Data control method and system

By using a data control method and system based on cybernetics and employing an encoding and decoding mechanism for controllable and controlled parameters, the problem of existing technologies being unable to effectively protect data security has been solved. This enables controllable and secure sharing and use of data in different environments, meeting the security requirements of the data element market.

CN120930173APending Publication Date: 2025-11-11BEIJING FUTURE DATA TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410581038.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-11
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing information theory-based data encryption, secret segmentation, and physical isolation technologies cannot effectively protect data security and cannot meet the controllable data security requirements of the data element market, especially when facing quantum computer attacks and internal attacks.

Method used

A data control method and system based on cybernetics is adopted. The data is encoded into control data and decoded into controlled data during use. The control parameters and controlled parameters are used to store, transmit and share the data securely, ensuring that the data is the same as the information data only when it meets the requirements of the control parameters.

Benefits of technology

It enables the controlled and secure sharing, exchange, and use of data across networks, systems, organizations, and countries, ensuring information and data security and preventing external circulation. At the same time, it controls the high confidentiality of data, prevents data loss and leakage, and meets the data rights protection needs of big data, cloud computing, mobile internet, and artificial intelligence technologies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120930173A_ABST
    Figure CN120930173A_ABST
Patent Text Reader

Abstract

The invention discloses a data control method and system. The method comprises the following steps: acquiring and coordinating control parameters and controlled parameters; the application controller encodes the information data into application control data according to the application control parameters; the controlled device decodes the control data into controlled data according to the controlled parameters; the information data is not provided externally, the control data is provided externally, and the controlled data participates in data processing activities. The system comprises a control device, a controlled device, a control measuring unit and a controlled measuring unit, the control measurement unit collects and sets control parameters and cooperates with the controlled measurement unit; the controlled measurement unit collects and sets controlled parameters and cooperates with the control measurement unit. The invention discloses a controllable data security technology mechanism based on a control theory, which provides a security guarantee for protecting data sovereignty in a data circulation process and provides a controllable data security technology support for efficient communication between artificial intelligence, data element marketization, data infrastructure, data space, data transaction and data sharing and exchange.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security, specifically to data security, controllable data security, data sovereignty protection, and a data control method and system. Background Technology

[0002] Digital rights refer to the rights that arise from the governance of a set of information codes with certain patterns or values ​​throughout its entire lifecycle, involving various rights such as personal privacy, digital property rights, data sovereignty, and data autonomy.

[0003] The subject of data rights is a specific rights holder, including the specific object to which the data refers, as well as the collectors, storers, transmitters, and processors of the data (including natural persons, legal persons, and unincorporated organizations).

[0004] The object of a number right is a set of data that has certain patterns or value.

[0005] The main contents of data rights include the right of control, the right of use, the right of income, and the right of sharing. The right of control refers to the right of the data rights holder to dominate the data rights object, placing the data rights object under the legitimate control of the data rights holder, and giving the data rights holder the right to freely exercise and legally control the data rights object without interference from others; the right of use refers to the right of the data rights holder to realize corresponding benefits by using the data rights object; the right of income is the right of the data rights holder to obtain income by using and sharing the data rights object; the right of sharing is the right of the data rights holder to ultimately consume and share the data rights object.

[0006] Data rights protection (also known as data sovereignty protection or data autonomy protection) refers to the complete control that a data rights holder enjoys over a data rights object. This ensures that the data rights object is under the legitimate control of the data rights holder, granting them the right to freely exercise and legally control the data object without interference from others. The essence of data rights protection is the control of the data rights object by the data rights holder. To safeguard the rights of the data rights holder, the data rights holder, as the controller, influences and controls all controlled objects throughout the entire lifecycle of the data rights object, including hardware and software facilities related to computing, storage, and transmission, such as information sources, channels, sinks, encoders, and decoders.

[0007] In 2019, the invention patent "A method, system, and device for data rights protection (Patent No.: 201910834410.9)" pioneered data cybernetics, integrating information theory and cybernetics for the first time. It provides a data control method covering the entire process from source to destination, achieving exclusive control of the data rights subject over the data rights object, protecting the data rights subject's control over the data rights object, and enabling the data rights subject to control the data object at the source, channel, and destination according to the data rights protection strategy. However, the invention patent "A method, system, and device for data rights protection (Patent No.: 201910834410.9)" did not propose a controllable and secure flow process and method of information data based on cybernetics.

[0008] By the end of 2022, my country had established 56 data exchanges and 232 data trading platforms, but none of them had achieved the expected goals for data trading and circulation. More than half of the respondents were concerned that valuable data and trade secrets would be pirated, sold, lost, or leaked during the data trading and circulation process, and that users would lose control of their own data during the data trading and circulation process.

[0009] In 2023, my country established the National Data Administration and proposed building its own data infrastructure. Whether this data infrastructure can achieve the goal of secure data flow requires significant breakthroughs in underlying security technologies. In fact, over the past four decades, all data sovereignty protection technologies based on encryption mechanisms have been cracked and rendered ineffective, including various products such as dongles, integrated devices, copyright protection software, copyright protection cards, and software license codes. Data infrastructure needs to address the challenge of data encryption technologies failing to effectively protect data sovereignty, requiring disruptive innovation in security mechanisms.

[0010] Various cryptographic techniques based on information theory, such as data encryption and secret partitioning, cannot guarantee the controllable security of data circulation. On the one hand, quantum computers can already crack many commonly used encryption algorithms; on the other hand, information theory-based data encryption, secret partitioning, and physical isolation techniques cannot prevent internal attacks. For example, if an insider leaks the key, the encryption technology will fail; if an insider leaks the secret partitioning algorithm, the confidentiality feature of the secret partitioning technology will fail; and if an insider leaks the data, physical isolation will fail.

[0011] Information-based security technologies cannot meet the controllable data security needs of the data element market. Summary of the Invention

[0012] Addressing the technical problem that information-based data encryption, secret segmentation, and physical isolation technologies cannot effectively protect data security and fail to meet the controllable data security requirements of the data element market, this invention proposes a data control method and system based on cybernetics to protect data in a controllable and secure state. This invention encodes the data requiring security protection (information data) into controlled data carrying control parameters for storage, transmission, sharing, and exchange. During use, the controlled data is decoded into controlled data; only when the control parameters are met does the controlled data become identical to the information data.

[0013] This invention discloses a controllable data security technology mechanism based on cybernetics, providing controllable data security support for the marketization of data elements, data infrastructure, data space, data transaction and exchange, and orderly data sharing.

[0014] In a first aspect, the present invention provides a data control method, characterized in that information data requiring security protection is encoded into control data according to control parameters; during use, the control data is decoded into controlled data by combining the controlled parameters, wherein the control data and the information data are different and can be securely stored, transmitted, shared, and exchanged. The method includes:

[0015] Collect and coordinate control parameters, including both the controlled parameters and the controlled parameters;

[0016] The controller encodes information data into control data based on the control parameters;

[0017] The controller decodes the applied data into controlled data based on the controlled parameters.

[0018] The control parameters refer to the stipulations and contractual requirements made by the index rights holder regarding the use of data at all levels of the data value chain, including controlling parameters and controlled parameters. The controlling parameters refer to the control parameters used in the process of encoding information data into controlled data; the controlled parameters refer to the control parameters used in the process of decoding controlled data into controlled data.

[0019] Preferably, the control parameters and the controlled parameters include a data dictionary, and the control data includes data content encoded according to the data dictionary.

[0020] Preferably, the control parameters include at least one environmental parameter of the controller;

[0021] Preferably, the controlled parameters include at least one environmental parameter of the controller;

[0022] The environmental parameters include: operating system information, middleware information, application software information, WIFI information, network card information, CPU information, SIM card information, upgrade patch information, USB device information, driver information, graphics card information, sound card information, speaker information, microphone information, memory information, monitor information, mouse information, keyboard information, electromagnetic wave IoT sensing information, magnetic field IoT sensing information, heat IoT sensing information, sound wave IoT sensing information, light wave IoT sensing information, spatial location IoT sensing information, gravity IoT sensing information, vibration IoT sensing information, stress IoT sensing information, or acceleration IoT sensing information.

[0023] Preferably, the control parameters include one or more of the following: data usage frequency; location, hardware and software environment, data space, and network space where the data is used; user, role, organization, security level, and legal entity using the data; time, duration, and triggering event for data use; controller, software, hardware, and license for data use; permissions for downloading, viewing, processing, storing, deleting, modifying, adding, forwarding, providing feedback, verifying, publishing, and adding watermarks to the data; historical data usage, context settings, artificial intelligence algorithms, and artificial intelligence algorithm data; data classification and identification information and attribute label information; and environmental parameters of the controller, including electromagnetic wave IoT sensing information, magnetic field IoT sensing information, heat IoT sensing information, sound wave IoT sensing information, light wave IoT sensing information, spatial location IoT sensing information, gravity IoT sensing information, vibration IoT sensing information, stress IoT sensing information, and acceleration IoT sensing information.

[0024] Preferably, the information data and the control data are different;

[0025] Preferably, the controlled data and the controlled data are different;

[0026] Preferably, when the controlled parameter and the controlled parameter are the same, the information data and the controlled data can be the same or different.

[0027] Preferably, the controller uses cryptographic encoding methods such as data encryption and secret segmentation;

[0028] Preferably, the control data is one or more encrypted data;

[0029] Preferably, the controller and the controlled device may or may not have XOR calculation function.

[0030] In a second aspect, the present invention provides a data control system, comprising: a controlled measurement unit, a controlled measurement unit, a controller, and a controller, wherein:

[0031] The control measurement unit collects the control parameters and coordinates the controlled parameters and control parameters with the controlled measurement unit;

[0032] The controlled measurement unit acquires controlled parameters and coordinates the controlled parameters and applied parameters with the controlled measurement unit;

[0033] The controller encodes information data into control data based on the control parameters;

[0034] The controller decodes the applied data into controlled data based on the controlled parameters;

[0035] Preferably, the actuator and the controlled device exchange feedback data. The feedback data includes control commands sent by the actuator to the controlled device and log information sent by the controlled device to the actuator.

[0036] Preferably, the controller has functions such as data encryption and secret segmentation to ensure that the controlled data is one or more encrypted data.

[0037] Preferably, the data provider holds information data and provides control data to the outside world; the data user uses controlled data, which is generated by the data user using a controller based on the control data. The controlled data is not necessarily the same as the information data. Only when the controller is under preset controlled parameter conditions can it ensure that the controlled data is the same as the information data.

[0038] The beneficial effects of this invention are as follows: 1) Based on cybernetics, a novel controllable and secure data technology mechanism is proposed, supporting the controllable and secure sharing, exchange, circulation, and use of data across networks, systems, organizations, and countries. 2) Information data is not circulated externally, ensuring its security. 3) Controlled data can circulate freely; during circulation, storage, transmission, sharing, and exchange, no leakage protection is required. 4) Controlled data possesses high confidentiality; data encryption and secret segmentation technologies are employed during its generation to ensure that it is one or more encrypted data sets. 5) The data provider holds the information data and provides the controlled data externally; the data user uses the controlled data, which is generated by the data user using a controller based on the controlled data. The controlled data is not necessarily the same as the information data; only under preset controlled parameter conditions can the controlled data be guaranteed to be identical to the information data. 6) This invention supports secure data transmission on all available networks and secure data storage in all available storage. 7) This invention meets the data rights protection needs in the application of technologies such as big data, cloud computing, mobile internet, IoT, and artificial intelligence; it also meets the data rights protection needs in application scenarios such as data transactions, privacy data protection, and data copyright protection. 8) This invention solves the technical problem that data space is vulnerable to security attacks and damage by data users, causing data connectors in the data space to fail to execute data control policies, thus rendering the data sovereignty protection mechanism ineffective. It can prevent the loss or leakage of valuable data and trade secrets of data rights holders in the data space, and prevent data rights holders from losing control of their own data, among other security risks. 9) This invention provides an efficient and secure data exchange method between artificial intelligence systems. Attached Figure Description

[0039] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0040] Figure 1 This is a flowchart of a data control method according to an embodiment of the present invention;

[0041] Figure 2 This is a schematic diagram of a data control system according to an embodiment of the present invention;

[0042] Figure 3 This is a flowchart of the encoding and decoding process for the data control method in the application example of this invention;

[0043] Figure 4 This is a flowchart illustrating the encoding and decoding process of a data control system, an application example of the present invention.

[0044] Figure 5 This is a flowchart illustrating the encoding and decoding process of a dictionary-based data control system, which is an application example of this invention. Detailed Implementation

[0045] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0046] like Figure 1 The diagram shown is a flowchart of a data control method according to an embodiment of the present invention, including:

[0047] 101. Acquire and coordinate control parameters, including both the controlled parameters and the controlled parameters;

[0048] 102. The controller encodes the information data into control data based on the control parameters;

[0049] 103. The controller decodes the applied control data into controlled data based on the controlled parameters.

[0050] Preferably, the control parameters include at least one environmental parameter of the controller;

[0051] Preferably, the controlled parameters include at least one environmental parameter of the controller;

[0052] The environmental parameters include: operating system information, middleware information, application software information, WIFI information, network card information, CPU information, SIM card information, upgrade patch information, USB device information, driver information, graphics card information, sound card information, speaker information, microphone information, memory information, monitor information, mouse information, keyboard information, electromagnetic wave IoT sensing information, magnetic field IoT sensing information, heat IoT sensing information, sound wave IoT sensing information, light wave IoT sensing information, spatial location IoT sensing information, gravity IoT sensing information, vibration IoT sensing information, stress IoT sensing information, or acceleration IoT sensing information.

[0053] Preferably, the control parameters include one or more of the following: data usage frequency; location, hardware and software environment, data space, and network space where the data is used; user, role, organization, security level, and legal entity using the data; time, duration, and triggering event for data use; controller, software, hardware, and license for data use; permissions for downloading, viewing, processing, storing, deleting, modifying, adding, forwarding, providing feedback, verifying, publishing, and adding watermarks to the data; historical data usage, context settings, artificial intelligence algorithms, and artificial intelligence algorithm data; data classification and identification information and attribute label information; and environmental parameters of the controller, including electromagnetic wave IoT sensing information, magnetic field IoT sensing information, heat IoT sensing information, sound wave IoT sensing information, light wave IoT sensing information, spatial location IoT sensing information, gravity IoT sensing information, vibration IoT sensing information, stress IoT sensing information, and acceleration IoT sensing information.

[0054] Preferably, the information data and the control data are different;

[0055] Preferably, the controlled data and the controlled data are different;

[0056] Preferably, when the controlled parameter and the controlled parameter are the same, the information data and the controlled data can be the same or different.

[0057] Preferably, the controller uses cryptographic encoding methods such as data encryption and secret segmentation;

[0058] Preferably, the control data is one or more encrypted data;

[0059] Preferably, the controller and the controlled device may or may not have XOR calculation function.

[0060] like Figure 2 The diagram shown is a schematic representation of a data control system according to an embodiment of the present invention. The system includes: a controlled measurement unit, a controlled measurement unit, a controller, and a controller, wherein:

[0061] 21. The control measurement unit collects the control parameters and coordinates the controlled parameters and control parameters with the controlled measurement unit;

[0062] 22. Controlled measurement unit, which collects controlled parameters and coordinates with the controlled measurement unit to collect controlled parameters and control parameters;

[0063] 23. The controller encodes information data into control data based on the control parameters;

[0064] 24. The controller decodes the applied data into controlled data based on the controlled parameters;

[0065] Preferably, the actuator and the controlled device exchange feedback data. The feedback data includes control commands sent by the actuator to the controlled device and log information sent by the controlled device to the actuator.

[0066] Preferably, the controller has functions such as data encryption and secret segmentation to ensure that the controlled data is one or more encrypted data.

[0067] Preferably, the data provider holds information data and provides control data to the outside world; the data user uses controlled data, which is generated by the data user using a controller based on the control data. The controlled data is not necessarily the same as the information data. Only when the controller is under preset controlled parameter conditions can it ensure that the controlled data is the same as the information data.

[0068] The above embodiments have the following beneficial effects:

[0069] 1) Based on cybernetics, a new technical mechanism for controllable and secure data is proposed to support the controllable and secure sharing, exchange, circulation and use of data across networks, systems, organizations and countries.

[0070] 2) Information and data are not circulated to the outside world, thus ensuring the security of information and data.

[0071] 3) Control data can flow freely, and leakage protection is not required during the flow, storage, transmission, sharing and exchange of control data;

[0072] 4) The control data has high confidentiality. During the generation of control data, technologies such as data encryption and secret segmentation are used to ensure that the control data is one or more encrypted data.

[0073] 5) The data provider holds information data and provides control data to the outside world; the data user uses controlled data, which is generated by the data user using a controller based on the control data. The controlled data is not necessarily the same as the information data. Only when the controller is under the preset controlled parameters can it ensure that the controlled data is the same as the information data.

[0074] 6) This invention supports secure data transmission on all available networks and secure data storage in all available storage.

[0075] 7) This invention meets the data rights protection needs in the application of technologies such as big data, cloud computing, mobile Internet, Internet of Things, and artificial intelligence; it also meets the data rights protection needs in application scenarios such as data trading, privacy data protection, and data copyright protection.

[0076] 8) This invention solves the technical problem that when data space is attacked and damaged by data users, the data connectors in the data space fail to execute data control policies, resulting in the failure of the data sovereignty protection mechanism of the data space. It can prevent the loss or leakage of valuable data and trade secrets of data rights holders in the data space, and prevent data rights holders from losing control of their own data and other security risks.

[0077] 9) It makes the protected data interconnected and interlocked with the data processing environment preset by the data rights holder. The data processing environment defines the content displayed by the data. If the environment does not meet the preset data processing environment conditions of the data rights holder, the data content will change, thus protecting the security of data circulation. It has the security protection effect of making data unusable due to data leakage and preventing unauthorized data from being used.

[0078] The following provides a detailed description of the above embodiments of the present invention through application examples:

[0079] like Figure 3 The diagram shown is a flowchart of the encoding and decoding process for the data control method in this invention, including:

[0080] 301. Acquisition and Coordinated Control Parameters: Acquire the operating system product ID (DataCtr-1) of the device where the controller is located and the device ID (DataCtr-2) of the device where the controller is located as control parameters; transmit the operating system product ID (DataCtr-1) of the device where the controller is located to the controller;

[0081] In this application example, the obtained DataCtr-1 is: 00342-30732-30282-AAOEM;

[0082] Its binary code is: 00110000 00110000 00110011 00110100 00110010 00101101 00110011 00110000 00110111 00110011 00110010 00101101 0011001100110000 00110010 00111000 00110010 00101101 01000001 01000001 0100111101000101 01001101;

[0086] The obtained DataCtr-2 is: FA8B3930-6807-425A-A577-CFCEE82888F7;

[0087] Its binary code is: 01000110 01000001 00111000 01000010 00110011 00111001 00110011 00110000 00101101 00110110 00111000 00110000 0011011100101101 00110100 00110010 00110101 01000001 00101101 01000001 0011010100110111 00110111 00101101 01000011 01000110 01000011 01000101 0100010100111000 00110010 00111000 00111000 00111000 01000110 00110111

[0092] 302. Controller Encoding: The controller receives information data and encodes it into control data according to the control parameters.

[0093] In this application example, the information data is: Beijing Future Data Communication Co., Ltd. is a data security company founded by a team that invented data rights protection technology. Its binary code is: 11100101 10001100 10010111 11100100 10111010 10101100 11100110 10011100 10101010 11100110 10011101 1010010111100110 10010101 10110000 11101001 10000000 10011010 11100101 1000010110101100 11100101 10001111 10111000 11100110 10011000 10101111 111001110010100 10110001 11100110 10010101 10110000 11100110 10011101 1000001111100100 10111111 10011101 11100110 10001010 10100100 11100110 1000101010000000 11100110 10011100 10101111 11100101 10001111 10010001 1110011010011000 10001110 11100101 10011011 10100010 11101001 10011000 100111111100101 10001000 10011011 11100101 10111011 10111010 11100111 1001101010000100 11100110 10010101 10110000 11100110 10001101 10101110 11100101101110 10001001 11100101 10000101 10101000 11100100 10111100 1000000111100100 10111000 10011010

[0096] The information encoding method is as follows: the information data is used as plaintext, DataCtr-1 is used as the key, and the RC4 encryption algorithm is used to calculate the ciphertext of the information data; the ciphertext of the information data is XORed with DataCtr-2, and the resulting data output is the control data.

[0097] In this application example, the binary encoding of the encrypted information data is as follows: 00110101 110100111010110111001001 10110101 11000101 11000100 01110101 01000110 0011001010011111 01111011 01000110 10101101 11111001 00101010 01110101 0111010011110010 00000100 11101100 11010000 11010011 00111100 11111110 0010010110000110 10001001 10111110 10000011 11100111 10010000 01011011 1011000010101001 11100111 01011001 11000100 00101100 11111111 00101000 0001110101000011 11100011 11101100 11110111 10111001 00001111 00001010 1000010101101110 11010100 10111110 11011110 01010111 11010000 11100000 1110001011100011 10101011 10011100 10111011 01001011 11100100 01000001 1001101000101100 11000010 10110010 10101011 01000101 01111011 01001011 10111111111111111 11000000 00010101 10110000 10110011 10001011 01100100 0111001111010011 00011111 01001000 00101100 11010100

[0098] Perform equal-length shaping on DataCtr-2 to obtain DataCtr-2A with the same length as the ciphertext of the information data. The process is as follows: Based on the length La of the ciphertext of the information data, construct the exclusive-or parameter DataCtr-2A with the same length as the ciphertext of the information data from DataCtr-2 (the length of DataCtr-2 is Lb). The construction method is as follows: If La < Lb, then take La binary codes from the head in DataCtr-2 as the value of DataCtr-2A; if La = Lb, then take DataCtr-2A = DataCtr-2; if La > Lb, then take the quotient of La divided by Lb plus 1 as data M, splice M DataCtr-2s to get DataCtr-2B, and take La binary codes from the head in DataCtr-2B as the value of DataCtr-2A.

[0099] In this application example, DataCtr-2A = 01000110 01000001 00111000 010000100011001100111001 00110011 00110000 00101101 00110110 00111000 0011000000110111 00101101 00110100 00110010 00110101 01000001 00101101 0100000100110101 00110111 00110111 00101101 01000011 01000110 01000011 0100010101000101 00111000 00110010 00111000 00111000 00111000 01000110 0011011101000110 01000001 00111000 01000010 00110011 00111001 001100000101101 00110110 00111000 00110000 00110111 00101101 00110100 0011001000110101 01000001 00101101 01000001 00110101 00110111 00110111 0010110101000011 01000110 01000011 01000101 01000101 00111000 00110010 0011100000111000 00111000 01000110 00110111 01000110 01000001 00111000 0100001000110011 00111001 00110011 00110000 00101101 00110110 00111000 0011000000110111 00101101 00110100

[0100] XORing the binary code of the encrypted information data with DataCtr-2A, i.e., Controlled Data = Encrypted Information Data ⊕ DataCtr-2A, yields Controlled Data = 01110011 10010010 100101011000101110000110 11111100 11110111 01000101 01101011 00000100 1010011101001011 01110001 10000000 11001101 0001100 01000000 00110101 1101111101000101 11011001 11100111 11100100 00010001 10111101 01100011 1100010111001100 11111011 10111011 11010101 10101000 01100011 10001000 1110111111010000 00011111 10000101 00010100 10111101 00011011 00100100 0111000011010011 11000001 11000001 10000001 00111111 00111101 10101000 0101101011100110 10001011 10011111 01111010 10010001 11010101 11010101 1101010010000110 11011111 11111101 00001000 10100001 00000100 10100010 0001111011111010 10001010 10010011 00000011 01001100 00001101 11111110 1100111110000010 00100110 10001001 10000000 10111011 01001001 01000101 1110101100101111 01111111 00000001 11100000

[0101] 303. Controller Decoding: The controller receives the operating system product ID (DataCtr-1) of the device where the controller resides and collects the device ID (DataCtr-2c) of the device where the controller resides, as the controlled parameter. The controller receives the controlled data, uses the controlled parameter, and decodes the controlled data to obtain the controlled data.

[0102] Perform equal-length shaping on DataCtr-2c to obtain DataCtr-2D with the same length as the controlled data. The process is as follows: Based on the length Ld of the controlled data, construct the exclusive-or parameter DataCtr-2D with the same length as the controlled data from DataCtr-2c (the length of DataCtr-2c is Le). The construction method is as follows: If Ld < Le, then take Ld binary codes from the head in DataCtr-2c as the value of DataCtr-2D; if Ld = Le, then take DataCtr-2D = DataCtr-2c; if Ld > Le, then take the quotient of data N = Ld divided by Le plus 1, splice N DataCtr-2c to get DataCtr-2e, and take La binary codes from the head in DataCtr-2e as the value of DataCtr-2D.

[0103] In this application example, DataCtr-2D = 01000110 01000001 00111000 010000100011001100111001 00110011 00110000 00101101 00110110 00111000 0011000000110111 00101101 00110100 00110010 00110101 01000001 00101101 0100000100110101 00110111 00110111 00101101 01000011 01000110 01000011 0100010101000101 00111000 00110010 00111000 00111000 00111000 01000110 0011011101000110 01000001 00111000 01000010 00110011 00111001 001100000101101 00110110 00111000 00110000 00110111 00101101 00110100 0011001000110101 01000001 00101101 01000001 00110101 00110111 00110111 0010110101000011 01000110 01000011 01000101 01000101 00111000 00110010 0011100000111000 00111000 01000110 00110111 01000110 01000001 00111000 0100001000110011 00111001 00110011 00110000 00101101 00110110 00111000 0011000000110111 00101101 00110100

[0104] The encrypted information data is calculated as: Controlled data ⊕ DataCtr-2D; where ⊕ is the XOR calculation symbol.

[0105] Obtained: Message data ciphertext data = 00110101 11010011 10101101 110010011011010111000101 11000100 01110101 01000110 00110010 10011111 0111101101000110 10101101 11111001 00101010 01110101 01110100 11110010 0000010011101100 11010000 11010011 00111100 11111110 00100101 10000110 1000100110111110 10000011 11100111 10010000 01011011 10110000 10101001 1110011101011001 11000100 00101100 11111111 00101000 00011101 01000011 1110001111101100 11110111 10111001 00001111 00001010 10000101 01101110 1101010010111110 11011110 01010111 11010000 11100000 11100010 11100011 1010101110011100 10111011 01001011 11100100 01000001 10011010 00101100 1100001010110010 10101011 01000101 01111011 01001011 10111111 11110111 1100000000010101 10110000 10110011 10001011 01100100 01110011 11010011 0001111101001000 00101100 11010100

[0108] Using DataCtr-1 as the key, the RC4 algorithm is used to decrypt the encrypted information data to obtain controlled data.

[0109] In this application example, the controlled data = 11100101 10001100 10010111 11100100 10111010 10101100 11100110 10011100 10101010 11100110 10011101 1010010111100110 10010101 10110000 11101001 10000000 10011010 11100101 1000010110101100 11100101 10001111 10111000 11100110 10011000 10101111 1110011110010100 10110001 11100110 10010101 10110000 11100110 10011101 1000001111100100 10111111 10011101 11100110 10001010 10100100 11100110 1000101010000000 11100110 10011100 10101111 11100101 10001111 10010001 1110011010011000 10001110 11100101 10011011 10100010 11101001 10011000 1001111111100101 10001000 10011011 11100101 10111011 10111010 11100111 1001101010000100 11100110 10010101 10110000 11100110 10001101 10101110 1110010110101110 10001001 11100101 10000101 10101000 11100100 10111100 1000000111100100 10111000 10011010

[0121] Controlled data and information data have the same binary encoding. When displayed as text, their content is also the same.

[0122] The above application examples have the following beneficial effects:

[0123] 1) During the process of encoding information data into control data, the encoding algorithm supports the use of data encryption. Supported data encryption algorithms include SM1 (SCB2), SM2, SM3, SM4, SM7, SM9, Zu Chongzhi Cryptography Algorithm (ZUC), AES encryption algorithm, DES encryption algorithm, and RSA encryption algorithm. The encoding algorithm supports the use of secret partitioning. Supported secret partitioning algorithms include: secret partitioning algorithm based on Shamir threshold scheme, secret partitioning algorithm based on Chinese Remainder Theorem (CRT), secret partitioning algorithm based on Brickell, and secret partitioning algorithm based on Blakley.

[0124] 2) Based on the parameters of the hardware device, the control data is encrypted and XORed to protect the security of the encryption key and prevent the security risk of key leakage.

[0125] 3) The control data has high confidentiality. During the generation of control data, technologies such as data encryption and secret segmentation are used to ensure that the control data is one or more encrypted data.

[0126] 4) The data provider holds information data and provides control data to the outside world; the data user uses controlled data, which is generated by the data user using a controller based on the control data. The controlled data is not necessarily the same as the information data. Only when the controller is under the preset controlled parameters can it ensure that the controlled data is the same as the information data.

[0127] 5) Supports secure data transmission on all available networks and secure data storage on all available storage.

[0128] 6) It makes the protected data interconnected and interlocked with the data processing environment preset by the data rights holder. The data processing environment defines the content displayed by the data. If the environment does not meet the preset data processing environment conditions of the data rights holder, the data content will change, thus protecting the security of data circulation. It has the security protection effect of making data unusable due to data leakage and preventing unauthorized data from being used.

[0129] like Figure 4 The diagram shown is a flowchart of the encoding and decoding process for a data control system, an application example of this invention, including:

[0130] 41. Controlled Measurement Unit: Collects the controller operating system product ID (DataCtr-1) and device ID (DataCtr-2), and sends them to the control strategy unit;

[0131] In this application example, the collected DataCtr-1 is: 00342-30732-30282-AAOEM, and its binary encoding is: 00110000 00110000 00110011 00110100 00110010 00101101 00110011 00110000 00110111 00110011 00110010 00101101 00110011 00110000 0011001000111000 00110010 00101101 01000001 01000001 01001111 01000101 01001101

[0134] The collected DataCtr-2 is: FA8B3930-6807-425A-A577-CFCEE82888F7; its binary code is: 01000110 01000001 00111000 01000010 00110011 00111001 00110011 00110011 00110000 00101101 00110110 00111000 00110000 00110111 00101101 0011010000110010 00110101 01000001 00101101 01000001 00110101 00110111 0011011100101101 01000011 01000110 01000011 01000101 01000101 00111000 0011001000111000 00111000 00111000 01000110 00110111

[0139] 42. Controlled Measurement Unit: Receives data from the controlled measurement unit, including the controller's operating system product ID (DataCtr-1) and device ID (DataCtr-2), and stores it as control parameters for the controller to access.

[0140] 43. Controller Encoding: Receives information data DataIn, calls the control parameters of the control measurement unit, and encodes the information data into control data.

[0141] DataIn is defined as follows: Beijing Future Data Technology Co., Ltd. is a data security company founded by a team that invented data rights protection technology. Its binary code is: 11100101 10001100 10010111 11100100 10111010 10101100 11100110 10011100 10101010 11100110 10011101 10100101 1110011010010101 10110000 11101001 10000000 10011010 11100101 10000101 1010110011100101 10001111 10111000 11100110 10011000 10101111 11100111 1001010010110001 11100110 10010101 10110000 11100110 10011101 10000011 1110010010111111 10011101 11100110 10001010 10100100 11100110 10001010 1000000011100110 10011100 10101111 11100101 10001111 10010001 11100110 1001100010001110 11100101 10011011 10100010 11101001 10011000 10011111 1110010110001000 10011011 11100101 10111011 10111010 11100111 10011010 1000010011100110 10010101 10110000 11100110 10001101 10101110 11100101 1010111010001001 11100101 10000101 10101000 11100100 10111100 10000001 111001001011100010011010

[0143] According to the encoding algorithm requirements, DataCtr-1 is constructed as encoding parameter XDataCtr-1, and DataCtr-2 is constructed as encoding parameter XDataCtr-2, including:

[0144] Based on the binary encoding length La of DataIn, construct the XOR parameter XDataCtr-1 of DataCtr-1. The construction method is as follows: divide the binary encoding length La of DataIn by the binary encoding length Ld1 of DataCtr-1, round the result and add 1 to get the number of concatenations U1 of DataCtr-1. Concatenate U1 DataCtr-1s to get a binary encoding of length U1 multiplied by Ld1. Extract the first La binary encodings of this string as the value of the XOR parameter XDataCtr-1. In this application example, La = 696; Ld1 = 184; U1 = 4.XDataCtr-1=0011000000110000 00110011 0011010000110010 00101101 00110011 00110000 00110111 00110011 00110010 0010110100110011 00110000 00110010 00111000 00110010 00101101 01000001 0100000101001111 01000101 01001101 00110000 00110000 00110011 00110100 0011001000101101 00110011 00110000 00110111 00110011 00110010 00101101 0011001100110000 00110010 00111000 00110010 00101101 01000001 01000001 0100111101000101 01001101 00110000 00110000 00110011 00110100 00110010 0010110100110011 00110000 00110111 00110011 00110010 00101101 00110011 0011000000110010 00111000 00110010 00101101 01000001 01000001 01001111 0100010101001101 00110000 00110000 00110011 00110100 00110010 00101101 0011001100110000 00110111 00110011 00110010 00101101 00110011 00110000 0011001000111000 00110010 00101101;

[0145] Based on the binary encoding length La of DataIn, construct the XOR parameter XDataCtr-2 of DataCtr-2. The construction method is as follows: divide the binary encoding length La of DataIn by the binary encoding length Ld2 of DataCtr-2, round the result, and add 1 to get the number of concatenations U2 of DataCtr-2. Concatenate U2 DataCtr-2s to get a binary encoding of length U2 multiplied by Ld2. Extract the first La binary encodings of this string as the value of the XOR parameter XDataCtr-2. In this application example, La = 696; Ld2 = 288; U2 = 3.XDataCtr-2=0100011001000001 00111000 0100001000110011 00111001 00110011 00110000 00101101 00110110 00111000 0011000000110111 00101101 00110100 00110010 00110101 01000001 00101101 0100000100110101 00110111 00110111 00101101 01000011 01000110 01000011 0100010101000101 00111000 00110010 00111000 00111000 00111000 01000110 0011011101000110 01000001 00111000 01000010 00110011 00111001 001100000101101 00110110 00111000 00110000 00110111 00101101 00110100 0011001000110101 01000001 00101101 01000001 00110101 00110111 00110111 0010110101000011 01000110 01000011 01000101 01000101 00111000 00110010 0011100000111000 00111000 01000110 00110111 01000110 01000001 00111000 0100001000110011 00111001 00110011 00110000 00101101 00110110 00111000 0011000000110111 00101101 00110100;

[0146] The controlled data DatOut is obtained by XORing DataIn with XDataCtr-1 and XDataCtr-2.

[0147] The controlled data is calculated according to the following formula: DataOut=DataIn⊕XDataCtr-1⊕XDataCtr-2; In the formula, ⊕ is the XOR calculation symbol.

[0148] In this application example, DataOut = 10010011 11111101 10011100 100100101011101110111000 11100110 10011100 10110000 11100011 10010111 1011100011100010 10001000 10110110 11100011 10000111 11110110 10001001 1000010111010110 10010111 11110101 10100101 10010101 11101101 11011000 1001000011111100 10111010 11100100 10011010 10111011 11101100 11110110 1000011110010010 11001100 10011101 10010110 10010100 1111010111101000 10011101 10010100 10101111 11100001 10010110 10010111 1111100110011110 11111111 11111111 11101001 10100101 11110011 10011100 1000001010010100 11110110 11101010 10001101 10111111 11000011 10011010 111001111110001 11101110 11100011 10110100 10010100 11111110 10111011 1001010010101101 10000111 11100101 10000111 10101000 11100001 10110100 1000001111101011 10100111 10000011

[0150] 44. Controller Decoding: Receives control data, calls the controlled measurement unit, collects the controller operating system product ID (DataCtr-1a) and device ID (DataCtr-2a) as controlled parameters, decodes the control data into controlled data, and outputs the controlled data.

[0151] The process is the same as step 43. Construct the XOR parameter xDataCtr-1a based on DataCtr-1a, construct the XOR parameter xDataCtr-2a based on DataCtr-2a, and calculate the controlled data.

[0152] In this application example, controlled data = controlled data DataOut ⊕ xDataCtr-1a ⊕ xDataCtr-2a

[0153] In this application example, DataCtr-1a = DataCtr-1; DataCtr-2a = DataCtr-2; xDataCtr-1a = xDataCtr-1; xDataCtr-2a = xDataCtr-2;

[0154] It can be calculated that: Controlled data = (DataIn⊕XDataCtr-1⊕XDataCtr-2)⊕xDataCtr-1a⊕

[0155] xDataCtr-2a = DataIn (i.e., information data)

[0156] If DataCtr-1a is not equal to DataCtr-1, or DataCtr-2a is not equal to DataCtr-2,

[0157] Therefore, controlled data and informational data are not the same.

[0158] The above application examples have the following beneficial effects:

[0159] 1) It provides a simple and efficient data control method and system implementation scheme.

[0160] 2) It makes the data to be encoded interconnected and interlocked with the data processing environment preset by the data rights holder. The data processing environment defines the content displayed by the data. If the environment does not meet the data processing environment conditions preset by the data rights holder, the data content will change, thus protecting the security of data circulation. It has the security protection effect of making data unusable due to data leakage and preventing unauthorized data from being used.

[0161] 3) Supports the collection of data processing environment parameters, including: computing device hardware and software attributes and specifications. Supported computing device hardware and software attributes include: operating system information, middleware information, application software information, WIFI information, network card information, CPU information, SIM card information, upgrade patch information, USB device information, driver information, graphics card information, sound card information, speaker information, microphone information, memory information, monitor information, mouse information, and keyboard information.

[0162] 4) Supports the collection and processing of environmental parameters, including: IoT sensing information. Supported IoT sensing information includes electromagnetic wave IoT sensing information, magnetic field IoT sensing information, heat IoT sensing information, sound wave IoT sensing information, light wave IoT sensing information, spatial location IoT sensing information, gravity IoT sensing information, vibration IoT sensing information, stress IoT sensing information, and acceleration IoT sensing information.

[0163] like Figure 5 The diagram shown is a flowchart of the dictionary-based data control system encoding and decoding process, an application example of the present invention, including:

[0164] 501. Controlled Measurement Unit: Sets the data encoding dictionary Dic and submits the data encoding dictionary Dic to the controlled measurement unit.

[0165] In this application example, the Dic setting for the controlled measurement unit is: 1 = "Data Security Law of the People's Republic of China"

[0166] 502. Controlled Measurement Unit: Stores the data encoding dictionary Dic, which is then sent via DicSend.

[0167] The contents of the data encoding dictionary DicSend are: 1 = "Data Security Law of the People's Republic of China"

[0168] 503. Controller Encoding: Receives information data, calls the data encoding dictionary DicSend, and encodes the information data.

[0169] To control data

[0170] The DataIn information contains: "Print the 'Data Security Law of the People's Republic of China'"; the encoding method is dictionary substitution. Replacing "Data Security Law of the People's Republic of China" with #1# results in the DataOut control data containing: "Print #1#".

[0171] 504. Controller Decoding: Receives controlled data, calls the data encoding dictionary Dic as the controlled parameter, decodes the controlled data into controlled data, and outputs the controlled data.

[0172] In this application example, the controller receives the following control data: print #1#; the data encoding dictionary Dic contains:

[0173] 1 = The Data Security Law of the People's Republic of China;

[0174] After dictionary decoding and substitution, the controlled data obtained is: Print the "Data Security Law of the People's Republic of China".

[0175] The above application examples have the following beneficial effects:

[0176] 1) It provides a scenario- and context-based data security method for AI communication.

[0177] 2) By adopting a dictionary encoding scheme, control data can be transformed into control commands. The data sender and receiver transmit control commands, not information data. The security of information data is guaranteed by dictionary security.

[0178] 3) Controlled data shared and exchanged between data providers and data users has high data compression and data confidentiality features.

[0179] 4) The controlled data decoded from the same controlled data will be different in different data dictionaries.

[0180] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

[0181] It should be understood that the specific order or hierarchy of steps in the disclosed process is an example of an exemplary method. Based on design preferences, it should be understood that the specific order or hierarchy of steps in the process may be rearranged without departing from the scope of this disclosure. The appended method claims provide elements of various steps in an exemplary order and are not intended to limit the scope to the specific order or hierarchy described.

[0182] In the above detailed description, various features are combined together in a single embodiment to simplify this disclosure. This approach to disclosure should not be construed as reflecting an intention that embodiments of the claimed subject matter require more features than are explicitly stated in each claim. Rather, as reflected in the appended claims, the invention is presented with fewer features than all of the features of the single disclosed embodiment. Therefore, the appended claims are hereby explicitly incorporated into the detailed description, wherein each claim stands alone as a preferred embodiment of the invention.

[0183] The disclosed embodiments have been described above to enable any person skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be applied to other embodiments without departing from the spirit and scope of this disclosure. Therefore, this disclosure is not limited to the embodiments given herein, but is consistent with the broadest scope of the principles and novel features disclosed in this application.

[0184] The foregoing description includes examples of one or more embodiments. It is certainly impossible to describe all possible combinations of components or methods in order to describe the above embodiments, but those skilled in the art will recognize that further combinations and arrangements of the various embodiments are possible. Therefore, the embodiments described herein are intended to cover all such changes, modifications, and variations that fall within the scope of the appended claims. Furthermore, the term "comprising" as used in the specification or claims is interpreted in a manner similar to the term "including," as interpreted when used as a conjunction in the claims. Additionally, the use of any term "or" in the specification of the claims is intended to mean "non-exclusive or."

[0185] Those skilled in the art will also understand that the various illustrative logical blocks, units, and steps listed in the embodiments of the present invention can be implemented by electronic hardware, computer software, or a combination of both. To clearly demonstrate the interchangeability of hardware and software, the functions of the various illustrative components, units, and steps described above have been generally described. Whether such functionality is implemented through hardware or software depends on the specific application and the overall system design requirements. Those skilled in the art can implement the described functions using various methods for each specific application, but such implementation should not be construed as exceeding the scope of protection of the embodiments of the present invention.

[0186] The various illustrative logic blocks or units described in the embodiments of this invention can be implemented or operate the described functions using a general-purpose processor, digital signal processor, application-specific integrated circuit (ASIC), field-programmable gate array or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof. The general-purpose processor can be a microprocessor; alternatively, it can be any conventional processor, controller, microcontroller, or state machine. The processor can also be implemented using a combination of computing devices, such as a digital signal processor and a microprocessor, multiple microprocessors, one or more microprocessors combined with a digital signal processor core, or any other similar configuration.

[0187] The steps of the methods or algorithms described in the embodiments of this invention can be directly embedded in hardware, a software module executed by a processor, or a combination of both. The software module can be stored in RAM, flash memory, ROM, EPROM, EEPROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium in the art. Exemplarily, the storage medium can be connected to the processor so that the processor can read information from and write information to the storage medium. Optionally, the storage medium can also be integrated into the processor. The processor and storage medium can be housed in an ASIC, which can be housed in a cloud service client terminal. Optionally, the processor and storage medium can also be housed in different components within the cloud service client terminal.

[0188] In one or more exemplary designs, the functions described in the embodiments of the present invention can be implemented in hardware, software, firmware, or any combination of these three. If implemented in software, these functions can be stored on a computer-readable medium or transmitted on a computer-readable medium in the form of one or more instructions or code. Computer-readable media include computer storage media and communication media that facilitate the transfer of computer programs from one place to another. Storage media can be any available media that can be accessed by a general-purpose or special-purpose computer. For example, such computer-readable media can include, but is not limited to, RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store program code in the form of instructions or data structures and other forms that can be read by a general-purpose or special-purpose computer, or a general-purpose or special-purpose processor. Furthermore, any connection can be suitably defined as a computer-readable medium, for example, if the software is transmitted from a website, server or other remote resource via a coaxial cable, fiber optic cable, twisted pair, digital cloud service client line (DSL), or wirelessly, such as infrared, wireless, and microwave, it is also included in the defined computer-readable medium. The disks and discs mentioned include compressed disks, laser discs, optical discs, DVDs, floppy disks, and Blu-ray discs. Disks typically copy data magnetically, while disks typically copy data optically using lasers. Combinations of the above can also be contained in computer-readable media.

[0189] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A data control method, characterized in that, The method involves encoding information data requiring security protection into control data based on control parameters; during use, the control data is decoded using controlled parameters to extract controlled data. The control data and information data are distinct and can be securely stored, transmitted, shared, and exchanged. Collect and coordinate control parameters, including both the controlled parameters and the controlled parameters; The controller encodes information data into control data based on the control parameters; The controller decodes the applied data into controlled data based on the controlled parameters.

2. The data control method according to claim 1, characterized in that, Information data is not provided to external parties, but controlled data is provided to external parties, and controlled data is used in data processing activities.

3. The control parameters and controlled parameters contain a data dictionary, and the control data contains data content encoded according to the data dictionary.

4. The data control method according to claim 1, characterized in that, The control parameters include one or more of the following: data usage frequency; location, hardware and software environment, data space, and network space where the data is used; user, role, organization, security level, and legal entity using the data; time, duration, and triggering event for data use; controller, software, hardware, and license for data use; permissions for downloading, viewing, processing, storing, deleting, modifying, adding, forwarding, providing feedback, verifying, publishing, and adding watermarks to the data; historical data usage, context settings, artificial intelligence algorithms, and artificial intelligence algorithm data; data classification and identification information and attribute label information; and environmental parameters of the controller, including electromagnetic wave IoT sensing information, magnetic field IoT sensing information, heat IoT sensing information, sound wave IoT sensing information, light wave IoT sensing information, spatial location IoT sensing information, gravity IoT sensing information, vibration IoT sensing information, stress IoT sensing information, and acceleration IoT sensing information.

5. The data control method according to claim 1, characterized in that, The controlled parameters include at least one environmental parameter of the controller; the environmental parameters include: operating system information, middleware information, application software information, WIFI information, network card information, CPU information, SIM card information, upgrade patch information, USB device information, driver information, graphics card information, sound card information, speaker information, microphone information, memory information, display information, mouse information, keyboard information, electromagnetic wave IoT sensing information, magnetic field IoT sensing information, heat IoT sensing information, sound wave IoT sensing information, light wave IoT sensing information, spatial location IoT sensing information, gravity IoT sensing information, vibration IoT sensing information, stress IoT sensing information, or acceleration IoT sensing information.

6. The data control method according to claim 1, characterized in that, The control parameters include at least one environmental parameter of the controller; the environmental parameters include: operating system information, middleware information, application software information, WIFI information, network card information, CPU information, SIM card information, upgrade patch information, USB device information, driver information, graphics card information, sound card information, speaker information, microphone information, memory information, display information, mouse information, keyboard information, electromagnetic wave IoT sensing information, magnetic field IoT sensing information, heat IoT sensing information, sound wave IoT sensing information, light wave IoT sensing information, spatial location IoT sensing information, gravity IoT sensing information, vibration IoT sensing information, stress IoT sensing information, or acceleration IoT sensing information.

7. A data control system, characterized in that, include: The control measurement unit, the controlled measurement unit, the controller, and the controller are, among which: The control measurement unit collects the control parameters and coordinates the controlled parameters and control parameters with the controlled measurement unit; The controlled measurement unit acquires controlled parameters and coordinates the controlled parameters and applied parameters with the controlled measurement unit; The controller encodes information data into control data based on the control parameters; The controller decodes the applied data into controlled data based on the controlled parameters.

8. A data control system according to claim 7, characterized in that, The controller and the controlled device exchange feedback data; the feedback data includes control commands sent by the controller to the controlled device and log information sent by the controlled device to the controller.

9. A data control system according to claim 7, characterized in that, The controller has functions such as data encryption and secret splitting to ensure that the controlled data is one or more ciphertext data. The controller supports data encryption and secret splitting, and the supported algorithms include: SM1 (SCB2), SM2, SM3, SM4, SM7, SM9, Zu Chongzhi Cryptography Algorithm (ZUC), encryption algorithm AES, encryption algorithm DES or encryption algorithm RSA; secret splitting algorithm based on Shamir threshold scheme, Chinese Remainder Theorem (CRT) secret splitting algorithm, Brickell secret splitting algorithm or Blakley secret splitting algorithm.

10. An application example of this invention: a dictionary-based data control system encoding and decoding flowchart, including:

501. Controlled Measurement Unit: Sets the data encoding dictionary Dic and submits the data encoding dictionary Dic to the controlled measurement unit; 502. Controlled Measurement Unit: Stores the data encoding dictionary Dic as DicSend; 503. Controller Encoding: Receives information data, calls the data encoding dictionary DicSend, and encodes the information data into control data; 504. Controller Decoding: Receives the controlled data, calls the data encoding dictionary Dic as the controlled parameter, decodes the controlled data into controlled data, and outputs the controlled data.

Citation Information

Patent Citations

  • A method, system and apparatus for protecting data rights

    CN112448937B