Multi-subject data security exchange method and system based on trusted space
Through logistics knowledge graph and reinforcement learning-driven dynamic mask generation, lightweight encryption and edge device clipping homomorphic encryption, the problems of high computational overhead and insufficient privacy protection of traditional encryption algorithms on edge devices are solved, and the efficient, secure and compliant secure exchange of multi-subject data is achieved, improving the efficiency and security of data exchange in multimodal transport scenarios.
Patent Information
- Application Number
- CN202511095168.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-06
- Publication Date
- 2025-09-30
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional homomorphic encryption algorithms have high computational overhead and are difficult to run efficiently on edge devices. They have not designed lightweight clipping strategies for the weights of core logistics dimensions, resulting in the encryption process being unable to adapt to edge-side resource constraints, restricting real-time interaction and secure sharing of ciphertext data; masking technology does not fully incorporate dynamic factors, does not associate logistics scenario compliance requirements and data-sensitive attributes, and cannot adjust the privacy protection strength in real time; in the consensus process of multi-subject collaboration requests, voting weight allocation relies on static rules, resulting in a disconnect between authority decisions and actual credibility; existing methods do not consider the time decay characteristics of logistics data, and the screening of core feature sets does not combine the dynamic association between current time and feature collection time, resulting in non-time-sensitive features interfering with the accuracy of data enhancement and secure exchange.
By building an association model through the logistics knowledge graph, the credibility score of the graph embedding calculation subject is calculated, and the logistics desensitization algorithm is combined to generate a dynamic mask. The reinforcement learning-driven authorization algorithm is used to dynamically allocate access rights, perform lightweight encryption and parallel processing, and combine edge device clipping, homomorphic encryption operators and graph neural networks to detect abnormal paths and generate data leakage audit reports.
It realizes efficient and secure exchange of multi-subject data on edge devices, dynamically adjusts the privacy protection strength, improves the anti-tampering ability of multi-signature approval, removes non-time-sensitive interference, ensures the timing accuracy of data exchange, reduces the risk of privacy leakage, and supports compliance supervision and collaborative operations in multimodal transport scenarios.
Smart Images

Figure CN120729501A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security, and in particular to a multi-agent data security exchange method and system based on a trusted space. Background Art
[0002] With the deepening of multimodal transport models in the logistics field, multi-agent collaborative operation scenarios are becoming increasingly complex, and the secure exchange of heterogeneous logistics data such as transportation tracks, warehousing records, equipment sensor data, enterprise qualification information and regulatory rules texts has become a core demand.
[0003] Traditional homomorphic encryption algorithms have high computational overhead and are difficult to run efficiently on edge devices. They also fail to design lightweight trimming strategies for the weights of core logistics dimensions, resulting in the encryption process being unable to adapt to edge-side resource constraints, restricting real-time interaction and secure sharing of ciphertext data. Masking technology does not fully incorporate dynamic factors, does not associate logistics scenario compliance requirements and data-sensitive attributes, and cannot adjust privacy protection strength in real time. Hidden field processing relies solely on a single hash or noise mechanism, lacks multi-layer protection, and has a high risk of privacy leakage.
[0004] In the consensus process of multi-party collaborative requests, the allocation of voting weights relies on static rules, resulting in a disconnect between authority decisions and actual credibility. The approval process is vulnerable to tampering attacks, and the parallel processing capabilities of multi-party voting opinions are insufficient, making it difficult to support efficient multi-signature approval result output.
[0005] In the feature processing of lightweight encrypted data sets, existing methods do not consider the time decay characteristics of logistics data, and the screening of core feature sets does not combine the dynamic correlation between the current time and the feature collection time, resulting in non-time-sensitive features interfering with the accuracy of data enhancement and secure exchange.
[0006] These issues make it difficult to balance security and efficiency in multi-agent data exchange, leading to high risks of privacy leakage, delayed consensus decision-making, and susceptibility to tampering. These factors hinder data-driven compliance monitoring and collaborative operations in multimodal transport scenarios. Therefore, there is an urgent need to develop a secure multi-agent data exchange method that combines edge computing power, dynamic privacy protection, efficient consensus approval, and timely feature screening to meet the complex demands of logistics scenarios. Summary of the Invention
[0007] The purpose of the present invention is to provide a multi-agent data security exchange method based on a trusted space.
[0008] To achieve the above object, the present invention is implemented according to the following technical solutions: The present invention comprises the following steps: Collect logistics subject data, organizational data, compliance rules data, and subject behavior data, and build an association model through the logistics knowledge graph to perform graph embedding and calculate the subject credibility score; the subjects include shippers, transporters, hub parties, acceptance parties, regulators, and compliance parties; Based on the subject credibility score and the shipper's waybill data and the acceptance party's data, the privacy and business areas are separated by a logistics desensitization algorithm to train the adversarial generative network to output a dynamic mask. Based on the long-tail distribution characteristics of structured data, enhanced data is generated through dynamic layering. The enhanced data is then associated with the transportation trajectory and the acceptance party's inspection characteristics to obtain a multimodal transport protection compliance dataset. Based on the subject's credibility score, a reinforcement learning-driven authorization algorithm is used to dynamically allocate access rights and generate instructions. Based on multi-subject collaboration requests, a consensus algorithm is used to process votes from regulators, hubs, compliance parties, and acceptance parties in parallel to obtain a multi-signature approval result. Based on the heterogeneous logistics data, the term graph alignment algorithm is used to map it into standard terms and lightly encrypt it, outputting a standardized encrypted data set. The encrypted data set is pruned by the homomorphic encryption operator on the edge device to obtain an encrypted feature vector. Based on the data access operation chain, graph neural networks are used to detect abnormal paths and output warning signals; based on the full-link records, time-space fingerprint hashing and Merkle tree reverse tracing are used to generate data leakage audit reports.
[0009] Furthermore, a method for constructing an association model through a logistics knowledge graph to perform graph embedding and calculate the subject credibility score includes: The logistics knowledge graph includes four types of nodes, including logistics subject nodes, organization nodes, compliance rule nodes, and subject behavior nodes. The cooperation and qualification associations of the four types of nodes are connected, and the nodes directly associated with the target node are regarded as neighbors. The entity data of the four types of nodes are weighted based on the dimension weights and integrated into the features extracted by graph embedding. The credibility of the neighbors is weighted and added by the association weights. The node attributes and association relationships are output as the subject credibility score. The formula is: , in, Indicator i The overall credibility score of For the d Dimension basic data, is the graph embedding feature of the d-th dimension in the knowledge graph, Indicates the d The k-th penalty factor of dimension, For the d Dimensional risk factor, Indicates the d The importance weight of the dimension data, Indicatori With neighbors j The association weight of 、 、 is the dimension enhancement coefficient, is the neighbor influence coefficient, is the risk compression coefficient, is the regularized minimum.
[0010] Furthermore, a method for training an adversarial generation network to output a dynamic mask by segmenting privacy and business areas using a logistics desensitization algorithm includes: Based on the dimensional differences between the logistics subject data and the masked data, the logistics desensitization algorithm divides the business feature retention area and the privacy hiding area. The logistics subject data includes: logistics subject qualifications and credit data; According to the subject's credibility, the adversarial training is adjusted and the dynamic mask is generated by strengthening the sensitive information hiding through privacy constraints. The formula is: , in, is the activation function, is the complementary term of credibility, , is the gradient accumulation of multiple batches of data, b is the batch index, is the gradient derivative with respect to the mask M, represents the logarithm of the output of the GAN discriminator D, represents the weight coefficient of privacy constraint, is the privacy loss function, the more fields are exposed The larger the value of Indicates the i The gradient of the mask of the field with respect to the privacy loss, is a very small number, To accumulate the differences in data dimensions, d is the dimension index, For the d Dimensional business data, For the d dimensional masked data, is the regularized small amount; Based on the dynamic mask, fields that meet the public attributes of the logistics business and whose subject credibility is higher than the credibility threshold are determined as exposed fields. Conversely, they are considered hidden fields. The exposed fields retain private data. The hidden fields are transformed by hash encryption basis and fused with dynamic Gaussian noise to output mask data. The formula is: , in, is the masked data of the final output, is the original privacy data, For basic privacy transformation, is the noise intensity coefficient, is the cumulative number of exposed fields in the mask, is the regularization constant, is Gaussian standard noise; Privacy is enhanced through time locks, sandbox environments, and waybill hash binding strategies, and strictness is dynamically determined by credibility. The formula is: , in, Represents the initial baseline noise intensity calibrated by the business scenario, is the constraint enhancement coefficient, is the credible threshold; The time lock controls the timing of permission effectiveness by setting a time threshold for accessing or decrypting hidden fields. The sandbox environment builds an independent and secure execution space to isolate the hash encryption and noise fusion operations of the hidden fields. The waybill hash binding strategy associates the hidden field with the waybill hash value.
[0011] Furthermore, the method for obtaining a multimodal transport protection compliance dataset by associating the enhanced data with the transport trajectory and the acceptance party's inspection characteristics includes: Based on the long-tail distribution characteristics of structured data, the frequency, long-tail weighted index, spatiotemporal similarity, historical compliance rate, and business rules for transportation trajectory and inspection characteristics of the structured data are used to initially divide the waybill data and transportation trajectory into levels. The weights of each level are calculated in real time and the levels are dynamically adjusted to generate enhanced data. The structured data includes waybill data, transportation trajectory, inspection records, and logistics entity qualifications and credit data. The formula for generating enhanced data is: , in, For the k Enhanced output of class data, For the k The original input of the class data represents the regular class sub-data extracted from the structured data, which is enhanced by the long-tail distribution characteristics. For the k The frequency of the class at level m, For the k The total frequency of the class across all N levels, is the long-tail weighted index of the mth level, For the k The spatiotemporal similarity of classes at the mth level, For the k Historical compliance rates for class data, is the global average frequency of the p-th category data, Based on transport trajectory and inspection characteristics and the business rule interpolator, is the business rule parameter for interpolation; The enhanced data is used as input, and the compliance correlation score is output by associating the transporter's transport trajectory and the acceptance party's receipt characteristics. , the associated data with compliance association scores greater than the compliance threshold is used as the multimodal protection compliance dataset, and the formula is: , in, is the real trajectory data, is the real acceptance characteristic data, For the k The p-th dimension feature of the class data enhancement output, is the regularized small quantity, is the spatial distance between the trajectory and the acceptance point, is the time difference between trajectory and acceptance, is the time difference scaling factor, is the scaling factor of the q-th dimension feature, i is the trajectory number, j is the acceptance party number, and k is the rule enhancement class number.
[0012] Furthermore, a method for dynamically allocating access rights and generating instructions by driving an authorization algorithm through reinforcement learning includes: By building sensitive classification rules based on waybill information, logistics entity qualifications and credit data, and historical compliance rates, resource sensitivity levels are divided. Real-time statistics are collected on the intervals between entity data accesses to obtain the duration of silence. By extracting the timestamps and spatial coordinates of the waybill's transport trajectory, the time-space deviation is calculated to obtain time-space constraints. Based on the logistics scenario learning reinforcement learning algorithm, the subject credibility, resource sensitivity level, silence duration and time and space constraints are taken as states. Through iterative optimization of the learning rate, the access permission allocation and instructions are dynamically output in combination with the scenario rules. The formula is: , in, is the learning rate, 、 、 is the weight coefficient, F is the real-time credibility of the subject, For the duration of silence, is the permission decision for the j-th resource, is the resource sensitivity level, Lat is the authorization delay, is the operation time difference, is the spatial distance between the subject and the resource, is the maximum value of the next state, Score the value of performing the authorized action a in state s; The value scoring includes dynamic authority allocation and instructions; Based on the consensus approval process of multi-subject collaboration requests, the voting weights of multiple subjects such as regulators and hub parties are allocated according to the qualifications of the logistics subjects, historical compliance rates and resource sensitivity levels. The collaboration requests are verified in parallel in the spatiotemporal dimensions based on the transportation trajectory and operation time, and the hash chain records the weight allocation and spatiotemporal verification data. The voting opinions of regulators, hubs, compliance parties and acceptance parties are processed in parallel to output an efficient and tamper-resistant weighted consent rate.
[0013] When the weighted approval rate is higher than the preset compliance approval threshold, the multi-signature approval result for opening access rights is output; otherwise, it is judged to be unsuccessful and access rights are restricted.
[0014] Furthermore, a method for obtaining an encrypted feature vector by performing a clipping homomorphic encryption operator based on an edge device includes: Homomorphic encryption operators are tailored based on edge device computing power constraints. Dynamic semantic matching and low-dimensional data compensation mapping are used to output standard terms based on heterogeneous logistics data, which are then combined with recursive hash chains to generate lightweight encrypted datasets. The heterogeneous logistics data includes transportation trajectories, warehousing records, equipment sensor data, enterprise qualification information, and regulatory rules. The formula for lightweight encryption of data sets is: , in, For heterogeneous logistics data, For the standard term map, is the weight of the core dimension of logistics, is a low-dimensional compensation switch, is the low-dimensional compensation coefficient, is the regularization parameter, is a recursive hash chain, is the hash function, k is the initial key, For lightweight encryption dataset; According to the lightweight encrypted data set, the homomorphic encryption is modulated dynamically by position, and the current time is and feature collection time The time difference is an exponential decay function Weighted, filter out features in the core feature set S whose weight is greater than the set threshold, and output encrypted feature vectors that support ciphertext operations , the formula is: , in, Locating data for edge devices, 、 is the basic parameter of homomorphic encryption, 、 is the position modulation coefficient, is homomorphic noise, S is the core feature set, It is a feature filtering switch; the core feature set includes transportation trajectory timestamp, cargo temperature, acceptance compliance signature, cargo type code and rule clearance threshold.
[0015] Furthermore, the method for obtaining early warning signals and generating a data leakage audit report includes: Based on the data access operation chain, a graph neural network is used to build a correlation map of users, devices, and data operations. It learns the path characteristics of normal access patterns, detects abnormal paths such as intensive access to sensitive waybills during non-working hours and abnormal cross-regional serial data, and outputs risk warning signals in real time. Based on the operation time, geographic coordinates, access subject, and data fingerprint recorded in the entire link, a full-link hash authentication chain is generated by binding time and location information through spatiotemporal fingerprint hashing and Merkle tree; The hash value of the full-link hash authentication chain is generated by the data content, access sequence and authentication chain structure. When it does not match the preset original hash, it is determined to be an abnormal hash value and the data is suspected of being leaked. The sources of the abnormal hash value include data tampering, non-working hours, cross-regional access sequence destruction and Merkle tree node chain changes that cause the authentication chain structure to break. The leakage path is traced back through the abnormal hash value to locate the tampered or illegally externalized nodes and sequence in the data access chain, and output a data leakage audit report containing the leakage path and the subject involved.
[0016] In a second aspect, a multi-agent data security exchange system based on a trusted space includes: Data collection and credibility calculation module: used to collect logistics subject data, organizational data, compliance rules data, and subject behavior data, and build an association model through the logistics knowledge graph to perform graph embedding and calculate the subject credibility score; Data desensitization and enhancement module: This module is used to train an adversarial generative network to output dynamic masks based on the subject credibility score, the shipper's waybill data, and the acceptor's data. This module uses a logistics desensitization algorithm to segment privacy and business areas, train an adversarial generative network, and output dynamic masks. This module also generates enhanced data based on the long-tail distribution characteristics of structured data. This module then associates the transport trajectory with the acceptance party's inspection characteristics to obtain a multimodal transport protection compliance dataset. Permission authorization and consensus approval module: This module is used to dynamically allocate access rights and generate instructions based on the subject's credibility score through a reinforcement learning-driven authorization algorithm. Based on multi-subject collaboration requests, it uses a consensus algorithm to parallelly process votes from regulators, hubs, compliance parties, and acceptance parties to obtain multi-signature approval results. Term alignment and encryption module: This module is used to map heterogeneous logistics data into standard terms using a term graph alignment algorithm, and then lightweight encrypt the output of a standardized encrypted data set. The encrypted feature vector is obtained by tailoring the homomorphic encryption operator on the edge device. Anomaly detection and audit tracing module: used to detect abnormal paths and output warning signals based on the data access operation chain through graph neural networks, and generate data leakage audit reports based on full-link records through spatiotemporal fingerprint hashing and Merkle tree reverse tracing.
[0017] The beneficial effects of the present invention are: The present invention is a method and system for securely exchanging multi-agent data based on a trusted space. Compared with the prior art, the present invention has the following technical effects: The present invention can break through the bottleneck of traditional homomorphic encryption overhead to ensure real-time and secure interaction of ciphertext data through data collection, subject credibility scoring, acquisition of multimodal transport protection compliance data set, allocation of permissions and instructions, acquisition of multi-signature approval results, logistics data encryption, and tracing of anomalies to generate audit reports. It can also build multi-layer barriers to reduce the risk of leakage, achieve efficient tamper-resistant multi-signature decision-making, remove non-time-sensitive interference to ensure the timing accuracy of data enhancement and secure exchange, and collaborate with multiple technologies to resolve the contradiction between security and efficiency of multimodal transport data exchange, promote compliance supervision and collaborative operation upgrades, and provide full-process technical support and reliability assurance for the secure exchange of multi-subject data. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 This is a flow chart of the steps of a multi-agent data secure exchange method based on a trusted space of the present invention. DETAILED DESCRIPTION
[0019] The present invention will be further described below through specific examples. The illustrative examples and descriptions of the present invention are used to explain the present invention but are not intended to limit the present invention.
[0020] The present invention provides a method and system for securely exchanging multi-agent data based on a trusted space, comprising the following steps: like Figure 1 As shown, in this embodiment, the following steps are included: Collect logistics subject data, organizational data, compliance rules data, and subject behavior data, and build an association model through the logistics knowledge graph to perform graph embedding and calculate the subject credibility score; the subjects include shippers, transporters, hub parties, acceptance parties, regulators, and compliance parties; In the actual assessment, the domestic industrial steel logistics transportation of XXXX was studied. The shipping number was LP2025xxx0701, with a cargo value of 5 million yuan and a weight of 30 tons. The case involved shipper D, cargo owner, transporter A, supervisor B, acceptance C, hub E, and compliance party F. Transporter A had Class A qualifications, 120 cooperative shipping orders, a historical compliance rate of 95%, and steel transportation accounted for 60% of the total in the past three years. Shipper D had an annual shipment volume of 500,000 tons, of which industrial steel accounted for 85%. Supervisor B had regional logistics compliance supervision qualifications and an annual review coverage rate of 98%. Using a graph embedding algorithm to map the associated data into vectors, and calculating vector similarity, the credibility score of transporter A was 92. Based on the subject credibility score and the shipper's waybill data and the acceptance party's data, the privacy and business areas are separated by a logistics desensitization algorithm to train the adversarial generative network to output a dynamic mask. Based on the long-tail distribution characteristics of structured data, enhanced data is generated through dynamic layering. The enhanced data is then associated with the transportation trajectory and the acceptance party's inspection characteristics to obtain a multimodal transport protection compliance dataset. In the actual assessment, the first 6 digits of the area code and the last 4 digits of the ID card of the cargo owner 1101011990XXXX1234 were extracted, and the middle segment was desensitized, with the mask being 110101****1234. The contract value of the cargo was RMB 5 million, and it was processed according to the industry fluctuation range of ±10%, with the mask being RMB 4.5-5.5 million. The telephone number of the hub operator E was 159****56781, and the operator identification 159 and the last digit feature 56781 were extracted. The number distribution pattern of the adversarial network learning number was masked to 158****67892, retaining the operator and the last digit features. The region retains the transport route and cargo classification as industrial steel, material Q345B, weight 30 tons. The transport trajectory is as follows: departure from a certain port, timestamp 7:00, weight 30.0 tons, arrival at a certain transfer station, timestamp 24:00, weight 29.9 tons, transit loss 0.1 tons, and receipt at a certain terminal, timestamp 48:00, weight 29.8 tons. The inspection characteristics of the acceptance party C are 99.2% intactness, -0.2% weight deviation, and 0 surface damage. After matching the waybill number LP2025xxx0701, the data is integrated into a compliant dataset containing the route, timeliness, weight change, and inspection results. Based on the subject's credibility score, a reinforcement learning-driven authorization algorithm is used to dynamically allocate access rights and generate instructions. Based on multi-subject collaboration requests, a consensus algorithm is used to process votes from regulators, hubs, compliance parties, and acceptance parties in parallel to obtain a multi-signature approval result. In the actual evaluation, reinforcement learning inputs were transporter A's credibility of 92 and a resource sensitivity level. After 15 iterations of the reward function, the output policy was to allow access to the plaintext fields of general-level fields (route, weight, and integrity), only allow access to the sensitive-level fields (operator phone mask 158****67892), and deny access to the core-level fields (cargo value range and ID mask). Supervisor B, acceptance party C, hub party E, and compliance party F voted on transporter A's access to the transfer terminal operation records. When the weighted approval rate exceeded 80%, permission was granted. Based on the heterogeneous logistics data, the term graph alignment algorithm is used to map it into standard terms and lightly encrypt it, outputting a standardized encrypted data set. The encrypted data set is pruned by the homomorphic encryption operator on the edge device to obtain an encrypted feature vector. In the actual evaluation, the homomorphic encryption operator was trimmed, retaining the core functions of the hash module and dynamic semantic encoding. The hidden field value mask of 4.5-5.5 million was mapped to the standard terminology industrial steel transportation value range, and the low-dimensional compensation was 500±10% of the numerical feature. The ID card mask 110101****1234 was semantically matched by the area code plus the last digit to generate a regional feature vector. The operator's phone mask 158****67892 was encoded by the operator plus the last digit, retaining the communication characteristics. A recursive hash chain calculation was performed to generate an encrypted feature vector group. Based on the data access operation chain, graph neural networks are used to detect abnormal paths and output warning signals. Based on the full-link records, spatiotemporal fingerprint hashing and Merkle tree reverse tracing are used to generate data leakage audit reports. In the actual assessment, the access records showed that the supervisor B attempted to read the core-level fields, with a hash value deviation of 18%, triggering an alert and unauthorized access to the core privacy fields. The access time was 15:30, and the access subject B's permissions only allowed viewing of sensitive-level fields, posing a risk of unauthorized access to core privacy data.
[0021] In this embodiment, a method for constructing an association model through a logistics knowledge graph and performing graph embedding to calculate the subject credibility score includes: The logistics knowledge graph includes four types of nodes, including logistics subject nodes, organization nodes, compliance rule nodes, and subject behavior nodes. The cooperation and qualification associations of the four types of nodes are connected, and the nodes directly associated with the target node are regarded as neighbors. The entity data of the four types of nodes are weighted based on the dimension weights and integrated into the features extracted by graph embedding. The credibility of the neighbors is weighted and added by the association weights. The node attributes and association relationships are output as the subject credibility score. The formula is: , in, Indicator i The overall credibility score of For the d Dimension basic data, is the graph embedding feature of the d-th dimension in the knowledge graph, Indicates the d The k-th penalty factor of dimension, For the d Dimensional risk factor, Indicates the d The importance weight of the dimension data, Indicator i With neighbors j The association weight of 、 、 is the dimension enhancement coefficient, is the neighbor influence coefficient, is the risk compression coefficient, is the regularized minimum.
[0022] In this embodiment, the method of training an adversarial generation network to output a dynamic mask by segmenting privacy and business areas using a logistics desensitization algorithm includes: Based on the dimensional differences between the logistics subject data and the masked data, the logistics desensitization algorithm divides the business feature retention area and the privacy hiding area. The logistics subject data includes: logistics subject qualifications and credit data; According to the subject's credibility, the adversarial training is adjusted and the dynamic mask is generated by strengthening the sensitive information hiding through privacy constraints. The formula is: , in, is the activation function, is the complementary term of credibility, , is the gradient accumulation of multiple batches of data, b is the batch index, is the gradient derivative with respect to the mask M, represents the logarithm of the output of the GAN discriminator D, represents the weight coefficient of privacy constraint, is the privacy loss function, the more fields are exposed The larger the value of Indicates the i The gradient of the mask of the field with respect to the privacy loss, is a very small number, To accumulate the differences in data dimensions, d is the dimension index, For the d Dimensional business data, For the d dimensional masked data, is the regularized small amount; Based on the dynamic mask, fields that meet the public attributes of the logistics business and whose subject credibility is higher than the credibility threshold are determined as exposed fields. Conversely, they are considered hidden fields. The exposed fields retain private data. The hidden fields are transformed by hash encryption basis and fused with dynamic Gaussian noise to output mask data. The formula is: , in, is the masked data of the final output, is the original privacy data, For basic privacy transformation, is the noise intensity coefficient, is the cumulative number of exposed fields in the mask, is the regularization constant, is Gaussian standard noise; Privacy is enhanced through time locks, sandbox environments, and waybill hash binding strategies, and strictness is dynamically determined by credibility. The formula is: , in, Represents the initial baseline noise intensity calibrated by the business scenario, is the constraint enhancement coefficient, is the credible threshold; The time lock controls the timing of permission effectiveness by setting a time threshold for accessing or decrypting hidden fields. The sandbox environment builds an independent and secure execution space to isolate the hash encryption and noise fusion operations of the hidden fields. The waybill hash binding strategy associates the hidden field with the waybill hash value.
[0023] In this embodiment, the method for obtaining a multimodal transport protection compliance dataset by associating the enhanced data with the transport trajectory and the acceptance party's inspection characteristics includes: Based on the long-tail distribution characteristics of structured data, the frequency, long-tail weighted index, spatiotemporal similarity, historical compliance rate, and business rules for transportation trajectory and inspection characteristics of the structured data are used to initially divide the waybill data and transportation trajectory into levels. The weights of each level are calculated in real time and the levels are dynamically adjusted to generate enhanced data. The structured data includes waybill data, transportation trajectory, inspection records, and logistics entity qualifications and credit data. The formula for generating enhanced data is: , in, For the k Enhanced output of class data, For the k The original input of the class data represents the regular class sub-data extracted from the structured data, which is enhanced by the long-tail distribution characteristics. For the k The frequency of the class at level m, For the k The total frequency of the class across all N levels, is the long-tail weighted index of the mth level, For the k The spatiotemporal similarity of classes at the mth level, For the k Historical compliance rates for class data, is the global average frequency of the p-th category data, Based on transport trajectory and inspection characteristics and the business rule interpolator, is the business rule parameter for interpolation; The enhanced data is used as input, and the compliance correlation score is output by associating the transporter's transport trajectory and the acceptance party's receipt characteristics. , the associated data with compliance association scores greater than the compliance threshold is used as the multimodal protection compliance dataset, and the formula is: , in, is the real trajectory data, is the real acceptance characteristic data, For the k The p-th dimension feature of the class data enhancement output, is the regularized small quantity, is the spatial distance between the trajectory and the acceptance point, is the time difference between trajectory and acceptance, is the time difference scaling factor, is the scaling factor of the q-th dimension feature, i is the trajectory number, j is the acceptance party number, and k is the rule enhancement class number.
[0024] In this embodiment, the method for dynamically allocating access rights and generating instructions by using a reinforcement learning-driven authorization algorithm includes: By building sensitive classification rules based on waybill information, logistics entity qualifications and credit data, and historical compliance rates, resource sensitivity levels are divided. Real-time statistics are collected on the intervals between entity data accesses to obtain the duration of silence. By extracting the timestamps and spatial coordinates of the waybill's transport trajectory, the time-space deviation is calculated to obtain time-space constraints. Based on the logistics scenario learning reinforcement learning algorithm, the subject credibility, resource sensitivity level, silence duration and time and space constraints are taken as states. Through iterative optimization of the learning rate, the access permission allocation and instructions are dynamically output in combination with the scenario rules. The formula is: , in, is the learning rate, 、 、 is the weight coefficient, F is the real-time credibility of the subject, For the duration of silence, is the permission decision for the j-th resource, is the resource sensitivity level, Lat is the authorization delay, is the operation time difference, is the spatial distance between the subject and the resource, is the maximum value of the next state, Score the value of performing the authorized action a in state s; The value scoring includes dynamic authority allocation and instructions; Based on the consensus approval process for multi-party collaboration requests, the voting weights of multiple parties such as regulators and hub parties are allocated according to the qualifications of the logistics entities, historical compliance rates, and resource sensitivity levels. The collaboration requests are verified in parallel in the spatiotemporal dimensions based on the transportation trajectory and operation time, and the weight allocation and spatiotemporal verification data are recorded in the hash chain. The voting opinions of regulators, hub parties, compliance parties, and acceptance parties are processed in parallel to output an efficient and tamper-resistant weighted consent rate. When the weighted approval rate is higher than the preset compliance approval threshold of 80%, the multi-signature approval result of opening access rights is output; otherwise, it is judged as failed and access rights are restricted.
[0025] In this embodiment, a method for obtaining an encrypted feature vector by performing a clipping homomorphic encryption operator based on an edge device includes: Homomorphic encryption operators are tailored based on edge device computing power constraints. Dynamic semantic matching and low-dimensional data compensation mapping are used to output standard terms based on heterogeneous logistics data, which are then combined with recursive hash chains to generate lightweight encrypted datasets. The heterogeneous logistics data includes transportation trajectories, warehousing records, equipment sensor data, enterprise qualification information, and regulatory rules. The formula for lightweight encryption of data sets is: , in, For heterogeneous logistics data, For the standard term map, is the weight of the core dimension of logistics, is a low-dimensional compensation switch, is the low-dimensional compensation coefficient, is the regularization parameter, is a recursive hash chain, is the hash function, k is the initial key, For lightweight encryption dataset; According to the lightweight encrypted data set, the homomorphic encryption is modulated dynamically by position, and the current time is and feature collection time The time difference is an exponential decay function Weighted, filter out features in the core feature set S whose weight is greater than the set threshold, and output encrypted feature vectors that support ciphertext operations , the formula is: , in, Locating data for edge devices, 、 is the basic parameter of homomorphic encryption, 、 is the position modulation coefficient, is homomorphic noise, S is the core feature set, It is a feature filtering switch; the core feature set includes transportation trajectory timestamp, cargo temperature, acceptance compliance signature, cargo type code and rule clearance threshold.
[0026] In this embodiment, the method for obtaining an early warning signal and generating a data leakage audit report includes: Based on the data access operation chain, a graph neural network is used to build a correlation map of users, devices, and data operations. It learns the path characteristics of normal access patterns, detects abnormal paths such as intensive access to sensitive waybills during non-working hours and abnormal cross-regional serial data, and outputs risk warning signals in real time. Based on the operation time, geographic coordinates, access subject, and data fingerprint recorded in the entire link, a full-link hash authentication chain is generated by binding time and location information through spatiotemporal fingerprint hashing and Merkle tree; The hash value of the full-link hash authentication chain is generated by the data content, access sequence and authentication chain structure. When it does not match the preset original hash, it is determined to be an abnormal hash value and the data is suspected of being leaked. The sources of the abnormal hash value include data tampering, non-working hours, cross-regional access sequence destruction and Merkle tree node chain changes that cause the authentication chain structure to break. The leakage path is traced back through the abnormal hash value to locate the tampered or illegally externalized nodes and sequence in the data access chain, and output a data leakage audit report containing the leakage path and the subject involved.
[0027] In a second aspect, a multi-agent data security exchange system based on a trusted space includes: Data collection and credibility calculation module: used to collect logistics subject data, organizational data, compliance rules data, and subject behavior data, and build an association model through the logistics knowledge graph to perform graph embedding and calculate the subject credibility score; Data desensitization and enhancement module: This module is used to train an adversarial generative network to output dynamic masks based on the subject credibility score, the shipper's waybill data, and the acceptor's data. This module uses a logistics desensitization algorithm to segment privacy and business areas, train an adversarial generative network, and output dynamic masks. This module also generates enhanced data based on the long-tail distribution characteristics of structured data. This module then associates the transport trajectory with the acceptance party's inspection characteristics to obtain a multimodal transport protection compliance dataset. Permission authorization and consensus approval module: This module is used to dynamically allocate access rights and generate instructions based on the subject's credibility score through a reinforcement learning-driven authorization algorithm. Based on multi-subject collaboration requests, it uses a consensus algorithm to parallelly process votes from regulators, hubs, compliance parties, and acceptance parties to obtain multi-signature approval results. Term alignment and encryption module: This module is used to map heterogeneous logistics data into standard terms using a term graph alignment algorithm, and then lightweight encrypt the output of a standardized encrypted data set. The encrypted feature vector is obtained by tailoring the homomorphic encryption operator on the edge device. Anomaly detection and audit tracing module: used to detect abnormal paths and output warning signals based on the data access operation chain through graph neural networks, and generate data leakage audit reports based on full-link records through spatiotemporal fingerprint hashing and Merkle tree reverse tracing.
[0028] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A multi-agent data security exchange method based on a trusted space, characterized in that: The following steps are involved: Collect logistics subject data, organizational data, compliance rules data, and subject behavior data, and build an association model through the logistics knowledge graph to perform graph embedding and calculate the subject credibility score; the subjects include shippers, transporters, hub parties, acceptance parties, regulators, and compliance parties; The subject behavior data includes: waybill data, transportation track, and inspection records; Based on the subject credibility score and the shipper's waybill data and the acceptance party's data, the privacy and business areas are separated by a logistics desensitization algorithm to train the adversarial generative network to output a dynamic mask. Based on the long-tail distribution characteristics of structured data, enhanced data is generated through dynamic layering. The enhanced data is then associated with the transportation trajectory and the acceptance party's inspection characteristics to obtain a multimodal transport protection compliance dataset. Based on the subject's credibility score, a reinforcement learning-driven authorization algorithm is used to dynamically allocate access rights and generate instructions. Based on multi-subject collaboration requests, a consensus algorithm is used to process votes from regulators, hubs, compliance parties, and acceptance parties in parallel to obtain a multi-signature approval result. Based on the heterogeneous logistics data, the term graph alignment algorithm is used to map it into standard terms and lightly encrypt it, outputting a standardized encrypted data set. The encrypted data set is pruned by the homomorphic encryption operator on the edge device to obtain an encrypted feature vector. Based on the data access operation chain, graph neural networks are used to detect abnormal paths and output warning signals; based on the full-link records, time-space fingerprint hashing and Merkle tree reverse tracing are used to generate data leakage audit reports.
2. The method for secure multi-agent data exchange based on a trusted space according to claim 1, characterized in that: The method of constructing an association model through a logistics knowledge graph to perform graph embedding and calculate the subject credibility score includes: The logistics knowledge graph includes four types of nodes, including logistics subject nodes, organization nodes, compliance rule nodes, and subject behavior nodes. The cooperation and qualification associations of the four types of nodes are connected, and the nodes directly associated with the target node are regarded as neighbors. The entity data of the four types of nodes are weighted based on the dimension weights and integrated into the features extracted by graph embedding. The credibility of the neighbors is weighted and added by the association weights. The node attributes and association relationships are output as the subject credibility score. The formula is: , in, Representation Agency i The overall credibility score of For the d Dimension basic data, is the graph embedding feature of the d-th dimension in the knowledge graph, Indicates the d The k-th penalty factor of dimension, For the d Dimensional risk factor, Indicates the d The importance weight of the dimension data, Representation Agency i With neighbors j The association weight of 、 、 is the dimension enhancement coefficient, is the neighbor influence coefficient, is the risk compression coefficient, is the regularized minimum.
3. The method for secure multi-agent data exchange based on a trusted space according to claim 1, characterized in that: The method of training an adversarial generation network to output a dynamic mask by segmenting privacy and business areas through a logistics desensitization algorithm includes: Based on the dimensional differences between the logistics subject data and the masked data, the logistics desensitization algorithm divides the business feature retention area and the privacy hiding area. The logistics subject data includes: logistics subject qualifications and credit data; According to the subject's credibility, the adversarial training is adjusted and the dynamic mask is generated by strengthening the sensitive information hiding through privacy constraints. The formula is: , in, is the activation function, is the complementary term of credibility, , is the gradient accumulation of multiple batches of data, b is the batch index, is the gradient derivative with respect to the mask M, represents the logarithm of the output of the GAN discriminator D, represents the weight coefficient of privacy constraint, is the privacy loss function, the more fields are exposed The larger the value of Indicates the i The gradient of the mask of the field with respect to the privacy loss, is a very small number, To accumulate the differences in data dimensions, d is the dimension index, For the d Dimensional business data, For the d dimensional masked data, is the regularized small amount; Based on the dynamic mask, fields that meet the public attributes of the logistics business and whose subject credibility is higher than the credibility threshold are determined as exposed fields. Conversely, they are considered hidden fields. The exposed fields retain private data. The hidden fields are transformed by hash encryption basis and fused with dynamic Gaussian noise to output mask data. The formula is: , in, is the masked data of the final output, is the original privacy data, For basic privacy transformation, is the noise intensity coefficient, is the cumulative number of exposed fields in the mask, is the regularization constant, is Gaussian standard noise; Privacy is enhanced through time locks, sandbox environments, and waybill hash binding strategies, and strictness is dynamically determined by credibility. The formula is: , in, Represents the initial baseline noise intensity calibrated by the business scenario, is the constraint enhancement coefficient, is the credible threshold; The time lock controls the timing of permission effectiveness by setting a time threshold for accessing or decrypting hidden fields. The sandbox environment builds an independent and secure execution space to isolate the hash encryption and noise fusion operations of the hidden fields. The waybill hash binding strategy associates the hidden field with the waybill hash value.
4. The method for secure multi-agent data exchange based on a trusted space according to claim 1, characterized in that: The method for obtaining a multimodal transport protection compliance dataset by associating the enhanced data with the transport trajectory and the acceptance party's inspection characteristics includes: Based on the long-tail distribution characteristics of structured data, the frequency, long-tail weighted index, spatiotemporal similarity, historical compliance rate, and business rules for transportation trajectory and inspection characteristics of the structured data are used to initially divide the waybill data and transportation trajectory into levels. The weights of each level are calculated in real time and the levels are dynamically adjusted to generate enhanced data. The structured data includes waybill data, transportation trajectory, inspection records, and logistics entity qualifications and credit data. The formula for generating enhanced data is: , in, For the k Enhanced output of class data, For the k The original input of the class data represents the regular class sub-data extracted from the structured data, which is enhanced by the long-tail distribution characteristics. For the k The frequency of the class at level m, For the k The total frequency of the class across all N levels, is the long-tail weighted index of the mth level, For the k The spatiotemporal similarity of classes at level m, For the k Historical compliance rates for class data, is the global average frequency of the p-th category data, Based on transport trajectory and inspection characteristics and the business rule interpolator, is the business rule parameter for interpolation; The enhanced data is used as input, and the compliance correlation score is output by associating the transporter's transport trajectory and the acceptance party's receipt characteristics. , the associated data with compliance association scores greater than the compliance threshold is used as the multimodal protection compliance dataset, and the formula is: , in, is the real trajectory data, is the real acceptance characteristic data, For the k The p-th dimension feature of the class data enhancement output, is the regularized small quantity, is the spatial distance between the trajectory and the acceptance point, is the time difference between trajectory and acceptance, is the time difference scaling factor, is the scaling factor of the q-th dimension feature, i is the trajectory number, j is the acceptance party number, and k is the rule enhancement class number.
5. The method for secure multi-agent data exchange based on a trusted space according to claim 1, characterized in that: The method of dynamically allocating access rights and generating instructions by using a reinforcement learning-driven authorization algorithm includes: By building sensitive classification rules based on waybill information, logistics entity qualifications and credit data, and historical compliance rates, resource sensitivity levels are divided. Real-time statistics are collected on the intervals between entity data accesses to obtain the duration of silence. By extracting the timestamps and spatial coordinates of the waybill's transport trajectory, the time-space deviation is calculated to obtain time-space constraints. Based on the logistics scenario learning reinforcement learning algorithm, the subject credibility, resource sensitivity level, silence duration and time and space constraints are taken as states. Through iterative optimization of the learning rate, the access permission allocation and instructions are dynamically output in combination with the scenario rules. The formula is: , in, is the learning rate, 、 、 is the weight coefficient, F is the real-time credibility of the subject, For the duration of silence, is the permission decision for the j-th resource, is the resource sensitivity level, Lat is the authorization delay, is the operation time difference, is the spatial distance between the subject and the resource, is the maximum value of the next state, Score the value of performing the authorized action a in state s; The value scoring includes dynamic authority allocation and instructions; Based on the consensus approval process for multi-party collaboration requests, the voting weights of multiple parties such as regulators and hub parties are allocated according to the qualifications of the logistics entities, historical compliance rates, and resource sensitivity levels. The collaboration requests are verified in parallel in the spatiotemporal dimensions based on the transportation trajectory and operation time, and the weight allocation and spatiotemporal verification data are recorded in the hash chain. The voting opinions of regulators, hub parties, compliance parties, and acceptance parties are processed in parallel to output an efficient and tamper-resistant weighted consent rate. When the weighted approval rate is higher than the preset compliance approval threshold, the multi-signature approval result for opening access rights is output; otherwise, it is judged to be unsuccessful and access rights are restricted.
6. The method for secure multi-agent data exchange based on a trusted space according to claim 1, characterized in that: A method for obtaining an encrypted feature vector by performing a clipping homomorphic encryption operator based on an edge device includes: Homomorphic encryption operators are tailored based on edge device computing power constraints. Dynamic semantic matching and low-dimensional data compensation mapping are used to output standard terms based on heterogeneous logistics data, which are then combined with recursive hash chains to generate lightweight encrypted datasets. The heterogeneous logistics data includes transportation trajectories, warehousing records, equipment sensor data, enterprise qualification information, and regulatory rules. The formula for lightweight encryption of data sets is: , in, For heterogeneous logistics data, For the standard term map, is the weight of the core dimension of logistics, is a low-dimensional compensation switch, is the low-dimensional compensation coefficient, is the regularization parameter, is a recursive hash chain, is the hash function, k is the initial key, For lightweight encryption dataset; According to the lightweight encrypted data set, the homomorphic encryption is modulated dynamically by position, and the current time is and feature collection time The time difference is an exponential decay function Weighted, filter out features in the core feature set S whose weight is greater than the set threshold, and output encrypted feature vectors that support ciphertext operations , the formula is: , in, Locating data for edge devices, 、 is the basic parameter of homomorphic encryption, 、 is the position modulation coefficient, is homomorphic noise, S is the core feature set, It is a feature filtering switch; the core feature set includes transportation trajectory timestamp, cargo temperature, acceptance compliance signature, cargo type code and rule clearance threshold.
7. The method for secure multi-agent data exchange based on a trusted space according to claim 1, characterized in that: Methods for obtaining early warning signals and generating data breach audit reports include: Based on the data access operation chain, a graph neural network is used to build a correlation map of users, devices, and data operations. It learns the path characteristics of normal access patterns, detects abnormal paths such as intensive access to sensitive waybills during non-working hours and abnormal cross-regional serial data, and outputs risk warning signals in real time. Based on the operation time, geographic coordinates, access subject, and data fingerprint recorded in the entire link, a full-link hash authentication chain is generated by binding time and location information through spatiotemporal fingerprint hashing and Merkle tree; The hash value of the full-link hash authentication chain is generated by the data content, access sequence and authentication chain structure. When it does not match the preset original hash, it is determined to be an abnormal hash value and the data is suspected of being leaked. The sources of the abnormal hash value include data tampering, non-working hours, cross-regional access sequence destruction and Merkle tree node chain changes that cause the authentication chain structure to break. The leakage path is traced back through the abnormal hash value to locate the tampered or illegally externalized nodes and sequence in the data access chain, and output a data leakage audit report containing the leakage path and the subject involved.
8. A multi-agent data security exchange system based on a trusted space, used to execute the method according to any one of claims 1 to 7, characterized in that: include: Data collection and credibility calculation module: used to collect logistics subject data, organizational data, compliance rules data, and subject behavior data, and build an association model through the logistics knowledge graph to perform graph embedding and calculate the subject credibility score; Data desensitization and enhancement module: This module is used to train an adversarial generative network to output dynamic masks based on the subject credibility score, the shipper's waybill data, and the acceptor's data. This module uses a logistics desensitization algorithm to segment privacy and business areas, train an adversarial generative network, and output dynamic masks. This module also generates enhanced data based on the long-tail distribution characteristics of structured data. This module then associates the transport trajectory with the acceptance party's inspection characteristics to obtain a multimodal transport protection compliance dataset. Permission authorization and consensus approval module: This module is used to dynamically allocate access rights and generate instructions based on the subject's credibility score through a reinforcement learning-driven authorization algorithm. Based on multi-subject collaboration requests, it uses a consensus algorithm to parallelly process votes from regulators, hubs, compliance parties, and acceptance parties to obtain multi-signature approval results. Term alignment and encryption module: This module is used to map heterogeneous logistics data into standard terms using a term graph alignment algorithm, and then lightweight encrypt the output of a standardized encrypted data set. The encrypted feature vector is obtained by tailoring the homomorphic encryption operator on the edge device. Anomaly detection and audit tracing module: used to detect abnormal paths and output warning signals based on the data access operation chain through graph neural networks, and generate data leakage audit reports based on full-link records through spatiotemporal fingerprint hashing and Merkle tree reverse tracing.