A Method and System for Trusted Circulation of Data Assets Based on Dynamic Evaluation using Smart Contracts
By dynamically assessing the security risks of data assets through smart contracts, dynamic security level adjustment and node reputation management for blockchain data asset circulation management are realized. This solves the problems of static security classification and loose permissions in existing technologies, and improves the security and flexibility of data circulation.
Patent Information
- Application Number
- CN202510898023.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-01
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-07-01
AI Technical Summary
Existing blockchain data asset circulation management methods suffer from static and crude data asset security classification mechanisms that fail to dynamically match actual risks, coarse circulation control granularity, mismatch between permission settings and asset characteristics, lack of dynamic node reputation management and real-time anomaly response mechanisms, and insufficient security protection capabilities.
By using a smart contract-based dynamic evaluation method, the basic attributes of data assets are extracted, a comprehensive security risk score is calculated, security levels are dynamically classified, circulation permissions are set, and node reputation scores are adjusted in real time to achieve on-chain dynamic verification and anomaly response.
It achieves a precise correspondence between data asset protection strategies and actual risk status, ensuring that data assets strictly adhere to customized security strategies when circulating between different nodes, preventing overreach of permissions and data abuse, and enhancing the system's trustworthy protection capabilities.
Smart Images

Figure CN120415902B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data asset circulation security technology, specifically to a method and system for trusted data asset circulation based on dynamic evaluation using smart contracts. Background Technology
[0002] With the rapid expansion of data assets and the widespread adoption of distributed applications, data ownership, circulation, and use have gradually become crucial issues in the digital economy era. Blockchain technology, with its decentralized, immutable, and traceable characteristics, provides new infrastructure support for data asset management. In recent years, blockchain-based platforms for data ownership confirmation, data trading, and data sharing have emerged, initially realizing the value transformation and cross-entity circulation of data assets. The introduction of smart contract technology allows data asset circulation rules to be executed automatically on the blockchain, improving the transparency and controllability of the data exchange process. Simultaneously, with increasing demands for privacy protection and data compliance, the security, compliance, and dynamic controllability of data assets during circulation have gradually become core concerns for the industry.
[0003] However, existing blockchain-based data asset circulation technologies still have many shortcomings, making it difficult to meet the increasingly complex needs of data security circulation. Firstly, in terms of data asset security classification management, most existing technologies adopt static, pre-defined classifications, lacking real-time risk assessment and classification adjustment mechanisms based on asset characteristics and dynamic environmental changes. This leads to a mismatch between data protection measures and actual risks, posing potential security vulnerabilities. Secondly, existing smart contracts generally rely on single, fixed rules for circulation control, failing to set fine-grained circulation permissions and dynamically adjust them according to the diverse security attributes of different data assets, easily leading to issues such as unauthorized access and abuse. Furthermore, during data circulation, existing technologies lack a robust dynamic node reputation management system, failing to effectively assess and restrict the operational behavior of low-reputation nodes on sensitive assets, increasing the risk of data leakage and unauthorized use. Simultaneously, real-time monitoring and anomaly response mechanisms during circulation are also weak. Existing solutions mostly rely on post-event auditing, lacking real-time detection and automatic classification response capabilities based on on-chain dynamic verification, resulting in an inability to quickly handle abnormal behavior and compromising the overall security level of data assets. In summary, existing technologies cannot achieve a secure blockchain data asset circulation system that considers data asset security levels, node dynamic reputation, and real-time anomaly detection closed-loop control, and thus cannot achieve the intelligent, controlled, and reliable data asset circulation effect proposed in this invention. Summary of the Invention
[0004] In view of the above-mentioned problems, the present invention is proposed.
[0005] Therefore, the technical problem solved by this invention is that existing blockchain data asset circulation management methods have static and coarse data asset security classification mechanisms that cannot dynamically match actual risks, coarse circulation control granularity, mismatch between permission settings and asset characteristics, lack of dynamic node reputation management and real-time anomaly response mechanisms, and insufficient security protection capabilities. The invention also addresses how to achieve data asset circulation based on dynamic security assessment, smart contract controlled circulation, and on-chain anomaly closed-loop prevention and control in an open blockchain environment.
[0006] To address the aforementioned technical problems, this invention provides the following technical solution: a method for the trusted circulation of data assets based on dynamic evaluation using smart contracts, comprising extracting basic attributes of multiple received data assets, including data type, sensitivity identifier, and source node authentication level information. Based on a security risk assessment model, a comprehensive security risk score is calculated, and security levels are dynamically assigned according to the score.
[0007] Match or generate corresponding smart contract templates based on the security level of data assets, set circulation permissions and complete on-chain binding of asset fingerprints and smart contract addresses, perform identity authentication and security attribute initialization on blockchain nodes, record node behavior and dynamically adjust node reputation scores based on historical operations, and map node access permissions in real time.
[0008] Upon receiving a circulation request, the system performs on-chain dynamic security verification, calculates a compliance score by considering the requesting node's qualifications, the current state of the asset, and the matching of circulation intent, decides on circulation permission, calls the smart contract interface to execute the circulation actions step by step, generates on-chain circulation trajectory records, and monitors the circulation status in real time.
[0009] As a preferred embodiment of the data asset trusted circulation method based on smart contract dynamic evaluation described in this invention, the basic attribute extraction of the data asset includes extracting data type, sensitivity identifier, source node ID, and historical circulation risk records. The sensitivity identifier is determined based on data content analysis to determine whether it involves privacy information, and the historical circulation risk records are obtained by querying the on-chain circulation trajectory chain to obtain abnormal circulation events.
[0010] As a preferred embodiment of the data asset trust circulation method based on smart contract dynamic evaluation described in this invention, the calculation of the comprehensive security risk score and the dynamic division of security levels according to the score include calculating the comprehensive security risk score through a multi-factor weighted fusion method, and dynamically dividing it into four security levels: public data, restricted data, sensitive data, and confidential data according to the score range. Different security levels correspond to different smart contract templates.
[0011] As a preferred embodiment of the data asset trusted circulation method based on smart contract dynamic evaluation described in this invention, the step of matching or generating a corresponding smart contract template according to the data asset security level includes setting a minimum reputation threshold for circulation request nodes, limiting the node whitelist access mechanism, limiting the scope of circulation use and setting an access time window. At the same time, the smart contract has embedded rules that if a node violates the usage restrictions or exceeds the access time window during access, the system automatically triggers circulation freezing logic and writes the violation event into the on-chain audit chain.
[0012] As a preferred embodiment of the data asset trusted circulation method based on smart contract dynamic evaluation described in this invention, the node identity authentication and security attribute initialization include the qualification authentication of the node's affiliated institution, the real-name authentication of the operator, and the trusted module authentication of the device. The initial node reputation value is assigned according to the authentication level. The system dynamically adjusts the node reputation value based on the compliance rate, the frequency of violations, and the records of abnormal circulation during the node's circulation behavior. When the node reputation value falls below the threshold set by the system, the access permissions are automatically tightened, allowing access only to low-security-level data, and the status change is simultaneously broadcast to all nodes in the network.
[0013] As a preferred embodiment of the data asset trusted circulation method based on smart contract dynamic evaluation described in this invention, the on-chain dynamic security verification includes verification of the request node's reputation value, verification of the target data asset's status, and verification of the matching between circulation intent and asset usage strategy. The system calculates a comprehensive compliance score based on the verification results and determines circulation permission based on a preset permission threshold. Simultaneously, after circulation approval, the system calls the smart contract interface according to the action plan to execute transfer, authorization, and archiving operations, generating an on-chain circulation trajectory record.
[0014] As a preferred embodiment of the data asset trusted circulation method based on smart contract dynamic evaluation described in this invention, the real-time detection of circulation includes out-of-scope access, illegal use, abnormal frequency access, and asset fingerprint tampering. The system dynamically adjusts the risk level according to the type and frequency of anomalies and executes a graded response strategy for different risk levels. Low-risk events trigger warnings and observation, medium-risk events trigger permission freezing and auditing, and high-risk events trigger asset recovery or destruction. At the same time, all abnormal events and processing procedures are written into the on-chain abnormal event chain to form an audit chain.
[0015] Another objective of this invention is to provide a trusted data asset circulation system based on smart contract dynamic evaluation. This system can solve the problem of static and fixed data security classification in current blockchain data asset circulation management, which cannot dynamically adjust security strategies according to real-time asset risks, by introducing a dynamic security risk assessment and classification mechanism.
[0016] As a preferred embodiment of the data asset trusted circulation system based on smart contract dynamic evaluation described in this invention, it includes a data asset security evaluation module, a smart contract configuration module, and a circulation execution monitoring module.
[0017] The data asset security assessment module is used to extract basic attributes of multiple received data assets, including data type, sensitivity identifier, and source node authentication level information. Based on the security risk assessment model, a comprehensive security risk score is calculated, and security levels are dynamically assigned according to the score.
[0018] The smart contract configuration is used to match or generate corresponding smart contract templates according to the security level of data assets, set circulation permissions and complete the on-chain binding of asset fingerprints and smart contract addresses, perform identity authentication and security attribute initialization of blockchain nodes, record node behavior and dynamically adjust node reputation scores based on historical operations, and map node access permissions in real time.
[0019] The circulation execution monitoring module is used to receive circulation requests, perform on-chain dynamic security verification, calculate compliance scores by comprehensively considering the qualifications of the requesting node, the current status of the asset, and the matching of circulation intentions, decide on circulation permission, call the smart contract interface to execute circulation actions step by step and generate on-chain circulation trajectory records, and monitor circulation status in real time.
[0020] A computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement a method for the trusted circulation of data assets based on dynamic evaluation of smart contracts.
[0021] A computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of a method for the trusted circulation of data assets based on dynamic evaluation of smart contracts.
[0022] The beneficial effects of this invention are as follows: The data asset trusted circulation method based on smart contract dynamic evaluation provided by this invention improves the security and flexibility of the circulation process by dynamically assessing the security risks of data assets and classifying security levels in real time, achieving a precise correspondence between data asset protection strategies and actual risk states. By setting fine-grained circulation permissions based on asset level, node reputation, and usage restrictions in smart contracts, it ensures that data assets strictly adhere to customized security strategies when circulating between different nodes, preventing permission overreach and data abuse. By scoring the historical behavior of blockchain nodes in real time and dynamically adjusting the range of assets they can access, it effectively limits the access of low-reputation nodes to highly sensitive data, enhancing the overall trusted protection capabilities of the system. This invention achieves better results in terms of security, flexibility, and trustworthiness. Attached Figure Description
[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0024] Figure 1 The first embodiment of the present invention provides an overall flowchart of a method for the trusted circulation of data assets based on dynamic evaluation of smart contracts. Detailed Implementation
[0025] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.
[0026] Example 1, referring to Figure 1 As an embodiment of the present invention, a method for trusted circulation of data assets based on dynamic evaluation of smart contracts is provided, comprising:
[0027] S1: Extract basic attributes of the received data assets, including data type, sensitivity identifier, and source node authentication level information. Based on the security risk assessment model, calculate a comprehensive security risk score and dynamically classify security levels according to the score.
[0028] Furthermore, the extraction of basic attributes of data assets includes extracting data type, sensitivity identifier, source node ID, and historical circulation risk records. Among them, the sensitivity identifier is based on data content analysis to determine whether it involves privacy information, and the historical circulation risk records are obtained by querying the on-chain circulation trajectory chain to obtain abnormal circulation events.
[0029] The system receives a set of data assets to be managed. For each data asset Extract data types, sensitivity identifiers, source node IDs, and historical circulation risk records.
[0030] It should be noted that the calculation of the comprehensive security risk score and the dynamic classification of security levels based on the score include calculating the comprehensive security risk score through a multi-factor weighted fusion method, and dynamically classifying it into four security levels based on the score range: public data, restricted data, sensitive data, and confidential data. Different security levels correspond to different smart contract templates.
[0031] The system calculates the comprehensive security risk score for each data asset based on a preset security risk assessment function and various attribute values. , represented as:
[0032]
[0033] in, To calculate the overall security risk score for data assets, For data asset sensitivity coefficient, This represents the credibility coefficient of the data asset source. The data asset integrity protection requirement coefficient. This is a factor representing the expected circulation frequency of data assets. For data assets, the strength factor of regulatory compliance is applied. This is the adjustment coefficient for the sensitivity term. This is the adjustment coefficient for the credibility term. This is the adjustment factor for the integrity term. This is the circulation frequency adjustment coefficient. This is a compliance adjustment coefficient.
[0034] Based on the comprehensive security risk score Based on preset score ranges, each data asset is assigned to a different security level, including Level 1 public assets, Level 2 restricted assets, Level 3 sensitive assets, and Level 4 confidential assets.
[0035] S2: Match or generate corresponding smart contract templates based on the security level of data assets, set circulation permissions and complete on-chain binding of asset fingerprints and smart contract addresses, perform identity authentication and security attribute initialization for blockchain nodes, record node behavior and dynamically adjust node reputation scores based on historical operations, and map node access permissions in real time.
[0036] Furthermore, based on the security level of data assets, matching or generating corresponding smart contract templates includes setting a minimum reputation threshold for nodes requesting circulation, limiting the access mechanism of node whitelists, limiting the scope of circulation uses, and setting access time windows. At the same time, the smart contract has embedded rules that if a node violates the usage restrictions or exceeds the access time window, the system will automatically trigger the circulation freeze logic and write the violation event into the on-chain audit chain.
[0037] Based on the security level labels of data assets, the system sets up basic contract templates for each security level. These templates clearly define the types of executable circulation actions (such as transfer, authorization, archiving, and destruction), the minimum reputation level requirements for participating nodes, usage restrictions, and access time window parameters. Preferably, for Level 3 sensitive assets, the system enforces a node whitelist mechanism, allowing only nodes confirmed through a specific authentication process to access the assets, while limiting their circulation to designated purposes and prohibiting secondary forwarding or processing.
[0038] The smart contract embeds automatic anomaly detection rules. When a node violates the scope of use or exceeds the access time window during actual access, the system immediately triggers the circulation freeze logic, interrupting the current node's access to the assets. At the same time, the violation is written into the on-chain audit chain in the form of an immutable event record to support subsequent responsibility determination and audit tracing.
[0039] It should be noted that node identity authentication and security attribute initialization include the qualification authentication of the node's affiliated institution, the real-name authentication of the operator, and the authentication of the trusted module of the device. The initial node reputation value is assigned based on the authentication level. The system dynamically adjusts the node reputation value based on the compliance rate, the frequency of violations, and the records of abnormal circulation during node circulation. When the node reputation value falls below the threshold set by the system, the access permissions are automatically tightened, allowing access only to low-security-level data, and the status change is broadcast synchronously to all nodes in the network.
[0040] It should also be noted that the node identity authentication and security attribute initialization module mainly includes three aspects: qualification authentication of the node's affiliated organization, real-name authentication of the node operator, and trusted module authentication of the device used by the node. Specifically, when a node connects to the system, it needs to provide organizational qualification certificates, operator identity verification materials, and device-level trusted module authentication. The system assigns an initial reputation value to the node based on the above three authentication levels. The initial reputation value is represented by a standardized score with a value of [0,1], where the higher the authentication level, the higher the initial reputation value.
[0041] During the subsequent actual circulation activities of a node, the system dynamically tracks the node's operational behavior, including indicators such as successful compliant circulation records, compliant circulation records, and high-frequency abnormal behavior. Based on preset rules, the system dynamically adjusts the reputation value, as shown below:
[0042]
[0043] in, For the node at time Reputation value at that time For a moment The node's reputation value, For a moment The node adds a number of compliant operations. For a moment The number of new violations by the node For compliance integral gain coefficient, To amplify the penalty for violations, The violation rate affects the weighting. This is the sensitivity adjustment coefficient for the violation rate. For a moment Cumulative violation rate of nodes The weighting is based on the sinusoidal fluctuation of activity. This is the periodic adjustment coefficient for access frequency. For the node at time The frequency of access behavior metrics.
[0044] When a node's reputation value drops below the system's preset security threshold, the system automatically tightens the node's access permissions, allowing it to access low-security-level data assets (Level 1 or Level 2), and synchronizes the node's reputation level change status to all nodes through an on-chain broadcast mechanism to ensure that the network-wide security policy is executed synchronously.
[0045] Preferably, the data asset circulation request and on-chain dynamic security verification process includes the following steps:
[0046] First, the requesting node must submit a standardized circulation request data packet, including the requesting node ID, the target data asset ID, the request operation type, the target user node ID, and a description of the circulation purpose. Upon receiving the circulation request, the system performs the following verification processes sequentially:
[0047] (1) Based on the current reputation value of the requesting node The rating is compared and verified against the minimum reputation threshold set for the target asset level.
[0048] (2) Verify whether the target data asset is currently in a non-circulating state such as frozen, archived, or pending destruction.
[0049] (3) Compare whether the requested purpose description complies with the preset purpose scope and circulation restrictions of the data asset smart contract. Furthermore, based on the above verification results, the system comprehensively assigns weights to calculate the security and compliance score of the circulation request. , represented as:
[0050]
[0051] in, The overall security and compliance score for circulation requests The normalized value of the current reputation score of the requesting node. Verify the score for the current state of the target asset. The score is based on the degree of fit for the intended use. Adjust parameters for node reputation. Amplify parameters for asset status score. To amplify the application matching parameter, The parameter representing the negative credit regulation strength of nodes. The parameters for the historical violation impact index. The number of historical violations for the requesting node is accumulated.
[0052] If the score is higher than the circulation approval threshold set by the system If the threshold is met, the request is approved and proceeds to the execution phase. If the threshold is not met, the request is rejected and an abnormal audit event is recorded.
[0053] S3: After receiving a circulation request, perform on-chain dynamic security verification, calculate a compliance score by combining the requesting node's qualifications, the current state of the asset, and the matching of circulation intentions, decide on circulation permission, call the smart contract interface to execute the circulation action step by step and generate an on-chain circulation trajectory record, and monitor the circulation status in real time.
[0054] Furthermore, on-chain dynamic security verification includes verification of the requesting node's reputation value, verification of the target data asset's status, and verification of the matching between the circulation intent and the asset usage strategy. The system calculates a comprehensive compliance score based on the verification results and determines circulation permission based on a preset permission threshold. After circulation approval, the system calls the smart contract interface according to the action plan to execute transfer, authorization, and archiving operations, generating an on-chain circulation trajectory record.
[0055] After a data asset circulation request is approved, a controlled circulation execution mechanism based on compliance decisions is adopted. Specifically, the system dynamically generates a circulation action plan based on the action type and action parameters defined in the smart contract.
[0056] Preferably, for asset control transfer operations, the system synchronously changes the asset holder identifier on the blockchain and updates the access control table. For authorization-only operations, the system records information such as the scope of authorization, usage restrictions, and access time limits in the asset control table without changing the asset ownership relationship. For archiving or destruction operations, the system marks the asset as "archived" or "pending destruction" and prohibits any subsequent access operations. Simultaneously, after each circulation action is executed, the system generates a circulation event log through a standardized on-chain recording mechanism. The log includes the initiating node ID, target node ID, asset hash fingerprint, circulation action type, execution timestamp, and operation confirmation node signature. All events are written to the blockchain circulation trajectory chain in an immutable form, forming a complete asset lifecycle trajectory.
[0057] It should be noted that the real-time detection of circulation includes access beyond the scope, illegal use, abnormal frequency of access, and asset fingerprint tampering. The system dynamically adjusts the risk level based on the type and frequency of the anomaly, and implements a graded response strategy for different risk levels. Low-risk events trigger warnings and observation, medium-risk events trigger permission freezing and auditing, and high-risk events trigger asset recovery or destruction. At the same time, all abnormal events and their handling processes are written into the on-chain abnormal event chain to form an audit chain.
[0058] Furthermore, after the asset circulation is completed, the system initiates a real-time on-chain status monitoring program to continuously monitor access behavior, analyze usage behavior, and review permission changes for the circulated data assets.
[0059] It should be noted that real-time status monitoring includes consistency detection between node access behavior and authorized purpose, comparison of access frequency with the set access frequency limit, and data asset fingerprint integrity verification to prevent asset content tampering.
[0060] Preferably, the system dynamically adjusts the abnormal event recognition threshold based on the set abnormality detection sensitivity parameter to match different security protection requirements at different security levels, as expressed as:
[0061]
[0062] in, For a moment The sensitivity of anomaly detection For a moment Sensitivity, For a moment The frequency of abnormal events occurring per unit time For a moment Quantitative indicators of sudden abnormal magnitude For a moment The cumulative risk value of the node group The gain coefficient is adjusted for abnormal frequencies. For sudden abnormal fluctuation response coefficients, As a sudden fluctuation cycle modulation factor, The parameter representing the impact of risk accumulation on sensitivity suppression.
[0063] When the system detects abnormal access behavior, such as access beyond the scope, unauthorized use, or data tampering, it will handle the abnormal behavior in a tiered manner based on its severity. The standard handling levels are: minor abnormality (warning and logging), moderate abnormality (freezing access permissions and triggering an audit process), and severe abnormality (revoking asset permissions and performing forced destruction). After each abnormal event is handled, the system will generate an abnormal audit record containing details of the abnormal behavior, the handling measures, and asset-related information, and write it to the on-chain abnormal event log chain, forming a two-way link with the original asset circulation trajectory chain.
[0064] Example 2 is the second embodiment of the present invention, which differs from the previous embodiment in that:
[0065] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0066] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-including system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0067] More specific examples (a non-exhaustive list) of computer-readable media include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which programs can be printed, because programs can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0068] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0069] Example 3 is the third embodiment of the present invention. This embodiment provides a system for a trusted circulation method of data assets based on dynamic evaluation of smart contracts, including a data asset security evaluation module, a smart contract configuration, and a circulation execution monitoring module.
[0070] The data asset security assessment module extracts basic attributes from multiple received data assets, including data type, sensitivity identifiers, and source node authentication level information. Based on a security risk assessment model, it calculates a comprehensive security risk score and dynamically classifies security levels according to the score. The smart contract configuration module matches or generates corresponding smart contract templates based on the data asset security level, sets circulation permissions, completes on-chain binding of asset fingerprints and smart contract addresses, performs identity authentication and security attribute initialization for blockchain nodes, records node behavior, dynamically adjusts node reputation scores based on historical operations, and maps node access permissions in real time. The circulation execution monitoring module, upon receiving a circulation request, performs on-chain dynamic security verification, calculates a compliance score based on the requesting node's qualifications, the current asset status, and the matching of circulation intent, decides on circulation permission, calls the smart contract interface to execute circulation actions step by step, generates on-chain circulation trajectory records, and monitors circulation status in real time.
[0071] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A method for the trusted circulation of data assets based on dynamic evaluation using smart contracts, characterized in that, include: The basic attributes of the received data assets are extracted, including data type, sensitivity identifier, and source node authentication level information. Based on the security risk assessment model, a comprehensive security risk score is calculated, and security levels are dynamically classified according to the score. Calculate the overall security risk score for each data asset by combining the attribute values; The attribute values include data asset sensitivity coefficient, data asset source credibility coefficient, data asset integrity protection requirement coefficient, data asset expected circulation frequency factor, and data asset applicable legal compliance strength factor. Match or generate corresponding smart contract templates based on the security level of data assets, set circulation permissions and complete on-chain binding of asset fingerprints and smart contract addresses, perform identity authentication and security attribute initialization on blockchain nodes, record node behavior and dynamically adjust node reputation scores based on historical operations, and map node access permissions in real time. Upon receiving a circulation request, perform on-chain dynamic security verification, calculate a compliance score by comprehensively considering the requesting node's qualifications, the current asset status, and the matching of circulation intentions, decide on circulation permission, call the smart contract interface to execute the circulation action step by step and generate an on-chain circulation trajectory record, and monitor the circulation status in real time. The process of matching or generating corresponding smart contract templates based on the security level of data assets includes setting a minimum reputation threshold for circulation request nodes, limiting the access mechanism of node whitelists, limiting the scope of circulation uses, and setting access time windows. At the same time, the smart contract has embedded rules that if a node violates the usage restrictions or exceeds the access time window during access, the system will automatically trigger the circulation freeze logic and write the violation event into the on-chain audit chain. The node identity authentication and security attribute initialization include the qualification authentication of the node's affiliated institution, the real-name authentication of the operator, and the authentication of the trusted module of the device. The initial node reputation value is assigned according to the authentication level. The system dynamically adjusts the node reputation value based on the compliance rate, the frequency of violations, and the records of abnormal circulation during the node's circulation behavior. When the node reputation value falls below the threshold set by the system, the access permissions are automatically tightened, allowing access only to low-security-level data, and the status change is broadcast synchronously to all nodes in the network. The on-chain dynamic security verification includes verification of the request node's reputation value, verification of the target data asset status, and verification of the matching between the circulation intention and the asset use strategy. The system calculates a comprehensive compliance score based on the verification results and determines the circulation permission based on the preset permission threshold. After the circulation is approved, the system calls the smart contract interface according to the action plan to execute the transfer, authorization, and archiving operations, and generates an on-chain circulation trajectory record. The real-time detection of circulation includes access beyond the scope, illegal use, abnormal frequency of access, and asset fingerprint tampering. The system dynamically adjusts the risk level based on the type and frequency of the anomaly, and implements a graded response strategy for different risk levels. Low-risk events trigger warnings and observation, medium-risk events trigger permission freezing and auditing, and high-risk events trigger asset recovery or destruction. At the same time, all abnormal events and their handling processes are written into the on-chain abnormal event chain to form an audit chain.
2. The method for trusted circulation of data assets based on dynamic evaluation of smart contracts as described in claim 1, characterized in that: The extraction of basic attributes of the data assets includes extracting data type, sensitivity identifier, source node ID, and historical circulation risk records. The sensitivity identifier is based on data content analysis to determine whether it involves privacy information, and the historical circulation risk records are obtained by querying the on-chain circulation trajectory chain to obtain abnormal circulation events.
3. The method for trusted circulation of data assets based on dynamic evaluation of smart contracts as described in claim 2, characterized in that: The calculation of the comprehensive security risk score and the dynamic classification of security levels based on the score include calculating the comprehensive security risk score through a multi-factor weighted fusion method, and dynamically classifying it into four security levels based on the score range: public data, restricted data, sensitive data, and confidential data. Different security levels correspond to different smart contract templates.
4. A system employing the data asset trusted circulation method based on smart contract dynamic evaluation as described in any one of claims 1 to 3, characterized in that: This includes a data asset security assessment module, a smart contract configuration module, and a circulation execution monitoring module. The data asset security assessment module is used to extract basic attributes of multiple received data assets, including data type, sensitivity identifier, and source node authentication level information. Based on the security risk assessment model, a comprehensive security risk score is calculated, and security levels are dynamically classified according to the score. The smart contract configuration is used to match or generate corresponding smart contract templates according to the security level of data assets, set circulation permissions and complete the on-chain binding of asset fingerprints and smart contract addresses, perform identity authentication and security attribute initialization of blockchain nodes, record node behavior and dynamically adjust node reputation scores according to historical operations, and map node access permissions in real time. The circulation execution monitoring module is used to receive circulation requests, perform on-chain dynamic security verification, calculate compliance scores by comprehensively considering the qualifications of the requesting node, the current status of the asset, and the matching of circulation intentions, decide on circulation permission, call the smart contract interface to execute circulation actions step by step and generate on-chain circulation trajectory records, and monitor circulation status in real time.
5. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the data asset trusted circulation method based on dynamic evaluation of smart contracts as described in any one of claims 1 to 3.
6. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the data asset trusted circulation method based on dynamic evaluation of smart contracts as described in any one of claims 1 to 3.
Citation Information
Patent Citations
Block chain-based data asset circulation method and device, and medium
CN116228229A
Block chain security verification protection method, block chain node, medium and product
CN119341847A
Data asset life cycle management method and system based on block chain
CN119963187A