Data asset voucher security control method and system based on data ownership control technology
Data asset certificates (DAC) are constructed through data ownership control (DOC) technology, which solves the problem of data in blockchain technology that cannot be stored on the holder's mobile phone, is inflexible and vulnerable to attacks, realizes the secure storage and flexible use of data assets, and enhances the security and regulatory capabilities of data assets.
Patent Information
- Application Number
- CN202410025393.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-08
- Publication Date
- 2025-07-08
AI Technical Summary
The existing data asset rights confirmation, exercise and rights protection solutions based on blockchain technology have problems such as data that cannot be truly stored on the holder's mobile phone, inflexible use, vulnerable to hackers, low network carrying capacity, and foreign technology is not conducive to supervision.
Data ownership control (DOC) technology is used to construct data asset certificate (DAC) templates to desensitize and hide sensitive information, use time stamped digital signatures to confirm rights, and securely package them on mobile devices, add text to add, and combine multi-domain black box verification to realize the confirmation, exercise and protection of data assets.
It realizes the secure storage and flexible use of data assets on the holder's mobile phone, prevents hacker attacks, avoids data silos, and enhances the security and regulatory capabilities of data assets.
Smart Images

Figure CN120277643A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to data security technology, specifically to the technology for the confirmation of rights, exercise of rights, and protection of rights of data assets. Background Art
[0002] The core elements of WEB3.0 can be summarized as: data right confirmation, data control right, data circulation right, and data value sharing right. Thus, various data elements can be conveniently transformed into data assets. From the perspective of the implementation and construction of WEB3.0, the blockchain technology is generally considered in the industry to be the best underlying support technology for WEB3.0. The anonymous registration, decentralization, distributed storage, smart contract, and accounting mechanism of the blockchain can well solve problems such as the confirmation of rights, authorization, control, circulation, sharing, transaction, and privacy protection of data. However, the blockchain technology is not the only option for WEB3.0. The blockchain technology also has its inherent weaknesses. For example, multi-node storage will lead to low storage efficiency; it is impossible to multi-point bear the same large-capacity data; the deployment of large-capacity data on heavy nodes will lead to a significant reduction in access efficiency. The blockchain technology is extremely likely to form a new "information island", and there is currently no effective supervision method for data on the chain; data applications are completely dependent on the blockchain environment and other problems. To overcome these weaknesses, it is necessary to explore and study whether there are other new technologies that can replace the blockchain technology or can be used as a supplement to the blockchain technology. The data ownership control (DOC) technology has thus emerged.
[0003] The data ownership control (DOC) technology is a new type of integrated technology independently developed in China. It originated from the wide application of electronic licenses in the government's "one network for all services" initiative. As the carrier technology of electronic licenses, it provides overall right confirmation protection, self-control use, and security control for electronic licenses, and has become an effective technology for upgrading the circulation management of license data elements to the right confirmation control of license data assets. The data ownership control (DOC) technology adopts the integration of multiple technologies such as signature, signing, desensitization, hiding, annotation, watermark, label, multi-domain, and black box, effectively ensuring the realization of the capabilities of data assets such as right confirmation, authorization, limit control, verification, data extraction, exchange and circulation, anti-leakage, anti-attack, non-tampering, non-counterfeiting, non-forgery, and non-repudiation on the network. The data ownership control (DOC) technology already fully possesses the support capabilities of the core elements of WEB3.0.
[0004] Existing data rights confirmation and control both adopt blockchain technology and rely on ledger-based bookkeeping methods to achieve the solidification and rights confirmation of data on the blockchain, and use smart contract tools to control the data. The storage method is a combination of centralized and distributed, that is, the data is centrally stored on a certain heavy node, and the data payload (HASH value) is stored on each node of the blockchain, facilitating the verification of the HASH value of the data on any node. There are the following deficiencies in this data rights confirmation and control method: 1. It completely depends on the blockchain, and the blockchain is not a network that can cover the whole society, easily forming data islands and having poor data sharing; 2. When the data assets are placed on the blockchain, the holder still feels that they are not in his own hands, which does not conform to the concept advocated by the state that whoever owns the data assets controls them, and the usability is poor; 3. When the data assets are stored on the blockchain, the holder can only rely on the blockchain to use them when using, and the usability and flexibility are poor; 4. Blockchain storage is also vulnerable to hacker attacks. Once breached, all data will be leaked, and the security is poor; 5. Blockchain technology comes from abroad, which is not conducive to the state's supervision of data.
[0005] Therefore, the existing data asset rights confirmation, exercise, and protection solutions supported by blockchain technology have the following main problems: 1. The confirmed data assets cannot be truly stored on the holder's mobile phone; 2. The scope and time of use of the data assets cannot be flexibly controlled when using; 3. It is impossible to effectively prevent hacker attacks when verifying the validity of data assets, and data leakage is likely to occur; 4. The carrying capacity and processing efficiency of the blockchain network are very low and cannot be used by a large number of users together; 5. Blockchain technology comes from abroad, which is not conducive to the supervision of data.
[0006] Therefore, how to effectively overcome the deficiencies of the existing data asset rights confirmation, exercise, and protection solutions based on blockchain technology is an urgent problem to be solved in this field. Summary of the Invention
[0007] Aiming at the problems existing in the existing data asset security management and control technology, the purpose of the present invention is to provide a security management and control solution for data assets based on Data Ownership Control (DOC) technology, realizing effective management and control of data asset certificates (DAC) for rights confirmation, exercise, and protection based on Data Ownership Control (DOC) technology (a technology belonging to the category of integrated technologies), which can effectively overcome the problems existing in the prior art.
[0008] To achieve the above purpose, the present invention provides a security management and control method for data assets based on Data Ownership Control (DOC) technology, and the security management and control method includes the following steps:
[0009] Step 1: Construct a Data Asset Certificate (DAC) template, input the corresponding data asset information into the Data Asset Certificate (DAC) template, and generate a Data Asset Certificate (DAC);
[0010] Step 2: Desensitize and hide the sensitive information on the cover of the Data Asset Certificate (DAC) and the sensitive information inside the Data Asset Certificate (DAC);
[0011] Step 3: Store the desensitized and hidden data asset information back into the Data Asset Certificate (DAC), and use a digital signature with a timestamp to electronically sign or digitally sign the Data Asset Certificate (DAC) to complete the confirmation of rights for the Data Asset Certificate (DAC);
[0012] Step 4: For the Data Asset Certificate (DAC) after the confirmation of rights, use a secure label encapsulation method to store the Data Asset Certificate (DAC) with a security label in a mobile device;
[0013] Step 5: The Data Asset Certificate (DAC) stored on the mobile device will be embedded with corresponding additional text based on an additional text annotation method, and a digital signature for the additional text will be completed to complete the exercise of rights for the Data Asset Certificate (DAC);
[0014] Step 6: During the network circulation and interaction process of the Data Asset Certificate (DAC), after being received by the receiving party's terminal device, it will be submitted to a certificate verification platform on the Internet for verification;
[0015] Step 7: For the verification result feedback by the certificate verification platform, decrypt the verification result based on the requester's ID parameter, and after passing the verification, read the cover information, sensitive information, and additional text information inside the Data Asset Certificate (DAC) through relevant interface forms to complete the protection of rights for the Data Asset Certificate (DAC).
[0016] In some embodiments of the present invention, the production of the Data Asset Certificate (DAC) template in step (1) includes the following steps:
[0017] Step A1: Scan a pre-designed cover picture of the Data Asset Certificate (DAC) to become the base plate of the Data Asset Certificate (DAC);
[0018] Step A2: According to the set cover information elements of the Data Asset Certificate (DAC), complete the definition of information attributes associated with the cover information elements on the base plate;
[0019] Step A3: Pre-generate an unlimited number of blank fields with specified names on the Data Asset Certificate (DAC) to complete the production of the blank template of the Data Asset Certificate (DAC).
[0020] In some embodiments of the present invention, when performing desensitization and hiding processing on sensitive information in step (2), according to the pre-set data desensitization and hiding policy information, for the sensitive information on the cover of the Data Asset Certificate (DAC), a masking operation is performed by using a mask to replace the sensitive information with "*", and the original sensitive information on the cover is stored in the Data Asset Certificate (DAC); for the sensitive information in the Data Asset Certificate (DAC), it is hidden in the Data Asset Certificate (DAC) in XML form and attached behind the Data Asset Certificate (DAC).
[0021] In some embodiments of the present invention, when encapsulating the confirmed Data Asset Certificate (DAC) based on the security label encapsulation method in step (4), it includes:
[0022] Step B1: Extract the basic attributes of the Data Asset Certificate (DAC) file to form a label file;
[0023] Step B2: Extract the encryption key based on the generated pseudo-random number, complete the overall encryption of the Data Asset Certificate (DAC), and then store the corresponding decryption key in the label file;
[0024] Step B3: Use the ID parameter key of the target mobile phone to encrypt the label file once with the corresponding encryption algorithm, load the encrypted label file onto the Data Asset Certificate (DAC) file, form a uniquely bound labeled Data Asset Certificate (DAC), and store it in the data space of the mobile device.
[0025] In some embodiments of the present invention, when embedding the corresponding additional text based on the additional text annotation method in step (5), it includes:
[0026] Step C1: Input the additional text content on the target mobile phone;
[0027] Step C2: According to the set additional text embedding strategy and additional text embedding method, embed the input additional text onto the Data Asset Certificate (DAC) of the target mobile phone in a visual form or a hidden form;
[0028] Step C3: Adopt the anti-counterfeiting method of the additional text to sign the Data Asset Certificate (DAC) and the additional text of the target mobile phone with a digital signature with a time stamp;
[0029] Step C4: Generate a mobile phone Data Asset Certificate (DAC) with the additional text embedded and protected by a digital signature with a time stamp, which can verify the validity of the digital signature information and domain of the additional text.
[0030] In some embodiments of the present invention, in step (6), a multi-domain black box verification method is used to verify the Data Asset Certificate (DAC), including:
[0031] Step D1: For the received Data Asset Certificate (DAC) verification request, the voucher verification platform sends the ID of the requester and the Data Asset Certificate (DAC) into the security verification area. The security verification area only receives task requests sent by the voucher verification platform and rejects all other requests.
[0032] Step D2: In the security verification area, verify the validity of the electronic signature or digital signature with a timestamp, the names and attributes of various "domains", the timestamped digital signature of the additional text, and the timestamped digital signature of the status domain of the Data Asset Certificate (DAC).
[0033] Step D3: Extract the time information in the Data Asset Certificate (DAC) and the time information in the additional text, and verify its validity.
[0034] Step D4: Extract the status information of the Data Asset Certificate (DAC) and verify its validity.
[0035] After the verification is completed, the verification result is encrypted using an encryption algorithm with the requester ID as a parameter and returned to the voucher verification platform.
[0036] In some embodiments of the present invention, blank "domains" are reserved on the Data Asset Certificate (DAC) of the mobile phone terminal without digital signature or electronic signature. The reserved blank "domains" are configured to be able to dynamically embed visual additional text or hide the stored additional text when adding additional text, and to securely verify the "domain" name and content information.
[0037] To achieve the above object, the present invention provides a data asset certificate security control system based on data ownership control technology. The security control system includes a Data Asset Certificate (DAC) confirmation unit, a Data Asset Certificate (DAC) exercise unit, a Data Asset Certificate (DAC) rights protection unit, a voucher template production module unit, a security label encapsulation module unit, an additional text annotation module unit, and a multi-domain black box verification module unit.
[0038] The Data Asset Certificate (DAC) confirmation unit is configured to complete the confirmation of the Data Asset Certificate (DAC) through the organic cooperation of voucher template production, data desensitization hiding, and electronic signature / digital signature with a timestamp.
[0039] The Data Asset Certificate (DAC) exercise unit is configured to complete the exercise of the Data Asset Certificate (DAC) through the organic cooperation of security label encapsulation and additional text annotation.
[0040] The data asset certificate (DAC) rights protection unit is configured to complete the rights protection of the data asset certificate (DAC) through the organic cooperation of multi-domain black box verification and extraction of certificate information;
[0041] The certificate template making module unit is configured to make the bottom plate of the certificate and input the face information of the data asset certificate into the bottom plate of the data asset certificate (DAC). The certificate template making module unit is configured to be callable by the data asset certificate (DAC) right confirmation unit;
[0042] The security label encapsulation module unit is configured to uniquely bind the label file to the confirmed data asset certificate (DAC) and save it to the mobile phone. The security label encapsulation module unit is configured to be callable by the data asset certificate (DAC) exercise unit;
[0043] The additional text annotation module unit is configured to embed additional text into the confirmed data asset certificate (DAC) on the mobile phone and complete the digital signature of the additional text; the additional text annotation module unit is configured to be callable by the data asset certificate (DAC) exercise unit;
[0044] The black box verification module unit is configured to receive, in a relatively secure and controllable space, the data asset certificate (DAC) that has completed the right confirmation and exercise processes by the data asset certificate (DAC) right confirmation unit and the data asset certificate (DAC) exercise unit submitted by the certificate verification platform, verify the validity and authenticity of multi-domain contents such as its electronic seal, digital signature, certificate validity time, and certificate status, and encrypt and return the verification result to the certificate verification platform; the black box verification module unit is configured to be callable by the data asset certificate (DAC) rights protection unit.
[0045] In some embodiments of the present invention, the data asset certificate (DAC) right confirmation unit includes a certificate template making module, a data desensitization and hiding module, and a timestamped electronic signature / digital signature module; the certificate template making module is configured to be able to make the data asset certificate (DAC); the data desensitization and hiding module is configured to interact with the certificate template making module and be able to perform desensitization and hiding processing on the sensitive information on the cover of the data asset certificate (DAC) and the sensitive information inside the data asset certificate (DAC); the timestamped electronic signature / digital signature module is configured to be able to perform electronic signature / digital signature protection on the data asset certificate (DAC) file after desensitization and hiding processing.
[0046] In some embodiments of the present invention, the data asset certificate (DAC) exercise unit includes a security label encapsulation module and an additional text annotation module; the security label encapsulation module is configured to uniquely bind a label file and a data asset certificate (DAC) and save them to a mobile phone; the additional text annotation module is configured to embed additional text into the data asset certificate (DAC) and complete a digital signature of the additional text.
[0047] In some embodiments of the present invention, the data asset certificate (DAC) rights protection unit includes a multi-domain black box verification module and an extraction of certificate information module;
[0048] The multi-domain black box verification module is configured to run in a relatively secure and controllable space and is used to verify the validity and authenticity of the multi-domain content of the electronic seal, digital signature, certificate expiration time, and certificate status of the data asset certificate (DAC), and encrypt and return the verification result;
[0049] The extraction of certificate information module is configured to interact with the multi-domain black box verification module and, after the data asset certificate (DAC) is verified, read the cover information, sensitive information, and additional text information in the data asset certificate (DAC) through relevant interface forms.
[0050] In some embodiments of the present invention, the certificate template production module unit includes a certificate base plate production module, an associated certificate cover information attribute module, a blank field generation module, and a certificate template storage module;
[0051] The certificate base plate production module is configured to make the cover picture of the data asset certificate (DAC) into the base plate of the certificate;
[0052] The associated certificate cover information attribute module is configured to complete the definition of the information attributes associated with the cover information elements on the base plate;
[0053] The blank field generation module is configured to pre-generate an unlimited number of blank "fields" with specified names on the data asset certificate (DAC) to complete the production of the blank template of the data asset certificate (DAC);
[0054] The certificate template storage module is configured to store the blank template of the data asset certificate (DAC) in the template database of the data asset certificate (DAC) after the production of the blank template of the data asset certificate (DAC) is completed.
[0055] In some embodiments of the present invention, the security label encapsulation module unit includes a label file generation module, a certificate encryption module, a label file encryption module, and a label and certificate decryption module;
[0056] The label file generation module is configured to be able to extract the basic attributes of the Data Asset Credential (DAC) file to form a label file;
[0057] The credential encryption module is configured to be able to extract the encryption key according to the generated pseudo-random number, and accordingly complete the overall encryption of the Data Asset Credential (DAC), and then store the corresponding decryption key in the label file;
[0058] The label file encryption module is configured to be able to encrypt the label file once based on the ID parameter key of the mobile phone, load the label file onto the Data Asset Credential (DAC) file, form a uniquely bound labeled Data Asset Credential (DAC), and store it in the data space of the device;
[0059] The label and credential decryption module is configured to be able to decrypt the label file of the Data Asset Credential (DAC) in the data space based on the ID parameter key of the mobile phone, and then take out the decryption key of the Data Asset Credential (DAC) to perform a decryption operation on the Data Asset Credential (DAC).
[0060] In some embodiments of the present invention, the additional text annotation module unit includes a mobile phone additional text information module, an additional text embedding strategy module, an additional text embedding algorithm module, a mobile phone credential embedding additional text processing module, and a mobile phone digital signature module;
[0061] The mobile phone additional text information module is configured to be able to input additional text content on the mobile phone;
[0062] The additional text embedding strategy module is configured to be able to embed the input additional text content in a visual form or a hidden storage form on the Data Asset Credential (DAC), and complete the setting of the additional text embedding strategy;
[0063] The additional text embedding algorithm module is configured to be able to automatically identify and dynamically calculate the font size and position of the text according to the additional text embedding strategy and the amount of the input additional text content;
[0064] The mobile phone credential embedding additional text processing module is configured to be able to embed the additional text content onto the mobile phone Data Asset Credential (DAC) according to the additional text embedding strategy information.
[0065] The mobile phone digital signature module is configured to be able to use the embedded additional text as the content form of the "field" and perform signature protection on the additional text in a digital signature manner with a time stamp.
[0066] In some embodiments of the present invention, the multi-domain black box verification module unit includes a credential element verification module, a time verification module, a status content verification module, and a verification result encryption and return module;
[0067] The described credential element verification module is configured to, after receiving a data asset credential (DAC) request on the credential verification platform, send the requester ID and the data asset credential (DAC) into the security verification area together, and in the security verification area, verify the data asset credential (DAC) for its timestamped electronic signature or digital signature, the names and attributes of various "domains", the timestamped digital signature of the additional text, and the timestamped digital signature of the status domain;
[0068] The time verification module is configured to extract the time information in the data asset credential (DAC) and the time information in the additional text, and verify its validity;
[0069] The status content verification module is configured to extract the status information of the data asset credential (DAC), and verify its validity;
[0070] The verification result encryption and return module is configured to, after the verification is completed, encrypt the verification result based on an encryption algorithm with the requester ID as a parameter and return it to the credential verification platform.
[0071] The security control solution for data assets provided by the present invention based on the data ownership control (DOC) technology has the following technical characteristics compared with the data asset control solution of blockchain technology:
[0072] 1. Using a layout file as the carrier container of the data asset, and adopting national commercial cryptography technology, the data asset credential (DAC) is authenticated through a timestamped electronic signature / digital signature, which is safer, more convenient, and more popular with holders than the blockchain technology commonly used in the industry as a method for authenticating data assets. At the same time, it has a flexible and comprehensive privacy protection function;
[0073] 2. It breaks through the problems that the layout file cannot be edited on the mobile device and the existing electronic signature / digital signature protection function of the layout file will be damaged when adding additional information, completes the operation of adding additional text information to the data asset credential (DAC) on the mobile device, and realizes the exercise of rights of the data asset credential (DAC). At the same time, the data asset credential (DAC) on the mobile device is uniquely bound to the security label, ensuring the security and flexibility of the mobile device credential;
[0074] 3. It breaks through the traditional single verification method of vouchers and adopts multi-domain verification technology. It is necessary to verify the electronic seal of the voucher to ensure that the issuing agency of the voucher will not forge; it is also necessary to verify the personal digital signature of the voucher user to ensure that the voucher user is not a forged imposter; it is also necessary to verify the current status validity of the voucher and that the key information has not been tampered with, etc. The rights protection of the Data Asset Certificate (DAC) is realized;
[0075] 4. When making the voucher template, embedding technology is used to pre-generate several blank fields with attributes, laying a foundation for adding annotation information and status information when using the voucher after the voucher is confirmed;
[0076] 5. Adopting the label technology that meets the requirements of national cryptography, it realizes the high-strength encryption protection of "one document, one key" and "one time, one key" for voucher files;
[0077] 6. It realizes that additional text is embedded in the voucher in two forms: visible or invisible. On the basis of not destroying the existing electronic signature protection of the voucher, it is superimposed on any page of the voucher in the form of a watermark and a personal digital signature is made to ensure the effectiveness and non-repudiation of the annotation information;
[0078] 7. The entire verification process is carried out in a secure verification area (i.e., "black box"), and the verification result is transmitted to the requester by an encryption method to prevent the verification result from being tampered with when the voucher verification platform is attacked by network hackers.
[0079] The security control solution for data assets based on data ownership control technology provided by the present invention has the following beneficial effects compared with the prior art:
[0080] 1. Data assets can be safely and effectively landed on the mobile phone of the holder, and the immersive experience of "whoever's assets, whoever controls" can be truly realized. The rights exercise behaviors such as authorization, annotation, and submission of data assets can be directly realized on the mobile phone;
[0081] 2. The operation of the Data Asset Certificate (DAC) completely depends on the Internet, not on the blockchain network, so it will not form an "information island";
[0082] 3. Since data assets are scattered on the mobile phones of holders, once the system is attacked by hackers, it will not cause a large area of data asset leakage. At most, only the data assets of individual mobile phones will be leaked, and the impact range will be very small;
[0083] 4. Due to the adoption of national commercial cryptography technology, means such as electronic seals, digital signatures, label encapsulation, and "black box" verification make data assets safer and more authentic;
[0084] 5. The annotation information is superimposed on the Data Asset Certificate (DAC) in a visible or invisible manner, which is both safe and beautiful, and intuitive and controllable.
[0085] Furthermore, in the solution provided by the present invention, the data asset desensitization and hiding method based on the layout file hiding technology can, in various scenarios of application data asset credentials (DAC), through the means of combining desensitization and hiding, ensure the reliable protection of the sensitive information of the data asset credentials (DAC) in different industrial applications.
[0086] Furthermore, in the solution provided by the present invention, the security label encapsulation method based on the corresponding data asset credentials (DAC) can ensure the secure use of the data asset credentials (DAC) in various scenarios such as storage and application on mobile phones, and has a strong ability to prevent hacker attacks.
[0087] Furthermore, in the solution provided by the present invention, the additional text annotation method based on the timestamp digital signature on the mobile phone can ensure the authenticity, integrity, immutability and extractability of the data asset credentials (DAC) information and the additional text content information on the mobile phone through the digital signature mechanism; the verifiability and security anti-counterfeiting of the additional text are ensured through the digital signature mechanism of the input additional text.
[0088] Furthermore, in the solution provided by the present invention, the multi-domain black box verification method based on the corresponding cryptographic technology can effectively block the harm caused by network hackers' attacks on Internet verification behaviors, and ensure the accuracy and authenticity of the verification results.
[0089] Furthermore, the data asset confirmation, exercise of rights and protection of rights method based on the data ownership control (DOC) technology provided by the present invention can play roles such as security and trustworthiness, and convenient application in the upgrading of data elements to data assets, can become a strong technical support base for the country's WEB3.0 digital strategy, and can be promoted and applied in different application scenarios of the whole society. BRIEF DESCRIPTION OF THE DRAWINGS
[0090] The present invention will be further described below in conjunction with the drawings and specific embodiments.
[0091] Figure 1 It is a schematic diagram of the composition of the confirmation of data asset credentials (DAC) in the embodiment of the present invention;
[0092] Figure 2 It is a schematic diagram of the composition of the exercise of rights of data asset credentials (DAC) in the embodiment of the present invention;
[0093] Figure 3 It is a schematic diagram of the composition of the protection of rights of data asset credentials (DAC) in the embodiment of the present invention;
[0094] Figure 4 It is a schematic diagram of the composition of the data asset credentials (DAC) template making module in the embodiment of the present invention;
[0095] Figure 5 Schematic diagram of the composition of the data asset certificate (DAC) security label encapsulation module in the embodiment of the present invention;
[0096] Figure 6 Schematic diagram of the composition of the data asset certificate (DAC) additional text annotation module in the embodiment of the present invention;
[0097] Figure 7 Schematic diagram of the composition of the multi-domain black box verification module of the data asset certificate (DAC) in the embodiment of the present invention. Specific implementation manners
[0098] In order to make the technical means, creative features, achieved purposes and effects of the present invention easy to understand, the present invention will be further described below with reference to specific drawings.
[0099] Here, the differences between the existing blockchain technology, non-fungible token (NFT) technology and the data ownership control (DOC) technology involved in this solution will be described first.
[0100] There are many differences between blockchain technology and data ownership control (DOC) technology: for example, blockchain technology uses a centralized + distributed method to store data assets, where the data assets are centrally stored on a certain node of the blockchain, and the hash (HASH) values of the data assets are distributed and stored on each node of the blockchain; while the data ownership control (DOC) technology uses a centralized + discrete method to store data assets, where the backups of the data assets are centrally stored on the central node, and the data assets are discretely stored on the mobile phone of the owner. However, blockchain technology and data ownership control (DOC) technology are two completely different technical routes. The confirmation, exercise and protection of rights of data assets by blockchain completely depend on the blockchain network. Without the blockchain network, there is no way to talk about the confirmation, exercise and protection of rights of data assets. The data ownership control (DOC) technology can confirm, exercise and protect the rights of data assets on the Internet without the support of blockchain technology. It can be seen that the means of confirming, exercising and protecting the rights of data assets by blockchain technology cannot be applied to this data ownership control (DOC) technology. In comparison, the application of the data ownership control (DOC) technology is more flexible, convenient, safe and reliable than blockchain technology.
[0101] There are many differences between non-fungible token (NFT) technology and data ownership control (DOC) technology: for example, the management function of the non-fungible token (NFT) technology for data assets must completely rely on the blockchain network, while the data ownership control (DOC) technology for data asset management functions can be fully realized on the network or partially realized offline (such as: display, send, receive, simple verification, etc.). When users use it, the data ownership control (DOC) technology stores data assets on mobile phones, making users feel more convenient and more at ease; the storage and backup of data assets by the non-fungible token (NFT) technology must be realized on the blockchain, while the storage of data assets by the data ownership control (DOC) technology can be stored on the owner's terminal or hosted on the cloud platform of the management center, and the backup of data assets can be backed up to the owner's own home personal cloud, and the owner can restore his data assets on the terminal at any time. Since the non-fungible token (NFT) technology completely relies on blockchain technology, the non-fungible token (NFT) technology and the data ownership control (DOC) technology are also two technologies with completely different technical routes. The non-fungible token (NFT) technology for the confirmation, exercise, and protection of rights of data assets completely depends on the blockchain network. Without the blockchain network, there is no way to talk about the confirmation, exercise, and protection of rights of data assets; while the data ownership control (DOC) technology can confirm, exercise, and protect the rights of data assets on the Internet without the support of blockchain technology. Thus, the means of confirming, exercising, and protecting the rights of data assets by the non-fungible token (NFT) technology cannot be applied to this data ownership control (DOC) technology.
[0102] The solution of the present invention aims at data assets, abandons the existing inherent technical ideas of using blockchain technology or non-fungible token (NFT) technology to realize the confirmation, exercise, and protection of rights, but innovatively introduces the data ownership control (DOC) technology, and based on the data ownership control (DOC) technology (a technology belonging to the category of fusion and integration), implements the confirmation, exercise, and protection of rights for the data asset certificate (DAC), thereby realizing the confirmation, exercise, and protection of rights for data assets.
[0103] The data assets described here include data, files, pictures, audio, video, and so on.
[0104] The definitions of the confirmation, exercise, and protection of rights for the data assets described here are as follows:
[0105] The confirmation of data asset rights refers to determining the ownership of data assets according to laws and policies, mainly including two levels: the first is to determine the subject of rights of data assets, that is, who has the rights to data assets; the second is to determine the content of rights, that is, what kind of rights are enjoyed (such as ownership, holding rights, etc.);
[0106] The exercise of data assets refers to the exercise of the rights to data assets, including the rights to authorized use, authorized operation, restricted use with information annotation, security control rights for shared information, etc.;
[0107] The protection of data assets refers to safeguarding the legitimate rights and interests of individuals or groups regarding data assets, that is, proving that the ownership of the data assets belongs to the parties.
[0108] Accordingly, based on the Data Ownership Control (DOC) technology, the present invention realizes packaging data assets into PDF or OFD format files to form Data Asset Certificates (DACs), and performs desensitization of sensitive information, hiding of important information, timestamp signature for rights confirmation on the Data Asset Certificates (DACs), and further completes the exercise of Data Asset Certificates (DACs) through security label encapsulation, control attribute annotation, and watermark information signature. Furthermore, the protection of Data Asset Certificates (DACs) is completed through multi-domain black box verification.
[0109] The following specifically describes the implementation solutions for the confirmation of rights, exercise of rights, and protection of rights of Data Asset Certificates (DACs) based on the Data Ownership Control (DOC) technology of the present invention.
[0110] Specifically, when the present invention implements the confirmation of rights, exercise of rights, and protection of rights for Data Asset Certificates (DACs) based on the Data Ownership Control (DOC) technology, it is mainly achieved through the following step solutions:
[0111] Step 1: Adopt the method for making templates of Data Asset Certificates (DACs), make the templates of Data Asset Certificates (DACs) on a computer, and input the data asset information corresponding to the templates into the Data Asset Certificate (DAC) templates to complete the production of Data Asset Certificates (DACs).
[0112] As an example, the templates here mainly include PDF format files / OFD format files.
[0113] Furthermore, the data asset information here mainly includes: data, files, pictures, audio, video, etc., but is not limited thereto.
[0114] Step 2: According to the pre-set sensitivity data processing strategy information, use the data desensitization and hiding method to process the sensitive information on the cover of the Data Asset Certificate (DAC) and the sensitive information inside the Data Asset Certificate (DAC) to ensure the data security of the Data Asset Certificate (DAC).
[0115] Step 3: Store the data asset information after the desensitization and hiding processes in Step 2 back into the Data Asset Certificate (DAC), and use the digital signature technology with timestamp to electronically sign or digitally sign the Data Asset Certificate (DAC) file to ensure the authenticity, integrity, verifiability, non-repudiation, and security and anti-counterfeiting properties of the Data Asset Certificate (DAC) file, thus completing the confirmation of rights for the Data Asset Certificate (DAC).
[0116] Step 4: For the Data Asset Certificate (DAC) whose rights have been confirmed in Step 3, use the secure label encapsulation method to store the Data Asset Certificate (DAC) with the security label in the mobile phone to ensure the security of the Data Asset Certificate (DAC) on the mobile phone.
[0117] Step 5: For the Data Asset Certificate (DAC) that has been stored in the mobile phone and whose rights have been confirmed in Step 4, further on the mobile phone, use the additional text annotation method to embed the additional text into the Data Asset Certificate (DAC), and complete the digital signature of the additional text to ensure the controllability and non-repudiation of the Data Asset Certificate (DAC), thereby completing the exercise of rights for the Data Asset Certificate (DAC).
[0118] Step 6: During the network circulation and interaction process of the Data Asset Certificate (DAC) that has been confirmed and exercised rights in Step 5, after the receiving party receives the corresponding Data Asset Certificate (DAC) on the terminal device, submit the received Data Asset Certificate (DAC) to the certificate verification platform on the Internet to request verification.
[0119] The certificate verification platform here is a certificate verification platform built relying on the national cryptographic service platform. This platform specifically accepts certificate verification requests, and the verification content includes national cryptographic electronic seals, digital signatures, certificate validity periods, certificate status, etc.
[0120] Furthermore, this certificate verification platform adopts the multi-domain black box verification method to verify the validity and authenticity of multi-domain contents such as its electronic seal, digital signature, certificate effective time, validity of the certificate "domain", and certificate status in the security verification space (i.e., the black box) kernel, and after encrypting the verification result, return it to the certificate verification platform to ensure the authenticity, integrity, validity, verifiability, non-repudiation, and security and anti-counterfeiting properties of the Data Asset Certificate (DAC).
[0121] Step 7: After the certificate verification platform in Step (6) verifies the received Data Asset Certificate (DAC), encrypt the verification result and return it to the requester; at the same time, the requester decrypts the verification result based on the corresponding algorithm with the requester's ID parameter. If the verification passes, the rights protection of the Data Asset Certificate (DAC) is realized, ensuring the legality of its application.
[0122] On this basis, the mobile application system can read the cover information, sensitive information, and additional text information in the Data Asset Certificate (DAC) through relevant interface forms.
[0123] Based on the organic coordination among the above 7 steps, this solution can store data assets on the holder's mobile phone and ensure effective control of data assets on the mobile side, that is, effectively implement and ensure the confirmation of rights, exercise of rights, and protection of rights for data assets on the mobile phone side, effectively overcoming the problems that existing data asset control solutions relying on blockchain technology and data asset right confirmation solutions relying on non-fungible token (NFT) technology cannot achieve the confirmation of rights, exercise of rights, and protection of rights for data assets after leaving the blockchain network.
[0124] Regarding the solution for implementing the confirmation of rights, exercise of rights, and protection of rights for the Data Asset Certificate (DAC) based on the Data Ownership Control (DOC) technology given in the present invention, the following further describes its implementation process and corresponding technical features.
[0125] In some embodiments of the present invention, when making the Data Asset Certificate (DAC) template in step (1), it can be achieved through the following steps:
[0126] Step A1: Scan the pre-designed cover picture of the Data Asset Certificate (DAC) on a computer to become the base plate of the Data Asset Certificate (DAC);
[0127] Step A2: According to the pre-set cover information elements of the Data Asset Certificate (DAC), complete the definition of information attributes associated with the cover information elements on the base plate, including content such as tables, fields, signature positions, font sizes, colors, coordinates, etc.;
[0128] Step A3: First, set the parameters for generating an unlimited number of blank "domains" with specified names on the Data Asset Certificate (DAC) in advance. Here, the parameters include: the positioning information of the blank "domain" on the certificate surface, the reserved space size information of the blank "domain", etc.; then complete the production of the blank template of the Data Asset Certificate (DAC); here, the blank "domain" is specifically a space with domain attributes but empty content, and the position and size of the blank "domain" can be pre-set with parameters according to the future role of the blank domain and the layout of the certificate surface before production;
[0129] Step A4: After the Data Asset Certificate (DAC) template is made, it is stored in the template database of the Data Asset Certificate (DAC) for calling when the rights of the Data Asset Certificate (DAC) are confirmed.
[0130] When making a Data Asset Certificate (DAC) template based on the above solution, the present solution innovatively reserves blank "fields" first, and then makes the template on this basis. In this way, when the certificate is confirmed with an electronic seal, the overall confirmation of the certificate except for the blank "fields" can be realized.
[0131] In some embodiments of the present invention, when inputting the data assets corresponding to the input template (including: data, files, pictures, audio, video, etc.) into the Data Asset Certificate (DAC) template in step (1), it can be attached as a visible attachment and displayed on the certificate file, or hidden as invisible information within the certificate file.
[0132] As a further explanation, the hiding method here is to attach the information to the certificate file in the form of xlm. When the certificate file is displayed, the information in xml format will be filtered and cannot be displayed.
[0133] In some embodiments of the present invention, when processing the sensitive information on the cover of the Data Asset Certificate (DAC) and the sensitive information within the Data Asset Certificate (DAC) using the data desensitization hiding method in step (2), according to the pre-set data desensitization hiding strategy information, for the sensitive information on the cover of the Data Asset Certificate (DAC), the sensitive information is masked with "*" in the form of a mask desensitization operation, and the original sensitive information on the cover is stored in the Data Asset Certificate (DAC); at the same time, for the sensitive information within the Data Asset Certificate (DAC), it is hidden in the Data Asset Certificate (DAC) in the form of XML and attached behind the Data Asset Certificate (DAC).
[0134] Through such processing, when the content of the Data Asset Certificate (DAC) is displayed, the sensitive information on the cover will display a mask of "*", and the sensitive information within the certificate has been hidden and will not be displayed. Reading the hidden sensitive information requires reading through an interface form.
[0135] In some embodiments of the present invention, when encapsulating the confirmed Data Asset Certificate (DAC) using the security label encapsulation method in step (4), it can be achieved through the following steps:
[0136] Step B1: According to the standard of the "GM / T 0055-2018 Technical Specification for Cryptographic Application of Electronic Documents" of the State Cryptography Administration, extract the basic attributes of the Data Asset Certificate (DAC) file, and thus form a label file; the basic attributes extracted in this step include basic information such as the creation date, modification date, file size, owner, and digest of the certificate file; the label file is a relatively independent file for storing parameters attached in front of the Data Asset Certificate (DAC) file header, and is uniquely bound to the Data Asset Certificate (DAC) file and cannot be detached;
[0137] Step B2: Use the pseudo-random number generated by the built-in pseudo-random function of the computer as the encryption key, and accordingly complete the overall encryption of the Data Asset Certificate (DAC), and then store the corresponding decryption key in the tag file;
[0138] Step B3: Use the ID parameter key of the mobile phone to encrypt the tag file once with SM9, load the tag file onto the Data Asset Certificate (DAC) file, form a uniquely bound tagged Data Asset Certificate (DAC), and store it in the data space of the device for storage, so that it can be called and read at any time when the application needs a certificate;
[0139] When reading, first use the ID parameter key of the mobile phone to decrypt the tag file of the Data Asset Certificate (DAC) in the data space, and then take out the decryption key of the Data Asset Certificate (DAC) to perform the decryption operation on the Data Asset Certificate (DAC).
[0140] When encapsulating the confirmed Data Asset Certificate (DAC) based on the organic cooperation of the above steps, using the tag technology that complies with the "GM / T 0055-2018 Technical Specification for Cryptographic Application of Electronic Documents" of the State Cryptography Administration to encapsulate the Data Asset Certificate (DAC) can ensure the information security of the Data Asset Certificate (DAC) file on the mobile terminal and the Internet, and prevent hackers from stealing the relevant information on the Data Asset Certificate (DAC).
[0141] In some embodiments of the present invention, when using the additional text annotation method in step (5) to embed additional text into the Data Asset Certificate (DAC) and complete the digital signature of the additional text, it mainly includes the following steps:
[0142] Step C1: Input the additional text content on the mobile phone, including specifying the recipient of the Data Asset Certificate (DAC), the usage scope, the usage validity period, etc.
[0143] Step C2: According to the set additional text embedding strategy and additional text embedding method, embed the additional text input in step (C1) into the Data Asset Certificate (DAC) on the mobile phone in a visual form or a hidden form;
[0144] Step C3: Use an anti-counterfeiting method with additional text to perform an overall signature on the mobile phone data asset certificate (DAC) and the additional text using a digital signature with a timestamp; since a blank "field" has been reserved and set in advance during template production, the content of the additional text is stored in the blank "field", and digitally signing the additional text will not affect the electronic signature of the original certificate file (when the original certificate file is protected by an electronic signature, a blank "field" has been left as not being part of the content of the certificate file). Therefore, when the original mobile phone data asset certificate (DAC) already contains digital signature information or electronic signature information with a timestamp, the digital signature information or electronic signature information of the original mobile phone data asset certificate (DAC) will not be damaged.
[0145] Step C4: For the mobile phone data asset certificate (DAC) generated in Step C3 with additional text embedded and protected by a digital signature with a timestamp, ensure the authenticity, integrity, validity, verifiability, non-repudiation, and security anti-counterfeiting of the additional text of the mobile phone data asset certificate (DAC) by verifying the digital signature information of the additional text and the validity of the "field" set during template production.
[0146] Based on the organic cooperation of the above steps to achieve embedding additional text into the data asset certificate (DAC) and complete the digital signature of the additional text, innovatively utilize the pre-reserved blank "field" of the certificate, input the annotation information of the certificate as additional text into the reserved blank "field", and use the method of digital signature to sign the blank "field" containing the annotation information and then overlay it on the data asset certificate (DAC), thereby ensuring the authenticity, integrity, validity, non-repudiation, verifiability, and security anti-counterfeiting of the additional text of the data asset certificate (DAC).
[0147] As a further explanation, in Step C2 above, when implementing the embedding of the additional text input in Step (C1) into the mobile phone data asset certificate (DAC) in a visual or hidden form according to the set additional text embedding strategy and additional text embedding method, a blank "field" is reserved on the mobile phone data asset certificate (DAC) without a digital signature or electronic signature (i.e., the blank "field" generated in Step A3 of Step 1). According to the requirements of the actual application scenario, ensure that the additional text can be dynamically embedded as visual additional text (e.g., using digital watermarking technology to display the additional text written into the "field") or hidden additional text (e.g., storing the additional text written into the "field" in xml format in the certificate file, and when displaying the certificate, the xml format information cannot be displayed and can only be read through an interface); the validity of the "field" and the content information can be safely verified; any malicious modification and deletion of the "field" can be prevented, that is, the additional text cannot be maliciously deleted. Once the additional text is tampered with or the "field" is deleted, the verification will return a "failed" verification message.
[0148] As a further illustration, when embedding the additional text input in step (C1) into the mobile phone data asset certificate (DAC) in a visual form or a hidden form according to the set additional text embedding strategy and additional text embedding method, it can be achieved through the following steps:
[0149] Step E1: Embed the input additional text content in a visual form (such as digital watermark) or a hidden storage form on the data asset certificate (DAC) to become additional text information that is visible or invisible to the human eye (machine visible);
[0150] Step E2: Set the additional text embedding strategy, where the additional text embedding strategy includes but is not limited to information such as the starting position of the text, text transparency, font name, font color, display method (such as left alignment, center alignment, right alignment, and non-display), embedding area range, and embedding page;
[0151] Step E3: Automatically identify and dynamically calculate the font size and position of the text according to the additional text embedding strategy and the amount of input additional text content;
[0152] Step E4: When embedding additional text in a visual form (such as digital watermark) according to the additional text embedding strategy information, it is possible to specify a page or all pages, a variable area, and automatically wrap and display the additional text information to ensure that all the input additional text content can be displayed on the page of the mobile phone data asset certificate (DAC);
[0153] When embedding additional text in a hidden storage form, the additional text can be stored in the data asset certificate (DAC) in XML form, attached behind the data asset certificate (DAC), and the additional text will not be displayed when displaying the data asset certificate (DAC), and the additional text needs to be read through an interface form;
[0154] Step E5: The embedded additional text will be in the form of the content of a "field", and the additional text will be protected by digital signature with a timestamp; since the originally reserved blank "field", after embedding the additional text, using the digital signature method with a timestamp to sign the additional text "field" can ensure the authenticity, integrity, validity, non-repudiation, verifiability, and security and anti-counterfeiting of the additional text.
[0155] In the above steps, innovatively, the additional text is displayed on the page of the data asset certificate (DAC) using watermark technology or hidden in the data asset certificate (DAC) in xml form (read through an interface) and protected by digital signature to ensure the authenticity, integrity, validity, non-repudiation, verifiability, and security and anti-counterfeiting of the additional text.
[0156] As a further illustration, in the above step C3, when using the anti-counterfeiting method of additional text for signature, the embedding technology of the additional text is combined with the digital signature technology with a timestamp to protect the signature of the attached text information through the digital signature technology.
[0157] Here, the anti-counterfeiting method of additional text is to perform an overall signature on the mobile phone terminal data asset voucher (DAC) and the additional text using a digital signature with a timestamp. Since a blank "field" has been reserved and set in advance during template production, the content of the additional text is stored in the blank "field", and digitally signing the additional text will not affect the electronic signature of the original voucher file (when the original voucher file is protected by an electronic signature, a blank "field" has been left as not being part of the content of the voucher file). Therefore, when the original mobile phone terminal data asset voucher (DAC) already contains digital signature information or electronic signature information with a timestamp, the digital signature information or electronic signature information of the original mobile phone terminal data asset voucher (DAC) will not be damaged.
[0158] As a further illustration, in the above step C4, when ensuring the authenticity, integrity, validity, non-repudiation, verifiability, and security anti-counterfeiting of the additional text of the mobile phone terminal data asset voucher (DAC) file by verifying the digital signature information of the additional text and the validity of the field, the following steps are included:
[0159] Step H1: Input the data asset voucher (DAC) generated in step C3 with additional text protected by a digital signature with a timestamp embedded.
[0160] Step H2: Before embedding the additional text, if there is a blank "field" with a specified name on the data asset voucher (DAC), then verify the digital signature information of the additional text in step C4 and the validity of the "field" set during template production, that is, verify the correctness of the "field" name, attribute information, and content information to prevent malicious modification and deletion of the "field" and ensure the validity of the additional text.
[0161] Step H3: By extracting the digital signature information of the data asset voucher (DAC) and the digital signature information of the additional text content, verify the authenticity, integrity, non-tamperability, verifiability, and security anti-counterfeiting of the digital signature of the data asset voucher (DAC) and the digital signature of the additional text.
[0162] Step H4: Only after verification can the additional text information be extracted and ensure its legal application.
[0163] When implementing the verification solution of step C4 through the organic cooperation of the above four steps, the mobile phone-side data asset certificate (DAC) with additional text embedded and protected by a digitally signed timestamp is input. By verifying the validity of the digital signature information of the additional text and the "domain" set during template production; that is, step H1 is to input the certificate; step H2 is to verify the "domain" name, attribute information, and content information; step H3 is to verify the certificate file and the additional text; and step H4 is that the additional text can be extracted only after verification.
[0164] Furthermore, when implementing the verification solution of step C4 through the organic cooperation of the above four steps, the electronic signature of the data asset certificate (DAC) file and the "domain" digital signature of the additional text are innovatively combined, achieving the embedding of additional text without damaging the electronic signature of the data asset certificate (DAC) file, and realizing the coexistence of the electronic signature of the data asset certificate (DAC) file and the digital signature of the additional text, both of which can be verified separately.
[0165] In some embodiments of the present invention, when verifying the data asset certificate (DAC) through the multi-domain black box verification method in step 6, the following steps are mainly included:
[0166] Step D1: The data asset certificate (DAC) request received by the certificate verification platform is sent together with the requester ID to the security verification area. The security verification area here only receives task requests sent by the certificate verification platform and rejects all other requests. External programs cannot access this area, thus forming a corresponding "black box".
[0167] Step D2: Inside the black box (i.e., the security verification area), the validity of the electronically signed timestamp or digital signature, the names and attributes of various "domains", the timestamped digital signature of the additional text, and the timestamped digital signature of the status domain of the data asset certificate (DAC) are respectively verified.
[0168] Step D3: The time information content on the data asset certificate (DAC) file and the time information content in the additional text are extracted, and their respective time validity periods are compared to verify whether the time has expired to determine the validity of the certificate.
[0169] Step D4: The status information content of the data asset certificate (DAC) is extracted, and its various forms of certificate status are compared to verify whether it is in a valid state to determine the validity of the certificate.
[0170] After the verification is completed, the verification result is encrypted using the national cryptography standard identification password (SM9) algorithm with the requester ID as a parameter and returned to the certificate verification platform.
[0171] When implementing the verification of data asset credentials (DAC) based on the multi-domain black-box verification method through the above steps in an organically coordinated manner, all verification processes are innovatively carried out within a relatively secure area, which is called "black-box" verification. The verification results are transmitted to the requester in an encrypted manner to ensure that the verification results cannot be tampered with by hackers.
[0172] In some embodiments of the present invention, for the authenticity, integrity, verifiability, non-tamperability, and security anti-counterfeiting of the data asset credential (DAC) file described in step 3, it can be achieved through the following steps:
[0173] Step F1: Input the data asset credential (DAC) file generated in step 3 that has been digitally signed with a timestamp.
[0174] Step F2: When verifying the data asset credential (DAC) within the black box (i.e., the security verification area) in step D2, extract the digital signature information content of the data asset credential (DAC) file and digitally sign the actual data asset credential (DAC) again to verify whether the two contents are exactly the same. If they are the same, the verification passes; otherwise, it fails. This ensures the authenticity, integrity, verifiability, non-tamperability, and security anti-counterfeiting of the data asset credential (DAC).
[0175] Step F3: Only after the verification passes can the legality of the application of the data asset credential (DAC) be ensured.
[0176] In the above steps, all verification processes are innovatively carried out within a relatively secure area, which is called "black-box" verification. The verification results are transmitted to the requester in an encrypted manner to ensure that the verification results cannot be tampered with by hackers.
[0177] In some embodiments of the present invention, for the authenticity, integrity, validity, verifiability, non-tamperability, and security anti-counterfeiting of the data asset credential (DAC) file described in step 6 and step C4, it can be achieved through the following steps:
[0178] Step G1: Input the data asset credential (DAC) generated in step C3 that has been embedded with additional text and digitally signed with a timestamp.
[0179] Step G2: When verifying the Data Asset Credential (DAC) within the black box (i.e., the security verification area) in Step D2, the digital signature information of the Data Asset Credential (DAC) and the content of the digital signature information of the additional text will be extracted, and a digital signature will be made again for the actual Data Asset Credential (DAC) and the additional text respectively. Verify whether the content of the extracted digital signature and the digital signature content made in real time are exactly the same. If they are the same, the verification passes; as long as one item is inconsistent, it fails. Thus, the authenticity, integrity, verifiability, non-tamperability, and security anti-counterfeiting of the Data Asset Credential (DAC) and the additional text are ensured.
[0180] Step G3: When verifying the Data Asset Credential (DAC) within the black box (i.e., the security verification area) in Step D2, the expiration time content of the Data Asset Credential (DAC) and the expiration time content of the additional text of the Data Asset Credential (DAC) will be extracted, and their respective time validity periods will be compared to verify whether the time has expired, so as to judge the time validity of the Data Asset Credential (DAC).
[0181] Step G4: When verifying the Data Asset Credential (DAC) within the black box (i.e., the security verification area) in Step D2, the status content of the Data Asset Credential (DAC) and the content of its digital signature information with a timestamp will be extracted, and a digital signature will be made again for the "field" of the status. Compare the various forms of the voucher status to verify whether it is a valid status and whether the digital signature value is exactly the same as the extracted digital signature value. If the status is valid and the digital signature values are exactly the same, it is judged that the verification passes; if the status is any non-valid status or the digital signature values are inconsistent, the verification fails. Thus, the status authenticity, integrity, validity, non-tamperability, and security anti-counterfeiting of the Data Asset Credential (DAC) are ensured.
[0182] Only after the verification passes can the legality of the application of the Data Asset Credential (DAC) be ensured.
[0183] In the solution formed based on the above steps, innovatively, the verification process is carried out within a relatively secure area, called "black box" verification, and the verification results are transmitted to the requester in an encrypted manner to ensure that the verification results will not be tampered with by hackers.
[0184] For the data asset credential management solution based on the data ownership control technology given in this example solution, in specific applications, corresponding software programs can be formed to form a corresponding data asset credential security management system based on the data ownership control technology.
[0185] When the software program is running, it will execute the above-mentioned data asset certificate control method based on data ownership control technology, implement the confirmation, exercise, and protection of rights for data asset certificates (DAC) based on data ownership control (DOC) technology, and at the same time store them in the corresponding storage medium for the processor to retrieve and execute.
[0186] The data asset certificate security control system formed thereby mainly includes a data asset certificate (DAC) confirmation unit 100, a data asset certificate (DAC) exercise unit 200, a data asset certificate (DAC) rights protection unit 300, a certificate template production module unit 400, a security label encapsulation module unit 500, an additional text annotation module unit 600, and a multi-domain black box verification module unit 700.
[0187] Among them, the data asset certificate (DAC) confirmation unit 100 is configured to achieve the confirmation of data asset certificates (DAC) through the organic cooperation among the three functions of certificate template production, data desensitization and hiding, and time-stamped electronic signature / digital signature.
[0188] The certificate template production function here is used for the production of certificate templates. The layout file is selected as the carrier of the certificate template, and data asset information (including: data, files, pictures, audio, video, etc.) is input into the certificate template to complete the production of data asset certificates (DAC); the data desensitization and hiding function is used to perform a masking desensitization operation on the sensitive information on the cover of the data asset certificate (DAC) by hitting "*", and the original sensitive information on the cover is stored in the data asset certificate (DAC). The sensitive information in the data asset certificate (DAC) is hidden in the data asset certificate (DAC) in XML form; the time-stamped electronic signature / digital signature function is used to protect the data asset certificate (DAC) file after desensitization and hiding processing with an electronic signature / digital signature, and use a time stamp to ensure its uniqueness, ensuring the authenticity, integrity, non-repudiation, and non-tamperability of the data asset certificate (DAC) file.
[0189] This data asset certificate (DAC) confirmation unit 100 specifically uses the layout file as the carrier container of the data asset, and adopts national commercial cryptography technology to achieve the confirmation of data asset certificates (DAC) through time-stamped electronic signature / digital signature. It is safer, more convenient, and more popular with holders than the commonly used blockchain technology as a method for data asset confirmation. At the same time, it has a flexible and comprehensive privacy protection function.
[0190] The data asset certificate (DAC) exercise unit 200 is configured to achieve the exercise of data asset certificates (DAC) through the mutual cooperation of the two functions of security label encapsulation and additional text annotation.
[0191] The security label encapsulation function here is used to uniquely bind the label file and the data asset credential (DAC), and save it to the mobile phone device; the additional text annotation function is used to embed additional text into the digital asset credential on the mobile side, and complete the digital signature of the additional text to ensure the controllability and non-repudiation of the data asset credential (DAC).
[0192] The exercise unit 200 of this data asset credential (DAC) effectively breaks through the problem that the layout file cannot be edited on the mobile side and the existing electronic seal / digital signature protection of the layout file will be damaged when adding additional information, realizes the annotation operation of additional text information on the mobile data asset credential (DAC), and realizes the exercise of the data asset credential (DAC). At the same time, the mobile data asset credential (DAC) is uniquely bound to the security label, ensuring the security and flexibility of the mobile credential.
[0193] The rights protection unit 300 of the data asset credential (DAC) is configured to realize the rights protection of the data asset credential (DAC) through the mutual cooperation of two functions: multi-domain black box verification and extraction of credential information.
[0194] The multi-domain black box verification function here is used to verify the validity and authenticity of multi-domain contents such as the electronic seal, digital signature, credential validity period, and credential status of the digital asset credential in a relatively secure and controllable space, and encrypt and return the verification result; the function of extracting credential information is used to read the cover information, sensitive information, and additional text information in the data asset credential (DAC) in the form of relevant interfaces after the data asset credential (DAC) verification passes to ensure the legality of its application.
[0195] The rights protection unit 300 of this data asset credential (DAC) can break through the traditional single verification method of the credential, adopt multi-domain verification technology, verify both the electronic seal of the credential to ensure that the issuing agency of the credential will not forge, and verify the personal digital signature of the credential user to ensure that the credential user is not forged under a false name. It also needs to verify the current status validity of the credential and that the key information has not been tampered with, etc. The rights protection of the data asset credential (DAC) is realized.
[0196] The voucher template production module unit 400 is configured to realize voucher template production through the organic cooperation of four functions: voucher bottom plate production, associated voucher cover information attributes, blank field generation, and voucher template warehousing.
[0197] The voucher baseboard production function here is used to produce the baseboard of the voucher from the cover picture of the Data Asset Certificate (DAC); the associated voucher cover information attribute function is used to complete the definition of information attributes related to the cover information elements on the baseboard, including (table, field, signature position, font size, color, coordinates), etc.; the blank field generation function is used to pre-generate an unlimited number of "blank fields" with specified names (with field attributes but empty content) on the Data Asset Certificate (DAC) to complete the production of the blank template of the Data Asset Certificate (DAC); the voucher template storage function is used to store the produced template of the Data Asset Certificate (DAC) in the template database of the Data Asset Certificate (DAC) for use when the Data Asset Certificate (DAC) is confirmed of rights.
[0198] This voucher template production module unit 400 innovatively uses the embedding technology to pre-generate a number of blank fields with attributes, laying a foundation for adding annotation information and status information for voucher use after the voucher rights are confirmed.
[0199] The security label encapsulation module unit 500 is configured to achieve security label encapsulation through the organic cooperation of four functions: label file generation, voucher encryption, label file encryption, and label and voucher decryption.
[0200] Here, the label file generation function is used to extract the basic attributes of the Data Asset Certificate (DAC) file according to the standard of the "Technical Specification for the Application of Electronic File Passwords GM / T 0055-2018" of the National Cryptography Administration to form a label file. The voucher encryption function is used to extract the encryption key from the pseudo-random number generated by the computer, complete the overall encryption of the Data Asset Certificate (DAC), and then store the corresponding decryption key in the label file. The label file encryption function is used to encrypt the label file once with the ID parameter key of the mobile phone terminal using SM9, load the label file onto the Data Asset Certificate (DAC) file, form a uniquely bound Data Asset Certificate (DAC) with a label, and store it in the data space of the device. The label and voucher decryption function is used to decrypt the label file of the Data Asset Certificate (DAC) in the data space with the ID parameter key of the mobile phone terminal, and then take out the decryption key of the Data Asset Certificate (DAC) to perform a decryption operation on the Data Asset Certificate (DAC).
[0201] This security label encapsulation module unit 500 uses a label technology that meets the requirements of national cryptography to effectively achieve high-strength encryption protection of "one document, one cipher" and "one time, one cipher" for voucher files.
[0202] The additional text annotation module unit 600 is configured to achieve the annotation of additional text through the organic cooperation of five functions: mobile terminal additional text information, additional text embedding strategy, additional text embedding algorithm, mobile terminal voucher embedding additional text processing, and mobile terminal digital signature.
[0203] The mobile device additional text information function here is used to input additional text content on the mobile phone (control attribute information of the Data Asset Certificate (DAC), such as elements specifying data asset users, usage scope, usage validity period, etc.).
[0204] The additional text embedding strategy function is used to embed the input additional text content in the Data Asset Certificate (DAC) in a visual form (such as digital watermark) or a hidden storage form, becoming additional text information that is visible or invisible to the human eye (visible to machines), and complete the setting of the additional text embedding strategy. The additional text embedding strategy includes, but is not limited to, information such as the starting position of the text, text transparency, font name, font color, display method (left alignment, center alignment, right alignment, and non-display), embedding area range, and embedding page.
[0205] The additional text embedding algorithm function is used to automatically identify and dynamically calculate the font size and position of the text according to the additional text embedding strategy and the amount of input additional text content.
[0206] The mobile device certificate embedding additional text processing function is used to, according to the additional text embedding strategy information, when visualizing and embedding additional text (such as digital watermark), specify a page or all pages, variable areas, and automatically wrap and display the additional text information to ensure that all the input additional text content can be displayed on the page of the mobile phone Data Asset Certificate (DAC); when embedding additional text in a hidden storage form, the additional text can be stored in the Data Asset Certificate (DAC) in XML form, attached to the back of the Data Asset Certificate (DAC), and the additional text will not be displayed when the Data Asset Certificate (DAC) is displayed, and the additional text needs to be read through an interface form.
[0207] The mobile device digital signature function is used to use the embedded additional text as the content form of the "field" and perform signature protection on the additional text in a digital signature manner with a time stamp.
[0208] This additional text annotation module unit 600 can realize embedding additional text in the certificate in two forms, visible or invisible, on the mobile phone. On the basis of not destroying the existing electronic signature protection of the certificate, it is superimposed on any page of the certificate in the form of a watermark and a personal digital signature is made to ensure the validity and non-repudiation of the annotation information.
[0209] The multi-domain black box verification module unit 700 is configured to implement multi-domain black box verification through the organic cooperation of four functions: certificate element verification, time verification, status content verification, and encrypted return of verification results.
[0210] The voucher element verification function here is used for the data asset voucher (DAC) requests received by the voucher verification platform. The requester ID and the digital asset voucher are sent into the security verification area (i.e., the "black box") together. In the "black box", the data asset voucher (DAC) is respectively verified for its timestamped electronic signature or digital signature, the names and attributes of various "domains", the timestamped digital signature of the additional text, and the timestamped digital signature of the status field to ensure the validity of the verification elements.
[0211] The time verification function is used to extract the time information in the data asset voucher (DAC) and the time information in the additional text and verify its validity.
[0212] The status content verification function is used to extract the status information of the digital asset voucher and verify its validity.
[0213] The verification result encryption and return function is used to, after the verification is completed, encrypt the verification result using the national cryptographic SM9 algorithm with the requester ID as a parameter and return it to the voucher verification platform.
[0214] This multi-domain black box verification module unit 700 innovatively conducts the entire verification process within a security verification area (i.e., the "black box"), and the verification result is transmitted to the requester using an encryption method to prevent the verification result from being tampered with when the voucher verification platform is attacked by network hackers.
[0215] The above-mentioned module units mainly implement the functions of data asset voucher (DAC) right confirmation, right exercise, and right protection. The function of data asset voucher (DAC) right confirmation is realized through unit 100; the function of data asset voucher (DAC) right exercise is realized through unit 200; the function of data asset voucher (DAC) right protection is realized through unit 300.
[0216] On this basis, unit 400 is installed inside unit 100 as an auxiliary function unit for data asset voucher (DAC) right confirmation, right exercise, and right protection. That is, before the data asset voucher (DAC) right confirmation, the bottom plate of the data asset voucher (DAC) must be pre-made, the relevant attributes of the data asset voucher (DAC) must be defined, several blank fields of the data asset voucher (DAC) must be reserved, and the data asset voucher (DAC) must be stored in the template library for ready use during the data asset voucher (DAC) right confirmation. Among them, reserving blank fields is for filling in the application attributes and status attributes of the voucher during the data asset voucher (DAC) right exercise, and also for verifying the authenticity, integrity, verifiability, non-tamperability, and security anti-counterfeiting of the application attributes and status attributes in this field during the data asset voucher (DAC) right protection.
[0217] Unit 500 is built into unit 200 as an auxiliary function unit for exercising and maintaining the rights of the data asset certificate (DAC). That is, before the data asset certificate (DAC) is exercised, the data asset certificate (DAC) that has been confirmed must be pre-packaged with a security label, that is, a label file must be generated in advance, and the encryption and decryption modules of the certificate and label file must be configured. The label file and the data asset certificate (DAC) are uniquely bound, so that the data asset certificate (DAC) can be called at any time when exercising and maintaining rights, thereby improving the security of the data asset certificate (DAC) file, preventing network hackers from stealing data asset certificate (DAC) information, and protecting sensitive information of the data asset certificate (DAC).
[0218] Unit 600 is built into unit 200 as an auxiliary function unit for exercising and protecting the data asset certificate (DAC). That is, before exercising the data asset certificate (DAC) on a mobile phone, the additional text (i.e., annotation information) of the certificate must be pre-filled in the confirmed data asset certificate (DAC) before use. The additional text includes the purpose of the certificate, validity period and other restrictive conditions, and is embedded in the data asset certificate (DAC) in the form of a watermark. The filled additional text is then protected by a digital signature to verify the authenticity, integrity, validity, verifiability, non-tamperability and security and anti-counterfeiting of the annotation information when protecting the data asset certificate (DAC).
[0219] Unit 700 is built into unit 300 as an auxiliary functional unit for data asset certificate (DAC) rights protection. That is, before the data asset certificate (DAC) rights protection, the data asset certificate (DAC) that has been confirmed and exercised must be submitted to the verification "black box" by the certificate verification platform before use. The seal / signature, domain name, domain attributes, additional text signature, status signature, certificate validity period, attachment text validity period, status content validity, etc. of the data asset certificate (DAC) file are verified in the "black box", and the verification results are returned to the certificate verification platform to ensure the authenticity and security of the verification results and prevent network hackers from attacking and tampering with the verification results.
[0220] The following further explains the specific implementation plan and corresponding technical features of the data asset credential security management and control system based on data ownership control technology.
[0221] In some embodiments of the present invention, Figure 1 As shown, the data asset certificate (DAC) confirmation unit 100 in the present system includes a certificate template production module 120, a data desensitization and hiding module 130, and an electronic signature / digital signature module 140 with a timestamp. The production and confirmation of the data asset certificate (DAC) 110 are realized through the cooperation between these three functional modules.
[0222] As a further illustration, the data asset certificate (DAC) rights confirmation unit 100, as the core functional unit of the data asset certificate (DAC) security control system, directly operates in the form of a functional subsystem of the data asset certificate (DAC) security control system.
[0223] Among them, the certificate template making module 120 in this unit 100 is configured to make templates for certificates and accept the input of data asset information (including: data, files, pictures, audio, video, etc.) into the data asset certificate (DAC) template. The certificate template making module 120, as an internal functional unit of the data asset certificate (DAC) rights confirmation unit 100, is called by the data asset certificate (DAC) rights confirmation unit 100.
[0224] The data desensitization and hiding module 130 in this unit 100 is configured to perform a desensitization operation on the sensitive information on the cover of the data asset certificate (DAC) by masking it with "*", store the original sensitive information on the cover into the data asset certificate (DAC), and hide the sensitive information in the data asset certificate (DAC) in XML form. The data desensitization and hiding module 130, as an internal functional unit of the data asset certificate (DAC) rights confirmation unit 100, is called by the data asset certificate (DAC) rights confirmation unit 100.
[0225] The timestamped electronic signature / digital signature module 140 in this unit 100 is configured to perform electronic signature / digital signature protection on the data asset certificate (DAC) file after being desensitized and hidden by the data desensitization and hiding module 130, and use a timestamp to ensure its uniqueness, ensuring the authenticity, integrity, non-repudiation, and non-tampering of the data asset certificate (DAC) file, and completing the rights confirmation of the data asset certificate (DAC). The timestamped electronic signature / digital signature module 140, as an internal functional unit of the data asset certificate (DAC) rights confirmation unit 100, is called by the data asset certificate (DAC) rights confirmation unit 100.
[0226] In some embodiments of the present invention, as Figure 2 shown, the data asset certificate (DAC) exercise unit 200 in this system includes a security label encapsulation module 230 and an additional text annotation module 240, and realizes the exercise of the mobile data asset certificate (DAC) 210.
[0227] As a further illustration, the data asset certificate (DAC) exercise unit 200, as the core functional unit of the data asset certificate (DAC) security control system, directly operates in the form of a functional subsystem of the data asset certificate (DAC) security control system.
[0228] Among them, the security label encapsulation module 230 in this unit 200 is configured to uniquely bind the label file and the confirmed data asset certificate (DAC) 220, and save them to the mobile phone side (such as a mobile phone device). As an internal functional unit of the data asset certificate (DAC) exercise unit 200, the security label encapsulation module 230 accepts the call of the data asset certificate (DAC) exercise unit 200.
[0229] The additional text annotation module 240 in this unit 200 is configured to embed additional text on the confirmed data asset certificate (DAC) 220 in the mobile phone side, and complete the digital signature 250 of the additional text to ensure the controllability and non-repudiation of the data asset certificate (DAC), and complete the exercise 210 of the data asset certificate (DAC). As an internal functional unit of the data asset certificate (DAC) exercise unit 200, the additional text annotation module 240 accepts the call of the data asset certificate (DAC) exercise unit 200.
[0230] In some embodiments of the present invention, such as Figure 3 shown, the data asset certificate (DAC) rights protection unit 300 in this system includes a multi-domain black box verification module 330, an extraction certificate information module 340, and realizes the rights protection of the data asset certificate (DAC) 310.
[0231] As a further explanation, the data asset certificate (DAC) rights protection unit 300, as the core functional unit of the data asset certificate (DAC) security control system, directly operates in the form of a functional subsystem of the data asset certificate (DAC) security control system.
[0232] Among them, the multi-domain black box verification module 330 in this unit 300 is configured to receive, in a relatively secure and controllable space, the data asset certificate (DAC) 320 that has been processed for confirmation and exercise by the data asset certificate (DAC) confirmation unit 100 and the data asset certificate (DAC) exercise unit 200 and submitted by the certificate verification platform, verify the validity and authenticity of multi-domain contents such as its electronic seal, digital signature, certificate validity time, and certificate status, and encrypt and return the verification result to the certificate verification platform. As an internal functional unit of the data asset certificate (DAC) rights protection unit 300, the multi-domain black box verification module 330 accepts the call of the data asset certificate (DAC) rights protection unit 300.
[0233] The extraction voucher information module 340 in this unit 300 is configured to allow the cover information, sensitive information, and additional text information in the data asset certificate (DAC) verified by the multi-domain black box verification module 330 to be read on the user terminal through the relevant interface form, ensuring the legality of its application and completing the rights protection 310 of the data asset certificate (DAC). As an internal functional unit of the data asset certificate (DAC) rights protection unit 300, the extraction voucher information module 340 is called by the data asset certificate (DAC) rights protection unit 300.
[0234] In some embodiments of the present invention, as Figure 4 shown, the voucher template making module unit 400 in this system includes a voucher base plate making module 420, an associated voucher cover information attribute module 430, a blank field generation module 440, and a voucher template warehousing module 450, and realizes the template making of the data asset certificate (DAC) 410.
[0235] As a further explanation, the voucher template making module unit 400 is the voucher template making module 120 internal to the data asset right confirmation unit 100, and it is called by the data asset certificate (DAC) right confirmation unit 100.
[0236] Among them, the voucher base plate making module 420 in this unit is configured to scan the cover blank picture of the data asset certificate (DAC) 410 that the user needs to make and make it into the base plate of the voucher. As an internal functional module of the voucher template making module unit 400, the voucher base plate making module 420 is called by the voucher template making module unit 400.
[0237] The associated voucher cover information attribute module 430 in this unit is configured to perform data interaction with the voucher base plate making module 420, and is used to complete the information attribute definition of the cover information elements associated on the base plate, including content such as tables, fields, signature positions, font sizes, colors, coordinates, etc. As an internal functional module of the voucher template making module unit 400, the associated voucher cover information attribute module 430 is called by the voucher template making module unit 400.
[0238] The blank field generation module 440 in this unit is configured to pre-generate an unlimited number of blank "fields" with specified names (with field attributes but empty content) on the data asset certificate (DAC) 410 that the user needs to make, and complete the production of the blank template of the data asset certificate (DAC). As an internal functional module of the voucher template making module unit 400, the blank field generation module 440 is called by the voucher template making module unit 400.
[0239] The voucher template storage module 450 in this unit is configured to interact with the blank field generation module 440, and is used to store the template database of the data asset voucher (DAC) after the production of the data asset voucher (DAC) template, so as to be called by the data asset voucher (DAC) confirmation unit 100 for its data asset voucher (DAC). As an internal functional module of the voucher template production module unit 400, the voucher template storage module 450 accepts the call of the voucher template production module unit 400.
[0240] In some embodiments of the present invention, as Figure 5 shown, the security label encapsulation module unit 500 in this system includes a label file generation module 520, a voucher encryption module 530, a label file encryption module 540, and a label and voucher decryption module 550, and realizes the security label encapsulation of the data asset voucher (DAC) 510.
[0241] As a further explanation, the security label encapsulation module unit 500 is the security label encapsulation module 230 internal to the data asset exercise right unit 200, and it accepts the call of the data asset voucher (DAC) exercise right unit 200.
[0242] Among them, the label file generation module 520 in this unit is configured to extract the basic attributes of the data asset voucher (DAC) 510 file after being confirmed by the data asset voucher (DAC) confirmation unit 100 according to the standard of the "GM / T 0055-2018 Technical Specification for Cryptographic Application of Electronic Documents" of the State Cryptography Administration to form a label file. As an internal functional module of the security label encapsulation module unit 500, the label file generation module 520 accepts the call of the security label encapsulation module unit 500.
[0243] The voucher encryption module 530 in this unit is configured to use the pseudo-random number generated by the pseudo-random function of the computer as the encryption key, and then complete the overall encryption of the data asset voucher (DAC) file after being confirmed by the data asset voucher (DAC) confirmation unit 100, and then store the corresponding decryption key in the label file. As an internal functional module of the security label encapsulation module unit 500, the voucher encryption module 530 accepts the call of the security label encapsulation module unit 500.
[0244] The label file encryption module 540 in this unit is configured to interact with the certificate encryption module 530 in terms of data, and encrypt the label file once with the national cipher SM9 based on the ID parameter key of the mobile phone, and load the label file onto the data asset certificate (DAC) file after being confirmed by the data asset certificate (DAC) confirmation unit 100, forming a uniquely bound data asset certificate (DAC) file with a label, and storing it in the data space of the terminal device. The label file encryption module 540, as an internal functional module of the security label encapsulation module unit 500, accepts the call of the security label encapsulation module unit 500.
[0245] The label and certificate decryption module 550 in this unit is configured to be able to decrypt the label file of the data asset certificate (DAC) file after being confirmed by the data asset certificate (DAC) confirmation unit 100 in the terminal data space based on the ID parameter key of the mobile phone, and then take out the decryption key of the data asset certificate (DAC) file to perform a decryption operation on the data asset certificate (DAC) file. The label and certificate decryption module 550, as an internal functional module of the security label encapsulation module unit 500, accepts the call of the security label encapsulation module unit 500.
[0246] In some embodiments of the present invention, as Figure 6 shown, the additional text annotation module unit 600 in this system includes a mobile terminal additional text information module 630, an additional text embedding strategy module 640, an additional text embedding algorithm module 650, a mobile terminal certificate embedding additional text processing module 660, and a mobile terminal digital signature module 670, and realizes the additional text annotation of the data asset certificate (DAC) 610.
[0247] As a further explanation, the additional text annotation module unit 600 is the additional text annotation module 240 internally provided in the data asset exercise right unit 200, and it accepts the call of the data asset certificate (DAC) exercise right unit 200.
[0248] Among them, the additional text information module 630 in this unit is configured to input additional text content (control attribute information of the data asset certificate (DAC), such as elements information such as the designated recipient of the data asset certificate (DAC), usage scope, and usage validity period, etc.) on the mobile phone. The additional text information module 630, as an internal functional module of the additional text annotation module unit 600, accepts the call of the additional text annotation module unit 600.
[0249] The additional text embedding strategy module 640 in this unit is configured to interact with the mobile additional text information module 630, and embed the input additional text content in a visual form (such as digital watermark) or a hidden storage form on the data asset certificate (DAC) 610 after being confirmed by the data asset certificate (DAC) confirmation unit 100 on the mobile phone side, becoming additional text information that is visible or invisible to the human eye (visible to machines), and complete the setting of the additional text embedding strategy. The additional text embedding strategy includes, but is not limited to, information such as the starting position of the text, text transparency, font name, font color, display method (left alignment, center alignment, right alignment, and not display), embedding area range, and embedding page. This additional text embedding strategy module 640, as an internal functional module of the additional text annotation module unit 600, accepts the call of the additional text annotation module unit 600.
[0250] The additional text embedding algorithm module 650 in this unit is configured to interact with the additional text embedding strategy module 640, and can automatically identify and dynamically calculate the font size and position of the text according to the additional text embedding strategy and the amount of input additional text content. This additional text embedding algorithm module 650, as an internal functional module of the additional text annotation module unit 600, accepts the call of the additional text annotation module unit 600.
[0251] The mobile certificate embedded additional text processing module 660 in this unit is configured to interact with the additional text embedding strategy module 640 and the additional text embedding algorithm module 650, and when embedding additional text in a visual form (such as digital watermark) according to the additional text embedding strategy information, it can specify a page or all pages, variable areas, and automatically wrap and display the additional text information to ensure that all the input additional text content can be displayed on the page of the mobile phone side data asset certificate (DAC); when embedding additional text in a hidden storage form, it can store the additional text in XML form inside the data asset certificate (DAC), attached to the data asset certificate (DAC), and the additional text will not be displayed when displaying the data asset certificate (DAC), and the additional text needs to be read through an interface form. This mobile certificate embedded additional text processing module 660, as an internal functional module of the additional text annotation module unit 600, accepts the call of the additional text annotation module unit 600.
[0252] The mobile digital signature module 670 in this unit is configured to use the digital signature method with timestamp on the mobile phone side to sign and protect the attached text in the form of "domain" content, thereby generating a data asset certificate (DAC) 610 with digital signature and embedded attached text. The mobile digital signature module 670, as an internal functional module of the attached text annotation module unit 600, accepts the call of the attached text annotation module unit 600.
[0253] In some embodiments of the present invention, as Figure 7 shown, the multi-domain black box verification module unit 700 in this system includes a certificate element verification module 730, a time verification module 740, a status content verification module 750, and a verification result encryption and return module 760, and realizes multi-dimensional verification of the data asset certificate (DAC) in the "black box".
[0254] As a further explanation, the multi-domain black box verification module unit 700 is the multi-domain black box verification module 330 internally provided in the data asset rights protection unit 300, and it accepts the call of the data asset certificate (DAC) rights protection unit 300.
[0255] Among them, the certificate element verification module 730 in this unit is configured to perform data interaction with the certificate verification platform, and is used to verify, in the security verification area, the certificate verification platform's input of the data asset certificate (DAC) 720 including the requester ID data and the data asset certificate (DAC) after rights confirmation and exercise according to the received data asset certificate (DAC) verification request. Specifically, it verifies the timestamped electronic signature or digital signature, the names and attributes of various "domains", the timestamped digital signature of the attached text, and the timestamped digital signature of the status domain of the data asset certificate (DAC) 720 respectively to ensure the validity of the verification elements. The certificate element verification module 730, as an internal functional module of the multi-domain black box verification module unit 700, accepts the call of the multi-domain black box verification module unit 700.
[0256] The time verification module 740 in this unit is configured to extract the time information of the data asset certificate (DAC) 720 and the time information in the attached text, and verify its validity. The time verification module 740, as an internal functional module of the multi-domain black box verification module unit 700, accepts the call of the multi-domain black box verification module unit 700.
[0257] The status content verification module 750 in this unit is configured to extract the status information of the data asset certificate (DAC) 720 and verify its validity. The status content verification module 750, as an internal functional module of the multi-domain black box verification module unit 700, accepts the call of the multi-domain black box verification module unit 700.
[0258] The verification result encryption and return module 760 in this unit is configured to interact with the voucher element verification module 730, the time verification module 740, and the status content verification module 750. After the verification is completed, the verification result is encrypted using the national cryptographic SM9 algorithm with the requester ID as a parameter and returned to the voucher verification platform. The verification result encryption and return module 760, as an internal functional module of the multi-domain black box verification module unit 700, accepts the call of the multi-domain black box verification module unit 700.
[0259] The following is an example to illustrate the specific implementation process of the data asset voucher (DAC) for rights confirmation, rights exercise, and rights protection based on the data asset voucher security control system formed by the above solution. The steps of the entire implementation process are as follows:
[0260] 1. The user application system sends three functional instructions for rights confirmation, rights exercise, and rights protection of the data asset voucher (DAC) to the data asset voucher security control system.
[0261] (DAC).
[0262] 2. After receiving the rights confirmation instruction, the data asset voucher security control system first scans the blank cover image of the data asset voucher (DAC) to be produced and makes it into the bottom plate of the voucher; completes the definition of information attributes related to the cover information elements, including (table, field, signature position, font size, color, coordinates), etc.; pre-locates and sets the parameters of an unlimited number of blank "domains" with specified names on the data asset voucher (DAC); the parameters here include: the positioning information of the blank "domain" on the voucher surface, the reserved space size information of the blank "domain", etc. (with domain attributes but empty content), and completes the production of the blank template of the data asset voucher (DAC); after the production of the data asset voucher (DAC) template is completed, it is stored in the template database of the data asset voucher (DAC) for use when the data asset voucher (DAC) is rights confirmed.
[0263] 3. When it is necessary to confirm the rights of a certain data asset voucher (DAC) in the voucher template database, the voucher template is retrieved from the voucher template database, and the corresponding data asset information (including data, files, pictures, audio, video, etc.) is input.
[0264] 4. According to the pre-set data desensitization and hiding strategy information, for the sensitive information on the cover of the data asset voucher (DAC), a mask form is used to mask the sensitive information with "*", and the original sensitive information on the cover is stored in the data asset voucher (DAC); at the same time, for the sensitive information in the data asset voucher
[0265] (DAC), it is hidden in the data asset voucher (DAC) in XML form.
[0266] Attach to the Data Asset Certificate (DAC) to ensure the data security of the Data Asset Certificate (DAC);
[0267] 5. Adopt the digital signature technology with timestamp to electronically sign or digitally sign the Data Asset Certificate (DAC) file, ensuring the authenticity, integrity, verifiability, non-repudiation, and security anti-counterfeiting of the Data Asset Certificate (DAC) file, thereby completing the confirmation of rights for the Data Asset Certificate (DAC). After the confirmation of rights, the Data Asset Certificate (DAC) can be stored in the Data Asset Certificate (DAC) library;
[0268] 6. After receiving its exercise right instruction, the Data Asset Certificate Security Control System first retrieves the confirmed Data Asset Certificate (DAC) file from the Data Asset Certificate (DAC) database; and according to the standard of the "GM / T 0055-2018 Technical Specification for the Application of Electronic File Password" of the State Cryptography Administration, extracts the basic attributes of the Data Asset Certificate (DAC) file (including basic information such as the creation date, modification date, file size, owner, digest, etc.) of the certificate file to form a tag file; after using the pseudo-random number generated by the pseudo-random function of the computer itself as the encryption key, complete the overall encryption of the Data Asset Certificate (DAC) file, and then store the corresponding decryption key in the tag file; based on the ID parameter key of the mobile phone terminal, encrypt the tag file once with the national secret SM9, and then load the tag file onto the Data Asset Certificate (DAC) file to form a uniquely bound Data Asset Certificate (DAC) file with a tag, and store it in the data space of the terminal device (mobile phone terminal);
[0269] 7. When exercising the right to the Data Asset Certificate (DAC) in the data space of the terminal device (mobile phone terminal), retrieve the confirmed Data Asset Certificate (DAC) from the data space of the mobile phone terminal, and based on the ID parameter key of the mobile phone terminal, decrypt the tag file of the Data Asset Certificate (DAC) file in the terminal data space, and then take out the decryption key of the Data Asset Certificate (DAC) file to perform the decryption operation on the Data Asset Certificate (DAC) file;
[0270] 8. Input additional text content (such as: new information on elements such as the designated recipient of the Data Asset Certificate (DAC), usage scope, usage validity period, etc.) on the mobile phone terminal, and overlay the additional text on the Data Asset Certificate (DAC) in a visible or invisible form;
[0271] 9. Use a digital signature with a timestamp to digitally sign the additional text of the Digital Asset Certificate (DAC) on the mobile phone side, ensuring the authenticity, integrity, validity, verifiability, non-repudiation, and security anti-counterfeiting of the additional text of the Digital Asset Certificate (DAC) on the mobile phone side, thereby completing the exercise control of the Digital Asset Certificate (DAC). After the exercise, the Digital Asset Certificate (DAC) can be used by the holder of the Digital Asset Certificate (DAC) to perform business operations such as authorization applications and online submissions through the mobile phone side, and the Digital Asset Certificate (DAC) is interacted to the recipient.
[0272] 10. After the recipient of the Digital Asset Certificate (DAC) issues a rights protection instruction to the Digital Asset Certificate Security Control System, first submit the received Digital Asset Certificate (DAC) to the certificate verification platform on the Internet for verification. Here, the certificate verification platform is a certificate verification platform built relying on the national cryptographic service platform. This platform specifically accepts certificate verification requests, and the verification content includes national cryptographic electronic seals, digital signatures, certificate validity periods, and certificate status, etc.
[0273] 11. The certificate verification platform adopts a multi-domain black box verification method in the security verification space ("black box")
[0274] The kernel verifies the validity and authenticity of multi-domain contents such as its electronic seal, digital signature, certificate effective time, validity of the certificate "domain", and certificate status, etc., and after encrypting the verification result, returns it to the certificate verification platform to ensure the authenticity, integrity, validity, verifiability, non-repudiation, and security anti-counterfeiting of the Digital Asset Certificate (DAC).
[0275] 12. After the certificate verification platform verifies the received Digital Asset Certificate (DAC), it encrypts the verification result and returns it to the requester; at the same time, the requester decrypts the verification result based on the corresponding algorithm with the requester's ID parameter. If the verification passes, the rights protection of the Digital Asset Certificate (DAC) is completed, ensuring the legality of the application of the Digital Asset Certificate (DAC).
[0276] Through the above implementation solutions and corresponding examples, it can be seen that the solution of the present invention uses Data Ownership Control (DOC) technology to implement the confirmation of rights, exercise of rights, and rights protection of the Digital Asset Certificate (DAC), and has obvious advantages compared with blockchain technology and Non-Fungible Token (NFT) technology.
[0277] Specifically, the data asset certificate security control solution based on the Data Ownership Control (DOC) technology provided by the present invention, compared with the blockchain technology and the Non-Fungible Token (NFT) technology, uses a layout file as the carrier container of the data asset, and adopts national commercial cryptography technology. The data asset certificate (DAC) is authenticated through an electronic signature / digital signature with a time stamp, which is safer, more convenient, and more popular among holders than the blockchain technology commonly used in the industry as a method for authenticating data assets. At the same time, it has a flexible and comprehensive privacy protection function.
[0278] Furthermore, the solution of the present invention can effectively solve the problems that layout files cannot be edited on mobile devices and the existing electronic signature / digital signature protection function of layout files will be damaged when additional information is added during editing, realize the operation of adding text information to the data asset certificate (DAC) on mobile devices, and realize the exercise of rights of the data asset certificate (DAC). At the same time, the data asset certificate (DAC) on the mobile device is uniquely bound to the security label, ensuring the security and flexibility of the mobile device certificate;
[0279] Furthermore, the solution of the present invention breaks through the traditional single verification method of certificates and adopts multi-domain verification technology. It is necessary to verify the electronic seal of the certificate to ensure that the issuing agency of the certificate will not forge it; it is also necessary to verify the personal digital signature of the certificate user to ensure that the certificate user is not a forged person; it is also necessary to verify the current state validity of the certificate and that the key information has not been tampered with, etc., to realize the protection of rights of the data asset certificate (DAC).
[0280] Furthermore, when making the certificate template of the solution of the present invention, several blank fields with attributes are pre-generated by using the embedding technology, laying a foundation for adding additional information and status information for using the certificate after the certificate is authenticated.
[0281] Furthermore, the solution of the present invention adopts a label technology that meets the requirements of national cryptography to form a high-strength encryption protection of "one document, one cipher" and "one time, one cipher" for the certificate file.
[0282] Furthermore, the solution of the present invention realizes that additional text is embedded in the certificate in two forms: visible and invisible. It can be superimposed on any page of the certificate in the form of a watermark without damaging the existing electronic signature protection of the certificate, and a personal digital signature is made to ensure the validity and non-repudiation of the added information.
[0283] Furthermore, the solution of the present invention places the entire verification process in a secure verification area (i.e., a "black box"), and the verification result is transmitted to the requester by using an encryption method to prevent the verification result from being tampered with when the certificate verification platform is attacked by network hackers.
[0284] Here, we further compare the relevant characteristics of Data Ownership Control (DOC) technology with blockchain technology and Non-Fungible Token (NFT) technology (see the following table):
[0285] Comparison Table of the Characteristics of Data Ownership Control (DOC) Technology, Blockchain Technology, and Non-Fungible Token Technology
[0286]
[0287]
[0288] In summary, since Non-Fungible Token (NFT) technology completely depends on blockchain technology, and the characteristics of Data Ownership Control (DOC) technology and blockchain technology have their own advantages, although they can both meet the core requirements of WEB3.0 and can both become the underlying support technologies of WEB3.0. However, in terms of the control rights, sharing rights, trading rights, storage methods, backup methods, indivisibility, risk prevention, security, and government supervision of data assets, Data Ownership Control (DOC) technology is more functionally complete and convenient to use than blockchain technology and Non-Fungible Token (NFT) technology.
[0289] Blockchain technology needs to build a blockchain network. When authenticating, exercising rights, and safeguarding rights for data assets, the data assets must be uploaded to the blockchain and stored on a certain heavy node of the blockchain, and the digest (Hash value) of the data assets must be stored on each node of the blockchain in a distributed storage method, so as to play the role of being tamper-proof and forgery-proof; when using data assets, the data asset holder needs to log in to a certain blockchain network system to complete functions such as authenticating, authorizing, and interacting with the data assets, and the data asset recipient also needs to log in to the same blockchain network system to complete functions such as querying, verifying, and exporting the data assets. The management of data assets must rely on a certain specific blockchain network system, and moreover, the data assets must always be stored on the blockchain. Once they are separated from the blockchain, the authentication, exercise of rights, and safeguarding of rights for the data assets will all get out of control. Therefore, the method of using blockchain technology to achieve the authentication, exercise of rights, and safeguarding of rights for data assets has great limitations and inconvenience in use.
[0290] The data ownership control (DOC) technology uses the data asset certificate (DAC) as the carrier of data assets, relying on a "WEB3.0 data asset trusted service cloud platform based on distributed deployment" on the Internet for the whole society, and saves the data asset certificate (DAC) on mobile devices through mobile APP, mini-programs and other means, so that data asset holders and recipients can use the data assets on the mobile terminal anytime and anywhere, and users can complete the functions of data asset confirmation, authorization, annotation, display, submission, verification, data extraction, interaction, export, archiving, and traceability, thereby building an ecological system for comprehensive management of data assets, and providing basic guarantees for various application scenarios such as subsequent evaluation and assessment of data assets, data asset transactions, mortgage financing, and data authorization operations. As long as the Internet is not interrupted, the use of data ownership control (DOC) technology can ensure that the confirmation, exercise and protection of data assets can be safely and effectively realized anytime and anywhere, meet the application needs of data assets in different social environments, fully reflect the value of data assets, and promote all people to share the dividends of digital economic development. Its convenience and security are better than blockchain technology.
[0291] At the same time, the scheme of the present invention can also organically integrate data ownership control (DOC) technology and blockchain technology, and store all kinds of operation behaviors of data asset certificates (DAC) on the blockchain. By utilizing the tamper-proof and traceable capabilities of blockchain, the life trajectory of data assets and the value evolution process of data assets are automatically and completely retained for users and those in need to trace the source, thereby building a technical support base for WEB3.0 that is inclusive of blockchain technology and superior to blockchain technology.
[0292] The above-mentioned method of the present invention, or a specific system unit, or a part of the same, is a pure software architecture, which can be arranged on a physical medium, such as a hard disk, an optical disk, or any electronic device (such as a smart phone, a computer-readable storage medium) through program code. When the machine loads the program code and executes it (such as a smart phone loading and executing it), the machine becomes a device for implementing the present invention. The above-mentioned method and device of the present invention can also be transmitted in the form of program code through some transmission media, such as cables, optical fibers, or any transmission mode. When the program code is received, loaded and executed by a machine (such as a smart phone), the machine becomes a device for implementing the present invention.
[0293] The above shows and describes the basic principles, main features and advantages of the present invention. It should be understood by those skilled in the art that the present invention is not limited to the above embodiments, and the above embodiments and descriptions are only for explaining the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention may have various changes and improvements, which fall within the scope of the present invention to be protected. The scope of protection of the present invention is defined by the attached claims and their equivalents.
Claims
1. A security control method for data asset vouchers based on data ownership control technology, characterized in that, The described security control method includes the following steps: Step 1: Construct a Data Asset Credential (DAC) template, and input the corresponding data asset information into the Data Asset Credential (DAC) template to generate a Data Asset Credential (DAC); Step 2: Perform desensitization and hiding processing on the sensitive information on the cover of the Data Asset Credential (DAC) and the sensitive information within the Data Asset Credential (DAC); Step 3: The data asset information after desensitization and hiding processing is stored back into the Data Asset Credential (DAC), and the Data Asset Credential (DAC) file is electronically signed or digitally signed using a digital signature with a timestamp to complete the confirmation of the Data Asset Credential (DAC); Step 4: For the confirmed Data Asset Credential (DAC), using a secure label encapsulation method, store the Data Asset Credential (DAC) with a security label in a mobile device; Step 5: The Data Asset Credential (DAC) stored on the mobile device will be embedded with corresponding additional text based on an additional text annotation method, and a digital signature for the additional text will be completed to complete the exercise of rights of the Data Asset Credential (DAC); Step 6: During the network circulation and interaction process of the Data Asset Credential (DAC), after being received by the receiving party's terminal device, it will be submitted to a credential verification platform on the Internet for verification; Step 7: For the encrypted verification result feedback by the credential verification platform, decrypt the verification result based on the requester's ID parameter, and after passing the verification, read the cover information, sensitive information, and additional text information within the Data Asset Credential (DAC) through relevant interface forms to complete the protection of rights of the Data Asset Credential (DAC).
2. The security control method for data assets based on the Data Ownership Control (DOC) technology according to claim 1, wherein, In the step (1), the production of the Data Asset Credential (DAC) template includes the following steps: Step A1: Scan a pre-designed cover picture of the Data Asset Credential (DAC) to become the base plate of the Data Asset Credential (DAC); Step A2: According to the set information elements of the Data Asset Credential (DAC) cover, complete the definition of information attributes associated with the cover information elements on the base plate; Step A3: Pre-generate an unlimited number of blank fields with specified names on the Data Asset Credential (DAC) to complete the production of the blank template of the Data Asset Credential (DAC).
3. The security control method for data assets based on the Data Ownership Control (DOC) technology according to claim 1, characterized in that, When performing desensitization and hiding processing on sensitive information in the step (2), according to the pre-set data desensitization and hiding strategy information, for the sensitive information on the cover of the Data Asset Credential (DAC), perform a "*" mask desensitization operation on the sensitive information in the form of a mask, and store the original sensitive information on the cover into the Data Asset Credential (DAC); for the sensitive information within the Data Asset Credential (DAC), hide it in the Data Asset Credential (DAC) in XML form and attach it behind the Data Asset Credential (DAC).
4. The security control method for data assets based on the Data Ownership Control (DOC) technology according to claim 1, characterized in that, When encapsulating the confirmed Data Asset Credential (DAC) based on the secure label encapsulation method in the step (4), it includes: Step B1: Extract the basic attributes of the Data Asset Credential (DAC) file to form a label file; Step B2: Extract the encryption key based on the generated pseudo-random number, complete the overall encryption of the Data Asset Credential (DAC), and then store the corresponding decryption key in the label file; Step B3: Use the ID parameter key of the target mobile phone to encrypt the label file once with the corresponding encryption algorithm, load the encrypted label file onto the Data Asset Credential (DAC) file to form a uniquely bound labeled Data Asset Credential (DAC), and store it in the data space of the mobile device.
5. The security control method for data assets based on the Data Ownership Control (DOC) technology according to claim 1, characterized in that, When embedding the corresponding additional text in the step (5) based on the additional text annotation method, it includes: Step C1: Input the additional text content on the target mobile phone; Step C2: Embed the input additional text in a visual or hidden form into the Data Asset Credential (DAC) of the target mobile phone according to the set additional text embedding strategy and method; Step C3: Use the anti-counterfeiting method of the additional text to sign the Data Asset Credential (DAC) of the target mobile phone and the additional text with a timestamped digital signature; Step C4: Generate a mobile phone Data Asset Credential (DAC) with additional text embedded and protected by a timestamped digital signature, which can verify the validity of the digital signature information and domain of the additional text.
6. The security control method for data assets based on the Data Ownership Control (DOC) technology according to claim 1, characterized in that, When using the multi-domain black box verification method to verify the Data Asset Credential (DAC) in the step (6), it includes: Step D1: For the received Data Asset Credential (DAC) verification request, the credential verification platform sends the requester's ID and the Data Asset Credential (DAC) to the security verification area together. The security verification area only accepts task requests sent by the credential verification platform and rejects all other requests; Step D2: In the security verification area, verify the validity of the timestamped electronic signature or digital signature, the names and attributes of various "domains", the timestamped digital signature of the additional text, and the timestamped digital signature of the status domain of the Data Asset Credential (DAC) respectively; Step D3: Extract the time information of the Data Asset Credential (DAC) and the time information in the additional text, and verify its validity; Step D4: Extract the status information of the Data Asset Credential (DAC) and verify its validity; After the verification is completed, use the encryption algorithm to encrypt the verification result with the requester ID as a parameter and return it to the credential verification platform.
7. The security control method for data assets based on the Data Ownership Control (DOC) technology according to claim 1, characterized in that, The method reserves blank "domains" on the Data Asset Credential (DAC) of the mobile phone without digital signature or electronic signature. The reserved blank "domains" are configured to be able to dynamically embed visual additional text or hidden additional text when adding additional text, and can securely verify the "domain" name and content information.
8. A data asset voucher security control system based on data ownership control technology, characterized in that, The security control system includes a Data Asset Credential (DAC) confirmation unit, a Data Asset Credential (DAC) exercise unit, a Data Asset Credential (DAC) rights protection unit, a credential template production module unit, a security label encapsulation module unit, an additional text annotation module unit, and a multi-domain black box verification module unit; The data asset credential (DAC) confirmation unit is configured to complete the confirmation of the data asset credential (DAC) through the organic cooperation among voucher template production, data desensitization and hiding, and timestamped electronic signature / digital signature; The data asset credential (DAC) exercise unit is configured to complete the exercise of the data asset credential (DAC) through the organic cooperation between security label encapsulation and additional text annotation; The data asset credential (DAC) rights protection unit is configured to complete the rights protection of the data asset credential (DAC) through the organic cooperation between multi-domain black box verification and extraction of voucher information; The voucher template production module unit is configured to produce the bottom plate of the voucher and input the face information of the data asset credential into the bottom plate of the data asset credential (DAC). The voucher template production module unit is configured to be callable by the data asset credential (DAC) confirmation unit; The security label encapsulation module unit is configured to uniquely bind the label file to the confirmed data asset credential (DAC) and save it to the mobile phone. The security label encapsulation module unit is configured to be callable by the data asset credential (DAC) exercise unit; The additional text annotation module unit is configured to embed additional text into the confirmed data asset credential (DAC) on the mobile phone and complete the digital signature of the additional text. The additional text annotation module unit is configured to be callable by the data asset credential (DAC) exercise unit; The black box verification module unit is configured to receive, in a relatively secure and controllable space, the data asset credential (DAC) that has completed confirmation and exercise processes by the data asset credential (DAC) confirmation unit and the data asset credential (DAC) exercise unit submitted by the voucher verification platform, verify the validity and authenticity of multi-domain contents such as its electronic seal, digital signature, voucher valid time, and voucher status, and encrypt and return the verification result to the voucher verification platform. The black box verification module unit is configured to be callable by the data asset credential (DAC) rights protection unit; 9. The data asset voucher security control system based on the data ownership control technology according to claim 8, wherein, The data asset credential (DAC) confirmation unit includes a voucher template production module, a data desensitization and hiding module, and a timestamped electronic signature / digital signature module. The voucher template production module is configured to be able to produce the data asset credential (DAC). The data desensitization and hiding module is configured to interact with the voucher template production module and be able to perform desensitization and hiding processing on the sensitive information on the cover of the data asset credential (DAC) and the sensitive information inside the data asset credential (DAC); The timestamped electronic signature / digital signature module is configured to be able to perform electronic signature / digital signature protection on the data asset credential (DAC) that has been desensitized and hidden.
10. The data asset voucher security control system based on data ownership control technology according to claim 8, characterized in that, The exercise unit of the Data Asset Certificate (DAC) includes a security label encapsulation module and an additional text annotation module; the security label encapsulation module is configured to uniquely bind the label file and the Data Asset Certificate (DAC), and save them to the mobile phone; the additional text annotation module is configured to embed additional text into the Data Asset Certificate (DAC) and complete the digital signature of the additional text.
11. The data asset voucher security control system based on data ownership control technology according to claim 8, characterized in that, The rights protection unit of the Data Asset Certificate (DAC) includes a multi-domain black box verification module and a certificate information extraction module; The multi-domain black box verification module is configured to run in a relatively secure and controllable space, and is used to verify the validity and authenticity of the multi-domain content of the electronic seal, digital signature, certificate validity period, and certificate status of the Data Asset Certificate (DAC), and encrypt and return the verification result; The certificate information extraction module is configured to interact with the multi-domain black box verification module, and can read the cover information, sensitive information, and additional text information in the Data Asset Certificate (DAC) in the form of relevant interfaces after the Data Asset Certificate (DAC) is verified.
12. The data asset voucher security control system based on data ownership control technology according to claim 8, characterized in that, The certificate template production module unit includes a certificate base plate production module, an associated certificate cover information attribute module, a blank field generation module, and a certificate template storage module; The certificate base plate production module is configured to produce the cover image of the Data Asset Certificate (DAC) into the base plate of the certificate; The associated certificate cover information attribute module is configured to complete the definition of the information attributes associated with the cover information elements on the base plate; The blank field generation module is configured to pre-generate an unlimited number of blank "fields" with specified names on the Data Asset Certificate (DAC) to complete the production of the blank template of the Data Asset Certificate (DAC); The certificate template storage module is configured to store the blank template of the Data Asset Certificate (DAC) in the template database of the Data Asset Certificate (DAC) after the production is completed.
13. The data asset voucher security control system based on the data ownership control technology according to claim 8, characterized in that, The security label encapsulation module unit includes a label file generation module, a certificate encryption module, a label file encryption module, and a label and certificate decryption module; The label file generation module is configured to extract the basic attributes of the Data Asset Certificate (DAC) file to form a label file; The certificate encryption module is configured to extract the encryption key according to the generated pseudo-random number, and accordingly complete the overall encryption of the Data Asset Certificate (DAC), and then store the corresponding decryption key in the label file; The label file encryption module is configured to encrypt the label file once based on the ID parameter key of the mobile phone, load the label file onto the Data Asset Certificate (DAC) file to form a uniquely bound Data Asset Certificate (DAC) with a label, and store it in the data space of the device; The label and certificate decryption module is configured to decrypt the label file of the Data Asset Certificate (DAC) in the data space based on the ID parameter key of the mobile phone, and then take out the decryption key of the Data Asset Certificate (DAC) to perform a decryption operation on the Data Asset Certificate (DAC).
14. The data asset voucher security control system based on the data ownership control technology according to claim 8, wherein, The additional text annotation module unit includes a mobile phone end additional text information module, an additional text embedding strategy module, an additional text embedding algorithm module, a mobile phone end voucher embedding additional text processing module, and a mobile phone end digital signature module; The mobile phone end additional text information module is configured to be able to input additional text content on the mobile phone end; The additional text embedding strategy module is configured to be able to embed the input additional text content on the data asset certificate (DAC) in a visual form or a hidden storage form, and complete the setting of the additional text embedding strategy; The additional text embedding algorithm module is configured to be able to automatically identify and dynamically calculate the font size and position of the text according to the additional text embedding strategy and the amount of the input additional text content; The mobile phone end voucher embedding additional text processing module is configured to be able to embed the additional text content on the mobile phone end data asset certificate (DAC) according to the additional text embedding strategy information. The mobile phone end digital signature module is configured to be able to use the embedded additional text as the content form of the "field", and perform signature protection on the additional text in a digital signature manner with a time stamp; 15. The data asset voucher security control system based on the data ownership control technology according to claim 8, characterized in that, The multi-domain black box verification module unit includes a voucher element verification module, a time verification module, a status content verification module, and a verification result encryption return module; The voucher element verification module is configured to be able to send the requester ID and the data asset certificate (DAC) to the security verification area together after receiving the data asset certificate (DAC) request on the voucher verification platform, and verify the time-stamped electronic signature or digital signature, the names and attributes of various "fields", the time-stamped digital signature of the additional text, and the time-stamped digital signature of the status field of the data asset certificate (DAC) in the security verification area; The time verification module is configured to be able to extract the time information of the data asset certificate (DAC) and the time information in the additional text, and verify its validity; The status content verification module is configured to be able to extract the status information of the data asset certificate (DAC), and verify its validity; The verification result encryption return module is configured to be able to return the verification result to the voucher verification platform after the verification, encrypted based on the encryption algorithm with the requester ID as a parameter.