A multi-agent collaborative data authorization operation management method and system
Through edge hierarchical verification, hierarchical encryption and smart contract dynamic authorization technologies, security and efficiency issues in traditional data authorization operation and management are solved, and the secure and efficient collaboration and optimized configuration of scientific research data are achieved.
Patent Information
- Application Number
- CN202510658197.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2045-05-21
AI Technical Summary
The traditional data authorization operation management methods have weak data security protection, cumbersome authorization processes, and low cross-subject collaboration efficiency, which cannot meet the dynamic authorization needs, and lack of flexibility and real-time permission management, resulting in limited data sharing efficiency.
We use edge hierarchical verification, layered encryption transmission, and dynamic authorization of smart contracts. By obtaining scientific research data, we generate smart contracts for dynamic authorization, layered encryption according to data type and purpose, and coordinated authorization of data is achieved through weight sorting.
It realizes the security control of the entire process of scientific research data, improves the data collaboration efficiency between multiple subjects, optimizes the allocation and utilization of data resources, and adapts to the needs of different scientific research data authorization operation and management systems.
Smart Images

Figure CN120238368B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of scientific research data management, and in particular to a multi-agent collaborative data authorization operation management method and system. Background Art
[0002] Driven by the wave of digital transformation, data collaboration and sharing among multiple entities have become the core driving force for scientific research innovation and industrial upgrading, especially scientific research data. Its efficient and secure authorization and operation management is not only related to the transformation efficiency of scientific research results, but also has far-reaching significance for improving scientific and technological innovation capabilities and promoting cross-domain collaborative development.
[0003] However, traditional data authorization operation and management methods generally have problems such as weak data security protection, cumbersome authorization process, and low cross-subject collaboration efficiency. For example, there is a lack of effective classification and verification mechanism during data collection and transmission, which easily leads to sensitive information leakage; a single encryption storage method is difficult to adapt to diverse data application scenarios and cannot meet the needs of dynamic authorization; at the same time, the authority management between data demanders and providers lacks flexibility and real-time performance, which limits data sharing efficiency. In recent years, with the development of new technologies such as edge computing, blockchain, and smart contracts, new solutions have been provided for data authorization operation and management. The present invention proposes a multi-subject collaborative data authorization operation and management method and system, which effectively overcomes the shortcomings of traditional technologies by integrating edge hierarchical verification, layered encryption transmission, smart contract dynamic authorization and other technologies, and not only realizes the security management of scientific research data from collection, transmission to use, but also improves the data collaboration efficiency among multiple subjects through the dynamic authorization mechanism, providing an innovative solution for the compliance and efficient operation of scientific research data, and has important practical value in promoting the optimal configuration and in-depth utilization of data resources in the scientific research field. Summary of the Invention
[0004] The purpose of the present invention is to provide a multi-agent collaborative data authorization operation management method and system.
[0005] To achieve the above object, the present invention is implemented according to the following technical solutions:
[0006] The present invention comprises the following steps:
[0007] Obtain scientific research data from scientific research institutions and perform edge classification, and perform edge verification and desensitization on the classified scientific research data to obtain desensitized shared data; the edge verification includes edge comparison and review by regulatory authorities;
[0008] The desensitized shared data is encrypted and transmitted to the cloud sharing platform, the storage path is determined according to the data type and data usage, and hierarchical encryption is performed according to the project stage and an upload log is generated;
[0009] The data-demanding research unit generates an encrypted request package, performs identity authentication and execution environment verification, and selects the data-providing research unit based on the encrypted request package;
[0010] The data providing scientific research units jointly decide to generate smart contracts for dynamic authorization, generate authorization instructions and authorization logs, verify the authorization instructions, and open data channel permissions to determine the accessed data;
[0011] The accessed data is decrypted in layers to obtain collaborative authorization data, and the collaborative authorization data is weighted according to the decryption level and data usage. The data-demanding scientific research unit accesses and downloads the collaborative authorization data according to the weighted ranking and updates the access log.
[0012] Furthermore, the method for obtaining desensitized shared data includes:
[0013] Determine the project stage corresponding to the scientific research data based on its data dimensions and time series, use principal component analysis to process the metadata of the scientific research data to obtain metadata features, and obtain the subject categories based on metadata feature matching;
[0014] Perform multimodal analysis on the original scientific research data to obtain structured scientific research data and unstructured scientific research data. Input the unstructured scientific research data into the bag-of-words model to obtain text vectors. Use a hierarchical weight matrix to convert the text vectors into sensitivity weight vectors and value weight vectors. Based on the structured data and the corresponding sensitivity weight vectors and value weight vectors, obtain the scientific research data score. Use a hierarchical decision tree to determine the scientific research data level of the scientific research data score, and use the project stage, subject category and scientific research data level as scientific research data labels.
[0015] The classified scientific research data are compared with the historical data provided by the corresponding scientific research units at the edge. The scientific research data that meets the edge comparison requirements are defined as data to be desensitized. The data that does not meet the edge comparison requirements are encrypted and transmitted to the supervisory unit for manual review. The supervisory unit transmits the review results back to the original port, and the scientific research data that passes the review is defined as data to be desensitized. The data to be desensitized are desensitized to obtain desensitized shared data; the edge comparison includes subject category comparison and historical statistical data comparison; the historical statistical data comparison includes skewness comparison, mean comparison and data volume comparison; the desensitized shared data covers the project establishment stage, trial stage, verification stage and conclusion stage;
[0016] The specific steps of the encrypted transmission are: generating the master key MasterKey by generating the NIST P-256 elliptic curve and reverse ECDH key exchange, and expanding the master key by HKDF-SHA3-256 algorithm to generate the session key , based on the session key Encrypt data, encrypt session keys based on the public key of the regulatory agency, and encrypt the results based on data encryption and session key encryption 、 Generate composite verification tags , the expression is:
[0017] ,
[0018] ,
[0019] ,
[0020] ;
[0021] in is the key extraction function, is the salt value, is context information including timestamp, device fingerprint and project number, For data Using session keys The encrypted ciphertext, is the Advanced Encryption Standard Hybrid Galois Algorithm, Session key Using the regulator's public key The encrypted ciphertext, For an efficient hybrid encryption scheme, Hybrid BLAKE2s encryption algorithm for key-based hash message authentication code, Session key Truncate the generated key;
[0022] The steps of performing data desensitization to obtain desensitized shared data are specifically as follows: using differential privacy protection to process numerical data, using BERT-Mask technology to process text data, adding horizontal correlation constraints, using utility loss compensation values to calibrate the desensitized statistics, and verifying the desensitization effect; the desensitization effect verification includes privacy protection strength verification, data utility preservation verification, and time series feature preservation verification.
[0023] The expression for processing numerical data is:
[0024] ,
[0025] in For desensitized numerical scientific research data, To desensitize scientific research data, is Gaussian noise, To query sensitivity, Budget for privacy, is the sensitivity level;
[0026] The horizontal association constraint expression is:
[0027] ,
[0028] in For the i and j The Pearson correlation coefficient of the desensitized numerical scientific research data, For the i and j Pearson correlation coefficient of the numerical scientific research data to be desensitized.
[0029] Furthermore, the method for performing layered encryption and generating an upload log includes:
[0030] Determine the storage path based on the data type and data usage, specifically: NSFC subject classification code / data usage / data format; the data format includes raw data, statistical data, and analysis text;
[0031] Determine the layered encryption strategy based on the project phase, perform layered encryption on the desensitized scientific research data according to the layered encryption strategy to obtain layered open data, layered encrypted data, and layered keys, store the layered open data and layered encrypted data in the cloud according to the storage path, and generate an upload log for the scientific research unit ID, scientific research data label, storage path, edge verification operation, encrypted transmission operation, and layered encryption operation;
[0032] The layered encryption strategy specifically includes: encrypting the metadata directory in the project establishment stage, encrypting the desensitized data set in the experimental stage, encrypting the original experimental data in the memory encryption bus verification stage, and encrypting the archived data in the conclusion stage.
[0033] Furthermore, the method of providing the screening data to the scientific research unit includes:
[0034] The data demand research unit generates an encrypted request package based on the subject information, historical collaboration information and data demand; the subject information includes the institution certificate, public key fingerprint and hardware fingerprint; the historical collaboration information is provided by the regulatory unit through query, including the evaluation index , number of collaborations and violation records The data requirements include usage classification, subject coding, data type and scientific research data level;
[0035] Authenticate the scientific research unit based on the institution certificate and conduct a dynamic trust comprehensive assessment of the execution environment of the scientific research unit. The expression is:
[0036] ,
[0037] ,
[0038] ,
[0039] in is the comprehensive trust assessment score, The hardware root of trust verification result is passed The function gets, Score the security status of the runtime environment through a multi-layer perceptron Processing input features get, For historical record information, including historical comprehensive trust assessment scores, historical security incident numbers and severity, 、 、 is the risk weight coefficient, which is adjusted according to the risk level through the Softmax function. Represents a specific set of registers, is the expected value of the register state metric, m is the number of input features;
[0040] Perform semantic matching ontologies according to discipline codes to calculate semantic similarity, determine relevant research units in the field based on semantic similarity, calculate the collaboration willingness of relevant research units in the field, and determine research units to be invited based on the collaboration willingness;
[0041] The encrypted request packet is input into the dynamic multi-factor decision function to obtain the collaboration index between the data demand unit and the research unit to be invited. The data providing research unit is selected based on the collaboration index. The collaboration index expression is:
[0042] ,
[0043] ,
[0044] ,
[0045] ,
[0046] in is the collaboration index, is the credit weight, is the credit index, is the compliance weight, is the compliance rate, which is determined by the ratio of the number of successful audits to the total number of collaborations. is the resource weight, The resource matching degree is determined by the ratio of the collaboration willingness of the invited research institutes to the number of collaboration requirements;
[0047] The specific rules for collaboration determination are: when the collaboration index is [0.9, 1], it is directly determined to be a data providing scientific research unit and is given priority resource scheduling authority; when the collaboration index is [0.7, 0.9), it is determined to be a data providing scientific research unit and is given standard resource scheduling authority; when the collaboration index is less than 0.7, the supervisory unit will review the additional conditions and determine the data providing scientific research unit.
[0048] Furthermore, the method for generating the authorization instruction and the authorization log includes:
[0049] According to the data demand, the preset contract template is matched. The encrypted request package of the data-demanding scientific research unit and the resource scheduling authority of each data-providing scientific research unit are input into the preset contract template to dynamically generate contract terms, dynamically match the collaboration conditions, and perform security reinforcement to obtain a smart contract.
[0050] The steps of dynamically generating contract terms include: generating access rules based on data levels and resource scheduling permissions, injecting the access rules into permission terms, converting natural time into blockchain block numbers to convert the timeliness of the contract, and binding compliance terms by automatically associating with the legal and regulatory database;
[0051] The step of dynamically matching collaboration conditions includes: adjusting credit clause parameters according to collaboration willingness and collaboration index, and injecting automatic termination clauses according to risk levels using a risk hedging mechanism;
[0052] The security reinforcement includes automatic vulnerability scanning and formal verification; the formal verification includes timeliness clauses that cannot be tampered with and data level permission control;
[0053] Select a chain platform based on the collaborator's infrastructure, register the contract address and inform all cooperating scientific research units;
[0054] Input the smart contract into the dynamic authorization instruction model to obtain authorization instructions and authorization logs;
[0055] The dynamic authorization instruction model includes a time limit instruction module, a path authorization instruction module, and a key application instruction module; the time limit instruction module generates an expiration instruction based on the blockchain block height of the smart contract time limit clause; the path authorization instruction module generates a scientific research data storage path instruction based on the smart contract permission clause; the key application instruction module generates a hierarchical key application instruction based on the permission clause and project stage;
[0056] The authorization instruction is generated by hash association of the invalidation instruction, the scientific research data storage path instruction and the hierarchical key application instruction; the authorization log includes the collaborative scientific research unit ID, the generation timestamp and the authorization instruction;
[0057] The authorization instruction is input into the regulatory unit for verification. The regulatory unit verifies the digital signature, execution environment and timeliness of the authorization instruction, and at the same time opens the data channel corresponding to the scientific research data storage path to obtain the accessed data and distributes the hierarchical key; the accessed data includes accessed public data and accessed encrypted data.
[0058] Furthermore, the method for weighting the collaborative authorization data includes:
[0059] The access encrypted data is decrypted in layers using the layered key to obtain the access decrypted data, and the access decrypted data and the access public data form the collaborative authorization data;
[0060] The data usage is determined based on the access logs, and the weight score of the collaborative authorization data of each scientific research unit is calculated based on the data usage, decryption level, scientific research data level and timeliness. The expression is:
[0061] ,
[0062] ,
[0063] ,
[0064] in W For weight scoring, is the level weight, is the data utility weight, D For scientific research data level, L Layered decryption levels for accessed encrypted data, U Use utility value for data, including data contribution , output rate , resource consumption ratio R , compliance risk value Risk and historical collaboration usage times H , is the time-dependent attenuation factor, The time difference between the generation of scientific research data and the present. is the high-value threshold for scientific research data, is the threshold of scientific research data decline period;
[0065] The collaborative authorization data of each scientific research unit is ranked by weight according to the weight score, and the scientific research unit with data demand accesses and downloads the collaborative authorization data according to the weight ranking;
[0066] According to the access records, layered decryption records, download records and corresponding timestamps of scientific research data of different scientific research units, the statistical access log is updated, and the verification results of the authorization instructions are added to the statistical access log to update the privacy access log.
[0067] Furthermore, the upload log is only open to regulatory units; the authorization log is only open to regulatory units; the access log includes statistical access log and privacy access log; the statistical access log is open to all scientific research units; the privacy access log is only open to regulatory units.
[0068] In the second aspect, a multi-agent collaborative data authorization operation and management system includes:
[0069] Data upload module: used to obtain scientific research data from scientific research units and perform edge classification, perform edge verification and desensitization on the classified scientific research data to obtain desensitized shared data, encrypt and transmit the desensitized shared data to the cloud sharing platform, determine the storage path according to the data type and data usage, perform hierarchical encryption according to the project stage, and generate an upload log;
[0070] Collaborative screening module: used to generate an encrypted request package through the data demand research unit, perform identity authentication and execution environment verification, and screen the data providing research units based on the encrypted request package;
[0071] Data authorization module: used to generate smart contracts through data provided by scientific research units for joint decision-making, and input the smart contracts into the dynamic authorization instruction model to obtain authorization instructions and authorization logs;
[0072] Data acquisition module: used to verify the authorization instruction, open the data channel authority to determine the accessed data, perform layered decryption on the accessed data to obtain collaborative authorization data, and weight the collaborative authorization data according to the decryption level and data usage. The data-demanding scientific research unit accesses and downloads the collaborative authorization data according to the weight ranking and generates an access log;
[0073] Operation management module: used to view, store and manage the upload log, the authorization log and the access log, and intuitively display the authorization operation status of scientific research data through visualization technology.
[0074] The beneficial effects of the present invention are:
[0075] The present invention is a multi-agent collaborative data authorization operation management method and system. Compared with the existing technology, the present invention has the following technical effects:
[0076] The present invention can improve the data preprocessing capabilities and enhance the model adaptability in the authorization and operation management of scientific research data through data edge processing, data layered encryption, data screening and provision to scientific research units, generation of smart contracts, dynamic authorization and weight sorting steps, and can improve the efficiency and accuracy of the authorization and operation management of scientific research data. The optimization of the scientific research data authorization and operation management technology can greatly save resources and improve work efficiency, provide more reliable technical support for the authorization and operation management of scientific research data, help break down data barriers, promote the complementary advantages of different scientific research entities, accelerate the progress of scientific research projects, and can adapt to different scientific research data authorization and operation management systems and the management needs of scientific research data authorization operations of different users, and has a certain universality. BRIEF DESCRIPTION OF THE DRAWINGS
[0077] Figure 1 This is a flowchart of the steps of a multi-agent collaborative data authorization operation management method of the present invention. DETAILED DESCRIPTION
[0078] The present invention will be further described below through specific examples. The illustrative examples and descriptions of the present invention are used to explain the present invention but are not intended to limit the present invention.
[0079] The present invention provides a multi-agent collaborative data authorization operation management method and system, comprising the following steps:
[0080] like Figure 1 As shown, in this embodiment, the following steps are included:
[0081] Obtain scientific research data from scientific research institutions and perform edge classification, and perform edge verification and desensitization on the classified scientific research data to obtain desensitized shared data; the edge verification includes edge comparison and review by regulatory authorities;
[0082] The desensitized shared data is encrypted and transmitted to the cloud sharing platform, the storage path is determined according to the data type and data usage, and hierarchical encryption is performed according to the project stage and an upload log is generated;
[0083] The data-demanding research unit generates an encrypted request package, performs identity authentication and execution environment verification, and selects the data-providing research unit based on the encrypted request package;
[0084] The data providing scientific research units jointly decide to generate smart contracts for dynamic authorization, generate authorization instructions and authorization logs, verify the authorization instructions, and open data channel permissions to determine the accessed data;
[0085] The accessed data is decrypted in layers to obtain collaborative authorization data, and the collaborative authorization data is weighted according to the decryption level and data usage. The data-demanding scientific research unit accesses and downloads the collaborative authorization data according to the weighted ranking and updates the access log.
[0086] In this embodiment, the method for obtaining desensitized shared data includes:
[0087] Determine the project stage corresponding to the scientific research data based on its data dimensions and time series, use principal component analysis to process the metadata of the scientific research data to obtain metadata features, and obtain the subject categories based on metadata feature matching;
[0088] Perform multimodal analysis on the original scientific research data to obtain structured scientific research data and unstructured scientific research data. Input the unstructured scientific research data into the bag-of-words model to obtain text vectors. Use a hierarchical weight matrix to convert the text vectors into sensitivity weight vectors and value weight vectors. Based on the structured data and the corresponding sensitivity weight vectors and value weight vectors, obtain the scientific research data score. Use a hierarchical decision tree to determine the scientific research data level of the scientific research data score, and use the project stage, subject category and scientific research data level as scientific research data labels.
[0089] The classified scientific research data are compared with the historical data provided by the corresponding scientific research units at the edge. The scientific research data that meets the edge comparison requirements are defined as data to be desensitized. The data that does not meet the edge comparison requirements are encrypted and transmitted to the supervisory unit for manual review. The supervisory unit transmits the review results back to the original port, and the scientific research data that passes the review is defined as data to be desensitized. The data to be desensitized are desensitized to obtain desensitized shared data; the edge comparison includes subject category comparison and historical statistical data comparison; the historical statistical data comparison includes skewness comparison, mean comparison and data volume comparison; the desensitized shared data covers the project establishment stage, trial stage, verification stage and conclusion stage;
[0090] The specific steps of the encrypted transmission are: generating the master key MasterKey by generating the NIST P-256 elliptic curve and reverse ECDH key exchange, and expanding the master key by HKDF-SHA3-256 algorithm to generate the session key , based on the session key Encrypt data, encrypt session keys based on the public key of the regulatory agency, and encrypt the results based on data encryption and session key encryption 、 Generate composite verification tags , the expression is:
[0091] ,
[0092] ,
[0093] ,
[0094] ;
[0095] in is the key extraction function, is the salt value, is context information including timestamp, device fingerprint and project number, For data Using session keys The encrypted ciphertext, is the Advanced Encryption Standard Hybrid Galois Algorithm, Session key Using the regulator's public key The encrypted ciphertext, For an efficient hybrid encryption scheme, Hybrid BLAKE2s encryption algorithm for key-based hash message authentication code, Session key Truncate the generated key;
[0096] The steps of performing data desensitization to obtain desensitized shared data are specifically as follows: using differential privacy protection to process numerical data, using BERT-Mask technology to process text data, adding horizontal correlation constraints, using utility loss compensation values to calibrate the desensitized statistics, and verifying the desensitization effect; the desensitization effect verification includes privacy protection strength verification, data utility preservation verification, and time series feature preservation verification.
[0097] The expression for processing numerical data is:
[0098] ,
[0099] in For desensitized numerical scientific research data, To desensitize the scientific research data, is Gaussian noise, To query sensitivity, Budget for privacy, is the sensitivity level;
[0100] The horizontal association constraint expression is:
[0101] ,
[0102] in For the i and j The Pearson correlation coefficient of the desensitized numerical scientific research data, For the i and j Pearson correlation coefficient of the numerical scientific research data to be desensitized;
[0103] In the actual evaluation, the background is that the national genetic research project of Institution A needs to share cancer genome data from other research institutions;
[0104] Taking the clinical trial statistics data uploaded by research unit B as an example, the metadata feature matching discipline category is clinical medicine (NSFC-H02). The hierarchical weight matrix converts the text vector consisting of patient age and efficacy indicators into a sensitivity weight of -PII and a value weight of -high value. The hierarchical decision tree determines that the scientific research data level is D2;
[0105] Comparing the historical data means, the average age of the current data is 52 years old (the historical database is 50 years old, with a deviation of <5%), and the subject category matching degree is 90% (threshold 70%). After verification, it is directly defined as the data to be desensitized;
[0106] Taking the data "average age 52 years old" as an example, the query sensitivity is 1. Privacy Budget 0.5, sensitivity level The value is 2 (consistent with the scientific research data level). After adding noise, the desensitized scientific research data is 53.2±1.1. The corresponding horizontal constraint is added: the correlation coefficient deviation between the efficacy index and age is ≤0.05*2=0.1;
[0107] Using utility loss compensation value (The average value of the desensitized data Take 50, scientific research data volume n Take 100, standard deviation of desensitized data Take 12.5) to calibrate the desensitized statistics to obtain the calibrated data (49.22+53.2) / 2=51.21±1.1, and pass the privacy protection strength verification (using anonymity k verification, ), data utility preservation verification (JS divergence between original data distribution P and desensitized data distribution Q ) and time series feature preservation verification (Fourier spectrum error ,in For the DFT spectrum of the scientific research data to be desensitized, To desensitize scientific research data DFT spectrum), the final desensitized shared data "average age 51.21±1.1 years old" was obtained.
[0108] In this embodiment, the method for performing layered encryption and generating an upload log includes:
[0109] Determine the storage path based on the data type and data usage, specifically: NSFC subject classification code / data usage / data format; the data format includes raw data, statistical data, and analysis text;
[0110] Determine the layered encryption strategy based on the project phase, perform layered encryption on the desensitized scientific research data according to the layered encryption strategy to obtain layered open data, layered encrypted data, and layered keys, store the layered open data and layered encrypted data in the cloud according to the storage path, and generate an upload log for the scientific research unit ID, scientific research data label, storage path, edge verification operation, encrypted transmission operation, and layered encryption operation;
[0111] The layered encryption strategy specifically includes: encrypting the metadata directory in the project establishment phase, encrypting the desensitized data set in the experimental phase, encrypting the original experimental data in the memory encryption bus verification phase, and encrypting the archived data in the project conclusion phase;
[0112] In the actual evaluation, the data storage path is NSFC-A0103 / Clinical Trials / Raw Data / Encrypted Gene Sequence. AES-128-GCM dynamic encryption and EdDSA digital signatures are used to encrypt the metadata directory in the project establishment phase. CP-ABE attribute encryption, dynamic access control lists, and differential privacy injection are used to encrypt the desensitized dataset in the experimental phase. Trusted Execution Environment (TEE) sealed storage, Paillier homomorphic encryption, and memory encryption bus are used to encrypt the raw experimental data in the verification phase. NTRU quantum-resistant encryption, blockchain fingerprint storage, and key sharding are used to encrypt the archived data in the project conclusion phase.
[0113] An upload log (log ID: LOG_20240320_B_001) is generated by the research unit ID (National Center for Genetic Research B / digital certificate fingerprint / hardware fingerprint), research data tags (experimental stage / NSFC-A0103 / D2 / raw data), storage path (NSFC-A0103 / clinical trial / raw data / encrypted gene sequence), edge verification operations (historical mean deviation 4% / skewness deviation 10% / disciplinary category matching 90% / automatic pass), encrypted transmission operations (master key: "ECDH-P256" / "Salt" / session key: "HKDF-SHA3-256") / C1: "AES-GCM-IV"-"Tag" / C2: "ECIES" / integrity tag: "HMAC-BLAKE2s"), and layered encryption operations.
[0114] In this embodiment, the method for providing screening data to a scientific research unit includes:
[0115] The data demand research unit generates an encrypted request package based on the subject information, historical collaboration information and data demand; the subject information includes the institution certificate, public key fingerprint and hardware fingerprint; the historical collaboration information is provided by the regulatory unit through query, including the evaluation index , number of collaborations and violation records The data requirements include usage classification, subject coding, data type and scientific research data level;
[0116] Authenticate the scientific research unit based on the institution certificate and conduct a dynamic trust comprehensive assessment of the execution environment of the scientific research unit. The expression is:
[0117] ,
[0118] ,
[0119] ,
[0120] in is the comprehensive trust assessment score, The hardware root of trust verification result is passed The function gets, Score the security status of the runtime environment through a multi-layer perceptron Processing input features get, For historical record information, including historical comprehensive trust assessment scores, historical security incident numbers and severity, 、 、 is the risk weight coefficient, which is adjusted according to the risk level through the Softmax function. Represents a specific set of registers, is the expected value of the register state metric, m is the number of input features;
[0121] Perform semantic matching ontologies according to discipline codes to calculate semantic similarity, determine relevant research units in the field based on semantic similarity, calculate the collaboration willingness of relevant research units in the field, and determine research units to be invited based on the collaboration willingness;
[0122] The encrypted request packet is input into the dynamic multi-factor decision function to obtain the collaboration index between the data demand unit and the research unit to be invited. The data providing research unit is selected based on the collaboration index. The collaboration index expression is:
[0123] ,
[0124] ,
[0125] ,
[0126] ,
[0127] in is the collaboration index, is the credit weight, is the credit index, is the compliance weight, is the compliance rate, which is determined by the ratio of the number of successful audits to the total number of collaborations. is the resource weight, The resource matching degree is determined by the ratio of the collaboration willingness of the invited research institutes to the number of collaboration requirements;
[0128] The specific rules for collaboration determination are as follows: when the collaboration index is [0.9, 1], it is directly determined to be a data providing research unit and is given priority resource scheduling authority; when the collaboration index is [0.7, 0.9), it is determined to be a data providing research unit and is given standard resource scheduling authority; when the collaboration index is less than 0.7, the supervisory unit will review additional conditions and determine the data providing research unit;
[0129] In the actual evaluation, research unit A requested to share cancer genome data from other research units (for targeted drug development). The input features included memory protection flags, process tree hashes, and system call frequencies. 、 , take the risk weight coefficient as =0.5, =0.3, =0.2, the calculated comprehensive trust evaluation score is 0.92> comprehensive trust evaluation threshold 0.5, and the execution environment verification is passed;
[0130] According to the subject code NSFC-A0103, ontology semantic matching is performed to calculate semantic similarity (the ontology semantic matching includes OWL2 reasoning of the scientific research ontology library and dynamic weight calculation of subject keyword IDF, with weights of 0.6 and 0.4 respectively). Relevant semantics include cancer targeted therapy, genomic analysis, clinical trial management, etc. Based on semantic similarity, the relevant scientific research units B, C, D, E, F, and G in the field are determined (the semantic similarity is greater than 0.7 units);
[0131] The collaboration willingness is determined based on the centrality of the research unit in the disciplinary collaboration network and the historical collaboration success rate. The collaboration willingness of the relevant research units in the field is calculated according to "0.6*collaboration success rate+0.3 / response time+0.1 resource contribution rate". Based on the collaboration willingness value of 0.75, the research units B, C, and F are selected for invitation.
[0132] Taking the generated encrypted request package and the collaboration index calculation of scientific research unit B as an example, the evaluation index is obtained , number of collaborations and violation records , compliance rate , resource matching ), take the credit weight =0.6, compliance weight =0.25, resource weight =0.15, computing and scientific research unit B collaboration index = 0.79, directly determine that research unit B is the data providing research unit, and the corresponding collaboration is determined to be granted standard resource scheduling authority; the standard resource scheduling authority does not exceed the data demand authority of the data demanding research unit and the standard data access authority of the data providing research unit;
[0133] The collaboration index between computing and research unit C is 0.91, which means it is directly identified as a data-providing research unit. The corresponding collaboration is determined as granting priority resource scheduling permissions. This priority resource scheduling permission allows access to all data types, research data levels, and hierarchically encrypted research data under the discipline code.
[0134] The calculated collaboration index with scientific research unit F is 0.65, which is not in compliance with the collaboration conditions after review by the regulatory authorities.
[0135] In this embodiment, the method for generating the authorization instruction and the authorization log includes:
[0136] According to the data demand, the preset contract template is matched. The encrypted request package of the data-demanding scientific research unit and the resource scheduling authority of each data-providing scientific research unit are input into the preset contract template to dynamically generate contract terms, dynamically match the collaboration conditions, and perform security reinforcement to obtain a smart contract.
[0137] The steps of dynamically generating contract terms include: generating access rules based on data levels and resource scheduling permissions, injecting the access rules into permission terms, converting natural time into blockchain block numbers to convert the timeliness of the contract, and binding compliance terms by automatically associating with the legal and regulatory database;
[0138] The step of dynamically matching collaboration conditions includes: adjusting credit clause parameters according to collaboration willingness and collaboration index, and injecting automatic termination clauses according to risk levels using a risk hedging mechanism;
[0139] The security reinforcement includes automatic vulnerability scanning and formal verification; the formal verification includes timeliness clauses that cannot be tampered with and data level permission control;
[0140] Select a chain platform based on the collaborator's infrastructure, write the contract address into the consortium chain directory service, and trigger the cross-chain notification protocol to inform all collaborators;
[0141] Input the smart contract into the dynamic authorization instruction model to obtain authorization instructions and authorization logs;
[0142] The dynamic authorization instruction model includes a time limit instruction module, a path authorization instruction module, and a key application instruction module; the time limit instruction module generates an expiration instruction based on the blockchain block height of the smart contract time limit clause; the path authorization instruction module generates a scientific research data storage path instruction based on the smart contract permission clause; the key application instruction module generates a hierarchical key application instruction based on the permission clause and project stage;
[0143] The authorization instruction is generated by hash association of the invalidation instruction, the scientific research data storage path instruction and the hierarchical key application instruction; the authorization log includes the collaborative scientific research unit ID, the generation timestamp and the authorization instruction;
[0144] The authorization instruction is input into the supervisory unit for verification. The supervisory unit verifies the digital signature, execution environment, and timeliness of the authorization instruction, and simultaneously opens a data channel corresponding to the scientific research data storage path to obtain access data and distributes a hierarchical key; the access data includes access public data and access encrypted data;
[0145] In the actual evaluation, the preset contract template (commercial and scientific research demand template) is matched according to the data demand (targeted drug development). The encrypted request package of the data demanding scientific research unit A and the resource scheduling permissions of each data providing scientific research unit (B is the standard resource scheduling permission, C is the priority resource scheduling permission) are input into the preset contract template to dynamically generate contract terms, dynamically match the collaboration conditions, and perform security reinforcement to obtain a smart contract.
[0146] Taking the generation of the smart contract for Research Unit B as an example, the timeliness clause is as follows: the estimated duration of the project of 3 months is converted into 12,000 blockchain blocks. When the blockchain height reaches 12,000, the relevant permissions are automatically terminated; the access rules are as follows: by granting standard resource scheduling permissions to B and setting A's project stage as the verification stage, it is determined that the smart contract stipulates that Research Unit A can only access the layered open data and layered encrypted data of Research Unit B under the storage path through authorized instructions (project establishment stage, trial stage and verification stage); the automatic termination clause conditions: according to the risk level assessment, when the compliance risk value of Research Unit A exceeds 0.5, or there are three consecutive violations during the collaboration process, the automatic termination clause is triggered. Once triggered, the smart contract automatically terminates, and Research Unit B's data access rights are immediately stopped. At the same time, the regulatory unit will receive a notification and take corresponding measures.
[0147] After research institutes A and B generate a smart contract, the system selects a consortium chain platform based on the collaborating parties' infrastructure. The system writes the contract address to the consortium chain directory service and triggers the cross-chain notification protocol to inform the corresponding collaborating parties. After receiving the notification, research institutes A and B update their local collaboration information records to facilitate subsequent data access operations based on the contract.
[0148] Input the smart contract into the dynamic authorization instruction model to obtain the authorization instruction, where the current blockchain height is 10,000 (corresponding to the termination condition of parts B and C is a blockchain height of 12,000), the expiration instruction includes the remaining blockchain termination height of 2,000 and the daily usage limit of 200, the path instruction includes the storage path and access protocol of the corresponding data of scientific research units B and C, and the key instruction includes the instruction key type and acquisition method. The expiration instruction, path instruction, and key instruction are combined into the authorization instruction;
[0149] An authorization log (ID: LOG_AUTH_20240320_A / B / C_001) is generated based on the participant (requester certificate / participant ID), authorization details (data level, granted permissions, restrictions), environment verification (SGX authentication results), and blockchain evidence (transaction hash, block height).
[0150] The authorization instruction is input into the regulatory unit for verification. The regulatory unit verifies the digital signature (passed), execution environment (SGX environment compliance) and timeliness (current block height 10,000 < block height limit 12,000, daily usage 120 < daily usage limit 200) of the authorization instruction. At the same time, the regulatory unit opens the data channel corresponding to the scientific research data storage path (Scientific Research Unit B: NSFC-A0103 / Cancer Treatment / Raw Data / Encrypted Gene Sequence, Scientific Research Unit C: NSFC-A0103 / Cancer Treatment / Statistical Data / Efficacy Evaluation) to obtain the accessed data and distributes hierarchical keys (Scientific Research Unit B distributes project establishment / experimentation / verification level keys, and Scientific Research Unit C distributes all level keys).
[0151] In this embodiment, the method for weighting the collaborative authorization data includes:
[0152] The access encrypted data is decrypted in layers using the layered key to obtain the access decrypted data, and the access decrypted data and the access public data form the collaborative authorization data;
[0153] The data usage is determined based on the access logs, and the weight score of the collaborative authorization data of each scientific research unit is calculated based on the data usage, decryption level, scientific research data level and timeliness. The expression is:
[0154] ,
[0155] ,
[0156] ,
[0157] in W For weight scoring, is the level weight, is the data utility weight, D For scientific research data level,L Layered decryption levels for accessed encrypted data, U Use utility value for data, including data contribution , output rate , resource consumption ratio R , compliance risk value Risk and historical collaboration usage times H , is the time-dependent attenuation factor, The time difference between the generation of scientific research data and the present. is the high-value threshold for scientific research data, is the threshold of scientific research data decline period;
[0158] The collaborative authorization data of each scientific research unit is ranked by weight according to the weight score, and the scientific research unit with data demand accesses and downloads the collaborative authorization data according to the weight ranking;
[0159] Update the statistical access log based on the access records, layered decryption records, download records, and corresponding timestamps of scientific research data from different scientific research units, and add the verification results of the authorization instructions to the statistical access log to update the privacy access log;
[0160] In the actual evaluation, taking the weight score calculation of the collaborative authorization data of scientific research unit B as an example, the grade weight is taken =0.6, data utility weight =0.4, high-value threshold for scientific research data =30, scientific research data decline threshold =60, substitute the scientific research data level D=2 , access encrypted data layered decryption level L=3 , data contribution =0.8, output rate =0.7, resource consumption ratio R=0.6 , compliance risk value Risk=0.1 and historical collaborative usage times H=3 , the time difference between the generation of scientific research data and the present =10, the weight score of collaborative authorization data of scientific research unit B is calculated to be 2.74. Similarly, the weight score of collaborative authorization data of scientific research unit C is calculated to be 4.8. The collaborative authorization data of each scientific research unit is ranked by weight according to the weight score. The data-requiring scientific research units access and download the collaborative authorization data according to the weight ranking;
[0161] Update the statistical access log of the corresponding data based on the access records of scientific research unit A (required discipline type, access path, data level), layered decryption records, download records and corresponding timestamps; update the privacy access log based on the verification results of the authorization instructions of scientific research unit A (requirer identification, data fingerprint, SXG authentication hash, memory protection status).
[0162] In this embodiment, the upload log is only open to the regulatory unit; the authorization log is only open to the regulatory unit; the access log includes the statistical access log and the privacy access log; the statistical access log is open to all scientific research units; the privacy access log is only open to the regulatory unit.
[0163] In the second aspect, a multi-agent collaborative data authorization operation and management system includes:
[0164] Data upload module: used to obtain scientific research data from scientific research units and perform edge classification, perform edge verification and desensitization on the classified scientific research data to obtain desensitized shared data, encrypt and transmit the desensitized shared data to the cloud sharing platform, determine the storage path according to the data type and data usage, perform hierarchical encryption according to the project stage, and generate an upload log;
[0165] Collaborative screening module: used to generate an encrypted request package through the data demand research unit, perform identity authentication and execution environment verification, and screen the data providing research units based on the encrypted request package;
[0166] Data authorization module: used to generate smart contracts through data provided by scientific research units for joint decision-making, and input the smart contracts into the dynamic authorization instruction model to obtain authorization instructions and authorization logs;
[0167] Data acquisition module: used to verify the authorization instruction, open the data channel authority to determine the accessed data, perform layered decryption on the accessed data to obtain collaborative authorization data, and weight the collaborative authorization data according to the decryption level and data usage. The data-demanding scientific research unit accesses and downloads the collaborative authorization data according to the weight ranking and generates an access log;
[0168] Operation management module: used to view, store and manage the upload log, the authorization log and the access log, and intuitively display the authorization operation status of scientific research data through visualization technology.
[0169] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A multi-agent collaborative data authorization operation management method, characterized in that: The following steps are involved: S1. Obtain scientific research data from scientific research institutions and perform edge classification, then perform edge verification and desensitization on the classified scientific research data to obtain desensitized shared data; the edge verification includes edge comparison and review by regulatory authorities; S2. Encrypt and transmit the desensitized shared data to the cloud sharing platform, determine the storage path based on the data type and data usage, perform hierarchical encryption according to the project stage, and generate an upload log; S3. The data-requiring research unit generates an encrypted request package, performs identity authentication and execution environment verification, and selects the data-providing research unit based on the encrypted request package; S4. The data providing scientific research unit jointly decides to generate a smart contract for dynamic authorization, generates authorization instructions and authorization logs, verifies the authorization instructions, and opens data channel permissions to determine the accessed data; S5. Decrypt the accessed data in layers to obtain collaborative authorization data, and weight the collaborative authorization data according to the decryption level and data usage. The data-demanding research unit accesses and downloads the collaborative authorization data according to the weight ranking and updates the access log. The method for obtaining desensitized shared data includes: Determine the project stage corresponding to the scientific research data based on its data dimensions and time series, use principal component analysis to process the metadata of the scientific research data to obtain metadata features, and obtain the subject categories based on metadata feature matching; Perform multimodal analysis on the original scientific research data to obtain structured scientific research data and unstructured scientific research data. Input the unstructured scientific research data into the bag-of-words model to obtain text vectors. Use a hierarchical weight matrix to convert the text vectors into sensitivity weight vectors and value weight vectors. Based on the structured data and the corresponding sensitivity weight vectors and value weight vectors, obtain the scientific research data score. Use a hierarchical decision tree to determine the scientific research data level of the scientific research data score, and use the project stage, subject category and scientific research data level as scientific research data labels. The classified scientific research data are compared with the historical data provided by the corresponding scientific research units at the edge. The scientific research data that meets the edge comparison requirements are defined as data to be desensitized. The data that does not meet the edge comparison requirements are encrypted and transmitted to the supervisory unit for manual review. The supervisory unit transmits the review results back to the original port, and the scientific research data that passes the review is defined as data to be desensitized. The data to be desensitized are desensitized to obtain desensitized shared data; the edge comparison includes subject category comparison and historical statistical data comparison; the historical statistical data comparison includes skewness comparison, mean comparison and data volume comparison; the desensitized shared data covers the project establishment stage, trial stage, verification stage and conclusion stage; The specific steps of the encrypted transmission are: generating the master key MasterKey by generating the NIST P-256 elliptic curve and reverse ECDH key exchange, and expanding the master key by HKDF-SHA3-256 algorithm to generate the session key , based on the session key Encrypt data, encrypt session keys based on the public key of the regulatory agency, and encrypt the results based on data encryption and session key encryption 、 Generate composite verification tags , the expression is: , , , ; in is the key extraction function, is the salt value, is context information including timestamp, device fingerprint and project number, For data Using session keys The encrypted ciphertext, is the Advanced Encryption Standard Hybrid Galois Algorithm, Session key Using the regulator's public key The encrypted ciphertext, For an efficient hybrid encryption scheme, Hybrid BLAKE2s encryption algorithm for key-based hash message authentication code, Session key Truncate the generated key; The steps of performing data desensitization to obtain desensitized shared data are specifically as follows: using differential privacy protection to process numerical data, using BERT-Mask technology to process text data, adding horizontal correlation constraints, using utility loss compensation values to calibrate the desensitized statistics, and verifying the desensitization effect; the desensitization effect verification includes privacy protection strength verification, data utility preservation verification, and time series feature preservation verification. The expression for processing numerical data is: , in For desensitized numerical scientific research data, To desensitize the scientific research data, is Gaussian noise, To query sensitivity, Budget for privacy, is the sensitivity level; The horizontal association constraint expression is: , in For the i and j The Pearson correlation coefficient of the desensitized numerical scientific research data, For the i and j Pearson correlation coefficient of the numerical scientific research data to be desensitized.
2. According to the multi-agent collaborative data authorization operation management method of claim 1, it is characterized by: The method for performing layered encryption and generating an upload log includes: Determine the storage path based on the data type and data usage, specifically: NSFC subject classification code / data usage / data format; the data format includes raw data, statistical data, and analysis text; Determine the layered encryption strategy based on the project phase, perform layered encryption on the desensitized scientific research data according to the layered encryption strategy to obtain layered open data, layered encrypted data, and layered keys, store the layered open data and layered encrypted data in the cloud according to the storage path, and generate an upload log for the scientific research unit ID, scientific research data label, storage path, edge verification operation, encrypted transmission operation, and layered encryption operation; The layered encryption strategy specifically includes: encrypting the metadata directory in the project establishment stage, encrypting the desensitized data set in the experimental stage, encrypting the original experimental data in the memory encryption bus verification stage, and encrypting the archived data in the conclusion stage.
3. The multi-agent collaborative data authorization operation management method according to claim 1 is characterized in that: The screening data provides research unit with methods including: The data demand research unit generates an encrypted request package based on the subject information, historical collaboration information and data demand; the subject information includes the institution certificate, public key fingerprint and hardware fingerprint; the historical collaboration information is provided by the regulatory unit through query, including the evaluation index , number of collaborations and violation records The data requirements include usage classification, subject coding, data type and scientific research data level; Authenticate the scientific research unit based on the institution certificate and conduct a dynamic trust comprehensive assessment of the execution environment of the scientific research unit. The expression is: , , , in is the comprehensive trust assessment score, The hardware root of trust verification result is passed The function gets, Score the security status of the runtime environment through a multi-layer perceptron Processing input features get, For historical record information, including historical comprehensive trust assessment scores, historical security incident numbers and severity, 、 、 is the risk weight coefficient, which is adjusted according to the risk level through the Softmax function. Represents a specific set of registers, is the expected value of the register state metric, m is the number of input features; Perform semantic matching ontologies according to discipline codes to calculate semantic similarity, determine relevant research units in the field based on semantic similarity, calculate the collaboration willingness of relevant research units in the field, and determine research units to be invited based on the collaboration willingness; The encrypted request packet is input into the dynamic multi-factor decision function to obtain the collaboration index between the data demand unit and the research unit to be invited. The data providing research unit is selected based on the collaboration index. The collaboration index expression is: , , , , in is the collaboration index, is the credit weight, is the credit index, is the compliance weight, is the compliance rate, which is determined by the ratio of the number of successful audits to the total number of collaborations. is the resource weight, The resource matching degree is determined by the ratio of the collaboration willingness of the invited research institutes to the number of collaboration requirements; The specific rules for collaboration determination are: when the collaboration index is [0.9, 1], it is directly determined to be a data providing scientific research unit and is given priority resource scheduling authority; when the collaboration index is [0.7, 0.9), it is determined to be a data providing scientific research unit and is given standard resource scheduling authority; when the collaboration index is less than 0.7, the supervisory unit will review the additional conditions and determine the data providing scientific research unit.
4. The multi-agent collaborative data authorization operation management method according to claim 1, characterized in that: The method for generating the authorization instruction and the authorization log includes: According to the data demand, the preset contract template is matched. The encrypted request package of the data-demanding scientific research unit and the resource scheduling authority of each data-providing scientific research unit are input into the preset contract template to dynamically generate contract terms, dynamically match the collaboration conditions, and perform security reinforcement to obtain a smart contract. The steps of dynamically generating contract terms include: generating access rules based on data levels and resource scheduling permissions, injecting the access rules into permission terms, converting natural time into blockchain block numbers to convert the timeliness of the contract, and binding compliance terms by automatically associating with the legal and regulatory database; The step of dynamically matching collaboration conditions includes: adjusting credit clause parameters according to collaboration willingness and collaboration index, and injecting automatic termination clauses according to risk levels using a risk hedging mechanism; The security reinforcement includes automatic vulnerability scanning and formal verification; the formal verification includes timeliness clauses that cannot be tampered with and data level permission control; Select a chain platform based on the collaborator's infrastructure, register the contract address and inform all cooperating scientific research units; Input the smart contract into the dynamic authorization instruction model to obtain authorization instructions and authorization logs; The dynamic authorization instruction model includes a time limit instruction module, a path authorization instruction module, and a key application instruction module; the time limit instruction module generates an expiration instruction based on the blockchain block height of the smart contract time limit clause; the path authorization instruction module generates a scientific research data storage path instruction based on the smart contract permission clause; the key application instruction module generates a hierarchical key application instruction based on the permission clause and project stage; The authorization instruction is generated by hash association of the invalidation instruction, the scientific research data storage path instruction and the hierarchical key application instruction; the authorization log includes the collaborative scientific research unit ID, the generation timestamp and the authorization instruction; The authorization instruction is input into the regulatory unit for verification. The regulatory unit verifies the digital signature, execution environment and timeliness of the authorization instruction, and at the same time opens the data channel corresponding to the scientific research data storage path to obtain the accessed data and distributes the hierarchical key; the accessed data includes accessed public data and accessed encrypted data.
5. The multi-agent collaborative data authorization operation management method according to claim 1 is characterized in that: The method for weighting the collaborative authorization data includes: The access encrypted data is decrypted in layers using the layered key to obtain the access decrypted data, and the access decrypted data and the access public data form the collaborative authorization data; The data usage is determined based on the access logs, and the weight score of the collaborative authorization data of each scientific research unit is calculated based on the data usage, decryption level, scientific research data level and timeliness. The expression is: , , , in W For weight scoring, is the level weight, is the data utility weight, D For scientific research data level, L Layered decryption levels for accessed encrypted data, U Use utility value for data, including data contribution , output rate , resource consumption ratio R , compliance risk value Risk and historical collaboration usage times H , is the time-dependent attenuation factor, The time difference between the generation of scientific research data and the present. is the high-value threshold for scientific research data, is the threshold of scientific research data decline period; The collaborative authorization data of each scientific research unit is ranked by weight according to the weight score, and the scientific research unit with data demand accesses and downloads the collaborative authorization data according to the weight ranking; According to the access records, layered decryption records, download records and corresponding timestamps of scientific research data of different scientific research units, the statistical access log is updated, and the verification results of the authorization instructions are added to the statistical access log to update the privacy access log.
6. The multi-agent collaborative data authorization operation management method according to claim 1, characterized in that: The uploaded log is only open to regulatory authorities; The authorization log is only open to regulatory units; the access log includes statistical access log and privacy access log; the statistical access log is open to all scientific research units; the privacy access log is only open to regulatory units.
7. A multi-agent collaborative data authorization operation and management system for executing the method according to any one of claims 1 to 6, characterized in that: include: Data upload module: used to obtain scientific research data from scientific research units and perform edge classification, perform edge verification and desensitization on the classified scientific research data to obtain desensitized shared data, encrypt and transmit the desensitized shared data to the cloud sharing platform, determine the storage path according to the data type and data usage, perform hierarchical encryption according to the project stage, and generate an upload log; Collaborative screening module: used to generate an encrypted request package through the data demand research unit, perform identity authentication and execution environment verification, and screen the data providing research units based on the encrypted request package; Data authorization module: used to generate smart contracts through data provided by scientific research units for joint decision-making, and input the smart contracts into the dynamic authorization instruction model to obtain authorization instructions and authorization logs; Data acquisition module: used to verify the authorization instruction, open the data channel authority to determine the accessed data, perform layered decryption on the accessed data to obtain collaborative authorization data, and weight the collaborative authorization data according to the decryption level and data usage. The data-demanding scientific research unit accesses and downloads the collaborative authorization data according to the weight ranking and generates an access log; Operation management module: used to view, store and manage the upload log, the authorization log and the access log, and intuitively display the authorization operation status of scientific research data through visualization technology.
Citation Information
Patent Citations
Data access control method based on block chain
CN112257112A
Government affair alliance chain-based government affair data access control method and system
CN115442045A