Government data sharing, exchange and traceability method and system based on data watermark
By embedding data watermarks in the government data sharing platform, the problem of inability to trace in data sharing and exchange is solved, data security traceability and risk management are realized, and the security sharing and cooperation of government data are promoted.
Patent Information
- Application Number
- CN202510669133.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2045-05-23
AI Technical Summary
The existing government data sharing and exchange methods lack data traceability mechanisms, and the data source cannot be confirmed, resulting in the inability to hold accountable after data leakage.
By embedding data watermarks in the data sharing platform, watermark data is generated, and the data flow path is tracked through the watermark extraction algorithm to achieve data traceability.
It has achieved rapid positioning of the source of data leakage, ensuring data security, reducing risks in the sharing process, and promoting inter-departmental cooperation.
Smart Images

Figure CN120197160B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data sharing, and in particular to a method and system for government data sharing, exchange and tracing based on data watermarks. Background Art
[0002] Government data typically includes information on government decision-making, administrative management, public services, economic regulation, market supervision, social management, and environmental protection. Data sharing between government departments is achieved through a data sharing and exchange platform. The shared data typically includes databases, tables, interfaces, and files. Databases and interfaces are the primary means of exchanging relational data, so watermarking and traceability of these database and table data are crucial. Data watermarking is a technology that embeds specific digital signals into digital products to protect their copyright, integrity, copy protection, or tracking.
[0003] The existing government data sharing and exchange methods focus on security measures such as data authorization and data transmission encryption, and lack traceability methods for data content. For data in the sharing process, it is impossible to confirm the source of the data. After the data is shared with partners, once a data leak occurs, it is impossible to determine the source of the leak and hold anyone accountable.
[0004] In the process of government data sharing and exchange, how to achieve data traceability and data security is a technical problem that needs to be solved. Summary of the Invention
[0005] The technical task of the present invention is to address the above shortcomings and provide a government data sharing, exchange and traceability method and system based on data watermarks to solve the technical problems of how to achieve data traceability and data security in the process of government data sharing and exchange.
[0006] In a first aspect, the present invention provides a method for tracing the source of government data sharing, exchange, and verification based on data watermarks, comprising the following steps:
[0007] Data application: After the data provider reviews the data resource application submitted by the data user through the government data sharing platform, the government data sharing platform authorizes the data resource based on the data user, data provider, and data resource information, and generates resource authorization information;
[0008] Data encryption: The government data sharing platform uses the authorized resource information as a parameter to set the watermark name and generate the corresponding key. Based on the key and the watermark embedding algorithm, the watermark information is embedded into the original data in the source database of the data provider to generate watermarked data. The watermarked data is then distributed to the target database of the data user. The mapping relationship between the watermark name, key, and resource authorization information is stored in the government data sharing platform.
[0009] Data traceability: The key is extracted from the watermarked data through the watermark extraction algorithm, and the corresponding resource authorization information is found based on the mapping relationship between the watermark name, key and resource authorization information. Based on the resource authorization information, the corresponding data provider and data user are found.
[0010] Preferably, the application information in the data resource application includes data user information, data usage scenario, application basis and data call frequency.
[0011] Preferably, when watermark information is embedded into original data based on a key and through a watermark embedding algorithm to generate watermarked data, for the original data in the source database of the data provider, the data type and data format of each attribute of the original data are identified, and the rules are adapted according to the sensitive type. The data of one or more rows that meet the sensitive type are changed, and the changed data maintains the same type and format as the original data.
[0012] Preferably, the watermark information is embedded into the original data by a watermark embedding algorithm based on a key to generate watermarked data, including the following steps:
[0013] For the original data in the source database of the data provider, identify the valid columns that can be watermarked, identify the sensitive types of the valid columns, and locate the watermark position using random sampling;
[0014] For the located data, select a certain data to modify, and after the modification, the basic characteristics of the overall data remain consistent.
[0015] In a second aspect, the present invention provides a government data sharing, exchange and traceability system based on data watermarking, comprising a data application module, a data encryption module and a data traceability module configured on a government data sharing platform;
[0016] The data application module is used to perform the following operations: support data users to submit data resource applications to the government data sharing platform, support data providers to review data resources submitted by data users through the government data sharing platform, authorize data resources based on data users, data providers and data resource information through the government data sharing platform, and generate resource authorization information;
[0017] The data encryption module is used to perform the following: using the government data sharing platform to set the watermark name as a parameter using the authorized resource information and generate a corresponding key; for the original data in the source database of the data provider, embedding the watermark information into the original data based on the key and using the watermark embedding algorithm to generate watermarked data; distributing the watermarked data to the target database of the data user; and storing the mapping relationship between the watermark name, key and resource authorization information in the government data sharing platform;
[0018] The data traceability module is used to perform the following: extract the key from the watermarked data through the watermark extraction algorithm, find the corresponding resource authorization information based on the mapping relationship between the watermark name, key and resource authorization information, and find the corresponding data provider and data user based on the resource authorization information.
[0019] Preferably, the application information in the data resource application includes data user information, data usage scenario, application basis and data call frequency.
[0020] Preferably, when watermark information is embedded into original data to generate watermarked data through a watermark embedding algorithm based on a key, for the original data in the source database of the data provider, the data encryption module is used to perform the following: identify the data type and data format of each attribute of the original data, adapt the rules according to the sensitive type, and change the data of one or more rows that meet the sensitive type, so that the changed data maintains the same type and format as the original data.
[0021] Preferably, the data encryption module is configured to perform the following steps to embed watermark information into original data based on a key and using a watermark embedding algorithm to generate watermarked data:
[0022] For the original data in the source database of the data provider, identify the valid columns that can be watermarked, identify the sensitive types of the valid columns, and locate the watermark position using random sampling;
[0023] For the located data, select a certain data to modify, and after the modification, the basic characteristics of the overall data remain consistent.
[0024] The data watermark-based government data sharing, exchange and traceability method and system of the present invention have the following advantages:
[0025] 1. Data traceability and rapid identification of risky parties: Data flows carry significant risks. When data leaks and thefts occur, data watermarks can help users quickly identify the perpetrators, identify who leaked the data, when, and what was leaked, ensuring secure data sharing.
[0026] 2. Reduce data sharing risks and promote data exchange, sharing and collaboration: The application of data watermark traceability in sharing and exchange reduces the risks of data sharing within various industry departments, promotes mutual cooperation between industry departments, and provides security for the circulation and utilization of data. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0028] The present invention will be further described below with reference to the accompanying drawings.
[0029] Figure 1 This is a flowchart of Example 1, a method for sharing, exchanging and tracing government data based on data watermarks. DETAILED DESCRIPTION
[0030] The present invention will be further described below with reference to the accompanying drawings and specific embodiments so that those skilled in the art can better understand the present invention and implement it. However, the embodiments given are not intended to limit the present invention. Unless there is a conflict, the embodiments of the present invention and the technical features in the embodiments may be combined with each other.
[0031] The embodiments of the present invention provide a government data sharing, exchange and traceability method and system based on data watermarks, which are used to solve the technical problems of how to achieve data traceability and data security in the process of government data sharing and exchange.
[0032] Example 1: The present invention provides a government data sharing, exchange and traceability method based on data watermarks, which includes three steps: data application, data encryption and data traceability.
[0033] Step S100 Data application: After the data provider reviews the data resource application submitted by the data user through the government data sharing platform, the government data sharing platform authorizes the data resource based on the data user, data provider and data resource information, and generates resource authorization information.
[0034] The application information in the data resource application includes data user information, data usage scenarios, application basis and data call frequency.
[0035] The data user selects the data resources to be applied for and fills in the application information, including data user information, usage scenarios, application basis, data call frequency and other information. After the data application is submitted, the data provider will review the application. After the review is passed, the government data sharing platform will generate resource authorization information appKey based on the data user, data provider and data resource information. The resource authorization information appKey uniquely determines the data resources that the data user can call.
[0036] Step S200 data encryption: The government data sharing platform uses the authorized resource information as a parameter to set the watermark name and generates a corresponding key. For the original data in the source database of the data provider, the watermark information is embedded in the original data based on the key and through the watermark embedding algorithm to generate watermarked data. The watermarked data is distributed to the target database of the data user. The mapping relationship between the watermark name, key and resource authorization information is stored in the government data sharing platform.
[0037] In this embodiment, when watermark information is embedded into original data using a watermark embedding algorithm based on a key to generate watermarked data, the data type and data format of each attribute of the original data in the source database of the data provider are identified, and rules are adapted according to the sensitive type. The data of one or more rows that meet the sensitive type are modified, and the modified data maintains the same type and format as the original data. The specific steps are as follows:
[0038] (1) For the original data in the source database of the data provider, identify the valid columns to which watermarks can be added, identify the sensitive types of the valid columns, and locate the watermark position by random sampling;
[0039] (2) For the located data, select a certain data to modify, and after the modification, the basic characteristics of the overall data remain consistent.
[0040] In this embodiment, a watermark embedding function is added to the government data sharing platform, and the resource authorization information appKey is used as a parameter to set the watermark name. Upon receiving the instruction, the government data sharing platform will automatically generate a key internally, and the key is invisible.
[0041] The generated key controls the data provider's source database, embedding the watermark information into the original data through a watermark embedding algorithm, ultimately producing watermarked data. The watermark uses a pseudo-row watermark. The watermark embedding function automatically identifies the data type and format of each attribute in the source data, adapts rules based on its sensitive type, and then modifies one or more rows (randomly positioned) that match the sensitive type. The modified data retains the same type and format as the original data.
[0042] The specific method is to first identify valid columns suitable for watermarking and their sensitive types, then locate the watermark position using random sampling. Within the located data, a specific bit is modified, maintaining the consistency of the underlying features of the overall data. For example, an ID card can be automatically identified, confirming that not all locations are suitable for modification. The modification is performed by selecting the appropriate modifiable bits, maintaining the same format as the original data, and keeping the check digit accurate. This watermark is embedded in a dispersed manner, making it difficult to detect.
[0043] The watermarked data can be exchanged and distributed through the government data sharing platform. It can be distributed in the form of files or to the target database of the data user.
[0044] Step S300: Data tracing: Extract the key from the watermarked data through the watermark extraction algorithm, find the corresponding resource authorization information based on the mapping relationship between the watermark name, key and resource authorization information, and find the corresponding data provider and data user based on the resource authorization information.
[0045] This embodiment uses the data watermark traceability management function to extract the corresponding key through the watermark extraction algorithm of the data, and finds the corresponding watermark name through the corresponding key. Based on the watermark name, the authorization information appKey can be found, thereby finding the corresponding job and information such as the provider and user, and then tracing the source to determine the final leakage subject and hold them accountable.
[0046] In the method disclosed in the present application, watermark information is hidden in the data after government data sharing and exchange. It includes two parts: watermark embedding and watermark extraction. During the exchange process, watermarks are embedded in the data currently being exchanged, and watermarks can be extracted from the data after exchange, thus realizing the embedding of different watermarks for the same data according to different users.
[0047] Example 2: The present invention provides a government data sharing, exchange and traceability system based on data watermarks, including a data application module, a data encryption module and a data traceability module configured on a government data sharing platform.
[0048] The data application module is used to perform the following: support data users to submit data resource applications to the government data sharing platform, support data providers to review the data resources submitted by data users through the government data sharing platform, authorize data resources based on data users, data providers and data resource information through the government data sharing platform, and generate resource authorization information.
[0049] The application information in the data resource application includes data user information, data usage scenarios, application basis and data call frequency.
[0050] The data user selects the data resources to be applied for and fills in the application information, including data user information, usage scenarios, application basis, data call frequency and other information. After the data application is submitted, the data provider will review the application. After the review is passed, the government data sharing platform will generate resource authorization information appKey based on the data user, data provider and data resource information. The resource authorization information appKey uniquely determines the data resources that the data user can call.
[0051] The data encryption module is used to perform the following: through the government data sharing platform, the authorized resource information is used as a parameter to set the watermark name and generate the corresponding key. For the original data in the source database of the data provider, the watermark information is embedded in the original data based on the key and the watermark embedding algorithm to generate watermarked data. The watermarked data is distributed to the target database of the data user. The mapping relationship between the watermark name, key and resource authorization information is stored in the government data sharing platform.
[0052] In this embodiment, when watermark information is embedded into original data using a watermark embedding algorithm based on a key to generate watermarked data, the data type and data format of each attribute of the original data in the source database of the data provider are identified, and rules are adapted according to the sensitive type. The data of one or more rows that meet the sensitive type are modified, and the modified data maintains the same type and format as the original data. The specific steps are as follows:
[0053] (1) For the original data in the source database of the data provider, identify the valid columns to which watermarks can be added, identify the sensitive types of the valid columns, and locate the watermark position by random sampling;
[0054] (2) For the located data, select a certain data to modify, and after the modification, the basic characteristics of the overall data remain consistent.
[0055] In this embodiment, a watermark embedding function is added to the government data sharing platform, and the resource authorization information appKey is used as a parameter to set the watermark name. Upon receiving the instruction, the government data sharing platform will automatically generate a key internally, and the key is invisible.
[0056] The generated key controls the data provider's source database, embedding the watermark information into the original data through a watermark embedding algorithm, ultimately producing watermarked data. The watermark uses a pseudo-row watermark. The watermark embedding function automatically identifies the data type and format of each attribute in the source data, adapts rules based on its sensitive type, and then modifies one or more rows (randomly positioned) that match the sensitive type. The modified data retains the same type and format as the original data.
[0057] The specific method is to first identify valid columns suitable for watermarking and their sensitive types, then locate the watermark position using random sampling. Within the located data, a specific bit is modified, maintaining the consistency of the underlying features of the overall data. For example, an ID card can be automatically identified, confirming that not all locations are suitable for modification. The modification is performed by selecting the appropriate modifiable bits, maintaining the same format as the original data, and keeping the check digit accurate. This watermark is embedded in a dispersed manner, making it difficult to detect.
[0058] The watermarked data can be exchanged and distributed through the government data sharing platform. It can be distributed in the form of files or to the target database of the data user.
[0059] The data traceability module is used to perform the following: extract the key from the watermarked data through the watermark extraction algorithm, find the corresponding resource authorization information based on the mapping relationship between the watermark name, key and resource authorization information, and find the corresponding data provider and data user based on the resource authorization information.
[0060] This embodiment uses the data watermark traceability management function to extract the corresponding key through the watermark extraction algorithm of the data, and finds the corresponding watermark name through the corresponding key. Based on the watermark name, the authorization information appKey can be found, thereby finding the corresponding job and information such as the provider and user, and then tracing the source to determine the final leakage subject and hold them accountable.
[0061] In the system disclosed in this application, watermark information is hidden in the data after government data sharing and exchange. It includes two parts: watermark embedding and watermark extraction. During the exchange process, watermarks are embedded in the data currently being exchanged, and watermarks can be extracted from the data after exchange, thus realizing the embedding of different watermarks for the same data according to different users.
[0062] The above is a detailed introduction to the government data sharing, exchange and traceability method and system based on data watermarks provided by the present invention. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for general technical personnel in this field, based on the ideas of the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.
Claims
1. A data watermark-based government data sharing, exchange and provenance tracing method, characterized in that: The steps include: Data application: After the data provider reviews the data resource application submitted by the data user through the government data sharing platform, the government data sharing platform authorizes the data resource based on the data user, data provider, and data resource information, and generates resource authorization information; Data encryption: The government data sharing platform uses the authorized resource information as a parameter to set the watermark name and generate the corresponding key. Based on the key and the watermark embedding algorithm, the watermark information is embedded into the original data in the source database of the data provider to generate watermarked data. The watermarked data is then distributed to the target database of the data user. The mapping relationship between the watermark name, key, and resource authorization information is stored in the government data sharing platform. Data traceability: The key is extracted from the watermarked data through the watermark extraction algorithm, and the corresponding resource authorization information is found based on the mapping relationship between the watermark name, key and resource authorization information. Based on the resource authorization information, the corresponding data provider and data user are found.
2. The government data sharing, exchange and traceability method based on data watermark according to claim 1 is characterized in that: The application information in the data resource application includes data user information, data usage scenarios, application basis and data call frequency.
3. The government data sharing, exchange and traceability method based on data watermark according to claim 1 is characterized in that: When watermark information is embedded into original data based on a key through a watermark embedding algorithm to generate watermarked data, for the original data in the source database of the data provider, the data type and data format of each attribute of the original data are identified, and rules are adapted according to the sensitive type. Data is changed for one or more rows that meet the sensitive type, and the changed data maintains the same type and format as the original data.
4. The government data sharing, exchange and traceability method based on data watermark according to claim 3 is characterized in that: Based on the key, the watermark information is embedded into the original data through the watermark embedding algorithm to generate watermarked data, including the following steps: For the original data in the source database of the data provider, identify the valid columns that can be watermarked, identify the sensitive types of the valid columns, and locate the watermark position using random sampling; For the located data, select a certain data to modify, and after the modification, the basic characteristics of the overall data remain consistent.
5. A government data sharing, exchange and traceability system based on data watermark, characterized by: It includes data application module, data encryption module and data traceability module configured on the government data sharing platform; The data application module is used to perform the following operations: support data users to submit data resource applications to the government data sharing platform, support data providers to review data resources submitted by data users through the government data sharing platform, authorize data resources based on data users, data providers and data resource information through the government data sharing platform, and generate resource authorization information; The data encryption module is used to perform the following: using the government data sharing platform to set the watermark name as a parameter using the authorized resource information and generate a corresponding key; for the original data in the source database of the data provider, embedding the watermark information into the original data based on the key and using the watermark embedding algorithm to generate watermarked data; distributing the watermarked data to the target database of the data user; and storing the mapping relationship between the watermark name, key and resource authorization information in the government data sharing platform; The data traceability module is used to perform the following: extract the key from the watermarked data through the watermark extraction algorithm, find the corresponding resource authorization information based on the mapping relationship between the watermark name, key and resource authorization information, and find the corresponding data provider and data user based on the resource authorization information.
6. The government data sharing, exchange and traceability system based on data watermark according to claim 5 is characterized in that: The application information in the data resource application includes data user information, data usage scenarios, application basis and data call frequency.
7. The government data sharing, exchange and traceability system based on data watermark according to claim 5 is characterized in that: When watermark information is embedded into original data to generate watermarked data through a watermark embedding algorithm based on a key, for the original data in the source database of the data provider, the data encryption module is used to perform the following: identify the data type and data format of each attribute of the original data, adapt the rules according to the sensitive type, and change the data of one or more rows that meet the sensitive type, so that the changed data maintains the same type and format as the original data.
8. The government data sharing, exchange and traceability system based on data watermark according to claim 7 is characterized in that: The data encryption module is used to perform the following steps to embed watermark information into original data based on a key and using a watermark embedding algorithm to generate watermarked data: For the original data in the source database of the data provider, identify the valid columns that can be watermarked, identify the sensitive types of the valid columns, and locate the watermark position using random sampling; For the located data, select a certain data to modify, and after the modification, the basic characteristics of the overall data remain consistent.
Citation Information
Patent Citations
A cloud manufacturing user data management and control method based on labels
CN103618693A
File data circulation security system based on block chain technology
CN119442321A