Data circulation method based on industry data platform and trusted data space

The integration of industry data platforms and trusted data spaces facilitates secure and efficient intra- and inter-industry data exchange, addressing data flow limitations and enhancing data utilization and value.

CN120321054AActive Publication Date: 2025-07-15NANJING FUTURE NETWORK CO LTD
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202510812962.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-07-15
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

In the existing technology, there are obvious limitations in the circulation of data within and across industries, and the safe, extensive and efficient circulation of data cannot be achieved, resulting in the inability to maximize the value of data.

Method used

Through an integrated login method based on the industry data platform and trusted data space, a cross-domain token is used for cross-domain verification, and two publishing methods are defined based on data attributes to achieve safe and extensive circulation of data within and across industries.

Benefits of technology

On the premise of ensuring data privacy and security, the diversified circulation of data in the broad data market has been achieved, the benefits of data providers have been improved, and a wider data source is provided for data consumers to assist in data decision-making.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321054A_ABST
    Figure CN120321054A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of data circulation, and discloses a data circulation method based on an industry data platform and a trusted data space. Comprising the following steps: a data platform of the industry obtains a credible certificate of a user of the industry, and generates a first access token after the credible certificate passes verification to confirm that the user successfully logs in the data platform of the industry; generating a corresponding cross-domain token, transmitting the cross-domain token to a connector in the industry for cross-domain verification based on a token transmission mechanism, and generating a second access token after the verification is passed to confirm that the user successfully logs in the trusted data space; acquiring data products of the industry uploaded by the users of the industry, registering the data products in a product catalog mode, and uploading the data products to the trusted data space when continuously judging that the product attributes are permitted to interpass circulation; and / or allowing the user to access the data product of the industry in the data platform of the industry and the data products of other industries in the trusted data space based on the request of the user of the industry. According to the invention, data circulation in the industry and cross-industry can be realized at the same time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data circulation, and particularly relates to a data circulation method based on an industry data platform and a trusted data space. Background Art

[0002] Data circulation in various industrial fields refers to the process of data flowing and being allocated in the market as a new type of production factor. Especially with the development of the data economy, it is of great significance to maximize the value of data circulation. Generally, data circulation is divided into two types: intra-industry data circulation and cross-industry data circulation.

[0003] For the aforementioned intra-industry data circulation, it is mainly carried out by constructing a supply chain covering the industry. Although China has the most complete industrial categories in the world, in each industrial category, only the leading enterprises at the forefront of the development of each industrial category can build a complete data chain covering the upstream and downstream of the industry supply chain. Therefore, there are obvious limitations in the intra-industry data circulation within each industrial category, that is: the data circulation within the entire industry has not been achieved.

[0004] For the aforementioned cross-industry data circulation, it is mainly carried out through over-the-counter transactions. That is, the data provider publishes data in the data market, and after the data demander has a purchase intention, over-the-counter transactions are carried out. However, in this non-technical means of transaction process, the security of the data cannot be ensured. Therefore, the data provider will worry about the security of the data, especially that the data will be resold after it flows out, which will make it difficult for the data demander to obtain a wide range of data sources and difficult to conduct full-scale and accurate data analysis and use.

[0005] It can be seen that in the prior art, whether it is intra-industry data circulation or cross-industry data circulation, there are obvious limitations in circulation, and the safe, wide-ranging, and efficient effective circulation of data cannot be achieved, thus the maximum value of the data cannot be realized and the effective development of various industries cannot be promoted. Summary of the Invention

[0006] The purpose of the present invention is to provide a data circulation method based on an industry data platform and a trusted data space to solve the technical problem that there are obvious limitations in circulation in both the existing intra-industry data circulation and cross-industry data circulation processes, and the safe, wide-ranging, and efficient effective circulation of data cannot be achieved.

[0007] To achieve the above object, the present invention proposes the following technical solutions: In a first aspect, a data circulation method based on an industry data platform and a trusted data space is provided, including the following steps: The industry data platform obtains the trusted credentials of the users in the industry, and after passing the verification of the trusted credentials, generates a first access token to confirm the successful login of the users in the industry to the industry data platform; Among them, the first access token includes an identity statement and a service statement; the identity statement includes: the address and validity period of users in this industry; the service statement includes: the address and authorization scope of the connector in this industry; In response to the first access token, a cross-domain token corresponding to the user in this industry is generated, and the cross-domain token is transmitted to the connector in this industry through a token passing mechanism for cross-domain verification. After the verification is passed, a second access token is generated to confirm the successful login of the user in this industry to the trusted data space; Among them, the cross-domain verification includes signature verification, validity verification, and authorization verification; signature verification is used to verify the signature validity of the cross-domain token, validity verification is used to verify the validity period of the cross-domain token and whether it has been revoked, and authorization verification is used to verify whether the authorization scope matches; Obtain and publish the data products in this industry uploaded by users in this industry. When it is continuously determined that the product attribute allows cross-industry circulation, upload the data products in this industry to the trusted data space for publication; and / or based on the request of users in this industry, allow them to access the data products in this industry within the data platform in this industry and the data products of other industries within the trusted data space; Among them, the data products of other industries are published by users of other industries who log in through the corresponding data platforms of other industries.

[0008] Further, the step of obtaining and publishing the data products in this industry uploaded by users in this industry and, when it is continuously determined that the product attribute allows cross-industry circulation, uploading the data products in this industry to the trusted data space for publication includes: Publish the data products in this industry that do not allow cross-industry circulation on the data platform in this industry, and allow some users in this industry to access them based on the first access right; Publish the data products in this industry that allow cross-industry circulation in the trusted data space, and allow users in this industry and users of other industries who have passed the access authentication through the trusted data space to access them based on the second access right; Among them, the data platform in this industry and the trusted data space are authorized by the data provider to open permissions to data consumers with access requirements.

[0009] Further, the step that the data platform in this industry obtains the trusted credentials of users in this industry and generates a first access token to confirm the successful login of users in this industry to the data platform in this industry after passing the verification of the trusted credentials includes: Obtain the trusted credentials input by users in this industry; Call the auth interface or the login interface to send the trusted credentials to the authentication center within the data platform in this industry; Generate a first access token after passing the verification of the trusted credentials and return it to the users in this industry.

[0010] Further, it includes: Build an industry connector corresponding to the industry data platform and an other-industry connector corresponding to any other industry data platform within the trusted data space; Based on the API interface, directly communicate and connect industry users with the industry data platform, and directly communicate and connect any other industry users with the corresponding other industry data platform; Based on the API interface, directly communicate and connect the industry data platform with the industry connector, and directly communicate and connect any other industry data platform with the corresponding other industry connector.

[0011] Furthermore, it includes: When it is determined that the remaining valid duration of the industry data product in the industry data platform and the trusted data space is less than the preset duration threshold, send a processing inquiry to the industry user who released the industry data product; Based on the first feedback, when the remaining valid duration is 0, delete the corresponding industry data product in the industry data platform and the trusted data space; based on the second feedback, when the remaining valid duration is 0, extend the valid duration of the corresponding industry data product in the industry data platform and the trusted data space by a preset duration.

[0012] In a second aspect, the present technical solution provides a data circulation system based on an industry data platform and a trusted data space, including: A first login module for the industry data platform to obtain the trusted credentials of industry users, and generate a first access token after passing the verification of the trusted credentials to confirm the successful login of industry users to the industry data platform; Among them, the first access token includes an identity claim and a service claim; the identity claim includes: the address and validity period of the industry user; the service claim includes: the address and authorization scope of the industry connector; A second login module for generating a cross-domain token corresponding to the industry user in response to the first access token, and transmitting the cross-domain token to the industry connector through the token transfer mechanism for cross-domain verification, and generating a second access token after passing the verification to confirm the successful login of the industry user to the trusted data space; Among them, the cross-domain verification includes signature verification, timeliness verification, and authorization verification; signature verification is used to verify the signature validity of the cross-domain token, timeliness verification is used to verify the validity period of the cross-domain token and whether it has been revoked, and authorization verification is used to verify whether the authorization scope matches; A data publishing and access module is used to obtain and publish industry data products uploaded by users in the same industry. When it continues to determine that the product attribute allows cross - industry circulation, the industry data product is uploaded to the trusted data space for publishing; and / or based on the request of users in the same industry, it allows them to access industry data products within the industry data platform and other industry data products within the trusted data space; Among them, the other industry data products are published by other industry users logged in through the corresponding other industry data platforms.

[0013] Furthermore, the data publishing and access module includes: The first permission unit is used to publish industry data products that do not allow cross - industry circulation on the industry data platform and allow some industry users to access based on the first access permission; The second permission unit is used to publish industry data products that allow cross - industry circulation in the trusted data space and allow industry users and other industry users authenticated through the trusted data space to access based on the second access permission; Among them, the industry data platform and the trusted data space are authorized by the data provider to open permissions for data consumers with access requirements.

[0014] Furthermore, the first login module includes: An acquisition unit is used to acquire the trusted credentials input by industry users; An authentication unit is used to call the auth interface or the login interface to send the trusted credentials to the authentication center within the industry data platform; A generation unit is used to generate a first access token and return it to the industry user after the trusted credentials pass the verification.

[0015] In a third aspect, the present technical solution provides an electronic device, including at least one processor, the processor is coupled with a memory, and a computer program is stored in the memory, and the computer program is configured to implement the method when being run by the processor.

[0016] In a fourth aspect, the present technical solution provides a computer - readable storage medium, on which a computer program is stored, and the computer program is used to be executed by a processor to implement the method.

[0017] Beneficial effects: As can be seen from the above technical solutions, the technical solution of the present invention provides a data circulation method based on an industry data platform and a trusted data space to simultaneously solve the technical defects existing in the current in - industry data circulation and cross - industry data circulation.

[0018] In this technical solution, a connector is deployed for each industry within the trusted data space, and then the connector is used as a gateway to achieve the circulation of data between the industry data platform and the trusted data space. Specifically, first, an integrated login method is set. During the login process, users in this industry directly send a login request to the industry data platform. At this time, after successful login, a cross-domain token will be automatically generated in response to the first access token, and the login to the trusted data space will be directly triggered according to the token transfer mechanism. This improves the efficiency and convenience of login and subsequent data interaction. Specifically, to ensure login security and thus data security, triple verification including signature verification, timeliness verification, and authorization verification is performed on the cross-domain token. Secondly, during the data publishing and access process, considering the purpose of data privacy and the necessity of disclosure to users in other industries, two data publishing methods are defined based on product attributes. One is the method that does not allow cross-industry data circulation, and the other is the method that allows cross-industry data circulation. The former only interacts within the industry data platform; the latter needs to interact through the trusted data space. The product attributes are completely customized by the data provider, realizing the user's autonomous setting of the circulation of their own data.

[0019] In summary, under the premise of ensuring the data privacy and security of the data provider, this application matches the supply and demand sides to circulate and use data according to the agreed rules, not only realizing the self-circulation of data within the industry, but also achieving the diversity of industry data in the extensive data market. It not only breaks the circulation barrier that data circulation within the industry only occurs between some enterprises, but also can be provided to more users across industries and regions. While increasing the income of the data provider, it can also enable the data consumer to obtain a wider range of data sources to assist in data decision-making.

[0020] It should be understood that all combinations of the foregoing concepts and additional concepts described in more detail below can be regarded as part of the inventive subject matter of the present disclosure as long as such concepts do not conflict with each other.

[0021] The foregoing and other aspects, embodiments, and features of the teachings of the present invention can be more fully understood from the following description in conjunction with the accompanying drawings. Other additional aspects of the present invention, such as the features and / or beneficial effects of the exemplary embodiments, will be apparent in the following description, or will be learned through the practice of the specific embodiments according to the teachings of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The drawings are not intended to be drawn to scale. In the drawings, each identical or nearly identical component shown in each figure may be represented by the same reference numeral. For clarity, not every component is labeled in each figure. Now, embodiments of various aspects of the present invention will be described by way of example and with reference to the drawings, where: Figure 1It is a flowchart for building the software architecture of the data circulation method based on the industry data platform and the trusted data space described in this embodiment; Figure 2 It is a flowchart of the data circulation method based on the industry data platform and the trusted data space described in this embodiment; Figure 3 It is a flowchart for obtaining the first access token; Figure 4 It is a flowchart for setting access permissions; Figure 5 It is a flowchart for processing data products with insufficient remaining valid duration; Figure 6 It is a structural block diagram of the data circulation system based on the industry data platform and the trusted data space described in this embodiment; Figure 7 It is a structural block diagram of the electronic device described in this embodiment. Detailed implementation manners

[0023] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the described embodiments of the present invention without creative efforts fall within the scope of protection of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein shall have the ordinary meanings understood by those of ordinary skill in the art to which the present invention belongs.

[0024] The "first", "second" and similar terms used in the specification and claims of this application do not denote any order, quantity or importance, but are only used to distinguish different components. Similarly, unless the context clearly indicates otherwise, the singular forms of "a", "an" or "the" and similar terms do not denote a quantity limitation, but mean that there is at least one. The terms such as "including" or "comprising" are intended to indicate that the elements or objects appearing before "including" or "comprising" cover the features, wholes, steps, operations, elements and / or components listed after "including" or "comprising", and do not exclude the existence or addition of one or more other features, wholes, steps, operations, elements, components and / or their combinations. The terms such as "upper", "lower", "left" and "right" are only used to represent relative positional relationships, and when the absolute position of the object being described changes, the relative positional relationship may also change accordingly.

[0025] China has the most complete range of industrial categories in the world. For data circulation within the industry, in each category, the leading enterprises in the industry basically have a relatively comprehensive and complete data chain covering the upstream and downstream of the industry supply chain for data circulation within the industry, but they cannot cover all enterprise users in the same industry. For cross-industry data circulation, it mainly relies on data releases in the data market. After having a purchase intention, off-site transactions are carried out. However, this non-technical means of trading has two major problems: First, data suppliers are concerned about the security of data, especially worried that the data will be resold after flowing out. Second, this concern of data suppliers will make it difficult for data demanders to obtain a wide range of data sources and conduct comprehensive and accurate data analysis and use. Based on this, this embodiment aims to provide a new data circulation method to simultaneously meet the data circulation needs within and between industries.

[0026] As shown in the following figures, the data circulation method based on the industry data platform and the trusted data space described in this embodiment will be specifically introduced.

[0027] To facilitate subsequent data circulation within the industry and cross-industry circulation, as shown in Figure 1 the following settings are made: Step S102: Build a connector for the industry corresponding to the industry data platform and a connector for any other industry corresponding to the data platform of that other industry within the trusted data space.

[0028] Step S104: Directly communicate and connect industry users with the industry data platform and any other industry users with the corresponding data platform of that other industry based on the API interface.

[0029] Step S106: Directly communicate and connect the industry data platform with the industry connector and any other industry data platform with the corresponding other industry connector based on the API interface.

[0030] At this time, based on steps S104 to S106, the corresponding software architecture can be built and communication connections can be established. In this embodiment, the trusted data space and the industry connector used are both executed according to the standard architecture of the International Data Space Association (IDSA). In specific implementation, the data provider transmits the data of the data owner to the trusted data space through the industry connector (IDS Connector). It allows others to use this data while retaining control over the users, usage methods, usage times, usage purposes, and usage prices. The data consumer processes the data according to the entrustment of the data user. The industry connector (IDS Connector) is a dedicated software component that provides each participant with the function of attaching data usage rules to the data space, executing the usage rules, and seamlessly tracking the data source. In specific implementation, the industry connector is the gateway for data and services and also provides a trusted operating environment for each application (App) and software.

[0031] Based on this, combined with Figure 2 As shown, taking the industry data platform as the first end, the circulation method described in this embodiment is explained as follows: Step S202: The industry data platform obtains the trusted credentials of the industry users. After passing the verification of the trusted credentials, a first access token is generated to confirm the successful login of the users to the industry data platform.

[0032] As a specific implementation method, combined with Figure 3 As shown, the verification of the trusted credentials and the acquisition of the first access token are specifically carried out in the following manner: Step S2022: Obtain the trusted credentials input by the industry users.

[0033] In specific implementation, considering the industry users, they enter the corresponding username and password on the industry data platform.

[0034] Step S2024: Call the auth interface or the login interface to send the trusted credentials to the authentication center within the platform.

[0035] Step S2026: After passing the verification of the trusted credentials by the authentication center, generate a first access token and return it to the industry users.

[0036] In specific implementation, the format of the first access token is: Key: user01_SSO, and it is also cached by the industry data platform through Redis.

[0037] In this embodiment, the first access token is a JWT token, and the security of the login can be guaranteed by an asymmetric encryption algorithm. Specifically, the first access token includes dual claims to facilitate the subsequent generation of cross-domain tokens, namely, identity claims and service claims. The identity claims include: the address, role, and validity period of the users in this industry. Among them, if the user in this industry only makes data access or publishing requests, their role is a data consumer or a data provider; if the user in this industry makes both data access and publishing requests at the same time, their role is a data consumer and a data provider. The service claims include: the address (client_id) of the connector in this industry and the authorization scope (scope: sso_api).

[0038] Step S204: In response to the first access token, generate a cross-domain token corresponding to the user in this industry, and transmit it to the connector in this industry for cross-domain verification based on the token transfer mechanism. After the verification passes, generate a second access token to confirm the successful login of the user to the trusted data space.

[0039] In this embodiment, the cross-domain token and the second access token are also JWT tokens. To ensure data security, the following triple verification is performed on the cross-domain token: signature verification, timeliness verification, and authorization verification. Among them, signature verification is used to verify the validity of the signature of the cross-domain token through a preset public key; timeliness verification is used to verify the validity period of the cross-domain token and whether it has been revoked based on the blacklist mechanism; authorization verification is used to verify whether the client_id matches the authorization scope.

[0040] In specific implementation, after the verification passes, the connector in this industry will create a local session (SessionID: xxxxx) and return the encrypted second access token (validity period: 300s). At this time, the connector in this industry realizes the integrated login to the trusted data space through the standard process of the trusted data space; that is, it realizes the trusted identity authentication of the trusted data space for the user in this industry.

[0041] Step S206: Obtain the industry data products uploaded by the user in this industry and publish them. When it continues to be determined that the product attribute allows cross-industry circulation, upload them to the trusted data space for publishing; and / or based on the request of the user in this industry, allow them to access the industry data products in the industry data platform and the other industry data products in the trusted data space.

[0042] Among them, the other industry data products are published by other industry users who log in through the corresponding other industry data platforms. During the publishing process, they are registered in the form of a product catalog.

[0043] For specific illustration, the following specific implementation process is introduced: When circulating in the industry, the first industry user 1 realizes the circulation of the industry data product to the first industry user 2 through the first industry data platform; the second industry user 3 realizes the circulation of the second industry data product (i.e., another industry data product) to the second industry user 4 through the second industry data platform. When cross-industry data circulates, the first industry user 1 realizes the circulation of the industry data product to the second industry user 3 through the first industry data platform, the first industry connector, the trusted data space, the second industry connector, and the second industry data platform.

[0044] As a preferred implementation manner, considering that the data provider only wants to provide some corresponding industry data products to some data consumers to improve data revenue or promote healthy competition within the industry, combined with Figure 4 as shown, the following steps are further included: Step S2062: Publish the industry data products that are not allowed to circulate across industries on the industry data platform, and allow some industry users to access based on the first access right.

[0045] Step S2064: Publish the industry data products that are allowed to circulate across industries in the trusted data space, and allow industry users and other industry users who have passed the access authentication through the trusted data space to access based on the second access right.

[0046] Specifically, the industry data platform and the trusted data space are authorized by the data provider to open permissions for data consumers with access requirements.

[0047] At this time, based on steps S2062 to S2064, access rights can be added to some data products according to actual needs. And the power to open the corresponding access rights is granted to the industry data platform and the trusted data space. At this time, data consumers with consumption needs only need to apply for access to the industry data platform or the trusted data space and can access after passing the verification, which is more efficient and convenient.

[0048] As a specific implementation manner, the product attributes are set as shown in Table 1 below. The specific product attributes also include name, type, time-delay date, and opening method.

[0049] Table 1 Example of product attributes of industry data products or other industry data products

[0050] Based on the above time-delay date attribute, this embodiment combines Figure 5 as shown, and the following steps are further included: Step S208: When it is determined that the remaining valid duration of the industry data products in the industry data platform and the trusted data space is less than a preset duration threshold, a processing inquiry is sent to the industry users who released the industry data products.

[0051] Step S210: Based on the first feedback, when the remaining valid duration is 0, the corresponding industry data products are deleted in the industry data platform and the trusted data space; based on the second feedback, when the remaining valid duration is 0, the remaining valid duration of the corresponding industry data products is extended by a preset duration in the industry data platform and the trusted data space.

[0052] At this time, when the expiration date of the industry data products is approaching the specified delay date, the industry data platform and the trusted data space can automatically delete or extend the delay date of the corresponding data products according to the requirements of the data provider, avoiding the long-term storage of invalid data or the need to repeat data publishing multiple times.

[0053] In summary, the data circulation method described in this embodiment realizes the in-industry and inter-industry circulation of data through the collaborative cooperation of the industry data platform and the trusted data circulation space. From a technical perspective, on the premise of ensuring the data privacy and security of the data provider, it matches the supply and demand sides to conduct data circulation and use according to the agreed rules, and realizes the self-circulation of in-industry data, achieving the diversity of industry data in the extensive data market. From an application perspective, using the trusted data circulation space increases the monetization channels of data holders. In addition to supplying data to the upstream and downstream users within the industry, data can also be provided to more users across industries and regions, and can generate multiple revenues from one upload. For data consumers, they can obtain a wider range of data sources to assist in data decision-making. At the same time, it can break the industry data barriers and provide a feasible path for the supervision of industry data circulation.

[0054] The above program can run in a processor or can also be stored in a memory (or referred to as a computer-readable storage medium). Computer-readable media include permanent and non-permanent, removable and non-removable media and can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media do not include transitory computer-readable media such as modulated data signals and carrier waves.

[0055] These computer programs can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate computer-implemented processing. Thus, the instructions executed on the computer or other programmable device provide for implementing the steps for the functions specified in Figure 1 one process or multiple processes and / or Figure 1 boxes or multiple boxes. The corresponding different steps can be implemented by different modules.

[0056] This embodiment also provides a data circulation system based on an industry data platform and a trusted data space. As shown in combination with Figure 6 the following, it includes the following functional modules: A first login module, which is used to obtain the trusted credentials of users in this industry from the industry data platform, and generate a first access token after passing the verification of the trusted credentials to confirm the successful login of the user to the industry data platform; wherein, the first access token includes an identity claim and a service claim; the identity claim includes: the address and validity period of the user in this industry; the service claim includes: the address and authorization scope of the industry connector.

[0057] The second login module is used to generate a cross-domain token corresponding to the users in this industry in response to the first access token, and transmit it to the connector in this industry through the token transmission mechanism for cross-domain verification. After the verification is passed, a second access token is generated to confirm the successful login of the user to the trusted data space. Among them, the cross-domain verification includes signature verification, validity verification, and authorization verification. The signature verification is used to verify the signature validity of the cross-domain token, the validity verification is used to verify the validity period of the cross-domain token and whether it has been revoked, and the authorization verification is used to verify whether the authorization scope matches.

[0058] The data publishing and access module is used to obtain and publish the industry data products uploaded by the users in this industry. When it continues to determine that the product attribute allows cross-industry circulation, it uploads them to the trusted data space for publishing; and / or based on the request of the users in this industry, it allows them to access the industry data products in the industry data platform of this industry and the other industry data products in the trusted data space. Among them, the other industry data products are published by other industry users who log in through the corresponding other industry data platforms.

[0059] Since the system is built based on the method, what has been described above will not be elaborated here. For example, the data publishing and access module includes: The first permission unit is used to publish the industry data products that do not allow cross-industry circulation on the industry data platform of this industry, and allow some users in this industry to access them based on the first access permission.

[0060] The second permission unit is used to publish the industry data products that allow cross-industry circulation in the trusted data space, and allow the users in this industry and other industry users who have passed the access authentication through the trusted data space to access them based on the second access permission.

[0061] Among them, the industry data platform and the trusted data space are authorized by the data provider to open permissions for data consumers with access needs.

[0062] For another example, the first login module includes: The acquisition unit is used to acquire the trusted credentials input by the users in this industry.

[0063] The authentication unit is used to call the auth interface or the login interface to send the trusted credentials to the authentication center in the platform.

[0064] The generation unit is used to generate a first access token and return it to the users in this industry after the verification of the trusted credentials passes.

[0065] Combined with Figure 7As shown, this embodiment also provides an electronic device, including at least one processor, the processor is coupled with a memory, a computer program is stored in the memory, and the computer program is configured to execute the above method when being run by the processor.

[0066] Meanwhile, a computer-readable storage medium is also provided, which is characterized in that a computer program is stored thereon, and the computer program is used to be executed by a processor to implement the above method.

[0067] Since the system, the electronic device and the computer-readable storage medium are all used to implement the above method, they have the advantages of realizing one-piece fast login and realizing various data publishing and access in practical applications, so as to meet the universality and efficiency of data circulation within the industry and between industries at the same time.

[0068] Although the present invention has been disclosed above with preferred embodiments, it is not intended to limit the present invention. Those with ordinary knowledge in the technical field to which the present invention pertains can make various changes and modifications without departing from the spirit and scope of the present invention. Therefore, the protection scope of the present invention shall be subject to what is defined by the claims.

Claims

1. A data circulation method based on an industry data platform and a trusted data space, characterized in that, It includes the following steps: The industry data platform obtains the trusted credentials of industry users. After passing the verification of the trusted credentials, it generates a first access token to confirm the successful login of industry users to the industry data platform; Among them, the first access token includes an identity claim and a service claim; the identity claim includes: the address and validity period of industry users; the service claim includes: the address and authorization scope of the industry connector; In response to the first access token, a cross-domain token corresponding to the industry user is generated, and the cross-domain token is transmitted to the industry connector based on the token passing mechanism for cross-domain verification. After passing the verification, a second access token is generated to confirm the successful login of industry users to the trusted data space; Among them, the cross-domain verification includes signature verification, timeliness verification, and authorization verification; signature verification is used to verify the signature validity of the cross-domain token, timeliness verification is used to verify the validity period of the cross-domain token and whether it has been revoked, and authorization verification is used to verify whether the authorization scope matches; Obtain and publish the industry data products uploaded by industry users. When it is continued to determine that the product attribute allows cross-industry circulation, upload the industry data products to the trusted data space for publication; and / or based on the request of industry users, allow them to access the industry data products in the industry data platform and other industry data products in the trusted data space; Among them, the other industry data products are published by other industry users who log in through the corresponding other industry data platforms.

2. The data circulation method based on the industry data platform and the trusted data space according to claim 1, characterized in that The obtaining and publishing of the industry data products uploaded by industry users. When it is continued to determine that the product attribute allows cross-industry circulation, uploading the industry data products to the trusted data space for publication includes: Publish the industry data products that do not allow cross-industry circulation on the industry data platform, and allow some industry users to access them based on the first access right; Publish the industry data products that allow cross-industry circulation in the trusted data space, and allow industry users and other industry users who have passed the access authentication through the trusted data space to access them based on the second access right; Among them, the industry data platform and the trusted data space are authorized by the data provider to open permissions to data consumers with access requirements.

3. The data circulation method based on an industry data platform and a trusted data space according to claim 1, wherein The obtaining of the trusted credentials of industry users by the industry data platform. After passing the verification of the trusted credentials, generating a first access token to confirm the successful login of industry users to the industry data platform includes: Obtain the trusted credentials input by industry users; Call the auth interface or login interface to send the trusted credentials to the authentication center in the industry data platform; Generate a first access token after passing the verification of the trusted credentials and return it to the industry user.

4. The data circulation method based on the industry data platform and the trusted data space according to claim 1, wherein It includes: Build an industry connector corresponding to the industry data platform and other industry connectors corresponding to any other industry data platform in the trusted data space; Directly communicate and connect industry users with the industry data platform based on the API interface, and directly communicate and connect any other industry users with the corresponding other industry data platforms; Directly communicate and connect the industry data platform with the industry connector based on the API interface, and directly communicate and connect any other industry data platforms with the corresponding other industry connectors.

5. The data circulation method based on the industry data platform and the trusted data space according to claim 1, characterized in that Including: When it is determined that the remaining valid duration of the industry data products in the industry data platform and the trusted data space is less than a preset duration threshold, a processing inquiry is sent to the industry users who released the industry data products; Based on the first feedback, when the remaining valid duration is 0, the corresponding industry data products are deleted in the industry data platform and the trusted data space; based on the second feedback, when the remaining valid duration is 0, the valid duration of the corresponding industry data products is extended by a preset duration in the industry data platform and the trusted data space.

6. A data circulation system based on an industry data platform and a trusted data space, characterized in that, Including: A first login module, which is used for the industry data platform to obtain the trusted credentials of industry users, and generate a first access token after passing the verification of the trusted credentials to confirm the successful login of industry users to the industry data platform; Among them, the first access token includes an identity statement and a service statement; the identity statement includes: the address and validity period of industry users; the service statement includes: the address and authorization scope of the industry connector; A second login module, which is used to generate a cross-domain token corresponding to industry users in response to the first access token, and transmit the cross-domain token to the industry connector through the token passing mechanism for cross-domain verification. After passing the verification, a second access token is generated to confirm the successful login of industry users to the trusted data space; Among them, the cross-domain verification includes signature verification, timeliness verification and authorization verification; signature verification is used to verify the signature validity of the cross-domain token, timeliness verification is used to verify the validity period of the cross-domain token and whether it is revoked, and authorization verification is used to verify whether the authorization scope matches; A data release and access module, which is used to obtain and release the industry data products uploaded by industry users, and continue to determine that when the product attribute allows cross-industry circulation, upload the industry data products to the trusted data space for release; and / or allow industry users to access the industry data products in the industry data platform and other industry data products in the trusted data space based on the requests of industry users; Among them, the other industry data products are released by other industry users who log in through the corresponding other industry data platforms.

7. The data circulation system based on the industry data platform and the trusted data space according to claim 6, characterized in that, The data release and access module includes: A first permission unit, which is used to release the industry data products that do not allow cross-industry circulation on the industry data platform, and allow some industry users to access based on the first access permission; A second permission unit, which is used to release the industry data products that allow cross-industry circulation in the trusted data space, and allow industry users and other industry users who pass the access authentication through the trusted data space to access based on the second access permission; Among them, the industry data platform and the trusted data space are authorized by the data provider to open permissions to data consumers with access needs.

8. The data circulation system based on the industry data platform and the trusted data space according to claim 6, wherein, The first login module includes: An acquisition unit, which is used to acquire the trusted credentials input by industry users; An authentication unit, which is used to call the auth interface or the login interface to send the trusted credentials to the authentication center in the industry data platform; A generation unit, which is used to generate a first access token and return it to the industry user after passing the verification of the trusted credentials.

9. An electronic device, characterized in that, Comprising at least one processor, the processor being coupled to a memory, and a computer program being stored in the memory, the computer program being configured to execute the method according to any one of claims 1-5 when run by the processor.

10. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and the computer program is used to be executed by a processor to implement the method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Smart password key authentication based cross-platform heterogeneous system login method

    CN107508837A

  • Login access method and device for service system, storage medium and processor

    CN108881232A

  • Identity identification and authentication system supporting multiple terminals and multiple certificates across network areas

    CN113067797A

  • Cross-domain single sign-on method and device

    CN114553480A

  • Method and system for rapid authentication among multiple services of coal mine

    CN119155129A