of factors in the local event factor group. Local event factor The inherent risk intensity; Determine the basic protection level ,in, , These are weighting coefficients, and ; It is the sigmoid normalization function; Calculate the true protection level ,in, This is the emergency adjustment coefficient; This represents the system resource sufficiency coefficient. Calculate the protection level after adding interference. : ; ; ; in, For threat response functions; Estimating the probability of an insider attacker; For response sensitivity coefficient; For unconventional utility values ​​of internal access streams; This is the interference increment; Determine the range of camouflage levels ,in, , Lower limit level, upper limit level; ; ; ; ; in, The moving average of the protection level as a historical safety baseline; This represents the average alignment of global event factors. This is the alignment adjustment factor; The average attribution confidence of the current event set; The confidence level affects the curvature parameter; The disturbance period is t; t is the current time. The amplitude of the periodic disturbance; Will , , The data is combined in sequence to form the first protection sequence for the corresponding sales type data.

2. The method for secure protection of pharmaceutical sales data according to claim 1, characterized in that, The correlation strength weight is determined based on the number of event nodes jointly connected by the two factor nodes and the temporal proximity of the time points corresponding to the edges connecting these event nodes in their respective dual-variable timelines.

3. The method for secure protection of pharmaceutical sales data according to claim 1, characterized in that, Determine the adaptation index for each service port and perform functional perturbation transformation analysis to obtain the adaptation feedback vector, including: A set of standardized test data perturbation sequences is injected into the dynamic verification set, and each service port is simultaneously observed during the observation period. The chain response within the time frame generates a corresponding observation vector, wherein the observation vector contains a response observation basis at several uniform sampling time points and a response amplitude based on each response observation basis; Several baseline response templates are extracted based on historical secure transmission records, and the single matching degree between each observation vector and each baseline response template is determined to obtain the native adaptability index of the corresponding service port. Each baseline response template is a vector with the same dimension as the observation vector. The native compatibility metrics of all service ports are used to construct an initial vector A, which is then divided into G1 disjoint subgroups. The number of ports contained in each subgroup may vary; Based on the average adaptability index of ports within the subgroup, the subgroup is divided into L levels, and all subgroups contained in each level are encrypted. The encrypted data is subjected to inter-level cross-obfuscation and noise that satisfies differential privacy is added, where the noise scale is related to the level. The ciphertext with added noise is decrypted using the private key corresponding to each level to obtain the perturbed subgroup data, and all subgroup data are reassembled in the original order to obtain the fitness feedback vector.

4. The method for secure protection of pharmaceutical sales data according to claim 3, characterized in that, Also includes: Adjust the size of the dynamic verification set consisting of all service ports involved in the dynamic transport architecture. : ; in, , These are the preset minimum validation set size and maximum validation set size, respectively; To adjust the slope coefficient; The information sensitivity index at the current moment is calculated based on the protection level, data volume, and historical abnormal access frequency of the pharmaceutical sales data to be transmitted. This is the floor symbol.

5. The method for secure protection of pharmaceutical sales data according to claim 1, characterized in that, The first protection sequence, the second protection sequence, and several encryption algorithms under the corresponding sales type data are integrated, including: Based on the first protection sequence True protection level in Calculate the ranking weight ; in, To set the slope coefficient; The protection level threshold; when When the weight exceeds the preset weight, the first protection sequence will be... Treat it as a sub-ordered sequence; otherwise, treat the first protected sequence. Each element in the sequence is randomly shuffled and sorted, and then treated as a random sorted sequence. Select the two elements with the highest overlap from the second protection sequence as core ordered elements, and use the remaining elements as auxiliary random elements; Two core ordered elements are used as fixed anchor points and placed at the beginning and golden section points of the blank sequence, respectively. Based on the remaining positions Assign ordered gap number With random gap number ,in, , ,in, The total length of the blank sequence is given by where is the security situation index based on the current system. Determine the maximum number of consecutive random elements allowed during the randomization process. ,in, Use a base random number; For the maximum increment; For smoothing parameters; First, insert the sorted elements from the sub-ordered sequence sequentially after the starting position, until the number of insertions is equal to the number of elements in the sub-ordered sequence. Consistent, where if there are not enough elements, they are used in a loop; Then insert sequentially before the golden ratio point. The elements are sorted from a random sequence and an auxiliary random element combination until the number of insertions is equal to the number of elements in the sequence. Consistent; if there are not enough elements, they are used in a circular manner. If, after the insertion is completed, there are blank positions in the position segment formed by the starting position and the golden section point position, then 0 and 1 are used to randomly insert into each blank position. If there are no blank positions, then no insertion is required. At this time, the insertion sequence is obtained based on the final insertion result, and then the integration algorithm is obtained by randomly sorting several encryption algorithms.

Citation Information

Patent Citations

  • Data processing method based on direct connection client

    CN118839115A

  • A computer software security encryption management system and method

    CN119783142A