A trusted data space management system and method based on blockchain

By adopting the combination of blockchain technology and initial data credit modules in the trusted data space, the problem of insufficient security of trusted data space in the prior art is solved, and efficient encryption of data and secure and trustworthy data circulation are achieved.

CN119402191BActive Publication Date: 2025-05-13TAIJI COMPUTER CORPORATION LIMITED
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411658625.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-19
Publication Date
2025-05-13
Estimated Expiration
2044-11-19

AI Technical Summary

Technical Problem

The security of trusted data space in the prior art is insufficient, making it difficult to effectively solve the security and trust problems between data element providers, users, and service providers.

Method used

The trusted data space management system based on blockchain is adopted, and the historical user access log is obtained through the initial data credit module for security grading, encrypting the data and putting it on the link; the storage module uses edge computing nodes to store encrypted data; the access module manages user access rights based on user permissions and data security level; the matching module determines the matching encrypted data based on the data fields that need to be accessed and releases access rights.

Benefits of technology

Ensure the immutability and traceability of encrypted data, improve response speed, realize role-based access control, improve encryption effect, and ensure data security and credibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119402191B_ABST
    Figure CN119402191B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of data security technology, and redefines a management system and method for a trusted data space based on blockchain, including: creating an initial data credit module in a trusted data space according to an initial credit result obtained through intelligent analysis of blockchain, and then performing security classification on the data to be encrypted in the initial data credit module, and encrypting the data to be encrypted according to different encryption strategies based on the security classification; a storage module for storing the encrypted data to be uploaded to the blockchain according to the computing power of the edge computing node; an access module for managing the user's access to and application of the data and policies to be accessed and releasing the corresponding access and application permissions; and a matching module for releasing the user's access rights to matching encrypted data. The architecture of the trusted data space of the present invention is established based on Trusted Computing 3.0, and the initial data credit module is distributed based on blockchain technology, which ensures the security and credibility of encrypted data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data security technology, and more specifically, to a blockchain-based trusted data space management system and method. Background Art

[0002] Driven by the wave of digital transformation, the industrial field is undergoing unprecedented changes. With the deep integration of technologies such as the Internet of Things, big data, cloud computing, and artificial intelligence, the industrial production process generates massive and complex data. These data are not only an important basis for corporate operational decisions, but also a key resource for promoting the intelligent upgrading of the manufacturing industry. However, the siloing, fragmentation, and security issues of data have seriously restricted the maximization of data value. Therefore, building a trusted, open, and shared industrial data space system architecture has become an urgent need to promote the circulation of industrial data, optimize resource allocation, and accelerate innovative applications.

[0003] Trusted data space is a distributed key data infrastructure for data aggregation, sharing, circulation and application built on the existing information network. Through systematic technical arrangements, it ensures the confirmation, implementation and maintenance of data circulation agreements, solves the security and trust issues between data element providers, users, service providers and other entities, and thus realizes data-driven digital transformation. How to establish a secure and reliable trusted data space has become a technical problem that needs to be solved urgently in this field. Summary of the invention

[0004] The present invention provides a blockchain-based trusted data space management system and method to solve the technical problem of insufficient security of trusted data space in the prior art, including:

[0005] The initial data credit module is used to obtain historical user access logs, perform security classification on the data to be encrypted according to the historical user access logs, and encrypt the data to be encrypted using different encryption strategies according to the security classification;

[0006] The storage module is used to create edge computing nodes and store the encrypted data to be uploaded to the blockchain according to the computing power of the edge computing nodes;

[0007] The access module is used to obtain the user's access request, manage the user's access, the application's access to data and policies according to the user's access request, user authority, and data security level, and release the corresponding access and application authority;

[0008] The matching module is used to determine matching encrypted data according to the data field of the data to be accessed, and release the access rights of the matching encrypted data to the user.

[0009] Furthermore, the initial data credit module performs security classification on the data to be encrypted according to the historical user access logs, including:

[0010] Determine the co-occurrence frequency of the data to be encrypted and the rest of the data based on historical user access logs;

[0011] Obtain the data type of the data to be encrypted, and calculate the access frequency of the data to be encrypted in the corresponding data type;

[0012] Calculate the ratio of the co-occurrence frequency of the data to be encrypted and the rest of the data to the access frequency, and obtain the correlation between the data to be encrypted and the rest of the data;

[0013] Perform edge connection on data with a correlation greater than a first preset threshold, and construct a data connection graph according to the correlation of all data to be encrypted;

[0014] The data sensitivity of each data to be encrypted is calculated according to the data connection diagram, and the security level of the data to be encrypted is determined according to the data sensitivity of each data to be encrypted.

[0015] Furthermore, the step of calculating the data sensitivity of each data to be encrypted according to the data connection diagram includes:

[0016] Determine the node degree of the data to be encrypted according to the data connection graph, and set the node degree of the data to be encrypted as the propagation sensitivity;

[0017] Obtain the sensitive field library, identify the fields of the data to be encrypted, and determine the content sensitivity based on the matching degree between the data fields of the data to be encrypted and the sensitive field library;

[0018] Obtaining content sensitivity of other data to be encrypted that is connected to the data to be encrypted, and screening out other data to be encrypted whose content sensitivity is greater than a second preset threshold;

[0019] Calculate the average value of the content sensitivity of the remaining data to be encrypted whose content sensitivity is greater than the second preset threshold value to obtain a sensitivity correction coefficient;

[0020] Multiply the content sensitivity by the transmission sensitivity to obtain the initial data sensitivity of the data to be encrypted;

[0021] The sensitivity correction coefficient is normalized, and the normalized sensitivity correction coefficient is multiplied by the initial data sensitivity to obtain the data sensitivity of the data to be encrypted.

[0022] Furthermore, the storage module stores the encrypted data to be uploaded to the blockchain according to the computing power of the edge computing node, including:

[0023] Acquire an allowable storage capacity of the edge computing node, and determine a first computing capacity value according to the allowable storage capacity of the edge computing node;

[0024] Obtain the workload of the edge computing node within a preset period, and draw a workload change curve according to the workload of the edge computing node within the preset period;

[0025] Obtain a preset sliding time window, and divide the workload change curve according to the preset sliding time window to obtain a plurality of sub-load change curves;

[0026] Calculate the average workload of each sub-load change curve, and draw an average workload change curve according to the average workload of each sub-load change curve;

[0027] Calculate the slope values ​​of two adjacent average workloads in the average workload change curve, calculate the average value of the slope values ​​in the average workload change curve, and obtain a second computing capacity value;

[0028] Determine the computing capacity of the edge computing node according to the first computing capacity value and the second computing capacity value;

[0029] Obtain the required computing power of the encrypted data that needs to be uploaded to the chain, and distribute the encrypted data that needs to be uploaded to the chain to the corresponding edge computing nodes according to the required computing power of the encrypted data that needs to be uploaded to the chain to complete the data upload.

[0030] Further, determining the computing capability of the edge computing node according to the first computing capability value and the second computing capability value includes:

[0031] The computing power of the edge computing node is determined according to the computing power formula, and the computing power formula is specifically:

[0032]

[0033] Wherein, Q is the computing power of the edge computing node, A is the first computing power value, and B is the second computing power value. is the third preset threshold, and R is the preset range coefficient.

[0034] Furthermore, the access module manages the user's access, the application's access to data and policies according to the user's access request, user authority, and data security level, and releases the corresponding access and application authority, including:

[0035] Obtain the user's historical access logs, and determine the user's access frequency to each encrypted data type based on the user's historical access logs;

[0036] Determine the user's access duration to each encrypted number type based on the user's historical access log, multiply the user's access duration to each encrypted number type by the corresponding access frequency, and obtain the user's matching coefficient to each encrypted number type;

[0037] Cluster the access data in the user's historical access log according to the matching coefficient, and assign roles to the user based on the clustering results;

[0038] Obtain the user's current access scenario data, and determine the user's access location, access time period, and access terminal based on the user's current access scenario data;

[0039] The access characteristic value is determined according to the user's access location, access period and access terminal, and a dynamic role is allocated to the user according to the access characteristic value.

[0040] Obtain the data security level of encrypted data and determine whether the user role and user permissions match the data security level;

[0041] If the user role and user permissions match the data security level, the user is allowed to access and apply the required data and policies and release the corresponding access and application permissions.

[0042] Furthermore, clustering the access data in the user's historical access log according to the matching coefficient and assigning roles to the user according to the clustering result includes:

[0043] Cluster the access data in the user's historical access log based on the k-means clustering algorithm, and determine the number of access data in each cluster partition according to the clustering results;

[0044] Screening out cluster partitions whose number of access data is greater than a third preset threshold, and determining corresponding encrypted data types according to the cluster partitions whose number of access data is greater than the third preset threshold;

[0045] A role corresponding to the encrypted data type is allocated to the user according to the encrypted data type corresponding to the cluster partition whose amount of access data is greater than a third preset threshold.

[0046] Furthermore, the determining of the access characteristic value according to the user's access location, access period and access terminal includes:

[0047] Obtain the user's current access scenario data, and determine the user's access location, access time period, and access terminal based on the user's current access scenario data;

[0048] Determine the geographical distance between the current visited location and the optimal visited location according to the user's visited location, and determine the first visit parameter according to the geographical distance between the current visited location and the optimal visited location;

[0049] Determine the time difference between the current access period and the optimal access period according to the user's access period, and determine the second access parameter according to the time difference between the current access period and the optimal access period;

[0050] Acquire an access terminal library, determine the terminal level of the current access terminal in the access terminal library according to the user's access terminal, and obtain a third access parameter;

[0051] Convert the first access parameter, the second access parameter and the third access parameter into a first line segment, a second line segment and a third line segment according to a preset ratio, and intersect the midpoint of the second line segment with the first line segment to construct a rhombus;

[0052] A quadrangular pyramid is constructed with the intersection of the second line segment and the first line segment as the base and the third line segment as the height, and the volume of the quadrangular pyramid is set as the access feature value of the user.

[0053] Furthermore, the matching module determines matching encrypted data according to a data field of the data to be accessed, including:

[0054] Extract data titles according to the data fields of the data to be accessed, and determine the target title matching coefficient according to the data titles;

[0055] Calculating the difference between the title matching coefficient of the remaining encrypted data and the target title matching coefficient, and determining the degree of title matching according to the difference between the title matching coefficient of the remaining encrypted data and the target title matching coefficient;

[0056] Screening out the remaining encrypted data whose title matching degree is greater than a fourth preset threshold value and sorting the remaining encrypted data according to the matching degree, and determining the data matching threshold value according to the sorting result;

[0057] The degree of field matching between the remaining encrypted data and the data to be accessed is calculated, and the remaining encrypted data whose field matching degree is greater than the corresponding data matching threshold is determined as the matching encrypted data.

[0058] The present invention also provides a blockchain-based trusted data space management method, comprising:

[0059] Obtain historical user access logs, classify the data to be encrypted according to the historical user access logs, and encrypt the data to be encrypted according to different encryption strategies based on the security classification;

[0060] Create edge computing nodes and store the encrypted data to be uploaded to the blockchain according to the computing power of the edge computing nodes;

[0061] Obtain the user's access request, manage the user's access, the application's access to data and policies based on the user's access request, user permissions, and data security level, and release the corresponding access and application permissions;

[0062] The matching encrypted data is determined according to the data field of the data to be accessed, and the access rights to the matching encrypted data are released to the user.

[0063] The beneficial effects of the present invention are:

[0064] By applying the above technical solutions, the present invention establishes a trusted data space architecture based on Trusted Computing 3.0, and constructs a data storage and exchange infrastructure based on a distributed initial data credit module based on blockchain technology, which can ensure the immutability and traceability of encrypted data. At the same time, edge computing nodes are created to process encrypted data on the chain, which effectively improves the response speed, and implements role-based access control for accessing users, thereby improving the encryption effect, ensuring the security and credibility of encrypted data, and enabling users to access data reliably and accurately. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0066] Figure 1 A schematic diagram of the structure of a blockchain-based trusted data space management system proposed in an embodiment of the present invention is shown;

[0067] Figure 2 The figure shows an overall flow chart of a trusted data space management method based on blockchain proposed in an embodiment of the present invention. DETAILED DESCRIPTION

[0068] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0069] The present application embodiment provides a blockchain-based trusted data space management system such as Figure 1 As shown, including:

[0070] The initial data credit module is used to obtain historical user access logs, perform security classification on the data to be encrypted based on the historical user access logs, and encrypt the data to be encrypted using different encryption strategies based on the security classification; the storage module is used to create edge computing nodes, and store the encrypted data to be uploaded to the blockchain based on the computing power of the edge computing nodes; the access module is used to obtain the user's access request, manage the user's access to the data and policies to be accessed, and release the corresponding access and application permissions based on the user's access request, user permissions, and data security level; the matching module is used to determine the matching encrypted data based on the data field of the data to be accessed, and release the access rights of the matching encrypted data to the user.

[0071] In this embodiment, a trusted data space architecture is established based on Trusted Computing 3.0, and a distributed initial data credit module based on blockchain technology is used to build a data storage and exchange infrastructure. Industrial data is stored and encrypted, and the encrypted data is uploaded to the chain through edge computing nodes. User access is controlled through the access module, and matching encrypted data is screened out through the matching module, so that users can access data reliably and accurately.

[0072] In some embodiments of the present application, the initial data credit module performs security classification on the data to be encrypted based on historical user access logs, including: determining the co-occurrence frequency of the data to be encrypted and other data based on the historical user access logs; obtaining the data type of the data to be encrypted, and calculating the access frequency of the data to be encrypted in the corresponding data type; calculating the ratio of the co-occurrence frequency of the data to be encrypted and the other data to the access frequency, and obtaining the correlation between the data to be encrypted and the other data; edge-connecting data whose correlation is greater than a first preset threshold, and constructing a data connection graph based on the correlation of all data to be encrypted; calculating the data sensitivity of each data to be encrypted based on the data connection graph, and determining the security level of the data to be encrypted based on the data sensitivity of each data to be encrypted.

[0073] In this embodiment, the co-occurrence frequency is obtained by counting the number of times the data to be encrypted and the other data co-appear in the access log through the historical user access log. The access frequency is obtained by counting the number of times the data to be encrypted is accessed in the corresponding data type, thereby obtaining the correlation between the data to be encrypted and the other data and constructing a data connection diagram. The security level is determined by the data sensitivity of the data to be encrypted in the data connection diagram. The greater the data sensitivity, the higher the corresponding security level. Different encryption strategies are implemented to encrypt the data to be encrypted according to different security levels. The higher the security level, the more complex the corresponding encryption strategy.

[0074] In some embodiments of the present application, the data sensitivity of each data to be encrypted is calculated according to the data connection graph, including: determining the node degree of the data to be encrypted according to the data connection graph, and setting the node degree of the data to be encrypted as the propagation sensitivity; obtaining a sensitive field library, performing field identification on the data to be encrypted, and determining the content sensitivity according to the matching degree between the data field of the data to be encrypted and the sensitive field library; obtaining the content sensitivity of the remaining data to be encrypted connected to the data to be encrypted, and screening out the remaining data to be encrypted whose content sensitivity is greater than a second preset threshold; calculating the average value of the content sensitivity of the remaining data to be encrypted whose content sensitivity is greater than the second preset threshold to obtain a sensitivity correction coefficient; multiplying the content sensitivity by the propagation sensitivity to obtain the initial data sensitivity of the data to be encrypted; normalizing the sensitivity correction coefficient, and multiplying the normalized sensitivity correction coefficient by the initial data sensitivity to obtain the data sensitivity of the data to be encrypted.

[0075] In this embodiment, the node degree is the number of edges connected to the data to be encrypted in the data connection graph. The content sensitivity is obtained by the ratio of the number of fields associated with the data fields of the data to be encrypted and the sensitive fields in the sensitive field library, and then the sensitivity correction coefficient is calculated. The range of the sensitivity correction coefficient is limited to 0-1 through normalization processing, so as to realize the correction of the initial data sensitivity.

[0076] In some embodiments of the present application, the storage module stores the encrypted data to be uploaded to the blockchain according to the computing power of the edge computing node, including: obtaining the allowable storage capacity of the edge computing node, and determining a first computing power value according to the allowable storage capacity of the edge computing node; obtaining the workload of the edge computing node within a preset period, and drawing a workload change curve according to the workload of the edge computing node within the preset period; obtaining a preset sliding time window, and dividing the workload change curve according to the preset sliding time window to obtain a plurality of sub-load change curves; calculating the average workload of each sub-load change curve, and drawing an average workload change curve according to the average workload of each sub-load change curve; calculating the slope value of two adjacent average workloads in the average workload change curve, and calculating the average value of the slope value in the average workload change curve to obtain a second computing power value; determining the computing power of the edge computing node according to the first computing power value and the second computing power value; obtaining the required computing power of the encrypted data to be uploaded to the chain, and allocating the encrypted data to be uploaded to the corresponding edge computing node according to the required computing power of the encrypted data to be uploaded to the chain, and completing the data upload.

[0077] In some embodiments of the present application, determining the computing power of the edge computing node according to the first computing power value and the second computing power value includes: determining the computing power of the edge computing node according to a computing power formula, and the computing power formula is specifically,

[0078]

[0079] Wherein, Q is the computing power of the edge computing node, A is the first computing power value, and B is the second computing power value. is the third preset threshold, and R is the preset range coefficient.

[0080] In this embodiment, a first computing power value is determined based on the allowable storage capacity of each edge computing node, and a second computing power value is determined based on the average slope of the workload change curve of the edge computing node within a preset period. The computing power of the edge computing node is determined by the first computing power value and the second computing power value, and the computing power of the edge computing node is matched with the required computing power of each data to be uploaded to the chain to achieve data uploading.

[0081] In some embodiments of the present application, the access module manages the user's access to the data and policies that the application needs to access and releases the corresponding access and application permissions according to the user's access request, user permissions, and data security level, including: obtaining the user's historical access log, determining the user's access frequency to each encrypted data type according to the user's historical access log; determining the user's access duration to each encrypted data type according to the user's historical access log, multiplying the user's access duration to each encrypted data type by the corresponding access frequency, and obtaining the user's matching coefficient for each encrypted data type; clustering the access data in the user's historical access log according to the matching coefficient, and assigning roles to the user according to the clustering result; obtaining the user's current access scenario data, determining the user's access location, access period, and access terminal according to the user's current access scenario data; determining the access feature value according to the user's access location, access period, and access terminal, and assigning a dynamic role to the user according to the access feature value. Obtain the data security level of the encrypted data, determine whether the user role and user permissions match the data security level; if the user role and user permissions match the data security level, allow the user to access the data and policies that the application needs to access and release the corresponding access and application permissions.

[0082] In this embodiment, the user is assigned a role through the user's historical access log to determine whether the user's role and the user's authority match the data security level of the target blockchain, and then determine whether the user is allowed to access and apply the required data and encryption policy and release the corresponding access and application permissions.

[0083] In some embodiments of the present application, the access data in the user's historical access log is clustered according to the matching coefficient, and the role is assigned to the user according to the clustering result, including: clustering the access data in the user's historical access log based on the k-means clustering algorithm, and determining the amount of access data in each cluster partition according to the clustering result; screening out the cluster partitions whose amount of access data is greater than a third preset threshold, and determining the corresponding encrypted data type according to the cluster partitions whose amount of access data is greater than the third preset threshold; and assigning the user a role corresponding to the encrypted data type according to the encrypted data type corresponding to the cluster partitions whose amount of access data is greater than the third preset threshold.

[0084] In this embodiment, role-based access control is implemented for accessing users. The access frequency is calculated by the ratio of the number of times the user accesses each data type in each access data of the historical access log to the total number of times the access data is accessed. The matching coefficient of each access data of the user is calculated by the access frequency and access duration. The matching coefficient is clustered based on the k-means clustering algorithm, and the user's access data is divided into multiple cluster partitions. The encrypted data type corresponding to the cluster partition whose number of access data is greater than the third threshold is screened out, and the role corresponding to the encrypted data type is assigned to the user.

[0085] In some embodiments of the present application, the access characteristic value determined according to the user's access location, access period and access terminal includes: determining the geographical distance between the current access location and the optimal access location according to the user's access location, and determining a first access parameter according to the geographical distance between the current access location and the optimal access location; determining the time difference between the current access period and the optimal access period according to the user's access period, and determining a second access parameter according to the time difference between the current access period and the optimal access period; obtaining an access terminal library, determining the terminal level of the current access terminal in the access terminal library according to the user's access terminal, and obtaining a third access parameter; converting the first access parameter, the second access parameter and the third access parameter into a first line segment, a second line segment and a third line segment according to a preset ratio, and constructing a rhombus by intersecting the midpoint of the second line segment with the first line segment; constructing a quadrangular pyramid with the intersection of the second line segment and the first line segment as the base and the third line segment as the height, and setting the volume of the quadrangular pyramid as the user's access characteristic value.

[0086] In this embodiment, a tetrahedron is constructed based on the user's access scenario, and the access characteristic value is set by the volume value of the tetrahedron. A dynamic role is assigned to the user according to the access characteristic value. The dynamic role is the role permission for the access level, and its permission priority is greater than that of the static role. When the volume value of the tetrahedron is greater than the preset volume threshold, the user is assigned a dynamic role with a lower access level. When the volume value of the tetrahedron is less than or equal to the preset volume threshold, the user is assigned a dynamic role with an increased access level.

[0087] In some embodiments of the present application, the matching module determines matching encrypted data based on the data field of the data to be accessed, including: extracting the data title based on the data field of the data to be accessed, and determining the target title matching coefficient based on the data title; calculating the difference between the title matching coefficient of the remaining encrypted data and the target title matching coefficient, and determining the title matching degree based on the difference between the title matching coefficient of the remaining encrypted data and the target title matching coefficient; screening out the remaining encrypted data whose title matching degree is greater than a fourth preset threshold and sorting the remaining encrypted data according to the matching degree, and determining the data matching threshold based on the sorting result; calculating the field matching degree of the remaining encrypted data and the data to be accessed, and determining the remaining encrypted data whose field matching degree is greater than the corresponding data matching threshold as matching encrypted data.

[0088] In this embodiment, a deep learning neural network model is established to extract data titles of data fields of data to be accessed, and a target title matching coefficient is set through the title feature vector of each data title. The title matching degree is determined by the difference between the title matching coefficient of the remaining encrypted data and the target title matching coefficient. The smaller the difference, the higher the corresponding title matching degree. The corresponding data matching threshold is assigned to each remaining encrypted data through the sorting result of the title matching degree. The higher the sorting position, the smaller the assigned data matching threshold. Finally, by calculating the field matching degree of the remaining encrypted data and the data to be accessed, the remaining encrypted data with a field matching degree greater than the corresponding data matching threshold is screened out as matching encrypted data, and the access rights of the matching encrypted data are also assigned to the user to facilitate the user's retrieval of data.

[0089] The embodiment of the present invention also provides a trusted data space management method based on blockchain, such as Figure 2 As shown, including:

[0090] S101, obtaining historical user access logs, performing security classification on the data to be encrypted according to the historical user access logs, and encrypting the data to be encrypted using different encryption strategies according to the security classification;

[0091] S102, creating an edge computing node, and storing the encrypted data to be uploaded to the blockchain according to the computing power of the edge computing node;

[0092] S103, obtaining the user's access request, managing the user's access, the application's access to data and policies according to the user's access request, user authority, and data security level, and releasing the corresponding access and application authority;

[0093] S104, determining matching encrypted data according to the data field of the data to be accessed, and releasing access rights of the matching encrypted data to the user.

[0094] By applying the above technical solution, the present invention creates an initial data credit module in the trusted data space according to the initial credit result obtained by intelligent analysis of the blockchain, and then performs security classification on the data to be encrypted in the initial data credit module, and encrypts the data to be encrypted according to different encryption strategies based on the security classification; the storage module is used to store the encrypted data to be uploaded to the blockchain according to the computing power of the edge computing node; the access module is used to manage the user's access to the data and policies to be accessed and release the corresponding access and application permissions; the matching module is used to release the access rights of the matching encrypted data to the user. The architecture of the trusted data space of the present invention is established based on Trusted Computing 3.0, and the initial data credit module is distributed based on blockchain technology, which ensures the security and credibility of encrypted data.

[0095] Through the description of the above implementation methods, those skilled in the art can clearly understand that the present invention can be implemented by hardware, or by software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present invention can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.), including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each implementation scenario of the present invention.

[0096] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A trusted data space management system based on blockchain, characterized in that: include: The initial data credit module is used to obtain historical user access logs, perform security classification on the data to be encrypted according to the historical user access logs, and encrypt the data to be encrypted using different encryption strategies according to the security classification; The storage module is used to create edge computing nodes and store the encrypted data to be uploaded to the blockchain according to the computing power of the edge computing nodes; The access module is used to obtain the user's access request, manage the user's access, the application's access to data and policies according to the user's access request, user authority, and data security level, and release the corresponding access and application authority; A matching module, used to determine matching encrypted data according to the data field of the data to be accessed, and release access rights of the matching encrypted data to the user; The initial data credit module performs security classification on the data to be encrypted according to the historical user access logs, including: Determine the co-occurrence frequency of the data to be encrypted and the rest of the data based on historical user access logs; Obtain the data type of the data to be encrypted, and calculate the access frequency of the data to be encrypted in the corresponding data type; Calculate the ratio of the co-occurrence frequency of the data to be encrypted and the rest of the data to the access frequency, and obtain the correlation between the data to be encrypted and the rest of the data; Perform edge connection on data with a correlation greater than a first preset threshold, and construct a data connection graph according to the correlation of all data to be encrypted; The data sensitivity of each data to be encrypted is calculated according to the data connection diagram, and the security level of the data to be encrypted is determined according to the data sensitivity of each data to be encrypted.

2. The blockchain-based trusted data space management system according to claim 1, characterized in that: The step of calculating the data sensitivity of each data to be encrypted according to the data connection diagram includes: Determine the node degree of the data to be encrypted according to the data connection graph, and set the node degree of the data to be encrypted as the propagation sensitivity; Obtain the sensitive field library, identify the fields of the data to be encrypted, and determine the content sensitivity based on the matching degree between the data fields of the data to be encrypted and the sensitive field library; Obtaining content sensitivity of other data to be encrypted that is connected to the data to be encrypted, and screening out other data to be encrypted whose content sensitivity is greater than a second preset threshold; Calculate the average value of the content sensitivity of the remaining data to be encrypted whose content sensitivity is greater than the second preset threshold value to obtain a sensitivity correction coefficient; Multiply the content sensitivity by the transmission sensitivity to obtain the initial data sensitivity of the data to be encrypted; The sensitivity correction coefficient is normalized, and the normalized sensitivity correction coefficient is multiplied by the initial data sensitivity to obtain the data sensitivity of the data to be encrypted.

3. The blockchain-based trusted data space management system according to claim 1, characterized in that: The storage module stores the encrypted data to be uploaded to the blockchain according to the computing power of the edge computing node, including: Acquire an allowable storage capacity of the edge computing node, and determine a first computing capacity value according to the allowable storage capacity of the edge computing node; Obtain the workload of the edge computing node within a preset period, and draw a workload change curve according to the workload of the edge computing node within the preset period; Obtain a preset sliding time window, and divide the workload change curve according to the preset sliding time window to obtain a plurality of sub-load change curves; Calculate the average workload of each sub-load change curve, and draw an average workload change curve according to the average workload of each sub-load change curve; Calculate the slope values ​​of two adjacent average workloads in the average workload change curve, calculate the average value of the slope values ​​in the average workload change curve, and obtain a second computing capacity value; Determine the computing capacity of the edge computing node according to the first computing capacity value and the second computing capacity value; Obtain the required computing power of the encrypted data that needs to be uploaded to the chain, and distribute the encrypted data that needs to be uploaded to the chain to the corresponding edge computing nodes according to the required computing power of the encrypted data that needs to be uploaded to the chain to complete the data upload.

4. The blockchain-based trusted data space management system according to claim 3 is characterized in that: The determining the computing capability of the edge computing node according to the first computing capability value and the second computing capability value includes: The computing power of the edge computing node is determined according to the computing power formula, and the computing power formula is specifically: , Wherein, Q is the computing power of the edge computing node, A is the first computing power value, and B is the second computing power value. is the third preset threshold, and R is the preset range coefficient.

5. The blockchain-based trusted data space management system according to claim 1, characterized in that: The access module manages the user's access, application's access to data and policies according to the user's access request, user authority, and data security level, and releases the corresponding access and application authority, including: Obtain the user's historical access logs, and determine the user's access frequency to each encrypted data type based on the user's historical access logs; Determine the user's access duration to each encrypted number type based on the user's historical access log, multiply the user's access duration to each encrypted number type by the corresponding access frequency, and obtain the user's matching coefficient to each encrypted number type; Cluster the access data in the user's historical access log according to the matching coefficient, and assign roles to the user based on the clustering results; Obtain the user's current access scenario data, and determine the user's access location, access time period, and access terminal based on the user's current access scenario data; Determine access feature values ​​based on the user's access location, access period, and access terminal, and assign dynamic roles to the user based on the access feature values; Obtain the data security level of encrypted data and determine whether the user role and user permissions match the data security level; If the user role and user permissions match the data security level, the user is allowed to access and apply the required data and policies and release the corresponding access and application permissions.

6. The blockchain-based trusted data space management system according to claim 5, characterized in that: The step of clustering the access data in the user's historical access log according to the matching coefficient and assigning roles to the user according to the clustering result includes: Cluster the access data in the user's historical access log based on the k-means clustering algorithm, and determine the number of access data in each cluster partition according to the clustering results; Screening out cluster partitions whose number of access data is greater than a third preset threshold, and determining corresponding encrypted data types according to the cluster partitions whose number of access data is greater than the third preset threshold; A role corresponding to the encrypted data type is allocated to the user according to the encrypted data type corresponding to the cluster partition whose amount of access data is greater than a third preset threshold.

7. The blockchain-based trusted data space management system according to claim 6, characterized in that: Determining the access characteristic value according to the user's access location, access period and access terminal includes: Obtain the user's current access scenario data, and determine the user's access location, access time period, and access terminal based on the user's current access scenario data; Determine the geographical distance between the current visited location and the optimal visited location according to the user's visited location, and determine the first visit parameter according to the geographical distance between the current visited location and the optimal visited location; Determine the time difference between the current access period and the optimal access period according to the user's access period, and determine the second access parameter according to the time difference between the current access period and the optimal access period; Acquire an access terminal library, determine the terminal level of the current access terminal in the access terminal library according to the user's access terminal, and obtain a third access parameter; Convert the first access parameter, the second access parameter and the third access parameter into a first line segment, a second line segment and a third line segment according to a preset ratio, and intersect the midpoint of the second line segment with the first line segment to construct a rhombus; A quadrangular pyramid is constructed with the intersection of the second line segment and the first line segment as the base and the third line segment as the height, and the volume of the quadrangular pyramid is set as the access feature value of the user.

8. The blockchain-based trusted data space management system according to claim 1, characterized in that: The matching module determines matching encrypted data according to the data field of the data to be accessed, including: Extract data titles according to the data fields of the data to be accessed, and determine the target title matching coefficient according to the data titles; Calculating the difference between the title matching coefficient of the remaining encrypted data and the target title matching coefficient, and determining the degree of title matching according to the difference between the title matching coefficient of the remaining encrypted data and the target title matching coefficient; Screening out the remaining encrypted data whose title matching degree is greater than a fourth preset threshold value and sorting the remaining encrypted data according to the matching degree, and determining the data matching threshold value according to the sorting result; The degree of field matching between the remaining encrypted data and the data to be accessed is calculated, and the remaining encrypted data whose field matching degree is greater than the corresponding data matching threshold is determined as the matching encrypted data.

9. A trusted data space management method based on blockchain, characterized in that: include: Obtain historical user access logs, classify the data to be encrypted according to the historical user access logs, and encrypt the data to be encrypted according to different encryption strategies based on the security classification; Create edge computing nodes and store the encrypted data to be uploaded to the blockchain according to the computing power of the edge computing nodes; Obtain the user's access request, manage the user's access, the application's access to data and policies based on the user's access request, user permissions, and data security level, and release the corresponding access and application permissions; Determine matching encrypted data based on the data field of the data to be accessed, and release access rights to the matching encrypted data to the user; The security classification of the data to be encrypted according to the historical user access logs includes: Determine the co-occurrence frequency of the data to be encrypted and the rest of the data based on historical user access logs; Obtain the data type of the data to be encrypted, and calculate the access frequency of the data to be encrypted in the corresponding data type; Calculate the ratio of the co-occurrence frequency of the data to be encrypted and the rest of the data to the access frequency, and obtain the correlation between the data to be encrypted and the rest of the data; Perform edge connection on data with a correlation greater than a first preset threshold, and construct a data connection graph according to the correlation of all data to be encrypted; The data sensitivity of each data to be encrypted is calculated according to the data connection diagram, and the security level of the data to be encrypted is determined according to the data sensitivity of each data to be encrypted.

Citation Information

Patent Citations

  • Blockchain access permission control method based on privacy protection and blockchain system

    CN113742782A

  • Enterprise sensitive data security access management method and system

    CN118656870A