A data sharing whole process tracing method based on digital watermark technology

Through methods such as differential structural feature extraction and zero-knowledge proof based on digital watermark technology, a data transmission traceability chain is built, which solves the problems of copyright protection and traceability in the data sharing process, and realizes the security and traceability of the entire process of data.

CN119762096BActive Publication Date: 2025-05-20JIANGSU SOUTHEAST INTELLIGENT TECH GRP CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510252662.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-05-20
Estimated Expiration
2045-03-05

AI Technical Summary

Technical Problem

The prior art is difficult to effectively solve the copyright protection and traceability problems of different structures and types of data in the process of data sharing, especially in terms of compatibility between complex data structures and multiple data types.

Method used

The data sharing full-process traceability method based on digital watermark technology is adopted, and the data feature space is obtained through the differential structural feature extraction integration model, the data owner information and sharing path are fused, and the digital watermark is generated using hierarchical fusion and multi-level encryption algorithm, and the target structure data is embedded through the differential watermark embedding algorithm. At the same time, a data transmission traceability chain is built using zero-knowledge proof and distributed federal algorithm, a distributed monitoring model for data transmission is configured, and the data transmission status and zero-knowledge proof results are monitored in real time to achieve full traceability and security of data transmission.

Benefits of technology

It realizes the copyright protection and traceability of the entire process of different types of data, ensures the security and traceability of data during transmission, and enhances the security and responsibility identification capabilities of data sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119762096B_ABST
    Figure CN119762096B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of data watermark traceability, and in particular, relates to a data sharing whole process traceability method based on digital watermark technology, comprising: firstly, obtaining multidimensional structure and unstructured data, and obtaining the target shared data feature space through a differential structural feature extraction integration model; secondly, fusing data owner information and sharing path, generating a final digital watermark through hierarchical fusion and multi-level encryption algorithm, and embedding the target structure data using a differential watermark embedding algorithm; thirdly, constructing a data transmission traceability chain with the help of blockchain and distributed federation algorithm based on relevant information, and configuring a monitoring model; fourthly, monitoring the data transmission status and zero-knowledge proof results of each node in real time, and transmitting them to the analysis control sub-model after analysis by the analysis sub-model; once an abnormal result is received, constructing a leakage scenario node map, and realizing abnormal tracing and marking of fixed nodes with the help of distributed monitoring model and blockchain smart contract.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data watermark tracing, and particularly relates to a method for tracing the whole process of data sharing based on digital watermark technology. Background Technique

[0002] With the continuous improvement of data value, the issues of security and traceability in the data sharing process have become increasingly important. On the one hand, data copyright protection is a key challenge in data sharing. In the data sharing scenario, data owners hope to ensure the clear copyright attribution of their data during the sharing process and prevent unauthorized use, copying, and dissemination of the data. For example, scientific research achievement data, business secret data, etc. Once the copyright is not effectively protected, data owners may suffer economic losses and infringement of rights. On the other hand, data traceability is crucial for maintaining the security of data sharing and liability determination. When a data leakage event occurs, being able to quickly and accurately trace the data leakage source is of great significance for taking timely measures to prevent further spread of the data and holding relevant responsible parties accountable. For example, in medical data sharing, if patient data is leaked, accurate traceability can help determine which link has problems, so as to take corresponding remedial measures to protect patient privacy. However, there are many deficiencies in the existing technologies in dealing with these problems.

[0003] From the perspective of data copyright protection, for example, the patent application with the publication number CN117118697A discloses a method, system, device, and medium for copyright protection based on multiple watermarks and blockchain. Although it uses blockchain network and watermark technology to protect copyright, there are some limitations. Although blockchain technology provides the characteristics of decentralization and immutability, building and maintaining a blockchain network requires certain technical thresholds and costs, which may be difficult for some small enterprises or individual data owners to bear. In addition, this method mainly focuses on encrypting and embedding the feature information of files for copyright protection, and may lack compatibility for complex data structures and multiple data types, making it difficult to adapt to diverse data sharing scenarios.

[0004] From the perspective of data traceability analysis, a method for tracing relational data proposed in the Chinese patent application with the authorization publication number CN110232263B confirms the leakage source by embedding watermark information. However, this method may have the risk that the watermark is easily tampered with or damaged. During the data sharing process, malicious users may remove or modify the watermark information through technical means, resulting in the failure of traceability. Moreover, this method only targets relational data and lacks an effective traceability mechanism for non-relational data such as text and images, and its applicable range is relatively narrow.

[0005] The above prior art has the following problems: The prior art has not effectively solved the technical problem of realizing the whole-process copyright protection and accurate traceability of data sharing for different structures and types of data. Therefore, the present invention provides a whole-process traceability method for data sharing based on digital watermark technology. Summary of the Invention

[0006] In view of the deficiencies of the prior art, the present invention proposes a whole-process traceability method for data sharing based on digital watermark technology, including: First, obtaining multi-dimensional structured and unstructured data, and obtaining the target shared data feature space through a differential structure feature extraction integration model; Second, fusing data owner information, sharing paths, and generating a final digital watermark through a hierarchical fusion and multi-level encryption algorithm, and embedding it into the target structured data using a differential watermark embedding algorithm. Third, constructing a data transmission traceability chain based on relevant information with the help of blockchain and distributed federated algorithms, and configuring a monitoring model; Fourth, real-time monitoring the data transmission status of each node and the zero-knowledge proof result, transmitting it to the analysis control sub-model after analysis by the analysis sub-model. Once an abnormal result is received, a leakage scenario node map is constructed, and fixed-node abnormal traceability and marking are realized with the help of a distributed monitoring model and blockchain smart contract to ensure the security and traceability of the whole process of data sharing.

[0007] To achieve the above object, the present invention provides the following technical solutions:

[0008] A whole-process traceability method for data sharing based on digital watermark technology, including:

[0009] S1. Obtain multi-dimensional structured and unstructured data, and obtain the target structured or unstructured shared data feature space through a configured differential structure feature extraction integration model;

[0010] S2. Obtain data owner information, sharing paths, shared target node information, the target structured or unstructured shared data feature space, and the security level of transmitted data, obtain the final digital watermark corresponding to the data type through a homomorphic encryption algorithm, and embed it into the corresponding target structured data through a differential watermark embedding algorithm;

[0011] S3. According to the data owner information, sharing paths, target information, and shared target node information, construct a data transmission traceability chain through zero-knowledge proof and distributed federated algorithms, and configure a data transmission distributed monitoring model in the data transmission traceability chain;

[0012] The data transmission traceability chain includes a familiar shared node community, a primary shared node community, and a strange shared node community;

[0013] S4. Monitor the transmission status of the data embedded with watermarks and the zero-knowledge proof evidence corresponding to each node in the real-time monitoring data transmission traceability chain, analyze the data transmission status and zero-knowledge proof evidence through the analysis sub-model configured for the corresponding node, and transmit the analysis results to the analysis control sub-model corresponding to the data owner through parameter interaction in the distributed monitoring model;

[0014] The zero-knowledge proof evidence is dynamically obtained through the community type to which the node in the data transmission traceability chain belongs, the historical data and interaction information corresponding to the node, and the transmission data security level;

[0015] S5. When the analysis control sub-model receives the analysis abnormal results of each sub-node, construct a leakage scenario node graph through the analysis abnormal results of the sub-node, perform node-specific abnormal tracing on the abnormal transmission process through the distributed monitoring model and the smart contract in the blockchain, and perform abnormal or malicious marking on the corresponding transmission node according to the analysis tracing results.

[0016] Specifically, the differential structure feature extraction integration model includes a data type discrimination sub-model, a relational feature extraction sub-model, a text extraction sub-model, an image extraction sub-model, and an audio extraction sub-model;

[0017] Specifically, the steps for obtaining the target structured or unstructured shared data feature space include:

[0018] S101. According to the multi-dimensional structured and unstructured data, obtain the data types included in the input transmission data as structured or unstructured through the configured data type discrimination sub-model;

[0019] S102. Input the relational data in the corresponding type into the relational feature extraction sub-model, perform feature extraction of the index relationship and hierarchical relationship under the corresponding type of data, and obtain the relational feature vector;

[0020] S103. Input each non-relational data in the corresponding type into the text extraction sub-model, the image extraction sub-model, and the audio extraction sub-model in parallel, and simultaneously obtain the non-relational text feature vector, the non-relational image feature vector, and the non-relational audio feature vector;

[0021] S104. Construct the target structured or unstructured shared data feature space according to the relational feature vector, the non-relational text feature vector, the non-relational image feature vector, and the non-relational audio feature vector;

[0022] S105. According to the attribute link between the relational and non-relational data in the input transmission data, construct the output data type-related attribute vector through the correlation coefficient algorithm, and add the related attribute vector to the target structured or unstructured shared data feature space.

[0023] Specifically, the steps for constructing the data transmission traceability chain include:

[0024] S301. Based on the corresponding node information of the data owner, the shared target node information, and the owner's historical shared target nodes, construct a data transmission traceability chain through the community discovery algorithm, and divide the data transmission traceability chain;

[0025] S302. If the corresponding node is both a node in the data transmission traceability chain and a historical shared target node, divide the corresponding node into the familiar shared node community. If the corresponding node is only a node in the data transmission traceability chain, divide the corresponding node into the initial shared node community;

[0026] S303. According to the sequence of corresponding data transmissions in the shared path, mark the nodes in the data transmission traceability chain by combining the timestamp service of the blockchain and the cryptographic hash chain;

[0027] S304. Configure a path node discrimination model to discriminate the transmission process of the watermarked data on the data transmission traceability chain, and determine whether the next transmission node is a node in the familiar shared node community. If so, verify the current node through the configured zero-knowledge proof algorithm and the key pair established by the corresponding node of the data owner. After the verification passes, transmit the data to the corresponding node.

[0028] Specifically, the steps for constructing the data transmission traceability chain also include:

[0029] S305. If the verification fails, feedback the corresponding verification information to the analysis control sub-model, and control the analysis sub-model configured by the corresponding node through the analysis control sub-model to perform verification anomaly analysis, obtain the anomaly analysis result, construct a causal graph for the corresponding node according to the anomaly analysis result, and feedback the verification anomaly graph of the corresponding node to the analysis control sub-model.

[0030] S306. According to the anomaly analysis result, evaluate the nodes with verification anomalies through an evaluation algorithm to obtain whether the anomaly of the corresponding node is a general anomaly or a malicious leakage anomaly, output the reputation evaluation score of the corresponding node, and mark the transmission of the corresponding node through the smart contract in the blockchain according to the evaluation result and the feedback causal graph;

[0031] S307. When the transmission mark is a general anomaly and the reputation evaluation score of the corresponding node is greater than the configured trustworthy score threshold, enhance the encrypted information of the data watermark transmitted to the corresponding node through the encryption adjustment algorithm configured by the previous node, and at the same time adjust the effective verification time interval configured in the historical key;

[0032] S308. When the transmission flag is a general exception and the corresponding node reputation evaluation score is less than or equal to the configured trusted score threshold or it is a malicious leakage exception, the corresponding node is deleted from the data transmission traceability chain through the analysis control sub-model, and the shared path corresponding to the current data transmission traceability chain is updated.

[0033] Specifically, the steps for constructing the data transmission traceability chain further include:

[0034] S309. When the next transmission node is a node in the initial sharing node community, the current node is verified through the configured zero-knowledge proof algorithm and the enhanced key pair established between the nodes of the data transmission traceability chain. After the verification passes, the data is transmitted to the corresponding node.

[0035] S310. When the verification fails, the corresponding node is deleted from the data transmission traceability chain through the analysis control sub-model, and the shared path corresponding to the current data transmission traceability chain is updated.

[0036] S311. If the current corresponding node is neither a node in the initial sharing node community nor a node in the familiar sharing node community, the corresponding transmission node is classified into the unfamiliar sharing node community.

[0037] S312. If the current node is a node in the unfamiliar sharing node community, the current node information is analyzed and evaluated through the analysis sub-model configured by the previous node. At the same time, the current node information is fed back to the corresponding node of the data owner, and it is judged whether the current node is a new transmission node added by the data owner through the analysis control sub-model.

[0038] S313. If so, the data parameter relationship corresponding to the current node is configured by the data owner, the connection relationship between the previous node and the current node is established, and the key of the corresponding transmitted data is configured into the connection relationship between the previous node and the current node, and the current node is reclassified into the initial sharing node community.

[0039] S314. Repeat the process of S309 - S310 to perform the data transmission verification and discrimination of the current node, and perform data sharing or node disconnection according to the discrimination result.

[0040] Specifically, the steps for constructing the data transmission traceability chain further include:

[0041] S315. If the current node is not a new transmission node added by the data owner, the information obtained by scanning the current node is analyzed through the corresponding analysis sub-model of the previous node to obtain whether there is an abnormal state in the history of the current node and obtain the corresponding node reputation evaluation score.

[0042] S316. If there is no abnormal state in the current node's history and the node reputation evaluation score is greater than the trustworthy score threshold, share the corresponding analysis result information into the analysis control sub-model through the corresponding analysis sub-model of the previous node, and obtain the instruction from the data owner on whether to add the node;

[0043] S317. When the data owner issues an instruction to add a node, control the corresponding analysis sub-model of the previous node through the analysis control sub-model. According to the same steps as S313, divide the current node into the initial shared node community, and at the same time repeat the steps of S314 to perform data sharing judgment;

[0044] S318. When the data owner does not issue an instruction to add a node, or there is an abnormal state in the history, or the node reputation evaluation score is less than or equal to the trustworthy score threshold, do not establish a connection relationship with the current node, mark the current node as abnormal, and save the marking result to the strange shared node community.

[0045] Specifically, the steps for obtaining the zero-knowledge proof evidence in S4 include:

[0046] S401. Configure the zero-knowledge proof protocol library, divide the basic information and historical data transmission interaction information of the corresponding nodes in the familiar shared node community, the initial shared node community, and the strange shared node community according to the data transmission traceability chain, and obtain the trustworthy data transmission score of the corresponding data transmission node through the evaluation algorithm;

[0047] S402. Construct a dynamic call factor for the zero-knowledge proof protocol according to the trustworthy data transmission score of the corresponding data transmission node and the community type to which the corresponding node belongs;

[0048] S403. Use the node historical data and interaction information recorded on the data transmission traceability chain, combine the data to be transmitted currently and the dynamic call factor of the knowledge proof protocol of the current corresponding data transmission node to call the corresponding zero-knowledge proof protocol, and generate the zero-knowledge proof evidence of the corresponding node;

[0049] S404. According to the community type to which the node belongs, differentiate the generation method of the challenge value respectively according to the sharing rules, historical interaction modes, sharing security levels, and security evaluation factors among the nodes in the community, so as to obtain the challenge value of the node in the transmission verification process;

[0050] S405. Build a dynamic verification model based on machine learning, input the dynamically generated zero-knowledge proof evidence, the dynamic call factor of the zero-knowledge proof protocol, and the challenge value into the dynamic verification model for training, obtain the trained dynamic verification model, and configure the trained dynamic verification model to the connection relationship between different nodes in the data transmission traceability chain for dynamic zero-knowledge proof verification.

[0051] Specifically, the configuration of the zero-knowledge proof protocol library includes: a first-level zero-knowledge proof protocol, a second-level zero-knowledge proof protocol, and a third-level zero-knowledge proof protocol. The strength relationship corresponding to the zero-knowledge proof protocols is: first-level zero-knowledge proof protocol < second-level zero-knowledge proof protocol < third-level zero-knowledge proof protocol; the dynamic call factors of the zero-knowledge proof protocol include a first-level call factor, a second-level call factor, and a third-level call factor; the first-level call factor corresponds to the first-level zero-knowledge proof protocol, the second-level call factor corresponds to the second-level zero-knowledge proof protocol, and the third-level call factor corresponds to the third-level zero-knowledge proof protocol.

[0052] Specifically, the steps for generating the zero-knowledge proof evidence of the corresponding node include:

[0053] S4031. According to the community type to which the corresponding node belongs, when the corresponding data transmission node is a node in the familiar shared node community, call the first-level zero-knowledge proof protocol through the first-level call factor, and combine the historical successful data transmission interaction information between the corresponding node and the owner node to generate the zero-knowledge proof evidence of the corresponding node;

[0054] S4032. When the corresponding data transmission node is a node in the initial shared node community, call the second-level zero-knowledge proof protocol through the second-level call factor, and combine the node registration information, initial verification record, and node addition protocol information between the data owner node and the current node recorded in the corresponding node in the data transmission traceability chain to generate the zero-knowledge proof evidence of the corresponding node;

[0055] S4033. When the corresponding data transmission node is a node in the unfamiliar shared node community, call the third-level zero-knowledge proof protocol through the third-level call factor, and combine the scanning record information of the previous node for the current node, historical exception information, and the data owner node in the data transmission traceability chain, and generate the zero-knowledge proof evidence of the corresponding node by analyzing the consent addition instruction information issued by the control sub-model.

[0056] A computer-readable storage medium stores computer instructions thereon, and when the computer instructions run, a data sharing whole-process traceability method based on digital watermark technology is executed.

[0057] Compared with the prior art, the beneficial effects of the present invention are:

[0058] 1. In view of the deficiencies of the prior art, the present invention processes data through a differential structure feature extraction integration model, enabling the method to adapt to various complex data forms, comprehensively covering the feature extraction requirements of different types of data, breaking through the limitations of traditional methods for specific data types. Secondly, by integrating multi-dimensional information such as data owner information, sharing path, and target node information, and combining a hierarchical fusion algorithm and a multi-level data encryption algorithm to generate digital watermarks, the watermarks contain rich and unique information. At the same time, the multi-level encryption enhances the security of the watermarks, making them difficult to be forged or cracked, effectively protecting data copyright. The differential watermark embedding algorithm is adopted to embed watermarks according to the characteristics of different target structure data, which can not only ensure the concealment of the watermarks but also ensure the stability of the watermarks during data transmission and use.

[0059] 2. In view of the deficiencies of the prior art, the present invention constructs a data transmission traceability chain by using zero-knowledge proof and a distributed federated algorithm. The privacy protection of zero-knowledge proof and the collaborative advantages of the distributed federated algorithm ensure that the entire process of data transmission is traceable, protect data privacy, and improve the reliability of the traceability chain. Secondly, a distributed monitoring model for data transmission is configured in the traceability chain, which can monitor the data transmission status and zero-knowledge proof results of each node in real time, realizing all-round and real-time monitoring of the data transmission process, promptly discovering potential problems, and ensuring the security and compliance of data transmission. Thirdly, by setting up different node attribute communities in the data transmission traceability chain and invoking different zero-knowledge proof protocols according to different node attribute communities, while enhancing the verification security level, the verification rate between nodes is improved.

[0060] 3. The present invention also analyzes the transmission status and proof results through the analysis sub-models configured on each node and transmits the results to the analysis control sub-model to realize intelligent analysis of data transmission anomalies, which can quickly and accurately discover abnormal situations. When an anomaly occurs, a leakage scenario node graph is constructed, and the distributed monitoring model and blockchain smart contract are used for node anomaly tracing, which can accurately locate abnormal or malicious transmission nodes, clarify the responsible entity, and facilitate timely measures to prevent further data leakage. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] Figure 1 is a flowchart of a method for tracing the whole process of data sharing based on digital watermark technology in Embodiment 1 of the present invention;

[0062] Figure 2 is a structural diagram of a differential structure feature extraction integration model in Embodiment 1 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0063] Embodiment 1

[0064] Please refer to Figure 1, an embodiment provided by the present invention: a method for tracing the whole process of data sharing based on digital watermark technology, the steps include:

[0065] S1. Obtain multi-dimensional structured and unstructured data, and through a configured differential structure feature extraction integration model, obtain a target structured or unstructured shared data feature space;

[0066] Further, please refer to Figure 2 , in this embodiment, the differential structure feature extraction integration model includes a data type discrimination sub-model, a relational feature extraction sub-model, a text extraction sub-model, an image extraction sub-model, and an audio extraction sub-model; further, the data type discrimination sub-model, the relational feature extraction sub-model, the text extraction sub-model, the image extraction sub-model, and the audio extraction sub-model in this embodiment are all constructed by existing pre-trained models, and are integrated in the data processing interface by an integration algorithm. According to the corresponding data types obtained by the secondary classification model, the corresponding sub-models are called to process the corresponding data and extract the corresponding type of data features;

[0067] Further, the steps for obtaining the target structured or unstructured shared data feature space in this embodiment include:

[0068] S101. According to the multi-dimensional structured and unstructured data, through the configured data type discrimination sub-model, obtain the data types corresponding to the input transmission data being structured or unstructured;

[0069] Further, the data type discrimination sub-model in this embodiment is constructed by a logical classification algorithm. First, it discriminates whether the corresponding data is relational data or non-relational data, and on this basis, discriminates whether the corresponding data is text data, image data, audio data, or tabular data type with relational indexes.

[0070] S102. Input the relational data in the corresponding type into the relational feature extraction sub-model to extract the features of the index relationship and hierarchical relationship under the corresponding type of data, and obtain the relational feature vector;

[0071] S103. Input each non-relational data in the corresponding type into the text extraction sub-model, the image extraction sub-model, and the audio extraction sub-model in parallel to obtain the non-relational text feature vector, the non-relational image feature vector, and the non-relational audio feature vector at the same time;

[0072] S104. According to the relational feature vector, the non-relational text feature vector, the non-relational image feature vector, and the non-relational audio feature vector, construct a target structured or unstructured shared data feature space. If there is no corresponding type of data in the current transmission data, the corresponding feature vector in the shared data feature space is replaced with 0;

[0073] S105. According to the attribute links between relational and non-relational data in the input transmission data, construct the relevant attribute vectors of the output data type through the correlation coefficient algorithm, and add the relevant attribute vectors to the target structured or unstructured shared data feature space.

[0074] This process utilizes a pre-trained data type discrimination sub-model and a secondary classification model to accurately identify and classify different data types (relational, text, image, audio); then, call the corresponding sub-models for feature extraction for different types of data to ensure that the features of each data type can be fully analyzed. Especially for relational data, extract the index and hierarchical relationships to generate relational feature vectors; for non-relational data, process text, images, and audio in parallel to obtain the corresponding feature vectors respectively. Finally, construct attribute links through the correlation coefficient algorithm and integrate all feature vectors into the shared data feature space. This method not only improves the efficiency and accuracy of data processing but also ensures the integrity and consistency of the feature space.

[0075] S2. Obtain the data owner information, sharing path, shared target node information, target structured or unstructured shared data feature space, and the security level of the transmission data. Through the homomorphic encryption algorithm, obtain the final digital watermark corresponding to the data type, and embed it into the corresponding target structured data through the differential watermark embedding algorithm;

[0076] Furthermore, the specific process of embedding the generated watermark into the corresponding target structured data through the differential watermark embedding algorithm in this embodiment is as follows:

[0077] Non-relational data includes text data, image data, and audio data;

[0078] For text data: In addition to embedding the watermark in the label attributes, metadata area, and data structure hierarchical relationship corresponding to the text data, also embed the watermark in the annotation and description parts of the data. At the same time, utilize the schema information of XML or JSON data to hide the watermark in the corresponding relationship between the schema definition and the data instance;

[0079] For image data: In addition to embedding the watermark in the DCT domain and the visual perception domain, also embed the watermark in the phase spectrum of the image. Phase information plays a key role in image reconstruction. By embedding the watermark in the phase spectrum, the robustness and imperceptibility of the watermark are improved. At the same time, utilize the metadata area of the image (such as the shooting device, time, etc.) to embed auxiliary watermark information to enhance the concealment of the watermark.

[0080] For audio data: In addition to embedding watermarks in the time-frequency domain and the auditory perception sensitive frequency bands, watermarks are also embedded in the echo hiding domain of the audio. By adjusting the echo characteristics of the audio signal to hide the watermarks, the inaudibility of the watermarks is improved by taking advantage of the insensitivity of the human auditory system to echoes.

[0081] S3. According to the data owner information, sharing path, target information, and shared target node information, construct a data transmission traceability chain through zero-knowledge proof and distributed federated algorithms, and configure a data transmission distributed monitoring model in the data transmission traceability chain;

[0082] Furthermore, the distributed monitoring model in this embodiment includes an analysis control sub-model and M analysis sub-models;

[0083] Furthermore, the analysis control sub-model in this embodiment is constructed through a reinforcement learning algorithm, and the M analysis sub-models are constructed through a comprehensive evaluation model;

[0084] Furthermore, the analysis control sub-model and the M analysis sub-models in this embodiment are integrated through a federated algorithm, the analysis control sub-model is deployed on the node where the data owner is located, and the M analysis sub-models are deployed on the corresponding M target transmission nodes in the data transmission traceability chain;

[0085] Furthermore, the construction steps of the data transmission traceability chain in this embodiment include:

[0086] S301. According to the corresponding node information of the data owner, shared target node information, and the owner's historical shared target nodes, construct a data transmission traceability chain through a community discovery algorithm, and divide the data transmission traceability chain;

[0087] S302. If the corresponding node is both a node in the data transmission traceability chain and a historical shared target node, then divide the corresponding node into the familiar shared node community. If the corresponding node is only a node in the data transmission traceability chain, then divide the corresponding node into the initial shared node community;

[0088] S303. According to the sequence of corresponding data transmissions in the sharing path, mark the nodes in the data transmission traceability chain by combining the timestamp service of the blockchain and the cryptographic hash chain;

[0089] S304. Configure a path node discrimination model to discriminate the transmission process of the data after adding the watermark on the data transmission traceability chain, and determine whether the next transmission node is a node in the familiar shared node community. If so, verify the current node through the configured zero-knowledge proof algorithm and the key pair established by the corresponding node of the data owner. When the verification passes, transmit the data to the corresponding node.

[0090] S305. If the verification fails, feedback the corresponding verification information to the analysis and control sub-model, control the analysis sub-model configured for the corresponding node through the analysis and control sub-model, perform verification anomaly analysis, obtain the anomaly analysis result, construct the causal graph for the corresponding node according to the anomaly analysis result, and feedback the verification anomaly spectrum anomaly of the corresponding node to the analysis and control sub-model.

[0091] S306. According to the anomaly analysis result, evaluate the nodes with verification anomalies through the evaluation algorithm, obtain whether the anomaly of the corresponding node is a general anomaly or a malicious leakage anomaly, output the reputation evaluation score of the corresponding node, and transmit and mark the corresponding node through the smart contract in the blockchain according to the evaluation result and the feedback causal graph;

[0092] S307. When the transmission mark is a general anomaly and the reputation evaluation score of the corresponding node is greater than the configured trustworthy score threshold, then, through the encryption adjustment algorithm configured by the previous node, perform secondary enhancement on the data watermark encryption information transmitted to the corresponding node, and at the same time adjust the effective verification time interval configured in the historically established key;

[0093] Further, in this embodiment, the secondary enhancement of the data watermark encryption information of the node is obtained by increasing the number of encryption rounds. For example, originally, a 128-bit key length and 10 rounds of encryption are used, and the number of rounds is increased to 14 rounds during secondary enhancement;

[0094] Further, in this embodiment, a new key is also generated through a key derivation function (KDF) according to the original encryption key for secondary encryption;

[0095] S308. When the transmission mark is a general anomaly and the reputation evaluation score of the corresponding node is less than or equal to the configured trustworthy score threshold or is a malicious leakage anomaly, then delete the corresponding node from the data transmission traceability chain through the analysis and control sub-model, and update the shared path corresponding to the current data transmission traceability chain.

[0096] S309. When the next transmission node is a node in the initial sharing node community, then verify the current node through the configured zero-knowledge proof algorithm and the enhanced key pair established between the nodes of the data transmission traceability chain. When the verification passes, transmit the data to the corresponding node;

[0097] S310. When the verification fails, then delete the corresponding node from the data transmission traceability chain through the analysis and control sub-model, and update the shared path corresponding to the current data transmission traceability chain;

[0098] S311. If the current corresponding node is neither a node in the initial sharing node community nor a node in the familiar sharing node community, classify the corresponding node into the unfamiliar sharing node community;

[0099] S312. If the current node is a node in the unfamiliar shared node community, analyze and evaluate the current node information through the analysis sub-model configured by the previous node. At the same time, feedback the current node information to the corresponding node of the data owner, and judge whether the current node is a new transmission node added by the data owner through the analysis control sub-model;

[0100] S313. If so, configure the data parameter relationship corresponding to the current node by the data owner, establish the connection relationship between the previous node and the current node, configure the key of the corresponding transmitted data into the connection relationship between the previous node and the current node, and re-classify the current node into the initial shared node community;

[0101] S314. Repeat the process of S309 - S310 to perform data transmission verification and discrimination on the current node, and perform data sharing or node disconnection according to the discrimination result.

[0102] S315. If the current node is not a new transmission node added by the data owner, analyze the information obtained by scanning the current node through the analysis sub-model corresponding to the previous node, obtain whether there is an abnormal state in the history of the current node and obtain the corresponding node reputation evaluation score;

[0103] S316. If there is no abnormal state in the history of the current node and the node reputation evaluation score is greater than the trusted score threshold, share the corresponding analysis result information into the analysis control sub-model through the analysis sub-model corresponding to the previous node, and obtain the instruction of whether the data owner adds a node;

[0104] S317. When the data owner issues an instruction to add a node, control the analysis sub-model corresponding to the previous node through the analysis control sub-model. According to the same steps as S313, classify the current node into the initial shared node community, and at the same time repeat the steps of S314 to perform data sharing judgment;

[0105] S318. When the data owner does not issue an instruction to add a node, or there is an abnormal state in the history, or the node reputation evaluation score is less than or equal to the trusted score threshold, do not establish a connection relationship with the current node, mark the current node as abnormal, and save the marking result to the unfamiliar shared node community.

[0106] Furthermore, in this embodiment, the data transmission traceability chain includes a familiar shared node community, an initial shared node community, and an unfamiliar shared node community;

[0107] This process comprehensively ensures the security and controllability of data on the transmission traceability chain through a series of rigorous and efficient mechanisms. First, according to whether a node is a historical shared target node, the nodes in the data transmission traceability chain are accurately divided into the familiar shared node community and the initial shared node community to achieve refined management. Such classification facilitates the adoption of differentiated verification and processing strategies based on the historical sharing relationships of nodes, enhancing the security and efficiency of data transmission. For example, for nodes in the familiar shared node community, verification and data transmission can be quickly completed relying on existing historical sharing records, trust relationships, and keys. Secondly, for unfamiliar nodes, by analyzing and evaluating their information, it is determined whether they are new nodes added by the data owner, and whether to establish a connection is decided in combination with their historical status and reputation scores, which not only ensures the openness of the traceability chain but also effectively prevents potential risks. Furthermore, the nodes are marked by combining the timestamp service of the blockchain and the cryptographic hash chain to ensure that the data transmission order is traceable and the node information cannot be tampered with. At the same time, a path node discrimination model is configured, and a multi-level verification system is constructed by combining the zero-knowledge proof algorithm and the corresponding keys. Different keys are used for verification of nodes in different communities to enhance pertinence and security, effectively preventing illegal node access and data leakage. When the verification fails, the anomalies are deeply analyzed and a causal graph is constructed to dig out the root cause, and differentiated processing strategies are adopted according to the anomaly type and node reputation to maintain the security and stability of the traceability chain.

[0108] S4. Real-time monitor the transmission status of the data embedded with watermarks and the zero-knowledge proof evidence corresponding to each node in the data transmission traceability chain, analyze the data transmission status and the zero-knowledge proof evidence through the analysis sub-model configured for the corresponding node, and transmit the analysis results to the analysis and control sub-model corresponding to the data owner through parameter interaction in the distributed monitoring model;

[0109] Furthermore, the steps for obtaining the zero-knowledge proof evidence in S4 of this embodiment include:

[0110] S401. Configure the zero-knowledge proof protocol library, and according to the basic information and historical data transmission interaction information of the corresponding nodes in the familiar shared node community, the initial shared node community, and the unfamiliar shared node community divided according to the data transmission traceability chain, obtain the trustworthy data transmission score of the corresponding data transmission node through the evaluation algorithm;

[0111] S402. Construct a dynamic call factor for the zero-knowledge proof protocol according to the trustworthy data transmission score of the corresponding data transmission node and the community type to which the corresponding node belongs;

[0112] S403. Utilize the historical data and interaction information of the nodes recorded on the data transmission traceability chain, combine the data to be transmitted currently and the dynamic call factor of the knowledge proof protocol of the current corresponding data transmission node to call the corresponding zero-knowledge proof protocol, and generate the zero-knowledge proof evidence of the corresponding node;

[0113] Furthermore, the process of protocol selection and invocation in this embodiment includes:

[0114] When selecting a zero-knowledge proof protocol, in addition to relying on the system's encryption and security mechanisms, it is also dynamically adjusted in combination with the type of node community. For example, for nodes in a familiar shared node community, since the trust level between nodes is relatively high and data interaction is frequent, a more efficient and concise zero-knowledge proof protocol is selected, such as the zero-knowledge proof protocol based on homomorphic encryption. This protocol can quickly complete the proof process while ensuring security, improving data transmission efficiency. For nodes in a first-time shared node community and an unfamiliar shared node community, due to the low trust level in the nodes, a non-interactive concise verifiable proof protocol based on zero-knowledge proof with stronger security is selected. This protocol can provide higher security protection against attacks from malicious nodes.

[0115] Based on the zero-knowledge proof protocol selected according to the above community division results, when the prover determines the statement to be proved, in addition to covering the legality statements of data sources and sharing rules, specific statements related to the node community will also be added, making the data transmission verification process more secure and rigorous.

[0116] For example, for nodes in a familiar shared node community, the statement may include content related to the specific sharing history and trust relationship of the community. For nodes in a first-time shared node community, the focus of the statement is to prove the legality and compliance of itself as a newly joined node. For nodes in an unfamiliar shared node community, the statement needs to emphasize the security assessment and verification of unknown nodes.

[0117] Furthermore, the process of evidence generation in this embodiment includes:

[0118] The blockchain technology is introduced to assist in generating zero-knowledge proof evidence. The prover uses the historical data and interaction information of nodes recorded on the blockchain, combined with the data to be transmitted currently, to generate evidence.

[0119] For example, for nodes in a familiar shared node community, the historical successful interaction records between nodes in the community recorded on the blockchain can be used as part of the evidence generation to increase the credibility of the proof. For nodes in a first-time shared node community, the node registration information and initial verification records on the blockchain are used to generate evidence. For nodes in an unfamiliar shared node community, the security assessment information and historical abnormal records of the node are queried through the blockchain and incorporated into the evidence generation process to more comprehensively prove its own security.

[0120] S404. According to the community type to which the node belongs, differentially adjust the generation method of the challenge value according to the sharing rules, historical interaction patterns, sharing security levels, and security assessment factors among the nodes within the community, so as to obtain the challenge value of the node during the transmission verification process;

[0121] Furthermore, the security assessment factors in this embodiment include: node reputation, compliance factors, emergency response capabilities, and data sensitivity, etc.;

[0122] Among them, the node reputation is measured based on the historical performance of the node in the data transmission traceability chain;

[0123] For example, whether the node has completed data transmission tasks on time and accurately in the past, whether there are records of data loss, tampering, or leakage, and whether it complies with the agreed rules and protocols during the interaction with other nodes, etc.; Nodes with high reputation are more trustworthy in data transmission, while nodes with low reputation may have higher security risks.

[0124] The compliance factor is to check whether the node complies with relevant laws, regulations, industry standards, and specifications; For example, in terms of data privacy protection, whether it complies with the requirements of the data protection law, and whether the collection, use, and storage of user data have obtained legal authorization; In terms of data transmission security, whether it complies with the network security level protection system, etc. Nodes with high compliance can better guarantee the legality and security of data during the data transmission process.

[0125] The emergency response ability is to evaluate the emergency response ability of the node in the face of security incidents; It includes whether a perfect emergency plan has been formulated, whether emergency drills are carried out regularly, and whether it can quickly and effectively take measures to handle after a security incident occurs, reducing the impact of the security incident on data transmission.

[0126] The data sensitivity is to evaluate the security risk of the node according to the sensitivity of the data transmitted by the node; For nodes that transmit sensitive data (such as personal privacy information, business secrets, etc.), higher security protection measures and more stringent security assessments are required. The higher the data sensitivity, the higher the security requirements for the node, and the greater the weight of the corresponding security assessment factor.

[0127] Furthermore, the process of obtaining the challenge value of the node during the transmission verification process in this embodiment includes:

[0128] For nodes familiar with the shared node community, the generation of the challenge value can be obtained based on the sharing rules and historical interaction patterns within the community. For example, the challenge value is related to the common data operation types and frequencies within the community to verify whether the prover complies with the community rules;

[0129] For nodes in a node community sharing for the first time, the generation of the challenge value focuses on verifying the node's understanding and execution ability of basic sharing rules and security requirements, and may involve some general security verification issues;

[0130] For nodes in an unfamiliar node community for sharing, the generation of the challenge value is more strict and comprehensive. Combining the security assessment information and potential risk points of the node, a targeted challenge value is generated to deeply verify the security of the node.

[0131] S405. Build a dynamic verification model based on machine learning, and input the dynamically generated zero-knowledge proof evidence, the dynamic call factor of the zero-knowledge proof protocol, and the challenge value into the dynamic verification model for training to obtain a trained dynamic verification model. Then configure the trained dynamic verification model on the connection relationship between different nodes in the data transmission traceability chain to perform dynamic zero-knowledge proof verification.

[0132] Furthermore, in this embodiment, a dynamic verification model based on the type of node community is built. This dynamic verification model learns the normal verification modes and abnormal situation characteristics of different node communities. During the verification process, the response of the prover and the information related to the node community are input into the machine learning model, and the model judges whether the verification passes according to the learned knowledge. For example, for a familiar node community for sharing, the model learns the response mode of normal verification and common abnormal situations within the community, such as a specific response value range and abnormal response characteristics; for a node community sharing for the first time and an unfamiliar node community for sharing, the model learns their corresponding verification modes and abnormal characteristics respectively. With the assistance of the machine learning model, the verification result can be judged more accurately, especially to identify some potential abnormal situations.

[0133] Furthermore, the zero-knowledge proof protocol library configured in this embodiment includes: a first-level zero-knowledge proof protocol, a second-level zero-knowledge proof protocol, and a third-level zero-knowledge proof protocol. The strength relationship corresponding to the zero-knowledge proof protocols is: first-level zero-knowledge proof protocol < second-level zero-knowledge proof protocol < third-level zero-knowledge proof protocol; the dynamic call factors of the zero-knowledge proof protocol include a first-level call factor, a second-level call factor, and a third-level call factor; the first-level call factor corresponds to the first-level zero-knowledge proof protocol, the second-level call factor corresponds to the second-level zero-knowledge proof protocol, and the third-level call factor corresponds to the third-level zero-knowledge proof protocol.

[0134] Furthermore, the steps for generating the zero-knowledge proof evidence corresponding to the node in this embodiment include:

[0135] S4031. According to the community type to which the corresponding node belongs, when the corresponding data transmission node is a node in the familiar shared node community, the first-level zero-knowledge proof protocol is called through the first-level call factor, and combined with the historical successful data transmission interaction information between the corresponding node and the owner node, the zero-knowledge proof evidence of the corresponding node is generated;

[0136] S4032. When the corresponding data transmission node is a node in the initial shared node community, the second-level zero-knowledge proof protocol is called through the second-level call factor, and combined with the node registration information, initial verification record, and node addition protocol information recorded by the corresponding node in the data transmission traceability chain between the data owner node and the current node, the zero-knowledge proof evidence of the corresponding node is generated;

[0137] S4033. When the corresponding data transmission node is a node in the unfamiliar shared node community, the third-level zero-knowledge proof protocol is called through the third-level call factor, and combined with the scanning record information of the previous node for the current node, historical abnormal information, and the data owner node in the data transmission traceability chain, by analyzing the consent addition instruction information sent by the control sub-model, the zero-knowledge proof evidence of the corresponding node is generated.

[0138] Furthermore, the zero-knowledge proof evidence in this embodiment is dynamically obtained through the community type to which the node in the data transmission traceability chain belongs, the corresponding historical data and interaction information of the node, and the data transmission security level;

[0139] In this process of obtaining zero-knowledge proof evidence, the trustworthy transmission score is evaluated based on the node community type, basic information, and historical interaction information, a dynamic call factor is constructed, blockchain technology is combined to assist in evidence generation, and at the same time, the challenge value generation method is adjusted differently according to the community type. These measures enhance the pertinence and credibility of the evidence. In terms of protocol selection, it is dynamically adjusted in combination with the system encryption security mechanism and the node community type, taking into account both efficiency and security to meet the needs of different trust scenarios. A dynamic verification model based on machine learning is constructed to learn different community verification modes and abnormal characteristics, improve verification accuracy, and effectively identify potential anomalies. The hierarchical configuration of the zero-knowledge proof protocol library and the design of the corresponding call factors make the protocol call more hierarchical and precise. Overall, this process comprehensively guarantees the security, accuracy, and efficiency of zero-knowledge proof in the data transmission traceability chain from evidence generation, protocol selection to verification, and improves the adaptability and risk prevention and control capabilities of the entire system for different node communities.

[0140] S5. When the analysis control sub-model receives the analysis abnormal results of each sub-node, a leakage scenario node map is constructed through the analysis abnormal results of the sub-node, and the abnormal process of the transmission is traced to a specific node through the distributed monitoring model and the smart contract in the blockchain, and the corresponding transmission node is marked as abnormal or malicious according to the analysis and tracing results.

[0141] Furthermore, the abnormal or malicious marks in this embodiment are specifically as follows:

[0142] General abnormal mark: applicable to those abnormal situations that have a certain impact on data transmission but are not caused by malicious intentions. For example, due to network fluctuations, temporary system failures, etc., the node fails the verification briefly or the data transmission status is abnormal during data transmission. Such marks indicate that the abnormal situation of the node is relatively minor and may return to normal data transmission after appropriate processing.

[0143] Malicious leakage abnormal mark: for situations where there are clear signs that the node deliberately leaks data or violates the sharing rules, posing a serious threat to data security. For example, the node bypasses the security verification mechanism and transmits data to an unauthorized third party, or tampers with the data watermark encryption information to cover up illegal acts. Once marked as such, the node will be regarded as a serious threat and will be resolutely deleted from the data transmission traceability chain to prevent further data leakage.

[0144] Potential risk mark: given when certain behaviors or states of the node do not constitute obvious abnormalities or maliciousness but there is a potential risk of data leakage. For example, for a node in an unfamiliar shared node community, although its historical data does not show abnormalities, its reputation score is at a relatively low level, close to the trustworthy threshold. At this time, it can be marked as a potential risk for subsequent closer monitoring and evaluation.

[0145] Repeated abnormal mark: If a node repeatedly shows the same type of abnormal situation within a period of time, it can be marked as a repeated abnormal. This indicates that the node may have systematic problems and requires more in-depth inspection and repair to avoid continuous interference with data transmission.

[0146] Security vulnerability mark: made when it is found that the node has security vulnerabilities and these vulnerabilities may be maliciously exploited to affect data transmission security. For example, through security assessment, it is found that there are weaknesses in the encryption algorithm of the node, or there is a risk that the identity authentication mechanism of the node can be bypassed, etc.

[0147] Embodiment 2

[0148] An electronic device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, a whole-process traceability method for data sharing based on digital watermark technology is implemented.

[0149] A computer-readable storage medium stores computer instructions, and when the computer instructions run, a whole-process traceability method for data sharing based on digital watermark technology is executed.

[0150] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementations, which are merely illustrative and not restrictive. Under the guidance of the present invention, ordinary technicians in this field can also change, modify, replace and modify the above-mentioned embodiments without departing from the scope of protection of the purpose of the present invention and the claims, and all of these are protected by the present invention.

[0151] If the disclosed technical solution involves personal information, the product using the disclosed technical solution has clearly informed the personal information processing rules and obtained the individual's voluntary consent before processing the personal information. If the disclosed technical solution involves sensitive personal information, the product using the disclosed technical solution has obtained the individual's separate consent before processing the sensitive personal information, and at the same time meets the "explicit consent" requirement. For example, on personal information collection devices such as cameras, set clear and obvious signs to inform that the personal information collection scope has been entered and personal information will be collected. If the individual voluntarily enters the collection scope, it is deemed that he or she agrees to collect his or her personal information; or on the device for personal information processing, when the personal information processing rules are notified by obvious signs / information, the individual's authorization is obtained through pop-up information or by asking the individual to upload his or her personal information; the personal information processing rules may include information such as the personal information processor, the purpose of personal information processing, the processing method, and the type of personal information processed.

Claims

1. A data sharing whole process tracing method based on digital watermark technology, characterized in that: include: S1. Obtain multi-dimensional structured and unstructured data, and extract the integrated model through the configured differential structural features to obtain the target structured or unstructured shared data feature space; S2, obtain the data owner information, sharing path, sharing target node information, target structured or unstructured shared data feature space and transmission data security level, obtain the final digital watermark of the corresponding data type through the homomorphic encryption algorithm, and embed it into the corresponding target structure data through the differential watermark embedding algorithm; S3. Based on the data owner information, shared path and target information, and shared target node information, a data transmission traceability chain is constructed through zero-knowledge proof and distributed federation algorithm, and a data transmission distributed monitoring model is configured in the data transmission traceability chain; The data transmission traceability chain includes a familiar sharing node community, a first-time sharing node community, and an unfamiliar sharing node community; S4, real-time monitoring of the transmission status and zero-knowledge proof evidence of the data after watermarking for each node in the data transmission traceability chain, and analysis of the data transmission status and zero-knowledge proof evidence through the analysis sub-model configured for the corresponding node, and transmission of the analysis results to the analysis control sub-model corresponding to the data owner through parameter interaction in the distributed monitoring model; The zero-knowledge proof evidence is dynamically obtained through the community type to which the node belongs in the data transmission traceability chain, the historical data and interaction information corresponding to the node, and the security level of the transmitted data; S5. When the analysis and control sub-model receives the abnormal analysis results of each sub-node, it constructs a leakage scenario node map through the abnormal analysis results of the sub-node, and traces the abnormal transmission process to a fixed node through the distributed monitoring model and the smart contract in the blockchain, and marks the corresponding transmission node as abnormal or malicious according to the analysis and tracing results.

2. A data sharing whole process tracing method based on digital watermark technology as claimed in claim 1, characterized in that: The differential structural feature extraction integrated model includes a data type discrimination sub-model, a relational feature extraction sub-model, a text extraction sub-model, an image extraction sub-model and an audio extraction sub-model; The step of acquiring the target structured or unstructured shared data feature space includes: S101, according to the multi-dimensional structure and unstructured data, through the configured data type discrimination sub-model, obtain the data type corresponding to the structure or unstructure of the input transmission data; S102, inputting the relational data of the corresponding type into the relational feature extraction sub-model, performing feature extraction of the index relationship and the hierarchical relationship under the corresponding type data, and obtaining a relational feature vector; S103, inputting each type of non-relational data in the corresponding type into the text extraction sub-model, the image extraction sub-model and the audio extraction sub-model in parallel, and simultaneously obtaining a non-relational text feature vector, a non-relational image feature vector and a non-relational audio feature vector; S104, constructing a target structured or unstructured shared data feature space according to the relational feature vector and the non-relational text feature vector, the non-relational image feature vector, and the non-relational audio feature vector; S105. According to the attribute links between relational and non-relational data in the input transmission data, a correlation coefficient algorithm is used to construct an output data type related attribute vector, and the related attribute vector is added to the target structured or unstructured shared data feature space.

3. A data sharing whole process tracing method based on digital watermark technology as claimed in claim 2, characterized in that: The steps of constructing the data transmission traceability chain include: S301. According to the corresponding node information of the data owner, the shared target node information and the owner's historical shared target node, a data transmission traceability chain is constructed through a community discovery algorithm, and the data transmission traceability chain is divided; S302: if the corresponding node is both a node in the data transmission traceability chain and a historical sharing target node, the corresponding node is divided into a familiar sharing node community; if the corresponding node is only a node in the data transmission traceability chain, the corresponding node is divided into a first-time sharing node community; S303, according to the order of corresponding data transmission in the shared path, the nodes in the data transmission traceability chain are marked by combining the timestamp service of the blockchain with the encrypted hash chain; S304. Configure the path node discrimination model to discriminate the data after adding the watermark during the transmission process on the data transmission traceability chain, and discriminate whether the next transmission node is a node in the familiar shared node community. If so, verify the current node through the configured zero-knowledge proof algorithm and the key established by the corresponding node of the data owner. When the verification is passed, the data is transmitted to the corresponding node.

4. A data sharing whole process tracing method based on digital watermark technology as claimed in claim 3, characterized in that: The steps of constructing the data transmission traceability chain also include: S305. If the verification fails, the corresponding verification information is fed back to the analysis and control sub-model, and the analysis sub-model configured for the corresponding node is controlled by the analysis and control sub-model to perform verification exception analysis, obtain the exception analysis result, and construct a cause-effect graph of the corresponding node according to the exception analysis result, and feed back the verification exception graph of the corresponding node to the analysis and control sub-model; S306. According to the abnormality analysis result, the node with the verification abnormality is evaluated through the evaluation algorithm to obtain whether the corresponding node abnormality is a general abnormality or a malicious leakage abnormality, and the corresponding node reputation evaluation score is output. According to the evaluation result and the feedback causal graph, the corresponding node is marked for transmission through the smart contract in the blockchain; S307, when the transmission mark is generally abnormal and the corresponding node reputation evaluation score is greater than the configured trust score threshold, the data watermark encryption information transmitted to the corresponding node is secondary enhanced through the encryption adjustment algorithm configured by the previous node, and the valid verification time interval configured in the historically established key is adjusted; S308. When the transmission is marked as a general exception and the corresponding node reputation assessment score is less than or equal to the configured trust score threshold or is a malicious leakage exception, the corresponding node is deleted from the data transmission traceability chain through the analysis control sub-model, and the shared path corresponding to the current data transmission traceability chain is updated.

5. A data sharing whole process tracing method based on digital watermark technology as claimed in claim 4, characterized in that: The steps of constructing the data transmission traceability chain also include: S309: When the next transmission node is a node in the first-time shared node community, the current node is verified by the configured zero-knowledge proof algorithm and the enhanced key established between the nodes of the data transmission traceability chain. When the verification is passed, the data is transmitted to the corresponding node; S310: When the verification fails, the corresponding node is deleted from the data transmission traceability chain by analyzing the control sub-model, and the shared path corresponding to the current data transmission traceability chain is updated; S311, if the current corresponding node is neither a node in the first-time shared node community nor a node in the familiar shared node community, classify the corresponding node into the unfamiliar shared node community; S312: If the current node is a node in an unfamiliar shared node community, the current node information is analyzed and evaluated through the analysis sub-model configured by the previous node, and the current node information is fed back to the node corresponding to the data owner, and the analysis control sub-model is used to determine whether the current node is a new transmission node added by the data owner; S313, if yes, then configure the data parameter relationship corresponding to the current node through the data owner, establish a connection relationship between the previous node and the current node, configure the key corresponding to the transmitted data into the connection relationship between the previous node and the current node, and re-divide the current node into the first shared node community; S314, repeating the process of S309-S310, performing data transmission verification and determination of the current node, and performing data sharing or node disconnection according to the determination result.

6. A data sharing whole process tracing method based on digital watermark technology as claimed in claim 5, characterized in that: The steps of constructing the data transmission traceability chain also include: S315. If the current node is not a new transmission node added by the data owner, the information obtained by scanning the current node is analyzed through the corresponding analysis sub-model of the previous node to obtain whether there is an abnormal state in the history of the current node and obtain the corresponding node reputation evaluation score; S316. If there is no abnormal state in the history of the current node and the node reputation evaluation score is greater than the trust score threshold, the corresponding analysis result information is shared to the analysis control sub-model through the corresponding analysis sub-model of the previous node, and the instruction of whether the data owner to add the node is obtained; S317: When the data owner issues a node adding instruction, the analysis sub-model corresponding to the previous node is controlled by analyzing the control sub-model, and the current node is divided into the first sharing node community according to the same steps as S313, and the step S314 is repeated to make data sharing judgment; S318: When the data owner does not issue a node add instruction or there is an abnormal state in the history or the node reputation evaluation score is less than or equal to the trust score threshold, no connection relationship is established with the current node, the current node is marked as abnormal, and the marking result is saved to the unfamiliar shared node community.

7. A data sharing whole process tracing method based on digital watermark technology as claimed in claim 6, characterized in that: The steps of obtaining the zero-knowledge proof evidence in S4 include: S401, configuring a zero-knowledge proof protocol library, dividing the basic information and historical data transmission interaction information of corresponding nodes in the familiar sharing node community, the first-time sharing node community and the unfamiliar sharing node community according to the data transmission traceability chain, and obtaining the trusted data transmission score of the corresponding data transmission node through an evaluation algorithm; S402, constructing a dynamic call factor of a zero-knowledge proof protocol according to the trusted data transmission score of the corresponding data transmission node and the community type to which the corresponding node belongs; S403, using the node historical data and interaction information recorded on the data transmission traceability chain, combined with the data to be transmitted and the knowledge proof protocol dynamic call factor of the current corresponding data transmission node, call the corresponding zero-knowledge proof protocol to generate zero-knowledge proof evidence of the corresponding node; S404, according to the type of community to which the node belongs, and according to the sharing rules, historical interaction patterns, shared security levels, and security assessment factors among the nodes in the community, the generation method of the challenge value is adjusted differentially, so as to obtain the challenge value of the node in the transmission verification process; S405. Build a dynamic verification model based on machine learning, and input the dynamically generated zero-knowledge proof evidence, the dynamic call factor of the zero-knowledge proof protocol, and the challenge value into the dynamic verification model for training to obtain a trained dynamic verification model. Configure the trained dynamic verification model to the connection relationship between different nodes in the data transmission traceability chain to perform dynamic zero-knowledge proof verification.

8. A data sharing whole process tracing method based on digital watermark technology as claimed in claim 7, characterized in that: The configured zero-knowledge proof protocol library includes: a first-level zero-knowledge proof protocol, a second-level zero-knowledge proof protocol and a third-level zero-knowledge proof protocol, and the strength relationship corresponding to the zero-knowledge proof protocol is: a first-level zero-knowledge proof protocol < a second-level zero-knowledge proof protocol < a third-level zero-knowledge proof protocol; the zero-knowledge proof protocol dynamic call factor includes a first-level call factor, a second-level call factor and a third-level call factor; the first-level call factor corresponds to the first-level zero-knowledge proof protocol, the second-level call factor corresponds to the second-level zero-knowledge proof protocol, and the third-level call factor corresponds to the third-level zero-knowledge proof protocol.

9. A data sharing whole process tracing method based on digital watermark technology as claimed in claim 8, characterized in that: The step of generating the zero-knowledge proof evidence of the corresponding node includes: S4031. According to the community type to which the corresponding node belongs, when the corresponding data transmission node is a node in a familiar shared node community, the first-level zero-knowledge proof protocol is called through the first-level calling factor, and the historical successful data transmission interaction information between the corresponding node and the owner node is combined to generate the zero-knowledge proof evidence of the corresponding node; S4032. When the corresponding data transmission node is a node in the first shared node community, the secondary zero-knowledge proof protocol is called through the secondary call factor, and the node registration information, initial verification record and node addition protocol information between the data owner node and the current node recorded in the data transmission traceability chain are combined to generate the corresponding node's zero-knowledge proof evidence; S4033. When the corresponding data transmission node is a node in an unfamiliar shared node community, the three-level zero-knowledge proof protocol is called through the three-level calling factor, and the previous node in the data transmission traceability chain scans the record information, historical abnormal information and data owner node of the current node, and the consent to add instruction information issued by the control sub-model is analyzed to generate zero-knowledge proof evidence of the corresponding node.

10. A computer-readable storage medium, characterized in that: Computer instructions are stored thereon, and when the computer instructions are executed, a data sharing whole process tracing method based on digital watermark technology as described in any one of claims 1 to 9 is executed.

Citation Information

Patent Citations

  • A method for tracing the origin of relational data

    CN110232263B

  • Method for tracing relational data

    CN110232263A

  • Copyright protection method, system and equipment based on multiple watermarks and block chain and medium

    CN117118697A