A data asset management method and data asset active management system

Through the data asset active management system AAS-DA, problems in data asset sharing, circulation, transaction and security protection are solved, and the full life cycle management and access permission control of data assets are realized, ensuring that data sovereignty is in the hands of the provider and improving the availability and security of data assets.

CN115130124BActive Publication Date: 2025-09-16CHINA ACADEMY OF INFORMATION & COMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210734005.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-06-27
Publication Date
2025-09-16
Estimated Expiration
2042-06-27

AI Technical Summary

Technical Problem

Data assets have problems such as poor quality, difficulty in data interoperability, high acquisition costs, difficulty in ensuring security, and complex ownership confirmation and valuation transactions. A technical system for data sharing, circulation, trading and security protection has not yet been formed.

Method used

A data asset active management system AAS-DA is provided. By dividing it into AAS-DA-supplier, AAS-DA-user and AAS-DA-public, it realizes the full life cycle management of data assets, including initial configuration, information release, smart contract conclusion, data usage monitoring and termination and destruction, ensuring that data sovereignty remains in the hands of the provider and realizing available, invisible, controllable and measurable access control.

Benefits of technology

A technical system has been formed for data sharing, circulation, transaction and security protection, which solves problems such as poor quality of data assets, difficulty in data interoperability, high acquisition costs, difficulty in ensuring security, and complex ownership confirmation and valuation transactions. It has achieved the availability and invisibility, controllability and measurability of data assets, and access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115130124B_ABST
    Figure CN115130124B_ABST
Patent Text Reader

Abstract

The present application discloses a data asset management method, which is applied to an active data asset management system. The method includes: after a data asset is formed, a data provider creates an AAS-DA-supplier corresponding to the data asset; the data provider saves the data asset information to be disclosed in the AAS-DA-supplier as a corresponding AAS-DA-public and uploads it to an intermediate service provider; the data user enters into a smart contract with the data provider through the AAS-DA-public; the data provider sends the data asset to the data user; the AAS-DA-user monitors the data asset usage process of the data user according to the smart contract; and the AAS-DA-user terminates the use of and / or destroys the data asset of the data user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, for example, to a data asset management method and a data asset active management system. Background Art

[0002] Currently, with the deepening digital transformation of the manufacturing industry, data, as a new production factor, is poised to play a greater role. As outlined in the Data Security Law, ensuring the orderly flow of data, fostering a data trading market, and strengthening the protection of critical data are becoming essential tasks in achieving the "last mile" of data value creation. As an information resource, data's two key asset characteristics are its ability to generate economic benefits for enterprises and its measurable costs and benefits. Compared to traditional tangible and intangible assets, data assets are non-physical, dependent, diverse, processable, volatile, multi-derivative, shareable, and cost-free.

[0003] During the implementation of the embodiments of the present disclosure, it was found that at least the following problems exist in the related art:

[0004] Due to the many characteristics of data assets, there are problems such as poor quality, difficulty in data interoperability, high acquisition costs, difficulty in ensuring security, and complex ownership confirmation and valuation transactions. A technical system for data sharing, circulation, trading and security protection has not yet been formed, which has led to bottlenecks in the realization of data value. Summary of the Invention

[0005] In order to provide a basic understanding of some aspects of the disclosed embodiments, a brief summary is given below. The summary is not an extensive review, nor is it intended to identify key / critical elements or delineate the scope of protection of these embodiments, but rather serves as a prelude to the detailed description that follows.

[0006] The embodiments of the present disclosure provide a data asset management method and a data asset active management system, computing equipment, and storage medium to manage and constrain data assets, give full play to the strategic resource role and innovation engine role of data, and promote the value of data elements.

[0007] In some embodiments, the data asset management method is applied to an active data asset management system AAS-DA, where the active data asset management system AAS-DA is divided into AAS-DA-supplier, AAS-DA-user, and AAS-DA-public. The method includes:

[0008] After the data asset is formed, the data provider creates an AAS-DA-supplier corresponding to the data asset and initializes the data asset configuration in the AAS-DA-supplier;

[0009] The data provider saves the data asset information to be disclosed in the AAS-DA-supplier as the corresponding AAS-DA-public and uploads it to the intermediate service provider. The intermediate service provider then publishes the AAS-DA-supplier information through the AAS-DA-public.

[0010] Data users read the data asset information disclosed in AAS-DA-public and enter into smart contracts with data providers through AAS-DA-public;

[0011] The data provider saves the AAS-DA-supplier as AAS-DA-user and sends the AAS-DA-user and pre-processed data assets to the data user.

[0012] AAS-DA-user monitors the data asset usage process of data users based on smart contracts and records all processing operations on data assets;

[0013] When the change of data assets reaches the boundary conditions of the smart contract or violates the constraints, AAS-DA-user terminates the use and / or destroys the data assets of the data user.

[0014] In some embodiments, the data asset active management system AAS-DA, according to the ownership of different stakeholders, the data asset active management system AAS-DA as described in any one of the present applications is divided into AAS-DA-supplier, AAS-DA-user and AAS-DA-public, wherein the three AAS-DAs of the same data asset are interrelated and can be merged under necessary conditions. AAS-DA-supplier has the highest authority and can read all the contents in AAS-DA-user and AAS-DA-public. The content specified by AAS-DA-user and AAS-DA-public is a subset of AAS-DA-supplier.

[0015] The computing device comprises a memory and a processor, wherein:

[0016] The memory is used to store computer programs;

[0017] The processor is used to execute the computer program to implement the data asset management method as described in this application.

[0018] In some embodiments, the storage medium stores program instructions, characterized in that when the program instructions are run, they execute the data asset management method as described in this application.

[0019] The data asset management method and active data asset management system, computing device, and storage medium provided in the embodiments of the present disclosure can achieve the following technical effects:

[0020] This application uses AAS-DA to achieve full life cycle management of data assets between data providers, data users and intermediary service providers, keeping data sovereignty in the hands of data providers, and achieving available but invisible, controllable and measurable data assets, access control, and post-use destruction. It solves the problems of poor quality of data assets, difficulty in data interoperability, high acquisition costs, difficult security assurance, ownership confirmation and complex valuation transactions, and forms a technical system for data sharing, circulation, transaction and security protection.

[0021] The above general description and the following description are exemplary and explanatory only and are not intended to limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] One or more embodiments are exemplarily described by corresponding drawings. These exemplary descriptions and drawings do not limit the embodiments. Elements with the same reference numerals in the drawings are shown as similar elements. The drawings do not constitute a scale limitation. In addition,

[0023] Figure 1 This is a functional architecture diagram of the AAS-DA provided by this application;

[0024] Figure 2 This is a flowchart of a data asset management method provided by this application;

[0025] Figure 3 This is a flowchart of another data asset management method provided by this application;

[0026] Figure 4 This is a flowchart of another data asset management method provided by this application;

[0027] Figure 5 This is a flowchart of another data asset management method provided by this application;

[0028] Figure 6 This is a flowchart of another data asset management method provided by this application;

[0029] Figure 7 This is a flowchart of another data asset management method provided by this application;

[0030] Figure 8 This is a flowchart of another data asset management method provided by this application;

[0031] Figure 9 This is a schematic diagram of the AAS-DA system structure provided by this application;

[0032] Figure 10 This is a flowchart of a data asset usage control method provided by this application;

[0033] Figure 11 This is a flowchart of another data asset usage control method provided by this application;

[0034] Figure 12 This is a flowchart of another data asset usage control method provided by this application;

[0035] Figure 13 This is a flowchart of another data asset usage control method provided by this application;

[0036] Figure 14 This is a flowchart of another data asset usage control method provided by this application;

[0037] Figure 15 This is a flowchart of another data asset usage control method provided by this application;

[0038] Figure 16 This is a flowchart of another data asset usage control method provided by this application;

[0039] Figure 17 It is a schematic diagram of a computing device provided by this application. DETAILED DESCRIPTION

[0040] In order to be able to understand the features and technical content of the embodiments of the present disclosure in more detail, the implementation of the embodiments of the present disclosure is described in detail below in conjunction with the accompanying drawings. The accompanying drawings are for reference only and are not used to limit the embodiments of the present disclosure. In the following technical description, for the sake of convenience of explanation, a full understanding of the disclosed embodiments is provided through multiple details. However, one or more embodiments can still be implemented without these details. In other cases, to simplify the drawings, well-known structures and devices can be simplified for display.

[0041] In the description and claims of the embodiments of the present disclosure, as well as in the accompanying drawings, the terms "first," "second," and the like are used to distinguish similar items and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate to describe the embodiments of the present disclosure herein. In addition, the terms "including," "having," and any variations thereof are intended to cover non-exclusive inclusions.

[0042] Unless otherwise stated, the term "plurality" means two or more.

[0043] In the embodiment of the present disclosure, the character " / " indicates that the preceding and following objects are in an "or" relationship. For example, A / B means: A or B.

[0044] The term "and / or" describes an association between objects, indicating that three relationships can exist. For example, A and / or B means: A or B, or A and B.

[0045] The term "correspondence" may refer to an association relationship or a binding relationship. The correspondence between A and B means that there is an association relationship or a binding relationship between A and B.

[0046] First, the technical terms involved in this application are explained:

[0047] AAS-DA (Active Administration System-Data Asset): is an active data asset management system that manages and controls the use of data assets throughout their lifecycle.

[0048] DA (Data-Asset): refers to data assets, used to identify a data asset.

[0049] API (Application Programming Interface) refers to the connection interface, and in this application refers to the interface in the data asset active management system AAS-DA.

[0050] In related technologies, data assets possess many characteristics and also face many challenges. According to PwC's definition, compared with traditional tangible and intangible assets, data assets are non-physical, dependent, diverse, processable, and have volatile value. Building on this, Everbright Bank and the Outlook Think Tank have added multiple derivatives, shareability, and zero-cost replicability. Specifically:

[0051] Non-practicality: It does not have a physical form and relies on a physical carrier to exist; it does not wear out or consume due to use; it can be used indefinitely during its existence.

[0052] Dependency: must be stored in a certain medium; can exist in multiple media at the same time in different forms.

[0053] Diversity: diverse forms of expression; diverse forms of integration; uncertain ways of use.

[0054] Value volatility: Value is affected by many different factors, including technology, capacity, value density, and the business model of the application.

[0055] Processability: can be maintained, updated, supplemented, and added; can be deleted, merged, aggregated, and de-redundant; can be analyzed, refined, and mined, etc.

[0056] Multiple derivability: refers to the fact that the same data subject can be processed at multiple levels and dimensions, thereby deriving different degrees of data value, conducting multi-level and multi-dimensional data asset potential value mining, and enriching data assets.

[0057] Sharability: Data assets can be exchanged, transferred, and used unlimitedly, and their sharing can maximize the value of data assets;

[0058] Zero-cost reproducibility: This means that the cost of data assets mainly lies in the early stages of data reading and research and development. Therefore, the cost of initial data assets is extremely high, but the marginal cost of subsequent replication and sharing tends to zero.

[0059] Therefore, the many characteristics of data assets have largely led to difficulties in confirming ownership and valuation transactions. This application aims to manage and restrict the above-mentioned characteristics of data assets.

[0060] At the same time, two key characteristics of data as an asset are its ability to generate economic benefits for enterprises and its measurable costs and benefits. The main reasons for data value realization bottlenecks include poor quality, difficulty in data interoperability, high acquisition costs, and difficulty in ensuring security. Therefore, data assets need to be managed through the following dimensions, including:

[0061] Data standards management: Normative constraints that ensure the consistency and accuracy of internal and external use and exchange of data.

[0062] Metadata management: abstract information about data, trace data, and explore the relationships between data.

[0063] Data quality management: Improve data quality and enhance the level of data applications and services.

[0064] Data security management: Divide data security levels and formulate data security management specifications to ensure that data can be managed beforehand, controlled during the process, and checked afterward.

[0065] Data value management: data cost management and data revenue management to optimize and maximize the release of data value.

[0066] Data sharing management: Release the internal and external value of data through internal data sharing, external data circulation, and external opening.

[0067] It can be seen that the problems and challenges faced by data assets in sharing include transparency, accessibility, standardization, security, and data integrity. Specifically:

[0068] Transparency: refers to the openness of all parties involved in sharing data assets to provide all the information required to successfully deliver the data sharing partnership.

[0069] Accessibility: refers to the ability of parties to access the data they need, when they need it.

[0070] Standardization: refers to the consistent legal, technical and other measures that should be adopted by all stakeholders in the data sharing process.

[0071] Security and data integrity: refers to the implementation of measures and mechanisms designed to securely protect information and data in order to achieve a secure environment for data sharing.

[0072] To this end, combined Figure 1 As shown, the present application provides a data asset active management system AAS-DA to carry out full life cycle management of data assets, as well as execution supervision, control and management during use. Among them, each data asset has a twin AAS-DA, thereby upgrading the data asset from a passive asset to an active asset. AAS-DA can define, configure and update the attribute information of data assets, record the full life cycle information, and perform the highest priority operations on data assets, including but not limited to desensitization, encryption, termination and destruction. When data assets are processed, AAS-DA can record the processing process and terminate and / or destroy the data assets when they do not meet the data asset security requirements and other constraints. When a data asset is copied, a new AAS-DA will be generated accordingly, and the AAS-DA of the copied data asset and the AAS-DA of the original data asset will be associated.

[0073] Optionally, the AAS-DA of this application supports all types of data assets, including but not limited to streaming data, event data, engineering drawings, videos, algorithms, machine learning models or knowledge graphs, etc.

[0074] Optionally, to ensure transparency in data asset sharing, circulation, and transactions, and to ensure all stakeholders are aware of relevant information, AAS-DA can be further divided into AAS-DA-supplier, AAS-DA-user, and AAS-DA-public, based on the ownership of different stakeholders. The three AAS-DAs for the same data asset are interconnected and can be merged when necessary. The AAS-DA-supplier has the highest permissions and can read all content in the AAS-DA-user and AAS-DA-public. The content specified by the AAS-DA-user and AAS-DA-public must be a subset of the AAS-DA-supplier.

[0075] Combine Figure 1 As shown in the figure, the functional architecture of the data asset active management system AAS-DA in this application consists of "identity tags" and "subjects." The identity tags are the globally unique identifiers of data assets and AAS-DA; the subjects include: the data asset lifecycle management component, control management component, log and evidence management component, interface management component and their corresponding attributes.

[0076] In an embodiment of the present application, the full lifecycle management component is configured to perform full lifecycle management of various subject attributes of data assets. The various subject attributes include data sovereignty, data history, data quality, data type, data level, data standard, data value, data sharing, and contract attributes, so as to achieve the management of data sovereignty, data history, data quality, data type, data level, data standard, data value, data sharing, and smart contracts of data assets. The detailed content of each attribute structure is shown in Table 1:

[0077] Table 1: Detailed table of attributes of data assets throughout their life cycle

[0078]

[0079]

[0080] In this way, the full life cycle management of data assets can be better achieved.

[0081] In an embodiment of the present application, the control management component is configured to manage the use process of data assets, which specifically includes attributes such as permission management, access control, contract settings, usage control, usage mode, collaboration mode, and usage environment security scan, so as to achieve the management of data assets' permissions, access control, contract settings, usage control, usage mode, collaboration mode, and usage environment security scan.

[0082] Specifically, permissions management controls user access to and use of data assets. According to security rules or policies, users are limited to authorized data assets. Permission management consists of two parts: user authentication and authorization, collectively referred to as authentication and authorization. Users who wish to access or use controlled data assets must first undergo identity authentication. Only after passing authentication can they gain access to or use the resource.

[0083] Access control includes settings, operations, monitoring, and interruptions. Settings mainly involve setting access control modes, subjects, behaviors, resources, and environments. Access control modes generally take the following forms: autonomous access control, command access control, role access control, attribute access control, or other types of access control; subjects include server administrators, data holders, contracted data users, uncontracted data users, and other role subjects; behaviors include reading, writing, copying, deleting, and other behaviors; resources are mainly references to data asset attributes in the full lifecycle management of data assets; and the environment refers to the time, location, and other environmental factors where data transactions occur. Interruptions are mainly divided into active interruptions and passive interruptions.

[0084] Contract settings mainly involve setting contract terms such as Value (hash value, DNA / ID card of data), Address (connecting different clients), State (input: target state, such as usage time, number of times, etc.) and Function (output: executable strategy) after an agreement is reached between the data provider and the data user.

[0085] Usage control primarily monitors the use of data assets, identifies anomalies, and terminates and destroys data assets based on the relevant requirements set in the contract. Data usage is monitored in real time via a monitor. When a user reaches a specific state (number of times reached, provider termination, or user default), the executor invokes the executable policy in the contract's Function setting to destroy, terminate, or pause the data asset.

[0086] Optionally, the usage modes generally include the following: regular use, privacy computing mode, federated learning mode, encryption mode, and other custom modes.

[0087] Collaboration modes include merged collaboration and associated collaboration. Two or more AAS-DA-suppliers that enable collaboration will achieve synchronized management of data assets during their use.

[0088] The use environment security scan is mainly carried out by AAS-DA-user before the data assets reach the data user. It scans the software layer and system layer of the use environment according to the requirements of the smart contract, and marks the software that meets the requirements of the smart contract.

[0089] The detailed properties of the data asset control management component are shown in Table 2:

[0090] Table 2: Detailed table of attributes for data asset management

[0091]

[0092]

[0093]

[0094] In this way, the use and control of data assets can be better achieved.

[0095] In an embodiment of the present application, the log evidence management component is configured to manage various types of logs generated during the use of the data asset active management system, wherein the various types of logs mainly include internal logs, data operation logs, and collaborative logs with other data asset management systems. Specifically, it includes but is not limited to the operations of each functional component in the AAS-DA-supplier, the operations of the AAS-DA-supplier on data assets, the operations on data assets sent by the AAS-DA-user to the AAS-DA-supplier, the operations on copied data or sub-data sent by other related AAS-DAs to the AAS-DA-supplier, etc., as well as a time-ordered collection of these operation results. Each log file consists of log records, and each log record describes a separate system event.

[0096] Typically, the system log is a local log of the AAS-DA-supplier that can be directly read by the data provider. It includes a timestamp and a message or other subsystem-specific information. The usage log is a log of data asset operations sent by the AAS-DA-user to the AAS-DA-supplier and AAS-DA-public during the data user's operation. It is generally stored on the blockchain for subsequent liquidation, auditing, and regulatory purposes.

[0097] In an embodiment of the present application, the interface management component is configured to manage the communication interface of the data asset active management system. Specifically, the interface management component mainly manages the communication interface between at least two data asset active management systems, and the communication interface between the data asset active management system and the data assets.

[0098] The data asset active management system provided by the embodiment of the present disclosure realizes the full life cycle management of data assets and effective governance of data assets by loading the full life cycle management components, control management components, log evidence management components and interface management components of identity tags and subjects and their attribute functions, solves the problems of poor quality of data assets, difficulty in data intercommunication, high acquisition cost, difficulty in ensuring security, and complex ownership confirmation and valuation transactions, and forms a technical system for data sharing, circulation, transaction and security protection.

[0099] In practical applications, such as Figure 2 As shown, the present application provides a data asset management method, which is applied to the data asset active management system AAS-DA. The data asset active management system AAS-DA is divided into AAS-DA-supplier, AAS-DA-user and AAS-DA-public. The method includes:

[0100] Step 201: After the data asset is formed, the data provider creates an AAS-DA-supplier corresponding to the data asset and initializes the configuration of the data asset in the AAS-DA-supplier.

[0101] Step 202: The data provider saves the data asset information to be disclosed in the AAS-DA-supplier as the corresponding AAS-DA-public and uploads it to the intermediate service provider. The intermediate service provider implements the information release of the AAS-DA-supplier through the AAS-DA-public.

[0102] Step 203: The data user reads the data asset information disclosed in AAS-DA-public and enters into a smart contract with the data provider through AAS-DA-public.

[0103] Step 204: The data provider saves the AAS-DA-supplier as an AAS-DA-user, and sends the AAS-DA-user and the pre-processed data assets to the data user.

[0104] Step 205: AAS-DA-user monitors the data asset usage process of the data user according to the smart contract and records all processing operation information of the data assets.

[0105] Step 206: When the change in data assets reaches the boundary conditions of the smart contract or violates the constraints, the AAS-DA-user terminates the use of and / or destroys the data assets of the data user.

[0106] By adopting the data asset management method provided by the embodiment of the present disclosure, the loading and use control of data assets is realized between the client as the data provider, the client as the data user and the intermediate service platform as the intermediate service provider through AAS-DA, so that the data sovereignty is kept in the hands of the data provider, and the data assets are available but invisible, controllable and measurable, with access rights controlled and burned after use. This solves the problems of poor quality of data assets, difficulty in data intercommunication, high acquisition cost, difficulty in ensuring security, and complex ownership confirmation and valuation transactions, and forms a technical system for data sharing, circulation, transaction and security protection.

[0107] In the embodiments of the present application, Figure 3 As shown, the initial configuration of data assets in AAS-DA-supplier includes:

[0108] Step 301: Generate the sovereignty initial information of the data asset in the AAS-DA-supplier, wherein the sovereignty initial information includes the ownership information, time information and location information of the data asset.

[0109] In the embodiment of the application, after the data asset is generated, the sovereignty initial information of the data asset is generated in the AAS-DA-supplier, including the ownership, time, location and other information of the data asset generation, to facilitate data ownership confirmation.

[0110] Step 302: Define, set, and update various subject attributes of data assets through AAS-DA-supplier.

[0111] In the embodiment of the application, various attributes of data assets can be defined, set and updated through AAS-DA-supplier, including data type, standards, specifications and laws and regulations followed by data assets, quality level, security level requirements, etc.

[0112] Step 303: When a data asset is copied or sub-data is generated, the data asset is associated with the respective AAS-DA-supplier.

[0113] In the embodiments of the application, when data assets are copied or sub-data are generated, they can be associated through their respective AAS-DAs to facilitate traceability.

[0114] Step 304: Desensitize or encrypt the data assets through the AAS-DA-supplier.

[0115] In the embodiment of the application, before the data assets are used, the AAS-DA-supplier can desensitize the data assets and encrypt the data according to the encryption algorithm requirements of the country and the enterprise.

[0116] In addition, during the use of data assets, the AAS-DA-user records all processing operation information for the data assets and provides feedback to the AAS-DA-supplier in real time or afterwards. After learning about the processing status of the data assets, the AAS-DA-supplier can proactively issue a termination / destruction instruction to the AAS-DA-user, and the AAS-DA-user can call the operation script to terminate / destroy the data assets. In addition, AAS-DA can manage the physical carriers and storage media of data assets.

[0117] In this way, data providers can better control and protect data assets.

[0118] In the embodiments of the present application, Figure 4 As shown, the intermediate service provider uses AAS-DA-public to implement AAS-DA-supplier information release, including:

[0119] Step 401: The intermediate service provider generates a resource directory based on the various subject attributes of AAS-DA-public to implement a centralized management mode or a distributed management mode for data assets.

[0120] In the embodiment of the application, the resource directory mainly includes the names of various resources and their metadata descriptions. The intermediate service platform supports the sharing and trading of the following three types of resources: one is the data asset class, including but not limited to streaming data, event data, CAD drawings, videos, algorithms, models, digital twins, knowledge graphs, APPs, API calls, etc. The metadata of the data asset class is stored in the full life cycle management component of the data asset of the corresponding AAS-DA-supplier; the second is the IT infrastructure class, including but not limited to cloud computing, edge computing, computing resources, communication resources, etc.; the third is the trusted environment solution class, including but not limited to trusted environment solutions for the hardware layer, system layer and software layer. Certified AAS-DA and resources will be included in the resource directory for management.

[0121] The data provider saves the information to be disclosed in AAS-DA-supplier as AAS-DA-public and uploads it to the intermediary service provider through the data provider. The AAS-DA-public that has been reviewed and approved by the intermediary service platform is included in the resource directory.

[0122] Step 402: The data user searches for data assets that meet the requirements by accessing the resource directory of the intermediary service provider.

[0123] Step 403: The intermediate service provider pushes the data assets to the data users based on the availability of the data assets in the resource directory.

[0124] In an embodiment of the application, data users can access the resource directory of the intermediate service provider to query data assets and other resources that meet their requirements. Data users can also subscribe to resource directory updates, or fill in the requirements for data assets and other resources of interest. The intermediate service provider can make precise push notifications based on the supply of data assets and other resources.

[0125] In this way, this application does not need to centralize the data assets themselves to an intermediate service provider, but only needs to manage AAS-DA-public and generate a resource directory based on the various attribute information in AAS-DA-public, thereby realizing the distributed management of data assets and the centralized management of AAS-DA, reducing the risks of data assets, and increasing the willingness of data providers to share data assets.

[0126] In the embodiments of this application, Figure 5 As shown, the data user reads the data asset information disclosed in AAS-DA-public and enters into a smart contract with the data provider through AAS-DA-public, including:

[0127] Step 501: A data user initiates an invitation to one or more data providers that meet its needs.

[0128] Step 502: The data provider who accepts the invitation will negotiate with the data user on the cooperation intention of the data assets and write the negotiated content into AAS-DA-public.

[0129] Step 503: Configure the data asset usage process in AAS-DA-public and store logs.

[0130] In an embodiment of the present application, a data user initiates an invitation to one or more data providers that meet their needs. The data provider that accepts the invitation will negotiate with the data user on the cooperation intention of the data asset, and write the negotiated content into the contract management attributes of the full life cycle management component of the data asset of AAS-DA-public. At the same time, in the control management component of the data asset of AAS-DA-public, the permission management, access control, contract settings, usage control, usage mode, collaborative mode attributes, etc. are configured. At the same time, the time when the smart contract is reached and the information of the two parties to the transaction will be recorded in the log evidence of AAS-DA-public.

[0131] In the embodiments of the present application, Figure 6 As shown, the AAS-DA-user monitors the data asset usage process of the data user according to the smart contract and records all processing operation information of the data assets, including:

[0132] Step 601: AAS-DA-user performs a security scan on the media and environment where the data assets will be stored and used according to the usage environment requirements in the smart contract.

[0133] In an embodiment of the present application, the present application can be scanned by the AAS-DA-user for the usage environment: according to the settings of the usage environment in the control management component of the data asset - usage control, the AAS-DA-user will call the control management component of the data asset - the usage environment security scanning function to perform a security scan on the software layer, system layer and hardware layer of the usage environment, and perform security marking on the software that meets the requirements of the smart contract. The software that passes the security marking will be included in the whitelist of access control or usage control in the control management component of the data asset. The AAS-DA-user will feed back the environmental security scan results to the AAS-DA-supplier through the client of the data user. After the AAS-DA-supplier data asset control management component - usage control approves it, the data user will be allowed to access the pre-processed data assets.

[0134] Optionally, according to the provisions of the AAS-DA-supplier data asset control management component-contract settings, the AAS-DA-supplier will pre-process the data asset through the usage mode of the data asset control management component, including but not limited to desensitization, encryption, and generation of calculation factors. If "regular use" is selected in the usage mode, the data asset will be sent to the data user in plain text. If the data usage process involves multi-party collaboration, such as multi-party privacy computing and federated learning, the collaborative mode of the data asset control management component will also be set. Two or more AAS-DA-suppliers that enable collaborative mode will achieve synchronous management of data assets during the use of data assets.

[0135] Step 602: Confirm the permissions of one or more processes that are about to call the data asset by reading the access control or usage control whitelist in AAS-DA-user.

[0136] In an embodiment of the present application, the permissions for one or more processes that will call a data asset are requested by the data user through the AAS-DA-user. The permissions for the one or more processes that will call the data asset are then confirmed by reading the access control or usage control whitelist in the AAS-DA-user's data asset control management component. If the process is on the whitelist, the AAS-DA-user will allow the process to operate on the data asset according to the Function attribute in the data asset control management component - contract settings; if the process is not on the whitelist, the AAS-DA-user will not allow the process to call the data asset.

[0137] Step 603: The AAS-DA-user monitors in real time whether the changes in data assets have reached the boundary conditions or whether any operations that violate the constraints have occurred, and writes the operation logs into the log evidence component.

[0138] In an embodiment of the present application, during data asset usage, the AAS-DA-user monitors the data asset. The AAS-DA-user uses the usage control monitor, a component of the data asset management and control system, to monitor in real time whether changes in the data asset have reached the maximum value of the boundary conditions or whether any operations that violate the constraints have occurred. If any of these situations occurs, the AAS-DA-user sends an exception message to the data user. The data user then uses the process monitoring executor to forcibly terminate the process. The AAS-DA-user then destroys the data asset using the usage control executor, a component of the data asset management and control system.

[0139] In this way, the use of data assets can be better controlled, and data sovereignty will always remain in the hands of the data provider.

[0140] In the embodiments of the present application, Figure 7 As shown, when the change of data assets reaches the boundary conditions of the smart contract or violates the constraints, the AAS-DA-user terminates the use and / or destroys the data assets of the data user, including:

[0141] Step 701: Based on the constraints and boundary conditions of the smart contract, the AAS-DA-user generates an operation script for terminating or destroying data assets.

[0142] Step 702: When the change in the data asset reaches the boundary conditions of the smart contract or violates the constraints, the AAS-DA-user will record the processing operation information and feed it back to the AAS-DA-supplier in real time or afterwards, so that the AAS-DA-supplier will issue a termination instruction to the AAS-DA-user, and the AAS-DA-user will call the operation script to terminate the use of the data asset. Alternatively, the AAS-DA-user can directly call the operation script to terminate the use of the data asset.

[0143] Step 703: After the use of the data asset is terminated or when the AAS-DA-user receives a destruction instruction from the AAS-DA-supplier, the data asset is destroyed.

[0144] In an embodiment of the present application, the present application generates an operation script for terminating and destroying data assets through AAS-DA-user according to the constraints and boundary conditions of the smart contract; during the use of the data assets, all processing operation information of the data assets is recorded by AAS-DA-user; and feedback is provided to AAS-DA-supplier in real time or afterwards. There are two possible situations: (1) After learning about the processing status of the data assets, the AAS-DA-supplier can actively issue a termination instruction to the AAS-DA-user, and the AAS-DA-user calls the operation script to terminate the use of the data assets; (2) When the constraints and boundary conditions of the smart contract are met, the AAS-DA-user calls the operation script to terminate the use of the data assets.

[0145] After data use ends or the AAS-DA-user receives a destruction instruction from the AAS-DA-supplier, the data asset is destroyed. Even after the data asset is destroyed, information about its entire life cycle and the status of its associated data assets can still be obtained through AAS-DA, facilitating subsequent audits, liquidations, arbitration, and the traceability of other data assets.

[0146] In this way, data assets can be better made available but invisible, controllable and measurable, with access rights controlled and self-destructing.

[0147] In the embodiments of the application, Figure 8 As shown, the data asset management method of the present application also includes:

[0148] Step 801: When the data asset is destroyed, the AS-DA-user terminates the smart contract and sends the data asset destruction and smart contract termination information to the data provider and the intermediary service provider.

[0149] Step 802: After receiving the information that the data assets have been destroyed and the smart contract has been terminated, the data provider terminates the smart contract through AAS-DA-supplier and sends the liquidation application information to the intermediary service provider and data user through the data provider.

[0150] Step 803: After receiving the liquidation application information, the intermediary service provider terminates the smart contract through AAS-DA-public, reads the log evidence components of AAS-DA-supplier and AAS-DA-user through AAS-DA-public, compares them with the contents of the smart contract, and implements liquidation and auditing based on the comparison results.

[0151] In the embodiments of the present application, the present application synchronizes the use process of data assets and stores evidence in multiple parties through the collaboration of AAS-DA-public, AAS-DA-user and AAS-DA-supplier, and based on the multi-party evidence storage of AAS-DA-public, AAS-DA-user and AAS-DA-supplier, liquidates and audits the use of data assets, so that the quality attributes and value attributes of data assets in AAS-DA-public can be dynamically adjusted according to the data users' evaluation of data quality and value.

[0152] Specifically, from the moment a smart contract is signed until the data asset is destroyed, all operations performed by the data provider, data user, and intermediary service provider on the data asset will be synchronously logged on the data provider's client, the data user's client, and the intermediary service platform. When necessary, all stored evidence can be managed and traced through the blockchain.

[0153] When data assets are destroyed, both the smart contract management function in the data user's client and the contract settings function in the AAS-DA-user data asset control and management component will terminate the smart contract. The data user's client will then send notification of the data asset destruction and contract termination to the intermediary service platform and the data provider's client. Upon receipt of this information, the intermediary service platform will terminate the contract through the contract settings function in the data asset control and management component, thereby initiating the liquidation process.

[0154] In the embodiments of this application, Figure 9 As shown, the data asset active management system AAS-DA of this application is deployed on the client and the intermediate service platform. The main functions of the client include AAS-DA management, identity registration and management, smart contract management, process usage control, usage environment scanning, process management, log storage, liquidation docking, and communication functions. Specifically, the client can be deployed locally or on a private cloud. The client can be placed in a trusted and secure environment at the hardware, system, and / or software levels, where:

[0155] (1) AAS-DA management: including creating, updating, and deleting AAS-DA and its components and attributes, and configuring AAS-DA interfaces.

[0156] (2) Identity registration and management: including the registration of client users, organizations, AAS-DA, data assets, and identity certificate management.

[0157] (3) Smart Contract Management:

[0158] 1. Create a new smart contract, including user permissions, usage environment, operations on data assets, IT infrastructure requirements, transmission security requirements, etc.

[0159] 2. When the client is offline, the smart contract can still be executed through the client;

[0160] 3. Boundary conditions: specify the maximum time and maximum number of operations on data assets;

[0161] 4. Constraints: These specify the types of operations that cannot be performed on data assets.

[0162] 5. Contract termination: When the data assets are destroyed, the contract is terminated.

[0163] (4) Process usage control:

[0164] Monitor: Monitors in real time whether the process's operations on data assets have reached the maximum value of the boundary conditions, or whether any operations that violate the constraints have occurred.

[0165] Executor: Abort process.

[0166] (5) Usage environment scanning: Perform usage environment scanning based on the requirements of the smart contract for the hardware, system, and software layers in the usage environment; generate a usage environment scanning result report and a process whitelist. The usage environment scanning result is sent by the data user's client to the intermediate service platform and the data provider's client at the same time, and the process whitelist is sent to the process management component for management.

[0167] (VI) Process Management: Dynamically manage the process whitelist for access control or usage control, including maintenance of processes in the whitelist (addition, update, and removal), process permission review, etc. Before data assets reach data users, the process whitelist output by the usage environment scanning function will serve as the initial whitelist. If a process on the whitelist is detected to violate the provisions of the smart contract during the use of data assets, it will be removed from the whitelist. Processes not included in the initial whitelist will be included in the whitelist after the client's process permission review.

[0168] (7) Log storage: For the client of the data provider, logs of the entire life cycle of the data asset are stored; for the client of the data user and the intermediate service platform, all operation logs of the data asset are stored after the smart contract takes effect and before the contract is terminated.

[0169] (8) Liquidation docking: When the contract is terminated, the number of times the data assets are used, the time, and abnormal situation handling are liquidated by reading the logs of the data user's client, the data provider's client, and the intermediate service platform.

[0170] (IX) Communication function: including communication between clients, communication between clients and AAS-DA, and communication between clients and intermediate service platforms.

[0171] In the embodiments of the present application, the functions of the intermediate service platform mainly include: identity authentication, resource directory management, supply and demand docking, smart contract management, log storage, liquidation audit, service evaluation and other functions. Specifically, the intermediate service platform can be deployed on a public cloud or a private cloud. The intermediate service platform must be placed in an environment where the hardware layer, system layer and software layer are all trusted and secure. The functions of the intermediate service platform can be implemented and operated by one or more organizations or units. Each organization or unit must pass identity authentication before starting related work.

[0172] Combine Figure 10 As shown, the present application also provides a method for controlling the use of data assets, which is applied to a client as a data provider, a client as a data user, and an intermediate service platform as an intermediate service provider, and the method includes:

[0173] Step 1001: The data provider and the data user perform user registration and identity authentication through their respective clients. The authenticated data provider registers and authenticates the data asset active management system AAS-DA to the intermediate service platform through the data provider's client.

[0174] Step 1002: The data provider saves the data asset information to be made public in AAS-DA-supplier as AAS-DA-public and uploads it to the intermediate service platform through the data provider's client, so that the data user and the data provider can enter into a smart contract.

[0175] Step 1003: The data user's client scans the usage environment and generates a whitelist of processes that are allowed to access or use control data assets. After confirming the processes in the whitelist, the data provider's client sends the AAS-DA-user and the pre-processed data assets to the data user's client.

[0176] Step 1004: During the use of data assets, the data user's client confirms whether one or more processes that are about to call the data assets have permission based on the processes in the whitelist, and terminates and / or destroys the data assets through AAS-DA-user and AAS-DA-public when the change of the data assets reaches the boundary conditions of the smart contract or violates the constraints.

[0177] By adopting the data asset usage control method provided by the embodiment of the present disclosure, the loading and usage control of data assets is realized between the client as the data provider, the client as the data user and the intermediate service platform as the intermediate service provider through AAS-DA, so that the data sovereignty is kept in the hands of the data provider, and the data assets are available but invisible, controllable and measurable, with access rights controlled and burned after use. It solves the problems of poor quality of data assets, difficulty in data intercommunication, high acquisition cost, difficulty in ensuring security, and complex ownership confirmation and valuation transactions, and forms a technical system for data sharing, circulation, transaction and security protection.

[0178] In the embodiments of this application, Figure 11 As shown, the data provider and the data user perform user registration and identity authentication through their respective clients. The authenticated data provider registers and authenticates the data asset active management system AAS-DA to the intermediate service platform through the data provider's client, including:

[0179] Step 1101: The data provider and the data user register as users through their respective clients, where user types include enterprises, organizations, and individuals.

[0180] In the embodiments of this application, all stakeholders involved in the trusted industrial data space, including but not limited to data providers, data users, and third parties providing log storage, liquidation, and audit services, need to register through their clients. User types include enterprises, organizations, and individuals.

[0181] Step 1102: The intermediate service platform reviews the user registration information sent by the client, authorizes a unique identity identifier for the user who passes the review, and manages the identity identifier according to the user type.

[0182] In an embodiment of the present application, the intermediate service platform will review the user registration information sent by the client. Users who pass the review will be authorized with a globally unique identity. The intermediate service platform manages the identity according to different user types.

[0183] Step 1103: The data provider who has passed identity authentication initiates an identity tag authorization application to the intermediate service platform through the data provider's client.

[0184] Step 1104: After the identity tag authorization application is approved, the intermediate service platform sends the unique data asset code and AAS-DA code to the data provider's client.

[0185] Step 1105: The data provider's client automatically writes the data asset code and AAS-DA code into the AAS-DA identity tag, completing the registration and authentication of the data asset active management system AAS-DA.

[0186] In this embodiment of the present application, an authenticated data provider initiates an identity tag authorization request to the intermediary service platform through their client. Upon approval, the intermediary service platform sends a unique "Global Data Asset Code" and "Global AAS-DA Code" to the data provider's client. The data provider's client automatically writes these two codes into the AAS-DA identity tag, completing AAS-DA registration and authentication.

[0187] In the embodiments of this application, Figure 12 As shown, the data provider saves the data asset information to be disclosed in AAS-DA-supplier as AAS-DA-public and uploads it to the intermediate service platform through the data provider's client, so that the data user and the data provider can enter into a smart contract, including:

[0188] Step 1201: The data provider saves the data asset information to be made public in AAS-DA-supplier as AAS-DA-public and uploads it to the intermediate service platform through the data provider's client. The AAS-DA-public that has been reviewed and approved by the intermediate service platform is included in the resource directory.

[0189] Step 1202: The data user's client accesses the resource directory of the intermediate service platform to query the data assets and other resources that meet the requirements. The data user's client subscribes to the resource directory or fills in the requirements for data assets and other resources. The intermediate service platform pushes data assets and other resources based on the supply of data assets and other resources.

[0190] Step 1203: The data user initiates an invitation to one or more data providers that meet its needs. The data provider that accepts the invitation will negotiate with the data user on the cooperation intention of data assets, and write the negotiated content into the smart contract management function of the intermediary service platform, as well as the smart contract management functions of the data user's client and the data provider's client.

[0191] In this way, data providers and data users use the intermediary service platform as a medium to achieve efficient supply and demand docking and smart contract setting, thereby increasing the transaction value of data assets.

[0192] In the embodiments of this application, Figure 13 As shown, the client of the data user scans the usage environment and generates a whitelist of processes that are allowed to access or use the control data assets. After confirming the processes in the whitelist, the client of the data provider sends the AAS-DA-user and the pre-processed data assets to the client of the data user, including:

[0193] Step 1301: Based on the data user's client's requirements for the usage environment, the data user's client will call the usage environment scanning component to perform a security scan on the hardware layer, system layer, and software layer of the usage environment, and security mark the processes that meet the smart contract requirements.

[0194] Step 1302: The processes that have passed the security annotation are included in the whitelist of access control or usage control in the process management component, and the client of the data user sends it to the intermediate service platform and the client of the data provider at the same time.

[0195] Step 1303: After the data provider's client confirms the whitelist, it pre-processes the data assets according to AAS-DA-supplier and saves them as AAS-DA-user, and then sends the AAS-DA-user and the pre-processed data assets to the data user's client.

[0196] In an embodiment of the present application, according to the provisions of the AAS-DA-supplier data asset control management component-contract settings, the AAS-DA-supplier will pre-process the data assets through the usage mode of the data asset control management component, including but not limited to desensitization, encryption, generation of calculation factors, etc. If "regular use" in the usage mode is selected, the data assets will be sent to the data user in plain text. If the data usage process involves multi-party collaboration, such as multi-party privacy computing, federated learning, etc., the collaborative mode of the data asset control management component will also be set. Two or more AAS-DA-suppliers that turn on the collaborative mode will realize the synchronous management of data assets during the use of data assets.

[0197] Optionally, the data provider's client can also send the AAS-DA-supplier and pre-processed data assets (plaintext or ciphertext) to the data consumer's client. The data consumer's client merges the received AAS-DA-supplier with the AAS-DA-user to generate a new AAS-DA-user. Based on the storage environment requirements of the AAS-DA-user data asset full lifecycle management component - contract management, the data assets are stored in a trusted environment.

[0198] In this way, the security and reliability of the data asset usage environment can be better guaranteed.

[0199] In the embodiments of this application, Figure 14 As shown, during the use of data assets, the client of the data user confirms whether one or more processes that are about to call the data asset have permission based on the processes in the whitelist, including:

[0200] Step 1401: One or more processes of the data asset are called to initiate a permission request to the client of the data user.

[0201] Step 1402: Confirm the permissions of one or more processes that are about to call the data asset by reading the whitelist of the client of the data user.

[0202] Step 1403: If the process is in the whitelist, the data user's client sends a confirmation instruction to the AAS-DA-user, allowing the process to operate on the data asset according to the Function attribute in the AAS-DA-user.

[0203] Step 1404: If the process is not in the whitelist, the data consumer's client will not allow the process to call the data asset.

[0204] In an embodiment of the present application, one or more processes that will call a data asset will initiate a permission request to the data user's client-process management. The permissions of the one or more processes that will call the data asset will be confirmed by reading the whitelist in the data user's client-process management. If the process is on the whitelist, the data user's client will send a confirmation instruction to the AAS-DA-user, allowing the process to operate on the data asset according to the Function attribute in the AAS-DA-user data asset control management component-contract settings. If the process is not on the whitelist, the data user's client will not allow the process to call the data asset.

[0205] In this way, the use of data assets can be better monitored based on the process permissions of data assets, thereby ensuring the data sovereignty and data security of data providers.

[0206] In the embodiments of this application, Figure 15 As shown, when the change of data assets reaches the boundary conditions of the smart contract or violates the constraints, the use of data assets will be terminated and / or destroyed through AAS-DA-user and AAS-DA-public, including:

[0207] Step 1501: Based on the boundary conditions and constraints of the smart contract, the data user's client monitors in real time whether the operation of the process on the data asset has reached the maximum value of the boundary conditions, or whether an operation that violates the constraints has occurred.

[0208] Step 1502: When the change of data assets reaches the boundary conditions of the smart contract or violates the constraints, the client of the data user forcibly terminates the process.

[0209] Step 1503: The data user's client sends an instruction to the AAS-DA-User, and the AAS-DA-user destroys the data assets.

[0210] In an embodiment of the present application, during the use of data assets, the data user's client performs process monitoring, and the data asset monitoring is performed by the AAS-DA-user. According to the boundary conditions and constraints in the smart contract management, the data user's client monitors the process of the data asset in real time through the process management-monitor to see whether the operation of the process on the data asset has reached the maximum value of the boundary conditions, or whether an operation that violates the constraint conditions has occurred. If one of the above situations occurs, the data user's client forcibly terminates the process through the process monitoring-executor and sends an instruction to the AAS-DA-User. The AAS-DA-user destroys the data asset through the data asset control management component-usage control-executor. At the same time, the AAS-DA-user monitors the changes of the data asset in real time through the data asset control management component-usage control-monitor to see whether the changes have reached the maximum value of the boundary conditions, or whether an operation that violates the constraint conditions has occurred. If one of the above situations occurs, the AAS-DA-user sends an exception message to the data user's client, and the data user's client forcibly terminates the process through the process monitoring-executor. The AAS-DA-user destroys the data asset through the data asset control management component-usage control-executor.

[0211] In this way, data sovereignty can be better firmly grasped in the hands of data providers, ensuring the stability of the value of data assets.

[0212] In the embodiments of this application, Figure 16 As shown, the usage control method provided in the embodiment of the present application further includes:

[0213] Step 1601: From the time the smart contract is concluded until the data assets are destroyed, all operations on the data assets by the data provider, data user, and the intermediary service platform will be synchronized and retained in the data provider's client, the data user's client, and the intermediary service platform in the form of logs.

[0214] Step 1602: When the data asset is destroyed, the data user's client and AAS-DA-user will terminate the smart contract and send the data asset destruction and smart contract termination information to the intermediary service platform and the data provider's client through the data user's client.

[0215] Step 1603: After the intermediary service platform receives the information that the data assets have been destroyed and the smart contract has been terminated, AAS-DA-public will terminate the contract through the contract setting function of the data asset control management component and initiate the liquidation process.

[0216] In an embodiment of the present application, when data assets are destroyed, the data user's client-smart contract management and the AAS-DA-user data asset control management component-contract settings will terminate the smart contract. Then, the data asset destruction and contract termination information is sent to the intermediate service platform and the data provider's client through the data user's client. After receiving the information, the data provider's client-smart contract management and AAS-DA-supplier will terminate the smart contract through the data asset control management component-contract settings. After the intermediate service platform receives the information, the contract of the AAS-DA-public data asset control management component-contract settings is terminated. AAS-DA-public reads the log evidence components of AAS-DA-supplier and AAS-DA-user, and compares them with the content of the data asset control management component-contract settings.

[0217] If a data user uses the data asset normally in accordance with the smart contract and ceases use when a boundary condition is triggered, AAS-DA-public will generate a settlement report based on the unit price of the data asset, the number of times / time of use, and other factors, and send it to the data user and data provider. After settlement, the data user can evaluate data asset attributes such as data quality. Based on this evaluation, AAS-DA-public will update attribute information such as the data quality management component of the data asset's full lifecycle management. Data providers can also evaluate the creditworthiness of data users.

[0218] If a data user fails to use the data asset in accordance with the smart contract, AAS-DA-public will generate a settlement report based on the unit price of the data asset, the number / duration of usage, and any violations, and send it to the data user and data provider. After settlement, the data user cannot evaluate the data asset's attributes. The intermediary service platform will downgrade the data user's credit rating. The data user's credit rating will affect the permissions management and other attributes of the AAS-DA-user data asset control and management component.

[0219] In addition, the intermediary service platform will retain AAS-DA-public until the retention period of AAS-DA-public expires, or the data provider submits an application for destruction of AAS-DA-public.

[0220] Optionally, if the smart contract allows the data user to copy the data asset, an AAS-DA-user-copy will be generated for the copied data asset and associated with the AAS-DA-user.

[0221] In this way, when abnormal usage of data assets occurs, data assets can be better managed and controlled through AAS-DA-user to ensure the value of data assets.

[0222] Optionally, the data asset usage control method of the present application also includes the storage and destruction of AAS-DA-supplier information, as well as the updating of AAS-DA-supplier and AAS-DA-public. For details, please refer to the aforementioned part of this specification, and this application will not go into details here.

[0223] Combine Figure 17 As shown, an embodiment of the present disclosure provides a computing device, including a processor 170 and a memory 171. Optionally, the device may also include a communication interface 172 and a bus 173. The processor 170, the communication interface 172, and the memory 171 can communicate with each other through the bus 173. The communication interface 172 can be used for information transmission. The processor 170 can call the logic instructions in the memory 171 to implement the data asset active management system of the above embodiment, or execute the data asset management method of the above embodiment, or execute the data asset use control method of the above embodiment.

[0224] In addition, the logic instructions in the memory 171 can be implemented in the form of software functional units and can be stored in a computer-readable storage medium when sold or used as an independent product.

[0225] Memory 171, as a computer-readable storage medium, can be used to store software programs and computer-executable programs, such as program instructions / modules corresponding to the methods in the embodiments of the present disclosure. Processor 170 executes the program instructions / modules stored in memory 171 to perform functional applications and data processing, thereby implementing the data asset active management system of the above-mentioned embodiments, or executing the data asset management method of the above-mentioned embodiments, or executing the data asset use control method of the above-mentioned embodiments.

[0226] The memory 171 may include a program storage area and a data storage area. The program storage area may store an operating system and application programs required for at least one function; the data storage area may store data generated based on the use of the terminal device. Furthermore, the memory 171 may include high-speed random access memory and non-volatile memory.

[0227] An embodiment of the present disclosure provides a storage medium storing program instructions. When the program instructions are executed, the data asset active management system of the above embodiment can be implemented, or the data asset management method of the above embodiment can be executed, or the data asset usage control method of the above embodiment can be executed.

[0228] The aforementioned storage medium may be a transient computer-readable storage medium or a non-transitory computer-readable storage medium.

[0229] The technical solution of the embodiments of the present disclosure may be embodied in the form of a software product, which is stored in a storage medium and includes one or more instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the embodiments of the present disclosure. The aforementioned storage medium may be a non-transitory storage medium, including: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program code, or a transient storage medium.

[0230] The above description and the accompanying drawings fully illustrate the embodiments of the present disclosure so that those skilled in the art can practice them. Other embodiments may include structural, logical, electrical, process and other changes. The embodiments represent only possible variations. Unless explicitly required, individual components and functions are optional, and the order of operations may vary. Parts and features of some embodiments may be included in or replace parts and features of other embodiments. Moreover, the words used in this application are only used to describe the embodiments and are not used to limit the claims. As used in the description of the embodiments and claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to also include plural forms. Similarly, the term "and / or" as used in this application refers to any and all possible combinations including one or more associated listings. In addition, when used in this application, the term "comprise" and its variations "comprises" and / or comprising refer to the presence of stated features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or groups of these. In the absence of further restrictions, an element defined by the sentence "comprising a..." does not exclude the presence of other identical elements in the process, method or device that includes the element. In this article, each embodiment may focus on the differences from other embodiments, and the same and similar parts between the various embodiments can be referenced to each other. For the methods, products, etc. disclosed in the embodiments, if they correspond to the method part disclosed in the embodiments, then the relevant parts can be found in the description of the method part.

[0231] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software may depend on the specific application and design constraints of the technical solution. The technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the embodiments of the present disclosure. The technicians will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0232] In the embodiments disclosed herein, the disclosed methods and products (including but not limited to devices, equipment, etc.) can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units can be merely a logical functional division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between each other shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, and can be electrical, mechanical or other forms. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the units may be selected to implement this embodiment according to actual needs. In addition, the functional units in the embodiments of the present disclosure may be integrated into a processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0233] The flowcharts and block diagrams in the accompanying drawings show the possible implementation architectures, functions and operations of the systems, methods and computer program products according to the embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment or part of the code, and the module, program segment or part of the code includes one or more executable instructions for implementing the specified logical functions. In some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, or they can sometimes be executed in the opposite order, which can depend on the functions involved. In the descriptions corresponding to the flowcharts and block diagrams in the accompanying drawings, the operations or steps corresponding to different boxes can also occur in an order different from that disclosed in the description, and sometimes there is no specific order between different operations or steps. For example, two consecutive operations or steps can actually be executed substantially in parallel, or they can sometimes be executed in the opposite order, which can depend on the functions involved. Each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented by a dedicated hardware-based system that performs the specified function or action, or may be implemented by a combination of dedicated hardware and computer instructions.

Claims

1. A data asset management method, characterized in that: Applied to the data asset active management system AAS-DA, the data asset active management system AAS-DA is divided into AAS-DA-supplier, AAS-DA-user and AAS-DA-public, the method includes: After a data asset is formed, the data provider creates an AAS-DA-supplier corresponding to the data asset and generates the data asset's initial sovereignty information in the AAS-DA-supplier, where the initial sovereignty information includes the data asset's ownership information, time information, and location information; defines, sets, and updates various subject attributes of the data asset through the AAS-DA-supplier; when a data asset is copied or sub-data is generated, it is associated through the respective AAS-DA-supplier; and data assets are desensitized or encrypted through the AAS-DA-supplier; The data provider saves the data asset information to be disclosed in the AAS-DA-supplier as the corresponding AAS-DA-public and uploads it to the intermediary service provider. The intermediary service provider generates a resource directory based on the various subject attributes of the AAS-DA-public, realizing a centralized or distributed management model for data assets. Data users access the resource directory of the intermediary service provider to query data assets that meet their needs. The intermediary service provider pushes data assets to data users based on the supply of data assets in the resource directory. Data users read the data asset information disclosed in AAS-DA-public and enter into smart contracts with data providers through AAS-DA-public; The data provider saves the AAS-DA-supplier as AAS-DA-user and sends the AAS-DA-user and pre-processed data assets to the data user. AAS-DA-user monitors the data asset usage process of data users based on smart contracts and records all processing operations on data assets; When the change of data assets reaches the boundary conditions of the smart contract or violates the constraints, AAS-DA-user terminates the use of and / or destroys the data assets of the data user; The data user reads the data asset information disclosed in AAS-DA-public and enters into a smart contract with the data provider through AAS-DA-public, including: The data user initiates an invitation to one or more data providers that meet their needs. The data provider that accepts the invitation will negotiate with the data user on the cooperation intention of the data asset and write the negotiated content into AAS-DA-public. The use process of the data asset is configured in AAS-DA-public and logged.

2. The data asset management method according to claim 1, characterized in that: Define, set, and update various subject attributes of data assets through AAS-DA-supplier, including data type, standards, specifications, laws and regulations followed by data assets, quality level, and at least one of the security level requirements.

3. The data asset management method according to claim 1, characterized in that: According to the provisions of the AAS-DA-supplier data asset control management component-contract settings, AAS-DA-supplier will pre-process data assets through the usage mode of the data asset control management component.

4. The data asset management method according to claim 1, characterized in that: The time when the smart contract is reached and the information of both parties to the transaction are recorded in the AAS-DA-public log.

5. The data asset management method according to claim 1, characterized in that: The AAS-DA-user monitors the data asset usage process of the data user according to the smart contract and records all processing operation information of the data assets, including: AAS-DA-user performs security scans on the media and environment where data assets will be stored and used, based on the usage environment requirements in the smart contract. By reading the access control or usage control whitelist in AAS-DA-user, confirm the permissions of one or more processes that will call data assets; AAS-DA-user monitors in real time whether changes in data assets have reached boundary conditions or whether any operations that violate constraints have occurred, and writes operation logs to the log evidence component.

6. The data asset management method according to claim 1, characterized in that: When the change of data assets reaches the boundary conditions of the smart contract or violates the constraints, AAS-DA-user terminates the use of and / or destroys the data assets of the data user, including: Based on the constraints and boundary conditions of the smart contract, the AAS-DA-user generates an operation script to terminate or destroy data assets; When the change of data assets reaches the boundary conditions of the smart contract or violates the constraints, the AAS-DA-user will record the processing operation information and feed it back to the AAS-DA-supplier in real time or afterwards, so that the AAS-DA-supplier can issue a termination instruction to the AAS-DA-user, and the AAS-DA-user will call the operation script to terminate the use of the data assets. Alternatively, the AAS-DA-user can directly call the operation script to terminate the use of the data assets. After the use of data assets is terminated or when the AAS-DA-user receives a destruction instruction from the AAS-DA-supply r, the data assets shall be destroyed.

7. The data asset management method according to claim 1, characterized in that: Also includes: When the data assets are destroyed, AS-DA-user terminates the smart contract and sends the destruction of the data assets and the termination of the smart contract to the data provider and the intermediary service provider; After receiving the information that the data assets have been destroyed and the smart contract has been terminated, the data provider will terminate the smart contract through AAS-DA-supplier and send the liquidation application information to the intermediary service provider and data user through the data provider; After receiving the liquidation application information, the intermediary service provider terminates the smart contract through AAS-DA-public, and reads the log evidence components of AAS-DA-supplier and AAS-DA-user through AAS-DA-public, compares them with the contents of the smart contract, and implements liquidation and auditing based on the comparison results.

8. A data asset active management system, characterized in that: According to the ownership of different stakeholders, the data asset active management system AAS-DA as described in any one of claims 1 to 7 is divided into AAS-DA-supplier, AAS-DA-user and AAS-DA-public, wherein the three AAS-DAs of the same data asset are interrelated and can be merged under necessary conditions. AAS-DA-supplier has the highest authority and can read all the contents in AAS-DA-user and AAS-DA-public. The contents specified by AAS-DA-user and AAS-DA-public are a subset of AAS-DA-supplier.

9. A computing device comprising a processor and a memory storing program instructions, characterized in that: The processor is configured to execute the data asset management method according to any one of claims 1 to 7 when running the program instructions.

10. A storage medium storing program instructions, characterized in that: When the program instructions are executed, the data asset management method according to any one of claims 1 to 7 is executed.

Citation Information

Patent Citations

  • Event-driven smart contract platform design

    CN112200670A

  • Data asset registration, derivation and circulation method and system

    CN112801799A