Why is data security important? How to protect it?
General Secretary of the Supreme Leader attaches great importance to network security, pointing out that "there is no national security without network security". The security of cyberspace includes not only the security of the network itself, but also the generalized security of data, information system, intelligent system, information physical integration system and so on. Data security is the foundation of cyberspace security and an important part of national security. Its importance has attracted the attention of government departments, enterprises and institutions, and it is also a research field that researchers need to pay more attention to.

Guan Xiaohong
Academician of China Academy of Sciences,
Director, Department of Electronics and Information, Xi ‘an Jiaotong University,
Chief scientist, Key Laboratory of Intelligent Network and Network Security, Ministry of Education
On September 1, 2021, the Data Security Law of People’s Republic of China (PRC) (hereinafter referred to as the Data Security Law) came into effect, which further ensured that data was in a state of effective protection and legal utilization, so as to better protect the legitimate rights and interests of individuals and organizations and safeguard national sovereignty, security and development interests. Based on this, it is necessary to adopt a two-pronged approach of technology and management, put forward systematic countermeasures and solutions, and formulate relevant standards and implementation methods.
Connotation of data security
Data security refers to taking necessary measures to ensure that data is in a state of effective protection and legal utilization, and has the ability to ensure a continuous security state. Data security should ensure the safety of the whole process of data production, storage, transmission, access, use, destruction and disclosure, and ensure the confidentiality, integrity and availability of data processing. In addition, we should also deal with the relationship of public data in a heterogeneous way, such as personal name, contact information, vehicle registration, social media and so on. Although these are all non-entity implied data, they often involve personal privacy and may even cause public safety problems such as real-time positioning.
Data security is closely related to network security, information security, system security, content security and information physical integration system security. In order to better understand the connotation of data security, it is necessary to summarize its main related contents.
Network security mainly refers to the safe operation of the Internet, other information networks and computer networks, monitoring and preventing attacks against and from the network, and ensuring the safe operation and legal use of network infrastructure. Data security involves the security in the production, transmission and use of network data, and ensuring the confidentiality, integrity, availability, authenticity and controllability of network data is the main task of network security.
Information security mainly refers to ensuring the availability, confidentiality, integrity and non-repudiation of information in the process of transmission, processing and storage of systems and networks, including the security of cryptographic systems. Among them, the data security involved in information security mainly includes two aspects: first, it refers to the security of the data itself, and generally adopts modern cryptographic algorithms and other technologies to actively protect the data; Second, it refers to the security of data protection, which usually adopts modern information storage and other means to actively protect data.
System security mainly refers to the safe operation of software and hardware information systems such as operating system, cloud system, terminal system and application software system, to ensure that the system is not attacked by malicious codes and other malicious attacks, and to ensure the normal operation and legal use of the system. Data security is the key factor of system operation security.
Content security mainly refers to the authenticity, reliability and legality of information content in the process of network communication. Content security involves the association of users’ multi-source data, the theft of private data, social network confrontation and other security issues.
The security of information and physical integration system mainly refers to the comprehensive security of key infrastructure such as energy and transportation, involving the engineering security of physical system and the network information security of information system and the security under their mutual influence. Information physics fusion system has the characteristics of flowing among data flow, energy flow and material flow. Data security and infrastructure engineering security interact with each other, resulting in new comprehensive security risks.

On May 27th, 2021, 2021 China International Big Data Industry Expo was held in Guiyang, Guizhou Province. The picture shows the participants stepping into the "Digital Expo" site.
The importance of data security
Data security is closely related to network security and is an important part of national sovereignty and national security. General Secretary of the Supreme Leader pointed out that data, as a new production factor, has a great influence on the transformation of traditional production methods. General Secretary of the Supreme Leader stressed: "We must effectively protect national data security. It is necessary to strengthen the security protection of key information infrastructure, strengthen the national key data resource protection capability, and enhance the data security early warning and traceability capabilities. "
Network data is one of the main targets of network attacks, for example, man-in-the-middle attacks may destroy the integrity and authenticity of transmitted data. At present, some network platforms, while providing services, have some problems, such as over-demanding, over-collecting, storing and sharing network data, and even "transferring" the rights and interests of data subjects to unauthorized institutions, thus threatening the security of network data processing and leading to serious network security risks. Ensuring network data security is an important basis for maintaining network security.
Data security is also the core of information security. Under the trend of intelligence, data forgery based on intelligent technology brings new challenges to information security. Taking face information forgery as an example, face data can be falsely generated by intelligent technology, which leads to errors in judgment of human and machine perception systems, personal privacy violations, commercial fraud and other problems, and even social crisis.
In recent years, intelligent systems are facing data security threats such as antagonistic samples and data pollution. Attackers can add malicious input samples formed by subtle interference, which leads to errors in the prediction results of intelligent systems, resulting in serious security risks of intelligent systems; You can even add a certain proportion of malicious samples to the normal sample data set for training through data pollution, which will trigger many intelligent systems to make mistakes and cause security hazards. Therefore, ensuring data security is an important means to maintain system security.
In terms of personal use, users’ data security may cause content security problems. Based on massive multi-source heterogeneous user data, including user interactions such as friends’ relationships, criminals can realize cross-network correlation analysis, generate fake text content with a low threshold, generate guiding information through specific subject content and deliver it to the target group, so as to achieve illegal purposes such as creating social contradictions.
In addition, errors in measurement or control data related to key infrastructure such as energy and transportation may cause cascading failures, resulting in serious security threats to information and physical integration systems. For example, in 2010, the international "earthquake net" attack against nuclear power plants destroyed the normal operation of centrifuges by hijacking and forging malicious control instructions, and at the same time stole and reset the system data during the normal operation of centrifuges to avoid the operation monitoring of the system, which eventually caused serious consequences of a large number of centrifuges being damaged.
To sum up, ensuring data security and promoting data development and utilization can effectively safeguard network security, information security, system security, content security and information physical integration system security, thus safeguarding national sovereignty, security and development interests.
Safeguard measures and innovation paradigm of data security
Ensuring data security is a complex system engineering. The general provisions of the Data Security Law stipulate that the competent departments of industry, telecommunications, transportation, finance, natural resources, health and wellness, education, science and technology shall be responsible for data security supervision in their own industries and fields. Public security organs and state security organs shall, in accordance with the provisions of this Law and relevant laws and administrative regulations, undertake the duties of data security supervision within the scope of their respective duties. In addition, it is stipulated in Article 16 of Chapter II that the state supports the research on data development and utilization and data security technology, encourages technology popularization and business innovation in the fields of data development and utilization and data security, and cultivates and develops data development and utilization and data security products and industrial systems. Therefore, to deal with the threats and challenges faced by data security, it is necessary not only to ensure the security of data in the whole life cycle from the perspective of science and technology, but also to provide legal basis and policy guarantee for data security protection from the perspective of government governance and cooperation with multiple departments by perfecting laws and regulations and establishing a supervision system.
Facing the data security in the whole life cycle of data production, storage, transmission, access, use and destruction, it is difficult to guarantee the accuracy, authenticity, fairness and security of data in the process of data production and collection, so we can establish a data classification management system by means of data classification. At the same time, technologies such as blockchain and digital watermarking can be used to identify and record data sources to prevent malicious tampering. In addition, through malicious data filtering technology, the possible biased samples, forged samples and antagonistic samples in the data are filtered, thus ensuring the safety of data production.
First of all, in view of the security problems such as unauthorized access to data, modification or destruction of data in the process of data storage, data can be encrypted by efficient encryption algorithm to ensure the security of data; Through the key management service, the whole life cycle security management of keys is realized; The data security is guaranteed by various strategies such as storage replication, data redundancy and hard disk protection.
Secondly, in view of the security problems in data transmission, a complete data gene system can be constructed by using data gene technology to ensure traceability, traceability and correlation during data transmission, so as to ensure the correctness of data transmission; Encrypted transmission can be used to encrypt data and secure data transmission through secure transmission protocol.
Thirdly, in view of the various malicious attacks and decryption algorithms in data access, which may lead to malicious and illegal access to data and lead to serious consequences such as data leakage, theft and abuse, new access control and multi-factor authentication mechanisms based on blockchain can be used to verify and authorize user identity.
Finally, in view of the security problems of data use, technologies such as data anonymization and data desensitization can be adopted to ensure that data is accessed and processed within the authorized scope, and to prevent security problems such as data theft, privacy disclosure and damage. In the process of data destruction, common methods are easy to cause incomplete data destruction and malicious recovery of data content, leading to serious security risks such as data leakage. Therefore, data can be completely destroyed or deleted by means of data association destruction, soft destruction and hard destruction.
At present, in order to solve the problem of data security protection, it is urgent to create a new computing paradigm constrained by privacy protection and security, and combine the technologies of edge data storage, decentralized distributed data storage and anonymous sensitive information to build a distributed data security management scheme to realize data security and privacy protection services. For example, enterprises or individuals can store files on edge devices through near-end services such as data encryption, and store data in a decentralized distributed storage system in combination with encrypted transmission. At the same time, they can manage and authorize access to anonymous personal files of sensitive information through blockchain and other technologies to realize data security and privacy calculation subject to security and privacy constraints.
At the same time, we should strengthen the formulation and implementation of data security-related laws and policies to make them an important part of the social governance system, and at the same time strengthen data security supervision and build a data security management system. Through the top-level design, detailed implementation rules are formulated, data ownership, use right and responsibility attribution are divided, and management methods such as hierarchical management and hierarchical protection are implemented. Combined with technical means, the data security computing paradigm based on the organic combination of data hosting and national supervision is realized.
Generally speaking, data security is not only an important aspect of safeguarding national security, but also closely related to personal rights and interests. Therefore, it is necessary to adopt a new paradigm of combining management and technology, establish a life-cycle data security technology system, and realize comprehensive and effective protection of data security.