A data sharing optimization method based on HarmonyOS distributed data management
By combining data encryption methods with quantum encryption and hash function, combined with device fingerprint credibility and permission verification of environmental risks, data transmission strategies are optimized, and the security and efficiency of traditional data sharing mechanisms are solved, and efficient and secure data sharing in complex scenarios such as smart medical care is realized.
Patent Information
- Application Number
- CN202510473116.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-04-16
AI Technical Summary
The traditional data sharing mechanism has significant disadvantages in security, permission management and transmission efficiency, and it is difficult to meet the data circulation needs in complex scenarios. Especially in smart medical scenarios, data security is difficult to resist quantum attacks, permission verification is too simple, transmission method is inflexible, resulting in data loss or excessive energy consumption.
An encryption algorithm based on the principle of quantum encryption and hash function is adopted to generate dynamic key sequences through quantum randomness and chaotic systems, bind data features for quantum gate encryption, and store data in the Hongmeng distributed database; a weighted permission verification model for device fingerprint credibility, user behavior matching and environmental risks is built; an adaptive data transmission algorithm is built using reinforcement learning to optimize transmission strategies based on device performance and network conditions.
Effectively resist quantum attacks, improve data security, accurately verify permissions, optimize transmission efficiency, realize efficient and secure data sharing, and ensure the security and reliability of data in complex environments.
Smart Images

Figure FHA0000012070820000011 
Figure FHA0000012070820000021 
Figure FHA0000012070820000022
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data sharing, and particularly relates to a data sharing optimization method based on HarmonyOS distributed data management. Background Art
[0002] At present, with the rapid popularization of the Internet of Things and intelligent devices, the demand for cross-device and cross-platform data sharing is increasing day by day. Taking the intelligent medical scenario as an example, doctors, patients, inspection devices, and cloud servers need to share key information such as medical record data, imaging materials, and monitoring indicators in real time to support remote diagnosis and treatment, health management, and scientific research analysis. However, the traditional data sharing mechanism has significant drawbacks in terms of security, permission management, and transmission efficiency, and it is difficult to meet the data circulation requirements in complex scenarios. In terms of data security, traditional encryption algorithms are difficult to resist the continuously upgraded quantum attacks, and data faces the risks of being stolen and tampered with during transmission and storage, which makes the protection of sensitive data extremely difficult. In the field of permission management, the existing verification methods are often too simple, relying only on a single factor for identity verification, and unable to comprehensively consider multiple factors such as devices, user behaviors, and environments, which easily leads to misjudgment of permissions and gives illegal users an opportunity. In addition, there is also a lack of an adaptive mechanism during data transmission, which cannot flexibly adjust the transmission method and rate according to device performance and network conditions, often resulting in problems such as too long transmission time, data loss, or excessive energy consumption, reducing the efficiency and experience of data sharing. Summary of the Invention
[0003] In view of the above technical problems existing in the background art, the present invention proposes a data sharing optimization method based on HarmonyOS distributed data management.
[0004] To achieve the above object, the technical solution adopted by the present invention is as follows, including the following steps:
[0005] S1. The data provider uses an encryption algorithm to encrypt the original data to generate encrypted data. The encryption algorithm combines the quantum encryption principle with a hash function, through the one-time use of the quantum key and the extraction of data features by the hash function;
[0006] S2. Store the encrypted data in the HarmonyOS distributed database, assign a unique distributed data identifier to it, and record the meta-information of the data, including data type, data size, and creation time;
[0007] S3. The data requester sends a data sharing request to the data provider, and the request includes its own device identifier, user identity information, and relevant descriptions of the requested data;
[0008] S4. After receiving the request, the data provider verifies the identity and permissions of the data requester according to the preset permission verification rules;
[0009] The permission verification rule is as follows: By inputting the device fingerprint credibility S device , the user behavior matching degree S user and the environmental risk R env into the weighted model, the permission score F is obtained: where ω d , ω u are the weights of the user behavior matching degree and the device fingerprint credibility, α and β are non-linear power parameters, γ are respectively the environmental risk suppression coefficients, and δ and η are the adjustment parameters of the environmental risk suppression factor. The higher the device fingerprint credibility, the stronger the tolerance for environmental risks; when the obtained permission score is greater than the threshold of 0.7, it indicates that the verification is passed, otherwise the access request is immediately blocked;
[0010] S5. If the verification is passed, the data provider determines the optimal data transmission method and transmission rate according to the device performance and network conditions of the data requester, extracts the encrypted data from the HarmonyOS distributed database and transmits it to the data requester;
[0011] S6. After receiving the encrypted data, the data requester decrypts the data using the decryption key stored locally to obtain the original data.
[0012] Preferably, the specific implementation of the encryption algorithm in step S1 is as follows: Generate a dynamic key sequence using quantum randomness and a chaotic system; Bind the data features to the key to resist quantum collision attacks; Perform dynamic quantum gate encryption.
[0013] Preferably, the implementation of generating a dynamic key sequence using quantum randomness and a chaotic system is as follows: First, generate an initial seed key S∈{0,1} λ using a quantum random number generator, satisfying λ≥256, and then input the quantum seed S into the mapped chaotic system to generate a chaotic sequence K. The chaotic sequence is where x k is the intermediate state value of the chaotic system, K k is the dynamic key generated by the chaotic system, μ is the parameter of the chaotic system, and the calculation method is: μ = 3.99 + 0.01·SHA3(S)mod2 16 ;
[0014] Preferably, after generating the dynamic key sequence, the implementation of binding the data features to the key to resist quantum collision attacks is to divide the original data D into blocks, calculate the quantum-resistant hash for each block and project it into a vector, and perform non-linear confusion on the chaotic sequence K and the hash feature H. The calculation method is: where is the bitwise exclusive OR operation, and K′ is the confused key.
[0015] Preferably, a quantum gate operation matrix is constructed based on the obfuscated key to implement encryption: K' is divided into control parameters to generate a set of dynamic quantum gates {U i}: where R Y is a Y-axis rotation gate, CNOT is a controlled NOT gate, and the data block D i is encoded into a quantum state |ψ i >, and the encrypted quantum state |ψ enc > is obtained by applying a sequence of quantum gates: where represents the tensor product. Finally, the encrypted quantum state is subjected to a basis measurement to generate a classical ciphertext C i : C i = Measure(|ψ enc , basis = K i ' mod 2).
[0016] Preferably, before data encryption in step S1, the data also needs to be de-duplicated. The semantic features, structural features, and time features of the data are extracted, the extracted multi-dimensional features are fused, the principal component analysis is used to transform the high-dimensional feature vectors into low-dimensional vectors, and a distributed hash table is used to construct a feature index. Each node is responsible for storing part of the feature index information, and the feature vectors are mapped to different nodes through a hash function. When new data needs to be stored, its feature vectors are calculated and whether there are similar features is searched in the distributed hash table;
[0017] For the similar features, a threshold is set. When the similarity between the feature vectors of the new data and the feature vectors of the already stored data exceeds the threshold, it is determined as duplicate data, and the similarity is calculated using the cosine similarity method.
[0018] Preferably, the implementation of the adaptive data transmission algorithm in step S5 is as follows: An intelligent decision-making model based on reinforcement learning is constructed. The device performance and network conditions are used as the environmental state vectors, the transmission mode and transmission rate are used as the action space, and a multi-objective optimization algorithm is adopted to find the optimal solution among multiple objectives such as the shortest transmission time, the highest data integrity, and the lowest energy consumption, and determine the optimal data transmission mode and transmission rate.
[0019] Compared with the prior art, the advantages and positive effects of the present invention are that, at the encryption level, it combines the principles of quantum encryption with hash functions, uses quantum randomness and chaotic systems to generate keys, binds data features and performs quantum gate encryption, effectively resists quantum attacks and ensures data security. In the authority verification stage, a weighted model is constructed by integrating factors such as device fingerprint credibility, user behavior matching and environmental risks to accurately evaluate authority and reduce the risk of misjudgment. In the data transmission stage, an intelligent decision-making model is constructed based on reinforcement learning. According to device performance and network conditions, the optimal transmission strategy is determined through multi-objective optimization to achieve a balance between transmission time, integrity and energy consumption. These innovative technologies work together to improve the security, accuracy and efficiency of data sharing and solve traditional technical problems. DETAILED DESCRIPTION
[0020] In order to more clearly understand the above-mentioned purpose, features and advantages of the present invention, the present invention is further described below in conjunction with embodiments. It should be noted that the embodiments of the present application and the features in the embodiments can be combined with each other without conflict.
[0021] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may also be implemented in other ways than those described herein. Therefore, the present invention is not limited to the specific embodiments of the following disclosure.
[0022] Embodiment: In response to the special needs of smart medical scenarios, the present invention proposes a data sharing optimization method based on Hongmeng distributed data management to ensure the reliability of medical data in the entire link of "secure storage-accurate authorization-efficient transmission".
[0023] First, when the hospital imaging system uploads CT image data, the multi-dimensional features of the data are extracted. Before the data is encrypted, the data needs to be deduplicated to extract the semantic features, structural features and time features of the data, and the extracted multi-dimensional features are fused. The high-dimensional feature vector is converted into a low-dimensional vector using principal component analysis, and a feature index is constructed using a distributed hash table. Each node is responsible for storing part of the feature index information. The feature vector is mapped to different nodes through a hash function. When new data needs to be stored, its feature vector is calculated and a search is performed in the distributed hash table to determine whether there are similar features. The similarity feature is to set a threshold. When the similarity between the feature vector of the new data and the feature vector of the stored data exceeds the threshold, it is determined to be duplicate data. The similarity calculation is performed using the cosine similarity method.
[0024] Next, for the security of data during storage and transmission, considering that existing data encryption technologies have the defect of being difficult to resist quantum attacks, and with the rapid development of quantum computing technology, traditional encryption algorithms are at risk of being cracked, and data is extremely vulnerable to being stolen and tampered with during transmission and storage. Therefore, the present invention adopts an encryption algorithm based on the combination of quantum encryption principle and hash function. A dynamic key sequence is generated by using the quantum random number generator and chaotic system of the hospital's trusted node. The initial seed key is generated by the quantum random number generator, and then it is transformed into a chaotic sequence through a specific chaotic system. This key generation method greatly improves the randomness and complexity of the key, making it difficult for attackers to crack. After that, the data features are bound to the key, and by calculating the quantum-resistant hash for each block of the original data and projecting it into a vector, and performing non-linear confusion with the chaotic sequence, quantum collision attacks can be effectively resisted, further enhancing the security of the data. Finally, a quantum gate operation matrix is constructed based on the confused key for dynamic quantum gate encryption, encoding the data block into a quantum state, and generating a classical ciphertext after encryption by the quantum gate sequence.
[0025] The implementation of generating the dynamic key sequence by using quantum randomness and chaotic system is that first, an initial seed key S∈{0,1} is generated by the quantum random number generator λ , satisfying λ≥256, and then the quantum seed S is input into the mapped chaotic system to generate a chaotic sequence K. The chaotic sequence is where x k is the intermediate state value of the chaotic system, K k is the dynamic key generated by the chaotic system, μ is the chaotic system parameter, and the calculation method is: μ = 3.99 + 0.01·SHA3(S) mod 2 16 . After generating the dynamic key sequence, the data features are bound to the key. The implementation of resisting quantum collision attacks is to divide the original data D into blocks, calculate the quantum-resistant hash for each block and project it into a vector, and perform non-linear confusion on the chaotic sequence K and the hash feature H. The calculation method is: where is the bitwise exclusive OR operation, and K′ is the confused key. Finally, a quantum gate operation matrix is constructed based on the confused key to achieve encryption: K′ is divided into control parameters to generate a set of dynamic quantum gates {U i}: where R Y is the Y-axis rotation gate, CNOT is the controlled NOT gate, q represents the quantum bit, and the data block D i is encoded into the quantum state |ψ i >, and the encrypted quantum state |ψ enc > is obtained by applying the quantum gate sequence: where represents the tensor product, and finally performs basis measurement on the encrypted quantum state. j represents the level of quantum gate application to generate the classical ciphertext C i :C i =Measure(|ψ enc >,basis=K i Compared with traditional encryption algorithms, it can better cope with the threat of quantum attacks, and comprehensively improve data security from key generation, data and key binding to encryption operations.
[0026] The encrypted CT image data is then stored in the Hongmeng distributed database, and a unique distributed data identifier is assigned to it for easy data management and retrieval. At the same time, the metadata of the data is recorded, including data type, data size, and creation time. Through distributed storage, servers in different hospital districts can synchronize image data in real time, support doctors to access data across hospital districts, and avoid data loss caused by single point failures.
[0027] Patients initiate data sharing requests to hospital servers through mobile devices. The requests include their own device identification, user identity information, and descriptions of the requested data, such as requesting customer transaction record data within a specific time period. After receiving the request, the data provider verifies the identity and authority of the data requester according to the preset authority verification rules.
[0028] Considering that the existing permission verification does not take into account multiple factors such as device fingerprint credibility, user behavior matching, and environmental risks, it only relies on a single factor for identity authentication, which has the defect of misjudgment of permissions. This allows illegal users to exploit verification loopholes to obtain data access rights, resulting in serious threats to data security and failure to ensure data privacy and integrity. The permission verification rule in the present invention is: the hospital server passes the device fingerprint credibility S device , User behavior matching degree S user and environmental risk R env Input the weighted model and get the authority score F: where ω d ,ω u is the weight of user behavior matching and device fingerprint credibility, α and β are nonlinear power parameters, γ is the environmental risk suppression coefficient, δ and η are the adjustment parameters of the environmental risk suppression factor. The higher the credibility of the device fingerprint, the stronger the tolerance to environmental risks. When the obtained permission score is greater than the threshold of 0.7, it indicates that the verification is passed, otherwise the access request is blocked immediately. While ensuring data security, it also takes into account the normal access needs of legitimate users in a complex network environment, providing more reliable security protection for data sharing.
[0029] If the permission verification passes, the data provider determines the optimal data transmission method and transmission rate according to the device performance and network conditions of the data requester by using an adaptive data transmission algorithm. The adaptive data transmission algorithm is implemented by constructing an intelligent decision-making model based on reinforcement learning. Using the device performance and network conditions as the environmental state vector, and the transmission method and transmission rate as the action space, a multi-objective optimization algorithm is adopted to find the optimal solution among multiple objectives such as the shortest transmission time, the highest data integrity, and the lowest energy consumption. When it is detected that the processing capacity of the requester device is strong, the network bandwidth is sufficient, and the latency is low, the algorithm may choose to transmit data at a higher transmission rate and method to ensure data integrity and transmission efficiency; while when the network condition is poor, the algorithm will adjust the transmission rate and method to give priority to ensuring data integrity and lower energy consumption.
[0030] Finally, after the home doctor workstation of the data requester receives the encrypted data, it decrypts the data using the decryption key stored locally to obtain the original data for formulating a personalized diagnosis and treatment plan, realizing the requirement of data sharing.
[0031] The present invention aims at the core pain points such as security, permissions, and transmission in data sharing, and is significantly superior to the built-in sharing mechanism of the HarmonyOS in terms of technical architecture and actual performance. At the data security level, the native mechanism of HarmonyOS uses classical encryption algorithms and is difficult to resist quantum attacks. However, the present invention integrates the quantum encryption principle and the chaotic hash binding technology, generates dynamic keys through quantum random numbers, non-linearly confuses data features with keys, and encrypts with dynamic quantum gates, improving the anti-quantum attack ability. At the same time, the storage volume of duplicate data is reduced by multi-dimensional feature deduplication. In the permission verification link, the HarmonyOS mechanism relies on single factors such as device ID and user account. The present invention constructs a multi-factor weighted model including device fingerprint credibility, user behavior matching degree, and environmental risk, and dynamically adjusts the permission threshold with the help of a non-linear function, reducing the permission misjudgment rate. Especially in scenarios such as cross-device access and abnormal environment operations, the ability to accurately identify risk requests is improved, effectively balancing security and access convenience. In the data transmission stage, HarmonyOS adopts a fixed rate strategy and is difficult to adapt to heterogeneous devices and dynamic network environments. The present invention improves the dynamic optimization among transmission time, integrity, and energy consumption through an intelligent decision-making model based on reinforcement learning, which can perceive the device performance and network status in real time.
[0032] Generally speaking, the built-in sharing mechanism of HarmonyOS is an efficient interconnection base for consumer-level scenarios. As an industry enhancement solution, the present invention systematically solves the bottlenecks of traditional mechanisms in terms of security strength, permission accuracy, and transmission adaptability through technological innovations such as anti-quantum encryption, multi-dimensional permission evaluation, and intelligent transmission optimization, providing professional support for the efficient and secure circulation of key data, and promoting the upgrade of distributed data sharing towards anti-quantum and intelligent directions.
[0033] The above are only the preferred embodiments of the present invention, and are not intended to limit the present invention in any other form. Any person skilled in the relevant art may use the technical content disclosed above to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as they do not depart from the technical solution content of the present invention, any simple modifications, equivalent changes and modifications made to the above embodiments based on the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.
Claims
1. A data sharing optimization method based on HarmonyOS distributed data management, characterized in that, The following steps are involved: S1. The data provider uses an encryption algorithm to encrypt the original data to generate encrypted data. The encryption algorithm is based on the principle of quantum encryption combined with a hash function, and extracts data features through the one-time use of the quantum key and the hash function; S2. Store the encrypted data in the Hongmeng distributed database and assign it a unique distributed data identifier, while recording the metadata of the data, including data type, data size, and creation time; S3. The data requesting end initiates a data sharing request to the data providing end. The request includes its own device identification, user identity information, and a description of the requested data. S4. After receiving the request, the data provider verifies the identity and authority of the data requester according to the preset authority verification rules; The permission verification rule is as follows: By inputting the device fingerprint credibility S device , the user behavior matching degree S user and the environmental risk R env into the weighted model, the permission score F is obtained: where ω d , ω u are the weights of the user behavior matching degree and the device fingerprint credibility, α and β are non-linear power parameters, γ are respectively the environmental risk suppression coefficients, and δ and η are the adjustment parameters of the environmental risk suppression factors. The higher the device fingerprint credibility, the stronger the tolerance for environmental risks. When the obtained permission score is greater than the threshold of 0.7, it indicates that the verification is passed; otherwise, the access request is immediately blocked. S5. If the verification is successful, the data provider uses an adaptive data transmission algorithm to determine the optimal data transmission method and transmission rate based on the device performance and network conditions of the data requester, extracts the encrypted data from the Hongmeng distributed database, and transmits it to the data requester; S6. After receiving the encrypted data, the data requesting end uses the locally stored decryption key to decrypt the data and obtain the original data; The specific implementation of the encryption algorithm in step S1 is: using quantum randomness and chaotic system to generate a dynamic key sequence; binding data features with keys to resist quantum collision attacks; performing dynamic quantum gate encryption; The implementation of generating a dynamic key sequence using quantum randomness and a chaotic system is as follows: First, an initial seed key S ∈ {0, 1} is generated by a quantum random number generator λ , where λ ≥ 256. Then, the quantum seed S is input into the mapped chaotic system to generate a chaotic sequence K. The chaotic sequence is where x k is the intermediate state value of the chaotic system, K k is the dynamic key generated by the chaotic system, and μ is the parameter of the chaotic system, calculated as: μ = 3.99 + 0.01 · SHA3(S) mod 2 16 ; After generating the dynamic key sequence, bind the data features to the key. The implementation of resisting quantum collision attacks is as follows: divide the original data D into blocks, calculate the quantum-resistant hash for each block and project it into a vector, and perform non-linear confusion on the chaotic sequence K and the hash feature H. The calculation method is as follows: where is the bitwise XOR operation, and K′ is the confused key; Construct a quantum gate operation matrix based on the obfuscated key to achieve encryption: Divide K′ into control parameters to generate a set of dynamic quantum gates {U i}: where R Y is a Y-axis rotation gate, CNOT is a controlled NOT gate, and encode the data block D i into the quantum state |ψ i >, and apply the quantum gate sequence to obtain the encrypted quantum state |ψ enc >: where represents the tensor product. Finally, perform a basis measurement on the encrypted quantum state to generate the classical ciphertext C i : C i = Measure(|ψ enc , basis = K i ′ mod 2).
2. The data sharing optimization method based on HarmonyOS distributed data management according to claim 1, characterized in that In step S1, before data encryption, the data needs to be deduplicated, the semantic features, structural features and time features of the data are extracted, the extracted multi-dimensional features are integrated, the high-dimensional feature vector is converted into a low-dimensional vector using principal component analysis, and a feature index is constructed using a distributed hash table. Each node is responsible for storing part of the feature index information, and the feature vector is mapped to different nodes through a hash function. When new data needs to be stored, its feature vector is calculated and a search is performed in the distributed hash table to find out whether there are similar features. The similarity feature is to set a threshold. When the similarity between the feature vector of new data and the feature vector of stored data exceeds the threshold, it is determined to be duplicate data. The similarity calculation is performed using the cosine similarity method.
3. A data sharing optimization method based on HarmonyOS distributed data management according to claim 1, characterized in that The implementation of the adaptive data transmission algorithm in step S5 is as follows: constructing an intelligent decision-making model based on reinforcement learning, taking device performance and network conditions as environmental state vectors, transmission mode and transmission rate as action space, and using a multi-objective optimization algorithm to find the optimal solution among multiple objectives of shortest transmission time, highest data integrity, and lowest energy consumption, and determine the optimal data transmission mode and transmission rate.
Citation Information
Patent Citations
Underwater sensor network encryption and decryption method and device, underwater equipment and storage medium
CN116781235A
Industrial internet data sharing method and system
CN116781423A
Big data transmission method and system based on hybrid distribution estimation algorithm
CN118509121A
Mobile terminal equipment credibility authentication method and system based on Internet of Things
CN118631570A