A data circulation method based on industry data platform and trusted data space

Through the method based on the industry data platform and trusted data space, integrated login and cross-domain token verification are used to solve the limitations of data circulation, and the data is safe, extensive and efficient circulation is achieved, and the data value is enhanced.

CN120321054BActive Publication Date: 2025-08-22NANJING FUTURE NETWORK CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510812962.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-08-22
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

The existing data circulation in the industry and cross-industry data circulation have obvious limitations, and the data cannot be safe, extensive and efficient circulation, resulting in the inability to maximize the value of the data.

Method used

Through an integrated login method based on the industry data platform and trusted data space, cross-domain tokens are used to perform cross-domain verification, and two publishing methods are defined based on data product attributes, one is interacting within the industry, and the other is interacting through trusted data space to ensure data security and privacy.

Benefits of technology

It realizes data circulation in the industry, breaks down industry barriers, provides it to more users, improves the income of data providers, enhances data sources of data consumers, and ensures data security and privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321054B_ABST
    Figure CN120321054B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of data circulation technology, and discloses a data circulation method based on an industry data platform and a trusted data space. It includes: the industry data platform obtains the trusted credentials of the industry users, generates a first access token after the trusted credentials are verified to confirm that the user has successfully logged in to the industry data platform; generates a corresponding cross-domain token, and passes it to the industry connector for cross-domain verification based on the token transfer mechanism, and generates a second access token after the verification is passed to confirm that the user has successfully logged in to the trusted data space; obtains the industry data products uploaded by the industry users and registers them in the form of a product catalog, and when it continues to judge that the product attributes are allowed to circulate across industries, uploads them to the trusted data space; and / or allows the industry users to access the industry data products in the industry data platform and other industry data products in the trusted data space based on their requests. The present invention can simultaneously realize data circulation within and across industries.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data circulation technology, and in particular to a data circulation method based on an industry data platform and a trusted data space. Background Art

[0002] Data circulation in various industrial sectors refers to the process by which data, as a new production factor, flows and is allocated within the market. Maximizing the value of data circulation is crucial, particularly with the development of the data economy. Data circulation is generally categorized into intra-industry and inter-industry data circulation.

[0003] The aforementioned intra-industry data flow is primarily achieved through the construction of industry-wide supply chains. Although my country boasts the most comprehensive range of industrial sectors in the world, only leading enterprises at the forefront of each sector's development can build a complete data chain covering the entire upstream and downstream of the industry supply chain. Therefore, the flow of industry data within each sector is significantly limited, meaning that data flow across the entire industry is not yet fully realized.

[0004] The aforementioned cross-industry data flow primarily occurs through over-the-counter transactions. Data suppliers publish data on the data market, and after a data demander expresses interest in purchasing, they conduct over-the-counter transactions. However, this non-technical transaction process cannot guarantee data security. Consequently, data suppliers worry about data security, especially if data is resold after it leaks. This, in turn, makes it difficult for data demanders to access a wide range of data sources and conduct comprehensive and accurate data analysis and utilization.

[0005] It can be seen from this that in the existing technology, whether it is data circulation within an industry or data circulation across industries, there are obvious circulation limitations, which make it impossible to achieve safe, extensive, efficient and effective circulation of data, and thus it is impossible to maximize the value of data and promote the effective development of various industries. Summary of the Invention

[0006] The purpose of the present invention is to provide a data circulation method based on an industry data platform and a trusted data space, so as to solve the technical problem that in the existing data circulation within an industry or across industries, there are obvious circulation limitations and it is impossible to achieve safe, extensive and efficient effective circulation of data.

[0007] To achieve the above objectives, the present invention proposes the following technical solutions:

[0008] In the first aspect, a data circulation method based on an industry data platform and a trusted data space is provided, comprising the following steps:

[0009] The industry data platform obtains the trusted credentials of the industry user, and after verifying the trusted credentials, generates a first access token to confirm that the industry user has successfully logged in to the industry data platform;

[0010] The first access token includes an identity statement and a service statement; the identity statement includes: the address and validity period of the user in this industry; the service statement includes: the address and authorization scope of the connector in this industry;

[0011] In response to the first access token, a cross-domain token corresponding to the industry user is generated, and the cross-domain token is passed to the industry connector based on the token passing mechanism for cross-domain verification. After the verification is passed, a second access token is generated to confirm that the industry user has successfully logged into the trusted data space;

[0012] Among them, the cross-domain verification includes signature verification, time verification and authorization verification; signature verification is used to verify the validity of the signature of the cross-domain token, time verification is used to verify the validity period of the cross-domain token and whether it has been revoked, and authorization verification is used to verify whether the authorization scope matches;

[0013] Obtain and publish data products uploaded by users in the same industry. If the product attributes are determined to allow cross-bank circulation, upload the data products in the same industry to the trusted data space for publication; and / or allow users in the same industry to access data products in the same industry within the data platform and other industry data products in the trusted data space upon their request.

[0014] Among them, the other industry data products are released by other industry users who log in through the corresponding other industry data platforms.

[0015] Furthermore, the acquisition and release of data products of the industry uploaded by users of the industry, and when further determining that the product attributes allow cross-bank circulation, uploading the data products of the industry to the trusted data space for release includes:

[0016] Publish industry data products that are not allowed to circulate across banks on the industry data platform, and allow access to some users in the industry based on first-level access rights;

[0017] Publish data products of the industry that are allowed to circulate across banks in the trusted data space, and allow users of the industry and other industries who have passed the trusted data space access authentication to access them based on the second access permission;

[0018] Among them, the industry's data platform and trusted data space are authorized by the data provider to open permissions to data consumers with access needs.

[0019] Furthermore, the industry data platform obtains the trusted credentials of the industry user, and after verifying the trusted credentials, generates a first access token to confirm that the industry user has successfully logged into the industry data platform, including:

[0020] Obtain trusted credentials entered by users in this industry;

[0021] Call the auth interface or login interface to send the trusted credentials to the authentication center in the industry data platform;

[0022] After the trusted credential is verified, a first access token is generated and returned to the industry user.

[0023] Further, including:

[0024] Build industry connectors corresponding to the industry data platform within the trusted data space, as well as other industry connectors corresponding to any other industry data platform;

[0025] Based on the API interface, users in this industry can be directly connected to the data platform of this industry, and users in any other industry can be directly connected to the corresponding data platform of other industries;

[0026] Based on the API interface, the industry data platform is directly connected to the industry connector, and any other industry data platform is directly connected to the corresponding other industry connector.

[0027] Further, including:

[0028] When it is determined that the remaining validity period of the data product of the industry in the industry data platform and the trusted data space is less than the preset time threshold, a processing query is sent to the user of the industry that published the data product of the industry;

[0029] Based on the first feedback, when the remaining valid time is 0, the corresponding data products of this industry will be deleted on the data platform of this industry and the trusted data space; based on the second feedback, when the remaining valid time is 0, the valid time of the corresponding data products of this industry will be extended according to the preset time on the data platform of this industry and the trusted data space.

[0030] Secondly, this technical solution provides a data circulation system based on an industry data platform and a trusted data space, including:

[0031] The first login module is used for the industry data platform to obtain the trusted credentials of the industry user, and after the trusted credentials are verified, generate a first access token to confirm that the industry user has successfully logged in to the industry data platform;

[0032] Among them, the first access token includes an identity statement and a service statement; the identity statement includes: the address and validity period of the user in this industry; the service statement includes: the address and authorization scope of the connector in this industry;

[0033] The second login module is configured to generate a cross-domain token corresponding to the industry user in response to the first access token, and pass the cross-domain token to the industry connector for cross-domain verification based on a token passing mechanism. After the verification is passed, a second access token is generated to confirm that the industry user has successfully logged into the trusted data space;

[0034] Among them, the cross-domain verification includes signature verification, time verification and authorization verification; signature verification is used to verify the validity of the signature of the cross-domain token, time verification is used to verify the validity period of the cross-domain token and whether it has been revoked, and authorization verification is used to verify whether the authorization scope matches;

[0035] The data publishing and access module is used to obtain and publish industry data products uploaded by industry users. If the product attributes are determined to allow cross-bank circulation, the module uploads the industry data products to the trusted data space for publication; and / or allows industry users to access industry data products within the industry data platform and other industry data products within the trusted data space upon their request.

[0036] Among them, the other industry data products are released by other industry users who log in through the corresponding other industry data platforms.

[0037] Furthermore, the data publishing and access module includes:

[0038] The first permission unit is used to publish industry data products that are not allowed to be circulated across industries on the industry data platform, and to allow some users in the industry to access them based on the first access permission;

[0039] The second permission unit is used to publish data products of the industry that are allowed to circulate across banks in the trusted data space, and to allow users of the industry and other industries that have passed the trusted data space access authentication to access them based on the second access permission;

[0040] Among them, the industry's data platform and trusted data space are authorized by the data provider to open permissions to data consumers with access needs.

[0041] Furthermore, the first login module includes:

[0042] An acquisition unit, used to obtain trusted credentials input by users in this industry;

[0043] An authentication unit, configured to call an auth interface or a login interface to send the trusted credentials to an authentication center within the industry data platform;

[0044] The generating unit is used to generate a first access token after verifying the trusted credential and return it to the user in the industry.

[0045] In a third aspect, the present technical solution provides an electronic device comprising at least one processor, wherein the processor is coupled to a memory, wherein a computer program is stored in the memory, and the computer program is configured to perform the method described when executed by the processor.

[0046] In a fourth aspect, the present technical solution provides a computer-readable storage medium on which a computer program is stored, and the computer program is used to be executed by a processor to implement the described method.

[0047] Beneficial effects:

[0048] It can be seen from the above technical solutions that the technical solution of the present invention provides a data circulation method based on an industry data platform and a trusted data space to simultaneously solve the technical defects of existing intra-industry data circulation and cross-industry data circulation.

[0049] This technical solution deploys a connector for each industry within the trusted data space, using the connector as a gateway to facilitate data flow between the industry data platform and the trusted data space. Specifically, an integrated login method is implemented. During the login process, users in the same industry directly request a login to the industry data platform. Upon successful login, a cross-domain token is automatically generated in response to the first access token, and login to the trusted data space is directly triggered based on the token passing mechanism. This improves the efficiency and convenience of login and subsequent data interaction. Specifically, to ensure login security and data security, the cross-domain token undergoes triple verification, including signature verification, time validity verification, and authorization verification. Secondly, during the data release and access process, considering data privacy and the need for disclosure to users in other industries, two data release methods are defined based on product attributes: one that disallows cross-industry data flow and one that allows cross-industry data flow. The former only interacts within the industry data platform; the latter requires interaction through the trusted data space. These product attributes are fully customized by the data provider, enabling users to independently configure the flow of their own data.

[0050] In summary, this application, while ensuring the data privacy and security of data suppliers, matches supply and demand parties to circulate and use data in accordance with agreed rules. This not only achieves the self-circulation of data circulation within the industry, but also realizes the diversity of industry data in a wide range of data markets. It not only breaks down the circulation barriers that limit data circulation within the industry to only certain companies, but also allows it to be provided to more users across industries and regions. While increasing the profits of data suppliers, it also enables data consumers to obtain a wider range of data sources to assist in data decision-making.

[0051] It should be appreciated that all combinations of the foregoing concepts, as well as additional concepts described in greater detail below, to the extent such concepts are not mutually inconsistent, can be considered to be part of the inventive subject matter of this disclosure.

[0052] The foregoing and other aspects, embodiments, and features of the present invention will be more fully understood from the following description in conjunction with the accompanying drawings. Other additional aspects of the present invention, such as features and / or beneficial effects of the exemplary embodiments, will become apparent from the following description or through practice of specific embodiments according to the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0053] The accompanying drawings are not intended to be drawn to scale. In the drawings, each identical or nearly identical component shown in various figures may be represented by the same reference numeral. For the sake of clarity, not every component is labeled in every figure. Embodiments of various aspects of the present invention will now be described by way of example and with reference to the accompanying drawings, in which:

[0054] Figure 1 A flowchart for the software architecture of the data circulation method based on the industry data platform and trusted data space described in this embodiment;

[0055] Figure 2 This is a flow chart of the data circulation method based on the industry data platform and trusted data space described in this embodiment;

[0056] Figure 3 A flowchart for obtaining a first access token;

[0057] Figure 4 Flowchart for setting access rights;

[0058] Figure 5 Flowchart for processing data products with insufficient remaining validity period;

[0059] Figure 6 This is a structural block diagram of the data circulation system based on the industry data platform and trusted data space described in this embodiment;

[0060] Figure 7 This is a structural block diagram of the electronic device described in this embodiment. DETAILED DESCRIPTION

[0061] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings of the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the described embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein should be the common meanings understood by people with ordinary skills in the field to which the present invention belongs.

[0062] The terms "first", "second" and similar words used in the specification and claims of this application do not indicate any order, quantity or importance, but are only used to distinguish different components. Similarly, unless the context clearly indicates otherwise, the singular forms of "a", "an" or "the" and similar words do not indicate a quantitative limitation, but rather indicate the presence of at least one. Words such as "include" or "comprise" mean that the elements or objects preceding "include" or "comprises" cover the features, wholes, steps, operations, elements and / or components listed after "include" or "comprises", and do not exclude the existence or addition of one or more other features, wholes, steps, operations, elements, components and / or their collections. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0063] my country has the most complete industrial categories in the world. For data circulation within the industry, in each category, the leading companies in the industry basically have a relatively comprehensive data chain covering the upstream and downstream of the industry supply chain to carry out data circulation within the industry, but they cannot cover all corporate users in the industry. For cross-industry data circulation, it mainly depends on the release of data on the data market, and after there is a purchase intention, over-the-counter transactions are carried out. However, this non-technical transaction method has two major problems: first, the data supplier is worried about the security of the data, especially worried that the data will be sold again after it is leaked; second, this concern of the data supplier will make it difficult for the data demander to obtain a wide range of data sources, and it is difficult to conduct full and accurate data analysis and use. Based on this, this embodiment aims to provide a new data circulation method to meet the data circulation needs within and between industries at the same time.

[0064] The following is a detailed introduction to the data circulation method based on the industry data platform and trusted data space described in this embodiment with reference to the accompanying drawings.

[0065] In order to facilitate the subsequent circulation of data within the industry and across industries, combined with Figure 1 As shown, make the following settings:

[0066] Step S102: Build the industry connector corresponding to the industry data platform and other industry connectors corresponding to any other industry data platform in the trusted data space.

[0067] Step S104: Based on the API interface, the users of this industry are directly connected to the data platform of this industry, and any other industry users are directly connected to the corresponding other industry data platform.

[0068] Step S106: Based on the API interface, the industry data platform is directly connected to the industry connector, and any other industry data platform is directly connected to the corresponding other industry connector.

[0069] At this point, the corresponding software architecture and communication connection can be established based on steps S104 to S106. In this embodiment, the trusted data space and industry connectors used are implemented in accordance with the International Data Space Association (IDSA) standard architecture. In specific implementation, the data provider (Data Provider) transfers the data owner's (Data Owner) data into the trusted data space through the industry connector (IDS Connector). This allows others to use this data while retaining control over who uses it, how it is used, when it is used, for what purpose, and at what price. The data consumer (Data Consumer) processes the data as authorized by the data user (Data User). The industry connector (IDS Connector) is a dedicated software component that allows participants to attach data usage rules to the data space, enforce these rules, and seamlessly track the source of data. In specific implementation, the industry connector serves as a gateway between data and services, and also provides a trusted operating environment for various applications (Apps) and software.

[0070] Based on this, combined Figure 2 As shown, taking the industry data platform as the first end, the circulation method described in this embodiment is explained as follows:

[0071] Step S202: The industry data platform obtains the trusted credentials of the industry user, and generates a first access token after verifying the trusted credentials to confirm that the user has successfully logged into the industry data platform.

[0072] As a specific implementation method, Figure 3 As shown, the trusted credentials are verified and the first access token is obtained in the following manner:

[0073] Step S2022: Obtain the trusted credentials input by the user in this industry.

[0074] During the specific implementation, users in this industry are taken into consideration and they enter the corresponding user name and password on the data platform of this industry.

[0075] Step S2024: call the auth interface or login interface to send the trusted certificate to the authentication center within the platform.

[0076] Step S2026: After the trusted credential is verified by the authentication center, a first access token is generated and returned to the industry user.

[0077] In specific implementation, the format of the first access token is: Key: user01_SSO, which is also cached by the industry data platform through Redis.

[0078] In this embodiment, the first access token is a JWT token, which can ensure the security of login through an asymmetric encryption algorithm. Specifically, the first access token includes a double statement to facilitate the subsequent generation of cross-domain tokens, namely, an identity statement and a service statement. The identity statement includes: the address, role and validity period of the user in this industry. Among them, if the user in this industry only makes data access or publish requests, its role is a data consumer or a data provider; if the user in this industry makes data access and publish requests at the same time, its role is a data consumer and a data provider. The service statement includes: the address (client_id) and the authorization scope (scope: sso_api) of the connector in this industry.

[0079] Step S204: In response to the first access token, a cross-domain token corresponding to the industry user is generated, and based on the token transfer mechanism, it is passed to the industry connector for cross-domain verification, and after the verification is passed, a second access token is generated to confirm that the user has successfully logged into the trusted data space.

[0080] In this embodiment, the cross-domain token and the second access token are also JWT tokens. To ensure data security, the cross-domain token undergoes the following three verifications: signature verification, time validity verification, and authorization verification. Signature verification verifies the validity of the cross-domain token's signature using a preset public key; time validity verification verifies the validity period and revocation of the cross-domain token based on a blacklist mechanism; and authorization verification verifies whether the client_id matches the authorized scope.

[0081] In practice, after verification, the industry connector will create a local session (SessionID: xxxxx) and return an encrypted secondary access token (valid for 300 seconds). At this point, the industry connector uses the standard trusted data space process to achieve integrated login to the trusted data space, thus enabling trusted identity authentication for industry users.

[0082] Step S206: Obtain and publish the data products of the industry uploaded by users of the industry. When it is determined that the product attributes allow cross-bank circulation, upload it to the trusted data space for publication; and / or allow users of the industry to access the data products of the industry in the industry data platform and other industry data products in the trusted data space based on their requests.

[0083] The aforementioned other industry data products are published by users of other industries who log in through the corresponding other industry data platforms. During the publishing process, they are registered in the form of product catalogs.

[0084] For detailed explanation, the following implementation process is introduced: During intra-industry data circulation, user 1 in the first industry circulates its data product to user 2 in the first industry through the first industry data platform; user 3 in the second industry circulates its data product in the second industry (i.e., a data product from another industry) to user 4 in the second industry through the second industry data platform. During cross-industry data circulation, user 1 in the first industry circulates its data product to user 3 in the second industry through the first industry data platform, the first industry connector, the trusted data space, the second industry connector, and the second industry data platform.

[0085] As a preferred implementation method, considering that the data provider only wants to provide some corresponding industry data products to some data consumers in order to increase data revenue or promote healthy competition within the industry, combined with Figure 4 As shown, the following steps are also included:

[0086] Step S2062: Publish the data products of the industry that are not allowed to circulate across banks on the data platform of the industry, and allow some users of the industry to access them based on the first access permission.

[0087] Step S2064: Publish the data products of the industry that are allowed to circulate across banks in the trusted data space, and allow users of the industry and other industries that have passed the trusted data space access authentication to access them based on the second access permission.

[0088] Specifically, the industry's data platform and trusted data space are authorized by data providers to open permissions to data consumers with access needs.

[0089] At this point, based on steps S2062 to S2064, access rights can be added to some data products as needed. The corresponding access rights are then granted to the industry data platform and trusted data space. Data consumers with consumption needs only need to apply for access to the industry data platform or trusted data space and have it verified, making it more efficient and convenient.

[0090] As a specific implementation method, the product attribute-related settings are shown in the example of Table 1 below. The specific product attributes also include name, type, delay date, and opening method.

[0091] Table 1 Examples of product attributes of data products in this industry or other industries

[0092]

[0093] Based on the above-mentioned delay date attribute, this embodiment combines Figure 5 As shown, the following steps are also included:

[0094] Step S208: When it is determined that the remaining effective duration of the industry data product in the industry data platform and the trusted data space is less than the preset duration threshold, a processing inquiry is sent to the industry user who published the industry data product.

[0095] Step S210: Based on the first feedback, when the remaining valid time is 0, the corresponding data product of the industry is deleted in the data platform of the industry and the trusted data space; based on the second feedback, when the remaining valid time is 0, the remaining valid time of the corresponding data product of the industry is extended according to the preset time on the data platform of the industry and the trusted data space.

[0096] At this time, when the expiration date of the industry's data products approaches the specified delay date, the industry's data platform and trusted data space can automatically delete or extend the delay date of the corresponding data products according to the needs of the data provider, avoiding the long-term storage of invalid data or the need for repeated data release.

[0097] From the above, it can be seen that the data circulation method described in this embodiment realizes the circulation of data within and between industries at the same time through the coordinated cooperation of the industry data platform and the trusted data circulation space. From a technical perspective, under the premise of ensuring the data privacy and security of the data supplier, the supply and demand are matched to circulate and use data in accordance with the agreed rules, and the self-circulation of data circulation within the industry is realized, realizing the diversity of industry data in a wide range of data markets. From an application perspective, the use of a trusted data circulation space increases the monetization channels for data holders. In addition to supplying data to upstream and downstream users within the industry, it can also be provided to more users across industries and regions, with multiple benefits from uploading once. For data consumers, they can obtain a wider range of data sources to assist in data decision-making. At the same time, it can break down industry data barriers, and provide a feasible path for the supervision of industry data circulation.

[0098] The above program can be executed in a processor or stored in a memory (also known as a computer-readable storage medium). Computer-readable media include both permanent and non-permanent, removable and non-removable media, and can be implemented using any method or technology to store information. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include temporary computer-readable media such as modulated data signals and carrier waves.

[0099] These computer programs can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps of the functions specified in one or more blocks can be implemented by different modules corresponding to different steps.

[0100] This embodiment also provides a data circulation system based on the industry data platform and the trusted data space. Figure 6 As shown, it includes the following functional modules:

[0101] The first login module is used for the industry data platform to obtain the trusted credentials of the users in this industry, and to generate the first access token after the trusted credentials are verified to confirm that the user has successfully logged in to the industry data platform; wherein, the first access token includes an identity statement and a service statement; the identity statement includes: the address and validity period of the users in this industry; the service statement includes: the address and authorization scope of the connector in this industry.

[0102] The second login module is used to respond to the first access token to generate a cross-domain token corresponding to the user of this industry, and pass it to the connector of this industry for cross-domain verification based on the token passing mechanism, and generate a second access token after the verification is passed to confirm that the user has successfully logged into the trusted data space; wherein, the cross-domain verification includes signature verification, time verification and authorization verification; signature verification is used to verify the validity of the signature of the cross-domain token, time verification is used to verify the validity period of the cross-domain token and whether it has been revoked, and authorization verification is used to verify whether the authorization scope matches.

[0103] The data publishing and access module is used to obtain and publish data products of the industry uploaded by users of the industry. When it is further determined that the product attributes allow cross-bank circulation, it is uploaded to the trusted data space for publication; and / or based on the request of users of the industry, it is allowed to access data products of the industry within the industry data platform and other industry data products within the trusted data space; wherein, the said other industry data products are published by users of other industries who log in through the corresponding other industry data platforms.

[0104] Since the system is built based on the method, the above has been explained and will not be repeated here. For example, the data publishing and access module includes:

[0105] The first permission unit is used to publish data products of the industry that are not allowed to circulate across banks on the data platform of the industry, and to allow some users of the industry to access them based on the first access permission.

[0106] The second permission unit is used to publish data products of the industry that are allowed to circulate across banks in the trusted data space, and to allow users of the industry and other industries who have passed the trusted data space access authentication to access them based on the second access permission.

[0107] Among them, the industry's data platform and trusted data space are authorized by the data provider to open permissions to data consumers with access needs.

[0108] For another example, the first login module includes:

[0109] The acquisition unit is used to obtain the trusted credentials input by users in this industry.

[0110] The authentication unit is used to call the auth interface or the login interface to send the trusted certificate to the authentication center in the platform.

[0111] The generating unit is used to generate a first access token after verifying the trusted credential and return it to the user in the industry.

[0112] Combine Figure 7As shown, this embodiment further provides an electronic device, including at least one processor, wherein the processor is coupled to a memory, wherein a computer program is stored in the memory, and the computer program is configured to execute the method when executed by the processor.

[0113] At the same time, a computer-readable storage medium is also provided, characterized in that a computer program is stored thereon, and the computer program is used to be executed by a processor to implement the method described.

[0114] Since the system, electronic device and computer-readable storage medium are all used to implement the method, it has the advantages of realizing integrated quick login, multiple data publishing and access in actual application, thereby satisfying the extensiveness and efficiency of data circulation within the industry and between industries at the same time.

[0115] While the present invention has been disclosed above with reference to preferred embodiments, this is not intended to limit the present invention. Persons skilled in the art will readily appreciate that various modifications and variations can be made without departing from the spirit and scope of the present invention. Therefore, the scope of protection of the present invention shall be determined by the claims.

Claims

1. A data circulation method based on an industry data platform and a trusted data space, characterized in that: Build the software architecture and set up communication connections as follows: First, build the industry connector corresponding to the industry data platform and other industry connectors corresponding to any other industry data platform in the trusted data space; second, directly connect the industry users with the industry data platform based on the API interface, and directly connect any other industry users with the corresponding other industry data platform; then, directly connect the industry data platform with the industry connector based on the API interface, and directly connect any other industry data platform with the corresponding other industry connector; And includes the following steps: The industry data platform obtains the trusted credentials of the industry user, and after verifying the trusted credentials, generates a first access token to confirm that the industry user has successfully logged in to the industry data platform; The first access token includes an identity statement and a service statement; the identity statement includes: the address and validity period of the user in this industry; the service statement includes: the address and authorization scope of the connector in this industry; In response to the first access token, a cross-domain token corresponding to the industry user is generated, and the cross-domain token is passed to the industry connector based on the token passing mechanism for cross-domain verification. After the verification is passed, a second access token is generated to confirm that the industry user has successfully logged into the trusted data space; Among them, the cross-domain verification includes signature verification, time verification and authorization verification; signature verification is used to verify the validity of the signature of the cross-domain token, time verification is used to verify the validity period of the cross-domain token and whether it has been revoked, and authorization verification is used to verify whether the authorization scope matches; Obtain and publish data products uploaded by users in the same industry. If the product attributes are determined to allow cross-bank circulation, upload the data products in the same industry to the trusted data space for publication; and / or allow users in the same industry to access data products in the same industry within the data platform and other industry data products in the trusted data space upon their request. The process of obtaining and publishing data products uploaded by users of the industry and, when further determining that the product attributes allow inter-bank circulation, uploading the data products of the industry to the trusted data space for publication includes: first, publishing the data products of the industry that do not allow inter-bank circulation on the industry data platform, and allowing access to some users of the industry based on the first access permission; second, publishing the data products of the industry that allow inter-bank circulation on the trusted data space, and allowing access to users of the industry and other industry users who have passed the trusted data space access authentication based on the second access permission; Among them, the industry data platform and trusted data space are authorized by the data provider to open permissions to data consumers with access needs; the other industry data products are published by other industry users who log in through the corresponding other industry data platforms.

2. The data circulation method based on the industry data platform and trusted data space according to claim 1 is characterized in that: The industry data platform obtains the trusted credentials of the industry user, and generates a first access token after verifying the trusted credentials to confirm that the industry user has successfully logged into the industry data platform, including: Obtain trusted credentials entered by users in this industry; Call the auth interface or login interface to send the trusted credentials to the authentication center in the industry data platform; After the trusted credential is verified, a first access token is generated and returned to the industry user.

3. The data circulation method based on the industry data platform and trusted data space according to claim 1 is characterized in that: include: When it is determined that the remaining validity period of the data product of the industry in the industry data platform and the trusted data space is less than the preset time threshold, a processing query is sent to the user of the industry that published the data product of the industry; Based on the first feedback, when the remaining valid time is 0, the corresponding data products of this industry will be deleted on the data platform of this industry and the trusted data space; based on the second feedback, when the remaining valid time is 0, the valid time of the corresponding data products of this industry will be extended according to the preset time on the data platform of this industry and the trusted data space.

4. A data circulation system based on an industry data platform and a trusted data space, characterized in that: The method for implementing claim 1 comprises: The first login module is used for the industry data platform to obtain the trusted credentials of the industry user, and after the trusted credentials are verified, generate a first access token to confirm that the industry user has successfully logged in to the industry data platform; The first access token includes an identity statement and a service statement; the identity statement includes: the address and validity period of the user in this industry; the service statement includes: the address and authorization scope of the connector in this industry; The second login module is configured to generate a cross-domain token corresponding to the industry user in response to the first access token, and pass the cross-domain token to the industry connector for cross-domain verification based on a token passing mechanism. After the verification is passed, a second access token is generated to confirm that the industry user has successfully logged into the trusted data space; Among them, the cross-domain verification includes signature verification, time verification and authorization verification; signature verification is used to verify the validity of the signature of the cross-domain token, time verification is used to verify the validity period of the cross-domain token and whether it has been revoked, and authorization verification is used to verify whether the authorization scope matches; The data publishing and access module is used to obtain and publish industry data products uploaded by industry users. If the product attributes are determined to allow cross-bank circulation, the module uploads the industry data products to the trusted data space for publication; and / or allows industry users to access industry data products within the industry data platform and other industry data products within the trusted data space upon their request. Among them, the other industry data products are released by other industry users who log in through the corresponding other industry data platforms.

5. The data circulation system based on the industry data platform and trusted data space according to claim 4 is characterized in that: The first login module includes: An acquisition unit, used to obtain trusted credentials input by users in this industry; An authentication unit, configured to call an auth interface or a login interface to send the trusted credentials to an authentication center within the industry data platform; The generating unit is used to generate a first access token after verifying the trusted credential and return it to the user in the industry.

6. An electronic device, characterized in that: The method comprises at least one processor, wherein the processor is coupled to a memory, wherein a computer program is stored in the memory, and wherein the computer program is configured to execute the method according to any one of claims 1 to 3 when executed by the processor.

7. A computer-readable storage medium, characterized in that A computer program is stored thereon, and the computer program is used to be executed by a processor to implement the method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Cross-domain single sign-on method and device

    CN114553480A

  • Application user single sign-on

    WO2019036012A1