Industrial data asset full life cycle tracking and credible traceability system
By combining data DNA fingerprinting and dynamic watermarking technologies with event logging and contract management, we have achieved full lifecycle tracking and trusted traceability of cross-enterprise industrial data assets, solving the problems of data privacy and cross-enterprise traceability in existing technologies, and realizing refined management and clear responsibilities.
Patent Information
- Application Number
- CN202610014589.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-07
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2046-01-07
AI Technical Summary
Existing technologies make it difficult to achieve refined tracking of cross-enterprise industrial data assets throughout their entire lifecycle, from collection and processing to contractual use and derived results, and to ensure reliable traceability of unauthorized use, without exposing the commercial secrets of enterprise industrial data.
By generating data DNA fingerprints through the asset identification slicing module, and combining them with the event collection and recording module, contract orchestration and agency module, trusted execution embedding module, and credential management and tracking module, the full lifecycle tracking and trusted traceability of industrial data assets can be realized, including semantic annotation and time window slicing, dynamic watermark embedding, cross-enterprise strategy contract binding, and evidence and credential management.
It enables detailed tracking and responsibility allocation of cross-enterprise industrial data assets throughout their entire lifecycle, ensuring strict compliance with data usage contracts and reliable tracing of violations, thus safeguarding data privacy and security.
Smart Images

Figure CN121456858A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of industrial data, in particular to an industrial data asset full life cycle tracking and credible traceability system. BACKGROUND
[0002] With the development of industrial internet and commercial information communication technology, multiple manufacturing enterprises converge data such as equipment operation, process parameters, quality inspection and operation and maintenance logs to a remote operation and maintenance platform for predictive maintenance and quality optimization. These data are gradually regarded as industrial data assets that can be valued and traded. However, the existing technology is mostly limited to file level, library table level or interface level management, which can only roughly record that a certain data set has been accessed, and it is difficult to accurately track when and in what way a piece of industrial data asset fragment data participates in a model training or reasoning. In addition, there is a lack of fine-grained data usage contract bound to data asset strategy, making it difficult to form a verifiable evidence chain without exposing the original production data. Some solutions introduce blockchain or watermark, but either a large amount of business data is directly chained, resulting in cost and leakage risk, or only static data is watermarked once, which cannot support dynamic tracing across enterprises and multiple calls. The present application realizes the full life cycle fine management and credible traceability of industrial data assets from collection, processing, contract constrained use to derived results without centralized exposure of original data by means of data DNA fingerprint, life cycle event double-channel recording, composable data usage contract based on asset strategy, data processing in a credible running environment and dynamic watermark embedding, combined with evidence certificate management and pedigree tracking. It supports income settlement and responsibility definition.
[0003] At present, the Chinese invention patent with application number 202111526516.6 discloses an industrial data asset publishing method and device. The industrial data asset publishing method shown in the present disclosure strictly requires that the development environment test be passed before publishing in the production environment. At the same time, the data of each task is obtained from a unified raw data layer to ensure data homogeneity and improve data consistency. In addition, the DHP (China Nuclear Power Big Nuclear Source Platform) data platform adopts a multi-tenant mode to provide computing resources and storage resources for each user. The multi-tenant shared platform resources are isolated in application program environment and data, avoiding mutual interference of work processes between different tenants and ensuring data privacy.
[0004] The above-mentioned technology cannot realize the full life cycle fine tracking of cross-enterprise industrial data assets from collection, processing, contract constrained use to derived results and the credible traceability of illegal use behavior without exposing the commercial secrets of enterprise industrial data. SUMMARY
[0005] The technical problem solved by the present application is that the prior art is difficult to realize the fine tracking of the whole life cycle of cross-enterprise industrial data assets from collection, processing, contract constraint use to derived results and the credible traceability of illegal use behavior without exposing the business secrets of enterprise industrial data.
[0006] To solve the above technical problems, the present application provides the following technical solutions: An industrial data asset whole life cycle tracking and credible traceability system comprises an asset identification slicing module, an event collection and recording module, a contract arrangement agent module, a credible execution embedding module, a certificate management and tracking module, and a traceability analysis output module. The asset identification slicing module collects industrial data asset original data, performs semantic annotation and time window slicing based on a preset business semantic model, forms industrial data asset segment data, and generates data DNA fingerprint data based on the industrial data asset segment data. The event collection and recording module is used to generate life cycle event data based on state change information data and data DNA fingerprint data. The contract arrangement agent module is used to read industrial data asset policy configuration data associated with the data DNA fingerprint data, filter candidate industrial data asset segment data in combination with target business call demand data, generate and sign data use contract data bound with the candidate industrial data asset segment data. The credible execution embedding module is used to execute processing of the corresponding industrial data asset segment data according to the data use contract data, generate intermediate feature data, and generate dynamic watermark parameter data based on the data DNA fingerprint data and the data use contract data, embed the dynamic watermark parameter data into the intermediate feature data to form watermark feature data. The certificate management and tracking module is used to aggregate life cycle event detail data, data use contract data, and dynamic watermark evidence data to generate evidence certificate data, sequentially account in the evidence certificate channel to form evidence chain data, and construct an industrial data asset pedigree graph based on the evidence chain data. The traceability analysis output module is used to output traceability analysis results and responsibility adjustment signals according to the industrial data asset pedigree graph and send them to a notification end.
[0007] Preferably, the asset identification slicing module comprises an original data collection unit, a semantic annotation and slicing unit, and a data fingerprint generation unit. The original data collection unit is used to collect industrial data asset original data from industrial control systems, production equipment, business systems, and log systems, wherein the industrial data asset original data comprises device operation data, process parameter data, quality detection data, and business operation log data. The semantic labeling and slicing unit is configured to perform equipment identification, time identification, process identification, and responsibility subject identification on the industrial data asset raw data according to a preset business semantic model, and divide the industrial data asset raw data into a plurality of industrial data asset segment data. The data fingerprint generation unit is configured to calculate a multi-algorithm hash value, a statistical feature digest, and a semantic label digest based on the industrial data asset segment data, and output data DNA fingerprint data corresponding to the industrial data asset segment data.
[0008] Preferably, the logic of the data fingerprint generation unit is as follows: The industrial data asset segment data is grouped according to a preset time window and a business granularity, and a first hash value, a second hash value, and a statistical feature vector are calculated for each group of industrial data asset segment data, wherein the statistical feature vector includes mean data, variance data, and abnormal point count data. The equipment identification, process identification, and responsibility subject identification in the business semantic model are encoded to obtain semantic label encoding data. The first hash value, the second hash value, the statistical feature vector, and the semantic label encoding data are spliced and re-hashed to output data DNA fingerprint data, and the data DNA fingerprint data and the corresponding industrial data asset segment data are indexed.
[0009] Preferably, the event collection and recording module includes a state change perception unit, a lifecycle event generation unit, and a lifecycle event registration unit. The state change perception unit is configured to perceive creation, cleaning, transformation, derivation, archiving, and destruction operations related to the industrial data asset segment data, and obtain state change information data. The lifecycle event generation unit is configured to generate lifecycle event data according to the state change information data and the corresponding data DNA fingerprint data, wherein the lifecycle event data includes event type data, event time data, event operator data, and event location data. The lifecycle event registration unit is configured to associate the lifecycle event data with the data DNA fingerprint data to form lifecycle event detail data.
[0010] Preferably, the logic of the lifecycle event registration unit is as follows: The lifecycle event detail data is split into business data channel event digest data and evidence voucher channel event digest data, wherein the business data channel event digest data is used to record internal flow information of the industrial data asset segment data in a business system, and the evidence voucher channel event digest data is used to record tamper-proof evidence of the industrial data asset segment data in an evidence voucher channel. The evidence credential channel event summary data is sent to a credential management tracking module, which accounts in the evidence credential channel and generates evidence credential data.
[0011] Preferably, the contract arrangement agent module comprises an asset strategy analysis unit, a contract arrangement unit and a contract approval and signing unit. The asset strategy analysis unit is configured to read industrial data asset strategy configuration data associated with the data DNA fingerprint data, the industrial data asset strategy configuration data comprising allowed invoker type data, allowed algorithm type data, regional restriction data and result retention duration data. The contract arrangement unit is configured to select candidate industrial data asset segment data from a plurality of industrial data asset segment data based on the industrial data asset strategy configuration data and target business invocation demand data, and generate pre-generated data use contract data comprising the candidate industrial data asset segment data list, allowed algorithm type data and result form constraint data. The contract approval and signing unit is configured to send the pre-generated data use contract data to the corresponding data provider, approve the pre-generated data use contract data, and generate a data use contract data with multi-party signature after approval, and bind the data use contract data with the related data DNA fingerprint data.
[0012] Preferably, the logic of the contract arrangement unit is as follows: The target business invocation demand data is received, and the target business invocation demand data comprises target algorithm type data, target service object data and target service region data. The target business invocation demand data is matched in the industrial data asset strategy configuration data output by the asset strategy analysis unit, and candidate industrial data asset segment data satisfying the target algorithm type data and the target service region data are screened. According to the allowed invoker type data, the result retention duration data and the authorized transfer restriction data corresponding to the candidate industrial data asset segment data, a cross-subject data use contract data is constructed, and the cross-subject data use contract data comprises industrial data asset segment data list, allowed algorithm type constraint data, result reuse constraint data and income distribution rule data.
[0013] Preferably, the trusted execution embedding module comprises a trusted runtime environment management unit, a data processing task execution unit and a dynamic watermark embedding unit. The trusted runtime environment management unit is configured to create an isolated trusted runtime environment on the data provider side, load the data use contract data and the data processing task description data. The data processing task execution unit is configured to read industrial data asset segment data corresponding to the data DNA fingerprint data in a trusted operating environment, and perform preprocessing, feature extraction and anonymization processing on the industrial data asset segment data according to the data processing task description data, and output intermediate feature data; The dynamic watermark embedding unit is configured to generate dynamic watermark parameter data based on the data DNA fingerprint data, the data use contract data, the caller identity data and the calling time data, and embed the dynamic watermark parameter data in the intermediate feature data, and output watermark feature data, and send the watermark feature data as business data in a business data channel to a business analysis service; The logic of the dynamic watermark embedding unit is as follows: The data DNA fingerprint data, the contract identifier data in the data use contract data, the caller identity data and the calling time data are encoded to obtain watermark seed data; Based on the watermark seed data, watermark position sequence data and watermark amplitude sequence data are generated, the watermark position sequence data is mapped to a plurality of feature dimensions in the intermediate feature data, and the watermark amplitude sequence data is superimposed on the corresponding feature dimensions to form watermark feature data with watermark disturbance; The watermark seed data and the watermark position sequence data are summarized as dynamic watermark summary data, which is associated with the data DNA fingerprint data and the data use contract data to generate dynamic watermark evidence data, which is sent to the evidence management tracking module through an evidence voucher channel for accounting.
[0014] Preferably, the evidence management tracking module includes an evidence voucher generation unit, an evidence channel accounting unit and a pedigree graph construction unit. The evidence voucher generation unit is configured to aggregate the lifecycle event detail data, the data use contract data, the dynamic watermark evidence data and the business calling event data into evidence voucher data. The evidence channel accounting unit is configured to sequentially write and integrity check the evidence voucher data in the evidence voucher channel to generate evidence chain data. The pedigree graph construction unit is configured to construct an industrial data asset pedigree graph connecting the data DNA fingerprint data, the data use contract data, the watermark feature data and the business output result data based on the evidence chain data.
[0015] Preferably, the traceability analysis output module includes a result correlation identification unit, a traceability path reconstruction unit and a responsibility and adjustment signal output unit. The result correlation identification unit is configured to extract dynamic watermark information data from abnormal business output result data or leaked result data and locate related data DNA fingerprint data and data use contract data in the industrial data asset pedigree graph when the abnormal business output result data or the leaked result data appears. The traceability path reconstruction unit is configured to reconstruct complete traceability path data from industrial data asset fragment data to abnormal business output result data based on an industrial data asset pedigree diagram; The responsibility and adjustment signal output unit is configured to generate responsibility division result data and responsibility adjustment signal data according to the traceability path data and the income distribution rule data and the violation responsibility rule data in the data use contract data, the responsibility adjustment signal data including income distribution adjustment information and violation warning information, and send the responsibility adjustment signal data to a notification end.
[0016] The present application has the following beneficial effects: The present application is directed to an industrial equipment remote operation and maintenance platform, and multiple manufacturing enterprises access the platform with equipment operation, process, quality inspection and operation and maintenance logs as industrial data assets, generate data DNA fingerprints through data asset identification and slicing, realize unified identification across systems and enterprises, record in business channels and evidence voucher channels through life cycle events, take into account business query and evidence collection, combine data use contracts based on asset strategies, data processing and dynamic watermark embedding in a trusted operating environment and data asset pedigree diagrams, and realize fine tracking and responsibility division of industrial data assets throughout their life cycle without centralized exposure of original data. BRIEF DESCRIPTION OF DRAWINGS
[0017] Figure 1 A basic flowchart of an industrial data asset full life cycle tracking and trusted traceability system according to an embodiment of the present application is provided. DETAILED DESCRIPTION
[0018] In order to make the above-mentioned objects, features and advantages of the present application more apparent and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments.
[0019] Embodiment, refer to Figure 1 , an industrial data asset full life cycle tracking and trusted traceability system is provided, which includes an asset identification slicing module, an event collection and recording module, a contract arrangement agent module, a trusted execution embedding module, a voucher management tracking module and a traceability analysis output module.
[0020] The asset identification slicing module collects industrial data asset original data, performs semantic annotation and time window slicing based on a preset business semantic model, forms industrial data asset fragment data, and generates data DNA fingerprint data based on the industrial data asset fragment data.
[0021] The event collection and recording module is configured to generate life cycle event data based on state change information data and data DNA fingerprint data.
[0022] The contract orchestration agent module is configured to read the industrial data asset policy configuration data associated with the data DNA fingerprint data, filter the candidate industrial data asset segment data in combination with the target business invocation requirement data, generate and sign the data use contract data bound with the candidate industrial data asset segment data.
[0023] The trusted execution embedding module is configured to execute processing on the corresponding industrial data asset segment data according to the data use contract data, generate intermediate feature data, and generate dynamic watermark parameter data based on the data DNA fingerprint data and the data use contract data, and embed the dynamic watermark parameter data into the intermediate feature data to form the watermarked feature data.
[0024] The certificate management tracking module is configured to aggregate the lifecycle event detail data, the data use contract data and the dynamic watermark evidence data to generate the evidence certificate data, sequentially record in the evidence certificate channel to form the evidence chain data, and construct the industrial data asset pedigree graph based on the evidence chain data.
[0025] The provenance analysis output module is configured to output the provenance analysis result and the responsibility adjustment signal according to the industrial data asset pedigree graph and send them to the notification end.
[0026] The industrial data asset refers to a manageable object composed of industrial data asset original data, business semantic annotation data associated therewith, data DNA fingerprint data and industrial data asset policy configuration data.
[0027] The industrial data asset original data is semantically annotated and sliced to form the industrial data asset segment data, and the industrial data asset segment data is bound with the data DNA fingerprint data and the industrial data asset policy configuration data to form the industrial data asset.
[0028] The asset identification slicing module includes an original data acquisition unit, a semantic annotation and slicing unit and a data fingerprint generation unit.
[0029] The original data acquisition unit is configured to acquire industrial data asset original data from industrial control systems, production equipment, business systems and log systems, and the industrial data asset original data includes equipment operation data, process parameter data, quality detection data and business operation log data.
[0030] The original data acquisition unit periodically acquires industrial data asset original data from industrial control systems, production equipment, business systems and log systems, wherein: The equipment operation data includes real-time speed data, real-time current data and real-time temperature data corresponding to the equipment number; The process parameter data includes process number, station number, control instruction sequence and beat time data; The quality detection data includes online visual inspection result data and sampling inspection qualified rate data. The business operation log data includes operator account data, login time data and work order number data.
[0031] The original data acquisition unit performs time alignment on the industrial data asset original data, controls the time error within milliseconds, and ensures that the device operation data, process parameter data and quality detection data of the same timestamp can be jointly analyzed.
[0032] The semantic annotation and slicing unit is configured to identify devices, times, processes and responsible subjects in the industrial data asset original data according to a preset business semantic model, and divide the industrial data asset original data into a plurality of industrial data asset segment data.
[0033] The semantic annotation and slicing unit adds device identification, time identification, process identification and responsible subject identification to the industrial data asset original data according to the preset business semantic model. The device identification is mapped from the device unique number, the time identification uses a unified timestamp format, the process identification is obtained by combining the process number and the station number in the process parameters, and the responsible subject identification is obtained by mapping the operator account in the business operation log.
[0034] In this embodiment, the semantic annotation and slicing unit takes 30 seconds as the preset time window, and aggregates the industrial data asset original data with the same device identification and process identification within the time window into an industrial data asset segment data. Each industrial data asset segment data includes device operation data, process parameter data, quality detection data and business operation log data within the corresponding time window.
[0035] The data fingerprint generation unit is configured to calculate multi-algorithm hash values, statistical feature abstracts and semantic tag abstracts based on the industrial data asset segment data, and output data DNA fingerprint data corresponding to the industrial data asset segment data.
[0036] The logic of the data fingerprint generation unit is as follows: The industrial data asset segment data is grouped according to the preset time window and business granularity, and the first hash value, the second hash value and the statistical feature vector are calculated for each group of industrial data asset segment data. The statistical feature vector includes mean data, variance data and abnormal point count data.
[0037] The device identification, process identification and responsible subject identification in the business semantic model are encoded to obtain semantic tag encoding data.
[0038] The first hash value, the second hash value, the statistical feature vector and the semantic label coding data are spliced and re-hashed to output data DNA fingerprint data, and the data DNA fingerprint data and the corresponding industrial data asset segment data are indexed.
[0039] The data fingerprint generation unit first groups the industrial data asset segment data according to a preset time window and a business granularity. In this embodiment, the business granularity is a combination of equipment, a process and a time window. Each group of industrial data asset segment data corresponds to the production behavior of a piece of equipment in a specific process and a specific time window. The first hash value, the second hash value and the statistical feature vector are calculated for each group of industrial data asset segment data. The first hash value is calculated based on the byte sequence obtained by splicing the original numerical value fields (rotational speed, current, temperature and online detection results) in the group of industrial data asset segment data in time sequence using the first hash algorithm. The second hash value is calculated based on the byte sequence obtained by splicing the key fields (equipment number, process number, beat time and work order number) in the group of industrial data asset segment data using the second hash algorithm. The statistical feature vector includes the mean value data and the variance data of the rotational speed data, the mean value data and the abnormal point count data (the number of samples whose current exceeds the preset range) of the current data, the maximum value data of the temperature data and the unqualified piece count data in the quality detection data in the time window.
[0040] The equipment identifier, the process identifier and the responsible subject identifier in the business semantic model are encoded to obtain semantic label coding data. The semantic label coding data is obtained by mapping the equipment identifier, the process identifier and the responsible subject identifier to a fixed-length integer sequence and splicing. The first hash value, the second hash value, the statistical feature vector and the semantic label coding data are spliced and re-hashed to obtain data DNA fingerprint data with a fixed length. The data fingerprint generation unit establishes an index relationship between the data DNA fingerprint data and the corresponding industrial data asset segment data in the local database, so as to be called by the subsequent life cycle event collection and trusted execution embedding module.
[0041] The event collection and recording module includes a state change perception unit, a life cycle event generation unit and a life cycle event registration unit.
[0042] The state change perception unit is used to perceive the creation, cleaning, transformation, derivation, archiving and destruction operations related to the industrial data asset segment data, and to obtain state change information data.
[0043] The state change perception unit monitors operation events related to each piece of industrial data asset fragment data. When the asset identification slicing module generates new data DNA fingerprint data and completes storage, a creation event is triggered. When data cleaning operations are performed on the industrial data asset fragment data, a cleaning event is triggered. When format conversion or feature transformation is performed based on the industrial data asset fragment data, a transformation event is triggered. When the industrial data asset fragment data is used to generate intermediate feature data or watermarked feature data, a derivation event is triggered. When the industrial data asset fragment data is migrated to an archival storage medium, an archiving event is triggered. When the industrial data asset fragment data is physically deleted according to a data retention policy, a destruction event is triggered.
[0044] The lifecycle event generation unit is configured to generate lifecycle event data according to the state change information data and the corresponding data DNA fingerprint data. The lifecycle event data includes event type data, event time data, event operator data, and event location data.
[0045] The lifecycle event registration unit is configured to associate the lifecycle event data with the data DNA fingerprint data to form lifecycle event detail data.
[0046] The logic of the lifecycle event registration unit is as follows: The lifecycle event detail data is split into business data channel event summary data and evidence voucher channel event summary data. The business data channel event summary data is used to record internal flow information of the industrial data asset fragment data in the business system, and the evidence voucher channel event summary data is used to record tamper-proof evidence of the industrial data asset fragment data in the evidence voucher channel.
[0047] The evidence voucher channel event summary data is sent to the voucher management tracking module, which performs accounting in the evidence voucher channel and generates evidence voucher data.
[0048] The lifecycle event generation unit generates lifecycle event data according to the corresponding data DNA fingerprint data and the change type when receiving the notification from the state change perception unit. The lifecycle event data includes: Event type data, indicating creation, cleaning, transformation, derivation, archiving, or destruction; Event time data, which is the precise timestamp of the event occurrence; Event operator data, which can be an operator account or a system process identifier; Event location data, indicating the factory number and proxy node number of the data provider.
[0049] The lifecycle event registration unit associates the lifecycle event data with the data DNA fingerprint data to form lifecycle event detail data. In order to meet the requirements of business query and evidence credibility at the same time, the lifecycle event registration unit splits the lifecycle event detail data into two parts: Business data channel event summary data: the data DNA fingerprint data, event type data, event time data and event location data are retained, which are used to record the internal flow information of the industrial data asset fragment data in the business system.
[0050] Evidence voucher channel event summary data: the event operator data and the event location data are hashed, and only the hash value, the data DNA fingerprint data, the event type data and the event time data are retained, forming the evidence voucher channel event summary data which does not contain sensitive business fields, which is used to record the tamper-proof evidence of the industrial data asset fragment data in the evidence voucher channel.
[0051] The lifecycle event registration unit sends the evidence voucher channel event summary data to the voucher management tracking module, and the evidence channel accounting unit sequentially writes and integrity checks in the evidence voucher channel to generate corresponding evidence voucher data and join the evidence chain data.
[0052] The contract arrangement agent module includes an asset policy analysis unit, a contract arrangement unit and a contract approval and signing unit.
[0053] The asset policy analysis unit is used to read the industrial data asset policy configuration data associated with the data DNA fingerprint data, which includes allowed caller type data, allowed algorithm type data, regional restriction data and result retention time length data.
[0054] The contract arrangement unit is used to select candidate industrial data asset fragment data from multiple industrial data asset fragment data based on industrial data asset policy configuration data and target business call demand data, and generate pre-generated data use contract data containing candidate industrial data asset fragment data list, allowed algorithm type data and result form constraint data.
[0055] The contract approval and signing unit is used to send the pre-generated data use contract data to the corresponding data provider, approve the pre-generated data use contract data, and generate the data use contract data with multi-party signature after the approval, and bind the data use contract data with the related data DNA fingerprint data.
[0056] The logic of the contract arrangement unit is: Receive target business call demand data, which includes target algorithm type data, target service object data and target service region data.
[0057] Based on the target business call demand data, the industrial data asset policy configuration data output by the asset policy analysis unit is matched to filter the candidate industrial data asset segment data that meets the target algorithm type data and the target service region data.
[0058] According to the allowed caller type data, the result retention time data and the transfer authorization restriction data corresponding to the candidate industrial data asset segment data, cross-subject data use contract data is constructed, which includes industrial data asset segment data list, allowed algorithm type constraint data, result reuse constraint data and income distribution rule data.
[0059] In this embodiment, the platform side needs to initiate a predictive maintenance service based on data from multiple factories: The asset policy analysis unit reads the industrial data asset policy configuration data associated with each data DNA fingerprint data from the platform side metadata storage. The industrial data asset policy configuration data records the allowed caller type data (such as limited to platform operators), allowed algorithm type data (such as allowed predictive maintenance algorithm), regional restriction data (such as prohibited cross-border calls) and result retention time data (such as 7 days).
[0060] The contract arrangement unit receives the target business call demand data, which includes the target algorithm type data as predictive maintenance algorithm, the target service object data as a certain production line, and the target service region data as a specified country.
[0061] The contract arrangement unit first filters the candidate industrial data asset segment data that meets the target algorithm type data and the target service region data, and then constructs cross-subject data use contract data according to the allowed caller type data, the result retention time data and the transfer authorization restriction data corresponding to the candidate industrial data asset segment data. The cross-subject data use contract data lists the industrial data asset segment data list (represented in the form of data DNA fingerprint data list), the allowed algorithm type constraint data (limited to predictive maintenance algorithm), the result reuse constraint data (prohibited for other model training) and the income distribution rule data (for example, a certain percentage of service income is shared).
[0062] The contract approval and signing unit sends the cross-subject data use contract data to the corresponding data provider. The data provider approves the cross-subject data use contract data. After the approval, the data use contract data with the data provider's signature and the platform operator's signature is generated, and the data use contract data is bound with the related data DNA fingerprint data. At the same time, the contract signing related evidence voucher data is sent to the evidence management tracking module through the evidence voucher channel.
[0063] The trusted execution embedding module comprises a trusted runtime environment management unit, a data processing task execution unit and a dynamic watermark embedding unit.
[0064] The trusted runtime environment management unit is configured to create an isolated trusted runtime environment at a data provider side, and load data usage contract data and data processing task description data.
[0065] The data processing task execution unit is configured to read industrial data asset segment data corresponding to the data DNA fingerprint data in the trusted runtime environment, and perform preprocessing, feature extraction and anonymization processing on the industrial data asset segment data according to the data processing task description data, and output intermediate feature data.
[0066] The dynamic watermark embedding unit is configured to generate dynamic watermark parameter data based on the data DNA fingerprint data, the data usage contract data, the caller identity data and the calling time data, and embed the dynamic watermark parameter data in the intermediate feature data, and output watermark feature data, and send the watermark feature data as business data in a business data channel to a business analysis service.
[0067] The logic of the dynamic watermark embedding unit is as follows: The data DNA fingerprint data, contract identifier data in the data usage contract data, the caller identity data and the calling time data are encoded to obtain watermark seed data.
[0068] Watermark position sequence data and watermark amplitude sequence data are generated based on the watermark seed data, the watermark position sequence data is mapped to a plurality of feature dimensions in the intermediate feature data, and the watermark amplitude sequence data is superimposed on the corresponding feature dimensions to form watermark feature data with watermark disturbance.
[0069] The watermark seed data and the watermark position sequence data are summarized as dynamic watermark summary data, which is associated with the data DNA fingerprint data and the data usage contract data to generate dynamic watermark evidence data, and is sent to a certificate management tracking module through an evidence certificate channel for accounting.
[0070] After the data usage contract data takes effect, the trusted execution embedding module: The trusted runtime environment management unit creates an isolated trusted runtime environment at the data provider side, and loads the data usage contract data and the data processing task description data into the trusted runtime environment.
[0071] The data processing task execution unit reads the industrial data asset segment data corresponding to the data DNA fingerprint data in the trusted running environment, pre-processes, extracts features, and anonymizes the industrial data asset segment data according to the constraints in the data use contract data, and outputs intermediate feature data containing device operation statistical features but not containing original identification fields that can directly identify specific devices or operators.
[0072] The dynamic watermark embedding unit encodes the data DNA fingerprint data, the contract identification data in the data use contract data, the caller identity data, and the calling time data, obtains watermark seed data, generates watermark position sequence data and watermark amplitude sequence data based on the watermark seed data, maps the watermark position sequence data to multiple feature dimensions in the intermediate feature data, and superimposes the watermark amplitude sequence data to the corresponding feature dimensions to form watermark feature data with watermark disturbance.
[0073] The dynamic watermark embedding unit associates the watermark seed data and the watermark position sequence data digest as dynamic watermark digest data with the data DNA fingerprint data and the data use contract data, generates dynamic watermark evidence data, and sends the dynamic watermark evidence data to the evidence management tracking module through the evidence voucher channel for accounting; the watermark feature data with watermark is sent to the platform-side business analysis service as business data in the business data channel, and is used for model training or online inference.
[0074] In this embodiment, the watermark amplitude is limited within a certain proportion of the standard deviation of the corresponding feature dimension, so that the error of the watermark feature data on the model output is kept within the preset business acceptable range.
[0075] The evidence management tracking module includes an evidence voucher generation unit, an evidence channel accounting unit, and a pedigree graph construction unit.
[0076] The evidence voucher generation unit is configured to aggregate the lifecycle event detail data, the data use contract data, the dynamic watermark evidence data, and the business call event data into evidence voucher data.
[0077] The evidence channel accounting unit is configured to sequentially write and integrity check the evidence voucher data in the evidence voucher channel to generate evidence chain data.
[0078] The pedigree graph construction unit is configured to construct an industrial data asset pedigree graph connecting the data DNA fingerprint data, the data use contract data, the watermark feature data, and the business output result data based on the evidence chain data.
[0079] The traceability analysis output module includes a result correlation identification unit, a traceability path reconstruction unit, and a responsibility and adjustment signal output unit.
[0080] The result correlation identification unit is configured to extract dynamic watermark information data from abnormal business output result data or leaked result data and locate related data DNA fingerprint data and data use contract data in the industrial data asset pedigree graph when the abnormal business output result data or the leaked result data occurs.
[0081] The traceability path reconstruction unit is configured to reconstruct complete traceability path data from industrial data asset fragment data to abnormal business output result data based on the industrial data asset pedigree graph.
[0082] The responsibility and adjustment signal output unit is configured to generate responsibility division result data and responsibility adjustment signal data according to the benefit allocation rule data and the violation responsibility rule data in the traceability path data and the data use contract data, the responsibility adjustment signal data including benefit allocation adjustment information and violation warning information, and send the responsibility adjustment signal data to a notification end.
[0083] In the normal operation process: The evidence voucher generation unit aggregates the life cycle event detail data, the data use contract data, the dynamic watermark evidence data and the business calling event data into evidence voucher data.
[0084] The evidence channel accounting unit sequentially writes and integrity checks the evidence voucher data in the evidence voucher channel to form evidence chain data.
[0085] The pedigree graph construction unit constructs an industrial data asset pedigree graph based on the evidence chain data, connects the data DNA fingerprint data, the data use contract data, the watermarked feature data and the business output result data, so that from any business output result data, the industrial data asset fragment data participating in the result generation and the corresponding data use contract data can be traced back.
[0086] When abnormal business output result data or leaked result data occurs: The result correlation identification unit extracts dynamic watermark information data from abnormal business output result data or leaked result data and locates related data DNA fingerprint data and data use contract data in the industrial data asset pedigree graph.
[0087] The traceability path reconstruction unit reconstructs complete traceability path data from industrial data asset fragment data to abnormal business output result data based on the industrial data asset pedigree graph.
[0088] The responsibility and adjustment signal output unit generates responsibility division result data and responsibility adjustment signal data according to the income distribution rule data and the violation responsibility rule data in the traceability path data and the data usage contract data, the responsibility adjustment signal data includes income distribution adjustment information and violation warning information, and sends the responsibility adjustment signal data to a notification end for reminding a platform operator, a data provider or a regulatory agency to perform subsequent processing.
[0089] Through the asset identification slicing module, the industrial data asset original data from the industrial control system, the production equipment, the business system and the log system is divided into industrial data asset fragment data according to business semantics, and data DNA fingerprint data is generated based on multi-algorithm hash values, statistical feature abstracts and semantic tag abstracts, so that each piece of industrial data asset fragment data has a unique verifiable identification in different systems and different time periods. This mechanism not only supports unified cataloging and retrieval of assets by the platform side according to the data DNA fingerprint data, but also provides a unified data identity basis for subsequent life cycle event records, data usage contract binding and dynamic watermark traceability.
[0090] The event collection and recording module generates life cycle event detail data through the state change perception unit and the life cycle event generation unit for the creation, cleaning, transformation, derivation, archiving and destruction of the industrial data asset fragment data, and the life cycle event registration unit splits the life cycle event detail data into business data channel event abstract data and evidence voucher channel event abstract data. The business data channel only records necessary flow information within the enterprise, and the evidence voucher channel forms evidence chain data in the form of an abstract in the voucher management tracking module. Through this dual-channel architecture, the present application realizes the tamper-proof recording of the life cycle evidence of the industrial data asset without centralized storage of business plaintext data, which not only reduces the intrusion into the enterprise internal data, but also meets the requirements of subsequent audit and arbitration for evidence credibility.
[0091] The contract arrangement agent module reads the industrial data asset strategy configuration data associated with the data DNA fingerprint data through the asset strategy analysis unit, filters candidate industrial data asset fragment data under the constraint of target business call demand data using the contract arrangement unit, and generates cross-subject data usage contract data, and then completes multi-party signing and binding through the contract approval and signing unit. This mechanism explicitly solidifies the policy such as allowed calling party type, allowed algorithm type, geographical restriction, result retention length and transfer authorization restriction into the data usage contract data, which ensures that the platform can only use the industrial data asset within the contract constraints from a technical point of view, and provides a clear basis for subsequent responsibility division and income distribution.
[0092] The trusted execution embedded module creates an isolated trusted running environment on the data provider side, and the data processing task execution unit locally preprocesses, extracts features and anonymizes the industrial data asset segment data, and only intermediate feature data is taken as a subsequent embedding object; the dynamic watermark embedding unit generates dynamic watermark parameter data based on data DNA fingerprint data, data usage contract data, caller identity data and calling time data, and adds the watermark amplitude to the specified feature dimension of the intermediate feature data without exceeding the preset error range, forming watermark feature data corresponding to the current calling session. Therefore, even if the watermark feature data or the model output result based thereon is leaked, the corresponding data DNA fingerprint data and data usage contract data can be located by extracting the dynamic watermark information data, and the accurate traceability and responsibility investigation of the illegal use behavior can be realized.
[0093] The evidence management tracking module aggregates the life cycle event detail data, the data usage contract data, the dynamic watermark evidence data and the business calling event data into evidence chain data through the evidence certificate generation unit and the evidence channel accounting unit, and constructs the industrial data asset pedigree graph connecting the data DNA fingerprint data, the data usage contract data, the watermark feature data and the business output result data based on the evidence chain data by the pedigree graph construction unit. When abnormal business output result data or leaked result data occurs, the traceability analysis output module uses the result correlation identification unit and the traceability path reconstruction unit to reconstruct the complete traceability path from the industrial data asset segment data to the abnormal business output result data in the industrial data asset pedigree graph, and generates responsibility division result data and responsibility adjustment signal data by the responsibility and adjustment signal output unit, and outputs the income distribution adjustment information and the illegal alarm information. This pedigree management method enables the platform operator and the data provider to understand the use flow and the resulting consequences of the industrial data asset in the commercial ICT platform from a global perspective, improving the transparency and controllability of data asset management.
[0094] The system is designed for a typical application environment of an industrial equipment remote operation and maintenance platform, and starts from the collaborative needs of three types of subjects including data providers, platform operators and downstream service objects. Through the linkage of data DNA fingerprint data, data usage contract data, watermark feature data and industrial data asset pedigree graph, the system realizes unified traceability capability under cross-enterprise, multi-algorithm and multi-business form, and can perform verifiable responsibility traceability and income settlement on the predictive maintenance, quality analysis and other service results provided by the platform without requiring enterprises to hand over all original industrial data, which is conducive to improving the willingness of enterprises to participate in remote operation and maintenance data cooperation, and promoting the safe circulation and value realization of industrial data assets on commercial information and communication technology platforms.
[0095] Those skilled in the art will appreciate that embodiments of the present application can be readily used as a method, a system or a computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (or computer- readable storage media) having computer-usable program code embodied in the medium. The medium can be any available medium or combination thereof that is accessible by a general purpose or special purpose computer. By way of example, such computer-usable storage media can include a volatile memory, such as a random access memory (RAM), a non-volatile memory, such as a read-only memory (ROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic disk, a flash memory, a compact disk (CD) or a digital versatile disk (DVD). The computer-usable program code can include any suitable set of instructions, statements or Figure 1 one or more functions specified in the flow or flows and / or blocks Figure 1 one or more functions specified in the flow or flows and / or blocks
[0096] It should be noted that the above-mentioned embodiments are only used to illustrate but not to limit the technical solutions of the present application. Although the present application is described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced equivalently without departing from the spirit and scope of the technical solutions of the present application, and they should be covered in the protection scope of the present application.
Claims
1. A system for tracking and reliable tracing industrial data assets throughout their entire lifecycle, characterized in that, It includes an asset identification slicing module, an event collection and recording module, a contract orchestration and proxy module, a trusted execution embedding module, a voucher management and tracking module, and a traceability analysis output module; The asset identification slicing module collects raw data of industrial data assets, performs semantic annotation and time window slicing based on a preset business semantic model, forms industrial data asset fragment data, and generates data DNA fingerprint data based on the industrial data asset fragment data. The event acquisition and recording module is used to generate lifecycle event data based on state change information data and data DNA fingerprint data; The contract orchestration agent module is used to read industrial data asset strategy configuration data associated with data DNA fingerprint data, filter candidate industrial data asset fragment data in combination with target business call requirement data, and generate and sign data use contract data bound to the candidate industrial data asset fragment data. The trusted execution embedding module is used to call the corresponding industrial data asset fragment data for execution processing based on the data usage contract data, generate intermediate feature data, and generate dynamic watermark parameter data based on the data DNA fingerprint data and the data usage contract data, and embed the dynamic watermark parameter data into the intermediate feature data to form watermarked feature data. The certificate management and tracking module is used to aggregate lifecycle event details, data usage contract data and dynamic watermark evidence data to generate evidence certificate data, sequentially record them in the evidence certificate channel to form evidence chain data, and construct an industrial data asset genealogy based on the evidence chain data. The traceability analysis output module is used to output traceability analysis results and responsibility adjustment signals based on the industrial data asset genealogy diagram and send them to the notification terminal.
2. The industrial data asset full lifecycle tracking and trusted traceability system as described in claim 1, characterized in that, The asset identification slicing module includes a raw data acquisition unit, a semantic annotation and slicing unit, and a data fingerprint generation unit; The raw data acquisition unit is used to acquire raw data of industrial data assets from industrial control systems, production equipment, business systems and log systems. The raw data of industrial data assets includes equipment operation data, process parameter data, quality inspection data and business operation log data. The semantic annotation and slicing unit is used to identify equipment, time, process and responsible entity in the original data of industrial data assets according to the preset business semantic model, and divide the original data of industrial data assets into several industrial data asset fragments. The data fingerprint generation unit is used to calculate multi-algorithm hash values, statistical feature summaries, and semantic tag summaries based on industrial data asset fragment data, and outputs data DNA fingerprint data that corresponds one-to-one with the industrial data asset fragment data.
3. The industrial data asset full lifecycle tracking and trusted traceability system as described in claim 2, characterized in that, The logic of the data fingerprint generation unit is as follows: The industrial data asset fragments are grouped according to a preset time window and business granularity. For each group of industrial data asset fragments, a first hash value, a second hash value, and a statistical feature vector are calculated. The statistical feature vector includes mean data, variance data, and outlier count data. Encode the equipment identifier, process identifier, and responsible entity identifier in the business semantic model to obtain semantic tag encoding data; The first hash value, the second hash value, the statistical feature vector, and the semantic label encoded data are concatenated and hashed again to output data DNA fingerprint data. The data DNA fingerprint data is then indexed with the corresponding industrial data asset fragment data.
4. The industrial data asset full lifecycle tracking and trusted traceability system as described in claim 3, characterized in that, The event acquisition and recording module includes a state change sensing unit, a lifecycle event generation unit, and a lifecycle event registration unit; The status change sensing unit is used to sense the creation, cleaning, transformation, derivation, archiving and destruction operations related to industrial data asset fragment data, and to obtain status change information data. The lifecycle event generation unit is used to generate lifecycle event data based on state change information data and corresponding data DNA fingerprint data. The lifecycle event data includes event type data, event time data, event operator data, and event location data. The lifecycle event registration unit is used to associate lifecycle event data with data DNA fingerprint data to form lifecycle event detail data.
5. The industrial data asset full lifecycle tracking and trusted traceability system as described in claim 4, characterized in that, The logic of the lifecycle event registration unit is as follows: The lifecycle event details data are split into business data channel event summary data and evidence credential channel event summary data. The business data channel event summary data is used to record the internal flow information of industrial data asset fragment data in the business system, and the evidence credential channel event summary data is used to record tamper-proof evidence of industrial data asset fragment data in the evidence credential channel. The event summary data of the evidence and voucher channel is sent to the voucher management and tracking module, which then records the data in the evidence and voucher channel and generates evidence and voucher data.
6. The industrial data asset full lifecycle tracking and trusted traceability system as described in claim 5, characterized in that, The contract orchestration agency module includes an asset strategy analysis unit, a contract orchestration unit, and a contract approval and signing unit; The asset strategy parsing unit is used to read industrial data asset strategy configuration data associated with data DNA fingerprint data. The industrial data asset strategy configuration data includes allowed caller type data, allowed algorithm type data, geographical restriction data, and result retention duration data. The contract orchestration unit is used to select candidate industrial data asset fragments from multiple industrial data asset fragments based on industrial data asset strategy configuration data and target business call requirement data, and generate pre-generated data use contract data containing a list of candidate industrial data asset fragments, allowed algorithm type data, and result form constraint data. The contract approval and signing unit is used to send the pre-generated data usage contract data to the corresponding data provider, approve the pre-generated data usage contract data, generate data usage contract data with multiple signatures after approval, and bind the data usage contract data with the relevant data DNA fingerprint data.
7. The industrial data asset full lifecycle tracking and trusted traceability system as described in claim 6, characterized in that, The logic of the contract orchestration unit is as follows: Receive target service call request data, which includes target algorithm type data, target service object data, and target service region data; Based on the target business call demand data, the data is matched with the industrial data asset policy configuration data output by the asset policy parsing unit to filter candidate industrial data asset fragment data that meet the target algorithm type data and target service region data. Based on the allowed caller type data, result retention duration data, and sublicensing restriction data corresponding to the candidate industrial data asset fragment data, cross-entity data use contract data is constructed. The cross-entity data use contract data includes an industrial data asset fragment data list, allowed algorithm type constraint data, result reuse constraint data, and revenue distribution rule data.
8. The industrial data asset full lifecycle tracking and trusted traceability system as described in claim 7, characterized in that, The trusted execution embedding module includes a trusted runtime environment management unit, a data processing task execution unit, and a dynamic watermark embedding unit; The Trusted Operating Environment Management Unit is used to create an isolated trusted operating environment on the data provider side, and load data using contract data and data processing task description data; The data processing task execution unit is used to read industrial data asset fragment data corresponding to data DNA fingerprint data in a trusted operating environment, and to perform preprocessing, feature extraction and anonymization processing on the industrial data asset fragment data according to the data processing task description data, and output intermediate feature data. The dynamic watermark embedding unit is used to generate dynamic watermark parameter data based on data DNA fingerprint data, data usage contract data, caller identity data and call time data, and embed the dynamic watermark parameter data into intermediate feature data, outputting watermarked feature data, and sending the watermarked feature data to the business analysis service as business data in the business data channel. The logic of the dynamic watermark embedding unit is as follows: Encode the data DNA fingerprint data, the contract identifier data in the data usage contract data, the caller identity data, and the call time data to obtain the watermark seed data; Watermark location sequence data and watermark amplitude sequence data are generated based on watermark seed data. The watermark location sequence data is mapped to multiple feature dimensions in the intermediate feature data, and the watermark amplitude sequence data is superimposed on the corresponding feature dimensions to form watermarked feature data with watermark perturbation. The watermark seed data and watermark location sequence data digest are used as dynamic watermark digest data and associated with data DNA fingerprint data and data usage contract data to generate dynamic watermark evidence data, which is then sent to the certificate management and tracking module for accounting through the evidence certificate channel.
9. The industrial data asset full lifecycle tracking and trusted traceability system as described in claim 8, characterized in that, The voucher management and tracking module includes an evidence voucher generation unit, an evidence channel accounting unit, and a genealogy chart construction unit; The evidence certificate generation unit is used to aggregate lifecycle event detail data, data usage contract data, dynamic watermark evidence data, and business call event data into evidence certificate data. The evidence channel accounting unit is used to sequentially write and verify the integrity of evidence document data in the evidence document channel, and generate evidence chain data. The genealogy map construction unit is used to construct an industrial data asset genealogy map based on the evidence chain data, which connects data DNA fingerprint data, data usage contract data, watermarked feature data, and business output result data.
10. The industrial data asset full lifecycle tracking and trusted traceability system as described in claim 9, characterized in that, The source tracing analysis output module includes a result correlation identification unit, a source tracing path reconstruction unit, and a responsibility and adjustment signal output unit; The result association identification unit is used to extract dynamic watermark information data from abnormal business output result data or leaked result data when abnormal business output result data or leaked result data occurs, and to locate the relevant data DNA fingerprint data and data usage contract data in the industrial data asset genealogy map. The source path reconstruction unit is used to reconstruct complete source path data from industrial data asset fragment data to abnormal business output result data based on the industrial data asset genealogy diagram. The responsibility and adjustment signal output unit is used to generate responsibility division result data and responsibility adjustment signal data based on the source tracing path data and the revenue distribution rule data and violation responsibility rule data in the data use contract data. The responsibility adjustment signal data includes revenue distribution adjustment information and violation alarm information, and sends the responsibility adjustment signal data to the notification terminal.
Citation Information
Patent Citations
Industrial data asset publishing method and device
CN114357041A
Universal product anti-counterfeiting traceability information processing and recording method and device
CN113869921A
Intelligent asset discovery method and device based on operation and maintenance system
CN113904910A
AI model management method and system based on dynamic NFT
CN121145267A
System and method for onboard data tracking
EP3166052A1