An intelligent management system for park data exchange based on the integration of blockchain and computing network
By adopting an intelligent management system integrating blockchain and computing network in the park data exchange management system, problems such as insufficient allocation of computing resources, low resource utilization, and in real-time data access permission audit are solved, and efficient and secure data exchange and processing are achieved.
Patent Information
- Application Number
- CN202411755551.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-03
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2044-12-03
AI Technical Summary
The existing campus data exchange management system has problems in the inadequate allocation of computing resources, low resource utilization, and in real-time data access permission audits, resulting in low data exchange efficiency and difficult to ensure the security of data during transmission and processing.
The intelligent management system based on the integration of blockchain and computing network is adopted. The data directory and permission information are chained and stored through the directory chain subsystem. The data probe subsystem is used to monitor the data source status. The computing network is integrated and scheduling subsystem generates the optimal computing power allocation plan. The audit subsystem conducts permission auditing. The smart contract subsystem executes data processing logic and computing power scheduling strategies. The computing network collaborative processing subsystem performs collaborative calculations. The security sandbox subsystem performs multi-layer encryption and isolation to ensure data security and efficiency.
It improves the security and efficiency of data transmission, ensures the immutability and traceability of data catalogs, improves resource utilization, and ensures the secure exchange of data within the park.
Smart Images

Figure CN119232354B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of digital information transmission technology, and in particular to an intelligent management system for park data exchange based on the integration of blockchain and computing network. Background Art
[0002] In the existing technology, with the development of the Internet of Things, big data and artificial intelligence, the demand for data exchange in the park has increased significantly. In order to better manage and utilize distributed computing resources, many systems have begun to adopt edge computing, cloud computing and their combined computing and network fusion architecture to improve computing efficiency while ensuring the real-time nature of data processing and the efficiency of resource utilization. At the same time, in order to ensure the security and credibility of data exchange, some systems have combined blockchain technology to store data on the chain to ensure that the data cannot be tampered with and is traceable, thereby enhancing the trust mechanism in data management and storage and improving the overall level of data management in the park.
[0003] However, existing park data exchange management systems generally face multiple technical bottlenecks. The main problems are that computing resource allocation is not intelligent enough, resource utilization is low, and the review process of data access rights lacks real-time performance, which easily affects the efficiency of data exchange. Traditional data management systems often rely on centralized storage and computing architectures, which are difficult to meet the needs of real-time and flexible resource scheduling. In addition, privacy protection and security measures are insufficient in the data exchange process, and the security of data during transmission and processing is difficult to guarantee, which poses a severe challenge to park application scenarios with high data sensitivity requirements.
[0004] Therefore, it is necessary to develop a new type of park data exchange management system. Summary of the invention
[0005] This application provides a campus data exchange intelligent management system based on the integration of blockchain and computing network to improve the security and efficiency of data transmission.
[0006] This application provides a park data exchange intelligent management system based on the integration of blockchain and computing network, including:
[0007] The directory chain subsystem is used to receive data directory information uploaded by the data provider, which includes the data provider's identity, data access strategy and computing requirements; generate a corresponding data directory based on the received data directory information, and store the data directory and its related permission information on the chain to ensure the immutability and traceability of the data directory;
[0008] The data probe subsystem is connected to the directory chain subsystem, and monitors the data status of the data source according to the data directory obtained from the directory chain subsystem; when the monitored data status is consistent with the data directory requirements, a data status report is generated and transmitted to the computing network fusion scheduling subsystem;
[0009] The computing network fusion scheduling subsystem is connected to the data probe subsystem, and obtains the computing task type and data scale based on the data status report provided by the data probe subsystem and the computing requirements in the directory chain subsystem; obtains the computing power status of the edge computing nodes and cloud computing centers in the park; generates the optimal computing power allocation plan according to the computing task type, data scale and current computing power status; and stores the optimal computing power allocation plan on the chain for verification and execution by the audit subsystem;
[0010] The audit subsystem is connected to the computing network fusion scheduling subsystem, and is used to receive data access applications submitted by data users and verify the validity of the computing power resource prepayment vouchers provided by them; based on the computing power allocation plan generated by the computing network fusion scheduling subsystem and the access policy in the data directory, the data access request is reviewed for permissions; if the review is passed, the audit result is generated and stored on the chain, providing a basis for compliance execution for the smart contract subsystem;
[0011] The smart contract subsystem is connected to the audit subsystem, and generates a smart contract including data processing logic and computing power scheduling strategy based on the audit results and permission information stored in the audit subsystem; deploys the generated smart contract to the blockchain network, and triggers the computing network fusion scheduling subsystem according to the audit results to coordinate and execute the allocated computing power resources;
[0012] The computing network collaborative processing subsystem is connected to the smart contract subsystem, and obtains the allocated edge computing and cloud computing resources from the computing network fusion scheduling subsystem according to the computing power scheduling strategy defined in the smart contract; coordinates the edge nodes and cloud computing centers to perform collaborative computing in a distributed computing environment according to the data processing logic, generates processing results and transmits them to the security sandbox system;
[0013] A security sandbox system is connected to the computing network collaborative processing subsystem, and builds a multi-level isolation environment based on the data processing results generated by the computing network collaborative processing subsystem, and performs parameter encryption, TLS channel encryption and environment security encryption on the data to ensure privacy and security during the data processing process; the encrypted processing results are output through the isolation mechanism and transmitted to the trusted exchange subsystem;
[0014] The trusted exchange subsystem is connected to the security sandbox system, and packages the encryption processing results provided by the security sandbox system and pushes them securely to the data user through the blockchain network; it records the entire data exchange and processing process, and triggers the release of computing resources and the cleaning of the security sandbox environment.
[0015] This application has the following beneficial technical effects:
[0016] (1) By combining the directory chain subsystem with the blockchain, the data directory and permission information are stored on the chain, ensuring that the data directory cannot be tampered with and is traceable, effectively preventing data from being maliciously modified, and improving the security and reliability of data exchange. (2) The system's computing network fusion scheduling subsystem can generate the optimal computing power allocation plan based on real-time monitoring of data status, computing requirements, and the actual status of edge and cloud computing resources, and reasonably schedule computing power resources, thereby improving the system's resource utilization and ensuring efficient allocation of computing resources. (3) The security sandbox system provides comprehensive privacy protection for data processing and transmission processes through multi-level isolation, parameter encryption, and transport layer encryption. It effectively prevents data leakage and unauthorized access and ensures the secure exchange of data within the park. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 This is a schematic diagram of a park data exchange intelligent management system based on the integration of blockchain and computing network provided in the first embodiment of the present application. DETAILED DESCRIPTION
[0018] Many specific details are described in the following description to facilitate a full understanding of the present application. However, the present application can be implemented in many other ways than those described herein, and those skilled in the art can make similar generalizations without violating the connotation of the present application, so the present application is not limited by the specific implementation disclosed below.
[0019] The first embodiment of this application provides a park data exchange intelligent management system based on the integration of blockchain and computing network. Figure 1 , which is a schematic diagram of the first embodiment of the present application. Figure 1 The first embodiment of the present application provides a detailed description of an intelligent management system for campus data exchange based on the integration of blockchain and computing network.
[0020] The campus data exchange intelligent management system based on the integration of blockchain and computing network includes a directory chain subsystem 101, a data probe subsystem 102, a computing network integration scheduling subsystem 103, an audit subsystem 104, a smart contract subsystem 105, a computing network collaborative processing subsystem 106, a security sandbox system 107 and a trusted exchange subsystem 108.
[0021] The directory chain subsystem 101 is used to receive data directory information uploaded by the data provider, and the data directory information includes the data provider's identity, data access strategy and computing requirements; generate a corresponding data directory based on the received data directory information, and store the data directory and its related permission information on the chain to ensure the immutability and traceability of the data directory.
[0022] First, the data provider transmits the data directory information to the directory chain subsystem 101 through the interface. The data directory information usually includes the identity of the data provider, data access strategy and computing requirements. The identity of the data provider refers to the unique identifier corresponding to the provider, which is used to identify the source of the data and ensure data security and credibility. The data access strategy contains the permission control information for data access, including the type of user allowed to access, access frequency and access rights, etc., to ensure that the data user can only access specific data within the authorized scope. The computing requirements specifically describe the usage requirements of the data in computing processing, including the required computing resource types, task complexity and the required computing timeliness.
[0023] After receiving the data directory information, the directory chain subsystem 101 generates a corresponding data directory based on the relevant information submitted by the data provider. The generation of the data directory includes the structured processing of the data content and permission information so that the subsequent processing modules of the system can read and call it efficiently. The generated data directory is stored in the form of data objects to ensure the integrity of the data content and facilitate calling. After the data directory is generated, the directory chain subsystem 101 uploads the data directory and its related permission information to the blockchain for evidence storage. The evidence storage process includes digitally signing and encrypting the data directory to generate an unalterable hash value and storing it on the chain. The on-chain evidence storage operation ensures that the data directory information is fully recorded on the blockchain, and all access records and operations can be traced, thereby providing a layer of security for the entire data exchange system.
[0024] The directory chain subsystem 101 also has real-time data verification and update functions. During system operation, the directory chain subsystem 101 can regularly update the new data directory information received, and upload the updated data directory information to the chain to ensure that the data directory and permission information used in the data exchange process are always kept up to date. In addition, through the distributed characteristics of the blockchain, the directory chain subsystem 101 can also effectively prevent data damage or loss caused by single point failures, providing stable and reliable basic data support for the entire park data exchange management system.
[0025] Furthermore, the directory chain subsystem includes a directory update module, and the directory update module is specifically used to:
[0026] Receiving a directory information update request initiated by a data provider, wherein the update request includes an update type identifier, update content, and an associated computing task identifier;
[0027] Construct a three-layer version tree structure, where the first layer records the main version number of the data directory, the second layer records the sub-version number associated with a specific computing task, and the third layer records the revision number of the specific update operation;
[0028] When performing a version update, the scope of influence of the update operation is determined based on the computing task identifier, and the new version of the data directory is only applied to computing tasks that have not yet started to be executed, while the original version of the data directory is maintained for computing tasks that are being executed, thereby achieving dynamic isolation of the data directory;
[0029] The version tree structure and update operation records are stored on the chain, and a version mapping table is maintained on the chain to establish the correspondence between the data directory version and the computing task, ensuring the consistency and traceability of the data processing process.
[0030] The directory chain subsystem has a directory update module, which is mainly responsible for the dynamic update and version management of the data directory to ensure the accuracy of the data directory and the data consistency between tasks. First, the directory update module can receive the directory information update request initiated by the data provider, which contains the identifier of the update type, the content to be updated, and the computing task identifier associated with it. This design enables the system to clearly identify the specific content of the update and the affected computing tasks when processing data directory changes, ensuring the efficiency and pertinence of the update process.
[0031] After receiving the update request, the directory update module manages the directory information in a three-layer version tree structure to ensure clear tracking and management of data versions. The first layer of the three-layer version tree structure is the main version number of the data directory, which is used to identify major version changes of the data directory. The second layer is the sub-version number related to a specific computing task. This layer records the data version information corresponding to each computing task to ensure that each computing task can be executed under the adapted directory version. The third layer is the revision number, which records the detailed changes of the specific update operation, so as to ensure that each update can be accurately tracked.
[0032] During the directory information update process, the directory update module determines the scope of the update based on the received computing task identifier. By judging the status of the computing task, the system limits the update operation to tasks that have not started, thereby avoiding interference with running tasks. Specifically, for computing tasks that have not started, the system will automatically apply the new version of the data directory; for tasks that have already started, the data directory version at the time of task startup will continue to be used. This method implements version management of the data directory through dynamic isolation, ensures the independence of data directory versions between different tasks, and avoids task execution errors caused by data directory updates.
[0033] To ensure the transparency and traceability of update operations, the directory update module will store the version tree structure and update operation information on the chain, and establish a version mapping table on the blockchain. The mapping table manages different versions of the data directory corresponding to specific computing tasks, so that the version selection of the data processing process can be accurately traced. The distributed ledger records of the blockchain ensure that all update information cannot be tampered with, providing reliable support for system auditing and data consistency.
[0034] The data probe subsystem 102 is connected to the directory chain subsystem, and monitors the data status of the data source based on the data directory obtained from the directory chain subsystem; when the monitored data status is consistent with the data directory requirements, a data status report is generated and transmitted to the computing network fusion scheduling subsystem.
[0035] The data probe subsystem 102 obtains the data directory from the directory chain subsystem and uses the set parameters in the directory to regularly monitor the status of the data source. The data directory usually includes information such as data access rights, data types, and computing requirements, which provide the data probe subsystem with a benchmark for data monitoring. The data probe subsystem detects the real-time status of the data source based on these benchmarks to ensure that it meets the requirements of the data directory.
[0036] In actual operation, the data probe subsystem monitors various status parameters of the data source, such as the frequency of data updates, the increase or decrease in data volume, and the integrity of the data content. If during the monitoring process, the probe subsystem detects that the data status does not meet the standards set in the directory chain subsystem, the data probe subsystem will not continue to transmit the data status report to the computing network fusion scheduling subsystem 103, but will re-monitor after a certain time interval until the data source status meets the requirements. In this way, the data probe subsystem can ensure that the data status report is generated only when the data source status meets the directory requirements, and the report is passed to the computing network fusion scheduling subsystem, thereby improving the accuracy and effectiveness of data exchange.
[0037] When the data probe subsystem detects that the status of the data source meets the requirements of the directory chain subsystem, the system immediately generates a data status report. The report contains the current status of the data, update status and related parameters that meet the computing requirements, and transmits the report to the computing network fusion scheduling subsystem 103 through the internal transmission mechanism for subsequent resource allocation decisions. Through this mechanism, the data probe subsystem realizes a closed loop of the entire process from data monitoring to feedback to report transmission, ensuring the real-time and accuracy of the data source status, and providing reliable status support for subsequent data computing tasks.
[0038] Another important function of the data probe subsystem 102 is the status verification and error feedback mechanism. If data inconsistency or transmission error occurs during the report transmission process, the system will notify the data provider through the status feedback mechanism to correct the data source to ensure the effectiveness of subsequent processing and the stability of the system.
[0039] Furthermore, the data probe subsystem includes a state matching module, which implements data state monitoring through a hierarchical progressive judgment method of data features, specifically including:
[0040] The first judgment layer is used to detect whether the data scale of the data source reaches the minimum processing volume required by the data directory. If it reaches it, it enters the second judgment layer. If not, it suspends judgment and continues monitoring.
[0041] The second judgment layer detects whether the data update frequency reaches the minimum update frequency required by the data directory within the last 10-minute time window. If it reaches the minimum update frequency, it enters the third judgment layer. If not, it returns to the first judgment layer.
[0042] The third judgment layer detects whether the non-null value ratio of the required data fields meets the integrity requirements of the data directory. If so, the calculation task is triggered. If not, it returns to the first judgment layer.
[0043] When detecting data scale at the first judgment layer, if the data growth rate is detected to exceed the historical average for three consecutive times, the prediction mechanism will be activated to reserve 30% computing power resources in advance;
[0044] When a computing task is triggered or the reserved computing resources are stopped, the judgment results and data features of each layer are recorded in the blockchain.
[0045] The data probe subsystem is equipped with a state matching module to achieve a layer-by-layer progressive judgment of the data state. The system uses layered judgment logic to accurately control the triggering of data monitoring and computing tasks, ensuring that computing tasks are started only when conditions are met, thereby optimizing resource utilization.
[0046] In the process of data status monitoring, the status matching module first enters the first judgment layer to detect the scale of the data source and determine whether it has reached the minimum processing volume specified in the data directory. If the data scale meets the requirements, it enters the second judgment layer; if it does not meet the standards, it will not continue to judge and keep monitoring the data source to ensure that data resources are used reasonably.
[0047] When the data scale meets the requirements of the first layer, the system enters the second judgment layer and detects the data update frequency within the most recent 10-minute time window to determine whether it reaches the minimum number of updates set in the data directory. The design of this time window can reflect the activity of the data so that the calculation task can be started in time when the data changes frequently. If the data update frequency meets the conditions, it will enter the third judgment layer; if it does not meet the requirements, the system will return to the first judgment layer to continuously monitor the scale changes of the data source.
[0048] After the data update frequency meets the requirements, the state matching module enters the third judgment layer to verify the integrity of the required data fields, that is, to determine whether the proportion of non-null values meets the integrity standards specified in the data directory. This integrity test ensures data quality and provides a reliable data basis for subsequent computing tasks. If the data integrity meets the conditions, the module will immediately trigger the computing task; if it does not meet the requirements, it will return to the first judgment layer to continuously monitor and make a judgment after the data meets the conditions.
[0049] In the first judgment layer, if the system detects that the growth rate of data scale exceeds the historical average for three consecutive times, the state matching module will actively start the prediction mechanism and reserve about 30% of computing power resources. This mechanism is designed to cope with the situation of rapid data growth, and reduce the startup delay of subsequent tasks by allocating computing power in advance, thereby improving the response efficiency of the system.
[0050] When a computing task is triggered or reserved computing resources are canceled, the state matching module will record the results and data features of each judgment layer to the blockchain. Through this way of evidence storage, the system ensures that the process of data status monitoring is transparent and traceable, providing a complete record for subsequent audits and data analysis.
[0051] The computing-network fusion scheduling subsystem 103 is connected to the data probe subsystem, and obtains the computing task type and data scale based on the data status report provided by the data probe subsystem and the computing requirements in the directory chain subsystem; obtains the computing power status of the edge computing nodes and cloud computing centers in the park; generates the optimal computing power allocation plan according to the computing task type, data scale and current computing power status; and stores the optimal computing power allocation plan on the chain for verification and execution by the audit subsystem.
[0052] The computing network fusion scheduling subsystem first receives the status report transmitted by the data probe subsystem and the computing requirements stored in the directory chain subsystem 101. The status report describes in detail whether the current status of the data source meets the requirements specified in the directory, and the computing requirement information includes the task type, data scale and corresponding priority. This information provides a basis for subsequent resource allocation decisions.
[0053] After obtaining computing requirements and data status information, the computing-network fusion scheduling subsystem obtains the resource utilization of edge computing nodes and cloud computing centers by retrieving the real-time computing power status of each computing node in the park, including parameters such as the total available resources of each node, the amount of resources currently used, and network delay. By comparing task requirements and computing power status, the computing-network fusion scheduling subsystem can determine the best allocation strategy for each computing task and generate the optimal computing power allocation plan through the resource scheduling algorithm. The resource scheduling algorithm comprehensively considers the time sensitivity, computing complexity, and network delay of the task to ensure that the task achieves efficient use of computing power resources while meeting the requirements.
[0054] Once the optimal computing power allocation plan is generated, the computing network fusion scheduling subsystem will store the plan on the chain through digital signature to ensure the transparency and immutability of the allocation plan. The allocation plan on the chain contains the specific parameters of the allocation decision, including the computing node to which the task is assigned, the estimated computing time, the network transmission path and other information. This evidence storage process ensures that each step of the computing power scheduling can be audited and traced, providing a verification basis for the subsequent audit subsystem 104, further improving the security and reliability of the system.
[0055] In actual applications, the computing-network fusion scheduling subsystem also has the ability to adjust dynamically. When the resource demand changes or the computing environment fluctuates during task execution, the subsystem can update the computing power allocation plan in real time and re-chain it for evidence. The flexible scheduling capability of this module ensures the resource utilization of the system, reduces resource waste, and records all allocation and adjustment history through the distributed storage mechanism of the blockchain.
[0056] Furthermore, the computing-network fusion scheduling subsystem is specifically used for:
[0057] Extract computing demand information from the directory chain subsystem, including computing task type, data size, and deadline, and obtain data status report from the data probe subsystem; calculate the comprehensive resource demand index according to the following formula 1:
[0058]
[0059] in, For computing tasks The comprehensive resource demand index, which reflects the overall demand intensity of the task for resources;
[0060] For computing tasks The deadline is the time constraint for the task to be completed. It is a parameter set by the system based on the specific requirements of the task, the upper-level strategy, and the actual application scenario, and is used to measure the time urgency of the task. For example, a real-time analysis task may be required to be completed within 10 minutes, and this time is used as .
[0061] For computing tasks The computational workload is usually estimated based on the number of operations, computational complexity, and data size of the task; the higher the computational workload, the more resources are required;
[0062] For computing tasks The scale of the data involved;
[0063] For computing tasks The priority of a task, usually expressed as an integer or a hierarchical identifier. Tasks with higher priorities receive more resource support;
[0064] For computing tasks System resource-specific dependency factors; System resource-specific dependency factors Used to measure computing tasks The degree of dependence on specific system resources. For example, some tasks may have a high degree of dependence on high-performance computing nodes, low-latency network connections, or specific types of hardware accelerators (such as GPUs and TPUs). These requirements will significantly affect the computing effect and execution efficiency of the task. In order to determine this factor, it is usually evaluated from the following aspects:
[0065] (1) Hardware dependency: If the task Specialized hardware resources are required, such as high-performance graphics processing units (GPUs) to accelerate calculations. You can assign a value based on the scarcity of the hardware and its impact on the task. For example, if the task execution must rely on the GPU, and the number of GPUs in the system is limited or the load is high, then A higher value is assigned to reflect the high dependency on this particular hardware resource.
[0066] (2) Network requirements: When the task Highly sensitive to low-latency network connections (such as those requiring real-time data transfer or frequent data exchange), The value of can be determined based on network latency or bandwidth requirements. If the task will cause significant performance degradation or affect the real-time nature of the data in a high-latency network environment, then Should be assigned a higher value.
[0067] (3) Storage requirements: Some tasks may require large storage resources, especially when the task involves processing large amounts of data. In this case, the system can set the storage capacity based on the task’s required storage capacity. For example, for tasks that require extra-large storage space, if the storage space in the system resources is tight or other tasks compete for it, The value will increase accordingly.
[0068] (4) Energy consumption requirements: In energy-sensitive environments (such as edge computing nodes in smart park systems), the energy consumption requirements of tasks are also For tasks that require more energy, the system can set to lower its priority or increase its resource allocation requirements.
[0069] Specifically, The value of can be quantified by weighted scoring or setting coefficients based on actual measured data and the current utilization or availability of various resources in the system. For example, for tasks that are extremely dependent on low-latency networks and GPUs, the system can score them based on the scarcity of GPUs and network latency, and use the weighted sum of the two as the value of This process makes It becomes a flexible and quantitative parameter, thus reflecting the priority and urgency of resource dependencies when scheduling computing tasks.
[0070] and is an adjustable parameter;
[0071] Obtain the real-time resource status of edge computing nodes and cloud computing centers within the park, including the total available resource capacity and the currently used resource amount; calculate the comprehensive computing power availability index according to the following formula 2:
[0072]
[0073] in, Represents the comprehensive computing power availability index, which indicates the total resource intensity currently available for task allocation in the system; is the total available resource capacity of the edge computing nodes; is the current amount of resources occupied by the edge computing node; is the maximum resource capacity of the edge computing node; is the total available resource capacity of the cloud computing center; The current amount of resources occupied by the cloud computing center; is the maximum resource capacity of the cloud computing center; Network delay refers to the data transmission delay between the edge computing node and the cloud computing center; is the time constant of network delay, which is used to balance the impact of network delay on system resource availability; and is the adjustment factor; and is the weight coefficient;
[0074] Combined with the task demand index and hashrate availability index , construct the multi-objective optimization function ObjectiveScore provided by the following formula 3:
[0075]
[0076] in, For computing tasks expected processing delays; For computing tasks Delays introduced by the system in the allocation and use of computing resources; It is a very small positive number to prevent the denominator from being zero;
[0077] is the amount of redundant resources for the task, expressed as a computing task The amount of additional computing resources reserved to provide fault tolerance and high reliability; represented as a computing task The utilization efficiency of the allocated computing resources, specifically expressed as the ratio of actual effective resources to total allocated resources; To adjust the parameters; Resource utilization efficiency refers to the computing task The ratio between the effective resources actually utilized during execution and the total resources allocated by the system for it;
[0078] The computing network fusion scheduling subsystem uses a particle swarm optimization algorithm to solve the multi-objective optimization function ObjectiveScore. The particle swarm optimization algorithm includes the following steps:
[0079] Initialization step P101: Generate an initial particle swarm based on system preset parameters, the particle swarm consists of multiple candidate solution particles, each particle represents a potential computing resource allocation scheme; assign an initial position and velocity vector to each particle, and set the global optimal solution and the local optimal solution;
[0080] Iterative update step P102: Update the particle swarm according to the following rules:
[0081] Calculate the fitness function value ObjectiveScore of each particle to evaluate the quality of the resource allocation plan;
[0082] Update the local optimal solution position of each particle and the global optimal solution position ;
[0083] Adjust the particle speed according to the following formulas 4 and 5 and location :
[0084]
[0085]
[0086] in, Represents the inertia weight coefficient, which is used to balance global search and local search; and is the learning factor, which controls the speed at which particles move toward the local and global optimal solutions; and For the interval A randomly generated number inside is used to increase the randomness of the solution space;
[0087] Convergence step P103: When the optimization target reaches the preset accuracy requirement; or the number of iterations reaches the preset maximum upper limit, the iteration is terminated and the optimal computing power allocation solution is output;
[0088] The optimal computing power allocation plan and related parameters are stored on the chain to provide verification and execution basis for the audit subsystem, ensuring the traceability and security of the entire process.
[0089] The audit subsystem 104 is connected to the computing network integration scheduling subsystem, and is used to receive data access applications submitted by data users and verify the validity of the computing power resource prepayment vouchers provided by them; based on the computing power allocation plan generated by the computing network integration scheduling subsystem and the access policy in the data directory, the data access request is subject to permission review; if the review is passed, the audit result is generated and uploaded to the chain for evidence storage, providing a basis for compliance execution for the smart contract subsystem.
[0090] The subsystem first receives the data access application submitted by the data user, and obtains the data user's identity authentication information and the data directory information required to be accessed. After receiving the access application, the audit subsystem will authenticate the identity of the data user to ensure that it has legal access rights. In addition, the audit subsystem 104 also verifies the validity of the computing resource prepayment voucher provided by the data user to ensure that the user has the corresponding resource commitment when applying for computing resources, reducing the risk of invalid access.
[0091] After completing the preliminary verification, the audit subsystem 104 conducts further audit based on the computing power allocation plan provided by the computing network fusion scheduling subsystem 103. The computing power allocation plan contains information such as the computing resource configuration and usage time of the task. The audit subsystem determines whether the resource allocation meets the needs of the data user by comparing the allocation plan and the data access request, and ensures that the data call is made within the authorized scope. At the same time, the audit subsystem combines the data access policy in the directory chain subsystem 101 to perform multi-level permission review on the access request. The data access policy usually includes restrictions such as the visitor's identity level, access frequency, and data reading permissions. By verifying these policies, the audit subsystem can accurately control authorized access to data to prevent unauthorized access and data leakage.
[0092] After completing the audit, the audit subsystem generates the audit results and stores the audit results and related operation information on the blockchain through blockchain technology to ensure the transparency and immutability of the audit process. This storage mechanism provides a compliance basis for subsequent data calls, making it easier for the smart contract subsystem 105 to execute the corresponding data processing logic and computing power scheduling strategy based on the audit results, thereby improving the data security and resource utilization efficiency of the entire system.
[0093] Furthermore, the audit subsystem implements the linkage audit of computing resources and data access rights through the following steps:
[0094] Read the computing resource prepayment voucher of the data user and extract the computing type, computing scale and usage time period;
[0095] Based on the access policies in the data catalog, determine whether the data user has the following data access qualifications:
[0096] Level 1 qualification, which allows access to raw data;
[0097] Level 2 qualification only allows access to statistical results;
[0098] Level 3 qualification only allows access to data tags;
[0099] The prepaid computing resources are divided according to the access qualification level of the data user:
[0100] In the case of first-level qualification, 80% of computing power is reserved for raw data processing and 20% for result generation;
[0101] In the case of Level 2 qualification, 30% of computing power is reserved for statistical analysis and 70% for result verification;
[0102] In the case of Level 3 qualification, all computing power is used for tag calculation and verification;
[0103] If a data user requests to access the same data set multiple times within a specified time period, the remaining computing resources will be automatically merged to achieve batch reuse of computing resources;
[0104] The linkage audit results are recorded in the blockchain, including access qualification level, computing power allocation ratio and remaining computing power status.
[0105] First, the audit subsystem reads the computing power resource prepayment voucher submitted by the data user. The voucher contains information such as the computing power type, computing power scale, and usage time period. This information provides the system with the resource background required for data access.
[0106] After obtaining information about computing resources, the audit subsystem further determines the qualifications of the data user based on the access policy in the data directory to determine whether it has the authority to access specific data. Data access qualifications are divided into three levels, where the first-level qualification grants data users the right to access raw data, the second-level qualification only allows access to statistical analysis results, and the third-level qualification is limited to viewing data tags. This grading mechanism ensures that data access complies with the prescribed authority control policy and protects the sensitivity of data and the rationality of its use.
[0107] According to the qualification level of the data user, the audit subsystem reasonably allocates its prepaid computing resources. In the case of first-level qualification, the system uses 80% of the computing resources for raw data processing operations, and the remaining 20% of the computing power is used to generate the final results, ensuring sufficient computing power when processing raw data. For users with second-level qualifications, the system uses 30% of the computing resources for the statistical analysis process, and the remaining 70% for the verification of the results to ensure the accuracy and reliability of the statistical results. For third-level qualifications, the audit subsystem uses all computing resources for the calculation and verification of data tags to meet the user's access rights requirements.
[0108] In addition, the audit subsystem also includes a batch reuse mechanism for computing resources to improve resource utilization. When a data user requests access to the same data set multiple times within a specified time period, the system will automatically merge its remaining computing resources so that computing power can be reused in subsequent requests, thereby reducing unnecessary resource allocation and waste. This batch reuse of computing resources can effectively improve the overall efficiency of the system, especially in frequent access scenarios.
[0109] After completing the linkage audit, the audit subsystem will record information such as access qualification level, computing power allocation ratio, and remaining computing power status to the blockchain. Through the blockchain's evidence storage function, the system realizes the transparency and non-tamperability of the audit process, providing reliable record support for subsequent audits and verifications.
[0110] The smart contract subsystem 105 is connected to the audit subsystem, and generates a smart contract including data processing logic and computing power scheduling strategy based on the audit results and permission information stored in the audit subsystem; deploys the generated smart contract to the blockchain network, and triggers the computing network fusion scheduling subsystem according to the audit results to coordinate and execute the allocated computing power resources.
[0111] After the audit subsystem 104 completes the data access rights audit and generates the audit results, the subsystem receives the audit results and permission information from the audit subsystem. Based on this information, the smart contract subsystem automatically generates a smart contract containing specific data processing logic and computing power allocation requirements. The smart contract is designed as an execution script containing multiple layers of logical instructions, which is used to guide the reasonable use of computing power resources in the subsequent data processing process and ensure the compliance of data processing.
[0112] After the smart contract is generated, the smart contract subsystem deploys the contract to the blockchain network. Through the distributed ledger characteristics of the blockchain, the contract content is ensured to be tamper-proof and the execution is transparent. During the deployment of the smart contract, the contract will be signed and stored to ensure that the contract maintains integrity and verifiability during execution. The storage method of the blockchain network makes the contract execution information public, transparent, and unchangeable, ensuring that the data exchange and resource allocation between data users and providers are carried out under the supervision of all parties.
[0113] Once the smart contract is deployed, the smart contract subsystem immediately triggers the computing network integration scheduling subsystem 103 to coordinate the computing resources of the edge computing nodes and cloud computing centers in the park. The computing scheduling strategy defined by the smart contract includes the selection of computing nodes, task priority management, computing resource allocation, and the execution process of computing tasks. According to these strategies in the smart contract, the scheduling subsystem reasonably allocates computing tasks to edge or cloud computing nodes to maximize the utilization of computing resources and ensure the timeliness and efficiency of computing tasks.
[0114] This mechanism of the smart contract subsystem gives the system highly automated decision-making capabilities, reducing the need for human intervention. Through the constraints and guidance of smart contracts, the entire data processing and computing power allocation process can be carried out under transparent and secure conditions. The smart contract subsystem can also generate an execution report after execution, including information such as the actual use of computing power resources, task completion time, and data processing status, and store this report on the blockchain to provide data support for subsequent resource evaluation and optimization.
[0115] The smart contract subsystem includes a state rollback module to deal with possible failures of edge computing nodes, thereby ensuring that computing tasks can be completed smoothly and the overall stability of the system is not affected. When the state rollback module detects that an edge computing node has failed, the system will immediately record the task execution status of the node, including the completed calculation steps and the generated intermediate calculation results. By fully recording the task execution status, the state rollback module can provide the necessary basic data for the subsequent continuation or reallocation of the task.
[0116] After the recording is completed, the state rollback module will establish a task rollback point based on the execution status information, thereby dividing the unfinished computing tasks into migratable tasks and tasks that need to be recalculated. Migratable tasks refer to tasks that only depend on the completed intermediate computing results, which means that these tasks can continue to be executed on other computing nodes without recalculation. Tasks that need to be recalculated are those that rely on the local data of the failed node. Due to the data dependency, the computing process needs to be restarted on the new node.
[0117] For migratable tasks, the state rollback module transfers the intermediate calculation results to the newly allocated computing nodes, so that the task can continue to execute from the rollback point, avoiding the waste of time and resources for repeated calculations. In this way, the system can quickly migrate tasks to new nodes to ensure the continuity and efficiency of calculations.
[0118] For tasks that need to be recalculated, the state rollback module will re-call the data source on the newly allocated computing node and start the task calculation process from the beginning to ensure that all calculations that rely on local data can be performed completely and correctly. At the same time, the state rollback module records the recalculation event in detail to the blockchain for subsequent traceability and verification. The blockchain's evidence storage function provides transparency for the execution process of computing tasks, ensuring the traceability and credibility of all rollback and recalculation operations.
[0119] In the park data exchange intelligent management system, the smart contract subsystem is equipped with a computing power reservation module to ensure that computing power resources are reasonably reserved in the case of continuous data processing needs. The computing power reservation module first extracts the characteristic information of the access pattern by analyzing the data user's recent 10 access records. These characteristics include the time interval for data processing, the degree of correlation between computing tasks, and the scale of computing power resource usage. Through this pattern analysis, the system can identify the typical usage behavior of the data user and thus determine its subsequent computing power needs.
[0120] After extracting the access pattern features, the computing power reservation module determines whether to trigger the resource reservation mechanism based on specific conditions. When the interval between two consecutive data processing by the data user is less than 30 minutes, or when there is a data dependency between the input and output of the computing task, or the usage scale of computing power resources fluctuates by no more than 20% between different tasks, the system will automatically start the computing power reservation mechanism. This reservation mechanism ensures the continuous availability of computing power resources to meet the immediate computing needs of data users and avoid processing delays caused by insufficient resources.
[0121] During resource reservation, the system strictly protects the allocated computing resources and prohibits other tasks from preempting these resources to ensure that the data user's tasks can be completed under the expected computing conditions. The reservation of computing resources remains valid until one of the following situations occurs: the reservation time exceeds 2 hours, the data user actively releases the resources, or the system detects that a higher priority urgent task needs to use the computing power. In these cases, the computing resources will be automatically unreserved so that they can be reallocated to other tasks, thereby ensuring the overall resource utilization of the system and the flexibility of priority scheduling.
[0122] This computing power reservation mechanism achieves efficient data processing flow by effectively identifying the continuity needs of data processing and rationally allocating computing power resources, while providing stable computing support for data users.
[0123] The computing-network collaborative processing subsystem 106 is connected to the smart contract subsystem, and obtains the allocated edge computing and cloud computing resources from the computing-network fusion scheduling subsystem according to the computing power scheduling strategy defined in the smart contract; coordinates the edge nodes and cloud computing centers for collaborative computing in a distributed computing environment according to the data processing logic, generates processing results and transmits them to the security sandbox system.
[0124] The computing network collaborative processing subsystem is connected to the smart contract subsystem, and according to the scheduling instructions in the smart contract, it obtains the pre-allocated edge computing resources and cloud computing resources from the computing network fusion scheduling subsystem 103. The allocation of each resource is based on the previous computing power demand analysis and task priority setting to ensure that the execution of computing tasks complies with the overall resource optimization strategy of the system.
[0125] After the resources are allocated, the computing network collaborative processing subsystem uses the distributed computing environment to coordinate the collaborative computing operations between the edge nodes and the cloud computing center. Specifically, the computing network collaborative processing subsystem divides the task into multiple subtasks and assigns them to each computing node according to the data processing logic set in the smart contract. During the execution of the task, the computing network collaborative processing subsystem dynamically monitors the resource usage of each node to ensure that the allocated resources are used reasonably. If a computing node has insufficient resources or reduced computing efficiency, the system can adjust the task allocation or execution order based on real-time feedback to ensure that the overall computing efficiency is not affected. This real-time allocation and adjustment of tasks not only improves the utilization of resources, but also reduces the execution delay of computing tasks, so that computing tasks can be completed efficiently within the set time.
[0126] After completing the computing task, the computing network collaborative processing subsystem summarizes the processing results and transmits the summarized results to the security sandbox system 107. The aggregation process ensures that the computing results of all subtasks are integrated into a complete output according to the established data processing logic for subsequent encryption and security processing. In this way, the computing network collaborative processing subsystem provides stable and efficient computing capabilities for the entire park data exchange system, and provides solid computing support for the secure transmission and use of sensitive data.
[0127] The security sandbox system 107 is connected to the computing network collaborative processing subsystem, and builds a multi-level isolation environment based on the data processing results generated by the computing network collaborative processing subsystem, and performs parameter encryption, TLS channel encryption and environment security encryption on the data to ensure privacy and security during data processing; the encrypted processing results are output through the isolation mechanism and passed to the trusted exchange subsystem.
[0128] This subsystem is connected to the computing network collaborative processing subsystem 106 and is responsible for comprehensive security protection of the data processing results it generates. To this end, the security sandbox system first builds a multi-level isolation environment to distinguish different computing tasks and data flows in a physical and logical isolation manner, ensuring that there is no unauthorized access between computing units and preventing sensitive data from being interfered with by unauthorized tasks or operations. This isolation environment has security mechanisms at both the hardware and software layers, so that the transmission and processing of data in each computing node is under control, improving data security.
[0129] On the basis of multi-level isolation, the security sandbox system further performs multi-layer encryption operations on the data. First, the subsystem encrypts the core parameters in the data processing results through parameter encryption to ensure that these data parameters cannot be illegally accessed even during the transmission process in the isolated environment. Next, the system establishes a secure communication tunnel for data transmission through TLS channel encryption to prevent network attacks or interception when the data crosses nodes or isolated environments. Finally, the security sandbox system performs environmental security encryption on the processed data, so that the integrity and confidentiality of the data can be guaranteed throughout the isolation and transmission process.
[0130] After the data encryption and isolation processing is completed, the security sandbox system outputs the encrypted data to the trusted exchange subsystem 108 through the isolation mechanism. During the output process, the security sandbox system verifies the data to ensure that all data complies with the preset security policies and privacy requirements. At this stage, the system generates an operation log by recording the detailed information of the data flow so that it can be stored on the blockchain, so that the entire data processing and transmission process has traceability and audit functions. Through this description, technicians in this field can achieve strict security control and efficient encryption isolation of data, ensure the safe circulation of data in the park intelligent management system, and ensure that the user's privacy information is protected in all operations.
[0131] Furthermore, the security sandbox system is specifically used for:
[0132] Use the trusted execution environment to implement a multi-layer isolation mechanism and calculate the isolation strength score according to the following formula 6. :
[0133]
[0134] in, For the The number of times a memory area is improperly accessed by other processes or threads during execution reflects the isolation effect of the memory area. If a region is frequently accessed by other processes, the isolation effect is poor.
[0135] For the The total number of accesses to a memory area is a measure of the total number of normal accesses to the area;
[0136] is the total number of memory areas; For the The weight coefficient of each memory area; For the The amount of resource sharing within an execution environment within a specified time refers to the use of resources within the execution environment by other tasks; For the The total resource usage of each execution environment within a specified time; is the total number of execution environments; For the The weight coefficient of each execution environment; For the The number of lock contentions between a thread and other threads; For the The total number of lock requests by threads; For the The weight coefficient of each thread; is the total number of threads; is an environmental factor, and ;
[0137] Parameters are encrypted based on the session key, and encryption parameters are generated according to the following formula 7 , the formula is:
[0138]
[0139] in, A cryptographic hash function, such as SHA-256; is the session key; is a random number; is the original parameter data; is the random displacement based on the time seed, calculated according to the following formula 8:
[0140]
[0141] in, The current timestamp is used to generate the time seed; is the displacement update interval, ensuring that the displacement changes over time; is the floor function; A cryptographic hash function, such as SHA-256; is the time period, used to calculate the time seed; is the maximum displacement, which is used to define the upper limit of data displacement;
[0142] Create a dynamic transport layer security channel and calculate the channel security strength according to the following formula 9 :
[0143]
[0144] in, For the The security factor of the encryption algorithm of a secure channel reflects the security strength of the algorithm; For the The key length of the secure channel; For the The key update cycle of a secure channel;
[0145] According to the following formula 10, calculate the comprehensive safety factor :
[0146]
[0147] in, is the adjustment factor; Score the strength of isolation; Score the strength of isolation It is calculated by evaluating the isolation of memory areas, execution environments, and threads in the system. When performing isolation, the system will assign different weights to each memory area, execution environment, and thread according to their isolation status, and score them layer by layer.
[0148] For memory regions, the system calculates how often each memory region is inappropriately accessed, and regions that are not interfered with by other processes are scored higher.
[0149] For execution environments, the system measures the degree of resource sharing. The stronger the resource isolation, the higher the score.
[0150] For threads, the system records resource contention between threads. Threads with less resource contention have higher scores.
[0151] The scores of each layer are weighted according to their respective weights, and then the final isolation strength score is obtained by summing up. .so, It can reflect the overall effect of multi-layer isolation within the system. The higher the value, the better the isolation effect and the higher the security.
[0152] is the threshold of isolation strength; Encryption parameters The entropy value of is the maximum entropy value of the encryption parameters under ideal conditions; is the channel security strength; is the time decay factor; The duration of encryption;
[0153] When the comprehensive safety factor When the preset threshold is exceeded, the three-step encryption process is considered effective; if the comprehensive safety factor If the preset threshold is not exceeded, the encryption parameters are readjusted and the above steps are repeated to ensure the best privacy and security of data processing.
[0154] The trusted exchange subsystem 108 is connected to the security sandbox system, and packages the encryption processing results provided by the security sandbox system and pushes them securely to the data user through the blockchain network; it records the entire data exchange and processing process, and triggers the release of computing resources and the cleaning of the security sandbox environment.
[0155] The subsystem is connected to the security sandbox system 107 and receives the encryption processing results transmitted by it. First, the trusted exchange subsystem verifies the received encrypted data to ensure that the data meets the privacy protection standards set by the security sandbox system. After the verification is passed, the trusted exchange subsystem packages the encrypted data to ensure that the data will not be interfered with or tampered with by the external environment during the subsequent transmission process.
[0156] After the data is packaged, the trusted exchange subsystem pushes the data to the designated data user through the blockchain network. The distributed nature of the blockchain network provides additional security. Every data transmission generates a record on the chain to ensure that the data transmission process is transparent, traceable and cannot be tampered with. In this way, the data user can verify the integrity and source credibility of the data at the receiving end, ensuring that the data content has not been illegally changed or damaged, and that the transmission process meets the security standards of the system.
[0157] In addition, the trusted exchange subsystem will store detailed information of the entire data exchange process after the data is successfully pushed. This information includes the data transmission time, the identity information of the data recipient, and the results of various security verifications. This evidence storage process uses blockchain technology to permanently store process records in a distributed ledger to prevent the loss or tampering of data exchange records and provide reliable data support for future audits or traceability. Through this mechanism, the trusted exchange subsystem not only ensures the security and transparency of the data user's receiving process, but also provides a reliable audit and verification basis for the entire park data exchange system.
[0158] Finally, the trusted exchange subsystem is also responsible for the automation of resource management, ensuring that computing resources are released immediately after data is successfully transmitted, and cleaning up the secure sandbox environment as needed to enable efficient recycling and reuse of system resources. Through this mechanism, the trusted exchange subsystem ensures the rational allocation of resources and optimizes the operating efficiency of the system.
[0159] In the campus data exchange intelligent management system, the hierarchical delivery module in the trusted exchange subsystem is designed to deliver data processing results efficiently and in blocks, especially for large-scale processing results. After receiving the data processing results, the hierarchical delivery module divides them into fixed-size data blocks to achieve a flexible and efficient delivery method. Each data block is attached with a unique identifier to ensure the integrity and traceability of the delivery. The identifier contains the data block's sequence number, hash value, timestamp, and the source computing node's identification, ensuring that the data can maintain its integrity during transmission and preventing content tampering.
[0160] The hierarchical delivery module optimizes the delivery order through priority management to ensure that important data blocks are delivered first. For data blocks marked as real-time analysis results, the system will deliver them immediately as the highest priority data blocks to meet the data users' demand for real-time data; for data blocks from computing nodes that are about to be released, these data will also be delivered first, so as to release computing resources in time and improve the overall resource utilization of the system. The remaining data blocks are delivered one by one in the order of serial numbers, thus realizing an orderly and efficient data delivery process.
[0161] During the delivery process, the hierarchical delivery module also continuously monitors the receiving status of the data user. If it is detected that the data user has timed out during the transmission process, the module will automatically suspend the delivery operation and keep the current computing resources locked to prevent repeated data transmission and waste of computing resources. Once the receiving status of the data user is restored, the system will continue to deliver the remaining data blocks from the interruption point to ensure the integrity and continuity of data delivery.
[0162] This module design implements block management and priority scheduling of data, thereby maintaining the stability and accuracy of data delivery even when the data scale is large or the transmission environment is unstable.
[0163] In the campus data exchange intelligent management system, the resource release module in the trusted exchange subsystem is responsible for efficiently releasing computing resources after data delivery is completed and allocating resource priorities for subsequent tasks. The resource release module first scans all nodes involved in the calculation and extracts the identity of each node, the contribution of the node in the calculation, and the duration of the node resource occupation. By recording the computing contribution of each node, the system can effectively measure the participation of each node in the task execution, and thus determine the scheduling priority of the next task based on its computing contribution.
[0164] Based on the computing contribution of the node, the resource release module will allocate the priority of the next computing task according to a specific strategy. For nodes with a contribution of more than 90%, the system grants them 10 minutes of priority scheduling rights, so that they can get priority resource allocation in future tasks. For nodes with a contribution of more than 70%, the system grants them 5 minutes of priority scheduling rights to ensure that the contributions of these nodes are appropriately incentivized. This priority allocation method can enhance the participation enthusiasm of high-contribution nodes and encourage efficient use of resources within the system.
[0165] After allocating the priority, the resource release module performs a comprehensive resource cleanup operation. The cleanup process includes deleting the intermediate calculation results remaining on the node to ensure that there is no redundant data occupying the node's storage resources after the task is completed; releasing the temporary communication link established between nodes to release network resources and prevent unnecessary data flow; and canceling the resource identifier temporarily allocated to the node during the task process to ensure the standardization and security of system resource management.
[0166] After the cleanup operation is completed, the resource release module will store the resource release record on the chain to ensure the transparency and traceability of the system operation. The record includes the time of resource release, the contribution of each node, and the allocation of priority, ensuring that the system can audit and verify each resource release operation. Based on this description, technicians in this field can use the resource release module to achieve orderly release and reasonable scheduling of resources to ensure the efficient operation of the park data exchange system and sustainable management of resources.
[0167] Although the present application is disclosed as above in the form of a preferred embodiment, it is not intended to limit the present application. Any technical personnel in this field may make possible changes and modifications without departing from the spirit and scope of the present application. Therefore, the scope of protection of the present application shall be based on the scope defined by the claims of the present application.
Claims
1. A park data exchange intelligent management system based on the integration of blockchain and computing network, characterized in that: include: The directory chain subsystem is used to receive data directory information uploaded by the data provider, the data directory information includes the data provider's identity, data access strategy and computing requirements; generate a corresponding data directory based on the received data directory information, and store the data directory and its related permission information on the chain; The data probe subsystem is connected to the directory chain subsystem, and monitors the data status of the data source according to the data directory obtained from the directory chain subsystem; when the monitored data status is consistent with the data directory requirements, a data status report is generated and transmitted to the computing network fusion scheduling subsystem; The computing network fusion scheduling subsystem is connected to the data probe subsystem, and obtains the computing task type and data scale based on the data status report provided by the data probe subsystem and the computing requirements in the directory chain subsystem; obtains the computing power status of the edge computing nodes and cloud computing centers in the park; generates the optimal computing power allocation plan according to the computing task type, data scale and current computing power status; The optimal computing power allocation plan is stored on the chain for verification and execution by the audit subsystem; The audit subsystem is connected to the computing network fusion scheduling subsystem, and is used to receive data access applications submitted by data users and verify the validity of the computing power resource prepayment vouchers provided by them; based on the computing power allocation plan generated by the computing network fusion scheduling subsystem and the access policy in the data directory, the data access request is reviewed for authority; If the review is passed, the review results will be generated and uploaded to the chain for evidence storage, providing a basis for compliance execution for the smart contract subsystem; The smart contract subsystem is connected to the audit subsystem, and generates a smart contract including data processing logic and computing power scheduling strategy based on the audit results and permission information stored in the audit subsystem; deploys the generated smart contract to the blockchain network, and triggers the computing network fusion scheduling subsystem according to the audit results to coordinate and execute the allocated computing power resources; The computing network collaborative processing subsystem is connected to the smart contract subsystem, and obtains the allocated edge computing and cloud computing resources from the computing network fusion scheduling subsystem according to the computing power scheduling strategy defined in the smart contract; coordinates the edge nodes and cloud computing centers to perform collaborative computing in a distributed computing environment according to the data processing logic, generates processing results and transmits them to the security sandbox system; A security sandbox system is connected to the computing network collaborative processing subsystem, and builds a multi-level isolation environment based on the data processing results generated by the computing network collaborative processing subsystem, and performs parameter encryption, TLS channel encryption and environment security encryption on the data; the encrypted processing results are output through the isolation mechanism and transmitted to the trusted exchange subsystem; The trusted exchange subsystem is connected to the security sandbox system, and packages the encrypted processing results provided by the security sandbox system and pushes them securely to the data user through the blockchain network; The entire data exchange and processing process is recorded, and the release of computing resources and the cleanup of the security sandbox environment are triggered.
2. The park data exchange intelligent management system according to claim 1, characterized in that: The directory chain subsystem includes a directory update module, which is specifically used to: Receiving a directory information update request initiated by a data provider, wherein the update request includes an update type identifier, update content, and an associated computing task identifier; Construct a three-layer version tree structure, where the first layer records the main version number of the data directory, the second layer records the sub-version number associated with a specific computing task, and the third layer records the revision number of the specific update operation; When performing a version update, the impact scope of the update operation is determined based on the computing task identifier, and the new version of the data directory is applied only to computing tasks that have not yet started to execute, while the original version of the data directory is maintained for computing tasks that are being executed; The version tree structure and update operation records are stored on the chain, and a version mapping table is maintained on the chain to establish the correspondence between the data directory version and the computing task.
3. The park data exchange intelligent management system according to claim 1, characterized in that: The data probe subsystem includes a state matching module, which implements data state monitoring through a hierarchical and progressive judgment method of data features, specifically including: The first judgment layer is used to detect whether the data scale of the data source reaches the minimum processing volume required by the data directory. If it reaches it, it enters the second judgment layer. If not, it suspends judgment and continues monitoring. The second judgment layer detects whether the data update frequency reaches the minimum update frequency required by the data directory within the last 10-minute time window. If it reaches the minimum update frequency, it enters the third judgment layer. If not, it returns to the first judgment layer. The third judgment layer detects whether the non-null value ratio of the required data fields meets the integrity requirements of the data directory. If so, the calculation task is triggered. If not, it returns to the first judgment layer. When detecting data scale at the first judgment layer, if the data growth rate is detected to exceed the historical average for three consecutive times, the prediction mechanism will be activated to reserve 30% computing power resources in advance; When a computing task is triggered or the reserved computing resources are stopped, the judgment results and data features of each layer are recorded in the blockchain.
4. The park data exchange intelligent management system according to claim 1, characterized in that: The audit subsystem implements the linkage audit of computing resources and data access rights through the following steps: Read the computing resource prepayment voucher of the data user and extract the computing type, computing scale and usage time period; Based on the access policies in the data catalog, determine whether the data user has the following data access qualifications: Level 1 qualification, which allows access to raw data; Level 2 qualification only allows access to statistical results; Level 3 qualification only allows access to data tags; The prepaid computing resources are divided according to the access qualification level of the data user: In the case of first-level qualification, 80% of computing power is reserved for raw data processing and 20% for result generation; In the case of Level 2 qualification, 30% of computing power is reserved for statistical analysis and 70% for result verification; In the case of Level 3 qualification, all computing power is used for tag calculation and verification; If a data user requests access to the same data set multiple times within a specified time period, its remaining computing resources will be automatically merged; The linkage audit results are recorded in the blockchain, including access qualification level, computing power allocation ratio and remaining computing power status.
5. The park data exchange intelligent management system according to claim 1, characterized in that: The smart contract subsystem includes a state rollback module, which is used to perform the following operations when an edge computing node failure is detected: Record the task execution status of the failed node, including the completed calculation steps and intermediate calculation results; Based on the recorded execution status, a task rollback point is constructed, and the unfinished computing tasks are divided into tasks that can be migrated and tasks that need to be recalculated; wherein, the migratable tasks refer to tasks that only rely on intermediate computing results; the tasks that need to be recalculated refer to tasks that rely on local data of the failed node; For migratable tasks, the intermediate computation results are transferred to the newly allocated computing nodes and the tasks are continued from the rollback point. For tasks that need to be recalculated, the data source is re-called on the new node and the calculation is started, and the recalculation event is recorded in the blockchain.
6. The park data exchange intelligent management system according to claim 1, characterized in that: The smart contract subsystem includes a computing power reservation module, which is used to perform the following operations when continuous data processing requirements are detected: Based on the data user's recent 10 access records, access pattern features including the time interval for data processing, the degree of correlation of computing tasks, and the scale of computing resource usage are extracted; The computing resource reservation mechanism is triggered when any of the following conditions is met: The time interval between two adjacent data processing is less than 30 minutes; There is data dependency between the input and output of computing tasks; The fluctuation of computing power resource usage shall not exceed 20%; During the reservation period, other tasks are prohibited from preempting the reserved computing resources until any of the following situations occurs: The reservation time exceeds 2 hours; The data user releases the data voluntarily; A higher priority urgent task has been detected.
7. The park data exchange intelligent management system according to claim 1, characterized in that: The trusted exchange subsystem includes a hierarchical delivery module, which is used to perform block delivery according to the scale of the data processing results, specifically including: When receiving the processing results, divide them into fixed-size data blocks; Generate a unique identifier for each data block, the unique identifier including a data block sequence number, a data block hash value, a timestamp, and a source computing node identifier; The order in which data blocks are delivered is determined according to the following priorities: The data blocks marked as real-time analysis results have the highest priority; The data blocks that are about to be released by the associated computing node have the second highest priority; The remaining data blocks are delivered in sequence number order; During the delivery process, the receiving status of the data consumer is continuously monitored. If a reception timeout is detected, the delivery is suspended and the computing resources are kept locked; if reception resumption is detected, the delivery is continued from the interruption point.
8. The park data exchange intelligent management system according to claim 1, characterized in that: The trusted exchange subsystem includes a resource release module, which is used to perform the following operations after completing data delivery: Scan all nodes involved in the calculation, extract node identity, node calculation contribution, and node resource occupancy time; Based on the node calculation contribution, the priority of the next calculation is allocated according to the following strategy: Nodes with a contribution greater than 90% will be given 10 minutes of priority scheduling; Nodes with a contribution greater than 70% will be given 5 minutes of priority scheduling; Perform resource cleanup, including deleting intermediate calculation results on the node, releasing the communication link between nodes, and canceling the temporarily allocated resource identifier; The resource release records are stored on the chain, and the resource release records include release time, node contribution, and priority allocation.
9. The park data exchange intelligent management system according to claim 1, characterized in that: The computing-network fusion scheduling subsystem is specifically used for: Extract computing demand information from the directory chain subsystem, including computing task type, data size, and deadline, and obtain data status report from the data probe subsystem; calculate the comprehensive resource demand index according to the following formula 1: in, For computing tasks Comprehensive resource demand index; For computing tasks The computational workload; For computing tasks The scale of the data involved; For computing tasks Prioritize tasks; For computing tasks The specific dependency factors of system resources; and is an adjustable parameter; For computing tasks Deadline: Obtain the real-time resource status of edge computing nodes and cloud computing centers within the park, including the total available resource capacity and the currently used resource amount; calculate the comprehensive computing power availability index according to the following formula 2: in, Represents the comprehensive computing power availability index, which indicates the total resource intensity currently available for task allocation in the system; is the total available resource capacity of the edge computing nodes; is the current amount of resources occupied by the edge computing node; is the maximum resource capacity of the edge computing node; is the total available resource capacity of the cloud computing center; The current amount of resources occupied by the cloud computing center; is the maximum resource capacity of the cloud computing center; Network delay refers to the data transmission delay between the edge computing node and the cloud computing center; is the time constant of network delay; and is the adjustment factor; and is the weight coefficient; Combined with the task demand index and hashrate availability index , construct the multi-objective optimization function ObjectiveScore provided by the following formula 3: in, For computing tasks expected processing delays; For computing tasks Delays introduced by the system in the allocation and use of computing resources; is a very small positive number to prevent the denominator from being zero; is the amount of redundant resources for a task, expressed as a computing task The amount of additional computing resources reserved; expressed as computing tasks The utilization efficiency of the allocated computing resources, specifically expressed as the ratio of actual effective resources to total allocated resources; To adjust the parameters; Resource utilization efficiency refers to the computing task The ratio between the effective resources actually utilized during execution and the total resources allocated by the system for it; The computing-network fusion scheduling subsystem uses a particle swarm optimization algorithm to solve the multi-objective optimization function ObjectiveScore. The particle swarm optimization algorithm includes the following steps: Initialization step P101: Generate an initial particle swarm based on system preset parameters. The particle swarm consists of multiple candidate solution particles, each particle represents a potential computing resource allocation scheme; assign an initial position and velocity vector to each particle, and set the global optimal solution and the local optimal solution; Iterative update step P102: Update the particle swarm according to the following rules: Calculate the fitness function value ObjectiveScore of each particle; Update the local optimal solution position of each particle and the global optimal solution position ; Adjust the particle speed according to the following formulas 4 and 5 and location : in, Represents the inertia weight coefficient, which is used to balance global search and local search; and is the learning factor, which controls the speed at which particles move toward the local and global optimal solutions; and For the interval A randomly generated number inside is used to increase the randomness of the solution space; Convergence step P103: When the optimization target reaches the preset accuracy requirement; or the number of iterations reaches the preset maximum upper limit, the iteration is terminated and the optimal computing power allocation solution is output; The optimal computing power allocation plan and related parameters are stored on the chain to provide verification and execution basis for the audit subsystem.
10. The park data exchange intelligent management system according to claim 1, characterized in that: The security sandbox system is specifically used for: Use the trusted execution environment to implement a multi-layer isolation mechanism and calculate the isolation strength score according to the following formula 6. : in, For the The number of times a memory area is improperly accessed by other processes or threads during execution; For the The total number of accesses to the memory area; is the total number of memory areas; For the The weight coefficient of each memory area; For the The amount of resources shared by each execution environment within a specified time; For the The total resource usage of each execution environment within a specified time; is the total number of execution environments; For the The weight coefficient of each execution environment; For the The number of lock contentions between a thread and other threads; For the The total number of lock requests by threads; For the The weight coefficient of each thread; is the total number of threads; is an environmental factor, and ; Parameters are encrypted based on the session key, and encryption parameters are generated according to the following formula 7 , the formula is: in, is a cryptographic hash function; is the session key; is a random number; is the original parameter data; is the random displacement based on the time seed, calculated according to the following formula 8: in, is the current timestamp; is the displacement update interval; is the floor function; is a cryptographic hash function; is the time period, used to calculate the time seed; is the maximum displacement, which is used to define the upper limit of data displacement; Create a dynamic transport layer security channel and calculate the channel security strength according to the following formula 9 : in, For the The security factor of the encryption algorithm of the secure channel; For the The key length of the secure channel; For the The key update cycle of a secure channel; According to the following formula 10, calculate the comprehensive safety factor : in, is the adjustment factor; score the strength of isolation; is the threshold of isolation strength; Encryption parameters The entropy value of is the maximum entropy value of the encryption parameters under ideal conditions; is the channel security strength; is the time decay factor; The duration of encryption; When the comprehensive safety factor When the preset threshold is exceeded, the three-step encryption process is considered effective; if the comprehensive safety factor If the preset threshold is not exceeded, the encryption parameters are readjusted and the above steps are repeated.
Citation Information
Patent Citations
Multi-modal data sensing method and device based on data probe
CN113961571A
Associated network construction and co-evolution method
CN115065551A