A network security treatment control method and system based on service promotion cross-section convergence
Patent Information
- Application Number
- CN202610605577.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-06
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2046-05-06
AI Technical Summary
[0005]鉴于上述实际情况,本申请提出了一种基于业务推进截面收束的网络安全处置控制方法及其系统,以解决现有技术中存在的网络安全处置偏向单点异常拦截,难以确定业务对象已经进入的业务作用范围,难以同时识别前向推进越界和逆向回写越界,并难以对业务对象的前向推进作用范围和逆向回写作用范围执行递进式闭合收束控制的问题
[0049]The network security handling control method and system proposed in this application based on business advancement section convergence realizes unified identification and alignment of the current processing section, forward expansion section, and reverse write-back section of the target business object. This enables the forward advancement over-boundary and reverse write-back over-boundary of the target business object to be associated and marked. By performing convergence control on the forward action node and the write-back action node through the section progressive convergence gating sequence, a closed-loop network security handling control is formed for the forward advancement action range and the reverse write-back action range of the business object without relying on the overall freezing of the business object.
Smart Images

Figure CN122475913B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of network security and business process security control technology, and in particular to a network security handling control method and system based on business advancement section convergence. Background Technology
[0002] In business environments such as customer relationship management, order management, supply chain collaboration, approval workflows, settlement write-back, and cross-system interface integration, business objects typically advance continuously along business processes, playing roles of reception, collaboration, execution, and write-back at different processing stages. The target business object involves multiple processing nodes, collaboration nodes, and write-back nodes during its advancement. Its security risks may not necessarily manifest as a single access anomaly but can gradually expand their impact as the business status evolves. Especially in cross-system collaboration scenarios, abnormal order modifications, abnormal approval triggers, abnormal interface calls, or abnormal write-back results can all continue to expand along the business advancement chain, thereby affecting the scope of subsequent processing and the status of preceding systems. Therefore, it is necessary to more precisely identify and control the scope of influence of business objects in the forward advancement and reverse write-back processes.
[0003] Network security response methods typically use account anomalies, API call anomalies, access control anomalies, business request anomalies, or single-point alarm events as entry points. Upon detecting abnormal behavior, actions such as blocking, freezing, rollback, issuing alarms, or manual review are taken against the relevant accounts, APIs, objects, or processes. These methods primarily focus on judging single access behaviors, individual risk nodes, or single business events, determining the appropriate action through permission verification, rule matching, risk scoring, or log auditing, and applying the results to the corresponding accounts, business objects, API call chains, or business process nodes.
[0004] The above-mentioned processing methods tend to intercept single-point anomalies, making it difficult to determine the scope of business action that the business object has entered. When the business object has entered multiple receiving nodes, collaborative nodes, or result write-back nodes, it is difficult to simultaneously identify its forward advance boundary violation and reverse write-back boundary violation. After the action is generated, it is also difficult to perform progressive closed-loop control on the forward advance scope and reverse write-back scope of the business object based on the correlation between the cross section where the business object is located, the forward expansion scope, and the reverse write-back scope. Summary of the Invention
[0005] In view of the above-mentioned actual situation, this application proposes a network security handling control method and system based on business advancement section convergence, in order to solve the problems existing in the prior art that network security handling is biased towards single-point anomaly interception, it is difficult to determine the business scope that the business object has entered, it is difficult to simultaneously identify forward advancement overbound and reverse write-back overbound, and it is difficult to perform progressive closed convergence control on the forward advancement scope and reverse write-back scope of the business object.
[0006] A network security handling and control method based on business advancement cross-section convergence includes:
[0007] The system acquires business advancement trajectory data, acceptance security baseline map data, and write-back security baseline map data corresponding to the target business object. It performs advancement stage positioning processing on the business advancement trajectory data to obtain advancement stage node data and object advancement identifier data. Based on the node positions of the advancement stage node data in the acceptance security baseline map data, it performs cross-sectional mapping processing to generate current processing cross-sectional data. The current processing cross-sectional data is used to characterize the business scope that the target business object has entered.
[0008] Using the current processing cross-sectional data as the cross-sectional reference, forward expansion cross-sectional data is constructed based on the receiving safety reference map data, and reverse write-back cross-sectional data is constructed based on the write-back safety reference map data. The forward expansion cross-sectional data and the reverse write-back cross-sectional data are then aligned according to the object advancement identification data to obtain advancement write-back cross-sectional aligned data.
[0009] Using the aforementioned safety baseline map data as the forward boundary verification baseline, the forward extension section in the propulsion write-back section alignment data is subjected to propulsion boundary crossing identification to obtain propulsion boundary crossing marker data; using the write-back safety baseline map data as the write-back boundary verification baseline, the reverse write-back section in the propulsion write-back section alignment data is subjected to write-back boundary crossing identification to obtain write-back boundary crossing marker data, and the propulsion boundary crossing marker data and the write-back boundary crossing marker data are associated with the propulsion write-back section alignment data to generate section anomaly marker data;
[0010] Based on the cross-section anomaly marker data and the current processing cross-section data, a cross-section progressive convergence gating sequence is generated, and the cross-section progressive convergence gating sequence is mapped to the advance write-back cross-section alignment data. Forward convergence markers are assigned to the forward action nodes in the forward expansion cross-section data, and write-back convergence markers are assigned to the write-back action nodes in the reverse write-back cross-section data, thereby obtaining the service advance cross-section convergence control data.
[0011] Based on the business advancement section convergence control data, section handling execution data is generated. Based on the object advancement identification data, the section handling execution data is used to perform convergence control processing on the advancement control process and write-back control process corresponding to the target business object, resulting in section convergence execution receipt data. The business advancement section convergence control data is then subjected to closure verification based on the section convergence execution receipt data. When the closure verification result meets the preset section closure condition, a network security handling control result is output to converge the forward advancement range and reverse write-back range of the target business object.
[0012] Furthermore, the step of performing advancement phase positioning processing on the business advancement trajectory data to obtain advancement phase node data and object advancement identifier data, and performing cross-sectional mapping processing on the node positions in the acceptance safety baseline map data based on the advancement phase node data, generates current processing cross-sectional data, including:
[0013] The business progress trajectory data is processed by merging events according to the target business object to obtain the object progress event chain;
[0014] Based on the stage switching records in the object advancement event chain, determine the advancement stage node corresponding to the target business object and generate the advancement stage node data;
[0015] Using the object identifier of the target business object as the main identifier, the processing node identifier and the result association identifier corresponding to the advancement stage node data are written into the same identifier mapping structure to generate the object advancement identifier data.
[0016] Based on the node positions in the security baseline map data of the advancement stage, the processing node range and processing boundary that the target business object has entered are determined, and the current processing section data is generated.
[0017] Furthermore, the step of constructing forward-expanding cross-sectional data based on the current processed cross-sectional data as the cross-sectional reference and the receiving safety reference map data includes:
[0018] Taking the processing action boundary corresponding to the current processing section data as the starting point of the section, the acceptance relationship is extended along the business advancement direction in the acceptance safety benchmark map data to obtain the subsequent acceptance section data;
[0019] In the received safety baseline map data, extract the collaborative processing nodes that have collaborative trigger edges with the current processing section data, and generate parallel collaborative section data;
[0020] According to the advancement direction of the target business object, the subsequent receiving section data and the parallel collaborative section data are subjected to section continuation processing to obtain the forward expansion section data.
[0021] Further, the step of constructing reverse write-back cross-section data based on the write-back security baseline map data, and performing cross-section alignment processing on the forward extension cross-section data and the reverse write-back cross-section data according to the object advancement identification data to obtain advancement write-back cross-section aligned data includes:
[0022] Using the result action node corresponding to the result association identifier in the object advancement identifier data as the write-back starting point, write-back association tracking is performed along the result write-back direction in the write-back security baseline map data to obtain candidate write-back cross-section data;
[0023] Based on the object advancement identification data, the preceding object domain node and preceding system domain node that have a result interaction relationship with the target business object are determined in the candidate write-back cross-section data, and the reverse write-back cross-section data is generated.
[0024] The nodes in the forward expansion section data that carry forward connection relationships and the nodes that carry collaborative triggering relationships are determined as forward action nodes, and the nodes in the reverse write-back section data that carry result write-back are determined as write-back action nodes.
[0025] Based on the object advancement identification data, a result connection relationship is established between the forward action node and the write-back action node to generate the advancement write-back section alignment data.
[0026] Further, the method involves using the safety baseline map data as the forward boundary verification baseline to identify propulsion boundary violations in the forward extension cross-section of the propulsion write-back cross-section alignment data, thereby obtaining propulsion boundary violation marker data; using the write-back safety baseline map data as the write-back boundary verification baseline to identify write-back boundary violations in the reverse write-back cross-section of the propulsion write-back cross-section alignment data, thereby obtaining write-back boundary violation marker data; and associating the propulsion boundary violation marker data and the write-back boundary violation marker data with the propulsion write-back cross-section alignment data to generate cross-section anomaly marker data, including:
[0027] The authorized acceptance boundary is extracted from the acceptance safety baseline map data, and the forward action node in the advance write-back section alignment data is compared with the authorized acceptance boundary to obtain the forward boundary matching result;
[0028] Based on the forward boundary matching results, determine the forward action nodes that exceed the authorized acceptance boundary, and generate the advance boundary crossing marker data;
[0029] The authorized write-back boundary is extracted from the write-back security baseline map data, and the write-back application node in the advance write-back section alignment data is compared with the authorized write-back boundary to obtain the write-back boundary matching result;
[0030] Based on the write-back boundary matching results, identify the write-back application nodes that exceed the authorized write-back boundary and generate the write-back out-of-bounds marker data;
[0031] The propulsion out-of-bounds marker data and the write-back out-of-bounds marker data are associated and labeled to the corresponding forward action node and write-back action node in the propulsion write-back section alignment data to generate the section anomaly marker data.
[0032] Further, the step involves generating a progressive convergence gating sequence based on the cross-section anomaly marker data and the currently processed cross-section data; mapping the progressive convergence gating sequence to the advance-write-back cross-section alignment data; assigning a forward convergence marker to the forward action nodes in the forward expansion cross-section data; and assigning a write-back convergence marker to the write-back action nodes in the reverse write-back cross-section data, thereby obtaining service advance cross-section convergence control data, including:
[0033] Based on the out-of-bounds direction and degree in the cross-section anomaly marker data, determine the convergence level data corresponding to the forward action node and the write-back action node respectively; based on the current processing cross-section data, determine the cross-section convergence order data of the convergence level data relative to the current processing cross-section; based on the convergence level data and the cross-section convergence order data, generate the cross-section progressive convergence gating sequence; map the cross-section progressive convergence gating sequence to the advance write-back cross-section alignment data to obtain forward convergence marker data and write-back convergence marker data; associate the forward convergence marker data with the forward action node in the forward expansion cross-section data, and associate the write-back convergence marker data with the write-back action node in the reverse write-back cross-section data to obtain the service advance cross-section convergence control data.
[0034] Furthermore, the method also includes:
[0035] Based on the business advancement section convergence control data, acceptance qualification mapping data is constructed in the forward expansion section data. This acceptance qualification mapping data characterizes the acceptance qualification relationship between the target business object and the forward action nodes in the forward expansion section data. The acceptance qualification set corresponding to the target business object is determined based on the acceptance qualification mapping data. The acceptance qualification set is then matched with the advancement boundary crossing marker data to obtain qualification retention marker data and qualification stripping marker data. Based on the qualification retention marker data, acceptance qualifications in the acceptance qualification set not associated with the advancement boundary crossing marker data are retained. Based on the qualification stripping marker data, acceptance qualifications in the acceptance qualification set associated with the advancement boundary crossing marker data are stripped to generate acceptance qualification stripping data. The acceptance qualification stripping data is then associated with the business advancement section convergence control data to restrict the target business object's continued acceptance capability in the forward expansion section data.
[0036] Furthermore, the method also includes:
[0037] When the closure verification result does not meet the preset section closure condition, the section advance margin data corresponding to the forward action node in the forward expansion section data is determined based on the convergence effective status represented by the advance boundary marker data, the write-back boundary marker data, and the section convergence execution receipt data.
[0038] Based on the matching relationship between the cross-sectional propulsion margin data and the preset propulsion margin boundary, the forward expansion cross-sectional data is subjected to propulsion margin layering processing to obtain cross-sectional layered data; the cross-sectional layered data is used to retain the reliable propulsion cross-section within the forward propulsion range, convert the propulsion cross-section to be verified into an additional verification object, and convert the restricted propulsion cross-section into a compression object.
[0039] Based on the cross-sectional layering data, the reliable propulsion cross section is retained within the forward propulsion range of the target business object, the restricted propulsion cross section is moved out of the forward propulsion range, and additional verification mark data is generated based on the propulsion cross section to be verified, thus obtaining compressed propulsion cross section data;
[0040] The operational propulsion section convergence control data is updated based on the compressed propulsion section data and the additional verification mark data.
[0041] Furthermore, the method also includes:
[0042] When the closure verification result does not meet the preset cross-section closure condition, and the cross-section convergence execution receipt data indicates the existence of an unclosed forward action node or an unclosed write-back action node, the derived business object triggered by the target business object is identified, and derived object association data is generated; the derived object association data is mapped to the forward extension cross-section data and the reverse write-back cross-section data to obtain residual action range data; when the residual action range data meets the preset damping condition, derived damping control data is generated based on the residual action range data, and the derived damping control data is used to attenuate the forward propulsion capability and reverse write-back capability of the derived business object; the business propulsion cross-section convergence control data is updated based on the derived damping control data to obtain derived damping update data; the updated residual action range data is determined based on the derived damping update data, and when the updated residual action range data meets the preset cross-section closure condition, the network security handling control result is output.
[0043] Furthermore, this application also discloses a network security handling and control system based on business advancement cross-section convergence, the system comprising:
[0044] The mapping acquisition unit is used to acquire business advancement trajectory data, acceptance security baseline map data, and write-back security baseline map data corresponding to the target business object. It performs advancement stage positioning processing on the business advancement trajectory data to obtain advancement stage node data and object advancement identifier data. Based on the node positions of the advancement stage node data in the acceptance security baseline map data, it performs cross-section mapping processing to generate current processing cross-section data. The current processing cross-section data is used to characterize the business scope that the target business object has entered.
[0045] The section alignment unit is used to construct forward expansion section data based on the current processing section data as the section reference, construct reverse write-back section data based on the receiving safety reference map data, and perform section alignment processing on the forward expansion section data and the reverse write-back section data according to the object advancement identification data to obtain advancement write-back section alignment data.
[0046] The boundary crossing marker unit is used to identify propulsion boundary crossings in the forward extension section of the propulsion write-back section alignment data by using the receiving safety reference map data as the forward boundary verification reference, and to obtain propulsion boundary crossing marker data; and to identify write-back boundary crossings in the reverse write-back section of the propulsion write-back section alignment data by using the write-back safety reference map data as the write-back boundary verification reference, and to obtain write-back boundary crossing marker data; and to associate the propulsion boundary crossing marker data and the write-back boundary crossing marker data with the propulsion write-back section alignment data to generate section anomaly marker data.
[0047] The gating convergence unit is used to generate a progressive convergence gating sequence based on the cross-section anomaly marker data and the current processing cross-section data, and map the progressive convergence gating sequence to the advance write-back cross-section alignment data. It assigns a forward convergence marker to the forward action node in the forward expansion cross-section data and a write-back convergence marker to the write-back action node in the reverse write-back cross-section data to obtain service advance cross-section convergence control data.
[0048] The closed output unit is used to generate cross-section handling execution data based on the business advancement cross-section convergence control data, and to perform convergence control processing on the advancement control flow and write-back control flow corresponding to the target business object based on the object advancement identification data and the cross-section handling execution data to obtain cross-section convergence execution receipt data; to perform closure verification on the business advancement cross-section convergence control data according to the cross-section convergence execution receipt data, and when the closure verification result meets the preset cross-section closure condition, to output the network security handling control result for converging the forward advancement range and reverse write-back range of the target business object.
[0049] The network security handling control method and system proposed in this application based on business advancement section convergence realizes unified identification and alignment of the current processing section, forward expansion section, and reverse write-back section of the target business object. This enables the forward advancement over-boundary and reverse write-back over-boundary of the target business object to be associated and marked. By performing convergence control on the forward action node and the write-back action node through the section progressive convergence gating sequence, a closed-loop network security handling control is formed for the forward advancement action range and the reverse write-back action range of the business object without relying on the overall freezing of the business object. Attached Figure Description
[0050] Figure 1 This is a schematic diagram of the overall process of a network security handling and control method based on the convergence of business advancement sections;
[0051] Figure 2 The diagram illustrates the structure for constructing the business advancement section and aligning the advancement write-back section.
[0052] Figure 3 A schematic structure for bidirectional convergence and closed-loop update control of the business advancement section is shown;
[0053] Figure 4 This diagram illustrates the relationship between push-out boundary value, write-back boundary value, and gating priority.
[0054] Figure 5 A schematic diagram showing the relationship between the cross-sectional advance margin and the derived damping closure is presented.
[0055] Figure 6 This is a schematic diagram of a network security handling and control system based on business advancement section convergence, provided as an embodiment of this application. Detailed Implementation
[0056] To make the objectives, technical solutions, and beneficial effects of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings. It should be understood that the embodiments described herein are for illustrating the technical solutions of this application and are not intended to limit the scope of protection of this application.
[0057] It should be noted that before acquiring business progress trajectory data, interface call records, permission configuration records, workflow records, collaboration trigger records, and result write-back records, and during the processing of the aforementioned data, the executing entity verifies the data source, collection authorization, access scope, and purpose of use. For data involving accounts, customers, orders, approval records, collaborator information, or system interface information, the executing entity performs permission confirmation, anonymization, field trimming, and minimized collection processing according to preset data access policies. Data that does not meet the authorization conditions or access control conditions will not enter the business progress section termination processing flow described in this application embodiment. The collection, transmission, storage, and processing of the aforementioned data comply with relevant laws and regulations, industry standards, and the data security management requirements corresponding to the target business system.
[0058] The network security handling and control method provided in this application is applicable to customer relationship management systems, order management systems, supply chain collaboration platforms, approval systems, settlement systems, interface integration platforms, and cross-system business collaboration environments. In these environments, business objects typically do not remain at a single processing node but continuously advance along the business process, generating acceptance, collaboration, execution, or write-back effects during the process. Any business processing environment in which business objects advance along the business process and affect subsequent processing nodes, collaborative processing nodes, or result write-back nodes falls within the application environments to which this application embodiment can be adapted.
[0059] The execution entity of the method described in this application embodiment is a computer device with data processing capabilities. This computer device includes a server, a business security gateway, a security handling platform, a business process engine, a distributed computing node, or a combination of the above. The execution entity receives business progress trajectory data from the business system, reads and writes back security baseline map data, and performs cross-section mapping, cross-section alignment, boundary crossing identification, gating convergence, and closure verification processing according to the current progress of the target business object. Log collection, interface call record acquisition, permission configuration reading, database storage, message queue transmission, communication protocol adaptation, and graph data storage are implementation methods well known to those skilled in the art, and this application embodiment does not limit the underlying tool type, database type, or communication protocol form.
[0060] To facilitate understanding of the technical solutions in the embodiments of this application, some basic terms involved in the embodiments of this application will be explained below.
[0061] A target business object refers to a data object that moves along the business process within the target business system and forms a receiving, coordinating, executing, or writing-back function during this process. Target business objects have different data representations in different business scenarios, but their common characteristics are: the object has a business flow state, can enter processing nodes, can trigger subsequent receiving relationships, and can generate result writing-back functions.
[0062] Business progress trajectory data refers to event chain data used to characterize the target business object in a business process according to the time sequence, stage sequence, or node flow sequence. Business progress trajectory data reflects the node process, stage switching, and processing result correlation of the target business object from creation, confirmation, distribution, execution to write-back.
[0063] The security baseline map data refers to the security boundary map data used to characterize the target business object's allowed continued acceptance by processed nodes, accepting nodes, or collaborating nodes during the forward advancement process. The security baseline map data is used to constrain the target business object's allowed acceptance range, allowed collaboration range, and allowed processing boundaries in the business advancement direction.
[0064] Writeback security baseline data refers to security boundary map data used to characterize the write-back of the processing results of a target business object to the preceding object domain or preceding system domain. Writeback security baseline data is used to constrain the allowed scope, allowed write-back nodes, and allowed result boundaries of the processing results of the target business object in the write-back direction.
[0065] In the embodiments of this application, the receiving security baseline graph data and the writing-back security baseline graph data do not merely represent the manual business rules themselves, but rather data objects formed by converting business processing nodes, inter-node relationships, authorization boundaries, and result relationships into graph structure data that can be read and traversed by computer devices. The receiving security baseline graph data focuses on describing the permissible relationships for the target business object to advance into the subsequent processing scope; the writing-back security baseline graph data focuses on describing the permissible relationships for the processing results of the target business object to act in reverse towards the preceding object domain or preceding system domain.
[0066] The current processing cross-section data refers to the data formed by mapping the node positions of the target business object's advancement phase nodes in the security baseline data, used to characterize the business scope that the target business object has entered. The current processing cross-section data is not a single processing node, but rather formed by the range of processing nodes corresponding to the current advancement phase and their processing boundaries.
[0067] Sectional convergence refers to the process of performing boundary compression, label control, qualification restrictions, and closure verification on the forward propagation range, parallel collaborative range, and reverse write-back range of a target business object. Sectional convergence differs from the overall freezing of the target business object; its goal is to restrict the target business object from continuing to propagate to unauthorized receiving nodes, to restrict the reverse effect of abnormal handling results on unauthorized write-back nodes, and to form a network security handling control result when the handling result meets the preset section closure conditions.
[0068] See Figure 1 , Figure 1 This application provides a general flowchart of a network security handling and control method based on business advancement cross-section convergence. The method is executed by a computer device with data processing capabilities and includes steps S101-S105.
[0069] S101, acquire the business advancement trajectory data, the acceptance security baseline map data, and the write-back security baseline map data corresponding to the target business object, perform advancement stage positioning processing on the business advancement trajectory data to obtain advancement stage node data and object advancement identifier data, and perform cross-section mapping processing on the node positions in the acceptance security baseline map data based on the advancement stage node data to generate current processing cross-section data. The current processing cross-section data is used to characterize the business scope that the target business object has entered.
[0070] S102, using the current processing cross-section data as the cross-section reference, construct forward expansion cross-section data according to the receiving safety reference map data, construct reverse write-back cross-section data according to the write-back safety reference map data, and perform cross-section alignment processing on the forward expansion cross-section data and the reverse write-back cross-section data according to the object advancement identification data to obtain advancement write-back cross-section aligned data;
[0071] S103, using the receiving safety reference map data as the forward boundary verification reference, perform propulsion boundary crossing identification on the forward extension section in the propulsion write-back section alignment data to obtain propulsion boundary crossing marker data; using the write-back safety reference map data as the write-back boundary verification reference, perform write-back boundary crossing identification on the reverse write-back section in the propulsion write-back section alignment data to obtain write-back boundary crossing marker data, and associate the propulsion boundary crossing marker data and the write-back boundary crossing marker data with the propulsion write-back section alignment data to generate section anomaly marker data;
[0072] S104, Generate a progressive convergence gating sequence based on the cross-section anomaly marker data and the current processing cross-section data, map the progressive convergence gating sequence to the advance write-back cross-section alignment data, assign a forward convergence marker to the forward action node in the forward expansion cross-section data, assign a write-back convergence marker to the write-back action node in the reverse write-back cross-section data, and obtain service advance cross-section convergence control data;
[0073] S105, based on the business advancement section convergence control data, generate section handling execution data, and based on the object advancement identification data, use the section handling execution data to perform convergence control processing on the advancement control process and write-back control process corresponding to the target business object, to obtain section convergence execution receipt data; perform closure verification on the business advancement section convergence control data according to the section convergence execution receipt data, and when the closure verification result meets the preset section closure condition, output the network security handling control result used to converge the forward advancement range and reverse write-back range of the target business object.
[0074] In S101, business progress trajectory data is used to provide a record of the progress of the target business object within the target business system. The executing entity does not directly generate the current processing cross-section data based on the business progress trajectory data. Instead, it first merges the business progress trajectory data according to the target business object to obtain the object progress event chain. The object progress event chain contains stage switching records related to the target business object, which are used to determine the progress stage that the target business object has reached. Unlike a log set arranged only in chronological order, the object progress event chain also retains the stage switching relationships, processing succession relationships, and result association relationships of the target business object across different processing nodes.
[0075] Advancement phase positioning processing refers to the process of determining the current business advancement phase of a target business object based on the phase switching records in the object advancement event chain. The advancement phase node data obtained from advancement phase positioning processing is used to characterize the current phase position of the target business object in the business process. Advancement phase node data is not an isolated point-in-time record, but rather the basis for positioning the target business object through cross-sectional mapping within the security baseline data.
[0076] Object advancement identification data refers to identification data used to establish the relationship between target business objects, processing nodes, and results. The executing entity uses the object identifier of the target business object as the primary identifier, and writes the processing node identifiers corresponding to the advancement phase node data and the result association identifiers into the same identifier mapping structure to generate object advancement identification data. This object advancement identification data is used in subsequent processing to establish a correspondence between the forward expansion cross-sectional data and the reverse write-back cross-sectional data.
[0077] Cross-section mapping processing refers to the process of determining the range of processing nodes and the boundaries of processing actions that the target business object has entered, based on the node positions of the advancement stage node data in the receiving security baseline map data. In other words, the current processing cross-section data is not directly extracted from the business advancement trajectory data, but rather formed by mapping the advancement stage nodes to the receiving security baseline map data, and then based on the receiving relationship, collaborative triggering relationship, and processing action boundary corresponding to the node position. In this way, the time-series business advancement trajectory is converted into the business action range in the graph structure, and the identification of subsequent forward expansion and reverse write-back both use this current processing cross-section data as the cross-section benchmark.
[0078] In S102, the current processing section data serves as the section benchmark in the construction of the forward expansion section data and the reverse write-back section data. The forward expansion section data characterizes the business scope of the target business object as it continues to expand from the current processing section to the subsequent acceptance scope and the parallel collaboration scope. Based on the current processing section data, the executing entity expands the acceptance relationship along the business advancement direction in the acceptance security benchmark data to obtain the subsequent acceptance section data; and based on the collaboration triggering relationship of the current processing section data in the acceptance security benchmark data, it obtains the parallel collaboration section data. The subsequent acceptance section data and the parallel collaboration section data undergo section continuation processing to form the forward expansion section data.
[0079] Reverse write-back cross-sectional data is used to characterize the scope of the business impact of the processing results of the target business object on the preceding object domain and preceding system domain. The executing entity takes the result impact node corresponding to the result association identifier in the object advancement identifier data as the write-back starting point, and performs write-back association tracing along the result write-back direction in the write-back security baseline map data to form candidate write-back cross-sectional data. Then, it determines the preceding object domain nodes and preceding system domain nodes that have a result impact relationship with the target business object from the candidate write-back cross-sectional data to generate reverse write-back cross-sectional data.
[0080] Section alignment processing refers to the process of establishing a result continuity relationship between forward expansion section data and reverse write-back section data based on object advancement identification data. The executing entity identifies nodes in the forward expansion section data that carry forward continuity relationships and nodes that carry collaborative triggering relationships as forward action nodes, and identifies nodes in the reverse write-back section data that carry result write-back as write-back action nodes. Based on the object advancement identification data, it establishes a result continuity relationship between the forward action nodes and the write-back action nodes to obtain the advancement write-back section alignment data. Thus, the forward diffusion capability and reverse write-back capability of the target business object are incorporated into the same alignment structure for subsequent identification.
[0081] In S103, the acceptance safety baseline map data serves as the forward boundary verification baseline, used to identify advance boundary violations in the forward extension cross-section of the advance write-back cross-section alignment data. The forward boundary verification baseline refers to the authorized acceptance boundary extracted from the acceptance safety baseline map data. This authorized acceptance boundary defines the permitted service scope, advance phase, or acceptance capacity of the forward action node. Advance boundary violation identification refers to the process of comparing the forward action nodes in the advance write-back cross-section alignment data with the authorized acceptance boundary and identifying forward action nodes that exceed the authorized acceptance boundary. Advance boundary violation marker data is generated after advance boundary violation identification.
[0082] The write-back safety baseline map data serves as the write-back boundary verification baseline, used to identify write-back out-of-bounds errors in the reverse write-back sections within the advance write-back section alignment data. The write-back boundary verification baseline refers to the authorized write-back boundary extracted from the write-back safety baseline map data. This authorized write-back boundary limits the preceding object domain, preceding system domain, or write-back application capacity that write-back application nodes are allowed to write back to. Write-back out-of-bounds identification refers to the process of comparing write-back application nodes in the advance write-back section alignment data with the authorized write-back boundary and identifying write-back application nodes that exceed the authorized write-back boundary. Write-back out-of-bounds marker data is generated after write-back out-of-bounds identification.
[0083] The advance boundary crossing marker data and the write-back boundary crossing marker data are not output as separate alarm results. Instead, they are associated with the corresponding forward action nodes and write-back action nodes in the advance-write-back cross-section alignment data, forming cross-section anomaly marker data. The cross-section anomaly marker data characterizes the location, direction, and degree of forward or write-back boundary crossings that have occurred in the advance-write-back cross-section alignment data. The safety baseline map data and the write-back safety baseline map data are used to construct the cross-section in S102 and for boundary verification in S103; they play different technical roles at different stages.
[0084] In S104, the executing entity generates a progressive convergence gating sequence based on the cross-section anomaly marker data and the currently processed cross-section data. The progressive convergence gating sequence is a data sequence used to instruct different forward action nodes and write-back action nodes to perform convergence control according to the convergence level and cross-section convergence order. The convergence level is determined based on the out-of-bounds direction and degree of out-of-bounds in the cross-section anomaly marker data, and the cross-section convergence order is determined based on the positional relationship of the corresponding node relative to the currently processed cross-section data.
[0085] The executing entity maps the progressive convergence gating sequence to the advance-writeback cross-section alignment data, assigns a forward convergence mark to the forward action nodes in the forward expansion cross-section data, and assigns a writeback convergence mark to the writeback action nodes in the reverse writeback cross-section data. The forward convergence mark restricts the target business object from continuing to advance towards or be taken over by the corresponding forward action node; the writeback convergence mark restricts the processing result of the target business object from continuing to be written back to the corresponding writeback action node. Assigning the forward convergence mark and the writeback convergence mark forms the business advancement cross-section convergence control data.
[0086] The business advancement section convergence control data is used to carry the convergence control relationships of the target business object on the current section, forward expansion section, and reverse write-back section. This data is further converted into section disposal execution data in subsequent processing, which is used to actually constrain the advancement control flow and write-back control flow corresponding to the target business object.
[0087] In S105, the executing entity generates section processing execution data based on the business advancement section convergence control data. This section processing execution data converts the business advancement section convergence control data into control data that can be executed by the advancement control flow and the write-back control flow. Based on the object advancement identifier data, the executing entity uses the section processing execution data to perform convergence control processing on the advancement control flow and the write-back control flow corresponding to the target business object. The advancement control flow controls whether the target business object continues to enter the forward action node; the write-back control flow controls whether the processing result of the target business object continues to act on the write-back action node.
[0088] After the convergence control process is completed, the executing entity generates cross-sectional convergence execution acknowledgment data. This data characterizes the execution status of forward convergence markers, write-back convergence markers, and corresponding cross-sectional disposal execution data. The data also characterizes the active status of forward convergence markers, the active status of write-back convergence markers, and any forward or write-back action nodes that are not yet closed.
[0089] The executing entity performs a closure check on the business advancement section convergence control data based on the section convergence execution receipt data. The closure check is used to determine whether the forward advancement range and reverse write-back range of the target business object have converged to the preset range.
[0090] The preset cross-section closure condition refers to the condition used to determine whether the cross-section convergence process is complete. This condition is jointly determined by the authorized acceptance boundary in the security baseline map data, the authorized write-back boundary in the write-back security baseline map data, the cross-section convergence execution receipt data, and the business security policy. When the closure verification result meets the preset cross-section closure condition, the executing entity outputs the network security handling control result. This network security handling control result is used to characterize that the forward advancement range and reverse write-back range of the target business object have been converged to the allowable range.
[0091] In the aforementioned overall process, the target business object enters the cross-section control side from the business advancement trajectory side, requiring the completion of advancement phase positioning, cross-section mapping, and advancement write-back alignment processing. To illustrate the correspondence between the aforementioned data objects, refer to... Figure 2 , Figure 2 The diagram illustrates the structure for constructing the business advancement section and aligning the advancement write-back section. Figure 2 The business progress trajectory shown on the left illustrates the object progress event chain formed during the creation, confirmation, distribution, approval, execution, and write-back processes of the target business object. This object progress event chain does not only represent the arrangement of events in time, but also carries the stage switching relationships, succession relationships, and result association relationships between processing nodes. Figure 2 The advancement stage node located on the business advancement trajectory corresponds to the stage position of the target business object in the current business process; the object advancement identifier data formed by the object identifier and the result association identifier is used to maintain the consistency of the same target business object on the forward receiving side and the reverse writing side during the subsequent section construction process.
[0092] Figure 2 The central area is used to illustrate the forward connection relationship corresponding to the safety baseline map data. Figure 2 The current processing object serves as the graphical center, representing the current processing cross-section that the target business object has entered in the current advancement phase. After the advancement phase nodes are mapped to the receiving security baseline map data, the range of processing nodes and processing action boundaries that the target business object has entered are first determined, thereby forming the current processing cross-section data. Figure 2 The forward extension region extending forward from the current processing section represents the subsequent scope that the target business object can continue to enter after the current processing section. Figure 2 The collaborative processing relationships that are laterally connected to the current processing section represent the scope of parallel collaborations that the target business object can trigger in the current processing stage. Subsequent successor relationships and collaborative triggering relationships together form the forward expansion section data.
[0093] Figure 2The right-hand area illustrates the reverse write-back relationships corresponding to the write-back security baseline data. After the result association identifier in the object advancement identifier data is mapped to the result action node, the executing entity traces along the write-back relationship edges in the write-back security baseline data to determine the preceding object domain and preceding system domain that have a result action relationship with the target business object, thereby forming the reverse write-back cross-sectional data. This reverse write-back cross-sectional data is in the opposite direction to the forward expansion cross-sectional data and is used to represent the reverse action range formed by the processing result of the target business object on the preceding object domain or preceding system domain.
[0094] Figure 2 The alignment shown illustrates the result continuation relationship between the forward expansion section and the reverse write-back section. Based on the object advancement identification data, the executing entity establishes a correspondence between the forward action nodes in the forward expansion section and the write-back action nodes in the reverse write-back section, forming advancement-write-back section alignment data. This alignment data places the forward advancement action and reverse write-back action of the same target business object within the same alignment structure. Based on this alignment structure, subsequent advancement boundary violation identification and write-back boundary violation identification are no longer performed separately on isolated nodes, but rather on the forward action nodes and write-back action nodes that have already formed a result continuation relationship.
[0095] Figure 2 The boundary verification and subsequent convergence control shown in the diagram illustrate the subsequent processing relationships after cross-section construction, including boundary identification, convergence control, and closure verification. Boundary verification in subsequent processing corresponds to both advancing boundary violation identification based on the forward boundary verification benchmark and writing back boundary violation identification based on the write-back boundary verification benchmark. Subsequent convergence control in subsequent processing corresponds to converting cross-section anomaly marker data into business advancement cross-section convergence control data and performing closure verification based on the cross-section convergence execution receipt data. Figure 2 The following section further explains the structured processing of business advancement trajectory data, the formation of object advancement event chains, the construction of receiving security baseline map data and writing back security baseline map data, and the generation process of advancement and write-back cross-section alignment data, based on the cross-section construction relationship shown in the diagram.
[0096] In one implementation, the process of performing advancement stage positioning processing on business advancement trajectory data to obtain advancement stage node data and object advancement identifier data, and performing cross-sectional mapping processing based on the node positions of the advancement stage node data in the receiving security baseline map data to generate the current processing cross-sectional data includes: performing event merging processing on the business advancement trajectory data according to the target business object to obtain the object advancement event chain; determining the advancement stage node corresponding to the target business object based on the stage switching records in the object advancement event chain to generate advancement stage node data; using the object identifier of the target business object as the main identifier, writing the processing node identifier and result association identifier corresponding to the advancement stage node data into the same identifier mapping structure to generate object advancement identifier data; and determining the processing node range and processing action boundary that the target business object has entered based on the node positions of the advancement stage node data in the receiving security baseline map data to generate the current processing cross-sectional data.
[0097] In one implementation, the process of constructing forward expansion cross-sectional data based on the current processing cross-sectional data as the cross-sectional reference and the receiving security reference map data includes: taking the processing action boundary corresponding to the current processing cross-sectional data as the cross-sectional starting point, expanding the receiving relationship along the business advancement direction in the receiving security reference map data to obtain subsequent receiving cross-sectional data; extracting collaborative processing nodes that have collaborative trigger edges with the current processing cross-sectional data in the receiving security reference map data to generate parallel collaborative cross-sectional data; and performing cross-sectional continuation processing on the subsequent receiving cross-sectional data and the parallel collaborative cross-sectional data according to the advancement direction of the target business object to obtain forward expansion cross-sectional data.
[0098] In one implementation, the process of constructing reverse write-back cross-section data based on write-back security baseline data and performing cross-section alignment processing on forward expansion cross-section data and reverse write-back cross-section data according to object advancement identifier data to obtain advance write-back cross-section aligned data includes: taking the result action node corresponding to the result association identifier in the object advancement identifier data as the write-back starting point, performing write-back association tracing along the result write-back direction in the write-back security baseline data to obtain candidate write-back cross-section data; determining the preceding object domain node and preceding system domain node that have a result action relationship with the target business object in the candidate write-back cross-section data based on the object advancement identifier data, and generating reverse write-back cross-section data; determining the nodes carrying the forward inheritance relationship and the nodes carrying the collaborative trigger relationship in the forward expansion cross-section data as forward action nodes, and determining the nodes carrying the result write-back in the reverse write-back cross-section data as write-back action nodes; and establishing a result inheritance relationship between the forward action nodes and the write-back action nodes based on the object advancement identifier data to generate advance write-back cross-section aligned data.
[0099] Business progress trajectory data is used to record the progress of a target business object within a target business system. In one implementation, the business progress trajectory data includes the target business object's object identifier, event occurrence time, processing node identifier, stage switching record, interface call record, result association identifier, execution status flag, and write-back trigger flag. The object identifier is used to distinguish different business objects; the event occurrence time is used to characterize the order in which business events occur; the processing node identifier is used to characterize the business processing position traversed by the target business object; the stage switching record is used to characterize the switching relationship of the target business object from one business stage to another; the interface call record is used to characterize the call path of the target business object in cross-system collaboration; the result association identifier is used to indicate the association between the processing result of the target business object and the subsequent write-back object; the execution status flag is used to record the execution status of the current business action; and the write-back trigger flag is used to record whether the processing result of the target business object has entered the write-back process.
[0100] Event merging is used to consolidate business events scattered across different systems, nodes, and interfaces under a single target business object. The executing entity merges event records generated in business systems, collaboration systems, approval systems, interface integration systems, and result write-back interfaces based on the object identifier of the target business object. For duplicate event records under the same object identifier with the same processing node identifier and the same event occurrence time, the executing entity retains the event records that correspond to stage switching records or result association identifiers. For event records under the same object identifier that are close in time but have different processing nodes, the executing entity determines their order based on the succession relationship between processing nodes. After event merging, an object-driven event chain is formed.
[0101] Object-driven event chains differ from log collections that are simply arranged in chronological order. They not only retain the time of event occurrence but also the relationships between processing nodes, stage transitions, API calls, and results. Through object-driven event chains, the executing entity can determine the processing positions already traversed by the target business object, its current business progression stage, and the write-back starting point associated with the processing result.
[0102] The advancement stage node data is determined by the stage switching records in the object advancement event chain. Stage switching records characterize the stage changes of the target business object in the business process. The executing entity determines the current advancement stage node of the target business object based on the stage switching records and uses this advancement stage node as the positioning node for subsequent cross-sectional mapping processing. Advancement stage node data not only characterizes the current business stage but also the node position of that stage in the inherited security baseline map data. In cases where multiple stage switching records appear in the object advancement event chain, the executing entity uses the processing node corresponding to the stage switching record that most recently formed a valid execution status marker as the advancement stage node; in cases where multiple valid execution status markers exist, the processing node that corresponds to the result association identifier is used as the advancement stage node.
[0103] Object advancement identification data is used to establish identification associations between the forward receiving side and the reverse write-back side. The executing entity uses the object identifier of the target business object as the primary identifier, and writes the processing node identifiers corresponding to the advancement stage node data and the result association identifiers into the same identifier mapping structure. This identifier mapping structure ensures that the forward-acting nodes of the same target business object in the forward expansion section data and the write-back nodes in the reverse write-back section data maintain a common origin relationship. Through this object advancement identification data, subsequent section alignment processing can determine which forward-acting nodes and which write-back nodes belong to the same target business object's processing chain.
[0104] The acceptance security baseline map data is used to represent the permissible acceptance range of a target business object in the forward direction. In one implementation, the acceptance security baseline map data includes processing nodes, acceptance relationship edges, collaborative triggering edges, authorized acceptance boundaries, acceptance qualification constraints, and node permission attributes. Processing nodes represent the business processing positions that the target business object can enter; acceptance relationship edges represent the permissible flow relationships in the business direction; collaborative triggering edges represent the relationship between the current processing node and collaborative processing nodes; authorized acceptance boundaries represent the boundary range within which the target business object is allowed to accept; acceptance qualification constraints represent the acceptance conditions that the target business object must meet before entering a certain forward action node; and node permission attributes represent the processing permissions of the processing node for the target business object.
[0105] The security baseline graph data is formed by transforming business process configurations, permission configurations, interface call strategies, and collaborative processing strategies. Business process configurations determine the connection relationships between processing nodes; permission configurations determine the processing permissions of different nodes for target business objects; interface call strategies determine the allowed paths for target business objects in cross-system calls; and collaborative processing strategies determine the allowed relationships for triggering collaborative processing nodes by the current processing node. The executing entity converts the above configurations into processing nodes, connection relationship edges, collaborative trigger edges, and authorized connection boundaries, making the security baseline graph data a graph structure that can be read, traversed, and compared by computer devices.
[0106] The write-back security baseline data is used to represent the permissible write-back range of the processing result of the target business object in the reverse direction. In one implementation, the write-back security baseline data includes result action nodes, write-back relationship edges, preceding object domain nodes, preceding system domain nodes, authorized write-back boundaries, and write-back application capacity. Result action nodes characterize the location where the processing result of the target business object takes effect; write-back relationship edges characterize the permissible relationship of writing the processing result back to the preceding object domain or preceding system domain; preceding object domain nodes characterize the scope of business objects that are reversely affected by the processing result of the target business object; preceding system domain nodes characterize the scope of systems that are reversely affected by the processing result of the target business object; authorized write-back boundaries characterize the permissible boundaries for result write-back; and write-back application capacity characterizes the write-back intensity, number of write-backs, or range of write-back status changes that a certain write-back application node is allowed to bear.
[0107] The write-back security baseline graph data is formed by transforming result write-back strategies, state synchronization strategies, interface return strategies, and preceding object associations. The result write-back strategy determines the result fields or result nodes that the processing result is allowed to affect; the state synchronization strategy determines whether the processing result enters the preceding system domain; the interface return strategy determines which write-back relationship edge the processing result returns to the preceding system through; and the preceding object association relationship determines the preceding object domain corresponding to the processing result. The executing entity transforms the above strategies into result-affected nodes, write-back relationship edges, preceding object domain nodes, preceding system domain nodes, and authorized write-back boundaries, making the write-back security baseline graph data a graph structure that can be traversed and compared by computer devices.
[0108] The security baseline data for receiving and writing back differ in their operational direction. The receiving security baseline data describes the permissible relationships for a target business object to advance into the subsequent processing scope, focusing on whether the business object is continued to be received by subsequent processing nodes, receiving nodes, or collaborating nodes. The writing back security baseline data describes the permissible relationships for the processing results of the target business object to act backward into the preceding object domain or preceding system domain, focusing on whether the processing results enter the authorized write-back scope. The two are linked through the result association identifier in the object advancement identifier data, ensuring that the forward advancement path and reverse write-back path of the target business object are uniformly incorporated into the advancement and write-back cross-section alignment data during subsequent processing.
[0109] Section mapping processing is used to convert the data of the advancement phase nodes from the business advancement trajectory side into the current business scope in the security baseline map data. Based on the node position of the advancement phase node data in the security baseline map data, the executing entity determines candidate nodes that have a connection, collaborative triggering relationship, or processing action relationship with that node position. Not all candidate nodes enter the current processing section data; the executing entity also determines whether the candidate node belongs to the business scope already entered by the target business object based on the section distance between the candidate node and the advancement phase node, the advancement timing offset, the object association strength, and the degree of permission effect.
[0110] Cross-sectional distance characterizes the topological distance between a candidate node and a stage node in the underlying security baseline graph data. Stage timing offset characterizes the time or stage offset of an event corresponding to a candidate node relative to the event corresponding to a stage node. Object association strength characterizes the degree of association between a candidate node and a target business object in terms of object identifier, processing node identifier, and result association identifier. Permission scope characterizes the authority a candidate node has over the processing result or processing status of the target business object. Using the above data, the executing entity transforms the time-series business advancement trajectory into current processing cross-sectional data in the graph structure.
[0111] In one implementation, the cross-sectional mapping intensity of the candidate processing node u in the current processing cross-sectional data is determined as follows: ,in This indicates the cross-sectional mapping intensity of candidate processing node u being included in the current processing cross-sectional data; p represents the advancement stage node determined by the business advancement trajectory data. This represents the value indicating the connection relationship between node p in the advancement phase and candidate processing node u. This indicates the strength of the object association between the candidate processing node u and the target business object; This indicates the degree of authority of the candidate processing node u over the processing result of the target business object; This represents the cross-sectional distance from node p in the advancement phase to candidate processing node u; This represents the timing offset of the candidate processing node u relative to the advancement stage node p.
[0112] In this embodiment, The connection is determined by the connection edges between the advancement stage node p and the candidate processing node u in the safety baseline map data. It is determined by the matching relationship between the object identifier, the processing node identifier, and the result association identifier; Determined by the node permission attributes of the candidate processing node u; Determined by the node hierarchy distance in the safety baseline map data; The difference in event occurrence time or stage order between the event corresponding to the candidate processing node and the event corresponding to the advancement stage node is determined. When the preset cross-section mapping threshold is reached, the executing entity includes the candidate processing node u in the current processing cross-section data. Through this process, the current processing cross-section data is jointly determined by the node position of the advancement phase node in the security baseline map data, the connection relationship of the candidate node, the object association strength of the candidate node, and the permission scope of the candidate node, avoiding the determination of the current scope of action based solely on a single time log.
[0113] The forward expansion cross-sectional data is obtained by extending the current processing cross-sectional data in the business advancement direction. The executing entity uses the processing action boundary corresponding to the current processing cross-sectional data as the starting point of the cross-section, and extends the acceptance relationship along the business advancement direction in the acceptance security baseline data to obtain subsequent acceptance cross-sectional data. Subsequent acceptance cross-sectional data is used to characterize the subsequent processing range that the target business object can enter after the current processing cross-section. The acceptance relationship extension starts from the processing action boundary in the current processing cross-sectional data, extends along the acceptance relationship edge in the acceptance security baseline data in the business advancement direction, and stops at the authorized acceptance boundary.
[0114] The executing entity also extracts collaborative processing nodes from the security baseline data that have collaborative triggering edges with the current processing cross-section data, generating parallel collaborative cross-section data. This parallel collaborative cross-section data characterizes the scope of the target business object's triggering of horizontal collaborative processing in the current processing stage. Whether a collaborative processing node enters the parallel collaborative cross-section data is determined by the collaborative triggering edge, node permission attributes, and acceptance qualification constraints. Following the target business object's advancement direction, the executing entity performs cross-section continuation processing on subsequent acceptance cross-section data and parallel collaborative cross-section data to obtain forward expansion cross-section data. Cross-section continuation processing is used to merge the vertical advancement relationships in subsequent acceptance cross-section data and the horizontal collaborative relationships in parallel collaborative cross-section data into the same forward expansion cross-section.
[0115] Reverse write-back cross-sectional data is obtained by tracing the write-back security baseline data along the result write-back direction. The executing entity uses the result-related node corresponding to the result association identifier in the object advancement identifier data as the write-back starting point, and performs write-back association tracing along the result write-back direction in the write-back security baseline data to obtain candidate write-back cross-sectional data. The candidate write-back cross-sectional data includes preceding object domain nodes and preceding system domain nodes that have a write-back relationship with the result-related node. Write-back association tracing is performed along the write-back relationship edges in the write-back security baseline data and stops at the authorized write-back boundary. Based on the object advancement identifier data, the executing entity determines the preceding object domain nodes and preceding system domain nodes that have a result-related relationship with the target business object in the candidate write-back cross-sectional data, generating reverse write-back cross-sectional data. The reverse write-back cross-sectional data is used to characterize the business scope and system scope of the reverse impact of the target business object's processing result.
[0116] The forward write-back cross-section alignment data is used to establish the result connection relationship between the forward expansion cross-section data and the reverse write-back cross-section data. The executing entity identifies the nodes in the forward expansion cross-section data that carry forward connection relationships and the nodes that carry collaborative triggering relationships as forward action nodes, and the nodes in the reverse write-back cross-section data that carry result write-back are identified as write-back action nodes. Forward action nodes characterize the position where the target business object continues to advance or engages in horizontal collaboration, while write-back action nodes characterize the position where the processing result of the target business object has a reverse effect. Based on the object advancement identifier data, the executing entity establishes a result connection relationship between the forward action nodes and the write-back action nodes, ensuring that the forward advancement and reverse write-back actions of the same target business object are associated within the same data structure.
[0117] In one implementation, the push-back alignment strength between forward-acting node i and back-write-acting node j is determined as follows: ,in This indicates the push-back alignment strength between forward-acting node i and back-acting node j; This indicates the strength of the result connection relationship between the forward-acting node i and the back-acting node j, based on the object advancement identifier data. This indicates the strength of the write-back application of the write-back application node j to the target business object. This represents the forward cross-section distance from node p during the propulsion phase to the forward acting node i; This represents the distance from the write-back node j to the cross-sectional reference of the advance stage node p.
[0118] In this embodiment, It is determined by the object identifier, processing node identifier, and result association identifier in the object advancement identifier data; Determined by the write-back application capacity and result effect node attributes in the write-back security baseline data; The hierarchical distance between the advance phase nodes and the forward action nodes in the safety baseline map data is determined by the following: The distance from the reverse action of the write-back safety baseline data to the cross-sectional baseline where the propulsion stage node is located is determined. When the preset alignment threshold is reached, the executing entity establishes a result connection relationship between the forward action node i and the back-write action node j, and generates the back-write section alignment data.
[0119] When a forward action node and multiple write-back action nodes all reach a preset alignment threshold, the executing entity determines the priority order of result acceptance based on the forward write-back alignment strength from high to low, and retains the write-back action node with the result association identifier consistent with the target business object as the primary alignment node. When multiple forward action nodes correspond to the same write-back action node, the executing entity determines the primary accepting node based on the object association strength and forward cross-section distance corresponding to each forward action node, and uses other nodes that meet the preset alignment threshold as auxiliary alignment nodes. The resulting forward write-back cross-section alignment data can simultaneously retain both primary and auxiliary alignment relationships, providing a unified data foundation for subsequent forward out-of-bounds identification and write-back out-of-bounds identification.
[0120] After the alignment data of the write-back section is formed, a result succession relationship is established between the forward action node and the write-back action node. The execution entity continues to perform boundary verification based on this alignment relationship, so that the boundary violation identification result can simultaneously reflect the action deviation in both the forward advancement direction and the reverse write-back direction.
[0121] In one implementation, using the acceptance safety baseline map data as the forward boundary verification baseline, propulsion boundary crossing identification is performed on the forward extension cross section in the propulsion write-back cross section alignment data to obtain propulsion boundary crossing marker data; using the write-back safety baseline map data as the write-back boundary verification baseline, write-back boundary crossing identification is performed on the reverse write-back cross section in the propulsion write-back cross section alignment data to obtain write-back boundary crossing marker data; the process of associating the propulsion boundary crossing marker data and the write-back boundary crossing marker data with the propulsion write-back cross section alignment data to generate cross section anomaly marker data includes: extracting the authorized acceptance boundary from the acceptance safety baseline map data, and associating the forward action node in the propulsion write-back cross section alignment data with the authorized acceptance boundary. Boundary comparison is performed to obtain forward boundary matching results. Based on the forward boundary matching results, forward action nodes exceeding the authorized write-back boundary are identified, and propulsion over-boundary marker data is generated. The authorized write-back boundary is extracted from the write-back safety baseline map data, and the write-back action nodes in the propulsion write-back section alignment data are compared with the authorized write-back boundary to obtain write-back boundary matching results. Based on the write-back boundary matching results, write-back action nodes exceeding the authorized write-back boundary are identified, and write-back over-boundary marker data is generated. The propulsion over-boundary marker data and write-back over-boundary marker data are associated and labeled to the corresponding forward action nodes and write-back action nodes in the propulsion write-back section alignment data to generate section anomaly marker data.
[0122] In one implementation, the process of generating a progressive convergence gating sequence based on cross-section anomaly marker data and currently processed cross-section data; mapping the progressive convergence gating sequence to advance-write-back cross-section alignment data; assigning forward convergence markers to forward-acting nodes in the forward-expanding cross-section data; and assigning write-back convergence markers to write-back nodes in the reverse-write-back cross-section data to obtain service advance-section convergence control data includes: determining the convergence level data corresponding to the forward-acting nodes and write-back nodes respectively based on the out-of-bounds direction and out-of-bounds degree in the cross-section anomaly marker data; and based on... The current processing section data is used to determine the section convergence order data relative to the current processing section. Based on the convergence level data and the section convergence order data, a progressive convergence gating sequence is generated. The progressive convergence gating sequence is mapped to the advance write-back section alignment data to obtain forward convergence marker data and write-back convergence marker data. The forward convergence marker data is associated with the forward action node in the forward expansion section data, and the write-back convergence marker data is associated with the write-back action node in the reverse write-back section data to obtain the business advance section convergence control data.
[0123] The authorized acceptance boundary is jointly determined by the node permission attributes, acceptance relationship edges, collaboration triggering edges, acceptance qualification constraints, and business stage constraints in the acceptance security baseline data. Node permission attributes are used to limit the processing permissions of forward-acting nodes on the target business object; acceptance relationship edges are used to limit the allowed paths for the target business object to advance from the current processing section to subsequent processing nodes; collaboration triggering edges are used to limit the allowed relationships for the current processing node to initiate collaborative processing to collaborative processing nodes; acceptance qualification constraints are used to limit the object state, business stage, and processing conditions that the target business object must meet before entering the forward-acting node; business stage constraints are used to limit the acceptance scope that the target business object can enter at a specific advancement stage.
[0124] The authorized acceptance boundary characterizes the scope of business objects, the scope of advancement stages, the acceptance capacity range, and the collaboration trigger boundary that a forward-acting node is allowed to accept in the business advancement direction. The acceptance capacity range characterizes the number of target business objects, processing intensity, or number of acceptances a forward-acting node can handle within a unit business cycle. The collaboration trigger boundary characterizes the node level, interface permissions, and business stage restrictions encountered by the current processing node when initiating collaborative processing with a collaborative processing node. After extracting the above boundary information from the acceptance security baseline data, the executing entity forms a forward boundary verification baseline for the forward-acting node.
[0125] The authorized write-back boundary is jointly determined by the result-effect node attributes, write-back relationship edges, preceding object domain nodes, preceding system domain nodes, write-back application capacity, and write-back state constraints in the write-back security baseline data. The result-effect node attributes limit the location where the processing result affects the target business object; the write-back relationship edges limit the allowed path for the processing result to enter the preceding object domain or preceding system domain along the write-back direction; the preceding object domain nodes limit the scope of business objects that the processing result can affect; the preceding system domain nodes limit the scope of systems that the processing result can enter; the write-back application capacity limits the write-back strength, number of write-backs, or magnitude of state changes; and the write-back state constraints limit the conditions under which the processing result overwrites, supplements, or synchronizes the state fields in the preceding object domain or preceding system domain.
[0126] The authorized writeback boundary is used to characterize the preceding object domain, preceding system domain, result field range, writeback status range, and writeback capacity that a writeback application node is allowed to write back in the result writeback direction. After extracting the above boundary information from the writeback security baseline data, the execution entity forms a writeback boundary verification baseline for the writeback application node.
[0127] The forward boundary matching result is used to characterize the matching relationship between the forward action node and the authorized acceptance boundary. When the executing entity compares the forward action node in the advance write-back section alignment data with the authorized acceptance boundary, it compares the acceptance relationship, acceptance capacity, business stage position, collaborative triggering relationship, and node permission attributes corresponding to the forward action node. When the actual forward action of the forward action node exceeds the authorized acceptance boundary, the executing entity determines the forward action node as an advance out-of-bounds node and generates advance out-of-bounds marker data.
[0128] The actual forward action is calculated from the forward write-back cross-section alignment data, which includes the number of object advances, collaborative triggers, cross-node acceptances, cross-stage advance magnitude, and result acceptance strength associated with the forward action node. The number of object advances characterizes the number of times the target business object advances towards the forward action node; the number of collaborative triggers characterizes the number of times the node triggers lateral collaborative processing; the number of cross-node acceptances characterizes the number of times the target business object crosses different processing nodes; the cross-stage advance magnitude characterizes the advance magnitude of the target business object beyond the current processing cross-section; and the result acceptance strength characterizes the alignment strength between the forward action node and the write-back action node. After conversion using the same measurement scale, the above data forms the actual forward action of the forward action node.
[0129] The write-back boundary matching result is used to characterize the matching relationship between write-back application nodes and authorized write-back boundaries. When the execution entity compares the write-back application nodes in the advance write-back section alignment data with the authorized write-back boundaries, it compares the write-back relationship, write-back application capacity, preceding object domain, preceding system domain, result field range, and write-back status range corresponding to the write-back application node. When the actual write-back application amount of a write-back application node exceeds the authorized write-back boundary, the execution entity identifies the write-back application node as a write-back out-of-bounds node and generates write-back out-of-bounds marker data.
[0130] The actual writeback cost is calculated from the number of result writebacks associated with the writeback application node, the coverage of the preceding object domain, the scope of the preceding system domain, the magnitude of state changes, and the strength of result continuity in the writeback cross-section alignment data. The number of result writebacks characterizes the number of times the processing result of the target business object is written back to the writeback application node; the coverage of the preceding object domain characterizes the scope of business objects affected by the processing result; the scope of the preceding system domain characterizes the scope of the system affected by the processing result; the magnitude of state changes characterizes the extent to which the processing result covers, supplements, or synchronizes the preceding state; and the strength of result continuity characterizes the alignment strength between the writeback application node and the preceding application node. After conversion using the same measurement scale, the above data forms the actual writeback cost of the writeback application node.
[0131] In one implementation, the advance out-of-bounds value of the forward-acting node i is determined as follows: ,in This represents the out-of-bounds value of the forward-acting node i; This represents the actual forward action of forward action node i in the data alignment of the write-back section; This represents the authorized boundary capacity for forward action node i in the safety baseline map data.
[0132] In one implementation, the write-back out-of-bounds value of write-back application node j is determined as follows: ,in This represents the write-out value of the write-back node j; This indicates the actual amount of writeback used by writeback node j in the data alignment process of the writeback section; This represents the authorized write-back boundary capacity for write-back application node j in the write-back security baseline graph data.
[0133] In the above formula This is used to keep the out-of-bounds value zero when the actual action amount does not exceed the corresponding authorized boundary capacity. The out-of-bounds value of the forward action node i. When the value is greater than zero, the executing entity generates advance out-of-bounds marker data corresponding to the forward acting node. The write-back out-of-bounds value of acting node j is then written back. When the value is greater than zero, the executing entity generates write-back out-of-bounds flag data corresponding to the write-back execution node. The larger the advance out-of-bounds value and the write-back out-of-bounds value, the greater the deviation of the corresponding node from the authorized boundary.
[0134] Advance boundary crossing marker data is used to characterize the boundary crossing state of forward-acting nodes in the forward advance direction. This data must at least record the forward-acting node identifier, corresponding authorized boundary, actual forward action, advance boundary crossing value, boundary crossing direction, and boundary matching result. Write-back boundary crossing marker data is used to characterize the boundary crossing state of write-back nodes in the reverse write-back direction. This data must at least record the write-back node identifier, corresponding authorized write-back boundary, actual write-back action, write-back boundary crossing value, boundary crossing direction, and boundary matching result.
[0135] The boundary crossing direction is used to distinguish the direction of action of the boundary crossing behavior in the cross-sectional structure. In one implementation, the boundary crossing direction includes forward acceptance boundary crossing direction, parallel collaborative boundary crossing direction, and reverse write-back boundary crossing direction. The forward acceptance boundary crossing direction is used to characterize the target business object advancing into the unauthorized subsequent acceptance range; the parallel collaborative boundary crossing direction is used to characterize the target business object triggering the unauthorized collaborative processing range; the reverse write-back boundary crossing direction is used to characterize the processing result of the target business object acting on the unauthorized preceding object domain or preceding system domain. The boundary crossing direction and the boundary crossing degree jointly participate in the determination of subsequent convergence level data.
[0136] The cross-section anomaly marker data is formed by associating and annotating the advance boundary crossing marker data and the write-back boundary crossing marker data with the advance-write-back cross-section aligned data. The advance boundary crossing marker data is associated with the forward action nodes in the advance-write-back cross-section aligned data, and the write-back boundary crossing marker data is associated with the write-back action nodes in the advance-write-back cross-section aligned data. After association and annotation, the advance-write-back cross-section aligned data no longer only represents the result inheritance relationship between the forward action nodes and the write-back action nodes, but also simultaneously represents the boundary crossing direction, boundary crossing degree, boundary matching status, and anomaly marker status in this result inheritance relationship.
[0137] In one implementation, the cross-sectional anomaly labeling data includes node identifiers, out-of-bounds direction, out-of-bounds degree, boundary matching results, result continuation relationships, primary labeling status, and secondary labeling status. Node identifiers are used to identify forward-acting nodes or write-back nodes that have experienced an out-of-bounds event; the out-of-bounds direction is used to distinguish between forward continuation out-of-bounds, parallel collaborative out-of-bounds, and reverse write-back out-of-bounds; the out-of-bounds degree is determined by the advance out-of-bounds value or the write-back out-of-bounds value; the boundary matching result characterizes the matching status between the node and its corresponding authorized boundary; the result continuation relationship characterizes the alignment relationship between the forward-acting node and the write-back node that experienced an out-of-bounds event; the primary labeling status identifies node pairs in the gating sequence that require priority convergence; and the secondary labeling status identifies associated nodes that share the same result continuation relationship as the primary labeling status.
[0138] When the same forward-acting node corresponds to multiple write-back nodes, the executing entity determines the primary marker state based on the advance-write-back alignment strength and the write-back out-of-bounds value; the remaining write-back nodes that meet the boundary anomaly conditions enter the auxiliary marker state. When multiple forward-acting nodes correspond to the same write-back node, the executing entity determines the primary marker state based on the advance-out-of-bounds value, the forward cross-section distance, and the strength of the result continuation relationship; the remaining forward-acting nodes that meet the boundary anomaly conditions enter the auxiliary marker state. Through the primary and auxiliary marker states, the cross-section anomaly marker data, while preserving the multi-node anomaly relationships, can still provide a clear primary and secondary order for the cross-section progressive convergence gating sequence.
[0139] After the cross-sectional anomaly marker data is generated, the executing entity determines the convergence level data based on the out-of-bounds direction and degree. The convergence level data is used to characterize the strength of convergence control required for forward-acting nodes or write-back-acting nodes. For aligned node pairs that have both advance and write-back out-of-bounds markers, the executing entity increases the convergence level of the aligned node pair; for forward-acting nodes with only advance out-of-bounds markers, the executing entity determines the forward convergence level based on the advance out-of-bounds value; for write-back-acting nodes with only write-back out-of-bounds markers, the executing entity determines the write-back convergence level based on the write-back out-of-bounds value; for forward-acting nodes with parallel cooperative out-of-bounds directions, the executing entity includes their cooperative triggering edges within the range of the forward convergence level determination.
[0140] The cross-section convergence order data is determined based on the positional relationship of the convergence level data relative to the current processing cross-section data. The executing entity determines the cross-section level of the corresponding node relative to the current processing cross-section based on the forward cross-section distance between the forward acting node and the current processing cross-section data, and the reverse cross-section distance from the write-back acting node to the current processing cross-section data. Nodes with high boundary crossing severity and closer to the current processing cross-section receive a higher cross-section convergence order; nodes with low boundary crossing severity and farther from the current processing cross-section receive a lower cross-section convergence order. In this way, the cross-section convergence order data represents the control order of progressive convergence from the current processing cross-section to the forward expansion cross-section and the reverse write-back cross-section.
[0141] In one implementation, the gating priority of the aligned node pair formed by the forward action node i and the back action node j in the cross-sectional progressive convergence gating sequence is determined as follows: ,in This indicates the gating priority of the aligned node pair formed by the forward action node i and the back action node j in the cross-sectional progressive convergence gating sequence. This represents the out-of-bounds value of the forward-acting node i; This represents the write-out value of the write-back node j; This indicates the push-back alignment strength between forward-acting node i and back-acting node j; This represents the forward cross-section distance from node p during the propulsion phase to the forward acting node i; This represents the distance from the write-back node j to the cross-sectional reference of the advance stage node p.
[0142] The gating priority mentioned above is not directly determined by a single out-of-bounds value, but rather by the push out-of-bounds value, write-back out-of-bounds value, push-back-write alignment strength, and the distance of the node relative to the current processing section. For an explanation of this control relationship, refer to... Figure 4 , Figure 4 The relationship between push-out boundary value, write-back boundary value and gating priority is shown. Figure 4 The horizontal axis represents the cross-sectional level or node pair sequence, the left vertical axis represents the out-of-bounds value, and the right vertical axis represents the gating priority. The advance out-of-bounds value curve corresponds to the degree of deviation of the forward action node from the authorized acceptance boundary, the write-back out-of-bounds value curve corresponds to the degree of deviation of the write-back action node from the authorized write-back boundary, and the gating priority curve corresponds to the processing priority of the aligned node pair formed by the forward action node and the write-back action node in the cross-sectional progressive convergence gating sequence.
[0143] Reference Figure 4 The trends of the push-back and write-back boundary value curves show that forward-acting nodes and write-back nodes at different cross-sectional levels exhibit varying degrees of boundary violations. Some node pairs generate higher push-back boundary values in the forward-acting direction, while others generate higher write-back boundary values in the reverse write-back direction. If sorting is based solely on a single boundary value, it is difficult to reflect the result continuity between forward-acting and reverse write-back actions. Therefore, in this embodiment, the gating priority also incorporates push-back alignment strength and the distance of the node from the current processing cross-section as control factors.
[0144] Reference Figure 4 The gating priority curve shows that node pairs closer to the current processing section have higher gating priorities when they simultaneously possess higher push-out limits, higher write-back limits, and stronger push-back-write alignment. As the section level moves further away from the current processing section, even if some nodes still have local limit-out peaks, their gating priority is still suppressed by the forward section distance and the write-back section distance. Therefore, the progressive convergence gating sequence is not arranged according to the order of node appearance, nor according to a single limit-out value, but rather according to the control priority relationship formed by the degree of limit-out, alignment relationship, and section distance.
[0145] Figure 4 The priority convergence region shown represents the set of node pairs with higher gating priority. Node pairs within this region typically have close cross-sectional distances, strong advance-writeback alignment relationships, and high advance or write-back boundary overflow values. Based on this gating priority, the executing entity preferentially maps the corresponding node pairs to the business advance cross-sectional convergence control data, assigning a forward convergence mark to forward-acting nodes and a write-back convergence mark to write-back-acting nodes. Based on this processing, the boundary overflow identification results are further transformed into gating convergence relationships with a processing order.
[0146] In one implementation, the progressive convergence gating sequence includes a current adjacency gating bit, a forward expansion gating bit, a cooperative triggering gating bit, and a reverse write-back gating bit. The current adjacency gating bit is used to process the aligned node pair closest to the current processing cross-section and with the highest degree of boundary violation; the forward expansion gating bit is used to process forward-acting nodes located in subsequent receiving cross-sections; the cooperative triggering gating bit is used to process cooperative processing nodes located in parallel cooperative cross-sections; and the reverse write-back gating bit is used to process write-back acting nodes located in reverse write-back cross-sections. The executing entity assigns different aligned node pairs to corresponding gating bits based on gating priority and cross-section level, and generates the progressive convergence gating sequence according to the gating bit order.
[0147] When the same node simultaneously satisfies the entry conditions of multiple gating positions, the executing entity determines the primary gating position based on gating priority and records the other gating positions as auxiliary gating positions. The primary gating position is used to determine the order of convergence execution, while the auxiliary gating positions are used to preserve the constraint relationships of the node in other cross-sectional directions. Through this process, the progressive convergence gating sequence maintains multi-directional cross-sectional constraint relationships while still forming a clear progressive convergence execution order.
[0148] After the cross-section progressive convergence gating sequence is mapped to the advance-write-back cross-section alignment data, forward convergence marker data and write-back convergence marker data are formed. Forward convergence marker data identifies the forward action node that needs to perform convergence control in the forward advance direction. The forward convergence marker acts on the forward advance capability of the target business object, restricting the target business object from being continued to be inherited by the corresponding forward action node, restricting it from triggering the corresponding collaborative processing node, and restricting it from continuing to cross the corresponding inheritance relationship edge. Write-back convergence marker data identifies the write-back action node that needs to perform convergence control in the reverse write-back direction. The write-back convergence marker acts on the result write-back capability of the target business object, restricting the processing result of the target business object from continuing to be written back to the corresponding write-back action node, restricting it from overwriting the state of the preceding object domain, and restricting it from triggering state synchronization in the preceding system domain.
[0149] The executing entity associates the forward convergence marker data with the forward action node in the forward expansion cross-section data, and associates the write-back convergence marker data with the write-back action node in the reverse write-back cross-section data, thus obtaining the business advancement cross-section convergence control data. This association annotation does not change the node structure of the forward expansion cross-section data and the reverse write-back cross-section data themselves, but adds convergence control markers, convergence levels, gating bits, gating priorities, and execution status fields to the corresponding nodes, enabling subsequent cross-section processing execution data to perform convergence control processing on the advancement control flow and the write-back control flow according to the gating sequence.
[0150] The business advancement section convergence control data is used to carry the data structure required for section convergence processing. In one embodiment, the business advancement section convergence control data includes forward action node identifier, write-back action node identifier, forward convergence mark, write-back convergence mark, section convergence order, convergence level data, result continuation relationship, gating bit, gating priority, boundary matching result, out-of-bounds degree, and execution status fields. Forward action node identifier and back-write action node identifier are used to locate the convergence object; forward convergence marker is used to restrict the target business object from continuing to advance to the corresponding forward action node or being accepted by the corresponding forward action node; back-write convergence marker is used to restrict the processing result of the target business object from continuing to be written back to the corresponding back-write action node; cross-sectional convergence order is used to determine the convergence execution order of different nodes; convergence level data is used to determine the convergence strength of different nodes; result acceptance relationship is used to preserve the alignment relationship between forward advancement and reverse back-write; gating bit is used to indicate the convergence stage to which the node belongs; gating priority is used to indicate the processing order of nodes in the same gating bit; boundary matching result and out-of-bounds degree are used to support the execution of subsequent processing; execution status field is used to record whether the corresponding convergence marker has been executed by the subsequent cross-sectional processing execution data.
[0151] In one implementation, the service advance section convergence control data also retains a primary marker state and an auxiliary marker state. The primary marker state indicates the alignment node pairs that require priority handling; the auxiliary marker state indicates other abnormal nodes that have the same target service object association with the primary marker state. When subsequently generating section handling execution data, the execution entity determines the main convergence object based on the primary marker state and simultaneously restricts the residual advance and residual write-back actions of the same target service object in other section directions based on the auxiliary marker state. Thus, the section abnormality marker data no longer remains an alarm marker but is further converted into service advance section convergence control data capable of driving forward convergence and write-back convergence.
[0152] After the convergence control data of the business advancement section is formed, the forward action nodes in the forward expansion section and the write-back action nodes in the reverse write-back section are each marked with corresponding convergence markers. To illustrate the role of these convergence markers in the bidirectional section and the update relationship when the closure is not satisfied, refer to... Figure 3 , Figure 3 A schematic structure for bidirectional convergence and closed-loop update control of the business advancement section is shown.
[0153] Reference Figure 3The bidirectional convergence structure shown in the middle has its current processing section located between the forward expansion section and the reverse write-back section. The forward propulsion range and reverse write-back range of the target service object are located on opposite sides of the current processing section. The forward action nodes in the forward expansion section are constrained by the propulsion over-limit marker and the forward convergence marker, while the write-back action nodes in the reverse write-back section are constrained by the write-back over-limit marker and the write-back convergence marker. Figure 3 The business advancement section shown in the middle is located at the convergence control position of the bidirectional action range. Its internal structure is used to carry forward convergence markers, write-back convergence markers, convergence level data, gating priority, and execution status fields, thereby incorporating the forward expansion section and the reverse write-back section into a unified section control structure.
[0154] Reference Figure 3 In the bidirectional convergence relationship, the forward convergence mark along the forward extension section restricts the target business object's ability to continue to receive and coordinate triggering, while the write-back convergence mark along the reverse write-back section restricts the target business object's ability to write back results and synchronize states. Figure 3 The convergence and compression relationship on the forward and reverse sides indicates that the scope of action of the target business object is simultaneously constrained in both the forward advance direction and the reverse write-back direction. This process does not stop processing the target business object as a whole, but rather places the out-of-bounds nodes, forward action nodes with result succession relationships, write-back action nodes, and convergence markers in the same cross-sectional control structure for progressive convergence.
[0155] Reference Figure 3 The closure update structure shown in the lower part: After the closure verification of the cross-section convergence execution acknowledgment data, if the closure verification result does not meet the preset cross-section closure condition, the process does not terminate, but enters the subsequent update branch. One update branch enters the reliable cross-section dynamic compression processing based on the cross-section convergence execution acknowledgment data, generates compressed advance cross-section data and additional verification mark data, and writes the compressed update result back to the business advance cross-section convergence control data; the other update branch, when the closure verification result does not meet the preset cross-section closure condition and there are unclosed forward action nodes or unclosed write-back action nodes, enters the derived object damping control processing, generates derived damping update data, and writes the derived damping update data back to the business advance cross-section convergence control data.
[0156] Reference Figure 3In the closed loop, neither of the two update branches mentioned above forms a normal bidirectional transmission relationship with the business advancement section convergence control data. Instead, they are triggered by the section convergence execution acknowledgment data and the closure verification result, and after generating the corresponding update data, they are re-applied to the business advancement section convergence control data. The updated business advancement section convergence control data then re-enters the closure verification; when the result of the second closure verification meets the preset section closure condition, the executing entity outputs the network security handling control result. Therefore, Figure 3 The structure shown illustrates the closed-loop control relationship of convergence execution, acknowledgment feedback, unclosed branch update, control data update write-back, and re-closure verification.
[0157] based on Figure 3 The closed update structure shown above, after the business advancement section convergence control data is generated, the execution entity further processes the acceptance qualification relationship of the target business object, the advance margin of the section, and the residual range of action of the derived business object. The acceptance qualification stripping, reliable section dynamic compression, and derived business object damping control are explained below.
[0158] In one implementation, the process of stripping acceptance qualifications includes: constructing acceptance qualification mapping data in the forward expansion cross-section data based on the business advancement cross-section convergence control data, wherein the acceptance qualification mapping data is used to characterize the acceptance qualification relationship between the target business object and the forward action node in the forward expansion cross-section data; determining the acceptance qualification set corresponding to the target business object based on the acceptance qualification mapping data; performing qualification matching processing on the acceptance qualification set and the advancement overstepping mark data to obtain qualification retention mark data and qualification stripping mark data; retaining the acceptance qualifications in the acceptance qualification set that are not associated with the advancement overstepping mark data based on the qualification retention mark data, and stripping the acceptance qualifications in the acceptance qualification set that are associated with the advancement overstepping mark data based on the qualification stripping mark data to generate acceptance qualification stripping data; and associating the acceptance qualification stripping data with the business advancement cross-section convergence control data to restrict the target business object's continued acceptance capability in the forward expansion cross-section data.
[0159] In one implementation, the process of dynamic compression of a reliable cross-section includes: when the closure verification result does not meet the preset cross-section closure condition, determining the cross-section advance margin data corresponding to the forward action node in the forward expansion cross-section data based on the convergence effectiveness status represented by the advance boundary marker data, the write-back boundary marker data, and the cross-section convergence execution receipt data; performing advance margin layering processing on the forward expansion cross-section data according to the matching relationship between the cross-section advance margin data and the preset advance margin boundary to obtain cross-section layered data; the cross-section layered data is used to retain the reliable advance cross-section within the forward advance action range, convert the advance cross-section to be verified into an additional verification object, and convert the restricted advance cross-section into a compressed object; based on the cross-section layered data, retaining the reliable advance cross-section within the forward advance action range of the target business object, moving the restricted advance cross-section out of the forward advance action range, and generating additional verification marker data based on the advance cross-section to be verified to obtain compressed advance cross-section data; and updating the business advance cross-section convergence control data based on the compressed advance cross-section data and the additional verification marker data.
[0160] In one implementation, the process of derived service object damping control includes: when the closure verification result does not meet the preset cross-section closure condition, and the cross-section convergence execution acknowledgment data indicates the existence of an unclosed forward action node or an unclosed write-back action node, identifying the derived service object triggered by the target service object and generating derived object association data; mapping the derived object association data to the forward extension cross-section data and the reverse write-back cross-section data to obtain residual action range data; when the residual action range data meets the preset damping condition, generating derived damping control data based on the residual action range data, the derived damping control data being used to attenuate the forward propulsion capability and reverse write-back capability of the derived service object; updating the service propulsion cross-section convergence control data based on the derived damping control data to obtain derived damping update data; determining the updated residual action range data based on the derived damping update data, and outputting the network security handling control result when the updated residual action range data meets the preset cross-section closure condition.
[0161] In the acceptance qualification stripping process, the acceptance qualification mapping data is jointly generated from the business advancement section convergence control data and the forward expansion section data. The business advancement section convergence control data provides forward action node identifiers, forward convergence markers, section convergence order, convergence level data, boundary matching results, and advancement over-boundary marker data; the forward expansion section data provides the forward action nodes, acceptance relationship edges, collaboration triggering edges, acceptance qualification constraints, and node permission attributes of the target business object in subsequent acceptance sections and parallel collaboration sections. The executing entity establishes a correspondence between the object identifier of the target business object and the forward action node identifier, and writes the acceptance qualification constraints, node permission attributes, forward convergence markers, and advancement over-boundary marker data corresponding to the forward action node into this correspondence, forming the acceptance qualification mapping data.
[0162] The acceptance qualification mapping data represents the qualification relationship of a target business object to continue to be accepted by forward-acting nodes in the forward expansion cross-sectional data. This qualification relationship does not indicate whether the target business object itself exists, but rather whether the target business object still has the conditions for continued acceptance with a specific forward-acting node. For the same target business object, there are multiple acceptance qualifications corresponding to different forward-acting nodes in the acceptance qualification mapping data. Each acceptance qualification is associated with the authorized acceptance boundary, acceptance qualification constraints, node permission attributes, and advancement over-boundary flag data of the corresponding forward-acting node.
[0163] The executing entity determines the set of acceptance qualifications corresponding to the target business object based on the acceptance qualification mapping data. Each acceptance qualification in the set corresponds to a forward acting node, and records the acceptance qualification constraints, node permission attributes, acceptance relationship edges, collaborative triggering edges, authorized acceptance boundaries, and boundary matching status of that forward acting node. The set of acceptance qualifications is used for subsequent qualification matching processing, so that the continued acceptance qualifications of the target business object on different forward acting nodes are identified item by item.
[0164] The qualification matching process is used to correlate and compare the set of acceptance qualifications with the advance boundary crossing marker data. The executing entity matches the forward action node identifier corresponding to each acceptance qualification in the acceptance qualification set with the forward action node identifier in the advance boundary crossing marker data. When a forward action node is not associated with the advance boundary crossing marker data, and the boundary matching result of the forward action node still satisfies the authorized acceptance boundary, the executing entity generates qualification retention marker data. When a forward action node is associated with the advance boundary crossing marker data, or when the forward action node is identified as a convergence object by the forward convergence marker, the executing entity generates qualification stripping marker data.
[0165] The qualification retention flag data is used to retain the qualification of a target business object to continue to be accepted at the corresponding forward action node. The qualification retention flag data does not remove other control flags in the business advancement section convergence control data; it only indicates that the acceptance qualification has not entered the stripping process. The qualification stripping flag data is used to indicate that the acceptance qualification of a target business object at the corresponding forward action node has entered the stripping process. The qualification stripping flag data maintains a correspondence with the advancement boundary crossing flag data, the forward convergence flag, and the authorized acceptance boundary.
[0166] The acceptance qualification stripping data is generated based on the qualification stripping marker data. The executing entity, based on the qualification stripping marker data, strips the acceptance qualification of the corresponding forward-acting node from the acceptance qualification set and associates the stripping result with the business advancement section convergence control data. The acceptance qualification stripping data includes the object identifier of the target business object, the identifier of the stripped forward-acting node, the corresponding acceptance relationship edge, the reason for qualification stripping, the corresponding advancement boundary crossing marker data, the stripping effective status, and the stripping time marker. After the acceptance qualification stripping data is entered into the business advancement section convergence control data, the target business object's ability to continue accepting in the forward expansion section data is restricted.
[0167] Stripping acceptance eligibility does not delete the target business object, nor does it freeze the entire business process containing the target business object. Acceptance eligibility stripping affects the continued acceptance relationship between the target business object and its forward-acting nodes. While the target business object remains within the current processing interface, the stripped acceptance eligibility restricts its continued entry into the corresponding forward-acting node, restricts its continued triggering of the corresponding collaborative processing node, and restricts its formation of new forward extensions through the corresponding acceptance relationship edge. Through this process, the existence state and continued diffusion capability of the target business object are separated and controlled.
[0168] In the dynamic compression processing of the reliable cross-section, if the closure verification result does not meet the preset cross-section closure condition, it indicates that there are still unrecovered portions in the forward propulsion range, the reverse write-back range, or the derived residual range. In this case, the executing entity does not expand the overall frozen range, but instead determines the cross-section propulsion margin data of each forward action node based on the convergence effectiveness status represented by the propulsion over-boundary marker data, the write-back over-boundary marker data, and the cross-section convergence execution receipt data.
[0169] Cross-sectional advance margin data characterizes the remaining advance space of the forward-acting node after forward convergence marking, write-back constraints, takeover qualification stripping, and execution acknowledgment feedback. This data differs from the authorized takeover capacity of the forward-acting node. The authorized takeover capacity represents the boundary capacity allowed to take over under baseline conditions; the cross-sectional advance margin data represents the advance margin still retained by the forward-acting node after convergence control processing.
[0170] In one implementation, the cross-sectional advance margin data of the forward action node i is determined as follows: ,in This represents the cross-sectional advance margin data of the forward-acting node i; This represents the authorized propulsion capacity corresponding to the forward action node i in the safety baseline map data. This indicates the propulsion capacity that has been occupied or stripped by the business propulsion section convergence control data; This represents the write-back constraint capacity, which is projected back onto the forward action node i by the write-back outbound marker data through the advance write-back section alignment data.
[0171] Authorized propulsion capacity Determined by the authorized acceptance boundary in the acceptance safety baseline map data. The propulsion capacity already occupied or stripped by the operational propulsion section convergence control data. This is determined by the forward convergence marker, the acceptance qualification stripping data, and the cross-sectional convergence execution receipt data. Write-back constraint capacity. The write-back boundary marker data is determined by the write-back action node corresponding to the write-back action node that has a result succession relationship with the forward action node i. The write-back boundary marker data acts in reverse on the forward action node by advancing the write-back section alignment data, so that the forward advance margin is not only affected by the forward boundary but also by the reverse write-back boundary constraint.
[0172] In one implementation, write-back constraint capacity This is calculated based on the write-back out-of-bounds value, advance write-back alignment strength, and write-back boundary matching result of the write-back application node that has a result inheritance relationship with the forward application node i. The higher the advance write-back alignment strength between the write-back application node and the forward application node, the larger the write-back out-of-bounds value, and the higher the write-back constraint capacity formed on the forward application node. Through this processing, the write-back out-of-bounds risk can be reversed to compress the forward advance margin.
[0173] The preset advance margin boundaries include a first advance margin boundary and a second advance margin boundary. The first advance margin boundary is used to distinguish whether the target business object is still within a stable advance range at the forward action node; the second advance margin boundary is used to distinguish whether the target business object has entered a restricted advance range at the forward action node. The first advance margin boundary is higher than the second advance margin boundary. The first and second advance margin boundaries are determined by the business security level, the target business object type, the forward action node level, historical handling records, and the target business system security policy.
[0174] The executing entity matches the cross-sectional propulsion margin data with the preset propulsion margin boundary and performs propulsion margin layering processing on the forward propulsion cross-sectional data. The cross-sectional layering data records the forward action node identifier, cross-sectional propulsion margin data, matched propulsion margin boundary, layering result, additional verification status, and compression status. Through this cross-sectional layering data, the forward propulsion cross-sectional data is divided into reliable propulsion cross-sections, propulsion cross-sections to be verified, and restricted propulsion cross-sections.
[0175] when When the target business object is above the first advance margin boundary, the forward action node i is included in the trusted advance section. A trusted advance section indicates that the target business object still meets the authorized advance conditions at the corresponding forward action node, and the section convergence execution acknowledgment data does not indicate that there is a risk of the node not closing. The trusted advance section is retained within the forward advance action range of the target business object, and the advance qualification of the corresponding forward action node is retained in the business advance section convergence control data.
[0176] when When the forward action node i is not higher than the first advance margin boundary but higher than the second advance margin boundary, it is included in the advance section to be verified. The advance section to be verified indicates that the target business object still retains a certain advance margin at the corresponding forward action node, but this advance margin is already constrained by advance over-boundary marker data, write-back over-boundary marker data, or section convergence execution receipt data. The execution entity generates additional verification marker data based on the advance section to be verified. The additional verification marker data is used to indicate that the corresponding forward action node needs to perform additional verification processing before the target business object continues to advance. The additional verification processing includes secondary permission confirmation, collaborative trigger confirmation, write-back impact confirmation, and disposal receipt review.
[0177] when When the target object is not higher than the second propulsion margin boundary, the forward action node i is included in the restricted propulsion section. The restricted propulsion section indicates that the target business object no longer meets the conditions for continued propulsion at the corresponding forward action node. The executing entity moves the restricted propulsion section out of the forward propulsion range of the target business object and converts the corresponding forward action node into a compressed object. After the restricted propulsion section is moved out, the executing entity obtains the compressed propulsion section data.
[0178] The compressed propulsion section data records the retained reliable propulsion sections, the propulsion sections awaiting verification in the additional verification process, the restricted propulsion sections that have been removed, and the propulsion margin data corresponding to each forward action node. The executing entity updates the operational propulsion section convergence control data based on the compressed propulsion section data and the additional verification mark data. The updated operational propulsion section convergence control data adds propulsion margin layering results, additional verification mark data, and compressed propulsion section data. In this way, the forward propulsion range of the target operational object is not handled by a single blocking method, but is dynamically compressed based on the propulsion margin of the section.
[0179] In the damping control processing of derived business objects, when the closure verification result fails to meet the preset section closure condition, and the section convergence execution acknowledgment data indicates the existence of an unclosed forward action node or an unclosed write-back action node, the executing entity further identifies the derived business object triggered by the target business object. A derived business object is a data object triggered by the target business object during its advancement, collaboration, execution, or write-back process, and still possesses forward advancement or reverse write-back capabilities. There are triggering relationships, succession relationships, result reference relationships, or state synchronization relationships between the derived business object and the target business object.
[0180] The identification criteria for derived business objects include unclosed forward action nodes, unclosed write-back action nodes, object advancement identifier data, collaboration trigger records, interface call records, result reference relationships, and state synchronization relationships. Unclosed forward action nodes indicate that the target business object still has residual effects in the forward advancement direction; unclosed write-back action nodes indicate that the target business object still has residual effects in the reverse write-back direction; collaboration trigger records indicate whether the target business object triggers new collaboration objects; interface call records indicate whether the target business object triggers external processing objects; result reference relationships indicate whether the processing results are continued to be referenced by other objects; and state synchronization relationships indicate whether the processing results continue to enter other system states.
[0181] The executing entity generates derived object association data based on the aforementioned identification criteria. This data records the trigger source, associated forward action nodes, associated write-back action nodes, result reference relationships, state synchronization relationships, and the effective status of the derived object between the derived business object and the target business object. After the derived object association data is formed, the executing entity maps it to forward expansion section data and reverse write-back section data to obtain residual scope data.
[0182] Residual scope data characterizes the residual advance scope of derived business objects in the forward expansion section data and the residual write-back scope in the reverse write-back section data. Residual scope data differs from the original forward advance scope of the target business object. It reflects the diffusion effect that continues to be retained by the derived business object after the target business object is terminated. Residual scope data includes the derived business object identifier, residual advance nodes, residual write-back nodes, residual advance strength, residual write-back strength, result reference relationships, and state synchronization relationships.
[0183] The preset damping conditions are used to determine whether a derived business object enters the damping control process. The preset damping conditions include at least one of the following: the derived business object still has forward propagation capability; the derived business object still has reverse write-back capability; the residual scope of the derived business object does not meet the preset cross-section closure condition; and there is still a result reference relationship between the derived business object and the target business object. When the residual scope data meets the preset damping conditions, the executing entity generates derived damping control data based on the residual scope data.
[0184] Derivative damping control data is used to attenuate the forward propagation and reverse write-back capabilities of derived business objects. This attenuation marking does not delete the derived business object, nor does it stop all associated processes; rather, it reduces the derived business object's ability to continue entering the forward expansion section and its ability to continue generating results for write-back to the reverse write-back section. Derivative damping control data includes the derived business object identifier, the associated target business object identifier, the residual propagation range, the residual write-back range, the damping control level, the attenuation mark, and the damping activation status.
[0185] In one implementation, the damped residual action value of the derived business object o is determined as follows: ,in This represents the damped residual effect value of the derived business object o; This indicates the residual propulsion strength of the derived business object o on the forward expansion section data; Indicates the residual write-back strength of the derived business object o for the reverse write-back cross-section data; This indicates the bidirectional coupling residual strength generated when the derived business object o simultaneously has both forward propagation and reverse write-back functions; This indicates the number of damping control levels that have been formed for the derived business object o in the derived damping control data.
[0186] Residual propulsion strength The number of residual push nodes after mapping from derived business objects to forward expansion cross-sectional data, the node permission attributes of the residual push nodes, and the corresponding connection edges of the residual push nodes are determined. Residual write-back strength. The number of residual write-back nodes, the write-back capacity of the residual write-back nodes, and the write-back relationship edges corresponding to the residual write-back nodes are determined after mapping the derived business object to the reverse write-back cross-section data. Bidirectional coupling residual strength. This is used to characterize the cumulative risk that arises when a derived business object is retained in both the forward and reverse write-back directions. Damping control levels. The number of attenuation marker levels already applied in the derived damping control data is determined.
[0187] To illustrate the continuity between the stratified propulsive margin of the cross section and the derived damping closure, refer to Figure 5 , Figure 5 The relationship between the cross-sectional advance margin and the derived damping closure is shown. Figure 5 The horizontal axis represents the convergence round or iteration stage, the left vertical axis represents the cross-sectional advance margin, and the right vertical axis represents the residual action value. The cross-sectional advance margin curve corresponds to the remaining advance space of the forward action node after forward convergence marking, write-back constraint, acceptance qualification stripping, and cross-sectional convergence execution feedback; the damped residual action value curve corresponds to the residual advance action and residual write-back action of the derived business object after the derived damping control data is applied.
[0188] Reference Figure 5 The cross-sectional advance margin curve shows that as the convergence rounds progress, the cross-sectional advance margin decreases due to the combined effects of forward convergence markers, acceptance qualification stripping data, and write-back out-of-bounds constraint capacity. This decrease is not a monotonically linear reduction relationship, but rather related to the update status between cross-sectional convergence execution receipt data, additional verification marker data, and compressed advance cross-sectional data. When the cross-sectional advance margin is higher than the first advance margin boundary, the corresponding forward action node is in a reliable advance cross-section; when the cross-sectional advance margin is not higher than the first advance margin boundary but higher than the second advance margin boundary, the corresponding forward action node enters the pending advance cross-section; when the cross-sectional advance margin is not higher than the second advance margin boundary, the corresponding forward action node enters the restricted advance cross-section and is removed from the forward advance action range of the target business object as a compression object.
[0189] Reference Figure 5 The layered region formed by the first and second propulsion margin boundaries has different handling results for the reliable propulsion section, the propulsion section to be verified, and the restricted propulsion section. The reliable propulsion section remains within the forward propulsion range; the propulsion section to be verified is converted into an additional verification object, and additional verification marker data is generated; the restricted propulsion section is converted into a compression object and removed from the forward propulsion range. Therefore, Figure 5 The propulsion margin curve of the cross section corresponds to the formation process of the propulsion cross section data after compression.
[0190] Reference Figure 5The residual action value curve after damping shows that the residual action value of the derived service object decreases as the damping control level increases. When the derived service object retains only unidirectional residual propulsion or unidirectional residual write-back, the decrease in the residual action value after damping is relatively gradual. When the derived service object retains both forward propulsion and reverse write-back, the bidirectional coupling residual strength participates in the calculation of the residual action value after damping. The derived damping control data attenuates this bidirectional coupling residual strength, causing the curve to show a more significant decrease in the corresponding convergence round. When the residual action value after damping decreases below the damping closure boundary, it indicates that the residual action range corresponding to the derived service object has entered the closed range.
[0191] Reference Figure 5 Within the closed region, the advance margin of the cross-section, after being compressed in layers, narrows the forward advance range of the target business object to the range defined by the credible advance cross-section and the advance cross-section to be verified. After the residual action value after damping is controlled by derived damping, the residual advance action and residual write-back action of the derived business object are reduced to within the preset damping closed boundary. The above two changes together support the subsequent closure verification: that is, after the business advance cross-section convergence control data completes the advance margin compression and derived damping update, it is verified again by the cross-section convergence execution receipt data until the preset cross-section closure condition is met.
[0192] when When the residual range of the derived business object is not higher than the preset damping closure boundary, the executing entity determines that the residual range of action satisfies the preset cross-sectional closure condition. When the damping exceeds the preset closure boundary, the executing entity updates the operational advance section convergence control data based on the derived damping control data to obtain derived damping update data, and determines the updated residual action range data based on the derived damping update data. The updated residual action range data continues to participate in the closure verification.
[0193] The derived damping update data is used to record the damping control results corresponding to the derived business objects. The derived damping update data includes the derived business object identifier, pre-damping residual range data, derived damping control data, post-damping residual range data, and damping closure status. The executing entity associates the derived damping update data with the business advancement section convergence control data, so that the residual advancement action and residual write-back action of the target business object and its derived business objects are included in the same closed-loop verification structure.
[0194] After the aforementioned qualification stripping, reliable cross-section dynamic compression, and derived business object damping control are completed, the closure verification checks the business advancement cross-section convergence control data based on the cross-section convergence execution receipt data. The cross-section convergence execution receipt data characterizes the execution status of the forward convergence marker, write-back convergence marker, qualification stripping data, compressed advancement cross-section data, and derived damping update data. Based on the cross-section convergence execution receipt data, the executing entity determines whether the corresponding forward action node, write-back action node, qualification, advancement margin stratification result, and derived residual action range in the business advancement cross-section convergence control data have reached the preset convergence state.
[0195] Specifically, the closure verification includes verifying the effectiveness status of the forward convergence marker. The executing entity reads the execution status field corresponding to the forward acting node from the cross-section convergence execution receipt data to determine whether the forward convergence marker has been applied to the corresponding forward acting node. When the forward convergence marker has been applied to the corresponding forward acting node, the forward acting node no longer receives requests to continue advancing the target business object, no longer accepts the target business object through the corresponding acceptance relationship edge, and no longer triggers unauthorized collaborative processing through the corresponding collaborative triggering edge. When the forward convergence marker has not completed its application, the forward acting node is retained as an unclosed forward acting node and continues to participate in subsequent trusted cross-section dynamic compression or derived business object damping control processing.
[0196] Closure verification also includes verifying the effectiveness status of the write-back termination marker. The execution entity reads the execution status field corresponding to the write-back application node from the cross-sectional termination execution receipt data to determine whether the write-back termination marker has been applied to the corresponding write-back application node. When the write-back termination marker has been applied to the corresponding write-back application node, the processing result of the target business object will no longer be written back to the preceding object domain or preceding system domain corresponding to the write-back application node, will no longer overwrite the corresponding preceding status field, and will no longer trigger the corresponding status synchronization relationship. When the write-back termination marker has not completed its effect, the write-back application node is retained as an unclosed write-back application node and continues to participate in subsequent derived business object identification and residual scope confirmation.
[0197] The closure verification also includes verifying the execution status of the acceptance qualification stripping data. Based on the cross-sectional convergence execution receipt data, the executing entity verifies whether the acceptance qualification stripping data has been associated with the business advancement cross-sectional convergence control data, and verifies whether the continued acceptance relationship between the target business object and the stripped forward action node has been terminated. When the acceptance qualification stripping data has taken effect, the target business object's continued acceptance capability at the corresponding forward action node is limited; when the acceptance qualification stripping data has not taken effect, the corresponding forward action node still has residual acceptance risk, and the executing entity retains this forward action node in the unclosed node set for subsequent processing.
[0198] Closure verification also includes verifying the effectiveness status of the compressed propulsion cross-section data. Based on the cross-section convergence execution receipt data, the executing entity verifies whether the reliable propulsion cross-section has been retained within the forward propulsion range of the target business object, whether the propulsion cross-section awaiting verification has been converted into an additional verification object, and whether the restricted propulsion cross-section has been moved out of the forward propulsion range of the target business object. After the compressed propulsion cross-section data becomes effective, the forward propulsion range of the target business object is compressed to the range jointly defined by the authorized acceptance boundary and the preset propulsion margin boundary. When the compressed propulsion cross-section data is not effective, there are still unclosed restricted propulsion cross-sections within the forward propulsion range, and the executing entity continues to update the business propulsion cross-section convergence control data based on the cross-section convergence execution receipt data.
[0199] The closure check also includes verifying the effectiveness of the derived damping update data. The executing entity determines the updated residual range data based on the derived damping update data and checks whether the forward propulsion and reverse write-back capabilities of the derived service object have been attenuated to within the preset damping closure boundary. After the derived damping update data takes effect, the residual propulsion range of the derived service object in the forward extension cross-sectional data and the residual write-back range in the reverse write-back cross-sectional data decrease. When the derived damping update data is not effective, the residual range data corresponding to the derived service object continues to participate in damping control processing and closure check.
[0200] In one implementation, the preset cross-section closure conditions are jointly determined by the receiving security baseline map data, the write-back security baseline map data, the business advancement cross-section convergence control data, the cross-section convergence execution receipt data, and the security policy of the target business system. The preset cross-section closure conditions include: the forward advancement range of the target business object does not exceed the authorized receiving boundary in the receiving security baseline map data; the reverse write-back range of the target business object does not exceed the authorized write-back boundary in the write-back security baseline map data; the cross-section advance margin data meets the preset advancement margin boundary; and the damped residual action value of the derived business object meets the preset damping closure boundary.
[0201] In one implementation, the forward propulsion range of the target business object does not exceed the authorized acceptance boundary, meaning that all forward action nodes retained in the forward expansion cross-sectional data are within the allowable acceptance range defined by the acceptance security baseline data, and are not identified as stripped objects by the acceptance qualification stripping data. The reverse writeback range of the target business object does not exceed the authorized writeback boundary, meaning that all writeback action nodes retained in the reverse writeback cross-sectional data are within the allowable writeback range defined by the writeback security baseline data, and are not identified as unclosed writeback action nodes by the writeback termination mark.
[0202] In one implementation, the propulsive margin data of the cross section satisfies the preset propulsive margin boundary, meaning that the forward action node in the forward expansion cross section data that is retained within the forward propulsive action range has a propulsive margin data higher than the lower limit of the propulsive margin set by the target service system, or the corresponding forward action node has been converted into a propulsive cross section to be verified and formed additional verification mark data. The damped residual action value of the derived service object satisfies the preset damping closure boundary, meaning that the damped residual action value corresponding to the derived service object is not higher than the preset damping closure boundary, and the residual propulsive nodes and residual write-back nodes recorded in the associated data of the derived object have all completed attenuation marking.
[0203] The preset advance margin boundary, preset damping closure boundary, and thresholds related to the preset cross-section closure condition are jointly determined by the business security level, system risk level, target business object type, forward action node level, write-back action node level, historical handling records, and enterprise security policy. The specific values of the above thresholds are determined by the security policy configuration of the target business system. This application's embodiments focus on the network security handling control chain formed based on the business advance cross-section, advance write-back alignment data, boundary crossing markers, and closure verification, and do not limit specific threshold values.
[0204] The following describes the complete execution process of the network security handling and control method described in this application embodiment, using an enterprise order collaboration scenario as an example. This scenario is only used to illustrate the processing logic of this application embodiment and does not limit the specific business type of the target business object.
[0205] In this scenario, the target business object is an order business object. After its creation in the order management system, this order business object enters the pre-distribution stage after confirmation and will send a collaborative confirmation request to the supply chain collaboration platform. The business progress trajectory data records the object identifier, creation event, confirmation event, distribution preparation event, interface call record, execution status flag, and result association flag for this order business object. The object progress event chain indicates that the order business object has completed the confirmation action but has not yet completed the distribution action; its current progress stage node is located at the pre-distribution processing node.
[0206] The acceptance safety baseline data records the allowed acceptance relationships for this order business object in the forward direction. According to this acceptance safety baseline data, in the stage before distribution after confirmation, this order business object is only allowed to enter the internal approval node and the authorized supply collaboration node. It is not allowed to trigger unauthorized external collaboration nodes, nor is it allowed to skip the internal approval node and directly enter the settlement confirmation node. The write-back safety baseline data records the allowed write-back relationships for the processing results of this order business object in the reverse write-back direction. According to this write-back safety baseline data, the processing results of this order business object are only allowed to write back to the order status field and the inventory pre-occupancy field. It is not allowed to directly write back to the settlement confirmation field, nor is it allowed to overwrite the pre-approval status that has already been approved.
[0207] After obtaining the business progress trajectory data, acceptance security baseline map data, and write-back security baseline map data corresponding to the order business object, the executing entity performs event merging processing on the business progress trajectory data to form the object progress event chain for the order business object. Based on the stage switching records in the object progress event chain, the executing entity determines the progress stage node corresponding to the order business object and generates progress stage node data. Subsequently, using the object identifier of the order business object as the primary identifier, the executing entity writes the processing node identifier corresponding to the pre-distribution stage after confirmation and the result association identifier into the same identifier mapping structure to generate object progress identifier data.
[0208] The executing entity performs cross-sectional mapping based on the node positions of the progress phase node data in the acceptance security baseline data. After confirmation, the processing nodes corresponding to the pre-distribution phase have acceptance relationships with internal approval nodes, authorized supply collaboration nodes, and some collaboration triggering nodes in the acceptance security baseline data. Based on the acceptance relationships, collaboration triggering relationships, processing action boundaries, and node permission attributes, the executing entity determines the range of processing nodes and processing action boundaries that the order business object has entered, and generates the current processing cross-sectional data.
[0209] The executing entity uses the current processing cross-sectional data as the cross-sectional baseline and extends the acceptance relationship along the business advancement direction in the acceptance safety baseline map data to obtain subsequent acceptance cross-sectional data. This subsequent acceptance cross-sectional data includes internal approval nodes and authorized supply collaboration nodes. The executing entity also extracts collaboration processing nodes that have collaboration trigger edges with the current processing cross-sectional data to generate parallel collaboration cross-sectional data. If there is a trigger record for an unauthorized external collaboration node in the current processing cross-sectional data, the unauthorized external collaboration node enters the parallel collaboration cross-sectional data and participates in the advancement boundary identification in subsequent boundary verification. After cross-sectional continuation processing of the subsequent acceptance cross-sectional data and the parallel collaboration cross-sectional data, forward expansion cross-sectional data is formed.
[0210] The executing entity determines the result-related nodes in the write-back security baseline data based on the result association identifiers in the object advancement identifier data, and performs write-back association tracing along the result write-back direction to obtain candidate write-back cross-sectional data. The candidate write-back cross-sectional data includes the order status field, inventory pre-occupancy field, settlement confirmation field, and approval status field. Based on the object advancement identifier data, the executing entity filters the preceding object field nodes and preceding system field nodes that have a result-related relationship with the order business object from the candidate write-back cross-sectional data to generate reverse write-back cross-sectional data. The order status field and inventory pre-occupancy field are within the authorized write-back scope, while the settlement confirmation field and approval status field are not within the authorized write-back scope in this scenario.
[0211] The executing entity identifies nodes in the forward expansion cross-sectional data that carry forward continuation relationships and nodes that carry collaborative triggering relationships as forward action nodes, and nodes in the reverse write-back cross-sectional data that carry result write-back relationships as write-back action nodes. Based on the object advancement identifier data, the executing entity establishes result continuation relationships between forward action nodes and write-back action nodes, generating advancement write-back cross-sectional alignment data. Through this advancement write-back cross-sectional alignment data, the result continuation relationships between unauthorized external collaborative nodes and abnormal settlement confirmation write-back nodes are preserved, ensuring that forward collaborative diffusion and reverse result write-back are no longer processed in isolation.
[0212] The executing entity extracts the authorized acceptance boundary from the acceptance security baseline data and compares the forward action nodes in the advance write-back section alignment data with the authorized acceptance boundary. The comparison results show that unauthorized external collaborative nodes are not within the allowed acceptance range of the order business object in the post-confirmation and pre-distribution stage, and the collaborative triggering relationship corresponding to the node exceeds the authorized acceptance boundary. Based on this, the executing entity generates advance out-of-bounds flag data. The executing entity extracts the authorized write-back boundary from the write-back security baseline data and compares the write-back action nodes in the advance write-back section alignment data with the authorized write-back boundary. The comparison results show that abnormal settlement confirmation write-back nodes are not within the allowed write-back range of the order business object in the current stage, and based on this, the executing entity generates write-back out-of-bounds flag data.
[0213] The executing entity associates and annotates the advance boundary violation marker data and the write-back boundary violation marker data with the corresponding forward action node and write-back action node in the advance-write-back cross-section alignment data to generate cross-section anomaly marker data. This cross-section anomaly marker data records the advance boundary violation direction of unauthorized external collaborative nodes, the write-back boundary violation direction of abnormal settlement confirmation write-back nodes, the corresponding boundary violation degree, and the result inheritance relationship between the two.
[0214] The executing entity determines the convergence level data corresponding to the forward action node and the write-back action node based on the out-of-bounds direction and degree in the cross-section anomaly marker data. For aligned node pairs formed by unauthorized external collaboration nodes and anomaly settlement confirmation write-back nodes, the executing entity determines the gating priority based on the advance out-of-bounds value, the write-back out-of-bounds value, and the advance-write-back alignment strength. Since this aligned node pair has both forward collaboration out-of-bounds and reverse write-back out-of-bounds, and is relatively close to the current processing cross-section, its gating priority is higher than that of nodes with only unidirectional out-of-bounds. The executing entity generates a cross-section progressive convergence gating sequence based on the gating priority.
[0215] The executing entity maps the progressive convergence gating sequence to the advance-writeback convergence alignment data, assigns forward convergence markers to unauthorized external collaborative nodes, and assigns write-back convergence markers to abnormal settlement confirmation write-back nodes, thus obtaining the business advance-section convergence control data. This business advance-section convergence control data records the forward action node identifier, write-back action node identifier, forward convergence marker, write-back convergence marker, gating bit, gating priority, convergence level data, result continuation relationship, and execution status fields.
[0216] The executing entity generates cross-sectional processing execution data based on the business advancement cross-sectional convergence control data. Based on the object advancement identifier data, it uses the cross-sectional processing execution data to perform convergence control processing on the advancement control flow and write-back control flow corresponding to the order business object. Upon receiving a forward convergence flag, the advancement control flow restricts the order business object from triggering unauthorized external collaboration nodes. Upon receiving a write-back convergence flag, the write-back control flow restricts the processing result of the order business object from being written back to the abnormal settlement confirmation write-back node. The executing entity generates cross-sectional convergence execution receipt data, which records the execution status of the forward convergence flag and the write-back convergence flag.
[0217] When the cross-section convergence execution receipt data indicates that the forward convergence mark of the unauthorized external collaborative node has taken effect, and the write-back convergence mark of the abnormal settlement confirmation write-back node has taken effect, the executing entity performs a closure check on the business advancement cross-section convergence control data. If the closure check result indicates that the order business object still has unclosed forward action nodes or unclosed write-back action nodes, the executing entity further performs acceptance qualification stripping, trusted cross-section dynamic compression, and derived business object damping control.
[0218] In the process of stripping acceptance qualifications, the executing entity constructs acceptance qualification mapping data in the forward expansion cross-section data based on the business advancement cross-section convergence control data. This acceptance qualification mapping data records the acceptance qualification relationships between the order business object and internal approval nodes, authorized supply collaboration nodes, and unauthorized external collaboration nodes. The executing entity performs qualification matching processing between the acceptance qualification set and the advancement overstepping marker data, generates qualification stripping marker data for the acceptance qualifications corresponding to unauthorized external collaboration nodes, and generates acceptance qualification stripping data. After the acceptance qualification stripping data is associated with the business advancement cross-section convergence control data, the order business object no longer has the qualification to be accepted by unauthorized external collaboration nodes.
[0219] In the trusted cross-section dynamic compression process, the executing entity determines the cross-section advance margin data corresponding to each forward action node in the forward expansion cross-section data based on the convergence effectiveness status represented by the advance boundary marker data, write-back boundary marker data, and cross-section convergence execution receipt data. Internal approval nodes whose cross-section advance margin data meets the first advance margin boundary enter the trusted advance cross-section; authorized supply collaboration nodes, affected by write-back boundary constraints, enter the pending verification advance cross-section and generate additional verification marker data; unauthorized external collaboration nodes do not meet the second advance margin boundary, enter the restricted advance cross-section, and are removed from the forward advance action range of the order business object. The executing entity then obtains the compressed advance cross-section data and updates the business advance cross-section convergence control data.
[0220] In the processing of derived business object damping control, if the cross-section convergence execution receipt data indicates the existence of a derived notification object or a derived settlement pre-confirmation object triggered by the order business object, and the derived business object still has forward propulsion capability or reverse write-back capability, the executing entity identifies the derived business object and generates derived object association data. The executing entity maps the derived object association data to the forward expansion cross-section data and the reverse write-back cross-section data to obtain residual effective range data. When the residual effective range data meets the preset damping conditions, the executing entity generates derived damping control data to attenuate the forward propulsion capability and reverse write-back capability of the derived business object. After the derived damping control data updates the business propulsion cross-section convergence control data, derived damping update data is formed, and the updated residual effective range data is determined accordingly.
[0221] When the updated residual action range data meets the preset cross-section closure condition, and the cross-section convergence execution receipt data indicates that the forward convergence mark, write-back convergence mark, acceptance qualification stripping data, compressed advance cross-section data, and derived damping update data have all reached an effective state, the executing entity outputs the network security handling control result. This network security handling control result is used to characterize that the forward advance action range of the order business object has been limited to the authorized acceptance boundary, the reverse write-back action range has been limited to the authorized write-back boundary, and the residual action range of the derived business object has met the preset damping closure boundary.
[0222] It should be noted that the above-described enterprise order collaboration scenario is only used to illustrate the processing procedure of the embodiments of this application. When the target business object is presented as a customer object, approval object, supply collaboration object, interface call object, or result write-back object in other business environments, the executing entity still executes the method described in the embodiments of this application according to the processing relationship between business progress trajectory data, acceptance security baseline map data, write-back security baseline map data, progress write-back section alignment data, section anomaly marker data, business progress section convergence control data, and section convergence execution receipt data.
[0223] The graph data storage, log collection, interface calls, permission rule reading, database read / write, message queue transmission, workflow engine execution, network communication protocols, and basic graph traversal algorithms are implemented using methods well-known to those skilled in the art, and will not be elaborated further in this application's embodiments. The above implementation details do not affect the understanding and implementation of this application's embodiments. The processing focus of this application's embodiments is to use the business advancement section as the control object, forming a network security handling control chain oriented towards the business diffusion process through the current processing section, forward expansion section, reverse write-back section, advance write-back section data alignment, boundary crossing markers, progressive convergence gating sequences, and closure checks.
[0224] Based on the description of the above embodiments of the network security handling and control method based on business advancement cross-section convergence, this application also discloses a network security handling and control system based on business advancement cross-section convergence. The network security handling and control system based on business advancement cross-section convergence can be a computer program (including program code) running the aforementioned network security handling and control method based on business advancement cross-section convergence. Please see the appendix. Figure 6 As shown, the network security response and control system based on the convergence of business advancement sections can operate the following units:
[0225] The mapping acquisition unit 110 is used to acquire business advancement trajectory data, acceptance security baseline map data, and write-back security baseline map data corresponding to the target business object, perform advancement stage positioning processing on the business advancement trajectory data to obtain advancement stage node data and object advancement identifier data, and perform cross-section mapping processing on the node positions in the acceptance security baseline map data based on the advancement stage node data to generate current processing cross-section data. The current processing cross-section data is used to characterize the business scope that the target business object has entered.
[0226] The section alignment unit 120 is used to construct forward expansion section data based on the current processing section data as the section reference, construct reverse write-back section data based on the receiving safety reference map data, and perform section alignment processing on the forward expansion section data and the reverse write-back section data according to the object advancement identification data to obtain advancement write-back section alignment data.
[0227] The boundary crossing marking unit 130 is used to identify the forward extension section in the propulsion write-back section alignment data by using the acceptance safety reference map data as the forward boundary verification reference, and to obtain propulsion boundary crossing marking data; and to identify the reverse write-back section in the propulsion write-back section alignment data by using the write-back safety reference map data as the write-back boundary verification reference, and to obtain write-back boundary crossing marking data; and to associate the propulsion boundary crossing marking data and the write-back boundary crossing marking data with the propulsion write-back section alignment data to generate section anomaly marking data.
[0228] The gating convergence unit 140 is used to generate a progressive convergence gating sequence based on the cross-section anomaly marker data and the current processing cross-section data, and map the progressive convergence gating sequence to the advance write-back cross-section alignment data. It assigns a forward convergence marker to the forward action node in the forward extension cross-section data and a write-back convergence marker to the write-back action node in the reverse write-back cross-section data to obtain service advance cross-section convergence control data.
[0229] The closed output unit 150 is used to generate cross-section handling execution data based on the business advancement cross-section convergence control data, and to perform convergence control processing on the advancement control flow and write-back control flow corresponding to the target business object based on the object advancement identification data and the cross-section handling execution data to obtain cross-section convergence execution receipt data; to perform closure verification on the business advancement cross-section convergence control data according to the cross-section convergence execution receipt data, and when the closure verification result meets the preset cross-section closure condition, to output the network security handling control result for converging the forward advancement range and reverse write-back range of the target business object.
[0230] The above description is merely a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the forms disclosed herein and should not be construed as excluding other embodiments. It can be used in various other combinations, modifications, and environments, and can be altered within the scope of the concept described herein through the above teachings or related technologies or knowledge. Modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention should be within the protection scope of the appended claims.
Claims
1. A network security handling and control method based on business advancement section convergence, characterized in that, include: The system acquires business advancement trajectory data, acceptance security baseline map data, and write-back security baseline map data corresponding to the target business object. It performs advancement stage positioning processing on the business advancement trajectory data to obtain advancement stage node data and object advancement identifier data. Based on the node positions of the advancement stage node data in the acceptance security baseline map data, it performs cross-sectional mapping processing to generate current processing cross-sectional data. The current processing cross-sectional data is used to characterize the business scope that the target business object has entered. Using the current processing cross-sectional data as the cross-sectional reference, forward expansion cross-sectional data is constructed based on the receiving safety reference map data, and reverse write-back cross-sectional data is constructed based on the write-back safety reference map data. The forward expansion cross-sectional data and the reverse write-back cross-sectional data are then aligned according to the object advancement identification data to obtain advancement write-back cross-sectional aligned data. Using the aforementioned safety baseline map data as the forward boundary verification baseline, the forward extension section in the forward write-back section alignment data is used to identify the propulsion boundary crossing, thereby obtaining propulsion boundary crossing marker data. Using the writeback security baseline data as the writeback boundary verification baseline, the reverse writeback section in the propulsion writeback section alignment data is identified to obtain writeback boundary marker data. The propulsion boundary marker data and the writeback boundary marker data are then associated with the propulsion writeback section alignment data to generate section anomaly marker data. Based on the cross-section anomaly marker data and the current processing cross-section data, a cross-section progressive convergence gating sequence is generated, and the cross-section progressive convergence gating sequence is mapped to the advance write-back cross-section alignment data. Forward convergence markers are assigned to the forward action nodes in the forward expansion cross-section data, and write-back convergence markers are assigned to the write-back action nodes in the reverse write-back cross-section data, thereby obtaining the service advance cross-section convergence control data. Based on the business advancement section convergence control data, section processing execution data is generated, and based on the object advancement identification data, the section processing execution data is used to perform convergence control processing on the advancement control process and write-back control process corresponding to the target business object to obtain section convergence execution receipt data; Based on the cross-section convergence execution receipt data, the business advancement cross-section convergence control data is closed-loop verified. When the closure verification result meets the preset cross-section closure condition, the network security handling control result for converging the forward advancement range and reverse write-back range of the target business object is output.
2. The network security handling and control method based on business advancement section convergence according to claim 1, characterized in that, The process involves performing phase positioning processing on the business advancement trajectory data to obtain advancement phase node data and object advancement identifier data. Then, based on the advancement phase node data and the node positions in the receiving safety baseline map data, cross-sectional mapping processing is performed to generate current processing cross-sectional data, including: The business progress trajectory data is processed by merging events according to the target business object to obtain the object progress event chain; Based on the stage switching records in the object advancement event chain, determine the advancement stage node corresponding to the target business object and generate the advancement stage node data; Using the object identifier of the target business object as the main identifier, the processing node identifier and the result association identifier corresponding to the advancement stage node data are written into the same identifier mapping structure to generate the object advancement identifier data. Based on the node positions in the security baseline map data of the advancement stage, the processing node range and processing boundary that the target business object has entered are determined, and the current processing section data is generated.
3. The network security handling and control method based on business advancement section convergence according to claim 2, characterized in that, The step of constructing forward-expanding cross-sectional data based on the current processed cross-sectional data as the cross-sectional reference and the receiving safety reference map data includes: Taking the processing action boundary corresponding to the current processing section data as the starting point of the section, the acceptance relationship is extended along the business advancement direction in the acceptance safety benchmark map data to obtain the subsequent acceptance section data; In the received safety baseline map data, extract the collaborative processing nodes that have collaborative trigger edges with the current processing section data, and generate parallel collaborative section data; According to the advancement direction of the target business object, the subsequent receiving section data and the parallel collaborative section data are subjected to section continuation processing to obtain the forward expansion section data.
4. The network security handling and control method based on business advancement section convergence according to claim 3, characterized in that, The step of constructing reverse write-back cross-section data based on the write-back security baseline map data, and performing cross-section alignment processing on the forward extension cross-section data and the reverse write-back cross-section data according to the object advancement identification data to obtain advancement write-back cross-section aligned data includes: Using the result action node corresponding to the result association identifier in the object advancement identifier data as the write-back starting point, write-back association tracking is performed along the result write-back direction in the write-back security baseline map data to obtain candidate write-back cross-section data; Based on the object advancement identification data, the preceding object domain node and preceding system domain node that have a result interaction relationship with the target business object are determined in the candidate write-back cross-section data, and the reverse write-back cross-section data is generated. The nodes in the forward expansion section data that carry forward connection relationships and the nodes that carry collaborative triggering relationships are determined as forward action nodes, and the nodes in the reverse write-back section data that carry result write-back are determined as write-back action nodes. Based on the object advancement identification data, a result connection relationship is established between the forward action node and the write-back action node to generate the advancement write-back section alignment data.
5. The network security handling and control method based on business advancement section convergence according to claim 4, characterized in that, The aforementioned security baseline map data is used as the forward boundary verification baseline to identify the forward extension section in the forward write-back section alignment data, thereby obtaining the forward boundary crossing marker data. Using the writeback security baseline map data as the writeback boundary verification baseline, writeback boundary overrun identification is performed on the reverse writeback section in the push writeback section alignment data to obtain writeback boundary overrun marker data; The propulsion out-of-bounds marker data and the write-back out-of-bounds marker data are associated with the propulsion write-back section alignment data to generate section anomaly marker data, including: The authorized acceptance boundary is extracted from the acceptance safety baseline map data, and the forward action node in the advance write-back section alignment data is compared with the authorized acceptance boundary to obtain the forward boundary matching result; Based on the forward boundary matching results, determine the forward action nodes that exceed the authorized acceptance boundary, and generate the advance boundary crossing marker data; The authorized write-back boundary is extracted from the write-back security baseline map data, and the write-back application node in the advance write-back section alignment data is compared with the authorized write-back boundary to obtain the write-back boundary matching result; Based on the write-back boundary matching results, identify the write-back application nodes that exceed the authorized write-back boundary and generate the write-back out-of-bounds marker data; The propulsion out-of-bounds marker data and the write-back out-of-bounds marker data are associated and labeled to the corresponding forward action node and write-back action node in the propulsion write-back section alignment data to generate the section anomaly marker data.
6. The network security handling and control method based on business advancement section convergence according to claim 5, characterized in that, The process involves generating a progressive convergence gating sequence based on the cross-section anomaly marker data and the currently processed cross-section data; mapping the progressive convergence gating sequence to the advance-write-back cross-section alignment data; assigning a forward convergence marker to the forward action nodes in the forward expansion cross-section data; and assigning a write-back convergence marker to the write-back action nodes in the reverse write-back cross-section data, thereby obtaining service advance cross-section convergence control data, including: Based on the out-of-bounds direction and degree in the cross-section anomaly marker data, determine the convergence level data corresponding to the forward action node and the write-back action node respectively; based on the current processing cross-section data, determine the cross-section convergence order data of the convergence level data relative to the current processing cross-section; based on the convergence level data and the cross-section convergence order data, generate the cross-section progressive convergence gating sequence; map the cross-section progressive convergence gating sequence to the advance write-back cross-section alignment data to obtain forward convergence marker data and write-back convergence marker data; associate the forward convergence marker data with the forward action node in the forward expansion cross-section data, and associate the write-back convergence marker data with the write-back action node in the reverse write-back cross-section data to obtain the service advance cross-section convergence control data.
7. The network security handling and control method based on business advancement section convergence according to claim 1, characterized in that, The method further includes: Based on the business advancement section convergence control data, acceptance qualification mapping data is constructed in the forward expansion section data. This acceptance qualification mapping data characterizes the acceptance qualification relationship between the target business object and the forward action nodes in the forward expansion section data. The acceptance qualification set corresponding to the target business object is determined based on the acceptance qualification mapping data. The acceptance qualification set is then matched with the advancement boundary crossing marker data to obtain qualification retention marker data and qualification stripping marker data. Based on the qualification retention marker data, acceptance qualifications in the acceptance qualification set not associated with the advancement boundary crossing marker data are retained. Based on the qualification stripping marker data, acceptance qualifications in the acceptance qualification set associated with the advancement boundary crossing marker data are stripped to generate acceptance qualification stripping data. The acceptance qualification stripping data is then associated with the business advancement section convergence control data to restrict the target business object's continued acceptance capability in the forward expansion section data.
8. The network security handling and control method based on business advancement section convergence according to claim 1, characterized in that, The method further includes: When the closure verification result does not meet the preset section closure condition, the section advance margin data corresponding to the forward action node in the forward expansion section data is determined based on the convergence effective status represented by the advance boundary marker data, the write-back boundary marker data, and the section convergence execution receipt data. Based on the matching relationship between the cross-sectional propulsion margin data and the preset propulsion margin boundary, the forward expansion cross-sectional data is subjected to propulsion margin layering processing to obtain cross-sectional layered data; the cross-sectional layered data is used to retain the reliable propulsion cross-section within the forward propulsion range, convert the propulsion cross-section to be verified into an additional verification object, and convert the restricted propulsion cross-section into a compression object. Based on the cross-sectional layering data, the reliable propulsion cross section is retained within the forward propulsion range of the target business object, the restricted propulsion cross section is moved out of the forward propulsion range, and additional verification mark data is generated based on the propulsion cross section to be verified, thus obtaining compressed propulsion cross section data; The operational propulsion section convergence control data is updated based on the compressed propulsion section data and the additional verification mark data.
9. The network security handling and control method based on business advancement section convergence according to claim 1, characterized in that, The method further includes: When the closure verification result does not meet the preset cross-section closure condition, and the cross-section convergence execution receipt data indicates the existence of an unclosed forward action node or an unclosed write-back action node, the derived business object triggered by the target business object is identified, and derived object association data is generated; the derived object association data is mapped to the forward extension cross-section data and the reverse write-back cross-section data to obtain residual action range data; when the residual action range data meets the preset damping condition, derived damping control data is generated based on the residual action range data, and the derived damping control data is used to attenuate the forward propulsion capability and reverse write-back capability of the derived business object; the business propulsion cross-section convergence control data is updated based on the derived damping control data to obtain derived damping update data; the updated residual action range data is determined based on the derived damping update data, and when the updated residual action range data meets the preset cross-section closure condition, the network security handling control result is output.
10. A network security handling and control system based on business advancement section convergence, characterized in that, The system includes: The mapping acquisition unit is used to acquire business advancement trajectory data, acceptance security baseline map data, and write-back security baseline map data corresponding to the target business object. It performs advancement stage positioning processing on the business advancement trajectory data to obtain advancement stage node data and object advancement identifier data. Based on the node positions of the advancement stage node data in the acceptance security baseline map data, it performs cross-section mapping processing to generate current processing cross-section data. The current processing cross-section data is used to characterize the business scope that the target business object has entered. The section alignment unit is used to construct forward expansion section data based on the current processing section data as the section reference, construct reverse write-back section data based on the receiving safety reference map data, and perform section alignment processing on the forward expansion section data and the reverse write-back section data according to the object advancement identification data to obtain advancement write-back section alignment data. The boundary crossing marker unit is used to identify propulsion boundary crossings in the forward extension section of the propulsion write-back section alignment data by using the receiving safety reference map data as the forward boundary verification reference, and to obtain propulsion boundary crossing marker data; and to identify write-back boundary crossings in the reverse write-back section of the propulsion write-back section alignment data by using the write-back safety reference map data as the write-back boundary verification reference, and to obtain write-back boundary crossing marker data; and to associate the propulsion boundary crossing marker data and the write-back boundary crossing marker data with the propulsion write-back section alignment data to generate section anomaly marker data. The gating convergence unit is used to generate a progressive convergence gating sequence based on the cross-section anomaly marker data and the current processing cross-section data, and map the progressive convergence gating sequence to the advance write-back cross-section alignment data. It assigns a forward convergence marker to the forward action node in the forward expansion cross-section data and a write-back convergence marker to the write-back action node in the reverse write-back cross-section data to obtain service advance cross-section convergence control data. The closed output unit is used to generate cross-section handling execution data based on the business advancement cross-section convergence control data, and to perform convergence control processing on the advancement control flow and write-back control flow corresponding to the target business object based on the object advancement identification data and the cross-section handling execution data to obtain cross-section convergence execution receipt data; to perform closure verification on the business advancement cross-section convergence control data according to the cross-section convergence execution receipt data, and when the closure verification result meets the preset cross-section closure condition, to output the network security handling control result for converging the forward advancement range and reverse write-back range of the target business object.
Citation Information
Patent Citations
Network scanning task intelligent segmentation and load balancing method and system
CN121567479A
Virtual data loopback and / or data capture in a computing system
US20130343378A1