Abstract
With the rapid evolution of information technology, enterprise information security management and risk assessment have gained paramount importance. The objective of this study is to offer a comprehensive solution aimed at bolstering the accuracy, security, and efficiency of information security management. This is achieved through the integration of big data and Internet of Things (IoT) technologies, thereby safeguarding critical enterprise data and private information. Effective management of enterprise information security systems is imperative for upholding confidentiality, integrity, and availability, necessitating a holistic approach. This study, through in-depth theoretical analysis, proposes the combination of blockchain technology with big data to enhance the security and trustworthiness of enterprise IoT systems. Starting with practical issues, the study stores identification cards for IoT sensor devices and related information’s hash values in the blockchain, thus establishing an integrated enterprise information security IoT system model that combines big data and blockchain. Finally, the model is tested and subjected to risk assessment. The results show that the model achieves an identification accuracy of 90.941% for system information security management, with stable data transmission latency at around 192 milliseconds, significantly outperforming other algorithms. This research carries significant implications for the field of enterprise information security management by presenting an innovative solution that demonstrates lower communication overhead and higher throughput than alternative algorithms. It not only pioneers a novel approach to managing enterprise information security but also establishes a robust experimental groundwork for the future evolution of intelligent enterprise information security management systems. By enhancing the efficiency of information security and risk assessments, this study aims to propel forward advancements in enterprise information security management, potentially mitigating risks to businesses and individuals alike, thereby contributing to the stability and security of the digital society.
Introduction
This study holds profound implications for the realm of enterprise information security management, introducing an innovative solution characterized by reduced communication overhead and enhanced throughput compared to existing algorithms. It not only forges a new pathway for managing enterprise information security but also lays a solid experimental foundation for the forthcoming development of sophisticated enterprise information security management systems. By elevating the effectiveness of information security and risk assessment processes, this research seeks to advance the field of enterprise information security management significantly, potentially reducing risks for businesses and individuals. Consequently, it contributes to the stability and security of our digital society.
These security challenges pose a serious threat to the business continuity and reputation of enterprises, forcing them to seek more intelligent and comprehensive information security solutions. In this context, this study aims to explore innovative solutions based on big data and IoT technologies to enhance the accuracy, security, and efficiency of enterprise information security management.
The extensive adoption of information technologies such as the IoT and cloud computing across various domains introduces a novel approach to managing vast and diverse datasets. Leveraging the capabilities of big data platforms ensures the enforcement of security policies from both technical and managerial perspectives. Furthermore, these platforms are instrumental in safeguarding big data security, mitigating risks of information exposure, data tampering, loss, and user privacy violations.1,2 The integration of IoT within enterprise operations facilitates real-time data collection, seamless network access, intelligent perception, identification, and the management of developmental and operational processes. This empowers ordinary physical objects to autonomously participate in a networked environment, forming a comprehensive IoT ecosystem. 3
The motivation behind this study is to address the technological gaps in enterprise information security management and tackle the numerous challenges existing information security management systems face. In many cases, current enterprise information security management systems struggle to effectively counter the increasingly complex security threats, resulting in frequent data breaches and hacker attacks, causing significant losses to businesses. Therefore, by combining big data and IoT technologies, this study aims to construct a comprehensive enterprise information security management solution to ensure the security of critical enterprise data and private information. This contributes to enhancing the intelligence level in enterprise information management and provides crucial experimental references for future digital developments.
In summary, this study aims to build an efficient, secure, and intelligent enterprise information security management solution by integrating big data and IoT technologies, offering a feasible approach and experimental reference for the future development of enterprise information security management. This study presents the integration of blockchain technology and large-scale data into the realm of enterprise information, with the purpose of securely storing the hash values of IoT sensor device identification cards (IDs) along with associated data within the blockchain framework. This integration results in the development of an enterprise information security IoT system model, which combines big data with blockchain technology. Subsequently, this model is subjected to a performance evaluation and risk assessment analysis. The aim is to furnish an empirical reference that may contribute to the intellectual advancement of enterprise information security.
This study presents enterprises with an innovative solution for effectively addressing the complex security challenges of today’s information technology landscape. The pioneering model, which integrates big data and IoT technologies, not only enhances the accuracy and security of enterprise information security management but also improves system performance and efficiency. Furthermore, the outcomes of this study hold significant implications for advancing the field of enterprise information security management, contributing to enhancing competitiveness and sustainability in enterprises’ digital transformation journey.
Literature review
The application of big data and IoT technologies in information security
Numerous researchers have investigated the utilization of big data and IoT technologies in information security. For instance, Zhang categorized the vulnerabilities arising from information security threats encountered by the energy Internet. He proposed a system architecture for distributed energy stations within the energy Internet environment and conducted an analysis of the corresponding information security safeguard measures. 4 In a similar vein, Unal et al. offered services pertaining to privacy preservation and secure big data analysis by integrating blockchain technology with Federated Learning (FL). 5 Chen et al. introduced an enhanced Practical Byzantine Fault Tolerance (PBFT) algorithm known as the Feature Grouping and Credit Optimization Byzantine Fault Tolerance (FCBFT) algorithm, aimed at optimizing the consensus efficiency of large-scale consortium chains. 6 Xu et al. proposed a blockchain integration solution for supply chains based on concurrent PBFT consensus, referred to as Concurrent Practical Byzantine Fault Tolerance (C-PBFT), addressing the consensus efficiency challenges arising from rapid node expansion in supply chains. 7 Suliyanti et al. presented the Double-Layer Byzantine Fault Tolerance (DLBFT) algorithm, designed to enhance the scalability and performance of blockchain in the context of information exchange within architectural information models. 8 Kim et al. introduced a mechanism based on reinforcement learning, modeling it as a context-based multi-armed bandit problem to select an optimal set of nodes and optimize vehicle-to-vehicle networks based on Hyperledger Fabric. 9 Navaroj et al. proposed an adaptive PBFT algorithm by categorizing nodes into trusted and faulty nodes, excluding nodes with a flawed reputation from the voting process, thus improving the efficiency and scalability of the consensus process. 10 Butijn et al. conducted a comprehensive survey of the latest research on blockchain technology, covering the definition of blockchain technology, architectural choices, trade-offs, and insights into current applications and challenges. 11 Sedlmeir et al. explored the challenge of excessive transparency faced when applying blockchain in enterprise and public sectors. 12 Zhang et al. elucidated the concept of blockchain and its practicality in contexts like Bitcoin-based online transactions, describing the essential security attributes required to support cryptocurrency systems akin to Bitcoin. 13
Information security testing in simulation environments using big data and IoT technologies
Moreover, to protect user data and maintain the integrity of the training model, simulating attack scenarios within a controlled simulation environment can be an effective strategy to evaluate the robustness of the security measures in place. He et al. introduced a novel access control mechanism based on risk prediction, showing that the machine learning model could implement relevant security policies derived from predictive analytics, thus safeguarding system information resources by regulating access rights. 14 Additionally, Zhu and Du proposed an evaluation framework to assess the logistics service capabilities of maritime enterprises, employing the Analytic Hierarchy Process (AHP) within the domain of logistics service capability evaluation, specifically focusing on maritime logistics. 15 Their findings revealed that this method of logistics capability assessment was highly applicable to the evaluation of marine logistics services, boasting an accuracy rate of 97%. This underscores the potential of analytical and predictive models in enhancing the security and efficiency of various sectors, including logistics and information systems.
Summary
The studies mentioned above have made notable contributions to information security management, privacy protection, and logistics service capability evaluation. Nonetheless, there are still some limitations to consider. For instance, there is a lack of exploration into comprehensive information security management solutions, as well as a dearth of comprehensive system development and testing that combines big data and IoT technologies, which may result in some limitations in terms of privacy protection. Moreover, in terms of evaluation methods, the impact of complex data interactions and system performance on security management has not been fully considered, leading to certain limitations in the accuracy and applicability of assessment results. Given these research gaps, this study aims to address the shortcomings in existing research by proposing a comprehensive enterprise information security management solution based on big data and IoT technologies. It explores an innovative model incorporating blockchain technology to enhance enterprise information security management’s accuracy, security, and efficiency. By meticulously addressing data interactions and system performance in model construction and testing, this study introduces a comprehensive and feasible information security management solution to tackle the present complexities of information security. It also furnishes a dependable experimental reference for the intelligent development of future enterprise information security management systems.
Research method
Analysis of enterprise information security management
Given the widespread adoption of technologies such as big data and IoT across diverse domains, enterprises have accumulated vast databases. Moreover, the intricate organizational structures within companies have led to the proliferation of interconnected management systems and modules. Each business unit encompasses varied product offerings and business types, posing a significant challenge in integrating all these systems seamlessly. Consequently, the company’s data and information security management grapple with a host of new issues, predominantly falling under the categories of management and technology,16–18 as illustrated in Figure 1. Schematic diagram of enterprise information security management (source: author’s own drawing).
In Figure 1, the issues surrounding management-related data and information security primarily include concerns such as neglect of enterprise information security, a flawed management framework, the lack of a specialized department for security oversight, low employee security consciousness, and inadequate threat detection capabilities. Technologically, as enterprises adopt big data and the Internet of Things (IoT), they face a complex array of security challenges. These include vulnerabilities in big data infrastructure, risks in data storage, network security threats, vulnerabilities in information computing models and systems, data breaches during analysis and mining processes, and the threat of attacks targeting extensive datasets. 19
These issues in information management and technology underscore the imperative of data security management in enterprise development. Big data security technology serves as an indispensable means for establishing a robust security assurance system for the big data platform. This technology, in conjunction with authentication, authorization, access control, and security auditing systems, realizes three protective capabilities: monitoring and identification, defense, and audit and recovery across physical, host, network, data, application, and other aspects.20,21 Blockchain technology, functioning as a time-chain structure, essentially operates as a distributed ledger system with mutual verification, ensuring the security and privacy of each network node within the IoT system. 22 Therefore, this study integrates blockchain technology and big data into the IoT system, applying them to enterprise information security management and risk assessment. This integration is of paramount importance for ensuring the healthy and sustainable development of enterprises.
Architecture analysis of the big data platform
The big data technology system encompasses several key components, namely, data acquisition and preprocessing, storage, and analysis, as well as privacy and security considerations.23,24
The stage of big data acquisition and preprocessing encompasses a variety of data types, including structured, unstructured, and semi-structured data such as databases, text, images, videos, and more. The common Extract-Transform-Load (ETL) tool is primarily responsible for the cleansing, transformation, and integration of relational data into the database, serving as the foundation for Online Analysis Processing (OLAP) and data mining. In the phase of data storage and management, big data poses several challenges to the storage system, notably concerning the scale of storage (ranging from petabytes to exabytes), the intricacies of control, and the demand for a wide range of data types and access levels. Additionally, this layer must provide efficient data access interfaces for upper-level applications, facilitating access to petabytes or exabytes of data and enabling real-time, effective processing.25,26 Moving to the stage of big data computing models and systems, the advent of diverse high-level abstractions and models tailored to specific data and computing characteristics has driven the advancement of this technology and its applications. In the analysis and mining phase, data exhibits diversity, dynamism, and heterogeneity, offering greater value compared to small sample datasets. Big data analysis and mining technologies enhance data quality and credibility, aiding users in comprehending semantics and providing intelligent query functionalities. 27
Key issues of enterprise big data security.
Table 1 shows that big data security guarantees are embodied in various mechanisms such as cognition, authorization, and access, including data hiding and encryption, data audit, and monitoring. Blockchain itself does not generate data; rather, it generates and records data through the use of related algorithms within its distributed nodes. Specifically, blockchain is a form of distributed ledger technology that allows participants to share and record transaction data within a network. Each new transaction is encrypted and bundled into a block, which is then added to the blockchain based on a timestamp. These blocks are encrypted using cryptographic algorithms to ensure their security. Simultaneously, blockchain employs a consensus mechanism to ensure that every node in the network agrees on the validity of transaction records, thereby preventing data tampering. This consensus mechanism guarantees the security and data integrity of the blockchain network, making it a reliable means of data storage and exchange, particularly suitable for safeguarding sensitive enterprise information. The security of the blockchain relies on the use of asymmetric encryption algorithms, where transactions are systematically organized into blocks at regular intervals based on timestamps. The consensus mechanism mandates that any modifications to block information necessitate the agreement of more than half of the blockchain nodes to effectuate the change. This stringent process serves to ensure the integrity and immutability of enterprise data and information.28,29
Blockchain technology is applied to enterprise big data systems. This study undertakes a crucial task by amalgamating blockchain technology with Privacy Enhancing Technology (PET) to enhance the level of privacy protection within the system. A PET solution based on homomorphic encryption technology is applied in the context of enterprise information security management and risk assessment. This technology enables data encryption while allowing for computation and analysis without exposing the data’s content. Homomorphic encryption technology is integrated with blockchain technology to augment the system’s privacy protection. The study commences by categorizing and identifying sensitive data within enterprise information systems, pinpointing critical information requiring encryption protection. Subsequently, homomorphic encryption algorithms are employed to encrypt this data, ensuring its safeguarding during transmission and storage. Within the blockchain system, homomorphic encryption technology is used to encrypt the data, ensuring that only authorized users can access and process it. Encrypted data is stored in the blockchain, preserving data security and integrity. In order to further fortify data security, rigorous data access control and identity authentication mechanisms are designed and implemented. These mechanisms ascertain that only authorized users can access encrypted data and obtain the corresponding decryption permissions. The PET solution based on homomorphic encryption technology, in conjunction with blockchain technology, furnishes robust privacy protection capabilities to enterprise information security management systems, guaranteeing the security and confidentiality of sensitive data. The specific organizational interaction architecture of enterprise big data is shown in Figure 2. Schematic diagram of organizational interaction architecture of enterprise big data.
In Figure 2, the organizational interaction architecture of enterprise big data includes three network nodes: Enterprise Information Security Center (EISC), edge node, and department. In this study, addressing the requirements for privacy protection, thoroughly verified hashing, encryption, and decryption solutions were chosen. Specifically, Secure Hash Algorithm-256 (SHA-256) was employed as the hashing function to ensure the security and integrity of data. For encryption and decryption, the Elliptic Curve Digital Signature Algorithm (ECDSA), based on elliptic curve cryptography and rooted in the discrete logarithm problem, was selected. This algorithm provides robust encryption protection. Furthermore, elliptic curve pairings were introduced to offer higher security and protection, ensuring the effective maintenance of data privacy during transmission and processing.
Concerning the privacy protection encryption process for enterprise user identities, an initialization process was conducted as the initial step. This process entails defining two cyclic groups, G1 and G2, with an order of
In equation (3), t refers to the number of digits of the message to be signed and encrypted. The encryption function
The public key
Then, enterprise big data is extracted. All enterprise department nodes need to be sent
Then, the enterprise department can send the public key obtained from EISC to any
Then, the data message is encrypted. If
Finally,
Construction of enterprise information security IoT system model based on big data fusion blockchain
To proficiently oversee the information security of enterprise data, this study introduces blockchain technology and integrates massive data within the enterprise’s information IoT system. Data generated by IoT devices typically possess characteristics such as real-time nature, distribution, and large-scale volume. This data is often generated rapidly and continuously, covering diverse types of information. However, digital signatures alone cannot entirely address the issue of ensuring the integrity of this data. While digital signatures can establish the trustworthiness of data sources, there remains a risk of data tampering during data transmission. Moreover, digital signatures do not provide data tamper resistance; once data is tampered with, digital signatures cannot detect or prevent such tampering. Therefore, it is necessary to combine blockchain technology to protect the integrity of data generated by IoT devices. Blockchain technology can offer distributed and tamper-proof data storage features, enhancing data security and integrity protection. Its decentralized and tamper-resistant attributes are harnessed for the storage of the hash value and pertinent details associated with the ID of IoT sensor devices within the blockchain. The distributed Edge Node is also incorporated to establish close integration with IoT terminal equipment or networks, offering computational resources for sensor nodes, resulting in substantial cost reduction and latency minimization. The introduction of decentralized edge nodes within the enterprise IoT system, coupled with the utilization of smart contracts, facilitates mutual identity authentication among IoT devices, thereby ensuring the accuracy and tamper-proof nature of data. Smart contracts play a pivotal role within the blockchain system, primarily aimed at achieving automated execution and management of contract terms to ensure the security and reliability of transactions. Through smart contracts, participants can engage in trusted transactions without the need for third-party intervention, automatically executing specific conditions and logic. The functions of smart contracts encompass various aspects such as fund transfers, data storage, conditional triggers, and more. In this system, the methods that smart contracts may expose include authentication methods, data encryption and decryption methods, transaction recording methods, and conditional trigger methods. Authentication methods are employed to verify the identities of IoT devices, ensuring that only registered and authenticated devices can partake in system communication. Data encryption and decryption methods serve to safeguard data confidentiality, ensuring privacy during data transmission and storage. Transaction recording methods are responsible for documenting and storing transaction information, guaranteeing transaction integrity and traceability. Conditional trigger methods are activated based on specific conditions to trigger corresponding security policies and control measures, addressing potential security threats and risks. The implementation of these methods ensures the security and reliability of enterprise information, as well as protects the IoT system from potential security threats and risks, effectively managing and maintaining the normal operation of the enterprise’s information security IoT system. In the process of identity authentication, the device establishes an authenticated timestamp, with the appropriate time being stored in the blockchain for access. The model framework of the enterprise information security IoT system, integrated with big data and blockchain technology, is illustrated in Figure 3. Schematic diagram of enterprise information security IoT system model based on big data fusion blockchain.
In Figure 3, authentication of users in physical space and digital users in virtual space is achieved through core technologies, which define the system’s key requirements for identity verification and data management. These core technologies primarily involve three key roles: the enterprise gateway, distributed edge nodes, and IoT devices. Building upon the requirements analysis, the system’s technical architecture is designed, outlining the roles and communication mechanisms between the enterprise gateway, distributed edge nodes, and IoT devices. Specific strategies for utilizing IoT sensors and other devices for user identity authentication and data management are determined. Among these components, the enterprise information management gateway has the capability to utilize IoT sensors and various devices for the management of user identification information within the data center, facilitating the registration of each individual device. On the other hand, the decentralized edge node is strategically positioned in proximity to the IoT sensor equipment at the edge, where it undertakes the localized preprocessing and computation of big data within the enterprise infrastructure. The crucial key pairs for IoT devices are generated using the ECDSA. ECDSA is a digital signature algorithm based on the elliptic curve discrete logarithm problem employed for key pair generation and digital signing. This algorithm utilizes a specific elliptic curve, typically the NIST-standard P-256 curve, as a public parameter. During this process, the private key is randomly generated, while the public key is derived using the openly specified elliptic curve, as calculated in equation (9):
In equation (9),
In the initial stage of the system, the key pairs in the user identity authentication system in the enterprise information security IoT are generated by the elliptic curve encryption algorithm. According to the elliptic curve
The private key
The public key calculation method corresponding to decentralized edge nodes is shown in equation (12):
Then, the calculation method of the private key
The public key
The calculation method of the private key
Pseudocode of enterprise information security IoT system model based on big data fusion blockchain.
Experimental results and discussion
Experimental and simulation environment
This study established an experimental environment simulation system to analyze the feasibility and stability of the enterprise information security IoT system model based on the fusion of big data and blockchain. In terms of hardware, an Intel® Core™ i7-4790 CPU with 8.00 GB RAM was selected for the enterprise information management gateway processor. In addition, edge nodes with a 4-core Cortex-A72 (ARM v8) 64-bit processor and 2.00 GB RAM were used to support data edge processing and transmission. For the application of blockchain technology, on the software side, the Ethereum Virtual Machine (EVM) was used, integrated within the Ubuntu 18.04 LTS operating system. Gannache was employed to launch a private chain for comprehensive testing of smart contracts. In web3j, Gannache’s RPC address was used, along with its default accounts, for contract deployment and compilation. Solidity, Java, and Go programming languages were utilized, and interaction with smart contracts was achieved through the Java library in web3j. Furthermore, 50 Ethereum addresses and 30 nodes were configured to simulate user-perceived device registration and identity verification in real-world application environments. These address and node settings were instrumental in verifying the practicality and scalability of the proposed model.
Experiment and performance evaluation
This study used the National Institute of Standards and Technology (NIST) security dataset, available at Current RDS Hash Sets | NIST. The dataset comprises network security event logs, malware samples, and other data related to information security. The network security event logs contain records of various security events, such as intrusion attempts, network traffic statistics, and abnormal activities. The malware sample dataset includes various types of malicious software samples. When conducting research using the NIST security dataset, the data underwent preprocessing, which included steps such as data cleaning, data integration, data transformation, and data reduction. Data cleaning removed noise, errors, or inconsistencies in the data to ensure data quality. The data integration stage consolidated data from different sources into a unified dataset for ease of subsequent analysis and modeling. Data transformation involves feature extraction or dimensionality reduction. Data reduction involved reducing the dataset’s size through methods like sampling or aggregation, enhancing efficiency, and reducing computational costs during the research process. The study conducted a comparative analysis of the algorithm along with PBFT, 32 Byzantine Fault Tolerance (BFT), 33 and Delegated Byzantine Fault Tolerance (DBFT). 34 This analysis was performed to evaluate the performance of user information security within the proposed model network. He et al. conducted a comprehensive comparison, considering factors such as communication overhead and other relevant aspects. This comparison was conducted to validate the system’s performance and assess the potential risks associated with information leakage.
This study employed a series of validated metrics, including identification accuracy, data transmission latency, communication overhead, and throughput, to effectively quantify and evaluate critical indicators of enterprise information security and risk assessment. These metrics provided an objective basis for the study’s analysis and results. Identification accuracy was calculated as the number of correctly identified samples divided by the total number of samples multiplied by 100%. Data transmission latency was determined by recording timestamps at the beginning and end of data transmission and calculating the time difference between them. Communication overhead was assessed by recording the amount of data sent and received during communication and calculating their total sum. Throughput was calculated by measuring the amount of data transmitted and the time taken for transmission, and then dividing the data transmission amount by the transmission time to obtain the data transmission rate per unit time.
Identification accuracy and time delay analysis of system information security management under different algorithms
The algorithms developed in this study, namely, PBFT, BFT, DBFT, and the approach proposed by He et al. are assessed based on the metrics of accuracy and average delay in the context of information security management. Accuracy assessment is defined as the degree of disparity between the results generated by the system during data processing and the expected outcomes. For a given metric or task, accuracy assessment is typically measured by comparing the similarity between the actual output and the expected output. In the provided data, the “Number of interactions (n)” represents the accuracy of the respective number of interactions, as shown in Figures 4 and 5. Identification accuracy results of system information security management under different consensus mechanisms. Average delay results of system information transmission under different algorithms.

In Figure 4, as the number of interactions increases, the accuracy rate exhibits a trend of initial improvement followed by stabilization. Notably, the accuracy rate of the model algorithm developed in this study significantly outperforms other algorithms. Specifically, at 100 interactio follows the order of priority: the research algorithm in this study > the model algorithm proposed by He et al. > PBFT > DBFT > BFT. The data accuracy of the proposed algorithm exhibits a gradual increase with the rising number of interactions, indicating that the algorithm can provide higher accuracy in data processing. The algorithm proposed by He et al. showed lower performance at lower interaction counts, but as the number of interactions increases, data accuracy also gradually improves. PBFT and DBFT algorithms demonstrate relatively stable data accuracy across various interaction counts, with a slight potential decrease at higher interaction levels. The BFT algorithm exhibits lower performance at lower interaction counts but shows a noticeable improvement in subsequent interactions. Consequently, the data storage model established for the enterprise information security management IoT system demonstrates enhanced performance as the number of interactions increases.
In Figure 5, the average delay demonstrates an upward trend in response to the data volume transmitted by the system, with the model algorithm maintaining a stable average delay of approximately 192 ms when handling 7Mb of data. The order of transmission delay, from lowest to highest, among the algorithms is as follows: the model algorithm proposed by He et al. < PBFT < DBFT < BFT. Thus, considering various data volumes, the blockchain-based enterprise information security management model presented in this study exhibits low latency and facilitates secure network data transmission.
System performance evaluation and analysis under different algorithms
The system throughput and communication overhead of each algorithm are assessed, and the results are depicted in Figures 6 and 7, respectively. Relationship between data volume and communication cost. Results of system throughput.

Figure 6 presents a comparison of the communication overhead between the proposed model algorithm and the alternatives, including PBFT, BFT, DBFT, and He et al. As the volume of hairstyle information data increases, there is an observed upward trajectory in the communication cost for each algorithm. Nevertheless, when conveying an equivalent number of messages, the communication cost associated with this study’s model algorithm is notably lower than other model algorithms. This outcome highlights the system’s enhanced efficiency in terms of message interaction time and consensus-building.
In Figure 7, this study observes a growing trend in system throughput as the transaction rate between nodes escalates. Notably, when the transaction rate between nodes surpasses 120, the throughput rate of the proposed privacy protection algorithm experiences a substantial increase. At a transaction rate of 210 between nodes, the throughput achieves a rate of 157.21 transactions per millisecond. This data indicates that PBFT, BFT, DBFT, and He et al. have the capacity to process more transactions within a block while maintaining looser delay constraints. This leads to an effective enhancement of consensus efficiency, substantial improvement in system throughput, and a more comprehensive risk assessment.
Discussion
In this study, a series of verified metrics, including identification accuracy, data transmission latency, communication overhead, and throughput, were employed to effectively quantify and assess crucial indicators for enterprise information security and risk evaluation. Identification accuracy is defined as the degree of variation between the results produced by the system when processing data and the actual expected results. For a given metric or task, identification accuracy is typically measured by comparing the similarity between the actual output and the expected output. In the provided data, “Number of interactions (n)” represents the accuracy of corresponding interaction counts. Hasan et al. emphasized the constraints imposed by Bangladeshi law on cryptocurrency-based financial transactions and proposed solutions based on mobile banking and digital payments. Additionally, their research mentioned a blockchain solution based on the Hyperledger Sawtooth API, which allows tracking a product’s entire history through scanning QR codes on its packaging. 35 In comparison with Hasan et al.'s study, the model algorithm proposed in this study exhibited superior performance in terms of accuracy and latency, particularly with a higher number of interactions, demonstrating higher accuracy and lower average delay. Li et al. identified the factors affecting enterprise information security investment through the use of the Delphi method, creating a multi-level hierarchical model. 36 The results indicated that the formation of decisions related to enterprise information security investment is influenced by several factors across various levels, including enterprise information security technology levels, information security behaviors, information security regulations, and national policies. This study focused on the multi-level relationships affecting the formation of decisions for enterprise information security investment, highlighting the complexity of such decisions. The aim of this study was to enhance the effectiveness and trustworthiness of enterprise information security management by leveraging big data and IoT technology in combination with blockchain technology. Both studies aimed to analyze the key factors involved in the formation of decisions for enterprise information security and proposed corresponding strategies and solutions. In contrast, this study placed a stronger emphasis on optimizing system performance and efficiency, as well as validating risk assessment within the context of constructing an enterprise information security management model. Siegfried et al. introduced a taxonomy covering six demand dimensions and analyzed the capabilities and limitations of blockchain technology in each of these dimensions. The study revealed areas where blockchain technology aligns well, such as reliability, non-repudiation, and adaptability, while identifying limitations, such as scalability, confidentiality, and performance. 37 In contrast, this study provided an analysis of the capabilities and limitations associated with blockchain technology and verified the superiority of the proposed model algorithm in an actual system. Matenga et al. integrated Industry 4.0 technologies to establish a collaborative and sustainable supply chain, focusing on railway vehicle manufacturers’ supply chain management. Their research introduced an integration of blockchain-based information systems and cloud-based manufacturing process systems. 38 In contrast, this study, while integrating Industry 4.0 technologies to build a supply chain management system, also incorporated the design of blockchain-based information systems and cloud manufacturing process systems to enhance system trustworthiness and management efficiency. It presented an innovative model based on the fusion of big data and blockchain for effectively managing enterprise information security and validating enterprise information security, offering an experimental reference for the intelligent development of enterprise information security management. In conclusion, this study provides empirical evidence of the significant advantages of the proposed enterprise information security management model in terms of enhancing information security management efficiency, reducing latency, and improving system throughput. It offers innovative solutions to address current security challenges and points the way for the future development of enterprise information security management. Therefore, another significant contribution of this study is promoting the development of the field of enterprise information security management at both the theoretical and practical levels and presenting an innovative model to address current security challenges.
Conclusion
Considering the challenges prevalent in enterprise information security system management and technology, this study amalgamates blockchain technology with the vast data within the enterprise’s Information IoT infrastructure. Empirical findings indicate that the model achieves an impressive recognition accuracy of 90.941% for the management of system information security, with a stable data transmission delay of approximately 192 milliseconds. Furthermore, the system exhibits superior performance in terms of communication overhead and throughput, thereby offering a robust experimental foundation for the advancement of intelligent enterprise information security management. However, this study also has certain limitations. Firstly, while the model exhibits impressive accuracy in identification, further refinement of the algorithm is required to enhance the overall system performance. Secondly, the big data analysis methods employed in the model may be influenced by data scale and quality, necessitating a more thorough consideration of data accuracy and integrity.
Furthermore, the scalability and applicability of the model in practical large-scale enterprise environments require further validation. In the future, this study could be expanded and enhanced in several aspects. Firstly, integrating more advanced machine learning and artificial intelligence algorithms could augment the system’s automation and predictive capabilities, thereby optimizing the effectiveness of enterprise information security management and risk assessment. Secondly, developing strategies to counter ever-evolving security threats and attacks, such as fortifying the model’s security defense mechanisms and emergency response capabilities, is crucial to combat increasingly complex and covert security challenges. Additionally, extending the application of this model to a broader spectrum of enterprise environments, encompassing diverse types and scales, would comprehensively assess its applicability and practicality, enhancing its performance and stability through ongoing experimentation and validation. In summary, this study provides valuable insights into the field of enterprise information security management and offers useful guidance and references for future research and practices.
Statements and declarations
Footnotes
Conflicting interest
The authors declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Funding
The author(s) disclosed receipt of the following financial support for the research, authorship, and/or publication of this article: This work was supported by the Project of Hunan Social Science Achievement Evaluation Committee in 2020 (No. XSP20YBC175).
