Data processing method and device, equipment, storage medium and computer program product

By packaging and processing the raw data to form the target data volume, the problem of needing connectors to enter the data space in existing technologies is solved. This enables data to flow in a self-protected, self-secure, and self-controlled manner, reducing development difficulty and cost, and fully leveraging the value of the data.

CN119583295BActive Publication Date: 2025-12-09CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411288863.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-13
Publication Date
2025-12-09
Estimated Expiration
2044-09-13

AI Technical Summary

Technical Problem

In existing technologies, each data transaction requires a connector to be provided on the participating node side before data can enter the data space, which makes data space application development difficult and costly, and makes it difficult to realize the value of data.

Method used

By packaging the raw data sent by the first data node, a target data body is formed, including data attribute information, data usage control information, and data security information. Data can flow without setting up additional connectors, and the data body is generated in the data space for application usage control.

Benefits of technology

It enables data circulation that is self-protected, self-secured, and self-controlled, reducing the difficulty and cost of developing data space applications and fully leveraging the value of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119583295B_ABST
    Figure CN119583295B_ABST
Patent Text Reader

Abstract

The application discloses a data processing method, device, equipment, storage medium and computer program product. The method comprises the following steps: obtaining original data sent by a first data node; performing packaging processing on the original data to obtain a target data body; the target data body comprises one or more of the following information: data attribute information, data use control information, data security information; transmitting the target data body to a data space, so as to generate a data body application corresponding to the target data body through a data body service in the data space, and transmitting the data body application to a second data node, so that the second data node controls the use of the data body application.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data service, and in particular to a data processing method and device, equipment, storage medium and computer program product. BACKGROUND

[0002] With the rapid development of digitization, the demand for data circulation and service is increasing, such as the wide application of the service system of data networking (DSSN, Data Switching Service Network). Data networking faces the data element circulation market, builds the next generation of intensive and efficient data circulation infrastructure across industries, regions, fields and subjects, provides a low-cost, efficient and reliable circulation environment for centralized transactions and decentralized transactions, meets the common needs of connection, computing power, security and compliance, and supports the efficient and healthy development of the national data element circulation market.

[0003] Data space is the core solution to realize data security and reliable circulation, which is a data element circulation space connecting multiple data providers and data demanders. The mainstream data space solution is established by referring to the International Data Space (IDS) standard. Among them, the connector is the core component of IDS, which provides data integration, data usage control, computing and consumption capabilities, and realizes the circulation and controllable use of data between different domains through the connector.

[0004] However, each data transaction flow process requires the nodes participating in the process (including data providers and data demanders) to provide connectors to enter IDS, so as to control the use of data. It can be seen that the data circulation scheme based on the connector technology architecture of the related technology needs to set up additional components to circulate data, and after the development of data governance and other functions after circulation, the data space application is packaged and distributed to the connector through the application store to be used. The development of data space application is difficult and costly, and it is difficult to realize the use value of data. SUMMARY

[0005] To solve the technical problems in the related art, the embodiments of the present application provide a data processing method, device, equipment, storage medium and computer program product.

[0006] To achieve the above purpose, the technical scheme of the embodiments of the present application is as follows:

[0007] In a first aspect, the embodiments of the present application provide a data processing method, which comprises:

[0008] obtaining original data sent by a first data node;

[0009] The original data is packaged to obtain a target data body; the target data body includes one or more of the following information: data attribute information; data use control information; data security information;

[0010] The target data body is transmitted to a data space to generate a data body application corresponding to the target data body through a data body service in the data space, and the data body application is sent to a second data node to enable the second data node to perform use control on the data body application.

[0011] In a second aspect, the embodiments of the present application further provide a data processing apparatus, and the apparatus comprises:

[0012] An acquisition unit is configured to acquire original data sent by a first data node;

[0013] A first processing unit is configured to package the original data to obtain a target data body; the target data body includes one or more of the following information: data attribute information; data use control information; data security information;

[0014] A second processing unit is configured to transmit the target data body to a data space to generate a data body application corresponding to the target data body through a data body service in the data space, and send the data body application to a second data node to enable the second data node to perform use control on the data body application.

[0015] In a third aspect, the embodiments of the present application further provide a data processing device, which comprises a processor and a memory for storing a computer program capable of running on the processor;

[0016] When the processor runs the computer program, the processor performs the steps of the data processing method according to the embodiments of the present application.

[0017] In a fourth aspect, the embodiments of the present application further provide a storage medium having a computer program stored thereon, and the computer program is executed by a processor to implement the steps of the data processing method according to the embodiments of the present application.

[0018] In a fifth aspect, the embodiments of the present application further provide a computer program product comprising a computer program, and the computer program is executed by a processor to implement the steps of the data processing method according to the embodiments of the present application.

[0019] The data processing method, device, equipment, storage medium and computer program product provided by the embodiment of the application, the original data sent by the first data node is obtained; the original data is packaged and processed to obtain a target data body; the target data body includes one or more of the following information: data attribute information; data use control information; data security information; the target data body is transmitted to a data space to generate a data body application corresponding to the target data body through a data body service in the data space, and the data body application is sent to a second data node to enable the second data node to control the use of the data body application. The method of the embodiment of the application is used, the original data sent by the first data node is packaged and processed to obtain a target data body that can realize data bootstrap function (including data self-protection, self-security and self-control), without setting an additional component such as a connector, data circulation can be performed, that is, the target data body is transmitted to the data space, and after the data enters the data space, a data body application, that is, a data space application, is generated by using a data body service in the data space, and the data space application is sent to the second data node for use control. It can be seen that the data service transaction function can be realized without the connector, the data space application development difficulty and cost are reduced, and the use value of the data is fully utilized. BRIEF DESCRIPTION OF DRAWINGS

[0020] Figure 1 A network architecture diagram for data circulation in the related art;

[0021] Figure 2 An interaction diagram of technical components of an IDS scheme in the related art;

[0022] Figure 3 A component architecture diagram of a connector in the related art;

[0023] Figure 4 A flowchart of the data processing method of the embodiment of the application Figure 1 ;

[0024] Figure 5 A structure diagram of the target data body of the embodiment of the application;

[0025] Figure 6 A data format diagram of the target data body of the embodiment of the application;

[0026] Figure 7 A flowchart of the data processing method of the embodiment of the application Figure 2 ;

[0027] Figure 8 A structure diagram of the data body service of the embodiment of the application;

[0028] Figure 9Architecture diagram of a data processing device according to an embodiment of the present application;

[0029] Figure 10 Architecture diagram of a data processing device according to an embodiment of the present application;

[0030] Figure 11 Architecture diagram of a data processing device according to an embodiment of the present application;

[0031] Figure 12 Architecture diagram of a data processing device according to an embodiment of the present application;

[0032] Figure 13 Architecture diagram of a data processing device according to an embodiment of the present application; DETAILED DESCRIPTION

[0033] The present application will be further described in detail below with reference to the accompanying drawings and embodiments.

[0034] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used in the description herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the present application.

[0035] At present, the National Data Bureau jointly with 16 departments issued the "Data Element X" Three-Year Action Plan (2024-2026), the purpose is to make the "sleeping" data "live", combined with the basic conditions and data endowment of different industries, to excavate and release data element typical field application scenarios, taking the scene as the traction, to promote the supply and circulation of data elements, and to accelerate the process of data element, so as to better realize the value of data, and build a digital economy based on data as the key element.

[0036] From the perspective of circulation and utilization, it is necessary to establish data infrastructure. In the traditional transaction market, the data flow and use mode are often controlled through exclusive possession of goods. The replication cost of plaintext data tends to be zero, and once the transaction is reached, the data holder (i.e. data supplier, which can be understood as seller node) not only loses control of the data, but also bears the security risk of data transaction, which leads to the "unwillingness to circulate" and "dare not to circulate" of the data holder. Therefore, to promote data circulation, it is necessary to accelerate the construction of data infrastructure to establish a reliable circulation system, use secure multi-party computation (MPC) and blockchain technology, so that the data supplier can effectively control the purpose, mode, flow of data use, realize the functions of "available but invisible" and "controllable and measurable" of data circulation, protect data security, prevent leakage risk, and realize the controllability of data.

[0037] From the perspective of security governance, new challenges are posed to data governance methods, and it is necessary to explore a security governance model that adapts to the characteristics of data. The digital economy, which takes data as a key element, is highly innovative, widely covered, and strongly penetrative. While expanding and extending the connotation of traditional productive forces, it has posed challenges to the traditional regulatory model. On the one hand, the process of large-scale circulation of data is also the process of fusion of multi-source and multi-party data. Once leaked or misused, it may lead to data leakage of personal privacy, trade secrets, etc., affecting privacy protection, industrial development, and even posing a challenge to national security. On the other hand, the digital economy has the characteristics of cross-border integration, which poses a challenge to the traditional division of industry regulation and territorial regulation. Therefore, how to achieve good economic benefits at an appropriate security cost, as well as high-quality development and utilization and high-level security benign interaction, and how to improve regulatory efficiency and build a digital governance system that takes into account vitality and order, need to be explored by all parties.

[0038] The network of numbers is a data element circulation market-oriented information service system relying on the connection + computing power + ability of China Mobile, which builds the next generation of intensive and efficient data circulation infrastructure across industries, regions, fields and subjects, provides a low-cost, efficient and reliable circulation environment for centralized transactions and decentralized transactions, meets the common needs of connection, computing power, security and compliance, and supports the efficient and healthy development of the national data element circulation market.

[0039] Figure 1 The network architecture of data circulation in related technologies is shown in the following figure: Figure 1As shown, a data service node (DSN) is deployed at a data provider to implement core functions such as data source docking, DSSN private network access, and data security calculation, and can provide different forms of products according to customer needs, wherein the DSN product forms include a standard version (such as a software form) and an enhanced version (such as a hardware form with high performance and security requirements). The DSN accesses the DSSN private network (which is a data sharing virtual private network based on existing network facilities to ensure the security and quality of service of data transmission) with the provided data, transmits the data to a data sharing platform (DSP) through an IF-2 DSN management interface, and the data sharing platform is used to provide services such as data access, task scheduling, reliable transmission, and secure calculation, and transmits the data to an industry application platform (such as a data flow transaction platform / service platform, etc.) through an IF-1 flow service interface to generate corresponding data applications. The data applications are transmitted to the data sharing platform through the IF-1 flow service interface, and are issued to a data requirement node (DRN) for use control through an IF-2 data requirement node (DRN) management interface, wherein the DRN is deployed at a data demander to implement core functions such as business system docking, DSSN private network access, visual development, and data security calculation, and can provide different forms of products according to customer needs, wherein the DRN product forms include a standard version (such as a software form with standard deployment) and a lightweight version (such as a software form with lightweight deployment). It should be noted that the DSN and the DRN can interoperate through an IF-3 DSN / DRN interconnection interface.

[0040] A data space is a core solution for realizing data security and trusted flow, which is a data element flow space connecting multiple data providers and data demanders. Under the premise of ensuring data use safety and compliance, it provides "data logistics" services for data commodity flow, such as data and data product information publishing, transaction negotiation, data transaction, data clearing, audit supervision, data pricing, billing, and other services. The number network is based on the principles of on-demand access, algorithm network foundation, secure sharing, open cooperation, and controllable management, and constructs a trusted data and algorithm integrated service network to achieve five goals: data access nearby, wide coverage flow network, trusted data delivery, secure and controllable management, and full compliance and certification.

[0041] The current mainstream data space solution is established with reference to the IDS standard, wherein the IDS can be Huawei's cloud exchange data space (EDS), Tsinghua's Qingyan data space, etc.

[0042] IDS is a virtual architecture for secure data sharing based on standard communication interfaces proposed by Fraunhofer Institute in Germany. The original name of this scheme is Industrial Data Space, which aims to solve the conflict between data protection and data sharing in the increasingly complex data services and new digital business models. Later, it was extended to enterprise entities across industries and even across geographical boundaries, so it was renamed International Data Space, and the corresponding International Data Space Association (IDSA) was established. So far, IDS has been applied in Europe and Japan, mainly in the fields of industry, mobile travel, energy, etc.

[0043] In 2020, the Ministry of Industry and Information Technology issued the Guidance on the Development of Industrial Big Data, which proposed the key task of building an industrial data space. In 2021, the Ministry of Industry and Information Technology issued the Three-Year Action Plan for the Innovative Development of Industrial Internet (2021-2023), which again proposed to explore the establishment of an industrial data space and promote data sharing. In January 2022, the Trusted Industrial Data Space Ecosystem Conference held by China Information and Communication Research Institute released the Trusted Industrial Data Space System Architecture 1.0 white paper, which proposed the preliminary architecture and standard system of the trusted industrial data space. In September 2022, Shuxin Technology released the Domain Data Space (DDS) based on in-depth research of the IDSA reference architecture, combined with domestic characteristics and needs. This is the first commercial product for data space based on data sovereignty control, data cross-domain, distribution, use, and connection. In the same year, Huawei launched the cloud service product-Cloud EDS, which designed the key of data space based on the framework of "trusted, controllable, and certifiable" to create full-stack capabilities for data controllable exchange. In 2023, Qingyan Technology released the new generation of data space solution SAFER (Security-Access control-Fairness-Efficiency-Regulation), which is developed based on IDS. Currently, Qingyan Technology is upgrading SAFER to support functions such as privacy computing.

[0044] Figure 2For the interaction diagram of the technical components of the IDS solution in the related art, from the architecture level, the IDS is actually a distributed network space connected by IDS connectors (which can be referred to as connectors) or other core components (metadata broker, clearing house, app store, vocabulary hub) and different participants. The functions of the above-mentioned several core components are described below.

[0045] The connector is the core component of the IDS, mainly providing data integration, data usage control, computing and consumption capabilities, and the flow and controllable use of data between different domains can be realized through the connector. The core of the connector is the data usage strategy engine, Figure 3 For the composition architecture diagram of the connector in the related art, as shown in Figure 3 The connector includes the following function points: policy administration point (PAP), policy enforcement point (PEP), policy information point (PIP), policy execution point (PXP), policy management point (PMP) and policy decision point (PDP).

[0046] The metadata broker is a connector used for registration, publishing, maintaining and querying self-describing endpoints. The IDS connector providing services or data can send its self-description to the metadata broker, so that each participant can find it in the data space. The IDS metadata broker can be understood as a telephone book. In a data space, there can be multiple IDS metadata brokers, allowing the distribution of metadata broker functions.

[0047] The clearing house is based on all system log recording services to clear, bill and audit information related to usage control.

[0048] The app store is a secure platform for distributing applications, supporting application registration, publishing, maintenance and query operations, and operations for pre-configuring applications to the connectors of application users. Third-party applications can use the connector trusted environment to implement business logic services, which can be downloaded through the IDS app store and deployed, executed and managed on the connector.

[0049] The vocabulary hub provides developers of domain-specific vocabularies with tools and functions to create, improve and publish terms.

[0050] However, in the related art, a connector needs to be provided at each node (including a data provider and a data demander) participating in each data transaction process to enter an IDS, so as to control the use of data, that is, an additional component needs to be set to circulate data, and after the circulation of data, data management and data production links such as conversion, analysis, and calculation of data need to be developed based on a connector technology architecture to package data space applications and distribute them to the connector through an application store for use. The development of data space applications is difficult and costly, and it is difficult to realize the use value of data.

[0051] Therefore, in various embodiments of the present application, the original data sent by the first data node is packaged to obtain a target data body capable of realizing data bootstrap functions (including data self-protection, self-security, and self-control), and data circulation can be performed without setting an additional component such as a connector, that is, the target data body is transmitted to a data space, and after the data enters the data space, a data body application, that is, a data space application, is generated by using a data body service in the data space, and the data space application is sent to the second data node for use control. It can be seen that the data service transaction function can be realized without a connector, the development difficulty and cost of the data space application are reduced, and the use value of data is fully realized.

[0052] The embodiments of the present application provide a data processing method, which is applied to a data processing device, Figure 4 The flow of the data processing method of the embodiments of the present application is shown in Figure 1 ; as Figure 4 shown, the data processing method comprises the following steps.

[0053] Step 401: Obtain original data sent by a first data node.

[0054] In the embodiments of the present application, the first data node represents a data provider, which can be understood as a party providing data, and ensures that the provided data is accurate, complete, and timely.

[0055] Here, the original data provided by the first data node is the data body, specifically including unstructured data, structured data, semi-structured data, and other data original information. For example, the unstructured data can include but is not limited to files, pictures, videos, and other data.

[0056] Step 402: Package the original data to obtain a target data body.

[0057] In the embodiments of the present application, the target data body includes one or more of the following information: data attribute information; data use control information; and data security information.

[0058] In response to the problem in related technologies that each data transaction requires a connector on the node participating in the process to enter the IDS and thus control data usage, i.e., additional components are needed for data circulation, this application embodiment packages the original data to form a data body (corresponding to the aforementioned target data body) with basic data attributes (corresponding to the aforementioned data attribute information), data usage control (such as data access control), data security, and other information. In other words, this application embodiment uses the data body method to achieve data bootstrapping, including data self-protection, self-security, and self-control functions, without the need to set up additional components such as connectors, so that data circulation can be carried out, i.e., the target data body can be transmitted to the data space.

[0059] Figure 5 This is a schematic diagram of the structure of the target data body in an embodiment of this application, as shown below. Figure 5 As shown, based on the packaging and processing of the original data, the target data body can be obtained. The target data body includes one or more of the following information: data attribute information; data usage control information; and data security information. It should be noted that data attribute information includes the data's unique identifier (ID), data type, data timestamp, data location information, and data owner. The data type can include, but is not limited to, file, table, row, column, and cell types. Data usage control information includes data usage methods (including data user information), data access control information (including data classification, hierarchical information, etc.), control policies, and policy enforcement information. Data security information includes security authentication, encryption / obfuscation methods, and tags.

[0060] Figure 6 This is a schematic diagram of the data format of the target data body in an embodiment of this application, such as... Figure 6 As shown, the data format of the target data body may include, but is not limited to: version number, serial number, data size, encryption method, security authentication, usage method, policy control, policy execution, data body ID, data type, data location, timestamp, data owner, etc. Specifically, after obtaining the raw data sent by the first data node, the data processing device serializes and encodes the raw data to obtain the target data body in the above-mentioned data format, for example, located at... Figure 5 The outermost target data volume.

[0061] Based on this, in one embodiment, the step of packaging the original data to obtain the target data body includes: serializing the original data to obtain serialized result data; and encoding the serialized result data to obtain the target data body.

[0062] Here, the serialization of the original data is actually a process of converting the original data into a storable or transmittable format, which usually refers to a string format or a binary format. The purpose of data serialization is to enable the complex data structure to be transmitted in the network or stored on the disk (for example, to persistently store the complex data structure to the database or file system), while maintaining its original structure and data.

[0063] Here, the data processing apparatus performs an encoding process on the serialized result data after serializing the original data to obtain the serialized result data. The encoding of the serialized result data is actually a process of converting the serialized result data into a data body specific format for storage, transmission or further data processing, wherein the further data processing includes data compression processing to reduce the volume of data and save storage space and transmission bandwidth; the further data processing also includes data encryption processing to protect the security and privacy of the data and prevent unauthorized access; the further data processing also includes verifying the integrity and source of the data through digital signature technology, and can also include detecting errors of the data in the transmission or storage process through methods such as adding checksums and / or using cyclic redundancy check (CRC).

[0064] In practical applications, the data processing apparatus can determine the serialization format used for serializing the original data according to the use scenario of the original data.

[0065] Based on this, in an embodiment, the serialization of the original data to obtain the serialized result data includes: determining a serialization format based on the use scenario of the original data; serializing the original data based on the determined serialization format to obtain the serialized result data.

[0066] In the embodiments of the present application, the use scenario of the original data can include but is not limited to: point-to-point transaction of the original data, one-to-many transaction, etc. Here, the serialization format can include but is not limited to: lightweight data exchange format (JSON, Java Script Object Notation), extensible markup language (XML, Extensible Markup Language), YAML format (a format with high readability used to express data serialization) and binary format, etc.

[0067] Step 403: transmitting the target data body to the data space to generate a data body application corresponding to the target data body through a data body service in the data space, and sending the data body application to a second data node to enable the second data node to use control the data body application.

[0068] In the embodiments of the present application, the second data node represents a data consumer, i.e., a data demander, which can be understood as a party using data.

[0069] In an embodiment, the transmitting the target data body to the data space comprises:

[0070] transmitting the target data body to the data space through networking.

[0071] In actual application, the data processing apparatus can divide the data body service into three types according to the use scenario of the original data: data body adaptation service, data body processing service, and data body control service. Among them, the data body adaptation service is used for the adaptation of the data body service and the external system and internal management, including data serialization and deserialization, data encoding and decoding, registration of the data body service, version management of the data body service, etc.

[0072] Based on this, in an embodiment, the data body service comprises a data body adaptation service; after the transmitting the target data body to the data space, the method further comprises:

[0073] decoding the target data body through the data body adaptation service to obtain decoded data;

[0074] deserializing the decoded data through the data body adaptation service to obtain the original data, and performing distributed storage on the original data.

[0075] Here, the decoding process of the target data body is the inverse process of encoding, that is, the encoded target data body is decoded through the data body adaptation service to obtain decoded data, that is, the decoded data is actually the data converted from the encoded target data body to its original data format.

[0076] Here, when transmitting data in the network, the original data needs to be serialized at the sending end before being sent, and correspondingly, the decoded data needs to be deserialized at the receiving end before being stored. It should be noted that deserialization is the inverse process of serialization, that is, the process of converting the serialized data body, such as the decoded data of the target data body, into the original data structure or object state. The deserialization operation enables data to be effectively exchanged between different systems, services or applications, while ensuring the integrity and availability of data.

[0077] In actual application, in order to enable the data in the target data body to be used in scenarios such as circulation, storage, calculation, modeling, etc., the data body processing service can read and analyze the original data and related data usage policy in the target data body, and perform data processing on the target data body according to the data usage policy to obtain a corresponding data processing result.

[0078] Based on this, in an embodiment, the data body service further includes a data body processing service; after the target data body is transmitted to the data space, the method further includes:

[0079] performing data processing on the target data body by the data body processing service to obtain a corresponding data processing result;

[0080] Among them, the data processing includes one of the following processing methods: data cleaning; data query; data conversion; data analysis; data mining.

[0081] Here, in actual application, in an embodiment, the data body service further includes a data body control service; the target data body is transmitted to the data space to generate a data body application corresponding to the target data body through the data body service in the data space, including:

[0082] The target data body is transmitted to the data space to arrange the target data body service through the data body control service in the data space to generate a data body application corresponding to the target data body.

[0083] Here, the service arrangement component is a core component in the data body control service, responsible for multiple key functions, can effectively manage the routing communication between data body services, provide flexible traffic control and strong security guarantee, therefore, the service arrangement component in the data body control service can be used to arrange the target data body service to generate a data body application corresponding to the target data body.

[0084] In actual application, in an embodiment, the target data body service is arranged to generate a data body application corresponding to the target data body, including:

[0085] The target data body is analyzed to obtain data usage control information;

[0086] Based on the data usage control information, the target data body service is arranged to generate a data body application corresponding to the target data body.

[0087] Here, since the target data volume includes data usage control information, the data usage control information is obtained by parsing the target data volume, and a control strategy in the data usage control information is used to arrange the target data volume service to generate a data volume application corresponding to the target data volume.

[0088] Here, the data volume application can be understood as a data volume product. After the data volume application corresponding to the target data volume is generated, the data volume application can be put on sale on a product store (also referred to as an application store (App Store)) for users to use.

[0089] In actual application, in an embodiment, after the data volume application is generated by arranging the target data volume service based on the data usage control information, the data volume application is transmitted to an application layer of the system to settle the data by a clearing and billing module of the application layer.

[0090] It should be noted that the data volume application can also be put on sale on the product store to display the data volume application through a user interface (UI) module of the application layer, or order management of the data through an order management module of the application layer, or audit monitoring of the data through an audit monitoring module of the application layer.

[0091] In actual application, since the data processing apparatus divides the data volume service into three types according to the usage scenario of the original data: data volume adaptation service, data volume processing service, and data volume control service, a network formed by multiple data volume services is formed in the data space, and the three service types correspond to a data volume adaptation service layer, a data volume processing service layer, and a data volume control service layer in the network respectively.

[0092] In an embodiment, the method further includes: constructing the data space.

[0093] The constructing the data space includes: constructing the data space based on the target data volume, the data volume service, and the data volume application.

[0094] Here, the target data volume, the data volume service (including the data volume adaptation service, the data volume processing service, and the data volume control service), and the data volume application form a data space based on a data network.

[0095] The embodiment of the application further provides another data processing method, which is applied to a data processing apparatus, Figure 7 The flowchart of the data processing method of the embodiment of the application is shown in FIG. 2. Figure 2 Figure 7 ​As shown, the data processing method comprises:

[0096] Step 701: obtaining original data sent by a first data node.

[0097] Step 702: serializing the original data to obtain serialized result data.

[0098] In an embodiment, the serializing the original data to obtain serialized result data comprises: determining a serialization format based on a use scenario of the original data; and serializing the original data based on the determined serialization format to obtain the serialized result data.

[0099] Step 703: encoding the serialized result data to obtain a target data body.

[0100] In an embodiment of the present application, the target data body comprises one or more of the following information: data attribute information; data use control information; and data security information.

[0101] Step 704: transmitting the target data body to a data space through networking to arrange a target data body service through a data body control service in the data space, so as to generate a data body application corresponding to the target data body.

[0102] In an embodiment of the present application, the arranging the target data body service to generate the data body application corresponding to the target data body comprises:

[0103] analyzing the target data body to obtain data use control information; and arranging the target data body service based on the data use control information to generate the data body application corresponding to the target data body.

[0104] In an embodiment, the method further comprises: constructing the data space;

[0105] The constructing the data space comprises: constructing the data space based on the target data body, the data body service and the data body application.

[0106] In an embodiment, the data body service comprises a data body adaptation service; and after the transmitting the target data body to the data space, the method further comprises:

[0107] decoding the target data body through the data body adaptation service to obtain decoded data;

[0108] de-serializing the decoded data through the data body adaptation service to obtain the original data, and performing distributed storage on the original data.

[0109] In an embodiment, the data body service further comprises a data body processing service; after the target data body is transmitted to the data space, the method further comprises:

[0110] performing data processing on the target data body through the data body processing service to obtain a corresponding data processing result;

[0111] The data processing comprises one of the following processing modes: data cleaning, data query, data conversion, data analysis, and data mining.

[0112] Step 705: sending the data body application to the second data node to enable the second data node to use control the data body application.

[0113] It should be noted that the specific processing process of the data processing device for data processing has been described in detail above, and will not be repeated here.

[0114] By adopting the technical solution of the embodiment of the present application, the original data sent by the first data node is packaged to obtain a target data body that can realize data bootstrap function (including data self-protection, self-security, and self-control), without the need to set an additional component such as a connector, the data flow can be circulated, that is, the target data body is transmitted to the data space, and after the data enters the data space, a data body application, that is, a data space application, is generated by using the data body service in the data space, and the data space application is sent to the second data node for use control. It can be seen that the data service transaction function can be realized without the connector, which reduces the development difficulty and cost of the data space application and fully utilizes the use value of the data.

[0115] The present application will be described below in conjunction with application examples.

[0116] The data flow circulation scheme in the related art has the following problems:

[0117] 1. In the current data space scheme, a connector needs to be provided on the side of the node participating in each data transaction flow process (such as a data provider and a data consumer) to enter the data space such as IDS, so as to enable the data to be used for control.

[0118] 2. The conversion, analysis, calculation, and other data management and data production links of the circulated data need to be developed based on the connector technology architecture to package the data management function into a data space application, which is distributed to the connector for use through the application store. It can be seen that the data space application has a large development difficulty, low reusability, and high cost, and it is difficult to utilize the use value of the data.

[0119] 3. The current connector containing the data usage control scheme must rely on external environments such as a trusted execution environment (TEE) and a secure environment such as a trusted container to ensure data security and data usage control, and cannot achieve the boot function of data security and data usage control.

[0120] 4. The current data space scheme uses a connector as the underlying layer, and more uses the scene of point-to-point transaction, and cannot solve the problem of availability in the functions of "available but invisible" and "controllable and measurable" in data circulation.

[0121] To solve the above problems, the application packages the original data to form a data body (corresponding to the target data body) with data basic attributes (corresponding to the data attribute information described above), data usage control, data security and other information.

[0122] The original data is the data body, which can include unstructured data (such as file, picture, video and other data), structured data, semi-structured data (such as parquet) and other data original information. The data basic attribute includes the unique ID of the data, the data type (such as file, table, row, column, cell and other data types), the data timestamp, the data location information, the data owner and other information. The data usage control information includes the data usage mode, the data access control information (such as data classification, grading and other related information), the control strategy, the strategy execution and other information. The data security information includes the security authentication, the encryption confusion mode, the label and other information.

[0123] Figure 8 The structure diagram of the data body service of the embodiment of the application is shown in Figure 8 The internal structure of the data body service includes the following modules: an application programming interface (API) service, a storage engine, a computing engine, and a service agent.

[0124] In order to enable the data in the data body to be used in the scenes of circulation, storage, calculation, modeling and the like, the data body service can read and analyze the data body and related data usage strategy, store data using the storage engine inside the data body service according to the data usage strategy, and analyze and calculate data using the computing engine inside the data body service, can realize the functions of interconnection, security management, policy execution and the like of the data body service through the service agent, and can provide data access service functions to the outside through the API service and the like.

[0125] According to the use scene of the original data, the data body service can be divided into three types, namely, a data body adaptation service, a data body processing service, and a data body control service. The three types of data body services will be described below.

[0126] Data body adaptation service: This service is used for the adaptation of data body services with external systems and internal management, including data serialization and deserialization, data encoding and decoding, data body service registration, data body service version management, etc.

[0127] Here, data serialization and deserialization are two key concepts in data body adaptation services, used in data storage, transmission and communication processes, including:

[0128] Network communication: When transmitting data in a network, the original data needs to be serialized before being sent from the sending end, and deserialized at the receiving end.

[0129] Data storage: When persistently storing data to a database or file system, data serialization and deserialization are usually required before storage.

[0130] Distributed system: In a distributed system, when making remote calls between data body services, request and response data need to be serialized.

[0131] Among them, data serialization is the process of converting raw data or its object state into a format that can be stored or transmitted (usually a string or binary format). The purpose of data serialization is to enable complex data structures to be transmitted over a network or stored on a disk while maintaining their original structure and data. According to the use scenario, the serialization format includes JSON, XML, YAML, binary format, etc.

[0132] Data deserialization is the inverse process of data serialization, which is the process of converting serialized data bodies into original data structures or object states. Data deserialization enables data to be effectively exchanged between different systems, services or applications, while ensuring data integrity and availability.

[0133] Data encoding and decoding is the process of encoding and decoding data, including:

[0134] Encoding: The process of converting data into a specific format of data body to facilitate storage, transmission or further processing, where further processing includes data compression process to reduce data volume, save storage space and transmission bandwidth; data encryption process to protect data security and privacy, prevent unauthorized access; verify data integrity and source through digital signature technology; detect errors in data transmission or storage process through checksum and / or CRC methods, etc.

[0135] Decoding: The inverse process of encoding, which is the process of converting encoded data bodies into their original data format.

[0136] Data body processing service: This service is used to read the original data in the data body and the data usage policy, and process the data according to the data usage policy, such as data cleaning, data query, data conversion, data analysis and data mining, etc.

[0137] (1) Data cleaning: Correct or delete incorrect data records through data cleaning techniques, such as removing duplicates, correcting format errors and filling missing values; implement data verification rules to ensure the accuracy and integrity of new data.

[0138] (2) Data query: A key function for efficiently retrieving, filtering, sorting and analyzing information from data bodies or data storage, usually including building conditional queries, applying logical operators, performing grouping and aggregation operations, merging multiple data sources, deduplication, pagination, full-text search, regular expression matching, time series and spatial data queries, data pivoting and result caching, etc.

[0139] (3) Data conversion: Data integration and merging data from different sources, data conversion redefines the organization of data elements through data mapping to adapt to specific data models or systems.

[0140] (4) Data analysis: Includes calculating mean, median, mode, variance, standard deviation, etc. to describe the basic characteristics of data; inferential statistics such as hypothesis testing and confidence intervals for inferring population characteristics from sample data; correlation and regression analysis to determine the relationship between variables; time series analysis to process and predict trends and patterns in time series data; and data visualization through charts and graphs to make analysis results easier to understand and interpret.

[0141] (5) Data mining: The process of extracting (mining) valuable information or knowledge from large amounts of data through algorithms and statistical models. This information or knowledge can be used to predict future trends, identify patterns, establish relationships and make decisions.

[0142] Data body control service, mainly including service orchestration component, service policy control component, service configuration component, authentication and authorization component, service monitoring component; wherein,

[0143] Service orchestration component is the core component of data body control service, responsible for multiple key functions, can effectively manage the routing communication between data body services, provide flexible traffic control and strong security protection, mainly including the following function modules:

[0144] Service registration: When the service instance starts, it registers its network location (such as IP address and port number) and metadata (such as service version, function description, etc.) in the service registry center.

[0145] Service Discovery: This module integrates with the underlying service discovery mechanism of K8s (such as Kubernetes) to monitor the registration and deregistration of services, ensuring that traffic can be routed to the correct target.

[0146] Route Management: Dynamically discovers service instances and incorporates them into routing decisions, defining the flow path of requests in the service network, including entry points, exit points, and intermediate service hops, while managing and optimizing the network topology between services.

[0147] Traffic Management: Supports complex traffic management functions, including traffic splitting, A / B testing, canary deployment, traffic mirroring, and fault injection.

[0148] Load Balancing: Performs load balancing between service instances and dynamically updates load balancing rules according to configured policies to achieve balanced distribution of requests.

[0149] Dependency Management: Tracks dependencies between services to properly manage and coordinate services during service updates or re-deployments.

[0150] Version Management: Supports multi-version registration of services, allowing clients to select specific versions of services as needed, and manages smooth updates and version rolling of services to reduce service interruptions.

[0151] Security: Responsible for managing the Transport Layer Security (TLS) certificates of the data body service agent, implementing mutual authentication and encrypted communication between services to ensure communication security.

[0152] Service Policy Control Component: Manages internal policies of data bodies, security policies of data body services, including access control and authentication policies, usage policies, etc. Mainly includes the following functional modules:

[0153] Policy Control: Responsible for implementing access control policies for data body services to ensure that inter-service communication complies with established security policies, while data body usage control policies are checked.

[0154] Policy Management: Used to manage usage-related policies, covering the entire life cycle of policies, including instantiation, deployment, and updates. In addition to data body service configuration, it also includes data body usage control policy configuration-related functions, i.e. rule definition of usage policy: who can access data, what purpose data can be used for, usage restrictions of data, etc. 21 kinds of data usage policies.

[0155] Policy Execution: Based on decision rules, some additional operations are performed, such as sending emails after data usage is completed, writing to specific log systems, etc.

[0156] Policy information: provides missing information for related decisions, and can also be used to obtain context information related to the behavior of the interception system, such as data flow information, the geographical location of the requesting device, etc.

[0157] Policy decision: according to the policy specified by policy management, call policy information to obtain related information, perform policy evaluation on events and trigger policy to perform additional operations.

[0158] Policy audit: collect policy log data, authorization data, and monitoring data between services, provide observability for the system, and synchronize to the upper layer clearing and audit center.

[0159] Service configuration component, responsible for verifying, collecting, processing and distributing the configuration of data body service, used to simplify the management of system configuration, improve the reliability and flexibility of configuration, reduce configuration errors and inconsistencies, improve system stability and maintainability, mainly including the following function modules:

[0160] Configuration template: responsible for generating configuration using templates, which can be customized to meet different deployment needs.

[0161] Configuration processing: responsible for processing configuration, including verifying, parsing, converting and standardizing configuration.

[0162] Configuration distribution: responsible for distributing processed configuration to other components, such as service discovery orchestration component and service monitoring component.

[0163] Configuration monitoring: responsible for monitoring changes in configuration and updating configuration information in real time.

[0164] Authentication and authorization component: used to manage the keys and certificates of data body and data body service, to ensure the communication security of data body and data body service; at the same time, responsible for verifying the identity of data body and data body service, and authorizing them to access specific resources or perform specific operations, mainly including the following function modules:

[0165] Certificate issuance management: automatically issues TLS certificates for all services and data bodies in the service network, and is responsible for the life cycle management of the TLS certificates.

[0166] Identity verification: generates identity credentials for each service in the service network, ensures the verifiability and security of inter-service communication, and provides authentication services.

[0167] Security configuration distribution: distributes security configuration and certificates to data body service agents, ensuring that they can communicate securely with other services.

[0168] Audit and monitoring: support audit and monitoring of security configuration, help operation and maintenance personnel understand the security status of the service network.

[0169] A service monitoring component, including monitoring data collection and synchronization, specifically for collecting log data, authorization data, monitoring data, and stress test data between services, providing observability data for the system, and synchronizing to the upper clearing and audit center.

[0170] Figure 9 A schematic diagram of the architecture of the data body service in the data space of the embodiments of the present application is shown in Figure 9 A network composed of multiple data body services is formed in the data space, and the data body services can be divided into three types, namely data body adaptation service, data body processing service, and data body control service; wherein the data body adaptation service is used for data serialization and deserialization, data encoding and decoding, etc., the data body control service mainly includes service orchestration component, service policy control component, service configuration component, authentication and authorization component, and service monitoring component, the service orchestration component includes but is not limited to the following functional modules: service registration, service discovery, routing management, and traffic management; the service policy control component includes but is not limited to the following functional modules: policy decision, policy information, policy management, and policy execution; the service configuration component includes but is not limited to the following functional modules: configuration template, configuration processing, configuration distribution, and configuration monitoring; the authentication and authorization component includes but is not limited to the following functional modules: audit and monitoring, identity verification, certificate issuance management, and security configuration distribution. It should be noted that the description of the above functional modules can be referred to the above understanding, and will not be repeated here.

[0171] Figure 10 A schematic diagram of the architecture of the data processing device of the embodiments of the present application is shown in Figure 10 The data processing device includes, from bottom to top: device and running environment layer, cloud service infrastructure layer, data body adaptation service layer, data body processing service layer, data body control service layer, and application layer, wherein the device in the device and running environment layer can be a physical machine, a virtual machine, etc., and the running environment can be a secure environment such as TEE, trusted container, etc.; the cloud service infrastructure layer includes various cloud service infrastructures, such as infrastructures for microservice management, container management, task scheduling, resource scheduling, data storage, and stream computing engine; the data body adaptation service layer includes but is not limited to the following functional modules: data serialization and deserialization, and data encoding and decoding; the data body processing service layer includes but is not limited to the following functional modules: data cleaning, data query, data conversion, data aggregation, data statistics, and data mining; the data body control service layer includes but is not limited to the following functional modules: service orchestration, policy control, service configuration, authentication and authorization, and service monitoring; and the application layer includes but is not limited to the following functional modules: product store, order management, clearing and billing, audit and monitoring, and UI display.

[0172] Here, by orchestrating the data body service layer, any data usage requirement can be simply realized, and settlement can be performed through the clearing and billing module of the application layer. Meanwhile, the data body service that is orchestrated can be formed into a data body product (corresponding to the data body application described above), and the data body product can be put on the product store for sale.

[0173] Based on the architecture of the data processing apparatus, the data body, the data body service and the data body application form a data space based on the data network. Figure 11 A schematic diagram of the data flow process of the embodiment of the present application is shown in Figure 11 As shown, first, the original data is serialized, encoded and processed to form a data body (corresponding to the target data body described above). The data body adaptation service transmits the data body to the data space through the data network, and performs deserialization processing on the data body for distributed storage. Alternatively, the data body processing service can perform cleaning, querying, conversion, statistics and other processing on the data body. These data body services form a data body application under the orchestration of the control layer service (corresponding to the data body control service) for user use. The data body application can be displayed through a data big screen. The data body application can be a business intelligence (BI, Business Intelligence) application. After the data body application is generated, the data body application is issued to the client to perform data conversion, analysis, calculation and other data governance.

[0174] Compared with the method of the related art, the scheme of the present application has the following beneficial effects:

[0175] (1) Using the data body can realize data bootstrap, including data security, data usage control, access control, etc., without the need for additional components for data circulation.

[0176] (2) Using the data body service realizes functions such as data entering the data space to become a data service, data service orchestration, data service transaction, etc., solves flexible data usage, low cost, and fully utilizes the value of data.

[0177] In order to realize the data processing method of the embodiment of the present application, the embodiment of the present application further provides a data processing apparatus, Figure 12 A schematic diagram of the composition structure of the data processing apparatus of the embodiment of the present application is shown in Figure 12 The data processing apparatus comprises:

[0178] The acquisition unit 121 is configured to acquire the original data sent by the first data node.

[0179] The first processing unit 122 is configured to perform packaging processing on the original data to obtain a target data body; the target data body comprises one or more of the following information: data attribute information; data usage control information; data security information.

[0180] The second processing unit 123 is configured to transmit the target data body to a data space, so as to generate a data body application corresponding to the target data body through a data body service in the data space, and send the data body application to a second data node, so as to control usage of the data body application by the second data node.

[0181] In an embodiment, the first processing unit 122 comprises a serialization subunit and an encoding subunit; wherein,

[0182] The serialization subunit is configured to serialize the original data to obtain serialized result data.

[0183] The encoding subunit is configured to encode the serialized result data to obtain the target data body.

[0184] In an embodiment, the serialization subunit is specifically configured to:

[0185] determine a serialization format based on a usage scenario of the original data;

[0186] serialize the original data based on the determined serialization format to obtain the serialized result data.

[0187] In an embodiment, the second processing unit 123 is specifically configured to:

[0188] transmit the target data body to the data space through networking.

[0189] In an embodiment, the data body service comprises a data body adaptation service; the apparatus further comprises a decoding unit, a deserialization unit and a storage unit; wherein,

[0190] The decoding unit is configured to decode the target data body through the data body adaptation service to obtain decoded data after the second processing unit 123 transmits the target data body to the data space.

[0191] The deserialization unit is configured to deserialize the decoded data through the data body adaptation service to obtain the original data.

[0192] The storage unit is configured to perform distributed storage on the original data.

[0193] In an embodiment, the data cube service further comprises a data cube processing service; the apparatus further comprises: a third processing unit; wherein,

[0194] The third processing unit is configured to perform data processing on the target data cube through the data cube processing service to obtain a corresponding data processing result after the second processing unit 123 transmits the target data cube to the data space.

[0195] The data processing comprises one of the following processing modes: data cleaning, data query, data conversion, data analysis, and data mining.

[0196] In an embodiment, the data cube service further comprises a data cube control service; and the second processing unit 123 is specifically configured to:

[0197] transmit the target data cube to the data space, so as to arrange the target data cube service through the data cube control service in the data space, to generate a data cube application corresponding to the target data cube.

[0198] In another embodiment, the second processing unit 123 is further specifically configured to:

[0199] analyze the target data cube to obtain data usage control information;

[0200] arrange the target data cube service based on the data usage control information, to generate a data cube application corresponding to the target data cube.

[0201] In an embodiment, the apparatus further comprises: a construction unit; wherein,

[0202] The construction unit is configured to construct the data space.

[0203] The construction unit is specifically configured to:

[0204] construct the data space based on the target data cube, the data cube service, and the data cube application.

[0205] In actual application, the acquisition unit 121 can be implemented by a communication interface in a data processing apparatus; the first processing unit 122 and the second processing unit 123 can be implemented by a processor in the data processing apparatus.

[0206] It should be noted that the data processing apparatus provided in the above embodiments is only used for illustrating the division of the above program modules when performing data processing, and in actual application, the above processing can be completed by different program modules according to needs, that is, the internal structure of the apparatus is divided into different program modules to complete all or part of the above-described processing. In addition, the data processing apparatus and the data processing method provided in the above embodiments belong to the same concept, and the specific implementation process is described in the data processing method embodiments, which will not be repeated here.

[0207] Based on the hardware implementation of the above program modules, and in order to realize the data processing method of the embodiments of the application, the embodiments of the application also provide a data processing device, Figure 13 The hardware component structure of the data processing device of the embodiments of the application is shown in FIG. 13, which comprises: Figure 13

[0208] A communication interface 131 capable of information interaction with other devices;

[0209] A processor 132 connected with the communication interface 131 to realize information interaction with other devices, used for running a computer program to execute the data processing method provided above, and the computer program is stored on a memory 133.

[0210] Specifically, the communication interface 131 is configured to obtain original data sent by a first data node;

[0211] The processor 132 is configured to perform packaging processing on the original data to obtain a target data body; the target data body comprises one or more of the following information: data attribute information; data use control information; data security information; the target data body is transmitted to a data space to generate a data body application corresponding to the target data body through a data body service in the data space, and the data body application is sent to a second data node to enable the second data node to perform use control on the data body application.

[0212] In an embodiment, the processor 132 is specifically configured to:

[0213] Serializing the original data to obtain serialized result data;

[0214] Encoding the serialized result data to obtain the target data body.

[0215] In an embodiment, the processor 132 is specifically configured to:

[0216] Determining a serialization format based on a use scenario of the original data;

[0217] ​serialize the original data based on the determined serialization format, to obtain the serialized result data.

[0218] In an embodiment, the processor 132 is specifically configured to:

[0219] transmit the target data volume to the data space through networking.

[0220] In an embodiment, the data volume service includes a data volume adaptation service; the processor 132 is further configured to, after the transmission of the target data volume to the data space, decode the target data volume through the data volume adaptation service, to obtain decoded data.

[0221] de-serialize the decoded data through the data volume adaptation service, to obtain the original data, and store the original data in a distributed manner.

[0222] In an embodiment, the data volume service further includes a data volume processing service; the processor 132 is further configured to, after the transmission of the target data volume to the data space, perform data processing on the target data volume through the data volume processing service, to obtain corresponding data processing result.

[0223] The data processing includes one of the following processing modes: data cleaning, data query, data conversion, data analysis, and data mining.

[0224] In an embodiment, the data volume service further includes a data volume control service; the processor 132 is specifically configured to:

[0225] transmit the target data volume to the data space, to arrange the target data volume service through the data volume control service in the data space, to generate a data volume application corresponding to the target data volume.

[0226] In an embodiment, the processor 132 is specifically configured to:

[0227] analyze the target data volume, to obtain data usage control information;

[0228] arrange the target data volume service based on the data usage control information, to generate a data volume application corresponding to the target data volume.

[0229] In an embodiment, the processor 132 is further configured to construct the data space.

[0230] The processor 132 is specifically configured to:

[0231] Based on the target data volume, the data volume service and the data volume application, the data space is constructed.

[0232] It should be noted that the specific processing procedures of the communication interface 131 and the processor 132 can be understood with reference to the above data processing method.

[0233] Of course, in actual applications, various components in the data processing device 130 are coupled together through the bus system 134. It can be understood that the bus system 134 is used to realize the connection communication between the components. The bus system 134 includes not only a data bus, but also a power bus, a control bus and a status signal bus. However, in order to clearly illustrate, all kinds of buses are marked as the bus system 134 in the Figure 13 .

[0234] The memory 133 in the embodiment of the present application is used to store various types of data to support the operation of the data processing device 130. Examples of these data include any computer programs used for operation on the data processing device 130.

[0235] The data processing method disclosed in the above embodiment of the present application can be applied to the processor 132 or implemented by the processor 132. The processor 132 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above data processing method can be completed by integrated logic circuits or instructions in the form of software in the processor 132. The above processor 132 can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 132 can implement or execute the data processing methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the data processing method disclosed in the embodiments of the present application, the hardware decoding processor can be directly executed to complete, or the hardware and software modules in the decoding processor can be combined to complete. The software module can be located in the storage medium, which is located in the memory 133, and the processor 132 reads the information in the memory 133 and combines the hardware to complete the steps of the above data processing method.

[0236] In an exemplary embodiment, the data processing device 130 can be implemented by one or more of an Application Specific Integrated Circuit (ASIC), a DSP, a Programmable Logic Device (PLD), a Complex Programmable Logic Device (CPLD), a Field-Programmable Gate Array (FPGA), a general-purpose processor, a controller, a microcontroller (MCU), a microprocessor (Microprocessor), or other electronic elements for executing the aforementioned data processing method.

[0237] It can be understood that the memory 133 of the embodiments of the present application can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. The non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM). The magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example but not limitation, many forms of RAM can be used, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), sync link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memory 133 described in the embodiments of the present application is intended to include, but not limited to, these and any other suitable types of memories.

[0238] In the example embodiments, the embodiments of the present application also provide a storage medium, specifically a computer readable storage medium, such as the memory 133 storing a computer program executable by the processor 132 in the data processing device 130 to complete the steps of the data processing method described in the foregoing embodiments of the present application. The computer readable storage medium can be FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.

[0239] In the example embodiments, the embodiments of the present application also provide a computer program product including a computer program executable by the processor 132 in the data processing device 130 to complete the steps of the data processing method described in the foregoing embodiments of the present application.

[0240] It should be noted that "first", "second", "third", etc. are used to distinguish similar objects, and do not necessarily describe a specific order or sequence.

[0241] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.

[0242] The above is merely specific embodiments of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A data processing method, characterized by, The method comprises: obtaining original data sent by a first data node; performing packaging processing on the original data to obtain a target data body; the target data body comprises one or more of the following information: data attribute information; data use control information; data security information; transmitting the target data body to a data space to generate a data body application corresponding to the target data body through a data body service in the data space, and sending the data body application to a second data node to enable the second data node to perform use control on the data body application.

2. The method of claim 1, wherein, The packaging processing on the original data to obtain a target data body comprises: serializing the original data to obtain serialized result data; encoding the serialized result data to obtain the target data body.

3. The method of claim 2, wherein, The serialization of the original data to obtain serialized result data comprises: determining a serialization format based on a use scenario of the original data; serializing the original data based on the determined serialization format to obtain the serialized result data.

4. The method according to any one of claims 1 to 3, characterized in that, The transmission of the target data body to the data space comprises: transmitting the target data body to the data space through networking.

5. The method of claim 1, wherein, The data body service comprises a data body adaptation service; after the transmission of the target data body to the data space, the method further comprises: decoding the target data body through the data body adaptation service to obtain decoded data; de-serializing the decoded data through the data body adaptation service to obtain the original data, and performing distributed storage on the original data.

6. The method of claim 1, wherein, The data body service further comprises a data body processing service; after the transmission of the target data body to the data space, the method further comprises: performing data processing on the target data body through the data body processing service to obtain a corresponding data processing result; wherein the data processing comprises one of the following processing modes: data cleaning; data query; data conversion; data analysis; data mining.

7. The method of claim 1, wherein, The data body service further comprises a data body control service; The transmission of the target data body to the data space to generate a data body application corresponding to the target data body through a data body service in the data space comprises: transmitting the target data body to the data space to arrange the target data body service through the data body control service in the data space to generate a data body application corresponding to the target data body.

8. The method of claim 7, wherein, The arrangement of the target data body service to generate a data body application corresponding to the target data body comprises: analyzing the target data body to obtain data use control information; arranging the target data body service based on the data use control information to generate a data body application corresponding to the target data body.

9. The method of claim 1, wherein, The method further comprises constructing the data space; The construction of the data space comprises: constructing the data space based on the target data body, the data body service, and the data body application.

10. A data processing apparatus, characterized by, The apparatus comprises: an obtaining unit, configured to obtain original data sent by a first data node; A first processing unit is configured to perform a packaging process on the original data to obtain a target data body; the target data body comprises one or more of the following information: data attribute information; data usage control information; data security information; A second processing unit is configured to transmit the target data body to a data space, to generate a data body application corresponding to the target data body through a data body service in the data space, and to send the data body application to a second data node, so that the second data node performs usage control on the data body application.

11. A data processing device, characterized by Comprise: a processor and a memory for storing a computer program capable of running on the processor; wherein the processor is configured to execute the computer program to perform the steps of the method of any one of claims 1 to 9.

12. A storage medium having stored thereon a computer program, characterized in that The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 9.

13. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 9. The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 9.

Citation Information

Patent Citations

  • Industrial data secure transmission method based on international data space

    CN117880324A

  • Method for processing a data transport service

    US20230283664A1