A full-process data operation and value co-creation system based on a trusted data space
By leveraging blockchain and federated learning technologies, a trusted data space is constructed, resolving trust mechanism issues and privacy leakage risks during cross-domain data flow. This enables transparent data supervision, immutability, and privacy protection, supporting the co-creation of data value across multiple fields.
Patent Information
- Application Number
- CN202511156972.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-19
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2045-08-19
AI Technical Summary
Existing end-to-end data operation and value co-creation systems based on trusted data spaces lack a unified trust mechanism when data flows across domains. Data may be tampered with and misused, affecting reliability and traceability. At the same time, there is a risk of data privacy leakage during collaborative data computing and analysis, making it difficult to meet security and compliance requirements.
It adopts a data circulation management algorithm based on blockchain technology, realizes the immutable recording and transparent supervision of data circulation by constructing a distributed ledger system, combines symmetric and asymmetric encryption technologies to ensure data confidentiality and integrity, and introduces a federated learning data privacy protection algorithm to ensure data security and privacy protection through distributed authentication and dynamic access control.
It achieves transparency, traceability, and security in the data circulation process, reduces the risk of data leakage, enhances the system's trust mechanism and privacy protection capabilities, supports cross-domain data value co-creation, and is applicable to sensitive data fields such as government affairs, healthcare, industry, and finance.
Smart Images

Figure CN120710797B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of blockchain, federated learning, and privacy protection, specifically to a full-process data operation and value co-creation system based on a trusted data space. Background Technology
[0002] Blockchain technology is a decentralized data storage and management technology designed to solve trust issues in data circulation. Through distributed ledgers and smart contracts, it achieves data immutability and traceability. In a full-process data operation and value co-creation system based on a trusted data space, blockchain technology is used to manage cross-domain data circulation. By establishing a transparent and trustworthy data flow mechanism, it ensures the security and regulatory oversight of data exchanged between different entities. Furthermore, blockchain's consensus mechanism and encryption technology effectively prevent malicious tampering and unauthorized access, providing technical safeguards for data resource sharing and transactions.
[0003] Federated learning and privacy protection technology is a distributed machine learning approach designed to address privacy breaches during data sharing. By training models locally among participating parties and exchanging only model parameters without transmitting raw data, it enables secure sharing of data value. In a full-process data operation and value co-creation system based on a trusted data space, federated learning combines differential privacy and secure multi-party computation technologies to ensure data participates in collaborative computation under privacy protection, preventing data misuse and leakage. Furthermore, this federated learning and privacy protection technology can establish a trusted data collaboration mechanism among different data holders, improving the utilization efficiency of data elements while ensuring data sovereignty.
[0004] The existing end-to-end data operation and value co-creation system based on trusted data space lacks a unified trust mechanism when data flows across domains. Data may be tampered with and misused during the flow, affecting the reliability and traceability of the data. Secondly, the system relies on traditional centralized data processing mode in the process of collaborative data computing and analysis, which poses a risk of data privacy leakage and makes it difficult to meet data security compliance requirements. Summary of the Invention
[0005] The purpose of this invention is to provide a full-process data operation and value co-creation system based on a trusted data space, in order to solve the problems mentioned in the background art regarding the lack of a unified trust mechanism when data flows across domains, the possibility of data being tampered with and abused during the flow process, affecting the reliability and traceability of data, and the system's reliance on traditional centralized data processing mode in the process of collaborative data computing and analysis, which poses a risk of data privacy leakage and makes it difficult to meet data security compliance requirements.
[0006] To achieve the above objectives, the present invention provides the following technical solution: a full-process data operation and value co-creation system based on a trusted data space, comprising a data acquisition and transmission module, a data aggregation and fusion module, a standard management and interoperability module, a data circulation and sharing module, a security and trusted control module, and a system operation and monitoring module. The system is characterized in that: the data acquisition and transmission module is used to collect raw data from multiple data sources and transmit it securely, ensuring that the data enters the system in real time, accurately, and securely; the data aggregation and fusion module includes a multi-source data integration unit and a data fusion analysis unit. The multi-source data integration unit is used to clean, standardize, and structure the multi-source data to ensure data consistency and high quality; the data fusion analysis unit is used to classify, fuse, and analyze the integrated data to ensure efficient extraction and utilization of data value; the standard management and interoperability module is used to formulate, manage, and execute data standards and interface protocols to ensure interoperability between modules. Interconnectivity and compatibility are achieved between different data systems. The data circulation and sharing module includes a data circulation management unit and a data utilization and operation unit. The data circulation management unit proposes a data circulation management algorithm based on blockchain technology to achieve tamper-proof recording, transparent supervision, and full-process tracking of data during cross-domain data circulation, ensuring the security and trustworthiness of data sharing and transfer. The data utilization and operation unit is used for the commercial development and operation management of shared data, ensuring the maximum utilization of data resources and the co-creation of value. The security and trust management module proposes a data privacy protection algorithm based on federated learning to implement distributed authentication, dynamic access control, and cross-domain data circulation privacy protection, ensuring the security, trustworthiness, and privacy protection of data throughout the entire process. The system operation and monitoring module is used to monitor and manage the system's operating status and data flow in real time, and to interact with users with information and control commands to ensure the stable and efficient operation of the system.
[0007] Preferably, the data acquisition and transmission module automatically acquires data from various data sources and employs encryption and distributed transmission protocols to ensure the real-time performance, integrity, and security of the data acquisition and transmission process.
[0008] Preferably, the data aggregation and fusion module includes a multi-source data integration unit. The multi-source data integration unit uses standardized interfaces and automated data preprocessing technology to ensure that raw data from different sources and with different formats can be accurately collected, standardized, and converted into a unified data format in the first time, thereby providing high-quality, structured basic data for subsequent deep data fusion.
[0009] Preferably, the data aggregation and fusion module includes a data fusion analysis unit. The data fusion analysis unit uses data normalization, cleaning, intelligent matching, and association rule analysis methods to ensure that the multi-source data after initial integration can effectively remove redundancy and fill in missing data, and achieve organic integration of data in multiple dimensions, ultimately generating accurate and applicable data products, providing solid data support for decision support, data sharing, and business value enhancement.
[0010] Preferably, the standard management and interoperability module ensures data interoperability and standard consistency between different platforms and systems by establishing unified data standards, metadata management, and semantic conversion mechanisms.
[0011] Preferably, the data circulation and sharing module includes a data circulation management unit, which proposes a data circulation management algorithm based on blockchain technology. By deploying a distributed ledger and smart contract mechanism based on blockchain technology, it ensures that cross-domain data is fully recorded, verified in real time, and is tamper-proof during the circulation process, thus guaranteeing the transparency and traceability of data transmission.
[0012] Preferably, the data circulation management algorithm based on blockchain technology is as follows: First, a trusted data space infrastructure is constructed through a blockchain network to achieve tamper-proof recording and transparent supervision of data circulation. A distributed ledger is created in the Ethereum blockchain network, and the specific formula of the data structure model is defined as follows:
[0013]
[0014] in, Represented as a blockchain ledger, Represented as the first Each block, Represented as a block count index, Represented as each independent block, The hash value of a block is used to uniquely identify the block and ensure its integrity. Represented as a collection of transactions within a block, it records the specific operations involved in data flow. The timestamp, representing the block's generation time, ensures temporal consistency. By initializing the distributed ledger and deploying smart contracts, it provides underlying rule constraints and automated execution mechanisms for subsequent data flow, ensuring the auditability of the entire data operation process. Then, the smart contract functions are designed. Its core functions include data ownership confirmation, access policy management, and transaction verification. Contract logic is implemented through… The language implementation, with key functions represented as follows:
[0015]
[0016] in, Represented as data metadata, This is represented as an attribute access strategy. Represented as a transaction identifier, Represented as a contract interface, it constructs an underlying ledger architecture for a trusted data space. Smart contract functions automate the execution of data operation rules, providing a trusted execution environment for the value co-creation system. Secondly, it combines symmetric and asymmetric encryption technologies to ensure the confidentiality and integrity of data during its flow. Decentralized storage is achieved using IPFS to reduce the risk of single points of failure. This is applied to pre-processed data. Two-stage encryption is performed, and the specific formula is as follows:
[0017]
[0018]
[0019] in, Represented as ciphertext after symmetric encryption. Represented as raw data, Represented as Advanced Encryption Standard, Represented as a symmetric encryption key, Represented as a 256-bit binary key space, Indicated as belonging to, Represented as the ciphertext after asymmetric encryption. Represented as an elliptic curve integration encryption function, This represents the public key of the data owner. This represents the private key of the data owner. Represented as the base point of an elliptic curve, used in the symmetric encryption phase. The algorithm on the original data Encryption is performed, and the ECIES function is used to process the symmetric key during the asymmetric encryption phase. Encrypt the ciphertext Uploaded to the IPFS network, a content identifier is obtained, expressed by the following formula:
[0020]
[0021] in, Represented as the IPFS content addressing hash function,
[0022] By employing layered encryption and distributed storage to address the secure sharing needs of the entire data operation process, the immutability of data assets during value co-creation is ensured. Then, fine-grained access control is implemented based on blockchain technology, ensuring that data is used only by authorized parties as needed. Simultaneously, dynamic policy updates and audit traceability are supported, and attribute sets are defined. The expression is calculated using a logic gate combination strategy, and the specific formula is as follows:
[0023]
[0024] in, This is represented as an attribute access control policy. Represented as the logical AND operator, Represented as user characteristics, Represented as the logical XOR operator, This is represented as the specific value that the attribute can take. This represents the total number of conditions in the strategy. Represented as an index of the conditions in the strategy, the strategy With ciphertext The binding process, which involves writing data to the blockchain via a smart contract, is expressed as follows:
[0025]
[0026] in, This is represented as a policy update transaction function, used to write new access control policies into the transaction records of the blockchain. This is represented as a smart contract update function. A digital signature representing the data owner is used to verify the legitimacy of policy updates. Then, it addresses the key management challenge in cross-domain data sharing by recording the key distribution trajectory through blockchain, achieving full traceability of the key's lifecycle. Data users... Initiating a key request triggers the smart contract to verify attribute matching. This is represented as an index of the number of data users, and the specific formula is as follows:
[0027]
[0028] in, This is represented as a validation function, used to check whether the user attribute set meets the access control policy. Represented as user A collection of attributes, containing user identity, role, and permission information. Represented as logical judgment symbols, the session key is negotiated through the improved ECDH protocol, and the specific formula is as follows:
[0029]
[0030] in, This is represented as a session key, used to encrypt communication between the data user and the data owner. This is represented as a hash-based message authentication code function, used to generate key derivation values. Represented as data user A temporary private key, used for key negotiation. This is represented as a random salt value, used to enhance key security and prevent replay attacks. Encrypted and written into the blockchain transaction
[0031]
[0032] in, Represented as a blockchain transaction record, it is used to store the encrypted session key. This is represented as a smart contract function, used to write the encryption key to the blockchain. Indicated as a data user public key Encryption functions, through on-chain evidence storage mechanisms for key distribution, can enhance the auditing capabilities of trusted data spaces and support the trust transfer of cross-domain value co-creation.
[0033] Preferably, the data circulation and sharing module includes a data utilization and operation unit. The data utilization and operation unit ensures that all participants can efficiently and securely access data, develop applications, and achieve commercial operation by building standardized data service interfaces and a flexible data development platform, thereby transforming the value of data circulation into practical application results.
[0034] Preferably, the security and trust management module proposes a data privacy protection algorithm based on federated learning. By integrating differential privacy and secure multi-party computation technologies based on federated learning, it ensures that data is not accessed or misused without authorization during cross-entity collaboration, and ensures the privacy, security, trust authentication, and dynamic management of the system during data circulation.
[0035] Preferably, the data privacy protection algorithm based on federated learning is as follows: First, a full-process data operation infrastructure based on a trusted data space is constructed to achieve secure interconnection between terminal devices, edge nodes, and cloud servers, providing a decentralized collaborative environment for subsequent privacy protection algorithms. Within the trusted data space, a consortium blockchain network composed of super edge nodes is deployed. Each SEN has edge computing, model aggregation, and blockchain verification functions, and initializes the global federated model parameters. ,in , Represented as an initialized high-dimensional parameter vector, Represented as model dimension, Represented as a model identifier, it generates initial identity credentials through a digital signature protocol. ,in, This represents the total number of participating devices. This is represented as an index of the number of participating devices. Represented as device The encrypted signature is used for authentication in subsequent communications, and the specific formula is expressed as follows:
[0036]
[0037] in, This represents a function that randomly initializes the model parameters. This is represented as a digital signature generation function. Represented as device A unique identifier, Represented as device public key, This is represented as a string concatenation operation. Model training is completed locally on the terminal device. Differential privacy technology protects sensitive user data, ensuring that data is available but not visible within a trusted data space. Download the latest global model from the edge nodes. Utilizing local datasets Conduct training. Represented as the index of the federated learning iteration number, used to calculate the local gradient. ,in The loss function is applied to the gradient. Norm clipping, specifically expressed by the formula:
[0038]
[0039] in, This is represented as the clipped local gradient vector. Represented as device The local gradient vector, Represented as Norm, This is represented as the gradient clipping threshold, with input Laplacian noise. Generate privacy-preserving gradients. This is represented as the Laplacian noise vector injected into the local gradient. Represented as a Laplace distribution, This is represented by gradient sensitivity and privacy budget, which control the strength of privacy protection. Secondly, local model updates are aggregated at the edge node layer, and blockchain technology is used to achieve trusted verification and traceability of parameters, supporting the auditability of the entire data operation process. Edge nodes receive privacy gradients uploaded by terminal devices. Verify digital signature To ensure the data source is legitimate, the federal average algorithm is applied, and the specific formula is as follows:
[0040]
[0041]
[0042] in, Represented as the first Global model parameters of the wheel, Represented as the learning rate, Represented as the first In the next iteration, the global model parameters are updated. Secondly, a federated learning model is used to generate personalized recommendations in real time at the edge layer. This combines user behavior data with global trend data to achieve value co-creation. The edge nodes then load the latest model. According to the user Local behavioral data Calculate the interest vector :
[0043]
[0044] in, This is represented as the model inference function. Then, it reads from the blockchain and merges the global hotspot vector to generate a hybrid recommendation score. The specific formula is as follows:
[0045]
[0046] in, Represented as user Recommendation scores for trending information Represented as personalized weights, Represented as user Interest vector, Represented as a global hotspot vector, this vector describes the characteristics and trends of hotspot information on a global scale, illustrating the overall user group's focus on trending topics. Finally, the model parameters and recommendation results are permanently stored on the blockchain, supporting multi-party data value sharing and auditing, and building a sustainable operating ecosystem. The specific formula is as follows:
[0047]
[0048] in, Represented as in the first Blockchain data blocks generated during the federated learning process Represented as the set of feedback vectors from all users, Represented as the first The hash value of a blockchain data block.
[0049] Preferably, the system operation and monitoring module monitors the system's operating status, data flow, and log records in real time, and interacts with users to exchange information and control commands, ensuring the platform's continuous, efficient, and stable operation and enabling timely detection and handling of anomalies.
[0050] Compared with the prior art, the beneficial effects of the present invention are:
[0051] 1. The data circulation management unit proposes a data circulation management algorithm based on blockchain technology. First, the algorithm provides a trusted infrastructure for a trusted data space by constructing a distributed ledger system based on blockchain. By recording the entire data circulation process through block structures, it ensures that all data additions, deletions, modifications, and queries during circulation are recorded in real time and are tamper-proof, thus achieving a highly transparent and traceable regulatory environment. Through the smart contract mechanism deployed on the Ethereum network, the algorithm can automatically complete key operations such as data ownership confirmation, access policy setting, and transaction verification on the chain, effectively improving the execution efficiency and credibility of data operation links and building a value co-creation platform with self-executing rule capabilities. Second, by combining symmetric and asymmetric encryption technologies, double-layer encryption is implemented in the data preprocessing stage, and the encrypted data is uploaded to the decentralized IPFS system for storage, effectively reducing the risk of data leakage and single point of failure, ensuring the confidentiality and integrity of data in cross-platform and cross-entity circulation. Furthermore, the algorithm introduces attribute-based fine-grained policy management in access control, enabling precise control of data access permissions and preventing unauthorized data use. The access policy also supports dynamic updates and on-chain auditing, greatly enhancing the flexibility and regulatory oversight of the data sharing process. In cross-domain sharing, the system records the entire key distribution process via blockchain, solving the trust bottleneck problem in traditional key management and achieving full-chain traceability of the key lifecycle. When a data user initiates an access request, the system automatically calls a smart contract to verify whether its attribute set meets the access policy. If the verification passes, a session key is dynamically generated based on the improved key negotiation protocol and encrypted and written into the blockchain to ensure the security of subsequent communications. Through the integration of these multi-dimensional mechanisms, the algorithm not only ensures the privacy, controllability, and verifiability of data assets throughout the entire operation process but also provides trust guarantees for the co-creation of data value with the participation of multiple stakeholders. This supports the application of trusted data spaces in multiple sensitive data areas such as government affairs, healthcare, industry, and finance, demonstrating extremely high promotional value and application prospects.
[0052] 2. The security and trust management module proposes a data privacy protection algorithm based on federated learning. This algorithm first establishes a trusted data space infrastructure to ensure secure connections between terminal devices, edge nodes, and cloud servers, providing a robust environment for distributed collaborative learning. Building upon this, a consortium blockchain network composed of super edge nodes is deployed, enabling each node to perform edge computing, model aggregation, and blockchain verification functions. This effectively enhances the system's decentralized governance capabilities and trust mechanisms. The introduction of the federated learning algorithm allows terminal devices to train models locally, and differential privacy technology protects sensitive user data, ensuring that data is always available but not visible. The algorithm participates in global modeling without leaving the local machine, effectively avoiding the privacy risks faced by traditional datasets. Furthermore, during local training, the algorithm applies L2 norm pruning and noise perturbation to the gradients, enhancing its resistance to inference attacks and providing a protected data model for edge aggregation. At the edge node layer, the algorithm verifies terminal digital signatures to ensure the integrity of data transmission and the trustworthiness of identities. Subsequently, a weighted average method is used to aggregate local model updates, improving model convergence efficiency. Through deep integration with blockchain, the auditability and immutability of the model parameter update process are achieved, providing technical support for subsequent data governance. During the model inference phase, the algorithm dynamically generates personalized recommendations based on local user behavior data and global hotspot trends, promoting the implementation of a data value co-creation mechanism. Edge nodes generate hybrid recommendation results by fusing user interest vectors and global hotspot vectors, ensuring a personalized experience and activating the reuse potential of data elements. Finally, the algorithm uploads the updated model parameters, user recommendation results, and feedback information to the blockchain to form trusted data evidence, supporting data value sharing among multiple parties. The data privacy protection algorithm based on federated learning not only comprehensively improves the system's security, auditability, and recommendation intelligence, but also promotes the closed-loop operation of the entire process from data collection to value transformation, establishing a sustainable operating ecosystem that emphasizes both privacy protection and value co-creation, demonstrating strong technological foresight and industrial applicability. Attached Figure Description
[0053] Figure 1 This is a schematic diagram of the structure of the present invention; Detailed Implementation
[0054] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0055] Please see Figure 1This invention provides a full-process data operation and value co-creation system based on a trusted data space, including a data acquisition and transmission module, a data aggregation and fusion module, a standards management and interoperability module, a data circulation and sharing module, a security and trusted control module, and a system operation and monitoring module. Its key features are: the data acquisition and transmission module collects raw data from multiple data sources and transmits it securely, ensuring that data enters the system in real time, accurately, and securely; the data aggregation and fusion module includes a multi-source data integration unit and a data fusion analysis unit. The multi-source data integration unit cleans, standardizes, and structures the diverse data to ensure data consistency and high quality, while the data fusion analysis unit classifies, fuses, and analyzes the integrated data to ensure efficient extraction and utilization of data value; the standards management and interoperability module formulates, manages, and executes data standards and interface protocols to ensure interoperability between modules and different data systems. The system achieves interconnection, interoperability, and compatibility. The data circulation and sharing module includes a data circulation management unit and a data utilization and operation unit. The data circulation management unit proposes a blockchain-based data circulation management algorithm to ensure immutable recording, transparent supervision, and full-process tracking of data during cross-domain data circulation, guaranteeing security and trustworthiness during data sharing and transfer. The data utilization and operation unit is used for the commercial development and operation management of shared data, ensuring maximum utilization of data resources and achieving value co-creation. The security and trust management module proposes a federated learning-based data privacy protection algorithm to implement distributed authentication, dynamic access control, and cross-domain data circulation privacy protection, ensuring data security, trustworthiness, and privacy protection throughout the entire process. The system operation and monitoring module is used for real-time monitoring and management of system operation status and data flow, and interacts with users to exchange information and control commands, ensuring stable and efficient system operation.
[0056] See Figure 1 Furthermore, the data acquisition and transmission module automatically collects data from various data sources and employs encryption and distributed transmission protocols to ensure the real-time nature, integrity, and security of the data acquisition and transmission process.
[0057] See Figure 1 Furthermore, the data aggregation and fusion module includes a multi-source data integration unit. This multi-source data integration unit uses standardized interfaces and automated data preprocessing technology to ensure that raw data from different sources and in different formats can be accurately collected, standardized, and converted into a unified data format in the first instance, thereby providing high-quality, structured basic data for subsequent deep data fusion.
[0058] See Figure 1Furthermore, the data aggregation and fusion module includes a data fusion analysis unit. This unit employs data normalization, cleaning, intelligent matching, and association rule analysis methods to ensure that the initially integrated multi-source data can effectively remove redundancy and fill in missing information, and achieve organic fusion of data in multiple dimensions. Ultimately, it generates accurate and applicable data products, providing solid data support for decision support, data sharing, and business value enhancement.
[0059] See Figure 1 Furthermore, the standard management and interoperability module ensures data interoperability and standard consistency between different platforms and systems by establishing unified data standards, metadata management, and semantic conversion mechanisms.
[0060] See Figure 1 Furthermore, the data circulation and sharing module includes a data circulation management unit, which proposes a data circulation management algorithm based on blockchain technology. By deploying a distributed ledger and smart contract mechanism based on blockchain technology, it ensures that cross-domain data is fully recorded, verified in real time, and is tamper-proof during the circulation process, thus guaranteeing the transparency and traceability of data transmission.
[0061] See Figure 1 Furthermore, the data circulation management algorithm based on blockchain technology is as follows: First, a trusted data space infrastructure is constructed through a blockchain network to achieve tamper-proof recording and transparent supervision of data circulation. A distributed ledger is created in the Ethereum blockchain network, and the specific formula of the data structure model is defined as follows:
[0062]
[0063] in, Represented as a blockchain ledger, Represented as the first Each block, Represented as a block count index, Represented as each independent block, The hash value of a block is used to uniquely identify the block and ensure its integrity. Represented as a collection of transactions within a block, it records the specific operations involved in data flow. The timestamp, representing the block's generation time, ensures temporal consistency. By initializing the distributed ledger and deploying smart contracts, it provides underlying rule constraints and automated execution mechanisms for subsequent data flow, ensuring the auditability of the entire data operation process. Then, the smart contract functions are designed. Its core functions include data ownership confirmation, access policy management, and transaction verification. Contract logic is implemented through… The language implementation, with key functions represented as follows:
[0064]
[0065] in, Represented as data metadata, This is represented as an attribute access strategy. Represented as a transaction identifier, Represented as a contract interface, it constructs an underlying ledger architecture for a trusted data space. Smart contract functions automate the execution of data operation rules, providing a trusted execution environment for the value co-creation system. Secondly, it combines symmetric and asymmetric encryption technologies to ensure the confidentiality and integrity of data during its flow. Decentralized storage is achieved using IPFS to reduce the risk of single points of failure. This is applied to pre-processed data. Two-stage encryption is performed, and the specific formula is as follows:
[0066]
[0067]
[0068] in, Represented as ciphertext after symmetric encryption. Represented as raw data, Represented as Advanced Encryption Standard, Represented as a symmetric encryption key, Represented as a 256-bit binary key space, Indicated as belonging to, Represented as the ciphertext after asymmetric encryption. Represented as an elliptic curve integration encryption function, This represents the public key of the data owner. This represents the private key of the data owner. Represented as the base point of an elliptic curve, used in the symmetric encryption phase. The algorithm on the original data Encryption is performed, and the ECIES function is used to process the symmetric key during the asymmetric encryption phase. Encrypt the ciphertext Uploaded to the IPFS network, a content identifier is obtained, expressed by the following formula:
[0069]
[0070] in, Represented as the IPFS content addressing hash function,
[0071] By employing layered encryption and distributed storage to address the secure sharing needs of the entire data operation process, the immutability of data assets during value co-creation is ensured. Then, fine-grained access control is implemented based on blockchain technology, ensuring that data is used only by authorized parties as needed. Simultaneously, dynamic policy updates and audit traceability are supported, and attribute sets are defined. The expression is calculated using a logic gate combination strategy, and the specific formula is as follows:
[0072]
[0073] in, This is represented as an attribute access control policy. Represented as the logical AND operator, Represented as user characteristics, Represented as the logical XOR operator, This is represented as the specific value that the attribute can take. This represents the total number of conditions in the strategy. Represented as an index of the conditions in the strategy, the strategy With ciphertext The binding process, which involves writing data to the blockchain via a smart contract, is expressed as follows:
[0074]
[0075] in, This is represented as a policy update transaction function, used to write new access control policies into the transaction records of the blockchain. This is represented as a smart contract update function. A digital signature representing the data owner is used to verify the legitimacy of policy updates. Then, it addresses the key management challenge in cross-domain data sharing by recording the key distribution trajectory through blockchain, achieving full traceability of the key's lifecycle. Data users... Initiating a key request triggers the smart contract to verify attribute matching. This is represented as an index of the number of data users, and the specific formula is as follows:
[0076]
[0077] in, This is represented as a validation function, used to check whether the user attribute set meets the access control policy. Represented as user A collection of attributes, containing user identity, role, and permission information. Represented as logical judgment symbols, the session key is negotiated through the improved ECDH protocol, and the specific formula is as follows:
[0078]
[0079] in, This is represented as a session key, used to encrypt communication between the data user and the data owner. This is represented as a hash-based message authentication code function, used to generate key derivation values. Represented as data user A temporary private key, used for key negotiation. This is represented as a random salt value, used to enhance key security and prevent replay attacks. Encrypted and written into the blockchain transaction
[0080]
[0081] in, Represented as a blockchain transaction record, it is used to store the encrypted session key. This is represented as a smart contract function, used to write the encryption key to the blockchain. Indicated as a data user public key Encryption functions, through on-chain evidence storage mechanisms for key distribution, can enhance the auditing capabilities of trusted data spaces and support the trust transfer of cross-domain value co-creation.
[0082] See Figure 1 Furthermore, the data circulation and sharing module includes a data utilization and operation unit. By constructing standardized data service interfaces and a flexible data development platform, the data utilization and operation unit ensures that all participants can efficiently and securely access data, develop applications, and achieve commercial operation, thereby transforming the value of data circulation into practical application results.
[0083] See Figure 1 Furthermore, the security and trust management module proposes a data privacy protection algorithm based on federated learning. By integrating differential privacy and secure multi-party computation technologies based on federated learning, it ensures that data is not accessed or misused without authorization during cross-entity collaboration, and ensures the privacy, security, trust authentication, and dynamic management of the system during data circulation.
[0084] See Figure 1 Furthermore, the data privacy protection algorithm based on federated learning is as follows: First, a full-process data operation infrastructure based on a trusted data space is constructed to achieve secure interconnection between terminal devices, edge nodes, and cloud servers, providing a decentralized collaborative environment for subsequent privacy protection algorithms. Within the trusted data space, a consortium blockchain network composed of super edge nodes is deployed. Each SEN has edge computing, model aggregation, and blockchain verification functions, and initializes the global federated model parameters. ,in , Represented as an initialized high-dimensional parameter vector, Represented as model dimension, Represented as a model identifier, it generates initial identity credentials through a digital signature protocol. ,in, This represents the total number of participating devices. This is represented as an index of the number of participating devices. Represented as device The encrypted signature is used for authentication in subsequent communications, and the specific formula is expressed as follows:
[0085]
[0086] in, This represents a function that randomly initializes the model parameters. This is represented as a digital signature generation function. Represented as device A unique identifier, Represented as device public key, This is represented as a string concatenation operation. Model training is completed locally on the terminal device. Differential privacy technology protects sensitive user data, ensuring that data is available but not visible within a trusted data space. Download the latest global model from the edge nodes. Utilizing local datasets Conduct training. Represented as the index of the federated learning iteration number, used to calculate the local gradient. ,in The loss function is applied to the gradient. Norm clipping, specifically expressed by the formula:
[0087]
[0088] in, This is represented as the clipped local gradient vector. Represented as device The local gradient vector, Represented as Norm, This is represented as the gradient clipping threshold, with input Laplacian noise. Generate privacy-preserving gradients. This is represented as the Laplacian noise vector injected into the local gradient. Represented as a Laplace distribution, This is represented by gradient sensitivity and privacy budget, which control the strength of privacy protection. Secondly, local model updates are aggregated at the edge node layer, and blockchain technology is used to achieve trusted verification and traceability of parameters, supporting the auditability of the entire data operation process. Edge nodes receive privacy gradients uploaded by terminal devices. Verify digital signature To ensure the data source is legitimate, the federal average algorithm is applied, and the specific formula is as follows:
[0089]
[0090]
[0091] in, Represented as the first Global model parameters of the wheel, Represented as the learning rate, Represented as the first In the next iteration, the global model parameters are updated. Secondly, a federated learning model is used to generate personalized recommendations in real time at the edge layer. This combines user behavior data with global trend data to achieve value co-creation. The edge nodes then load the latest model. According to the user Local behavioral data Calculate the interest vector :
[0092]
[0093] in, This is represented as the model inference function. Then, it reads from the blockchain and merges the global hotspot vector to generate a hybrid recommendation score. The specific formula is as follows:
[0094]
[0095] in, Represented as user Recommendation scores for trending information Represented as personalized weights, Represented as user Interest vector, Represented as a global hotspot vector, the model parameters and recommendation results are finally permanently stored on the blockchain, supporting data value sharing and auditing by multiple parties, and building a sustainable operating ecosystem. The specific formula is as follows:
[0096]
[0097] in, Represented as in the first Blockchain data blocks generated during the federated learning process Represented as the set of feedback vectors from all users, Represented as the first The hash value of a blockchain data block.
[0098] See Figure 1 Furthermore, the system operation and monitoring module monitors the system's operating status, data flow, and log records in real time, and interacts with users to exchange information and control commands, ensuring the platform's continuous, efficient, and stable operation and enabling timely detection and handling of anomalies.
[0099] In practical use, firstly, the data acquisition and transmission module collects raw data from multiple data sources and transmits it securely, ensuring that the data enters the system in real time, accurately, and securely. Secondly, the data aggregation and fusion module includes a multi-source data integration unit and a data fusion analysis unit. The multi-source data integration unit cleans, standardizes, and structures the diverse data to ensure data consistency and high quality, while the data fusion analysis unit classifies, fuses, and analyzes the integrated data to ensure efficient extraction and utilization of data value. Then, the standards management and interoperability module is used to formulate, manage, and execute data standards and interface protocols, ensuring interconnectivity and compatibility between modules and different data systems. Finally, the data circulation and sharing module includes a data circulation management unit and a data utilization and operation unit. The circulation management unit proposes a data circulation management algorithm based on blockchain technology to achieve tamper-proof recording, transparent supervision, and full-process tracking of data during cross-domain data circulation, ensuring the security and trustworthiness of data sharing and transfer. The data utilization and operation unit is used for the commercial development and operation management of shared data, ensuring the maximum utilization of data resources and the realization of value co-creation. Then, the security and trust management module proposes a data privacy protection algorithm based on federated learning to implement distributed authentication, dynamic access control, and cross-domain data circulation privacy protection, ensuring the security, trustworthiness, and privacy protection of data throughout the entire process. Finally, the system operation and monitoring module is used to monitor and manage the system's operating status and data flow in real time, and to interact with users with information and control commands to ensure the stable and efficient operation of the system.
[0100] Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A full-process data operation and value co-creation system based on a trusted data space, comprising a data acquisition and transmission module, a data aggregation and fusion module, a standards management and interoperability module, a data circulation and sharing module, a security and trusted control module, and a system operation and monitoring module, characterized in that: The data acquisition and transmission module is used to collect raw data from multiple data sources and transmit it securely; the data aggregation and fusion module is used to clean, standardize, structure, and analyze multi-source data; the standards management and interoperability module is used to formulate data standards and interface protocols to ensure interconnectivity; the data circulation and sharing module includes a data circulation management unit and a data utilization and operation unit. The data circulation management unit proposes a data circulation management algorithm based on blockchain technology to achieve tamper-proof recording, transparent supervision, and full-process tracking of cross-domain data circulation. The data utilization and operation unit is used for commercial development and value co-creation of shared data; the security and trust management module proposes a data privacy protection algorithm based on federated learning to implement distributed authentication, dynamic access control, and privacy protection; the system operation and monitoring module is used to monitor the system's operating status and user interaction in real time. The data circulation management algorithm based on blockchain technology constructs a trusted data space based on the Ethereum blockchain. It utilizes a distributed ledger, Solidity smart contracts, IPFS two-stage encrypted AES256 symmetric encryption, and ECIES asymmetric encryption keys. The specific formula is as follows: , , ,in, Represented as ciphertext after symmetric encryption. Represented as raw data, Represented as Advanced Encryption Standard, Represented as a symmetric encryption key, Represented as the ciphertext after asymmetric encryption. Represented as an elliptic curve integration encryption function, This represents the public key of the data owner. Represented as the IPFS content addressing hash function, it employs a logic gate combination calculation strategy and generates session keys through an improved ECDH protocol, achieving end-to-end traceability of cross-domain key distribution. The specific formula is as follows: , in, This is represented as a session key, used to encrypt communication between the data user and the data owner. This is represented as a hash-based message authentication code function, used to generate key derivation values. Represented as data user A temporary private key, used for key negotiation. This is represented as a random salt value, used to enhance key security and prevent replay attacks. Encrypted and written into the blockchain transaction , in, Represented as a blockchain transaction record, it is used to store the encrypted session key. This is represented as a smart contract function, used to write the encryption key to the blockchain. For timestamps, Indicated as a data user public key The function performs encryption; the data privacy protection algorithm based on federated learning constructs a terminal-edge-cloud architecture, deploys a consortium blockchain network, and achieves differential privacy protection through gradient pruning, Laplacian noise injection, and blockchain notarization, and integrates interest vectors to generate a hybrid recommendation score, the specific formula of which is... To achieve personalized recommendations, among which Represented as user Recommendation scores for trending information Represented as personalized weights, Represented as user Interest vector, Represented as a global hotspot vector; the data privacy protection algorithm based on federated learning first constructs a secure interconnection architecture from terminal to edge to cloud in a trusted data space, deploys a consortium blockchain network composed of multiple super edge nodes (SENs), each SEN has edge computing, model aggregation and blockchain verification functions, and the system initializes global model parameters. and through digital signature protocol for Taiwan device generates identity credentials Subsequently, each terminal device downloads the latest global model. Training is performed using a local dataset, and the calculated gradients are then analyzed. Apply Norm clipping and Laplacian noise injection yield local gradients that satisfy differential privacy. Edge nodes receive and verify the signatures and privacy gradients uploaded by devices, and perform secure federated averaging to update global parameters. .
2. The end-to-end data operation and value co-creation system based on a trusted data space as described in claim 1, characterized in that: The data circulation management unit proposes a data circulation management algorithm based on blockchain technology to achieve tamper-proof recording, transparent supervision, and full-process tracking of data during cross-domain data circulation. The security and trust management module proposes a data privacy protection algorithm based on federated learning to implement distributed authentication, dynamic access control, and privacy protection for cross-domain data circulation. The system operation and monitoring module is used to monitor and manage the system's operating status and data flow in real time, and to interact with users for information and control commands. The data circulation and sharing module includes a data circulation management unit and a data utilization and operation unit. The data circulation management unit proposes a data circulation management algorithm based on blockchain technology by deploying a distributed ledger and smart contract mechanism based on blockchain technology. The data utilization and operation unit constructs standardized data service interfaces and a flexible data development platform.
3. The end-to-end data operation and value co-creation system based on a trusted data space according to claim 2, characterized in that: The data acquisition and transmission module automatically collects data from various data sources and employs encryption and distributed transmission protocols.
4. The end-to-end data operation and value co-creation system based on a trusted data space according to claim 3, characterized in that: The data aggregation and fusion module includes a multi-source data integration unit and a data fusion analysis unit. The multi-source data integration unit adopts standardized interfaces and automated data preprocessing technology. The data fusion analysis unit adopts data normalization, cleaning, intelligent matching, and association rule analysis methods.
5. The end-to-end data operation and value co-creation system based on a trusted data space according to claim 4, characterized in that: The standard management and interoperability module establishes a unified data standard, metadata management, and semantic conversion mechanism.
6. The end-to-end data operation and value co-creation system based on a trusted data space according to claim 5, characterized in that: The security and trust management module proposes a data privacy protection algorithm based on federated learning, which integrates differential privacy and secure multi-party computation techniques based on federated learning technology.
7. A full-process data operation and value co-creation system based on a trusted data space according to claim 6, characterized in that: The system operation and monitoring module monitors the system's operating status, data flow, and log records in real time, and interacts with users to exchange information and control commands.
Citation Information
Patent Citations
Agricultural data security sharing method based on federal learning
CN120151029A
Federal learning CIM system information security protection method based on block chain and TEE
CN120337292A