Multi-agent collaborative data authorization operation management method and system
Through edge hierarchical verification, layered encryption transmission and smart contract dynamic authorization technology, the security and efficiency problems in traditional data authorization operation and management are solved, and the efficient and secure collaborative management of scientific research data is realized, and the dynamic authorization needs of diverse data application scenarios are adapted to the dynamic authorization needs.
Patent Information
- Application Number
- CN202510658197.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-05-21
AI Technical Summary
The traditional data authorization operation management methods have problems such as weak data security protection, cumbersome authorization processes, and inefficient cross-subject collaboration. Especially in diversified data application scenarios, it is difficult to meet the dynamic authorization needs, and permission management lacks flexibility and real-timeness.
We adopt edge hierarchical verification, layered encryption transmission, and dynamic smart contract authorization technologies, and obtain scientific research data for edge hierarchy and desensitization, generate encryption request packets and perform identity verification, and use smart contracts to generate authorization instructions, perform data hierarchical decryption and weight sorting, and realize dynamic authorization and collaborative management.
It improves the efficiency and accuracy of scientific research data authorization operation management, enhances data security, adapts to the needs of different scientific research data authorization operation management systems, promotes complementary advantages among different scientific research subjects, saves resources, and improves work efficiency.
Smart Images

Figure CN120238368A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of scientific research data management, and particularly to a multi-agent collaborative data authorization operation management method and system. Background Art
[0002] Driven by the wave of digital transformation, data collaboration and sharing among multiple agents have become the core driving forces for scientific research innovation and industrial upgrading. Especially for scientific research data, its efficient and secure authorization operation management not only concerns the transformation efficiency of scientific research achievements, but also has far-reaching significance for enhancing scientific and technological innovation capabilities and promoting cross-field collaborative development.
[0003] However, traditional data authorization operation management methods generally have problems such as weak data security protection, cumbersome authorization processes, and low cross-agent collaboration efficiency. For example, there is a lack of effective classification and verification mechanisms during data collection and transmission, which easily leads to the leakage of sensitive information; a single encryption storage method is difficult to adapt to diverse data application scenarios and cannot meet the requirements of dynamic authorization; at the same time, the permission management between data demanders and providers lacks flexibility and real-time nature, restricting data sharing efficiency. In recent years, with the development of new technologies such as edge computing, blockchain, and smart contracts, new solutions have been provided for data authorization operation management. The present invention proposes a multi-agent collaborative data authorization operation management method and system, which effectively overcomes the deficiencies of traditional technologies by integrating technologies such as edge classification verification, hierarchical encrypted transmission, and smart contract dynamic authorization. It not only realizes the security control of the entire process of scientific research data from collection, transmission to use, but also improves the data collaboration efficiency among multiple agents through a dynamic authorization mechanism, providing an innovative solution for the compliant and efficient operation of scientific research data, and having important practical value for promoting the optimal allocation and in-depth utilization of data resources in the scientific research field. Summary of the Invention
[0004] The object of the present invention is to provide a multi-agent collaborative data authorization operation management method and system.
[0005] To achieve the above object, the present invention is implemented according to the following technical solutions: The present invention includes the following steps: Obtain scientific research data of a scientific research institution and perform edge classification, and perform edge verification and desensitization on the classified scientific research data to obtain desensitized shared data; the edge verification includes edge comparison and review by a regulatory unit; Encrypt and transmit the desensitized shared data to a cloud sharing platform, determine the storage path according to the data type and data use, perform hierarchical encryption according to the project stage, and generate an upload log; A scientific research institution in need of data generates an encrypted request packet, performs identity verification and execution environment verification, and screens a scientific research institution providing data according to the encrypted request packet; Joint decisions are made by the scientific research institutions providing the data to generate an intelligent contract for dynamic authorization to generate authorization instructions and authorization logs, the authorization instructions are verified, and the data channel permissions are enabled to determine the accessed data; The accessed data is decrypted in layers to obtain collaborative authorization data, the collaborative authorization data is weighted and sorted according to the decryption level and data usage, and the scientific research institutions in need of data access the and download the collaborative authorization data according to the weighted sorting and update the access log.
[0006] Further, the method for obtaining desensitized shared data includes: Determine the project stage corresponding to the scientific research data according to the data dimension and time series of the scientific research data, process the metadata of the scientific research data using the principal component analysis method to obtain metadata features, and match the subject categories according to the metadata features; Perform multi-modal parsing on the original scientific research data to obtain structured scientific research data and unstructured scientific research data, input the unstructured scientific research data into the bag-of-words model to obtain text vectors, use a hierarchical weight matrix to transform the text vectors into sensitive weight vectors and value weight vectors, obtain the scientific research data score according to the structured data and the corresponding sensitive weight vectors and value weight vectors, use a hierarchical decision tree to determine the scientific research data level of the scientific research data score, and use the project stage, subject category, and scientific research data level as scientific research data labels; Perform edge comparison on the classified scientific research data and the historical data provided by the corresponding scientific research institutions, define the scientific research data that meets the edge comparison requirements as the data to be desensitized, encrypt and transmit the data that does not meet the edge comparison requirements to the regulatory agency for manual review, the regulatory agency transmits the review result back to the original port, define the scientific research data that passes the review as the data to be desensitized, and desensitize the data to be desensitized to obtain desensitized shared data; the edge comparison includes subject category comparison and historical statistical data comparison; the historical statistical data comparison includes skewness comparison, mean comparison, and data volume comparison; the desensitized shared data covers the project establishment stage, experimental stage, verification stage, and conclusion stage; The specific steps of the encrypted transmission are as follows: Generate the NIST P-256 elliptic curve and the reverse ECDH key exchange to generate the master key MasterKey, and use the HKDF-SHA3-256 algorithm to expand the master key to generate the session key According to the session key Encrypt the data, encrypt the session key according to the public key of the regulatory agency, and generate a composite verification label based on the data encryption and the session key encryption result 、 Generate a composite verification label The expression is: , , , ; wherein is the key extraction function, is the salt value, is the context information including timestamp, device fingerprint and project number, is the data encrypted with the session key ciphertext, is the Advanced Encryption Standard Galois Mix algorithm, is the session key encrypted with the public key of the regulatory agency ciphertext, is the efficient hybrid encryption scheme, is the key-based hash message authentication code hybrid BLAKE2s encryption algorithm, is the session key truncated generated key; The steps of obtaining the desensitized shared data by data desensitization are specifically as follows: using differential privacy protection to process numerical data, using the BERT-Mask technology to process text data, adding horizontal association constraints, calibrating the desensitized statistics with the utility loss compensation value, and performing desensitization effect verification; the desensitization effect verification includes privacy protection strength verification, data utility retention verification and temporal feature retention The expression for processing numerical data is: , wherein is the desensitized numerical scientific research data, is the scientific research data to be desensitized, is the Gaussian noise, is the query sensitivity, is the privacy budget, is the sensitivity level; The expression for the horizontal association constraint is: , wherein is the Pearson correlation coefficient of the i and j th desensitized numerical scientific research data, is the Pearson correlation coefficient of the i and j th numerical scientific research data to be desensitized.
[0007] Furthermore, the method for hierarchical encryption and generating an upload log includes: Determine the storage path according to the data type and data usage, specifically: NSFC subject classification code / data usage / data format; the data format includes raw data, statistical data, and analysis text; Determine the hierarchical encryption strategy according to the project stage, and perform hierarchical encryption on the desensitized scientific research data according to the hierarchical encryption strategy to obtain hierarchical open data, hierarchical encrypted data, and hierarchical keys. Store the hierarchical open data and hierarchical encrypted data in the cloud according to the storage path, and generate an upload log for the scientific research unit ID, scientific research data label, storage path, edge verification operation, encrypted transmission operation, and hierarchical encryption operation; The specific hierarchical encryption strategy includes: encrypting the metadata directory in the project establishment stage, encrypting the desensitized data set in the experimental stage, encrypting the original experimental data in the memory encryption bus verification stage, and encrypting the archived data in the project conclusion stage.
[0008] Furthermore, the method for screening data to provide scientific research units includes: The scientific research unit in need of data generates an encrypted request packet according to the subject information, historical cooperation information, and data requirements; the subject information includes institutional certificate, public key fingerprint, and hardware fingerprint; the historical cooperation information is provided by querying through the regulatory unit and includes evaluation index , number of collaborations and violation records ; the data requirements include usage classification, subject code, data type, and scientific research data level; Authenticate the scientific research unit according to the institutional certificate, and conduct a dynamic trust comprehensive assessment of the execution environment of the scientific research unit. The expression is: , , , where is the comprehensive trust assessment score, is the result of the hardware trusted root verification, obtained through the function, is the security status score of the runtime environment, obtained by processing the input features through a multi-layer perceptron , is the historical record information, including historical comprehensive trust assessment score, number and severity of historical security events, , , are the risk weight coefficients, adjusted according to the risk level through the Softmax function, represents a set of specific registers, is the expected value of the register status metric, mis the number of input features; Perform ontology semantic matching according to the subject code to calculate the semantic similarity, determine the domain-related scientific research institutions based on the semantic similarity, calculate the collaboration willingness of the domain-related scientific research institutions, and determine the scientific research institutions to be invited according to the collaboration willingness; Input the encrypted request packet into the dynamic multi-factor decision function to obtain the collaboration index between the data demand unit and the scientific research institutions to be invited. Screen and obtain the data-providing scientific research institutions according to the collaboration index. The expression of the collaboration index is: , , , , where is the collaboration index, is the credit weight, is the credit index, is the compliance weight, is the compliance rate, which is determined by the ratio of the number of successful audits to the total number of collaborations, is the resource weight, is the resource matching degree, which is determined by the ratio of the collaboration willingness of the scientific research institutions to be invited to the number of collaboration requirement items; The specific rules for the collaboration determination are as follows: when the collaboration index belongs to [0.9, 1], it is directly determined as the data-providing scientific research institution and given the priority resource scheduling permission. When the collaboration index belongs to [0.7, 0.9), it is determined as the data-providing scientific research institution and given the standard resource scheduling permission. When the collaboration index is less than 0.7, the regulatory unit reviews the additional conditions to determine the data-providing scientific research institution.
[0009] Further, the method for generating the authorization instruction and the authorization log includes: Match the preset contract template according to the data demand. Input the encrypted request packet of the data demand scientific research unit and the resource scheduling permissions of each data-providing scientific research unit into the preset contract template to dynamically generate contract terms, dynamically match collaboration conditions, and perform security reinforcement to obtain the smart contract; The steps for dynamically generating the contract terms include: generating access rules according to the data level and the resource scheduling permission, injecting the access rules as permission terms, converting the natural time into the blockchain block number to perform the timeliness conversion of the contract, and binding the compliance terms by automatically associating with the legal regulations library; The steps for dynamically matching the collaboration conditions include: adjusting the credit clause parameters according to the collaboration willingness and the collaboration index, and injecting the automatic termination clause according to the risk level by adopting the risk hedging mechanism; The security reinforcement includes automatic vulnerability scanning and formal verification; the formal verification includes non-tampering of timeliness clauses and data level permission control; Select a chain platform according to the infrastructure of the collaborating party, register the contract address and inform each assisting scientific research unit; Input the smart contract into the dynamic authorization instruction model to obtain authorization instructions and authorization logs; The dynamic authorization instruction model includes a timeliness instruction module, a path authorization instruction module, and a key application instruction module; the timeliness instruction module generates invalidation instructions through the blockchain block height of the timeliness clause of the smart contract; the path authorization instruction module generates scientific research data storage path instructions according to the permission clause of the smart contract; the key application instruction module generates hierarchical key application instructions according to the permission clause and the project stage; The authorization instruction is generated by hashing association of the invalidation instruction, the scientific research data storage path instruction, and the hierarchical key application instruction; the authorization log includes the ID of the collaborating scientific research unit, the generation timestamp, and the authorization instruction; Input the authorization instruction into the regulatory unit for verification. The regulatory unit verifies the digital signature, execution environment, and timeliness of the authorization instruction, and at the same time opens the data channel corresponding to the scientific research data storage path to obtain the accessed data and distribute the hierarchical key; the accessed data includes accessed public data and accessed encrypted data.
[0010] Further, a method for weight sorting of the collaborative authorization data includes: Use the hierarchical key to decrypt the accessed encrypted data layer by layer to obtain the accessed decrypted data, and the collaborative authorization data is composed of the accessed decrypted data and the accessed public data; Determine the data usage situation according to the access log, and calculate the weight score of the collaborative authorization data of each scientific research unit according to the data usage situation, decryption level, scientific research data level, and timeliness. The expression is: , , , where W is the weight score, is the level weight, is the data utility weight, D is the scientific research data level, L is the hierarchical decryption level of the accessed encrypted data, U is the data usage utility value, including the data contribution degree 、the achievement output rate 、the resource consumption ratio R 、the compliance risk value Risk and the historical collaborative usage times H , is the timeliness decay factor, is the time difference since the generation of scientific research data, is the high-value period threshold of scientific research data, is the decay period threshold of scientific research data; Sort the collaborative authorization data of each scientific research unit according to the weight score, and the scientific research unit in need of data accesses and downloads the collaborative authorization data according to the weight ranking; Update the statistical access log according to the access records, hierarchical decryption records, download records and corresponding timestamps of scientific research data of different scientific research units, and add the verification result of the authorization instruction to the statistical access log to update the privacy access log.
[0011] Furthermore, the upload log is only open to the regulatory unit; the authorization log is only open to the regulatory unit; the access log includes the statistical access log and the privacy access log; the statistical access log is open to all scientific research units; the privacy access log is only open to the regulatory unit.
[0012] In a second aspect, a multi-agent collaborative data authorization operation and management system includes: Data upload module: used to obtain the scientific research data of the scientific research unit and perform edge grading, perform edge verification and desensitization on the graded scientific research data to obtain desensitized shared data, encrypt and transmit the desensitized shared data to the cloud sharing platform, determine the storage path according to the data type and data usage, perform hierarchical encryption according to the project stage, and generate an upload log; Collaborative screening module: used to generate an encrypted request packet by the scientific research unit in need of data, perform identity verification and execution environment verification, and screen the scientific research unit providing data according to the encrypted request packet; Data authorization module: used to generate an intelligent contract through joint decision-making by the scientific research unit providing data, and input the intelligent contract into the dynamic authorization instruction model to obtain an authorization instruction and an authorization log; Data acquisition module: used to verify the authorization instruction, open the data channel permission to determine the accessed data, perform hierarchical decryption on the accessed data to obtain collaborative authorization data, perform weight ranking on the collaborative authorization data according to the decryption level and data usage, and the scientific research unit in need of data accesses and downloads the collaborative authorization data according to the weight ranking and generates an access log; Operation and management module: used to view, store and manage the upload log, the authorization log and the access log, and visually display the authorization operation status of scientific research data through visualization technology.
[0013] The beneficial effects of the present invention are: The present invention is a multi-agent collaborative data authorization operation and management method and system. Compared with the prior art, the present invention has the following technical effects: Through steps of data edge processing, data hierarchical encryption, screening data to provide scientific research institutions, generating smart contracts, dynamic authorization, and weight ranking, the present invention can improve the data preprocessing ability and enhance the model adaptability in the authorized operation management of scientific research data, can improve the efficiency and accuracy of the authorized operation management of scientific research data, optimize the technology of the authorized operation management of scientific research data, greatly save resources, improve work efficiency, provide more reliable technical support for the authorized operation management of scientific research data, help break data barriers, promote the complementary advantages between different scientific research entities, accelerate the process of scientific research projects, and can adapt to the management requirements of authorized operation of scientific research data in different scientific research data authorized operation management systems and different users, having certain universality. Brief Description of the Drawings
[0014] Figure 1 It is a step flowchart of a multi - subject collaborative data authorization operation management method of the present invention. Detailed Embodiments
[0015] The present invention will be further described below through specific embodiments. The illustrative embodiments and explanations of this invention are used to explain the present invention, but do not limit the present invention.
[0016] A multi - subject collaborative data authorization operation management method and system of the present invention include the following steps: As Figure 1 shown, in this embodiment, it includes the following steps: Obtain the scientific research data of scientific research institutions and conduct edge grading, and perform edge verification and desensitization on the graded scientific research data to obtain desensitized shared data; the edge verification includes edge comparison and review by regulatory units; Encrypt and transmit the desensitized shared data to the cloud sharing platform, determine the storage path according to the data type and data usage, perform hierarchical encryption according to the project stage, and generate an upload log; The scientific research institution in need of data generates an encrypted request packet, conducts identity verification and execution environment verification, and screens the scientific research institutions providing data according to the encrypted request packet; Joint decision - making by the scientific research institutions providing data generates a smart contract for dynamic authorization to generate an authorization instruction and an authorization log, verifies the authorization instruction, and opens the data channel permission to determine the accessed data; Perform hierarchical decryption on the accessed data to obtain collaboratively authorized data, perform weight ranking on the collaboratively authorized data according to the decryption level and data usage situation, and the scientific research institution in need of data accesses and downloads the collaboratively authorized data according to the weight ranking and updates the access log.
[0017] In this embodiment, the method for obtaining desensitized shared data includes: Determine the project stage corresponding to the scientific research data according to the data dimension and time series of the scientific research data, process the metadata of the scientific research data using the principal component analysis method to obtain metadata features, and match the subject categories according to the metadata features; Perform multi-modal parsing on the original scientific research data to obtain structured scientific research data and unstructured scientific research data. Input the unstructured scientific research data into the bag-of-words model to obtain text vectors, and use a hierarchical weight matrix to convert the text vectors into sensitive weight vectors and value weight vectors. Obtain the scientific research data score according to the structured data and the corresponding sensitive weight vectors and value weight vectors, and use a hierarchical decision tree to determine the scientific research data level corresponding to the scientific research data score. Use the project stage, subject category, and scientific research data level as scientific research data labels; Perform marginal comparison on the classified scientific research data and the historical data provided by the corresponding scientific research unit. Define the scientific research data that meets the marginal comparison requirements as data to be desensitized, encrypt and transmit the data that does not meet the marginal comparison requirements to the regulatory unit for manual review. The regulatory unit transmits the review result back to the original port, define the scientific research data that passes the review as data to be desensitized, and perform data desensitization on the data to be desensitized to obtain desensitized shared data; The marginal comparison includes subject category comparison and historical statistical data comparison; The historical statistical data comparison includes skewness comparison, mean comparison, and data volume comparison; The desensitized shared data covers the project establishment stage, experimental stage, verification stage, and conclusion stage; The specific steps of the encrypted transmission are as follows: Generate the NIST P-256 elliptic curve and the reverse ECDH key exchange to generate the master key MasterKey, and use the HKDF-SHA3-256 algorithm to expand the master key to generate the session key According to the session key Encrypt the data, encrypt the session key according to the public key of the regulatory agency, and generate a composite verification label based on the data encryption and the session key encryption result 、 The expression is: , , , , ; Where Is the key extraction function, Is the salt value, Is the context information including the timestamp, device fingerprint, and project number, Is the data The ciphertext encrypted using the session key , Is the Advanced Encryption Standard MixGalois algorithm, For the session key Adopt the public key of the regulatory agency The encrypted ciphertext, Is an efficient hybrid encryption scheme, Is a hybrid BLAKE2s encryption algorithm based on a key-based hash message authentication code For the session key The truncated generated key; The step of obtaining the desensitized shared data by data desensitization is specifically as follows: adopting differential privacy protection to process numerical data, adopting BERT-Mask technology to process text data, adding horizontal association constraints, calibrating the desensitized statistics with the utility loss compensation value, and performing desensitization effect verification; the desensitization effect verification includes privacy protection strength verification, data utility retention verification and temporal feature retention The expression for processing numerical data is: , Where Is the desensitized numerical scientific research data, Is the scientific research data to be desensitized, Is Gaussian noise, Is the query sensitivity, Is the privacy budget, Is the sensitivity level; The horizontal association constraint expression is: , Where Is the i And j Pearson correlation coefficient of the desensitized numerical scientific research data of the Is the i And j Pearson correlation coefficient of the numerical scientific research data to be desensitized of the In the actual evaluation, taking the national gene research project of Institution A that needs to share the cancer genome data of other scientific research units as the background; Taking the data of the clinical trial statistical table uploaded by Research Institution B as an example, the metadata feature matching discipline category is clinical medicine (NSFC-H02), and the hierarchical weight matrix converts the text vector composed of patient age and efficacy indicators into sensitive weight-PII and value weight-high value, and determines the scientific research data level as D2 through the hierarchical decision tree; Perform a comparison of the historical data mean. The current average age of the data is 52 years old (50 years old in the historical database, deviation <5%), and the discipline category matching degree is 90% (threshold 70%). It is directly defined as the data to be desensitized through verification; Taking the desensitization of the data "average age 52 years old" as an example, take the query sensitivity As 1, the privacy budget is 0.5, sensitivity level is 2 (consistent with the scientific research data level). After adding noise, the desensitized scientific research data is 53.2 ± 1.1. Add the corresponding horizontal constraint: the deviation of the correlation coefficient between the efficacy index and age ≤ 0.05 * 2 = 0.1; Adopt the utility loss compensation value (where the mean value of the desensitized data takes 50, the scientific research data volume n takes 100, the standard deviation of the desensitized data takes 12.5) to calibrate the desensitized statistic to obtain the calibrated data (49.22 + 53.2) / 2 = 51.21 ± 1.1, and verify through the privacy protection strength (using the anonymity k verification, ), verify the data utility retention (the JS divergence between the original data distribution P and the desensitized data distribution Q ), and verify the time series feature retention (the Fourier spectrum error , where is the DFT spectrum of the scientific research data to be desensitized, is the DFT spectrum of the desensitized scientific research data), and finally obtain the desensitized shared data "average age 51.21 ± 1.1 years old".
[0018] In this embodiment, the method for performing hierarchical encryption and generating an upload log includes: Determine the storage path according to the data type and data use, specifically: NSFC subject classification code / data use / data format; the data format includes raw data, statistical data, and analysis text; Determine the hierarchical encryption strategy according to the project stage, perform hierarchical encryption on the desensitized scientific research data according to the hierarchical encryption strategy to obtain hierarchical open data, hierarchical encrypted data, and hierarchical keys, store the hierarchical open data and hierarchical encrypted data in the cloud according to the storage path, and generate an upload log from the scientific research unit ID, scientific research data label, storage path, edge verification operation, encrypted transmission operation, and hierarchical encryption operation; The hierarchical encryption strategy specifically includes: encrypting the metadata directory at the project establishment stage, encrypting the desensitized data set at the experimental stage, encrypting the original experimental data at the memory encryption bus verification stage, and encrypting the archived data at the conclusion stage; In the actual evaluation, the data storage path is NSFC-A0103 / Clinical Trials / Original Data / Encrypted Gene Sequences. The metadata directory in the project establishment stage is encrypted using AES-128-GCM dynamic encryption and EdDSA digital signature. The desensitized dataset in the experimental stage is encrypted using CP-ABE attribute encryption, dynamic access control list, and differential privacy injection. The original experimental data in the memory encryption bus verification stage is encrypted using a trusted execution environment (TEE) sealed storage, Paillier homomorphic encryption. The archived data in the project conclusion stage is encrypted using NTRU quantum-resistant encryption, blockchain fingerprint evidence storage, and key sharding trusteeship; An upload log (Log ID: LOG_20240320_B_001) is generated from the scientific research unit ID (National Gene Research Center B / Digital Certificate Fingerprint / Hardware Fingerprint), scientific research data label (Experimental Stage / NSFC-A0103 / D2 / Original Data), storage path (NSFC-A0103 / Clinical Trials / Original Data / Encrypted Gene Sequences), edge verification operation (historical mean deviation 4% / skewness deviation 10% / disciplinary category matching degree 90% / automatically pass), encrypted transmission operation (master key: "ECDH-P256" / "Salt" / session key: "HKDF-SHA3-256") / C1: "AES-GCM-IV"-"Tag" / C2: "ECIES" / integrity label: "HMAC-BLAKE2s") and hierarchical encryption operation.
[0019] In this embodiment, the method for screening data to provide scientific research units includes: An encrypted request packet is generated by the scientific research unit in need of data according to the subject information, historical collaboration information, and data requirements; the subject information includes institutional certificate, public key fingerprint, and hardware fingerprint; the historical collaboration information is provided by querying through the regulatory unit and includes evaluation indexes , number of collaborations and violation records ; the data requirements include usage classification, subject coding, data type, and scientific research data level; The identity of the scientific research unit is verified according to the institutional certificate, and a dynamic trust comprehensive evaluation is performed on the execution environment of the scientific research unit. The expression is: , , , where is the comprehensive trust evaluation score, is the result of the hardware trusted root verification, obtained through the function, is the security status score of the runtime environment, through a multi-layer perceptron Process the input features Obtain as historical record information, including historical comprehensive trust assessment scores, the number and severity of historical security incidents 、 、 as risk weight coefficients, adjusted according to the risk level through the Softmax function represents a specific set of registers is the expected value of the register status metric m is the number of input features; Perform ontology semantic matching according to the subject code to calculate the semantic similarity, determine the domain-related scientific research institutions according to the semantic similarity, calculate the willingness to collaborate of the domain-related scientific research institutions, and determine the scientific research institutions to be invited according to the willingness to collaborate; Input the encrypted request packet into the dynamic multi-factor decision function to obtain the collaboration index between the data demand unit and the scientific research institutions to be invited. According to the collaboration index, perform collaboration judgment screening to obtain the data-providing scientific research institutions. The expression of the collaboration index is: , , , , where is the collaboration index, is the credit weight, is the credit index, is the compliance weight, is the compliance rate, determined by the ratio of the number of successful audits to the total number of collaborations, is the resource weight, is the resource matching degree, determined by the ratio of the willingness to collaborate of the scientific research institutions to be invited to the number of collaboration requirement items; The specific rules for the collaboration judgment are as follows: when the collaboration index belongs to [0.9, 1], it is directly determined as a data-providing scientific research institution and given priority resource scheduling authority. When the collaboration index belongs to [0.7, 0.9), it is determined as a data-providing scientific research institution and given standard resource scheduling authority. When the collaboration index is less than 0.7, the regulatory unit reviews the additional conditions to determine the data-providing scientific research institution; In actual evaluation, scientific research institution A requests to share the cancer genome data of other scientific research institutions (usage: targeted drug research and development). The input features include memory protection flags, process tree hashes, and system call frequencies, and obtain 、 , and take the risk weight coefficient as = 0.5, = 0.3, = 0.2, the comprehensive trust evaluation score is calculated to be 0.92 > the comprehensive trust evaluation threshold of 0.5, and the execution environment is verified and passed; Perform ontology semantic matching according to the discipline code NSFC-A0103 to calculate the semantic similarity (the ontology semantic matching includes OWL2 reasoning of the scientific research ontology library and dynamic weight calculation of discipline keywords IDF, with weights accounting for 0.6 and 0.4 respectively). The relevant semantics include cancer targeted therapy, genomic analysis, clinical trial management, etc. Determine the domain-related scientific research units B, C, D, E, F, G according to the semantic similarity (take the semantic similarity greater than 0.7 units); The willingness to collaborate is determined according to the centrality of the scientific research unit in the discipline collaboration network and the historical collaboration success rate. Calculate the willingness to collaborate of the domain-related scientific research units according to "0.6 * collaboration success rate + 0.3 / response time + 0.1 resource contribution rate". Select the determined scientific research units B, C, F to be invited according to the willingness to collaborate value of 0.75; Taking the calculation of the collaboration index with scientific research unit B using the generated encrypted request packet as an example, obtain the evaluation index and the number of collaborations and violation records and compliance rate and resource matching degree ), take the credit weight = 0.6, compliance weight = 0.25, resource weight = 0.15, calculate the collaboration index with scientific research unit B = 0.79, directly determine that scientific research unit B is the data-providing scientific research unit, and the corresponding collaboration determination is to give the standard resource scheduling permission; the standard resource scheduling permission does not exceed the data demand permission of the data-demanding scientific research unit and the standard data access permission of the data-providing scientific research unit; Calculate the collaboration index with scientific research unit C to be 0.91, directly determine it as the data-providing scientific research unit, and the corresponding collaboration determination is to give the priority resource scheduling permission; the priority resource scheduling permission can access all data types, scientific research data levels, and hierarchically encrypted scientific research data under the discipline code; Calculate the collaboration index with scientific research unit F to be 0.65, and it does not meet the collaboration conditions after being reviewed by the regulatory unit.
[0020] In this embodiment, the method for generating the authorization instruction and authorization log includes: Match the preset contract template according to the data demand, input the encrypted request packet of the data-demanding scientific research unit and the resource scheduling permissions of each data-providing scientific research unit into the preset contract template to dynamically generate contract terms, dynamically match collaboration conditions, and perform security reinforcement to obtain the smart contract; The steps of dynamically generating contract terms include: generating access rules based on data levels and resource scheduling permissions, injecting the access rules as permission terms, converting natural time into blockchain block numbers for contract timeliness conversion, and binding compliance terms by automatically associating with a legal and regulatory library; The steps of dynamically matching collaboration conditions include: adjusting credit term parameters according to collaboration willingness and collaboration index, and injecting an automatic termination clause according to the risk level by adopting a risk hedging mechanism; The security reinforcement includes automatic vulnerability scanning and formal verification; the formal verification includes non-tampering of timeliness terms and data level permission control; Select a chain platform according to the infrastructure of the collaborating party, write the contract address into the consortium chain directory service, and trigger a cross-chain notification protocol to inform all collaborating parties; Input the smart contract into the dynamic authorization instruction model to obtain authorization instructions and authorization logs; The dynamic authorization instruction model includes a timeliness instruction module, a path authorization instruction module, and a key application instruction module; the timeliness instruction module generates an expiration instruction through the blockchain block height of the smart contract timeliness terms; the path authorization instruction module generates a scientific research data storage path instruction according to the smart contract permission terms; the key application instruction module generates a hierarchical key application instruction according to the permission terms and project phases; The authorization instruction is generated by hashing and associating the expiration instruction, the scientific research data storage path instruction, and the hierarchical key application instruction; the authorization log includes the ID of the collaborating scientific research unit, the generation timestamp, and the authorization instruction; Input the authorization instruction into the regulatory unit for verification. The regulatory unit verifies the digital signature, execution environment, and timeliness of the authorization instruction, and at the same time opens a data channel corresponding to the scientific research data storage path to obtain the accessed data and distribute hierarchical keys; the accessed data includes accessed public data and accessed encrypted data; In the actual evaluation, match the preset contract template (commercial and scientific research demand template) according to the data requirements (targeted drug research and development), and input the encrypted request package of the data requirement scientific research unit A and the resource scheduling permissions of each data-providing scientific research unit (B is the standard resource scheduling permission, C is the priority resource scheduling permission) into the preset contract template to dynamically generate contract terms, dynamically match collaboration conditions, and perform security reinforcement to obtain a smart contract; Taking the generation of some smart contracts of Research Institution B as an example, timeliness clause: Convert the expected project duration of 3 months into 12,000 blockchain blocks. When the blockchain height reaches 12,000, the relevant permissions will automatically terminate; access rules: Through B, standard resource scheduling permissions are given. The project stage of A is the verification stage. It is determined that in the smart contract, Research Institution A can only access the corresponding hierarchical open data and hierarchical encrypted data of Research Institution B under the storage path through an authorization instruction (project establishment stage, experimental stage, and verification stage); conditions for the automatic termination clause: According to the risk level assessment, when the compliance risk value Risk of Research Institution A exceeds 0.5, or there are 3 consecutive violations during the collaboration process, the automatic termination clause is triggered. Once triggered, the smart contract will automatically terminate, the data access permission of Research Institution B will immediately stop, and at the same time, the regulatory unit will receive a notice for corresponding handling; After Research Institutions A and B generate the smart contract, the system selects a consortium chain platform according to the infrastructure of the collaborating parties. The system writes the contract address into the consortium chain directory service and triggers the cross-chain notification protocol to inform the corresponding collaborating parties. After receiving the notice, Research Institutions A and B update the local collaboration information record for subsequent data access operations according to the contract; Input the smart contract into the dynamic authorization instruction model to obtain the authorization instruction. Among them, the current blockchain height is 10,000 (the termination condition for parts B and C corresponds to a blockchain height of 12,000). The invalidation instruction includes the remaining blockchain termination height of 2,000 and the daily usage limit of 200. The path instruction includes the storage paths and access protocols of the corresponding data of Research Institutions B and C. The key instruction includes the instruction key type and the acquisition method. Combine the invalidation instruction, path instruction, and key instruction to form the authorization instruction; Generate an authorization log (ID: LOG_AUTH_20240320_A / B / C_001) from the participating party (requester certificate / participant ID), authorization details (data level, granted permissions, restricted conditions), environment verification (SGX authentication result), and blockchain deposit (transaction hash, block height); Input the authorization instruction into the regulatory unit for verification. The regulatory unit verifies the digital signature (passed) of the authorization instruction, the execution environment (SGX environment compliance), and timeliness (current block height 10,000 < block height limit 12,000, daily usage 120 < daily usage limit 200). At the same time, open the data channels corresponding to the scientific research data storage paths (Research Institution B: NSFC-A0103 / Cancer Treatment / Original Data / Encrypted Gene Sequences, Research Institution C: NSFC-A0103 / Cancer Treatment / Statistical Data / Therapeutic Efficacy Evaluation) to obtain the accessed data, and distribute hierarchical keys (Research Institution B distributes project establishment / experimental / verification level keys, and Research Institution C distributes keys for all levels);
[0021] In this embodiment, the method for weight sorting of the collaborative authorization data includes: Using a hierarchical key to perform hierarchical decryption on the accessed encrypted data to obtain accessed decrypted data, and the collaborative authorization data is composed of the accessed decrypted data and the accessed public data; Determining the data usage situation according to the access log, and calculating the weight scores of the collaborative authorization data of each scientific research unit according to the data usage situation, decryption level, scientific research data level, and timeliness. The expression is: , , , where W is the weight score, is the level weight, is the data utility weight, D is the scientific research data level, L is the hierarchical decryption level of the accessed encrypted data, U is the data usage utility value, including the data contribution degree , the achievement output rate , the resource consumption ratio R , the compliance risk value Risk, and the historical collaborative usage times H , is the timeliness decay factor, is the time difference since the scientific research data was generated, is the high-value period threshold of the scientific research data, is the decline period threshold of the scientific research data; Performing weight sorting on the collaborative authorization data of each scientific research unit according to the weight scores, and the scientific research unit in need of data accesses and downloads the collaborative authorization data according to the weight sorting; Updating the statistical access log according to the access records, hierarchical decryption records, download records, and corresponding timestamps of the scientific research data of different scientific research units, and adding the verification result of the authorization instruction to the statistical access log to update the privacy access log; In actual evaluation, taking the calculation of the weight score of the collaborative authorization data of scientific research unit B as an example, taking the level weight = 0.6, the data utility weight = 0.4, the high-value period threshold of the scientific research data = 30, the decline period threshold of the scientific research data = 60, substituting into the scientific research data level D=2 , the hierarchical decryption level of the accessed encrypted data L=3 , the data contribution degree = 0.8, the achievement output rate = 0.7, the resource consumption ratio R=0.6, compliance risk value Risk = 0.1 and the historical number of collaborative uses H=3 , the time difference since the generation of scientific research data = 10, calculate that the weight score of the collaborative authorization data of scientific research institution B is 2.74. Similarly, calculate that the weight score of the collaborative authorization data of scientific research institution C is 4.8. Sort the collaborative authorization data of each scientific research institution according to the weight score, and the data - demanding scientific research institution accesses and downloads the collaborative authorization data according to the weight ranking; Update the statistical access log of the corresponding data according to the access records (required subject type, access path, data level), hierarchical decryption records, download records and corresponding timestamps of scientific research institution A. Update the privacy access log according to the verification results of the authorization instructions of scientific research institution A (demander identifier, data fingerprint, SXG authentication hash, memory protection status).
[0022] In this embodiment, the upload log is only open to the regulatory unit; the authorization log is only open to the regulatory unit; the access log includes a statistical access log and a privacy access log; the statistical access log is open to all scientific research institutions; the privacy access log is only open to the regulatory unit.
[0023] In a second aspect, a multi - subject collaborative data authorization operation and management system includes: Data upload module: used to obtain the scientific research data of scientific research institutions and perform edge classification, perform edge verification and desensitization on the classified scientific research data to obtain desensitized shared data, encrypt and transmit the desensitized shared data to the cloud sharing platform, determine the storage path according to the data type and data use, perform hierarchical encryption according to the project stage and generate an upload log; Collaborative screening module: used to generate an encrypted request packet by the data - demanding scientific research institution, perform identity verification and execution environment verification, and screen the data - providing scientific research institutions according to the encrypted request packet; Data authorization module: used to generate an intelligent contract through the joint decision of the data - providing scientific research institutions, input the intelligent contract into the dynamic authorization instruction model to obtain an authorization instruction and an authorization log; Data acquisition module: used to verify the authorization instruction, open the data channel permission to determine the accessed data, perform hierarchical decryption on the accessed data to obtain collaborative authorization data, sort the collaborative authorization data according to the decryption level and data usage, and the data - demanding scientific research institution accesses and downloads the collaborative authorization data according to the weight ranking and generates an access log; Operation and management module: used to view, store and manage the upload log, the authorization log and the access log, and visually display the scientific research data authorization operation status through visualization technology.
[0024] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A multi-subject collaborative data authorization operation management method, characterized in that: The following steps are involved: S1. Obtain scientific research data from scientific research institutions and perform edge classification, and perform edge verification and desensitization on the classified scientific research data to obtain desensitized shared data; the edge verification includes edge comparison and review by regulatory authorities; S2. Encrypt and transmit the desensitized shared data to the cloud sharing platform, determine the storage path according to the data type and data usage, perform hierarchical encryption according to the project stage, and generate an upload log; S3. The data-demanding scientific research unit generates an encrypted request package, performs identity authentication and execution environment verification, and selects the data-providing scientific research unit based on the encrypted request package; S4. The data providing scientific research unit jointly decides to generate a smart contract for dynamic authorization to generate authorization instructions and authorization logs, verify the authorization instructions, and open the data channel authority to determine the accessed data; S5. Perform hierarchical decryption on the accessed data to obtain collaborative authorization data, and weight the collaborative authorization data according to the decryption level and data usage. The data-demanding scientific research unit accesses and downloads the collaborative authorization data according to the weight ranking and updates the access log.
2. According to the multi-agent collaborative data authorization operation management method of claim 1, it is characterized in that: The method for obtaining desensitized shared data includes: Determine the project stage corresponding to the scientific research data based on its data dimensions and time series, use principal component analysis to process the metadata of the scientific research data to obtain metadata features, and obtain the subject category based on metadata feature matching; The original scientific research data is subjected to multimodal analysis to obtain structured scientific research data and unstructured scientific research data. The unstructured scientific research data is input into the bag-of-words model to obtain a text vector. The text vector is converted into a sensitive weight vector and a value weight vector using a hierarchical weight matrix. The scientific research data score is obtained based on the structured data and the corresponding sensitive weight vector and value weight vector. A hierarchical decision tree is used to determine the scientific research data level of the scientific research data score, and the project stage, subject category and scientific research data level are used as scientific research data labels; The classified scientific research data are compared with the historical data provided by the corresponding scientific research units, and the scientific research data that meets the requirements of the edge comparison are defined as data to be desensitized. The data that does not meet the requirements of the edge comparison are encrypted and transmitted to the supervision unit for manual review. The supervision unit transmits the review results back to the original port, and defines the scientific research data that has passed the review as data to be desensitized. The data to be desensitized are desensitized to obtain desensitized shared data; the edge comparison includes subject category comparison and historical statistical data comparison; the historical statistical data comparison includes skewness comparison, mean comparison and data volume comparison; the desensitized shared data covers the project establishment stage, trial stage, verification stage and project conclusion stage; The specific steps of the encrypted transmission are: using the NIST P-256 elliptic curve and reverse ECDH key exchange to generate the master key MasterKey, using the HKDF-SHA3-256 algorithm to expand the master key to generate the session key , based on the session key Encrypt data, encrypt session key based on the public key of the regulatory agency, and encrypt the result based on data encryption and session key encryption , Generate composite verification tags , the expression is: , , , ; in is the key extraction function, is the salt value, is context information including timestamp, device fingerprint and project number. For data Using Session Key The encrypted ciphertext, is the Advanced Encryption Standard Hybrid Galois Algorithm, Session key Use the regulator’s public key The encrypted ciphertext, For an efficient hybrid encryption scheme, It is a key-based hash message authentication code hybrid BLAKE2s encryption algorithm. Session key Truncate the generated key; The steps of performing data desensitization to obtain desensitized shared data are specifically: using differential privacy protection to process numerical data, using BERT-Mask technology to process text data, adding horizontal association constraints, using utility loss compensation values to calibrate the desensitized statistics, and verifying the desensitization effect; the desensitization effect verification includes privacy protection strength verification, data utility preservation verification, and time series feature preservation verification. The expression for processing numerical data is: , in For desensitized numerical scientific research data, To anonymize the scientific research data, is Gaussian noise, To query sensitivity, Budget for privacy. is the sensitivity level; The horizontal association constraint expression is: , in For the i and j Pearson correlation coefficient of desensitized numerical scientific research data, For the i and j Pearson correlation coefficient of the numerical scientific research data to be desensitized.
3. According to the multi-agent collaborative data authorization operation management method of claim 1, it is characterized in that: The method for performing layered encryption and generating an upload log includes: Determine the storage path according to the data type and data usage, specifically: NSFC subject classification code / data usage / data format; the data format includes raw data, statistical data and analysis text; Determine the layered encryption strategy according to the project stage, perform layered encryption on the desensitized scientific research data according to the layered encryption strategy to obtain layered open data, layered encrypted data and layered keys, store the layered open data and layered encrypted data in the cloud according to the storage path, and generate an upload log for the scientific research unit ID, scientific research data label, storage path, edge verification operation, encrypted transmission operation and layered encryption operation; The layered encryption strategy specifically includes: encrypting the metadata directory in the project establishment stage, encrypting the desensitized data set in the experimental stage, encrypting the original experimental data in the memory encryption bus verification stage, and encrypting the archived data in the project conclusion stage.
4. According to the multi-agent collaborative data authorization operation management method of claim 1, it is characterized in that: The screening data provides methods for scientific research units, including: The data demand research unit generates an encrypted request package based on the subject information, historical collaboration information and data demand; the subject information includes the institution certificate, public key fingerprint and hardware fingerprint; the historical collaboration information is provided by the regulatory unit through query, including the evaluation index , Collaboration times and violation records ; The data requirements include usage classification, subject coding, data type and scientific research data level; The scientific research unit is authenticated based on the institution certificate, and the execution environment of the scientific research unit is dynamically trusted and comprehensively evaluated. The expression is: , , , in is the comprehensive trust assessment score, The hardware root of trust verification result is The function gets, Score the security status of the runtime environment through a multi-layer perceptron Processing input features get, It is historical record information, including historical comprehensive trust evaluation scores, historical security incident numbers and severity, , , is the risk weight coefficient, which is adjusted according to the risk level through the Softmax function. Represents a specific set of registers, is the expected value of the register state metric, m is the number of input features; Perform semantic matching ontologies according to subject codes to calculate semantic similarity, determine relevant scientific research units in the field based on semantic similarity, calculate the collaboration willingness of relevant scientific research units in the field, and determine the scientific research units to be invited based on the collaboration willingness; The encrypted request packet is input into the dynamic multi-factor decision function to obtain the collaboration index between the data demand unit and the research unit to be invited, and the data providing research unit is obtained by collaboration determination and screening based on the collaboration index. The collaboration index expression is: , , , , in is the collaboration index, is the credit weight, is the credit index, is the compliance weight, is the compliance rate, which is determined by the ratio of the number of successful audits to the total number of collaborations. is the resource weight, The resource matching degree is determined by the ratio of the collaboration willingness of the research institutes to be invited to collaborate and the number of collaboration requirements; The specific rules for collaboration determination are as follows: when the collaboration index belongs to [0.9, 1], it is directly determined as a data providing scientific research unit and is given priority resource scheduling authority; when the collaboration index belongs to [0.7, 0.9), it is determined as a data providing scientific research unit and is given standard resource scheduling authority; when the collaboration index is less than 0.7, the regulatory unit shall review the additional conditions and determine the data providing scientific research unit.
5. According to the multi-agent collaborative data authorization operation management method of claim 1, it is characterized in that: The method for generating an authorization instruction and an authorization log includes: According to the data demand matching preset contract template, the encrypted request package of the data demand research unit and the resource scheduling authority of each data providing research unit are input into the preset contract template to dynamically generate contract terms, dynamically match the collaboration conditions, and perform security reinforcement to obtain the smart contract; The step of dynamically generating contract terms includes: generating access rules according to data level and resource scheduling authority, injecting access rules into authority terms, converting natural time into blockchain block number to convert the timeliness of the contract, and binding compliance terms by automatically associating the legal and regulatory database; The step of dynamically matching cooperation conditions includes: adjusting credit clause parameters according to cooperation willingness and cooperation index, and injecting automatic termination clauses according to risk level by using risk hedging mechanism; The security reinforcement includes automatic vulnerability scanning and formal verification; the formal verification includes timeliness clauses that cannot be tampered with and data level permission control; Select a chain platform based on the infrastructure of the collaborating party, register the contract address and inform all assisting scientific research units; Input the smart contract into the dynamic authorization instruction model to obtain the authorization instruction and authorization log; The dynamic authorization instruction model includes a time limit instruction module, a path authorization instruction module, and a key application instruction module; the time limit instruction module generates an invalidation instruction through the blockchain block height of the smart contract time limit clause; the path authorization instruction module generates a scientific research data storage path instruction according to the smart contract authority clause; the key application instruction module generates a hierarchical key application instruction according to the authority clause and project stage; The authorization instruction is generated by hash association of the invalidation instruction, the scientific research data storage path instruction and the hierarchical key application instruction; the authorization log includes the collaborative scientific research unit ID, the generation timestamp and the authorization instruction; The authorization instruction is input into the regulatory unit for verification. The regulatory unit verifies the digital signature, execution environment and timeliness of the authorization instruction, and at the same time opens the data channel corresponding to the scientific research data storage path to obtain the accessed data and distributes the hierarchical key; the accessed data includes accessed public data and accessed encrypted data.
6. According to the multi-agent collaborative data authorization operation management method of claim 1, it is characterized in that: The method for weighting the collaborative authorization data includes: The access encrypted data is decrypted in layers using the hierarchical key to obtain the access decrypted data, and the access decrypted data and the access public data form the collaborative authorization data; The data usage is determined based on the access logs, and the weight score of the collaborative authorization data of each scientific research unit is calculated based on the data usage, decryption level, scientific research data level and timeliness. The expression is: , , , in W For weight scoring, is the level weight, is the data utility weight, D For scientific research data level, L Layered decryption levels for access to encrypted data, U Use utility value for data, including data contribution , output rate , resource consumption ratio R , compliance risk value Risk and historical collaboration usage times H , is the time-dependent attenuation factor, is the time difference from when the scientific research data was generated to now. is the high-value threshold of scientific research data, is the threshold of scientific research data decline period; The collaborative authorization data of each scientific research unit is ranked by weight according to the weight score, and the scientific research unit with data demand accesses and downloads the collaborative authorization data according to the weight ranking; The statistical access log is updated according to the access records, layered decryption records, download records and corresponding timestamps of scientific research data of different scientific research units, and the verification results of authorization instructions are added to the statistical access log to update the privacy access log.
7. According to the multi-agent collaborative data authorization operation management method of claim 1, it is characterized by: The uploaded log is only open to the supervisory unit; The authorization log is only open to regulatory units; the access log includes statistical access log and privacy access log; the statistical access log is open to all scientific research units; the privacy access log is only open to regulatory units.
8. A multi-agent collaborative data authorization operation management system, used to execute the method according to any one of claims 1 to 7, characterized in that: include: Data upload module: used to obtain scientific research data from scientific research units and perform edge classification, perform edge verification and desensitization on the classified scientific research data to obtain desensitized shared data, encrypt and transmit the desensitized shared data to the cloud sharing platform, determine the storage path according to the data type and data usage, perform hierarchical encryption according to the project stage, and generate an upload log; Collaborative screening module: used to generate an encrypted request package through the data demand scientific research unit, and perform identity authentication and execution environment verification, and screen the data providing scientific research unit according to the encrypted request package; Data authorization module: used to generate smart contracts through data provision for scientific research units to make joint decisions, and input the smart contracts into the dynamic authorization instruction model to obtain authorization instructions and authorization logs; Data acquisition module: used to verify the authorization instruction, open the data channel authority to determine the accessed data, perform hierarchical decryption on the accessed data to obtain collaborative authorization data, and weight the collaborative authorization data according to the decryption level and data usage. The data demand scientific research unit accesses and downloads the collaborative authorization data according to the weight ranking and generates an access log; Operation management module: used to view, store and manage the upload log, the authorization log and the access log, and to intuitively display the authorization operation status of scientific research data through visualization technology.
Citation Information
Patent Citations
Data access control method based on block chain
CN112257112A
Government affair alliance chain-based government affair data access control method and system
CN115442045A
Trusted authorization data sharing method based on distributed identity and alliance chain
CN117200966A
Multi-subject information sharing and exchanging method and device, electronic equipment and storage medium
CN118964316A
Cited By
Government affair data processing method, system and equipment and storage medium
CN120409972A
Authorized operation collaborative management system and method based on multi-source data
CN120874125A
A multi-source data-based authorized operation collaborative management system and method
CN120874125B
Multi-party collaborative digital management platform system for new energy project
CN120893968A
Online contract signing management method and system based on intelligent contract
CN120952706A