Data element credible management system

By introducing a trusted management system for data elements into the data management system, using key management, data element management, secure database, calculation module, encryption and decryption module and authentication and permission module, it is built based on a confidential computing environment, and the shortcomings of the data management system in data security, management complexity and cross-system collaborative computing are solved, and data security management and efficient computing are realized.

CN120046185APending Publication Date: 2025-05-27HANGZHOU NUOWEI INFORMATION TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510094386.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

Existing data management systems have shortcomings in data security, management complexity and cross-system collaborative computing, resulting in inefficient data management and prone to data leakage.

Method used

It provides a trusted management system for data elements, including a key management module, a data element management module, a secure database, a data element calculation module, an encryption and decryption module, and an authentication and permission module. It is built based on a confidential computing environment to realize the security management and calculation of data.

Benefits of technology

On the premise of ensuring data security, we can realize flexible data management and calculation, improve the efficiency of data resource use, and solve the security and efficiency problems existing in the data processing process of existing systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046185A_ABST
    Figure CN120046185A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to a credible management system for data elements. The credible management system comprises a key management module, a data element management module, a security database, a data element calculation module, an encryption and decryption module and an authentication and authority module, the key management module, the data element management module, the security database, the data element calculation module, the encryption and decryption module and the authentication and authority module are constructed based on a confidential calculation environment. According to the technical scheme provided by the embodiment of the invention, flexible management and calculation of data can be realized on the premise of ensuring data security, the use efficiency of data resources is improved, and the security and efficiency problems of an existing system in a data processing process are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the technical fields of data management and computing, and in particular, to a trusted management system for data elements. Background Art

[0002] With the wide application of data, as a new type of production factor, how to safely and compliantly store and compute data elements has become a major challenge in current technologies. Existing data management systems have deficiencies in data security, management complexity, and cross-system collaborative computing, which may lead to low data management efficiency and easy data leakage in complex environments. Summary of the Invention

[0003] Based on the above situation of the prior art, the purpose of the embodiments of the present invention is to provide a trusted management system for data elements, which can improve the security of the data storage and management process.

[0004] To achieve the above object, according to one aspect of the present invention, a trusted management system for data elements is provided, including a key management module, a data element management module, a secure database, a data element computing module, an encryption and decryption module, and an authentication and authorization module; the key management module, the data element management module, the secure database, the data element computing module, the encryption and decryption module, and the authentication and authorization module are built based on a confidential computing environment;

[0005] The data element management module is used to construct data elements according to preset definitions and generate management instructions to manage the entire life cycle of the data elements;

[0006] The key management module is used to manage encryption keys and decryption keys, and the encryption keys and decryption keys are used for the data encryption process and data decryption process of the other modules;

[0007] The authentication and authorization module is used to authenticate and control the access rights of visitors to the secure database with the support of the key management module;

[0008] The data element computing module is used to access the data in the secure database according to the management instructions of the data element management module and after being authenticated by the authentication and authorization module, and compute the data;

[0009] The encryption and decryption module is used to encrypt and decrypt data according to the encryption keys and decryption keys provided by the key management module.

[0010] Further, the preset definitions include the fields, content, usage scenarios, and modes of the data elements.

[0011] Further, the keys are divided into a root key, a first-level key, and a second-level key from high to low in level; a high-level key can decrypt a low-level key.

[0012] Further, the key management module is used to store the root key.

[0013] Further, the security database is used to store high-security-level data, reference data, and improvement data.

[0014] Further, the high-security-level data includes data with high-security confidentiality requirements, the reference data includes data at the intermediate value or median among multiple data; the improvement data includes data used to improve other data.

[0015] Further, the system further includes a charging and settlement module and a supervision and auditing module;

[0016] The charging and settlement module is used to collect the usage situation of the data elements and perform revenue settlement based on the usage situation;

[0017] The supervision and auditing module is used to supervise and audit the usage situation of the data elements.

[0018] Further, the system further includes a tabling and registration module for converting the data elements into measurable assets.

[0019] Further, the system further includes a remote synchronization interface, a collaboration interface, and a management interface;

[0020] The collaboration interface is used to collaborate and settle with other data element trusted management systems;

[0021] The management interface is used to manage the data element trusted management system through a central supervision platform.

[0022] In summary, the embodiment of the present invention provides a trusted management system for data elements, including a key management module, a data element management module, a security database, a data element calculation module, an encryption and decryption module, and an authentication and authorization module; the key management module, the data element management module, the security database, the data element calculation module, the encryption and decryption module, and the authentication and authorization module are built based on a confidential computing environment; the data element management module is used to construct data elements according to preset definitions and generate management instructions to manage the entire life cycle of the data elements; the key management module is used to manage encryption keys and decryption keys, and the encryption keys and decryption keys are used for the data encryption process and data decryption process of the other modules; the authentication and authorization module is used to authenticate and control the access rights of visitors to the security database with the support of the key management module; the data element calculation module is used to access the data in the security database and calculate the data according to the management instructions of the data element management module and after being authenticated by the authentication and authorization module; the encryption and decryption module is used to encrypt and decrypt data according to the encryption keys and decryption keys provided by the key management module. The technical solution provided by the embodiment of the present invention can achieve flexible management and calculation of data on the premise of ensuring data security, improve the utilization efficiency of data resources, and solve the security and efficiency problems existing in the existing system during the data processing process. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 is a structural block diagram of the trusted management system for data elements provided by the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0024] To make the objectives, technical solutions, and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below in conjunction with specific embodiments and with reference to the accompanying drawings. It should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present invention. In addition, in the following description, the descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present invention.

[0025] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in one or more embodiments of the present invention should have the ordinary meaning understood by those of ordinary skill in the art to which the present invention belongs. The "first", "second" and similar terms used in one or more embodiments of the present invention do not denote any order, quantity or importance, but are only used to distinguish different components. Words such as "including" or "comprising" mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. Words such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect.

[0026] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings. An embodiment of the present invention provides a trusted management system for data elements. Figure 1 The block diagram of the trusted management system for data elements provided by the embodiment of the present invention is shown in Figure 1 As shown, the system includes a Key Management Service (KMS), a data element management module, a security database, a data element calculation module, an encryption / decryption module, and an authentication and authorization module. Among them, the key management module, the data element management module, the security database, the data element calculation module, the encryption / decryption module, and the authentication and authorization module are built based on a confidential computing environment. Building the above modules in the confidential computing environment can make the processes of constructing, calculating, encrypting / decrypting data elements, and storing important data elements all executed in the confidential computing environment, thereby improving the security during the data storage and processing processes. The confidential computing environment can be implemented, for example, by creating a Trusted Execution Environment (TEE).

[0027] The data element management module is used to construct data elements according to preset definitions and generate management instructions to manage the entire life cycle of the data elements. The preset definitions include the fields, content, usage scenarios, and modes of the data elements. The data element management module can also be used to coordinate the security database and the data element calculation module for data calculation. A data element refers to data that can be calculated, and data value can be extracted through calculation. Data elements can be data in various formats, and the fields and other content included can be different. Data elements are converted from data. Individual data may have no value or have format problems. Through the management of the entire life cycle of data elements, the data can be processed to form data elements for subsequent operations such as storage and deletion.

[0028] The key management module is used to manage encryption keys and decryption keys, which are used for the data encryption process and data decryption process of the other modules. The keys involved in the encryption keys and decryption keys are divided into root keys, first-level keys, and second-level keys from high to low according to the level; high-level keys can decrypt low-level keys. For example, if data is encrypted with a first-level key and the first-level key is encrypted with a root key, the first-level key can be decrypted according to the root key to decrypt the encrypted data. The encrypted data and the low-level keys used for encryption can be stored outside the confidential computing environment, and high-level keys such as root keys are stored in the key management module in the confidential computing environment. During the decryption process, the root key is used to decrypt the lower-level key, and then the decrypted lower-level key is used to decrypt the data. Only the root key is saved in the key management module in the confidential computing environment, reducing the storage volume while ensuring security.

[0029] The security database is used to store core data, that is, to implement the storage of data in a secure encryption state and support the operation of the data element management module. Core data refers to the most core underlying key data and configuration data stored separately. The security database is used to store high-security-level data, reference data, and improvement data. The high-security-level data includes data with high-security confidentiality requirements, the reference data includes data with intermediate values or medians among multiple data; the improvement data includes data used to improve other data. When the security database cannot run in the confidential computing environment, the maximum security credibility can still be maintained. For example, data from different data source parties can be divided into corresponding security levels, and the security database can store the highest-level data; for example, a batch of data contains data in multiple fields, and the security database can select the most important several fields that require high security for data storage, reducing the usability of the remaining data of the data source party (unable to generate data value). The security database can also be used to store reference data. For example, if the data in a certain field of multiple data source parties fluctuates around a certain data, the security database can save this data as reference data, and the remaining fluctuation information is stored in each data source party. For example, the pixel values of a certain image data are 130, 125, etc. The security database can store 128, and the data source party stores +2, -3 (occupying fewer bytes). Through the above storage method, the data storage occupancy of the data source party can be reduced, and the data security can be improved. The security database can also store some data obtained by improving the data based on the data source party. For example, after improving the data based on the data of three data source parties, a set of data will be obtained for the first data source party to improve the original data. If this data is directly sent to the data source party, it will cause data leakage. At this time, the improved data can be stored in the security database and called when needed.

[0030] The authentication and authorization module is used to authenticate visitors to the secure database and control permissions with the support of the key management module. The authentication and authorization module is responsible for managing user authentication and authorization. This authentication and authorization module ensures that only users who have been verified and authorized (with different levels of access permissions for different levels of data) can access or operate on data elements, thereby protecting the security and compliance of the data. The authentication and authorization module is also used for permission control and can assign corresponding data access permissions according to the roles and responsibilities of users, including operations such as reading, writing, modifying, and deleting.

[0031] The data element calculation module is used to access the data in the secure database according to the management instructions of the data element management module and after being authenticated by the authentication and authorization module, and calculate the data. The data element calculation module can, under the management of data element management, obtain commands from the coordination interface, and after being authenticated and approved by the authentication and authorization module, securely access the secure database for calculation. Or it can implement collaborative calculations between multiple data element trusted management systems, such as implementing calculation modes like federated learning, PSI (Private Set Intersection), and oblivious query PIR (Private Information Retrieval).

[0032] The encryption and decryption module is used to encrypt and decrypt data according to the encryption key and decryption key provided by the key management module.

[0033] According to some optional embodiments, the data element trusted management system further includes a billing and settlement module and a supervision and audit module.

[0034] The billing and settlement module is used to collect and summarize operation calculation logs and the usage of data elements, and perform revenue settlement based on the usage. The billing and settlement module can, based on the operation calculation logs, record the usage of data elements, such as the number of times of use and the usage method (such as using in plaintext or ciphertext), and then perform revenue settlement for the data element owners.

[0035] The supervision and audit module is used to supervise and audit the usage of data elements. The supervision and audit module is used to monitor the compliance and security of the data element trusted management system, ensure that the processing of data elements complies with regulatory requirements, and can provide audit trails and reports.

[0036] According to some optional embodiments, the data element trusted management system further includes a tabulation and registration module for converting the data elements into measurable assets. The tabulation and registration module can convert data elements into assets that can be managed and measured by enterprises. This tabulation and registration module covers the entire process of identification, evaluation, classification, measurement, and tabulation of data assets.

[0037] According to some optional embodiments, the data element trusted management system further includes a remote synchronization interface, a collaboration interface, and a management interface.

[0038] The collaboration interface is used for collaborative settlement with other data element trusted management systems.

[0039] The management interface is used to manage the data element trusted management system through the central supervision platform. By using confidential computing environment and secure database technologies, the entire process of data processing can be carried out in a secure environment.

[0040] In summary, the embodiments of the present invention relate to a data element trusted management system, including a key management module, a data element management module, a secure database, a data element calculation module, an encryption and decryption module, and an authentication and authorization module; the key management module, the data element management module, the secure database, the data element calculation module, the encryption and decryption module, and the authentication and authorization module are built based on a confidential computing environment; the data element management module is used to construct data elements according to preset definitions and generate management instructions to manage the entire life cycle of data elements; the key management module is used to manage encryption keys and decryption keys, and the encryption keys and decryption keys are used for the data encryption process and data decryption process of the other modules; the authentication and authorization module is used to authenticate and control the access rights of visitors to the secure database with the support of the key management module; the data element calculation module is used to access the data in the secure database and calculate the data according to the management instructions of the data element management module after being authenticated by the authentication and authorization module; the encryption and decryption module is used to encrypt and decrypt data according to the encryption keys and decryption keys provided by the key management module. The technical solution provided by the embodiments of the present invention can achieve flexible management and calculation of data while ensuring data security, improve the utilization efficiency of data resources, and solve the security and efficiency problems existing in the existing system during the data processing process.

[0041] It should be understood that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the present invention (including the claims) is limited to these examples; under the concept of the present invention, the technical features in the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations in different aspects of one or more embodiments of the present invention as described above, and they are not provided in detail for the sake of brevity. The above specific embodiments of the present invention are only used for exemplary illustration or explanation of the principle of the present invention and do not constitute a limitation to the present invention. Therefore, any modifications, equivalent replacements, improvements, etc. made without departing from the spirit and scope of the present invention shall be included within the protection scope of the present invention. In addition, the appended claims of the present invention are intended to cover all variations and modifications that fall within the scope and boundaries of the appended claims, or equivalent forms of such scope and boundaries.

Claims

1. A data element trusted management system, characterized in that: It includes a key management module, a data element management module, a security database, a data element calculation module, an encryption and decryption module, and an authentication and permission module; the key management module, the data element management module, the security database, the data element calculation module, the encryption and decryption module, and the authentication and permission module are constructed based on a confidential computing environment; The data element management module is used to construct data elements according to preset definitions and generate management instructions to manage the entire life cycle of data elements; The key management module is used to manage encryption keys and decryption keys, which are used in the data encryption process and data decryption process of the other modules; The authentication and authority module is used to authenticate and control the authority of the visitor to the security database with the support of the key management module; The data element calculation module is used to access the data in the security database and calculate the data according to the management instructions of the data element management module and after being authenticated by the authentication and authority module; The encryption and decryption module is used to encrypt and decrypt data according to the encryption key and decryption key provided by the key management module.

2. The system according to claim 1, characterized in that The preset definition includes the fields, content, usage scenarios and modes of the data elements.

3. The system according to claim 2, characterized in that The keys are divided into root keys, primary keys and secondary keys according to their levels from high to low; high-level keys can decrypt low-level keys.

4. The system according to claim 3, characterized in that The key management module is used to store the root key.

5. The system according to claim 1, characterized in that The security database is used to store high security level data, reference data and improved data.

6. The system according to claim 5, characterized in that The high-security level data includes data with high security and confidentiality requirements, the benchmark data includes data that is an intermediate value or median among multiple data; and the perfect data includes data used to perfect other data.

7. The system according to any one of claims 1 to 6, characterized in that: The system also includes a billing and settlement module and a supervision and audit module; The billing and settlement module is used to collect usage of the data elements and perform revenue settlement based on the usage; The supervision and audit module is used to supervise and audit the use of the data elements.

8. The system according to claim 7, characterized in that The system also includes an entry and registration module for converting the data elements into measurable assets.

9. The system according to claim 8, characterized in that The system also includes a remote synchronization interface, a coordination interface, and a management interface; The collaborative interface is used for collaborative settlement with other data element trusted management systems; The management interface is used to manage the data element trusted management system through a central supervision platform.

Citation Information

Patent Citations

  • Decryption and encryption method and device

    CN117221012A

  • Data asset management system based on full life cycle management

    CN118886606A

  • Data trusted management method and device based on data security

    CN119155028A