An Industrial Internet-based Data Security and Privacy Fusion Method and System

Through differential privacy processing, blockchain technology and homomorphic encryption technology, a security framework and data fusion model are built, which solves the problem of poor data security in the industrial Internet and realizes the secure sharing and privacy protection of data.

CN119210854BActive Publication Date: 2025-07-11BEIJING UNIV OF POSTS & TELECOMM
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411349522.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-26
Publication Date
2025-07-11
Estimated Expiration
2044-09-26

AI Technical Summary

Technical Problem

In the industrial Internet environment, the existing data is poor in security, and it is difficult to achieve effective utilization and data sharing across organizations while ensuring data security. Especially when the data volume is large, widely distributed and strong real-time, traditional data protection measures have limitations.

Method used

Differential privacy processing technology is used to protect data privacy, build a security framework and define security levels, create a decentralized identity authentication system through blockchain technology, dynamically adjust access control permissions, combine homomorphic encryption technology to ensure data transmission security, and generate a data fusion model to include the data contribution degree and sensitive information protection strategies of all participating entities.

Benefits of technology

Improve data security and privacy protection capabilities, ensure the security and privacy of data during transmission and processing, and realize the effective utilization of data and secure sharing across organizations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119210854B_ABST
    Figure CN119210854B_ABST
Patent Text Reader

Abstract

This application provides a data security and privacy fusion method and system based on the industrial Internet. Among them, a security framework is constructed for data streams based on differential privacy processing, and the security levels of the data within the security framework are defined; a decentralized identity authentication system is created for each participating entity through blockchain technology, and the access control permissions of the identity authentication system are dynamically adjusted according to the security levels; according to the access control permissions and the security levels of the data streams, data encryption and decryption rules are established and applied to the data streams; the encrypted data streams are transmitted to the cloud data center, and homomorphic encryption technology is used to ensure the security of the data during the transmission process; using the results of homomorphic encryption technology, a data fusion model is generated in the cloud data center; according to the data fusion model, the final data security and privacy fusion result is generated. The technical solution provided by this application can improve data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the technical field of data protection, and in particular, to a data security and privacy fusion method and system based on the industrial Internet. Background Art

[0002] With the rapid development of the industrial Internet, manufacturing enterprises are facing the management and analysis requirements of massive device data. This data covers key parameters in the production process, equipment operation status and other important information, which is of great significance for improving production efficiency and optimizing resource allocation. However, with the growth of the data volume and the expansion of the distribution range, how to effectively utilize the data on the premise of ensuring data security has become an urgent problem to be solved. Cross-organization data sharing has become increasingly frequent, which not only requires effective protection of data during transmission and storage, but also needs to ensure that privacy is not violated during the data processing process. Therefore, it is particularly important to develop a data processing method that can both protect data security and maintain user privacy.

[0003] Currently, some common data protection measures in the industry mainly include data encryption technology, access control mechanism, and anonymization processing; however, these traditional methods have certain limitations when facing the characteristics of large data volume, wide distribution, and strong real-time nature in the industrial Internet environment. Summary of the Invention

[0004] The embodiments of the present application provide a data security and privacy fusion method and system based on the industrial Internet to solve the problem of poor data security in the prior art.

[0005] In a first aspect, the embodiments of the present application provide a data security and privacy fusion method based on the industrial Internet, including:

[0006] Collect the data stream generated by industrial devices and perform differential privacy processing;

[0007] Build a security framework based on the data stream processed by differential privacy and define the security levels of the data within the security framework;

[0008] In the security framework, create a decentralized identity authentication system for each participating entity through blockchain technology, and dynamically adjust the access control permissions of the identity authentication system according to the security level;

[0009] Establish data encryption and decryption rules according to the access control permissions and the security level of the data stream, and apply the data encryption and decryption rules to the data stream;

[0010] Transmit the encrypted data stream to the cloud data center, and use homomorphic encryption technology to ensure the security of the data during the transmission process;

[0011] Using the result of the homomorphic encryption technology, a data fusion model is generated in the cloud data center, and the data fusion model includes the data contribution degrees of all participating entities and the sensitive information protection strategy;

[0012] According to the data fusion model, a final data security and privacy fusion result is generated, and the result at least includes the data contribution degree, the sensitive information protection strategy, and the data usage permissions of each participating entity.

[0013] Optionally, a decentralized identity authentication system is created for each participating entity through blockchain technology, specifically including:

[0014] Register the identity information of each participating entity in the blockchain network and record it in an immutable block;

[0015] According to the preset smart contract, when a participating entity initiates a data request, the identity authentication process is automatically executed;

[0016] If the identity authentication is successful, the participating entity is allowed to access the corresponding data resources, otherwise the access request is rejected.

[0017] Optionally, according to the access control permissions and the security levels of data streams, data encryption and decryption rules are established, specifically including:

[0018] For data streams with different security levels, different encryption algorithms are used for encryption processing, and a multi-layer encryption mechanism is introduced to enhance security;

[0019] Set an encryption intensity threshold, and when the access control permission level is higher than the preset threshold, a higher-level encryption algorithm is enabled;

[0020] Combine a quantum random number generator to provide an unpredictable encryption key for each encryption operation.

[0021] Optionally, the homomorphic encryption technology is used to ensure the security during data transmission, specifically including:

[0022] Use a fully homomorphic encryption scheme to encrypt the data so that the data can be calculated without decryption;

[0023] Decrypt the data after calculation at the receiving end to restore the original data value;

[0024] Adopt zero-knowledge proof technology to verify the correctness of the encrypted data without revealing any information about the actual content of the data.

[0025] Optionally, the data fusion model includes the data contribution degrees of all participating entities and the sensitive information protection strategy, specifically including:

[0026] Define a method for calculating data contribution to ensure that the contributions of each participant can be quantitatively evaluated;

[0027] Design a sensitive information protection strategy to clarify the protection strategies for different types of information in different situations;

[0028] Integrate the above data contribution and sensitive information protection strategies into the data fusion model to form a complete data security and privacy framework.

[0029] Optionally, the combined quantum random number generator provides an unpredictable encryption key for each encryption operation, and the specific calculation formula is:

[0030]

[0031] Among them, K i represents the encryption key of the i-th device; H() is a secure hash function; K master is the master key; ∥ represents the concatenation operator; D i represents the identification information of the i-th device; T i represents the timestamp; R i represents the random salt value; Π represents the product; p k represents the k-th prime number; ek represents the exponent of the prime number p k ; m represents the number of prime numbers used.

[0032] Optionally, the determination of the encryption strength threshold has the following specific calculation formula:

[0033]

[0034] Among them, E s represents the encryption strength; m represents the data quality; v represents the data stream speed; w j represents the j-th weight factor; T k represents the key valid range; T m represents the preset threshold; f(x) is a monotonically increasing function; l is the number of weight factors; g(θ, φ) represents a correction term related to the geographical angle θ and the azimuth angle φ.

[0035] Optionally, the quantitative evaluation of the data contribution has the following specific calculation formula:

[0036]

[0037] Among them, C j represents the data contribution of the j-th participating entity; w i represents the weight of the i-th contribution index; d ijDenote the score of the j-th participating entity on the i-th contribution metric; n is the number of contribution metrics; μ and σ represent the mean and standard deviation of the scores respectively; R represents the number of additional evaluation dimensions; h r (d ij ) represents the non-linear transformation function on the r-th dimension for the score d ij ; Z represents the normalization constant.

[0038] In a second aspect, an industrial Internet-based data security and privacy fusion system is provided in an embodiment of the present application, including:

[0039] A collection module, configured to collect data streams generated by industrial devices and perform differential privacy processing;

[0040] A construction module, configured to construct a security framework based on the data streams processed by differential privacy and define the security levels of the data within the security framework;

[0041] An adjustment module, configured to create a decentralized identity authentication system for each participating entity through blockchain technology in the security framework and dynamically adjust the access control permissions of the identity authentication system according to the security levels;

[0042] An encryption module, configured to establish data encryption and decryption rules according to the access control permissions and the security levels of the data streams, and apply the data encryption and decryption rules to the data streams;

[0043] A transmission module, configured to transmit the encrypted data streams to a cloud data center, and adopt homomorphic encryption technology to ensure the security during the data transmission process;

[0044] A generation module, configured to generate a data fusion model in the cloud data center by using the results of the homomorphic encryption technology, where the data fusion model includes the data contribution degrees of all participating entities and sensitive information protection strategies;

[0045] An output module, configured to generate a final data security and privacy fusion result according to the data fusion model, where the result at least includes data contribution degrees, sensitive information protection strategies, and data usage permissions of each participating entity.

[0046] In a third aspect, an embodiment of the present application provides a computing device, including a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a data security and privacy fusion method based on industrial Internet as described in any item of the first aspect.

[0047] In the embodiments of the present application, data streams generated by industrial devices are collected and differentially private processing is performed; a security framework is constructed based on the differentially private processed data streams, and the security levels of the data within the security framework are defined; in the security framework, a decentralized identity authentication system is created for each participating entity through blockchain technology, and the access control permissions of the identity authentication system are dynamically adjusted according to the security levels; according to the access control permissions and the security levels of the data streams, data encryption and decryption rules are established and applied to the data streams; the encrypted data streams are transmitted to the cloud data center, and homomorphic encryption technology is used to ensure the security of the data during the transmission process; using the results of the homomorphic encryption technology, a data fusion model is generated in the cloud data center, and the data fusion model includes the data contribution degrees of all participating entities and sensitive information protection strategies; according to the data fusion model, a final data security and privacy fusion result is generated, and the result at least includes data contribution degrees, sensitive information protection strategies, and data usage permissions of each participating entity. The technical solution provided by the present application can improve data security.

[0048] These aspects or other aspects of the present application will be more clearly understood in the following description of the embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application or in the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0050] Figure 1 It is a flowchart of a data security and privacy fusion method based on industrial Internet provided by an embodiment of the present application;

[0051] Figure 2 It is a schematic structural diagram of a data security and privacy fusion system based on industrial Internet provided by an embodiment of the present application;

[0052] Figure 3 It is a schematic structural diagram of a computing device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0053] In order to enable those skilled in the art to better understand the solution of the present application, the following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application.

[0054] In some of the processes described in the specification, claims, and the above-mentioned drawings of this application, a number of operations appear in a specific order. However, it should be clearly understood that these operations may not be executed in the order in which they appear herein or may be executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish different operations, and the serial numbers themselves do not represent any order of execution. Additionally, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions such as "first", "second", etc. in this article are used to distinguish different messages, devices, modules, etc., do not represent a sequence, and do not limit that "first" and "second" are of different types.

[0055] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative efforts belong to the scope of protection of the present application.

[0056] Figure 1 The flowchart of a data security and privacy integration method based on the industrial Internet provided by the embodiments of the present application is as Figure 1 shown, and the method includes:

[0057] 101. Collect the data stream generated by industrial devices and perform differential privacy processing;

[0058] In this step, industrial devices refer to various hardware facilities used in industrial production, such as machinery, instruments, and automation control systems, such as sensors, robots, and numerically controlled machine tools.

[0059] Data stream: A continuous data sequence generated by industrial devices during operation, usually including various types of data such as device status, operation parameters, and environmental monitoring.

[0060] Differential privacy processing: A data privacy protection technology that adds random noise to the original data, making it difficult to accurately identify the data of an individual, thereby protecting data privacy. The core of differential privacy is that regardless of whether the data set contains the data of an individual, the probability distribution of the query results is almost the same, so as to protect individual privacy.

[0061] In the embodiments of the present application, it is assumed that devices on a factory production line (such as sensors, machine vision systems, etc.) generate a large amount of real-time data, and this data needs to be collected and used for analysis to optimize the production process. First, the data acquisition module deployed on the devices collects the data streams from each device.

[0062] Next, to protect data privacy, differential privacy processing is performed on the collected data stream. Specifically, the Laplace Mechanism can be used to blur the true values of individual data by adding random noise to the data. For example, suppose it is necessary to count the product qualification rate on a certain production line, and the original qualification rate is 95%. To introduce differential privacy, a random noise obeying the Laplace distribution can be added to this data:

[0063] Noise~Laplace(0,b)

[0064] where b is a parameter of the privacy budget, which determines the magnitude of the added noise. Suppose b = 10, then the possible noise values will be distributed between -10 and +10. Add the noise to the original qualification rate:

[0065] NoisyRate=95+Noise

[0066] Suppose the added noise is 3, then the finally reported qualification rate is 98%. In this way, even if the data is accessed by a third party, it is difficult to infer the exact original data value from the data due to the added noise, thus protecting data privacy.

[0067] The main purpose of this step is to protect the privacy information in the data stream collected from industrial devices through differential privacy processing technology. The design principle is to mask the true data value by introducing random noise, so that even the exact data cannot be directly inferred from the processed data, thus achieving the effect of protecting privacy.

[0068] Compared with directly transmitting the unprocessed original data in the traditional scheme, this step enhances the security of the data through differential privacy processing, making it difficult to expose sensitive information during data sharing and analysis. This processing method is especially applicable to the situation where data needs to be shared across organizations in the industrial Internet environment, and can maximize the value of data while protecting privacy.

[0069] Suppose it is necessary to count the product qualification rate on a certain production line, and the original qualification rate is 95%. We choose the privacy budget parameter b = 10, then the added noise obeys the Laplace distribution Noise~Laplace(0, 10).

[0070] Suppose the generated noise Noise = 3, then:

[0071] NoisyRate=95+3=98

[0072] Therefore, the finally reported qualification rate is 98%, rather than the true 95%, which makes it difficult to leak the true information during data transmission and use.

[0073] 102. Construct a security framework based on the data stream processed by differential privacy, and define the security levels of the data within the security framework;

[0074] In this step, differential privacy processing: A privacy protection technique that adds random noise to data to prevent sensitive information from being identified.

[0075] Security framework: A set of security protection systems established around the data processing process.

[0076] Security level: According to factors such as the importance and sensitivity of the data, the data is divided into different security levels.

[0077] Access control: Set who can access which data and under what conditions.

[0078] Encryption policy: Specify the encryption measures that should be taken when the data is stored and transmitted.

[0079] Audit mechanism: Record the data access and usage situations for tracking and auditing.

[0080] In an embodiment of the present application, assume that a factory has collected a large amount of production data through various sensors on its production line and has performed differential privacy processing on this data. The next step is to construct a security framework based on these processed data streams and define the security levels of the data.

[0081] Constructing the security framework:

[0082] First, it is necessary to define the basic components of the security framework, including but not limited to:

[0083] Data classification: Divide the data into different categories according to the data type and usage.

[0084] Access control: Set who can access which data and under what conditions.

[0085] Encryption policy: Specify the encryption measures that should be taken when the data is stored and transmitted.

[0086] Audit mechanism: Record the data access and usage situations for tracking and auditing.

[0087] Defining the security levels:

[0088] Next, it is necessary to define security levels according to the importance and sensitivity of the data. For example, the data can be divided into three levels: public level, internal level, and confidential level:

[0089] Public level: Data that is publicly available and can be accessed by anyone.

[0090] Internal level: Data that is only accessible to company internal employees.

[0091] Confidential level: Extremely sensitive data that can only be accessed by specific authorized personnel.

[0092] Suppose the production data of a certain factory includes the following categories:

[0093] Temperature data: Used to monitor the working temperature of production equipment, which belongs to internal-level data.

[0094] Output data: Records the daily output quantity of the production line, which belongs to internal-level data.

[0095] Fault alarm data: Records the fault information of production equipment, which belongs to confidential-level data.

[0096] The process of building a security framework is as follows:

[0097] Data classification: Classify temperature data and output data as internal-level data, and classify fault alarm data as confidential-level data.

[0098] Access control: Specify that all internal-level data can only be accessed by factory internal personnel, and confidential-level data can only be accessed by designated maintenance engineers or management personnel.

[0099] Encryption strategy: All internal-level data is stored and transmitted using the AES-256 encryption algorithm, and confidential-level data is stored and transmitted using a higher-level RSA-4096 encryption algorithm.

[0100] Audit mechanism: Record every data access behavior, especially the access records of confidential-level data, and conduct regular reviews to ensure that there are no unauthorized access behaviors.

[0101] The main purpose of this step is to further strengthen data security management by building a security framework and defining security levels on the basis of data collection and processing. The design principle is to classify and grade the data and adopt differential protection measures to ensure better protection of important data.

[0102] 103. In the security framework, create a decentralized identity authentication system for each participating entity through blockchain technology, and dynamically adjust the access control permissions of the identity authentication system according to the security level;

[0103] Optionally, creating a decentralized identity authentication system for each participating entity in step 103 through blockchain technology specifically includes: registering the identity information of each participating entity in the blockchain network and recording it in an immutable block; according to a preset smart contract, automatically execute the identity authentication process when a participating entity initiates a data request; if the identity authentication is successful, allow the participating entity to access the corresponding data resources, otherwise reject the access request.

[0104] In this step, Blockchain Technology: A decentralized database technology that records transaction information through a distributed ledger and has the characteristic of being immutable. Blockchain technology ensures data consistency through a consensus mechanism and guarantees data security through encryption technology.

[0105] Decentralized Identity Verification System: An identity management system created using blockchain technology that does not rely on a central agency but rather jointly maintains and verifies identity information through multiple nodes in the blockchain network.

[0106] Smart Contract: A program running on the blockchain used to automatically execute, control, or record transactions of digital assets. A smart contract can automatically execute the contract terms according to preset conditions without manual intervention.

[0107] Identity Information: Information used to identify a participating entity, such as a username, public key, biometric data, etc.

[0108] Block: A data structure unit in the blockchain that stores transaction information. Each block contains several transaction records and links to the hash value of the previous block to form a chain structure.

[0109] Authentication: The process of confirming a user's identity to ensure that the user is who they claim to be.

[0110] Access Control: The process of determining whether a user can access a specific resource based on their permissions.

[0111] In an embodiment of this application, in an industrial Internet application scenario, assume that there are multiple factories that need to share production data to optimize supply chain management. To ensure the secure sharing of data, this application proposes to create a decentralized identity authentication system for each participating entity through blockchain technology and dynamically adjust the access control permissions of the identity authentication system according to the security level.

[0112] Registered identity information:

[0113] First, each participating entity (such as Factory A, B, C) needs to register its identity information in the blockchain network. This information can include the factory's name, address, contact person, public key, etc., and is recorded in the blocks of the blockchain. For example:

[0114] Block #1: Factory A: Name = Factory A, Address = Address A, Contact Person = Contact A, Public Key = PublicKey A

[0115] Block #2: Factory B: Name = Factory B, Address = Address B, Contact Person = Contact B, Public Key = PublicKey B

[0116] Block #3: Factory C: Name = Factory C, Address = Address C, Contact Person = Contact C, Public Key = PublicKey C

[0117] Writing smart contracts:

[0118] Next, write smart contracts to automatically execute the authentication process. The verification logic when a participating entity initiates a data request is defined in the smart contract. The specific logic is described as follows:

[0119] Check if the address of the requester exists in the whitelist: The smart contract checks if the address of the requester is in the whitelist.

[0120] Check the request type: Different levels of permission checks are performed according to the request type (public, internal, confidential).

[0121] If the request type is "public", then everyone is allowed to access.

[0122] If the request type is "internal", then further check if the address of the requester is in the internal access list.

[0123] If the request type is "confidential", then check if the address of the requester is in the confidential access list.

[0124] Authentication process:

[0125] When Factory A wants to access the internal data of Factory B, it initiates a request. The smart contract automatically executes the authentication logic:

[0126] The smart contract checks if the address of Factory A is in the whitelist.

[0127] If the address of Factory A is in the whitelist, further check if its address is in the internal access list.

[0128] If the address of Factory A is also in the internal access list, its access to the internal data of Factory B is allowed; otherwise, the access request is rejected.

[0129] The main purpose of this step is to create a decentralized identity authentication system for participating entities through blockchain technology and dynamically adjust access control permissions according to security levels. The design principle is to utilize the immutability of the blockchain and the automatic execution ability of smart contracts to ensure the secure storage and automatic verification of identity information, thereby improving the security and reliability of data access control.

[0130] 104. Establish data encryption and decryption rules according to the access control permissions and the security levels of data flows, and apply the data encryption and decryption rules to the data flows;

[0131] Optionally, the establishment of data encryption and decryption rules according to the access control permissions and the security levels of data flows in step 104 specifically includes: for data flows with different security levels, different encryption algorithms are used for encryption processing, and a multi-layer encryption mechanism is introduced to enhance security; an encryption strength threshold is set, and when the access control permission level is higher than the preset threshold, a higher-level encryption algorithm is enabled; a quantum random number generator is combined to provide an unpredictable encryption key for each encryption operation.

[0132] Optionally, the combination of the quantum random number generator to provide an unpredictable encryption key for each encryption operation in step 104 has the following specific calculation formula:

[0133]

[0134] where K i represents the encryption key of the i-th device; H() is a secure hash function; K master is the master key; ∥ represents the concatenation operator; D i represents the identification information of the i-th device; T i represents the timestamp; R i represents the random salt value; Π represents the product; p k represents the k-th prime number; ek represents the exponent of the prime number p k and m represents the number of prime numbers used.

[0135] Optionally, the determination of the encryption strength threshold in step 104 has the following specific calculation formula:

[0136]

[0137] where E s represents the encryption strength; m represents the data quality; v represents the data flow rate; w jrepresents the j-th weight factor; T k represents the key valid range; T m represents a preset threshold; f(x) is a monotonically increasing function; l is the number of weight factors; g(θ, φ) represents a correction term related to the geographical angle θ and the azimuth angle φ.

[0138] In this step:

[0139] Data Stream: A continuous data sequence generated by industrial equipment during operation, usually containing various types of data such as equipment status, operating parameters, and environmental monitoring.

[0140] Encryption Algorithm: An algorithm used to convert plaintext data into ciphertext data to protect the security of the data.

[0141] Multi-layer Encryption Mechanism: Using multiple encryption algorithms or encrypting multiple times to increase the security of the data.

[0142] Encryption Strength Threshold: An encryption strength standard determined according to parameters such as data quality and data stream speed, used to judge when to use a higher-strength encryption algorithm.

[0143] Quantum Random Number Generator (QRNG): A device that generates truly random numbers using the principles of quantum mechanics, used to improve the unpredictability of encryption keys.

[0144] Secure Hash Function: A function used to generate a fixed-length digest, often used to verify data integrity.

[0145] Master Key: The basic key used to generate other keys.

[0146] ID Information: Information used to uniquely identify a device, such as a device ID.

[0147] In the embodiments of this application, it is assumed that a factory needs to encrypt the device data on its production line to protect the security of the data. The following is a specific embodiment:

[0148] Determine the security level of the data stream:

[0149] Suppose the factory divides the data stream into three security levels: Public, Internal, and Confidential.

[0150] Use different encryption algorithms for encryption processing

[0151] Public-level data stream: Encrypted using the symmetric encryption algorithm AES-128.

[0152] Internal-level data stream: Encrypted using the symmetric encryption algorithm AES-256.

[0153] Confidential-level data stream: Encrypted using the asymmetric encryption algorithm RSA-2048 and combined with the symmetric encryption algorithm AES-256 for double encryption.

[0154] Introduce a multi-layer encryption mechanism:

[0155] For the confidential-level data stream, in addition to using RSA-2048 for asymmetric encryption, AES-256 is also used for symmetric encryption to increase data security.

[0156] Set the encryption strength threshold:

[0157] Suppose the factory sets the encryption strength threshold according to data quality and data stream speed. The specific calculation formula is:

[0158]

[0159] Where E s represents the encryption strength; m represents the data quality; v represents the data stream speed; w j represents the jth weight factor; T k represents the key valid range; T m represents the preset threshold; f(x) is a monotonically increasing function; l is the number of weight factors; g(θ, φ) represents a correction term related to the geographical angle θ and the azimuth angle φ.

[0160] Calculation example:

[0161]

[0162] E s = 25000 + 5.5 + 5 = 25010.

[0163] When E s is greater than the preset threshold, enable a higher-level encryption algorithm.

[0164] Combine a quantum random number generator to generate encryption keys:

[0165] Use a quantum random number generator to provide an unpredictable encryption key for each encryption operation. The specific calculation formula is as follows:

[0166]

[0167] where E s represents the encryption strength; m represents the data quality; v represents the data stream speed; w j represents the jth weight factor; T k represents the key valid range; T m represents the preset threshold; f(x) is a monotonically increasing function; l is the number of weight factors; g(θ, φ) represents a correction term related to the geographical angle θ and the azimuth angle φ.

[0168] Calculation example:

[0169] K i

[0170] = H("MasterKey123" || "DeviceID001" || "202409160042" || "SaltValue456") + 2 1 ·3 2 ·5 3

[0171] Assume the output of the hash function H(·) is "abcdefg...".

[0172] K i = "abcdefg..." + 2·9·125 = "abcdefg..." + 2250

[0173] The main purpose of this step is to establish data encryption and decryption rules according to the security level and access control permissions of the data stream, and combine a quantum random number generator to generate an unpredictable encryption key to enhance the security of the data. The design principle is to ensure the security of the data at different security levels through a multi-layer encryption mechanism and dynamic adjustment of the encryption strength.

[0174] 105. Transmit the encrypted data stream to the cloud data center, and use homomorphic encryption technology to ensure the security of the data during transmission;

[0175] Optionally, the use of homomorphic encryption technology to ensure the security of the data during transmission in step 105 specifically includes: using a fully homomorphic encryption scheme to encrypt the data so that the data can be calculated without decryption; decrypting the calculated data at the receiving end to restore the original data value; using zero-knowledge proof technology to verify the correctness of the encrypted data without revealing any information about the actual content of the data.

[0176] In this step, homomorphic encryption: a cryptographic technique that allows computations to be performed directly on encrypted data without having to decrypt the data first. After the computation is completed, the correct result of the computation can be obtained by decrypting. Fully Homomorphic Encryption (FHE) allows arbitrary numbers of addition and multiplication operations on encrypted data.

[0177] Fully Homomorphic Encryption Scheme: A homomorphic encryption scheme that supports arbitrary numbers of addition and multiplication operations on encrypted data, enabling complex computations on data without decryption.

[0178] Zero-Knowledge Proof: A cryptographic protocol that allows one party (the prover) to prove the truth of a statement to another party (the verifier) without revealing any information about the actual content of the statement. This means that the verifier can be convinced that the prover's statement is correct without knowing the specific content of the statement.

[0179] Data Stream: A continuous sequence of data generated by industrial devices during operation, usually containing various types of data such as device status, operating parameters, and environmental monitoring.

[0180] Cloud Data Center: A data center located on a cloud platform, responsible for storing, processing, and managing large amounts of data.

[0181] In the embodiments of this application, assume that a factory needs to encrypt the device data on its production line and transmit it to the cloud data center for further processing. To ensure the security during data transmission, a fully homomorphic encryption scheme is used to encrypt the data, and zero-knowledge proof technology is used to verify the correctness of the encrypted data.

[0182] Data Encryption:

[0183] Use a fully homomorphic encryption scheme to encrypt the data. Assume that the factory selects a mature fully homomorphic encryption algorithm (such as Gentry's FHE scheme) to encrypt the device data on the production line.

[0184] For example, assume that the factory needs to transmit a set of temperature data, and the encrypted data can be represented as:

[0185] EncryptedData = Encrypt PK (TemperatureData)

[0186] Among them, Encrypt PK represents the encryption operation using the public key PK, and TemperatureData is the original temperature data.

[0187] Data transmission:

[0188] Transmit the encrypted data stream to the cloud data center. Assume there is a secure transmission channel between the factory and the cloud data center, and the encrypted data can be transmitted to the data center through this channel.

[0189] Data calculation:

[0190] In the cloud data center, the encrypted data can be calculated. Assume the data center needs to calculate the average temperature, and the calculation can be performed without decrypting the data:

[0191] EncryptedAverage = ComputeOnEncryptedData(EncryptedData)

[0192] Among them, ComputeOnEncryptedData represents the operation of calculating on the encrypted data.

[0193] Data decryption:

[0194] At the receiving end (such as the data processing department of the factory), use the private key to decrypt the calculated data and restore the original data value:

[0195] Average = Decrypt Sk (EncryptedAverage)

[0196] Among them, Decrypt SK represents the decryption operation using the private key SK.

[0197] Zero-knowledge proof:

[0198] To verify the correctness of the encrypted data, zero-knowledge proof technology is adopted. Assume the factory needs to verify whether the average temperature calculated by the data center is correct, and it can request the data center to provide a zero-knowledge proof:

[0199] ZKP = GenerateZKP(EncryptedAverage)

[0200] Among them, GenerateZKP represents the operation of generating a zero-knowledge proof.

[0201] After the factory receives the zero-knowledge proof, it can verify the correctness of the calculation result without obtaining any information about the actual content of the data.

[0202] The main purpose of this step is to encrypt data using a fully homomorphic encryption scheme and combine zero - knowledge proof technology to verify the correctness of the encrypted data, ensuring the security of data during transmission and processing. The design principle is to perform calculations on data without decrypting it and use zero - knowledge proof technology to ensure the validity of evidence without revealing any information about the actual content of the data.

[0203] 106. Utilize the result of the homomorphic encryption technology to generate a data fusion model in the cloud data center. The data fusion model includes the data contribution degrees of all participating entities and sensitive information protection strategies.

[0204] Optionally, the data fusion model in step 106 includes the data contribution degrees of all participating entities and sensitive information protection strategies, specifically including: defining a calculation method for data contribution degrees to ensure that the contributions of each participant can be quantitatively evaluated; designing sensitive information protection strategies to clarify the protection strategies for different types of information in different situations; integrating the above - mentioned data contribution degrees and sensitive information protection strategies in the data fusion model to form a complete data security and privacy framework.

[0205] Optionally, for the quantitative evaluation of the data contribution degree in step 106, the specific calculation formula is:

[0206]

[0207] where C j represents the data contribution degree of the j - th participating entity; w i represents the weight of the i - th contribution index; d ij represents the score of the j - th participating entity on the i - th contribution index; n is the number of contribution indices; μ and σ respectively represent the mean and standard deviation of the scores; R represents the number of additional evaluation dimensions; h r (d ij ) represents the non - linear transformation function of the score d ij on the r - th dimension; Z represents the normalization constant.

[0208] In this step, the data contribution degree: A quantitative index that measures the contribution of each participating entity in the data fusion process. By calculating the quality and quantity of the data provided by each participant, the degree of its influence on the overall data fusion result can be evaluated.

[0209] Sensitive Information Protection Policy: Defines the methods and rules for protecting different types of information during the data fusion process. These policies clarify how to handle and protect sensitive information in different situations to ensure data security and privacy.

[0210] Data Fusion Model: Integrates data from different sources into a comprehensive model for better analysis and utilization of this data. The model includes the data contribution degrees of all participating entities and sensitive information protection policies.

[0211] Contribution Metrics: Used to evaluate various dimensions of the contributions of participating entities, such as data quality, data volume, data timeliness, etc.

[0212] Non-linear Transformation Function: Used to transform the contribution scores into a form more suitable for calculation to reflect the influence degrees of the contribution scores in different dimensions.

[0213] Normalization Constant: Used to ensure that the calculation results are within a certain range for facilitating the comparison of the contribution degrees of different participating entities.

[0214] In the embodiments of the present application, it is assumed that a manufacturing enterprise has multiple partners in its supply chain, and these partners need to share production data to optimize production processes and supply chain management. To ensure data security and privacy, the present application proposes to generate a data fusion model in the cloud data center by using the results of homomorphic encryption technology, and includes the data contribution degrees of all participating entities and sensitive information protection policies.

[0215] Define the calculation method of data contribution degree:

[0216] First, the calculation method of data contribution degree needs to be defined. The specific calculation formula is:

[0217]

[0218] Among them, C j represents the data contribution degree of the jth participating entity; w i represents the weight of the ith contribution metric; d ij represents the score of the jth participating entity on the ith contribution metric; n is the number of contribution metrics; μ and σ respectively represent the mean and standard deviation of the scores; R represents the number of additional evaluation dimensions; h r (d ij) represents the non - linear transformation function of the score d in the r - th dimension; Z represents the normalization constant. ij

[0219] Suppose we have three participating entities (Factory A, B, C), and each entity has four contribution indicators (data quality, data volume, data timeliness, data accuracy). Suppose the weights of each contribution indicator are 0.3, 0.3, 0.2, 0.2 respectively, the mean μ of the scores is 50, and the standard deviation σ is 10.

[0220]

[0221] Design sensitive information protection policies:

[0222] Next, it is necessary to design sensitive information protection policies. Suppose Factory A, B, C need to protect the following types of information during the data sharing process: production cost data (high - sensitive); production process data (medium - sensitive); equipment status data (low - sensitive).

[0223] The sensitive information protection policies are as follows: production cost data is only viewable by internal factory personnel; production process data can be viewed by specific authorized personnel; equipment status data can be publicly viewed; integrate data contribution degree and sensitive information protection policies.

[0224] Finally, integrate the above - mentioned data contribution degree and sensitive information protection policies into the data fusion model. The specific steps are as follows:

[0225] Calculate the data contribution degree of each participating entity according to the above formula.

[0226] Integrate the sensitive information protection policies into the data fusion model to ensure that the protection policies are followed during the data fusion process.

[0227] Form a complete data security and privacy framework to ensure that data is both fully utilized and privacy - protected during the sharing and processing process.

[0228] The main purpose of this step is to ensure that the contributions of each participating entity can be quantitatively evaluated and sensitive information is effectively protected during the data fusion process by defining the data contribution degree calculation method and designing sensitive information protection policies. The design principle is to ensure the security and fairness of data during the sharing and processing process by quantitatively evaluating the data contribution degree and clarifying the protection policies.

[0229] 107. Generate the final data security and privacy fusion result according to the data fusion model, and this result includes at least the data contribution degree, sensitive information protection policies, and data usage permissions of each participating entity.

[0230] In this step, the data fusion model: refers to the process of integrating data from different sources with the aim of analyzing data from multiple perspectives and improving the quality of decision-making. Data fusion can occur at multiple levels, from simple data merging to complex multi-source information integration.

[0231] Data contribution degree: Measures the importance and influence of the data provided by each participating party in the entire dataset. This helps to evaluate the contribution of each party to the final result and to make reasonable benefit distribution or rewards accordingly.

[0232] Sensitive information protection strategy: Refers to the methods and measures used to protect the sensitive information of individuals or organizations to prevent data leakage, abuse, or unauthorized access. Common strategies include, but are not limited to, data encryption, anonymization, access control, etc.

[0233] Data usage permissions of each participating entity: Defines which participants can access which data and the operations they can perform on the data (such as read, modify, delete, etc.). Permission management is a key component in ensuring data security.

[0234] In the embodiments of this application, assume that a research project needs to collect patient data from different hospitals for the study of disease patterns, but directly sharing the original data may violate the privacy of patients. The following are the implementation steps:

[0235] Data fusion model design: The researchers developed a data fusion model that can receive anonymized data fragments from different hospitals and synthesize these fragments to study disease patterns without exposing individual information.

[0236] Calculate the data contribution degree: The amount and quality of data provided by each hospital determine its contribution degree. For example, if Hospital A provides a large amount of high-quality data while Hospital B only provides a small amount of data, then Hospital A has a higher contribution degree.

[0237] Formulate a sensitive information protection strategy: All participating hospitals agree to perform de-identification on the data to remove information that can directly or indirectly identify patients. In addition, all data transmissions need to be encrypted and only authorized researchers can access the data.

[0238] Allocate data usage permissions: Based on the contribution degree of each hospital, the research team formulates different data access permissions. For example, researchers from Hospital A can have full access to the research data, while researchers from Hospital B can only view part of the data.

[0239] The main purpose of this step is to ensure the security and privacy of data while protecting the interests of all parties. By quantifying the data contribution, the contribution of each participant can be fairly and reasonably evaluated, and the benefits or rewards can be distributed accordingly. At the same time, formulating sensitive information protection strategies and clear data usage permissions can minimize the risk of data leakage, protect personal privacy, and maintain the trust relationship among all parties.

[0240] The improvement compared with the traditional solution is that the traditional data sharing method usually lacks an effective privacy protection mechanism, which may lead to the leakage of sensitive information. In this embodiment, by using a data fusion model to process data, not only the security of the data is improved, but also a fair and reasonable cooperation model is achieved through the contribution calculation and permission allocation mechanism.

[0241] Figure 2 FIG. provides a schematic structural diagram of a data security and privacy fusion system based on the industrial Internet, as Figure 2 shown, the device includes:

[0242] A collection module 21, configured to collect the data stream generated by industrial devices and perform differential privacy processing;

[0243] A construction module 22, configured to construct a security framework based on the data stream processed by differential privacy and define the security level of the data within the security framework;

[0244] An adjustment module 23, configured to create a decentralized identity authentication system for each participating entity through blockchain technology in the security framework, and dynamically adjust the access control permissions of the identity authentication system according to the security level;

[0245] An encryption module 24, configured to establish data encryption and decryption rules according to the access control permissions and the security level of the data stream, and apply the data encryption and decryption rules to the data stream;

[0246] A transmission module 25, configured to transmit the encrypted data stream to the cloud data center, and use homomorphic encryption technology to ensure the security of the data during the transmission process;

[0247] A generation module 26, configured to generate a data fusion model in the cloud data center by using the result of the homomorphic encryption technology, where the data fusion model includes the data contribution of all participating entities and the sensitive information protection strategy;

[0248] An output module 27, configured to generate a final data security and privacy fusion result according to the data fusion model, where the result at least includes the data contribution, the sensitive information protection strategy, and the data usage permissions of each participating entity.

[0249] Figure 2The described data security and privacy integration system based on the industrial Internet can execute Figure 1 the data security and privacy integration method based on the industrial Internet described in the illustrated embodiment. Its implementation principle and technical effects will not be elaborated further. For the data security and privacy integration system in the above embodiment, the specific ways in which each module and unit perform operations have been described in detail in the embodiment related to this method, and will not be elaborated here.

[0250] In a possible design, Figure 2 the data security and privacy integration system based on the industrial Internet in the illustrated embodiment can be implemented as a computing device, such as Figure 3 shown, this computing device may include a storage component 31 and a processing component 32;

[0251] The storage component 31 stores one or more computer instructions, wherein the one or more computer instructions are called and executed by the processing component 32.

[0252] The processing component 32 is used for: collecting the data stream generated by industrial devices and performing differential privacy processing; constructing a security framework based on the data stream after differential privacy processing and defining the security levels of the data within the security framework; in the security framework, creating a decentralized identity authentication system for each participating entity through blockchain technology and dynamically adjusting the access control permissions of the identity authentication system according to the security levels; establishing data encryption and decryption rules according to the access control permissions and the security levels of the data stream, and applying the data encryption and decryption rules to the data stream; transmitting the encrypted data stream to the cloud data center, and using homomorphic encryption technology to ensure the security of the data during the transmission process; using the result of the homomorphic encryption technology to generate a data fusion model in the cloud data center, the data fusion model includes the data contribution degrees and sensitive information protection strategies of all participating entities; generating a final data security and privacy integration result according to the data fusion model, and this result at least includes the data contribution degrees, sensitive information protection strategies and the data usage permissions of each participating entity.

[0253] Among them, the processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above method. Of course, the processing component can also be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors or other electronic components for executing the above method.

[0254] The storage component 31 is configured to store various types of data to support the operation of the terminal. The storage component can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0255] Of course, the computing device may also necessarily include other components, such as input / output interfaces, display components, communication components, etc.

[0256] The input / output interface provides an interface between the processing component and the peripheral interface module, and the above-mentioned peripheral interface module may be an output device, an input device, etc.

[0257] The communication component is configured to facilitate communication between the computing device and other devices in a wired or wireless manner, etc.

[0258] Among them, the computing device may be a physical device or an elastic computing host provided by a cloud computing platform, etc. At this time, the computing device may refer to a cloud server, and the above-mentioned processing component, storage component, etc. may be basic server resources leased or purchased from a cloud computing platform.

[0259] The embodiment of the present application also provides a computer storage medium storing a computer program, and when the computer program is executed by a computer, it can implement the above-mentioned Figure 1 data security and privacy fusion method based on the industrial Internet shown in the embodiment.

[0260] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments, and will not be described herein again.

[0261] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement without creative labor.

[0262] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the above technical solution, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0263] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of each embodiment of the present application.

Claims

1. A data security and privacy integration method based on the industrial Internet, characterized in that, include: Collect data streams generated by industrial equipment and perform differential privacy processing; Building a security framework based on the data flow processed by the differential privacy, and defining the security level of the data within the security framework; In the security framework, a decentralized identity authentication system is created for each participating entity through blockchain technology, and the access control authority of the identity authentication system is dynamically adjusted according to the security level; Establishing data encryption and decryption rules according to the access control authority and the security level of the data flow, and applying the data encryption and decryption rules to the data flow; The encrypted data stream is transmitted to the cloud data center, and homomorphic encryption technology is used during the transmission process to ensure the security of the data transmission process; Using the result of the homomorphic encryption technology, a data fusion model is generated in the cloud data center, wherein the data fusion model includes data contribution and sensitive information protection strategy of all participating entities; Generate a final data security and privacy fusion result based on the data fusion model, which at least includes data contribution, sensitive information protection strategy and data usage rights of each participating entity; The data encryption and decryption rules are established according to the access control authority and the security level of the data flow, specifically including: Different encryption algorithms are used to encrypt data streams at different security levels, and a multi-layer encryption mechanism is introduced to enhance security. Set the encryption strength threshold. When the access control permission level is higher than the preset threshold, a higher level encryption algorithm is enabled. Combined with a quantum random number generator to provide unpredictable encryption keys for each encryption operation; The determination of the encryption strength threshold is specifically calculated by the following formula: ; Among them, represents the encryption strength; represents the data quality; represents the data flow rate; represents the th weight factor; represents the valid range of the key; represents the preset threshold; is a monotonically increasing function; is the number of weight factors; represents a correction term related to the geographic angle and the azimuth angle.

2. The method according to claim 1, wherein The decentralized identity authentication system is created for each participating entity through blockchain technology, specifically including: Register the identity information of each participating entity in the blockchain network and record it in an unalterable block; According to the pre-set smart contract, when the participating entity initiates a data request, the identity verification process is automatically executed; If the authentication is successful, the participating entity is allowed to access the corresponding data resources, otherwise the access request is denied.

3. The method according to claim 1, characterized in that, The homomorphic encryption technology is used to ensure the security of data transmission, specifically including: Encrypt data using a fully homomorphic encryption scheme so that data can be calculated without being decrypted; Decrypt the calculated data at the receiving end to restore the original data value; Zero-knowledge proof technology is used to verify the correctness of encrypted data without revealing any information about the actual content of the data.

4. The method according to claim 1, characterized in that The data fusion model includes the data contribution of all participating entities and the sensitive information protection strategy, including: Define the data contribution calculation method to ensure that the contribution of each participant can be quantified and evaluated; Design sensitive information protection strategies and clarify the protection strategies for different types of information in different situations; The above data contribution and sensitive information protection strategies are integrated into the data fusion model to form a complete data security and privacy framework.

5. The method according to claim 1, characterized in that The combined quantum random number generator provides an unpredictable encryption key for each encryption operation. The specific calculation formula is: ; Among them, represents the encryption key of the th device; H() is a secure hash function; is the master key; represents the concatenation operator; represents the th device's identification information; represents the timestamp; represents the timestamp; represents the product; represents the th prime number; represents the prime number 's exponent; represents the number of prime numbers used.

6. The method according to claim 4, wherein The quantitative evaluation of the data contribution is calculated as follows: ; Among them, represents the data contribution degree of the th participating entity; represents the weight of the th contribution index; represents the score of the th participating entity on the th contribution index; is the number of contribution indexes; and respectively represent the mean and standard deviation of the scores; represents the number of additional evaluation dimensions; represents the non - linear transformation function of the score on the th dimension; represents the normalization constant.

7. A data security and privacy integration system based on the industrial Internet, characterized in that, include: The collection module is used to collect the data streams generated by industrial equipment and perform differential privacy processing; A building module for building a security framework based on the data stream processed by differential privacy and defining the security levels of the data within the security framework; An adjustment module for creating a decentralized identity authentication system for each participating entity through blockchain technology in the security framework and dynamically adjusting the access control permissions of the identity authentication system according to the security levels; An encryption module for establishing data encryption and decryption rules according to the access control permissions and the security levels of the data stream and applying the data encryption and decryption rules to the data stream; A transmission module for transmitting the encrypted data stream to the cloud data center and ensuring the security of the data transmission process by using homomorphic encryption technology during the transmission; A generation module for generating a data fusion model in the cloud data center by using the result of the homomorphic encryption technology, where the data fusion model includes the data contribution degrees of all participating entities and the sensitive information protection strategies; An output module for generating a final data security and privacy fusion result according to the data fusion model, where the result at least includes the data contribution degrees, the sensitive information protection strategies, and the data usage permissions of each participating entity; The establishment of data encryption and decryption rules according to the access control permissions and the security levels of the data stream specifically includes: For data streams with different security levels, different encryption algorithms are used for encryption processing, and a multi-layer encryption mechanism is introduced to enhance security; An encryption intensity threshold is set, and when the access control permission level is higher than the preset threshold, a higher-level encryption algorithm is enabled; A quantum random number generator is combined to provide an unpredictable encryption key for each encryption operation; The determination of the encryption intensity threshold specifically has the following calculation formula: ; Among them, represents the encryption strength; represents the data quality; represents the data stream speed; represents the th weight factor; represents the key valid range; represents the preset threshold; is a monotonically increasing function; is the number of weight factors; represents a correction term related to the geographic angle and the azimuth angle ; 8. A computing device, characterized in that, Including a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a data security and privacy fusion method based on industrial Internet as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Hierarchical encryption privacy protection method based on block chain

    CN116842573A

  • Dynamic secure login method and system

    CN117040789A

  • Data security transmission system

    CN117319030A

  • Multi-data center cooperation method combining medical imaging omics and federated learning

    CN118366622A