A data collaboration method and device based on a smart community and a readable storage medium
Patent Information
- Application Number
- CN202310117295.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-30
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2043-01-30
AI Technical Summary
[0003]本发明所要解决的技术问题是针对现有技术的上述不足,提供一种基于智慧社区的数据协作方法、装置及可读存储介质,用以解决现有的基于智慧社区的数据协作方法存在敏感数据泄露、被窃听和篡改的风险的问题
[0029]本发明提供的基于智慧社区的数据协作方法、装置及可读存储介质,首先在智慧社区的各数据方搭建本地可信执行环境;然后验证所述可信执行环境的可信度并得到可信时间段;再在所述可信时间段内,各数据方将其私密数据和计算模型通过预设的安全传输层协议TLS加密通道上载到所述可信执行环境中进行计算,得到计算结果;最后将所述计算结果通过所述TLS加密通道发送给隐私计算平台,以使所述隐私计算平台根据所述计算结果进行融合分析计算,并把融合分析计算结果返回给对应的使用方。本申请通过搭建本地可信执行环境,并在所述本地可信执行环境中进行存储和运算,能够保证智慧社区的数据在该区域在一定时间范围内的代码和数据的安全可信,能够实现隐私保护下智慧社区各数据方的高质量数据协作,助力政务数据安全合规开放及融合应用,且能提高行政管理能力,解决了现有的基于智慧社区的数据协作方法存在敏感数据泄露、被窃听和篡改的风险的问题。
Smart Images

Figure CN116028987B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of smart community technology, and in particular to a data collaboration method, apparatus and readable storage medium based on smart communities. Background Technology
[0002] With the deepening of the construction of Digital China, smart communities have become a major means and project form of social governance. Smart community data includes not only basic data such as population, housing, and property information, but also government data such as video surveillance, traffic, and case data, which contains a large amount of sensitive information with significant value and high sensitivity. Furthermore, to maximize the value of this data, it is necessary to connect with the management platforms of relevant administrative departments, which places high demands on the security and stability of the data use and analysis platforms. In the process of collecting and using resident information, the impact of leaked personal privacy information is enormous. Existing technologies mostly employ dedicated lines, encrypted transmission, and network gateways to securely isolate or manage data transmission and access points. Data needs to be transferred from local storage environments to computing centers for processing, posing risks of sensitive data leakage, eavesdropping, and tampering. Summary of the Invention
[0003] The technical problem to be solved by the present invention is to address the above-mentioned shortcomings of the prior art by providing a data collaboration method, apparatus and readable storage medium based on smart communities, so as to solve the problems of sensitive data leakage, eavesdropping and tampering risks in the existing data collaboration methods based on smart communities.
[0004] In a first aspect, the present invention provides a data collaboration method based on a smart community, the method comprising:
[0005] Build local trusted execution environments for each data provider in the smart community;
[0006] Verify the trustworthiness of the trusted execution environment and obtain a trusted time period;
[0007] During the trusted time period, each data party uploads its private data and computation model to the trusted execution environment through a preset secure transport layer protocol (TLS) encrypted channel for computation, and obtains the computation result.
[0008] The calculation result is sent to the privacy computing platform through the TLS encrypted channel, so that the privacy computing platform can perform fusion analysis calculation based on the calculation result and return the fusion analysis calculation result to the corresponding user.
[0009] Furthermore, the data providers include: government systems, telecom operators, and communities; the trusted execution environment is isolated by hardware.
[0010] Furthermore, the private data is encrypted using a communication key. After establishing a local trusted execution environment at each data provider in the smart community, the method further includes:
[0011] Each data party negotiates and formulates the communication key with the corresponding local trusted execution environment, and constructs the TLS encrypted channel.
[0012] Furthermore, verifying the trustworthiness of the trusted execution environment and obtaining the trusted time period specifically includes:
[0013] The credibility of the trusted execution environment within a preset time period is measured to obtain a credibility metric value;
[0014] If the credibility metric is equal to the preset baseline value, then the preset time period is a credible time period.
[0015] Furthermore, the start and end times of the preset time period are T1~T2, where T1 is the end time of the most recent credibility measurement, T2 is the time when the system was first attacked and destroyed after the most recent credibility measurement ended, and T2≥T1.
[0016] Furthermore, the measurement of the credibility of the trusted execution environment within a preset time period to obtain a credibility metric value specifically includes:
[0017] Calculate the credibility metric values of all trusted metric entities corresponding to the trusted execution environment within a preset time period;
[0018] If the credibility metric is equal to a preset baseline value, then the preset time period is a credible time period, specifically including:
[0019] If the credibility metric values of all the credibility metric entities are equal to the corresponding benchmark value, then the preset time period is a credibility time period.
[0020] Furthermore, after obtaining the calculation result, the method further includes:
[0021] The data in the trusted execution environment is cleared, including the private data, the computation model, and intermediate data during the computation process.
[0022] Secondly, the present invention provides a data collaboration device based on a smart community, comprising:
[0023] The Trusted Environment Setup Module is used to build a local trusted execution environment for various data providers in a smart community.
[0024] The credibility verification module is connected to the trusted environment construction module and is used to verify the credibility of the trusted execution environment and obtain a trusted time period.
[0025] The upload calculation module is connected to the trust verification module and is used to upload each data party’s private data and calculation model to the trusted execution environment for calculation within the trusted time period through a preset secure transport layer protocol TLS encrypted channel to obtain the calculation result.
[0026] The data collaboration module, connected to the upload computing module, is used to send the computing results to the privacy computing platform through the TLS encrypted channel, so that the privacy computing platform can perform fusion analysis computing based on the computing results and return the fusion analysis computing results to the corresponding user.
[0027] Thirdly, the present invention provides a data collaboration device based on a smart community, including a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to implement the data collaboration method based on a smart community described in the first aspect above.
[0028] Fourthly, the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the data collaboration method based on smart communities described in the first aspect.
[0029] This invention provides a data collaboration method, apparatus, and readable storage medium based on smart communities. First, a local trusted execution environment is established for each data provider in the smart community. Then, the trustworthiness of the trusted execution environment is verified, and a trusted time period is obtained. Within this trusted time period, each data provider uploads its private data and computational model to the trusted execution environment via a pre-defined secure transport layer protocol (TLS) encrypted channel for computation, obtaining the computation result. Finally, the computation result is sent to a privacy computing platform via the TLS encrypted channel, enabling the privacy computing platform to perform fusion analysis computation based on the computation result and return the fusion analysis computation result to the corresponding user. By establishing a local trusted execution environment and performing storage and computation within it, this application ensures the security and trustworthiness of the code and data of the smart community within a certain time range in that area. It enables high-quality data collaboration among data providers in the smart community under privacy protection, facilitating the secure, compliant, open, and integrated application of government data, improving administrative management capabilities, and solving the risks of sensitive data leakage, eavesdropping, and tampering inherent in existing smart community-based data collaboration methods. Attached Figure Description
[0030] Figure 1This is a scenario diagram illustrating a data collaboration method based on a smart community, according to an embodiment of the present invention.
[0031] Figure 2 This is a flowchart of a data collaboration method based on a smart community according to Embodiment 1 of the present invention;
[0032] Figure 3 This is a schematic diagram of the structure of a data collaboration device based on a smart community according to Embodiment 2 of the present invention;
[0033] Figure 4 This is a schematic diagram of a data collaboration device based on a smart community according to Embodiment 3 of the present invention. Detailed Implementation
[0034] To enable those skilled in the art to better understand the technical solution of the present invention, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0035] It is understood that the specific embodiments and accompanying drawings described herein are merely for explaining the invention and are not intended to limit the invention.
[0036] It is understood that, without conflict, the various embodiments and features in the embodiments of the present invention can be combined with each other.
[0037] It is understood that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, while the parts unrelated to the present invention are not shown in the drawings.
[0038] It is understood that each unit or module involved in the embodiments of the present invention may correspond to only one entity structure, or may be composed of multiple entity structures, or multiple units or modules may be integrated into one entity structure.
[0039] It is understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of this invention may occur in a different order than that marked in the accompanying drawings.
[0040] It is understood that the flowcharts and block diagrams of this invention illustrate the possible architecture, functions, and operations of systems, apparatuses, devices, and methods according to various embodiments of this invention. Each block in the flowchart or block diagram may represent a unit, module, program segment, or code, containing executable instructions for implementing the specified function. Furthermore, each block or combination of blocks in the block diagram and flowchart can be implemented using a hardware-based system to achieve the specified function, or using a combination of hardware and computer instructions.
[0041] It is understood that the units and modules involved in the embodiments of the present invention can be implemented by software or by hardware. For example, the units and modules can be located in a processor.
[0042] It should be noted that the scenario diagrams described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided in the embodiments of this application. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0043] like Figure 1 The diagram shown illustrates a scenario of a data collaboration method based on a smart community, as provided in this application embodiment. The data providers primarily consist of three parts: government systems, telecom operators, and the community itself. The data providers mainly act as owners of the smart community data and providers of the computational results. Specifically, each part is described below:
[0044] (1) Government system: The government system includes data collection and analysis platforms of relevant management departments. The main types of data are video surveillance data, traffic data, case data, individual objects, personnel relationships, social relationships, individual characteristics, etc. The information collection method is mainly based on web integration technology, supplemented by FTP technology.
[0045] (2) Operators: mainly refers to telecommunications operators, who are the owners of telecommunications business operation data, telecommunications user behavior data, telecommunications terminal equipment data, telecommunications network capability data, telecommunications platform operation capability data, etc.
[0046] (3) Community: The community mainly possesses data from community IoT devices (such as electronic fences), entrance and exit videos, facial recognition data, trajectory data, identity information collection systems, and other related data. The data types mainly consist of smart device network data and basic data such as community property management data, including population, housing, vehicles, organizations, equipment, geographical location, events, public sentiment, video surveillance, access control, etc. The data collected by smart devices includes data collected by millimeter-wave radar, vibration and tilt sensors, smoke and fog sensors, manhole cover monitoring, electricity consumption sensing devices, wearable devices for key personnel supervision, and grid worker terminals.
[0047] (4) Users: mainly the parties authorized to use the data calculation results of the smart community. They can be participants in the construction, operation, management and other related work of the smart community, without specific restrictions. Among them, the data provider can also be a user.
[0048] (5) Trusted Execution Environment: Trusted Execution Environment is a hardware-isolated trusted execution environment technology that provides an independent area for storage and computation on the hardware devices of each data party.
[0049] (6) Privacy Computing Platform: Connects with various data providers or trusted execution environments to achieve the integration of government data with data from communities, operators and other parties.
[0050] It should be noted that the data sources in smart communities are categorized into shareable and non-shareable data based on risk type and confidentiality level. Shareable data mainly refers to publicly available data, such as publicly disclosed community epidemic information; non-shareable data mainly refers to data containing a large amount of sensitive information, possessing significant value and high sensitivity. Shareable data can be connected to a privacy computing platform via a dedicated line. Non-shareable data can be collaboratively processed through multi-party data collaboration using the smart community-based data collaboration method proposed in this invention.
[0051] based on Figure 1 The following is a description of a scenario diagram, followed by relevant embodiments of the data collaboration method based on smart communities involved in this application.
[0052] Example 1:
[0053] This embodiment provides a data collaboration method based on smart communities, such as... Figure 2 As shown, the method includes:
[0054] Step S101: Build a local trusted execution environment for each data provider in the smart community.
[0055] In this embodiment, to address the risks of sensitive data leakage, eavesdropping, and tampering when data from existing smart communities is transferred from local storage environments to computing centers for computation, a local trusted execution environment (TEE) is established for each data provider within the smart community. This TEE technology uses hardware isolation to provide an independent area on the hardware devices of each data provider for storage and computation. The data providers include government systems, telecom operators, and the community itself. Government systems include data collection and analysis platforms from relevant management departments, and telecom operators primarily refer to telecommunications operators.
[0056] Optionally, after establishing local trusted execution environments at each data provider in the smart community, the method further includes:
[0057] Each data party negotiates and formulates a communication key with the corresponding local trusted execution environment, and establishes a TLS (Transport Layer Security Protocol) encrypted channel.
[0058] In this embodiment, to further ensure data transmission security, the control centers and trusted execution environments of each data party negotiate and formulate communication keys, and construct TLS encrypted channels. The keys are stored in the local environment of each data party. Specifically, this method is used to construct encrypted channels between the data party's control center and its local trusted execution environment, between the local trusted execution environment and the privacy computing platform, and between the privacy computing platform and the data user. The communication keys are used to encrypt the transmitted data.
[0059] Step S102: Verify the trustworthiness of the trusted execution environment and obtain the trusted time period.
[0060] In this embodiment, the credibility of the trusted execution environment is verified by measuring the integrity of the computing environment corresponding to the trusted execution environment within a certain period of time, thereby obtaining the trusted time period.
[0061] Optionally, verifying the trustworthiness of the trusted execution environment and obtaining the trusted time period may specifically include:
[0062] The credibility of the trusted execution environment within a preset time period is measured to obtain a credibility metric value;
[0063] If the credibility metric is equal to the preset baseline value, then the preset time period is a credible time period.
[0064] In this embodiment, the start and end times of the preset time period are T1 to T2, where T1 is the end time of the most recent trustworthiness measurement, T2 is the time when the system was first attacked and compromised after the most recent trustworthiness measurement ended, and T2 ≥ T1. If the system is trustworthy within this time period (i.e., the measurement value equals the baseline value), then any point in time within this time period is trustworthy.
[0065] Optionally, the step of measuring the credibility of the trusted execution environment within a preset time period to obtain a credibility metric value specifically includes:
[0066] Calculate the credibility metric values of all trusted metric entities corresponding to the trusted execution environment within a preset time period;
[0067] If the credibility metric is equal to a preset baseline value, then the preset time period is a credible time period, specifically including:
[0068] If the credibility metric values of all the credibility metric entities are equal to the corresponding benchmark value, then the preset time period is a credibility time period.
[0069] In this embodiment, the baseline value is the state value during the initial startup phase of the trusted execution environment. At this time, trusted measurement entities such as the hardware and software platform, operating system, and upper-layer applications have not yet started. This baseline value is denoted as Tsv. The baseline values of all trusted measurement entities are stored in the trusted baseline library Tsd, i.e., the set Tsd = {Tsv1, Tsv2, Tsv3…Tsvn}. Trusted measurement entities mainly include BIOS, BootLoader, host operating system OS, and hypervisor (hardware platform, bootloader, operating system, upper-layer applications), etc. All trusted measurement entities are represented by the set E, where E = {e1, e2, e3…en} represents all entities that affect the integrity of trusted measurement. The baseline value of entity e1 is Tsv1, and the baseline values of entities en are Tsvn.
[0070] In this embodiment, the credibility Tr of all credibility measurement entities within a preset time period is calculated, and the credibility of e1 is recorded as Tr1, the credibility of e2 as Tr2, and so on, up to the credibility Trn of en. The credibility Tr is compared with the benchmark value Tsv. If Tr1 = Tsv1...Trn = Tsvn, it means that the environment is credible at time T, and T = T1; if Tr1 ≠ Tsv1...Trn ≠ Tsvn, it means that the environment is damaged and untrustworthy at time T, and T = T2.
[0071] Step S103: During the trusted time period, each data party uploads its private data and calculation model to the trusted execution environment through a preset TLS encrypted channel for calculation to obtain the calculation result.
[0072] In this embodiment, the private data is encrypted using a communication key. During the time period T1 to T2, each data party uploads its private data and calculation model to the computing unit of the local trusted execution environment through a TLS encrypted channel for calculation, and obtains the corresponding calculation results.
[0073] Optionally, after obtaining the calculation result, the method further includes:
[0074] The data in the trusted execution environment is cleared, including the private data, the computation model, and intermediate data during the computation process.
[0075] In this embodiment, in order to further prevent sensitive data from being leaked or eavesdropped on, the data in the local trusted execution environment is cleared after calculation. This data includes the uploaded raw data and the intermediate data during the calculation process.
[0076] Step S104: The calculation result is sent to the privacy computing platform through the TLS encrypted channel, so that the privacy computing platform performs fusion analysis calculation based on the calculation result and returns the fusion analysis calculation result to the corresponding user.
[0077] In this embodiment, the calculation results are returned to the privacy computing platform via a TLS encrypted channel for fusion analysis and calculation, and the results are then returned to the data user, thereby realizing the fusion of government data with data from multiple parties such as communities and operators. The models and algorithms used for fusion analysis and calculation can be pre-defined according to specific application scenarios, such as cross-domain data queries (identity authentication, etc.), multi-party joint modeling, and data aggregation analysis.
[0078] It should be noted that the trusted execution environment in this invention is hardware-based, resulting in faster execution speeds and performance advantages compared to software implementations. In practice, experiments have also verified that when processing datasets of the same size, the trusted execution environment performs better in terms of time consumption, CPU usage, and memory usage, making it particularly suitable for application scenarios in smart communities that involve large computational demands, complexity, and rapidly changing requirements.
[0079] In one specific embodiment, the data collaboration method based on smart communities may include the following steps:
[0080] (1) Build a local trusted execution environment in various data providers such as communities, public security bureaus, and telecom operators.
[0081] (2) The data party control center and the trusted execution environment negotiate and formulate a communication key to build a TLS encrypted channel. The key is stored in the local environment of each data party. (The encrypted channels between the data party control center and the local trusted execution environment, the local trusted execution environment and the privacy computing platform, and the privacy computing platform and the data user are all built through this method).
[0082] (3) Verify the trustworthiness of the trusted execution environment. Measure the integrity of the computing environment over a certain period of time. If the environment is trustworthy during that period (i.e., the metric equals the baseline value), then any point in time within that period is trustworthy.
[0083] The start and end times of this time period are T1~T2, where T1 is the end time of the most recent credibility measurement, T2 is the time of the first attack and destruction after the end of the most recent credibility measurement (i.e. after T1), and T2≥T1.
[0084] The baseline value is the state value during the initial startup phase of the Trusted Execution Environment (TSE). At this time, the trusted measurement entities, such as the software and hardware platform, operating system, and upper-layer applications, have not yet started. This baseline value is denoted as Tsv. The baseline values of all trusted measurement entities are stored in the Trusted Baseline Library Tsd, i.e., the set Tsd = {Tsv1, Tsv2, Tsv3, ..., Tsvn}.
[0085] Step (3) includes:
[0086] (3-1): Definition of Trusted Measurement Entities. Trusted measurement entities mainly include BIOS, BootLoader, host operating system (OS), and hypervisor (hardware platform, bootloader, operating system, upper-layer applications), etc. All entities are represented by a set E, where E = {e1, e2, e3…en} represents all entities that affect the integrity of the trusted measurement. The baseline value of entity e1 is Tsv1…the baseline value of entity en is Tsvn.
[0087] (3-2): Calculate the credibility Tr of all credibility measurement entities and record the measurement end time T. The credibility Tr of e1 at time T and the credibility Trn of en are recorded.
[0088] (3-3): Compare the credibility Tr with the benchmark value Tsv. If Tr1=Tsv1…Trn=Tsvn, it means that the environment is credible at time T, and T= T1; if Tr1≠Tsv1…Trn≠Tsvn, it means that the environment is damaged and untrustworthy at time T, and T= T2.
[0089] (3-4): The data control center applies for verification T X The trustworthiness of the trusted execution environment at any given time, if T1≤T X If <T2, the feedback indicates a trustworthy execution environment. Otherwise, the feedback indicates an untrustworthy environment, and steps (3-2) and (3-3) are executed again.
[0090] (4) During the T1~T2 time period, each data party uploads its private data and computing model to the computing unit of the local trusted execution environment through the TLS encrypted channel for computing.
[0091] (5) After calculation, the data in the local trusted execution environment is cleared, including the uploaded raw data and the intermediate data in the calculation process.
[0092] (6) The calculation results are returned to the privacy computing platform through the TLS encrypted channel for fusion analysis and calculation, and the results are returned to the data users, thereby realizing the fusion of government data with data from communities, operators and other parties.
[0093] The data collaboration method based on smart communities provided in this invention first establishes a local trusted execution environment for each data party in the smart community; then, it verifies the trustworthiness of the trusted execution environment and obtains a trusted time period; within the trusted time period, each data party uploads its private data and computational model to the trusted execution environment for computation through a preset secure transport layer protocol (TLS) encrypted channel to obtain the computation result; finally, the computation result is sent to a privacy computing platform through the TLS encrypted channel, so that the privacy computing platform performs fusion analysis computation based on the computation result and returns the fusion analysis computation result to the corresponding user. This application, by establishing a local trusted execution environment and performing storage and computation within that environment, can ensure the security and trustworthiness of the code and data of the smart community within a certain time range in that region. It enables high-quality data collaboration among data parties in the smart community under privacy protection, facilitates the secure, compliant, open, and integrated application of government data, and improves administrative management capabilities. It also solves the problems of sensitive data leakage, eavesdropping, and tampering risks inherent in existing data collaboration methods based on smart communities.
[0094] Example 2:
[0095] like Figure 3 As shown, this embodiment provides a data collaboration device based on a smart community, used to execute the above-described data collaboration method based on a smart community, including:
[0096] Trusted environment building module 11 is used to build a local trusted execution environment for each data party in the smart community;
[0097] The credibility verification module 12 is connected to the trusted environment construction module 11 and is used to verify the credibility of the trusted execution environment and obtain a trusted time period.
[0098] The upload calculation module 13 is connected to the trust verification module 12 and is used to upload each data party’s private data and calculation model to the trusted execution environment for calculation within the trusted time period through a preset secure transport layer protocol TLS encrypted channel to obtain the calculation result.
[0099] The data collaboration module 14, connected to the upload computing module 13, is used to send the computing results to the privacy computing platform through the TLS encrypted channel, so that the privacy computing platform can perform fusion analysis computing based on the computing results and return the fusion analysis computing results to the corresponding user.
[0100] Optionally, the data providers include: government systems, telecom operators, and communities; the trusted execution environment is isolated by hardware.
[0101] Optionally, the device further includes:
[0102] The negotiation module is used by each data party to negotiate and formulate the communication key with the corresponding local trusted execution environment, and to build the TLS encrypted channel.
[0103] Optionally, the credibility verification module 12 specifically includes:
[0104] The credibility measurement unit is used to measure the credibility of the trusted execution environment within a preset time period and obtain a credibility measurement value.
[0105] A reliable time period determination unit is used to determine if the preset time period is a reliable time period if the reliability metric value is equal to a preset benchmark value.
[0106] Optionally, the start and end times of the preset time period are T1~T2, where T1 is the end time of the most recent credibility measurement, T2 is the time when the system was first attacked and destroyed after the most recent credibility measurement ended, and T2≥T1.
[0107] Optionally, the credibility measurement unit is specifically used for:
[0108] Calculate the credibility metric values of all trusted metric entities corresponding to the trusted execution environment within a preset time period;
[0109] The reliable time period determination unit is specifically used for:
[0110] If the credibility metric values of all the credibility metric entities are equal to the corresponding benchmark value, then the preset time period is a credibility time period.
[0111] Optionally, the device further includes:
[0112] The data clearing module is used to clear the data in the trusted execution environment, wherein the data in the trusted execution environment includes the private data, the calculation model, and the intermediate data in the calculation process.
[0113] Example 3:
[0114] refer to Figure 4 This embodiment provides a data collaboration device based on a smart community, including a memory 21 and a processor 22. The memory 21 stores a computer program, and the processor 22 is configured to run the computer program to execute the data collaboration method based on a smart community in Embodiment 1.
[0115] The memory 21 is connected to the processor 22. The memory 21 can be a flash memory, a read-only memory or other memory, and the processor 22 can be a central processing unit or a microcontroller.
[0116] Example 4:
[0117] This embodiment provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the data collaboration method based on smart communities described in Embodiment 1 above.
[0118] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, computer program modules or other data. Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other memory technologies, CD-ROM (Compact Disc Read-Only Memory), DVD or other optical disc storage, cartridges, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and is accessible to a computer.
[0119] In summary, the data collaboration method, apparatus, and readable storage medium based on smart communities provided by this invention first establish a local trusted execution environment for each data party in the smart community; then, the trustworthiness of the trusted execution environment is verified and a trusted time period is obtained; within the trusted time period, each data party uploads its private data and computational model to the trusted execution environment for computation through a preset secure transport layer protocol (TLS) encrypted channel to obtain the computation result; finally, the computation result is sent to a privacy computing platform through the TLS encrypted channel, so that the privacy computing platform performs fusion analysis computation based on the computation result and returns the fusion analysis computation result to the corresponding user. This application, by establishing a local trusted execution environment and storing and computing within it, can ensure the security and trustworthiness of the code and data of the smart community within a certain time range in that area. It can achieve high-quality data collaboration among data parties in the smart community under privacy protection, facilitate the secure, compliant, open, and integrated application of government data, and improve administrative management capabilities. It also solves the problems of sensitive data leakage, eavesdropping, and tampering risks inherent in existing data collaboration methods based on smart communities.
[0120] It is understood that the above embodiments are merely exemplary embodiments used to illustrate the principles of the present invention, and the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.
Claims
1. A data collaboration method based on smart communities, characterized in that, include: Build local trusted execution environments for each data provider in the smart community; Verify the trustworthiness of the trusted execution environment and obtain a trusted time period; During the trusted time period, each data party uploads its private data and computation model to the trusted execution environment through a preset secure transport layer protocol (TLS) encrypted channel for computation, and obtains the computation result. The calculation result is sent to the privacy computing platform through the TLS encrypted channel, so that the privacy computing platform can perform fusion analysis calculation based on the calculation result and return the fusion analysis calculation result to the corresponding user. The process of verifying the trustworthiness of the trusted execution environment and obtaining a trusted time period specifically includes: Calculate the credibility metric values of all trusted metric entities corresponding to the trusted execution environment within a preset time period; If the credibility metric values of all the credibility metric entities are equal to the corresponding baseline values, then the preset time period is a credibility time period. The start and end times of the preset time period are T1~T2, where T1 is the end time of the most recent credibility measurement, T2 is the time when the system was first attacked and destroyed after the most recent credibility measurement ended, and T2≥T1.
2. The method according to claim 1, characterized in that, The data providers include: government systems, telecom operators, and communities; the trusted execution environment is isolated by hardware.
3. The method according to claim 2, characterized in that, The private data is encrypted using a communication key. After establishing a local trusted execution environment at each data provider in the smart community, the method further includes: Each data party negotiates and formulates the communication key with the corresponding local trusted execution environment, and constructs the TLS encrypted channel.
4. The method according to claim 1, characterized in that, After obtaining the calculation result, the method further includes: The data in the trusted execution environment is cleared, including the private data, the computation model, and intermediate data during the computation process.
5. A data collaboration device based on a smart community, characterized in that, include: The Trusted Environment Setup Module is used to build a local trusted execution environment for various data providers in a smart community. The credibility verification module is connected to the trusted environment construction module and is used to verify the credibility of the trusted execution environment and obtain a trusted time period. The upload calculation module is connected to the trust verification module and is used to upload each data party’s private data and calculation model to the trusted execution environment for calculation within the trusted time period through a preset secure transport layer protocol TLS encrypted channel to obtain the calculation result. The data collaboration module, connected to the upload computing module, is used to send the computing results to the privacy computing platform through the TLS encrypted channel, so that the privacy computing platform can perform fusion analysis computing based on the computing results and return the fusion analysis computing results to the corresponding user. The credibility verification module specifically includes: The credibility measurement unit is used to calculate the credibility measurement value of all credibility measurement entities corresponding to the trusted execution environment within a preset time period. A reliable time period determination unit is used to determine if the preset time period is a reliable time period if the reliability metric values of all the reliable metric entities are equal to the corresponding benchmark values. The start and end times of the preset time period are T1~T2, where T1 is the end time of the most recent credibility measurement, T2 is the time when the system was first attacked and destroyed after the most recent credibility measurement ended, and T2≥T1.
6. A data collaboration device based on a smart community, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program and the processor is configured to run the computer program to implement the data collaboration method based on smart communities as described in any one of claims 1-4.
7. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the data collaboration method based on a smart community as described in any one of claims 1-4.