Enterprise management system optimization method based on background data

By employing technologies such as layered encryption, dynamic access control, and load balancing, an adaptive and optimized enterprise management system architecture is constructed. This addresses the security and efficiency issues of existing systems under diverse business scenarios and dynamic security threats, enabling differentiated protection and real-time optimization of sensitive data, and improving system security and response efficiency.

CN121902174APending Publication Date: 2026-04-21FUTURE SMART CITY (BEIJING) TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
FUTURE SMART CITY (BEIJING) TECHNOLOGY CO LTD
Filing Date
2025-12-31
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing enterprise management systems face challenges such as fixed encryption strength and access permissions, high computational overhead, system resource bottlenecks, and delayed identification of abnormal operations when dealing with diverse business scenarios and dynamic security threats. These issues make it difficult to achieve fine-grained, dynamic data presentation control and security response.

Method used

By employing layered encryption algorithms, dynamic access control, load balancing, full lifecycle monitoring, and abnormal behavior detection, an adaptive and optimized enterprise management system architecture is constructed. Through layered encryption processing, access level judgment, load balancing, transmission path optimization, and abnormal response mechanisms, differentiated protection of sensitive data and real-time system optimization are achieved.

Benefits of technology

It achieves differentiated protection for sensitive data, reduces the risk of core data leakage, meets compliance requirements, reduces unnecessary resource consumption, improves system response efficiency, adapts to business and security changes, simplifies operation and maintenance troubleshooting, and supports enterprise digital transformation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121902174A_ABST
    Figure CN121902174A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of enterprise management systems, in particular to an enterprise management system optimization method based on background data, which comprises the following steps of: performing hierarchical encryption on sensitive data, dividing a core original layer, an aggregation middle layer and an abstract display layer, and matching a differentiation algorithm; then calculating a permission score through a hybrid model, and dynamically controlling data presentation; an encryption queue is optimized based on real-time load activation weighted polling or a minimum connection number algorithm, an access range is shrunk by combining access map pruning, and threats are isolated; switching a national cipher SM9 protocol and dual-channel redundancy transmission according to channel quality, and realizing full-life-cycle anomaly detection through a data blood relationship chain and a graph neural network; finally, the dynamic presentation rule is optimized through reinforcement learning iteration. According to the method, accurate protection of sensitive data, dynamic adaptation of system loads, controllability of authority fine grit and traceability of a data circulation full link are achieved, the service adaptability and user experience are improved, compliance requirements are met, and stable and efficient support is provided for digital transformation of enterprises.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of enterprise management system technology, and specifically to an optimization method for an enterprise management system based on backend data. Background Technology

[0002] Against the backdrop of enterprise digital transformation and continuous business expansion, enterprise management systems, as core platforms supporting efficient organizational operations, play a crucial role in resource integration, process collaboration, and data security. With increasingly complex business scenarios and rapidly growing data volumes, higher demands are being placed on the system's ability to protect sensitive information and its operational efficiency. Maintaining good system performance while ensuring data security has become a significant challenge in the optimization of current enterprise management systems.

[0003] Currently, common data protection methods in enterprise management systems mostly employ unified encryption strategies or role-based static access control. While these methods meet basic security requirements to some extent, they are significantly inadequate in addressing diverse business scenarios and dynamic security threats. Existing solutions typically set encryption strength and access permissions to a fixed pattern, rarely considering the varying sensitivity of different data types or changes in users' actual business needs. Furthermore, most systems do not implement collaborative, full lifecycle protection for data at each stage of storage, transmission, and access, resulting in limited protection effectiveness against advanced persistent threats or unauthorized internal operations.

[0004] The secure management of sensitive enterprise data involves several interrelated technical dimensions. On the one hand, while encryption can effectively prevent data leakage, its computational overhead increases significantly with the amount of data, potentially affecting system response speed and user experience. On the other hand, different user roles have different access needs for the same dataset; for example, financial summary views and detailed records should be accessible to different permission levels. However, existing technologies are not yet perfect in achieving fine-grained, dynamic data presentation control, often relying on manual configuration or post-event auditing, making it difficult to adapt to changes in permissions and risk profiles in real time.

[0005] Especially in high-concurrency business scenarios, the concentrated execution of encryption tasks can easily cause system resource bottlenecks, while static permission models cannot flexibly adjust the data visibility scope according to real-time load and security status. At the same time, the lack of a linkage mechanism between channel security and access behavior traceability during data flow leads to delays in abnormal operation identification and security response. These factors collectively constitute the technical challenge of synergistically optimizing data security and system efficiency.

[0006] Therefore, how to build an enterprise management system architecture that can implement layered encryption based on data type, dynamically adjust data presentation based on user permissions, and adaptively optimize in conjunction with system load and transmission status has become an important direction for improving enterprise data governance capabilities and operational resilience. Summary of the Invention

[0007] The purpose of this invention is to address the aforementioned shortcomings in the prior art by providing an optimization method for an enterprise management system based on backend data.

[0008] The objective of this invention is achieved through the following technical solution: an optimization method for an enterprise management system based on backend data, comprising the following steps: S1. Obtain sensitive information stored in the enterprise management system, and perform layered encryption processing on the sensitive information through a preset encryption algorithm to obtain an encrypted data block. The layered encryption algorithm divides multiple encryption levels according to the data type and determines the encryption strength of each encryption level to match business requirements. S2. Based on the obtained encrypted data blocks, the user identity information is captured using an access log recording mechanism. The permission level is extracted from the user identity information. If the permission level is higher than a preset threshold, all data blocks are directly decrypted; otherwise, only the data blocks with the summarized encryption level are decrypted to obtain the adjusted data presentation format. S3. By adjusting the data presentation format, obtain the real-time system load index, analyze the distribution of computing costs from the real-time system load index, and determine if the computing cost exceeds the preset threshold. Then, activate the load balancing algorithm to optimize the encryption process and determine the optimized encryption queue to reduce the overall burden. S4. Based on the determined optimized encryption queue, the access scope corresponding to the user identity is updated using a dynamic permission mapping model. Potential security threat features are extracted from the access scope. If the features match a preset pattern, the affected data blocks are isolated to obtain a protected dataset. S5. Obtain the status parameters of the transmission channel through the enhanced protection dataset, evaluate the multi-level requirement compliance from the status parameters, and determine if the compliance is lower than the preset threshold. Then, apply the transmission encryption protocol to adjust the channel configuration and determine a secure transmission path to maintain operational efficiency. S6. Based on the secure transmission path, a full lifecycle monitoring algorithm is used to track the data flow trajectory, identify abnormal access patterns from the data flow trajectory, and if an abnormal pattern occurs, trigger an alarm response mechanism to isolate the abnormal user's identity and obtain a clean system environment. S7. By purifying the system environment, obtain the summarized business requirement feedback, optimize the dynamic presentation rules from the business requirement feedback, determine if the risk of information leakage is reduced after the dynamic presentation rules are updated, then apply the dynamic presentation rules to all data blocks, and determine the final balance state to support the operation of the enterprise management system.

[0009] The present invention is further configured such that: the layered encryption processing includes data type identification, encryption level division, and encryption strength allocation; the adjusted data presentation format includes permission-driven decryption, data granularity control, and view reconstruction; the computational cost distribution analysis includes CPU utilization statistics, memory consumption monitoring, and disk latency measurement; the enhanced protection dataset includes access scope remapping, threat feature extraction, and isolation policy execution; the secure transmission path includes channel status assessment, dynamic protocol switching, and path redundancy configuration; the purified system environment includes trajectory backtracking analysis, abnormal behavior modeling, and identity isolation operations; and the final equilibrium state includes rule version management, risk quantification verification, and global policy synchronization.

[0010] The present invention is further configured such that, in obtaining sensitive information stored in the enterprise management system, the sensitive information is subjected to layered encryption processing using a preset encryption algorithm to obtain an encrypted data block. Specifically, the layered encryption algorithm divides the data into multiple encryption levels based on the data type, and the encryption strength of each encryption level is determined to match business requirements. Scan the field metadata in the enterprise management system database, identify data fields belonging to the finance, human resources or customer categories based on a predefined sensitive tag library, and generate a list of sensitive data. Based on the aforementioned sensitive data list, the data is divided into three encryption layers: the core raw layer, the aggregation intermediate layer, and the digest display layer, which correspond to AES-256, SM4, and lightweight obfuscation algorithms, respectively. Based on the access frequency and compliance requirements in the business context, a corresponding key rotation cycle and encryption computing resource quota are allocated to each encryption level to generate a hierarchical encryption policy table. Based on the hierarchical encryption strategy table, the original data is encrypted field by field according to the corresponding encryption level, and the structured encrypted data block is output and written to the distributed storage node.

[0011] The present invention is further configured such that, based on the obtained encrypted data blocks, an access log recording mechanism is used to capture user identity information, and the permission level is extracted from the user identity information. If the permission level is higher than a preset threshold, all data blocks are directly decrypted; otherwise, only the data blocks with the summarized encryption level are decrypted. The adjusted data presentation format is as follows: When a user initiates a data query request, the authentication gateway intercepts the JWT token in the request header and parses out the user ID, role group, and department affiliation information. The user ID is input into the permission decision engine, and the comprehensive permission score of the user is calculated by combining the RBAC and ABAC hybrid model. If the permission score is greater than or equal to 90, then the full decryption module is called to load the core original layer key and perform reverse decryption on all three encryption layers of data blocks; If the permission score is below 90, only the summary display layer key is loaded, the encryption status of the two encryption layers, the aggregation intermediate layer and the core original layer, is retained, and the de-identified summary view is returned.

[0012] The present invention is further configured such that, by obtaining real-time system load indicators through the adjusted data presentation format, analyzing the distribution of computational costs from the real-time system load indicators, and determining that if the computational cost exceeds a preset threshold, a load balancing algorithm is activated to optimize the encryption process, and an optimized encryption queue is determined to reduce the overall burden. Specifically, this involves: After each encryption or decryption operation is completed, the performance probe collects the CPU utilization, heap memory usage, and disk read / write latency of the current thread. The collected metrics are stored in a time-series database according to their timestamps, and associated with the corresponding operation type and data block size. A moving average of the indicator series within the most recent 5 minutes is calculated using a sliding time window to generate unit data processing cost curves for each operation type. If the unit cost of any operation type exceeds a preset threshold, the operation is marked as a high-load task, triggering subsequent optimization processes.

[0013] The present invention is further configured such that, based on the determined optimized encryption queue, the access scope corresponding to the user identity is updated using a dynamic permission mapping model, potential security threat features are extracted from the access scope, and if the features match a preset pattern, the affected data blocks are isolated to obtain a protected enhanced dataset. Construct a user-resource access graph, where nodes represent users or data blocks, and edge weights represent historical access frequency and permission levels; When the system load is too high, the graph pruning algorithm is activated to remove low-frequency access edges and shrink the access radius of some users. Based on the shrunk graph, the set of reachable data nodes for each user is recalculated to generate a new access range descriptor; Inject the descriptor into the access control list to restrict subsequent requests to only hit data blocks within the authorized subset.

[0014] The present invention is further configured such that, by obtaining the status parameters of the transmission channel through the enhanced protection dataset, evaluating the multi-level requirement compliance from the status parameters, and determining that if the compliance is lower than a preset threshold, the transmission encryption protocol is applied to adjust the channel configuration and determine a secure transmission path to maintain operational efficiency, specifically: Before data is transmitted across services, the channel proxy module collects the current network bandwidth, packet loss rate, and TLS handshake latency. The parameters are input into a pre-trained channel quality assessment model, which outputs the current channel's adaptation score for high-density, medium-density, and low-density data. If the compatibility score of high-density data is below 0.7, it will automatically switch to the national cryptographic SM9 protocol and enable dual-channel redundant transmission. At the same time, channel configuration change events are recorded for subsequent auditing and policy rollback.

[0015] The present invention is further configured such that, based on a secure transmission path, a full lifecycle monitoring algorithm is used to track the data flow trajectory, abnormal access patterns are identified from the data flow trajectory, and if an abnormal pattern occurs, an alarm response mechanism is triggered to isolate the abnormal user's identity, thereby obtaining a purified system environment. Specifically, this involves: A unique watermark is embedded when each data block is first generated, and the source address, destination address, operator, and timestamp are recorded by the log middleware during each cross-node transmission. Construct all flow records into a directed acyclic graph to represent the complete lineage of this data block; The deployment graph neural network model traverses the lineage chain in real time to detect unauthorized redirects, high-frequency access, or abnormal geographic locations. Once a behavior matching a preset abnormal pattern is identified, the user session is immediately frozen and its associated data copy is blocked.

[0016] The present invention is further configured such that, by purifying the system environment, obtaining aggregated business requirement feedback, optimizing dynamic presentation rules from the business requirement feedback, and determining that if the risk of information leakage is reduced after the dynamic presentation rules are updated, the dynamic presentation rules are applied to all data blocks to determine the final balance state to support the operation of the enterprise management system. Regularly aggregate user operation logs, customer service tickets, and security audit reports to extract feedback items regarding insufficient data visibility or information overload; Natural language processing is performed on the feedback items to identify the specific data fields, user roles, and expected presentation granularity involved. Based on a reinforcement learning framework, the rule base is dynamically updated iteratively, with the reward function being the rate of decrease in information leakage risk and the rate of improvement in user operation efficiency. If a new dynamic presentation rule does not trigger permission violations and user satisfaction increases by more than 5% for 7 consecutive days in the test environment, it will be pushed to the production environment for full implementation.

[0017] The present invention is further configured such that the load balancing algorithm is a weighted round-robin algorithm or a least-connections algorithm.

[0018] The beneficial effects of this invention are as follows: This invention achieves differentiated protection of sensitive data through three-level encryption and precise algorithm matching. Combined with full lifecycle lineage tracking, real-time detection of abnormal behavior, and optimization of national cryptographic protocol transmission, it comprehensively blocks vulnerabilities in storage, access, and transmission, significantly reduces the risk of core data leakage, and meets compliance requirements.

[0019] This invention uses a load balancing algorithm and dynamic shrinkage of access range to adapt to system load in real time, reduce unnecessary resource consumption, break the dilemma of security versus efficiency, and maintain low latency response even in high-concurrency scenarios.

[0020] This invention implements fine-grained access control based on a hybrid RBAC and ABAC model, dynamically adapting to changes in business and security. It satisfies the differentiated data needs of multiple roles while preventing unauthorized access, eliminating the need for frequent manual configuration.

[0021] The dynamic presentation rules of this invention are iteratively optimized through business feedback to accurately match the needs of multiple scenarios and improve user operation efficiency; the full-link traceability and automated early warning mechanism simplifies operation and maintenance troubleshooting, reduces operating costs, and provides stable support for enterprise digital transformation. Attached Figure Description

[0022] The invention will be further described with reference to the accompanying drawings, but the embodiments in the drawings do not constitute any limitation on the invention. For those skilled in the art, other drawings can be obtained based on the following drawings without creative effort.

[0023] Figure 1 This is a flowchart of the method of the present invention. Detailed Implementation

[0024] The present invention will be further described in conjunction with the following embodiments.

[0025] Depend on Figure 1 As can be seen, the enterprise management system optimization method based on backend data described in this embodiment includes the following steps: S1. Obtain sensitive information stored in the enterprise management system, and perform layered encryption processing on the sensitive information through a preset encryption algorithm to obtain an encrypted data block. The layered encryption algorithm divides multiple encryption levels according to the data type and determines the encryption strength of each encryption level to match business requirements. S2. Based on the obtained encrypted data blocks, the user identity information is captured using an access log recording mechanism. The permission level is extracted from the user identity information. If the permission level is higher than a preset threshold, all data blocks are directly decrypted; otherwise, only the data blocks with the summarized encryption level are decrypted to obtain the adjusted data presentation format. S3. By adjusting the data presentation format, obtain the real-time system load index, analyze the distribution of computing costs from the real-time system load index, and determine if the computing cost exceeds the preset threshold. Then, activate the load balancing algorithm to optimize the encryption process and determine the optimized encryption queue to reduce the overall burden. S4. Based on the determined optimized encryption queue, the access scope corresponding to the user identity is updated using a dynamic permission mapping model. Potential security threat features are extracted from the access scope. If the features match a preset pattern, the affected data blocks are isolated to obtain a protected dataset. S5. Obtain the status parameters of the transmission channel through the enhanced protection dataset, evaluate the multi-level requirement compliance from the status parameters, and determine if the compliance is lower than the preset threshold. Then, apply the transmission encryption protocol to adjust the channel configuration and determine a secure transmission path to maintain operational efficiency. S6. Based on the secure transmission path, a full lifecycle monitoring algorithm is used to track the data flow trajectory, identify abnormal access patterns from the data flow trajectory, and if an abnormal pattern occurs, trigger an alarm response mechanism to isolate the abnormal user's identity and obtain a clean system environment. S7. By purifying the system environment, obtain the summarized business requirement feedback, optimize the dynamic presentation rules from the business requirement feedback, determine if the risk of information leakage is reduced after the dynamic presentation rules are updated, then apply the dynamic presentation rules to all data blocks, and determine the final balance state to support the operation of the enterprise management system.

[0026] This embodiment describes an enterprise management system optimization method based on backend data. The layered encryption processing includes data type identification, encryption level division, and encryption strength allocation. The adjusted data presentation format includes permission-driven decryption, data granularity control, and view reconstruction. The computational cost distribution analysis includes CPU utilization statistics, memory consumption monitoring, and disk latency measurement. The enhanced protection dataset includes access scope remapping, threat feature extraction, and isolation policy execution. The secure transmission path includes channel status assessment, dynamic protocol switching, and path redundancy configuration. The purified system environment includes trajectory backtracking analysis, abnormal behavior modeling, and identity isolation operations. The final equilibrium state includes rule version management, risk quantification verification, and global policy synchronization.

[0027] This embodiment describes an optimization method for an enterprise management system based on backend data. The method involves acquiring sensitive information stored in the enterprise management system, performing layered encryption processing on the sensitive information using a preset encryption algorithm to obtain encrypted data blocks. Specifically, the layered encryption algorithm divides data into multiple encryption levels based on data type, and determines the encryption strength of each level to match business requirements. This includes: scanning the field metadata in the enterprise management system database; identifying data fields belonging to the finance, human resources, or customer categories based on a predefined sensitive tag library, and generating a sensitive data list; dividing the data into three encryption levels—core original layer, aggregation intermediate layer, and summary display layer—corresponding to AES-256, SM4, and lightweight obfuscation algorithms, respectively; allocating corresponding key rotation cycles and encryption computing resource quotas to each encryption level according to access frequency and compliance requirements in the business context, and generating a layered encryption strategy table; and performing encryption operations on each field of the original data according to the layered encryption strategy table, outputting structured encrypted data blocks and writing them to distributed storage nodes.

[0028] This embodiment accurately identifies core sensitive data such as financial, human resources, and customer data through a sensitive tag library. It differentiates and matches AES-256, SM4, and lightweight obfuscation algorithms according to the core original layer, aggregation intermediate layer, and summary display layer. This ensures high-strength encryption of core data while avoiding over-encryption of low-sensitivity data, thus balancing security and efficiency. Customized key rotation cycles and computing resource quotas are allocated to each encryption layer to adapt to different business access frequencies and compliance requirements. At the same time, structured encrypted data blocks are written to distributed storage nodes to improve data storage reliability and scalability.

[0029] This embodiment describes an enterprise management system optimization method based on backend data. Based on the obtained encrypted data blocks, an access log recording mechanism is used to capture user identity information. The permission level is extracted from the user identity information. If the permission level is higher than a preset threshold, all data blocks are directly decrypted; otherwise, only the data blocks at the summary encryption level are decrypted to obtain the adjusted data presentation format. Specifically, when a user initiates a data query request, the authentication gateway intercepts the JWT token in the request header and parses out the user ID, role group, and department affiliation information. The user ID is input into the permission decision engine, and a comprehensive permission score for the user is calculated using a hybrid RBAC and ABAC model. If the permission score is greater than or equal to 90 points, the full decryption module is called to load the core original layer key, and reverse decryption is performed on all three encryption levels of the data blocks. If the permission score is lower than 90 points, only the digest display layer key is loaded, and the encryption status of the aggregation intermediate layer and the core original layer is retained, returning a de-identified summary view.

[0030] This embodiment uses JWT tokens to parse user identity information and calculates a comprehensive permission score through a hybrid RBAC and ABAC model. A 90-point threshold enables precise hierarchical classification of full decryption and anonymized summary, preventing unauthorized access. Low-privilege users only receive an anonymized summary view of the summary display layer to avoid sensitive data leakage, while high-privilege users obtain complete original data. This satisfies the business needs of different roles and simplifies the data access process.

[0031] This embodiment describes an enterprise management system optimization method based on background data. Specifically, it involves obtaining real-time system load indicators through adjusted data presentation, analyzing the computational cost distribution from these indicators, and determining if the computational cost exceeds a preset threshold. If so, it activates a load balancing algorithm to optimize the encryption process and identifies an optimized encryption queue to reduce the overall burden. The method includes: after each encryption or decryption operation, a performance probe collects the CPU utilization, heap memory usage, and disk read / write latency of the current thread; storing the collected indicators in a time-series database by timestamp and associating them with the corresponding operation type and data block size; using a sliding time window to perform a moving average calculation on the indicator sequence within the last 5 minutes to generate a unit data processing cost curve for each operation type; and marking the operation as a high-load task and triggering subsequent optimization processes when the unit cost of any operation type exceeds a preset threshold.

[0032] This embodiment collects metrics such as CPU utilization, memory usage, and disk latency using performance probes. Combined with time-series databases and sliding time window analysis, it accurately identifies high-load operation types. It triggers a load balancing algorithm to optimize the encryption queue, avoiding resource congestion caused by concentrated encryption / decryption tasks, ensuring system response speed and operational stability in high-concurrency scenarios, and reducing unnecessary resource consumption.

[0033] This embodiment describes an enterprise management system optimization method based on backend data. Specifically, the method involves: updating the access range corresponding to user identities using a dynamic permission mapping model based on a determined optimized encrypted queue; extracting potential security threat features from the access range; and isolating affected data blocks if the features match a preset pattern to obtain an enhanced protection dataset. This process includes: constructing a user-resource access graph, where nodes represent users or data blocks, and edge weights represent historical access frequency and permission levels; when the system load is too high, initiating a graph pruning algorithm to remove low-frequency access edges and shrink the access radius of some users; based on the shrunken graph, recalculating the reachable data node set for each user to generate a new access range descriptor; and injecting the descriptor into an access control list to restrict subsequent requests to only hit data blocks within the authorized subset.

[0034] This embodiment prunes the user-resource access graph, removing low-frequency access edges and shrinking the access radius to reduce unnecessary data processing overhead under high load. Based on the shrunken graph, it updates the access control list, restricting users to access only authorized subsets of data. Combined with threat features, it extracts and isolates risky data blocks to improve the system's resistance to attacks.

[0035] This embodiment describes an enterprise management system optimization method based on backend data. Specifically, it involves obtaining transmission channel status parameters through a protected dataset, evaluating the compliance of multi-level requirements from these parameters, and determining if the compliance is below a preset threshold. If so, it applies a transmission encryption protocol to adjust the channel configuration and establish a secure transmission path to maintain operational efficiency. Before data is transmitted across services, the channel proxy module collects current network bandwidth, packet loss rate, and TLS handshake latency. These parameters are input into a pre-trained channel quality assessment model, which outputs the current channel's adaptation scores for high-security, medium-security, and low-security data. If the adaptation score for high-security data is below 0.7, it automatically switches to the national cryptographic SM9 protocol and enables dual-channel redundant transmission. Simultaneously, it records channel configuration change events for subsequent auditing and policy rollback.

[0036] This embodiment outputs an adaptation score through a channel quality assessment model. When the adaptation of high-density data is insufficient, it automatically switches to the national cryptographic SM9 protocol to meet compliance requirements. Dual-channel redundant transmission is enabled to resist network interruption and eavesdropping risks. Channel configuration change records support auditing and rollback to ensure that the transmission process is traceable and controllable, balancing security and operational efficiency.

[0037] This embodiment describes an enterprise management system optimization method based on backend data. Specifically, it involves using a secure transmission path and a full lifecycle monitoring algorithm to track data flow, identify abnormal access patterns from the data flow trajectory, and trigger an alarm response mechanism to isolate abnormal user identities if an abnormal pattern occurs, thus achieving a purified system environment. The method includes: embedding a unique watermark identifier when each data block is first generated; recording the source address, destination address, operator, and timestamp during each cross-node transmission using log middleware; constructing a directed acyclic graph (DAG) of all flow records as the complete lineage chain of the data block; deploying a graph neural network model to traverse the lineage chain in real time to detect unauthorized jumps, high-frequency access, or abnormal geographic locations; and immediately freezing the user session and blocking its associated data copies once a behavior matching a preset abnormal pattern is identified.

[0038] This embodiment uses data watermarking and directed acyclic graph lineage chains to fully record the entire trajectory of data generation, transmission, and access, providing a basis for security auditing and problem investigation; the graph neural network model detects abnormal behaviors such as unauthorized redirects and high-frequency access in real time, quickly freezes sessions and blocks data copies, solves the problem of delayed anomaly identification, and significantly reduces data leakage losses.

[0039] This embodiment describes an enterprise management system optimization method based on backend data. The method involves purifying the system environment, obtaining aggregated business demand feedback, optimizing dynamic presentation rules from this feedback, and determining if the risk of information leakage is reduced after updating the dynamic presentation rules. If so, the dynamic presentation rules are applied to all data blocks to determine the final balance state to support the operation of the enterprise management system. Specifically, this involves: periodically aggregating user operation logs, customer service tickets, and security audit reports to extract feedback items regarding insufficient data visibility or information overload; performing natural language processing on the feedback items to identify the specific data fields, user roles, and expected presentation granularity involved; iteratively updating the dynamic presentation rule library based on a reinforcement learning framework, using the information leakage risk reduction rate and user operation efficiency improvement rate as reward functions; and pushing the new dynamic presentation rule to the production environment for full implementation when it does not trigger permission violations and user satisfaction increases by more than 5% for 7 consecutive days in the test environment.

[0040] This embodiment identifies user roles, data fields, and presentation granularity requirements, and dynamically presents a rule base based on reinforcement learning. The new rules are tested and verified for 7 days to ensure that there are no permission violations and that user satisfaction is improved by more than 5%. This reduces the risk of information leakage, solves the problems of insufficient data visibility or information overload, and improves business processing efficiency.

[0041] This embodiment describes an optimization method for an enterprise management system based on backend data. The load balancing algorithm is either a weighted round-robin algorithm or a minimum connection algorithm. The weighted round-robin algorithm is suitable for scenarios with varying server performance, while the minimum connection algorithm is suitable for scenarios with uneven request distribution. Both algorithms are available, allowing for precise optimization of the encrypted queue based on the actual system load characteristics, balancing server resource usage, further reducing the overall system burden, and ensuring stable and efficient system operation.

[0042] Specifically, in a real-world deployment scenario, this embodiment assumes a large manufacturing enterprise has deployed a comprehensive enterprise management platform that includes subsystems such as finance, human resources, and customer relationship management. This platform generates a large amount of structured and unstructured data daily, including highly sensitive fields such as employee salaries, supplier contracts, and customer contact information. To ensure data security and improve system efficiency, the method of this invention is integrated into the enterprise's backend service architecture. First, the sensitive information acquisition and layered encryption module initiates a workflow, triggering a full scan of the field metadata of all tables in the enterprise management system database via a scheduled task. During the scan, a predefined sensitive tag library (e.g., a set of regular expressions containing keywords such as ID card number, bank card number, salary, and contract amount) is invoked to match and analyze each field name, annotation, and sample value, identifying sensitive data fields belonging to the financial, human resources, or customer categories, and generating a structured list of sensitive data. Subsequently, based on the list, the raw data is divided into three encryption layers: the core raw layer (stores unprocessed raw sensitive values, such as complete ID card numbers), the aggregation intermediate layer (stores anonymized or aggregated intermediate results, such as average departmental salaries), and the summary display layer (retains only statistical summaries used for report display, such as total number of employees and total expenditures). For these three layers, the module is configured with AES-256 symmetric encryption algorithm, the national cryptographic SM4 algorithm, and lightweight obfuscation algorithms (such as character substitution or hash truncation). Based on the access frequency in the business context (such as the HR department's high-frequency daily access to salary data) and compliance requirements (such as GDPR requiring strong protection of personal identification information), an independent key rotation cycle (e.g., every 24 hours for the core layer and every 7 days for the summary layer) and encryption computing resource quotas (such as CPU time slice percentage) are allocated to each layer. Finally, based on the generated hierarchical encryption strategy table, the corresponding level of encryption operation is performed on each sensitive field in the database, outputting structured encrypted data blocks, which are then written to a distributed storage node cluster based on the Raft consensus protocol to ensure data redundancy and consistency.

[0043] After encryption, the system enters the permission-driven data decryption and presentation module. When an enterprise user initiates a data query request through the front-end interface, the request is first intercepted by the authentication gateway. The gateway extracts the JWT (JSON Web Token) token from the HTTP request header and parses it to obtain the user ID, their role group (e.g., "Finance Specialist," "Department Manager"), and department affiliation information (e.g., "East China Sales Department"). This information is then passed to the permission decision engine, which integrates a hybrid RBAC (Role-Based Access Control) and ABAC (Attribute-Based Access Control) model: the RBAC part matches a preset permission template based on the user's role, while the ABAC part dynamically scores the user based on contextual attributes such as current time, geographical location, and device fingerprint. The engine combines the results from both parts to calculate the user's overall permission score (out of 100). If the score is 90 or higher (e.g., a company CFO or security auditor), the full decryption module is invoked, loading the AES-256 key corresponding to the core original layer. Reverse decryption is then performed on all three layers of data blocks to restore the original data for display. If the score is below 90 (e.g., a regular sales representative), only the lightweight obfuscation key for the summary display layer is loaded. The aggregation intermediate layer and the core original layer remain encrypted, and a de-identified summary view is returned (e.g., displaying only "salary range" instead of specific values). The decryption result is returned to the front end in structured JSON format, completing the data presentation.

[0044] While presenting the data, the system load monitoring and cost analysis module automatically collects the current thread's CPU utilization (read via the / proc / stat interface), heap memory usage (obtained via JVMMemoryMXBean), and disk I / O latency (sampled via the iostat command) after each encryption or decryption operation, using a performance probe embedded in the encryption service. These metrics, along with the operation type (e.g., core layer encryption, digest layer decryption), data block size, and timestamp, are written to a time-series database built on InfluxDB. A 5-minute sliding time window is used to calculate the moving average of the metric series for the same operation type, generating a unit data processing cost curve (e.g., average time of 180ms per MB for core layer encryption). When the unit cost of any operation type exceeds a preset threshold (e.g., 200ms / MB), the system determines that the operation is a high-load task and sends an optimization trigger signal to the next module.

[0045] Upon receiving a signal, the load balancing and encryption queue optimization module maintains a priority encryption task queue, where tasks are sorted by data sensitivity and urgency. When high load is detected, the module invokes a load balancing algorithm (such as weighted round-robin or least connections) to migrate some non-urgent encryption tasks (such as infrequently accessed customer history records) to standby computing nodes or postpone their execution to system idle periods. Simultaneously, the execution order of the encryption queue is re-planned, prioritizing requests from high-privilege users or data with high compliance requirements, thereby reducing the overall computational burden on the master node. The optimized encryption queue configuration is persistently stored and passed as input to the dynamic permission mapping and threat isolation module.

[0046] The dynamic permission mapping and threat isolation module first constructs a user-resource access graph, stored as a directed graph in the Neo4j graph database. Nodes include user entities (attributes include ID, role, and department) and data block entities (attributes include hierarchy, business domain, and encryption algorithm). Edges represent historical access relationships, and edge weights are determined by both access frequency and permission level (e.g., high-frequency, high-priority access has a weight of 10, while low-frequency, low-priority access has a weight of 1). When the system load is too high, a graph pruning algorithm is initiated, removing edges with weights below a threshold (e.g., 3) and shrinking the access radius of some non-critical users (e.g., restricting regional sales staff to accessing only customer data within their own region). Based on the pruned graph, the reachable data node set for each user is recalculated, generating a new access scope descriptor (e.g., JSON-formatted ACL rules). This descriptor is then injected into the API gateway's access control list, ensuring that subsequent user requests are filtered before routing, allowing only data blocks within the authorized subset to be accessed.

[0047] After the data access scope is updated, if cross-service data transmission is involved (such as the financial system pushing monthly reports to the BI platform), the transmission channel assessment and path configuration module will intervene. Before data transmission, the channel proxy component deployed in the service mesh collects current network status parameters, including available bandwidth (tested via iperf3), packet loss rate (statistically measured via ping), and TLS 1.3 handshake latency (analyzed via OpenSSL logs). These parameters are input into a pre-trained XGBoost channel quality assessment model, which outputs the current channel's adaptation score (range 0-1) for high-security (core raw layer), medium-security (aggregate intermediate layer), and low-security (digest display layer) data. If the adaptation score for high-security data is below 0.7 (indicating that the current channel has a risk of eavesdropping or man-in-the-middle attacks), the system automatically switches to the national cryptographic SM9 identifier cryptography protocol and enables dual-channel redundant transmission (the main channel uses an internal dedicated line, and the backup channel uses IPSecVPN). All channel configuration change events are recorded in the audit log and synchronized to the configuration center for subsequent rollback.

[0048] When data is transmitted through a secure channel, the data flow tracking and anomaly response module embeds a unique watermark (such as a UUIDv4 string) into the metadata of each data block when it is first generated by the encryption module. Subsequently, whenever the data block is transmitted across nodes (e.g., from a database node to an application server), the log plugin deployed in the Kafka message middleware records the source IP address, destination IP address, operator user ID, and a timestamp accurate to milliseconds. All flow records are written to a graph database in real time, constructing a directed acyclic lineage chain for the data block. The module deploys a graph neural network model based on GraphSAGE to perform real-time traversal analysis of the lineage chain, detecting unauthorized jumps (e.g., data flowing from the HR system to an unauthorized third-party API), high-frequency access (a single user accessing 5 different department data blocks within 10 seconds), or abnormal geographic location (a user's login location is Shanghai, China, but the data access source IP is located overseas). Once behavior matching a preset abnormal pattern is identified, the session management service is immediately invoked to freeze all active sessions of the user, and a distributed lock mechanism is used to block the associated data replicas to prevent further spread.

[0049] Finally, the system enters the business feedback aggregation and rule optimization module. This module periodically (e.g., daily at 2 AM) aggregates feedback data from multiple sources, including user operation logs (recording events such as export failures and invisible fields), customer service ticket systems (extracting complaints about missing details and insufficient report information), and security audit reports (marking risks such as excessive permissions and abnormal downloads). The module performs natural language processing on text-based feedback items, using the BERT model for intent recognition and entity extraction to identify the specific data fields involved (e.g., contract number), user roles (e.g., purchasing specialist), and desired presentation granularity (e.g., needing to view the full name of the supplier rather than an abbreviation). Subsequently, the module constructs a policy network based on a reinforcement learning framework (e.g., the PPO algorithm), using the information leakage risk reduction rate (calculated through simulated attack tests) and the user operation efficiency improvement rate (measured through task completion time) as a joint reward function to iteratively update the decryption strategy in the dynamic presentation rule base. The new rules will first be run in an isolated test environment. If no permission violation alerts are triggered for 7 consecutive days and the user satisfaction survey score increases by more than 5%, they will be gradually pushed to the production environment through a canary release mechanism, eventually achieving global policy synchronization and bringing the entire system into a new equilibrium state.

[0050] The modules mentioned above communicate loosely via message queues (such as RabbitMQ) and RESTful APIs. Internally, each module employs a microservice architecture, allowing for independent scaling. This entire process forms a closed-loop system encompassing data encryption, access control, load optimization, threat isolation, secure transmission, behavior monitoring, and rule evolution, ensuring that enterprises can operate efficiently while meeting increasingly stringent data security and compliance requirements.

[0051] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit the scope of protection of the present invention. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the essence and scope of the technical solutions of the present invention.

Claims

1. A method for optimizing an enterprise management system based on backend data, characterized in that: Includes the following steps: S1. Obtain sensitive information stored in the enterprise management system, and perform layered encryption processing on the sensitive information through a preset encryption algorithm to obtain an encrypted data block. The layered encryption algorithm divides multiple encryption levels according to the data type and determines the encryption strength of each encryption level to match business requirements. S2. Based on the obtained encrypted data blocks, the user identity information is captured using an access log recording mechanism. The permission level is extracted from the user identity information. If the permission level is higher than a preset threshold, all data blocks are directly decrypted; otherwise, only the data blocks with the summarized encryption level are decrypted to obtain the adjusted data presentation format. S3. By adjusting the data presentation format, obtain the real-time system load index, analyze the distribution of computing costs from the real-time system load index, and determine if the computing cost exceeds the preset threshold. Then, activate the load balancing algorithm to optimize the encryption process and determine the optimized encryption queue to reduce the overall burden. S4. Based on the determined optimized encryption queue, the access scope corresponding to the user identity is updated using a dynamic permission mapping model. Potential security threat features are extracted from the access scope. If the features match a preset pattern, the affected data blocks are isolated to obtain a protected dataset. S5. Obtain the status parameters of the transmission channel through the enhanced protection dataset, evaluate the multi-level requirement compliance from the status parameters, and determine if the compliance is lower than the preset threshold. Then, apply the transmission encryption protocol to adjust the channel configuration and determine a secure transmission path to maintain operational efficiency. S6. Based on the secure transmission path, a full lifecycle monitoring algorithm is used to track the data flow trajectory, identify abnormal access patterns from the data flow trajectory, and if an abnormal pattern occurs, trigger an alarm response mechanism to isolate the abnormal user's identity and obtain a clean system environment. S7. By purifying the system environment, obtain the summarized business requirement feedback, optimize the dynamic presentation rules from the business requirement feedback, determine if the risk of information leakage is reduced after the dynamic presentation rules are updated, then apply the dynamic presentation rules to all data blocks, and determine the final balance state to support the operation of the enterprise management system.

2. The method for optimizing an enterprise management system based on backend data according to claim 1, characterized in that: The layered encryption process includes data type identification, encryption level division, and encryption strength allocation. The adjusted data presentation format includes permission-driven decryption, data granularity control, and view reconstruction. The computational cost distribution analysis includes CPU utilization statistics, memory consumption monitoring, and disk latency measurement. The enhanced protection dataset includes access scope remapping, threat feature extraction, and isolation policy execution. The secure transmission path includes channel status assessment, dynamic protocol switching, and path redundancy configuration. The purified system environment includes trajectory backtracking analysis, abnormal behavior modeling, and identity isolation operations. The final equilibrium state includes rule version management, risk quantification verification, and global policy synchronization.

3. The method for optimizing an enterprise management system based on backend data according to claim 1, characterized in that: The process involves acquiring sensitive information stored in the enterprise management system, performing layered encryption on the sensitive information using a preset encryption algorithm, and obtaining encrypted data blocks. Specifically, the layered encryption algorithm divides the data into multiple encryption levels based on the data type, and determines the encryption strength of each encryption level to match business requirements. Scan the field metadata in the enterprise management system database, identify data fields belonging to the finance, human resources or customer categories based on a predefined sensitive tag library, and generate a list of sensitive data. Based on the aforementioned sensitive data list, the data is divided into three encryption layers: the core raw layer, the aggregation intermediate layer, and the digest display layer, which correspond to AES-256, SM4, and lightweight obfuscation algorithms, respectively. Based on the access frequency and compliance requirements in the business context, a corresponding key rotation cycle and encryption computing resource quota are allocated to each encryption level to generate a hierarchical encryption policy table. Based on the hierarchical encryption strategy table, the original data is encrypted field by field according to the corresponding encryption level, and the structured encrypted data block is output and written to the distributed storage node.

4. The method for optimizing an enterprise management system based on backend data according to claim 1, characterized in that: Based on the obtained encrypted data blocks, an access log recording mechanism is used to capture user identity information. The permission level is extracted from the user identity information. If the permission level is higher than a preset threshold, all data blocks are directly decrypted; otherwise, only the data blocks with the summarized encryption level are decrypted. The adjusted data presentation format is as follows: When a user initiates a data query request, the authentication gateway intercepts the JWT token in the request header and parses out the user ID, role group, and department affiliation information. The user ID is input into the permission decision engine, and the comprehensive permission score of the user is calculated by combining the RBAC and ABAC hybrid model. If the permission score is greater than or equal to 90, then the full decryption module is called to load the core original layer key and perform reverse decryption on all three encryption layers of data blocks; If the permission score is below 90, only the summary display layer key is loaded, the encryption status of the two encryption layers, the aggregation intermediate layer and the core original layer, is retained, and the de-identified summary view is returned.

5. The method for optimizing an enterprise management system based on backend data according to claim 1, characterized in that: The process involves obtaining real-time system load metrics through the adjusted data presentation format, analyzing the computational cost distribution from these metrics, and determining if the computational cost exceeds a preset threshold. If so, a load balancing algorithm is activated to optimize the encryption process, and an optimized encryption queue is identified to reduce the overall burden. Specifically, this involves: After each encryption or decryption operation is completed, the performance probe collects the CPU utilization, heap memory usage, and disk read / write latency of the current thread. The collected metrics are stored in a time-series database according to their timestamps, and associated with the corresponding operation type and data block size. A moving average of the indicator series within the most recent 5 minutes is calculated using a sliding time window to generate unit data processing cost curves for each operation type. If the unit cost of any operation type exceeds a preset threshold, the operation is marked as a high-load task, triggering subsequent optimization processes.

6. The method for optimizing an enterprise management system based on backend data according to claim 1, characterized in that: The process of updating the access scope corresponding to the user identity using a dynamic permission mapping model based on the determined optimized encryption queue, extracting potential security threat features from the access scope, and determining whether the features match a preset pattern, then isolating the affected data blocks to obtain the enhanced protection dataset, specifically involves: Construct a user-resource access graph, where nodes represent users or data blocks, and edge weights represent historical access frequency and permission levels; When the system load is too high, the graph pruning algorithm is activated to remove low-frequency access edges and shrink the access radius of some users. Based on the shrunk graph, the set of reachable data nodes for each user is recalculated to generate a new access range descriptor; Inject the descriptor into the access control list to restrict subsequent requests to only hit data blocks within the authorized subset.

7. The method for optimizing an enterprise management system based on backend data according to claim 1, characterized in that: The process involves obtaining transmission channel status parameters from the enhanced protection dataset, evaluating multi-level requirement compliance from these parameters, and determining if the compliance is below a preset threshold. Specifically, this process involves applying a transmission encryption protocol to adjust the channel configuration and determine a secure transmission path to maintain operational efficiency. Before data is transmitted across services, the channel proxy module collects the current network bandwidth, packet loss rate, and TLS handshake latency. The parameters are input into a pre-trained channel quality assessment model, which outputs the current channel's adaptation score for high-density, medium-density, and low-density data. If the compatibility score of high-density data is below 0.7, it will automatically switch to the national cryptographic SM9 protocol and enable dual-channel redundant transmission. At the same time, channel configuration change events are recorded for subsequent auditing and policy rollback.

8. The method for optimizing an enterprise management system based on backend data according to claim 1, characterized in that: The process involves using a secure transmission path and a full lifecycle monitoring algorithm to track data flow, identifying abnormal access patterns from the data flow trajectory, and triggering an alarm response mechanism to isolate the abnormal user if an abnormal pattern occurs, thereby achieving a cleaned system environment. A unique watermark is embedded when each data block is first generated, and the source address, destination address, operator, and timestamp are recorded by the log middleware during each cross-node transmission. Construct all flow records into a directed acyclic graph to represent the complete lineage of this data block; The deployment graph neural network model traverses the lineage chain in real time to detect unauthorized redirects, high-frequency access, or abnormal geographic locations. Once a behavior matching a preset abnormal pattern is identified, the user session is immediately frozen and its associated data copy is blocked.

9. The method for optimizing an enterprise management system based on backend data according to claim 1, characterized in that: The process involves purifying the system environment, obtaining aggregated business requirement feedback, optimizing dynamic presentation rules based on this feedback, and determining if the risk of information leakage is reduced after updating the dynamic presentation rules. If so, the dynamic presentation rules are applied to all data blocks to determine the final balance state to support the operation of the enterprise management system. Specifically, this process is as follows: Regularly aggregate user operation logs, customer service tickets, and security audit reports to extract feedback items regarding insufficient data visibility or information overload; Natural language processing is performed on the feedback items to identify the specific data fields, user roles, and expected presentation granularity involved. Based on a reinforcement learning framework, the rule base is dynamically updated iteratively, with the reward function being the rate of decrease in information leakage risk and the rate of improvement in user operation efficiency. If a new dynamic presentation rule does not trigger permission violations and user satisfaction increases by more than 5% for 7 consecutive days in the test environment, it will be pushed to the production environment for full implementation.

10. The method for optimizing an enterprise management system based on backend data according to claim 1, characterized in that: The load balancing algorithm is either a weighted round-robin algorithm or a minimum number of connections algorithm.

Citation Information

Patent Citations

  • Data management method and system based on data resource security identification level

    CN119442320A

  • Intelligent management method for cloud storage access authority based on reinforcement learning

    CN119538288A

  • A communication protocol intelligent switching method and system for omni-channel contact center

    CN119788751A

  • Industrial control system security auditing method and system

    CN120930143A

  • Security protection method and apparatus for customer service management system

    WO2025222719A1