Full-process data protection method and system for procurement management
By building a full-process procurement management database stored in blockchain, the problem of data protection measures in existing technologies affecting data call efficiency has been solved, and the security and responsiveness of data in the entire process have been improved.
Patent Information
- Application Number
- PCT/CN2024/085803
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-19
- Filing Date
- 2024-04-03
- Publication Date
- 2025-09-25
AI Technical Summary
In existing technologies, data protection measures are unable to fully protect the entire process data of procurement management, affecting the efficiency of data retrieval.
By obtaining the target access request and judging whether it complies with the predetermined access logic, the target digital middle platform of the procurement management full process database is constructed and stored on the blockchain information chain. The target object code is obtained based on the target object information index, and the order is retrieved and downloaded under the blockchain information chain, and the target object order is sent.
It improves data security throughout the entire process while ensuring data call responsiveness, thereby enhancing the data security and efficiency of procurement management.
Smart Images

Figure CN2024085803_25092025_PF_FP_ABST
Abstract
Description
Full-process data protection method and system for procurement management Technical Field
[0001] The present invention relates to the field of data security technology, and in particular to a full-process data protection method and system for procurement management. Background Art
[0002] In procurement management, data protection is crucial for ensuring smooth procurement activities and information security. Traditional data protection methods primarily include data encryption, access control, and backup measures. However, these methods are often limited to specific steps or data types and fail to fully protect data throughout the entire procurement management process. Furthermore, there are technical issues with data protection methods that can affect data access efficiency. Summary of the Invention
[0003] The purpose of the present invention is to provide a full-process data protection method and system for procurement management. This method addresses the technical problem in existing technologies where data protection measures affect data access efficiency, thereby improving full-process data security while ensuring data access responsiveness.
[0004] In a first aspect, the present invention provides a full-process data protection method for procurement management, wherein the method comprises:
[0005] Obtain a target access request, where the target access request refers to a data access request made by a target user under his or her target role; determine whether the target access request complies with a predetermined access logic; if so, construct a target digital middle platform for a procurement management full-process database in combination with the target user and the target role, wherein the procurement management full-process database is stored on a blockchain information chain; obtain a target object code by indexing the target digital middle platform according to the target object information in the target access request; perform order retrieval and download under the blockchain information chain based on the target object code to obtain a target object order; and send the target object order to the target user.
[0006] In a second aspect, the present invention further provides a full-process data protection system for procurement management, wherein the system comprises:
[0007] A request receiving module, the request receiving module is used to obtain a target access request, the target access request refers to a data access request made by a target user under his target role; a logic checking module, the logic checking module is used to determine whether the target access request complies with a predetermined access logic; a data transfer module, the data transfer module is used to, if it complies, combine the target user and the target role to construct a target digital middle platform for the procurement management full-process database, wherein the procurement management full-process database is stored on the blockchain information chain; an object indexing module, the object indexing module is used to obtain a target object code by indexing the target digital middle platform according to the target object information in the target access request; an order retrieval module, the order retrieval module is used to retrieve and download orders based on the target object code under the blockchain information chain to obtain a target object order; an order communication module, the order communication module is used to send the target object order to the target user.
[0008] One or more technical solutions provided in the present invention have at least the following technical effects or advantages:
[0009] The system obtains a target access request (a data access request made by a target user under their target role); determines whether the target access request complies with the predetermined access logic; if so, constructs a target digital middle platform for the procurement management full-process database, combining the target user and target role. This database is stored on the blockchain information chain; obtains the target object code based on the target object information in the target access request; retrieves and downloads an order based on the target object code on the blockchain information chain to obtain the target object order; and sends the target object order to the target user. This achieves the technical effect of improving data security throughout the entire process while ensuring data call responsiveness.
[0010] The above description is only an overview of the technical solution of the present invention. In order to more clearly illustrate the technical means of the present invention and to implement it in accordance with the contents of the specification, and to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are specifically listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] The embodiments of the present invention and the following brief description are illustrated in conjunction with the accompanying drawings, which are described as follows:
[0012] FIG1 is a flow chart of a full-process data protection method for procurement management according to the present invention;
[0013] FIG2 is a schematic structural diagram of the full-process data protection system for procurement management according to the present invention.
[0014] Description of the accompanying drawings: request receiving module 11, logic checking module 12, data transfer module 13, object indexing module 14, order retrieval module 15, order transmission module 16. Best Mode for Carrying Out the Invention
[0015] Example 1 Modes for Carrying Out the Invention
[0016] The technical solution provided in the embodiments of the present invention is to solve the technical problem in the prior art that data protection measures affect data call efficiency. The overall concept adopted is as follows:
[0017] First, a target access request is obtained. A target access request refers to a data access request made by a target user under their target role. Next, a determination is made as to whether the target access request complies with the predetermined access logic. If so, the target digital middle platform, combining the target user and target role, is constructed to represent the database for the entire procurement management process. This database is stored on the blockchain information chain. Next, the target object code is retrieved from the target digital middle platform based on the target object information in the target access request. Then, based on the target object code, an order is retrieved and downloaded from the blockchain information chain to obtain the target object order. Finally, the target object order is sent to the target user. This achieves the technical effect of improving data security throughout the entire process while ensuring data call responsiveness.
[0018] The above technical solution will be described in detail below in conjunction with the accompanying drawings and specific implementation methods of the specification to better understand the above technical solution. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments of the present invention. It should be understood that the present invention is not limited to the example embodiments used only to explain the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention. In addition, it should be noted that, for the convenience of description, only the parts related to the present invention, rather than all, are shown in the drawings.
[0019] Example 1
[0020] As shown in FIG1 , the present invention provides a full-process data protection method for procurement management, the method comprising:
[0021] S100: Obtain a target access request, where the target access request refers to a data access request made by a target user under his target role;
[0022] A target access request is a data access request made by a target user in their target role. Each user has one or more roles, and different roles have different permissions. For example, a user may have both employee and administrator roles within a company. The employee role may only access certain data, while the administrator role has full access. A target access request is a request for data operations by a user in different roles.
[0023] S200: Determine whether the target access request complies with a predetermined access logic;
[0024] Optionally, the predefined access logic includes trustworthiness and time constraints. For example, based on the user's role and permissions, a determination is made as to whether the user is trustworthy enough to perform the access operation. Trustworthiness can be assessed based on the user's historical behavior, role, and other factors. Based on the timestamp of the access request and the time constraints defined in the predefined access logic, a determination is made as to whether the access request falls within the permitted time range. If it does not fall within the time range, the predefined access logic is determined to be incompatible with the predefined access logic.
[0025] Optionally, the trustworthiness and time constraints within the predefined access logic are comprehensively considered. If both are consistent with the predefined access logic, the access request is considered to be consistent with the predefined access logic. If either is inconsistent, the request is considered to be inconsistent with the predefined access logic. Through these steps, whether the target access request complies with the predefined access logic can be determined, ensuring the security and compliance of data access.
[0026] S300: If the target user and the target role are met, a target digital middle platform for a procurement management full-process database is constructed, wherein the procurement management full-process database is stored on a blockchain information chain;
[0027] Optionally, if the target access request conforms to the predetermined access logic, relevant data for the entire procurement management process, including procurement plans, purchase orders, supplier information, procurement contracts, and delivery information, will be collected and stored based on the target access request. Next, a database for the entire procurement management process will be constructed based on the collected data. This database must be able to support multi-dimensional data query and analysis. Finally, all purchase orders related to the target user and target role will be stored in the target digital middle platform. This platform will integrate user interfaces and data analysis tools to provide unified data management and application interfaces, thereby improving the efficiency and transparency of procurement management. Furthermore, blockchain-based storage can enhance data security and credibility.
[0028] Optionally, the full procurement management process database is stored on the blockchain information chain. This database serves as an index structure, mapping object information to object codes. When an object is needed, the database is indexed, the corresponding object code is found, and then the object is retrieved and downloaded off-chain. By storing objects off-chain, the amount of information on-chain can be reduced, thereby achieving a lightweight blockchain. Only the object code and related metadata need to be stored on-chain, not the actual object data.
[0029] S400: Obtaining a target object code according to the target object information in the target access request and indexing the target digital platform;
[0030] Optionally, the target digital middle platform interacts with the procurement management full-process database, matches the target object information with the object information in the database, and finds the corresponding target object code. Based on the matching result, the target object code is obtained for subsequent data access and operations. Through the above steps, the target object code is obtained by indexing the target digital middle platform based on the target object information in the target access request, achieving precise positioning and retrieval of the target object.
[0031] Optionally, the target object information is basic information of the target object obtained from the target access request, illustratively including object name, type, etc.
[0032] S500: Search and download the order in the blockchain information chain based on the target object code to obtain the target object order;
[0033] Optionally, order retrieval and downloading are performed under the blockchain information chain based on the target object code. First, the obtained target object code is used as a parameter to perform order retrieval under the blockchain information chain to find the order information associated with the target object code; then, the retrieved target object order information is downloaded to the local or target system, such as the target digital middle platform, for subsequent processing or use.
[0034] S600: Send the target object order to the target user.
[0035] Optionally, the target digital middle platform transmits the target object order to the target user based on the network connection, and confirms that the target user has successfully received the order information, exemplarily through receipt confirmation or other means.
[0036] Optionally, use an appropriate encryption algorithm (such as AES or RSA) to encrypt the target order information to ensure its security during transmission. A digital signature algorithm (such as RSA or DSA) is used on the encrypted order information to generate a digital signature, which is used to verify the integrity and authenticity of the order information. After receiving the encrypted order information and digital signature, the target user uses the corresponding decryption algorithm to decrypt the order information and verify the validity of the digital signature to ensure the integrity and authenticity of the order information. Through these steps, the target order can be securely sent to the target user, ensuring the security and integrity of the order information during transmission.
[0037] In some embodiments, determining whether the target access request complies with a predetermined access logic includes:
[0038] Analyzing the target behavior record of the target user to obtain target trustworthiness;
[0039] Analyzing database access records of the procurement management full-process database to obtain an average target role trustworthiness of the target role;
[0040] Combining the target trustworthiness with the average target role trustworthiness to obtain a request trustworthiness index of the target access request;
[0041] Determining whether the request credibility index reaches a predetermined credibility threshold in the predetermined access logic;
[0042] When the request credibility index reaches the predetermined credibility threshold, determining whether the target request time in the target access request is within a predetermined target access time domain, wherein the predetermined target access time domain refers to an access time domain corresponding to the target role in the predetermined access logic;
[0043] If so, the target access request complies with the predetermined access logic.
[0044] Optionally, the target user's credibility can be evaluated by analyzing the target user's behavior records, such as historical access records, operation records, etc., to ensure that the target user who requested the access is a genuine user.
[0045] Optionally, a request credibility index for the target access request is calculated by combining the target user's credibility and the target role's average credibility. This includes taking a weighted sum or product of the target user's credibility and the target role's average credibility. The resulting request credibility index can be used to assess the credibility of the target access request and further determine whether the request complies with predetermined logic.
[0046] Optionally, first, the calculated request credibility index is compared with a predetermined credibility threshold. If the request credibility index reaches or exceeds the predetermined credibility threshold, the next step is performed; otherwise, the request is considered untrustworthy and does not comply with the predetermined access logic.
[0047] Optionally, if the request credibility index reaches or exceeds a predetermined credibility threshold, the target request time in the target access request is obtained. A determination is then made as to whether the target request time falls within a predetermined target access time domain. If so, the target access request complies with the predetermined access logic; otherwise, it does not. The predetermined target access time domain represents a time limit for access to the target role. For example, a role may only have a certain access right during a predetermined time period within a unit period.
[0048] Furthermore, analyzing the target user's target behavior record to obtain the target trustworthiness includes:
[0049] The target behavior record includes multiple database access records of the target user;
[0050] determining whether a first database access record among the multiple database access records conforms to a predetermined access category;
[0051] If it does not match, add the first database access record to the abnormal access list; if it does not match, add the first database access record to the safe access list;
[0052] The predetermined access categories include illegal connection categories, unauthorized access categories, and predetermined port scanning categories;
[0053] The target trustworthiness of the target user is obtained according to the number of records in the abnormal access list and the safe access list.
[0054] Optionally, multiple database access records for the target user are obtained, including information such as access time and access objects. The database access records are then checked to see if they fall into predefined access categories, such as illegal connections, unauthorized access, and port scanning. The illegal connection category checks whether access records involve unauthorized connection attempts or illegal access. The unauthorized access category checks whether access records contain access actions that exceed the user's permissions. The predefined port scanning category checks whether access records involve scanning the target port.
[0055] Optionally, records of illegal connections, unauthorized access, and pre-defined port scans are added to an abnormal access list. The target user's credibility is calculated based on the number of records in the abnormal access list and the security access list. The credibility calculation method can be adjusted based on specific needs and circumstances. For example, credibility is calculated based on the 3 Sigma method: the number of abnormal accesses is divided by the total number of accesses to obtain the abnormal access rate. The mean and standard deviation of the total number of accesses are then calculated. The 3 Sigma range is calculated based on the mean and standard deviation, and the abnormal access rate is compared with the 3 Sigma range. If the abnormal access rate exceeds the 3 Sigma range, the user's access behavior is considered abnormal.
[0056] Optionally, different user roles correspond to different exception access lists. The same access behavior is different for user roles with different access rights.
[0057] Furthermore, the database access records of the procurement management full process database are analyzed to obtain the average target role trustworthiness of the target role, including:
[0058] The database access record includes multiple behavior records of multiple users accessing the database with the target role;
[0059] The average of the first trustworthiness of the first behavior record and the second trustworthiness of the second behavior record is taken as the average target character trustworthiness, where the first behavior record is any behavior record among the multiple behavior records, and the second behavior record is any behavior record among the multiple behavior records that is different from the first behavior record.
[0060] For example, the average target role trustworthiness is analyzed and obtained. First, based on database access records, multiple behavior records of multiple users accessing the database as the target role are collected, including information such as access time and access object. Then, any two different access records are selected from all users' access records, recorded as the first behavior record and the second behavior record. Next, the average trustworthiness of the first behavior record and the trustworthiness of the second behavior record are taken as the average target role trustworthiness. This process is repeated by selecting different access records and calculating the average trustworthiness of these records until all users' access records have been processed. The average target role trustworthiness is then calculated, thereby assessing the overall trustworthiness of the character.
[0061] In some embodiments, the full-process data protection method for procurement management further includes:
[0062] Generate a target access log, wherein the target access log refers to a record log of the target user accessing the target object order;
[0063] The target access log is added to the target behavior record of the target user and the database access record of the procurement management full-process database respectively.
[0064] Optionally, based on the obtained target access request, a target access log is generated, and then the generated target access log is updated to the target user's target behavior record and the database access record of the procurement management full-process database, which are used to evaluate the trustworthiness of the target user and trace the database access situation respectively.
[0065] In some embodiments, before building the target digital middle platform for the procurement management full-process database, the following steps are included:
[0066] Establishing a first set of involved personnel for a first purchase order in the purchase order set, wherein the first set of involved personnel includes a plurality of involved personnel having role identifiers;
[0067] Obtaining a first order information set for the first purchase order, the first order information set including the order contract date, order contract number, supplier information, purchase material type, purchase material model, purchase material quantity, purchase material unit price, material delivery deadline, material delivery method, and warehouse in / out records;
[0068] Encoding the order contract number of the first purchase order based on an encryption algorithm principle to obtain a first order code;
[0069] Establishing a first mapping relationship between the multiple persons involved with role identifiers, the first order information set, and the first order code;
[0070] The procurement management full-process database is formed based on the first mapping relationship.
[0071] Optionally, before constructing the target digital middle platform for the procurement management full-process database, the procurement management full-process database is first constructed or updated. For example, first, the personnel with role identifications involved are obtained from the first purchase order to form a first set of involved personnel. Then, the order contract date, order contract number, supplier information, type of purchased materials, model of purchased materials, quantity of purchased materials, unit price of purchased materials, material delivery period, material delivery method, warehouse in and out records and other information are obtained from the first purchase order to form a first order information set. Next, the order contract number is encoded using an encryption algorithm to obtain the first order code, and the order contract number is converted into a string of ciphertext. Only those with the decryption key can restore it to the original order contract number. This effectively protects the privacy and security of the order contract number. Then, based on the database language and management tools, a mapping relationship is established between the personnel involved, the order information set and the order code to form a procurement management full-process database.
[0072] Through the above steps, a procurement management full process database including personnel, order information and order codes is constructed to record and manage relevant information in the procurement process.
[0073] In some embodiments, the target object information includes one or more of the target order information sets of the target object orders.
[0074] Optionally, the target object information refers to at least one or more information sets of the target object order, and the amount of information required to be included in the target object information is determined based on the security requirements of the target scenario or the target order.
[0075] For example, for orders with different security levels, the target object information may include key order information, such as order number, amount, supplier information, delivery date, etc., as well as other order-related information, such as payment information and delivery method. Orders with different security levels may require different amounts of information and security measures to protect the security of order information.
[0076] By limiting the information items included in the target object information, it is ensured that only users who know some information about the order can perform order retrieval, thereby improving information security in the target scenario.
[0077] In some embodiments, the full-process data protection method for procurement management also includes monitoring and protecting the procurement material warehouse based on a predetermined physical protection plan, and the predetermined physical protection plan includes at least one of setting warehouse access control and setting warehouse monitoring.
[0078] Optionally, you can monitor and protect the procurement material warehouse based on a pre-defined physical protection plan. Setting up warehouse access control can restrict unauthorized access and ensure the safety of materials within the warehouse. Setting up warehouse monitoring can monitor the warehouse's internal conditions in real time through video surveillance and other means, allowing you to promptly detect and respond to any abnormalities, improving material safety and management efficiency.
[0079] In summary, the full-process data protection method for procurement management provided by the present invention has the following technical effects:
[0080] Obtain a target access request, which refers to a data access request made by a target user under their target role; determine whether the target access request complies with the predetermined access logic; if so, build a target digital middle platform for the procurement management full-process database based on the target user and target role, where the procurement management full-process database is stored on the blockchain information chain; obtain the target object code based on the target object information in the target access request through the target digital middle platform index; retrieve and download the order based on the target object code on the blockchain information chain to obtain the target object order; and send the target object order to the target user. This achieves the technical effect of improving data security throughout the entire process while ensuring data call responsiveness.
[0081] Example 2
[0082] Figure 2 is a schematic diagram of the structure of the full-process data protection system for procurement management of the present invention. For example, the flowchart of the full-process data protection method for procurement management of the present invention in Figure 1 can be implemented by the structure shown in Figure 2.
[0083] Based on the same concept as the full-process data protection method for procurement management in the above embodiment, the present invention also provides a full-process data protection system for procurement management, the system comprising:
[0084] The request receiving module 11 is used to obtain a target access request, where the target access request refers to a data access request made by a target user under his target role;
[0085] a logic checking module 12, configured to determine whether the target access request complies with a predetermined access logic;
[0086] The data transfer module 13 is used to build a target digital middle platform for the procurement management full process database based on the target user and the target role if it meets the requirements, wherein the procurement management full process database is stored on the blockchain information chain;
[0087] An object indexing module 14 is configured to obtain a target object code by indexing the target object information in the target digital medium according to the target object information in the target access request;
[0088] An order retrieval module 15 is used to retrieve and download orders from the blockchain information chain based on the target object code to obtain the target object order;
[0089] The order transmission module 16 is used to send the target object order to the target user.
[0090] Furthermore, the logic checking module 12 further includes:
[0091] A target trustworthiness analysis unit, configured to analyze the target behavior record of the target user to obtain target trustworthiness;
[0092] A target role trustworthiness analysis unit, configured to analyze database access records of the procurement management full-process database to obtain an average target role trustworthiness of the target role;
[0093] a request trust index unit, configured to obtain a request trust index of the target access request by combining the target trustworthiness and the average target role trustworthiness;
[0094] a trust threshold determination unit, configured to determine whether the request trust index reaches a predetermined trust threshold in the predetermined access logic;
[0095] an access time domain determining unit, configured to determine, when the request credibility index reaches the predetermined credibility threshold, whether the target request time in the target access request is within a predetermined target access time domain, wherein the predetermined target access time domain refers to the access time domain corresponding to the target role in the predetermined access logic;
[0096] The request compliance unit is configured to: if , the target access request complies with the predetermined access logic.
[0097] Furthermore, the trustworthiness analysis unit further includes:
[0098] A predetermined access category unit, configured to determine whether a first database access record among the plurality of database access records conforms to a predetermined access category; wherein the predetermined access category includes an illegal connection category, an unauthorized access category, and a predetermined port scan category;
[0099] a list accumulation unit, configured to add the first database access record to an abnormal access list if the access is in compliance with the requirements, and to add the first database access record to a safe access list if the access is not in compliance with the requirements;
[0100] The target trustworthiness calculation unit is configured to obtain the target trustworthiness of the target user according to the number of records in the abnormal access list and the safe access list.
[0101] Furthermore, the target role trustworthiness analysis unit also includes:
[0102] An average target role trustworthiness unit is used to take the average of the first trustworthiness of a first behavior record and the second trustworthiness of a second behavior record as the average target role trustworthiness, where the first behavior record is any behavior record among the multiple behavior records, and the second behavior record is any behavior record among the multiple behavior records that is different from the first behavior record.
[0103] Furthermore, the system further includes a record updating unit, configured to:
[0104] Generate a target access log, wherein the target access log refers to a record log of the target user accessing the target object order;
[0105] The target access log is added to the target behavior record of the target user and the database access record of the procurement management full-process database respectively.
[0106] Furthermore, the data transfer module 13 also includes:
[0107] A personnel unit is used to form a first personnel set involved in a first purchase order in the purchase order set, wherein the first personnel set involved includes a plurality of personnel involved with role identifiers;
[0108] an order information unit, configured to obtain a first order information set for the first purchase order, the first order information set including the order contract date, order contract number, supplier information, purchase material type, purchase material model, purchase material quantity, purchase material unit price, material delivery deadline, material delivery method, and warehouse in / out records;
[0109] an encryption encoding unit, configured to encode the order contract number of the first purchase order based on an encryption algorithm principle to obtain a first order code;
[0110] an association mapping unit, configured to establish a first mapping relationship between the plurality of persons involved with role identifiers, the first order information set, and the first order code;
[0111] A structured processing unit is used to form the procurement management full-process database based on the first mapping relationship.
[0112] Furthermore, the system further includes a physical protection unit for:
[0113] The purchased material warehouse is monitored and protected based on a predetermined physical protection plan, and the predetermined physical protection plan includes at least one of setting warehouse access control and setting warehouse monitoring.
[0114] It should be understood that the embodiments mentioned in this specification focus on their differences from other embodiments. The specific embodiments in the aforementioned embodiment one are also applicable to the intelligent monitoring system for the operating status of wind power equipment described in embodiment two. For the sake of brevity of the specification, no further elaboration is given here.
[0115] It should be understood that the embodiments disclosed in the present invention and the above description can enable those skilled in the art to use the present invention to implement the present invention. At the same time, the present invention is not limited to the embodiments mentioned above. It should be understood that those skilled in the art can still modify the technical solutions described in the above embodiments or replace some of the technical features therein with equivalents; and such modifications or replacements do not deviate from the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention and are all included in the scope of protection of the present invention.
Claims
1. A full-process data protection method for procurement management, characterized in that: include: Obtaining a target access request, where the target access request refers to a data access request made by a target user under his or her target role; Determining whether the target access request complies with a predetermined access logic; If it is in line with the requirements, the target digital middle platform of the procurement management full process database is constructed in combination with the target user and the target role, wherein the procurement management full process database is stored on the blockchain information chain; Obtaining a target object code according to the target object information in the target access request and indexing the target digital station; Based on the target object code, the order is retrieved and downloaded under the blockchain information chain to obtain the target object order; Send the target object order to the target user.
2. The full-process data protection method for procurement management according to claim 1 is characterized in that: Determining whether the target access request complies with a predetermined access logic includes: Analyzing the target behavior record of the target user to obtain target trustworthiness; Analyzing database access records of the procurement management full-process database to obtain an average target role trustworthiness of the target role; Combining the target trustworthiness with the average target role trustworthiness to obtain a request trustworthiness index of the target access request; Determining whether the request credibility index reaches a predetermined credibility threshold in the predetermined access logic; When the request credibility index reaches the predetermined credibility threshold, determining whether the target request time in the target access request is within a predetermined target access time domain, wherein the predetermined target access time domain refers to an access time domain corresponding to the target role in the predetermined access logic; If so, the target access request complies with the predetermined access logic.
3. The full-process data protection method for procurement management according to claim 2 is characterized in that: Analyzing the target user's target behavior record to obtain target trustworthiness includes: The target behavior record includes multiple database access records of the target user; determining whether a first database access record among the multiple database access records conforms to a predetermined access category; If it does not match, add the first database access record to the abnormal access list; if it does not match, add the first database access record to the safe access list; The predetermined access categories include illegal connection categories, unauthorized access categories, and predetermined port scanning categories; The target trustworthiness of the target user is obtained according to the number of records in the abnormal access list and the safe access list.
4. The full-process data protection method for procurement management according to claim 3 is characterized in that: Analyzing the database access records of the procurement management full-process database to obtain the average target role trustworthiness of the target role includes: The database access record includes multiple behavior records of multiple users accessing the database with the target role; The average of the first trustworthiness of the first behavior record and the second trustworthiness of the second behavior record is taken as the average target character trustworthiness, where the first behavior record is any behavior record among the multiple behavior records, and the second behavior record is any behavior record among the multiple behavior records that is different from the first behavior record.
5. The full-process data protection method for procurement management according to claim 2 is characterized in that: The method also includes: Generate a target access log, wherein the target access log refers to a record log of the target user accessing the target object order; The target access log is added to the target behavior record of the target user and the database access record of the procurement management full-process database respectively.
6. The full-process data protection method for procurement management according to claim 1 is characterized in that: Before building the target digital middle platform for the procurement management full-process database, it includes: Establishing a first set of involved personnel for a first purchase order in the purchase order set, wherein the first set of involved personnel includes a plurality of involved personnel having role identifiers; Obtaining a first order information set for the first purchase order, the first order information set including the order contract date, order contract number, supplier information, purchase material type, purchase material model, purchase material quantity, purchase material unit price, material delivery deadline, material delivery method, and warehouse in / out records; Encoding the order contract number of the first purchase order based on an encryption algorithm principle to obtain a first order code; Establishing a first mapping relationship between the multiple persons involved with role identifiers, the first order information set, and the first order code; The procurement management full-process database is formed based on the first mapping relationship.
7. The full-process data protection method for procurement management according to claim 6 is characterized in that: The target object information includes one or more items in the target order information set of the target object order.
8. The full-process data protection method for procurement management according to claim 1 is characterized in that: The method also includes monitoring and protecting the purchased material warehouse based on a predetermined physical protection plan, and the predetermined physical protection plan includes at least one of setting warehouse access control and setting warehouse monitoring.
9. A full-process data protection system for procurement management, characterized by: The system is used to perform the method according to any one of claims 1 to 8, and the system comprises: A request receiving module, configured to obtain a target access request, wherein the target access request refers to a data access request made by a target user under his or her target role; A logic checking module, configured to determine whether the target access request complies with a predetermined access logic; A data transfer module, which is used to build a target digital middle platform for the procurement management full process database based on the target user and the target role if it meets the requirements, wherein the procurement management full process database is stored on the blockchain information chain; An object indexing module, configured to obtain a target object code by indexing the target object in the target digital medium according to the target object information in the target access request; An order retrieval module, which is used to retrieve and download orders from the blockchain information chain based on the target object code to obtain the target object order; An order communication module is used to send the target object order to the target user.
Citation Information
Patent Citations
Network access control method and device
CN106850509A
Power grid data sharing method and system based on block chain and data resource directory
CN112463843A
Access control method and device, electronic equipment and computer readable storage medium
CN112906028A
Data security management method and device, data cloud platform and storage medium
CN114239015A