A security management method and system for data asset transactions
Through the integration of blockchain technology and smart contracts, hashing operations and fine-grained semantic verification, the security risks of the centralized platform in data asset transactions are solved, distributed evidence storage and automated management of data assets are realized, and the security and transparency of data transactions are improved.
Patent Information
- Application Number
- CN202510596076.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-05-09
AI Technical Summary
The existing data asset security management solutions rely on centralized platforms, and there is a risk of data tampering and abuse. It is difficult to achieve transparent and trustworthy data circulation and compliance supervision across subjects and industries. It lacks fine-grained automated verification methods, and it is difficult to detect abnormal behaviors in a timely manner.
By deeply integrating blockchain technology with smart contracts, hashing operations are used to generate unique identifiers and chunked hash fingerprints, distributed evidence storage and automated management are realized, combined with fine-grained semantic verification mechanisms, real-time monitoring of the usage behavior and policy consistency of data assets, and triggering alarm prompts.
It improves the security and transparency of data asset transactions, ensures that each data call is controllable and traceable, prevents unauthorized access and malicious operations, and builds a more secure, transparent and trustworthy market environment for data elements.
Smart Images

Figure CN120106841B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of intelligent management, and more specifically, to a security management method and system for data asset transactions. Background Art
[0002] With the rapid development of the digital economy, data has become an important production factor driving social progress and industrial upgrading. The value of data assets has become increasingly prominent in all walks of life. However, at the same time, data also faces many security challenges in the processes of circulation, transaction, and sharing, such as data tampering, abuse, leakage, and unclear property rights. To ensure the security, integrity, and compliant use of data assets, it has become an industry consensus to build a scientific and effective data asset security management solution. This not only helps to protect the legitimate rights and interests of data providers and users, but also promotes the efficient circulation and market-oriented allocation of data elements, thus releasing greater economic and social value.
[0003] Existing data asset security management solutions mainly rely on centralized platforms for data registration, deposit, and transaction matching. In this mode, the platform, as an intermediary, is responsible for maintaining data information and transaction records. However, it itself is at risk of being attacked or internal malfeasance, resulting in data being easily tampered with or abused. In addition, when traditional solutions achieve cross-subject and cross-industry data circulation, due to the lack of a transparent and trustworthy mechanism, it is also difficult to meet the regulatory requirements for transaction traceability and compliance. In addition, for complex data usage behaviors and policy matching, there is currently a lack of fine-grained automated verification means, which makes it difficult to detect and warn of abnormal behaviors in a timely manner. Thus, how to achieve decentralized and immutable data deposit and conduct a detailed audit of the full process behavior is an issue that the existing technology urgently needs to break through.
[0004] Therefore, an optimized security management method for data asset transactions is expected. Summary of the Invention
[0005] To solve the above technical problems, this application is proposed. Embodiments of this application provide a security management method and system for data asset transactions, which deeply integrate blockchain technology with smart contracts to provide a new paradigm for distributed storage and automated management of data assets. Specifically, by performing semantic-level embedded encoding on the asset usage behavior logs recorded in the smart contract and preset data usage policies, and using a fine-grained semantic verification mechanism, automatic comparison of the consistency between actual behaviors and policies is achieved. Once a deviation from the preset policy or an abnormal access is detected, an alarm prompt can be triggered in real time. In this way, not only the response ability of the system to illegal operations or potential risk events is improved, but also every data call can be kept under control and traceable, effectively preventing unauthorized access and malicious operations, and creating a more secure, transparent and trustworthy operating environment for the entire data element market.
[0006] According to one aspect of this application, a security management method for data asset transactions is provided, which includes:
[0007] Obtain the data assets uploaded by the data provider;
[0008] Perform a hash operation on the data content of the data asset to generate a unique hash value as the identifier of the data asset;
[0009] After dividing the data content of the data asset into chunks, calculate the hash values of each data chunk to obtain a hash fingerprint composed of multiple hash values;
[0010] Write the identifier of the data asset, the key meta-information of the data asset, and the hash fingerprint of the data asset as a transaction record into the blockchain network;
[0011] In response to a request to verify the integrity of the data asset, recalculate the verification hash value and verification hash fingerprint of the data content of the data asset, compare the verification hash value with the identifier of the data asset stored in the blockchain network, and compare the verification hash fingerprint with the hash fingerprint stored in the blockchain network to obtain an integrity verification result.
[0012] According to another aspect of this application, a security management system for data asset transactions is provided, which includes:
[0013] A data asset acquisition module for obtaining the data assets uploaded by the data provider;
[0014] A hash calculation module for performing a hash operation on the data content of the data asset to generate a unique hash value as the identifier of the data asset;
[0015] A hash fingerprint generation module, which is used to perform data chunking on the data content of a data asset and calculate the hash values of each data chunk to obtain a hash fingerprint composed of multiple hash values;
[0016] A transaction record writing module, which is used to write the identifier of the data asset, the key meta-information of the data asset, and the hash fingerprint of the data asset into the blockchain network as a transaction record;
[0017] A verification result generation module, which is used to respond to a request to verify the integrity of the data asset, recalculate the verification hash value and the verification hash fingerprint of the data content of the data asset, compare the verification hash value with the identifier of the data asset stored in the blockchain network, and compare the verification hash fingerprint with the hash fingerprint stored in the blockchain network to obtain an integrity verification result.
[0018] Compared with the prior art, a security management method and system for data asset transactions provided by the present application deeply integrates blockchain technology and smart contracts, providing a new paradigm for distributed storage and automated management of data assets. Specifically, by performing semantic-level embedded encoding on the asset usage behavior logs recorded in the smart contract and the preset data usage policies, and using a fine-grained semantic verification mechanism, automatic comparison of the consistency between the actual behavior and the policy is realized. Once a deviation from the preset policy or an abnormal access is detected, an alarm prompt can be triggered in real time. In this way, not only the response ability of the system to illegal operations or potential risk events is improved, but also every data call can be kept under control and traceable, effectively preventing unauthorized access and malicious operations, and creating a more secure, transparent and trustworthy operating environment for the entire data element market. Description of the Drawings
[0019] By describing the embodiments of the present application in more detail in conjunction with the drawings, the above and other objects, features and advantages of the present application will become more obvious. The drawings are used to provide a further understanding of the embodiments of the present application, and constitute a part of the specification. They are used to explain the present application together with the embodiments of the present application, and do not constitute a limitation to the present application. In the drawings, the same reference numerals generally represent the same components or steps.
[0020] Figure 1 It is a flowchart of a security management method for data asset transactions according to an embodiment of the present application;
[0021] Figure 2 It is a schematic diagram of data flow of a security management method for data asset transactions according to an embodiment of the present application;
[0022] Figure 3 It is a block diagram of a security management system for data asset transactions according to an embodiment of the present application. Detailed Embodiments
[0023] Hereinafter, example embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all embodiments of the present application. It should be understood that the present application is not limited by the example embodiments described herein.
[0024] As shown in the present application and the claims, unless the context clearly indicates otherwise, words such as "a", "an", "one", and / or "the" are not specifically singular and may also include plural. Generally speaking, the terms "comprising" and "including" only indicate the inclusion of the steps and elements that have been clearly identified, and these steps and elements do not constitute an exclusive list. A method or device may also include other steps or elements.
[0025] Although the present application makes various references to certain modules in the system according to the embodiments of the present application, any number of different modules can be used and run on the user terminal and / or server. The modules are merely illustrative, and different aspects of the system and method can use different modules.
[0026] In the technical solution of the present application, a security management method for data asset trading is proposed.
[0027] Hereinafter, example embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all embodiments of the present application. It should be understood that the present application is not limited by the example embodiments described herein.
[0028] In the technical solution of the present application, a security management method for data asset trading is proposed. Figure 1 FIG. is a flowchart of a security management method for data asset trading according to an embodiment of the present application. Figure 2 FIG. is a schematic diagram of data flow of a security management method for data asset trading according to an embodiment of the present application. As Figure 1 and Figure 2As shown, a security management method for data asset transactions according to an embodiment of the present application includes the steps of: S1, obtaining data assets uploaded by data providers; S2, performing a hashing operation on the data content of the data assets to generate a unique hash value as the identifier of the data assets; S3, dividing the data content of the data assets into data blocks and calculating the hash values of each data block to obtain a hash fingerprint composed of multiple hash values; S4, writing the identifier of the data assets, the key meta-information of the data assets, and the hash fingerprint of the data assets as a transaction record into the blockchain network; S5, in response to a request to verify the integrity of the data assets, recalculating the verification hash value and the verification hash fingerprint of the data content of the data assets, comparing the verification hash value with the identifier of the data assets stored in the blockchain network, and comparing the verification hash fingerprint with the hash fingerprint stored in the blockchain network to obtain an integrity verification result.
[0029] In particular, in S1, data assets uploaded by data providers are obtained. Among them, data assets refer to a set of digital resources with quantifiable value, clear ownership, and the need for security control in the circulation link. Its forms can cover original data records, structured databases, derivative data sets after desensitization processing, and associated meta-data (such as data sources, formats, creation times, ownership, etc.). The circulation value of data as a new production factor needs to be realized through the active uploading behavior of the ownership subject. However, traditional centralized platforms have risks of data tampering and lack of trust mechanisms, resulting in the lack of willingness of data holders to share securely. By establishing a standardized data upload interface, the system can uniformly incorporate data resources scattered in multi-source heterogeneous environments into the blockchain evidence storage framework, laying a foundation for subsequent generation of unique identifiers, integrity verification, and compliance auditing. In this way, the core pain point of "raw data is untrustworthy" in the market-based allocation of data elements is effectively solved, enabling data providers to securely store evidence on the chain in a decentralized architecture. At the same time, a trust anchor based on cryptographic verification is constructed for cross-institutional data transactions, significantly enhancing the non-repudiation and traceability of data assets during the transfer process.
[0030] Specifically, in step S2, a hashing operation is performed on the data content of the data asset to generate a unique hash value as the identifier of the data asset. It should be understood that as a digital object with value attributes, the uniqueness authentication of data assets is crucial in the circulation process. However, traditional platforms rely on manual entry or institution-defined identification rules, making it difficult to resist the risk of identification conflicts caused by malicious modification by internal personnel or external attacks. In the technical solution of this application, by performing a mathematical digest calculation on the data content through a hashing algorithm (such as SHA-256), an irreversible fixed-length hash value can be generated based on the uniqueness of the original byte stream. That is, by constructing a trustless data identity anchor point, the blockchain network can verify the originality and uniqueness of data assets without relying on a third-party authoritative institution, and at the same time provide a basic comparison benchmark for subsequent generation of block hash fingerprints and integrity verification. On the one hand, through the hash value, it can be ensured that each data asset has an irrepeatable and forgery-proof "fingerprint" when registered on the chain, fundamentally preventing the confusion of data from different sources or with similar content, and also avoiding identity disputes in subsequent transaction processes; on the other hand, due to the collision-resistant property of the hashing algorithm, even a minor change in the data will result in a completely different hash result. Therefore, this identifier naturally has an integrity verification function, providing a basis for subsequent data consistency verification. It is worth mentioning that the introduction of the hash identifier not only solves the problem of ownership disputes caused by inconsistent identification rules in cross-platform data transactions, but also eliminates the errors that may be introduced by manual operations through algorithmic determinism, enabling the identity verification of data assets to be quickly completed based on cryptographic evidence for each transfer, providing an undeniable technical voucher for data compliance auditing.
[0031] Specifically, in step S3, after data chunking the data content of the data asset, the hash value of each data chunk is calculated to obtain a hash fingerprint composed of multiple hash values. It should be understood that in the actual application scenarios of data assets, multi-party collaborative processing or partial updates are often involved (such as partial slice modification of a medical image dataset, incremental addition of financial transaction records). If only relying on the overall hash value verification, although it can identify whether the data has been tampered with, it cannot accurately locate the specific data segment where the tampering occurred, and the verification efficiency of full-scale recalculating the hash will decrease significantly as the data volume increases. Therefore, in the technical solution of this application, the data chunking technology is adopted to split the data asset into multiple logical data chunks according to a preset rule (such as cutting by a fixed number of bytes or dynamic chunking based on content sensitivity), and the hash value of each chunk is calculated independently, and then these hash values are combined in the chunking order to form a hash fingerprint chain. Here, the global hash identifier is used to quickly verify the overall integrity of the data, while the chunked hash fingerprint supports fine-grained tampering localization, enabling auditors to quickly identify the specific data interval that has been tampered with (such as malicious modification of a certain clause in a contract document) without having to recalculate the hash of all the data. In this way, not only the large-scale data auditing efficiency is significantly improved, but also the data integrity protection is extended from static evidence storage to dynamic update scenarios. In addition, the combination of the chunked hash fingerprint and blockchain storage provides a technical basis for the distributed storage of data assets.
[0032] Specifically, in S4, the identifier of the data asset, the key meta-information of the data asset, and the hash fingerprint of the data asset are written into the blockchain network as a transaction record. It should be understood that traditional solutions rely on a single institution to maintain data deposit records, which poses a risk of artificial tampering or system failures leading to the invalidation of the deposit. For example, in a cross-border trade scenario, a logistics platform may, driven by interests, tamper with the timestamp of the cargo temperature record or sensor data, making it impossible to provide credible original evidence when disputes occur. To address this, the system, through the multi-node consensus mechanism of the blockchain network, encapsulates the hash identifier of the data asset (such as the full-scale hash value generated by SHA-256), the key meta-information (including structured fields such as data creation time, data source, data owner, etc.), and the chunk hash fingerprint (a sequence of hash values generated from data chunks) into a transaction data packet in a specific format, and calls the blockchain smart contract interface to write it into the latest block. Specifically, the system will use a lightweight data serialization protocol (such as Protocol Buffers) to encode and compress these three types of information, initiate a transaction request through the preset blockchain node API, and after verification by the consensus nodes, package the transaction record together with additional information such as timestamps and digital signatures into a block and broadcast it to all network nodes for distributed storage. That is, by building a decentralized data deposit infrastructure, the initial state and key features of the data asset are permanently anchored using the immutable characteristics of the blockchain, forming an electronic certificate with legal effect. Here, the bound storage of the hash identifier and the meta-information ensures that the uniqueness of the data identity can be verified, preventing the cloning or misappropriation of the data asset during the circulation process; the chained storage structure of the chunk hash fingerprint makes it inevitable that local data tampering will trigger a change in the corresponding chunk hash value; in addition, the timestamp service of the blockchain provides deposit effectiveness at the level of judicial evidence collection for the data asset.
[0033] Specifically, S5, in response to a request to verify the integrity of the data asset, recalculates the check hash value and check hash fingerprint of the data asset's data content, compares the check hash value with the identifier of the data asset stored on the blockchain network, and compares the check hash fingerprint with the hash fingerprint stored on the blockchain network to obtain an integrity verification result. Considering that when data assets are transmitted across borders, involved in multi-party collaboration, or stored for a long time (for example, clinical trial datasets shared between multinational pharmaceutical companies), the recipient or regulatory agency needs to have the ability to verify data integrity in real time. However, the verification services provided by traditional centralized platforms have the risk of single points of failure and cannot prove the neutrality of the verification process. To this end, the system implements a two-way verification of on-chain and off-chain data through a triggered verification mechanism. When a data user or auditor initiates a verification request, the system first retrieves the original content of the target data asset from distributed storage nodes and recalculates the overall checksum hash value and block checksum hash fingerprint according to the same preprocessing rules as the initial storage phase (including data cleaning format, block size setting, and hash algorithm selection). The system then queries the original hash identifier and fingerprint chain written to the chain during the data asset registration through the blockchain browser interface. A dual-threaded comparison engine performs both global hash value exact matching (whether the overall hash value is consistent) and block hash fingerprint sequence consistency verification (whether the hash values of each data block correspond exactly in sequence). If a block hash mismatch is detected (e.g., if the temperature data of a batch in a logistics record has been tampered with), the system locates the anomalous block index and generates a tampering location report. In other words, by building a decentralized, self-verifying ecosystem, any participant can independently complete data integrity audits without relying on third-party institutions. Furthermore, through algorithmic replication and cross-validation of on-chain records, the verification process is repeatable and non-repudiation-resistant. Here, the verification process based on cryptographic primitives achieves mathematically proven reliability, eliminating verification errors caused by human intervention. Furthermore, the chained verification structure of the block hash fingerprint extends data integrity protection from overall verification to fine-grained detection, significantly improving the verification efficiency of large-scale data sets. Furthermore, the tamper-proof nature of blockchain storage and the dynamic verification of real-time computation form a closed loop, allowing any state changes of data assets throughout their lifecycle to be accurately captured. This combination of technologies effectively resolves the contradiction between decentralized verification authority and trustworthy verification results in the circulation of data elements, providing a fundamental trust infrastructure for building an open data ecosystem.
[0034] However, it should be understood that in actual scenarios, solely relying on traditional rule matching is difficult to cope with complex and ever-changing data usage scenarios and anomaly detection requirements, and simply relying on coarse-grained logs cannot effectively identify subtle or hidden data abuse behaviors. In the technical solution of this application, by extracting the latest operation records (i.e., asset usage behavior logs) and corresponding data usage policies from smart contracts in real time, converting the two into comparable, high-dimensional and expressive semantic vectors, and then using feature search engines such as self-attention mechanisms to dynamically and meticulously compare each actual operation with the established policies. This approach not only improves the automation level in the monitoring and auditing processes but also can respond promptly to new types of violation patterns in complex or cross-domain scenarios. By combining blockchain technology with smart contracts to automatically generate and store these logs, the information transparency and trust can be significantly enhanced, effectively preventing human tampering or forgery.
[0035] Specifically, first, extract the asset usage behavior logs from the smart contracts of data assets. It should be understood that the operation records manually maintained by platform administrators in traditional solutions are easily tampered with or deleted by internal personnel, while the log generation mechanism based on smart contracts ensures that each data operation is permanently solidified from the moment it occurs through the consensus verification and distributed storage characteristics of the blockchain, forming a chain of behavioral evidence with forensic evidentiary effect. Among them, the asset usage behavior log refers to the time-sequenced digital certificate of the full-life cycle operation events of data assets recorded in real time through the automated execution characteristics of blockchain smart contracts, and its content covers dimensions such as the identity of the data access subject, operation type (such as data download, modification authorization, secondary distribution), operation timestamp, data operation magnitude, and associated environmental parameters (such as access IP geofence, device fingerprint). By extracting these detailed behavior logs, the actual data operations can be deeply compared with the preset data usage policies at the semantic level, not only capable of judging whether a specific operation conforms to the authorization but also able to analyze potential abnormal patterns in continuous operation sequences, realizing the accurate identification of complex violation scenarios (such as permission overstepping, multiple re-authorizations, etc.). In this way, the system's control ability over various risks in the full life cycle of data assets is greatly enhanced. Whether in normal operation or emergency response scenarios, real-time monitoring, automatic alerting, and efficient traceability can be achieved based on the tamper-proof and highly credible behavior logs, laying a solid foundation for protecting the rights and interests of data providers and users, preventing malicious attacks, and internal misconduct.
[0036] Next, extract the preset data usage policies from the smart contract of the data asset. Among them, the preset data usage policies refer to a series of rules regarding how the data is accessed, processed, shared, and authorized, etc., which are formulated and solidified in the smart contract in advance by the data owner or administrator according to laws and regulations, industry norms, and their own needs when the data asset is generated or uploaded to the blockchain. These policies may include access permission restrictions (such as only specific users / roles can access), usage restrictions (such as only for scientific research / non-commercial resale), time range restrictions (such as available within the validity period), operation frequency restrictions, and special protection requirements for sensitive fields, etc. By solidifying these complex and diverse data usage policies in an immutable and automatically executable smart contract and being able to extract them automatically in real time, it can ensure that each behavior verification is based on the latest and authoritative policies, effectively preventing human omissions or subjective and arbitrary interpretations; in addition, this mechanism greatly improves the system's adaptability to new types of violation patterns (such as combined authorization, multi-level sub-authorization, etc.) in complex and changing scenarios, achieving highly flexible and fine-grained compliance supervision.
[0037] Subsequently, perform semantic embedding encoding on the asset usage behavior logs and the preset data usage policies to obtain a sequence of asset usage behavior semantic fine-grained description encoding vectors and preset data usage policy semantic encoding vectors. It should be understood that the asset usage behavior logs record the specific operation details of users on the data asset, while the preset data usage policies contain diverse and complex constraint conditions and business logics. Performing semantic-level embedding encoding on the two can transform text-based and structured data into high-dimensional vector expressions, thereby capturing their inherent semantic associations and context information, and making up for the deficiency that traditional symbol matching means cannot effectively identify fuzzy and obscure violation operations. In this way, the system can understand the operation intention and policy requirements more comprehensively and meticulously, and accurately identify the compliance degree or potential deviation between the behavior and the policy. In this way, a large amount of complex behaviors and variable policies are transformed into expressive and machine-parsable semantic vectors, greatly enriching the feature space and recognition ability of data security auditing. In addition, based on the fine-grained query and aggregation of the encoding vectors, the detection of abnormal behaviors not only covers the surface-level coarse-grained violations, but also can penetrate into the latent semantic deviations and hidden risks, reducing the false negative and false positive rates, and providing more reliable support for security operations. Finally, this encoding method promotes the transformation of data asset security management from static rules to dynamic semantic understanding, laying a solid technical foundation for realizing more intelligent, efficient, and trustworthy full-life-cycle management of data assets.
[0038] In a specific example of the present application, the asset usage behavior log and the preset data usage policy can be semantically embedded and encoded through the following steps to obtain a sequence of asset usage behavior semantic fine-grained description encoding vectors and a preset data usage policy semantic encoding vector: First, use the asset usage behavior embedding matrix to perform embedding encoding on each behavior log in the asset usage behavior log to obtain a sequence of asset usage behavior log embedding encoding vectors; use the preset data usage policy embedding matrix to perform embedding encoding on each policy in the preset data usage policy to obtain a preset data usage policy embedding encoding vector; then, perform a context semantic encoder based on a bidirectional LSTM model on the sequence of asset usage behavior log embedding encoding vectors and the preset data usage policy embedding encoding vector to obtain a sequence of asset usage behavior semantic fine-grained description encoding vectors and a preset data usage policy semantic encoding vector.
[0039] Furthermore, the sequence of the encoded vectors of the fine-grained description of the asset usage behavior semantics and the encoded vector of the preset data usage policy semantics are input into the intelligent contract semantic fine-grained query and audit module to obtain the fine-grained verification aggregation encoded vector of the asset usage behavior - preset data usage policy semantics. It should be understood that in actual business, data usage behaviors may involve multi-agent and multi-stage interaction operations (such as cross-departmental data sharing, periodic authorization updates, or condition-triggered access behaviors), while preset policies often contain nested compliance constraints (such as time limits, permission granularity, or usage scopes). Traditional methods rely on the static matching of rule engines and are difficult to capture the implicit semantic associations between behaviors and policies. For example, it is ambiguous whether "bulk exporting data to an external system" in the behavior log complies with the description of "only for internal analysis use" in the policy. Therefore, in order to construct a dynamic and adaptive semantic verification mechanism that enables the audit process to penetrate the surface feature comparison and deeply understand the semantic consistency between behaviors and policies, in the technical solution of this application, the sequence of the encoded vectors of the fine-grained description of the asset usage behavior semantics and the encoded vector of the preset data usage policy semantics are input into the intelligent contract semantic fine-grained query and audit module to obtain the fine-grained verification aggregation encoded vector of the asset usage behavior - preset data usage policy semantics. In this process, first, through feature enhancement based on deconvolutional encoding, the fine-grained description encoded vector of the behavior log and the policy encoded vector are aligned in the feature scale to ensure their comparability in the semantic space; then, the single semantic query unit quantifies the deep semantic associations between the behavior features and the policy features (such as the implicit conflict between the "export" behavior and the "prohibiting external transmission" policy) through dynamic projection and covariance matrix calculation. This process not only focuses on the isolated matching of a single behavior and policy, but also analyzes the context semantic distribution of the overall behavior sequence through self-attention aggregation to identify the pattern deviation of abnormal behaviors (such as the deviation trend between high-frequency access and low-frequency policies), so as to realize the semantic risk perception from local to global. Through the fine-grained verification aggregation encoded vector of the asset usage behavior - preset data usage policy semantics, the model can dynamically capture the complex non-linear relationships between behaviors and policies, such as identifying operations that are not clearly defined but implicitly prohibited in the policy (such as inferring data abuse risks through combined behaviors). In the cross-industry data circulation scenario, this mechanism can automatically adapt to the policy semantics under different regulatory frameworks (such as the compliance differences between financial data and medical data) to avoid misjudgments caused by differences in policy expressions; in the real-time monitoring scenario, it dynamically focuses on high-risk behavior nodes (such as data access during non-working hours) through self-attention weights to achieve early warning of abnormal behaviors. In this way, the full-life cycle audit of data assets is shifted from passive rule matching to active semantic insight, significantly improving the coverage breadth and response efficiency of security management.
[0040] More specifically, first, the preset data usage policy semantic coding vector is subjected to feature enhancement based on deconvolution coding to obtain an enhanced preset data usage policy semantic coding vector. It should be understood that preset policies (such as "internal access only" or "prohibited cross-domain transmission") often exist in the form of abstract rules or natural language clauses, and their semantic coding may be limited by the insufficient granularity of the original feature extraction, making it difficult to cover the multi-level constraints (such as time conditions, permission nesting, or dynamic authorization logic) implicit in the policy. When traditional methods directly match the policy coding vector with the behavior log, it is easy to ignore the semantic depth of the policy due to the shallowness of the feature expression. For example, it is impossible to distinguish the essential differences between temporary authorization and long-term authorization in "access permission". Therefore, in order to construct an enhanced representation system for policy semantics, which can not only retain the normative constraints of the original policy but also achieve dynamic alignment with the fine-grained coding of the behavior log in a unified semantic space, in the technical solution of this application, the preset data usage policy semantic coding vector is subjected to feature enhancement based on deconvolution coding to obtain an enhanced preset data usage policy semantic coding vector. Among them, the enhanced preset data usage policy semantic coding vector has the same feature scale as the semantic fine-grained description coding vector of each asset usage behavior.
[0041] Here, through reverse feature mapping reconstruction, deconvolution coding can recover high-dimensional feature details from the compressed semantic coding, solve the problem of information loss caused by dimensionality reduction operations for policy semantics, and thus lay a foundation for subsequent cross-modal semantic matching. Specifically, the deconvolution operation adaptively captures the local semantic patterns (such as the logical association between policy clauses) implicit in the policy coding vector through a learnable upsampling kernel and expands to the feature scale matching the behavior coding. For example, for the composite condition of "data export requires secondary approval" in the policy, after deconvolution enhancement, its coding vector can be decomposed into sub-features such as "trigger condition for export action" and "approval level association", forming a multi-dimensional comparable relationship with events such as "user A initiates an export request" and "approval log missing" in the behavior log. This feature reconstruction not only improves the expressive power of policy semantics but also eliminates the dimensional deviation during cross-modal matching through scale consistency, avoiding the risk of misjudgment caused by misalignment of the feature space. The enhanced preset data usage policy semantic coding vector can penetrate the surface rule description and capture the dynamic semantic boundary of the policy clause. In this way, the intelligent contract audit module can extract richer compliance clues from the enhanced semantics of the policy, providing a deep semantic basis for abnormal behavior detection.
[0042] In a specific example of this application, the preset data usage policy semantic coding vector is subjected to feature enhancement based on deconvolution coding with the following deconvolution formula to obtain an enhanced preset data usage policy semantic coding vector; where the deconvolution formula is:
[0043]
[0044] Among them, is the semantic encoding vector of the preset data usage policy, is the deconvolution encoding, is the deconvolution weight matrix, is the first norm of the vector, is the enhanced preset data usage policy semantic encoding vector.
[0045] Next, each asset usage behavior semantic fine-grained description encoding vector in the sequence of the enhanced preset data usage policy semantic encoding vector and the asset usage behavior semantic fine-grained description encoding vector is separately subjected to monomer semantic query encoding to obtain a set of preset data usage policy monomer semantic query score encoding vectors. It should be understood that in actual business, data usage behaviors (such as "user A batches and exports sensitive data during non-working hours") often involve multi-dimensional operation details, while preset policies (such as "prohibit data export during unauthorized periods") may imply multi-level constraint conditions (such as time range, operation type, user permissions). Traditional rule engines rely on keyword matching or simple logical judgments, and it is difficult to capture the dynamic semantic association between "prohibit export" in the policy clause and "export operation" in the behavior log (for example, whether the export is accompanied by a compliance approval process), and it is even more impossible to quantify the matching degree between the fuzzy condition (such as "unauthorized period") in the policy and the specific behavior timestamp. Therefore, in order to construct a fine-grained semantic association network and enable the model to mine implicit compliance clues from the encoding vectors of policies and behaviors, in the technical solution of this application, each asset usage behavior semantic fine-grained description encoding vector in the sequence of the enhanced preset data usage policy semantic encoding vector and the asset usage behavior semantic fine-grained description encoding vector is separately subjected to monomer semantic query encoding to obtain a set of preset data usage policy monomer semantic query score encoding vectors.
[0046] Through the monomer semantic query unit, the enhanced policy encoding vector (such as "prohibit external transmission") and each behavior encoding vector (such as "user B uploads data to an external cloud disk") perform dynamic interaction in the deep neural network to generate multi-dimensional semantic matching scores. These scores are not simple yes / no judgments, but rather quantify the degree of fit between policy constraints and behavior characteristics at different semantic levels (for example, the association strength between "transmission target address" and "external cloud disk", and the deviation degree of "operation time" from the policy-restricted period). This encoding process transforms the abstract rules of policy clauses into computable multi-dimensional semantic vectors through non-linear mapping in the feature space, enabling the audit module to penetrate the surface behavior description and identify potential conflicts (such as the "secondary approval" requirement in the policy and the absence of approval records in the behavior log). By generating a set of preset data usage policy monomer semantic query score encoding vectors, the model can analyze the association patterns between behavior sequences and policies item by item. This fine-grained matching not only covers explicit rules (such as clearly prohibited operation types), but also captures abnormal patterns that are not clearly defined in the policy but imply risks (such as statistical deviations between high-frequency access behaviors and low-frequency policies), enabling the intelligent contract audit module to accurately locate high-risk nodes from a large number of behavior logs and provide dynamic and interpretable semantic support for the full-process security management of data assets.
[0047] In a specific example of the present application, the following semantic query formula is used to perform monomer semantic query encoding on each asset usage behavior semantic fine-grained description encoding vector in the sequence of the enhanced preset data usage policy semantic encoding vector and the asset usage behavior semantic fine-grained description encoding vector respectively to obtain a set of preset data usage policy monomer semantic query score encoding vectors; wherein, the semantic query formula is:
[0048]
[0049] Wherein, is the sequence of asset usage behavior semantic fine-grained description encoding vectors, are respectively the 1st, 2nd, th, and th asset usage behavior semantic fine-grained description encoding vectors in the sequence of asset usage behavior semantic fine-grained description encoding vectors, and are respectively the trainable weight matrix and the trainable bias vector, is the vector concatenation operation, is function, is the preset data usage policy monomer semantic query score encoding vector of the
[0050] Subsequently, determine the monomer semantic matching degree of each preset data usage policy monomer semantic query score encoding vector in the set of preset data usage policy monomer semantic query score encoding vectors to obtain a set of preset data usage policy monomer semantic matching degrees. That is, in the embodiments of the present application, first, perform mapping specification fixed optimization on each preset data usage policy monomer semantic query score encoding vector in the set of preset data usage policy monomer semantic query score encoding vectors to obtain a set of optimized preset data usage policy monomer semantic query score encoding vectors. It should be understood that when the smart contract auditing module initially associates the behavior log with the policy through the monomer semantic query unit, due to the inherent misalignment between the feature space and the semantic query encoding space (for example, the difference in semantic coverage of the same policy in different behavior sequences, the mismatch between the policy constraint conditions and the implicit dimensions of the behavior features, etc.), the query score encoding vector generated by directly splicing features is difficult to accurately represent the deep semantic association between the policy and the behavior. This misalignment may lead to policy matching deviations in the subsequent aggregation stage. For example, a legal but semantically marginalized operation may be misjudged as a violation, or a hidden attack that breaks through the policy restrictions through multi-step combinations may be ignored. Therefore, to dynamically correct the projection relationship between the feature space and the semantic query encoding space, in a preferred example of the present application, perform mapping specification fixed optimization on each preset data usage policy monomer semantic query score encoding vector in the set of preset data usage policy monomer semantic query score encoding vectors to obtain a set of optimized preset data usage policy monomer semantic query score encoding vectors.
[0051] That is, by introducing the interaction potential vector and the covariance matrix, the cascaded features (the splicing of the policy and behavior encodings) are dynamically projected into the semantic query space, and the mapping process is constrained by the covariance path under the condition of gauge symmetry. For example, the "data encryption level requirement" in the policy and the "actual encryption algorithm" in the behavior may not be directly related due to different feature scales in the original encoding, while the optimization process dynamically adjusts the mapping parameters to enable them to form a comparable relationship in the unified semantic space. This optimization is not a simple linear transformation, but through the dynamic reconstruction and inherent alignment of the feature space, ensuring the deep integration of the abstract constraints of the policy clauses and the concrete features of the behavior details at the semantic level. The set of optimized preset data usage policy monomer semantic query score encoding vectors not only retains the fine-grained features of the monomer semantic query (for example, whether a certain data download behavior touches the policy boundary in the dual dimensions of the time window and user permissions), but also eliminates the cross-dimensional semantic interference through the inherent alignment mechanism (such as misassociating the data format compliance to the usage frequency limit). This optimization mechanism provides a high-fidelity semantic basis for the subsequent dynamic allocation of self-attention weights, enabling the alarm trigger decision to penetrate the complex behavior appearance and directly point to the essential logic of policy violations, ultimately realizing the leap from extensive rule matching to intelligent semantic reasoning in security control.
[0052] Furthermore, based on the distribution characteristics of the set of optimized preset data usage policy monomer semantic query score encoding vectors, the monomer semantic matching degree of each optimized preset data usage policy monomer semantic query score encoding vector is calculated to obtain a set of preset data usage policy monomer semantic matching degrees. It should be understood that when the system obtains more accurate encoding vectors through mapping specifications, it is easy to fall into the local optimal trap when evaluating the matching relationship between a single vector and the policy in isolation. For example, a high-frequency but compliant operation may be misjudged as abnormal, or the systematic policy deviation caused by the accumulation of multiple low-risk behaviors may be ignored. By introducing a dynamic perception mechanism of set distribution characteristics, the system can break through the vision limitation of single-point analysis and identify the implicit association patterns between behaviors and policies at the global level, thereby avoiding the misjudgment risk caused by the amplification of local features or noise interference. That is, by mining the distribution laws of the encoding vector set (such as density aggregation, outlier characteristics, gradient change trends), an attempt is made to construct a dynamic evaluation system for the association strength between behaviors and policies. This adaptive adjustment mechanism based on population distribution enables the system to automatically identify weak links in policy execution according to the evolution of behavior patterns in the actual business scenario. For example, when a certain type of data download behavior breaks through the access frequency specified by the policy in the time dimension, even if a single operation is compliant, its matching degree will be marked as a potential risk due to abnormal distribution. By calculating the semantic matching degree by placing each optimized preset data usage policy monomer semantic query score encoding vector in the overall context of the set distribution, the system realizes the upgrade of the audit mode from static rule matching to dynamic context awareness. This mechanism can not only capture obvious violations (such as unauthorized IP access), but also detect hidden risks (such as the accumulation of unconventional behavior patterns in compliant operations) through distribution anomaly detection, enabling the alarm system to have the ability of predictive risk prevention, rather than relying solely on post-event rule comparison. Finally, this semantic matching degree calculation based on global distribution characteristics provides intelligent audit support with both sensitivity and specificity for the full life cycle security management of data assets.
[0053] In this example, the monomer semantic matching degree of each preset data usage policy monomer semantic query score encoding vector in the set of preset data usage policy monomer semantic query score encoding vectors is determined by the following semantic matching formula to obtain a set of preset data usage policy monomer semantic matching degrees; where the semantic matching formula is:
[0054]
[0055] Where is the preset data usage policy query potential vector, is the projection weight matrix, is the preset data usage policy query interaction encoding vector, is the coupling constant, which is calculated in the same way as when deconvolution is enhanced to maintain symmetry. Query the covariance matrix for the preset data usage policy. Is the score encoding vector for querying the monomer semantics of the preset data usage policy after calibration. Is The number of Is the th optimized score encoding vector for querying the monomer semantics of the preset data usage policy. Is The natural exponential function with as the base. Is the function. Is the monomer semantic matching degree of the preset data usage policy.
[0056]
[0057] Furthermore, the set of monomer semantic matching degrees of the preset data usage policy is input into the relational gating processing module to obtain the set of monomer query semantic self-attention weights of the preset data usage policy. It should be understood that when the system directly generates self-attention weights through the optimized set of semantic matching degrees, due to the complex semantic relationships such as the coupling relationship between different policy clauses (such as the coupling relationship between data usage geographical restrictions and encryption levels), potential violation patterns across behavioral sequences (such as policy breakthroughs triggered by the superposition of multiple low-frequency unconventional accesses), etc., which are difficult to be captured by linear weight assignment, simple weighted aggregation may lead to the dilution of key violation signals or the over-amplification of marginal compliance behaviors. Therefore, in the technical solution of this application, the set of monomer semantic matching degrees of the preset data usage policy is input into the relational gating processing module to obtain the set of monomer query semantic self-attention weights of the preset data usage policy.Among them, the gating processing module establishes a gauge-symmetric mapping path between the feature space and the semantic encoding space through operations on the coupling constant and the covariant matrix, enabling the deep semantic association between the policy constraint and the behavior feature to be made explicit. For example, when it is detected that a certain type of data access behavior shows a systematic deviation in the matching degrees of multiple policy clauses, the gating mechanism will automatically increase the association weights of these matching degree signals, so that the subsequent aggregation process can focus on complex violation features instead of evaluating the compliance of a single clause in isolation. This dynamic regulation ability enables the system to break through the rigid threshold limit of the traditional rule engine and achieve an intelligent leap from discrete rule matching to continuous semantic association. The preset data usage policy monomer after the relational gating process queries the set of semantic self-attention weights, effectively realizing the fine control of semantic relationships in the policy audit process. Through the dynamic eigenstate projection of the interaction potential vector and the gauge fixation of the covariant path, the system can capture the implicit coupling pattern between the policy constraint and the behavior feature in the feature space. This mechanism not only improves the detection sensitivity to complex violation patterns but also enhances the credibility of the audit results through the interpretability of the weight distribution, ultimately forming a data asset security protection system with both intelligence and reliability.
[0058] In a specific example of this application, the set of semantic matching degrees of the preset data usage policy monomer is input into the relational gating processing module according to the following gating formula to obtain the set of semantic self-attention weights for querying the preset data usage policy monomer; where the gating formula is:
[0059]
[0060] Among them, is a preset threshold, is the semantic self-attention weight for querying the preset data usage policy monomer.
[0061] Subsequently, based on the preset data usage policy monomers, a set of semantic self-attention weights is queried to aggregate a set of preset data usage policy monomer semantic query score encoding vectors to obtain an asset usage behavior - preset data usage policy semantic fine-grained verification aggregation encoding vector. It should be understood that when the intelligent contract auditing system completes the dynamic calculation of policy matching degree and weight adjustment through the previous steps, if a fixed rule is used for information aggregation (such as average weighting or simple threshold determination), it will be difficult to adapt to the non-linear coupling relationship between multi-dimensional policy constraints and behavior characteristics. For example, in the cross-subject data sharing scenario, the constraint intensity of different policy clauses on data usage behavior may change dynamically with the business scenario, and a single behavior may simultaneously involve the composite compliance requirements of multiple policies. This dynamic association characteristic requires the aggregation mechanism to have the ability to autonomously focus on key semantic features. Therefore, in the technical solution of this application, a set of preset data usage policy monomer semantic query score encoding vectors is aggregated based on a set of semantic self-attention weights queried from the preset data usage policy monomers to obtain an asset usage behavior - preset data usage policy semantic fine-grained verification aggregation encoding vector.
[0062] Here, through the dynamic allocation mechanism of self-attention weights, the system can break through the mechanical limitations of traditional aggregation methods and achieve the adaptive fusion of policy semantic associations and behavior risk characteristics. This process performs associative weighting on each semantic query score encoding vector with its corresponding dynamic weight, making the aggregation process no longer a simple numerical superposition, but transformed into a deep feature reconstruction of the policy-behavior semantic space. This reconstruction is essentially to construct a mapping relationship network between policy constraints and behavior trajectories in the high-dimensional semantic space. By dynamically adjusting the weight allocation, key violation signals (such as the associative anomalies of high-frequency unconventional access) are highlighted while non-key noises (such as accidental deviations in normal operations) are suppressed, so as to extract core audit features with decision-making value in complex data circulation scenarios. This aggregation mechanism endows the audit module with the ability to penetrate and identify complex violation behaviors, making the alarm trigger logic no longer rely on strong abnormal signals in a single dimension, but based on the collaborative abnormal analysis of multi-source semantic features, and finally forming an intelligent security protection system with both sensitivity and accuracy.
[0063] In a specific example of this application, the following aggregation formula is used to aggregate a set of preset data usage policy monomer semantic query score encoding vectors to obtain an asset usage behavior - preset data usage policy semantic fine-grained verification aggregation encoding vector; where the aggregation formula is:
[0064]
[0065] Among them, is the asset usage behavior - preset data usage policy semantic fine-grained verification aggregation encoding vector.
[0066] Finally, based on the asset usage behavior - preset data usage policy semantic fine - grained verification aggregation coding vector, it is determined whether to trigger an alarm prompt. That is, in the technical solution of this application, the asset usage behavior - preset data usage policy semantic fine - grained verification aggregation coding vector is passed through an alarm promptor based on a classifier to obtain an alarm prompt result, and the alarm prompt result is used to indicate whether to trigger an alarm prompt. It should be understood that although the asset usage behavior - preset data usage policy semantic fine - grained verification aggregation coding vector realizes fine - grained correlation analysis, it is still necessary to convert the abstract semantic features into specific compliance judgments (such as the threshold or pattern for triggering an alarm). Traditional methods rely on manual rule setting or static threshold monitoring, and it is difficult to adapt to policy dynamic adjustment or behavior pattern evolution (such as the emergence of new data abuse means). For example, when the policy is updated to "limit high - frequency access", traditional static rules may not be able to adaptively identify the reasonable access frequency in different business scenarios. Therefore, to build an intelligent risk decision - making engine so that the alarm prompt can not only capture obvious violation behaviors (such as unauthorized data export), but also identify implicit abnormal patterns (such as low - frequency but high - risk sensitive data access), in the technical solution of this application, the asset usage behavior - preset data usage policy semantic fine - grained verification aggregation coding vector is passed through an alarm promptor based on a classifier to obtain an alarm prompt result, and the alarm prompt result is used to indicate whether to trigger an alarm prompt. That is, by the classifier learning the implicit rules of historical compliance data and abnormal patterns, a mapping relationship from semantic features to alarm decisions is established to solve the problem of adaptive risk determination in dynamic scenarios. In this process, the classifier can dynamically identify the risk signals hidden in the aggregation coding vector by training and learning the semantic feature pattern differences between historical compliance behaviors and violation behaviors. For example, when the aggregation coding vector shows a specific distribution in implicit dimensions such as "abnormal data usage frequency", "access subject permission overstep", "policy clause coupling deviation", etc., the classifier can judge whether it belongs to a new attack mode or potential violation behavior through a non - linear decision boundary. By classifying and analyzing the verification aggregation coding vector through the classifier, the system can not only effectively avoid false negatives and false positives caused by rough manual rules, but also dynamically adapt to the diversification and evolution of data asset usage scenarios, support the automatic update and optimization of real - time alarm policies. In addition, this method promotes the transformation of the alarm mechanism from passive triggering to active intelligent prediction, greatly improving the overall security operation efficiency and response speed.
[0067] In summary, the security management method for data asset transactions according to the embodiments of the present application is elucidated. By deeply integrating blockchain technology with smart contracts, it provides a new paradigm for distributed evidence storage and automated management of data assets. Specifically, through semantic-level embedded encoding of the asset usage behavior logs recorded in the smart contract and preset data usage policies, and using a fine-grained semantic verification mechanism, automatic comparison of the consistency between actual behavior and policies is achieved. Once a deviation from the preset policy or an abnormal access is detected, an alarm prompt can be triggered in real time. In this way, not only the system's response ability to illegal operations or potential risk events is improved, but also every data call can be kept under control and traceable, effectively preventing unauthorized access and malicious operations, and creating a more secure, transparent and trustworthy operating environment for the entire data element market.
[0068] Furthermore, a security management system for data asset transactions is also provided.
[0069] Figure 3 FIG. is a block diagram of a security management system for data asset transactions according to the embodiments of the present application. As Figure 3 shown, the security management system 300 for data asset transactions according to the embodiments of the present application includes: a data asset acquisition module 310 for acquiring data assets uploaded by data providers; a hash calculation module 320 for performing a hash operation on the data content of the data assets to generate a unique hash value as the identifier of the data assets; a hash fingerprint generation module 330 for calculating the hash values of each data block after data chunking of the data content of the data assets to obtain a hash fingerprint composed of multiple hash values; a transaction record writing module 340 for writing the identifier of the data assets, the key meta-information of the data assets, and the hash fingerprint of the data assets as a transaction record into the blockchain network; a verification result generation module 350 for, in response to a request to verify the integrity of the data assets, recalculating the verification hash value and verification hash fingerprint of the data content of the data assets, comparing the verification hash value with the identifier of the data assets stored in the blockchain network, and comparing the verification hash fingerprint with the hash fingerprint stored in the blockchain network to obtain an integrity verification result.
[0070] As described above, the security management system 300 for data asset trading according to the embodiments of the present application can be implemented in various wireless terminals, such as a server with a data asset security management algorithm. In a possible implementation manner, the security management system 300 for data asset trading according to the embodiments of the present application can be integrated into the wireless terminal as a software module and / or a hardware module. For example, the security management system 300 for data asset trading can be a software module in the operating system of the wireless terminal, or can be an application program developed for the wireless terminal; of course, the security management system 300 for data asset trading can also be one of the many hardware modules of the wireless terminal.
[0071] Alternatively, in another example, the security management system 300 for data asset trading and the wireless terminal can also be separate devices, and the security management system 300 for data asset trading can be connected to the wireless terminal through a wired and / or wireless network, and transmit interaction information in accordance with a predefined data format.
[0072] The embodiments of the present disclosure have been described above. The above description is exemplary and not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The selection of the terms used herein is intended to best explain the principles of the embodiments, the practical application, or the improvement of the technology in the market, or to enable other ordinary skill in the art to understand the embodiments disclosed herein.
Claims
1. A security management method for data asset trading, characterized in that, Including: Obtaining a data asset uploaded by a data provider; Performing a hashing operation on the data content of the data asset to generate a unique hash value as the identifier of the data asset; Performing data chunking on the data content of the data asset and then calculating the hash value of each data chunk to obtain a hash fingerprint composed of multiple hash values; Writing the identifier of the data asset, the key meta-information of the data asset, and the hash fingerprint of the data asset as a transaction record into the blockchain network; In response to a request to verify the integrity of the data asset, recalculating the verification hash value and the verification hash fingerprint of the data content of the data asset, comparing the verification hash value with the identifier of the data asset stored in the blockchain network, and comparing the verification hash fingerprint with the hash fingerprint stored in the blockchain network to obtain an integrity verification result; The method further includes: Extracting an asset usage behavior log from the smart contract of the data asset; Extracting a preset data usage policy from the smart contract of the data asset; Performing semantic embedding encoding on the asset usage behavior log and the preset data usage policy to obtain a sequence of asset usage behavior semantic fine-grained description encoding vectors and a preset data usage policy semantic encoding vector; Inputting the sequence of asset usage behavior semantic fine-grained description encoding vectors and the preset data usage policy semantic encoding vector into a smart contract semantic fine-grained query and audit module to obtain an asset usage behavior - preset data usage policy semantic fine-grained verification aggregation encoding vector; Based on the asset usage behavior - preset data usage policy semantic fine-grained verification aggregation encoding vector, determining whether to trigger an alarm prompt.
2. The security management method for data asset trading according to claim 1, wherein, The key meta-information of the data asset includes the data creation time, data source, data format, data size, and data owner.
3. The security management method for data asset trading according to claim 2, characterized in that, Inputting the sequence of asset usage behavior semantic fine-grained description encoding vectors and the preset data usage policy semantic encoding vector into a smart contract semantic fine-grained query and audit module to obtain an asset usage behavior - preset data usage policy semantic fine-grained verification aggregation encoding vector, including: Performing single-entity semantic query encoding on the preset data usage policy semantic encoding vector and each asset usage behavior semantic fine-grained description encoding vector in the sequence of asset usage behavior semantic fine-grained description encoding vectors to obtain a set of preset data usage policy single-entity semantic query score encoding vectors; Respectively calculating the single-entity semantic weight of each preset data usage policy single-entity semantic query score encoding vector in the set of preset data usage policy single-entity semantic query score encoding vectors to obtain a set of preset data usage policy single-query semantic self-attention weights; Aggregating the set of preset data usage policy single-entity semantic query score encoding vectors based on the set of preset data usage policy single-query semantic self-attention weights to obtain an asset usage behavior - preset data usage policy semantic fine-grained verification aggregation encoding vector.
4. The security management method for data asset trading according to claim 3, characterized in that, Performing single-entity semantic query encoding on the preset data usage policy semantic encoding vector and each asset usage behavior semantic fine-grained description encoding vector in the sequence of asset usage behavior semantic fine-grained description encoding vectors to obtain a set of preset data usage policy single-entity semantic query score encoding vectors, including: Perform feature enhancement based on deconvolution coding on the preset data using the policy semantic coding vector to obtain an enhanced preset data usage policy semantic coding vector; Perform monomer semantic query coding on each asset usage behavior semantic fine-grained description coding vector in the sequence of the enhanced preset data usage policy semantic coding vector and the asset usage behavior semantic fine-grained description coding vector respectively to obtain a set of preset data usage policy monomer semantic query score coding vectors.
5. The security management method for data asset trading according to claim 4, characterized in that, The enhanced preset data usage policy semantic coding vector has the same feature scale as each asset usage behavior semantic fine-grained description coding vector.
6. The security management method for data asset trading according to claim 5, wherein Calculate the monomer semantic weights of each preset data usage policy monomer semantic query score coding vector in the set of preset data usage policy monomer semantic query score coding vectors respectively to obtain a set of preset data usage policy monomer query semantic self-attention weights, including: Based on the self-distribution characteristics of the feature set of the set of preset data usage policy monomer semantic query score coding vectors, determine the monomer semantic matching degree of each preset data usage policy monomer semantic query score coding vector in the set of preset data usage policy monomer semantic query score coding vectors to obtain a set of preset data usage policy monomer semantic matching degrees; Input the set of preset data usage policy monomer semantic matching degrees into the relational gating processing module to obtain a set of preset data usage policy monomer query semantic self-attention weights.
7. The security management method for data asset trading according to claim 6, characterized in that Based on the self-distribution characteristics of the feature set of the set of preset data usage policy monomer semantic query score coding vectors, determine the monomer semantic matching degree of each preset data usage policy monomer semantic query score coding vector in the set of preset data usage policy monomer semantic query score coding vectors to obtain a set of preset data usage policy monomer semantic matching degrees, including: Perform mapping specification fixed optimization on each preset data usage policy monomer semantic query score coding vector in the set of preset data usage policy monomer semantic query score coding vectors to obtain a set of optimized preset data usage policy monomer semantic query score coding vectors; Calculate the monomer semantic matching degree of each optimized preset data usage policy monomer semantic query score coding vector based on the distribution characteristics of the set of optimized preset data usage policy monomer semantic query score coding vectors to obtain a set of preset data usage policy monomer semantic matching degrees.
8. The security management method for data asset trading according to claim 7, wherein Based on the asset usage behavior - preset data usage policy semantic fine-grained verification aggregation coding vector, determine whether to trigger an alarm prompt, including: Pass the asset usage behavior - preset data usage policy semantic fine-grained verification aggregation coding vector through an alarm prompt device based on a classifier to obtain an alarm prompt result, and the alarm prompt result is used to indicate whether to trigger an alarm prompt.
9. A security management system for data asset trading, which is used to execute the method described in any one of claims 1 to 8, characterized in that, Including: A data asset acquisition module for acquiring data assets uploaded by data providers; A hash calculation module for performing a hash operation on the data content of the data asset to generate a unique hash value as the identifier of the data asset; A hash fingerprint generation module for calculating the hash values of each data block after data chunking of the data content of the data asset to obtain a hash fingerprint composed of multiple hash values; A transaction record writing module, which is used to write the identifier of the data asset, the key meta-information of the data asset, and the hash fingerprint of the data asset into the blockchain network as a transaction record; A verification result generating module, which is used to respond to a request to verify the integrity of the data asset, recalculate the verification hash value and the verification hash fingerprint of the data content of the data asset, compare the verification hash value with the identifier of the data asset stored in the blockchain network, and compare the verification hash fingerprint with the hash fingerprint stored in the blockchain network to obtain an integrity verification result.
Citation Information
Patent Citations
Block chain-based asset data management method and system
CN114329529A
Digital right encryption management method and system based on block chain
CN119557854A