Data security system and method based on multi-party collaboration

Through the multi-party collaborative data security system with data slicing and isolated storage, the data security and availability issues in multi-party data flow scenarios are solved, and the ultimate data security and efficient management are achieved.

CN120597302BActive Publication Date: 2025-10-10SHANGHAI QINGBIAO INFORMATION TECH SERVICE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511094214.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-10-10
Estimated Expiration
2045-08-06

AI Technical Summary

Technical Problem

Existing data processing systems find it difficult to provide sufficient security while ensuring availability in multi-party data flow scenarios. Traditional access control and data encryption solutions cannot effectively prevent data from being misused or leaked at non-compliant process nodes.

Method used

Data slicing and isolated storage are used to separate data ownership and usage rights. The node manager arbitrates the process order, and heterogeneous authentication key mechanisms and transient view generation devices are used to reorganize data to ensure that data access and processing follow the preset permission order.

Benefits of technology

It achieves ultimate data security and efficient management, eliminates the risk of data misuse due to process disorders or illegal operations, and ensures system-level data security without the need for complex encryption algorithms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120597302B_ABST
    Figure CN120597302B_ABST
Patent Text Reader

Abstract

The application provides a kind of data security system and method based on multi-party cooperation, belong to information security technical field, the data security system based on multi-party cooperation of the application, including data slicing device, encrypted storage, node manager, key coordinator and instantaneous view generation device, the method is through data slicing and isolated storage, heterogeneous authentication key mechanism separates the readability of data and use mode in technology and is in the control of different participants, so that the disclosure of any single component or repository does not expose meaningful complete information, node manager as process arbitration core, the accessibility of data and the promotion state of business process, data evolution state are strongly bound, fundamentally eliminate the data misuse risk caused by process disorder or illegal operation, without setting complex encryption algorithm, the security processing of data can be realized from system level, improve the security and efficiency of data management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a data security system and method based on multi-party collaboration. Background Art

[0002] In existing data processing systems, data confidentiality typically relies on two technologies: access control (such as RBAC) and data encryption (such as AES and RSA). Access control cannot prevent data misuse by authorized insiders or compromised legitimate accounts. Data encryption, on the other hand, faces the risks of complex key management, high performance overhead, and global failure if a key is compromised. For example, in data processing scenarios involving multi-party data transfer, such as those involving CNITSEC and CCRC accreditation, data needs to flow between institutions and individuals in different trust domains. Traditional solutions struggle to ensure both availability and adequate security.

[0003] Therefore, a new security solution that does not rely on complex algorithms is urgently needed to solve this problem. Summary of the Invention

[0004] The present invention provides a data security system and method based on multi-party collaboration to solve the defect of complicated data security management in the prior art and to achieve the effect of improving the security and efficiency of data management.

[0005] The present invention provides a data security system based on multi-party collaboration, comprising:

[0006] It includes a data slicing device, an encryption memory, a node manager, a key coordinator, and a transient view generating device;

[0007] The data slicing device is used to split the original certification materials submitted by the enterprise into at least two data slices based on the data compliance model of the target qualification certification project; the data slices include confidential value slices in which the data values ​​have been reversibly obfuscated, and structured framework slices for defining the certification document structure and field context;

[0008] The encrypted memory is used to store the secret value slice separately from the structured frame slice;

[0009] The node manager is used to manage participating entity nodes arranged in the target authority order; the participating entity nodes are nodes of different participating entities in the target qualification certification project;

[0010] The key coordinator is scheduled by the node manager and is used to, when receiving data access requests from different participating entity nodes, respectively request and receive heterogeneous authentication keys with different functions from the participating entities corresponding to the data requested in the data access requests;

[0011] The transient view generating device is activated by the node manager and is used to reorganize the data slices corresponding to the data access request into a temporary authentication material view in the temporary storage area of ​​the target qualification authentication project after receiving the heterogeneous authentication keys of all functions and verifying the status of the entity nodes participating in the target authority order and the data status of the processed data slices; the data status is used to represent the processing status of the data slice in the target qualification authentication project.

[0012] According to a data security system based on multi-party collaboration provided by the present invention, after receiving a data access request sent based on the target authority order, the node manager determines the participating entity nodes corresponding to each data slice based on the data slices corresponding to the data access request and determines the data transmission order of the participating entity nodes corresponding to each data slice based on the target authority order; the instantaneous view generation device determines the status of the participating entity nodes corresponding to each data slice and the data status of the data slices processed by the participating entity nodes in sequence based on the data transmission order.

[0013] According to a data security system based on multi-party collaboration provided by the present invention, the instantaneous view generation device is used to reorganize each data slice when the status of the participating entity node corresponding to each data slice is the completed data processing status and the data status of the derived data slice after processing by the participating entity node is available for reference.

[0014] According to a data security system based on multi-party collaboration provided by the present invention, the data slicing device is used to slice and encrypt the data processed by the participating entity nodes again based on the data compliance model of the target qualification certification project.

[0015] According to a multi-party collaborative data security system provided by the present invention, heterogeneous authentication keys with different functions include: a value decryption key provided by a participating entity corresponding to the enterprise party serving as the data owner, the value decryption key being a technical parameter for performing a reverse transformation on the confidential value slice to restore it to the real enterprise data;

[0016] And, a structured framework assembly key provided by a participating entity corresponding to the certification consulting service provider, wherein the structured framework assembly key is used to indicate the structured framework parameters for filling the real enterprise data, and the index and mapping parameters for filling the real enterprise data.

[0017] According to a data security system based on multi-party collaboration provided by the present invention, the different participating entity nodes in the target qualification certification project include participating entity nodes corresponding to the certification consulting service provider and participating entity nodes corresponding to the enterprise party of the data owner.

[0018] According to a data security system based on multi-party collaboration provided by the present invention, the data compliance model predefines slicing rules for different types of certification materials of the target qualification certification project and their corresponding target permission order.

[0019] According to a multi-party collaborative data security system provided by the present invention, the value decryption key is a one-time random salt value dynamically generated for each purposeful access request; the authentication data view output by the transient view generation device is presented in a secure sandbox environment; and the secure sandbox is configured with an offline data processing tool.

[0020] According to a data security system based on multi-party collaboration provided by the present invention, the instantaneous view generation device is a temporary processing unit operating in the volatile memory of the server. The instantaneous view generation device is used to destroy the authentication data view and the heterogeneous authentication keys used in this session after the review task is completed, and generate a collaborative audit log.

[0021] The present invention further provides a multi-party collaboration-based data security method applied to the multi-party collaboration-based data security system, comprising:

[0022] Based on the data compliance model of the target qualification certification project, the original certification materials submitted by the enterprise are split into at least two data slices; the data slices include a confidential value slice whose data values ​​have been reversibly obfuscated, and a structured framework slice used to define the certification document structure and field context; the confidential value slice and the structured framework slice are stored separately in an encrypted memory;

[0023] Upon receiving data access requests from different participating entity nodes, respectively requesting and receiving heterogeneous authentication keys of different functions from the participating entities corresponding to the data requested in the data access request; the participating entity nodes are managed in the order of target permissions; the participating entity nodes are nodes of different participating entities in the target qualification authentication project;

[0024] After receiving the heterogeneous authentication keys for all functions and verifying the status of the entity nodes participating in the target authority order and the data status of the processed data slices, the data slices corresponding to the data access request are reorganized into a temporary authentication material view in the temporary storage area of ​​the target qualification authentication project; the data status is used to represent the processing status of the data slice in the target qualification authentication project.

[0025] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the data security method based on multi-party collaboration as described above is implemented.

[0026] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the above-described data security methods based on multi-party collaboration.

[0027] The present invention also provides a computer program product, comprising a computer program, which, when executed by a processor, implements any of the above-described data security methods based on multi-party collaboration.

[0028] The data security system and method based on multi-party collaboration provided by the present invention technically separates the readability (ownership) and usage (usage rights) of data through data slicing and isolated storage, and a heterogeneous authentication key mechanism, and puts them under the control of different participants, so that the leakage of any single component or repository will not expose meaningful and complete information. The node manager, as the process arbitration core, strongly binds the accessibility of data with the advancement status of the business process and the evolution status of the data, fundamentally eliminating the risk of data misuse caused by process confusion or illegal operations. Without setting up complex encryption algorithms, data security processing can be achieved at the system level, improving the security and efficiency of data management. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0030] Figure 1 It is a structural diagram of the data security system based on multi-party collaboration provided by the present invention;

[0031] Figure 2 This is a schematic diagram of the workflow of the data security system based on multi-party collaboration provided by the present invention;

[0032] Figure 3 This is a flowchart of a data security method based on multi-party collaboration provided by the present invention;

[0033] FIG4 is a schematic structural diagram of an electronic device provided by the present invention. DETAILED DESCRIPTION

[0034] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0035] This invention provides a multi-party collaborative data security system and method for complex business processes, particularly for enterprises undergoing high-security certifications such as CNITSEC and CCRC. Traditional access control or data encryption solutions, when dealing with multi-party participation, dynamic data state evolution, and strong reliance on process timing, often face challenges such as complex permission configuration, unclear responsibility definitions, and an inability to fundamentally prevent data misuse or leakage at non-compliant process nodes.

[0036] The present invention aims to solve the above-mentioned technical difficulties by slicing the original authentication data in context, technically separating the ownership of the data (reflected in the ability to decrypt content) and the right to use the data (reflected in the ability to assemble structures and advance processes). A centralized node manager is introduced as the arbitration core of the process to ensure that every access and evolution of the data strictly follows the preset authentication business process sequence and data status, thereby realizing an architecture-native, process-driven, and extremely secure data collaborative processing model.

[0037] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be noted that this embodiment is only a preferred example of the present invention and is not intended to limit the scope of protection of the present invention.

[0038] Reference Figure 1 The embodiment of the present invention provides a data security system based on multi-party collaboration, which mainly includes: a data slicing device, an encryption memory, a node manager, a key coordinator and an instant view generation device.

[0039] The data slicing device is the data entry and processing source for this system. It is used to automatically disassemble a complete, unstructured or structured enterprise original certification document into multiple logically independent and physically separable data slices based on a pre-set data compliance model that is closely related to the business scenario. The data slicing device can eliminate the integrity of a single data file, rendering it meaningless until it is reassembled without authorization.

[0040] A data compliance model is a configurable set of rules, typically stored in JSON, XML, or a database table. It transforms abstract certification business requirements into machine-readable, specific data processing instructions. Rather than hard-coded system logic, it can be defined and adjusted by business administrators or compliance experts based on different certification programs, such as CNITSEC Level 3 and CCRC EAL 4+.

[0041] The data compliance model can include the following mapping relationships.

[0042] Data type - slicing rules: For example, the definition of "core technical personnel list.docx" needs to be segmented into independent fields such as "name", "ID number", "mobile phone number", "project experience", etc.; while "network topology diagram.png" can be segmented into the image itself and a descriptive metadata slice.

[0043] Data field - sensitivity level: For example, define "ID number" as L3 (highest sensitivity) and "project experience" as L2 (medium sensitivity).

[0044] Data Type - Initial Data Status: After the "List of Core Technical Personnel" is uploaded, its initial data status is defined as Awaiting_Compliance_Review (pending compliance review).

[0045] Material Type - Target Authority Order: Defines that the processing of this material must follow the target authority order of "Internal Compliance Officer - Material Writer - Project Supervisor - Project Manager".

[0046] It is understandable that the data compliance model predefines the slicing rules for different types of certification materials of the target qualification certification project and their corresponding target permission order.

[0047] In this implementation, the predefined data compliance model can make the system extremely flexible and scalable, and can quickly adapt to qualification certification projects of different types and requirements without modifying the core system code.

[0048] A data slice is the smallest information unit after the original data is split. In the present invention, data slices include at least the following two core types: confidential value slices and structured framework slices.

[0049] Confidential value slices are slices containing only the original data "value" itself (e.g., "Zhang San" or "138xxxx8000"). To achieve ultimate security, these "values" must undergo a reversible obfuscation process before being stored in the database. This process is not complex symmetric or asymmetric encryption, but rather a lightweight transformation that relies on external parameters (such as a salt value) to be reversed.

[0050] For example, Base64 (value + salt) can be used, or each character of value can be shifted or XORed based on the salt. Specifically, without the salt parameter, the slice itself is a string of meaningless gibberish. Each confidential value slice has a unique ID in the database, such as cvs-uuid-001.

[0051] A structured frame slice is a template that extracts all specific values, leaving only the "structure" and "context" of the original data. It describes what the data should look like, but does not indicate what the data is.

[0052] For example, for a JSON document, it is a template that retains all keys and replaces values ​​with placeholders (such as {slot_id}), for example, {"Name":"{slot-name}","ID Number":"{slot-idcard}"}. For a Word document, it can be the document's DOM structure or paragraph layout template. Each structured frame slice also has a unique ID, such as sfs-uuid-001.

[0053] It's understandable that this approach completely separates data content from structure. Even if an attacker obtains both a slice of the secret value and a slice of the structured framework, they still can't piece together meaningful information due to the lack of a mapping relationship between the two and the salt required to recover the secret value.

[0054] The encrypted memory is responsible for persistent storage of various slices processed by the data slicing device, thereby ensuring isolation and security.

[0055] For ultimate physical security, the database storing the secret value slices (e.g., a high-performance NoSQL database like Redis or DynamoDB) and the database storing the structured schema slices (e.g., a relational database like PostgreSQL or MySQL) can be deployed on completely different servers, in different VPCs (virtual private clouds), or even in different physical data centers. This physical isolation ensures that even if a single database is completely compromised, the attacker cannot obtain all the components needed to reconstruct the data.

[0056] It is understandable that at the storage level, you can still use the database's own transparent data encryption (TDE) or file system-level encryption as an additional encryption measure.

[0057] Therefore, through physical or logical forced isolation, the separation of data content and structure can be further strengthened, so that attacks on a single storage system cannot lead to catastrophic data leakage, greatly improving the system's anti-attack capabilities.

[0058] The Node Manager is used for process arbitration, managing and enforcing the target permission sequence set within a specific qualification process. It ensures that all data access and processing operations proceed in a sequence along a strictly defined protocol, eliminating any skipped steps or unauthorized forwarding operations.

[0059] A participating entity node corresponds to a specific participant role in the authentication process. A participating entity node represents a role with a specific set of responsibilities and permissions. Figure 1 shows participating entity nodes 1, 2, and 3.

[0060] For example, a CCRC certification may include the following nodes: Node A (our internal compliance officer), Node B (our document writer), Node C (the client's authorized contact person), and Node D (the external certification expert). Together, these nodes constitute the participating entities of a certification project.

[0061] The target permission sequence is a strict, linear processing chain for specific types of authentication data, pre-defined in the data compliance model. It stipulates the causal relationship between operations between participating entity nodes.

[0062] For example, for the "List of Core Technical Personnel", the target permission order may be defined as Node A to Node B. This means that only after Node A completes its work (such as verification and desensitization) and generates the corresponding derived data, Node B is eligible to perform the next operation (such as citation) on the derived data.

[0063] Data status is a lifecycle status label for a data slice. It is used to precisely mark the stage of a piece of data in the authentication process.

[0064] The data state of a personnel list might evolve from Awaiting_Review to Review_Approved to Desensitized_Ready_For_Quote to Archived. The node manager strictly verifies that a node's operation matches the current data state. For example, when the data state is Awaiting_Review, only node A can perform the operation; when the data state is Desensitized_Ready_For_Quote, only node B can perform the operation.

[0065] The node manager can be composed of a state machine engine such as the open source Spring State Machine and a set of rule tables. When each certification project is started, an independent state machine instance will be created in the node manager.

[0066] When a participating entity node, such as Node B, initiates a data access request, the request is first sent to the Node Manager. The Node Manager parses the request, identifying the requester role (Node B), the request target (personnel list), and the request purpose (quote). It queries the state machine instance of the current authentication project to check whether Node B's turn is currently in the process. It queries the "data state" of the target data to check whether it is Desensitized_Ready_For_Quote. It should be noted that the data state is the same as the data state in the aforementioned embodiment. Only when the process sequence and data state simultaneously meet the preset rules will the Node Manager approve the request and proceed to the next step of scheduling. Otherwise, it will directly reject the request and return a specific failure reason (such as "the upstream node has not completed processing"). After approval, it formats the request and forwards it to the key coordinator, simultaneously activating the transient view generation device and passing it the verification instruction.

[0067] In this way, any non-compliant process jumps can be eliminated, ensuring the order and compliance of data processing. Any operation on any node must be arbitrated by the node manager, making every step in the process traceable and auditable.

[0068] Furthermore, the node manager not only manages processes but, more importantly, manages the evolution of data. When node A finishes processing data, the node manager instructs the data slicing device to generate a new "derivative data slice" and update the data status. This "derivative data" is then accessible to node B, thus physically isolating data at different stages and achieving ultimate security.

[0069] The key coordinator is dispatched by the node manager to communicate securely with the participating entities of different roles in the authentication process to obtain heterogeneous authentication keys with completely different functions required to reconstruct the data view.

[0070] Heterogeneous authentication keys are two or more sets of technical parameters required to unlock a piece of data, provided by different parties, and with completely different functions and properties.

[0071] In some implementations, the heterogeneous authentication keys of different functions include: a value decryption key provided by a participating entity corresponding to an enterprise party as a data owner, the value decryption key being a technical parameter for reverse transformation of a confidential value slice to restore real enterprise data; and a structured framework assembly key provided by a participating entity corresponding to an authentication consulting service provider, the structured framework assembly key being used to indicate a structured framework parameter filled with real enterprise data, and an index and mapping parameter filled with real enterprise data.

[0072] The value decryption key is generally held and provided by the data owner, i.e., the participating entity corresponding to the enterprise party. In the present embodiment, the value decryption key is a one-time random salt value necessary for restoring the "confidential value slice". Without the value decryption key, only a string of random codes is obtained from the database.

[0073] The structured framework assembly key is generally held and provided by the authentication consulting service provider. It can include two pieces of information, i.e., the ID of the "structured framework slice" to be used and the "mapping relationship" of the position in the framework where the restored real value is filled.

[0074] In the present implementation, perfect separation of data ownership and usage is achieved. The data owner (enterprise) controls the final readability of the data (by providing the salt value), and the service provider (consulting company) controls the usage scenario and presentation of the data (by providing the structure and mapping), and external personnel cannot restore valuable information alone.

[0075] In some implementations, the value decryption key is a one-time random salt value dynamically generated for each purposeful access request; the authentication material view output by the instantaneous view generation device is presented in a secure sandbox environment; and the secure sandbox is configured with an offline data processing tool.

[0076] The communication between the key coordinator and each participating entity (or the key management service KMS of the agent thereof) must be carried out through an encrypted channel (such as HTTPS / TLS). For each data access request, especially for the request of "value decryption key (salt value)", a one-time random salt value with a short life cycle should be dynamically generated by the KMS of the data owner party. This salt value is bound to the session ID of the present time, and is burned after use, which greatly reduces the risk of key leakage.

[0077] The generated view is not directly returned in the form of a file, but in the form of a data stream, which is pushed to a secure sandbox environment in the front end for rendering.

[0078] A security sandbox is a front-end technology implementation that can be an iframe or a restricted DOM environment built using modern browser technologies (such as Content Security Policy (CSP)). Within this environment, JavaScript can be used to disable right-click menus, prohibit content selection and copying (user-select:none), and employ technical means to interfere with or prevent the operation of standard screenshot software.

[0079] Inside the sandbox, some secure "offline" tools that do not communicate with the outside world can be provided. For example, users can be allowed to analyze and process data, but the results of these operations are only saved in the memory of this session or sent back to the server in a secure manner without being leaked to the user's local computer.

[0080] The transient view generator is the data exporter and final presentation unit of this system. It can be temporary, in-memory, and self-destructing. It organizes the separated slices and keys into a user-readable view, but never stores the reorganized complete data in any form of persistent storage.

[0081] The transient view generation device is a temporary processing unit operating in the volatile memory of the server. The transient view generation device is used to destroy the authentication data view and the heterogeneous authentication keys used in this session after the review task is completed, and generate a collaborative audit log.

[0082] It can be a temporary container (such as Docker / Kubernetes Pod) started on demand by the node manager, or a thread-level security context created in the application server and bound to a specific session.

[0083] Specifically, the transient view generation device receives an activation command and a status verification pass signal from the node manager, as well as all heterogeneous authentication keys (such as salt, structure ID, and mappings) from the key coordinator. Based on the structure ID and mapping, the transient view generation device retrieves the corresponding structured frame slice and secret value slice from encrypted storage. In server memory, the secret value slice is inversely transformed using the value decryption key (salt) to restore the true value. This restored true value is then populated into the structured frame placeholder according to the mapping, generating a complete, readable authentication data view.

[0084] When the user closes the page, or the session times out, or the node manager instructs the session to end, the transient view generation device can immediately clear the memory and destroy all keys, slices, and reorganized views used in this session.

[0085] Before destruction, a detailed collaborative audit log can be generated, recording the session ID, requester, purpose of the operation, all key providers, accessed data ID, timestamp, and summary hash value of the generated view, and this log will be sent to an independent, tamper-proof audit system.

[0086] This implementation ensures that sensitive data is "deleted after reading," leaving no complete plaintext trace at any intermediate stage (including on server disks). Secure sandbox technology minimizes data leakage during use. Detailed audit logs provide strong, irrefutable evidence for subsequent tracing.

[0087] The following takes a complete business scenario of "processing the list of core technical personnel in CNITSEC certification" as an example to explain in detail how the various components in the multi-party collaboration-based data security system provided by the present invention work together.

[0088] The scenario is a technology company applying for CNITSEC Level 3 certification. The certification documents include a list of core technical personnel, including their names, ID numbers, mobile phone numbers, and project experience.

[0089] The target permissions are set in the order of Node A (Internal Compliance Officer Mr. Wang) - Node B (Document Writer Mr. Li). Node A is required to review the complete original information for verification and then generate a redacted version. Node B can only reference the redacted version when writing application materials and must not see sensitive information such as ID numbers.

[0090] like Figure 2 As shown, the workflow steps of the system provided by the embodiment of the present invention are as follows.

[0091] Step 1: Data upload and initial slicing.

[0092] The enterprise authorizes the user to upload the "List of Core Technical Personnel.xlsx" through the system front end.

[0093] The data slicing device is called. It loads the "data compliance model" for CNITSEC certification and identifies the file type. According to the model rules, the device reads Excel line by line and splits each employee's information into independent "confidential value slices." For example, "Zhang San" becomes cvs-uuid-001:"aBcXyZ..." after salting and obfuscation, and "110...4321" becomes cvs-uuid-002:"pQrStU...". At the same time, a "structured framework slice" is generated, such as sfs-uuid-001:{"Name":"{slot1}","ID number":"{slot2}",...}, as well as an internal mapping relationship table. All slices are stored in different areas of the encrypted memory.

[0094] The node manager creates a state machine instance for the project and sets the data state of sfs-uuid-001 to Awaiting_Review.

[0095] Step 2: Compliance review of node A.

[0096] Mr. Wang logs into the system and sees the "Review the list of core technical personnel" task in his to-do list. He clicks to view it. A data access request is sent to the node manager. The request contains: {user: "Mr. Wang", role: "Compliance Officer", target: "sfs-uuid-001"}.

[0097] Node Manager Verification: ① The role is "Compliance Officer" and is the starting node in the "Target Permission Order." ② The data status of sfs-uuid-001 is Awaiting_Review. The two match, and verification passes.

[0098] The node manager issues a scheduling instruction to the key coordinator. The key coordinator executes parallel requests: 1. It requests the value decryption key (one-time salt) associated with this session from the enterprise's (data owner's) KMS; 2. It requests the structured framework assembly key (structure ID + mapping relationship) corresponding to sfs-uuid-001 from our (service provider's) internal keystore.

[0099] After the two heterogeneous authentication keys are successfully obtained, they are sent to the transient view generator. The transient view generator completes the process in memory, generating a complete list view containing all the original sensitive information and presenting it to Mr. Wang in a secure sandbox.

[0100] Step 3: Generation of derivative data and data state evolution.

[0101] After verifying the view, Mr. Wang can click the corresponding button. This operation instruction is sent back to the instant view generation device. According to the preset desensitization rules (such as ID number masking and name hiding), the newly generated view is processed to obtain a "cleansed version" of the data. Furthermore, the data write-back channel is activated, and this "cleansed version" of the data is securely transmitted back to the data slicing device. The data slicing device slices the "cleansed version" of the data again, generating a new set of confidential value slices and structured framework slices (such as sfs-uuid-002), and stores them in encrypted storage. This new set of data is called a derived data slice.

[0102] If the operation succeeds, the node manager is notified. The node manager then performs the following atomic operations: The original data sfs-uuid-001 is updated to Archived. The new derived data sfs-uuid-002 is also updated to Desensitized_Ready_For_Quote. This also advances the project's process state machine from "Internal Pre-Review" to "Materials Writing."

[0103] Step 4: Compliance citation.

[0104] Now, Mr. Li logs into the system and begins writing his application materials. He needs to cite a list of individuals and initiates an access request. The node manager receives the request.

[0105] Node Manager Verification: ① The role is "Materials Writer," and the node is the second in the "Target Permission Order." ② The data sfs-uuid-002 requested (the system automatically associates this derived data) has a data status of Desensitized_Ready_For_Quote; verification passes.

[0106] The subsequent process is similar to step 2, with the system organizing a view for Mr. Li. However, this time, the source data for the organization is the slice corresponding to sfs-uuid-002, so the view he sees is naturally the desensitized version.

[0107] If Mr. Li tries to access the data before step 3 is completed, the node manager will directly reject his request because the data status does not match (it is still Awaiting_Review).

[0108] Step 5: Session termination and audit.

[0109] Mr. Li completed the reference and closed the view page. The instantaneous view generation device captured the session end signal and immediately destroyed all relevant data and keys in memory. Simultaneously, a detailed collaborative audit log was generated and archived, completing the closed-loop process.

[0110] According to the data security system based on multi-party collaboration provided by the embodiment of the present invention, through data slicing and isolated storage, the heterogeneous authentication key mechanism technically separates the readability (ownership) and usage (usage rights) of the data and puts them under the control of different participants, so that the leakage of any single component or repository will not expose meaningful and complete information. The node manager, as the process arbitration core, strongly binds the accessibility of the data with the advancement status of the business process and the evolution status of the data, fundamentally eliminating the risk of data misuse caused by process disorder or illegal operations. There is no need to set up complex encryption algorithms to achieve secure data processing at the system level, thereby improving the security and efficiency of data management.

[0111] In some implementations, after receiving a data access request sent based on a target authority order, the node manager determines the participating entity nodes corresponding to each data slice based on each data slice corresponding to the data access request and determines the data transmission order of the participating entity nodes corresponding to each data slice based on the target authority order; the instantaneous view generation device determines the status of the participating entity nodes corresponding to each data slice and the data status of the data slices processed by the participating entity nodes in sequence based on the data transmission order.

[0112] The data transmission order does not refer to the order in which packets are transmitted at the network level. Rather, it is a logically generated execution plan or verification checklist with strict timing constraints, generated by the node manager when arbitrating an access request. The data transmission order specifies the order in which the transient view generator must organize data and the prerequisites it must verify before organizing it. It is the instantiation of the target permission order within a specific access request.

[0113] Specifically, when the node manager receives a data access request (for example, node B requests to access derived data D'), it performs the following series of operations.

[0114] Step 6.1: Request parsing and target identification: The node manager first parses the request and identifies that the requester is node B and the requested data object is derived data D'.

[0115] Step 6.2: Tracing the dependency chain upstream. The node manager queries its internally maintained "data evolution graph" or metadata. It discovers that the derived data D' is generated by processing the original data D by node A. Therefore, it determines the dependency chain for this access request to be: node A - node B.

[0116] Step 6.3: Generate Data Transfer Sequence (Execution Plan). Based on the dependency chain described above, the node manager dynamically generates a structured execution plan. This plan is not just a simple list of sequences, but also a set of instructions that will be sent to the transient view generation device.

[0117] As you can understand, the above steps decouple the judgment of process logic (responsible for the node manager) from the execution verification of process conditions (responsible for the transient view generator), making the system architecture clearer and more maintainable. Furthermore, a dual verification mechanism is implemented: pre-admission (node ​​manager) and pre-execution (transient view generator). The node manager is responsible for macro-level process control, while the transient view generator is responsible for micro-level final state verification. This greatly improves the robustness and security of the process, ensuring that any inconsistent data is not processed incorrectly.

[0118] In some implementations, the transient view generation device is used to reorganize each data slice when the status of the participating entity node corresponding to each data slice is the data processing completed state and the data status of the derived data slice after processing by the participating entity node is available for reference.

[0119] The data processing completed state is one of the final states of a participating entity node. It indicates that the node has not only accessed the data, but more importantly, it has completed all business responsibilities assigned to it at that process node (such as verification, annotation, and desensitization) and successfully triggered the generation of the "derived data slice."

[0120] Referenceable is a specific data state of a derived data slice. It indicates that the data is the final, compliant product of its upstream node processing and has been marked by the system as safe for access and use by downstream nodes.

[0121] This implementation precisely distinguishes between the two distinct business activities of viewing data and completing data processing. This effectively prevents the significant security vulnerability of downstream nodes being able to access data simply by glancing at it from an upstream node. It ensures that data flows only continue downstream after explicit, responsible business confirmation from the upstream node. This ensures that downstream nodes always reference the final, compliant, and processed data from the upstream node, avoiding business errors and data inconsistencies caused by referencing intermediate or unfinalized data.

[0122] In some implementations, the data slicing device is used to slice and encrypt the data processed by the participating entity nodes based on the data compliance model of the target qualification certification project.

[0123] The re-slicing process is technically identical to the initial slicing in the aforementioned implementation, but its triggering timing and processing targets are completely different. It specifically refers to the process during the lifecycle of a transient view: after a user completes operations such as modification, desensitization, or annotation on the view, the system sends the evolved in-memory data back to the data slicing device for a new round of slicing.

[0124] It should be noted that the above data write-back and reprocessing process may include the following steps.

[0125] Step 7.1: Data Evolution in Memory: As in the previous example, a node (e.g., node A) completes its business operations in the memory view of the transient view generator (e.g., masking certain fields using the interface tool).

[0126] Step 7.2: Trigger the write-back instruction. When the user clicks the relevant final state button, a write-back instruction containing the evolved data is triggered.

[0127] Step 7.3: Establish a secure data write-back channel. The system securely transfers the new in-memory data from the transient view generator to the data slicing device via an encrypted internal API channel. This channel is temporary and has strict access controls, ensuring that only legitimate, authorized sessions can write data back.

[0128] Step 7.4: Re-invoke the data slicing device. After receiving the new data, the data slicing device re-invokes the data compliance model, performing a new round of confidentiality value slicing and structured framework slicing on it, just like processing a new original document, to generate a new, independent set of derived data slices.

[0129] Step 7.5: Storage and Linking: This new set of derived data slices is stored in encrypted storage and linked to its parent data (original data) at the metadata level, forming a clear evolution chain.

[0130] This approach doesn't modify the original data. Instead, it creates multiple versions of the data by reading, processing, and generating new versions. This adheres to the principle of immutability in data management, ensuring that every data change is traceable, greatly enhancing auditing capabilities and system traceability. Different nodes operate on different versions of data slices. Node B can never access the original data slice operated by Node A, and vice versa. This physical isolation based on data version evolution provides a higher level of security than traditional role-based logical isolation.

[0131] The following describes the multi-party collaboration-based data security method provided by the present invention and applied to the aforementioned multi-party collaboration-based data security system. The multi-party collaboration-based data security method described below and the multi-party collaboration-based data security system described above can be referenced to each other.

[0132] The data security method based on multi-party collaboration in an embodiment of the present invention includes step 310 , step 320 and step 330 .

[0133] Step 310: Based on the data compliance model of the target qualification certification project, the original certification materials submitted by the enterprise are split into at least two data slices; the data slices include a confidential value slice whose data values ​​have been reversibly obfuscated, and a structured framework slice used to define the certification document structure and field context; the confidential value slice and the structured framework slice are stored separately in an encrypted memory;

[0134] Step 320: Upon receiving data access requests from different participating entity nodes, request and receive heterogeneous authentication keys of different functions from the participating entities corresponding to the data requested in the data access requests; the participating entity nodes are managed in the order of target permissions; and the participating entity nodes are nodes of different participating entities in the target qualification authentication project;

[0135] Step 330, after receiving the heterogeneous authentication keys of all functions and verifying the status of the entity nodes participating in the target authority order and the data status of the processed data slices, the data slices corresponding to the data access request are reorganized into a temporary authentication data view in the temporary storage area of ​​the target qualification authentication project; the data status is used to represent the processing status of the data slice in the target qualification authentication project.

[0136] According to the data security method based on multi-party collaboration provided by an embodiment of the present invention, through data slicing and isolated storage, the heterogeneous authentication key mechanism technically separates the readability (ownership) and usage (usage rights) of the data and puts them under the control of different participants, so that the leakage of any single component or repository will not expose meaningful and complete information. The node manager, as the process arbitration core, strongly binds the accessibility of the data with the advancement status of the business process and the evolution status of the data, fundamentally eliminating the risk of data misuse caused by process disorder or illegal operations. There is no need to set up complex encryption algorithms to achieve secure data processing at the system level, thereby improving the security and efficiency of data management.

[0137] Figure 4 shows a schematic diagram of the physical structure of an electronic device, as shown in Figure 4, which can include a processor 410, a communication interface 420, a memory 430, and a communication bus 440, wherein the processor 410, the communication interface 420, and the memory 430 communicate with each other through the communication bus 440. The processor 410 can invoke the logical instructions in the memory 430 to execute the multi-party collaborative data security method, which includes: based on the data integration model of the target qualification certification project, splitting the original certification materials submitted by the enterprise into at least two data slices; the data slice includes a secret value slice in which the data value is reversibly obfuscated, and a structured framework slice for defining the context of the authentication document structure and fields; storing the secret value slice and the structured framework slice separately to the encrypted storage; upon receiving a data access request from different participating entity nodes, requesting and receiving different function heterogeneous authentication keys from the participating entities corresponding to the data requested in the data access request; the participating entity nodes are managed in accordance with the target permission sequence; the participating entity nodes are nodes of different participating entities in the target qualification certification project; after receiving all function heterogeneous authentication keys and verifying the status of the participating entity nodes in the target permission sequence and the data state of the processed data slice, recombining each data slice corresponding to the data access request into a temporary certification material view in the temporary storage area of the target qualification certification project; the data state is used to indicate the processing state of the data slice in the target qualification certification project.

[0138] In addition, the logical instructions in the memory 430 described above can be implemented in the form of a software function unit and sold or used as an independent product, which can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the part of the prior art that essentially contributes or the part of the technical solutions can be embodied in the form of a software product, which is stored in a storage medium and includes instructions for making a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the method described in various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various program code storage media.

[0139] On the other hand, the present invention further provides a computer program product, comprising a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the data security method based on multi-party collaboration provided by the above methods, the method comprising: splitting the original certification materials submitted by the enterprise into at least two data slices based on the data compliance model of the target qualification certification project; the data slices include a confidential value slice in which the data value has been reversibly obfuscated, and a structured framework slice for defining the certification document structure and field context; and storing the confidential value slice and the structured framework slice separately in an encrypted memory; When receiving data access requests from different participating entity nodes, heterogeneous authentication keys with different functions are requested and received from the participating entities corresponding to the data requested in the data access request; the participating entity nodes are managed in the target authority order; the participating entity nodes are nodes of different participating entities in the target qualification authentication project; after receiving the heterogeneous authentication keys of all functions and verifying the status of the participating entity nodes in the target authority order and the data status of the processed data slices, the data slices corresponding to the data access request are reorganized into a temporary authentication data view in the temporary storage area of ​​the target qualification authentication project; the data status is used to represent the processing status of the data slice in the target qualification authentication project.

[0140] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the data security method based on multi-party collaboration provided by the above-mentioned methods, the method comprising: based on the data compliance model of the target qualification certification project, splitting the original certification materials submitted by the enterprise into at least two data slices; the data slices include confidential value slices in which the data values ​​have been reversibly obfuscated, and structured framework slices for defining the certification document structure and field context; storing the confidential value slices and the structured framework slices separately in an encrypted memory; when receiving data access requests from different participating entity nodes, requesting and receiving heterogeneous authentication keys of different functions from the participating entities corresponding to the data requested in the data access request; the participating entity nodes are managed in accordance with the target authority order; the participating entity nodes are nodes of different participating entities in the target qualification certification project; after receiving the heterogeneous authentication keys of all functions and verifying the status of the participating entity nodes in the target authority order and the data status of the processed data slices, reorganizing the data slices corresponding to the data access request into a temporary certification material view in the temporary storage area of ​​the target qualification certification project; the data status is used to represent the processing status of the data slice in the target qualification certification project.

[0141] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0142] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.

[0143] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A data security system based on multi-party collaboration, characterized in that: It includes a data slicing device, an encryption memory, a node manager, a key coordinator, and a transient view generating device; The data slicing device is used to split the original certification materials submitted by the enterprise into at least two data slices based on the data compliance model of the target qualification certification project; the data slices include confidential value slices in which the data values ​​have been reversibly obfuscated, and structured framework slices for defining the certification document structure and field context; The encrypted memory is used to store the secret value slice separately from the structured frame slice; The node manager is used to manage participating entity nodes set in the target authority order; The participating entity nodes are nodes of different participating entities in the target qualification certification project; The key coordinator is scheduled by the node manager and is used to, when receiving data access requests from different participating entity nodes, respectively request and receive heterogeneous authentication keys with different functions from the participating entities corresponding to the data requested in the data access requests; The transient view generating device is activated by the node manager and is used to reorganize the data slices corresponding to the data access request into a temporary authentication material view in the temporary storage area of ​​the target qualification authentication project after receiving the heterogeneous authentication keys of all functions and verifying the status of the entity nodes participating in the target authority order and the data status of the processed data slices; the data status is used to represent the processing status of the data slice in the target qualification authentication project.

2. The data security system based on multi-party collaboration according to claim 1 is characterized in that: After receiving a data access request sent based on the target authority order, the node manager determines the participating entity nodes corresponding to each data slice based on the data slices corresponding to the data access request and determines the data transmission order of the participating entity nodes corresponding to each data slice based on the target authority order; the instantaneous view generation device determines the status of the participating entity nodes corresponding to each data slice and the data status of the data slices processed by the participating entity nodes in sequence based on the data transmission order.

3. The data security system based on multi-party collaboration according to claim 2 is characterized in that: The transient view generating device is used to reorganize each data slice when the status of the participating entity node corresponding to each data slice is the data processing completion status and the data status of the derived data slice processed by the participating entity node is available for reference.

4. The data security system based on multi-party collaboration according to claim 3 is characterized in that: The data slicing device is used to slice and encrypt the data processed by the participating entity nodes based on the data compliance model of the target qualification certification project.

5. The data security system based on multi-party collaboration according to any one of claims 1 to 4, characterized in that: Heterogeneous authentication keys with different functions include: a value decryption key provided by a participating entity corresponding to the enterprise party that is the data owner, the value decryption key being a technical parameter for reversely transforming the confidential value slice to restore it to the real enterprise data; And, a structured framework assembly key provided by a participating entity corresponding to the certification consulting service provider, wherein the structured framework assembly key is used to indicate the structured framework parameters for filling the real enterprise data, and the index and mapping parameters for filling the real enterprise data.

6. The data security system based on multi-party collaboration according to claim 1 is characterized in that: The different participating entity nodes in the target qualification certification project include participating entity nodes corresponding to the certification consulting service provider and participating entity nodes corresponding to the enterprise party of the data owner.

7. The data security system based on multi-party collaboration according to claim 1 is characterized in that: The data compliance model predefines the slicing rules for different types of certification materials of the target qualification certification project and their corresponding target permission order.

8. The data security system based on multi-party collaboration according to claim 5 is characterized in that: The value decryption key is a one-time random salt value dynamically generated for each purposeful access request; the authentication data view output by the transient view generation device is presented in a secure sandbox environment; and the secure sandbox is equipped with an offline data processing tool.

9. The data security system based on multi-party collaboration according to claim 1 is characterized in that: The transient view generation device is a temporary processing unit operating in the volatile memory of the server. The transient view generation device is used to destroy the authentication data view and the heterogeneous authentication keys used in this session after the review task is completed, and generate a collaborative audit log.

10. A data security method based on multi-party collaboration applied to the data security system based on multi-party collaboration according to any one of claims 1 to 9, characterized in that: The method comprises: Based on the data compliance model of the target qualification certification project, the original certification materials submitted by the enterprise are split into at least two data slices; the data slices include a confidential value slice whose data values ​​have been reversibly obfuscated, and a structured framework slice used to define the certification document structure and field context; the confidential value slice and the structured framework slice are stored separately in an encrypted memory; Upon receiving data access requests from different participating entity nodes, respectively requesting and receiving heterogeneous authentication keys of different functions from the participating entities corresponding to the data requested in the data access request; the participating entity nodes are managed in the order of target permissions; the participating entity nodes are nodes of different participating entities in the target qualification authentication project; After receiving the heterogeneous authentication keys for all functions and verifying the status of the entity nodes participating in the target authority order and the data status of the processed data slices, the data slices corresponding to the data access request are reorganized into a temporary authentication material view in the temporary storage area of ​​the target qualification authentication project; the data status is used to represent the processing status of the data slice in the target qualification authentication project.

Citation Information

Patent Citations

  • Cloud platform business process driving method and system based on API and flow

    CN116996558A

  • Security encryption key value pair data storage method and system

    CN117216814A