An Endogenous Security Government Affairs Data Sharing Method Based on the Digital Object Architecture
Through the digital object architecture and dynamic heterogeneous redundant architecture, the inconsistency of standards, missing identification and security vulnerabilities in government data sharing are solved, and the efficiency, secure sharing and traceability of government data are achieved, and the practicality and security of data sharing are improved.
Patent Information
- Application Number
- CN202510327130.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-03-19
AI Technical Summary
Existing government data sharing faces problems such as inconsistent data standards, lack of unified identification, weak security control and difficulty in supervision and traceability. Traditional methods are difficult to achieve efficient and secure data sharing across domains and across systems.
The digital object architecture is adopted to encapsulate government data, metadata and computing resources into standardized data containers, and precise positioning and efficient access are achieved through digital object identification and coding. It combines dynamic heterogeneous redundant architecture and blockchain technology to ensure the security and traceability of data sharing.
It realizes the discoverability, accessibility, interoperability and traceability of government data, improves the efficiency of cross-departmental and cross-regional data coordination, enhances the transparency of security control and supervision, and meets the security requirements of "available and unavailable".
Smart Images

Figure CN119848146B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data sharing, and in particular to an endogenous security government data sharing method based on a digital object architecture. Background Art
[0002] With the rapid development of big data and "Internet +", government data, as an important national basic strategic resource, has an increasingly urgent need for sharing and opening. However, current government data sharing faces many challenges: First, data standards are inconsistent, resulting in difficult data interconnection and interoperability; second, there is a lack of unified identification, making it difficult to achieve accurate data positioning and efficient access; third, security control is weak, with risks of data leakage and tampering; fourth, supervision and traceability are difficult, and the data usage process is not transparent.
[0003] Traditional government data sharing methods mainly achieve it by establishing large data exchange platforms or data middle platforms. This method not only requires a large amount of data relocation, increasing system complexity, but also has security risks and is difficult to meet the security requirements of "usable but not available" for data. In addition, most existing methods adopt "post-remedial" security measures, such as external security products like firewalls and VPNs, which cannot fundamentally solve security problems.
[0004] Therefore, there is an urgent need for a new government data sharing method that can achieve efficient sharing and utilization of cross-domain and cross-system government data while ensuring data security. Summary of the Invention
[0005] The purpose of the present invention is to provide an endogenous security government data sharing method based on a digital object architecture, solve problems such as inconsistent data standards, lack of unified identification, and security vulnerabilities in existing government data sharing, and achieve discoverability, accessibility, interoperability, and traceability of government data.
[0006] To achieve the above object, the present invention provides an endogenous security government data sharing method based on a digital object architecture, including:
[0007] Encapsulating openable or authorized government data, metadata, computing resources, and data access mechanisms into standardized data containers, deploying them at the edge nodes of existing government information systems, and forming a multi-level government data space through containerized orchestration to achieve a collaborative operation architecture of cloud centralized control and edge node autonomous operation;
[0008] Based on the digital object architecture, the government affairs data within the container is abstracted into digital objects, and a unique digital object identification code is assigned to each digital object. The digital objects and their description information are registered in the digital object registration system and stored and maintained in the digital object repository system. The resolution of the identification code to the data entity is completed through the collaboration of the local identification registration and resolution system and the global identification registration and resolution system, where the access address of the global identification registration and resolution system is globally known and remains unchanged.
[0009] Through the collaboration of the digital object identification resolution system with the digital object interface protocol and the identification resolution protocol, cross-domain digital object location, discovery, approval, and access are realized. A data catalog is constructed based on metadata search and the data tag network, providing search and identification capabilities for cross-departmental and cross-regional data calls.
[0010] Based on the dynamic heterogeneous redundancy architecture, heterogeneous basic hardware, operating systems, and Web containers are run simultaneously as multiple heterogeneous execution bodies. The mimicry adjudication mechanism is used to perform consistency comparison on the output results of each execution body. If inconsistent output results are detected, the abnormal execution body is taken offline based on the voting result, and the abnormal execution body is automatically rotated and cleaned through virtual machine restart or container replacement.
[0011] A service catalog is constructed based on the digital object architecture. The mapping information of the data container is stored through the inverted index mechanism, and blockchain technology is introduced to perform distributed storage and hash chain recording on the catalog information, ensuring the traceability and immutability of the creation, update, and access processes of the service catalog.
[0012] Furthermore, micro-isolation technology is adopted between the data containers. The lateral flow between the data containers is restricted through the dynamic authentication and authorization mechanism, and only unidirectional data flow from the system to the data containers is allowed.
[0013] Furthermore, the government affairs data encapsulated in the data container includes structured data, unstructured data, and unstructured files. The metadata includes the hierarchical classification, tag features, and multi-angle description information of the data. The computing resources include computing modules for data processing and analysis. The data access mechanism includes identity authentication, permission control, and access auditing.
[0014] Furthermore, the digital object identification coding scheme is based on the Handle coding standard, including an identification prefix and an identification suffix. The identification coding prefix consists of a provincial code, a provincial / municipal department code, and a district / county code. The identification coding suffix consists of a basic classification code, a data resource code, a table sequence code, and a primary key code.
[0015] Furthermore, the dynamic heterogeneous redundancy architecture includes three levels of heterogeneous hierarchies:
[0016] Hardware layer: adopting a heterogeneous combination of processors with x86, ARM, and RISC-V architectures;
[0017] System layer: deploying a heterogeneous operating environment for CentOS, Windows Server, and Ubuntu operating systems;
[0018] Container layer: configuring a combined deployment of three Web containers, namely Tomcat, Nginx, and Jetty.
[0019] Furthermore, the service directory adopts an inverted index mechanism to establish inverted index mappings for the data and metadata in the data containers respectively, achieving a retrieval complexity independent of the dataset size and a relatively low time complexity. The blockchain technology adopts a consortium chain structure to automatically execute permission control and auditing for data sharing through smart contracts.
[0020] Furthermore, the global identifier registration and resolution system adopts a dual-active node deployment architecture to achieve global visibility of the access address through DNS load balancing technology, and the address is stored in a fixed manner in the blockchain. The service resolution of the global identifier registration and resolution system adopts a three-level node hierarchical query mechanism:
[0021] Top-level node: receiving a resolution request and routing it to the corresponding provincial node;
[0022] Provincial node: forwarding it to the district / county node after verifying the request permission;
[0023] District / county node: returning the physical address of the target data container.
[0024] Furthermore, the digital object interoperability is achieved through an open software architecture and a standardized interoperability protocol, supporting the interconnection and interoperability of data with different owners, in different locations, and of different architectures.
[0025] Furthermore, the cross-department and cross-regional data interoperability is achieved through a digital object interface protocol, specifically including steps of data invocation, access approval, and data transmission.
[0026] The beneficial effects of the present invention are:
[0027] By introducing the digital object architecture and the concept of endogenous security into the government affairs data sharing solution, the present invention effectively solves practical problems such as inconsistent data standards, missing identifiers, weak security control, and difficult traceability. The present invention adopts standardized data containers and multi-level government affairs data spaces, taking into account centralized control in the cloud and autonomous operation of edge nodes, effectively improving the data collaboration efficiency between departments and regions. Based on the digital object architecture, a unique identification code is assigned to each data resource. Combining the local and global identification registration and resolution systems, the target data can be accurately located and efficiently retrieved, improving the problems of low search efficiency and inconvenient access in the past. Through the dynamic heterogeneous redundancy (DHR) architecture and the mimicry adjudication mechanism, potential attack risks are suppressed from the bottom layer. By using the collaboration and consistency comparison of multiple heterogeneous execution bodies, abnormal execution bodies can be quickly identified and isolated, fundamentally strengthening the security control of data sharing. By introducing blockchain technology into the service catalog management and using distributed storage and hash chain recording means, it is ensured that the catalog or data call information is "traceable and tamper-proof", greatly improving the supervision transparency and facilitating legal and compliant audits. In addition, by constructing a data container and a dynamic authentication and authorization mechanism, the sharing requirements can be met without a large amount of data migration. While simplifying the system setup and maintenance costs, the principle of "available but not obtainable" is taken into account, improving the practicability and security of data sharing.
[0028] The innovation of the present invention lies in the effective combination of the digital object architecture and the endogenous security technology, providing an all-chain guarantee for government affairs data from identification establishment to secure sharing. Without reducing the sharing efficiency, the security and traceability of the system are greatly improved, which has important application value for the cross-regional and cross-departmental linkage of government affairs big data. Brief Description of the Drawings
[0029] Figure 1 is a schematic flow chart of the endogenous security government affairs data sharing method based on the digital object architecture of the present invention;
[0030] Figure 2 is a schematic diagram of the digital object architecture of the endogenous security government affairs data sharing method based on the digital object architecture of the present invention;
[0031] Figure 3 is a schematic diagram of the prefix structure of the government affairs digital object identification code of the endogenous security government affairs data sharing method based on the digital object architecture of the present invention;
[0032] Figure 4 is a schematic diagram of the suffix structure of the government affairs digital object identification code of the endogenous security government affairs data sharing method based on the digital object architecture of the present invention;
[0033] Figure 5 is a schematic diagram of the system model of the dynamic heterogeneous redundancy architecture of the endogenous security government affairs data sharing method based on the digital object architecture of the present invention;
[0034] Figure 6 It is a schematic diagram of the government data sharing process of the intrinsically secure government data sharing method based on the digital object architecture of the present invention. DETAILED DESCRIPTION
[0035] In order to better understand the technical solution, the method of the present invention is described in detail below with reference to the accompanying drawings and embodiments.
[0036] This embodiment provides an intrinsically secure government data sharing method based on a digital object architecture, which is used to solve the data sharing and circulation problems of inconsistent government data standards and lack of unified data identification, as well as data security issues such as backdoors and loopholes that may exist in government information systems. The current traditional data center model of government data governance cannot meet the needs. This embodiment is based on a digital object architecture and uses an intrinsically secure structure to solve government data security issues, which is suitable for secure and trusted sharing of government data.
[0037] like Figure 1 As shown, the steps of this embodiment include: first, data container, which forms a data container with the data to be opened, metadata, and access mechanism, and deploys it at the edge of the existing system; second, data space, which combines several data containers into a government data space for data sharing; third, government digital object architecture, which packages the data in the data container into a digital object based on the digital object architecture, and performs identification encoding; fourth, relying on the intrinsic security theory, by designing data sharing components that support the DHR architecture, the security and reliability of the data sharing process are guaranteed; fifth, the service directory, which uses the data object discovery capability of digital objects to ensure ease of use and efficiency in data sharing; sixth, data service, which uses the data interoperability capability of digital objects to parse the identification code into the desired data.
[0038] As the basic unit of the entire architecture, the data container refers to a virtualized unit that encapsulates open data, metadata, computing resources, and data access mechanisms. The first step in building a data container is to take inventory of data resources. In view of the characteristics of government data resources, such as large data volume, multiple data types, and outstanding data value, it is necessary to comprehensively sort out the data that can be used as resources. In reality, the construction of government informationization is built separately by various departments, and then integrated according to business needs in the later stage, which brings about problems such as data unavailability and data islands. Therefore, the first task is to understand the overall picture of departmental data resources and sort them out according to the principle of "whoever produces is responsible, whoever collects is responsible". Data resources can generally be divided into structured data, unstructured data, and unstructured files, and then the data is divided into general, important, and core data to prepare for further opening. It should also be made clear that data resource inventory is an ongoing and continuously optimized work, which requires the system platform to have the ability to dynamically update.
[0039] After the inventory of data resources, the data sources of government affairs information systems have been understood. Next, data source management is required, which is an important part of transforming data into data containers and lays the foundation for the creation of subsequent data services. Data source management supports various relational databases (such as MySql, Oracle, SqlServer, etc.) and non-relational databases (such as Mongo, ES, etc.), and provides functions for adding, deleting, modifying, and querying data sources, as well as synchronizing the table and field information of data sources. For example, for data of the table type, users need to add a data source through data source management first. For data of the audio, video, picture, and text file type, users need to upload the files to the specified object storage system first.
[0040] After the data source is determined, it is further necessary to collect the metadata information of the data source. Metadata provides functions for viewing metadata, editing the hierarchical classification of data, searching for metadata information, and adding metadata descriptions. After adding a data source, the system will automatically synchronize the metadata information of this type of data, such as field names, field types, indexes, constraints, etc. Then, continue to classify, layer, grade, divide the label characteristics of data objects, and describe data information from multiple perspectives for the metadata. Support for providing batch import of metadata information.
[0041] After the metadata collection is completed, due to the sensitivity and privacy of government affairs data, it is also necessary to audit the data to be opened. The content to be audited includes the integrity and accuracy of data resources, the validity of data models, the rationality of data flows, the clarity of data ownership and access rights, and data compliance requirements and security. The integrity and accuracy of data resources ensure that the inventory of data resources covers every data resource, preventing data protection gaps caused by omissions; the validity of data models, the data model should accurately reflect the data structure and data flow; the rationality of data flows, clarifying the data sources, destinations, and usage situations helps to identify the value and potential risks of data resources; the clarity of data ownership and access rights ensures that the ownership of each data resource is clear; data compliance requirements and security, auditing data resources to meet relevant regulations and compliance requirements, and evaluating the security performance of data resources.
[0042] After the above steps, a data container is finally formed. A data container contains open data, metadata, computing resources, and data access mechanisms. The data container is deployed at the edge of the government affairs information system and has complete identity and access management. The data container and the government affairs information system have one-way communication. Only the government affairs information system is allowed to flow data to the data container, and the data container cannot send any data or requests to the government affairs information system, effectively avoiding north-south traffic attacks.
[0043] After constructing a single data container, several data containers together constitute the government affairs data space, which becomes the basic environment for data sharing. In the government affairs data space, micro-isolation technology is adopted between data containers, and the access between data containers must undergo dynamic authentication and authorization to restrict the lateral flow of data or requests, effectively avoiding east-west traffic attacks.
[0044] To achieve the standardized management and interoperability of data in the government affairs data space, this embodiment introduces the digital object architecture, which is a data architecture built on top of the basic network mainly for data system interoperability and computing. Focusing on government affairs data, this embodiment provides an implementation of the government affairs digital object architecture. This architecture is a data-centric open software architecture, which is a logical extension of the Internet architecture, solves the management requirements of government affairs information systems, and realizes the interoperability between participating government affairs information systems. The digital object architecture abstracts data resources in the form of digital objects, and assigns an identifier to each digital object to uniquely and persistently identify each digital object, ensuring the persistent referability of resources. A digital object is a collection of a bit sequence or a series of bit sequences. Digital objects are used to abstract the data on the Internet, so that heterogeneous data resources can be encapsulated and modeled in a unified form, thus shielding the heterogeneity of data resources. A digital object is assigned a unique identifier to uniquely and persistently identify each digital object, regardless of factors such as the storage location and access method of the digital object. As Figure 2 shown, the digital object architecture includes two basic protocols, namely the Digital Object Identification / Resolution Protocol (DO-IRP) and the Digital Object Interface Protocol (DOIP), which are used for the creation, modification, deletion, and resolution of digital objects. The digital object architecture includes three core components, namely the digital object identification and resolution system, the digital object warehouse system, and the digital object registration system.
[0045] On the basis of establishing the digital object architecture, it is necessary to encode the digital object identification of government affairs data. Based on the Handle encoding standard, the present invention provides an identification encoding scheme applicable to government affairs data. The identification encoding, as the unique and unchanging identifier of the data object, consists of an identification prefix and an identification suffix, and the identification prefix and the identification suffix are separated by the UTF-8 character " / ". As Figure 3 shown, the government affairs digital object identification prefix is composed of the provincial code, the provincial / municipal department code, and the district / county code, separated by the UTF-8 character ".". As Figure 4As shown, the identification suffix is composed of a basic classification code, a data resource code, a table sequence code, and a primary key code. The basic classification code consists of 5 digits and classifies the form of the data resource. The code is divided into three levels and is used to identify data objects in terms of the form of the data resource. The data resource code is used to identify the object of the data resource. The table sequence code and the primary key code consist of variable-length digits and are both optional codes used to identify tables in the database.
[0046] This standardized identification coding scheme is conducive to the sharing and exchange of data from different owners, locations, and architectures, and thus provides great help in eliminating the problems of data chimneys and data islands. The government affairs data identification coding scheme can be compatible with mainstream identification coding structures, specifications, and standards, providing a basis for address resolution for the identification resolution of each level of nodes. Based on the segmented prefix and the prefix code combined with the administrative division code coding, it is more conducive to hierarchical structure management of data resources from the geopolitical dimension.
[0047] After the identification coding is completed, the digital object discovery function needs to be implemented. The digital object discovery method helps users or systems quickly find the required digital objects through specific mechanisms or tools. In the data interconnection and sharing network based on the digital object architecture, data providers characterize data resources based on usage scenarios in different regions or fields, encapsulate the data resources in their data platforms and systems into digital objects, obtain a standardized identification from the identification resolution system as the unique identification of the digital object, register the description information as metadata in the registry system, store and manage the digital objects in the digital object warehouse system, and thus achieve the standardized encapsulation, discoverability, addressability, and usability of data resources. Based on digital object registration and collaborative metadata search to form a data directory and a data label network, it can achieve cross-domain data resource discovery and identification, and at the same time support the precise search and fuzzy query of data objects.
[0048] Corresponding to digital object discovery is digital object resolution. The digital object identification resolution method accurately locates the required digital object by resolving the identifier of the digital object into a specific access address. The identification is used to uniquely and persistently identify each digital object. By resolving the identification of the digital object, the data corresponding to the digital object entity can be obtained, realizing the access to cross-domain data resources. The digital object identification resolution system is one of the three basic components in the digital object architecture system, mainly responsible for the identification and resolution of digital objects. Data users use the identification resolution technology through the identification network to address and access the required digital objects from a large amount of digital resources. In the hierarchical identification network, users accurately locate cross-domain data scattered in the Internet environment by searching for the identification layer by layer.
[0049] Finally, the digital object interoperability ability is realized, that is, independent systems or platforms can recognize, exchange, and use each other's data objects, so as to achieve cross-system data sharing and business collaboration. The interoperability of data objects helps to establish logical or physical connections between data objects, enabling data to be interconnected and shared among different systems or platforms. The digital object architecture is essentially a system physically distributed in different locations. To achieve data sharing and exchange across organizations, domains, and systems, all data resources are established as independent digital objects, and data is defined through a basic model. This standardized processing enables data from different sources and in different formats to be managed and operated within a unified framework.
[0050] In the process of data sharing, security issues are particularly important. Traditional data security protection often adopts an overlay security defense system. Whether it is engineering implementation technologies such as blockchain, zero trust, and encryption authentication, it is impossible to avoid endogenous security problems. Compared with traditional data security, endogenous security suppresses data security, functional security, and information security problems existing in the form of differential mode within the structure through the DHR architecture. As Figure 5 shown, in the DHR system model, the concept of data infrastructure can be large or small. It can be the entire government data space or a middleware in the data flow process. The IPO model of the DHR system is: Inputs -> Agent -> Processes -> Adjudication -> Outputs, that is, the entire process of input -> agent -> multiple execution bodies processing -> adjudication -> output.
[0051] Based on the DHR architecture, a data security sharing component is designed in this embodiment. Regarding attacks on data, vulnerability backdoors often hijack the communication process of facilities or directly control facilities. Therefore, the key point of the solution lies in timely detecting hijacked data components and modified data packets, and rotating the malicious application. An equivalent heterogeneous data sharing component, as an execution entity, consists of heterogeneous basic hardware, heterogeneous operating systems, and heterogeneous web containers. The hardware generally includes CPUs with architectures such as x86, ARM, and RISC-V. The heterogeneous operating systems can be selected from CentOS, Ubuntu, Windows Server, etc., and can also adapt to the requirements of domestic data infrastructure. This makes the instruction set architecture, operating system, and runtime diverse. Different manufacturers' basic hardware and operating systems with different architectures are used to achieve the heterogeneity of the data infrastructure. The heterogeneous web containers include deploying equivalent heterogeneous software on containers such as Tomcat, Nginx, and Jetty to achieve the heterogeneity of the web containers. When there is a data access request, multiple equivalent heterogeneous execution entities execute redundantly, and the arbiter judges the consistency of the data returned by different execution entities, and votes on the returned data through the arbiter. For the returned results of the heterogeneous execution entities that pass the vote, record the redundant execution status and allow the passed execution entities to output data, and return the response to the request side. For the requests of heterogeneous execution entities that do not pass the vote, block the behavior of the corresponding heterogeneous execution entity application from accessing and modifying the persistently stored data, report the application status of the corresponding heterogeneous execution entity, and at the same time rotate the application of the heterogeneous execution entity. This method can effectively resist the attack of differential-mode vulnerabilities.
[0052] After implementing the data security sharing component, in order to improve the convenience of data sharing, a government service catalog is constructed in this embodiment. The service catalog will display all digital objects in the government data space and the data services that can be provided. According to the digital object discovery ability, a standardized service list is formed, and different service views are formed according to different classifications to facilitate service query. The service catalog provides functions for ordinary users to view the published service list, preview data, display service details, apply for services, and evaluate services at this node and across nodes / departments. The digital object retrieval of the service catalog adopts the method of inverted index, and inverted index mappings are established for the data and metadata in the data container respectively. In this way, the retrieval complexity independent of the dataset size and a low time complexity can be achieved, which is crucial for the retrieval of massive government data.
[0053] To ensure the reliability of service catalog information, this embodiment also uses blockchain technology to ensure the traceability and immutability of service catalog information. The service catalog adds new service catalogs and updates the status of service catalogs in the blockchain system through operations such as uploading to the chain and downloading services. Each update of the service catalog will be recorded on the blockchain, forming a complete historical record chain. By using the Hash value and consecutive block numbers of the blockchain, it is ensured that once the service catalog content is uploaded to the chain, it cannot be tampered with. The Hash value of each block depends on the Hash value of the previous block, forming a chain structure. The Hash value within the block and the consecutive block numbers ensure the immutability of the service catalog, and the distributed storage structure ensures that data is difficult to lose. The service catalog data is stored on multiple nodes of the blockchain, and each node stores a complete data copy, enhancing the security and reliability of the data.
[0054] Based on the service catalog, this embodiment further provides government affairs data services. The data service has a DHR structure and is deployed on the cloud platform. By using the ability of digital object resolution, the data is resolved into the data that wants to be obtained through identification coding. The identification resolution system includes a local identification registration and resolution system LRS and a global identification registration and resolution system GRS. GRS is a special identification resolution system, and its access address is globally known and unchanged. The digital object repository is responsible for encapsulating digital resources into digital objects and managing digital objects. The digital object obtains a unique identifier from the identification resolution system, and at the same time, the metadata of the digital object is registered in the digital object registry, and the registry establishes a metadata index for it.
[0055] Through identification resolution, the status information of the digital object can be located in the hierarchical identification resolution system, and then the warehouse address where the digital object is located can be queried. The digital object corresponding to the identifier can be obtained by retrieving the warehouse. By searching keywords, data distributed in different node systems can be discovered based on metadata. Relying on the open software architecture and two basic standard protocols, it is possible to efficiently connect various data platforms and systems, supporting the interconnection and interoperability of data with different owners, in different locations, and of different types.
[0056] Integrating the above components, a complete government affairs data sharing process is finally formed. The government affairs data space is a system physically distributed in different locations. It is necessary to build several system nodes on the Internet and network them based on standard protocols to form a networked software system, supporting the identification, resolution, search, discovery, and use of data in the form of digital objects on the Internet. The components in data sharing adopt the DHR architecture, which can ensure security in data sharing and circulation. The sharing process is as Figure 6 shown.
[0057] Taking the data circulation and sharing process across nodes as an example, assume that the data provider and the data user are located at the third-level node and the top-level node respectively. Data provider a publishes a data service in system B (third-level node), and the published service will be uploaded to the chain. After being uploaded to the chain, data user b sees this service in the service catalog in system A (top-level node) and applies for the service. System A will parse according to the prefix code of the node where the service is located and send a service application request to node B. After system B receives the service application request, data provider a needs to approve the request, and the approval result is either passed or rejected. If it is rejected, the data sharing process ends. Assuming that the approval result is passed at this time, system B needs to parse according to the application node identification code and send the application approval result to system A. At the same time, the application approval will be uploaded to the chain. After data user b sees that the approval has passed, it will subscribe to the service. System A sends a subscription request to system B again, and system B will return a subscription voucher and related parameters to system A. Finally, data user b gets the subscription-related information and can obtain the data. At the same time, our component adopts the DHR architecture and can provide data security guarantee.
[0058] Through the above implementation manners, the present invention realizes an endogenous security government affairs data sharing method based on a digital object architecture, solves problems such as inconsistent government affairs data standards, lack of unified identification, and security vulnerabilities, and realizes the discoverability, accessibility, interoperability and traceability of government affairs data.
Claims
1. An endogenous security government data sharing method based on the digital object architecture, characterized in that, Including: Encapsulate the openable or authorizable government affairs data, metadata, computing resources, and data access mechanisms into a standardized data container, deploy it on the edge nodes of the existing government affairs information system, and form a multi-level government affairs data space through containerized orchestration to achieve a collaborative operation architecture of centralized cloud control and autonomous operation of edge nodes; Based on the digital object architecture, abstract the government affairs data in the container into digital objects, and assign a unique digital object identification code to each digital object. The identification code is based on the Handle coding standard, including an identification prefix composed of a provincial code, a provincial / municipal department code, and a district / county code, and an identification suffix composed of a basic classification code, a data resource code, a table sequence code, and a primary key code; register the digital object and its description information in the digital object registration system, and store and maintain it in the digital object warehouse system; Complete the resolution of the identification code to the data entity through the cooperation of the local identification registration and resolution system and the global identification registration and resolution system. The global identification registration and resolution system adopts a dual-active node deployment architecture, and realizes that the access address is globally visible and unchanged through DNS load balancing technology, and the service resolution adopts a three-level node hierarchical query mechanism: the top-level node receives the resolution request and routes it to the corresponding provincial node, the provincial node forwards it to the district / county node after verifying the request permission, and the district / county node returns the physical address of the target data container; Through the digital object identification resolution system to coordinate the digital object interface protocol and the identification resolution protocol, realize cross-domain digital object location, discovery, approval and access, and build a data directory based on metadata search and data tag network to provide search and identification capabilities for cross-departmental and cross-regional data calls; Based on the dynamic heterogeneous redundancy architecture, run heterogeneous basic hardware, operating systems, and Web containers as multiple heterogeneous execution bodies at the same time. Among them: the hardware layer adopts a heterogeneous combination of x86, ARM, and RISC-V architecture processors; the system layer deploys a heterogeneous running environment of CentOS, Windows Server, and Ubuntu operating systems; the container layer configures a combined deployment of three Web containers, Tomcat, Nginx, and Jetty; Perform consistency comparison on the output results of each execution body through the mimicry adjudication mechanism; if the output results are detected to be inconsistent, offline the abnormal execution body based on the voting results, and automatically rotate and clean the abnormal execution body by restarting the virtual machine or replacing the container; Build a service directory based on the digital object architecture, store the mapping information of the data container through the inverted index mechanism, and introduce blockchain technology to perform distributed storage and hash chain recording on the directory information. The blockchain technology adopts a consortium chain structure to automatically execute the permission control and auditing of data sharing through smart contracts, ensuring the traceability and immutability of the creation, update, and access processes of the service directory.
2. The method for sharing government affairs data with built-in security based on the digital object architecture according to claim 1, wherein: The micro-isolation technology is adopted between the data containers, and the lateral flow between the data containers is restricted through the dynamic authentication and authorization mechanism, and only the unidirectional data flow from the system to the data container is allowed.
3. A method for sharing endogenous security government affairs data based on a digital object architecture according to claim 1, characterized in that: The government affairs data encapsulated in the data container includes structured data, unstructured data, and unstructured files. The metadata includes the hierarchical classification, label features, and multi-angle description information of the data. The computing resources include computing modules for data processing and analysis. The data access mechanism includes authentication, permission control, and access auditing.
4. A method for sharing government affairs data with built-in security based on a digital object architecture according to claim 1, characterized in that: The service directory adopts an inverted index mechanism to establish inverted index mappings for the data and metadata in the data container respectively, achieving a retrieval complexity independent of the dataset size and a low time complexity.
5. A method for sharing endogenous security government affairs data based on a digital object architecture according to claim 1, characterized in that: The digital object interoperability is realized through an open software architecture and a standardized interoperability protocol, supporting the interconnection and interoperability of data with different owners, in different locations, and of different types.
6. The method for sharing government affairs data with built-in security based on the digital object architecture according to claim 1, wherein: The cross-department and cross-region data interoperability is realized through the digital object interface protocol, which specifically includes the steps of data invocation, access approval, and data transmission.
Citation Information
Patent Citations
Universal distributed heterogeneous data integrated physical convergence, organization, release and service method and system
CN111259006A
Mimicry defense system
CN114448711A
Government affair data transparent sharing method and storage medium
CN118096058A