Data transfer method, system and gateway device for heterogeneous data space
By designing the heterogeneous data space data flow conversion protocol (HDDSP) between heterogeneous data spaces and utilizing the blockchain verification mechanism, the security risks of data circulation and sharing between heterogeneous data spaces are solved, and efficient and trustworthy data flow is achieved.
Patent Information
- Application Number
- CN202510163945.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-14
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-02-14
AI Technical Summary
The prior art is difficult to realize data circulation and sharing between heterogeneous data spaces, especially in terms of data security, interface security and identity security, which leads to security risks.
By designing the heterogeneous data space data flow conversion protocol (HDDSP), the data source proof information and source data are converted into target data packets and verified using blockchain to ensure the trusted flow of data between heterogeneous data spaces.
It realizes efficient and trustworthy data flow between heterogeneous data spaces, breaks down the architectural design barriers of heterogeneous data spaces, reduces economic costs, and improves the security of data circulation.
Smart Images

Figure CN119652669B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of information security technology, and in particular, relates to a data flow method, system and gateway device for heterogeneous data space. Background Art
[0002] Technical research and application of data element sharing, circulation and value realization are being widely explored and carried out in various fields. Practice in a small range of fields such as government affairs, finance, medical care and industry has verified that through the existing data circulation technology, data security technology and data mining and analysis technology, data across data management domains can be "available", "flowable" and "relatively secure", thereby realizing the sharing, circulation and utilization of data elements within organizations.
[0003] With the vigorous development of the data element market and the effective verification of its effectiveness, under the competition in the data element market, various industries, fields, and organizations will purchase data circulation products from different manufacturers to build their own data space. The large-scale circulation and sharing of data elements within industries, fields, and organizations is just around the corner. But problems follow. First, when the market needs to open up the existing data space and share data between the data spaces of various manufacturers, the different data standards, different data open interfaces, and different data space architectures of various manufacturers will hinder the circulation and sharing of data elements across heterogeneous data spaces; in addition, different data space architectures lead to differences in data security, interface security, identity security, etc., which brings security risks to the circulation and sharing of data between heterogeneous data spaces.
[0004] At present, an exploratory interconnection scheme has been proposed around heterogeneous privacy computing platforms. However, the existing scheme only makes extension designs for specific privacy computing algorithm protocols in the interconnection scenarios between heterogeneous privacy computing platforms. Through such extension designs, privacy computing such as privacy data intersection can be realized between open source and closed source platforms. Therefore, the existing scheme has limitations and cannot fully cover the complete scenarios of data element sharing and circulation. For example, non-privacy data cannot be circulated and utilized between heterogeneous platforms, new privacy computing needs require targeted algorithm extension design, and endorsement institutions are required to build a trust system for cross-platform data computing.
[0005] Therefore, how to realize data flow in heterogeneous data space has become an urgent problem to be solved. Summary of the invention
[0006] The embodiments of the present application provide a data flow method, system and gateway device for heterogeneous data space, aiming to realize data flow in heterogeneous data space.
[0007] In a first aspect, an embodiment of the present application provides a data flow method for a heterogeneous data space, which is applied to a first gateway device, wherein the first gateway device is a heterogeneous data space gateway device adapted to a first data space, and the first data space is a data space that provides source data. The method comprises: obtaining data source certification information and the source data from the first data space, and uploading the data source certification information to a blockchain, wherein the data source certification information is used to characterize the identity of a target data source, and the target data source is a data source that accesses the first data space and provides the source data to the first data space; based on a heterogeneous data space data flow conversion protocol, converting the data source certification information and the source data into the first target data space; The first target data packet is sent to a second gateway device, wherein the heterogeneous data space data flow conversion protocol is used to define the data structure of heterogeneous data space data flow, and the data structure includes cross-data space message content and cross-data space message proof; the first target data packet is sent to a second gateway device, so that the second gateway device parses the first target data packet to obtain the data source proof information and the source data, and verifies the data source proof information based on the blockchain. After the verification, the source data is sent to the second data space, the second gateway device is a heterogeneous data space gateway device adapted to the second data space, the second data space is a data space for receiving the source data, and the first data space is heterogeneous with the second data space.
[0008] In one possible implementation, the data source proof information and the source data are converted into a first target data packet based on a heterogeneous data space data flow conversion protocol, including: based on the heterogeneous data space data flow conversion protocol, the data source proof information is written into a first field, and the source data is written into a second field to obtain the first target data packet, wherein the first field is used to represent a cross-data space message proof, and the second field is used to represent a cross-data space message content.
[0009] In a possible implementation, the data structure also includes a transaction identifier of the message on the trusted blockchain, and the method also includes: obtaining data processing proof information from the first data space, and uploading the data processing proof information to the blockchain, wherein the data processing proof information is proof information generated based on a process of performing data processing in the first data space to obtain the source data; based on the heterogeneous data space data flow conversion protocol, writing the data source proof information into the first field, writing the source data into the second field, and writing the data processing proof information into the third field to obtain a second target data packet, wherein the third field is used to represent the transaction identifier of the message on the trusted blockchain; sending the second target data packet to the second gateway device, so that the second gateway device parses the second target data packet to obtain the data source proof information, the source data, and the data processing proof information, and verifies the data source proof information and the data processing proof information based on the blockchain, and after the verification is passed, sending the source data to the second data space.
[0010] In a possible implementation, before obtaining the data source certification information and the source data from the first data space and uploading the data source certification information to the blockchain, the method also includes: sending the first root certificate of the first gateway device to the second gateway device, and receiving the second root certificate sent by the second gateway device; sending the first organization certificate of the first gateway device to the second gateway device, and when the second gateway device verifies the first organization certificate based on the first root certificate, receiving the second organization certificate sent by the second gateway device; verifying the second organization certificate based on the second root certificate, and establishing a communication connection with the second gateway device after the verification is passed.
[0011] In a possible implementation, before obtaining the data source proof information and the source data from the first data space and uploading the data source proof information to the blockchain, the method also includes: obtaining data publishing rules from the first data space, and uploading the data publishing rules to the blockchain; when the blockchain reviews and approves the data subscription application initiated by the second gateway device based on the data publishing rules, receiving the data publishing instruction sent by the blockchain, executing the operation of obtaining the data source proof information and the source data from the first data space, and uploading the data source proof information to the blockchain.
[0012] In a second aspect, an embodiment of the present application provides a data flow method for a heterogeneous data space, which is applied to a second gateway device, wherein the second gateway device is a heterogeneous data space gateway device adapted to the second data space, and the second data space is a data space for receiving source data. The method includes: receiving a first target data packet sent by a first gateway device, wherein the first gateway device is a heterogeneous data space gateway device adapted to the first data space, and the first data space is a data space for providing the source data. The first target data packet is obtained by the first gateway device converting the data source proof information and the source data based on a heterogeneous data space data flow conversion protocol, wherein the heterogeneous data space data flow conversion protocol is used to define a data structure for heterogeneous data space data flow, wherein the data structure includes cross-data space message content and cross-data space message proof, and the data source proof information is used to characterize the identity of the target data source, and the target data source is a data source that accesses the first data space and provides the source data to the first data space; parsing the first target data packet to obtain the data source proof information and the source data, and verifying the data source proof information based on the blockchain; when the verification passes, sending the source data to the second data space.
[0013] In a possible implementation, the data structure also includes a transaction identifier of the message on a trusted blockchain, and the method also includes: receiving a second target data packet sent by the first gateway device, the second target data packet being obtained by the first gateway device converting the data source proof information, the source data, and the data processing proof information based on the heterogeneous data space data flow conversion protocol, the data processing proof information being proof information generated based on a process of performing data processing in the first data space to obtain the source data; parsing the second target data packet to obtain the data source proof information, the source data, and the data processing proof information, and verifying the data source proof information and the data processing proof information based on the blockchain; when the verification is passed, sending the source data to the second data space.
[0014] In a possible implementation, before receiving the first target data packet sent by the first gateway device, the method also includes: obtaining a data directory from the blockchain, wherein the data directory is used to record the source data; receiving a data subscription instruction initiated by the second data space based on the data target, and sending a data subscription application to the blockchain based on the data subscription instruction, wherein the data subscription application is used to apply for access to the source data; when the blockchain reviews and approves the data subscription application based on the data publishing rules uploaded by the first gateway device, the operation of receiving the first target data packet sent by the first gateway device is performed.
[0015] In the third aspect, an embodiment of the present application provides a data flow system for a heterogeneous data space, the system comprising a first data space, a first gateway device, a second data space, a second gateway device and a blockchain; the first data space is a data space for providing source data, the first gateway device is a heterogeneous data space gateway device adapted to the first data space, the second data space is a data space for receiving the source data, the second gateway device is a heterogeneous data space gateway device adapted to the second data space, and the first data space is heterogeneous with the second data space; the first data space is used to access the target data source and record data source certification information, store the source data provided by the target data source, and the data source certification information is used to characterize the identity of the target data source; the first gateway device is used to execute the method as described in the first aspect or any one of the implementations thereof; the second gateway device is used to execute the method as described in the second aspect or any one of the implementations thereof, and the second data space is used to receive the source data sent by the second gateway device; the blockchain is used to store the data source certification information.
[0016] In a fourth aspect, an embodiment of the present application provides a heterogeneous data space gateway device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method described in the first aspect or the second aspect or any one of the implementation methods thereof is implemented.
[0017] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described in the first aspect or the second aspect or any one of the implementation methods thereof is implemented.
[0018] In a sixth aspect, an embodiment of the present application provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the steps of the method described in the first aspect or the second aspect or any one of the implementation methods therein.
[0019] Compared with the prior art, the embodiments of the present application have the following beneficial effects: a first gateway device adapted to the first data space obtains data source certification information and source data from the first data space, and uploads the data source certification information to the blockchain; based on the heterogeneous data space data flow conversion protocol, the data source certification information and source data are converted into a first target data packet; the heterogeneous data space data flow conversion protocol is used to define the data structure of heterogeneous data space data flow, and the data structure includes cross-data space message content and cross-data space message certification; the first target data packet is sent to a second gateway device adapted to the second data space, so that the second gateway device parses the first target data packet to obtain data source certification information and source data, and verifies the data source certification information based on the blockchain; after the verification is passed, the source data is sent to the second data space; the data structure format standard of heterogeneous data space data flow is standardized through the heterogeneous data space data flow conversion protocol, so that data can be smoothly circulated and shared between heterogeneous data spaces according to the heterogeneous data space data flow conversion protocol, breaking through the architectural design barriers of heterogeneous data spaces, and realizing efficient and reliable flow of data between heterogeneous data spaces.
[0020] It can be understood that the data flow system of the heterogeneous data space, the heterogeneous data space gateway device, the computer-readable storage medium and the computer program product provided in the embodiments of the present application have the same beneficial effects as the data flow method of the heterogeneous data space mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0022] Figure 1 A schematic diagram of the architecture of a data flow system for a heterogeneous data space provided in one embodiment of the present application;
[0023] Figure 2 A schematic diagram of a data structure of an HDDSP protocol provided in an embodiment of the present application;
[0024] Figure 3 A schematic diagram of a flow chart of a data flow method for a heterogeneous data space provided in one embodiment of the present application;
[0025] Figure 4 A flowchart of another method for transferring data in a heterogeneous data space provided in one embodiment of the present application;
[0026] Figure 5A flowchart of another method for transferring data in a heterogeneous data space provided in an embodiment of the present application;
[0027] Figure 6 A schematic diagram of a flow chart of a distributed bidirectional mutual authentication method for heterogeneous data space gateway devices provided in one embodiment of the present application;
[0028] Figure 7 A schematic diagram of the structure of a heterogeneous data space gateway device provided in one embodiment of the present application;
[0029] Figure 8 A schematic diagram of the structure of another heterogeneous data space gateway device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0030] In the following description, specific details such as specific system structures, technologies, etc. are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.
[0031] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.
[0032] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0033] As used in the specification and appended claims of this application, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce [described condition or event] is detected" or "in response to detecting [described condition or event]", depending on the context.
[0034] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0035] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0036] To facilitate understanding, some concepts involved in the embodiments of the present application are first explained.
[0037] (1) Data elements
[0038] Data elements refer to data resources that exist in electronic form, participate in production and operation activities through computing, and play an important role. In the digital economy, the role of data elements is comparable to traditional production factors (such as labor, capital, and land). Data elements are the core engine driving the development of the digital economy, an important support for enabling the digital transformation and intelligent upgrading of industries, and a national basic strategic resource.
[0039] (2) Data space
[0040] The data space achieves unified organization and management of multi-source heterogeneous data through technologies such as data integration, virtualization, semantic modeling and metadata management, and supports functions such as data cataloging, browsing, searching, querying, updating and monitoring.
[0041] (3) Data standard conversion
[0042] The open data of different manufacturers' data spaces are processed according to the same standard specifications, including the processing of data formats, data types and data content.
[0043] (4) Data conversion protocol
[0044] The protocol used for data standard conversion.
[0045] (5) Secure circulation of data elements
[0046] In the process of data sharing, no security incidents such as data privacy leakage, original data leakage, and data theft will occur. Data will not be obtained by unauthorized parties in the circulation system.
[0047] (6) Circulation and sharing of heterogeneous data space
[0048] The data flow between data spaces of different manufacturers often has different data standards, open data formats, different architectures, and different authentication systems, which hinder the data flow and sharing of heterogeneous data spaces.
[0049] The technical solution of the present application will be described in detail below with reference to the accompanying drawings.
[0050] Figure 1 A schematic diagram of the architecture of a data flow system for a heterogeneous data space provided in one embodiment of the present application is shown in FIG. Figure 1 As shown, the data flow system of heterogeneous data space includes data spaces of multiple different manufacturers, heterogeneous data space gateway devices adapted to the data spaces of each manufacturer, and blockchain.
[0051] Specifically, heterogeneous data space gateway devices are deployed on the data space side respectively. One heterogeneous data space gateway device can be accessed by multiple data spaces within the organization. The heterogeneous data space gateway device integrates the heterogeneous data space data flow conversion protocol (Heterogeneous DataZpaces data Sharing Protocol, HDDSP) and zero-trust data space distributed two-way mutual authentication technology proposed in this application. The data in the data space is converted into HDDSP protocol data packets according to the HDDSP protocol standard, and then forwarded to the opposite heterogeneous data space gateway device by the adapted heterogeneous data space gateway device. Each heterogeneous data space gateway device completes the authentication and connection between devices based on the distributed two-way mutual authentication technology proposed in this application, so as to ensure the standardization and security of data between heterogeneous data spaces; blockchain is the infrastructure for building a trusted system, which is responsible for storing the data source proof and data processing proof of the circulating data, so that the heterogeneous data space gateway device at the data receiving end can effectively verify the credibility of the data source.
[0052] As an example, since the data space products currently on the market can only transfer data within the data space and between homogeneous data spaces, and since different manufacturers have different data space technology architectures, open application programming interface (API) formats and data specifications, it is difficult for heterogeneous data spaces to interact with each other. In order to route and circulate data across heterogeneous data spaces and enable consistent data transfer and sharing between heterogeneous data spaces, this application designs a HDDSP general heterogeneous data space data flow protocol similar to the Transmission Control Protocol / Internet Protocol (TCP / IP).
[0053] Among them, the HDDSP protocol mainly revolves around the data structure. The main features of this data structure for data flow in heterogeneous data space are: cross-heterogeneous data space services, cross-heterogeneous data space data source proof, and cross-heterogeneous data space data processing proof.
[0054] For example, Figure 2 The data structure defined by the HDDSP protocol is shown in the figure. From and To represent the IDs of the source data space service and the target data space service respectively. The format is<GATEWAY ID> :<DATAZONE ID> :<DATASERVICE ID> . GATEWAY ID indicates the ID of the gateway device to which the source data space / target data space is connected; DATAZONE ID indicates the ID of the data space to which the gateway device is connected, that is, the ID of the source / target data space; DATASERVICEID indicates the data service ID in the data space. If the data being accessed is the result of data processing in the source data space, DATASERVICE ID is the number of the data processing service; if the data being accessed is the data directory in the data space, DATASERVICE ID is the number of the data directory.
[0055] The HDDSP TYPE field is the type of data flowing in the heterogeneous data space, including data processing data and data directory original data, etc. In specific application scenarios, the type can be expanded according to actual needs.
[0056] The PAYLOAD field is the content of the cross-data space message. Since the data spaces are connected using the Transport Layer Security (TLS) protocol, the data is transmitted in encrypted form, which ensures transmission security. Therefore, the data content in the PAYLOAD field will not be encrypted again.
[0057] The PROOF field is a cross-data space message proof, which stores the ownership information when the data source in the source data space is accessed, such as data source certification information, etc. This ownership information is stored in the blockchain and can be verified through the blockchain transaction hash.
[0058] The TRANSACTION ID field is the transaction ID of the message on the trusted blockchain. When the HDDSP type is data processing data, the target gateway device can verify this field to prove whether the obtained data is calculated according to the specified data processing flow.
[0059] The GROUP field is the message information in a one-to-many scenario. It stores the FROM IDs of all source data spaces in the multi-source data space requirements. That is, the target data space needs data from multiple source data spaces to conduct business.
[0060] The VERSION field is the protocol version number.
[0061] In the specific implementation, the HDDSP protocol standardizes the data format standard for data flow in heterogeneous data spaces, so that data can be smoothly circulated and shared between heterogeneous data spaces according to HDDSP, and special data source proof and data processing proof fields are set up to create a basis for the trusted flow of data across heterogeneous data spaces.
[0062] It can be understood that the HDDSP protocol proposed in this application is a universal protocol that can standardize the data structure of heterogeneous data spaces during data flow, in which the PROOF and TRANSACTION ID fields are used to verify the credibility of the data. If this protocol is used and other methods are used to verify the credibility of the data source and the credibility of the data processing process, it is still within the scope of protection of the application, only different verification methods are used.
[0063] It should be noted that in the data flow system of the heterogeneous data space provided in this application, each organization can use data space products of the same manufacturer to realize data flow between institutions within the organization, that is, data flow in homogeneous data space; or use data space products of different manufacturers to realize data flow between institutions, that is, data flow in heterogeneous data space.
[0064] Figure 3 A flow chart of a data flow method for a heterogeneous data space provided in an embodiment of the present application is provided. For the sake of convenience, only the part related to the present embodiment is shown. The method provided in the present embodiment is applied to a first gateway device, the first gateway device is a heterogeneous data space gateway device adapted to the first data space, and the first data space is a data space providing source data, and specifically includes the following steps:
[0065] S310, obtaining data source certification information and source data from the first data space, and uploading the data source certification information to the blockchain, where the data source certification information is used to characterize the identity of the target data source, which is a data source that accesses the first data space and provides source data to the first data space.
[0066] In the specific implementation, during the data access stage, the first data space accesses the target data source, registers the data source certification information of the target data source to the first gateway device, and obtains the source data from the target data source for management. The data source certification information of the target data source includes the data source type, name and collection unit of the target data source; when the first data space needs to perform data flow in heterogeneous data spaces for source data, data sharing of the source data across heterogeneous data spaces is performed through the first gateway device.
[0067] As an example, if the source data needs to be processed before it can be used, the data is processed in the first data space to obtain the source data, and the processing process generates data processing certification information. The first data space registers the data processing certification information to the first gateway device, and the first gateway device uploads the data processing certification information to the blockchain.
[0068] Exemplarily, the method of generating data processing proof information for the data processing process includes using zero-knowledge proof technology to generate a computational integrity proof for the processing process. If the proof verification passes, it means that the first data space honestly processed the data according to the algorithm flow; hash proofs can also be generated at each step of the data processing process, and then the hash proof set is generated into a Merkle tree, and during verification, it is verified whether the tree nodes, paths and root hashes match.
[0069] In addition, before executing step S310, the first data space determines the data publishing rules and sends the data publishing rules to the first gateway device. After receiving the data publishing rules sent by the first data space, the first gateway device uploads them to the blockchain; when the blockchain reviews and approves the data subscription application initiated by the second gateway device based on the data publishing rules, it receives the data publishing instruction sent by the blockchain, executes the operation of obtaining data source proof information and source data from the first data space, and uploads the data source proof information to the blockchain.
[0070] S320, based on the heterogeneous data space data flow conversion protocol, convert the data source certification information and the source data into a first target data packet. The heterogeneous data space data flow conversion protocol is used to define the data structure of the heterogeneous data space data flow, and the data structure includes cross-data space message content and cross-data space message certification.
[0071] In one possible implementation, based on a heterogeneous data space data flow conversion protocol, the data source proof information is written into a first field, and the source data is written into a second field to obtain a first target data packet. The first field is used to represent the cross-data space message proof, and the second field is used to represent the cross-data space message content.
[0072] In the specific implementation, refer to Figure 2 As shown, the first gateway device packages data such as data source proof information and source data in accordance with the HDDSP protocol, wherein the source data is written into the PAYLOAD field, and the on-chain hash value of the data source proof information is written into the PROOF field, to obtain the first target data packet.
[0073] In another possible implementation, the data structure defined by the HDDSP protocol also includes a transaction identifier of the message on the trusted blockchain. Based on the heterogeneous data space data flow conversion protocol, the data source proof information is written into the first field, the source data is written into the second field, and the data processing proof information is written into the third field to obtain a second target data packet. The third field is used to represent the transaction identifier of the message on the trusted blockchain.
[0074] In the specific implementation, refer to Figure 2 As shown, the first gateway device packages data such as data source proof information, source data, and data processing proof information in accordance with the HDDSP protocol, wherein the source data is written into the PAYLOAD field, the on-chain hash value of the data source proof information is written into the PROOF field, and the data processing proof information is written into the TRANSACTION ID field to obtain a second target data packet.
[0075] S330, sending the first target data packet to the second gateway device, so that the second gateway device parses the first target data packet to obtain data source certification information and source data, and verifies the data source certification information based on the blockchain. After the verification is passed, the source data is sent to the second data space. The second gateway device is a heterogeneous data space gateway device adapted to the second data space. The second data space is a data space for receiving source data, and the first data space and the second data space are heterogeneous.
[0076] In a specific implementation, the first data space forwards the first target data packet to the second gateway device through the first gateway device. Since TLS is used to establish a connection and encrypt data transmission between the first gateway device and the second gateway device, the security of the data during the transmission stage can be guaranteed.
[0077] In another possible implementation, the second target data packet is sent to the second gateway device, so that the second gateway device parses the second target data packet to obtain data source proof information, source data, and data processing proof information, and verifies the data source proof information and data processing proof information based on the blockchain. After the verification is passed, the source data is sent to the second data space.
[0078] The technical solution provided by this embodiment is that the first gateway device adapted to the first data space obtains data source certification information and source data from the first data space, and uploads the data source certification information to the blockchain, and converts the data source certification information and source data into a first target data packet based on the heterogeneous data space data flow conversion protocol, and the heterogeneous data space data flow conversion protocol is used to define the data structure of heterogeneous data space data flow, and the data structure includes cross-data space message content and cross-data space message certification; the first target data packet is sent to the second gateway device adapted to the second data space, so that the second gateway device parses the first target data packet to obtain the data source certification information and source data, and verifies the data source certification information based on the blockchain. After the verification is passed, the source data is sent to the second data space, and the data structure format standard of the heterogeneous data space data flow is standardized through the heterogeneous data space data flow conversion protocol, so that the data can be smoothly circulated and shared between heterogeneous data spaces according to the heterogeneous data space data flow conversion protocol, breaking through the architectural design barriers of heterogeneous data spaces, and realizing efficient and reliable flow of data between heterogeneous data spaces.
[0079] Based on the above embodiment, this embodiment further illustrates and optimizes the technical solution. Specifically, in this embodiment, before obtaining the data source certification information and the source data from the first data space and uploading the data source certification information to the blockchain, it also includes:
[0080] Sending a first root certificate of the first gateway device to the second gateway device, and receiving a second root certificate sent by the second gateway device;
[0081] Sending the first organization certificate of the first gateway device to the second gateway device, and when the second gateway device verifies the first organization certificate based on the first root certificate, receiving the second organization certificate sent by the second gateway device;
[0082] The second organization certificate is verified based on the second root certificate, and after the verification passes, a communication connection with the second gateway device is established.
[0083] In a specific implementation, the organization corresponding to the first gateway device and the organization corresponding to the second gateway device trust each other, and the two parties exchange their root certificates (root.cert). The first gateway device sends its first root certificate to the second gateway device, and the second gateway device sends its second root certificate to the first gateway device. In the TLS handshake phase, the first gateway device sends its first organization certificate to the second gateway device, and the second gateway device uses the first root certificate of the first gateway device to perform certificate chain verification on the first organization certificate. After the verification is successful, the second gateway device sends its second organization certificate to the first gateway device in reverse, and the first gateway device uses the second root certificate of the second gateway device to perform certificate chain verification on the second organization certificate. After both-way verifications are successful, it proves that the first gateway device and the second gateway device trust each other, and then a communication connection is established.
[0084] As an example, after the two-way authentication between the first gateway device and the second gateway device is passed, a peer-to-peer (P2P) connection is established between the two.
[0085] The technical solution provided in this embodiment realizes distributed two-way mutual authentication in zero-trust data space. In the scenario of data flow and sharing between non-trusted organizational units, it breaks the identity security authentication barriers between heterogeneous data spaces, realizes decentralized, efficient and trusted authentication of the data flow and sharing network, and thus ensures the security of data flow between heterogeneous data spaces.
[0086] Figure 4 A flow chart of another data flow method for heterogeneous data space provided in an embodiment of the present application. For the sake of convenience, only the part related to the present embodiment is shown. The method provided in the present embodiment is applied to a second gateway device, and the second gateway device is a heterogeneous data space gateway device adapted to the second data space. The second data space is a data space for receiving source data, and specifically includes the following steps:
[0087] S410, receiving a first target data packet sent by a first gateway device, the first gateway device is a heterogeneous data space gateway device adapted to the first data space, the first data space is a data space that provides source data, the first target data packet is obtained by the first gateway device converting data source certification information and source data based on a heterogeneous data space data flow conversion protocol, the heterogeneous data space data flow conversion protocol is used to define a data structure for heterogeneous data space data flow, the data structure includes cross-data space message content and cross-data space message certification, the data source certification information is used to characterize the identity of the target data source, the target data source is a data source that accesses the first data space and provides source data to the first data space.
[0088] In a specific implementation, before executing S410, the second gateway device obtains a data directory from the blockchain, where the data directory is used to record source data; receives a data subscription instruction initiated by the second data space based on the data directory, and sends a data subscription application to the blockchain based on the data subscription instruction, where the data subscription application is used to apply for access to the source data; when the blockchain reviews and approves the data subscription application based on the data publishing rules uploaded by the first gateway device, it executes an operation of receiving the first target data packet sent by the first gateway device.
[0089] As an example, the second gateway device synchronizes the data directory from the blockchain, the second data space retrieves the data directory through the second gateway device, and initiates a data subscription application to the blockchain through the second gateway device. The blockchain reviews the data subscription application according to the data publishing rules stored on the chain. If the review is passed, the first data space is notified to provide the source data.
[0090] In another possible implementation, the data structure defined by the HDDSP protocol also includes a transaction identifier of the message on the trusted blockchain. The second gateway device can also receive a second target data packet sent by the first gateway device. The second target data packet is obtained by the first gateway device converting the data source proof information, source data and data processing proof based on the heterogeneous data space data flow conversion protocol. The data processing proof is proof information generated based on the process of processing the source data in the first data space.
[0091] S420, parse the first target data packet to obtain data source certification information and source data, and verify the data source certification information based on the blockchain.
[0092] In a specific implementation, after receiving the first target data packet, the second gateway device parses the content of the PROOF field to obtain the data source proof information, parses the content of the PAYLOAD field to obtain the source data, and verifies whether the data source is credible through the blockchain, that is, verifies the data source proof information.
[0093] In another possible implementation, the second gateway device can also receive a second target data packet sent by the first gateway device. In this case, the second gateway device parses the contents of the PROOF field and the TRANSACTION ID field, and verifies whether the data source and the data processing process are credible through the blockchain, that is, verifies the data source proof information and the data processing proof information.
[0094] S430: When the verification is passed, the source data is sent to the second data space.
[0095] The technical solution provided in this embodiment is that after the gateway device adapted to the data space of the data receiving end receives the HDDSP protocol data packet sent by the gateway device adapted to the data space of the data sending end, it parses the contents of the PROOF field and the TRANSACTION ID field, and verifies whether the data source and the data processing process are credible through the blockchain. Only after the verification is passed will the source data be sent to the data space of the data receiving end, thereby ensuring the security of data flow in heterogeneous data spaces.
[0096] Figure 5 A flowchart of another method for transferring data in a heterogeneous data space provided for one embodiment of the present application is provided. For ease of explanation, only the part related to the present embodiment is shown. The method provided by the present embodiment includes a data access stage, a data processing stage, a data publishing stage, and a data access stage. In these stages, data space manufacturers need to adapt the gateway equipment of their products to achieve the reliability, security, and standardization of data transfer across data spaces. However, the cost of unified adaptation work for standard protocols is much lower than the cost of adapting to other data space manufacturers in the absence of standards. Specifically, the following steps are included:
[0097] (1) Data access stage
[0098] Step 1: Access the data source on the source data space side. The source data space registers the data source access information to the source data space gateway. The registration information includes the data source type, name, collection unit, etc. The source data space gateway uploads the registration information to the chain.
[0099] (2) Data processing stage
[0100] Step 2: If the source data needs to be processed before it can be used, the data is processed in the source data space, and a proof is generated for the processing process. There are many ways to generate proofs, such as using zero-knowledge proof technology to generate a computational integrity proof for the processing process. If the proof can be verified, it means that the source data space honestly processes the source data according to the algorithm flow; for example, a hash proof is generated at each step of the data processing process, and then the hash proof set is used to generate a Merkle tree. During verification, the tree nodes, paths, and root hashes are verified to match. The source data space registers the proof to the source data space gateway, and the source data space gateway registers the proof on the chain. During the data flow stage, the transaction hash of the proof on the chain will be packaged into the TRANSACTION ID field for verification by the target gateway device.
[0101] (3) Data release stage
[0102] Step 3: The source data space determines the publishing rules and publishes the data. The publishing rules will be registered to the blockchain through the source data space gateway.
[0103] (4) Data access phase
[0104] Step 4: The target data space gateway synchronizes the data directory from the blockchain. The target data space retrieves the data directory through the target data space gateway and initiates a subscription application.
[0105] Step 5: The blockchain reviews the subscription application based on the publishing rules stored on the chain. If the application is approved, the source data space is notified to provide the data.
[0106] Step 6: The source data space packages the data in accordance with the HDDSP protocol, where the chain hash of the proof of data source ownership and the proof of data processing are written into PROOF and TRANSACTION ID respectively.
[0107] Step 7: The source data space forwards the data packet to the target data space gateway through the source data space gateway. Since TLS is used to establish a connection and encrypt data transmission between gateway devices, the security of the data during the transmission stage can be guaranteed.
[0108] Step 8: The target data space gateway receives the data packet, parses the contents of the PROOF and TRANSACTION ID fields, and verifies whether the data source and data processing process are credible through the blockchain.
[0109] Step 9: If the credibility verification passes, the target data space gateway sends the data to the target data space.
[0110] The technical solution provided in this embodiment can achieve reliable, secure and standardized data flow across heterogeneous data spaces after cost-controlled adaptation of the data spaces of various manufacturers.
[0111] Furthermore, the gateway devices establish TLS connections based on digital certificates, thereby achieving secure data transfer. This type of security is based on the trustworthiness of the gateway devices, and the trustworthiness of the gateway devices is based on the trustworthiness of the centralized certificate authority (CA). The data transfer system is composed of mutually untrustworthy organizations. If the centralized CA is untrustworthy, colludes with the organization during the organization access process, and publishes false and illegal original data after the organization enters the data transfer system, then even if PROOF and TRANSACTIONID are used for trusted verification, the healthy and safe operation of the cross-data space data transfer system cannot be guaranteed due to problems with the original data.
[0112] This embodiment proposes a zero-trust data space distributed two-way mutual authentication method to address this problem. The certificate management authority is transferred from the central organization to the deployment organization of each heterogeneous data space gateway device. The gateway devices of each organization issue gateway access certificates to other gateway devices, and the certificate authentication is completed during the handshake connection phase between nodes. This method has the advantages of decentralization, high efficiency and high reliability.
[0113] In this embodiment, Figure 1 Based on the data flow system of the heterogeneous data space shown in the figure, firstly, each organization that has deployed a heterogeneous data space gateway device is a certificate authority (CA), has its own independent root certificate (root.cert), and self-signs and generates an organization certificate (agency.cert); secondly, the certificate access system is divided into two layers, the first layer is the access of the gateway device, and the second layer is the access of the data space.
[0114] (1) Access to gateway devices
[0115] The gateway devices use a distributed two-way mutual authentication method to conduct mutual recognition and access. Figure 6 A flow chart of a distributed bidirectional mutual authentication method for heterogeneous data space gateway devices provided in one embodiment of the present application. The method includes a certificate exchange phase and a bidirectional mutual authentication phase with other gateway devices. Figure 6 As shown, the gateway device to be connected is ready to access the data flow system of the heterogeneous data space, and needs to be mutually recognized with gateway device A and gateway device B. The detailed process is as follows:
[0116] 1) Certificate exchange phase
[0117] Step 1: The networked heterogeneous data space device (referred to as the networked device) has trusted the organizations corresponding to heterogeneous data space device A (referred to as device A) and heterogeneous data space device B (referred to as device B), and the organizations corresponding to devices A and B have also trusted the networked device organization, so the three parties can exchange their root certificates. The networked device organization sends its root.cert to the organizations of devices A and B, and the organizations of devices A and B send their root.cert to the networked device.
[0118] 2) Bidirectional mutual recognition stage with device A
[0119] The networked device establishes a TLS connection with device A
[0120] Step 2: During the TLS handshake phase, the networked device sends its own agency.cert to device A, which uses the root.cert of the networked device to verify the certificate chain. After the verification is successful, device A sends its own agency.cert to the networked device, which uses the root.cert of device A to verify the certificate chain. After both sides have passed the verification, it proves that the networked device and device A trust each other, and then establishes a P2P connection.
[0121] 3) Bidirectional mutual recognition stage with device B
[0122] This is the same as the two-way mutual authentication process between the network access device and device A, and will not be repeated here.
[0123] Access authentication is performed through this process. Only when the network-accessing device obtains the trust of other gateway devices can it be verified and passed, which solves the security issues caused by collusion between centralized CA and network-accessing devices.
[0124] (2) Access to data space
[0125] The gateway device acts as an independent CA and issues subordinate certificates for the data space accessed by the organization. The data space and the gateway device can be verified according to the common certificate chain.
[0126] In summary, the data flow method for heterogeneous data space proposed in this application mainly includes the following key innovations:
[0127] 1) Data transfer and conversion protocol in heterogeneous data space
[0128] This application designs a data flow conversion protocol for heterogeneous data spaces. After various organizations have adopted data spaces from different manufacturers to complete the data circulation infrastructure, the HDDSP protocol is used to break through the architectural design barriers of heterogeneous data spaces to achieve efficient and reliable data flow between heterogeneous data spaces.
[0129] 2) Zero-trust data space distributed two-way mutual authentication technology
[0130] This application proposes and implements zero-trust data space distributed two-way mutual authentication technology. In the scenario of data flow and sharing between untrusted organizations, it breaks the identity security authentication barrier when heterogeneous data spaces access the data circulation and sharing network system, realizes the decentralized, efficient and trusted authentication of the data circulation and sharing network, and builds a large-scale heterogeneous data space data circulation and sharing trusted network, thereby ensuring the security of data flow between heterogeneous data spaces.
[0131] 3) Heterogeneous data space gateway equipment
[0132] This application designs a heterogeneous data space gateway device, which is divided into a data plane and a control plane, integrates a heterogeneous data space data flow conversion protocol and a data space distributed two-way mutual authentication technology, and is a product form of a large-scale heterogeneous data space data flow system.
[0133] Based on the above key innovations, the technical solution provided by this application has the following beneficial effects:
[0134] The economic cost of connecting heterogeneous data spaces is reduced, and the implementation process is controllable. The unified data structure standard proposed in this application is adopted to adapt heterogeneous data space gateways under a unified framework, which reduces the implementation steps and makes it easier to control the economic cost and implementation progress.
[0135] No trust barriers. To implement data transfer in heterogeneous data spaces between organizational units, a unified trust agency is required. By adopting the distributed two-way mutual authentication technology proposed in this application, each organizational unit can connect to an independent CA. Only when organizations fully recognize each other can they enter the data transfer network system, effectively reducing or even eliminating trust barriers.
[0136] 3) This application introduces blockchain technology to build a trust system for data flow in heterogeneous data spaces, reducing the trust cost between organizations.
[0137] Figure 7 This is a schematic diagram of the structure of a heterogeneous data space gateway device provided in one embodiment of the present application. Figure 7 As shown, the heterogeneous data space gateway device is divided into a control bus and a data bus. The control bus and the data bus are connected to the device bus, and the control plane and the data plane are coordinated and scheduled by the device bus.
[0138] The control bus is connected with a network authentication module, an access control module, a scheduling instruction module and a resource management module. The network authentication module integrates a zero-trust data space distributed two-way mutual authentication technology to achieve the following: Figure 6 The distributed two-way mutual authentication method of heterogeneous data space gateway devices shown in the figure; the access control module is adapted to the blockchain, used for internal access to data space products, and to perform permission control on data access to the data flow system; the scheduling instruction module is used for routing control of data packet forwarding; and the resource management module is used to manage the data space.
[0139] The data bus is connected with an encryption card, a data resource directory module, an HDDSP protocol module and a data flow module. The encryption card is a reserved module. Considering the performance and actual needs, this module is reserved to flexibly adapt to the password card used for data encryption; the data resource directory module is used to synchronize the data directory resources of the data flow system from the blockchain; the HDDSP protocol module integrates the heterogeneous data space data flow conversion protocol, which is used to package and parse the flow data according to the protocol, and verify the credibility of the data; the data flow module is used to route shared data internally and externally.
[0140] A heterogeneous data space gateway device provided in an embodiment of the present application has the same beneficial effects as the above-mentioned data flow method of a heterogeneous data space.
[0141] It should be noted that the information interaction, execution process, etc. between the above-mentioned devices / units are based on the same concept as the method embodiment of the present application. Their specific functions and technical effects can be found in the method embodiment part and will not be repeated here.
[0142] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of this application. The specific working process of the units and modules in the above-mentioned system can refer to the corresponding process in the aforementioned method embodiment, which will not be repeated here.
[0143] Figure 8 This is a schematic diagram of the structure of another heterogeneous data space gateway device provided in one embodiment of the present application. Figure 8 As shown, the heterogeneous data space gateway device 8 of this embodiment includes: at least one processor 80 ( Figure 8 Only one is shown in the figure), a memory 81, and a computer program 82 stored in the memory 81 and executable on at least one processor 80, the processor 80 executes the computer program 82 to implement the above Figure 3 , Figure 4 , Figure 5 or Figure 6 Steps in a method embodiment.
[0144] The heterogeneous data space gateway device 8 may include but is not limited to a processor 80 and a memory 81. Those skilled in the art will appreciate that Figure 8 It is merely an example of the heterogeneous data space gateway device 8 and does not constitute a limitation on the heterogeneous data space gateway device 8. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components, for example, it may also include input and output devices, network access devices, etc.
[0145] The processor 80 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc.
[0146] In some embodiments, the memory 81 may be an internal storage unit of the heterogeneous data space gateway device 8, such as a hard disk or memory of the heterogeneous data space gateway device 8. In other embodiments, the memory 81 may also be an external storage device of the heterogeneous data space gateway device 8, such as a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. equipped on the heterogeneous data space gateway device 8. Furthermore, the memory 81 may also include both the internal storage unit and the external storage device of the heterogeneous data space gateway device 8. The memory 81 is used to store operating systems, applications, boot loaders (BootLoader), data, and other programs, such as program codes of computer programs. The memory 81 can also be used to temporarily store data that has been output or is to be output.
[0147] The embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.
[0148] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, it can implement the steps of the above-mentioned method embodiments. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device that can carry the computer program code to a heterogeneous data space gateway device, a recording medium, a computer memory, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), an electrical carrier signal, a telecommunication signal, and a software distribution medium. For example, a USB flash drive, a mobile hard disk, a disk or an optical disk.
[0149] A computer-readable storage medium provided in an embodiment of the present application has the same beneficial effects as the above-mentioned data flow method of a heterogeneous data space.
[0150] An embodiment of the present application provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.
[0151] A computer program product provided in an embodiment of the present application has the same beneficial effects as the above-mentioned data flow method in a heterogeneous data space.
[0152] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0153] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0154] In the embodiments provided in the present application, it should be understood that the disclosed devices / equipment and methods can be implemented in other ways. For example, the device / equipment embodiments described above are merely schematic, for example, the division of the modules or units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0155] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0156] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A data transfer method for heterogeneous data space, characterized in that: Applied to a first gateway device, the first gateway device is a heterogeneous data space gateway device adapted to a first data space, the first data space is a data space providing source data, the method includes: Acquire data source certification information and the source data from the first data space, and upload the data source certification information to the blockchain, wherein the data source certification information is used to characterize the identity of a target data source, and the target data source is a data source that accesses the first data space and provides the source data to the first data space; Based on a heterogeneous data space data flow conversion protocol, converting the data source certification information and the source data into a first target data packet, the heterogeneous data space data flow conversion protocol is used to define a data structure of heterogeneous data space data flow, the data structure including cross-data space message content and cross-data space message certification; The first target data packet is sent to a second gateway device, so that the second gateway device parses the first target data packet to obtain the data source certification information and the source data, and verifies the data source certification information based on the blockchain. After the verification, the source data is sent to a second data space. The second gateway device is a heterogeneous data space gateway device adapted to the second data space. The second data space is a data space for receiving the source data. The first data space and the second data space are heterogeneous.
2. The method according to claim 1, characterized in that The method of converting the data source certification information and the source data into a first target data packet based on the heterogeneous data space data flow conversion protocol includes: Based on the heterogeneous data space data flow conversion protocol, the data source proof information is written into the first field, and the source data is written into the second field to obtain the first target data packet. The first field is used to represent the cross-data space message proof, and the second field is used to represent the cross-data space message content.
3. The method according to claim 2, characterized in that The data structure also includes a transaction identifier of the message on the trusted blockchain, and the method further includes: Acquire data processing certification information from the first data space, and upload the data processing certification information to the blockchain, wherein the data processing certification information is certification information generated based on a process of performing data processing in the first data space to obtain the source data; Based on the heterogeneous data space data flow conversion protocol, the data source certification information is written into the first field, the source data is written into the second field, and the data processing certification information is written into the third field to obtain a second target data packet, wherein the third field is used to indicate a transaction identifier of the message on the trusted blockchain; The second target data packet is sent to the second gateway device, so that the second gateway device parses the second target data packet to obtain the data source proof information, the source data and the data processing proof information, and verifies the data source proof information and the data processing proof information based on the blockchain. After the verification is passed, the source data is sent to the second data space.
4. The method according to claim 1, characterized in that: Before obtaining the data source certification information and the source data from the first data space and uploading the data source certification information to the blockchain, the method further includes: Sending a first root certificate of the first gateway device to the second gateway device, and receiving a second root certificate sent by the second gateway device; Sending the first organization certificate of the first gateway device to the second gateway device, and when the second gateway device verifies the first organization certificate based on the first root certificate, receiving the second organization certificate sent by the second gateway device; The second organization certificate is verified based on the second root certificate, and after the verification passes, a communication connection with the second gateway device is established.
5. The method according to claim 1, characterized in that Before obtaining the data source certification information and the source data from the first data space and uploading the data source certification information to the blockchain, the method further includes: Acquire data publishing rules from the first data space, and upload the data publishing rules to the blockchain; When the blockchain approves the data subscription application initiated by the second gateway device based on the data publishing rules, it receives the data publishing instruction sent by the blockchain, executes the operation of obtaining the data source proof information and the source data from the first data space, and uploading the data source proof information to the blockchain.
6. A data transfer method for heterogeneous data space, characterized in that: Applied to a second gateway device, the second gateway device is a heterogeneous data space gateway device adapted to a second data space, the second data space is a data space for receiving source data, the method includes: Receive a first target data packet sent by a first gateway device, where the first gateway device is a heterogeneous data space gateway device adapted to a first data space, where the first data space is a data space that provides the source data, and the first target data packet is obtained by the first gateway device converting data source certification information and the source data based on a heterogeneous data space data flow conversion protocol, where the heterogeneous data space data flow conversion protocol is used to define a data structure for heterogeneous data space data flow, where the data structure includes cross-data space message content and cross-data space message certification, and the data source certification information is used to characterize the identity of a target data source, where the target data source is a data source that accesses the first data space and provides the source data to the first data space; Parsing the first target data packet to obtain the data source certification information and the source data, and verifying the data source certification information based on the blockchain; When the verification is passed, the source data is sent to the second data space.
7. The method according to claim 6, characterized in that The data structure also includes a transaction identifier of the message on the trusted blockchain, and the method further includes: Receive a second target data packet sent by the first gateway device, where the second target data packet is obtained by the first gateway device converting the data source certification information, the source data, and the data processing certification information based on the heterogeneous data space data flow conversion protocol, where the data processing certification information is certification information generated based on a process of performing data processing in the first data space to obtain the source data; Parsing the second target data packet to obtain the data source certification information, the source data, and the data processing certification information, and verifying the data source certification information and the data processing certification information based on the blockchain; When the verification is passed, the source data is sent to the second data space.
8. The method according to claim 6, characterized in that Before receiving the first target data packet sent by the first gateway device, the method further includes: Obtain a data directory from the blockchain, where the data directory is used to record the source data; receiving a data subscription instruction initiated by the second data space based on the data directory, and sending a data subscription application to the blockchain based on the data subscription instruction, wherein the data subscription application is used to apply for access to the source data; When the blockchain approves the data subscription application based on the data publishing rules uploaded by the first gateway device, the operation of receiving the first target data packet sent by the first gateway device is performed.
9. A data transfer system for heterogeneous data space, characterized in that: The system includes a first data space, a first gateway device, a second data space, a second gateway device and a blockchain; the first data space is a data space that provides source data, the first gateway device is a heterogeneous data space gateway device adapted to the first data space, the second data space is a data space that receives the source data, the second gateway device is a heterogeneous data space gateway device adapted to the second data space, and the first data space and the second data space are heterogeneous; The first data space is used to access the target data source and record data source certification information, and store the source data provided by the target data source, wherein the data source certification information is used to characterize the identity of the target data source; The first gateway device is used to execute the method according to any one of claims 1 to 5; The second gateway device is used to execute the method according to any one of claims 6 to 8, The second data space is used to receive the source data sent by the second gateway device; The blockchain is used to store the data source certification information.
10. A heterogeneous data space gateway device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 5 or 6 to 8 is implemented.
Citation Information
Patent Citations
Multi-user heterogeneous data merging and evidence storing method based on block chain privacy protection
CN114139206A
Heterogeneous TEE unified oracle authentication method and platform based on block chain
CN114726584A