Enterprise financial data security management system and method

By implementing hierarchical encryption and placeholder replacement for corporate financial data, combined with cloud-based verification and decryption technology, the security and efficiency issues of data sharing in corporate financial data security management are resolved, achieving secure and efficient data sharing.

CN122020686APending Publication Date: 2026-05-12YONGLANG GRP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
YONGLANG GRP
Filing Date
2026-01-23
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

In existing technologies, enterprise financial data security management solutions pose a risk of leakage when high-privilege users share highly sensitive data during the data sharing process. Furthermore, when low-privilege users share data with high-privilege users, the manual desensitization process is cumbersome, reducing the security and efficiency of data sharing with external business partners.

Method used

By employing hierarchical encryption technology, enterprise financial data is marked with sensitivity levels and encrypted hierarchically, generating hierarchically encrypted data. After replacing the data with placeholders, a document is generated. The document is then verified and decrypted in the cloud to fill in the user's permission content, thus achieving secure data sharing.

Benefits of technology

It enables convenient data sharing and circulation while ensuring data security, reduces the risk of encrypted data leakage, and improves the security and efficiency of data sharing with external partners.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122020686A_ABST
    Figure CN122020686A_ABST
Patent Text Reader

Abstract

The invention discloses an enterprise financial data security management system and method, and relates to the technical field of financial data management, and the method comprises the steps: collecting enterprise financial data needing to be shared, marking the business type, sensitivity level and data mode corresponding to the enterprise financial data, and generating financial sharing and marking data; selecting a proper preset document template based on the data modality, and generating document template sample data; according to the method, the enterprise financial data are subjected to hierarchical encryption, the data subjected to hierarchical encryption are replaced by the placeholders, common documents in various formats are generated, and shared users log in the specified cloud through identity verification; after the shared document is uploaded, the cloud end can decrypt the enterprise financial data which conforms to the identity authority according to the authority of the verified identity and then fill the enterprise financial data into the position of the corresponding placeholder, so that the shared user can obtain the encrypted data which conforms to the authority, and the risk of leakage of the encrypted data is reduced at the same time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of financial data management technology, specifically to an enterprise financial data security management system and method. Background Technology

[0002] In current financial data security management practices, the "server-side dynamic generation" approach has become the mainstream technical approach. The core of this approach is to retain core data and access control logic entirely on the server side, while the client (such as a browser) only receives and displays the final view (such as PDF, image, or HTML in a specific format) dynamically generated by the server. This ensures that the client receives a "snapshot of the result" that does not contain underlying sensitive data, and the security boundary is strictly limited to the server, effectively preventing the leakage of the original data.

[0003] However, the existing technologies mentioned above also have drawbacks. It is inconvenient for the recipient to share the "snapshot" again after receiving it. For example, if the "snapshot" received by a recipient with high privileges contains highly sensitive data, it is easy to cause data leakage if it is directly shared with other users. Manually desensitizing highly sensitive data is cumbersome. Even if a recipient with low privileges shares the "snapshot" with a user with high privileges, the user with high privileges cannot obtain encrypted data with higher privileges than the sharer and still needs to apply to the data source. This greatly reduces the security or efficiency of sharing corporate financial data with external business partners to complete related business. Summary of the Invention

[0004] The purpose of this invention is to provide a corporate financial data security management system and method to address the aforementioned shortcomings in the prior art.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a method for enterprise financial data security management, comprising the following steps:

[0006] S1. Collect the financial data of the enterprises that need to be shared, and label the business type, sensitivity level and data modality corresponding to the financial data to generate financial sharing and labeling data;

[0007] S2. Select a suitable preset document template based on the data modality and generate document template sample data;

[0008] S3. Collect the shared user information and the business type and sensitivity level data corresponding to the shared user information, and generate the shared user permission data;

[0009] S4. The enterprise financial data is subjected to hierarchical encryption processing according to the corresponding sensitivity level to generate hierarchically encrypted data; furthermore, hierarchical encryption can select different encryption algorithms for encryption according to the different sensitivity levels of the enterprise financial data.

[0010] S5. Fill the enterprise financial data into the corresponding position of the corresponding document template sample data according to the template format, and use placeholders to fill and update the position of the enterprise financial data corresponding to the hierarchical encrypted data in the document template sample data (that is, the enterprise financial data corresponding to the hierarchical encrypted data filled in the document template sample data is covered by the placeholders, and the enterprise financial data corresponding to the hierarchical encrypted data no longer exists in the document template sample data). Generate a shared document and send it to the shared user after assigning a unique document identification code to each shared document.

[0011] S6. While generating the shared document, record the unique document identifier of each shared document, the position of each placeholder, the corresponding hierarchical encrypted data, the sensitivity level and the business type, and generate a shared document information directory.

[0012] S7. Based on the received shared document uploaded by the shared user, the shared user's permission data, and the shared document information directory, fill the corresponding position of the shared document with hierarchical encrypted data that conforms to the user's permissions.

[0013] Furthermore, S2 includes the following steps:

[0014] S2.1 Collect historical corporate financial data according to the data modal (such as Excel, PDF, etc.) of the corporate financial data, and obtain a set of modal corporate financial data that corresponds one-to-one with the number of data modalities;

[0015] S2.2. Perform feature extraction and normalization on the financial data of each modal enterprise in each set of modal enterprise financial data to generate a set of feature vectors for the corresponding modal enterprise financial data.

[0016] S2.3. Perform cluster analysis on the feature vectors of financial data of enterprises in each modality's financial data feature vector set to obtain multiple modality financial data feature clusters, and record the center vector of the corresponding modality feature cluster; when performing feature extraction, for example, for structured data such as Excel / CSV, features such as table headers and row and column structures can be extracted; for PDF / scanned documents, OCR is used to recognize text and layout; for Word / PPT, styles, paragraphs and tables are extracted;

[0017] S2.3. Based on one or more modal enterprise financial data feature clusters corresponding to the same data modality and the corresponding modal enterprise financial data, a corresponding modal document template sample is set through manual review, and modal document template sample data is generated, so that each data modality of enterprise financial data corresponds to at least one modal document template sample data; furthermore, a candidate template can be automatically recommended for each modal enterprise financial data feature cluster (such as selecting the "highest quality" historical document within the cluster).

[0018] S2.4 Collect all modal document template sample data and generate a document template sample data set;

[0019] S2.5. Based on the data modalities annotated in the financial sharing and annotation data, perform feature extraction and normalization on the enterprise financial data in the financial sharing and annotation data to obtain the corresponding modal enterprise financial data feature vector, and generate the modal enterprise financial sharing data feature vector.

[0020] S2.6. Calculate the vector distance between the feature vector of the modal enterprise financial shared data and the center vector of each modal feature cluster corresponding to the same data modality. Select the modal document template sample data corresponding to the modal enterprise financial data feature cluster with the smallest vector distance, and generate the corresponding document template sample data. The vector distance can be obtained by calculating the Euclidean distance or cosine distance between vectors.

[0021] Furthermore, S5 includes the following steps:

[0022] S5.1 Manually fill in the historical enterprise financial data into the corresponding positions in the corresponding historical modal document template sample data to generate the corresponding historical modal document data;

[0023] S5.2. Using historical corporate financial data and corresponding historical modal document template sample data as input, and corresponding historical modal document data as output, train a neural network model to obtain a financial data-template mapping model; the neural network model can be selected, such as LayoutLM, TAPAS, MATCHA, etc.

[0024] S5.3 Input the enterprise financial data and corresponding document template sample data from the financial sharing and annotation data into the financial data-template mapping model. The financial data-template mapping model fills the input enterprise financial data into the corresponding positions in the input document template sample data to generate document data.

[0025] S5.4 Use placeholders to fill in the position of the enterprise financial data corresponding to the hierarchical encrypted data in the document data, and generate the corresponding shared document;

[0026] S5.5 Generate a unique document identifier for each shared document and mark the corresponding unique document identifier on the shared document. The unique document identifier can be marked on the shared document by adding watermarks or editing headers and footers.

[0027] S5.6. Send the shared document to the user to whom it is shared.

[0028] Furthermore, S4 includes the following steps:

[0029] S4.1 Set the encryption and decryption algorithms for each sensitivity level and generate a sensitivity level-encryption and decryption algorithm comparison table;

[0030] S4.2 Search the sensitivity level-encryption / decryption algorithm comparison table for the encryption / decryption algorithm corresponding to the sensitivity level of each enterprise's financial data in the financial sharing and labeled data, and generate target encryption / decryption algorithm data for each enterprise's financial data;

[0031] S4.3. Use the enterprise financial data target encryption and decryption algorithm to encrypt the corresponding enterprise financial data and generate corresponding hierarchical encrypted data.

[0032] Furthermore, the financial sharing and annotation data, document template sample data, shared user permission data, hierarchical encrypted data, and shared document information directory, as well as the various encryption and decryption algorithms used to encrypt and decrypt the hierarchical encrypted data, are uploaded and stored in the cloud.

[0033] Furthermore, S7 includes the following steps:

[0034] S7.1 The shared user logs into the cloud by verifying their identity through the corresponding shared user information; for example: the shared user enters the shared user information through the user terminal, the user terminal sends the entered shared user information to the cloud, the cloud verifies the entered shared user information based on the saved shared user permission data, if they match, the verification is successful and the shared user is allowed to log in to the cloud, if they do not match, the verification fails and the shared user is denied to log in to the cloud.

[0035] S7.2 Upload the received shared document to the cloud; or upload the unique document identifier of the shared document to the cloud;

[0036] S7.3 The cloud searches the shared user permission data to find the business type and sensitivity level data that match the shared user information, and obtains the target business type and sensitivity level data;

[0037] S7.4 If the user uploads a unique document identifier, the corresponding shared document is first retrieved based on the unique document identifier. Then, the location of the hierarchical encrypted data and placeholders corresponding to the target business type and sensitivity level data in the shared document information directory is searched. The corresponding hierarchical encrypted data is decrypted and filled into the corresponding placeholder location in the shared document to generate a user permission content document. This allows the user to view hierarchical encrypted data that matches their business type and sensitivity level in the shared document after identity verification.

[0038] Furthermore, S7 can also include the following steps:

[0039] Based on the unique identifier of the document uploaded by the user being shared, the user's permission data, and the shared document information directory, hierarchical encrypted data conforming to user permissions is filled into the corresponding position of the shared document.

[0040] A corporate financial data security management system, comprising a user terminal and a cloud terminal;

[0041] The user terminal and the cloud are connected via the Internet;

[0042] The user terminal is used to collect data, upload it to the cloud, and visualize the data.

[0043] The cloud is used to store and process data. The cloud also stores computer programs, which are executed to implement a method for secure management of corporate financial data.

[0044] 1. Compared with the prior art, the present invention provides an enterprise financial data security management system and method, which encrypts enterprise financial data in a hierarchical manner and replaces the encrypted data with placeholders to generate ordinary documents in various formats for sharing with users who are not affiliated with the enterprise but have cooperation with it. This allows the users to view the unencrypted part of the enterprise financial data through any browser, reader, etc., which facilitates the sharing and circulation of data.

[0045] 2. After the shared user logs in to the designated cloud after verifying their identity and uploads the shared document, the cloud can decrypt the hierarchically encrypted corporate financial data that matches the verified identity's permissions and fill it into the corresponding placeholder position. This ensures that the shared user can obtain encrypted data that matches their permissions, while reducing the risk of encrypted data leakage. Attached Figure Description

[0046] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0047] Figure 1 This is a schematic diagram of the method steps provided in an embodiment of the present invention;

[0048] Figure 2 This is a system structure block diagram provided for an embodiment of the present invention. Detailed Implementation

[0049] To enable those skilled in the art to better understand the technical solution of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings.

[0050] In the description of this invention, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the stated features. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified. Exemplary embodiments will be described more fully below with reference to the accompanying drawings; however, these exemplary embodiments may be embodied in different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will enable those skilled in the art to fully understand the scope of this disclosure.

[0051] Where there is no conflict, the various embodiments of this disclosure and the features thereof in the embodiments may be combined with each other.

[0052] As used herein, the term “and / or” includes any and all combinations of one or more related enumerated entries.

[0053] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. As used herein, the singular forms “a” and “the” are also intended to include the plural forms unless the context clearly indicates otherwise. It will also be understood that when the terms “comprising” and / or “made of” are used in this specification, the presence of the stated feature, integral, step, operation, element, and / or component is specified, but the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or groups thereof is not excluded.

[0054] The embodiments described herein can be described with reference to plan and / or cross-sectional views using the ideal schematic diagrams of this disclosure. Therefore, the example illustrations may be modified according to manufacturing techniques and / or tolerances. Thus, the embodiments are not limited to those shown in the accompanying drawings, but include modifications to configurations formed based on manufacturing processes. Unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art.

[0055] Please see Figure 1 A method for managing the security of enterprise financial data includes the following steps:

[0056] S1. Collect the financial data of the enterprises that need to be shared, and label the business type, sensitivity level and data modality of the financial data to generate financial sharing and labeled data;

[0057] Specifically, the financial data necessary for completing a specific business activity such as managing or auditing corporate financial data is tagged with the corresponding business type label. For example, auditing "Accrued Employee Compensation" requires a list of employees and total compensation; therefore, the financial data corresponding to "Employee Name" and "Employee Monthly Salary" is tagged "Accrued Employee Compensation Audit." The sensitivity level of corporate financial data can be set according to the company's actual needs. For instance, three sensitivity levels can be set, from most important to least important: Level 1, Level 2, and Level 3. For example, Level 1 sensitivity might include core personnel compensation data and bank account information (such as bank account numbers, USB key passwords, and large-scale fund transfer plans); Level 2 sensitivity might include product / department cost details, budget drafts, detailed customer transaction records, supplier purchase price lists, sales details, inventory details, and gross profit margin analysis tables; Level 3 sensitivity might include published annual reports, audit reports, and summary performance charts used for internal publicity. Data formats include Excel, CSV, PDF, scanned copies, Word, and PPT.

[0058] S2. Select a suitable preset document template based on the data modality and generate document template sample data. The preset document template can be selected manually or through the following steps:

[0059] S2.1 Collect historical corporate financial data according to the data modal (such as Excel, PDF, etc.) of the corporate financial data, and obtain a set of modal corporate financial data that corresponds one-to-one with the number of data modalities;

[0060] S2.2. Perform feature extraction and normalization on the financial data of each modal enterprise in each set of modal enterprise financial data to generate a set of feature vectors for the corresponding modal enterprise financial data.

[0061] S2.3. Perform cluster analysis on the feature vectors of financial data of enterprises in each modality's financial data feature vector set to obtain multiple modality financial data feature clusters, and record the center vector of the corresponding modality feature cluster; when performing feature extraction, for example, for structured data such as Excel / CSV, features such as table headers and row and column structures can be extracted; for PDF / scanned documents, OCR is used to recognize text and layout; for Word / PPT, styles, paragraphs and tables are extracted;

[0062] S2.3. Based on one or more modal enterprise financial data feature clusters corresponding to the same data modality and the corresponding modal enterprise financial data, a corresponding modal document template sample is set through manual review, and modal document template sample data is generated, so that each data modality of enterprise financial data corresponds to at least one modal document template sample data; furthermore, a candidate template can be automatically recommended for each modal enterprise financial data feature cluster (such as selecting the "highest quality" historical document within the cluster).

[0063] S2.4 Collect all modal document template sample data and generate a document template sample data set;

[0064] S2.5. Based on the data modalities annotated in the financial shared and labeled data, perform feature extraction and normalization on the enterprise financial data in the financial shared and labeled data to obtain the corresponding modal enterprise financial data feature vectors and generate modal enterprise financial shared data feature vectors.

[0065] S2.6 Calculate the vector distance between the feature vector of the modal enterprise financial shared data and the center vector of each modal feature cluster corresponding to the same data modality. Select the modal document template sample data corresponding to the modal enterprise financial data feature cluster whose center vector has the smallest vector distance, and generate the corresponding document template sample data. The vector distance can be obtained by calculating the Euclidean distance or cosine distance between vectors.

[0066] S3. Collect the information of the shared users and the business type and sensitivity level data corresponding to the shared user information, and generate the permission data of the shared users; for example, "Shared User 1" is responsible for the business type "Accrued Employee Compensation Audit Business", and its permission is to allow viewing of Level 2 and Level 3 sensitivity levels; the information of the shared users includes the shared username, account, password, and identity profile.

[0067] S4. Based on the corresponding sensitivity level, perform hierarchical encryption processing on the enterprise's financial data to generate hierarchically encrypted data, including the following steps:

[0068] S4.1 Set the encryption and decryption algorithms for each sensitivity level and generate a sensitivity level-encryption and decryption algorithm comparison table;

[0069] S4.2 Search the sensitivity level-encryption / decryption algorithm comparison table for the encryption / decryption algorithm corresponding to the sensitivity level of each enterprise's financial data in the financial shared and labeled data, and generate target encryption / decryption algorithm data for each enterprise's financial data;

[0070] S4.3. Use the enterprise financial data target encryption and decryption algorithm to encrypt the corresponding enterprise financial data and generate corresponding hierarchical encrypted data.

[0071] Furthermore, hierarchical encryption can select different encryption algorithms based on the different sensitivity levels of the enterprise's financial data. For example, for level 1 sensitivity, algorithms such as SM4, SM3, AES-256, or RSA-3072 / 4096 can be used for encryption and decryption; for level 2 sensitivity, algorithms such as AES-256, AES-128, or RSA-2048 can be used for encryption and decryption; and for level 3 sensitivity, AES-128 can be used for encryption and decryption.

[0072] S5. According to the template format, fill the corresponding positions of the enterprise financial data into the corresponding document template sample data. Use placeholders to fill and update the position of the enterprise financial data corresponding to the hierarchical encrypted data in the document template sample data (that is, the enterprise financial data corresponding to the hierarchical encrypted data filled in the document template sample data is covered by the placeholders, and the enterprise financial data corresponding to the hierarchical encrypted data no longer exists in the document template sample data). Generate a shared document and assign a unique document identification code to each shared document before sending it to the shared user. This includes the following steps:

[0073] S5.1 Manually fill in the historical enterprise financial data into the corresponding positions in the corresponding historical modal document template sample data to generate the corresponding historical modal document data;

[0074] S5.2. Using historical corporate financial data and corresponding historical modal document template sample data as input, and corresponding historical modal document data as output, train a neural network model to obtain a financial data-template mapping model; the neural network model can be selected, such as LayoutLM, TAPAS, MATCHA, etc.

[0075] S5.3 Input the enterprise financial data and corresponding document template sample data from the financial shared and labeled data into the financial data-template mapping model. The financial data-template mapping model will fill the input enterprise financial data into the corresponding positions in the input document template sample data to generate document data.

[0076] S5.4 Use placeholders to fill in the position of the enterprise financial data corresponding to the hierarchical encrypted data in the document data, and generate the corresponding shared document;

[0077] S5.5 Generate a unique document identifier for each shared document and mark the corresponding unique document identifier on the shared document. The unique document identifier can be marked on the shared document by adding watermarks or editing headers and footers.

[0078] S5.6 Send the shared document to the user who will share it.

[0079] S6. While generating shared documents, record the unique document identifier of each shared document, the position of each placeholder, the corresponding hierarchical encrypted data, the sensitivity level and business type, and generate a shared document information directory.

[0080] Furthermore, financial sharing and annotation data, document template sample data, shared user permission data, hierarchical encrypted data and shared document information directory, as well as various encryption and decryption algorithms used to encrypt and decrypt hierarchical encrypted data are uploaded and stored in the cloud.

[0081] S7. Based on the received shared document uploaded by the shared user, the shared user's permission data, and the shared document information directory, fill the corresponding location of the shared document with hierarchically encrypted data that conforms to the user's permissions. Alternatively, based on the received document unique identifier uploaded by the shared user, the shared user's permission data, and the shared document information directory, fill the corresponding location of the shared document with hierarchically encrypted data that conforms to the user's permissions.

[0082] Specifically, the following steps are included:

[0083] S7.1 The shared user logs into the cloud by verifying their identity through the corresponding shared user information; for example: the shared user enters the shared user information through the user terminal, the user terminal sends the entered shared user information to the cloud, the cloud verifies the entered shared user information based on the saved shared user permission data, if the match is passed the verification is passed and the shared user is allowed to log in to the cloud, if the match is not passed the verification is failed and the shared user is denied to log in to the cloud.

[0084] S7.2 Upload the received shared document to the cloud; or upload the unique document identifier of the shared document to the cloud;

[0085] S7.3 The cloud searches the shared user permission data to find the business type and sensitivity level data that match the shared user information, and obtains the target business type and sensitivity level data;

[0086] S7.4 If the user uploads a unique document identifier, first retrieve the corresponding shared document based on the unique document identifier. Then, search the shared document information directory for the location of the hierarchical encrypted data and placeholders corresponding to the target business type and sensitivity level data in the shared document. Based on the sensitivity level-encryption / decryption algorithm lookup table, decrypt the corresponding hierarchical encrypted data using the corresponding encryption / decryption algorithm and fill it into the location of the corresponding placeholder in the shared document to generate a user-permitted content document. This allows the user to view hierarchical encrypted data that matches their business type and sensitivity level in the shared document after identity verification.

[0087] Please see Figure 2 A corporate financial data security management system, including a user terminal and a cloud platform;

[0088] The user terminal and the cloud are connected via the Internet;

[0089] The user-side application is used to collect data, upload it to the cloud, and visualize the data.

[0090] The cloud is used to store and process data. It also stores computer programs, which are then executed to implement a method for secure management of corporate financial data.

[0091] The foregoing has only described certain exemplary embodiments of the present invention by way of illustration. Undoubtedly, those skilled in the art can modify the described embodiments in various ways without departing from the spirit and scope of the present invention. Therefore, the foregoing drawings and descriptions are illustrative in nature and should not be construed as limiting the scope of protection of the claims of the present invention.

Claims

1. A method for managing the security of enterprise financial data, characterized in that, Includes the following steps: S1. Collect the financial data of the enterprises that need to be shared, and label the business type, sensitivity level and data modality corresponding to the financial data to generate financial sharing and labeling data; S2. Select a suitable preset document template based on the data modality and generate document template sample data; S3. Collect the shared user information and the business type and sensitivity level data corresponding to the shared user information, and generate the shared user permission data; S4. Based on the corresponding sensitivity level, perform hierarchical encryption processing on the enterprise's financial data to generate hierarchically encrypted data; S5. Fill the enterprise financial data into the corresponding position of the corresponding document template sample data according to the template format, use placeholders to fill and update the position of the enterprise financial data corresponding to the hierarchical encrypted data in the document template sample data, generate a shared document, assign a unique document identification code to each shared document, and then send it to the shared user. S6. While generating the shared document, record the unique document identifier of each shared document, the position of each placeholder, the corresponding hierarchical encrypted data, the sensitivity level and the business type, and generate a shared document information directory. S7. Based on the received shared document uploaded by the shared user, the shared user's permission data, and the shared document information directory, fill the corresponding position of the shared document with hierarchical encrypted data that conforms to the user's permissions.

2. The enterprise financial data security management method according to claim 1, characterized in that, S2 includes the following steps: S2.1 Collect historical enterprise financial data according to the data modes of enterprise financial data to obtain a set of enterprise financial data with modalities that correspond one-to-one with the number of data modes; S2.

2. Perform feature extraction and normalization on the financial data of each modal enterprise in each set of modal enterprise financial data to generate a set of feature vectors for the corresponding modal enterprise financial data. S2.

3. Perform cluster analysis on the feature vectors of financial data of enterprises in each modality's financial data feature vector set to obtain multiple feature clusters of financial data of enterprises in each modality, and record the center vector of the corresponding feature cluster. S2.3 Based on one or more modal enterprise financial data feature clusters corresponding to the same data modality and the corresponding modal enterprise financial data, a corresponding modal document template sample is set through manual review, and modal document template sample data is generated. S2.4 Collect all modal document template sample data and generate a document template sample data set; S2.

5. Based on the data modalities annotated in the financial sharing and annotation data, perform feature extraction and normalization on the enterprise financial data in the financial sharing and annotation data to obtain the corresponding modal enterprise financial data feature vector, and generate the modal enterprise financial sharing data feature vector. S2.6 Calculate the vector distance between the feature vector of the modal enterprise financial shared data and the center vector of each modal feature cluster corresponding to the same data modality, select the modal document template sample data corresponding to the center vector of the modal feature cluster with the smallest vector distance, and generate the corresponding document template sample data.

3. The enterprise financial data security management method according to claim 1, characterized in that, S5 includes the following steps: S5.1 Manually fill in the historical enterprise financial data into the corresponding positions in the corresponding historical modal document template sample data to generate the corresponding historical modal document data; S5.

2. Using historical corporate financial data and corresponding historical modal document template sample data as input, and corresponding historical modal document data as output, train a neural network model to obtain a financial data-template mapping model. S5.3 Input the enterprise financial data and corresponding document template sample data from the financial sharing and annotation data into the financial data-template mapping model to generate document data; S5.4 Use placeholders to fill in the position of the enterprise financial data corresponding to the hierarchical encrypted data in the document data, and generate the corresponding shared document; S5.

5. Generate a unique document identifier for each shared document and mark the corresponding unique document identifier on the shared document; S5.

6. Send the shared document to the user to whom it is shared.

4. The enterprise financial data security management method according to claim 1, characterized in that, S4 includes the following steps: S4.1 Set the encryption and decryption algorithms for each sensitivity level and generate a sensitivity level-encryption and decryption algorithm comparison table; S4.2 Search the sensitivity level-encryption / decryption algorithm comparison table for the encryption / decryption algorithm corresponding to the sensitivity level of each enterprise's financial data in the financial sharing and labeled data, and generate target encryption / decryption algorithm data for each enterprise's financial data; S4.

3. Use the enterprise financial data target encryption and decryption algorithm to encrypt the corresponding enterprise financial data and generate corresponding hierarchical encrypted data.

5. The enterprise financial data security management method according to claim 1, characterized in that, The financial sharing and annotation data, document template sample data, shared user permission data, hierarchical encrypted data and shared document information directory, as well as the various encryption and decryption algorithms used to encrypt and decrypt the hierarchical encrypted data, are uploaded and stored in the cloud.

6. The enterprise financial data security management method according to claim 5, characterized in that, S7 includes the following steps: S7.1 The shared user logs in to the cloud by verifying their identity using the corresponding shared user information; S7.2 Upload the received shared document to the cloud; S7.3 The cloud searches the shared user permission data to find the business type and sensitivity level data that match the shared user information, and obtains the target business type and sensitivity level data; S7.4 Search the shared document information directory for the location of the hierarchical encrypted data and placeholders corresponding to the target business type and sensitivity level data in the shared document, and decrypt the corresponding hierarchical encrypted data and fill it into the location of the corresponding placeholder in the shared document to generate a user permission content document.

7. The enterprise financial data security management method according to claim 1, characterized in that, S7 may also include the following steps: Based on the unique identifier of the document uploaded by the user being shared, the user's permission data, and the shared document information directory, hierarchical encrypted data conforming to user permissions is filled into the corresponding position of the shared document.

8. A corporate financial data security management system, used to execute the corporate financial data security management method according to any one of claims 1-7, characterized in that, Including the client-side and the cloud; The user terminal is connected to the cloud via the Internet. The user terminal is used to collect data, upload it to the cloud, and visualize the data. The cloud is used to store and process data, and also stores computer programs. The computer programs are executed to implement the enterprise financial data security management method according to any one of claims 1-7.