Real-time circulation monitoring method and platform in trusted data space
By introducing a real-time data flow monitoring platform into a trusted data space, and utilizing hash algorithms to generate data identifiers, deploying seamless monitoring agents, and conducting dynamic trust assessments, the problems of traditional data monitoring latency and fragmented cross-organizational monitoring are solved, enabling efficient and reliable data flow monitoring and rapid dispute resolution.
Patent Information
- Application Number
- CN202511087815.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-05
- Publication Date
- 2025-11-18
AI Technical Summary
Traditional data monitoring solutions rely on batch log analysis, which has minute-level latency. When data flows across organizations, there is a lack of verifiable joint auditing mechanisms, resulting in a high dispute rate and fragmented monitoring data between heterogeneous systems. The lack of standardized interfaces leads to low monitoring coverage for multi-organization data collaboration.
A real-time circulation monitoring platform in a trusted data space is adopted, including a digital fingerprint generation module, a probe deployment module, a dynamic trust assessment engine, and an audit trail module. It generates unique identifiers for data assets through hash algorithms, deploys a seamless monitoring agent, achieves millisecond-level trust score updates, supports evidence storage on private and public chains, and provides real-time trust heatmaps and alarm event timelines.
It achieves millisecond-level monitoring latency, supports real-time analysis of hundreds of millions of data events per second, reduces false alarm rate, ensures the immutability of audit evidence, shortens judicial verification time from hours to minutes, and improves dispute resolution efficiency.
Smart Images

Figure CN120973629A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data management and security, in particular to a real-time flow monitoring method and platform in a trusted data space. BACKGROUND
[0002] With the widespread application of data in various industries, the security and controllability of data flow have become increasingly important issues. In the fields of finance, medicine, etc., data flow not only needs to be efficiently processed, but also must ensure its security and compliance. However, the existing traditional data flow management system mostly focuses on data storage and access control, but lacks real-time monitoring and risk warning mechanisms for the whole process of data flow, and cannot fully cope with the risks that may arise when data flows across platforms and departments, such as data leakage, tampering or misuse. In order to solve this problem, a trusted data space has emerged, which provides a secure environment to ensure the trustworthiness of data in the flow process.
[0003] However, the traditional data monitoring scheme relies on batch log analysis, has a minute-level delay, and lacks a verifiable joint audit mechanism when data flows across organizations, resulting in a high dispute rate. In addition, the monitoring data between heterogeneous systems is fragmented, and lacks standardized interfaces, resulting in low monitoring coverage for multi-organizational data collaboration. Therefore, it does not meet the existing needs, and for this we propose a real-time flow monitoring method and platform in a trusted data space. SUMMARY
[0004] The purpose of the present application is to provide a real-time flow monitoring method and platform in a trusted data space to solve the problems of the traditional data monitoring scheme relying on batch log analysis, having a minute-level delay, and lacking a verifiable joint audit mechanism when data flows across organizations, resulting in a high dispute rate, and the monitoring data between heterogeneous systems being fragmented, lacking standardized interfaces, and resulting in low monitoring coverage for multi-organizational data collaboration, etc.
[0005] To achieve the above purpose, the present application provides the following technical solution: a real-time flow monitoring platform in a trusted data space, comprising a monitoring system, the monitoring system comprising a digital fingerprint generation module, a probe deployment module, a dynamic trust evaluation engine, an audit tracking module and a visualization console;
[0006] Digital fingerprint production module: generate a unique identifier for data assets by using a hash algorithm, and bind metadata contract;
[0007] Probe deployment module: deploy a non-invasive monitoring agent at data gateways and edge computing nodes;
[0008] Dynamic trust evaluation engine: implement millisecond-level updates of trust scores based on a stream computing framework;
[0009] Audit trail module: Supports dual-chain evidence storage for both private and public blockchains;
[0010] Visual console: Provides data flow topology diagram, real-time trust heatmap, and alarm event timeline.
[0011] Preferably, the digital fingerprint production module includes a base layer, a contract layer, and an identifier layer. The base layer produces a hash value of digital content using a hash algorithm. The contract layer is used to embed data usage constraints, and the identifier layer is used to attach a digital signature of the data owner.
[0012] Preferably, the probe deployment module embeds microservice probes into the data space entry gateway and edge routing nodes to intercept six types of key events in real time: data access requests, cross-domain transmission events, copy generation operations, data desensitization behavior, permission change records, and storage location migration, and pushes the six types of event streams to the computing engine through a DTLS encrypted channel.
[0013] Preferably, the dynamic trust assessment engine includes a behavior analyzer, a risk calculator, and a decision-maker. The behavior analyzer is used to compare real-time operations with historical baseline patterns. The risk calculator includes node security authentication level, number of violations per unit time, current session encryption strength, and data sensitivity coefficient. The decision-maker is used to calculate trust scores, assess risk levels, and issue handling suggestions based on the monitored data.
[0014] Preferably, the audit trail module includes a private chain and a public chain, wherein the private chain is used to store detailed monitoring logs, and the public chain is used to anchor key evidence hash values.
[0015] The monitoring method of a real-time circulation monitoring platform in a trusted data space includes the following steps:
[0016] S1: The digital fingerprint generation module extracts multi-dimensional features from the input data asset to generate an irreversible digital fingerprint. The fingerprint contains metadata such as data source, sensitivity level label, and authorized scope.
[0017] S2: Lightweight monitoring probes are embedded in the data flow path through the probe deployment module to capture flow events in real time. These events include: data access requests, cross-domain transmission events, copy generation operations, data desensitization behavior, permission change records, and storage location migration.
[0018] S3: Calculates real-time trust score based on dynamic trust assessment model. The model input includes: historical behavior baseline, node security authentication level, and operational compliance indicators.
[0019] S4: When a trust score threshold exceeding the limit or an abnormal behavior pattern is detected, or multiple such patterns are detected, a multi-level alarm mechanism is triggered and the circulation link is frozen.
[0020] S5: The audit trail module synchronizes key monitoring evidence to the blockchain network, generating an immutable audit trail.
[0021] Preferably, the dynamic trust assessment model in S3 uses a weighted adaptive algorithm, and the basic trust weight α of the circulation node is calculated using the following formula:
[0022] α = k1·Node security authentication level + k2·Historical violation coefficient + k3·Real-time load factor
[0023] Among them, k1-k3 are dynamically adjustable parameters that are automatically adjusted according to the data sensitivity level.
[0024] Preferably, the multi-level alarm mechanism in step S4 includes:
[0025] Level 1 Alert: Operation review is triggered when the trust score drops to the threshold;
[0026] Level 2 Alarm: Flow is blocked when an unauthorized data copy is detected.
[0027] Level 3 Alert: Initiate judicial evidence preservation when cross-domain abnormal access is detected.
[0028] Compared with the prior art, the beneficial effects of the present invention are:
[0029] 1. This invention achieves millisecond-level monitoring latency through the cooperation between various module components, improving response speed by many times compared to traditional solutions, supporting real-time analysis of hundreds of millions of data events per second, and effectively preventing the risk of data leakage;
[0030] 2. This invention dynamically adjusts node trust scores through a weighted adaptive algorithm, reducing false alarm rates and accurately identifying high-risk behaviors such as unauthorized circulation and abnormal copy generation;
[0031] 3. This invention ensures that audit evidence is tamper-proof through a dual-chain collaborative evidence storage mechanism, reducing judicial verification time from hours to minutes and improving dispute resolution efficiency. Attached Figure Description
[0032] Fig. 1 This is a flowchart of the system architecture of the present invention;
[0033] Fig. 2 This is a system diagram of the audit trail module of the present invention;
[0034] Fig. 3 This is an overview diagram of the inter-module connection architecture of the present invention. Detailed Implementation
[0035] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.
[0036] Please see Figs. 1 to 3 The present invention provides an embodiment of a real-time circulation monitoring platform in a trusted data space, comprising a monitoring system, which includes a digital fingerprint generation module, a probe deployment module, a dynamic trust assessment engine, an audit trail module, and a visualization console.
[0037] Digital fingerprint generation module: Generates a unique identifier for data assets using a hash algorithm and binds it to metadata contracts;
[0038] Probe deployment module: Deploys seamless monitoring agents on data gateways and edge computing nodes;
[0039] Dynamic Trust Assessment Engine: Enables millisecond-level updates of trust scores based on a streaming computing framework;
[0040] Audit trail module: Supports dual-chain evidence storage for both private and public blockchains;
[0041] Visual console: Provides data flow topology diagram, real-time trust heatmap, and alarm event timeline.
[0042] The digital fingerprint production module includes a base layer, a contract layer, and an identification layer. The base layer produces hash values of digital content through a hash algorithm, the contract layer is used to embed data usage constraints, and the identification layer is used to attach the digital signature of the data owner.
[0043] The probe deployment module embeds microservice probes into the data space entry gateway and edge routing nodes to intercept six types of key events in real time: data access requests, cross-domain transmission events, replica generation operations, data anonymization behavior, permission change records, and storage location migration. The six types of event streams are then pushed to the computing engine through a DTLS encrypted channel.
[0044] The dynamic trust assessment engine includes a behavior analyzer, a risk calculator, and a decision-maker. The behavior analyzer compares real-time operations with historical baseline patterns. The risk calculator includes node security authentication level, number of violations per unit time, current session encryption strength, and data sensitivity coefficient. The decision-maker calculates trust scores, assesses risk levels, and issues handling recommendations based on the monitored data.
[0045] The audit trail module includes a private blockchain and a public blockchain. The private blockchain is used to store detailed monitoring logs, while the public blockchain is used to anchor key evidence hash values.
[0046] The monitoring method of a real-time circulation monitoring platform in a trusted data space includes the following steps:
[0047] S1: The digital fingerprint generation module extracts multi-dimensional features from the input data asset to generate an irreversible digital fingerprint. The fingerprint contains metadata such as data source, sensitivity level label, and authorized scope.
[0048] S2: Lightweight monitoring probes are embedded in the data flow path through the probe deployment module to capture flow events in real time. Events include: data access requests, cross-domain transmission events, copy generation operations, data desensitization behavior, permission change records, and storage location migration.
[0049] S3: Calculates real-time trust score based on dynamic trust assessment model. The model input includes: historical behavior baseline, node security authentication level, and operational compliance indicators.
[0050] S4: When a trust score threshold exceeding the limit or an abnormal behavior pattern is detected, or multiple such patterns are detected, a multi-level alarm mechanism is triggered and the circulation link is frozen.
[0051] S5: The audit trail module synchronizes key monitoring evidence to the blockchain network, generating an immutable audit trail.
[0052] The dynamic trust assessment model in S3 uses a weighted adaptive algorithm for calculation. The formula for calculating the basic trust weight α of the circulation node is as follows:
[0053] α = k1·Node security authentication level + k2·Historical violation coefficient + k3·Real-time load factor
[0054] Among them, k1-k3 are dynamically adjustable parameters that are automatically adjusted according to the data sensitivity level.
[0055] The multi-level alarm mechanism of step S4 includes:
[0056] Level 1 Alert: Operation review is triggered when the trust score drops to the threshold;
[0057] Level 2 Alarm: Flow is blocked when an unauthorized data copy is detected.
[0058] Level 3 Alert: Initiate judicial evidence preservation when cross-domain abnormal access is detected.
[0059] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the invention can be implemented in other specific forms without departing from its spirit or essential characteristics. Therefore, the embodiments should be considered in all respects as exemplary and non-limiting, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be included within the present invention. No reference numerals in the claims should be construed as limiting the scope of the claims.
Claims
1. A real-time circulation monitoring platform in a trusted data space, including a monitoring system, characterized in that: The monitoring system includes a digital fingerprint generation module, a probe deployment module, a dynamic trust assessment engine, an audit trail module, and a visual console; Digital fingerprint generation module: Generates a unique identifier for data assets using a hash algorithm and binds it to metadata contracts; Probe deployment module: Deploys seamless monitoring agents on data gateways and edge computing nodes; Dynamic Trust Assessment Engine: Based on a streaming computing framework, it achieves millisecond-level updates of trust scores; Audit trail module: Supports dual-chain evidence storage for both private and public blockchains; Visual console: Provides data flow topology diagram, real-time trust heatmap, and alarm event timeline.
2. The real-time circulation monitoring platform in the trusted data space according to claim 1, characterized in that: The digital fingerprint production module includes a base layer, a contract layer, and an identifier layer. The base layer generates a hash value for digital content using a hash algorithm. The contract layer is used to embed data usage constraints, and the identifier layer is used to attach a digital signature of the data owner.
3. The real-time circulation monitoring platform in the trusted data space according to claim 1, characterized in that: The probe deployment module embeds microservice probes into the data space entry gateway and edge routing nodes to intercept six types of key events in real time: data access requests, cross-domain transmission events, copy generation operations, data desensitization behavior, permission change records, and storage location migration. The six types of event streams are then pushed to the computing engine through a DTLS encrypted channel.
4. The real-time circulation monitoring platform in the trusted data space according to claim 1, characterized in that: The dynamic trust assessment engine includes a behavior analyzer, a risk calculator, and a decision-maker. The behavior analyzer is used to compare real-time operations with historical baseline patterns. The risk calculator includes node security authentication level, number of violations per unit time, current session encryption strength, and data sensitivity coefficient. The decision-maker is used to calculate trust scores, assess risk levels, and issue handling suggestions based on the monitored data.
5. The real-time circulation monitoring platform in the trusted data space according to claim 1, characterized in that: The audit trail module includes a private chain and a public chain. The private chain is used to store detailed monitoring logs, and the public chain is used to anchor key evidence hash values.
6. A monitoring method for a real-time circulation monitoring platform in a trusted data space according to any one of claims 1-5, characterized in that... Includes the following steps: S1: The digital fingerprint generation module extracts multi-dimensional features from the input data asset to generate an irreversible digital fingerprint. The fingerprint contains metadata such as data source, sensitivity level label, and authorized scope. S2: Lightweight monitoring probes are embedded in the data flow path through the probe deployment module to capture flow events in real time. These events include: data access requests, cross-domain transmission events, copy generation operations, data desensitization behavior, permission change records, and storage location migration. S3: Calculates real-time trust score based on dynamic trust assessment model. The model input includes: historical behavior baseline, node security authentication level, and operational compliance indicators. S4: When a trust score threshold exceeding the limit or an abnormal behavior pattern is detected, or multiple such patterns are detected, a multi-level alarm mechanism is triggered and the circulation link is frozen. S5: The audit trail module synchronizes key monitoring evidence to the blockchain network, generating an immutable audit trail.
7. The real-time circulation monitoring platform in the trusted data space according to claim 6, characterized in that: The dynamic trust assessment model in S3 uses a weighted adaptive algorithm for calculation. The formula for calculating the basic trust weight α of the circulation node is as follows: α = k1·Node security authentication level + k2·Historical violation coefficient + k3·Real-time load factor Among them, k1-k3 are dynamically adjustable parameters that are automatically adjusted according to the data sensitivity level.
8. The real-time circulation monitoring platform in the trusted data space according to claim 6, characterized in that: The multi-level alarm mechanism in step S4 includes: Level 1 Alert: Operation review is triggered when the trust score drops to the threshold; Level 2 Alarm: Flow is blocked when an unauthorized data copy is detected. Level 3 Alert: Initiate judicial evidence preservation when cross-domain abnormal access is detected.
Citation Information
Cited By
Trusted data space data supervision and auditing method and system for data circulation
CN121615131A