Data transmission method, device, system and equipment and storage medium

Through permission server verification and encryption processing, safe and reliable data transmission between chip design and chip production is achieved, data barriers and security risks are solved, and production efficiency and information security are improved.

CN120128402APending Publication Date: 2025-06-10DONGFANG JINGYUAN ELECTRON LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510344602.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

There is a significant data barrier between chip design and chip production, which leads to the inability to understand the other party's data in a timely manner during the design and production process, affecting production efficiency and posing data security risks.

Method used

The target data request of the data requesting end is obtained and verified through the permission server, and after confirming the permission verification, the target data request is sent to the data provider, and through the encryption and transmission of layers of keys, the security and reliability of data transmission are ensured.

Benefits of technology

It realizes safe and reliable data transmission between chip design and chip production, solves the problem of data barriers, and ensures the security of information in the data transmission process, avoiding leakage and resource waste.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128402A_ABST
    Figure CN120128402A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data transmission method, device, system and equipment and a storage medium, and the method comprises the steps: verifying a target data request provided by a data request end through a permission server, and transmitting the target data request to a data providing end when the permission verification is passed; after a data providing end allows a data requesting end to obtain target data, the data providing end sends a target data secret key to an authority server, and the authority server can determine a corresponding temporary data reading secret key and send the temporary data reading secret key to the data requesting end. And the data request end can read the key according to the temporary data and acquire the target data from the data private cloud. According to the technical scheme, reliable identities of two data transmission parties are effectively guaranteed, security and reliability of the data transmission process can be effectively guaranteed through encryption and transmission of secret keys layer by layer, and the problems of secret leakage and information leakage are avoided. The problem of data barrier possibly existing between the data requesting end and the data providing end is solved, and meanwhile safety and reliability of the data transmission process are guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of data communication, and particularly relates to a data transmission method, device, system, equipment, and storage medium. Background Art

[0002] Currently, chip manufacturing can be divided into two major links: chip design and chip production, and the two links are usually responsible by different teams or manufacturers.

[0003] At present, there is a significant data gap between chip design and production, which makes it impossible to directly understand the relevant data in the chip production process during the chip design process. As a result, it may be impossible to fully consider whether the chip design scheme can be effectively supported by the technology in the production process when designing the chip. On the other hand, the data in the design process cannot be directly understood during the chip production process. When actually producing chips, it is impossible to timely determine whether the problem occurs in the production process or in the chip design itself, which seriously affects the production efficiency of the chips and causes time consumption and resource waste. If the design and production parties directly exchange data, there may be significant data security risks and disclosure risks, and information security cannot be fully guaranteed. Summary of the Invention

[0004] Embodiments of this application provide a data transmission method, device, system, equipment, and storage medium to achieve secure and reliable data transmission between chip design and chip production.

[0005] In a first aspect, embodiments of this application provide a data transmission method. This data transmission method is applied to an authority server and includes:

[0006] Obtain a target data request sent by a data request end, where the target data request includes a data request range and a data request key;

[0007] When it is determined that the target data request passes the authority verification according to the data request key, send the target data request to the data providing end;

[0008] Receive a target data key generated by the data providing end for the target data. The target data key is used to represent the data range corresponding to the target data and the data usage time of the target data. The target data key is generated by the data providing end when it is determined that the data request end is allowed to obtain the target data corresponding to the data request range;

[0009] Determine a temporary data reading key corresponding to the target data key;

[0010] Send the temporary data reading key to the data request side, so that the data request side can obtain the target data restricted by the data usage time from the preset data private cloud according to the temporary data reading key. The data corresponding to the data request side and the data providing side is pre-stored in the data private cloud.

[0011] In a second aspect, an embodiment of the present application provides a data transmission method. This data transmission method is applied to the data request side and includes:

[0012] Send the target data request to the permission server. The target data request includes a data request range and a data request key;

[0013] Receive the temporary data reading key sent by the permission server. The temporary data reading key is determined by the permission server based on the target data key when it determines that the target data request passes the permission verification. The target data key is generated and sent to the permission server by the data providing side when it determines that the data request side is allowed to obtain the target data corresponding to the data request range, and is used to represent the data range corresponding to the target data and the data usage time of the target data;

[0014] Obtain the target data restricted by the data usage time from the preset data private cloud according to the temporary data reading key.

[0015] In a third aspect, an embodiment of the present application provides a data transmission method. This data transmission method is applied to the data providing side and includes:

[0016] Receive the target data request sent by the permission server. The target data request includes a data request range and a data request key, and is sent to the data providing side by the permission server when it determines that the target data request passes the permission verification based on the data request key sent by the data request side;

[0017] Judge whether to allow the data request side to obtain the target data corresponding to the data request range according to the target data request;

[0018] If so, generate the target data key corresponding to the target data. The target data key is used to represent the data range corresponding to the target data and the data usage time when the data providing side restricts the data request side from using the target data;

[0019] Send the target data key to the permission server, so that the permission server can generate the temporary data reading key corresponding to the target data key according to the target data key;

[0020] Send the temporary data reading key to the data request side through the permission server, so that the data request side can obtain the target data restricted by the data usage time from the preset data private cloud according to the temporary data reading key.

[0021] In a fourth aspect, an embodiment of the present application provides a data transmission system, including: a data request end, a data providing end, and an authorization server;

[0022] The data request end is configured to send a target data request to the authorization server, receive a temporary data reading key sent by the authorization server, and obtain, according to the temporary data reading key, target data restricted by a data usage time from a preset data private cloud. The target data request includes a data request range and a data request key;

[0023] The authorization server is configured to obtain the target data request sent by the data request end, send the target data request to the data providing end when it is determined that the target data request passes the authorization verification according to the data request key, generate a temporary data reading key according to the target data key sent by the data providing end, and send the temporary data reading key to the data request end. The target data key is used to represent the data range corresponding to the target data and the data usage time for which the data providing end restricts the data request end from using the target data;

[0024] The data providing end is configured to receive the target data request sent by the authorization server, generate a target data key for the target data when it is determined that the data request end is allowed to obtain the target data according to the target data request, and send the target data key to the authorization server.

[0025] In a fifth aspect, an embodiment of the present application provides an electronic device, which includes a processor, a memory, and a program or instruction stored on the memory and executable on the processor. When the program or instruction is executed by the processor, the steps of any data transmission method in the embodiments of the present application are implemented.

[0026] In a fourth aspect, an embodiment of the present application provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of any data transmission method in the embodiments of the present application are implemented.

[0027] In a fifth aspect, an embodiment of the present application provides a computer program product. When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device is enabled to execute the steps of any data transmission method in the embodiments of the present application.

[0028] The technical solutions provided by the embodiments of the present application at least bring the following beneficial effects:

[0029] An embodiment of the present application provides a data transmission method, including: obtaining and verifying a target data request provided by a data request end through an authorization server, and when it is determined that the authorization verification is passed, sending the target data request to a data providing end. The processing process of passing the authorization verification effectively ensures the reliability of the identities of both parties in data transmission and the information security of subsequent target data transmission.

[0030] Then, after the data providing end allows the data request end to obtain the target data, the data providing end may send a corresponding target data key to the authorization server, and the authorization server may determine a corresponding temporary data reading key based on this and send it to the data request end. The encryption and transmission of keys layer by layer can effectively ensure the security and reliability of the data transmission process, and effectively avoid problems such as leakage and information disclosure. Finally, the data request end may obtain the target data from the data private cloud according to the temporary data reading key. The overall data transmission process is safe and reliable, which not only solves the possible data gap problem between the data request end and the data providing end, but also ensures the security and stability of the data transmission process.

[0031] It should be understood that the above general description and subsequent detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required to be used in the embodiments of the present application. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.

[0033] Figure 1 It is a schematic flowchart of a data transmission method applied to an authorization server provided by an embodiment of the present application;

[0034] Figure 2 It is a schematic diagram of an example in which data corresponding to a data providing end and a data request end in an embodiment of the present application is pre-stored in a data private cloud;

[0035] Figure 3 It is a schematic flowchart of the execution process of a data transmission method during the chip manufacturing process provided by an embodiment of the present application;

[0036] Figure 4 It is a schematic flowchart of a data transmission method applied to a data request end provided by an embodiment of the present application;

[0037] Figure 5 It is a schematic flowchart of a data transmission method applied to a data providing end provided by an embodiment of the present application;

[0038] Figure 6Schematic diagram of the working process of a data transmission system provided by an embodiment of the present application;

[0039] Figure 7 Schematic diagram of the structure of a data transmission device applied to an authorization server provided by another embodiment of the present application;

[0040] Figure 8 Schematic diagram of the structure of a data transmission device applied to a data request end provided by another embodiment of the present application;

[0041] Figure 9 Schematic diagram of the structure of a data transmission device applied to a data provider provided by another embodiment of the present application;

[0042] Figure 10 Schematic diagram of the hardware structure of a data transmission device provided by another embodiment of the present application. Detailed implementation manners

[0043] The features and exemplary embodiments of various aspects of the present application will be described in detail below. For the purpose of making the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than limiting the present application. For those skilled in the art, the present application can be implemented without some of these specific details. The following description of the embodiments is only intended to provide a better understanding of the present application by showing examples of the present application.

[0044] It should be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover a non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, elements defined by the statement "comprising..." do not exclude the presence of additional identical elements in the process, method, article or device comprising the elements.

[0045] Chip design and chip production are two very important links in the chip manufacturing process, and they are closely related. However, at present, chip design and chip production are mostly responsible for by different teams or manufacturers, and there is a serious data gap between design and production. As a result, during the chip design process, it is impossible to fully consider whether the production technology can support it, and during the chip production process, it is also impossible to promptly identify whether the problem is caused by production or the chip design itself when problems occur.

[0046] Such problems will seriously reduce the execution efficiency of the overall chip manufacturing process, causing unnecessary waste of time and resources. If direct data interaction occurs between the two parties, there will be significant security risks and the risk of information leakage, and the information security of confidential data related to the chip cannot be fully guaranteed.

[0047] Based on the technical problems mentioned in the above content, embodiments of the present application provide a data transmission method, device, system, equipment, and storage medium. The target data request provided by the data request side can be obtained and verified through the permission server, and when it is determined that the permission verification is passed, the target data request is sent to the data providing side. By performing permission verification on the target data request, the reliability of the identities of both parties in the data transmission and the information security of the subsequent target data transmission are effectively guaranteed.

[0048] After the data providing side allows the data request side to obtain the target data, the data providing side can send the corresponding target data key to the permission server, and the permission server can determine the corresponding temporary data reading key based on this and send it to the data request side. Through the encryption and transmission of the above layers of keys, the security and reliability of the data transmission process can be effectively guaranteed, and the problems of leakage and information disclosure during the data transmission process can be avoided to a great extent.

[0049] Furthermore, the data request side can obtain the target data from the data private cloud according to the temporary data reading key. Through the above complete data transmission process, secure and reliable data transmission can be achieved, and the data gap problem between the data request side and the data providing side can be effectively solved.

[0050] Regarding the specific application scenarios corresponding to the data transmission method, device, system, equipment, and storage medium provided by the embodiments of the present application, no strict definition is made in the present application, and they can be flexibly applied according to actual needs. For the sake of easy understanding, the following gives examples of the specific application scenarios of the data transmission method, device, system, equipment, and storage medium provided by the embodiments of the present application.

[0051] For example, during the chip manufacturing process, when the chip production side wants to obtain complete or partial chip design data for detecting problems occurring during the chip production process, the chip production side and the chip design side can achieve secure and reliable data transmission by applying the technical solution provided in the embodiments of the present application.

[0052] Specifically, it can obtain and verify the target data request of the chip production side through the permission server, and when it is determined that the verification is passed, send the target data request to the chip design side. When the chip design side determines to allow the chip production side to obtain the corresponding target data according to the received target data request, it can generate the corresponding target data key and return it to the permission server. The permission server can determine the corresponding temporary data reading key according to the target data key and send it to the chip production side. Then, the chip production side can obtain the required chip design data from the preset data private cloud according to the received temporary data reading key.

[0053] In addition, the data transmission direction between the chip design side and the chip production side in the above example can also be reversed, that is, the chip design side can also obtain the data of the chip production side through the above technical solution. In this example, the technical solution provided in the embodiments of the present application can efficiently and securely realize the data transmission between the chip design side and the chip production side, and the security and reliability of the data transmission process and information security can be effectively guaranteed through the process of permission verification and encrypted transmission.

[0054] It should be noted that the application scenarios described in the above embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Those of ordinary skill in the art know that with the emergence of new application scenarios, the technical solutions provided in the embodiments of the present application are equally applicable to similar technical problems. The data transmission method provided in the embodiments of the present application can be applied to any application scenario where data transmission is required between a data provider and a data requester that may have data barriers.

[0055] Figure 1 It is a schematic flow chart of a data transmission method applied to a permission server provided in an embodiment of the present application.

[0056] As Figure 1 shown, the data transmission method applied to the permission server provided in the embodiments of the present application includes steps S101 to S105.

[0057] S101: Obtain the target data request sent by the data requester.

[0058] In step S101, the permission server applying the data transmission method provided in the embodiments of the present application can obtain the target data request generated and sent by the data requester.

[0059] Among them, the target data request may specifically include a data request scope and a data request key.

[0060] The data request scope may specifically be used to represent the data scope that the data request side intends to obtain from the data providing side. The data request key is specifically used for subsequent permission verification, and may specifically be used to represent, but not limited to, the identity information corresponding to the data request side, the permission scope corresponding to the data request side, the usage time limit of the data request key, etc.

[0061] S102: When it is determined that the target data request passes the permission verification according to the data request key, send the target data request to the data providing side.

[0062] In step S102, the permission server may determine whether the target data request sent by the data request side can pass the permission verification process according to the data request key obtained from the target data request.

[0063] It should be noted that the specific processing process of the permission verification process is not strictly limited in the implementation provided by this application, and can be flexibly set and adjusted according to the actual application scenario.

[0064] In an embodiment provided by this application, the permission server may determine the key information included in the data request key by parsing the data request key in the target data request. The key information may specifically include at least the identity information and permission information corresponding to the data request side. Further, the permission server may determine whether the data request key meets the pre-set permission verification rules according to the relevant information such as the identity information corresponding to the data request side and the permission information corresponding to the data request side indicated by the key information, so as to determine whether the target data request passes the permission verification process.

[0065] The above embodiment is a feasible method for specifically implementing the permission verification process in this application. In addition to this, other feasible methods and means may also be used to implement the permission verification of the target data request.

[0066] Through the above processing process of the permission server for performing permission verification on the target data request, it can ensure that the identity information of the data request side is public and reliable. Effectively improve the security and stability of the data transmission process, and provide a strong guarantee for the information security of the confidential data corresponding to the data request side and the data providing side respectively.

[0067] Furthermore, when the permission server determines that the target data request passes the permission verification, the permission server may send the target data request to the data providing side, so that the data providing side can perform subsequent processing processes and the generation process of the target data key.

[0068] S103: Receive the target data key generated by the data provider for the target data.

[0069] In step S103, the permission server can receive the target data key generated by the data provider for the target data.

[0070] Specifically, after receiving the target data request that has passed the permission verification sent by the permission server, when the data provider determines to allow the data requester to obtain the target data corresponding to the data request scope, the target data key is generated according to the data scope corresponding to the target data.

[0071] Specifically, the target data key can include, but is not limited to, the data scope of the target data that the data provider allows the data requester to obtain, and information such as the data usage time limit set by the data provider for the target data to be used by the data requester.

[0072] Regarding the specific processing process of the data provider to determine whether to allow the data requester to obtain the target data according to the target data request, it is not strictly limited in the embodiments provided in this application and can be flexibly set according to the actual application scenario and requirements.

[0073] In an embodiment provided in this application, after receiving the target data request, the data provider can execute the internal approval process preset inside the data provider according to the target data request.

[0074] Specifically, the approval process can determine whether to agree that the data requester can obtain the data corresponding to the data request scope according to the data request scope in the target data request. The approval process can be actively confirmed and approved manually, or the data provider can automatically approve according to the pre-set allowed transmission data scope.

[0075] When the data provider determines that the target data request has passed the internal approval process, it can determine to allow the data requester to obtain the target data corresponding to the data request scope. Then, the data provider can generate a corresponding target data key for the target data and send it to the permission server so that the permission server can generate the subsequent temporary data reading key.

[0076] S104: Determine the temporary data reading key corresponding to the target data key.

[0077] In step S104, the permission server can determine the corresponding temporary data reading key according to the target data key obtained from the data provider.

[0078] Among them, the temporary data reading key can specifically be a key further generated by the permission server based on the content represented by the target data key, and there is an associated relationship with the target data key. Specifically, it can also represent the data range corresponding to the target data, and the data provider allows the data requester to use the data use time of the target data. In addition, the effective use time of the temporary data reading key can be set. After exceeding the effective use time, the temporary data reading key can automatically become invalid.

[0079] When generating the target data key at the data provider above, the effective use time of the target data key can also be set. After exceeding the effective use time of the target data key, the target data key can automatically become invalid. At this time, regardless of whether the effective use time of the temporary data reading key is exceeded, the temporary data reading key will also automatically become invalid.

[0080] The validity of the temporary data reading key is determined not only based on its own effective use time, but also based on the validity of the target data key. For example, if the target data key is cancelled or invalidated by the data provider midway during data transmission, the temporary data reading key can become invalid accordingly. Through the conversion generation between the above keys and the mutual association of the key validities, the information security during data transmission can be effectively guaranteed, and the risk of leakage problems can be reduced.

[0081] S105: Send the temporary data reading key to the data requester so that the data requester can obtain the target data restricted by the data use time from the preset data private cloud according to the temporary data reading key.

[0082] In step S105, the permission server can send the temporary data reading key generated based on the target data key to the data requester, so that the data requester can obtain the target data restricted by the data use time corresponding to the target data key from the preset data private cloud according to the received temporary data reading key.

[0083] Among them, the data private cloud is a privatized cloud computing environment designed specifically for data security, and can specifically be used to highly securely encrypt and store the respective corresponding data of the data provider and the data requester before data transmission.

[0084] Based on the data private cloud, the embodiments provided in this application can achieve that during data transmission, except for the last stage when the data requester obtains the target data from the data private cloud, the target data itself is not directly involved in other processes. It effectively guarantees the security of the target data during the overall data transmission process, and greatly avoids the problems and risks of the target data being obtained or leaked by others.

[0085] Regarding the specific process of pre-storing the data corresponding to the data provider and the data requester in the data private cloud, in an embodiment provided by the present application, the permission server may send corresponding encryption keys to the data provider and the data requester, so that both ends encrypt and upload the data according to the encryption keys.

[0086] Specifically, the permission server may, according to the data upload request sent by the data requester, send the encryption key preset for the data requester to the data requester. After receiving the encryption key returned by the permission server, the data requester encrypts the data corresponding to the data requester and uploads the encrypted data to the data private cloud for storage.

[0087] Similarly, after receiving the data upload request sent by the data provider, the permission server may also send the encryption key preset for the data provider to the data provider. After receiving the encryption key returned by the permission server, the data provider can encrypt the data corresponding to itself and upload the encrypted data to the data private cloud for storage.

[0088] To facilitate understanding of the above process of pre-storing the data corresponding to the data provider and the data requester in the data private cloud, taking the chip production end in the chip manufacturing process as the data requester and the chip design end as the data provider as an example, based on a schematic diagram of the process of pre-storing the data corresponding to one data provider and one data requester in the data private cloud, the description is as follows Figure 2 as shown.

[0089] Figure 2 This is a schematic diagram of an example of pre-storing the data corresponding to the data provider and the data requester in the data private cloud provided by an embodiment of the present application.

[0090] As Figure 2 shown, the chip production end as the data requester and the chip design end as the data provider can respectively send data upload requests to the permission server through step S201, and the permission server can respectively return corresponding encryption keys according to the data upload requests through step S202.

[0091] The chip production end and the chip design end can encrypt the corresponding data according to the received encryption keys, and then send the encrypted chip production data and chip design data to the data private cloud for storage through step S203.

[0092] Through the above process of encrypting and storing the respective data of the data provider and the data requester in the data private cloud, it can effectively ensure the centralized management of the data at both ends and greatly avoid the direct participation of data with high confidentiality requirements during the data transmission process. While enhancing the security and reliability of the data transmission process, it also provides strong security guarantees for the data security of the data provider and the data requester.

[0093] Regarding the specific process of the above data requester obtaining the target data from the data private cloud according to the temporary data reading key, in an embodiment provided by the present application, after receiving the temporary data reading key sent by the permission server, the data requester can perform key parsing on the temporary data reading key to determine the data request range represented by the temporary data reading key and the data usage time for restricting the data provider to use the target data.

[0094] Then, the data requester can generate a data acquisition request for the data request range corresponding to the temporary data key (i.e., the target data) according to the data request range corresponding to the temporary data key, and send it to the data private cloud storing the target data, so as to obtain the target data with the above data usage time limit from the data private cloud.

[0095] Through the above process of obtaining the target data from the data private cloud according to the temporary data reading key, it can effectively improve the security and stability of the overall data transmission process. While realizing the efficient interaction of data between the data provider and the data requester, the high security and stability of the transmission process also provide effective security guarantees for the confidential data corresponding to the data provider and the data requester respectively.

[0096] Among them, regarding the specific process of the data requester obtaining the target data with data usage time limit from the data private cloud. In an embodiment provided by the present application, the data requester can send the data acquisition request determined based on the data request range corresponding to the temporary data key to the data private cloud, so that the data private cloud can return the corresponding pre-encrypted and stored target data to the data requester according to the data acquisition request.

[0097] After the data requester receives the encrypted target data returned by the data private cloud, it can decrypt the data to obtain the target data. It should be noted that before obtaining the target data and entering the usage state, the data requester will also restrict the usage of the target data according to the data usage time corresponding to the temporary data key, so as to obtain the target data with data usage time limit. After that, the target data with data usage time limit will enter the usage state at the data requester.

[0098] For the decryption process of the encrypted target data returned by the data private cloud, in an embodiment provided by the present application, specifically, after the data request end receives the encrypted target data, it requests the decryption key from the permission server to complete the decryption.

[0099] In addition, in the embodiments provided by the present application, the specific manner of implementing the data usage time limit of the target data is not strictly limited and can be flexibly adjusted according to the actual application scenarios and requirements. For example, in an embodiment provided by the present application, it can be specified that when the data request end obtains the target data from the data private cloud, it can only perform caching processing in the device memory. The caching time of the target data is the limited data usage time corresponding to the target data key or the temporary data reading key. After exceeding the data usage time, the cache will be automatically cleared, and during the cache time, it is only for viewing and cannot be stored by copying or cutting, etc.

[0100] Through the above processing process, the data request end can successfully obtain the target data it wants while strictly restricting the usage time of the target data. It effectively ensures the security and reliability of the data transmission process, and by restricting the usage time of the target data of the data request end in ways such as only using it in memory, it can effectively ensure the information security of the target data and greatly reduce the risk of information leakage.

[0101] The above overall process is the specific processing flow of the data transmission method applied to the permission server provided by the embodiments of the present application. In the actual application process of the method, the specific identities of the data request end and the data providing end can be flexibly selected according to different application scenarios and application requirements.

[0102] In an embodiment provided by the present application, the data request end can be the chip production end in the chip manufacturing process, and the data providing end can be the chip design end. The data corresponding to the data request end stored in the data private cloud can be the chip production data corresponding to the chip production end, and the data corresponding to the data providing end can be the chip design data corresponding to the chip design end.

[0103] For ease of understanding, the following is a structural schematic diagram of the execution process of the data transmission method in the chip manufacturing process, as Figure 3 shown in.

[0104] Figure 3 This is a flow schematic diagram of the execution process of a data transmission method in the chip manufacturing process provided by an embodiment of the present application.

[0105] As Figure 3As shown in [figure], the data transmission method provided by the embodiments of the present application can be applied during the chip manufacturing process. The chip production end can send a target data request for the chip design data corresponding to the chip design end to the permission server through step S301. When the permission server determines that the target data request passes the permission verification through step S302, it can send the target data request to the chip design end.

[0106] Through step S303, after the chip design end determines to allow the chip production end to obtain and use the target data corresponding to the data request scope in the target data request, it can generate a corresponding target data key for the target data and send it to the permission server. Then, through step S304, the permission server can determine a corresponding temporary data reading key according to the target data key and send it to the chip production end. Finally, through steps S305 and S306, the chip production end can obtain the target data with data usage time limit in the chip design data from the data private cloud according to the temporary data reading key.

[0107] Through the above processing process, efficient and secure data transmission between the chip production end and the chip design end during the chip manufacturing process can be achieved based on the data transmission method provided by the embodiments of the present application. When the chip production end encounters problems or special situations during the chip production process, it can obtain the corresponding chip design data in a timely manner through the above steps to quickly identify the source of the problem, thereby effectively improving the chip production efficiency and reducing time and resource waste.

[0108] In addition, during the chip manufacturing process, the identities of the data request end and the data providing end can also be exchanged with each other. In another embodiment provided by the present application, the data request end can be the chip design end, and the data providing end can be the chip production end. The data corresponding to the data request end stored in the data private cloud can be the chip design data corresponding to the chip design end, while the data corresponding to the data providing end can be the chip production data corresponding to the chip production end.

[0109] Similar to the above process, the chip design end can send a target data request for the chip production data corresponding to the chip production end to the permission server. When the permission server determines that the target data request passes the permission verification, it sends the target data request to the chip production end.

[0110] Then, after the chip production end determines to allow the chip design end to obtain and use the target data corresponding to the data request scope in the target data request, it can generate a corresponding target data key and send it to the permission server. The permission server can determine a corresponding temporary data reading key and send it to the chip design end. The chip design end can obtain the target data with data usage time limit in the chip production data from the data private cloud according to the received temporary data reading key.

[0111] Similarly, through the application process of the technical solution provided by the embodiments of the present application in the chip manufacturing process, efficient and secure data transmission can be achieved between the chip production end and the chip design end. The chip design end can obtain the chip production data of the chip production end when designing the chip, so as to design a chip that is more suitable for the chip production end based on the technical support in the chip production process, effectively improving the chip design and production efficiency, while greatly reducing the possibility of problems occurring in the chip production process and accelerating the manufacturing and application of the chip.

[0112] The above all content is a data transmission method applied to a permission server provided by the embodiments of the present application. For ease of understanding, the data transmission method provided by the embodiments of the present application will be shown in a process respectively with the data request end and the data providing end as the execution subjects, as Figure 4 and Figure 5 shown.

[0113] Figure 4 FIG. is a schematic flow chart of a data transmission method applied to a data request end provided by an embodiment of the present application, specifically including steps S401 to S403.

[0114] S401: Send a target data request to the permission server, where the target data request includes a data request range and a data request key;

[0115] S402: Receive a temporary data reading key sent by the permission server.

[0116] S403: According to the temporary data reading key, obtain target data restricted by the data usage time from a preset data private cloud.

[0117] Figure 5 FIG. is a schematic flow chart of a data transmission method applied to a data providing end provided by an embodiment of the present application, specifically including steps S501 to S505.

[0118] S501: Receive a target data request sent by the permission server.

[0119] S502: According to the target data request, determine whether to allow the data request end to obtain the target data corresponding to the data request range.

[0120] S503: If so, generate a target data key corresponding to the target data.

[0121] S504: Send the target data key to the permission server, so that the permission server generates a temporary data reading key corresponding to the target data key according to the target data key.

[0122] S505: Send the temporary data reading key to the data requestor through the permission server, so that the data requestor can obtain the target data restricted by the data usage time from the preset data private cloud according to the temporary data reading key.

[0123] Regarding the specific content introductions corresponding to the above S401 to S403 and steps S501 to S505, there are similar descriptions and explanations in the specific introductions of the above steps S101 to S105, which can be directly referred to, and there will be no excessive repeated discussions here.

[0124] In addition to the above content, an embodiment of the present application also provides a data transmission system, which includes a data requestor, a data provider, and a permission server. The specific working process of the data transmission system can be referred to Figure 6 as shown in

[0125] Figure 6 is a schematic diagram of the working process of a data transmission system provided by an embodiment of the present application.

[0126] As Figure 6 shown, the data requestor can specifically send the target request data to the permission server through step S601. Then, receive the temporary data reading key sent by the permission server through step S604, and obtain the target data with the data usage time limit in the target data request from the data private cloud through step S605.

[0127] The permission server can specifically be used to obtain the target data request sent by the data requestor. When it is determined that the target data request passes the permission verification according to the data request key in the target data request, the permission server can send the target data request to the data provider through step S602. Then, receive the target data key returned by the data provider based on the target data request, generate the corresponding temporary data reading key, and send it to the data requestor.

[0128] The data provider can specifically be used to receive the target data request sent by the permission server. When it is determined according to the target data request that the data requestor is allowed to obtain and use the target data, generate the target data key corresponding to the target data through step S603, and send it to the permission server.

[0129] Through Figure 6The data transmission system shown can efficiently and securely achieve data interaction between the data request side and the data providing side. Whether it is the data request side and the data providing side with data barriers, such as the chip design side and the chip production side in the chip manufacturing process mentioned in the above embodiments, or the data request side and the data providing side without data barriers but with high-level confidentiality requirements for data, the technical solutions provided by the embodiments of the present application can be applied. The technical solutions provided by the embodiments of the present application effectively ensure the security and reliability in the data transmission process and reduce the risk of leakage of confidential data.

[0130] In addition to the above content, it should be noted that the data transmission method provided by the embodiments of the present application can be applied not only to the permission server, the data request side, and the data providing side mentioned in the above content, but also to the software program jointly deployed by the data request side and the data providing side. When data is transmitted through the software program applying the data transmission method provided by this embodiment, the technical personnel corresponding to the data request side and the data providing side do not need to directly participate in the data transmission process, and the corresponding software program performs the corresponding operations.

[0131] Specifically, the software program applying the data transmission method provided by this embodiment on the data request side can be responsible for determining the data request key corresponding to the data request range required by the data request side, determining the corresponding target data request, and sending it to the permission server. Then, in the subsequent process, it receives and decrypts the temporary data reading key sent by the permission server, obtains the encrypted target data from the data private cloud, adds a data usage time limit, and caches it in the software memory. The data request side itself only participates in providing the data request range and the subsequent use of the target data, and does not participate in other intermediate processes.

[0132] Similarly, the software program applying the data transmission method provided by this embodiment on the data providing side can be responsible for receiving the target data request sent by the permission server. When it is determined within the data providing side that the data request side is allowed to obtain and use the target data, the software program on the data providing side can generate the corresponding target data key for the target data and return it to the permission server. The data providing side itself is only used to receive the target data request sent by the software program, perform internal approval, and send the approval result to the software program, and does not participate in other intermediate processes.

[0133] Through the above processing process, it can effectively ensure the security and stability of the data transmission process between the data providing side and the data request side, reduce the direct participation of the data request side and the data providing side in the transmission process, facilitate more rapid location of problems when problems occur in the transmission process, improve the data transmission efficiency, and provide guarantee for information security.

[0134] The above is the specific implementation of the data transmission method and system provided by the embodiments of the present application. Through the permission server applying the technical solution provided by the embodiments of the present application, the target data request provided by the data request end can be obtained and verified, and when the permission verification is passed, the target data request is sent to the data provider. The above processing process of permission verification can effectively ensure the reliability of the identities of both parties in the data transmission process and the information security of the subsequent target data during the data transmission process.

[0135] After the data provider allows the data request end to obtain the target data, the data provider can send the target data key corresponding to the target data to the permission server, and the permission server can determine the corresponding temporary data reading key based on this and send it to the data request end. The encryption and transmission of the above-layered keys can effectively ensure the security and reliability of the data transmission process and effectively avoid problems such as leakage and information disclosure.

[0136] Finally, the data request end can obtain the target data from the data private cloud according to the temporary data reading key. The data transmission process implemented by the technical solution provided by the embodiments of the present application is safe and reliable, which not only solves the possible data gap problem between the data request end and the data provider, but also provides a strong guarantee for the information security during the data transmission process.

[0137] Based on the data transmission method applied to the permission server provided in the above embodiments, correspondingly, the present application also provides a specific implementation of the data transmission device. Please refer to the following embodiments.

[0138] Figure 7 FIG. is a schematic structural diagram of a data transmission device applied to a permission server provided in another embodiment of the present application.

[0139] An obtaining unit 701 is configured to obtain a target data request sent by a data request end, where the target data request includes a data request range and a data request key;

[0140] A permission verification unit 702 is configured to send the target data request to the data provider when it is determined that the target data request passes the permission verification according to the data request key;

[0141] A key receiving unit 703 receives a target data key generated by the data provider for the target data. The target data key is used to represent the data range corresponding to the target data and the data usage time of the target data. The target data key is generated by the data provider when it is determined to allow the data request end to obtain the target data corresponding to the data request range;

[0142] A temporary key determining unit 704 is configured to determine a temporary data reading key corresponding to the target data key;

[0143] A data acquisition unit 705 is configured to send a temporary data reading key to a data requester, so that the data requester can obtain target data restricted by data usage time from a preset data private cloud according to the temporary data reading key. The data corresponding to the data requester and the data provider is pre-stored in the data private cloud.

[0144] In the embodiment provided by the present application, through the above device, the permission server can obtain and verify a target data request provided by the data requester, and send the target data request to the data provider when it is determined that the permission verification is passed. The above permission verification process can effectively ensure the reliability of the identities of both parties during the data transmission process and the information security of the subsequent target data during the data transmission process. After the data provider allows the data requester to obtain the target data, the data provider can send a target data key corresponding to the target data to the permission server, and the permission server can determine a corresponding temporary data reading key based on this and send it to the data requester. The encryption and transmission of the above-layered keys can effectively ensure the security and reliability of the data transmission process, and effectively avoid problems such as data leakage and information disclosure.

[0145] Finally, the data requester can obtain the target data from the data private cloud according to the temporary data reading key. The data transmission process implemented by the technical solution provided by the embodiment of the present application is safe and reliable, which not only solves the possible data gap problem between the data requester and the data provider, but also provides strong guarantee for the information security during the data transmission process.

[0146] In one embodiment, the above data acquisition unit 705 is specifically configured to, according to a data upload request of the data requester, send an encryption key preset for the data requester to the data requester, so that the data requester encrypts the data corresponding to the data requester and uploads it to the data private cloud for storage;

[0147] and according to a data upload request of the data provider, send an encryption key preset for the data provider to the data provider, so that the data provider encrypts the data corresponding to the data provider and uploads it to the data private cloud for storage.

[0148] In one embodiment, the above permission verification unit 702 is specifically configured to parse the data request key to determine the key information included in the data request key, and the key information at least includes identity information and permission information corresponding to the data requester;

[0149] If it is determined that the key information meets a preset permission verification rule, it is determined that the target data request passes the permission verification.

[0150] In one embodiment, the data request end is the chip production end, the data providing end is the chip design end, the data corresponding to the data providing end is the chip design data corresponding to the chip design end, and the target data is the target design data in the chip design data;

[0151] Specifically, the above data acquisition unit 705 is configured to send a temporary data reading key to the chip production end, so that the chip production end determines the target design data restricted by the data usage time from the chip design data pre-stored in the data private cloud by the chip design end according to the temporary data reading key.

[0152] In one embodiment, the data request end is the chip design end, the data providing end is the chip production end, the data corresponding to the data providing end is the chip production data corresponding to the chip production end, and the target data is the target production data in the chip production data;

[0153] Specifically, the above data acquisition unit 705 is configured to send a temporary data reading key to the chip design end, so that the chip design end determines the target production data restricted by the data usage time from the chip production data pre-stored in the data private cloud by the chip production end according to the temporary data reading key.

[0154] Figure 8 The figure is a schematic structural diagram of a data transmission device applied to a data request end provided in another embodiment of the present application.

[0155] A request sending unit 801, configured to send a target data request to an authorization server, where the target data request includes a data request range and a data request key;

[0156] A key receiving unit 802, configured to receive a temporary data reading key sent by the authorization server. The temporary data reading key is determined by the authorization server according to a target data key when it determines that the target data request passes the authorization verification. The target data key is generated and sent to the authorization server by the data providing end when it determines to allow the data request end to obtain the target data corresponding to the data request range, and is used to represent the data range corresponding to the target data and the data usage time of the target data;

[0157] A data acquisition unit 803, configured to obtain the target data restricted by the data usage time from a preset data private cloud according to the temporary data reading key.

[0158] In one embodiment, specifically, the above data acquisition unit 803 is configured to perform key parsing on the temporary data reading key to determine the data request range and the data usage time corresponding to the temporary data reading key.

[0159] Read the data request range corresponding to the key according to the temporary data, and generate a data acquisition request for the target data;

[0160] According to the data acquisition request, obtain the target data restricted by the data usage time from the preset data private cloud.

[0161] In one embodiment, the above data acquisition unit 803 is specifically configured to send the data acquisition request to the data private cloud, so that the data private cloud returns the pre-encrypted target data according to the data acquisition request;

[0162] Decrypt the pre-encrypted target data to obtain the target data;

[0163] According to the data usage time, restrict the use of the target data to determine the target data restricted by the data usage time.

[0164] Figure 9 It is a schematic structural diagram of a data transmission device applied to a data providing end provided by another embodiment of the present application.

[0165] A request receiving unit 901, configured to receive a target data request sent by an authorization server, where the target data request includes a data request range and a data request key, and is sent to the data providing end by the authorization server when it determines that the target data request passes the authorization verification according to the data request key sent by the data request end;

[0166] A request judgment unit 902, configured to judge whether to allow the data request end to obtain the target data corresponding to the data request range according to the target data request;

[0167] A key generation unit 903, configured to, if so, generate a target data key corresponding to the target data, where the target data key is used to represent the data range corresponding to the target data and the data usage time for the data providing end to restrict the data request end from using the target data;

[0168] A key sending unit 904, configured to send the target data key to the authorization server, so that the authorization server generates a temporary data reading key corresponding to the target data key;

[0169] A data transmission unit 905, configured to send the temporary data reading key to the data request end through the authorization server, so that the data request end obtains the target data restricted by the data usage time from the preset data private cloud according to the temporary data reading key.

[0170] Figure 10 It is a schematic hardware structure diagram of a data transmission device provided by another embodiment of the present application.

[0171] A data transmission device may include a processor 1001 and a memory 1002 storing computer program instructions.

[0172] Specifically, the processor 1001 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application.

[0173] The memory 1002 may include a mass storage for data or instructions. By way of example and not limitation, the memory 1002 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. In a suitable case, the memory 1002 may include a removable or non-removable (or fixed) medium. In a suitable case, the memory 1002 may be inside or outside the integrated gateway disaster recovery device. In a specific embodiment, the memory 1002 is a non-volatile solid state memory.

[0174] In a specific embodiment, the memory 1002 includes a read only memory (ROM). In a suitable case, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically rewritable ROM (EAROM), or a flash memory, or a combination of two or more of these.

[0175] The processor 1001 reads and executes the computer program instructions stored in the memory 1002 to implement any one of the data transmission methods in the above embodiments.

[0176] In one example, the data transmission device may further include a communication interface 1003 and a bus 1010. Among them, as Figure 10 shown, the processor 1001, the memory 1002, and the communication interface 1003 are connected through the bus 1010 and complete communication with each other.

[0177] The communication interface 1003 is mainly used to implement communication between modules, devices, units, and / or devices in the embodiments of the present application.

[0178] Bus 1010 includes hardware, software, or both, and couples the components of the online data flow metering device to each other. By way of example and not limitation, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a MicroChannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable bus or a combination of two or more of these. Where appropriate, bus 1010 may include one or more buses. Although the embodiments of the present application describe and illustrate specific buses, the present application contemplates any suitable bus or interconnect.

[0179] In addition, in combination with the data transmission method in the above embodiments, an embodiment of the present application can be implemented by providing a computer storage medium. Computer program instructions are stored on the computer storage medium; when the computer program instructions are executed by a processor, any one of the data transmission methods in the above embodiments is implemented.

[0180] An embodiment of the present application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, any one of the data transmission methods in the above embodiments is implemented.

[0181] It should be clear that the present application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present application is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications, and additions, or change the order between steps after understanding the spirit of the present application.

[0182] The functional blocks shown in the above-described structural block diagrams can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application-specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, and so on. When implemented in software, the elements of the present application are programs or code segments for performing the required tasks. The program or code segment can be stored in a machine-readable medium or transmitted via a data signal carried in a carrier wave over a transmission medium or a communication link. "Machine-readable medium" can include any medium that can store or transmit information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical discs, hard disks, fiber optic media, radio frequency (RF) links, and so on. The code segment can be downloaded via a computer network such as the Internet, an intranet, and so on.

[0183] It should also be noted that in the exemplary embodiments mentioned in the present application, some methods or systems are described based on a series of steps or devices. However, the present application is not limited to the order of the above steps, that is, the steps can be executed in the order mentioned in the embodiments, or different from the order in the embodiments, or several steps can be executed simultaneously.

[0184] Aspects of the present disclosure have been described above with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each block in the flowcharts and / or block diagrams, and the combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing device enable the implementation of the functions / actions specified in one or more blocks of the flowchart and / or block diagram. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It can also be understood that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, can also be implemented by dedicated hardware for performing the specified functions or actions, or by a combination of dedicated hardware and computer instructions.

[0185] The above are only specific embodiments of the present application. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, modules, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should be covered within the protection scope of the present application.

Claims

1. A data transmission method, characterized in that: The data transmission method is applied to the authority server, comprising: Obtaining a target data request sent by a data requesting end, wherein the target data request includes a data request range and a data request key; When it is determined according to the data request key that the target data request passes the authority verification, sending the target data request to the data provider; receiving a target data key generated by the data provider for the target data, the target data key being used to indicate a data range corresponding to the target data and a data usage time of the target data, the target data key being generated by the data provider when determining that the data requester is allowed to obtain the target data corresponding to the data request range; Determine a temporary data read key corresponding to the target data key; The temporary data reading key is sent to the data requesting end, so that the data requesting end obtains the target data subject to the data usage time limit from the preset data private cloud according to the temporary data reading key, and the data corresponding to the data requesting end and the data providing end are pre-stored in the data private cloud.

2. The method according to claim 1, characterized in that: Pre-storing the data corresponding to the data requester and the data provider in the data private cloud includes: According to the data upload request of the data request end, an encryption key preset for the data request end is sent to the data request end, so that the data request end encrypts the data corresponding to the data request end and uploads it to the data private cloud for storage; and According to the data upload request of the data provider, the encryption key preset for the data provider is sent to the data provider, so that the data provider encrypts the data corresponding to the data provider and uploads it to the data private cloud for storage.

3. The method according to claim 1, characterized in that Determining, according to the data request key, that the target data request passes the authority verification includes: Parsing the data request key to determine key information contained in the data request key, wherein the key information at least includes identity information and authority information corresponding to the data request end; If it is determined that the key information satisfies a preset authority verification rule, it is determined that the target data request passes the authority verification.

4. The method according to claim 1, characterized in that: The data requesting end is a chip production end, the data providing end is a chip design end, the data corresponding to the data providing end is chip design data corresponding to the chip design end, and the target data is target design data in the chip design data; The temporary data read key is sent to the data request end, so that the data request end obtains the target data subject to the data usage time limit from the preset data private cloud according to the temporary data read key, including: The temporary data reading key is sent to the chip production end, so that the chip production end determines the target design data subject to the data usage time limit from the chip design data pre-stored in the data private cloud by the chip design end according to the temporary data reading key.

5. The method according to claim 1, characterized in that The data requesting end is a chip designing end, the data providing end is a chip producing end, the data corresponding to the data providing end is the chip producing data corresponding to the chip producing end, and the target data is the target producing data in the chip producing data; The temporary data read key is sent to the data request end, so that the data request end obtains the target data subject to the data usage time limit from the preset data private cloud according to the temporary data read key, including: The temporary data reading key is sent to the chip design end, so that the chip design end determines the target production data subject to the data usage time limit from the chip production data pre-stored in the data private cloud by the chip production end according to the temporary data reading key.

6. A data transmission method, characterized in that: The data transmission method is applied to a data requesting end, comprising: Sending a target data request to an authority server, wherein the target data request includes a data request range and a data request key; Receive a temporary data read key sent by the authority server, where the temporary data read key is determined by the authority server based on a target data key when it is determined that the target data request has passed the authority verification, and the target data key is generated and sent to the authority server by the data provider when it is determined that the data requester is allowed to obtain the target data corresponding to the data request range, and is used to indicate the data range corresponding to the target data and the data usage time of the target data; The target data subject to the data usage time limit is obtained from a preset data private cloud according to the temporary data reading key.

7. The method according to claim 6, characterized in that According to the temporary data reading key, the target data subject to the data usage time limit is obtained from the preset data private cloud, including: Performing key analysis on the temporary data read key to determine the data request range and data usage time corresponding to the temporary data read key; Generate a data acquisition request for the target data according to the data request range corresponding to the temporary data reading key; According to the data acquisition request, target data subject to the data usage time limit is acquired from a preset data private cloud.

8. The method according to claim 7, characterized in that According to the data acquisition request, target data subject to the data usage time limit is acquired from a preset data private cloud, including: Sending the data acquisition request to the data private cloud, so that the data private cloud returns the pre-encrypted target data according to the data acquisition request; Decrypting the pre-encrypted target data to obtain the target data; According to the data usage time, the target data is restricted in usage, and the target data subject to the data usage time restriction is determined.

9. A data transmission method, characterized in that: The data transmission method is applied to a data provider, and includes: Receiving a target data request sent by an authority server, wherein the target data request includes a data request range and a data request key, and is sent to the data provider when the authority server determines that the target data request passes the authority verification according to the data request key sent by the data requester; According to the target data request, determining whether the data request end is allowed to obtain the target data corresponding to the data request range; If yes, generate a target data key corresponding to the target data, wherein the target data key is used to indicate a data range corresponding to the target data and to indicate that the data provider restricts the data requester from using the target data for a data usage time; Sending the target data key to the authority server, so that the authority server generates a temporary data reading key corresponding to the target data key according to the target data key; The temporary data read key is sent to the data request end through the authority server, so that the data request end obtains the target data subject to the data usage time limit from the preset data private cloud according to the temporary data read key.

10. A data transmission system, characterized in that: The data transmission system comprises: a data requesting end, a data providing end, and an authority server; The data request end is used to send a target data request to the authority server, receive a temporary data read key sent by the authority server, and obtain target data subject to data usage time restrictions from a preset data private cloud according to the temporary data read key, wherein the target data request includes a data request range and a data request key; The authority server is used to obtain the target data request sent by the data request end, and when it is determined that the target data request passes the authority verification according to the data request key, send the target data request to the data provider end, generate a temporary data read key according to the target data key sent by the data provider end, and send the temporary data read key to the data request end, wherein the target data key is used to indicate the data range corresponding to the target data, and indicates that the data provider end limits the data usage time of the target data to the data request end; The data provider is used to receive the target data request sent by the authority server, and when it is determined according to the target data request that the data requester is allowed to obtain the target data, generate the target data key for the target data, and send the target data key to the authority server.