Data compliance design method based on trusted data space scene

By using blockchain to store data contracts and generate contract rules in a trusted data space, combined with computation sandboxes and boundary sandboxes, compliance management issues in the dynamic use of data are resolved, achieving full lifecycle transparency and security of data operations, and promoting the reliability of data sharing and circulation.

CN121547302AActive Publication Date: 2026-02-17CETC BIGDATA RES INST CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202610071782.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-20
Publication Date
2026-02-17
Estimated Expiration
2046-01-20

AI Technical Summary

Technical Problem

Existing data compliance design schemes are insufficient to achieve comprehensive compliance management of the dynamic use of data within a trusted data space. In particular, in data sharing scenarios, it is difficult to clarify the data compliance responsibilities of each party, which can easily lead to the phenomenon of shirking responsibility.

Method used

By using blockchain technology to store data using contracts, and recording data operation behavior through the contract chain and compliance record chain, contract rules are generated to control operations within the data sandbox. Combined with the computing sandbox and boundary sandbox, an isolated environment is provided to achieve dynamic monitoring and management of data operations.

Benefits of technology

It achieves full auditability and transparency in data operations, ensures compliance of data throughout its entire lifecycle within a trusted data space, prevents data leakage and misuse, and promotes the security and reliability of data sharing and circulation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121547302A_ABST
    Figure CN121547302A_ABST
Patent Text Reader

Abstract

The invention provides a data compliance design method based on a trusted data space scene, and aims to guarantee the security and compliance in a data circulation process, write a use contract agreed by both parties into a block chain contract chain before data operation, ensure that terms cannot be tampered, and improve the security and compliance of the data. All operation behaviors in circulation are recorded in another compliance record chain in real time, so that the whole process can be audited, an independent calculation and boundary data sandbox is created for each user, an isolated operation environment is provided, data operation in the sandbox is dynamically controlled through a machine readable contract rule generated from a contract, and the operation efficiency is improved. By regularly comparing the contents on the two chains, the illegal behavior can be automatically identified, and after the contract is terminated, the sandbox and the data in the sandbox are safely destroyed. According to the invention, refined management and control, transparent supervision and compliance guarantee of data in the sharing and using process are realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of data security, and specifically relates to a data compliance design method based on a trusted data space scenario. BACKGROUND

[0002] The data compliance design in the trusted data space scenario mainly involves the compliance guarantee of the safe storage, transmission, sharing and operation of data. The purpose is to ensure that the use of data in the trusted data space complies with legal regulations, and to protect the confidentiality, integrity and availability of data.

[0003] The existing data compliance design scheme has achieved certain results in the static protection and audit of data, but there are still deficiencies in the comprehensive compliance management of the dynamic use process of data in the trusted data space. The existing technology mainly focuses on the protection of the static encryption storage and transmission process of data and the user identity authentication, and lacks supervision of the dynamic use link of data in the trusted data space. Because it mainly relies on access control strategy to limit user access permissions, it is difficult to control the specific operation behavior of users after legal access, and it is difficult to ensure the full life cycle compliance of data in the trusted data space. Especially in the data sharing scenario, the use of data by different participants is various and complex, and it is difficult to clearly define the data compliance responsibilities of each party by relying on permission control, and it is easy to appear the phenomenon of shirking responsibility. SUMMARY

[0004] According to the first aspect of the application, the application claims a data compliance design method based on a trusted data space scenario, comprising: Step S1: Before the start of data operation, the authorized party and the authorized party sign a data use contract, and write the contract content into the contract chain of the block chain, wherein the contract content includes authorized party information, authorized party information, authorization period, data use range, data processing method and data processing purpose; Step S2: In the data flow process, write the data operation behavior record into the compliance record chain of the block chain, wherein the data operation behavior includes data uploading, downloading, modifying and deleting; Step S3: Create an independent data sandbox for each user, wherein the data sandbox includes a computing sandbox and a boundary sandbox, which are used to isolate the data operation environment; Step S4: Generate contract rules according to the contract content, wherein the contract rules include subject, action, object and domain, and control the operation in the data sandbox according to the contract rules; Step S5: Compare the contents of the contract chain and the compliance record chain regularly to identify irregularities in data operation; Step S6: When the data operation is completed or the contract is terminated, destroy the data sandbox according to the contract rules.

[0005] Further, in step S1, the contract chain stores contract content using blockchain technology, ensuring the non-tamperability and traceability of the contract.

[0006] Further, in step S3, creating a data sandbox further includes the following sub-steps: Sub-step S3.1: According to the user identity and contract content, initializing a boundary sandbox, which includes a data input agent, a control center, and a bypass monitoring module; Sub-step S3.2: Initializing a computing sandbox, which includes a distributed computing service, an encrypted computing service, and a control center; Sub-step S3.3: Embedding the contract rules into the control center of the data sandbox, dynamically controlling data operations according to the contract rules; Sub-step S3.4: Configuring the data sandbox with communication modules, storage modules, encryption modules, and computing modules, providing distributed computing, distributed storage, user authentication, behavior authorization, auditing, and data leakage prevention services.

[0007] Further, in step S4, generating contract rules further includes the following sub-steps: Sub-step S4.1: Defining the subject of the contract rules, including operation executors, at least including audit procedures, deep packet detection procedures, or sandbox control nodes; Sub-step S4.2: Defining the action of the contract rules, including specific operation commands, at least including initialization, auditing, and destruction; Sub-step S4.3: Defining the object of the contract rules, including operation objects, at least including data, code, models, or sandboxes; Sub-step S4.4: Defining the domain of the contract rules, including operation environments or rule sets, at least including trust node lists, audit rules, or destruction rules; Sub-step S4.5: Converting the contract rules into a machine-readable format and storing them on the sandbox system server for controlling data operation processes.

[0008] Further, in step S2, when the compliance record chain records data operation behavior, it also includes data warehousing time, data flow path, and compliance check results.

[0009] Further, in step S5, when comparing the contract chain and the compliance record chain, it also includes checking whether the data operation exceeds the authorized period, whether the data usage range is compliant, and whether the data processing purpose is consistent with the contract.

[0010] Further, in step S6, when destroying the data sandbox, it also includes cleaning all data and computing traces in the sandbox and generating a destruction audit log.

[0011] Furthermore, in sub-step S3.1, the initialization of the boundary sandbox also includes configuring the listening rules of the data input agent and the contract execution logic of the control center.

[0012] Furthermore, the method also includes step S7: when a violation is identified, a violation alert is generated and the relevant responsible party is notified, while the data sandbox of the violation operation is suspended.

[0013] This invention proposes a data compliance design method based on a trusted data space scenario, aiming to ensure the security and compliance of data circulation. Before data operations, the agreed-upon usage contract is written into a blockchain contract chain to ensure the terms are immutable. All operations during circulation are recorded in real-time on another compliance record chain, achieving full auditability. An independent computing and boundary data sandbox is created for each user, providing an isolated operating environment. Data operations within the sandbox are dynamically controlled through machine-readable contract rules generated from the contract. By periodically comparing the content on the two chains, violations can be automatically identified. After contract termination, the sandbox and its data are securely destroyed. This invention achieves refined management, transparent supervision, and compliance assurance during data sharing and use. Attached Figure Description

[0014] Figure 1 A flowchart illustrating the workflow of a data compliance design method based on a trusted data space scenario, as claimed in an embodiment of the present invention. Figure 2 A second flowchart of a data compliance design method based on a trusted data space scenario, as claimed in an embodiment of the present invention; Figure 3 The third flowchart is a data compliance design method based on a trusted data space scenario, which is claimed in an embodiment of the present invention. Detailed Implementation

[0015] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of the embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0016] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a mutually exclusive, independent, or alternative embodiment. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0017] According to the first embodiment of the present invention, referring to Figure 1 This invention claims protection for a data compliance design method based on a trusted data space scenario, comprising: Step S1: Before the data operation begins, the authorizing party and the authorized party sign a data usage contract and write the contract content into the contract chain of the blockchain. The contract content includes authorizing party information, authorized party information, authorization period, data usage scope, data processing method and data processing purpose. Step S2: During the data circulation process, the data operation behavior is recorded and written into the compliance record chain of the blockchain. The data operation behavior includes data uploading, downloading, modification and deletion. Step S3: Create an independent data sandbox for each user, which includes a computing sandbox and a boundary sandbox to isolate the data operation environment; Step S4: Generate contract rules based on the contract content. The contract rules include subjects, actions, objects, and domains. Control the operations within the data sandbox according to the contract rules. Step S5: Periodically compare the contents of the contract chain with the compliance record chain to identify violations in data operations; Step S6: When the data operation is completed or the contract is terminated, the data sandbox is destroyed in accordance with the contract rules.

[0018] In this embodiment, the contract chain accurately records the initial contract details, including key information such as the authorizing party, the authorized party, the authorization period, and the scope of data use, ensuring that the contract content is tamper-proof and traceable.

[0019] The compliance record chain meticulously records all user actions on the trusted data space platform, such as uploading, downloading, modifying, and deleting data, forming a complete behavioral trajectory.

[0020] Finally, by periodically comparing the contract chain with the compliance record chain, violations in data operations can be quickly identified, providing a basis for data compliance management in a trustworthy data space and ensuring the transparency and auditability of data operations.

[0021] The contract is signed by the authorizing party and the authorized party, and the contract content is written into the contract chain. The contract content includes key information such as the information of the authorizing party and the authorized party, the authorization period, whether the data can be transferred, the scope of data transfer, the data processing method, and the purpose of data processing.

[0022] Data entry involves the data resource supply platform entering the data tables into the database, while simultaneously writing information such as the authorizing party, the authorized party, the authorization period, and the data entry time into the compliance record chain to ensure the compliance of the data source.

[0023] Data tables circulate within a trusted data space. The process and status of data circulation are recorded and written into a compliant record chain to ensure the transparency and traceability of data circulation.

[0024] The data table processing method is recorded and written into the compliance record chain to ensure that the data processing process complies with the contract.

[0025] Purpose of data processing: The purpose of data processing is recorded and written into the compliance record chain to ensure the legality and compliance of data processing.

[0026] Personal information data within the data is subject to compliance checks, and the results are written into the compliance record chain to ensure the compliance of the data content.

[0027] By comparing contracts and compliance records, and by comparing the contract chain and the compliance record chain, violations in data operations can be discovered, providing a basis for data compliance management in a trustworthy data space and ensuring the transparency and auditability of data operations.

[0028] Furthermore, in step S1, the contract chain uses blockchain technology to store the contract content, ensuring the immutability and traceability of the contract.

[0029] Furthermore, referring to Figure 2 In step S3, creating a data sandbox further includes the following sub-steps: Sub-step S3.1: Initialize the boundary sandbox according to the user's identity and contract content. The boundary sandbox includes a data input agent, a control center, and a bypass monitoring module. Sub-step S3.2: Initialize the computing sandbox, which includes a distributed computing service, an encrypted computing service, and a control center; Sub-step S3.3: Embed the contract rules into the control center of the data sandbox, and dynamically control data operations according to the contract rules; Sub-step S3.4: Configure the data sandbox with a communication module, storage module, encryption module and computing module to provide distributed computing, distributed storage, user authentication, behavior authorization, auditing and data leakage prevention services.

[0030] In this embodiment, the sandbox is divided into a computation sandbox and a boundary sandbox. The computation sandbox consists of three parts: CEndpointA, CEndpointB, and CEndpointC. CEndpointA is a traditional distributed computing service; CEndpointA serves as the endpoint of the computation sandbox, connecting other CEndpointA instances to form a distributed computing environment, such as HDFS, MapReduce, Spark, Mahout, and MLLIB. CEndpointC is a distributed computing service based on homomorphic encryption; CEndpointC connects other CEndpointC instances to form an encrypted distributed computing environment, such as federated learning. CEndpointB is the control center of the computation sandbox, connecting to different boundary sandboxes through embedded contracts and controlling CEndpointA and CEndpointC according to the contract rules.

[0031] The boundary sandbox consists of three parts: BEndpointA, BEndpointB, and BEndpointC. BEndpointA—the endpoint of the boundary sandbox—receives user input and accepts bypass monitoring and control from BEndpointC, while also being controlled by both BEndpointB and BEndpointC. BEndpointB—the control center of the boundary sandbox—connects to the computation sandbox through an embedded contract and controls both BEndpointA and the data receiver's BEndpointC according to the contract rules. BEndpointC—acting as a proxy for the data input party—performs bypass monitoring and control of BEndpointA.

[0032] The entire sandbox system will provide four main services: distributed computing, distributed storage, user authentication and behavior authorization, and auditing and data leakage prevention. The system's technical architecture is divided into four modules: communication, storage, encryption, and computing. The communication module ensures dynamic networking of nodes, distributed consistency, and breakpoint resumption; the storage module ensures distributed encrypted data storage and disaster recovery; the encryption module ensures the confidentiality and integrity of data storage and transmission; and the computing module provides users with big data computing and analysis services. It requires the following technical support: key management, distributed consistency, redundancy backup, distributed authentication and access control, distributed computing, and deep packet inspection.

[0033] The external interface information of the sandbox system is shown in Table 1; Table 1. External Interface Information of Sandbox System

[0034] Furthermore, referring to Figure 3In step S4, generating contract rules further includes the following sub-steps: Sub-step S4.1: Define the subject of the contract rules, including the operation execution body, which includes at least an auditing procedure, a deep message detection procedure, or a sandbox control node; Sub-step S4.2: Define the actions of the contract rules, including specific operation commands, at least including initialization, review, and destruction; Sub-step S4.3: Define the object of the contract rule, including the operation object, which includes at least data, code, model, or sandbox; Sub-step S4.4: Define the domain of the contract rules, including the operating environment or rule set, including at least a list of trusted nodes, audit rules, or destruction rules; Sub-step S4.5: Convert the contract rules into a machine-readable format and store them on the sandbox system server for controlling data operation processes.

[0035] In this embodiment, the contract is a series of activity rules within the sandbox system, including node allocation and data verification. These rules are jointly formulated and signed by the data requester and data provider, and govern behavior within the boundary sandbox and computation sandbox. Each service requires a contract, which includes the following sections, each further divided into four parts: Subject (the entity executing the contract rules), Action (the specific command to be executed), Object (the recipient of the action), and Domain (the environment or rules in which the command operates). The contract format is shown in Table 2.

[0036] Table 2 Overall Design of Contract Rules

[0037] (1) List of nodes that start the boundary sandbox: Subject-ClientsList (a list of nodes that can have control over the boundary sandbox), Action-init (command to start the sandbox), Object-BoundarySandbox (the boundary sandbox), Domain-HostsList (a list of trusted nodes for running the boundary sandbox). (2) List of startup nodes for the computing sandbox: Subject-SandboxServer (sandbox service), Action-init (start sandbox command), Object-ComputeSandbox (computation sandbox), Domain-HostsList (list of trusted nodes for running the computing sandbox); (3) Code upload review rules: Subject-AduitProgram (review program), Action-reviewCode (review code), Object-Code (uploaded code), Domain-HostsList (code review rules); (4) Data upload review rules: Subject-AduitProgram (review program), Action-reviewInputData (review data), Object-InputData (uploaded data), Domain (shared data rules); (5) Download model monitoring rules: Subject-DPI (deep message detection program), Action-reviewModel (detection training model), Object-Model (the model obtained after calculation), Domain (model detection rules); (6) Download data monitoring rules: Subject-DPI (deep packet inspection program), Action-reviewOutputData (detect download data), Object-OutputData (downloaded data), Domain (shared data rules); (7) Boundary Sandbox Destruction Rules: Subject-BoundarySandboxOwner (Boundary Sandbox Control Node), Action-burn (Destruction), Object-BoundarySandbox (Boundary Sandbox), Domain-BurningRules (Destruction Rules); (8) Calculation sandbox destruction rules: Subject-SandboxServer (sandbox service), Action-burn (destruction), Object-BoundarySandbox (computation sandbox), Domain-BurningRules (destruction rules); Furthermore, in step S2, when the compliance record chain records data operation behavior, it also includes data entry time, data flow path, and compliance inspection results.

[0038] Furthermore, in step S5, when comparing the contract chain with the compliance record chain, it also includes checking whether the data operation exceeds the authorization period, whether the scope of data use is compliant, and whether the purpose of data processing is consistent with the contract.

[0039] Furthermore, in step S6, when destroying the data sandbox, it also includes cleaning up all data and computational traces within the sandbox and generating a destruction audit log.

[0040] Furthermore, in sub-step S3.1, the initialization of the boundary sandbox also includes configuring the listening rules of the data input agent and the contract execution logic of the control center.

[0041] In this embodiment, the sandbox processing flow includes: The data requester downloads the contract form from the system, fills it out, and uploads it to the sandbox system server. The sandbox system server reviews the contract submitted by the data requester to determine if it complies with system rules. If it does not, the data requester is notified to modify the contract or abandon the application; if it complies, the data provider receives the contract submitted by the data requester, reviews it, and signs it. The data provider reviews and signs the contract. If the review fails, the data applicant A is notified to modify the contract or abandon the application. After the review is approved, the sandbox system server verifies the contract, opens the boundary sandbox between the data applicant and the data provider, and embeds the contract. After the sandbox system server verifies the contract, the data requester activates the relevant service programs in the boundary sandbox, reviews the code according to the contract requirements, and uploads the code to the boundary sandbox; the data provider activates the relevant service programs in the boundary sandbox as needed, reviews the data according to the contract, uploads it to the boundary sandbox, connects with the data requester, and activates the monitoring service program.

[0042] After the data provider connects with the data requester and starts the monitoring service program, the sandbox system server selects trusted computing nodes and starts the computing sandbox according to the contract requirements.

[0043] After the sandbox system server selects trusted computing nodes and starts the computing sandbox according to the contract requirements, the data requester uploads data and sends the analysis model according to the contract requirements; the data provider monitors and reviews the data call of the data requester according to the contract. Finally, the boundary sandbox is destroyed after the data requester completes the upload; the boundary sandbox is destroyed after the data provider completes the monitoring; and the computation sandbox is destroyed after the sandbox system server completes the calculation.

[0044] Furthermore, the method also includes step S7: when a violation is identified, a violation alert is generated and the relevant responsible party is notified, while the data sandbox of the violation operation is suspended.

[0045] The technical effects achieved by this invention include at least the following: By integrating blockchain and sandbox technologies, this innovative approach combines the immutability and traceability of blockchain with the isolation and security of a data sandbox, enabling comprehensive monitoring and refined management of data operations.

[0046] The dual-chain data monitoring system employs two independent blockchains: a contract chain and a compliance record chain. These blockchains separately record contract details and operational behaviors, forming a complete behavioral trajectory. By comparing the two chains, violations can be quickly identified, providing a basis for data compliance management and ensuring operational transparency and auditability.

[0047] A contract-driven sandbox system defines data operation rules in the form of contracts, covering elements such as subjects, actions, objects, and domains, enabling fine-grained control over data operations. Based on these contractual rules, the sandbox system rigorously reviews and monitors the behavior of data requesters and providers, ensuring the legality and compliance of data processing.

[0048] Multi-dimensional data security is ensured through a collaborative computing sandbox and boundary sandbox, which are responsible for data computation and boundary control respectively, creating a multi-layered isolation environment to prevent data leakage and misuse. The sandbox system provides services such as distributed computing, storage, user authentication, behavior authorization, auditing, and data leakage prevention, comprehensively protecting data security.

[0049] Process data compliance management records and monitors all data operations from signing, storage, transfer, processing to destruction, ensuring compliance throughout the data lifecycle. Real-time monitoring and auditing promptly identify and intervene in violations, preventing potential losses and promoting the security and reliability of data sharing and circulation.

[0050] To enhance the transparency and auditability of data operations, blockchain technology records the entire data operation process, forming an immutable audit record. This allows regulatory agencies and internal audit departments to view the data operation history at any time, quickly detect violations, and improve the transparency and trustworthiness of data management.

[0051] To enhance data security, data sandboxes provide an isolated environment for data operations, preventing data leaks and misuse. Even during data sharing and computation, data remains under the protection of the sandbox, ensuring its confidentiality, integrity, and availability. Furthermore, the sandbox system has data leakage prevention capabilities, further reducing data security risks.

[0052] This invention enables compliant management of data throughout its entire lifecycle, covering all stages from data generation to destruction. It ensures that the use of data in a trusted data space complies with legal and regulatory requirements, such as the Data Security Law and the Personal Information Protection Law, effectively avoiding legal risks and economic losses caused by data violations.

[0053] Promoting data sharing and circulation involves clarifying the responsibilities of all parties in data sharing scenarios, resolving trust issues between data providers and users, providing reliable technical support for data sharing and circulation, promoting the healthy development of the data element market, and unlocking the value of data.

[0054] The specific embodiments of the invention have been described in detail above, but they are only examples, and this application is not limited to the specific embodiments described above. For those skilled in the art, any equivalent modifications or substitutions to the invention are also within the scope of this application. Therefore, all equivalent changes, modifications, and improvements made without departing from the spirit and principles of this application should be covered within the scope of this application.

Claims

1. A method for data compliance design based on trusted data space scenario, characterized in that, The application comprises the following steps: Step S1: Before the start of data operation, the authorized party signs a data use contract with the authorized party, and writes the contract content into the contract chain of the blockchain, including authorized party information, authorized party information, authorization period, data use range, data processing method and data processing purpose; Step S2: In the process of data flow, the data operation behavior record is written into the compliance record chain of the blockchain, including data uploading, downloading, modifying and deleting; Step S3: An independent data sandbox is created for each user, including a computing sandbox and a boundary sandbox, which is used to isolate the data operation environment; Step S4: Generate contract rules according to the contract content, including subject, action, object and domain, and control the operation in the data sandbox according to the contract rules; Step S5: Compare the contents of the contract chain and the compliance record chain regularly to identify irregularities in data operation; Step S6: When the data operation is completed or the contract is terminated, the data sandbox is destroyed according to the contract rules.

2. A data compliance design method based on a trusted data space scenario as claimed in claim 1, wherein, In step S1, the contract chain uses blockchain technology to store contract content, ensuring the non-tamperability and traceability of the contract.

3. A data compliance design method based on a trusted data space scenario as claimed in claim 1, wherein, In step S3, creating a data sandbox also includes the following sub-steps: Sub-step S3.1: Initialize the boundary sandbox according to the user identity and contract content, including data input agent, control center and bypass monitoring module; Sub-step S3.2: Initialize the computing sandbox, which includes distributed computing service, encryption computing service and control center; Sub-step S3.3: Embed the contract rules into the control center of the data sandbox, and dynamically control the data operation according to the contract rules; Sub-step S3.4: Configure communication module, storage module, encryption module and computing module for the data sandbox, providing distributed computing, distributed storage, user authentication, behavior authorization, audit and data leakage prevention services.

4. The method of claim 1, wherein the method is based on a trusted data space scenario for data compliance design, and In step S4, generating contract rules also includes the following sub-steps: Sub-step S4.1: Define the subject of the contract rules, including operation execution body, at least including audit program, deep packet detection program or sandbox control node; Sub-step S4.2: Define the action of the contract rules, including specific operation command, at least including initialization, audit and destruction; Sub-step S4.3: Define the object of the contract rules, including operation object, at least including data, code, model or sandbox; Sub-step S4.4: Define the domain of the contract rules, including operation environment or rule set, at least including trust node list, audit rule or destruction rule; Sub-step S4.5: Convert the contract rules into machine-readable format and store them in the sandbox system server to control the data operation process.

5. The method of claim 1, wherein the method is based on a trusted data space scenario for data compliance design, and In step S2, when the compliance record chain records the data operation behavior, it also includes data warehousing time, data flow path and compliance check result.

6. A data compliance design method based on a trusted data space scenario as claimed in claim 1, wherein, In the step S5, when comparing the contract chain with the compliance record chain, it also includes checking whether the data operation exceeds the authorized period, whether the data usage range is compliant, and whether the data processing purpose is consistent with the contract.

7. A data compliance design method based on a trusted data space scenario as claimed in claim 1, wherein, In the step S6, when destroying the data sandbox, it also includes cleaning all data and computing traces in the sandbox, and generating a destruction audit log.

8. A data compliance design method based on a trusted data space scenario as claimed in claim 3, wherein, In the sub-step S3.1, the initialization of the boundary sandbox also includes configuring the listening rules of the data input agent and the contract execution logic of the control center.

9. A data compliance design method based on a trusted data space scenario as claimed in claim 1, wherein, It also includes a step S7: when a violation is identified, a violation alert is generated and the relevant responsible party is notified, and the data sandbox of the violating operation is suspended.

Citation Information

Patent Citations

  • Data contract type opening method based on data sandbox and related equipment

    CN116628682A

  • Cross-chain data transmission type sandbox supervision method and system for ideal lattice attribute encryption on block chain

    CN119577034A

  • Data asset life cycle management method and system based on block chain

    CN119963187A

  • Automobile trusted data space system

    CN120408673A

  • System and method for generating sandbox environments in a computing network

    US20250315515A1