Systems and methods for auditable data management

Through the client-server model and immutable storage digital signature technology, the problem of inefficient query in Geodata management is solved, the traceability and auditability of Geodata are realized, and the query efficiency of the data management system is improved.

CN117015770BActive Publication Date: 2025-07-25HONG KONG APPLIED SCI & TECH RES INST
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202280000826.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-04-01
Filing Date
2022-04-07
Publication Date
2025-07-25
Estimated Expiration
2042-04-07

AI Technical Summary

Technical Problem

The existing technology is difficult to effectively manage and trace a large amount of geospatial data (Geodata), especially when it is jointly created and updated by different parties, resulting in inefficient data query and uncertain traceability.

Method used

Using the client-server model, using immutable storage and digital signature technology, data traceability and auditability are achieved by generating and storing data records and signature records, and data snapshots and collaborative rating technologies are used to improve query efficiency.

Benefits of technology

It improves the query efficiency of the data management system, ensures the traceability and auditability of Geodata, and reduces the consumption of data verification time and storage resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117015770B_ABST
    Figure CN117015770B_ABST
Patent Text Reader

Abstract

The present invention provides systems and methods for auditable data. Embodiments of the data management system facilitate the storage and management of various data (e.g., information about transactions, customers, infrastructure, geographical locations, medical records, etc.) to support data creation, manipulation, storage, and / or sharing by different parties. Users can create new and / or update data, digitally sign the data, and store the digital signature and the data on an immutable storage using the data structures of the data management system. Using a data structure in which data and associated metadata are stored on an immutable storage in association with corresponding data and user digital signatures can be used to provide data traceability and audibility. Snapshots of merged data can be implemented for data with many updates to avoid latency when querying the data by merging the updated data. A collaborative rating mechanism can provide a measure of trust in the data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to data management, and particularly to auditable data management techniques. Background Art

[0002] In today's society, the generation, collection, aggregation, and management of various types of data have become increasingly common. For example, with the popularity of processor-based systems and their almost ubiquitous interconnectivity, large amounts of data are created, manipulated, stored, and shared in the daily activities of enterprises and individuals. For example, data may include information about transactions, customers, infrastructure, geographical locations, medical records, etc. The ability to verify, validate, and / or audit this data, manage data updates, and provide other aspects of data management pose significant challenges, especially in cases where there is a large amount of data, a large number of users creating and updating data, or a large number of updates or other revisions to the data.

[0003] Geographic spatial data (Geodata) is an example of a data type for which large amounts of data are created, manipulated, stored, and shared. Geodata is data related to a location relative to the Earth. For example, large collections of Geodata can form core infrastructure (e.g., three-dimensional (3D) city models and sensor data) to support smart city applications. The typical file size of Geodata is usually very large, typically between 100 MB and 500 MB.

[0004] The management of Geodata can pose some challenges. For example, Geodata is provided by a number of different parties that are usually not related. For example, Geodata can include Building Information Modeling (BIM) data for intelligent software modeling for collaborative building design, operation, and / or management. BIM data can be created by different entities, such as architects, water and sewage infrastructure providers, telecommunications and communication infrastructure providers, power supply infrastructure providers, etc., involved in the design, construction, operation, and / or maintenance of one or more respective buildings. In addition, Geodata often requires cumulative updates. In the BIM example, important parts of Geodata may be updated at different construction stages (e.g., planning, design, construction, and operation). Thus, different parties may update Geodata from time to time.

[0005] Since Geodata is provided by different parties, it can be particularly difficult to verify and audit changes to Geodata. As Geodata is changed by different parties from time to time, it is difficult to verify each party and audit these changes. In addition, it can be quite difficult to verify Geodata unilaterally. Therefore, the traceability and auditability of the data that makes up Geodata are often impractical or uncertain. In addition, cumulative updates to Geodata can lead to inefficient data queries (for example, when the server combines various updates to Geodata, long waiting times may be experienced).

[0006] Existing solutions for managing geospatial data and other data types that create, manipulate, store, and share large amounts of data do not fully address the above and other challenges. For example, the technology for generating and updating multi-person geospatial information data described in CN 113568921A provides for the generation and update of geospatial information data. According to the operation of CN 113568921A, centralized management of massive data is performed in a server, and multi-person offline collaborative operation and editing are performed on the client side. An enterprise-level geodatabase is used, which relies on a database administrator (such as an SQL DBA) to configure and ensure data security. The solution of CN 113568921A does not well facilitate the traceability and auditability of geospatial information data provided and updated by multiple parties. In addition, the query optimization that can be implemented by the database administrator is not very suitable for efficiently querying the cumulative update data of the traceable data update chain.

[0007] US 10552381 B2 provides a transaction blockchain that can be used as a reference for various purposes and can be accessed by relevant parties later for ledger verification. According to the operation of US 10552381 B2, it can include: determining that a shared file is being edited by one or more entities, determining one or more changes to the shared file while it is being edited, signing the one or more changes with one or more public keys, and adding the one or more changes to the blockchain. Although relatively high security may be provided in terms of transaction data, the operation according to US 10552381 B2 is inefficient, may result in the use of a large amount of computing and storage resources, and significant latency in storing and querying data. Summary of the Invention

[0008] The present invention relates to systems and methods for providing traceable and / or auditable data, such as in situations where large amounts of data (e.g., information about transactions, customers, infrastructure, geographical locations, medical records, etc.) are created, manipulated, stored, and / or shared by several different parties. Embodiments of the data management techniques of the present invention help improve the efficiency of storing and querying data. Additionally, or alternatively, data management implemented according to the concepts of the present invention facilitates the verification of data, e.g., enabling a single party to effectively and efficiently verify data.

[0009] Embodiments of the present invention implement a client-server model that includes a server with immutable storage. Users of the data management system and method can generate or otherwise obtain a private and public key pair for use with aspects of the data management system. In operation according to an embodiment, a user can create new and / or update data, digitally sign the data using the private key of the key pair, and store the digital signature and data on the immutable storage using a data structure according to the concepts herein, thereby facilitating the traceability and audibility of the data. Thus, according to embodiments of the present invention, users can be enabled to store and / or update data shared by different parties and data shared among different parties, thereby facilitating the traceability and / or audibility of the data. For example, according to an embodiment, a data structure can be used in which data (e.g., new data and updated data mapped to instances of previously stored new / updated data) and associated metadata are stored on the immutable storage in association with a digital signature corresponding to the data and the user for providing traceability and audibility of the data. Embodiments can also implement techniques for creating snapshots of data regarding cumulative updates, thereby improving the query efficiency regarding the data. For example, snapshots of merged data can be implemented for data with many updates to avoid latency when merging updated data for querying the data. Additionally, embodiments of the present invention can implement rating techniques to provide a degree of trust associated with the data, thereby facilitating the efficient and effective verification of the data. For example, a collaborative rating mechanism can provide a degree of trust associated with the data (e.g., the server can perform matrix operations on the ratings to calculate the degree of trust), which can, for example, be used by a user to reduce the time and effort of data verification.

[0010] According to some examples, the system and method are configured to manage geospatial data (Geodata). For example, Geodata can include building information model (BIM) data. Embodiments can be used to ensure that Geodata is traceable and auditable. According to some embodiments, the efficiency of Geodata querying is facilitated by using effective data structures, including using data snapshots. According to some embodiments, rating of users and Geodata can be implemented to provide a degree of trust, as can be used to verify Geodata according to the concepts herein.

[0011] The features and technical advantages of the present invention have been outlined quite extensively above in order to better understand the following detailed description of the present invention. Other features and advantages of the present invention will be described below, and these features and advantages form the subject matter of the claims of the present invention. Those skilled in the art should understand that the disclosed concepts and specific embodiments can be readily used as a basis for modifying or designing other structures to achieve the same purpose of the present invention. Those skilled in the art should also recognize that such equivalent structures do not depart from the spirit and scope of the present invention as set forth in the appended claims. When considered in conjunction with the accompanying drawings, the novel features, including its organization and method of operation, as well as further objects and advantages, which are considered to be the characteristics of the present invention, can be better understood from the following description. However, it should be clearly understood that each drawing is provided for purposes of illustration and description only and is not intended as a definition of the limitations of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] To more fully understand the present invention, reference is now made to the following description taken in conjunction with the accompanying drawings, in which:

[0013] Figure 1 A data management system showing an embodiment of the present invention, which is configured to facilitate auditable data management;

[0014] Figure 2A An example of a data structure implemented on a signature record showing an embodiment of the present invention;

[0015] Figure 2B An example of a data structure implemented on a data record showing an embodiment of the present invention;

[0016] Figure 2C Storage of signature records related to data records on a storage of a data management system showing an embodiment of the present invention;

[0017] Figure 3A Details of examples of data records of new data and updated data showing an embodiment of the present invention, which can be generated by the data management system for storage and management;

[0018] Figure 3B Storage of signature records related to corresponding data records on a storage of a data management system showing an embodiment of the present invention;

[0019] Figure 3C An example of an update tree extracted from a reference within a reference data identifier (ID) field of a data record showing an embodiment of the present invention;

[0020] Figure 3D An example of a snapshot of merged data regarding data capture with multiple updates showing an embodiment of the present invention;

[0021] Figure 4A The user ability to rate any data of the data management system by the collaborative rating technology of the embodiments of the present invention;

[0022] Figure 4B The user ability to rate any user of the data management system by the collaborative rating technology of the embodiments of the present invention;

[0023] Figure 5 Show details of an example of a data record regarding rated data of the embodiments of the present invention, which can be generated by the data management system for storage and management;

[0024] Figure 6 Show an example flowchart of the client system operation of the client-server data management system of the embodiments of the present invention;

[0025] Figure 7 Show an example flowchart of the server system operation of the client-server data management system of the embodiments of the present invention. Detailed Description of the Invention

[0026] Figure 1 Show an embodiment of the data management system 100, which is configured to facilitate auditable data management according to the concept of the present invention. The data management system 100 of the shown embodiment is configured to provide data traceability and auditability for various types of data. The data for which the data management system 100 provides auditable data management can include a large amount of data (e.g., information about transactions, customers, infrastructure, geographical locations, medical records, etc.), which can be created, operated, stored, and / or shared by multiple different parties.

[0027] As a specific example, the data for which the data management system 100 provides auditable data management can include geospatial data (Geodata). For example, Geodata can include building information model (BIM) data. Although the embodiments of the data management system 100 are described herein with reference to Geodata to provide an example to help understand the concept of the present invention, it should be understood that the data management system 100 of the embodiments can be used for other or alternative types of data.

[0028] Figure 1The data management system 100 includes a data management platform 110 to provide auditable data management functions, such as facilitating the storage, update, access, and / or sharing of data by users of the data management system 100 and sharing data among users. For example, the data management platform 110 may include one or more processor-based servers configured to control the storage and access of data. Thus, the data management platform 110 is connected to the storage 120 or otherwise communicates with the storage 120.

[0029] The storage 120 may include one or more forms of computer-readable media (e.g., various forms of tangible, non-transitory computer-readable media). According to some embodiments of the present invention, the storage 120 may include random access memory (RAM), flash memory, disk memory, solid state drive (SSD) memory, optical memory, write once read many (WORM) memory, etc. The storage 120 may include a storage array or other storage systems, such as a redundant array of independent disks (RAID) array, a storage area network (SAN), a network attached storage (NAS) array, etc. In operation according to embodiments of the present invention, the storage 120 may be used to store various information, including program code for data management logic (e.g., executed by one or more processors of the data management platform 110), program code for client applications (e.g., executed by one or more processors of the user device 130), system and / or operation data (e.g., used by any one or all of the data management platform 110, the user device 130, and their various applications), data managed by the data management platform 110, etc. Portions of the storage 120 may include part of one or more systems of the data management system 100 (e.g., the data management platform 110), and / or may be separated from such systems (e.g., provided as an independent database system).

[0030] Regardless of the specific form of the medium constituting the storage 120, the storage 120 of the embodiments is configured to provide immutable storage for the data managed by the data management platform 110. For example, the medium of the storage 120 (e.g., WORM memory) itself may be configured to provide immutability for some or all of the data stored thereon. Additionally or alternatively, the data management platform 110 and the storage 120 may cooperate (e.g., implementing blockchain storage technology) to provide immutability for some or all of the data stored on the storage 120.

[0031] The illustrated embodiment of the data management system 100 provides a client-server configuration for managing data created, manipulated, stored, and / or shared by several different parties. Accordingly, the data management platform 110 is shown communicating with various systems (e.g., user devices 130) that users can use to create, manipulate, store, and / or share data. In an example where Geodata is data managed by the data management platform 110, users of the user device 130 can include individuals associated with architects, water and sewer infrastructure providers, telecommunications and communication infrastructure providers, power supply infrastructure providers, etc., who are involved in the design, construction, operation, and / or maintenance of one or more corresponding buildings. The user device 130 can be embodied in various forms and configurations of processor-based systems, such as a portable computer system (e.g., user device 130a), a desktop computer system (e.g., user device 130b), a smart phone (e.g., user device 130c), a tablet device (not shown), a personal digital assistant (not shown), an Internet device (not shown), a networked computer system (not shown), etc.

[0032] The illustrated embodiment of the data management system 100 shows a representative example of the number and configuration of various devices, systems, and platforms for providing functions related to data management. However, it should be understood that the specific number and configuration shown are simplified to facilitate understanding of the concepts of the present invention, and embodiments of the present invention are not limited to application to the specific representative number and configuration shown. For example, embodiments of the data management system 100 can include multiple data management platforms and / or more or fewer user devices. Additionally or alternatively, the data management system 100 can include devices, systems, and / or platforms other than those shown for creating, manipulating, storing, sharing, etc. data.

[0033] The various devices, systems, platforms, and other components of the data management system 100 can each include one or more processor-based systems. Such processor-based systems can include one or more processors, such as CORE or PENTIUM processors; necessary computer / processor-readable memory, such as RAM, read-only memory (ROM), flash memory, disk memory, SSD memory, optical memory, etc.; and input / output components, such as a display, a network interface card (NIC), a keyboard, a digital pointer, a printer, etc.; connected to one or more processors via a data bus to provide the functions described herein. For example, the data management platform 110, the storage 120, and / or the user device 130 can include a memory storing logic configured to provide their respective functions, and at least one processor can execute the logic to implement the functions described herein.

[0034] The network 101 of the illustrated embodiment provides communication links to facilitate communication among various devices, systems, and other components of the data management system 100, such as some or all of the data management platform 110, the storage 120, and / or the user devices 130. Thus, the network 101 can include any number of network configurations, such as the Internet, an intranet, a public switched telephone network (PSTN), a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a cellular network, a wireless network, a cable transmission network, and the like. The communication links between the various nodes of the network can include wired links, wireless links, and combinations thereof.

[0035] The data management platform 110 of the embodiment can be provided in a cloud-based implementation (e.g., the data management platform 110 exists in the "cloud" of the network 101 of the data management system 100) and is accessible to various devices, systems, and other components communicating with the network 101. For example, the data management platform 110 or portions thereof in some embodiments can include computer-executable code executed on one or more processor-based systems (e.g., web servers) deployed in the network 101. Additionally or alternatively, the data management platform 110 or portions thereof can include one or more discrete host platforms (e.g., network edge devices) or other forms of processor-based system implementations that communicate via the network 101.

[0036] The data management platform 110 of the embodiment of the data management system 100 can cooperate with one or more user devices 130 to provide various functions related to creating, operating, storing, and / or sharing data. For example, the data management platform 110 of the embodiment can provide functions for auditable data management, such as data traceability and auditability related to one or more types of data according to the inventive concept. The user devices 130 of the embodiment can provide functions for users interacting with the data management platform 110, such as facilitating the creation, update, and access of data managed by the data management platform 110 by the users. Thus, the data management platform 110 of the embodiment includes server-implemented data management logic (e.g., one or more sets of processor-executable instructions) configured to facilitate the operation of auditable data management. Correspondingly, the user devices 130 of the embodiment include client-implemented data interface logic (e.g., one or more sets of processor-executable instructions) configured to cooperate with the server-implemented data management logic to facilitate the creation, update, and access of data managed by the data management platform 110.

[0037] In an example operation of the data interface logic performed by a user device of user device 130, the user device generates or otherwise obtains a private key and a public key pair for data management system 100. For example, the data interface logic may implement an asymmetric encryption algorithm (e.g., Rivest-Shamir-Adleman (RSA), Digital Signature Algorithm (DSA), Elliptic Curve Cryptography (ECC), etc.) to generate the private key and public key pair. The public key in the private key and public key pair may be used to represent the user in the data management system.

[0038] The user may utilize the corresponding one or more user devices 130 to create new data to be managed by data management system 100. Additionally or alternatively, the user may utilize the corresponding one or more user devices 130 to update data managed by data management system 100. In an example operation of the data interface logic performed by the user device, the private key of the private key and public key pair is used to digitally sign the data, and a signature record including the digital signature is created. The data interface logic performed by the user device of this example may also create a data record including the data (e.g., new data, updated data, etc.) for data management system 100 to manage.

[0039] Figure 2A An example of the data structure implemented for the signature record is shown, namely signature record 210. In the example of signature record 210, the Identification (ID) field 211 includes an identifier of the signature record. For example, the identifier of the ID field 211 may include a unique identifier of the signature record, which may be used, for example, to associate the signature record with a corresponding data record (e.g., the data record includes new data, updated data, and / or rating data), etc. The signature field 212 of the illustrated example of signature record 210 includes the digital signature of the corresponding data record (e.g., using the above private key). For example, the digital signature may include signature function signature(data record)=E(H(data record)), where E() is an encryption function using the private key (e.g., RSA, DSA, ECC, etc.), and H() is a hash function (e.g., Message Digest Algorithm Version 5 (MD5), Secure Hash Algorithm 1 (SHA-1), Secure Hash Algorithm 2 (SHA-2), etc.). According to an embodiment of the present invention, the digital signature is used to facilitate the auditability and traceability of the corresponding data record (e.g., to prove who created the data record).

[0040] Figure 2B An example of the data structure implemented for the data record is shown, namely data record 220. The data record 220 of the illustrated embodiment includes a plurality of data fields, which are useful for auditable data management according to the concepts herein. In particular, Figure 2BThe data record 220 of the embodiment includes an ID field 221, a reference signature ID field 222, a public key field 223, a type field 224, a reference data ID field 225, a data field 226, and a metadata field 227, which will be described in further detail below. It should be understood that the specific data fields of the data record 220 describe the number, type, configuration, etc. of the data fields used according to the embodiments of the present invention. Some embodiments may include more or fewer data fields, as well as different and / or alternative data fields.

[0041] In Figure 2B In the example of the data record 220 shown, the ID field 221 may include an identifier of the data record. For example, the identifier of the ID field 221 may include a unique identifier of the data record, which may be used to associate the data record with a corresponding data record (e.g., the data record includes update data and / or rating data). The identifier of the reference signature ID field 222 may include an identifier of the associated signature record. For example, the identifier value in the ID field 211 of the signature record 210 instance, including the digital signature of the data record 220 instance in its signature field 212, may be provided as the identifier value in the reference signature ID field 222 for the traceability and / or auditability of the data record 220 instance.

[0042] The public key field 223 of the embodiment of the data record 220 may include the public key of the private key - public key pair for the digital signature in the signature field 212 of the instance of the signature record 210 identified by the reference signature ID field 222. The key field 223 may correspond to the user who created the instance of the data record 220, e.g., for tracking and / or auditing the instance of the data record 220 and / or the data therein.

[0043] The type field 224 may include information about the type of the data record. For example, the information included in the type field 224 of the embodiment may identify the data record 220 instance as type "new", "update", or "rating", e.g., corresponding to a specific data type in one or more further fields of the data record 220.

[0044] According to some examples of data record 220, data field 226 may include the main or payload data of an instance of the data record. For example, data field 226 may include new data created by a user (for whom the data management system 100 provides data management) (e.g., raw data, which may be updated from time to time). In the example of Geodata, data field 226 may include new BIM data related to building design, operation, and / or management. Data field 226 may additionally or alternatively include update data corresponding to changes, modifications, revisions, updates, etc. of the existing data (e.g., previous new data and / or updated data) managed by data management system 100. For example, the update data of data field 226 may include updates to certain parts of the existing data on data management system 100. In the example of Geodata, the update data of data field 226 may include one or more updates to the Geodata stored on storage 120. Additionally, or alternatively, data field 226 may include rating data corresponding to the data and / or users of the data management system. For example, a user of the data management system may provide rating information for the data managed by data management system 100 (e.g., a rating from 0 to 1, where 0 is the lowest and 1 is the highest) (e.g., to indicate their assessment of the accuracy, validity, authenticity, relevance, etc. of the specific data being managed). Similarly, a user of the data management system may additionally or alternatively provide rating information about other users of data management system 100 (e.g., a rating from 0 to 1, where 0 is the lowest and 1 is the highest) (e.g., to indicate their assessment of the reliability, authenticity, dependability, etc. of a specific user of the data management system).

[0045] The information included in type field 224 of an embodiment of data record 220 corresponds to the data type included in data field 226 of that instance of data record 220. For example, in the case where data field 226 includes new data created by a user and data management system 100 provides data management, type field 224 may identify the data record 220 instance as type "new" or include type "new". Similarly, in the case where data field 226 includes update data corresponding to changes, modifications, revisions, updates, etc. of the existing data managed by data management system 100, type field 224 may identify the data record 220 instance as type "update" or include type "update". Further, in the case where data field 226 includes rating data corresponding to the data and / or users of the data management system, type field 224 may identify the data record 220 instance as type "rating" or include type "rating".

[0046] The reference data ID field 225 of an embodiment of the data record 220 may include an identifier of another data record related to the data in the data field 226 of the data record 220 instance. For example, the identifier value in the ID field 221 of the first instance of the data record 220 may be provided as the identifier value in the reference data ID field 225 of the second instance of the data record 220, where the first instance of the data record 220 includes data updated by the data of the second instance of the data record 220 (including the updated data in the data field 226). For example, using the identifier of the reference data ID field 225 of the second instance of the data record 220 to identify the first instance of the data record 220 can be used to identify the cumulatively updated data using the updated data of the second instance of the data record 220. The identifier value in the ID field 221 of the first instance of the data record 220 may be provided as the identifier value in the reference data ID field 225 of the second instance of the data record 220, where the first instance of the data record 220 includes rating data of the second instance of the data record 220 (including the rating data in the data field 226). For example, using the identifier of the reference data ID field 225 of the second instance of the data record 220 to identify the first instance of the data record 220 can be used to apply a rating to the corresponding data. The identifier value in the ID field 221 of the first instance of the data record 220 may be provided as the identifier value in the reference data ID field 225 of the second instance of the data record 220, where the first instance of the data record 220 includes the public key of the user of the rating data of the second instance of the data record 220 (including the rating data in the data field 226). For example, using the identifier of the reference data ID field 225 of the second instance of the data record 220 to identify the first instance of the data record 220 can be used to apply a rating to the corresponding user.

[0047] According to some examples of the data record 220, the metadata field 227 may include data providing information about one or more aspects of the data record and / or its data. For example, the metadata field 227 of an instance of the data record 220 in an embodiment may include user-defined metadata related to the data in the data field 226 of that instance of the data record. Additionally or alternatively, the metadata field 227 of an instance of the data record 220 in an embodiment may include user-defined metadata related to the data of another instance of the data record 220 (e.g., identified by the reference data ID 225). In the example of Geodata, the user-defined metadata may include location information (e.g., [latitude, longitude]), descriptive information (e.g., "This is a description of Geodata"), and / or other information about Geodata or other relevant information.

[0048] In an operation according to an embodiment of the present invention, when a user wants to save data for management by the data management system 100, an instance of a data record 220 containing the data and a corresponding signature record (e.g., generated by the data interface logic of a user device 130 used by the user) will be generated. Thus, according to the concept herein, the generated signature record and data record can be provided by the user device (e.g., the user device in the user device 130) to the data management platform 110 for storage (e.g., in the storage 120) and for providing data management. Figure 2C Shows the storage of a first data record 2201 (e.g., Data_Record_1) and a related first signature record 2101 (e.g., Signature_Record_1) on the storage 120.

[0049] The following pseudocode shows an example of payload data including Geodata (e.g., Geodata_1) and metadata related to the Geodata (e.g., Meta_1), which can be generated (e.g., by the data interface logic of a user device 130 used by the user) and stored in an instance of a data record (e.g., Data_Record_1) of the data management system 100.

[0050]

[0051] Figure 3A Shows details of an example of a data record that can be generated (e.g., by the data interface logic of one or more user devices 130 used by the user) for storage and management by an embodiment of the data management system 100. Figure 3AThe data record 2201 (e.g., Data_Record_1) shows an embodiment of a data record that includes new Geodata generated in the form of Geodata_1 in the above example, generated by a user with the public key PK1. According to this example, the data record 2201 is generated according to the configuration of the above data record 220. Thus, the embodiment of the data record 2201 (e.g., Data_Record_1) contains a unique identifier in the ID field 2211, a unique identifier of the corresponding signature record (e.g., Signature_Record_1) in the reference signature ID field 2221, the user's public key PK1 in the public key field 2231, "new" type code information in the type field 2241, "empty" information related to the corresponding data field (e.g., Geodata is not "updated" and / or "rated", where if the type is "new", the data reference is "empty") in the reference data ID field 2251, the data payload Geodata_1 in the data field 2261, and the metadata Meta_1 in the metadata field 2271.

[0052] Although Figure 3A not shown in, according to the embodiment, an instance of the signature record corresponding to the data record 2201 is generated according to the configuration of the signature record 210 described above (e.g., generated by the data interface logic of one of the user devices 130 used by the user) to facilitate the auditability and traceability of the data record. For example, Figure 2C the signature record 2101 shown (e.g., Signature_Record_1) can be generated relative to the data record 2201 and contains a unique identifier in the ID field 211 and a digital signature of the data record 2201 (e.g., Signature(Data_Record_1)) in the signature field 212. The signature record 2101 and the data record 2201 can be stored on the storage 120 by the data management platform 110 (e.g., by the data management logic of the data management platform 110), as referred to above Figure 2C described.

[0053] The storage 120 of the embodiment provides an immutable storage device for the data managed by the data management platform 110. According to an embodiment of the present invention, immutability, the association between the data record and the signature record including the digital signature of the data record, and the public key representing the user cooperate to facilitate the auditability and traceability of the data record.

[0054] In the operation of an example of the immutable configuration of the storage 120, no records that are data - managed by the data management system are deleted from the storage 120 (e.g., the data records and the corresponding signature records will remain unchanged and be effectively stored during the period in which data management is provided for the data therein). Thus, embodiments of the present invention can implement techniques for effectively storing data within the storage 120. For example, updates to the immutable data stored on the storage 120 can be provided by storing differential data for the update. According to an embodiment, the update data of the data field 226 of an update instance of the data record 220 can include, for example, the difference between two sets of data (e.g., the existing data on the data management system 100 and the data updated by the user), for example, to facilitate cumulative updates of related data. In the example of Geodata, the update data of the data field 226 can include the difference between an existing Geodata set and an updated set of the Geodata. This configuration of the update data helps to maintain the updated data without storing the complete data set in multiple instances even in the case where the data is updated by several different parties from time to time. In addition, embodiments of the present invention provide users with the ability to track changes related to the immutable stored data, enabling users to check whether their data is outdated and avoid writing outdated data into the storage of the data management system, thus saving storage space.

[0055] Figure 3A and 3B shows the use of data record references, which, according to embodiments of the present invention, facilitates effective data storage of update data including the difference between two sets of data. In particular, Figure 3B shows the storage 120, which has multiple signature records (shown as signature records 2101 - 210 Z ) and corresponding data records (shown as data records 2201 - 220 Z ) stored on the storage 120. As Figure 3B shown, the data records can have various associations with other data records. For example, data record 2202 is related to data record 2201 as its update data; data record 2203 is related to data record 2202 as its update data; data record 2204 is related to data record 2201 as its update data; data record 2207 is related to data record 2202 as its update data.

[0056] Figure 3A The data records 2201 - 220 M (e.g., M < Z) shows the details of an example data record implementing the aforementioned update data relationships. In Figure 3A the update data records 2202 and 220 MIn the example, the updated data of each data field includes the difference between two sets of data (e.g., the existing data on the data management system 100 and the data updated by the user). In particular, the data record 2202 provides the difference data GeoDiff_2 in the data field 2262 as the updated data regarding Geodata_1 in the data field 2261 of the data record 2201. In addition, the data record 220 M provides the difference data GeoDiff_M in the data field 226 M as the updated data regarding GeoDiff_2 in the data field 2262 of the data record 2202. According to an embodiment of the present invention, these relationships help accumulate the updated data, enabling the user to use the difference between the two sets of data (e.g., use the GeoDiff data regarding Geodata) to update their own data or the data of other users.

[0057] The following pseudocode shows an example of a user with the public key PK2 of Geodata_2 generating a GeoDiff update for Geodata_1 in the above example (e.g., generated by the data interface logic of the user device 130 used by the user). The generated GeoDiff data (GeoDiff_2) can be stored in the data record 2202 (e.g., Data_Record_2) on the storage 120 of the data management system 100. Although not shown in the following pseudocode, metadata related to Geodata_2 (e.g., Meta_2) can also be generated and stored in the data record 2202 (e.g., Data_Record_2) on the storage 120 of the data management system 100 as shown in the above pseudocode.

[0058]

[0059]

[0060] The user can obtain / access the updated data through the operation of the data management platform 110 (e.g., by the data management logic of the data management platform 110) and merge the difference data with the reference data. For example, in response to a user's query regarding Geodata corresponding to Geodata_1 (e.g., queried through the data interface logic of the user device 130 used by the user), by using the data record 220 MThe differential data (GeoDiff_M) is merged with the differential data (GeoDiff_2) of data record 2202, and the resulting differential data is merged with the Geodata (Geodata_1) of data record 2201 (e.g., GeoDiff_M + GeoDiff_2 + Geodata_1), and an updated instance of Geodata can be generated (e.g., generated by the data management logic of data management platform 110).

[0061] According to an embodiment of the present invention, an update tree can be utilized to generate an instance of updated data in terms of merging data. For example, an update tree can be extracted from data records by using a reference data ID field (e.g., Figure 3A In the example, reference data ID fields 2251, 2252,... 225 M ). An example of an update tree is shown as update tree 300 in Figure 3C . The nodes of the update tree 300 of the illustrated embodiment (e.g., leaves 301 - 305) show the cumulative update relationships of various data of the reference data records represented by their respective reference data ID fields. According to an embodiment of the present invention, the nodes of the update tree 300 can be traversed to merge data and generate an instance of updated data.

[0062] As should be understood from the above, the user of the data management system 100 of the embodiment is able to store and / or update data shared by different parties and shared among different parties, thereby promoting traceability and / or auditability regarding the data. However, merging data to provide an instance of updated data may consume a considerable amount of processing time, especially in cases where there are a large number of cumulative updates and / or the data to be merged is quite complex. Therefore, in some cases (e.g., when executed in response to a user's real-time query of the data), the merging of data may result in a degraded user experience and / or other undesirable operations of the data management system 100. Thus, embodiments of the present invention can implement some techniques to improve the query performance for data with many updates, complex updates, etc.

[0063] For example, according to an embodiment of the present invention, a technique of creating a snapshot related to cumulative update data can be utilized to provide improved efficiency for data queries involving cumulative update data. As Figure 3D shown, in the operation of the snapshot technique according to some examples, for data with many updates (e.g., data 2261, 2262, 2267,... 226 M)Capture or otherwise generate a snapshot of the merged data (e.g., update data snapshot 326). The update data snapshot can be captured in association with an update data instance generated from the accumulated update data (e.g., associated with the update data stored on the storage of the data management system, associated with a user data query including updated data, etc.) so as to use the update data snapshot to avoid the latency of merging the update data for subsequent queries of the data. For example, the data management platform 110 (e.g., the data management logic of the data management platform 110) can return a pre-generated update data snapshot to the user (e.g., the user device 130 used by the user) instead of querying and merging all the updates of the specific data queried by the user.

[0064] In an operation according to an embodiment, the data management platform 110 (e.g., the data management logic of the data management platform 110) can monitor the processing time of the acquired data from Geodata_1 to Geodata_M (e.g., Geodata_ are nodes in the relevant update tree) to determine when to capture an updated data snapshot. The processing time of the merged data can be expressed as

[0065]

[0066] where Query(K) is the time to query K records from the storage and Merge(K) is the time to merge K records into the merged Geodata.

[0067] According to some examples, when determining whether to capture an updated data snapshot, a threshold time (Ttime) can be used for the processing time of the updated data. For example, if the processing time Geodata_1到Geodata_M>Ttime, an updated data snapshot record can be created in storage. The value of the threshold time (Ttime) provides control over the frequency of capturing updated data snapshots. Implementations with more updated data snapshots (e.g., lower Ttime values) generally experience improved response times, but typically use more storage space accordingly and may cause an overloaded load on the data management platform server. Regarding the threshold time (Ttime) for the use of updated data snapshots, it can be preset, for example, according to a value that promotes the desired quality of service level. For example, the threshold time can be selected within a range from 0.1 second to 10 seconds. According to some examples, the threshold time is selected within a range from 0.5 second to 5 seconds (e.g., 0.5s, 1s, 1.5s, 2s, 2.5s, 3s, 3.5s, 4s, 4.5s, or 5 seconds). According to some embodiments, the value of the threshold time (Ttime) can initially be the high-end value of a range (e.g., 10s), and then decreased (e.g., after observing the performance of the data management system, when more computing resources are available, etc.) to further improve the performance to a desired or acceptable level.

[0068] Embodiments of the present invention can implement collaborative rating techniques, such as facilitating data verification. According to some examples of the collaborative rating technique, a user can rate any data of the data management system 100 (e.g., as Figure 4A shown) and / or any other user (e.g., as Figure 4B shown). For example, a user can create (e.g., through the operation of the data interface logic of the user device 130 used by the user) a rating type data record according to the configuration of the above data record 220. Thus, as Figure 3B shown, the data record can be related to other data records, not only as an update type data record, but also as a rating type data record, related to other data records. For example, the data record 2205 is related to the data record 2203 as the rating data of the data record 2203; the data record 2206 is related to the data record 2202 as the rating data of the data record 2202. For example, such a rating type data record can provide rating information related to the data and / or rating information related to other users, as described above. In Figure 5 the example, the data record 2206 provides rating data regarding the data (e.g., Geodata_2) and / or the user (e.g., the user with the public key PK2), and has provided the data in the data field 2262 of the data record 2202 as the rating data Rating in the data field 2266. In this example, the reference data ID field 2256 includes information identifying the data record 2202 (Data_Record_2).

[0069] The following pseudocode shows an example where a user rates another user and Geodata and generates rating data (e.g., through the data interface logic of user device 130 used by the user). The generated rating data can be stored in a data field of a data record in storage 120, which data field references another data record that rates the user and the data. The following pseudocode also shows an example of metadata related to the rating data, which can also be generated for storage in the data record.

[0070]

[0071] The ratings implemented according to embodiments of the present invention can be used to provide a measure of trust in the data managed by data management system 100. When providing a measure of trust for collaborative rating implementation, embodiments of the present invention can utilize one or more rating matrices that include rating data and perform matrix operations on the ratings to calculate the measure of trust. For example, the data management logic of data management platform 110 can scan the data records stored in storage 120, or certain portions thereof, to collect rating information associated therewith (e.g., that can be obtained from rating type data records), and generate one or more rating matrices. For example, the rating information can be scanned periodically to generate and / or update one or more rating matrices. Additionally, or alternatively, one or more rating matrices can be generated or updated together with data records that include rating data stored on the storage of the data management system.

[0072] The user rating data of the embodiments includes user / user ratings (UUR) of user / user rating pairs (e.g., one user rates another user). The following table shows an example of a user / user rating pair (e.g., rating pair 12 where user_1 rates user_2) of an embodiment of data management system 100 for which ratings can be collected.

[0073] User / User User_1 … User_x User_1 UUR_11 … UUR_1x … … … … User_x UUR_x1 … UUR_xx

[0074] The rating information for each user / user rating pair can be specified using a pairing designation corresponding to the user / user pair in the above table (e.g., rating UUR_1x corresponds to the user / user rating pair User_1 / User_x). According to an embodiment of the present invention, the following is an example of a user rating matrix that can be generated to include the evaluation information of user / user rating pairs.

[0075]

[0076] Additionally, or rather, the user rating data of the embodiments includes ratings of user / data rating pairs (UDRs) (e.g., a user rates specific data). The following table shows an example of user / data rating pairs, where the data includes Geodata of an embodiment of the data management system 100 (e.g., the rating pair 12 where user_1 rates Geodata_2), for which ratings can be collected.

[0077] User / Data Geodata_1 … Geodata_z User_1 UDR_11 … UDR_1z … … … … User_x UDR_x1 … UDR_xz

[0078] The rating information for each user / data rating pair can be specified using a pairing designation corresponding to the user / data pair in the above table (e.g., the rating UDR_1z corresponds to the user / data rating pair user_1 / Geodata_z). According to an embodiment of the present invention, the following is an example of a data rating matrix that can be generated to include the rating information of user / data rating pairs.

[0079]

[0080] Embodiments of the present invention utilize rating matrices, such as the above user rating matrix (A) and data rating matrix (B), to calculate a trust level (T) regarding the data managed by the data management system 100. For example, according to some embodiments, the data management logic of the data management platform 110 can perform one or more operations on the rating matrix to calculate the trust level.

[0081] Matrix operations can be performed on the user rating and data rating matrices, including vectorization of the transpose of the matrix product (e.g., ) to calculate the trust level of the embodiment. The rating matrix operations in this example calculate the trust level as a combination of user ratings and data ratings, thus providing a multi-dimensional based trust level regarding the data of the data management system 100.

[0082] In a simplified example of the above matrix operations, the user rating matrix can be provided as The data rating matrix can be provided as The vectorized matrix can be provided as The matrix operations in this example provide where T 1,1 = 3.5 and T 2,1 = 2.6. In this example, T 1,1 > T 2,1 , so the trust level of Geodata_1 is higher.

[0083] It should be understood that in the operation of collaborative rating techniques where users rate data and / or other users, users may provide unfair or inaccurate ratings. Such inaccurate ratings can be easily detected, for example, when the correctness of the data is verified (e.g., by another user), when a user's rating often or consistently falls outside the corresponding ratings of other users, and so on. A feedback mechanism for user ratings can be implemented (e.g., based on direct feedback from another user on a user's rating, based on a comparison of a user's rating with the corresponding ratings of other users, etc.), whereby actions can be taken to reduce the impact of ratings made by users determined to be inaccurate. For example, ratings made by users determined to be inaccurate can be omitted from the above matrix, can be weighted down in matrix operations, or otherwise have their contribution reduced.

[0084] Using the rating information provided for specific data, users of the data management system 100 can accordingly adjust the time and / or effort they spend validating the data (e.g., based on the trust level provided for users who have already provided data and / or the trust level provided for specific data). For example, a user can spend time only validating specific data with a relatively low trust level (e.g., data with the lowest percentile of trust level, such as the bottom 10%, 25%, 33%, or 50% of the trust level of database data, data with a trust level below a threshold, etc.). Thus, the trust level implemented according to an embodiment of the data management system 100 can facilitate the efficient and effective validation of data.

[0085] Figure 6 and Figure 7 A high-level flowchart is provided that operates according to an embodiment of the present invention in accordance with the above examples. In particular, Figure 6 shows the operation of the client system in a client-server data management system implementation (e.g., the user device 130 executes data interface logic to perform the functions as described herein). Accordingly, Figure 7 shows the operation of the server system in a client-server data management system implementation (e.g., the data management platform 110 executes data management logic to perform the functions as described herein).

[0086] First referring to Figure 6 , the user performs one or more activities to store data on the data management system of an embodiment of the present invention, causing the process 600 for the client system to run to start at step 601. For example, the user creates, updates, and / or rates data under the management of the data management platform, causing the client system (e.g., the user device 130) to initiate process 600 and store the data on the storage of the data management system.

[0087] After startup, the process of flow 600 according to the illustrated embodiment proceeds to step 602, where it is determined whether one or more private and public key pairs related to a user in the data management system have been generated. If it is determined that the required private and public key pairs have not been generated, the process according to the illustrated embodiment proceeds to step 603 to generate the private and public key pairs, and then to step 604 to determine the type of data stored on the storage of the data management system. However, if it is determined at step 602 that the required private and public key pairs have been generated, the process according to the illustrated embodiment proceeds to step 604 to determine the type of data stored on the storage of the data management system.

[0088] In step 604 of the illustrated embodiment, the type of data record to be stored on the storage of the data management system is determined. For example, the data record can be identified as a "new", "updated", or "rated" type to correspond to a specific type of data generated or otherwise provided by the user. If it is determined that the type of the data record is "new", the process according to the illustrated embodiment proceeds to step 605 to prepare a data record containing the new data to be stored by the data management system. However, if it is determined that the type of the data record is "updated", the process according to the illustrated embodiment proceeds to step 606 to prepare a data record containing the updated data to be stored by the data management system. Similarly, if it is determined that the type of the data record is "rated", the process according to the illustrated embodiment proceeds to step 607 to prepare a data record containing the rated data to be stored by the data management system.

[0089] According to an example of flow 600, after a data record is generated (e.g., a "new" data record in step 605, an "updated" data record in step 606, or a "rated" data record in step 607), the process according to the illustrated embodiment proceeds to step 608 to prepare a signature record. For example, a signature record including a digital signature of the data record can be generated for storage on the data management system in association with the data record.

[0090] In step 609, the data record and the corresponding signature record are provided for storage on the data management system. For example, a client system (e.g., user device 130) can transmit the data record and the signature record to a server system (e.g., data management platform 110) for recording on its storage medium (e.g., storage 120).

[0091] Now refer to Figure 7, the client system performs one or more activities related to the data management system of the embodiments of the present invention, causing the operation flow 700 of the server system to start at step 701. For example, under the management of the user data management platform, data is created, updated, and / or rated, causing the client system (e.g., user device 130) to transmit data records and related signature records to the server system (e.g., data management platform 110) for storage, so that the server system starts process 700 and stores the data on the storage of the data management system. Additionally or alternatively, when a user accesses or otherwise queries data managed by the data management system, it may cause the client system (e.g., user device 130) to transmit a data query to the server system (e.g., data management platform 110) to access the data, so that the server system starts process 700 to retrieve the data stored on the data management system.

[0092] After startup, the process of flow 700 according to the illustrated embodiment proceeds to step 702 to determine whether the activity includes a data query. For example, the client system may perform various activities regarding the data management system, such as storing data on its storage, accessing or otherwise querying data managed by the data management system, etc. Based on the operation of step 702, the activity being performed is determined, and corresponding functions are provided according to the branches of flow 700.

[0093] If it is determined at step 702 that the activity does not include a data query (e.g., data is to be stored on the storage of the data management system), then the process according to the illustrated embodiment proceeds to step 703 to perform appropriate operations related to the data, monitor the processing time related to the data, and / or calculate the trust level related to the data. For example, if the activity includes storing data records and related signature records on the storage of the data management system, then the storage of these records is completed and the data is placed under the management of the data management system. Additionally, or rather, if the activity is regarding updating data (e.g., data records including updated data are being stored), then the operation of merging the data may be performed and the processing time for doing so may be monitored. Similarly, if the activity is regarding rating data (e.g., data records including rating data are being stored), then the operation of generating or updating the trust level may be performed.

[0094] In step 704 of the illustrated example, it is determined whether the monitored processing time exceeds a threshold time. For example, if the activity includes monitoring the processing time in step 703 (e.g., the activity is related to updating data and the processing time for merging the updated data is monitored), then the processing time is compared with the threshold time (e.g., Ttime). According to the example of process 700, if it is determined that the monitored processing time does not exceed the threshold time, the operation regarding the activity instance is completed and the process returns to step 702 to process subsequent activities. However, if it is determined that the monitored processing time exceeds the threshold time, the process according to the illustrated embodiment proceeds to step 705 to capture a snapshot of the data (e.g., a snapshot of the updated data for the merged data), and the process returns to step 702 to process subsequent activities.

[0095] After describing the branch of process 700 corresponding to determining in step 702 that the activity does not include a query, the branch of the illustrated embodiment of process 700 corresponding to determining in step 702 that the activity does include a query will now be described. If it is determined in step 702 that the activity does include a data query (e.g., data stored on the storage of a data management system is being accessed or otherwise queried), the process according to the illustrated embodiment proceeds to step 706 to determine whether a snapshot of the data regarding the query (e.g., an updated data snapshot) is available. If it is determined in step 706 that a snapshot of the data regarding the query is available, the process according to the illustrated embodiment proceeds to step 707, where the snapshot (e.g., the updated data snapshot) and the confidence level regarding the data are returned (e.g., transmitted from a server system to a client system). However, if it is determined that a snapshot of the data regarding the query is not available, the process according to the illustrated embodiment proceeds to step 708, where the data (e.g., including any updated data being merged therein) and the confidence level regarding the data are returned (e.g., transmitted from a server system to a client system).

[0096] According to some embodiments, the operations performed at step 708 may include: monitoring the processing time (e.g., as described regarding step 703); determining whether the processing time exceeds a threshold time (e.g., as described regarding step 704); and if the processing time exceeds the threshold time (e.g., as described regarding step 705), capturing a snapshot. Thus, accessing or otherwise querying data that results in the processing time exceeding the threshold time may trigger the capture of a snapshot (e.g., an updated data snapshot) for improving the query response regarding subsequent queries. This monitoring of the processing time at step 708, determining whether the processing time exceeds the threshold time, and capturing a snapshot when the processing time exceeds the threshold time may be complementary to or an alternative to the corresponding operations performed at steps 703, 704, and 705 of the embodiments of the present invention.

[0097] According to the example of process 700, after returning data and the confidence level about the data (e.g., the snapshot and confidence level returned at step 707 or the data and confidence level returned at step 708), the process according to the illustrated embodiment proceeds to step 702 to process subsequent activities. Thereafter, the server system may monitor subsequent activities of one or more client systems.

[0098] Although various aspects of the invention and their advantages have been described in detail, it should be understood that various changes, substitutions, and alterations can be made herein without departing from the spirit and scope of the invention as defined by the appended claims. In addition, the scope of this application is not intended to be limited to the specific embodiments of the processes, machines, manufactures, compositions of matter, devices, methods, and steps described in the specification. As will be readily understood by those of ordinary skill in the art from the disclosure of the present invention, processes, machines, manufactures, compositions of matter, devices, methods, or steps currently existing or later developed that perform substantially the same function or achieve substantially the same result as the corresponding embodiments described herein can be utilized in accordance with the present invention. Accordingly, the appended claims are intended to include such processes, machines, manufactures, compositions of matter, devices, methods, or steps within their scope.

[0099] In addition, the scope of this application is not intended to be limited to the specific embodiments of the processes, machines, manufactures, compositions of matter, devices, methods, and steps described in the specification.

Claims

1. A method for auditable data management, comprising: storing, by a data management platform of a data management system, a plurality of data records on an immutable storage of the data management system, wherein the plurality of data records include a new type of data record composed of original data stored by the data management system, an updated type of data record composed of original data or other updated data stored by the data management system, and a rating type of data record composed of rating data related to the original data or updated data stored by the data management system or a user of the data management system; storing, by the data management platform, a plurality of signature records on the immutable storage of the data management system, wherein each signature record in the plurality of signature records is associated with a corresponding data record in the plurality of data records, and wherein the signature record includes a digital signature related to the corresponding data record, and the digital signature associates the data record with a specific user entity using the data management system; generating, by the data management platform, a trust level for the original data of the new type of data record and the updated data of the updated type of data record in the plurality of data records according to the rating data of the rating type of data record in the plurality of data records; receiving, by the data management platform, a query for requested data managed by the data management system from a user device; obtaining, by the data management platform, the requested data from one or more data records in the plurality of data records from the immutable storage; and returning, by the data management platform, the requested data to the user device and providing one or more corresponding trust levels related to the one or more data records from which the requested data is obtained.

2. The method according to claim 1, wherein The rating type of data record includes a reference data identification field, and the reference data identification field includes information identifying a specific data record of the new type or updated type and provides rating information for at least one of the user of the data record or the data in the data record.

3. The method according to claim 1, wherein, The updated type of data record includes a reference data identification field, and the reference data identification field includes information identifying a specific data record of the new type or updated type and provides updated data for the data of the data record.

4. The method according to claim 1, wherein The updated data includes difference data regarding the difference between two sets of data.

5. The method according to claim 4, further comprising: monitoring, by the data management system, the processing time of the merged data of the updated data; and if the processing time exceeds a threshold time, capturing, by the data management system, a snapshot of the merged data.

6. The method according to claim 5, wherein, Returning the requested data includes returning data of a snapshot of the requested data, and the data of the snapshot includes updated data of a corresponding snapshot of the captured merged data.

7. The method according to claim 1, wherein, Generating the trust level includes performing matrix operations on the rating data of the rating type of data record in the plurality of data records.

8. The method according to claim 7, wherein, The matrix used in the matrix operations includes a user rating matrix and a data rating matrix, and wherein the trust level includes a multi-dimensional based trust level from a combination of user rating and data rating.

9. A method for auditable data management, comprising: A data record is provided from a user device of a data management system to a data management platform of the data management system for storage on an immutable storage of the data management system, wherein a plurality of data records are managed by the data management system, and wherein the plurality of data records include: a data record of a new type consisting of original data stored by the data management system, an updated data record of an updated type consisting of original data or other updated data stored by the data management system, and a rating data record of a rating type consisting of rating data related to the original data or the updated data stored by the data management system or a user of the data management system, wherein the data record provided for storage by the user device is a data record of a new type, an updated type, or a rating type corresponding to the plurality of data records managed by the data management system; A signature record is provided from the user device to the data management platform for storage on the immutable storage of the data management system, there are a plurality of signature records, and each signature record is associated with a corresponding data record among the plurality of data records, wherein the signature record includes a digital signature of a specific user entity associated with the user device; The user device queries the requested data managed by the data management system from the data management platform; and The user device receives the requested data and one or more trust levels from the data management platform, wherein the one or more trust levels are generated according to the rating data of the rating type data records among the plurality of data records for one or more data records of the acquired requested data.

10. The method according to claim 9, further comprising: The user device generates a private key - public key pair; The user device generates a digital signature based on the data record using the private key in the private key - public key pair; And The user device includes the digital signature in a data structure of the signature record, wherein the signature record includes an identification field and a signature field, the identification field includes unique identification information of the signature record, and the signature field includes the digital signature.

11. The method according to claim 9, wherein, The rating type data record includes a reference data identification field, and the reference data identification field includes information identifying a specific data record of a new type or an updated type, and provides rating information for at least one of the user of the data record or the data in the data record.

12. The method according to claim 9, wherein The updated type data record includes a reference data identification field, and the reference data identification field includes information identifying a specific data record of a new type or an updated type, and provides updated data for the data of the data record.

13. The method according to claim 9, wherein the updated data includes difference data regarding the difference between two sets of data.

14. The method according to claim 13, wherein the requested data received by the user device includes data of a snapshot of the requested data, and the data of the snapshot includes updated data of a corresponding snapshot of the merged data that has been captured.

15. The method according to claim 14, wherein, Capture the snapshot in response to the processing time of the merged data of the updated data exceeding a threshold time.

16. The method according to claim 9, wherein, The confidence level is generated by performing matrix operations on the rating data of the rating type data records among the multiple data records, wherein the matrix used in the matrix operations includes a user rating matrix and a data rating matrix, and the confidence level includes a multi-dimensional based confidence level from a combination of user ratings and data ratings.

17. The method according to claim 9, further comprising: Adjust the time taken for the user equipment to receive the requested data from the data management system according to one or more corresponding confidence levels.

18. A system for auditable data management, comprising: An immutable store that stores multiple data records managed by a data management system and stores multiple signature records, wherein each signature record is associated with a corresponding data record among the multiple data records, and the multiple data records include: new type data records composed of original data stored by the data management system, updated type data records composed of original data or other updated data stored by the data management system, and rating type data records composed of rating data related to the original data or updated data stored by the data management system or a user of the data management system, wherein the signature records include digital signatures related to the corresponding data records, and the digital signatures associate the data records with a specific user entity using the data management system; and A data management platform of the data management system that communicates with one or more user devices of the data management system, wherein the data management platform is configured to generate a confidence level for the original data of the new type data records and the updated data of the updated type data records among the multiple data records according to the rating data of the rating type data records among the multiple data records, to receive a query from a user device among the one or more user devices for the requested data managed by the data management system, to obtain the requested data from one or more data records among the multiple data records, and to return the requested data to the user device, and to provide one or more corresponding confidence levels related to the one or more data records from which the requested data is obtained.

19. The system according to claim 18, wherein, The updated data includes difference data regarding the difference between two sets of data, wherein the data management platform is configured to monitor the processing time of the merged data regarding the updated data, and if the processing time exceeds a threshold time, capture a snapshot of the merged data.

20. The system according to claim 18, wherein, The data management platform is configured to generate the confidence level by performing matrix operations on the rating data of the rating type data records among the multiple data records, and the matrix used in the matrix operations includes a user rating matrix and a data rating matrix, wherein the confidence level includes a multi-dimensional based confidence level from a combination of user ratings and data ratings.

Citation Information

Patent Citations

  • Multi-person collaborative operation method for geographic information data production and updating

    CN113568921A

  • Shared document editing in the blockchain

    US10552381B2

  • TOKENIZED REITS block chain asset management system

    CN113592657A

  • Blockchain-supported device location verification with digital signatures

    US20170041148A1