Traffic data asset full life cycle management method based on trusted data space

By employing a traffic data management approach based on a trusted data space and utilizing digital identity authentication and smart contract technologies, the problems of ownership definition, untrusted source, value quantification, and usage control in traffic data management have been solved. This approach enables trusted data management and automated compliance throughout the entire data lifecycle, thereby enhancing the credibility and security of data management.

CN121882931APending Publication Date: 2026-04-17BEIJING ZHONGKEHUIJU SCI & TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING ZHONGKEHUIJU SCI & TECH CO LTD
Filing Date
2026-01-20
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing traffic data management technologies suffer from problems such as difficulty in defining data ownership, unreliable sources, lack of value quantification, rough use control, and lack of full lifecycle management. This results in low levels of automation in compliance management and makes it difficult to achieve refined control and secure data destruction.

Method used

By adopting a trusted data space-based approach, the identity and integrity of the data source are verified through digital identity authentication and cryptographic signature technology. A trusted label is generated and a globally unique asset identifier is attached. A weighted multidimensional evaluation model is used for value assessment, which is then encoded into a smart contract and deployed to the blockchain to achieve fine-grained access control and automated compliance management.

Benefits of technology

It enables trusted verification, ownership registration, dynamic valuation, smart contract-based circulation, and secure disposal of traffic data, thereby improving the credibility and compliance of data management, reducing compliance and operating costs, and ensuring data security and integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121882931A_ABST
    Figure CN121882931A_ABST
Patent Text Reader

Abstract

The invention discloses a traffic data asset full life cycle management method based on a trusted data space, and the method comprises the steps: verifying the data source identity and integrity of traffic data through employing a digital identity authentication and cryptographic signature technology, and generating an asset identifier and asset metadata; performing digital signature on the asset identifier and the data hash by using a private key of the initial contributor, generating an initial ownership certificate, and submitting the initial ownership certificate to the block chain; determining a value evaluation result of the asset metadata by using a weighted multi-dimensional evaluation model, and submitting the value evaluation result to the block chain; coding the contract into an automatically executed intelligent contract through asset data, checking contract logic consistency through a formalized verification engine, and deploying the contract to a block chain to obtain a contract address; and the asset metadata and the contract address are bound and then published to a data flow network. According to the method, full-process management of credible verification, right confirmation registration, dynamic valuation, intelligent contract circulation, compliance use control and safety disposal of multi-source heterogeneous data in the traffic field is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of traffic data management technology, specifically to a method for full lifecycle management of traffic data assets based on a trusted data space. Background Technology

[0002] The rapid development of intelligent transportation has generated massive amounts of traffic data, including vehicle trajectories, road condition information, signal control, parking status, and charging records. This data has become a key production factor, but current management and utilization of this data face the following technological bottlenecks:

[0003] 1. Difficulty in defining data ownership: Existing technologies lack a clear mechanism for defining the boundaries of rights among data contributors, processors and users. Traditional database systems only provide access control and cannot generate legally valid ownership certificates.

[0004] 2. Inability to verify the credibility of data sources: Existing data collection systems lack a reliable verification mechanism for the data generation process, posing a risk of data tampering and forgery. Traditional hash verification can only verify integrity, not the true identity of the source.

[0005] 3. Lack of a value quantification system: There is a lack of a multi-dimensional valuation model that combines cost, quality, scarcity, and application scenarios. Traditional pricing relies on manual evaluation and cannot reflect the true market value of data in different scenarios.

[0006] 4. Insufficient fine-grained usage control: Existing access control technologies can only achieve coarse-grained permission management, making it difficult to achieve fine-grained control such as "data is available but not visible" and "use according to the contract, and stop when the contract is exceeded".

[0007] 5. Low level of automation in compliance management: The Personal Information Protection Law grants personal information subjects multiple rights, but existing systems rely heavily on manual processes and lack automated compliance engines and a full-process evidence chain generation mechanism.

[0008] 6. Lack of full lifecycle management: Existing solutions mostly focus on specific stages and lack a unified and reliable management framework covering registration, circulation, use, archiving and destruction. In particular, there is a lack of technical means to prove that the data has been securely and thoroughly destroyed. Summary of the Invention

[0009] To address these issues, this application provides a method for full lifecycle management of traffic data assets based on a trusted data space, in order to solve the problems of unclear ownership, unreliable sources, difficulty in quantifying value, difficulty in controlling use, high compliance costs, and lack of full-process traceability in existing traffic data management methods.

[0010] To achieve the above objectives, this application provides the following technical solution:

[0011] Firstly, a method for full lifecycle management of transportation data assets based on a trusted data space includes:

[0012] Step 1: Collect raw traffic data from the data source and perform data preprocessing;

[0013] Step 2: Use digital identity authentication and cryptographic signature technology to verify the identity of the data source and the integrity of the preprocessed raw traffic data. After successful verification, attach a trusted label to the raw traffic data.

[0014] Step 3: Use standardized registration to generate a globally unique asset identifier for the verified raw traffic data and generate asset metadata;

[0015] Step 4: Use the private key of the initial contributor to digitally sign the asset identifier and data hash of the asset metadata, generate the initial ownership certificate, and submit it to the blockchain to obtain the evidence circulation identifier.

[0016] Step 5: Use a pre-built weighted multidimensional evaluation model to determine the asset valuation and credit rating of the asset metadata, obtain the value assessment result, and submit the value assessment result to the blockchain corresponding to the asset metadata;

[0017] Step 6: The asset data is encoded into an automatically executable smart contract, and after the contract logic is checked for consistency by a formal verification engine, it is deployed to the blockchain to obtain the contract address;

[0018] Step 7: After binding the asset metadata with the contract address, publish it to the data circulation network.

[0019] As a preferred option, it also includes:

[0020] The system receives and verifies data access requests with access tokens initiated by data requesters. After successful verification, the system routes the computing task to the designated privacy computing environment according to the contract requirements, performs data processing in the privacy computing environment, generates a metering certificate with a timestamp and digital signature, and submits the metering certificate to the smart contract to trigger fee settlement before submitting it to the blockchain for evidence storage.

[0021] As a preferred option, it also includes:

[0022] The asset repository is scanned periodically to identify assets that meet the conditions for archiving or destruction based on preset criteria. The metadata of assets that meet the archiving conditions is migrated to cold storage, and the asset status is updated before being submitted to the blockchain for storage. The metadata of assets that meet the destruction conditions is used to generate destruction proposals and initiate a multi-party approval process. After approval, destruction instructions are sent to all storage nodes that store data copies. The storage nodes perform physical-level security erasure and generate destruction certificates before submitting them to the blockchain for storage.

[0023] As a preferred option, it also includes:

[0024] The system receives rights requests from individuals, uses privacy-preserving retrieval technology to locate all data assets containing personal information based on the rights requests, retrieves all smart contracts bound to all data assets, analyzes the impact of executing the rights requests on contract performance, provides feedback on the processing results to the individuals, and submits the processing results to the blockchain for storage.

[0025] As a preferred option, step 2 specifically includes: verifying the validity of the digital certificate of the data acquisition device, and using the public key of the digital certificate to verify the digital signature of the preprocessed original traffic data, verifying the rationality of the timestamp and the sequence logic, and after the verification is passed, attaching a trusted label containing the verification time, verification method and credibility score to the original traffic data.

[0026] Preferably, in step 3, the asset metadata includes: data summary, data hash value, trusted tag, initial contributor information, and anonymous identifier of the associated personal information subject.

[0027] Preferably, in step 5, the weighted multidimensional evaluation model is pre-constructed by integrating cost input, data quality, scenario utility, and market supply and demand.

[0028] Secondly, a transportation data asset lifecycle management system based on a trusted data space includes:

[0029] The multi-source data access and preprocessing module is used to collect raw traffic data from data sources and perform data preprocessing.

[0030] The data source trust verification module is used to verify the data source identity and data integrity of the preprocessed raw traffic data using digital identity authentication and cryptographic signature technology. After the verification is successful, a trust label is attached to the raw traffic data.

[0031] The data asset registration module is used to generate globally unique asset identifiers for verified raw traffic data using standardized registration, and to generate asset metadata.

[0032] The data asset ownership confirmation module uses the private key of the initial contributor to digitally sign the asset identifier and data hash of the asset metadata, and then submits the initial ownership certificate to the blockchain to obtain a certificate of evidence circulation.

[0033] The data asset valuation and pricing module is used to determine the asset valuation and credit rating of asset metadata using a pre-built weighted multidimensional valuation model, obtain the valuation result, and submit the valuation result to the blockchain corresponding to the asset metadata.

[0034] The data asset smart contract management module is used to encode asset data into automatically executed smart contracts, and after checking the consistency of the contract logic through a formal verification engine, it is deployed to the blockchain to obtain the contract address;

[0035] The Data Asset Circulation and Contractual Data Circulation Network Module is used to bind asset metadata with contract addresses and then publish it to the data circulation network.

[0036] As a preferred option, it also includes:

[0037] The data asset access control and trusted metering module receives and verifies data access requests with access tokens initiated by data requesters. After successful verification, it routes the computing task to the designated privacy computing environment according to the contract requirements, performs data processing in the privacy computing environment, generates metering certificates with timestamps and digital signatures, and submits the metering certificates to the smart contract to trigger fee settlement before submitting them to the blockchain for evidence storage.

[0038] As a preferred option, it also includes:

[0039] The data asset lifecycle strategy engine is used to periodically scan the asset repository, identify assets that meet the conditions for archiving or destruction based on preset criteria, migrate the metadata of assets that meet the archiving conditions to cold storage, update the asset status, and submit it to the blockchain for storage; generate destruction proposals for the metadata of assets that meet the destruction conditions, initiate a multi-party approval process, and send destruction instructions to all storage nodes storing data copies after approval; the storage nodes perform physical-level security erasure, generate destruction proofs, and submit them to the blockchain for storage.

[0040] The Data Compliance and Information Subject Rights Management module is used to receive rights requests from personal information subjects, locate all data assets containing personal information using privacy-preserving retrieval technology based on the rights requests, retrieve all smart contracts bound to all data assets, analyze the impact of executing the rights requests on contract performance, provide feedback on the processing results to the personal information subjects, and submit the processing results to the blockchain for storage.

[0041] Compared with the prior art, this application has at least the following beneficial effects:

[0042] Based on further analysis and research of existing technical problems, this application provides a method for full lifecycle management of transportation data assets based on a trusted data space. The method includes: verifying the source identity and data integrity of original transportation data using digital identity authentication and cryptographic signature technology; attaching a trusted label to the original transportation data after successful verification; generating a globally unique asset identifier for the verified original transportation data using standardized registration, and generating asset metadata; digitally signing the asset identifier and data hash of the asset metadata using the private key of the initial contributor, generating an initial ownership certificate, and submitting it to the blockchain to obtain a notarized circulation identifier; determining the asset valuation and credit rating of the asset metadata using a pre-built weighted multidimensional evaluation model, obtaining a value assessment result, and submitting the value assessment result to the blockchain corresponding to the asset metadata; encoding the asset data into an automatically executable smart contract, checking the contract logic consistency through a formal verification engine, and deploying it to the blockchain to obtain a contract address; binding the asset metadata with the contract address and publishing it to the data circulation network. This method realizes full-process management of trusted verification, ownership registration, dynamic valuation, smart contract-based circulation, compliant use control, and secure disposal of multi-source heterogeneous data in the transportation field. Attached Figure Description

[0043] To more intuitively illustrate the prior art and this application, exemplary drawings are provided below. It should be understood that the specific shapes and structures shown in the drawings should not generally be regarded as limiting conditions for implementing this application; for example, based on the technical concept disclosed in this application and the exemplary drawings, those skilled in the art are able to easily make conventional adjustments or further optimizations to the addition / reduction / classification, specific shapes, positional relationships, connection methods, size ratios, etc. of certain units (components).

[0044] Figure 1 A flowchart illustrating a method for full lifecycle management of transportation data assets based on a trusted data space, provided in Embodiment 1 of this application;

[0045] Figure 2 This is a diagram illustrating the full lifecycle state migration of traffic data assets provided in Embodiment 1 of this application.

[0046] Figure 3 A detailed sequence diagram of the data source trust verification, asset registration, and ownership confirmation process provided in Embodiment 1 of this application;

[0047] Figure 4 The following is a logic diagram of the data asset dynamic value assessment algorithm based on multi-dimensional factors provided in Embodiment 1 of this application;

[0048] Figure 5 This is a sequence diagram of data asset circulation, authorization, and controlled access based on smart contracts provided in Embodiment 1 of this application;

[0049] Figure 6 This is a flowchart illustrating the closed-loop process for secure destruction and evidence preservation of data assets, provided in Embodiment 1 of this application.

[0050] Figure 7 This is a flowchart of an automated compliance process for responding to a data subject's deletion request, provided in Embodiment 1 of this application.

[0051] Figure 8 This is a diagram illustrating the architecture of a traffic data asset lifecycle management system based on a trusted data space, provided in Embodiment 2 of this application.

[0052] Figure 9 This is a general architecture diagram of a traffic data asset lifecycle management system based on a trusted data space, provided in Embodiment 2 of this application.

[0053] Figure 10 This is a diagram illustrating the data asset lifecycle monitoring and dynamic compliance check architecture provided in Embodiment 2 of this application. Detailed Implementation

[0054] The present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0055] In the description of this application: unless otherwise stated, "a plurality of" means two or more. The terms "first," "second," "third," etc., in this application are intended to distinguish the objects referred to and do not have any special meaning in terms of technical connotation (e.g., they should not be construed as an emphasis on importance or order). Expressions such as "including," "comprising," and "having" also mean "not limited to" (certain units, components, materials, steps, etc.).

[0056] The terms used in this application, such as "upper," "lower," "left," "right," and "middle," are generally used to indicate the general relative positional relationship for the purpose of intuitive understanding by referring to the accompanying drawings, and are not absolute limitations on the positional relationship in the actual product.

[0057] Example 1

[0058] Please see Figure 1 , Figure 2 and Figure 3 This embodiment provides a method for full lifecycle management of transportation data assets based on a trusted data space, including:

[0059] S1: Collect raw traffic data from the data source and perform data preprocessing;

[0060] Specifically, this step involves collecting raw traffic data from sources such as vehicle terminals and roadside equipment, and performing data preprocessing, which includes data cleaning, format standardization, and de-identification.

[0061] S2: Use digital identity authentication and cryptographic signature technology to verify the identity of the data source and the integrity of the preprocessed raw traffic data. After successful verification, attach a trusted label to the raw traffic data.

[0062] Specifically, this step verifies the validity of the digital certificate of the data collection device, uses the public key of the digital certificate to verify the digital signature of the data packet (i.e., the original traffic data), verifies the rationality of the timestamp and the sequence logic, and prevents replay attacks; after the verification is passed, a trusted label containing the verification time, verification method and trust score is attached to the data.

[0063] This step, at the starting point of data assetization, verifies the digital certificate of the data acquisition device and checks the data packet signature and timestamp to ensure the authenticity and trustworthiness of the data source. This step employs a triple verification mechanism: digital certificate chain verification, SM2 digital signature verification, and timestamp logic check, ensuring the authenticity and trustworthiness of the data source. Trustworthiness score, as an important component of the quality factor, significantly impacts asset valuation.

[0064] S3: Utilize standardized registration to generate globally unique asset identifiers for verified raw traffic data and generate asset metadata;

[0065] Specifically, this step generates a globally unique asset identifier for the original traffic data through standardized registration, and creates structured asset metadata that includes data summary, data hash value, trusted label, initial contributor information, and anonymous identifiers associated with the personal information subjects.

[0066] S4: Use the private key of the initial contributor to digitally sign the asset identifier and data hash of the asset metadata, generate the initial ownership certificate, and submit it to the blockchain to obtain the evidence circulation identifier.

[0067] Specifically, this step uses the private key used by the initial contributor to digitally sign the asset identifier and data hash of the asset metadata and generate an initial ownership certificate; the asset identifier, metadata hash, and ownership certificate are submitted to the blockchain to complete the asset registration and notarization and obtain a notarized circulation identifier.

[0068] This step generates ownership certificates through the contributor's digital signature and preserves them immutably using a distributed ledger.

[0069] S5: Use a pre-built weighted multidimensional evaluation model to determine the asset valuation and credit rating of the asset metadata, obtain the value assessment result, and submit the value assessment result to the blockchain corresponding to the asset metadata;

[0070] For details, please refer to Figure 4This embodiment pre-establishes a weighted multi-dimensional evaluation model that integrates cost input, data quality, scenario utility, and market supply and demand. The cost factor covers acquisition, storage, processing, and compliance costs; the quality factor comprehensively evaluates completeness, accuracy, timeliness, consistency, and credibility; the utility factor is calculated based on the matching degree between asset tags and application scenarios; and the market factor is dynamically adjusted according to recent transaction prices and supply and demand relationships. This step uses a weighted summation formula to calculate asset valuation and credit rating, which are regularly updated and stored on the blockchain.

[0071] In other words, this step involves activating a value assessment engine to calculate cost factors (collection, storage, processing, and compliance costs), evaluate quality factors (completeness, accuracy, timeliness, consistency, and credibility), analyze utility factors (scenario matching and premium coefficient), and obtain market factors (transaction price and supply-demand relationship). Then, based on a weighted multidimensional assessment model, the asset valuation and credit rating are calculated, and the valuation results are updated to the asset metadata and submitted to the blockchain for notarization. Periodic reassessments and dynamic valuation updates are performed. It should be noted that in this embodiment, the weights can be dynamically configured according to industry characteristics.

[0072] S6: The asset data is encoded into an automatically executed smart contract, and after the contract logic is checked for consistency by a formal verification engine, it is deployed to the blockchain to obtain the contract address;

[0073] For details, please refer to Figure 5 In this step, the data provider configures the contract terms using a visual editor, including usage restrictions, privacy protection requirements, personal information protection agreements, access quotas, billing methods, and validity period. A formal verification engine performs static analysis on the contract logic, detecting potential vulnerabilities or conflicting clauses. The data provider signs the contract content using their private key. The smart contract is then deployed to the blockchain, obtaining the contract address.

[0074] This step encodes data usage rules, access restrictions, privacy protection requirements, billing models, and compliance terms into automatically executable smart contracts. Contract terms include restrictions on the purpose of use, technical measures requirements, personal information protection agreements, access quotas, fee settlement, liability for breach of contract, and validity period. The contract logic consistency is checked using a formal verification engine, and it is automatically executed after deployment to the blockchain.

[0075] This step encodes complex data into smart contracts using strategies, achieving automated governance through "code as rules." The contract terms cover comprehensive constraints, including purpose of use, technical measures, privacy protection, quota limits, billing and settlement, and liability for breach of contract. A formal verification engine ensures that the contract logic is conflict-free.

[0076] S7: After binding the asset metadata with the contract address, publish it to the data circulation network.

[0077] Specifically, this step involves binding the asset metadata with the contract address and then publishing the binding relationship between the asset and the contract to the data circulation network.

[0078] This embodiment provides a method for full lifecycle management of transportation data assets based on a trusted data space, which further includes:

[0079] The system receives and verifies data access requests with access tokens initiated by data requesters. After successful verification, the system routes the computing task to the designated privacy computing environment according to the contract requirements, performs data processing in the privacy computing environment, generates a metering certificate with a timestamp and digital signature, and submits the metering certificate to the smart contract to trigger fee settlement before submitting it to the blockchain for evidence storage.

[0080] Specifically, in this embodiment, the data requester retrieves the target asset and its associated contracts through a data circulation network and reviews the contract terms online. If they agree, they sign the contract using their private key. The smart contract automatically verifies the requester's qualifications. After the requester fulfills the preconditions stipulated in the contract, the contract status is updated to "activated." The smart contract automatically generates an access token, which includes the contract address, authorized operation type, validity period, quota limit, etc., and sends it to the requester through an encrypted channel after signing it with the contract's private key. The transaction event is then submitted to the blockchain for evidence storage.

[0081] The requesting party initiates a data access request carrying an access token. The access control module intercepts the request, parses the token to extract the contract address, queries the blockchain to verify the current state of the contract and the validity of the token, and verifies the token signature. It extracts parameters such as the operation type, data range, and target environment of the request, compares it with the smart contract terms to determine compliance, checks quota limits, and assesses environmental security. Upon successful verification, the computational task is routed to the designated privacy computing environment according to contract requirements. Data processing is performed in the privacy computing environment, ensuring that the requesting party cannot access the raw data. The trusted metering unit accurately measures the data access volume and computing resource consumption, generating a metering certificate with a timestamp and digital signature. The metering certificate is submitted to the smart contract to trigger fee settlement and then submitted to the blockchain for notarization.

[0082] This implementation achieves "data usable but not visible" through privacy-preserving computing technologies such as trusted execution environments, secure multi-party computation, and federated learning. The access control module verifies the access tokens issued by the smart contract, executes fine-grained authorization according to the contract terms, and routes computing tasks to qualified privacy-preserving computing environments. Data usage and computing resource consumption are precisely measured, and the measurement results are submitted to the smart contract and stored on the blockchain.

[0083] This embodiment provides a method for full lifecycle management of transportation data assets based on a trusted data space, which further includes:

[0084] The asset repository is scanned periodically to identify assets that meet the conditions for archiving or destruction based on preset criteria. The metadata of assets that meet the archiving conditions is migrated to cold storage, and the asset status is updated before being submitted to the blockchain for storage. The metadata of assets that meet the destruction conditions is used to generate destruction proposals and initiate a multi-party approval process. After approval, destruction instructions are sent to all storage nodes that store data copies. The storage nodes perform physical-level security erasure and generate destruction certificates before submitting them to the blockchain for storage.

[0085] Specifically, the lifecycle strategy engine periodically scans the asset repository, identifying assets that meet archiving or destruction conditions based on factors such as archiving duration, contract status, and access frequency. For assets meeting archiving conditions, data is migrated to cold storage, the asset status is updated, and the data is recorded on the blockchain. For assets meeting destruction conditions, a destruction proposal is generated. Prerequisites are checked: whether there are any outstanding compliance requests, regulatory freeze orders, or whether the statutory minimum retention period has expired. A multi-party approval process is initiated, requiring digital signature authorization from pre-defined roles such as data asset administrators and compliance officers. After authorization, a destruction instruction is sent to all nodes storing data copies. Storage nodes perform physical-level secure erasure, overwriting data blocks multiple times to generate a destruction certificate containing the erasure algorithm, timestamp, and operator signature. The destruction coordinator collects and verifies the destruction certificates from all nodes. The destruction proposal, authorization signature, and destruction certificate are submitted to the blockchain for evidence storage. The asset status is updated to destroyed, and the complete evidence storage chain for the asset is sealed. A minimal metadata set is reserved for regulatory auditing, such as... Figure 6 As shown.

[0086] This embodiment utilizes blockchain technology to immutably record key events throughout the entire process of data asset registration and destruction. Events such as asset registration, value assessment, contract deployment, access measurement, compliance operations, status changes, and secure destruction are all synchronously recorded on the blockchain, forming a complete audit trail chain. The destruction process requires multi-party approval and authorization. After the storage node performs physical-level secure erasure, a destruction certificate is generated, and finally, the destruction event is recorded on the blockchain and the evidence chain is sealed.

[0087] This embodiment employs a data erasure protocol conforming to DoD 5220.22-M or higher standards, overwriting the data block more than seven times. The destruction process requires multi-party approval and authorization, with each storage node independently generating a destruction certificate. Finally, the complete destruction evidence is uploaded to the blockchain for storage, ensuring that the data is completely destroyed and verifiable.

[0088] This embodiment provides a method for full lifecycle management of transportation data assets based on a trusted data space, which further includes:

[0089] The system receives rights requests from individuals, uses privacy-preserving retrieval technology to locate all data assets containing personal information based on the rights requests, retrieves all smart contracts bound to all data assets, analyzes the impact of executing the rights requests on contract performance, provides feedback on the processing results to the individuals, and submits the processing results to the blockchain for storage.

[0090] Specifically, this embodiment receives a rights request from a personal information subject and verifies their identity. Privacy-preserving retrieval technology is used to locate all data assets containing the subject's information. All smart contracts bound to these assets are retrieved, and the impact of executing the rights request on contract performance is analyzed. The legality of the request is assessed according to relevant provisions of the Personal Information Protection Law, and any exemptions are checked. For operations requiring multi-party consent, a multi-signature authorization process is automatically initiated. After authorization, operation instructions are sent to the storage node to execute operations such as viewing, copying, correcting, deleting, or transferring. For deletion requests, physical-level data erasure or precise anonymization is performed. Proof of operation completion is collected. Asset metadata is updated, marking that the operation has been legally executed. The rights request, legal basis, authorization signature, and operation proof are packaged into compliant evidence and submitted to the blockchain for storage. The processing result and blockchain storage certificate are fed back to the personal information subject, such as... Figure 7 As shown.

[0091] This embodiment incorporates regulatory compliance logic, automatically parsing and responding to the rights requests of individuals. It locates relevant data assets through privacy-preserving retrieval technology, assesses the legality of requests according to the Personal Information Protection Law, and triggers automated operations such as viewing, copying, correcting, deleting, and transferring data after coordinating authorization from multiple parties. It collects operational evidence and submits the complete compliance process to the blockchain for evidence storage. Through this closed-loop process of privacy-preserving retrieval, legality assessment, multi-party authorization coordination, automated operation execution, and the generation of a complete chain of evidence, compliance costs and risks are significantly reduced.

[0092] This embodiment provides a method for full lifecycle management of transportation data assets based on a trusted data space, supporting simultaneous submission of evidence to multiple consortium blockchains (i.e., cross-domain trusted mutual recognition), and synchronizing evidence information through a cross-chain relay network. A digital identity federation is established based on the W3C DID standard to achieve "one-time registration, full-domain mutual recognition." Standardized contract interface specifications are defined to support cross-domain smart contract interoperability.

[0093] In this embodiment, key events such as asset registration, valuation updates, contract deployment, access measurement, compliance operations, status changes, and secure destruction are automatically triggered for blockchain-based evidence storage in all the steps described above. Each evidence storage session includes the event type, asset identifier, event content hash, timestamp, and operator signature. All evidence storage records form an immutable audit trail chain in chronological order, supporting regulatory audits, judicial evidence collection, dispute resolution, and ownership tracing, achieving full lifecycle evidence storage chain maintenance.

[0094] Example 1: Data Source Trust Verification Process

[0095] A connected car manufacturer's in-vehicle terminal collects and uploads driving data. The terminal has a built-in digital certificate and uses its private key to perform SM2 signing on data packets and timestamps. The data packets are uploaded to the cloud via a TLCP encrypted channel. A preprocessing module performs format standardization and de-identification. A trusted verification module extracts the digital certificate, verifies the certificate chain validity, uses the certificate's public key to verify the data signature, and checks the timestamp's validity and sequence logic. Upon successful verification, a trusted label is generated, containing the verification time, verification method, and trust score. The trust score, as a crucial component of the quality factor, significantly impacts subsequent asset valuation.

[0096] Example 2: Data Asset Valuation

[0097] The evaluation model employs a weighted multidimensional formula. The cost factor calculates the total cost of data collection, storage, processing, and compliance. The quality factor comprehensively evaluates five indicators: completeness, accuracy, timeliness, consistency, and credibility, with the credible source tag contributing to a credibility score of 90-100. The utility factor is calculated based on the vector similarity between asset tags and application scenario requirements, combined with historical transaction premium coefficients. The market factor is dynamically adjusted based on recent transaction prices of similar assets and supply and demand relationships. After setting weights, the final valuation and credit rating are calculated. The evaluation engine periodically recalculates, dynamically updates the valuation, and stores the data on the blockchain.

[0098] Example 3: Smart Contract-Based Access Control

[0099] Autonomous driving algorithm companies need road image data to train lane line recognition models. The data provider configures contract terms in the smart contract management module, including restrictions on usage to lane detection model training, mandatory differential privacy, prohibition of re-identification, prohibition of data export, a maximum of one million records per month, and billing based on query count. After a formal verification engine checks the consistency of the terms, the data provider signs and deploys the contract to the blockchain. The requesting party reviews and signs the contract, and after payment, the contract is activated and an access token is automatically generated. The requesting party includes the token when initiating a federated learning task request. The access control module verifies the token's validity, checks quota limits, and confirms environmental security before granting permission. The task is routed to a domestic TEE node for execution; the requesting party only receives model gradient updates and cannot access the original images. A trusted metering unit records access volume and resource consumption, generates metering vouchers, and submits them to the contract and the blockchain.

[0100] Example 4: Automated Compliance Processing

[0101] Car owner Li Si discovered that a certain data asset contained his personal trajectory information and requested its deletion based on Article 47 of the Personal Information Protection Law. Li Si submitted a deletion request after passing multi-factor authentication. The compliance module used privacy-preserving retrieval technology to locate three data assets containing Li Si's information. It retrieved relevant smart contracts and analyzed the impact of the deletion operation. Based on the Personal Information Protection Law, it assessed the legality of the request, confirming that it met the statutory requirements and had no exemptions. It initiated a multi-party authorization process, obtaining digital signature authorization from the data provider and data user. A deletion command was sent to the storage node, which located Li Si's trajectory points within the TEE and deleted them, performing a physical erasure of the relevant data blocks seven times. The node returned proof of deletion completion. The compliance module updated the asset metadata, packaging the rights request, legal basis, authorization signature, and deletion proof onto the blockchain for evidence storage. It then fed back the processing result and blockchain evidence to Li Si.

[0102] Example 5: Secure Destruction of Data Assets

[0103] The data assets have been archived for two years, and all contracts have terminated. A lifecycle strategy engine scan confirmed that the destruction conditions were met. No outstanding compliance requests, regulatory freeze orders, or statutory retention periods were found. A destruction proposal was generated, initiated for multi-party approval, and digital signature authorization was obtained from the data asset administrator, compliance officer, and legal representative. Destruction instructions were sent to three storage nodes. After verifying the legality of the instructions, the nodes performed seven overwrites on the data block using the DoD standard to generate a destruction certificate. The destruction coordinator collected and verified the destruction certificates from all nodes, then packaged the destruction proposal, authorization signatures, and destruction certificates and uploaded them to the blockchain for evidence storage. The asset status was updated to destroyed, and the evidence storage chain was sealed. A minimal metadata set, including the asset identifier, destruction time, and blockchain anchor, was retained for auditing.

[0104] Example 6: Cross-domain trusted mutual recognition

[0105] Traffic data assets managed by the Beijing Municipal Commission of Transport are stored on the Chang'an Chain, while an autonomous driving company in Shanghai is registered on the FISCO BCOS Chain. The company retrieves the notarized information of the traffic data through a cross-chain relay. Both parties sign a cross-domain smart contract, which is deployed simultaneously on both chains. The company uses tokens on the FISCO BCOS Chain to access assets on the Chang'an Chain. Measurement results are simultaneously stored on both chains to ensure audit integrity. A digital identity federation based on the W3C DID standard achieves "one-time registration, full-domain mutual recognition." Standardized contract interface specifications support cross-domain smart contract interoperability.

[0106] The transportation data asset lifecycle management method based on trusted data space provided in this embodiment has the following advantages:

[0107] 1. Achieving Trustworthy Data Asset Empowerment: A triple verification mechanism combining digital identity authentication and cryptographic signatures ensures the authenticity of data sources and the integrity of content. A trusted tagging mechanism enhances the reliability of data quality assessment, providing high-quality training data for downstream AI applications.

[0108] 2. Activate the data element market: A dynamic multi-dimensional value assessment model enables fair pricing of data assets. Smart contract-based transactions reduce transaction and trust costs. Experimental data shows that compared to traditional platforms, transaction matching time is reduced by 70%, and transaction costs are reduced by 50%.

[0109] 3. Ensuring Data Security and Compliance: The "contract as policy" access control mechanism enables fine-grained usage management. Privacy-preserving computing technology integration ensures "data is usable but not visible." The automated compliance engine embeds regulatory requirements into technical processes, reducing compliance request response time from seven to fifteen business days to less than two hours, and ensuring 100% completeness of compliance operation evidence.

[0110] 4. Improve operational efficiency: End-to-end automation and intelligent design significantly reduce labor costs. Automatic execution of smart contracts eliminates manual coordination costs and reduces transaction disputes. Real-world application cases show that data asset operating costs have been reduced by more than 60%.

[0111] 5. Building a Trustworthy Ecosystem Foundation: A complete blockchain-based evidence storage chain provides tamper-proof technical evidence for data asset ownership protection, transaction arbitration, and regulatory auditing. It supports cross-domain trusted mutual recognition of data assets, promoting the healthy development of the data element market. It complies with the requirements of laws and regulations such as the Data Security Law and the Personal Information Protection Law.

[0112] This embodiment provides a method for full lifecycle management of transportation data assets based on a trusted data space, marking the first application of a trusted data space architecture to the full lifecycle management of transportation data assets. It innovatively integrates multiple technologies such as digital identity, smart contracts, privacy computing, and blockchain notarization to form a systematic solution. A multi-dimensional data asset value assessment model incorporating trustworthiness scoring is proposed. Finally, a three-in-one data governance architecture of "contract-driven + privacy computing + automatic compliance" is achieved.

[0113] Example 2

[0114] Please see Figure 8 , Figure 9 and Figure 10 This embodiment provides a traffic data asset lifecycle management system based on trusted data space. The system adopts a layered microservice architecture, including an infrastructure layer, a trusted data space basic service layer, a core function service layer, and an application interface layer.

[0115] The infrastructure layer includes distributed storage clusters, blockchain networks, privacy computing clusters, and key management services.

[0116] The Trusted Data Space Infrastructure Service Layer provides fundamental capabilities such as distributed digital identity management, secure communication using national cryptographic algorithms, unified key management, distributed ledger notarization, global audit logs, and cross-chain relay. Distributed digital identity management, based on the W3C DID standard, provides verifiable digital identities for various entities. Secure communication using national cryptographic algorithms provides TLCP secure communication protocols based on SM2 / SM3 / SM4. Unified key management employs hardware security modules or cloud key management services. Distributed ledger notarization provides high-performance, tamper-proof notarization based on a consortium blockchain. Global audit logs record key system operations and support audit queries.

[0117] The core functional service layer includes: multi-source data access and preprocessing module, data source trusted verification module, data asset registration module, data asset ownership confirmation module, data asset value assessment and pricing module, data asset smart contract management module, data asset circulation and contractual data circulation network module, data asset access control and trusted measurement module, data asset lifecycle strategy engine, and data compliance and information subject rights management module.

[0118] The multi-source data access and preprocessing module is used to collect raw traffic data from data sources and perform data preprocessing.

[0119] Specifically, the multi-source data access and preprocessing module adapts to multi-source data interfaces such as vehicle terminals, roadside equipment, and traffic management systems, and performs data cleaning, format standardization, and de-identification processing to conduct a preliminary data quality assessment.

[0120] The data source trust verification module is used to verify the data source identity and data integrity of the preprocessed raw traffic data using digital identity authentication and cryptographic signature technology. After successful verification, a trust label is attached to the raw traffic data.

[0121] Specifically, the data source trust verification module verifies the validity of the digital certificate of the data acquisition device, verifies the digital signature and timestamp logic of the data packet, confirms the authenticity and integrity of the data source, and generates a trust label containing the verification time, verification method, and trust score.

[0122] The data asset registration module is used to generate globally unique asset identifiers for verified raw traffic data using standardized registration, and to generate asset metadata.

[0123] The data asset ownership confirmation module uses the private key of the initial contributor to digitally sign the asset identifier and data hash of the asset metadata, and then submits the initial ownership certificate to the blockchain to obtain a certificate of evidence circulation.

[0124] The data asset valuation and pricing module is used to determine the asset valuation and credit rating of asset metadata using a pre-built weighted multidimensional valuation model, obtain the valuation result, and submit the valuation result to the blockchain corresponding to the asset metadata.

[0125] Specifically, the data asset valuation and pricing module integrates a multi-dimensional valuation model, which calculates asset valuation and credit rating based on cost, quality, utility, and market factors, and updates it dynamically on a regular basis.

[0126] The data asset smart contract management module is used to encode asset data into automatically executed smart contracts, and after checking the consistency of the contract logic through a formal verification engine, it is deployed to the blockchain to obtain the contract address.

[0127] Specifically, the data asset smart contract management module provides a contract template library and a visual editor, supports contract terms configuration, checks logical consistency through a formal verification engine, deploys to the blockchain, and provides an execution interface.

[0128] The Data Asset Circulation and Contractual Data Circulation Network Module is used to bind asset metadata with contract addresses and then publish it to the data circulation network.

[0129] Specifically, the data asset circulation and contractual data circulation network module provides services such as asset catalog publishing, multi-dimensional retrieval, intelligent demand matching, online contract negotiation, automatic smart contract matching and settlement.

[0130] The data asset access control and trusted metering module receives and verifies data access requests with access tokens initiated by data requesters. After successful verification, it routes the computing task to the designated privacy computing environment according to the contract requirements, performs data processing in the privacy computing environment, generates metering certificates with timestamps and digital signatures, and submits the metering certificates to the smart contract to trigger fee settlement before submitting them to the blockchain for evidence storage.

[0131] Specifically, the data asset access control and trusted metering module verifies the validity of the access token, executes fine-grained authorization according to the smart contract terms, routes tasks to the privacy computing environment, accurately measures data usage and resource consumption, and stores the data on the blockchain.

[0132] The data asset lifecycle strategy engine periodically scans the asset repository, identifies assets that meet archiving or destruction criteria based on preset conditions, migrates the metadata of assets meeting archiving criteria to cold storage, updates the asset status, and submits it to the blockchain for storage, and generates destruction proposals for assets meeting destruction criteria, initiating a multi-party approval process. Upon approval, destruction instructions are sent to all storage nodes storing data copies. Storage nodes perform physical-level secure erasure and generate destruction proofs, which are then submitted to the blockchain for storage. In short, the data asset lifecycle strategy engine automatically manages asset status migration according to preset policies, coordinates multi-party approvals to execute secure destruction, collects destruction proofs and stores them on the blockchain, and seals the evidence storage chain.

[0133] Specifically, the data asset lifecycle strategy engine periodically scans the asset repository, identifying assets that meet archiving or destruction conditions based on factors such as archiving duration, contract status, and access frequency. For assets meeting archiving conditions, data is migrated to cold storage, asset status is updated, and notarized on the blockchain. For assets meeting destruction conditions, a destruction proposal is generated. Prerequisites are checked: whether there are any outstanding compliance requests, regulatory freeze orders, or whether the statutory minimum retention period has expired. A multi-party approval process is initiated, requiring digital signature authorization from pre-defined roles such as data asset administrators and compliance officers. After authorization, a destruction instruction is sent to all nodes storing data copies. Storage nodes perform physical-level secure erasure, overwriting data blocks multiple times to generate a destruction certificate containing the erasure algorithm, timestamp, and operator signature. The destruction coordinator collects and verifies the destruction certificates from all nodes. The destruction proposal, authorization signature, and destruction certificate are submitted to the blockchain for notarization. The asset status is updated to destroyed, and the complete notarization chain of the asset is sealed. A minimal metadata set is retained for regulatory auditing.

[0134] The Data Compliance and Information Subject Rights Management module receives rights requests from individuals, uses privacy-preserving retrieval technology to locate all data assets containing their personal information based on these requests, retrieves all smart contracts bound to these data assets, analyzes the impact of executing the rights requests on contract performance, provides feedback on the processing results to the individuals, and submits the results to the blockchain for storage. In other words, the Data Compliance and Information Subject Rights Management module receives and verifies rights requests from individuals, locates relevant assets and contracts, assesses the legality of the requests, coordinates multi-party authorizations, triggers automated compliance operations, and generates a complete chain of evidence.

[0135] The core functional service layer also includes: a trusted data space basic service module, which provides the system with basic capabilities such as distributed identity, secure communication, key management, evidence storage services, audit logs, and cross-chain relay.

[0136] Application Interface Layer: RESTful API Gateway, GraphQL Service, WebSocket Service, Web Management Portal, Mobile SDK.

[0137] This embodiment provides a transportation data asset lifecycle management system based on a trusted data space. Through trusted data space infrastructure services, it performs digital identity verification and data integrity checks at the starting point of data assetization, ensuring the trustworthiness of asset origins. A multi-dimensional evaluation model integrating cost, quality, utility, and market factors is employed to achieve dynamic valuation. Smart contract technology is used to codify data usage rules, combined with a privacy computing environment to achieve controlled access to data that is usable but not visible. An automated compliance engine is built-in to legally respond to requests from individuals regarding their rights. Based on blockchain technology, key events throughout the entire lifecycle of data assets, including registration, circulation, use, archiving, and destruction, are immutably documented, forming a complete audit trail chain. This invention solves technical problems such as unclear ownership of transportation data, untrustworthy sources, difficulty in quantifying value, difficulty in controlling use, high compliance costs, and lack of full-process traceability. It provides systematic technical support for building a safe, compliant, and efficient transportation data element market, meeting the requirements of laws and regulations such as the Data Security Law and the Personal Information Protection Law.

[0138] For details on the specific implementation of each module in a traffic data asset lifecycle management system based on a trusted data space, please refer to the above description of the limitations of a traffic data asset lifecycle management method based on a trusted data space; these details will not be repeated here.

[0139] The technical features of the above embodiments can be combined in any way (as long as there is no contradiction in the combination of these technical features). For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described; these embodiments not explicitly written should also be considered to be within the scope of this specification.

Claims

1. A method for managing the whole life cycle of traffic data assets based on a trusted data space, characterized in that, include: Step 1: Collect raw traffic data from the data source and perform data preprocessing; Step 2: Use digital identity authentication and cryptographic signature technology to verify the identity of the data source and the integrity of the preprocessed raw traffic data. After successful verification, attach a trusted label to the raw traffic data. Step 3: Use standardized registration to generate a globally unique asset identifier for the verified raw traffic data and generate asset metadata; Step 4: Use the private key of the initial contributor to digitally sign the asset identifier and data hash of the asset metadata, generate the initial ownership certificate, and submit it to the blockchain to obtain the evidence circulation identifier. Step 5: Use a pre-built weighted multidimensional evaluation model to determine the asset valuation and credit rating of the asset metadata, obtain the value assessment result, and submit the value assessment result to the blockchain corresponding to the asset metadata; Step 6: The asset data is encoded into an automatically executable smart contract, and after the contract logic is checked for consistency by a formal verification engine, it is deployed to the blockchain to obtain the contract address; Step 7: After binding the asset metadata with the contract address, publish it to the data circulation network.

2. The method for managing the whole life cycle of traffic data assets based on the trusted data space according to claim 1, characterized in that, Also includes: Receive and verify data access requests with access tokens initiated by data requesters; After verification, the computing task is routed to the designated privacy computing environment according to the contract requirements. Data processing is performed in the privacy computing environment to generate a metering certificate with a timestamp and digital signature. The metering certificate is then submitted to the smart contract to trigger fee settlement and then submitted to the blockchain for evidence storage.

3. The method for managing the whole life cycle of traffic data assets based on trusted data space according to claim 1, characterized in that, Also includes: Regularly scan the asset database and identify assets that meet the conditions for archiving or destruction based on preset criteria; Migrate the metadata of assets that meet the archiving conditions to cold storage, update the asset status, and submit it to the blockchain for storage; generate destruction proposals for the metadata of assets that meet the destruction conditions, initiate a multi-party approval process, and send destruction instructions to all storage nodes that store data copies after approval. The storage node performs a physical-level secure erase and generates a destruction certificate, which is then submitted to the blockchain for storage.

4. The method for managing the whole life cycle of traffic data assets based on trusted data space according to claim 1, characterized in that, Also includes: The system receives rights requests from individuals, uses privacy-preserving retrieval technology to locate all data assets containing personal information based on the rights requests, retrieves all smart contracts bound to all data assets, analyzes the impact of executing the rights requests on contract performance, feeds back the processing results to the individuals, and submits the processing results to the blockchain for storage.

5. The method for full lifecycle management of transportation data assets based on trusted data space according to claim 1, characterized in that, Step 2 specifically includes: verifying the validity of the digital certificate of the data acquisition device, and using the public key of the digital certificate to verify the digital signature of the preprocessed original traffic data, verifying the rationality of the timestamp and the sequence logic, and after the verification is passed, attaching a trusted label containing the verification time, verification method and credibility score to the original traffic data.

6. The method for full lifecycle management of transportation data assets based on trusted data space according to claim 1, characterized in that, In step 3, the asset metadata includes: data summary, data hash value, trusted tag, initial contributor information, and anonymous identifier of the associated personal information subject.

7. The method for full lifecycle management of transportation data assets based on trusted data space according to claim 1, characterized in that, In step 5, the weighted multidimensional evaluation model is pre-constructed by integrating cost input, data quality, scenario utility, and market supply and demand.

8. A transportation data asset lifecycle management system based on a trusted data space, characterized in that, include: The multi-source data access and preprocessing module is used to collect raw traffic data from data sources and perform data preprocessing. The data source trust verification module is used to verify the data source identity and data integrity of the preprocessed raw traffic data using digital identity authentication and cryptographic signature technology. After the verification is successful, a trust label is attached to the raw traffic data. The data asset registration module is used to generate globally unique asset identifiers for verified raw traffic data using standardized registration, and to generate asset metadata. The data asset ownership confirmation module uses the private key of the initial contributor to digitally sign the asset identifier and data hash of the asset metadata, and then submits the initial ownership certificate to the blockchain to obtain a certificate of evidence circulation. The data asset valuation and pricing module is used to determine the asset valuation and credit rating of asset metadata using a pre-built weighted multidimensional valuation model, obtain the valuation result, and submit the valuation result to the blockchain corresponding to the asset metadata. The data asset smart contract management module is used to encode asset data into automatically executable smart contracts, and after checking the consistency of the contract logic through a formal verification engine, it is deployed to the blockchain to obtain the contract address; The Data Asset Circulation and Contractual Data Circulation Network Module is used to bind asset metadata with contract addresses and then publish it to the data circulation network.

9. The transportation data asset lifecycle management system based on trusted data space according to claim 8, characterized in that, Also includes: The data asset access control and trusted metering module receives and verifies data access requests with access tokens initiated by data requesters. After verification, the computing task is routed to the designated privacy computing environment according to the contract requirements. Data processing is performed in the privacy computing environment to generate a metering certificate with a timestamp and digital signature. The metering certificate is then submitted to the smart contract to trigger fee settlement and then submitted to the blockchain for evidence storage.

10. The traffic data asset lifecycle management system based on trusted data space according to claim 8, characterized in that, Also includes: The data asset lifecycle strategy engine is used to periodically scan the asset library and identify assets that meet the conditions for archiving or destruction based on preset criteria. Migrate the metadata of assets that meet the archiving conditions to cold storage, update the asset status, and submit it to the blockchain for storage; generate destruction proposals for the metadata of assets that meet the destruction conditions, initiate a multi-party approval process, and send destruction instructions to all storage nodes that store data copies after approval. The storage node performs a physical-level secure erase and generates a destruction certificate, which is then submitted to the blockchain for storage. The Data Compliance and Information Subject Rights Management module is used to receive rights requests from personal information subjects, locate all data assets containing personal information using privacy-preserving retrieval technology based on the rights requests, retrieve all smart contracts bound to all data assets, analyze the impact of executing the rights requests on contract performance, provide feedback on the processing results to the personal information subjects, and submit the processing results to the blockchain for storage.

Citation Information

Patent Citations

  • Complete data asset credible management and value circulation system and method

    CN115049398A

  • Data trusted circulation method, device and equipment and readable storage medium

    CN116232606A

  • Traffic data sharing system and method based on block chain BaaS platform

    CN120410525A

  • Block chain-based data asset credible right confirmation method and system

    CN120632945A

  • Clinical test data integrity system based on block chain

    CN120692096A