Data exchange management platform and data exchange method

By designing a data exchange management platform and engine, the problem of high-cost data exchange system construction was solved, and a secure, reliable, and scalable data exchange solution was achieved.

CN121907925APending Publication Date: 2026-04-21NUCTECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NUCTECH CO LTD
Filing Date
2025-11-28
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

In international trade and information technology development, the demand for data exchange between various departments and systems has increased, resulting in high costs for building dedicated systems for each pair of data exchange participants.

Method used

A data exchange management platform is provided, including an operations center, a data exchange engine, and a data exchange information system. Data exchange is achieved through the data exchange engine, allowing initial information systems to join the platform and exchange data with other systems, reducing the need for building dedicated exchange systems.

Benefits of technology

It reduces system setup costs, ensures the security and traceability of data exchange, and guarantees the reliability of data exchange and the scalability of the platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121907925A_ABST
    Figure CN121907925A_ABST
Patent Text Reader

Abstract

The invention discloses a data exchange management platform and a data exchange method, and relates to the technical field of shared data. The data exchange management platform comprises an operation center, a data exchange engine and a data exchange information system, wherein the data exchange information system is in communication connection with the operation center through the data exchange engine; the data exchange information system comprises an initial information system which is successfully added into the data exchange management platform. The data exchange management platform has good expansibility, an initial information system with data exchange requirements can be allowed to be added into the data exchange management platform, and after the initial information system is successfully added into the data exchange management platform, data exchange can be carried out through a data exchange engine and other data exchange information systems in the platform; and an exclusive exchange system does not need to be established for both data exchange parties, so that the system establishment cost is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of data sharing technology, and in particular relates to a data exchange management platform and a data exchange method. Background Technology

[0002] With the continuous growth of international trade and the strengthening of information technology infrastructure, there are increasingly more scenarios for data exchange between various departments and systems within customs. When implementing a single window system, data exchange with other departments has become a necessary core function. Furthermore, customs authorities of different countries also require data exchange to facilitate business cooperation in international processes such as customs clearance, inspection, and declaration. As the demand for data exchange continues to increase, building a dedicated data exchange system for each pair of data exchange participants would be extremely costly. Summary of the Invention

[0003] This application provides a data exchange management platform and a data exchange method. The data exchange management platform has good scalability, allowing new initial information systems to join the platform. Data exchange information systems within the platform can exchange data through a data exchange engine, eliminating the need to establish dedicated exchange systems for both parties and reducing system setup costs.

[0004] On one hand, embodiments of this application provide a data exchange management platform, including: an operation center, a data exchange engine, and a data exchange information system. The data exchange information system communicates with the operation center through the data exchange engine. The data exchange information system includes an initial information system for those who have successfully joined the data exchange management platform. The data exchange engine is used to forward the first joining application sent by the initial information system to the operation center, which reviews the first joining application. The data exchange engine is also used to forward the review result of the operation center to the corresponding initial information system. If the review result is approved, the initial information system successfully joins the data exchange management platform. The data exchange information system includes the dual identities of data requester and data provider. The data exchange engine is also used to forward the exchange request from the data requester's data exchange information system to the data provider's data exchange information system, and to forward the target exchange data fed back by the data provider's data exchange information system to the data requester's data exchange information system.

[0005] In some embodiments, the data exchange management platform further includes: a certification authority and a timestamp authority, which are respectively connected to the data exchange engine. The certification authority is used to provide certification services, and the timestamp authority is used to provide timestamp services. The data exchange engine is also used to authenticate the data exchange information system of the data applicant through the certification authority. If the authentication is successful, the exchange application is timestamped by the timestamping authority and the signature information of the data exchange engine is added. The exchange application with the added timestamped and signed information is then forwarded to the data provider's data exchange information system. The data exchange engine is also used to authenticate the data provider's data exchange information system through a certification authority. If the authentication is successful, a timestamp is added to the target exchange data through a timestamp authority, and the signature information of the data exchange engine is added. The target exchange data with added timestamp and signature information is then forwarded to the data requester's data exchange information system.

[0006] In some embodiments, before forwarding the first join request sent by the data exchange information system to the operation center, the data exchange engine is further configured to, upon receiving the first connection request sent by the data exchange information system, authenticate the data exchange information system, and, if the authentication is successful, return the first identity information of the data exchange engine to the data exchange information system, which then authenticates the data exchange engine and, if the authentication is successful, sends the first join request to the data exchange engine; wherein, the first connection request is generated by the data exchange information system in response to the user's first operation; The operations center includes a participant management unit, which verifies the legitimacy of the first application. If the first application is legitimate, it submits the application for approval and, after completing the approval process, sends the review result of the first application to the data exchange engine. The data exchange engine then forwards the review result of the first application to the corresponding data exchange information system.

[0007] In some embodiments, the operations center also includes an engine management unit; The engine management unit is used to receive the second connection request sent by the data exchange engine, authenticate the data exchange engine, and if the authentication is successful, to feed back the second identity information of the operation center to the data exchange engine. The data exchange engine then authenticates the operation center and, if the authentication is successful, sends a second join request to the operation center. The engine management unit is also used to verify the legitimacy of the second join application. If the second join application is legitimate, it submits the second join application for approval and, after completing the approval process, feeds back the approval result to the data exchange engine.

[0008] In some embodiments, the operations center further includes a rule configuration unit, a certification authority configuration unit, and a timestamp authority configuration unit; The rule configuration unit is used to configure the first rule for data exchange between the data exchange engine and the data exchange information system, the second rule for the data exchange engine to join and leave the data exchange management platform, and the third rule for the data exchange information system to join and leave the data exchange management platform. The certification authority configuration unit is used to configure the certification authorities that are allowed to be used in the data exchange management platform; The timestamp organization configuration unit is used to configure the timestamp organizations that are allowed to be used in the data exchange management platform; The operations center is also used to respond to synchronization requests sent by the data exchange engine, and to feed back the target information to the data exchange engine for synchronization and updating. The target information includes the first rule, the second rule, the third rule, the certification authority configuration information, and the timestamp authority configuration information updated since the last synchronization request.

[0009] In some embodiments, the operations center includes at least one operations device; when the number of operations devices is greater than or equal to two, the functional units and unit configurations of all operations devices are identical.

[0010] In some embodiments, the data exchange management platform includes a first data exchange management platform and a second data exchange management platform. The operation centers in the first data exchange management platform and the second data exchange platform are connected in a federated mode. The two operation centers negotiate data exchange rules, and the data exchange information system in the first data exchange management platform and the data exchange information system in the second data exchange management platform exchange data through corresponding data exchange engines.

[0011] In some embodiments, the data exchange management platform includes at least two data exchange engines, and any two data exchange engines are connected in communication.

[0012] In some embodiments, the data exchange engine includes at least one engine device; when the number of engine devices is greater than or equal to two, the functional units and unit configurations of all engine devices located in the same data exchange engine are identical.

[0013] In some embodiments, the data exchange information system includes a resource publishing unit and a resource retrieval unit; The resource publishing unit is used to respond to the user's second operation by sending a publishing request to the data exchange engine; The data exchange engine authenticates the data exchange information system through a certification authority. If the authentication is successful, the data exchange engine adds its signature information to the publishing request and adds a timestamp to the publishing request through a timestamp authority. The publishing request with the added timestamp and signature information is then forwarded to the operation center, which authenticates the data exchange engine through a certification authority. If the authentication is successful, the received resources are published. The resource retrieval unit is used to respond to a third user action by sending a retrieval request to the data exchange engine; The data exchange engine authenticates the data exchange information system through a certification authority. If the authentication is successful, the data exchange engine adds its signature information to the search request and adds a timestamp to the search request through a timestamp authority. The search request with the added timestamp and signature information is then forwarded to the operations center. The operations center authenticates the data exchange engine through a certification authority. If the authentication is successful, the search results are fed back to the data exchange engine, which then forwards the search results to the corresponding data exchange information system.

[0014] On the other hand, embodiments of this application also provide a data exchange method applied to a data exchange engine in a data exchange management platform. The data exchange management platform further includes an operation center and a data exchange information system. The data exchange information system communicates with the operation center through the data exchange engine. The data exchange information system includes an initial information system that has successfully joined the data exchange management platform and includes dual identities of a data requester and a data provider. The method includes: Receive the first joining application sent by the initial information system and forward it to the operations center for review; The operations center forwards the review result of the first application to the corresponding initial information system; if the review result is approved, the initial information system is successfully added to the data exchange management platform. Receive exchange requests from the data exchange information system of the data requester, and forward the exchange requests to the data exchange information system of the data provider; Receive the target exchange data from the data provider's data exchange information system and forward the target exchange data to the data requester's data exchange information system.

[0015] This application provides a data exchange management platform and a data exchange method. The data exchange management platform has good scalability and can allow initial information systems with data exchange needs to join the data exchange management platform. After the initial information system successfully joins the data exchange management platform, it can exchange data with other data exchange information systems in the platform through the data exchange engine. It does not require the establishment of a dedicated exchange system for the two parties to the data exchange, thus reducing the system construction cost. Attached Figure Description

[0016] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 This is a schematic diagram of the structure of a data exchange management platform provided in an embodiment of this application; Figure 2 This is a schematic diagram of the structure of another data exchange management platform provided in this application embodiment; Figure 3 This application provides a schematic diagram of the structure of an operation center. Figure 4 This is a schematic diagram of the structure of a data exchange engine provided in an embodiment of this application; Figure 5 This is a schematic diagram of the structure of a data exchange information system provided in an embodiment of this application; Figure 6 This is a schematic diagram of the structure of another data exchange management platform provided in the embodiments of this application; Figure 7 This is a schematic diagram of the structure of another data exchange management platform provided in this application embodiment; Figure 8 This application provides a schematic diagram of the structure for establishing a federation model between two operation centers. Figure 9 This is a schematic diagram of the structure of another data exchange management platform provided in the embodiments of this application; Figure 10 This is a schematic diagram illustrating the process of adding a data exchange engine to a data exchange management platform according to an embodiment of this application; Figure 11 This application provides a schematic diagram of the process of adding a data exchange information system to a data exchange management platform according to an embodiment of the present application; Figure 12 This application provides a schematic diagram of the process for establishing a federation in an operations center. Figure 13This is a schematic diagram illustrating a process for resource publishing, resource retrieval, and resource exchange provided in an embodiment of this application; Figure 14 This is a flowchart illustrating a data exchange method provided in an embodiment of this application; Figure 15 This is a schematic diagram of the structure of an engine device provided in an embodiment of this application; Figure 16 This is a schematic diagram of the structure of an operating device provided in an embodiment of this application. Detailed Implementation

[0018] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.

[0019] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.

[0020] To address the problems raised in the background art, embodiments of this application provide a data exchange management platform and a data exchange method. The data exchange management platform provided in this application embodiment will be described first below.

[0021] Figure 1 This is a schematic diagram of the structure of a data exchange management platform provided in an embodiment of this application. (Refer to...) Figure 1The data exchange management platform may include: an operations center 1, a data exchange engine 2, and a data exchange information system 3. The data exchange information system 3 can communicate with the operations center 1 through the data exchange engine 2. The data exchange information system 3 includes an initial information system that has successfully joined the data exchange management platform. The data exchange engine 2 forwards the first joining application sent by the initial information system to the operations center 1, which reviews the application. The data exchange engine 2 also forwards the review result of the operations center 1 to the corresponding initial information system. If the review result is approved, the initial information system successfully joins the data exchange management platform. The data exchange information system 3 includes both a data requester and a data provider. The data exchange engine 2 also forwards the exchange application from the data requester's data exchange information system 3 to the data provider's data exchange information system 3, and forwards the target exchange data returned by the data provider's data exchange information system 3 to the data requester's data exchange information system 3.

[0022] Operations Center 1 serves as the management and rule-making center for the data exchange management platform, possessing the functions of rule-making, managing the data exchange engine, and managing the data exchange information system. The rules formulated by Operations Center 1 include: the first rule for data exchange between the data exchange engine and the data exchange information system; the second rule for configuring the data exchange engine to join and leave the data exchange management platform; and the third rule for configuring the data exchange information system to join and leave the data exchange management platform. The Operations Center is responsible for providing data exchange support and operation for the data exchange information system, such as resource publishing and retrieval services, and for coordinating collaboration among various parts, but does not participate in the actual data exchange process.

[0023] Data exchange information system 3 is not a functional module implemented by the data exchange system. Instead, it is a system that actually uses the data exchange management platform. After implementing the interface standards defined by the data exchange management platform and registering with the operation center 1, it is added to the data exchange management platform. After being added to the data exchange management platform, it can exchange data with other data exchange information systems through the data exchange engine.

[0024] Data exchange engine 2 serves as the entry point and executor for data exchange. It establishes a communication connection between the initial information system (not yet joined to the data exchange management platform) and the operation center 1. After the operation center 1 approves the first joining application sent by the initial information system, the initial information system successfully joins the data exchange management platform, becoming a legitimate data exchange information system 3 within the platform. Data exchange information system 3 can exchange data with other data exchange information systems 3 within the platform through data exchange engine 2. For example, ... Figure 1As shown, the data exchange management platform includes three data exchange information systems 3, and any two data exchange information systems 3 can exchange data through the data exchange engine 2.

[0025] Operations Center 1 features authoritative, convenient, and consistent services. Its authoritative service ensures the security of data exchange among all participants. Its convenient service reduces the operational complexity for participants in accessing system services, enabling easy service access. Its consistent service ensures the system maintains stable and unified service output and maintenance capabilities throughout its entire lifecycle.

[0026] Operations Center 1 uses a preset interface protocol for communication, allowing all initial information systems that conform to the preset interface protocol to join the data exchange management platform. Initial information systems connect to Data Exchange Engine 2 by implementing the interface corresponding to the preset interface protocol, and then register with Operations Center 1 through Data Exchange Engine 2. After Operations Center 1 approves the registration, the initial information system becomes a data exchange information system of the data exchange management platform, enabling it to perform data exchange functions within the platform.

[0027] The default interface protocol includes all types of interface protocols known to those skilled in the art, and is not limited thereto. As an example, the default interface protocol may include Representational State Transfer (REST) ​​or Simple Object Access Protocol (SOAP). The service description for REST is defined using the OpenAPI3 specification, and the service description for SOAP is defined using WSDL. This data exchange management platform allows any initial information system conforming to either the REST service or the SOAP protocol to join.

[0028] Each data exchange information system 3 needs to correspond to a data exchange engine 2, and a data exchange engine 2 can support multiple data exchange information systems 3 at the same time.

[0029] The data exchange management platform provided in this application embodiment has good scalability, allowing initial information systems with data exchange needs to join the data exchange management platform. After the initial information system successfully joins the data exchange management platform, it can exchange data with other data exchange information systems 3 in the platform through the data exchange engine 2. It does not require the establishment of a dedicated exchange system for the two parties to the data exchange, thus reducing the system construction cost.

[0030] In some embodiments, such as Figure 2As shown, the data exchange management platform also includes: a certification authority 4 and a timestamp authority 5. The certification authority 4 and the timestamp authority 5 are respectively connected to the data exchange engine 2. The certification authority 4 is used to provide certification services, and the timestamp authority 5 is used to add a trusted timestamp at a specific point in time to provide timestamp services.

[0031] In this embodiment, the operation center 1 also has the function of configuring authentication authorities 4 and timestamp authorities 5 that are allowed to be used in the data exchange management platform. The authentication authority 4 configured by the operation center 1 is a trusted authentication authority, and the timestamp authority 5 configured by it is a trusted timestamp authority.

[0032] The identity information of Operation Center 1, Data Exchange Engine 2 and Data Exchange Information System 3 within the Data Exchange Management Platform all adopt the form of digital certificates. All digital certificates involved in the Data Exchange Management Platform originate from the certification authority 4 configured by the Operation Center, and all timestamps originate from the timestamp authority configured by the Operation Center.

[0033] The data exchange engine 2 is also used to authenticate the data exchange information system 3 of the data applicant through the authentication authority 4. If the authentication is successful, the exchange application is timestamped by the timestamping authority 5 and the signature information of the data exchange engine 2 is added. The exchange application with the added timestamped and signature information is then forwarded to the data exchange information system 3 of the data provider.

[0034] The data exchange engine 2 is also used to authenticate the data provider's data exchange information system 3 through the certification authority 4. If the authentication is successful, the target exchange data is timestamped by the timestamping authority 5 and the signature information of the data exchange engine is added. The target exchange data with added timestamping and signature information is then forwarded to the data applicant's data exchange information system 3.

[0035] As an example, the identity information of the data exchange information system 3 is represented in the form of a digital certificate. When the data exchange engine 2 receives an exchange request (or target exchange data), it also obtains the digital certificate of the corresponding data exchange information system 3 and verifies the legality of the digital certificate through the certification authority 4. If the digital certificate originates from a trusted certification authority 4 and is within its validity period, the data exchange engine 2 adds a timestamp and signature information to the exchange request (or target exchange data) and forwards the exchange request (or target exchange data) with the added timestamp and signature information to the corresponding data exchange information system 3.

[0036] Through trusted third-party service providers (i.e., certification authorities and timestamp authorities), during the data exchange process, the data exchange engine 2 verifies the identities of all participants in the data exchange (data applicants and data providers). Only after successful identity verification will subsequent steps be executed, ensuring the security of the data exchange. At the same time, a trusted timestamp is added to the data exchange behavior, making the data exchange traceable and non-repudiable.

[0037] In some embodiments, before forwarding the first join request sent by the data exchange information system to the operation center, the data exchange engine is further configured to authenticate the data exchange information system upon receiving the first connection request sent by the data exchange information system, and if the authentication is successful, to return the first identity information of the data exchange engine to the data exchange information system. The data exchange information system then authenticates the data exchange engine and, if the authentication is successful, sends the first join request to the data exchange engine. The first connection request is generated by the data exchange information system in response to a user's first operation. The operation center includes a participant management unit, which verifies the legality of the first join request. If the first join request is legal, the participant management unit submits the first join request for approval and, after completing the approval process, sends the review result of the first join request to the data exchange engine, which then forwards the review result of the first join request to the corresponding data exchange information system.

[0038] For example, the process of a data exchange information system joining a data exchange management platform is as follows: Figure 11 As shown, the specific process is as follows: Before the initial information system joins the data exchange management platform, the initial information system initiates a secure connection creation request (i.e., the first connection request) to the data exchange engine. The data exchange engine and the initial information system mutually authenticate each other, verifying the legitimacy of each other's identities. Authentication includes verifying whether the digital certificate originates from a certification authority configured by the operations center and the validity of the digital certificate. If both parties are legitimate, the initial information system sends the first joining request to the data exchange engine. The data exchange engine forwards the first joining request to the operations center, which verifies the legitimacy of the first joining request. If legitimate, it submits it for approval. According to the operations center's preset regulations, the approval process can be completed manually or automatically. After the approval process is completed, the operations center sends the approval result to the data exchange engine, which forwards the approval result to the corresponding initial information system and saves the approval result in its local configuration. After the initial information system joins the data exchange management platform, it becomes a data exchange information system, and the data exchange information system saves the approval result.

[0039] It should be noted that, Figure 11The example shown is merely illustrative and it will be apparent to those skilled in the art that the process specifications here are dynamic and can be adapted to different scenarios.

[0040] In this embodiment, the data exchange information system 3 needs to join the data exchange management platform through the data exchange engine 2, and realize the data exchange function through the data exchange engine 2. During the operation of communication, the data exchange engine 2 will verify the identity and validity of the communication partner, as well as the validity of key timestamps. When transmitting data or sending commands, it will also add signature information to the data to ensure that the source of the data is reliable and traceable, which is conducive to improving the security of data exchange.

[0041] In some embodiments, the operations center further includes an engine management unit; the engine management unit is used to receive a second connection request sent by the data exchange engine, authenticate the data exchange engine, and, if the authentication is successful, provide the data exchange engine with the second identity information of the operations center, so that the data exchange engine can authenticate the operations center and, if the authentication is successful, send a second join request to the operations center; the engine management unit is also used to verify the legality of the second join request, and, if the second join request is legal, submit the second join request for approval, and, after completing the approval process, provide the approval result to the data exchange engine.

[0042] In this embodiment, the addition of a data exchange engine to the data exchange management platform also requires approval through the procedures stipulated by the operations center. The process for adding a data exchange engine to the data exchange management platform is as follows: Figure 10 As shown, the specific situation is as follows: The system setup personnel need to configure the operations center address in the data exchange engine. The data exchange engine accesses the operations center address and sends a second connection request to the operations center. Upon receiving the second connection request, the operations center first verifies the legitimacy of the data exchange engine's identity, including but not limited to whether its digital certificate originates from a designated trusted certification authority and is valid. After successful identity verification, the operations center sends its identity information to the data exchange engine, which also verifies the operations center's legitimacy. After both the data exchange engine and the operations center successfully verify their identities, a secure connection is established, and they begin communication.

[0043] After a secure connection is established, the data exchange engine sends a second join request. The operations center verifies the legitimacy of the second join request. If it is legitimate, it submits it for approval. According to the operations center's regulations, the approval process can be completed manually or automatically. After the approval process is completed, the approval result is sent to the data exchange engine. Upon receiving the result, the data exchange engine updates the relevant results and maintains the join status.

[0044] Each data exchange engine joins the operations center by registering. Each data exchange engine that joins the operations center can obtain the operations center's rules, trusted certification authorities, trusted timestamp authorities, and configuration information such as other data exchange engines. Based on the relevant configuration, the data exchange engine can communicate with other data exchange engines and perform data exchange operations.

[0045] It should be noted that, Figure 10 The example shown is merely illustrative and it will be apparent to those skilled in the art that the process specifications here are dynamic and can be adapted to different scenarios.

[0046] In some embodiments, the operation center further includes a rule configuration unit, a certification authority configuration unit, and a timestamp authority configuration unit. The rule configuration unit is used to configure a first rule for data exchange between the data exchange engine and the data exchange information system, a second rule for the data exchange engine to join and leave the data exchange management platform, and a third rule for the data exchange information system to join and leave the data exchange management platform. The certification authority configuration unit is used to configure the certification authorities allowed to be used in the data exchange management platform. The timestamp authority configuration unit is used to configure the timestamp authorities allowed to be used in the data exchange management platform. The operation center is also used to respond to a synchronization request sent by the data exchange engine by feeding back target information to the data exchange engine for synchronization and updating. The target information includes the first rule, the second rule, the third rule, the certification authority configuration information, and the timestamp authority configuration information updated since the last synchronization request.

[0047] To ensure the timeliness of rules, processes, and configuration information, the data exchange engine periodically sends synchronization requests to the operations center to query and download the latest relevant information. The validity period of the downloaded information is determined by the rules of the operations center. To avoid downloading all content each time and consuming too much bandwidth and computing resources, all rules and records in the operations center have creation and modification timestamps, allowing only changed or soon-to-expire content to be updated each time.

[0048] like Figure 10 As shown, after the data exchange engine joins the data exchange management platform, it will periodically trigger requests for the latest rule configurations. Upon receiving the request, the operations center collects the latest rule configuration information based on the updated version and feeds the latest rule configuration results back to the data exchange engine. After receiving the results, the data exchange engine updates and maintains the latest rule configuration locally.

[0049] For example, such as Figure 3As shown, the operations center includes at least the following units: rule configuration, certification authority configuration, timestamp authority configuration, engine management, participant management, collaborator management, address management, routing management, monitoring, logging, and security services.

[0050] The rule configuration unit is used to configure the rule requirements (i.e., the first rule) for the data exchange engine, data exchange information system, and shared resources in the data exchange management platform; configure the process for the data exchange engine to join and leave the data exchange management platform (i.e., the second rule); configure the process for the data exchange information system to join or leave the data exchange management platform (i.e., the third rule); configure the process for publishing, retrieving, and exchanging resources; and configure security rule requirements, etc.

[0051] The Certification Authority Configuration Unit is used to configure the certification authorities that are allowed to be used in the data exchange management platform. All digital certificates involved in the data exchange management platform must originate from the certification authorities configured by the operations center.

[0052] The timestamp organization configuration unit is used to configure the timestamp organizations that are allowed to be used in the data exchange management platform. In the data exchange management platform, timestamp authentication for all specific points in time can only be provided by the timestamp organizations configured by the operations center.

[0053] The engine management unit manages the data exchange engines that join the data exchange management platform. The operations center conducts security verification on the applications of engines and approves their joining according to the approval process. When the data exchange management platform includes multiple data exchange engines, the operations center shares relevant information about the data exchange engines with other data exchange engines to facilitate data exchange between them.

[0054] The participant management unit manages the data exchange information systems that join the data exchange management platform. The operations center conducts security verification on initial applications for joining and approves their joining according to the approval process. The operations center shares information from the data exchange information systems with the platform's data exchange engine or other data exchange information systems. After joining the platform, the data exchange information systems can publish resources, retrieve resources, and trade resources (i.e., exchange data) within the platform.

[0055] The Federation Collaboration Management Unit is used to establish a federation model between different operations centers. This involves connecting two data exchange management platforms, maintaining and monitoring the federation, and negotiating rules, certification authorities, and compliant data exchange information systems between the federation members. Establishing a federation between two different operations centers means connecting their respective data exchange management platforms, enabling secure data exchange between the data exchange information systems belonging to those platforms.

[0056] Address management is used to manage the address information of all data exchange engines, data exchange information systems, and collaborators.

[0057] The routing management unit is used to manage routing information between data exchange information systems, enabling secure communication between the two parties exchanging data.

[0058] The monitoring unit collects operational report data and technical monitoring information from the data exchange management platform. It monitors the operational status and data transaction information of all data exchange engines, facilitating understanding of each other's availability among the engines, analyzing their operational status, and monitoring the operational information of the data exchange information system. For data exchange transactions within the data exchange information system, only the basic transaction metadata is monitored; the transaction data content is not monitored.

[0059] The log unit is used to record all business operations of the operations center, as well as the working status of the data exchange engine, the operation actions of the data exchange information system, and the data transaction status.

[0060] Security services are used to ensure the communication security of the operations center. The operations center primarily communicates with the data exchange engine and the operations centers of collaborating parties, but it also communicates indirectly with the data exchange information system through the data exchange engine.

[0061] In some embodiments, the operations center includes at least one operations device; when the number of operations devices is greater than or equal to two, the functional units and unit configurations of all operations devices are identical.

[0062] Each operational device possesses all the functionalities of an operations center instance. It can be remotely controlled via the Secure Shell (SSH) protocol and configured and managed through a web management page. Once connected to power and network, the operational device can function independently as an operations center. Multiple operational devices can also be used to form an operations center cluster (e.g.,...). Figure 6 As shown in the diagram, multiple operating devices within the cluster have the same functional units and unit configurations. The failure of a single operating device will not cause the operation center to become unavailable, nor will it affect the engine's execution of data exchange tasks, thus providing a highly available operation center service for the data exchange management platform.

[0063] In some embodiments, such as Figure 8 As shown, the data exchange management platform includes a first data exchange management platform and a second data exchange management platform. The operation centers in the first data exchange management platform and the second data exchange platform are connected in a federated mode. The two operation centers negotiate data exchange rules. The data exchange information system in the first data exchange management platform and the data exchange information system in the second data exchange management platform exchange data through corresponding data exchange engines.

[0064] In this embodiment, before the federation is established, the first data exchange management platform and the second data exchange management platform are independent of each other. The data exchange information systems of the two data exchange management platforms can only exchange data within the platform and cannot exchange data across platforms.

[0065] The operation centers of the two data exchange management platforms establish a federation model through negotiation. After the federation model is successfully established, the two operation centers negotiate the federation agreement and configure data exchange rules, and the data exchange engines obtain data exchange permissions. The two operation centers will periodically synchronize relevant information of each other's data exchange engines and data exchange information systems to facilitate data exchange between the various data exchange engines and data exchange information, enabling not only data exchange within the platform but also cross-platform data exchange.

[0066] In this embodiment, by establishing a connection between the operation centers of two different data exchange management platforms in a federated mode, data exchange between the data exchange information systems of different data exchange management platforms is realized. This is applicable to international cooperation scenarios such as customs clearance, inspection, and declaration in different countries.

[0067] For example, such as Figure 12 The diagram shown is a schematic representation of a process for establishing a federation of operations centers according to an embodiment of this application. (Refer to...) Figure 12 The federation is established starting with one of the operation centers, for example, Operation Center I. Operation Center I initiates a secure connection with Operation Center II. Operation Center II first verifies the identity and legitimacy of Operation Center I. Upon successful verification, Operation Center II sends its own identity information back to Operation Center I. Operation Center I then verifies the legitimacy of Operation Center II and initiates a federation request. After verifying the federation request, Operation Center II sends the result back to Operation Center I. Operation Center I receives the result and processes the response. If the result is successful, it sends rule configuration to Operation Center II. After verifying and matching the rule configuration, Operation Center II returns the matched rule result to Operation Center I. After confirming the matching rule is successful, Operation Center I sends a list of trusted libraries to Operation Center II. The trusted libraries include trusted certification authorities and trusted timestamp authorities. After verifying and matching the trusted libraries, Operation Center II returns the matched trusted library result to Operation Center I. Once Operation Center I receives and confirms the result, the federation is established.

[0068] Once the federated model is successfully established, the two operation centers will periodically synchronize relevant information from each other's data exchange engines and data exchange information systems, facilitating data exchange transactions between the various data exchange engine and data exchange information system personnel. For example... Figure 12 As shown, each of the two operation centers independently and periodically sends data exchange engine and data exchange information system information that meet the synchronization conditions to the other party. After receiving the information, the other party confirms and saves it.

[0069] It should be noted that, Figure 12 This is merely an example; it will be apparent to those skilled in the art that timed information synchronization can take various flexible forms or processes. This is just one example, and this method also supports other forms of information synchronization mechanisms.

[0070] In some embodiments, such as Figure 7 As shown, the data exchange management platform includes at least two data exchange engines 2, and any two data exchange engines 2 are connected in communication.

[0071] For example, such as Figure 7 The two data exchange information systems 3 participating in the data exchange belong to different data exchange engines 2. During the data exchange process, the data exchange engine 2 of the data provider also needs to verify the identity of the data exchange engine 2 of the data requester. Only after the identity verification is passed will the application be forwarded to the data exchange engine 2 of the data provider. At the same time, the data exchange engine 2 of the data requester also verifies the identity of the data exchange engine 2 of the data provider. Only after the identity verification is passed will the target exchange data be forwarded to the data requester.

[0072] It should be noted that even if the two data exchange information systems 3 participating in the data exchange belong to the same data exchange engine 2, the data exchange engine 2 still needs to authenticate the two data exchange information systems 3.

[0073] Similarly, the operations center will be configured with multiple timestamp institutions. When the remote service of a certain timestamp institution is unavailable, the data exchange engine can select other timestamp institutions to provide timestamp services, thereby improving the availability of the data exchange system.

[0074] In some embodiments, the data exchange engine includes at least one engine device; when the number of engine devices is greater than or equal to two, the functional units and unit configurations of all engine devices located in the same data exchange engine are identical.

[0075] The engine device includes all the functionality of a data exchange engine instance, and can be remotely controlled via SSH or configured and managed through a web management page. Once connected to power and network, the engine device can operate independently as a data exchange engine. Multiple engine devices can also be used to form a cluster of data exchange engines (e.g.,...). Figure 6 As shown, it provides a highly available data exchange engine service for the data exchange management platform.

[0076] For example, such as Figure 4As shown, the data exchange engine includes at least the following units: certification authority maintenance, timestamp authority maintenance, identity information maintenance, address maintenance, digital certificate maintenance, identity verification, security verification, encryption and decryption, digital signature, message routing, resource exchange, resource publishing, resource retrieval, log recording, and error handling.

[0077] The certification body maintenance unit is used to periodically synchronize certification body information with the operations center, updating the latest changes and information on certification bodies that have expired each time.

[0078] The timestamp organization maintenance unit is used to periodically synchronize the trusted timestamp organization information of the operations center, and to maintain the latest changes and expired timestamp organization information each time.

[0079] The identity information maintenance unit is used to periodically synchronize information between the data exchange engine and the data exchange information system of the operations center, maintaining the latest changes and expired content each time.

[0080] The address maintenance unit is used to periodically synchronize the address information of other data exchange engines and their stored data exchange information systems, and to maintain the latest changes and expired content each time.

[0081] The digital certificate maintenance unit is used to temporarily store verified digital certificate information for the data exchange engine and data exchange information system, including the latest changes and expired content for each maintenance.

[0082] The authentication unit is used to verify whether the digital certificates of other communication objects are issued by a trusted certification authority and to verify the validity of the digital certificates. When communicating with the operations center, other data exchange engines, and data exchange information systems, it is necessary to verify the other party's digital certificate. During data exchange, it is also necessary to verify the identities of the data provider and the exchange applicant.

[0083] The security verification unit is used to verify the identity, permissions, and transmitted content of the communication objects to ensure the security, integrity, and consistency of data during the exchange process. The timestamp needs to be verified as being issued by a trusted timestamp organization.

[0084] The encryption / decryption unit is used to encrypt and decrypt specific data during communication to protect data security.

[0085] Digital signature units are used to digitally sign messages (such as exchange requests or target exchange data) during communication to identify the provider of the message.

[0086] The log recording unit is used to record all action information executed by the data exchange engine, which facilitates understanding the operation of the data exchange engine and troubleshooting faults and defects.

[0087] The error handling unit is used to handle all operational errors or anomalies, preventing them from affecting the subsequent operation of the data exchange management platform. This configuration ensures the robustness of the data exchange engine, preventing operational failures caused by environmental anomalies or erroneous data.

[0088] The message routing unit is used to parse the routing status of messages, making it easier to understand the data source and the path to the destination.

[0089] The resource publishing unit is responsible for publishing the resource publishing information submitted by the data exchange information system to the operation center so that other data exchange information systems can retrieve the relevant information.

[0090] The resource retrieval unit is responsible for forwarding the retrieval criteria issued by the data exchange information system to the operation center, which then performs the retrieval and feeds back the retrieval results to the corresponding data exchange information system.

[0091] The resource exchange unit is responsible for establishing secure connections and using functional units such as authentication, digital signature, encryption / decryption, and transmission to complete secure data exchange.

[0092] In this embodiment, the data exchange engine is the core component of the data exchange management platform. It serves as the access point for the data exchange information system and the executor of all data exchange activities. It provides functions such as data transmission and command forwarding, ensuring the security, integrity, consistency, and non-repudiation of data exchange. Simultaneously, the data exchange engine periodically updates information such as authentication authority information, timestamp authority information, data exchange engine information, data exchange information system information, identity information, and address information, avoiding the need to access the operations center every time communication occurs.

[0093] For example, such as Figure 9As shown, message communication between Data Exchange Engine 2 and Operation Center 1 uses Transport Layer Security (TLS) for verification, and the digital certificates used are all from the certification authorities configured by Operation Center. Data Exchange Engine 2 downloads the global configuration of Operation Center 1 and performs authentication and security verification according to the requirements of Operation Center 1 during command execution and data exchange. Message communication between Data Exchange Engine 2 and Data Exchange Information System 3 is also completed through the TLS protocol, and certificate verification is required when the two parties establish a connection. Data Exchange Engine 2 verifies the legality of relevant certificates through the certification authorities configured by Operation Center 1, verifying that all digital certificates originate from the designated trusted certification authority library. Data Exchange Engine 2 also adds timestamps to all messages, and the timestamps are obtained from the timestamp authority 5 configured by Operation Center 1. When Data Exchange Engines 2 communicate with each other, all messages also use the bidirectional TLS protocol to ensure security, and certificate verification is required when exchanging data, and digital signatures are required when sending messages.

[0094] In some embodiments, when performing data exchange, the data exchange engine temporarily stores the configuration rules and digital certificates involved in the local system. When used again, if the above information is still valid, it can be used directly, and security verification is performed based on the information temporarily stored in the local system. When the local network fails, the data exchange function can still be completed.

[0095] In some embodiments, during data exchange and communication, the data exchange engine verifies the validity of the digital certificate of the communicating party through the certification authority and temporarily stores the verified digital certificate in the local system. The temporary storage result can be reused repeatedly within a preset time period, without having to access the remote certification authority for each communication. This can improve verification efficiency, prevent network or remote service failures, and enhance availability.

[0096] In some embodiments, during data exchange and communication, messages or data transmitted by the data exchange engine carry timestamps. The purpose of timestamps is to prove the existence of messages or data at a specific point in time. All timestamps within the data exchange management platform are provided by timestamp authorities configured by the operations center. When using timestamp services, the data exchange engine temporarily stores verification information such as digital certificates from relevant timestamp authorities. When it is necessary to verify the validity of a timestamp, the data exchange engine can use the temporarily stored digital certificates for verification. This improves verification performance and ensures that verification remains available even if the remote timestamp service fails, thereby enhancing system effectiveness.

[0097] In some embodiments, the data exchange information system includes a resource publishing unit; the resource publishing unit is used to send a publishing request to the data exchange engine in response to a second operation by the user; the data exchange engine authenticates the data exchange information system through an authentication authority, and if the authentication is successful, adds the data exchange engine's signature information to the publishing request, adds a timestamp to the publishing request through a timestamp authority, and forwards the publishing request with the added timestamp and signature information to the operation center, whereby the operation center authenticates the data exchange engine through an authentication authority, and publishes the received resources if the authentication is successful.

[0098] In some embodiments, the data exchange information system further includes a resource retrieval unit; the resource retrieval unit is used to issue a retrieval request to the data exchange engine in response to a third operation by the user; the data exchange engine authenticates the data exchange information system through an authentication authority, and when the authentication is successful, adds the data exchange engine's signature information to the retrieval request, adds a timestamp to the retrieval request through a timestamp authority, and forwards the retrieval request with added timestamp and signature information to the operation center, whereby the operation center authenticates the data exchange engine through an authentication authority, and when the authentication is successful, feeds back the retrieval results to the data exchange engine, which then forwards the retrieval results to the corresponding data exchange information system.

[0099] For example, such as Figure 5 As shown, the data exchange information system may include resource management, resource publishing, resource application, resource review, resource exchange, identity information maintenance, access control and identity verification and authorization units.

[0100] The resource management unit is used to manage and maintain shareable resources, and also provides retrieval functions to support resource requests from other data exchange information systems.

[0101] The resource publishing unit is used to publish resources to the data exchange management platform, enabling other data exchange information systems to retrieve relevant information.

[0102] The resource request unit is used to send resource request information (i.e., exchange request) to the data provider. If the data provider approves the request, data exchange can take place.

[0103] The resource review unit is used by the data provider to review the resource requests submitted by the data requester. If the review is approved, resource exchange can take place.

[0104] Resource exchange is used to securely exchange resources (i.e., target exchange data) for resource transactions. The data exchange information system needs to sign the resource provider itself; other exchange processes are executed by the data exchange engine.

[0105] The identity information maintenance unit maintains the identity information and digital certificate information of the data exchange information system itself.

[0106] The access control unit is used to maintain the operational permissions of the data exchange information system itself, as well as access permissions to shared resources, i.e. whether the relevant resources can be exchanged.

[0107] The identity verification and authorization unit manages the identity of the other party in the data exchange information system through identity verification and authorization, and verifies the permissions of resource requests. Resource requests that pass authentication can be exchanged.

[0108] In this embodiment, the data exchange information system serves as the information system for resource users. Initially, the information system implements a standard interface to enable data exchange. Then, it registers with the operation center through the data exchange engine. After being approved by the operation center, it can use functions such as resource publishing, resource application, and resource exchange on the data exchange management platform.

[0109] For example, such as Figure 13 The diagram illustrates, schematically, the process of resource publishing, application, and exchange within the data exchange management platform provided in this embodiment of the application. (Refer to...) Figure 13 When data exchange occurs between a data provider and a data requester, the data provider typically publishes the resource first, then the data requester searches for it and submits a resource transaction request. Once the request is successful, the data exchange can proceed. This description represents a typical scenario, not a mandatory procedure. Upon discovering the resource's location, a resource transaction request can be directly submitted to the resource provider; resource publishing and retrieval are not mandatory steps. Figure 13 This is a typical example, and it is obvious to those skilled in the art that the process specifications here are dynamic and can be adapted to different scenarios.

[0110] like Figure 13 As shown, the data exchange information system, acting as the data provider, publishes resources so that other data exchange information systems can retrieve them. The data provider sends a resource publication request. After the request reaches the data exchange engine, the engine verifies the sender's identity and records the operation. The engine checks the signature and identity using the Online Certificate Status Protocol (OCSP) to verify the certificate's validity. The engine also obtains a timestamp from a timestamp authority, adds signature information to the message, and then submits the request to the operations center. The operations center verifies and records the request. The operations center also verifies the legality and validity of the digital certificate through a certification authority. After successful verification, the operations center publishes the resource publicly, and the publication information is stored in the resource publication repository.

[0111] like Figure 13 As shown, when a data exchange information system, acting as a consumer, needs to consume resources, it can first search for whether relevant resources have been published. The specific search process is as follows: a resource search command is sent to the data exchange engine. The data exchange engine also adds a timestamp and signature information to the message and records it in the log, then forwards the request to the operations center. After the operations center verifies the command, it retrieves the resources from the resource publishing library and returns the resource search results to the data exchange engine, which then forwards the resource search results to the data exchange information system.

[0112] like Figure 13 As shown, after the consumer's data exchange information system obtains the resource retrieval results, it initiates a resource transaction request (i.e., an exchange request) for the resources it needs. This exchange request is also sent to the data exchange engine, which adds a timestamp and signature to the request, logs it, and then forwards it. The exchange request is routed to the data provider's data exchange engine. Upon receiving the request, the data provider's engine verifies and records it, verifies the legality and validity of the digital signature through a certification authority, and, if successful, sends the request to the data provider's data exchange information system. Upon receiving the request, the data provider's system processes it according to its own permission settings. If it agrees to the data exchange, the data provider returns the resource (the target exchange data) to its own engine. This engine also adds a timestamp and signature to the message, logs it, and then forwards the message to the requester's engine. The requester's engine verifies the message and forwards the resource message to the requester's system, which then processes the data for consumption.

[0113] Based on the data exchange management platform provided in the above embodiments, this application also provides specific implementations of the data exchange management method. Please refer to the following embodiments.

[0114] This application also provides a data exchange method, which is applied to a data exchange engine in a data exchange management platform. The data exchange management platform also includes an operation center and a data exchange information system. The data exchange information system communicates with the operation center through the data exchange engine. The data exchange information system includes an initial information system that has successfully joined the data exchange management platform and includes dual identities of data applicant and data provider.

[0115] like Figure 14 As shown, the data exchange method may include the following steps: S110~S140.

[0116] S110. Receive the first joining application sent by the initial information system and forward the first joining application to the operation center, whereby the operation center reviews the first joining application.

[0117] S120. The operation center forwards the review result of the first application to the corresponding initial information system; if the review result is approved, the initial information system is successfully added to the data exchange management platform.

[0118] S130. Receive the exchange request sent by the data exchange information system of the data requester, and forward the exchange request to the data exchange information system of the data provider.

[0119] S140. Receive the target exchange data fed back from the data provider's data exchange information system, and forward the target exchange data to the data requester's data exchange information system.

[0120] The data exchange method provided in this application embodiment involves an initial information system applying to the operation center to join the data exchange management platform through a data exchange engine. After the operation center approves the application, the initial information system successfully joins the data exchange management platform and can then exchange data with other data exchange information systems within the platform through the data exchange engine. This eliminates the need to establish a dedicated exchange system for both parties involved in the data exchange, thus reducing system setup costs.

[0121] In some embodiments, the data exchange management platform further includes a certification authority and a timestamp authority, which are respectively connected to the data exchange engine. Accordingly, "forwarding the exchange request to the data provider's data exchange information system" may include the following steps: The data exchange information system of the data applicant is authenticated by the certification authority; Once identity verification is successful, a timestamp is added to the exchange request by the timestamp authority, and a signature is added to the data exchange engine. The exchange request with the added timestamp and signature is then forwarded to the data provider's data exchange information system. Forwarding target exchange data to the data requester's data exchange information system may include the following steps: The data provider's data exchange information system is authenticated by a certification authority; Once authentication is successful, a timestamp is added to the target exchange data by a timestamp authority, and a signature is added to the data exchange engine. The target exchange data with the added timestamp and signature is then forwarded to the data exchange information system of the data requester.

[0122] The data exchange method provided in this application embodiment uses a trusted third-party service organization (i.e., an authentication authority and a timestamp authority) to authenticate all participants (data requester and data provider) during the data exchange process. Only after successful authentication will subsequent steps be executed, thus ensuring the security of the data exchange. At the same time, a trusted timestamp is added to the data exchange behavior, making the data exchange traceable and non-repudiable.

[0123] In some embodiments, prior to forwarding the first joining request to the operations center, the data exchange method may further include the following steps: Upon receiving a first connection request from the data exchange information system, the system is authenticated, wherein the first connection request is generated by the data exchange information system in response to a first operation by the user. If the identity verification is successful, the first identity information of the data exchange engine is fed back to the data exchange information system. The data exchange information system then verifies the identity of the data exchange engine and sends the first join request to the data exchange engine if the identity verification is successful.

[0124] After "forwarding the first joining application to the operations center", the data exchange method may also include the following steps: The system receives the review result of the first joining application sent by the operations center and forwards the review result of the first joining application to the corresponding data exchange information system. The operations center is used to verify the legality of the first joining application. If the first joining application is legal, the operations center submits the first joining application for approval and sends the review result of the first joining application to the data exchange engine after the approval process is completed.

[0125] In some embodiments, the data exchange method may further include the following steps: Send a second connection request to the operations center, which will then authenticate the data exchange engine and, if the authentication is successful, provide the data exchange engine with the operations center's second identity information. The system verifies the identity of the operations center and sends a second join request to the operations center if the identity verification is successful. The operations center then verifies the legality of the second join request and submits it for approval if it is legal. After the approval process is completed, the approval result is fed back to the data exchange engine. Receive the approval results of the second application to join.

[0126] The data exchange method provided in this application embodiment can be found in the previous embodiment of the data exchange management platform, and will not be repeated here.

[0127] Based on the data exchange method provided in the above embodiments, this application also provides specific implementations of the engine device. Please refer to the following embodiments.

[0128] Figure 15 A schematic diagram of the hardware structure of the engine device provided in an embodiment of this application is shown.

[0129] The engine device may include a processor 201 and a memory 202 storing computer program instructions.

[0130] Specifically, the processor 201 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.

[0131] Memory 202 may include mass storage for data or instructions. For example, and not limitingly, memory 202 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 202 may include removable or non-removable (or fixed) media. Where appropriate, memory 202 may be internal or external to the engine device. In a particular embodiment, memory 202 is a non-volatile solid-state memory.

[0132] Memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Therefore, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the methods according to one aspect of this disclosure.

[0133] The processor 201 reads and executes computer program instructions stored in the memory 202 to implement any of the data exchange methods executed by the data exchange engine in the above embodiments.

[0134] In one example, the engine device may also include a communication interface 203 and a bus 204. Wherein, as... Figure 15 As shown, the processor 201, memory 202, and communication interface 203 are connected through bus 204 and complete communication with each other.

[0135] The communication interface 203 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.

[0136] Bus 204 includes hardware, software, or both, that couples components of an online data flow metering device together. For example, and not limited to, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hypertext Transfer (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VESA Local Bus, VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, bus 204 may include one or more buses. Although specific buses are described and illustrated in the embodiments of this application, this application considers any suitable bus or interconnection.

[0137] This application also provides a data exchange method, which is applied to the operation center in a data exchange management platform. The data exchange management platform also includes a data exchange engine and a data exchange information system. The data exchange information system communicates with the operation center through the data exchange engine. The data exchange information system includes an initial information system that has successfully joined the data exchange management platform and includes dual identities of data applicant and data provider.

[0138] The data exchange method may include the following steps: The first join application forwarded by the data exchange engine is reviewed, and the review result of the first join application is sent to the data exchange engine, which then forwards the review result to the corresponding initial information system. If the review result is approved, the initial information system is successfully added to the data exchange management platform. The operations center does not participate in the data exchange process.

[0139] The data exchange method provided in this application embodiment involves an initial information system applying to the operation center to join the data exchange management platform through a data exchange engine. After the operation center approves the application, the initial information system successfully joins the data exchange management platform and can then exchange data with other data exchange information systems within the platform through the data exchange engine. This eliminates the need to establish a dedicated exchange system for both parties involved in the data exchange, thus reducing system setup costs.

[0140] In some embodiments, the data exchange management platform further includes a certification authority and a timestamp authority, which are respectively connected to the data exchange engine. Accordingly, "reviewing the first join request forwarded by the data exchange engine" may include the following steps: The legitimacy of the first joining application is verified. If the first joining application is legitimate, it is submitted for approval. After the approval process is completed, the review result of the first joining application is sent to the data exchange engine.

[0141] In some embodiments, the data exchange method may further include the following steps: Upon receiving a second connection request from the data exchange engine, the data exchange engine is authenticated. If the identity verification is successful, the second identity information of the operation center is fed back to the data exchange engine. The data exchange engine then verifies the identity of the operation center and sends a second join request to the operation center if the identity verification is successful. The operations center verifies the legitimacy of the second application and, if the application is legitimate, submits it for approval. After completing the approval process, the center sends the approval result back to the data exchange engine. If the approval result is successful, the data exchange engine is successfully added to the data exchange management platform.

[0142] The data exchange method provided in this application embodiment can be found in the previous embodiment of the data exchange management platform, and will not be repeated here.

[0143] Based on the data exchange method provided in the above embodiments, this application also provides specific implementation methods for operating equipment. Please refer to the following embodiments.

[0144] Figure 16The diagram shows a schematic representation of the hardware structure of the operating equipment provided in an embodiment of this application.

[0145] The operating equipment may include a processor 301 and a memory 302 storing computer program instructions. The processor 301 reads and executes the computer program instructions stored in the memory 302 to implement any of the data exchange methods executed by the operation center in the above embodiments.

[0146] In one example, the operating equipment may also include a communication interface 303 and a bus 304. For example, Figure 16 As shown, the processor 301, memory 302, and communication interface 303 are connected through bus 304 and complete communication with each other.

[0147] The communication interface 303 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.

[0148] Bus 304 includes hardware, software, or both, that couples components of an online data flow metering device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hypertext Transfer (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Micro Channel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VESA Local Bus, VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, bus 304 may include one or more buses. Although specific buses are described and illustrated in the embodiments of this application, this application considers any suitable bus or interconnection.

[0149] This application also provides a computer storage medium for implementation. The computer storage medium stores computer program instructions; when executed by a processor, these computer program instructions implement any one of the data exchange methods executed by the operation center in the above embodiments, or any one of the data exchange methods executed by the data exchange engine in the above embodiments.

[0150] This application also provides a computer program product, including a computer program, which, when executed, implements any one of the data exchange methods executed by the operation center in the above embodiments, or implements any one of the data exchange methods executed by the data exchange engine in the above embodiments.

[0151] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.

[0152] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatuses, systems, and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to create a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.

[0153] The above description is merely a specific implementation of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.

Claims

1. A data exchange management platform, characterized in that, include: The system comprises an operations center, a data exchange engine, and a data exchange information system, wherein the data exchange information system communicates with the operations center through the data exchange engine; the data exchange information system includes an initial information system for successful joining of the data exchange management platform. The data exchange engine is used to forward the first joining application sent by the initial information system to the operation center, where the operation center reviews the first joining application. The data exchange engine is also used to forward the review result of the operation center on the first joining application to the corresponding initial information system. If the review result is approved, the initial information system successfully joins the data exchange management platform. The data exchange information system includes dual identities of data applicant and data provider. The data exchange engine is also used to forward the exchange application of the data applicant's data exchange information system to the data provider's data exchange information system, and to forward the target exchange data fed back by the data provider's data exchange information system to the data applicant's data exchange information system.

2. The data exchange management platform according to claim 1, characterized in that, Also includes: The authentication authority and the timestamp authority are respectively connected to the data exchange engine. The authentication authority is used to provide authentication services, and the timestamp authority is used to provide timestamp services. The data exchange engine is also used to authenticate the data exchange information system of the data applicant through the certification authority. If the authentication is successful, the engine adds a timestamp to the exchange application through the timestamp authority and adds the signature information of the data exchange engine. The exchange application with the added timestamp and signature information is then forwarded to the data exchange information system of the data provider. The data exchange engine is also used to authenticate the data provider's data exchange information system through the certification authority. If the authentication is successful, the engine adds a timestamp to the target exchange data through the timestamp authority and adds the signature information of the data exchange engine. The target exchange data with the added timestamp and signature information is then forwarded to the data applicant's data exchange information system.

3. The data exchange management platform according to claim 2, characterized in that, Before forwarding the first join request sent by the data exchange information system to the operation center, the data exchange engine is further configured to, upon receiving the first connection request sent by the data exchange information system, authenticate the data exchange information system, and, if the authentication is successful, return the first identity information of the data exchange engine to the data exchange information system. The data exchange information system then authenticates the data exchange engine, and, if the authentication is successful, sends the first join request to the data exchange engine. The first connection request is generated by the data exchange information system in response to a user's first operation. The operation center includes a participant management unit, which is used to verify the legality of the first joining application. If the first joining application is legal, the participant management unit submits the first joining application for approval. After the approval process is completed, the review result of the first joining application is sent to the data exchange engine, which then forwards the review result of the first joining application to the corresponding data exchange information system.

4. The data exchange management platform according to claim 3, characterized in that, The operations center also includes an engine management unit; The engine management unit is used to receive the second connection request sent by the data exchange engine, authenticate the data exchange engine, and if the authentication is successful, feed back the second identity information of the operation center to the data exchange engine. The data exchange engine then authenticates the operation center and, if the authentication is successful, sends a second join request to the operation center. The engine management unit is also used to verify the legality of the second joining application. If the second joining application is legal, the second joining application is submitted for approval, and after the approval process is completed, the approval result is fed back to the data exchange engine.

5. The data exchange management platform according to claim 4, characterized in that, The operation center also includes a rule configuration unit, a certification authority configuration unit, and a timestamp authority configuration unit; The rule configuration unit is used to configure the first rule for data exchange between the data exchange engine and the data exchange information system, configure the second rule for the data exchange engine to join and leave the data exchange management platform, and configure the third rule for the data exchange information system to join and leave the data exchange management platform. The certification authority configuration unit is used to configure the certification authorities that are allowed to be used in the data exchange management platform; The timestamp organization configuration unit is used to configure the timestamp organizations that are allowed to be used in the data exchange management platform; The operation center is also used to respond to the synchronization request sent by the data exchange engine, and feed back the target information to the data exchange engine for synchronization and updating. The target information includes the first rule, the second rule, the third rule, the certification authority configuration information, and the timestamp authority configuration information updated since the last synchronization request.

6. The data exchange management platform according to any one of claims 1-5, characterized in that, The operation center includes at least one operation device; when the number of operation devices is greater than or equal to two, the functional units and unit configurations of all operation devices are identical.

7. The data exchange management platform according to claim 6, characterized in that, The data exchange management platform includes a first data exchange management platform and a second data exchange management platform. The operation centers of the first data exchange management platform and the second data exchange platform are connected in a federated mode. The two operation centers negotiate data exchange rules. The data exchange information system of the first data exchange management platform and the data exchange information system of the second data exchange management platform exchange data through corresponding data exchange engines.

8. The data exchange management platform according to claim 1, characterized in that, The data exchange management platform includes at least two data exchange engines, and any two data exchange engines can communicate with each other.

9. The data exchange management platform according to claim 8, characterized in that, The data exchange engine includes at least one engine device; when the number of engine devices is greater than or equal to two, the functional units and unit configurations of all engine devices located in the same data exchange engine are identical.

10. The data exchange management platform according to claim 2, characterized in that, The data exchange information system includes a resource publishing unit and a resource retrieval unit; The resource publishing unit is used to send a publishing request to the data exchange engine in response to the user's second operation; The data exchange engine authenticates the data exchange information system through the certification authority. If the authentication is successful, the data exchange engine adds its signature information to the publishing request and adds a timestamp to the publishing request through the timestamp authority. The publishing request with added timestamp and signature information is then forwarded to the operation center, which authenticates the data exchange engine through the certification authority and publishes the received resources if the authentication is successful. The resource retrieval unit is used to respond to a third user operation by sending a retrieval request to the data exchange engine; The data exchange engine authenticates the data exchange information system through the certification authority. If the authentication is successful, the data exchange engine adds its signature information to the search request and adds a timestamp to the search request through the timestamp authority. The search request with added timestamp and signature information is then forwarded to the operation center. The operation center authenticates the data exchange engine through the certification authority. If the authentication is successful, the search results are fed back to the data exchange engine, which then forwards the search results to the corresponding data exchange information system.

11. A data exchange method, characterized in that, A data exchange engine is applied in a data exchange management platform, which also includes an operations center and a data exchange information system. The data exchange information system communicates with the operations center through the data exchange engine. The data exchange information system includes an initial information system for successful users joining the data exchange management platform, and the data exchange information system includes dual identities of data requester and data provider. The method includes: The system receives a first joining application sent by the initial information system and forwards the first joining application to the operation center, whereby the operation center reviews the first joining application. The operation center forwards the review result of the first application to the corresponding initial information system; if the review result is approved, the initial information system successfully joins the data exchange management platform. Receive the exchange request sent by the data exchange information system of the data requester, and forward the exchange request to the data exchange information system of the data provider; Receive the target exchange data fed back from the data exchange information system of the data provider, and forward the target exchange data to the data exchange information system of the data requester.