Resource unified identification and analytic calculation method based on trusted data space

By introducing a unified resource identification and parsing calculation method based on trusted data space in the resource management system, the complexity problem caused by the separation of resource identifiers and states in traditional systems is solved, and the intelligent representation of resource states and dynamic adjustment of access rights is realized, improving the efficiency and security of the system.

CN120068088AActive Publication Date: 2025-05-30SHENCAI ZHILIAN (BEIJING) TECH DEV CO LTD

Patent Information

Application Number
CN202510148006.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-11
Publication Date
2025-05-30
Estimated Expiration
2045-02-11

AI Technical Summary

Technical Problem

In traditional resource management systems, the identifier of the resource and the state of the resource are usually separated, resulting in the need of additional logical or database queries to match the identifier and state, increasing the complexity of the system and maintenance costs.

Method used

The unified resource identification and parsing calculation method based on trusted data space is adopted, and the factors influencing resource status are introduced by generating a composite structure of resource identifiers, and the identifier generation strategy is dynamically adjusted using distributed hashing algorithms and multi-factor analysis, and the encrypted identifier is stored through the blockchain to trigger the smart contract to verify the legitimacy of resource identifiers.

Benefits of technology

It realizes that resource identifiers can not only represent the basic characteristics of the resource, but also reflect the current status of the resource, simplify query logic, reduce system complexity and maintenance costs, and dynamically adjust access rights through smart contracts, enhancing the security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068088A_ABST
    Figure CN120068088A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of trusted computing, in particular to a resource unified identification and analytic computing method based on a trusted data space. The method comprises the following steps: generating a composite structure of a resource identifier according to a multi-source characteristic of a resource, and dynamically adjusting a generation strategy of the resource identifier by adopting a distributed hash algorithm and multi-factor analysis; storing the encrypted resource identifier by using a block chain, and when the resource identifier is updated or verified each time, triggering an intelligent contract to verify whether the resource identifier is legal; and after the verification of the resource identifier is passed, the system allocates an analysis task of the resource identifier to each distributed node according to a load balancing algorithm. According to the method, a state weight mechanism is introduced, so that the generated identifier not only can represent the basic characteristics of the resource, but also can reflect the current state of the resource, in addition, the query logic can be simplified, and the state of the resource does not need to be determined by additionally executing query operation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of trusted computing, and more specifically, to a unified resource identification and resolution calculation method based on a trusted data space. Background Art

[0002] With the continuous development of information technology, the management of data resources has become increasingly complex. Especially in large-scale distributed systems, there is a wide variety of resources distributed widely. How to manage and access these resources efficiently and accurately, especially in the context of massive data and high concurrent requests, has become an important and urgent challenge. Traditional resource management methods often rely on centralized databases or static identifier systems, which are often difficult to meet the needs of dynamic environments and distributed systems. Therefore, a resource management system should not only be able to handle the basic information of resources, but also be able to reflect the status of resources in real time, and optimize the query and resource scheduling processes.

[0003] In traditional resource management systems, the identifier of a resource and the status of the resource are usually separated. The status of the resource is usually determined through additional query operations, which requires additional logic or database queries to match the identifier and the status, increasing the complexity and maintenance cost of the system. Therefore, a unified resource identification and resolution calculation method based on a trusted data space is designed. Summary of the Invention

[0004] The purpose of the present invention is to provide a unified resource identification and resolution calculation method based on a trusted data space to solve the problem that in the above-mentioned background art, the identifier of a resource and the status of the resource are usually separated, and the status of the resource is usually determined through additional query operations, which requires additional logic or database queries to match the identifier and the status, increasing the complexity and maintenance cost of the system.

[0005] To achieve the above purpose, the present invention provides a unified resource identification and resolution calculation method based on a trusted data space, including the following steps:

[0006] S1. Generate a composite structure of resource identifiers according to the multi-source characteristics of resources, dynamically adjust the generation strategy of resource identifiers by using a distributed hash algorithm and multi-factor analysis, and then encrypt the generated identifiers. During the process of generating the composite structure of resource identifiers according to the multi-source characteristics of resources, introduce the influencing factors of resource status for optimization;

[0007] S2. Use a blockchain to store the encrypted resource identifiers. Whenever the resource identifiers are updated or verified, trigger a smart contract to verify whether the resource identifiers are legal, and at the same time record the historical changes and verification processes of the resource identifiers through the distributed ledger of the blockchain;

[0008] After the resource identifier verification passes, the system assigns the parsing tasks of the resource identifier to each distributed node according to the load balancing algorithm. After each distributed node executes the identifier parsing task in parallel, their respective processing results are merged, and finally the result of the identifier parsing is returned.

[0009] As a further improvement of this technical solution, the multi-source characteristics of the resources include, but are not limited to, resource type, creation time, geographical location, and version information.

[0010] As a further improvement of this technical solution, in S1, the specific steps for generating the composite structure of the resource identifier according to the multi-source characteristics of the resources are as follows:

[0011] Generation of the composite structure of the resource identifier:

[0012] UID r = H(Type r ||Time r ||Location r ||Version r );

[0013] Among them, UID r represents the preliminary identifier of resource r; Type r represents the resource type; Time r represents the resource creation time; Location r represents the geographical location where the resource is created; Version r represents the version information of the resource; H is a hash function; || represents the operation of merging different attributes of the resource.

[0014] As a further improvement of this technical solution, in S1, during the process of generating the composite structure of the resource identifier according to the multi-source characteristics of the resources, the influence factor of the resource status is introduced for optimization. After optimization, it is specifically:

[0015] UID r ' = H(Type r ||Time r ||Location r ||Version r ||(ω(Status r ) × Status r ));

[0016] Among them, UID r ' is the identifier of the optimized resource r; ω(Status r ) is the weight of the status of resource r; Status r is the status of resource r;

[0017] where ω(Status r ) takes the following values:

[0018] When Status r is in the active state, ω(Status r ) = 1, indicating that the resource r is in a normal available state;

[0019] When Status r is in the pending state, ω(Status r ) = 0.5, indicating that the resource r is currently inactive;

[0020] When Status r is in the expired state, ω(Status r ) = 0, indicating that the resource r has expired.

[0021] As a further improvement of this technical solution, in S1, the specific steps for dynamically adjusting the generation strategy of the resource identifier using the distributed hash algorithm and multi-factor analysis are as follows:

[0022] S11. The comprehensive weight of the multi-factor comprehensive influence:

[0023] W total = w U ·U r + w F ·F r + w L ·L + w P ·P r ;

[0024] where W total is the weighted sum of the multi-factors; U r is the resource update time index; w U is the weight of the resource update time index; F r is the resource access frequency; w F is the weight of the resource access frequency; L is the system load; w L is the weight of the system load; P r is the resource priority; w P is the weight of the resource priority;

[0025] S12. Adjust the resource identifier generation strategy according to the comprehensive weight;

[0026] Set the weight threshold W threshold of the comprehensive influence in advance;

[0027] If W total > W threshold , then:

[0028] UID r ” = H(Type r ||Time r ||Location r ||Version r ||w U ·U r ||w F ·F r ||w L ·L||w P ·P r );

[0029] If W total ≤ W threshold , then:

[0030] UID r ” = H(Type r ||Time r ||Location r ||Version r );

[0031] where UID r ” is the identifier of the adjusted resource r.

[0032] As a further improvement of this technical solution, the smart contract can execute resource management tasks at each stage of the resource identifier life cycle, where the resource management tasks include verification of the creation, modification, and destruction processes.

[0033] As a further improvement of this technical solution, in S2, the smart contract is triggered to verify whether the resource identifier is legal, and the specific steps are as follows:

[0034] S21. The smart contract sets access control rules based on user roles, device attributes, and time limits to restrict different users' access rights to resources;

[0035] S22. Each time a user requests a resource, the smart contract verifies the user's permissions according to the pre-set access control policy and returns the corresponding resource information according to the permission policy;

[0036] S23. After the permission verification is completed, based on the multi-dimensional access control policy of the resource identifier, calculate the user's access permission score, and then dynamically adjust the user's access permission.

[0037] As a further improvement of this technical solution, verifying the user's permissions in S22 includes checking whether the user role meets the requirements; verifying whether the device attributes meet the access conditions; confirming whether the access request is within the allowed time range; and confirming whether other defined access rules are met.

[0038] As a further improvement of this technical solution, calculating the user's access permission score in S23 is based on the user role, the authentication status of the device, the device type or the security level of the device, the time of the access request and the set allowed time range, the user's historical behavior, the frequency of the user accessing resources, and the security status of the current trusted data space. Specifically as follows:

[0039] User role score R:

[0040] R = {1, 0.75, 0.5, 0.25, 0};

[0041] Wherein, R is the user role score; when the user role is an administrator, then R = 1; when the user role is a senior user, then R = 0.75; if the user role is a regular user, then R = 0.5; if the user role is a visitor, then R = 0.25; if the user role is a banned user, then R = 0;

[0042] Device authentication status score D status :

[0043] D status = {0, 1};

[0044] Wherein, D status is the device authentication status score; when the device is authenticated, then D status = 1; when the device is not authenticated, then D status = 0;

[0045] Device security level score D security :

[0046]

[0047] Wherein, D security is the device security level score; MaxSecurityLevel is the maximum value of the device security level; DeviceSecurityLevel is the security level of the device;

[0048] Access time score T access :

[0049]

[0050] Wherein, T accessLet Score be the access time score; T be the access time; AllowedTimeRange be the allowed time range; AccessTime be the time point of the access request;

[0051] The historical behavior score H history :

[0052] H history = 1 - penaltyFactor;

[0053] where H history is the historical behavior score; penaltyFactor is the penalty factor based on historical behavior;

[0054] The access frequency score F access :

[0055] F access = e -b·AccessFrequency ;

[0056] where F access is the access frequency score; b is a constant controlling the influence of access frequency; AccessFrequency is the access frequency;

[0057] Then, the user's access permission score:

[0058] Score = w 1 ·R + w 2 ·D status + w 3 ·D security + w 4 ·T access + w 5 ·H history + w 6 ·F access + w 7 ·S data ;

[0059] where Score is the user's access permission score; w 1 is the weight of the user role score; w 2 is the weight of the device authentication status score; w 3 is the weight of the device security level score; w 4 is the weight of the access time score; w 5 is the weight of the historical behavior score; w 6 is the weight of the access frequency score; w 7 is the weight of the data space security score.

[0060] As a further improvement of this technical solution, an artificial intelligence model is used to optimize the query during the process of parsing the S3 resource identifier. Specifically, by analyzing historical query data, a prediction model for resource queries is established, and the node allocation and load balancing strategies for resource queries are dynamically adjusted according to the query prediction model. In the case of high concurrency, the optimal query node is selected.

[0061] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0062] 1. In this method for unified identification and parsing calculation of resources based on a trusted data space, by introducing a status weight mechanism, the generated identifier can not only represent the basic characteristics of the resource but also reflect the current state of the resource. This enables the system to make more intelligent choices in more complex scenarios. In addition, it helps to simplify the query logic and eliminates the need to perform additional query operations to determine the status of the resource.

[0063] 2. In this method for unified identification and parsing calculation of resources based on a trusted data space, according to the weight score of user access, the smart contract can dynamically adjust the user's access rights. The smart contract can automatically adjust the permissions to enhance the security of the system and prevent abuse. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] Figure 1 It is the overall method flow chart of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0065] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0066] Embodiment

[0067] Please refer to Figure 1 As shown, a method for unified identification and parsing calculation of resources based on a trusted data space is provided, including the following steps:

[0068] S1. Generate a composite structure of the resource identifier according to the multi-source characteristics of the resource, adopt a distributed hash algorithm and multi-factor analysis to dynamically adjust the generation strategy of the resource identifier, and then encrypt the generated identifier. During the process of generating the composite structure of the resource identifier according to the multi-source characteristics of the resource, the influencing factors of the resource state are introduced for optimization;

[0069] The multi-source characteristics of resources include, but are not limited to, resource type, creation time, geographical location, and version information; among them, the resource type refers to the category to which the resource belongs, such as files, database records, images, videos, etc.; the creation time refers to the time when the resource was created, usually represented by a timestamp; the geographical location refers to the physical or logical location of the resource, which can be represented by longitude and latitude, data center location, etc.; the version information refers to the version number of the resource.

[0070] In S1, the specific steps for generating the composite structure of the resource identifier according to the multi-source characteristics of the resource are as follows:

[0071] Generation of the composite structure of the resource identifier:

[0072] UID r = H(Type r || Time r || Location r || Version r );

[0073] Among them, UID r represents the preliminary identifier of resource r; Type r represents the resource type; Time r represents the resource creation time; Location r represents the geographical location where the resource was created; Version r represents the version information of the resource; H is a hash function used to calculate a unique identifier after concatenating the above multiple fields; || represents the operation of merging different attributes of the resource;

[0074] Process the preliminary identifier UID of resource r using the distributed hash algorithm: r :

[0075] H(UID r ) = Hash(UID r ) mod N;

[0076] Among them, N is the number of nodes in the trusted data space; H(UID r ) is the hash value of the preliminary identifier of resource r.

[0077] In S1, during the process of generating the composite structure of the resource identifier according to the multi-source characteristics of the resource, the influencing factor of the resource status is introduced for optimization. The resource status refers to the current status of the resource, such as "active", "archived", "deleted". After optimization, it is specifically:

[0078] UID r ' = H(Type r || Time r || Locationr ||Version r ||(ω(Status r )×Status r ));

[0079] Among them, UID r ' is the identifier of the optimized resource r; ω(Status r ) is the weight of the status of resource r; Status r is the state of resource r;

[0080] Among them, ω(Status r ) can take the following values:

[0081] When Status r When it is active, ω(Status r )=1, indicating that resource r is in a normal and available state;

[0082] When Status r When the status is pending, ω(Status r ) = 0.5, indicating that resource r is currently inactive and needs further processing;

[0083] When Status r When the status is expired, ω(Status r ) = 0, indicating that resource r has expired and has almost no priority;

[0084] The main difference between the formulas before and after optimization is whether the status information of the resource is taken into account. The formula before optimization was based only on static attributes (such as type, time, and location, etc.), and ignored the dynamically changing status; in contrast, the optimized formula introduces a status weight mechanism, so that the generated identifier can not only represent the basic characteristics of the resource, but also reflect the current status of the resource. This enables the system to make smarter choices in more complex scenarios, such as giving priority to important resources that are active, or ignoring entries that have expired and are no longer relevant. In addition, this approach also helps to simplify query logic, because developers can get information about the resource status directly from the identifier without having to perform additional query operations to determine the status of the resource.

[0085] In S1, the specific steps of using the distributed hash algorithm and multi-factor analysis to dynamically adjust the resource identifier generation strategy are as follows:

[0086] S11. Comprehensive weight of the combined impact of multiple factors:

[0087] W total =w U ·U r+w F ·F r +w L ·L + w P ·P r ;

[0088] Wherein, W total is the weighted sum of multiple factors; U r is the update time index of the resource, usually expressed as the difference from the current time or the correlation of the update time; w U is the weight of the update time index of the resource; F r is the access frequency of the resource, reflecting the usage of the resource; w F is the weight of the access frequency of the resource; L is the system load, which may take values from 0 to 1, indicating the degree of the current load (the lower the load, the more complex calculations may be allowed); w L is the weight of the system load; P r is the priority of the resource, which may be a ranking value; w P is the weight of the priority of the resource;

[0089] S12. Adjust the identifier generation strategy of the resource according to the comprehensive weight;

[0090] Preset the weight threshold W of the comprehensive influence threshold ;

[0091] If W total > W threshold , it means that the resource is in a state of high priority, high activity or low system load. At this time, the system selects a more complex generation method to ensure the quality and uniqueness of the identifier. The generation method may include a hash algorithm with a higher number of digits, more feature dimensions, and weighted generation considering more factors. Then:

[0092] UID r ” = H(Type r || Time r || Location r || Version r || w U · U r || w F · F r || w L · L || w P · P r );

[0093] If W total ≤ W threshold, indicating that the resource status is relatively low or the system load is relatively high. At this time, a simplified generation strategy can be selected to improve efficiency. For example, a simpler field concatenation or a hash algorithm with a lower number of bits can be adopted, then:

[0094] UID r ” = H(Type r ||Time r ||Location r ||Version r );

[0095] Among them, UID r ” is the identifier of the adjusted resource r;

[0096] To sum up, weight coefficients are defined for each influencing factor, and the comprehensive influence weight is calculated. Then, according to the results of the multi-factor analysis, the generation strategy of the identifier is adjusted. If the weights of some factors are large (for example, the resources are updated frequently or the system load is low), the system may choose a more complex generation method to ensure the high quality of the identifier. If the weights are small, the system can choose a more simplified generation method to improve the generation efficiency.

[0097] The identifier generation strategy is to adjust the identifier generation strategy according to the results of the multi-factor analysis before assigning tasks. If the weights of some factors are large (for example, the resources are updated frequently or the system load is low), the system may choose a more complex generation method to ensure the high quality of the identifier. If the weights are small, the system can choose a more simplified generation method to improve the generation efficiency. For example, if the load of a certain node is low, the system may choose a more complex generation strategy (such as a more accurate hash method), while when the load is high, a fast and simple hash algorithm may be selected;

[0098] S2. Use the blockchain to store the encrypted resource identifier. Whenever the resource identifier is updated or verified, the smart contract is triggered to verify whether the resource identifier is legal, and at the same time, the historical changes and verification process of the resource identifier are recorded through the distributed ledger of the blockchain;

[0099] The smart contract can execute resource management tasks at each stage of the resource identifier life cycle. Among them, the resource management tasks include the verification of the creation, modification, and destruction processes;

[0100] The smart contract is automatically executed on the blockchain and does not depend on central control or manual intervention. For example, when the identifier is created, the smart contract will automatically trigger the relevant verification process; when the identifier needs to be updated, the smart contract will also automatically verify whether the update complies with the rules.

[0101] At each stage, the tasks of the smart contract can be further subdivided:

[0102] Resource creation (creation phase): Ensure the uniqueness of the resource identifier; verify requirements such as the format, structure, and permissions of the resource identifier; record the creation operation and metadata;

[0103] Resource update (modification phase): Verify whether the identifier update is legal; ensure that the update complies with business rules (such as permission checks, version control, etc.); automatically trigger the verification process related to the update;

[0104] Resource destruction (destruction phase): Ensure the legality of the identifier destruction (such as confirming that the identifier is no longer in use and preventing illegal deletion, etc.); complete the destruction operation and record.

[0105] In S2, trigger the smart contract to verify whether the resource identifier is legal. The specific steps are as follows:

[0106] S21. The smart contract sets access control rules based on user roles, device attributes, and time limits to restrict the access rights of different users to resources; by setting precise access control rules for different users, devices, and time ranges, the system can dynamically authorize according to specific usage scenarios. This can significantly improve the security of the system, ensure that only users meeting specific conditions can access resources, and thus prevent unauthorized access and abuse of resources.

[0107] S22. Each time a user requests a resource, the smart contract verifies the user's permissions according to the pre-set access control policy and returns the corresponding resource information according to the permission policy; ensure the dynamicity and timeliness of permissions. This can not only effectively control improper access but also flexibly respond to different business requirements and operation scenarios.

[0108] Verifying the user's permissions includes: checking whether the user role meets the requirements; verifying whether the device attributes meet the access conditions (such as whether the device is certified); confirming whether the access request is within the permitted time range; confirming whether other defined access rules are met;

[0109] Verification of user roles can ensure that users with different roles can only perform operations within their permission scopes. This is the basis for hierarchical management of access, which can effectively limit user permissions and prevent unauthorized operations.

[0110] Device authentication is an important means to ensure access security. By checking whether the device attributes meet the requirements, the system can avoid access through insecure or uncertified devices, enhancing the security of resources. Ensure that only devices meeting security standards can access sensitive resources, further preventing the intrusion of malicious devices or data leakage.

[0111] Time limits are an effective means of preventing unauthorized access, especially for resources that are only available for use during specific time periods. This can prevent users from accessing resources at inappropriate times (such as outside of working hours, holidays, etc.), thereby reducing potential security risks.

[0112] In addition to factors such as roles, devices, and time, the system can also introduce other custom rules (such as geographical location, access frequency, etc.). These rules can more finely control permissions, ensure that access behaviors comply with regulations and organizational policies, and avoid violations of internal procedures.

[0113] S23. After the permission verification is completed, based on the multi-dimensional access control policy of the resource identifier, calculate the user's access permission score, and then dynamically adjust the user's access permission;

[0114] Calculating the user's access permission score is based on the user's role (such as administrator, ordinary user, visitor, etc.), the authentication status of the device, the device type or the security level of the device, the time of the access request and the set allowed time range, the user's historical behavior, the frequency of the user accessing the resource, and the security status of the current trusted data space, specifically as follows:

[0115] User role score R:

[0116] R = {1, 0.75, 0.5, 0.25, 0};

[0117] Among them, R is the user role score; when the user role is an administrator, then R = 1; when the user role is a senior user, then R = 0.75; if the user role is an ordinary user, then R = 0.5; if the user role is a visitor, then R = 0.25; if the user role is a banned user, then R = 0;

[0118] By assigning different scores to different roles, the resource access permissions can be flexibly controlled according to the user's identity. Administrators can obtain the highest permissions, while banned users cannot access resources. This role differentiation can enhance the security of the system, prevent unauthorized users from accessing sensitive information, and at the same time ensure that senior users and ordinary users have different access scopes according to their permission levels;

[0119] Device authentication status score D status :

[0120] D status = {0, 1};

[0121] Among them, D status is the device authentication status score; when the device is authenticated, then D status = 1; when the device is not authenticated, then D status = 0;

[0122] Using the device authentication status score can ensure that only authenticated devices can obtain higher permissions, preventing insecure devices from accessing important resources. By introducing the non-linear characteristics of the Sigmoid function, it is possible to smoothly adjust the impact of the authentication status on access permissions, enabling the system to provide fine-grained access control under different authentication statuses and enhancing device security;

[0123] Device security level score D security :

[0124]

[0125] where D security is the device security level score; MaxSecurityLevel is the maximum value of the device security level; DeviceSecurityLevel is the security level of the device;

[0126] Scoring based on the device's security level can effectively screen high-security devices and avoid threats to resources posed by low-security-level devices. Through the standardized scoring of the device security level, the system can dynamically adjust access permissions to ensure that devices access resources within the allowed security range, helping to prevent security vulnerabilities and potential attack risks;

[0127] Access time score T access :

[0128]

[0129] where T access is the access time score, indicating the degree of match between the access time selected by the user when requesting resources and the preset allowed time range. The higher the score, the closer the access time is to the expected time range, and vice versa; T is the access time, that is, the time when the user actually initiates the request. Usually a specific timestamp (e.g., hours, minutes, seconds), used to compare with the allowed time range; AllowedTimeRange is the allowed time range, indicating the time period set by the system or administrator for the user to access resources. This is a time interval, usually representing a fixed window, such as 9 am to 5 pm; AccessTime is the time point of the access request, indicating the specific moment when the user issues the resource request;

[0130] If T is within the allowed time window, the deviation between the access time T and the set allowed time range is calculated, and the smaller the value, the closer it is to the preset time range and the higher the score; if T is not within the allowed time range: at this time, the score is directly 0, indicating that the access time is not within the predetermined allowed range, so there is no permission to access the resources.

[0131] By restricting the access time, it can ensure that users make resource requests within the specified time window and avoid accessing at inappropriate times. For example, the system can prevent resource access during non-working hours, improving the compliance and security of resource usage. This scoring mechanism based on time windows can effectively manage access requests at different times and prevent abuse or unauthorized access;

[0132] Historical behavior score H history :

[0133] H history = 1 - penaltyFator;

[0134] where H history is the historical behavior score; penaltyFactor is the penalty factor based on historical behavior; the user's historical behavior score reflects whether the user has a good behavior record, and the score is adjusted based on the penalty factor penaltyFactor of historical behavior. If the user has no bad records, the score is 1; if there are bad records, the score will be reduced accordingly;

[0135] By considering the user's historical behavior, users with bad records can be identified and access control can be performed according to their behavior. This penalty mechanism can effectively reduce potential risks, reduce the access rights of malicious users, and thus improve the overall security of the system. By reviewing historical behavior, the user's access rights can be adjusted more intelligently, reducing the incidence of violations;

[0136] Access frequency score F access :

[0137] F access = e -b·AccessFrequency ;

[0138] where F access is the access frequency score; b is a constant that controls the impact of access frequency; AccessFrequency is the access frequency; the score of the access frequency uses an exponential decay function. Frequent access requests will cause the score to decrease, and vice versa, the score will be higher;

[0139] Scoring according to the frequency of the user's access to resources can effectively prevent the abuse of resources. Users with frequent access will receive a lower access score, which helps to avoid over-requests that cause excessive system load or resource abuse. By introducing a penalty mechanism for access frequency, the use of system resources can be balanced, ensuring fair and stable resource allocation;

[0140] Then, the user's access right score:

[0141] Score = w 1 ·R + w2 ·D status + w 3 ·D security + w 4 ·T access + w 5 ·H history + w 6 ·F access + w 7 ·S data ;

[0142] Among them, Score is the access privilege score of the user; w 1 is the weight of the user role score; w 2 is the weight of the device authentication status score; w 3 is the weight of the device security level score; w 4 is the weight of the access time score; w 5 is the weight of the historical behavior score; w 6 is the weight of the access frequency score; w 7 is the weight of the data space security score

[0143] According to the score, the smart contract can dynamically adjust the user's access privilege. For example, when the user's access score is high, higher privileges (such as more data access privileges) may be granted, while when the score is low, the access scope or functions may be restricted; if the system discovers anomalies (such as malicious behaviors, frequently failed access requests, etc.) based on the access frequency or historical behavior, the smart contract can automatically adjust the privileges to enhance the system's security and prevent abuse.

[0144] S3. After the resource identifier is verified, the system allocates the resolution task of the resource identifier to each distributed node according to the load balancing algorithm. After each distributed node executes the identifier resolution task in parallel, their respective processing results are merged, and finally the result of the identifier resolution is returned;

[0145] Through the parallelized task allocation, each node can process different resolution tasks simultaneously, thus greatly improving the concurrent processing ability and response speed of the system; by dynamically adjusting the task volume of each node, it is possible to avoid overloading some nodes while other nodes are idle, improving the resource utilization efficiency.

[0146] During the process of S3 resource identifier resolution, an artificial intelligence model is used for query optimization, specifically: by analyzing historical query data, a prediction model for resource queries is established, and the node allocation and load balancing strategy of resource queries are dynamically adjusted according to the query prediction model, and the optimal query node is selected under high concurrency.

[0147] The load balancing algorithm ensures the reasonable allocation and parallel processing of resource identifier resolution tasks, thereby enhancing the processing capacity of the system. Through the analysis and prediction of historical query data, the artificial intelligence model optimizes query allocation and query node selection in a high-concurrency environment, further improving the system's response speed and resource utilization efficiency. This optimization method effectively reduces the performance bottlenecks that may occur in complex and high-load environments and improves the intelligence and adaptability of the system.

[0148] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification are only preferred examples of the present invention and are not used to limit the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed.

Claims

1. A resource unified identification and parsing calculation method based on a trusted data space, characterized in that: The steps include: S1. Generate a composite structure of resource identifiers according to the multi-source characteristics of resources, dynamically adjust the generation strategy of resource identifiers using a distributed hash algorithm and multi-factor analysis, and then encrypt the generated identifiers. In the process of generating the composite structure of resource identifiers according to the multi-source characteristics of resources, introduce the influencing factors of resource status for optimization; S2. Use blockchain to store encrypted resource identifiers. Whenever a resource identifier is updated or verified, a smart contract is triggered to verify whether the resource identifier is legal. At the same time, the historical changes and verification process of the resource identifier are recorded through the distributed ledger of the blockchain. S3. After the resource identifier is verified, the system assigns the resource identifier resolution task to each distributed node according to the load balancing algorithm. After each distributed node executes the identifier resolution task in parallel, it merges their respective processing results and finally returns the result of the identifier resolution.

2. The method for unified resource identification and parsing calculation based on a trusted data space according to claim 1, characterized in that: The multi-source characteristics of the resources include, but are not limited to, resource type, creation time, geographic location, and version information.

3. The method for unified resource identification and parsing calculation based on a trusted data space according to claim 2 is characterized in that: In S1, the specific steps of generating a composite structure of a resource identifier according to the multi-source characteristics of the resource are as follows: The composite structure of the resource identifier is generated: UID r =H(Type r ||Time r ||Location r ||Version r ); Among them, UID r Represents the preliminary identifier of resource r; Type r Indicates the resource type; Time r Indicates the time when the resource was created; Location r Indicates the geographic location where the resource was created; Version r Represents the version information of the resource; H is a hash function; || represents the operation of merging different attributes of the resource.

4. The method for unified resource identification and analysis calculation based on a trusted data space according to claim 3 is characterized in that: In S1, in the process of generating the composite structure of the resource identifier according to the multi-source characteristics of the resource, the influencing factors of the resource status are introduced for optimization, and the optimization is specifically as follows: UID r =H(Type r ||Time r ||Location r ||Version r ||(ω(Status r )×Status r )); Among them, UID r ′ is the identifier of the optimized resource r; ω(Status r ) is the weight of the status of resource r; Status r is the state of resource r; Among them, ω(Status r ) can take the following values: When Status r When it is active, ω(Status r )=1, indicating that resource r is in a normal and available state; When Status r When the status is pending, ω(Status r )=0.5, indicating that resource r is currently inactive; When Status r When the status is expired, ω(Status r )=0, indicating that resource r has expired.

5. The method for unified resource identification and parsing calculation based on a trusted data space according to claim 4 is characterized in that: In S1, the specific steps of using the distributed hash algorithm and multi-factor analysis to dynamically adjust the resource identifier generation strategy are as follows: S11. Comprehensive weight of the combined impact of multiple factors: W total =w U ·U r +w F ·F r +w L ·L+w P ·P r ; Among them, W total is the weighted sum of multiple factors; U r is the update time indicator of the resource; w U is the weight of the resource update time indicator; F r is the access frequency of the resource; w F is the weight of the access frequency of the resource; L is the system load; w L is the weight of the system load; P r is the priority of the resource; w P is the weight of the resource priority; S12, adjusting the resource identifier generation strategy according to the comprehensive weight; Set the weight threshold W of the comprehensive impact in advance threshold ; If W total >W threshold ,but: UID r =H(Type r ||Time r ||Location r ||Version r ||w U ·U r ||w F ·F r ||w L ·L||w P ·P r ); If W total ≤W threshold ,but: UID r ″=H(Type r ||Time r ||Location r ||Version r ); Among them, UID r ″ is the identifier of the adjusted resource r.

6. The method for unified resource identification and analysis calculation based on a trusted data space according to claim 5 is characterized in that: The smart contract is capable of performing resource management tasks at each stage of the resource identifier life cycle, wherein the resource management tasks include verification of the creation, modification, and destruction processes.

7. The method for unified resource identification and parsing calculation based on a trusted data space according to claim 6 is characterized in that: In S2, the smart contract is triggered to verify whether the resource identifier is legal. The specific steps are as follows: S21. Smart contracts set access control rules based on user roles, device attributes, and time limits to limit different users’ access rights to resources. S22. Every time a user requests a resource, the smart contract verifies the user's authority according to the pre-set access control policy and returns the corresponding resource information according to the authority policy; S23. After the permission verification is completed, the user's access permission score is calculated based on the multi-dimensional access control strategy of the resource identifier, and the user's access permission is dynamically adjusted.

8. The method for unified resource identification and parsing calculation based on a trusted data space according to claim 7 is characterized in that: Verifying the user's authority in S22 includes checking whether the user role meets the requirements; verifying whether the device attributes meet the access conditions; confirming whether the access request is within the allowed time range; and confirming whether other defined access rules are met.

9. The method for unified resource identification and parsing calculation based on a trusted data space according to claim 8, characterized in that: The calculation of the user's access rights score in S23 is based on the user role, the authentication status of the device, the device type or the security level of the device, the time of the access request and the set allowed time range, the user's historical behavior, the frequency of the user's access to resources, and the security status of the current trusted data space, as follows: User role score R: R={1,0.75,0.5,0.25,0}; Among them, R is the user role score; when the user role is an administrator, R = 1; when the user role is a senior user, R = 0.75; if the user role is a common user, R = 0.5; if the user role is a visitor, R = 0.25; if the user role is a banned user, R = 0; Equipment certification status score D status : D status ={0,1}; Among them, D status D is the device authentication status score; when the device is authenticated, status =1; when the device is not authenticated, D status =0; Equipment safety level score D security : Among them, D security is the device security level score; MaxSecurityLevel is the maximum value of the device security level; DeviceSecurityLevel is the security level of the device; Access time score T access : Among them, T access is the access time score; T is the access time; AllowedTimeRange is the allowed time range; AccessTime is the time point of the access request; Historical behavior score H history : H history =1-penaltyFactor; Among them, H history is the historical behavior score; penaltyFactor is the penalty factor based on historical behavior; Visit frequency score F access : F access =e -b·AccessFrequency ; Among them, F access is the access frequency score; b is the constant controlling the impact of access frequency; AccessFrequency is the access frequency; Then, the user's access rights score is: Score=w1·R+w2·D status +w3·D security +w4·T access +w5·H history +w6·F access +w7·S data ; Among them, Score is the user's access permission score; w1 is the weight of the user role score; w2 is the weight of the device authentication status score; w3 is the weight of the device security level score; w4 is the weight of the access time score; w5 is the weight of the historical behavior score; w6 is the weight of the access frequency score; and w7 is the weight of the data space security score.

10. The method for unified resource identification and parsing calculation based on a trusted data space according to claim 9, characterized in that: During the S3 resource identifier resolution process, an artificial intelligence model is used to perform query optimization, specifically: by analyzing historical query data, a prediction model for resource query is established, and the node allocation and load balancing strategy for resource query is dynamically adjusted according to the query prediction model, and the optimal query node is selected under high concurrency conditions.

Citation Information

Patent Citations

  • Digital identity authentication method based on block chain technology

    CN117216740A

  • Internet of Things identifier analysis-oriented block chain reputation management system

    CN119172099A

  • Trusted data exchange method and device based on trusted space and storage medium

    CN119227120A

  • Verifiable labels for mandatory access control

    US20220043902A1

Cited By

  • Distributed data identification activeness consensus method based on block chain

    CN120821778A