Data encryption and privacy protection method of a trusted data exchange platform

By analyzing data exchange requests in the data exchange platform, identifying encryption tags and performing hierarchical encryption, and monitoring data transmission in real time, the problem of insufficient security and privacy protection in existing data exchange technologies is solved, and an efficient and flexible data exchange process is achieved.

CN120263495BActive Publication Date: 2025-10-24GUANGZHOU ZHISUAN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510472970.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-10-24
Estimated Expiration
2045-04-16

AI Technical Summary

Technical Problem

Existing data exchange methods lack differentiated encryption capabilities, making it difficult to effectively prevent data leakage or tampering, and lacking real-time monitoring and dynamic assessment of the encryption requirements of the data exchange process.

Method used

By analyzing the data to be exchanged, the encryption tag for each data exchange request is determined, and the hierarchical data is encrypted. Data transmission is monitored in real time, and a data exchange report is generated, thus achieving fine-grained hierarchical and multi-level protection.

Benefits of technology

It ensures the security, efficiency and flexibility of the data exchange process, reduces the risk of data leakage, and improves the transparency and credibility of the data exchange platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263495B_ABST
    Figure CN120263495B_ABST
Patent Text Reader

Abstract

The application provides a data encryption and privacy protection method of a trusted data exchange platform, and belongs to the technical field of data transmission.The method comprises the following steps: step 1: a data exchange platform receives data exchange requests of multiple requesters, and determines to-be-exchanged data of the data exchange platform; step 2: historical request exchange evaluation values and historical receiving exchange evaluation values of each to-be-exchanged sub-data are determined; step 3: an encryption label of each data exchange request is determined, and hierarchical data of the data exchange platform is determined; step 4: hierarchical data is subjected to data encryption, and the hierarchical data subjected to data encryption is subjected to data transmission; and step 5: a data exchange report is generated, and trusted data exchange is realized.The method can realize fine-grained classification and encryption of data exchange requests, realize multi-level data protection and privacy protection, ensure the safety, efficiency and flexibility of the data exchange process, reduce the risk of data leakage, and improve the transparency, credibility and safety of the data exchange platform.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data transmission, in particular to a data encryption and privacy protection method of a trusted data exchange platform. BACKGROUND

[0002] At present, with the continuous development of information society, data exchange becomes more and more important in various industries. However, with the frequent occurrence of data leakage events, the security and privacy protection of data exchange have become increasingly prominent. Traditional data exchange methods often rely on simple encryption technology and lack the ability to differentiate encryption according to data sensitivity, resulting in insufficient protection of some high-sensitive data. In addition, existing technologies often lack the ability to monitor and dynamically evaluate the encryption needs of data exchange processes in real time, making it difficult to effectively prevent potential data leakage or tampering.

[0003] Therefore, the present application provides a data encryption and privacy protection method of a trusted data exchange platform. SUMMARY

[0004] The present application provides a data encryption and privacy protection method of a trusted data exchange platform, which determines the encryption label of each data exchange request by analyzing the determined data to be exchanged, and determines the hierarchical data of the data exchange platform. The hierarchical data is encrypted, and the hierarchical data after data encryption is transmitted and monitored in real time to generate a data exchange report, realizing trusted data exchange. The method can realize fine-grained classification and encryption of data exchange requests, realize multi-level data protection and privacy protection, ensure the security, efficiency and flexibility of the data exchange process, reduce the risk of data leakage, and improve the transparency, credibility and security of the data exchange platform.

[0005] The present application provides a data encryption and privacy protection method of a trusted data exchange platform, comprising:

[0006] Step 1: The data exchange platform receives data exchange requests from multiple request parties, and determines the data to be exchanged of the data exchange platform, wherein the data to be exchanged includes multiple data to be exchanged;

[0007] Step 2: Extract and analyze the request party data and the receiving party data of each data to be exchanged in the data to be exchanged, and determine the historical request exchange evaluation value and the historical receiving exchange evaluation value of each data to be exchanged;

[0008] Step 3: Based on the data to be exchanged, the request party data, the receiving party data, the historical request exchange evaluation value and the historical receiving exchange evaluation value, determine the encryption label of each data exchange request, and determine the hierarchical data of the data exchange platform;

[0009] Step 4: data encryption is performed on the hierarchical data, and the hierarchical data after data encryption is transmitted;

[0010] Step 5: real-time monitoring is performed on the data transmission of the hierarchical data, a data exchange report is generated, and trusted data exchange is realized.

[0011] According to the data encryption and privacy protection method of the trusted data exchange platform provided by the application, the data exchange platform receives data exchange requests of multiple requesters, determines to-be-exchanged data of the data exchange platform, including:

[0012] The data exchange platform determines the receiver of each data exchange request, and performs identity authentication on the requester and the receiver of each data exchange request respectively;

[0013] The to-be-exchanged sub-data of the data exchange request whose requester and receiver are authenticated at the same time is received, wherein the to-be-exchanged sub-data at least includes the requester, the receiver, the request time and the to-be-exchanged data of the data exchange request;

[0014] Based on all the received to-be-exchanged sub-data, the to-be-exchanged data of the data exchange platform is determined.

[0015] According to the data encryption and privacy protection method of the trusted data exchange platform provided by the application, the requester data and the receiver data of each to-be-exchanged sub-data in the to-be-exchanged data are extracted and analyzed, and the historical request exchange evaluation value and the historical receiving exchange evaluation value of each to-be-exchanged sub-data are determined, including:

[0016] The requester data of the requester of the data exchange request of each to-be-exchanged sub-data in the to-be-exchanged data is extracted from the database of the data exchange platform, wherein the requester data includes the request business scene, the request data asset type and the request historical exchange data, wherein the request historical exchange data includes the data exchange sub-report of each historical data exchange of the requester in a historical specified time period;

[0017] Based on the request historical exchange data of each data exchange request, the historical request exchange evaluation value of each to-be-exchanged sub-data is calculated;

[0018] ;

[0019] Wherein, The historical request exchange evaluation value of the a-th data exchange request is represented as The number of historical data exchanges of the requester in the request historical exchange data of the a-th data exchange request in a historical specified time period is represented as The data leakage value in the data exchange sub-report of the i-th historical data exchange of the requester in the request historical exchange data of the a-th data exchange request is represented as Indicates the data matching value of the requester's i-th historical data exchange in the request history exchange data of the a-th data exchange request, represents the matching factor, represents the leakage factor, represents the frequency factor, Indicates the current time, represents the time decay factor, Indicates the exchange time in the data exchange sub-report of the i-th historical data exchange of the requester in the request history exchange data of the a-th data exchange request, Indicates the exchange time in the data exchange sub-report of the first historical data exchange of the requesting party in the historical exchange data of the ath data exchange request within the specified historical time period;

[0020] Extracting, from a database of the data exchange platform, recipient data of a recipient of a data exchange request for each sub-data to be exchanged in the data to be exchanged, wherein the recipient data includes a receiving business scenario, a receiving data asset type, and receiving historical exchange data, wherein the receiving historical exchange data includes a data exchange sub-report for each historical data exchange within a specified historical time period;

[0021] Calculate the historical reception exchange evaluation value of each data exchange request for each sub-data to be exchanged based on the reception history exchange data of each data exchange request;

[0022] ;

[0023] in, Indicates the historical received exchange evaluation value of the a-th data exchange request, Indicates the number of historical data exchanges on the receiving side of the received historical exchange data for the ath data exchange request within the specified historical time period. Indicates the data matching value in the data exchange sub-report of the receiver's j-th historical data exchange in the received historical exchange data of the a-th data exchange request, Indicates the data leakage value in the data exchange sub-report of the receiver's j-th historical data exchange in the historical exchange data of the a-th data exchange request, Indicates the exchange time in the data exchange sub-report of the first historical data exchange of the recipient in the historical exchange data of the ath data exchange request within the specified historical time period. Indicates the exchange time in the data exchange sub-report of the jth historical data exchange of the receiver in the historical exchange data received for the ath data exchange request, Indicates the length of the specified historical time period. Indicates the base exchange frequency of the data exchange platform.

[0024] According to the data encryption and privacy protection method of the trusted data exchange platform provided by the application, the encryption label of each data exchange request is determined based on the data to be exchanged, the requester data, the receiver data, the historical request exchange evaluation value and the historical reception exchange evaluation value, and the hierarchical data of the data exchange platform is determined, including:

[0025] Sensitive information identification is performed on the waiting exchange data of each data to be exchanged in the data to be exchanged, and the sensitive data of each data exchange request of each data to be exchanged is determined;

[0026] Feature extraction is performed on the sensitive data of each data to be exchanged in the data to be exchanged, and the sensitive feature vector of each data exchange request of each data to be exchanged is determined, wherein the sensitive feature vector includes a plurality of sensitive features;

[0027] Feature extraction is performed on the request business scenario and the request data asset type in the requester data of each data exchange request, and the request feature vector of each data exchange request is determined, and at the same time, feature extraction is performed on the receiving business scenario and the receiving data asset type in the receiver data of each data exchange request, and the receiving feature vector of each data exchange request is determined;

[0028] Based on the sensitive feature vector, the request feature vector, the receiving feature vector, the historical request exchange evaluation value and the historical reception exchange evaluation value of each data exchange request, the encryption label of each data exchange request is determined;

[0029] Based on the data to be exchanged of all data exchange requests with the same encryption label, the hierarchical sub-data of each encryption label is determined;

[0030] Based on the hierarchical sub-data of all encryption labels, the hierarchical data of the data exchange platform is determined.

[0031] According to the data encryption and privacy protection method of the trusted data exchange platform provided by the application, the encryption label of each data exchange request is determined based on the sensitive feature vector, the request feature vector, the receiving feature vector, the historical request exchange evaluation value and the historical reception exchange evaluation value of each data exchange request, including:

[0032] ;

[0033] ;

[0034] ;

[0035] Wherein, The encryption label of the a-th data exchange request is represented as an encryption score value representing the a-th data exchange request, a data matching value representing the a-th data exchange request, a sensitive feature vector representing the a-th data exchange request, a request feature vector representing the a-th data exchange request, a receiving feature vector representing the a-th data exchange request, a first anti-zero parameter, a second anti-zero parameter, a difference value representing the request feature vector and the receiving feature vector of the a-th data exchange request, a first-level encryption score threshold value, a second-level encryption score threshold value.

[0036] According to the data encryption and privacy protection method of the trusted data exchange platform provided by the application, the hierarchical data is encrypted, and the method comprises the following steps:

[0037] The sensitive data of each to-be-exchanged sub-data in the to-be-exchanged data is encrypted in a format reservation manner;

[0038] In the hierarchical data, the data of each data exchange request in the hierarchical sub-data with a first-level encryption label, except the sensitive data, is encrypted based on a first-level strategy, and a first-level key is generated;

[0039] In the hierarchical data, the data of each data exchange request in the hierarchical sub-data with a second-level encryption label, except the sensitive data, is encrypted based on a second-level strategy, and a second-level key is generated;

[0040] In the hierarchical data, the data of each data exchange request in the hierarchical sub-data with a third-level encryption label, except the sensitive data, is encrypted based on a third-level strategy, and a third-level key is generated.

[0041] According to the data encryption and privacy protection method of the trusted data exchange platform provided by the application, the hierarchical data after data encryption is transmitted, and the method comprises the following steps:

[0042] Each hierarchical sub-data after data encryption is transmitted based on a transmission protocol of each encryption label.

[0043] According to the data encryption and privacy protection method of the trusted data exchange platform provided by the application, the data transmission of the hierarchical data is monitored in real time, a data exchange report is generated, and trusted data exchange is realized, and the method comprises the following steps:

[0044] monitoring the data transmission of the to-be-exchanged sub-data of each data exchange request in each encrypted label sub-data of the hierarchical data in real time, determining the exchange time, the leaked data and the successfully exchanged data of each data exchange request;

[0045] determining the data leakage value of each data exchange request based on the leaked data, the successfully exchanged data and the to-be-exchanged data of each data exchange request;

[0046] generating a data exchange sub-report of each data exchange request based on the exchange time, the to-be-exchanged data, the data matching value, the leaked data, the successfully exchanged data and the data leakage value of each data exchange request;

[0047] generating a data exchange report of the data exchange platform based on the data exchange sub-reports of all data exchange requests.

[0048] Compared with the prior art, the beneficial effects of the present application are as follows:

[0049] By analyzing the determined to-be-exchanged data, the encrypted label of each data exchange request is determined, and the hierarchical data of the data exchange platform is determined, the hierarchical data is encrypted, the hierarchical data after data encryption is transmitted and monitored in real time, a data exchange report is generated, and trusted data exchange is realized. The fine-grained hierarchical and encryption of data exchange request can be realized, multi-level data protection and privacy protection can be realized, the security, efficiency and flexibility of the data exchange process can be ensured, the data leakage risk can be reduced, and the transparency, credibility and security of the data exchange platform can be improved. BRIEF DESCRIPTION OF DRAWINGS

[0050] In order to more clearly illustrate the technical solutions in the present application or prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0051] Figure 1 is a flowchart of a trusted data exchange platform data encryption and privacy protection method provided by an embodiment of the present application. DETAILED DESCRIPTION

[0052] In order to make the purpose, technical scheme and advantages of the present application more clear, the technical scheme in the present application will be described clearly and completely in the following by combining the drawings in the present application. Obviously, the described embodiments are some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor belong to the protection scope of the present application.

[0053] Embodiment 1:

[0054] The embodiment of the present application provides a data encryption and privacy protection method of a trusted data exchange platform, as shown in the figure, comprising: Figure 1

[0055] Step 1: The data exchange platform receives data exchange requests of multiple requesters, and determines to-be-exchanged data of the data exchange platform, wherein the to-be-exchanged data comprises multiple to-be-exchanged sub-data;

[0056] Step 2: Extract and analyze requester data and receiver data of each to-be-exchanged sub-data in the to-be-exchanged data, and determine a historical request exchange evaluation value and a historical reception exchange evaluation value of each to-be-exchanged sub-data;

[0057] Step 3: Based on the to-be-exchanged data, the requester data, the receiver data, the historical request exchange evaluation value and the historical reception exchange evaluation value, determine an encryption label of each data exchange request, and determine hierarchical data of the data exchange platform;

[0058] Step 4: Perform data encryption on the hierarchical data, and perform data transmission on the hierarchical data after data encryption;

[0059] Step 5: Real-time monitoring of data transmission of the hierarchical data, generating a data exchange report, realizing trusted data exchange.

[0060] In the embodiment, the data exchange platform receives exchange requests of multiple requesters, and the platform determines to-be-exchanged data by verifying the identity of the requester and the receiver of each request.

[0061] In the embodiment, after receiving the data exchange request and extracting the requester data and the receiver data of all to-be-exchanged sub-data, detailed analysis is performed, an encryption label of each data exchange request is determined, and the data is divided into hierarchical data. The encryption label of the data determines the data protection level and the encryption strategy.

[0062] In the embodiment, according to the encryption label of the hierarchical data, the platform encrypts the to-be-exchanged data, and applies different encryption strategies according to different encryption labels (first-level, second-level and third-level encryption). The encrypted data will be transmitted in the platform to ensure that the data is not leaked or tampered with during transmission.

[0063] In the embodiment, the platform real-time monitors the entire process of data transmission, collects detailed information about the exchanged data, including exchange time, successfully exchanged data, potential leaked data, etc. The monitoring result is used to generate a data exchange report.

[0064] ​The beneficial effects of the above technical solutions are: by analyzing the determined to-be-exchanged data, determining the encryption label of each data exchange request, determining the hierarchical data of the data exchange platform, performing data encryption on the hierarchical data, performing data transmission on the hierarchical data after data encryption, and real-time monitoring, generating a data exchange report, and realizing trusted data exchange. The fine-grained classification and encryption of data exchange requests can be realized, multi-level data protection and privacy protection can be realized, the security, efficiency and flexibility of the data exchange process can be ensured, the risk of data leakage can be reduced, and the transparency, credibility and security of the data exchange platform can be improved.

[0065] Embodiment 2:

[0066] The embodiment of the application provides a data encryption and privacy protection method of a trusted data exchange platform. The data exchange platform receives data exchange requests of multiple requesters, determines to-be-exchanged data of the data exchange platform, and comprises the following steps:

[0067] The data exchange platform determines the receiver of each data exchange request, and respectively performs identity authentication on the requester and the receiver of each data exchange request.

[0068] The to-be-exchanged sub-data of the data exchange request, in which the requester and the receiver are simultaneously authenticated, is received, wherein the to-be-exchanged sub-data at least comprises the requester, the receiver, the request time and the to-be-exchanged data of the data exchange request.

[0069] Based on all the received to-be-exchanged sub-data, the to-be-exchanged data of the data exchange platform is determined.

[0070] In the embodiment, the requester verification can verify the legality of the requester identity through a digital certificate, an API key or an OAuth 2.0 protocol; the receiver verification can check whether the receiver is an authorized entity registered by the platform, and confirm the permission range (such as whether to allow receiving specific type data).

[0071] In the embodiment, only when the requester and the receiver are both verified, the data exchange request enters the subsequent processing flow; the request that fails to pass the verification is recorded and an alarm is triggered (such as suspected illegal access).

[0072] In the embodiment, the requester represents an entity (such as an enterprise department or a third-party service provider) that initiates the data exchange demand actively, and needs to pass the platform authentication to obtain the operation permission.

[0073] In the embodiment, the receiver represents a target entity (such as a partner or an internal system) of the data exchange, and needs to verify the identity and the data receiving permission.

[0074] In this embodiment, each verified request corresponds to a to-be-exchanged sub-data, which contains the following core metadata: requestor: a verified requestor; receiver: a verified receiver; request timestamp: the precise time of request initiation; to-be-exchanged data: specific data content (such as database records, file blocks) extracted from a data source (such as a CDM data lake).

[0075] In this embodiment, the platform aggregates all verified to-be-exchanged sub-data to generate a global to-be-exchanged data set.

[0076] In this embodiment, the to-be-exchanged sub-data represents the minimum data unit corresponding to a single data exchange request, and contains the requestor, receiver, timestamp, and data body.

[0077] The above technical solution has the following beneficial effects: The data exchange platform receives data exchange requests from multiple requestors, determines the to-be-exchanged data of the data exchange platform, can realize double verification of the identity safety of the requestor and the receiver, reduces the risk of data leakage, enhances the data exchange transparency and credibility of the platform, and realizes precise auditing and post-tracing of exchange behavior.

[0078] Embodiment 3:

[0079] The embodiment of the application provides a data encryption and privacy protection method of a trusted data exchange platform, extracts and analyzes the requestor data and receiver data of each to-be-exchanged sub-data in to-be-exchanged data, determines the historical request exchange evaluation value and the historical receiving exchange evaluation value of each to-be-exchanged sub-data, including:

[0080] From the database of the data exchange platform, the requestor data of the requestor of the data exchange request of each to-be-exchanged sub-data in the to-be-exchanged data is extracted, wherein the requestor data includes a request business scenario, a request data asset type, and request historical exchange data, and the request historical exchange data includes a data exchange sub-report of each historical data exchange of the requestor within a historical specified time period;

[0081] Based on the request historical exchange data of each data exchange request, the historical request exchange evaluation value of each to-be-exchanged sub-data is calculated;

[0082] ;

[0083] wherein, represents the historical request exchange evaluation value of the a th data exchange request, represents the number of historical data exchanges of the requestor in the request historical exchange data of the a th data exchange request within the historical specified time period, a data leakage value in a data exchange sub-report of an i-th historical data exchange of the requestor in the request historical exchange data of the a-th data exchange request, a data matching value in a data exchange sub-report of an i-th historical data exchange of the requestor in the request historical exchange data of the a-th data exchange request, representing a matching factor, representing a leakage factor, representing a frequency factor, representing a current time, representing a time decay factor, a exchange time in a data exchange sub-report of an i-th historical data exchange of the requestor in the request historical exchange data of the a-th data exchange request, a exchange time in a data exchange sub-report of a first historical data exchange of the requestor in the request historical exchange data of the a-th data exchange request within a historical specified time period;

[0084] extracting, from a database of the data exchange platform, receiver data of a receiver of a data exchange request of each to-be-exchanged sub-data in the to-be-exchanged data, wherein the receiver data includes a receiving business scenario, a receiving data asset type, and receiving historical exchange data, wherein the receiving historical exchange data includes a data exchange sub-report of each historical data exchange within a historical specified time period;

[0085] calculating a historical receiving exchange evaluation value of the data exchange request of each to-be-exchanged sub-data based on the receiving historical exchange data of each data exchange request;

[0086]

[0087] wherein, a historical receiving exchange evaluation value of the a-th data exchange request, a number of historical data exchanges of the receiver in the receiving historical exchange data of the a-th data exchange request within a historical specified time period, a data matching value in a data exchange sub-report of a j-th historical data exchange of the receiver in the receiving historical exchange data of the a-th data exchange request, a data leakage value in a data exchange sub-report of a j-th historical data exchange of the receiver in the request historical exchange data of the a-th data exchange request, a exchange time in a data exchange sub-report of a first historical data exchange of the receiver in the receiving historical exchange data of the a-th data exchange request within a historical specified time period, a exchange time in a data exchange sub-report of a j-th historical data exchange of the receiver in the receiving historical exchange data of the a-th data exchange request, a time length representing a historical specified time period, a reference exchange frequency representing a data exchange platform.

[0088] In this embodiment, the platform extracts the requester data of each data exchange request from the database, including: request business scenario: the business background or scenario in which the requester may exchange data; request data asset type: the type of data that the requester may exchange; request historical exchange data: the data exchange sub-report generated by the platform from the historical database for each data exchange record of the requester within a specific time period.

[0089] In this embodiment, the platform extracts the receiver data of each data exchange request from the database, including: receiving business scenario: the data demand background of the receiver; receiving data asset type: the data demand type of the receiver; receiving historical exchange data: the historical data exchange record of the receiver, the data exchange sub-report generated by the platform from the historical database for each data exchange record of the receiver within a specific time period.

[0090] In this embodiment, the platform calculates the historical request exchange evaluation value and the historical receiving exchange evaluation value according to the historical data exchange records of the requester and the receiver.

[0091] In this embodiment, represents the exchange evaluation rate of the receiver in the receiving historical exchange data of the a-th data exchange request within a historical specified time period.

[0092] In this embodiment, represents the exchange frequency within the exchange time of the first historical data exchange and the exchange time of the i-th historical data exchange in the request historical exchange data of the a-th data exchange request.

[0093] In this embodiment, for processing the exchange time in the data exchange sub-report of the i-th historical data exchange of the requester in the request historical exchange data, ensuring that the data closest to the current time contributes more.

[0094] In this embodiment, to avoid the influence of excessively high exchange frequency on calculation stability.

[0095] In this embodiment, the data matching value and the data leakage value jointly determine the data exchange security level.

[0096] The technical scheme has the beneficial effects that: the requestor data and the receiver data of each to-be-exchanged sub-data in the to-be-exchanged data are extracted and analyzed, the historical request exchange evaluation value and the historical reception exchange evaluation value of each to-be-exchanged sub-data are determined, the historical performance of the requestor and the receiver can be quantified, and more intelligent and safer data exchange management is realized.

[0097] Embodiment 4:

[0098] The embodiment of the application provides a data encryption and privacy protection method of a trusted data exchange platform, based on to-be-exchanged data, requestor data, receiver data, historical request exchange evaluation value and historical reception exchange evaluation value, determining an encryption label of each data exchange request, and determining hierarchical data of the data exchange platform, comprising:

[0099] Sensitive information identification is performed on the to-be-exchanged data of each to-be-exchanged sub-data in the to-be-exchanged data, and sensitive data of the data exchange request of each to-be-exchanged sub-data is determined;

[0100] Feature extraction is performed on the sensitive data of each to-be-exchanged sub-data in the to-be-exchanged data, and a sensitive feature vector of the data exchange request of each to-be-exchanged sub-data is determined, wherein the sensitive feature vector comprises a plurality of sensitive features;

[0101] Feature extraction is performed on the request business scenario and the request data asset type in the requestor data of each data exchange request, and a request feature vector of each data exchange request is determined, and feature extraction is performed on the reception business scenario and the reception data asset type in the receiver data of each data exchange request, and a reception feature vector of each data exchange request is determined;

[0102] Based on the sensitive feature vector, the request feature vector, the reception feature vector, the historical request exchange evaluation value and the historical reception exchange evaluation value of each data exchange request, an encryption label of each data exchange request is determined;

[0103] Based on the to-be-exchanged sub-data of all data exchange requests with the same encryption label, hierarchical sub-data of each encryption label is determined;

[0104] Based on the hierarchical sub-data of all encryption labels, hierarchical data of the data exchange platform is determined.

[0105] In this embodiment, the to-be-exchanged sub-data is scanned by a rule engine (such as a regular expression to match an ID card number or a mobile phone number) and an AI model (such as a BERT to identify disease names in medical texts), and sensitive fields are marked to generate sensitive data.

[0106] In this embodiment, the sensitive features can be identity information, financial data, etc.

[0107] In this embodiment, the service scenarios of the requester and the receiver, and the data asset types are extracted to generate a request feature vector and a receiving feature vector. These vectors are used to analyze the attributes of the requester and the receiver to determine their matching degree.

[0108] In this embodiment, the sensitive feature vector of the request, the request feature vector, the receiving feature vector, the historical request exchange evaluation value, and the historical receiving exchange evaluation value are combined to determine the encryption label of each data exchange request by analyzing the relationship between these vectors and the historical records.

[0109] In this embodiment, based on all requests with the same encryption label, the platform classifies the sub-exchange data of these requests to form hierarchical sub-data of each encryption label.

[0110] In this embodiment, the platform determines the hierarchical data of the data exchange platform by merging the hierarchical sub-data of all encryption labels.

[0111] The above technical solution has the following advantages: based on the sub-exchange data, the requester data, the receiver data, the historical request exchange evaluation value, and the historical receiving exchange evaluation value, the encryption label of each data exchange request is determined, and the hierarchical data of the data exchange platform is determined, which can realize fine-grained classification and encryption of each data exchange request, improve the transparency and compliance of data exchange, and enhance the protection of sensitive data.

[0112] Embodiment 5:

[0113] The embodiment of the application provides a data encryption and privacy protection method of a trusted data exchange platform, which determines the encryption label of each data exchange request based on the sensitive feature vector of each data exchange request, the request feature vector, the receiving feature vector, the historical request exchange evaluation value, and the historical receiving exchange evaluation value, including:

[0114] ;

[0115] ;

[0116] ;

[0117] wherein, represents the encryption label of the a-th data exchange request, represents the encryption score value of the a-th data exchange request, represents the data matching value of the a-th data exchange request, represents the sensitive feature vector of the a-th data exchange request, represents the request feature vector of the a-th data exchange request, a-th data exchange request, a first anti-zero parameter, a second anti-zero parameter, a difference value of the request feature vector and the receiving feature vector of the a-th data exchange request, a first encryption score threshold value, a second encryption score threshold value.

[0118] In this embodiment, is an interaction term of the sensitive feature vector and the request feature vector of the a-th data exchange request, indicating the matching degree of the sensitive information of the a-th data exchange request and the request business scenario and the request data asset type.

[0119] In this embodiment, is a normalized similarity of the sensitive feature vector and the receiving feature vector of the a-th data exchange request, indicating the matching degree of the sensitive information of the a-th data exchange request and the receiving business scenario and the receiving data asset type.

[0120] In this embodiment, if and are very close, it indicates that the business needs and data asset types of the requestor and the receiver are similar, and the data exchange is reasonable, so that the encryption strength can be reduced; if and are quite different, it indicates that the business scenarios and data asset types of the requestor and the receiver are different, which may involve data abuse or cross-industry circulation, and the encryption strength needs to be improved.

[0121] In this embodiment, is used to punish the mismatch of the request business scenario, the request data asset type, the receiving business scenario, and the receiving data asset type.

[0122] In this embodiment, the greater the encryption score value is: it indicates that the sensitivity of the corresponding data exchange request is higher, or the similarity between the requestor and the receiver is stronger, and higher encryption protection is needed.

[0123] In this embodiment, the smaller the encryption score value is: it indicates that the sensitivity of the corresponding data exchange request is lower, or the similarity between the requestor and the receiver is weaker, and lower encryption strength can be used to improve efficiency.

[0124] The beneficial effects of the above technical solutions are: based on the sensitive feature vector, the request feature vector, the receiving feature vector, the historical request exchange evaluation value, and the historical receiving exchange evaluation value of each data exchange request, the encryption label of each data exchange request is determined, high-quality data support is provided for determining hierarchical data, accurate protection of different data is realized, and data security is improved.

[0125] Embodiment 6:

[0126] The embodiment of the application provides a data encryption and privacy protection method of a trusted data exchange platform, which encrypts hierarchical data, and comprises the following steps:

[0127] Sensitive data of each to-be-exchanged sub-data in the to-be-exchanged data is encrypted in a format reservation mode.

[0128] In the hierarchical data, the data of each data exchange request, which is to be exchanged and is except the sensitive data, in the hierarchical sub-data with a first-level encryption tag is encrypted based on a first-level strategy, and a first-level key is generated.

[0129] In the hierarchical data, the data of each data exchange request, which is to be exchanged and is except the sensitive data, in the hierarchical sub-data with a second-level encryption tag is encrypted based on a second-level strategy, and a second-level key is generated.

[0130] In the hierarchical data, the data of each data exchange request, which is to be exchanged and is except the sensitive data, in the hierarchical sub-data with a third-level encryption tag is encrypted based on a third-level strategy, and a third-level key is generated.

[0131] In the embodiment, the first-level strategy can be SM4-256 (in a CBC mode) + SM3 hash integrity verification + asymmetric key exchange based on SM2.

[0132] In the embodiment, the second-level strategy can be AES-256-GCM (supporting stream encryption and authentication encryption) + RSA-3076 key encapsulation.

[0133] In the embodiment, the third-level strategy can be ChaCha20-Poly1305 lightweight encryption + ECDH key agreement.

[0134] In the embodiment, the first-level key can be a true random number key generated by a hardware security module (HSM) and stored in a blockchain network (based on a threshold signature scheme TSS) in a fragmented mode.

[0135] In the embodiment, the second-level key can be a sub-key derived from a master key by using a key derivation function (KDF) and binding a session ID.

[0136] In the embodiment, the third-level key can be based on a temporary session key (forward security design).

[0137] In this embodiment, the sensitive data in each sub-data to be exchanged in the data to be exchanged is format-preserved encrypted. This means that the sensitive data is encrypted while preserving the format structure of the original data. For example, if the original data is in date format or number format, after encryption, it still maintains these formats, rather than becoming unrecognizable random codes. Format-preserved encryption ensures that the data can continue to be processed during the exchange process, but protects the sensitive information of the data from being leaked.

[0138] In this embodiment, the data to be exchanged in the hierarchical sub-data with a first-level encryption encryption tag is encrypted. The first-level encryption is targeted at data other than sensitive data. The first-level encryption is suitable for high-risk data, and the strongest encryption algorithm and key strategy are used to maximize the protection of the confidentiality and integrity of the data.

[0139] In this embodiment, the data to be exchanged in the hierarchical sub-data with a second-level encryption encryption tag is encrypted. In addition to sensitive data, other data will be encrypted based on a second-level encryption strategy and generate a second-level key. The second-level encryption is suitable for medium-risk data and requires stronger encryption protection to ensure that even if the data is intercepted, it cannot be accessed by unauthorized parties.

[0140] In this embodiment, the data to be exchanged in the hierarchical sub-data with a third-level encryption encryption tag is encrypted. In addition to sensitive data, other data will be encrypted based on a third-level encryption strategy and generate a third-level key. The platform will use the third-level key to encrypt these non-sensitive data based on the third-level encryption strategy, ensuring that they are protected during the data exchange process.

[0141] The beneficial effects of the above technical solutions are: data encryption of hierarchical data can achieve accurate protection of different data, improve data security, ensure efficiency and flexibility during data exchange, and enhance personalized protection of different data.

[0142] Embodiment 7:

[0143] The embodiment of the application provides a data encryption and privacy protection method of a trusted data exchange platform, which transmits the hierarchical data after data encryption, comprising:

[0144] Based on the transmission protocol of each encryption tag, the hierarchical sub-data of each encryption tag after data encryption is transmitted.

[0145] In this embodiment, during the data exchange process, the platform selects a corresponding transmission protocol for different hierarchical sub-data based on each encryption tag. According to the encryption level (first level, second level, third level) of the data, the platform will use different encryption transmission strategies and protocols for hierarchical sub-data with different encryption tags.

[0146] In this embodiment, for the hierarchical sub-data of the first-level encryption, the strongest transmission protocol is adopted to ensure the absolute confidentiality and security of the high-sensitivity data.

[0147] In this embodiment, for the hierarchical sub-data of the second-level encryption, the platform selects a more stringent transmission protocol to provide higher security and data integrity protection.

[0148] In this embodiment, for the hierarchical sub-data of the third-level encryption, a simpler transmission protocol is adopted to ensure the secure transmission of low-risk data.

[0149] In this embodiment, for each data exchange request, the platform will transmit the encrypted data according to the protocol specified by the corresponding encryption label. Different transmission protocols will adopt different encryption methods, identity verification methods, data integrity checks, and other measures according to encryption strength and security requirements.

[0150] In this embodiment, the first-level transmission protocol provides the strongest encryption protection, suitable for the transmission of highly sensitive data to prevent data from being stolen or tampered with during transmission.

[0151] In this embodiment, the second-level transmission protocol provides medium-level encryption and security to ensure the secure transmission of medium-risk data.

[0152] In this embodiment, the third-level transmission protocol is suitable for the rapid transmission of low-risk data, with lower security and encryption strength.

[0153] The beneficial effects of the above technical solutions are: performing data transmission on the encrypted hierarchical data can achieve fine encryption protection and secure transmission, improve the efficiency of data exchange, enhance the protection capability of data at different security levels, reduce the risk of data leakage and tampering, and improve the credibility and security of the data exchange platform.

[0154] Embodiment 8:

[0155] The embodiment of the application provides a data encryption and privacy protection method of a trusted data exchange platform, which monitors the data transmission of hierarchical data in real time, generates a data exchange report, and realizes trusted data exchange, comprising:

[0156] Monitoring the data transmission of each data exchange request of the hierarchical sub-data of each encryption label in the hierarchical data, determining the exchange time, leaked data, and successfully exchanged data of each data exchange request;

[0157] Determining the data leakage value of each data exchange request based on the leaked data, successfully exchanged data, and waiting exchange data of each data exchange request;

[0158] Based on the exchange time, waiting exchange data, data matching value, leaked data, successfully exchanged data and data leakage value of each data exchange request, a data exchange sub-report of each data exchange request is generated;

[0159] Based on the data exchange sub-reports of all data exchange requests, a data exchange report of the data exchange platform is generated.

[0160] In this embodiment, during the data exchange process, the platform monitors the transmission process of the hierarchical sub-data of each encrypted label in real time. The monitoring content includes: exchange time: records the time of each data exchange; leaked data: if any data leakage event is found during the monitoring process, the amount and type of leaked data are recorded in time; successfully exchanged data: the amount and type of data successfully completed exchange, without any leakage or loss.

[0161] In this embodiment, the calculation formula of the data leakage value can be: .

[0162] In this embodiment, according to the monitoring data of each data exchange request, the platform generates a data exchange sub-report. The report includes: exchange time, data matching value, leaked data, successfully exchanged data, data leakage value, etc., which details the process, effectiveness and risk of each exchange.

[0163] In this embodiment, the platform integrates all data exchange sub-reports to generate a general data exchange report.

[0164] The beneficial effects of the above technical solutions are: real-time monitoring of hierarchical data transmission, generating a data exchange report, realizing trusted data exchange, which can improve the transparency of the data exchange process, improve the security and credibility of data exchange, and reduce the potential risk of data leakage.

[0165] The device embodiments described above are only schematic, wherein the units illustrated as separate components can or can not be physically separate, and the components illustrated as units can or can not be physical units, i.e., can be located in one place, or can be distributed on multiple network units. According to actual needs, part or all of the modules can be selected to achieve the purpose of the embodiment. Those skilled in the art can understand and implement without creative labor.

[0166] Those skilled in the art can clearly understand the technical solutions of the various embodiments from the above description of the embodiments, and the various embodiments can be implemented by means of software with the necessary general hardware platforms, and of course, can also be implemented by hardware. Based on such understanding, the above technical solutions, essentially or in other words, the part of the prior art that makes a contribution, can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, and the like, and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0167] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for some technical features therein; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A data encryption and privacy protection method of a trusted data exchange platform, characterized in that, Comprising: Step 1: The data exchange platform receives data exchange requests of multiple requesters, and determines the data to be exchanged of the data exchange platform, wherein the data to be exchanged comprises multiple data to be exchanged; Step 2: Extract and analyze the requester data and receiver data of each data to be exchanged in the data to be exchanged, determine the historical request exchange evaluation value and the historical receiving exchange evaluation value of each data to be exchanged; Step 3: Based on the data to be exchanged, the requester data, the receiver data, the historical request exchange evaluation value and the historical receiving exchange evaluation value, determine the encryption label of each data exchange request, and determine the hierarchical data of the data exchange platform; Step 4: Data encryption is performed on the hierarchical data, and data transmission is performed on the hierarchical data after data encryption; Step 5: Real-time monitoring of the data transmission of the hierarchical data, generating a data exchange report, realizing trusted data exchange; Wherein, extracting and analyzing the requester data and receiver data of each data to be exchanged in the data to be exchanged, determining the historical request exchange evaluation value and the historical receiving exchange evaluation value of each data to be exchanged, comprising: From the database of the data exchange platform, extract the requester data of the requester of the data exchange request of each data to be exchanged in the data to be exchanged, wherein the requester data comprises request business scenario, request data asset type and request historical exchange data, wherein the request historical exchange data comprises the data exchange sub report of the requester in each historical data exchange within a historical specified time period; Based on the request historical exchange data of each data exchange request, calculate the historical request exchange evaluation value of each data to be exchanged; ; wherein, represents a historical request exchange evaluation value of the a-th data exchange request, represents a number of historical data exchanges of the requestor in the request historical exchange data of the a-th data exchange request within a historical specified time period, represents a data leakage value in a data exchange sub-report of the i-th historical data exchange of the requestor in the request historical exchange data of the a-th data exchange request, represents a data matching value in a data exchange sub-report of the i-th historical data exchange of the requestor in the request historical exchange data of the a-th data exchange request, represents a matching factor, represents a leakage factor, represents a frequency factor, represents a current time, represents a time decay factor, represents an exchange time in a data exchange sub-report of the i-th historical data exchange of the requestor in the request historical exchange data of the a-th data exchange request, represents an exchange time in a data exchange sub-report of the 1-th historical data exchange of the requestor in the request historical exchange data of the a-th data exchange request within a historical specified time period; From the database of the data exchange platform, extract the receiver data of the receiver of the data exchange request of each data to be exchanged in the data to be exchanged, wherein the receiver data comprises receiving business scenario, receiving data asset type and receiving historical exchange data, wherein the receiving historical exchange data comprises the data exchange sub report of each historical data exchange within a historical specified time period; Based on the receiving historical exchange data of each data exchange request, calculate the historical receiving exchange evaluation value of each data to be exchanged; ; wherein, represents a history reception exchange evaluation value of the a-th data exchange request, represents a number of history data exchanges of the a-th data exchange request in the reception history exchange data of the a-th data exchange request, represents a data matching value in the data exchange sub-report of the j-th history data exchange of the reception party in the reception history exchange data of the a-th data exchange request, represents a data leakage value in the data exchange sub-report of the j-th history data exchange of the reception party in the reception history exchange data of the a-th data exchange request, represents an exchange time in the data exchange sub-report of the 1st history data exchange of the reception party in the reception history exchange data of the a-th data exchange request, represents an exchange time in the data exchange sub-report of the j-th history data exchange of the reception party in the reception history exchange data of the a-th data exchange request, represents a length of time of the history specified time period, represents a reference exchange frequency of the data exchange platform.

2. The data encryption and privacy protection method of a trusted data exchange platform according to claim 1, characterized in that, The data exchange platform receives data exchange requests of multiple requesters, and determines the data to be exchanged of the data exchange platform, comprising: The data exchange platform determines the receiver of each data exchange request, and respectively authenticates the requester and the receiver of each data exchange request; The data exchange request of the requester and the receiver is received simultaneously through the identity authentication, wherein the data to be exchanged at least comprises the requester, the receiver, the request time and the data to be exchanged of the data exchange request; Based on all the received data to be exchanged, determine the data to be exchanged of the data exchange platform.

3. The data encryption and privacy protection method of a trusted data exchange platform according to claim 1, characterized in that, Based on the data to be exchanged, the requester data, the receiver data, the historical request exchange evaluation value and the historical receiving exchange evaluation value, determine the encryption label of each data exchange request, and determine the hierarchical data of the data exchange platform, comprising: The waiting exchange data of each to-be-exchanged sub-data in the to-be-exchanged data is subjected to sensitive information identification, and sensitive data of each to-be-exchanged sub-data is determined. The sensitive data of each to-be-exchanged sub-data in the to-be-exchanged data is subjected to feature extraction, and a sensitive feature vector of the data exchange request of each to-be-exchanged sub-data is determined, wherein the sensitive feature vector includes multiple sensitive features. The request business scenario and the request data asset type in the requestor data of each data exchange request are subjected to feature extraction, and a request feature vector of each data exchange request is determined, and the receiving business scenario and the receiving data asset type in the receiver data of each data exchange request are subjected to feature extraction, and a receiving feature vector of each data exchange request is determined. Based on the sensitive feature vector, the request feature vector, the receiving feature vector, the historical request exchange evaluation value and the historical receiving exchange evaluation value of each data exchange request, an encryption label of each data exchange request is determined. Based on the to-be-exchanged sub-data of all data exchange requests with the same encryption label, a hierarchical sub-data of each encryption label is determined. Based on the hierarchical sub-data of all encryption labels, a hierarchical data of the data exchange platform is determined.

4. The data encryption and privacy protection method of a trusted data exchange platform according to claim 3, characterized in that, Based on the sensitive feature vector, the request feature vector, the receiving feature vector, the historical request exchange evaluation value and the historical receiving exchange evaluation value of each data exchange request, an encryption label of each data exchange request is determined. ; ; ; wherein, represents an encryption label of the a-th data exchange request, represents an encryption score value of the a-th data exchange request, represents a data matching value of the a-th data exchange request, represents a sensitive feature vector of the a-th data exchange request, represents a request feature vector of the a-th data exchange request, represents a reception feature vector of the a-th data exchange request, represents a first anti-zero parameter, represents a second anti-zero parameter, represents a difference value of the request feature vector and the reception feature vector of the a-th data exchange request, represents a primary encryption score threshold value, represents a secondary encryption score threshold value.

5. The data encryption and privacy protection method of a trusted data exchange platform according to claim 3, characterized in that, The hierarchical data is subjected to data encryption, including: The sensitive data of each to-be-exchanged sub-data in the to-be-exchanged data is subjected to format-preserving encryption; In the hierarchical sub-data with the first-level encryption in the hierarchical data, the data of each data exchange request in the waiting exchange data except the sensitive data is subjected to encryption based on a first-level strategy, and a first-level key is generated; In the hierarchical sub-data with the second-level encryption in the hierarchical data, the data of each data exchange request in the waiting exchange data except the sensitive data is subjected to encryption based on a second-level strategy, and a second-level key is generated; In the hierarchical sub-data with the third-level encryption in the hierarchical data, the data of each data exchange request in the waiting exchange data except the sensitive data is subjected to encryption based on a third-level strategy, and a third-level key is generated.

6. The data encryption and privacy protection method of a trusted data exchange platform according to claim 5, characterized in that, The hierarchical data subjected to data encryption is subjected to data transmission, including: The hierarchical sub-data of each encryption label subjected to data encryption is subjected to data transmission based on the transmission protocol of each encryption label respectively.

7. The data encryption and privacy protection method of a trusted data exchange platform according to claim 4, characterized in that, The data transmission of the hierarchical data is monitored in real time to generate a data exchange report, and trusted data exchange is realized, including: The data transmission of the to-be-exchanged sub-data in the hierarchical sub-data of each encryption label in the hierarchical data is monitored in real time to determine the exchange time, the leaked data and the successfully exchanged data of each data exchange request; The data leakage value of each data exchange request is determined based on the leaked data, the successfully exchanged data and the waiting exchange data of each data exchange request; The data exchange sub-report of each data exchange request is generated based on the exchange time, the waiting exchange data, the data matching value, the leaked data, the successfully exchanged data and the data leakage value of each data exchange request. Based on the data exchange sub-reports of all data exchange requests, a data exchange report of the data exchange platform is generated.

Citation Information

Patent Citations

  • Financial data protection system based on cloud computing

    CN118410524A

  • Data exchange management method and system

    CN118473784A