Safety management method and system for data asset transaction
By integrating blockchain technology with smart contracts, the distributed proof storage and automated management of data assets are solved, and the centralized risks and untraceability of data asset security management in the existing technology are solved, and security and transparency are improved.
Patent Information
- Application Number
- CN202510596076.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-05-09
AI Technical Summary
The existing data asset security management solutions rely on centralized platforms and pose the risk of being attacked or internally committed evil, making it difficult to achieve decentralized, tampered with proof of data storage and meticulous audit of the entire process behavior.
By deeply integrating blockchain technology with smart contracts, distributed evidence storage and automated management of data assets can be realized. The specific methods include semantic embedding encoding of the asset usage behavior log recorded in the smart contract and the preset data usage strategy, and using a fine-grained semantic verification mechanism to achieve automatic comparison of the consistency of actual behavior and strategy.
It improves the system's response ability to illegal operations or potential risk events, ensures that every data call is in a controllable and traceable state, effectively prevents unauthorized access and malicious operations, and creates a safer, transparent and trustworthy operating environment for the data element market.
Smart Images

Figure CN120106841A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of intelligent management, and more specifically, to a security management method and system for data asset transactions. Background Art
[0002] With the rapid development of the digital economy, data has become an important production factor driving social progress and industrial upgrading. The value of data assets in all walks of life is becoming increasingly prominent, but at the same time, data also faces many security challenges in the process of circulation, trading and sharing, such as data tampering, abuse, leakage and unclear property rights. In order to ensure the security, integrity and compliance of data assets, it has become an industry consensus to build a scientific and effective data asset security management solution. This not only helps to protect the legitimate rights and interests of data providers and users, but also promotes the efficient circulation and market-oriented allocation of data elements, thereby releasing greater economic and social value.
[0003] Existing data asset security management solutions mainly rely on centralized platforms for data registration, evidence storage, and transaction matching. In this model, the platform, as an intermediary, is responsible for maintaining data information and transaction records, but it itself is at risk of being attacked or internally malicious, which makes the data easy to be tampered with or abused. In addition, when traditional solutions achieve cross-subject and cross-industry data circulation, due to the lack of a transparent and reliable mechanism, it is also difficult to meet the regulatory requirements for transaction traceability and compliance. In addition, for complex data usage behaviors and policy matching, there is currently a lack of fine-grained automated verification methods, which makes it difficult to detect and warn abnormal behaviors in a timely manner. It can be seen that how to achieve decentralized and tamper-proof data evidence storage and conduct detailed audits of the entire process behavior is a problem that the existing technology urgently needs to break through.
[0004] Therefore, an optimized security management method for data asset transactions is desired. Summary of the invention
[0005] In order to solve the above technical problems, the present application is proposed. The embodiment of the present application provides a security management method and system for data asset transactions, which deeply integrates blockchain technology with smart contracts to provide a new paradigm of distributed evidence storage and automated management for data assets. Specifically, by embedding the asset usage behavior log and the preset data usage policy recorded in the smart contract at the semantic level, and using a fine-grained semantic verification mechanism, the consistency of actual behavior and policy is automatically compared. Once a deviation from the preset policy or abnormal access is detected, an alarm prompt can be triggered in real time. In this way, not only the system's responsiveness to illegal operations or potential risk events is improved, but also it can ensure that each data call is in a controllable and traceable state, effectively preventing unauthorized access and malicious operations, and creating a more secure, transparent and reliable operating environment for the entire data factor market.
[0006] According to one aspect of the present application, a security management method for data asset transactions is provided, which includes: Get data assets uploaded by data providers; Perform hash operations on the data content of data assets to generate a unique hash value as the identifier of the data asset; After dividing the data content of the data asset into blocks, the hash value of each data block is calculated to obtain a hash fingerprint composed of multiple hash values; Write the data asset's identifier, key metadata, and hash fingerprint into the blockchain network as a transaction record; In response to a request to verify the integrity of a data asset, a check hash value and a check hash fingerprint of the data content of the data asset are recalculated, the check hash value is compared with an identifier of the data asset stored in the blockchain network, and the check hash fingerprint is compared with a hash fingerprint stored in the blockchain network to obtain an integrity verification result.
[0007] According to another aspect of the present application, a security management system for data asset transactions is provided, comprising: A data asset acquisition module is used to acquire data assets uploaded by a data provider; A hash calculation module is used to perform a hash operation on the data content of a data asset to generate a unique hash value as an identifier of the data asset; A hash fingerprint generation module is used to divide the data content of the data asset into blocks and then calculate the hash value of each data block to obtain a hash fingerprint composed of multiple hash values; The transaction record writing module is used to write the data asset identifier, key metadata of the data asset, and the hash fingerprint of the data asset into the blockchain network as a transaction record; A verification result generation module is used to verify the integrity of the data asset in response to a request, recalculate the verification hash value and verification hash fingerprint of the data content of the data asset, compare the verification hash value with the identifier of the data asset stored in the blockchain network, and compare the verification hash fingerprint with the hash fingerprint stored in the blockchain network to obtain an integrity verification result.
[0008] Compared with the prior art, the present application provides a security management method and system for data asset transactions, which deeply integrates blockchain technology with smart contracts to provide a new paradigm for distributed evidence storage and automated management of data assets. Specifically, by embedding the asset usage behavior log and the preset data usage policy recorded in the smart contract at the semantic level, and using a fine-grained semantic verification mechanism, an automatic comparison of the consistency between the actual behavior and the policy is achieved. Once a deviation from the preset policy or abnormal access is detected, an alarm prompt can be triggered in real time. In this way, not only is the system's ability to respond to illegal operations or potential risk events improved, but it can also ensure that every data call is in a controllable and traceable state, effectively preventing unauthorized access and malicious operations, and creating a more secure, transparent and trustworthy operating environment for the entire data factor market. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] By describing the embodiments of the present application in more detail in conjunction with the accompanying drawings, the above and other purposes, features and advantages of the present application will become more apparent. The accompanying drawings are used to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the present application and do not constitute a limitation of the present application. In the accompanying drawings, the same reference numerals generally represent the same components or steps.
[0010] Figure 1 A flowchart of a security management method for data asset transactions according to an embodiment of the present application; Figure 2 A data flow diagram of a security management method for data asset transactions according to an embodiment of the present application; Figure 3 A block diagram of a security management system for data asset transactions according to an embodiment of the present application. DETAILED DESCRIPTION
[0011] Below, the exemplary embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application, and it should be understood that the present application is not limited to the exemplary embodiments described here.
[0012] As shown in this application and claims, unless the context clearly indicates an exception, the words "a", "an", "an" and / or "the" do not refer to the singular and may also include the plural. Generally speaking, the terms "include" and "comprise" only indicate the inclusion of the steps and elements that have been clearly identified, and these steps and elements do not constitute an exclusive list. The method or device may also include other steps or elements.
[0013] Although the present application makes various references to certain modules in the system according to the embodiments of the present application, any number of different modules can be used and run on the user terminal and / or server. The modules are only illustrative, and different aspects of the system and method can use different modules.
[0014] Flowcharts are used in the present application to illustrate the operations performed by the system according to the embodiments of the present application. It should be understood that the preceding or following operations are not necessarily performed accurately in order. On the contrary, various steps may be processed in reverse order or simultaneously as required. Meanwhile, other operations may also be added to these processes, or a certain step or several steps of operations may be removed from these processes.
[0015] Below, the exemplary embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application, and it should be understood that the present application is not limited to the exemplary embodiments described here.
[0016] In the technical solution of the present application, a security management method for data asset transactions is proposed. Figure 1 This is a flowchart of a security management method for data asset transactions according to an embodiment of the present application. Figure 2 Schematic diagram of data flow for a secure management method for data asset transactions according to an embodiment of the present application. Figure 1 and Figure 2 As shown, according to an embodiment of the present application, a security management method for data asset transactions includes the following steps: S1, obtaining data assets uploaded by a data provider; S2, performing a hash operation on the data content of the data asset to generate a unique hash value as an identifier of the data asset; S3, performing data block division on the data content of the data asset and calculating the hash value of each data block to obtain a hash fingerprint composed of multiple hash values; S4, writing the identifier of the data asset, the key metadata of the data asset, and the hash fingerprint of the data asset as a transaction record into a blockchain network; S5, in response to a request to verify the integrity of the data asset, recalculating the verification hash value and the verification hash fingerprint of the data content of the data asset, comparing the verification hash value with the identifier of the data asset stored in the blockchain network, and comparing the verification hash fingerprint with the hash fingerprint stored in the blockchain network to obtain an integrity verification result.
[0017] In particular, the S1 obtains the data assets uploaded by the data provider. Among them, data assets refer to a collection of digital resources with quantifiable value, clear ownership and security control in the circulation link. Its form can include original data records, structured databases, desensitized derivative data sets and related metadata (such as data source, format, creation time, ownership, etc.). The circulation value of data as a new type of production factor needs to be converted into assets through the active upload behavior of the right holder, while the traditional centralized platform has the risk of data tampering and the lack of trust mechanism, resulting in the lack of security sharing willingness of data holders. By establishing a standardized data upload interface, the system can uniformly incorporate data resources scattered in multi-source heterogeneous environments into the blockchain evidence framework, laying the foundation for subsequent unique identification generation, integrity verification and compliance audit. In this way, the core pain point of "unreliable original data" in the market-oriented configuration of data elements is effectively solved, enabling data providers to realize the safe chain evidence storage of assets under a decentralized architecture, and at the same time, a trust anchor based on cryptographic verification is constructed for cross-institutional data transactions, significantly improving the anti-repudiation and traceability of data assets in the circulation process.
[0018] In particular, S2 performs a hash operation on the data content of the data asset to generate a unique hash value as the identification of the data asset. It should be understood that as a digital object with value attributes, the uniqueness authentication of data assets is crucial in the circulation link, and traditional platforms rely on manual entry or organization-defined identification rules, which are difficult to resist the risk of identification conflicts caused by malicious modifications by internal personnel or external attacks. In the technical solution of the present application, a mathematical summary calculation is performed on the data content through a hash algorithm (such as SHA-256), which can generate an irreversible fixed-length hash value based on the uniqueness of the original byte stream. That is, by constructing a decentralized data identity anchor point, the blockchain network can verify the originality and uniqueness of the data asset without relying on a third-party authority, and at the same time provide a basic comparison benchmark for subsequent block hash fingerprint generation and integrity verification. On the one hand, the hash value can ensure that each data asset has a non-repeatable and non-forgeable "fingerprint" when it is registered on the chain, which fundamentally prevents the confusion of data from different sources or with similar content, and avoids identity disputes in subsequent transactions; on the other hand, because the hash algorithm has anti-collision characteristics, even a small change in the data will lead to a completely different hash result, so the identifier naturally has an integrity verification function, which provides a basis for subsequent data consistency verification. It is worth mentioning that the introduction of hash identifiers not only solves the ownership dispute problem caused by inconsistent identification rules in cross-platform data transactions, but also eliminates the errors that may be introduced by manual operations through algorithmic determinism, so that each transfer of data assets can quickly complete identity verification based on cryptographic evidence, providing irrefutable technical credentials for data compliance audits.
[0019] In particular, the S3, after data blocks are formed on the data content of the data asset, the hash value of each data block is calculated to obtain a hash fingerprint composed of multiple hash values. It should be understood that the actual application scenarios of data assets often involve multi-subject collaborative processing or local updates (such as partial slice modification of medical imaging data sets, incremental addition of financial transaction records). If only the overall hash value verification is relied on, although it can identify whether the data has been tampered with, it is impossible to accurately locate the specific data segment where the tampering occurred, and the verification efficiency of the full recalculation of the hash will significantly decrease with the increase of the data volume. To this end, in the technical solution of the present application, the data block technology is adopted to split the data assets into multiple logical data blocks according to preset rules (such as fixed byte number cutting or content-sensitive dynamic block), and independently calculate the hash value of each block, and then combine these hash values in the block order to form a hash fingerprint chain. Here, the global hash identifier is used to quickly verify the overall integrity of the data, while the block hash fingerprint supports fine-grained tampering positioning, so that auditors can quickly identify specific data intervals that have been tampered with (such as malicious modification of a clause in a contract document) without recalculating all data hashes. In this way, not only the efficiency of large-scale data auditing is significantly improved, but also the data integrity protection is extended from static evidence storage to dynamic update scenarios. In addition, the combination of block hash fingerprints and blockchain storage provides a technical basis for the distributed storage of data assets.
[0020] In particular, the S4 writes the identifier of the data asset, the key meta-information of the data asset, and the hash fingerprint of the data asset as a transaction record into the blockchain network. It should be understood that the traditional solution relies on a single institution to maintain data evidence records, and there is a risk of evidence invalidation due to human tampering or system failure. For example, in a cross-border trade scenario, a logistics platform may tamper with the timestamp or sensor data of the cargo temperature record due to profit-driven reasons, resulting in the inability to provide credible original evidence when a dispute occurs. To this end, the system uses the multi-node consensus mechanism of the blockchain network to encapsulate the hash identifier of the data asset (such as the full hash value generated by SHA-256), key meta-information (including structured fields such as data creation time, data source, data owner, etc.) and the block hash fingerprint (the hash value sequence generated by the data block) into a transaction data packet in a specific format, and calls the blockchain smart contract interface to write it into the latest block. In specific implementation, the system will use lightweight data serialization protocols (such as Protocol Buffers) to encode and compress these three types of information, initiate transaction requests through the preset blockchain node API, and after verification by the consensus node, package the transaction record together with additional information such as timestamps and digital signatures into blocks, and broadcast them to all network nodes for distributed storage. In other words, by building a decentralized data storage infrastructure, the initial state and key features of data assets are permanently anchored by the tamper-proof characteristics of the blockchain to form a legally effective electronic certificate. Here, the binding storage of hash identifiers and meta-information ensures that the uniqueness of data identity can be verified, preventing data assets from being cloned or misused in the circulation link; the chain storage structure of the block hash fingerprint makes it inevitable that local data tampering will trigger changes in the corresponding block hash value; in addition, the blockchain's timestamp service provides data assets with judicial evidence-level storage effectiveness.
[0021] In particular, S5, in response to a request to verify the integrity of a data asset, recalculates the verification hash value and the verification hash fingerprint of the data content of the data asset, compares the verification hash value with the identifier of the data asset stored in the blockchain network, and compares the verification hash fingerprint with the hash fingerprint stored in the blockchain network to obtain an integrity verification result. Considering that when data assets are in cross-border transmission, multi-party collaboration or long-term storage (such as clinical trial data sets shared between multinational pharmaceutical companies), the recipient or regulatory agency needs to have the ability to verify data integrity in real time, but the verification service provided by traditional centralized platforms has a single point failure risk and cannot prove the neutrality of the verification process. To this end, the system implements two-way verification of on-chain and off-chain data through a triggered verification mechanism: when a data user or auditor initiates a verification request, the system first obtains the original content of the target data asset from the distributed storage node, and recalculates the overall verification hash value and the block verification hash fingerprint according to the same preprocessing rules as the initial evidence storage stage (including data cleaning format, block size setting and hash algorithm selection); then, the system queries the original hash identifier and fingerprint chain written to the chain when the data asset is registered through the blockchain browser interface, and uses a dual-threaded comparison engine to perform global hash value precise matching (whether the overall hash value is consistent) and block hash fingerprint sequence consistency verification (whether the hash value of each data block completely corresponds in sequence). If a block hash value mismatch is detected (such as the temperature data of a batch in the logistics record is tampered with), the system will locate the abnormal block index and generate a tampering location report. In other words, by building a self-verification ecosystem in a decentralized environment, any participant can independently complete the data integrity audit without relying on a third-party organization, and at the same time, through algorithm reproduction and cross-verification of on-chain records, the repeatability and non-repudiation of the verification process are ensured. Here, the verification process based on cryptographic primitives has the reliability of mathematical proof level, eliminating the verification errors caused by human intervention; and the chain verification structure of block hash fingerprints extends data integrity protection from overall verification to fine-grained detection, greatly improving the verification efficiency of large-scale data sets; in addition, the tamper-proof characteristics of blockchain storage and the dynamic verification of real-time calculation form a closed loop, so that any state change of data assets in its entire life cycle can be accurately captured. This combination of technologies effectively solves the contradiction between the decentralization of verification authority and the credibility of verification results in the circulation of data elements, and provides a basic trust infrastructure for building an open data ecosystem.
[0022] However, it should be understood that in actual scenarios, relying solely on traditional rule matching is difficult to cope with complex and changeable data usage scenarios and anomaly detection needs, and coarse-grained logs alone cannot effectively identify subtle or hidden data abuse behaviors. In the technical solution of this application, by extracting the latest operation records (i.e., asset usage behavior logs) and corresponding data usage strategies from smart contracts in real time, the two are converted into comparable, high-dimensional and expressive semantic vectors, and then using feature search engines such as self-attention mechanisms, each actual operation is dynamically and meticulously compared with the established strategy. This approach not only improves the level of automation in the monitoring and auditing process, but also responds promptly to new violation patterns in complex or cross-domain scenarios. By combining blockchain technology with smart contracts to automatically generate and store these logs, the transparency and trust of information can be significantly improved, and human tampering or forgery can be effectively prevented.
[0023] Specifically, first, extract the asset usage behavior log from the smart contract of the data asset. It should be understood that the operation records manually maintained by the platform administrator in the traditional solution are easily tampered or deleted by internal personnel, while the log generation mechanism based on the smart contract ensures that each data operation is permanently solidified from the moment it occurs through the consensus verification and distributed storage characteristics of the blockchain, forming a behavioral evidence chain with judicial evidence effectiveness. Among them, the asset usage behavior log refers to the time-series digital certificate of the operation events of the entire life cycle of the data asset recorded in real time through the automated execution characteristics of the blockchain smart contract. Its content covers the identity of the data access subject, the type of operation (such as data download, modification authorization, secondary distribution), the operation timestamp, the magnitude of the data operation and the associated environmental parameters (such as access IP geo-fence, device fingerprint) and other dimensional information. By extracting these detailed behavior logs, the actual data operation can be deeply compared with the preset data usage strategy at the semantic level, which can not only determine whether a specific operation complies with the authorization, but also analyze the potential abnormal patterns in the continuous operation sequence, and realize the accurate identification of complex violation scenarios (such as authority overstepping, multiple re-authorization, etc.). In this way, the system's ability to control various risks throughout the life cycle of data assets has been greatly enhanced. Whether in regular operations or emergency response scenarios, real-time monitoring, automatic alarms, and efficient traceability can be achieved based on tamper-proof, highly reliable behavior logs, laying a solid foundation for protecting the rights and interests of data providers and users and preventing malicious attacks and internal misconduct.
[0024] Next, the preset data usage policy is extracted from the smart contract of the data asset. The preset data usage policy refers to a series of rules on how the data is accessed, processed, shared and authorized, which are formulated and solidified in the smart contract in advance by the data owner or manager in accordance with laws, regulations, industry norms and their own needs when the data asset is generated or uploaded to the chain. These policies may include access permission restrictions (such as only specific users / roles can access), use restrictions (such as only for scientific research / not for commercial resale), time range restrictions (such as available within the validity period), operation frequency restrictions, and special protection requirements for sensitive fields. By solidifying these complex and diverse data usage policies in an unalterable and automatically executed smart contract, and being able to extract them automatically in real time, it can ensure that each behavior verification is based on the latest and authoritative policies, effectively preventing human omissions or subjective and arbitrary interpretations; in addition, this mechanism greatly improves the system's adaptability to new violation modes (such as combined authorization, multi-level sub-authorization, etc.) in complex and changing scenarios, and realizes highly flexible and fine-grained compliance supervision.
[0025] Then, the asset usage behavior log and the preset data usage policy are semantically embedded and encoded to obtain a sequence of asset usage behavior semantic fine-grained description encoding vectors and preset data usage policy semantic encoding vectors. It should be understood that the asset usage behavior log records the specific operation details of the user on the data asset, while the preset data usage policy contains diverse and complex constraints and business logic. Embedding the two at the semantic level can convert textual and structured data into high-dimensional vector expressions, thereby capturing its inherent semantic associations and contextual information, and making up for the insufficiency of traditional symbol matching methods that cannot effectively identify fuzzy and obscure illegal operations. In this way, the system can understand the operation intentions and policy requirements more comprehensively and meticulously, and accurately identify the degree of compliance or potential deviations between behaviors and policies. In this way, it is possible to convert massive complex behaviors and variable strategies into expressive and machine-parseable semantic vectors, greatly enriching the feature space and recognition capabilities of data security audits. In addition, fine-grained query and aggregation based on coding vectors enable abnormal behavior detection to not only cover surface coarse-grained violations, but also go deep into potential semantic deviations and hidden risks, reduce missed reports and false alarms, and provide more reliable support for security operations. Finally, this coding method promotes the transformation of data asset security management from static rules to dynamic semantic understanding, laying a solid technical foundation for achieving more intelligent, efficient and reliable data asset full life cycle management.
[0026] In a specific example of the present application, the asset usage behavior log and the preset data usage policy can be semantically embedded and encoded through the following steps to obtain a sequence of asset usage behavior semantic fine-grained description encoding vectors and a preset data usage policy semantic encoding vector: first, the asset usage row embedding matrix is used to embed the individual behavior logs in the asset usage behavior log to obtain a sequence of asset usage behavior log embedded encoding vectors; the preset data usage policy embedding matrix is used to embed the individual policies in the preset data usage policy to obtain a preset data usage policy embedded encoding vector; then, the sequence of asset usage behavior log embedded encoding vectors and the preset data usage policy embedded encoding vector are subjected to a contextual semantic encoder based on a bidirectional LSTM model to obtain a sequence of asset usage behavior semantic fine-grained description encoding vectors and a preset data usage policy semantic encoding vector.
[0027] Furthermore, the sequence of asset usage behavior semantic fine-grained description coding vectors and preset data usage policy semantic coding vectors are input into the smart contract semantic fine-grained query audit module to obtain the asset usage behavior-preset data usage policy semantic fine-grained verification aggregate coding vector. It should be understood that in actual business, data usage behavior may involve multi-subject and multi-stage interactive operations (such as cross-departmental data sharing, periodic authorization updates, or condition-triggered access behaviors), and preset policies often contain nested compliance constraints (such as time limits, permission granularity, or scope of use). Traditional methods rely on static matching of rule engines, which makes it difficult to capture implicit semantic associations between behaviors and policies, such as whether "bulk export of data to external systems" in behavior logs complies with the ambiguous description of "for internal analysis only" in the policy. Therefore, in order to build a dynamic and adaptive semantic verification mechanism, so that the audit process can penetrate the surface feature comparison and deeply understand the semantic consistency of behavior and strategy, in the technical solution of this application, the sequence of asset usage behavior semantic fine-grained description coding vectors and preset data usage strategy semantic coding vectors are input into the smart contract semantic fine-grained query audit module to obtain asset usage behavior-preset data usage strategy semantic fine-grained verification aggregation coding vector. In this process, first, through feature enhancement based on deconvolution coding, the fine-grained description coding vector of the behavior log and the strategy coding vector are aligned on the feature scale to ensure the comparability of the two in the semantic space; then, the monomer semantic query unit quantifies the deep semantic association between the behavior feature and the strategy feature (such as the implicit conflict between the "export" behavior and the "prohibit external transmission" strategy) through dynamic projection and covariance matrix calculation. This process not only focuses on the isolated matching of a single behavior and strategy, but also analyzes the contextual semantic distribution of the overall behavior sequence through self-attention aggregation, identifies the pattern deviation of abnormal behavior (such as the deviation trend between high-frequency access and low-frequency strategy), and thus realizes semantic risk perception from local to global. Through the asset usage behavior-preset data usage policy semantic fine-grained verification aggregation coding vector, the model can dynamically capture the complex nonlinear relationship between behavior and policy, such as identifying operations that are not clearly defined but implicitly prohibited in the policy (such as inferring data abuse risks through combined behavior). In cross-industry data circulation scenarios, this mechanism can automatically adapt to policy semantics under different regulatory frameworks (such as compliance differences between financial data and medical data) to avoid misjudgments due to differences in policy expressions; in real-time monitoring scenarios, high-risk behavior nodes (such as data access during non-working hours) are dynamically focused through self-attention weights to achieve early warning of abnormal behavior. In this way, the full life cycle audit of data assets is transformed from passive rule matching to active semantic insights, significantly improving the coverage breadth and response efficiency of security management.
[0028] More specifically, first, the semantic coding vector of the preset data usage policy is enhanced based on deconvolution coding to obtain an enhanced semantic coding vector of the preset data usage policy. It should be understood that preset policies (such as "internal access only" or "cross-domain transmission is prohibited") often exist in the form of abstract rules or natural language clauses, and their semantic coding may be limited by the insufficient granularity of the original feature extraction, and it is difficult to cover the multi-level constraints implied in the policy (such as time conditions, permission nesting or dynamic authorization logic). When the traditional method directly matches the policy coding vector with the behavior log, it is easy to ignore the semantic depth of the policy due to the shallow expression of features, for example, it is impossible to distinguish the essential difference between temporary authorization and long-term authorization in "access rights". Therefore, in order to construct an enhanced representation system of policy semantics, so that it can not only retain the normative constraints of the original policy, but also realize dynamic alignment with the fine-grained coding of the behavior log in a unified semantic space, in the technical solution of the present application, the semantic coding vector of the preset data usage policy is enhanced based on deconvolution coding to obtain an enhanced semantic coding vector of the preset data usage policy. Among them, the enhanced semantic coding vector of the preset data usage policy has the same feature scale as the semantic fine-grained description coding vector of each asset usage behavior.
[0029] Here, deconvolution coding can recover high-dimensional feature details from compressed semantic coding through inverse feature mapping reconstruction, solve the problem of information loss caused by dimensionality reduction operation in policy semantics, and lay the foundation for subsequent cross-modal semantic matching. Specifically, the deconvolution operation adaptively captures the local semantic patterns implicit in the policy encoding vector (such as the logical association between policy clauses) through a learnable upsampling kernel, and expands it to a feature scale that matches the behavior encoding. For example, the compound condition of "data export requires secondary approval" in the policy can be decomposed into sub-features such as "export action triggering conditions" and "approval level association" after deconvolution enhancement, forming a multi-dimensional comparable relationship with events such as "user A initiates export request" and "approval log missing" in the behavior log. This feature reconstruction not only improves the expressiveness of policy semantics, but also eliminates dimensional deviations during cross-modal matching through scale consistency, avoiding the risk of misjudgment caused by feature space dislocation. The enhanced preset data usage policy semantic encoding vector can penetrate the surface rule description and capture the dynamic semantic boundaries of policy clauses. In this way, the smart contract audit module can extract richer compliance clues from the enhanced semantics of the policy, providing a deep semantic basis for abnormal behavior detection.
[0030] In a specific example of the present application, the preset data usage strategy semantic coding vector is subjected to feature enhancement based on deconvolution coding using the following deconvolution formula to obtain an enhanced preset data usage strategy semantic coding vector; wherein the deconvolution formula is:
[0031] in, Using a strategic semantic encoding vector for the preset data, is the deconvolutional coding, is the deconvolution weight matrix, is the one-norm of the vector, Use policy semantic encoding vectors to enhance preset data.
[0032] Next, the semantic fine-grained description encoding vectors of asset usage behaviors in the sequence of the enhanced preset data usage policy semantic encoding vectors and the asset usage behavior semantic fine-grained description encoding vectors are subjected to monomer semantic query encoding to obtain a set of preset data usage policy monomer semantic query score encoding vectors. It should be understood that in actual business, data usage behaviors (such as "user A exports sensitive data in batches during non-working hours") often involve multi-dimensional operation details, while preset policies (such as "prohibiting data export during unauthorized time periods") may imply multi-level constraints (such as time range, operation type, user permissions). Traditional rule engines rely on keyword matching or simple logical judgments, and it is difficult to capture the dynamic semantic association between "prohibiting export" in policy terms and "export operations" in behavior logs (for example, whether the export is accompanied by a compliance approval process), and it is even more impossible to quantify the degree of matching between fuzzy conditions in the policy (such as "unauthorized time periods") and specific behavior timestamps. Therefore, in order to construct a fine-grained semantic association network so that the model can mine implicit compliance clues from the coding vectors of policies and behaviors, in the technical solution of the present application, each asset usage behavior semantic fine-grained description coding vector in the sequence of the preset data usage policy semantic coding vector and the asset usage behavior semantic fine-grained description coding vector is enhanced and monomer semantic query encoding is performed separately to obtain a set of preset data usage policy monomer semantic query score coding vectors.
[0033] Through the single semantic query unit, the enhanced policy encoding vector (such as "forbid external transmission") and each behavior encoding vector (such as "user B uploads data to an external cloud disk") dynamically interact in the deep neural network to generate multi-dimensional semantic matching scores. These scores are not simple right and wrong judgments, but quantify the degree of fit between policy constraints and behavior characteristics at different semantic levels (for example, the correlation strength between "transmission target address" and "external cloud disk", and the deviation between "operation time" and the policy restriction period). This encoding process transforms the abstract rules of policy clauses into computable multi-dimensional semantic vectors through nonlinear mapping of feature space, enabling the audit module to penetrate the surface behavior description and identify potential conflicts (such as the "secondary approval" requirement in the policy and the lack of approval records in the behavior log). By generating a set of single semantic query score encoding vectors for preset data usage policies, the model can analyze the association patterns between behavior sequences and policies one by one. This fine-grained matching not only covers explicit rules (such as explicitly prohibited operation types), but also captures abnormal patterns that are not clearly defined in the policy but contain implicit risks (such as statistical deviations between high-frequency access behaviors and low-frequency policies). This enables the smart contract audit module to accurately locate high-risk nodes from massive behavior logs, providing dynamic and explainable semantic support for the full-process security management of data assets.
[0034] In a specific example of the present application, the following semantic query formula is used to perform monomer semantic query encoding on each asset usage behavior semantic fine-grained description encoding vector in the sequence of the enhanced preset data usage strategy semantic encoding vector and the asset usage behavior semantic fine-grained description encoding vector to obtain a set of preset data usage strategy monomer semantic query score encoding vectors; wherein the semantic query formula is:
[0035] in, A sequence of encoding vectors that describe the semantic fine-grained nature of asset usage behavior, are the first, second, and third vectors in the sequence of the asset usage behavior semantic fine-grained description encoding vectors. and Each asset is encoded using a fine-grained description of behavioral semantics. and are the trainable weight matrix and the trainable bias vector, respectively. For vector concatenation operations, for function, for The preset data uses the strategy monomer semantic query score encoding vector.
[0036] Then, determine the monomer semantic matching degree of each preset data usage strategy monomer semantic query score encoding vector in the set of preset data usage strategy monomer semantic query score encoding vectors to obtain a set of preset data usage strategy monomer semantic matching degrees. That is, in an embodiment of the present application, first, each preset data usage strategy monomer semantic query score encoding vector in the set of preset data usage strategy monomer semantic query score encoding vectors is subjected to mapping specification fixed optimization to obtain a set of optimized preset data usage strategy monomer semantic query score encoding vectors. It should be understood that when the smart contract audit module makes a preliminary association between the behavior log and the strategy through the monomer semantic query unit, due to the inherent misalignment of the feature space and the semantic query encoding space (for example, the difference in semantic coverage of the same strategy in different behavior sequences, the policy constraints and the implicit dimensions of the behavior characteristics do not correspond, etc.), the query score encoding vector generated by directly splicing the features is difficult to accurately characterize the deep semantic association between the strategy and the behavior. This misalignment may lead to a policy matching deviation in the subsequent aggregation stage, such as misjudging a legal but semantically marginalized operation as a violation, or ignoring a covert attack that breaks through the policy restrictions through a multi-step combination. Therefore, in order to dynamically correct the projection relationship between the feature space and the semantic query encoding space, in a preferred example of the present application, each preset data usage strategy monomer semantic query score encoding vector in the set of preset data usage strategy monomer semantic query score encoding vectors is subjected to mapping specification fixed optimization to obtain a set of optimized preset data usage strategy monomer semantic query score encoding vectors.
[0037] That is, by introducing the interaction potential vector and covariance matrix, the cascade features (the concatenation of the policy and behavior encoding) are dynamically projected into the semantic query space, and the mapping process is constrained by the covariance path under the canonical symmetry condition. For example, the "data encryption level requirement" in the policy and the "actual encryption algorithm" in the behavior may not be directly associated in the original encoding due to different feature scales, and the optimization process dynamically adjusts the mapping parameters to make the two form a comparable relationship in a unified semantic space. This optimization is not a simple linear transformation, but through the dynamic reconstruction and inherent alignment of the feature space, it ensures that the abstract constraints of the policy terms and the concrete features of the behavior details are deeply integrated at the semantic level. The optimized set of single semantic query score encoding vectors of the preset data usage policy not only retains the fine-grained features of the single semantic query (for example, whether a data download behavior touches the policy boundary in the dual dimensions of time window and user authority), but also eliminates cross-dimensional semantic interference (such as mistakenly associating data format compliance with usage frequency restrictions) through the inherent alignment mechanism. This optimization mechanism provides a high-fidelity semantic basis for the subsequent dynamic allocation of self-attention weights, allowing the alarm triggering decision to penetrate the complex behavioral appearances and directly point to the essential logic of policy violations, ultimately achieving a security management transition from extensive rule matching to intelligent semantic reasoning.
[0038] Then, based on the distribution characteristics of the set of optimized preset data usage strategy monomer semantic query score encoding vectors, the monomer semantic matching degree of each optimized preset data usage strategy monomer semantic query score encoding vector is calculated to obtain the set of preset data usage strategy monomer semantic matching degrees. It should be understood that when the system obtains a more accurate encoding vector through fixed optimization of mapping specifications, the isolated evaluation of the matching relationship between a single vector and a strategy is prone to fall into the local optimal trap, for example, a high-frequency but compliant operation may be misjudged as an abnormality, or the systematic strategy deviation caused by the superposition of multiple low-risk behaviors may be ignored. By introducing a dynamic perception mechanism of set distribution characteristics, the system can break through the field of view limitations of single-point analysis and identify the implicit association pattern between behavior and strategy at the global level, thereby avoiding the risk of misjudgment caused by local feature amplification or noise interference. That is, by mining the distribution law of the set of encoding vectors (such as density aggregation, outlier characteristics, and gradient change trends), an attempt is made to construct a dynamic evaluation system for the strength of the association between behavior and strategy. This adaptive adjustment mechanism based on group distribution enables the system to automatically identify weak links in policy execution according to the evolution of behavioral patterns in actual business scenarios. For example, when a certain type of data download behavior exceeds the access frequency specified by the policy in the time dimension, even if the single operation is compliant, its matching degree will be marked as a potential risk due to distribution anomalies. By placing each optimized preset data usage policy monomer semantic query score encoding vector in the overall context of the set distribution for semantic matching calculation, the system has achieved an upgrade from static rule matching to dynamic context-aware audit mode. This mechanism can not only capture explicit violations (such as unauthorized IP access), but also discover hidden risks (such as the accumulation of unconventional behavior patterns in compliant operations) through distribution anomaly detection, so that the alarm system has predictive risk prevention and control capabilities, rather than relying solely on post-rule comparison. Ultimately, this semantic matching degree calculation based on global distribution characteristics provides intelligent audit support with both sensitivity and specificity for the full life cycle security management of data assets.
[0039] In this example, the monomer semantic matching degree of each preset data usage strategy monomer semantic query score encoding vector in the set of preset data usage strategy monomer semantic query score encoding vectors is determined by the following semantic matching formula to obtain a set of preset data usage strategy monomer semantic matching degrees; wherein the semantic matching formula is:
[0040] in, Use the strategy to query the potential vector for the preset data, is the projection weight matrix, query interaction encoding vectors for preset data using strategies, is the coupling constant, calculated in the same way as in deconvolution enhancement to preserve symmetry, Use the strategy to query the covariance matrix for the preset data. The single semantic query score encoding vector is used for the calibrated preset data. for The number of For the An optimized preset data usage strategy single semantic query score encoding vector, For The natural exponential function with base , for function, Use the strategy monomer semantic matching degree for preset data, is the mask function.
[0041] Furthermore, the set of semantic matching degrees of preset data usage policy monomers is input into the relationship gating processing module to obtain the set of semantic self-attention weights of preset data usage policy monomer queries. It should be understood that when the system directly generates self-attention weights through the optimized semantic matching degree set, due to the constraint associations between different policy clauses (such as the coupling relationship between data usage geographical restrictions and encryption levels), potential violation patterns across behavioral sequences (such as policy breakthroughs triggered by the superposition of multiple low-frequency unconventional accesses), and other complex semantic relationships that are difficult to capture by linear weight allocation, simple weighted aggregation may cause key violation signals to be diluted or marginal compliance behaviors to be over-amplified. Therefore, in order to build a nonlinear mapping bridge between policy semantic associations and behavioral risks, in the technical solution of the present application, the set of semantic matching degrees of preset data usage policy monomers is input into the relationship gating processing module to obtain the set of semantic self-attention weights of preset data usage policy monomer queries.
[0042] Among them, the gated processing module establishes a canonical symmetric mapping path between the feature space and the semantic encoding space through the operation of coupling constants and covariant matrices, so that the deep semantic association between policy constraints and behavioral features can be made explicit. For example, when a certain type of data access behavior is detected to show a systematic deviation in the matching degree of multiple policy clauses, the gating mechanism will automatically enhance the association weight of these matching degree signals, so that the subsequent aggregation process can focus on the complex violation characteristics, rather than evaluating the compliance of a single clause in isolation. This dynamic regulation capability enables the system to break through the rigid threshold limit of the traditional rule engine and achieve an intelligent transition from discrete rule matching to continuous semantic association. The preset data processed by relational gating uses the set of semantic self-attention weights of the policy monomer query, which effectively realizes the refined control of the semantic relationship of the policy audit process. Through the dynamic eigenstate projection of the interaction potential vector and the canonical fixation of the covariant path, the system can capture the implicit coupling mode of policy constraints and behavioral characteristics in the feature space. This mechanism not only improves the detection sensitivity of complex violation patterns, but also enhances the credibility of the audit results through the interpretability of weight distribution, and finally forms a data asset security protection system with both intelligence and reliability.
[0043] In a specific example of the present application, the set of preset data usage strategy monomer semantic matching degrees is input into the relationship gating processing module using the following gating formula to obtain a set of preset data usage strategy monomer query semantic self-attention weights; wherein the gating formula is:
[0044] in, is the preset threshold, Use the strategy to query semantic self-attention weights for preset data.
[0045] Subsequently, based on the set of the semantic self-attention weights of the preset data usage strategy monomer query, the set of the preset data usage strategy monomer semantic query score encoding vectors is aggregated to obtain the asset usage behavior-preset data usage strategy semantic fine-grained verification aggregate encoding vector. It should be understood that when the smart contract audit system completes the dynamic calculation and weight adjustment of the policy matching degree through the previous steps, if a fixed rule is used for information aggregation (such as average weighting or simple threshold determination), it will be difficult to adapt to the nonlinear coupling relationship between multi-dimensional policy constraints and behavioral characteristics. For example, in a cross-subject data sharing scenario, the constraint strength of different policy clauses on data usage behavior may change dynamically with the business scenario, and a single behavior may involve the complex compliance requirements of multiple policies at the same time. This dynamic association characteristic requires the aggregation mechanism to have the ability to autonomously focus on key semantic features. Therefore, in the technical solution of the present application, based on the set of the semantic self-attention weights of the preset data usage strategy monomer query, the set of the preset data usage strategy monomer semantic query score encoding vectors is aggregated to obtain the asset usage behavior-preset data usage strategy semantic fine-grained verification aggregate encoding vector.
[0046] Here, through the dynamic allocation mechanism of self-attention weights, the system can break through the mechanical limitations of traditional aggregation methods and achieve adaptive fusion of policy semantic associations and behavioral risk features. This process weights the correlation between each semantic query score encoding vector and its corresponding dynamic weight, so that the aggregation process is no longer a simple numerical superposition, but is transformed into a deep feature reconstruction of the policy-behavior semantic space. This reconstruction is essentially to build a mapping relationship network between policy constraints and behavioral trajectories in a high-dimensional semantic space. Through the dynamic adjustment of weight allocation, key violation signals (such as correlation anomalies of high-frequency unconventional access) are highlighted while non-critical noise (such as accidental deviations in routine operations), thereby extracting core audit features with decision-making value in complex data circulation scenarios. This aggregation mechanism gives the audit module the ability to penetrate complex violations, so that the alarm triggering logic no longer relies on strong abnormal signals in a single dimension, but is based on collaborative abnormal analysis of multi-source semantic features, ultimately forming an intelligent security protection system with both sensitivity and accuracy.
[0047] In a specific example of the present application, the set of preset data usage policy monomer semantic query score encoding vectors is aggregated by the following aggregation formula to obtain the asset usage behavior-preset data usage policy semantic fine-grained verification aggregation encoding vector; wherein the aggregation formula is:
[0048] in, Aggregate encoding vectors for asset usage behavior - semantic fine-grained verification of preset data usage policies.
[0049] Finally, based on the asset usage behavior-preset data usage policy semantic fine-grained verification aggregate coding vector, determine whether to trigger an alarm prompt. That is, in the technical solution of the present application, the asset usage behavior-preset data usage policy semantic fine-grained verification aggregate coding vector is passed through a classifier-based alarm prompter to obtain an alarm prompt result, and the alarm prompt result is used to indicate whether to trigger an alarm prompt. It should be understood that although the asset usage behavior-preset data usage policy semantic fine-grained verification aggregate coding vector realizes fine-grained association analysis, it still needs to convert abstract semantic features into specific compliance judgments (such as thresholds or patterns that trigger alarms). Traditional methods rely on manual rule setting or static threshold monitoring, which is difficult to adapt to dynamic policy adjustments or behavioral pattern evolution (such as the emergence of new data abuse methods). For example, when the policy is updated to "limit high-frequency access", traditional static rules may not be able to adaptively identify reasonable access frequencies in different business scenarios. Therefore, in order to build an intelligent risk decision engine, so that the alarm prompt can capture both explicit violations (such as unauthorized data export) and implicit abnormal patterns (such as low-frequency but high-risk sensitive data access), in the technical solution of this application, the asset usage behavior-preset data usage policy semantic fine-grained verification aggregate coding vector is passed through the classifier-based alarm prompter to obtain the alarm prompt result, and the alarm prompt result is used to indicate whether to trigger the alarm prompt. That is, the classifier learns the implicit rules of historical compliance data and abnormal patterns, and establishes a mapping relationship from semantic features to alarm decisions to solve the problem of adaptive risk determination in dynamic scenarios. In this process, the classifier can dynamically identify the risk signals implicit in the aggregate coding vector by training and learning the differences in semantic feature patterns between historical compliance behaviors and illegal behaviors. For example, when the aggregate coding vector presents a specific distribution in implicit dimensions such as "abnormal data usage frequency", "access subject authority crossing the boundary", and "policy clause coupling deviation", the classifier can determine whether it belongs to a new attack mode or potential violation through a nonlinear decision boundary. By using the classifier to classify and analyze the check aggregation coding vector, the system can not only effectively avoid omissions and false positives caused by rough manual rules, but also dynamically adapt to the diversification and evolution of data asset usage scenarios, and support the automatic update and optimization of real-time alarm strategies. In addition, this method promotes the transformation of the alarm mechanism from passive triggering to active intelligent prediction, greatly improving the overall security operation efficiency and response speed.
[0050] In summary, the security management method for data asset transactions according to the embodiment of the present application is explained, which deeply integrates blockchain technology with smart contracts to provide a new paradigm of distributed evidence storage and automated management for data assets. Specifically, by embedding the asset usage behavior log and the preset data usage policy recorded in the smart contract at the semantic level, and using a fine-grained semantic verification mechanism, an automatic comparison of the consistency between the actual behavior and the policy is achieved. Once a deviation from the preset policy or abnormal access is detected, an alarm prompt can be triggered in real time. In this way, not only is the system's ability to respond to illegal operations or potential risk events improved, but it can also ensure that each data call is in a controllable and traceable state, effectively preventing unauthorized access and malicious operations, and creating a more secure, transparent and reliable operating environment for the entire data factor market.
[0051] Furthermore, a security management system for data asset transactions is also provided.
[0052] Figure 3 FIG. 1 is a block diagram of a security management system for data asset transactions according to an embodiment of the present application. Figure 3 As shown, according to an embodiment of the present application, a security management system 300 for data asset transactions includes: a data asset acquisition module 310, which is used to acquire data assets uploaded by a data provider; a hash calculation module 320, which is used to perform a hash operation on the data content of the data asset to generate a unique hash value as an identifier of the data asset; a hash fingerprint generation module 330, which is used to perform data block division on the data content of the data asset and then calculate the hash value of each data block to obtain a hash fingerprint composed of multiple hash values; a transaction record writing module 340, which is used to write the identifier of the data asset, the key metadata of the data asset and the hash fingerprint of the data asset as a transaction record into the blockchain network; a verification result generation module 350, which is used to respond to a request to verify the integrity of the data asset, recalculate the verification hash value and the verification hash fingerprint of the data content of the data asset, compare the verification hash value with the identifier of the data asset stored in the blockchain network, and compare the verification hash fingerprint with the hash fingerprint stored in the blockchain network to obtain an integrity verification result.
[0053] As described above, the security management system 300 for data asset transactions according to the embodiment of the present application can be implemented in various wireless terminals, such as a server with a data asset security management algorithm. In one possible implementation, the security management system 300 for data asset transactions according to the embodiment of the present application can be integrated into the wireless terminal as a software module and / or a hardware module. For example, the security management system 300 for data asset transactions can be a software module in the operating system of the wireless terminal, or can be an application developed for the wireless terminal; of course, the security management system 300 for data asset transactions can also be one of the many hardware modules of the wireless terminal.
[0054] Alternatively, in another example, the security management system 300 for data asset transactions and the wireless terminal may also be separate devices, and the security management system 300 for data asset transactions may be connected to the wireless terminal via a wired and / or wireless network and transmit interactive information in accordance with an agreed data format.
[0055] The embodiments of the present disclosure have been described above, and the above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and changes will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The selection of terms used herein is intended to best explain the principles of the embodiments, practical applications, or improvements to the technology in the market, or to enable other persons of ordinary skill in the art to understand the embodiments disclosed herein.
Claims
1. A security management method for data asset transactions, characterized in that: include: Get data assets uploaded by data providers; Perform hash operations on the data content of data assets to generate a unique hash value as the identifier of the data asset; After dividing the data content of the data asset into blocks, the hash value of each data block is calculated to obtain a hash fingerprint composed of multiple hash values; Write the data asset's identifier, key metadata, and hash fingerprint into the blockchain network as a transaction record; In response to a request to verify the integrity of a data asset, a check hash value and a check hash fingerprint of the data content of the data asset are recalculated, the check hash value is compared with an identifier of the data asset stored in the blockchain network, and the check hash fingerprint is compared with a hash fingerprint stored in the blockchain network to obtain an integrity verification result.
2. The security management method for data asset transactions according to claim 1, characterized in that: The key metadata of data assets includes data creation time, data source, data format, data size and data owner.
3. The security management method for data asset transactions according to claim 2 is characterized in that: Also includes: Extract asset usage behavior logs from the smart contracts of data assets; Extract preset data usage policies from smart contracts of data assets; Perform semantic embedding encoding on the asset usage behavior log and the preset data usage strategy to obtain a sequence of asset usage behavior semantic fine-grained description encoding vectors and a preset data usage strategy semantic encoding vector; Input the sequence of asset usage behavior semantic fine-grained description coding vectors and preset data usage strategy semantic coding vectors into the smart contract semantic fine-grained query audit module to obtain the asset usage behavior-preset data usage strategy semantic fine-grained verification aggregate coding vector; Based on the asset usage behavior and the preset data usage policy semantics, the aggregate coding vector is verified in a fine-grained manner to determine whether to trigger an alarm prompt.
4. The security management method for data asset transactions according to claim 3 is characterized in that: The sequence of asset usage behavior semantic fine-grained description encoding vectors and preset data usage strategy semantic encoding vectors are input into the smart contract semantic fine-grained query audit module to obtain the asset usage behavior-preset data usage strategy semantic fine-grained verification aggregate encoding vector, including: Performing monomer semantic query encoding on each asset usage behavior semantic fine-grained description encoding vector in the sequence of the preset data usage strategy semantic encoding vector and the asset usage behavior semantic fine-grained description encoding vector to obtain a set of preset data usage strategy monomer semantic query score encoding vectors; Calculate the monomer semantic weight of each preset data usage strategy monomer semantic query score encoding vector in the set of preset data usage strategy monomer semantic query score encoding vectors to obtain a set of preset data usage strategy monomer query semantic self-attention weights; Based on the set of preset data usage strategy single query semantic self-attention weights, a set of preset data usage strategy single semantic query score encoding vectors is aggregated to obtain the asset usage behavior-preset data usage strategy semantic fine-grained verification aggregate encoding vector.
5. The security management method for data asset transactions according to claim 4 is characterized in that: Performing monomer semantic query encoding on each asset usage behavior semantic fine-grained description encoding vector in the sequence of the preset data usage strategy semantic encoding vector and the asset usage behavior semantic fine-grained description encoding vector to obtain a set of preset data usage strategy monomer semantic query score encoding vectors, including: Performing feature enhancement based on deconvolution coding on the preset data usage strategy semantic coding vector to obtain an enhanced preset data usage strategy semantic coding vector; Each asset usage behavior semantic fine-grained description encoding vector in the sequence of enhanced preset data usage strategy semantic encoding vector and asset usage behavior semantic fine-grained description encoding vector is subjected to monomer semantic query encoding to obtain a set of preset data usage strategy monomer semantic query score encoding vectors.
6. The security management method for data asset transactions according to claim 5, characterized in that: The semantic encoding vector of the enhanced preset data usage strategy and the semantic fine-grained description encoding vector of each asset usage behavior have the same characteristic scale.
7. The security management method for data asset transactions according to claim 6 is characterized in that: The monomer semantic weights of each preset data usage strategy monomer semantic query score encoding vector in the set of preset data usage strategy monomer semantic query score encoding vectors are calculated respectively to obtain a set of preset data usage strategy monomer query semantic self-attention weights, including: Based on the feature set self-distribution characteristics of the set of preset data usage strategy monomer semantic query score encoding vectors, determine the monomer semantic matching degree of each preset data usage strategy monomer semantic query score encoding vector in the set of preset data usage strategy monomer semantic query score encoding vectors to obtain a set of preset data usage strategy monomer semantic matching degrees; The set of preset data usage strategy monomer semantic matching degrees is input into the relationship gating processing module to obtain the set of preset data usage strategy monomer query semantic self-attention weights.
8. The security management method for data asset transactions according to claim 7 is characterized in that: Based on the feature set self-distribution characteristics of the set of preset data usage strategy monomer semantic query score encoding vectors, determining the monomer semantic matching degree of each preset data usage strategy monomer semantic query score encoding vector in the set of preset data usage strategy monomer semantic query score encoding vectors to obtain a set of preset data usage strategy monomer semantic matching degrees, including: Performing mapping specification fixed optimization on each preset data usage strategy monomer semantic query score encoding vector in the set of preset data usage strategy monomer semantic query score encoding vectors to obtain a set of optimized preset data usage strategy monomer semantic query score encoding vectors; Based on the distribution characteristics of the set of optimized preset data usage strategy monomer semantic query score encoding vectors, the monomer semantic matching degree of each optimized preset data usage strategy monomer semantic query score encoding vector is calculated to obtain a set of preset data usage strategy monomer semantic matching degrees.
9. The security management method for data asset transactions according to claim 8, characterized in that: Based on the asset usage behavior and the preset data usage policy semantics, the aggregated coding vector is verified in a fine-grained manner to determine whether to trigger an alarm prompt, including: The asset usage behavior-preset data usage policy semantic fine-grained verification aggregation coding vector is passed through a classifier-based alarm prompter to obtain an alarm prompt result, and the alarm prompt result is used to indicate whether to trigger an alarm prompt.
10. A security management system for data asset transactions, characterized in that: include: A data asset acquisition module is used to acquire data assets uploaded by a data provider; A hash calculation module is used to perform a hash operation on the data content of a data asset to generate a unique hash value as an identifier of the data asset; A hash fingerprint generation module is used to divide the data content of the data asset into blocks and then calculate the hash value of each data block to obtain a hash fingerprint composed of multiple hash values; The transaction record writing module is used to write the data asset identifier, key metadata of the data asset, and the hash fingerprint of the data asset into the blockchain network as a transaction record; A verification result generation module is used to verify the integrity of the data asset in response to a request, recalculate the verification hash value and verification hash fingerprint of the data content of the data asset, compare the verification hash value with the identifier of the data asset stored in the blockchain network, and compare the verification hash fingerprint with the hash fingerprint stored in the blockchain network to obtain an integrity verification result.
Citation Information
Patent Citations
Block chain-based asset data management method and system
CN114329529A
Financial big data optimization storage method
CN118363961A
Digital right encryption management method and system based on block chain
CN119557854A
Modification of in-execution smart contract programs
US10831452B1
Method and system for validation of claims against policy with contextualized semantic interoperability
US20120029951A1
Cited By
Internet asset sensitive data management method and system based on digital model
CN120893078A
An internet asset sensitive data management method and system based on a digital model
CN120893078B
Deep network security data protection strategy optimization method fusing behavior analysis
CN120934874A
Optimization Methods for Deep Cybersecurity Data Protection Strategies Integrating Behavioral Analysis
CN120934874B
Method and system for detecting abnormal operation of platform
CN121000414A