Data cross-domain interconnection and intercommunication method and system based on decentration
By employing a decentralized cross-domain data interconnection method, and utilizing the collaborative work of authentication nodes, transaction nodes, and data nodes, the problems of trust establishment and secure transmission in cross-domain data sharing are solved, achieving secure and efficient data sharing and transmission, and improving user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHONGDIAN DATA IND CO LTD
- Filing Date
- 2025-12-17
- Publication Date
- 2026-04-17
AI Technical Summary
In existing technologies, cross-domain data sharing faces challenges such as difficulty in establishing trust, risks in secure transmission, and high operation and maintenance costs. In particular, in centralized data exchange platforms, the risk of single point of failure and the difficulty in establishing trust lead to insecure data interoperability.
By adopting a decentralized cross-domain data interconnection method, and through the collaborative work of authentication nodes, transaction nodes, and data nodes, two-way identity authentication, short-term access token verification, HTTPS encrypted transmission, and blockchain-recorded transactions are achieved, ensuring the security and traceability of data transmission.
It achieves trusted and efficient data transmission for cross-domain data interoperability while ensuring security, improving data sharing performance, reducing operation and maintenance costs, enhancing user experience.
Smart Images

Figure CN121887451A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of visual tracking technology, and in particular to a decentralized method and system for cross-domain data interconnection. Background Technology
[0002] In the current digital economy era, the circulation and value release of data elements face significant challenges. Severe data silos exist between organizations. Cross-domain data sharing currently primarily employs a centralized API gateway model, where a centralized data exchange gateway is deployed. Each participant registers with the gateway and obtains an API key, using the gateway for unified identity authentication and data routing, and employing the OAuth 2.0 protocol for authorization management. Alternatively, federated learning or consortium blockchain models exist, where data remains within its domain, model parameters are transmitted across domains, data privacy is protected through differential privacy and homomorphic encryption, and a central coordinating node schedules the training process for all parties. However, these methods are hampered by single-point-of-failure risks and difficulties in establishing trust, thus hindering secure and effective data interoperability. Summary of the Invention
[0003] This invention provides a decentralized cross-domain data interconnection method and system to solve the problem that existing methods cannot effectively utilize hyperspectral images for target tracking.
[0004] This invention provides a decentralized cross-domain data interconnection and interoperability method, the method comprising: The system is configured with authentication nodes, transaction nodes, and data nodes. The authentication nodes store the identity credentials or root certificates of the transaction nodes and the data nodes. The data nodes include provider data nodes and user data nodes. When the provider data node pre-lists data, the transaction node triggers the authentication node to authenticate the provider data node. After the authentication is successful, the data metadata information is obtained based on the data to be pre-listed, and a unique data identifier for the pre-listed data is generated based on the data metadata information. The data is then listed and displayed. When the user data node pre-acquires data, the transaction node triggers the authentication node to authenticate the user data node. After the authentication is successful, an order identity token for the pre-acquired data is generated based on the data displayed on the platform. After authentication by the authentication node and confirmation of permissions by the provider data node, the provider data node encrypts and transmits the data to the user data node.
[0005] Optionally, the authentication node performs identity authentication on the data node, including: performing a complete certificate chain verification when the data nodes interact for the first time, and verifying the data node by generating a short-term access token through the authentication node when the data nodes interact again after successful authentication, wherein the short-term access token includes the issuer, user, validity period and permission scope.
[0006] Optionally, the step of verifying the data node by generating a short-term access token includes: The authentication node verifies the validity of the data node's digital certificate based on the PKI system and generates the short-term access token. The short-term access token adopts the JWT format and is signed using the authentication node's private key to ensure the integrity of the short-term access token.
[0007] Optionally, after the data is uploaded and displayed, the method further includes: registering the uploaded and displayed data in the data directory; The step of generating an order identity token for pre-acquiring data based on the data displayed on the shelves includes: the user data node generating an order identity token for acquiring data by searching the data directory and selecting the required target data from the data directory.
[0008] Optionally, the provider data node encrypts and transmits the data to the user data node, including: The provider data node uses its private key to sign key parameters of the data to be transmitted and performs transport layer encryption via HTTPS protocol. The key parameters include the provider data node's identity code, request serial number, and timestamp. After verifying the signature of the key parameters and checking the access token permissions, the user data node receives and saves the data sent by the provider data node.
[0009] Optionally, the provider data node confirms permissions, including: The provider data node checks the permissions in the user data node's order identity token to determine whether the user data node has permission to access the data. It also verifies the user data node's purchase records and permission status through the transaction node. After successful verification, the provider data node is triggered to encrypt and transmit the data to the user data node.
[0010] Optionally, there are multiple authentication nodes, and different authentication nodes are distributed in different security domains. Each security domain has its own root certificate and certificate authority. In cross-domain interconnection, authentication nodes achieve cross-domain trust transfer through cross-authentication. That is, each authentication node holds its own root certificate and private key, and maintains a trusted root certificate list, which includes the root certificates of other authentication nodes. When two authentication nodes pre-establish a trust relationship, they exchange their respective root certificates and add the other party's root certificate to their trusted root certificate list.
[0011] Optionally, the method further includes: when the transaction node generates an order, recording the hash value of the order on the blockchain, wherein the hash value of the order includes an order ID, a data identifier, the two parties to the transaction, and a timestamp; during data transmission, the data node records proof of completion of each batch of transmission on the blockchain, wherein the proof includes a data hash, transmission time, and signatures of both parties; after the data transmission is completed, the data node notifies the transaction node to update the order status to complete, and the transaction node records the order status information on the blockchain, forming a multi-version change record of the order.
[0012] Secondly, this invention provides a decentralized cross-domain data interconnection system, comprising: authentication nodes, transaction nodes, and data nodes, wherein the data nodes include provider data nodes and user data nodes; wherein... The authentication node is used to store the identity credentials or root certificates of the transaction node and the data node, and to perform identity authentication on the data node based on the triggering of the transaction node. The transaction node is used to obtain data metadata information based on the data to be listed according to the data to be listed based on the trigger of the provider data node, generate a unique data identifier for the data to be listed based on the data metadata information, then trigger the provider data node to list the data, and generate an order identity token for the data to be acquired based on the trigger of the user data node, and trigger the provider data node to encrypt and transmit the data to the user data node. The data node is used to trigger the authentication node to authenticate the provider data node through the transaction node when pre-listing and acquiring data, and to upload and display the data or transmit the data in encrypted form after the authentication is successful.
[0013] Thirdly, the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements any of the methods described above.
[0014] The beneficial effects of this invention are as follows: This invention enables decentralization and provides excellent data sharing performance while ensuring security, thereby meeting the data interoperability needs of various data exchange scenarios and greatly improving the user experience.
[0015] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, and in order to make the above and other objects, features and advantages of the present invention more apparent and understandable, specific embodiments of the present invention are described below. Attached Figure Description
[0016] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Furthermore, the same reference numerals denote the same parts throughout the drawings. In the drawings: Figure 1 This is a flowchart illustrating a decentralized cross-domain data interconnection method provided in an embodiment of the present invention; Figure 2 This is a schematic diagram of the identity authentication process provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of the data transmission security process provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the structure of a decentralized cross-domain data interconnection system provided in an embodiment of the present invention. Detailed Implementation
[0017] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and do not limit the scope of the invention.
[0018] Existing cross-domain data sharing suffers from the following problems: Difficulty in establishing trust: Different organizations lack a unified trust anchor, making it difficult to verify the authenticity of each other's identities; Security risks in transmission: Cross-network domain data transmission faces security threats such as eavesdropping, tampering, and repudiation; High operation and maintenance costs: Centralized data exchange platforms have single-point-of-failure risks and high maintenance costs. To address these issues, this invention provides a decentralized cross-domain data interconnection method, see [link to relevant documentation]. Figure 1 The method includes: S101. Configure authentication nodes, transaction nodes, and data nodes; In this embodiment of the invention, the authentication node stores the identity credentials or root certificates of the transaction node and the data node. Specifically, in this embodiment of the invention, the data node can be divided into provider data node and user data node according to the function currently implemented by the data node. In specific implementation, the authentication node in this embodiment of the invention serves as a trust anchor point, stores the root certificates and identity credentials of each participating party, provides a standard identity authentication service interface, realizes the trust transfer and mutual recognition mechanism between authentication nodes, and maintains the revocation status information of identity credentials.
[0019] The transaction node in this embodiment of the invention is used to provide a user interface for data nodes and to handle business logic such as data retrieval, data purchase, and order management; then it calls the authentication node service to complete user authentication; and at the same time maintains the data directory and transaction records.
[0020] The data node in this embodiment of the invention is used for actual data storage and transmission, provides a unified data access and output interface, supports the conversion of multiple data formats (API interface, file, etc.), and realizes encrypted data transmission and integrity protection.
[0021] It should be noted that, in this embodiment of the invention, the data nodes perform identity authentication and participate in business on the transaction nodes and authentication nodes; and the data nodes carry corresponding digital identities according to the enterprise, individual or organization to which they belong; and assume the role of data provider or data user in specific transactions.
[0022] S102. When data is pre-listed or pre-acquired at a data node, the transaction node triggers the authentication node to authenticate the identity of the provider data node. After successful authentication, the data is listed and displayed or the provider data node is triggered to encrypt and transmit the data to the user data node.
[0023] In simple terms, in this embodiment of the invention, the authentication node is a core node that provides identity verification services and maintains trust relationships; the transaction node provides data retrieval, purchase, and order management functions; the data node is an infrastructure node responsible for data storage, transmission, and format conversion; and the data node is the identity entity participating in cross-domain data transaction transmission.
[0024] Specifically, in this embodiment of the invention, when the provider data node pre-lists data, the transaction node triggers the authentication node to perform identity authentication on the provider data node. After the identity authentication is successful, the data metadata information is obtained based on the data to be pre-listed, and a unique data identifier for the pre-listed data is generated based on the data metadata information, and the data is then listed and displayed. When the user data node pre-acquires data, the transaction node triggers the authentication node to authenticate the user data node. After the authentication is successful, an order identity token for the pre-acquired data is generated based on the data displayed on the platform. After authentication by the authentication node and confirmation of permissions by the provider data node, the provider data node encrypts and transmits the data to the user data node.
[0025] In this embodiment of the invention, the authentication node performs identity authentication on the data node, including: performing a complete certificate chain verification when the data nodes interact for the first time, and verifying the data node by generating a short-term access token through the authentication node when the data nodes interact again after successful authentication. The short-term access token includes the issuer, user, validity period, and scope of permissions.
[0026] In specific implementation, the embodiments of the present invention adopt a two-way identity authentication mechanism, that is, a complete certificate chain verification is performed when data nodes interact for the first time. After authentication is successful, a short-term access token is issued for subsequent use. The token in the embodiments of the present invention contains information such as issuer, user, validity period, and scope of permissions.
[0027] In this embodiment of the invention, data nodes are verified by generating short-lived access tokens, including: the authentication node verifies the validity of the digital certificate of the data node based on the PKI system, and generates the short-lived access token, wherein the short-lived access token adopts the JWT format and is signed using the private key of the authentication node to ensure the integrity of the short-lived access token.
[0028] Furthermore, embodiments of the present invention also include registering the data displayed on the shelves to a data directory; then the user data node generates an order identity token for obtaining the data by retrieving the data directory and selecting the required target data from the data directory.
[0029] In specific implementation, the provider data node of this embodiment of the invention transmits encrypted data to the user data node, including: the provider data node signing key parameters of the data to be transmitted using its private key, and encrypting the data at the transport layer using the HTTPS protocol, wherein the key parameters include the provider data node's identity code, request serial number, and timestamp; the user data node verifies the signature of the key parameters and checks the access token permissions, and then receives and saves the data sent by the provider data node.
[0030] The provider data node's permission confirmation includes: the provider data node checking the permissions in the user data node's order identity token to determine whether the user data node has permission to access the data, and verifying the user data node's purchase records and permission status through the transaction node. After successful verification, the provider data node is triggered to encrypt and transmit the data to the user data node.
[0031] In specific implementation, multiple authentication nodes can be set up in this embodiment of the invention, and different authentication nodes can be distributed in different security domains. Each security domain has its own root certificate and certificate authority. In cross-domain interconnection, authentication nodes achieve cross-domain trust transfer through cross-authentication. That is, each authentication node holds its own root certificate and private key, and maintains a trusted root certificate list, which includes the root certificates of other authentication nodes. When two authentication nodes pre-establish a trust relationship, they exchange their respective root certificates and add the other party's root certificate to their trusted root certificate list.
[0032] In other words, embodiments of the present invention can implement a cross-domain trust transfer mechanism: that is, in cross-domain interconnection scenarios, the participating parties may belong to different security domains, and each domain has its own root certificate and Certificate Authority (CA). In this invention, cross-domain trust transfer is achieved between authentication nodes through cross-authentication. Specific steps include: Each authentication node holds its own root certificate and private key, and maintains a list of trusted root certificates, including the root certificates of other authentication nodes; When two authentication nodes need to establish a trust relationship, they exchange their root certificates and add each other's root certificates to their own list of trusted root certificates. To verify the identity credentials issued by the peer node, the authentication node uses the peer's root certificate to verify its certificate chain. Meanwhile, to ensure real-time trust, the authentication node periodically synchronizes the Certificate Revocation List (CRL) or queries the certificate status via the Online Certificate Status Protocol (OCSP). To reduce the complexity of cross-domain verification, authentication nodes can cache verified certificate chains and set reasonable cache times.
[0033] In specific implementation, when the transaction node generates an order, the hash value of the order is recorded on the blockchain. The hash value of the order includes the order ID, data identifier, transaction parties, and timestamp. During data transmission, the data node records proof of completion of each batch of transmission on the blockchain. This proof includes the data hash, transmission time, and signatures of both parties. After the data transmission is completed, the data node notifies the transaction node to update the order status to complete, and the transaction node records the order status information on the blockchain, forming a multi-version change record of the order.
[0034] In other words, the embodiments of this invention can achieve verifiable data transaction auditing: to ensure the traceability and immutability of data transactions, this invention utilizes blockchain technology to record key events of the transaction. Specifically, this includes: when a transaction node generates an order, recording the order's hash value on the blockchain. The order hash includes information such as order ID, data identifier, transaction parties, and timestamp. During data transmission, the data node records proof of the completion of each batch of transmission (including data hash, transmission time, signatures of both parties, etc.) on the blockchain. After data transmission is completed, the data node notifies the transaction node to update the order status to complete, and the transaction node records the order status information on the blockchain, forming a multi-version change record of the order. Through the records on the blockchain, any participant can verify the authenticity and integrity of the transaction, and there is no way to deny it.
[0035] Furthermore, the intelligent adaptation of data format conversion in this embodiment of the invention includes: when converting data formats, data nodes intelligently select conversion strategies based on factors such as data content, user needs, and network conditions. For example, if the data volume is large and the user needs batch analysis, it is automatically converted to CSV or Parquet formats and compressed using formats such as ZIP or Snappy to reduce storage space and transmission bandwidth. If the user needs real-time queries, it is converted to an API interface and supports pagination and filtering. If network conditions are poor, it is converted to a file format and supports resuming interrupted downloads. If the data contains sensitive information, it is anonymized or encrypted during the conversion process, such as anonymizing information like mobile phone numbers, ID card numbers, and home addresses.
[0036] The following will combine Figure 2 and Figure 3 The method described in the embodiments of the present invention will be explained and illustrated in detail through a specific example: The authentication node stores the identity credentials or root certificate of other nodes, provides identity authentication services, and can verify the identity of various types of nodes and return the identity identifier.
[0037] The data node submits an authentication login request to the transaction node. The transaction node's backend calls the authentication node's identity authentication service, and the authentication login is completed after the verification is successful.
[0038] Data nodes, as data providers, can register data for storage and designate data nodes; data users can retrieve data, purchase data, and designate data nodes.
[0039] The data node submits an authentication login request, and the data node's backend calls the authentication node's identity authentication service. Once the verification is successful, the authentication login is completed.
[0040] Data nodes are designated as transaction nodes. Data nodes connect to transaction nodes for identity authentication and to obtain data node orders.
[0041] The user's data node requests data transmission services from the provider's data node based on the order information. Data transmission is supported via API, file pull (download), and file push (stream).
[0042] As a data provider, a data node can output order data (supporting interface or file formats) and provide data transmission services for users to call.
[0043] Data nodes, as data users, can receive order data and convert the data into API calls or save it in file formats.
[0044] In this embodiment of the invention, the first step is to perform identity authentication, see [link to relevant documentation]. Figure 2 The identity authentication in this embodiment of the invention specifically includes: the authentication node verifying the validity of the requester's digital certificate based on the PKI system; generating a short-term access token containing an identity identifier and permission scope; the token adopting JWT format and being signed using the authentication node's private key to ensure integrity. Access token example: { "iss": "auth-node-1", "sub": "data-owner-123", "iat": 1620000000, "exp": 1620003600, "scope": ["data_read", "data_write"], "node_id": "transaction-node-1", "signature": "Ee8Ae5dNmVb8..." } The second step is to conduct data transactions, which involves first registering and listing data. Specifically, in this embodiment of the invention, the data provider completes identity authentication at the transaction node, fills in data metadata information, designates the data node responsible for data transmission (the provider's data node), and the transaction node generates a unique data identifier and lists and displays the data. When purchasing data, the data user searches and browses the data catalog, selects the target data, initiates a purchase request, and specifies the data node (the user's data node) to receive the data. The transaction node then generates an order and records the transaction information. The third step is data transmission; see [link / reference] Figure 3 The data transmission security mechanism of this invention is as follows: the HTTPS protocol is used to ensure transport layer encryption, the requester uses a private key to sign key parameters to prevent tampering, and the responder verifies the signature and checks the access token permissions. It supports data transmission via API and file, and uses information such as length and fragmentation to verify data integrity.
[0045] Example of a data transfer request: POST / api / data / transfer HTTP / 1.1 Host: provider-data-node Authorization: Bearer eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9... X-Signature: Ee8Ae5dNmVb8ZR4fKc9Pq7wM6jXyLt3H Content-Type: application / json { "data_id": "dataset-001", "target_node": "consumer-data-node-1", "transfer_mode": "api_stream", format: "json" } In this embodiment of the invention, data nodes need to support flexible conversion between API interface calls and file formats to meet the usage requirements of different data nodes. This conversion capability is one of the key technical features for achieving cross-domain data interconnection.
[0046] In this embodiment of the invention, API-to-file conversion refers to the process of converting HTTP interface-based data responses into persistent file storage. This conversion is suitable for the following scenarios: data users need to process historical data in batches, data caching in unstable network environments, meeting data archiving and auditing requirements, and supporting offline data analysis. Code example: class APIToFileConverter: API to File Converter def __init__(self, config): self.supported_formats = ['json', 'csv', 'xml', 'parquet'] self.chunk_size = config.get('chunk_size', 1000) self.encryption_enabled = config.get('encryption', True) def convert_api_response_to_file(self, api_url, headers, output_path, output_format='json', compression=None): """ Convert API response to file parameter: api_url: API interface address headers: Request headers, including authentication tokens, etc. output_path: Output file path output_format: Output file format compression: Compression method (gzip, zip, or None) """ try: # 1. Call the API to retrieve data response = self._call_protected_api(api_url, headers) # 2. Verify data integrity and signature if not self._verify_response_signature(response): Raise a SecurityException("Response signature verification failed") # 3. Data Format Conversion data = response.json() converted_data = self._convert_data_format(data, output_format) # 4. Data Encryption (Optional) if self.encryption_enabled: converted_data = self._encrypt_data(converted_data, output_path) # 5. Write to file self._write_to_file(converted_data, output_path, compression) # 6. Generate file metadata metadata = self._generate_file_metadata(api_url, output_path, output_format) return { 'status': 'success', 'file_path': output_path, 'metadata': metadata, 'checksum': self._calculate_checksum(output_path) } except Exception as e: logger.error(f"API file conversion failed: {str(e)}") return {'status': 'error', 'message': str(e)} def _call_protected_api(self, api_url, headers): """Calling protected API interfaces""" # Add security header information secure_headers = { 'Authorization': f"Bearer {headers.get('access_token')}", 'X-Data-Signature': headers.get('signature'), 'X-Request-ID': self._generate_request_id(), 'Content-Type': 'application / json' } response = requests.get( api_url, headers=secure_headers, timeout=30, verify=True # Enable SSL certificate verification ) if response.status_code != 200: raise APICallException(f"API call failed: {response.status_code}") return response def _convert_data_format(self, data, target_format): "Data Format Conversion" converters = { 'json': self._to_json_format, 'csv': self._to_csv_format, 'xml': self._to_xml_format, 'parquet': self._to_parquet_format } if target_format not in converters: raise ValueError(f"Unsupported format: {target_format}") return converters[target_format](data) def _to_json_format(self, data): Convert to JSON format. return json.dumps(data, ensure_ascii=False, indent=2) def _to_csv_format(self, data): Convert to CSV format if isinstance(data, list) and len(data)>0: df = pd.DataFrame(data) return df.to_csv(index=False, encoding='utf-8') else: Raise a ValueError("Data format is not suitable for conversion to CSV") Furthermore, the method described in this embodiment of the invention also includes a security enhancement mechanism, a secure data transmission mechanism, and unauthorized access control, wherein, In this embodiment of the invention, a two-way authentication mechanism is implemented, in which a complete certificate chain verification is performed during the initial interaction between nodes. After successful authentication, a short-term access token is issued for subsequent use. The token contains information such as the issuer, user, validity period, and scope of permissions.
[0047] The code for the data security transmission mechanism in this embodiment of the invention includes: class SecurityManager: "Security Manager" def __init__(self, pki_config): self.pki_config = pki_config def verify_data_signature(self, data, signature, public_key_path): "Verify data signature" try: with open(public_key_path, 'r') as f: public_key = RSA.import_key(f.read()) # Verify signature verifier = PKCS1_v1_5.new(public_key) digest = SHA256.new(data.encode('utf-8')) return verifier.verify(digest, signature) except Exception as e: logger.error(f"Signature verification failed: {str(e)}") return False def encrypt_file_content(self, file_path, public_key_path): """Encrypted file content""" with open(file_path, 'rb') as f: file_data = f.read() # Encrypt using public key with open(public_key_path, 'r') as f: public_key = RSA.import_key(f.read()) cipher = PKCS1_OAEP.new(public_key) encrypted_data = cipher.encrypt(file_data) # Save encrypted files encrypted_path = file_path + '.encrypted' with open(encrypted_path, 'wb') as f: f.write(encrypted_data) return encrypted_path In this embodiment of the invention, the unauthorized access control is based on fine-grained permission checks using identity identifiers. Data nodes verify whether the requester has the right to access specific data, and transaction nodes verify the user's purchase records and permission status.
[0048] It should be noted that in this embodiment of the invention, PKI stands for Public Key Infrastructure, a system used to manage digital certificates and encryption keys; CA stands for Certificate Authority, a trusted entity responsible for issuing and managing digital certificates; HTTPS stands for Hypertext Transfer Security Protocol, which adds an SSL / TLS encryption layer on top of HTTP; the access token is a temporary credential issued after identity authentication, containing identity information and permission scope, used for subsequent interface access; and cross-domain mutual recognition is a mechanism for mutual recognition and verification of identity credentials between different trusted domains.
[0049] Accordingly, embodiments of the present invention provide a decentralized cross-domain data interconnection system, see [link to relevant documentation]. Figure 4 The system includes: authentication nodes, transaction nodes, and data nodes, wherein the data nodes include provider data nodes and user data nodes; wherein, The authentication node is used to store the identity credentials or root certificates of the transaction node and the data node, and to perform identity authentication on the data node based on the triggering of the transaction node. The transaction node is used to obtain data metadata information based on the data to be listed according to the data to be listed based on the trigger of the provider data node, generate a unique data identifier for the data to be listed based on the data metadata information, then trigger the provider data node to list the data, and generate an order identity token for the data to be acquired based on the trigger of the user data node, and trigger the provider data node to encrypt and transmit the data to the user data node. The data node is used to trigger the authentication node to authenticate the provider data node through the transaction node when pre-listing and acquiring data, and to upload and display the data or transmit the data in encrypted form after the authentication is successful.
[0050] In addition, embodiments of the present invention also provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements any of the methods described above.
[0051] It should be noted that the relevant content of the system embodiments and storage medium embodiments of the present invention can be understood by referring to the method embodiments of the present invention, and will not be discussed in detail here.
[0052] Although preferred embodiments of the invention have been disclosed for illustrative purposes, those skilled in the art will recognize that various modifications, additions, and substitutions are possible, and therefore the scope of the invention should not be limited to the embodiments described above.
Claims
1. A decentralized method for cross-domain data interconnection and interoperability, characterized in that, The method includes: setting up authentication nodes, transaction nodes, and data nodes, wherein the authentication node stores the identity credentials or root certificates of the transaction nodes and the data nodes, and the data nodes include provider data nodes and user data nodes; When the provider data node pre-lists data, the transaction node triggers the authentication node to authenticate the provider data node. After the authentication is successful, the data metadata information is obtained based on the data to be pre-listed, and a unique data identifier for the pre-listed data is generated based on the data metadata information. The data is then listed and displayed. When the user data node pre-acquires data, the transaction node triggers the authentication node to authenticate the user data node. After the authentication is successful, an order identity token for the pre-acquired data is generated based on the data displayed on the platform. After authentication by the authentication node and confirmation of permissions by the provider data node, the provider data node encrypts and transmits the data to the user data node.
2. The method according to claim 1, characterized in that, The authentication node performs identity authentication on the data node, including: When data nodes interact for the first time, a complete certificate chain verification is performed. After successful authentication, when data nodes interact again, a short-term access token is generated by the authentication node to verify the data nodes. The short-term access token includes the issuer, user, validity period, and scope of permissions.
3. The method according to claim 2, characterized in that, The method of verifying data nodes by generating short-term access tokens includes: The authentication node verifies the validity of the data node's digital certificate based on the PKI system and generates the short-term access token. The short-term access token adopts the JWT format and is signed using the authentication node's private key to ensure the integrity of the short-term access token.
4. The method according to claim 1, characterized in that, After the data is uploaded and displayed, the method further includes: registering the uploaded and displayed data in the data directory; The step of generating an order identity token for pre-acquiring data based on the data displayed on the shelves includes: the user data node generating an order identity token for acquiring data by searching the data directory and selecting the required target data from the data directory.
5. The method according to claim 1, characterized in that, The provider data node encrypts and transmits data to the user data node, including: The provider data node uses its private key to sign key parameters of the data to be transmitted and performs transport layer encryption via HTTPS protocol. The key parameters include the provider data node's identity code, request serial number, and timestamp. After verifying the signature of the key parameters and checking the access token permissions, the user data node receives and saves the data sent by the provider data node.
6. The method according to any one of claims 1-5, characterized in that, The provider data node's confirmation permissions include: The provider data node checks the permissions in the user data node's order identity token to determine whether the user data node has the right to access the data. It also verifies the user data node's purchase records and permission status through the transaction node. After successful verification, the provider data node is triggered to encrypt and transmit the data to the user data node.
7. The method according to any one of claims 1-5, characterized in that, There are multiple authentication nodes, and different authentication nodes are distributed in different security domains. Each security domain has its own root certificate and certificate authority. In cross-domain interconnection, authentication nodes achieve cross-domain trust transfer through cross-authentication. That is, each authentication node holds its own root certificate and private key, and maintains a trusted root certificate list, which includes the root certificates of other authentication nodes. When two authentication nodes pre-establish a trust relationship, they exchange their respective root certificates and add the other party's root certificate to their trusted root certificate list.
8. The method according to any one of claims 1-5, characterized in that, The method further includes: When an order is generated at the transaction node, the hash value of the order is recorded on the blockchain. The hash value of the order includes the order ID, data identifier, transaction parties, and timestamp. During data transmission, the data node records the proof of completion of each batch of transmission on the blockchain, wherein the proof includes the data hash, transmission time, and signatures of both parties; After the data transmission is completed, the data node notifies the transaction node to update the order status to complete, and the transaction node records the order status information on the blockchain, forming a multi-version change record of the order.
9. A decentralized cross-domain data interconnection system, characterized in that, The system includes: authentication nodes, transaction nodes, and data nodes, wherein the data nodes include provider data nodes and user data nodes; wherein... The authentication node is used to store the identity credentials or root certificates of the transaction node and the data node, and to perform identity authentication on the data node based on the triggering of the transaction node. The transaction node is used to obtain data metadata information based on the data to be listed according to the data to be listed based on the trigger of the provider data node, generate a unique data identifier for the data to be listed based on the data metadata information, then trigger the provider data node to list the data, and generate an order identity token for the data to be acquired based on the trigger of the user data node, and trigger the provider data node to encrypt and transmit the data to the user data node. The data node is used to trigger the authentication node to authenticate the provider data node through the transaction node when pre-listing and acquiring data, and to upload and display the data or transmit the data in encrypted form after the authentication is successful.
10. A computer-readable storage medium storing a computer program that, when executed by a processor, implements the method of any one of claims 1-9.