Satellite data right confirmation and data tracing method and related equipment
By generating and embedding multi-dimensional ownership tags, and combining consortium blockchains and private blockchains to store traceability information, the immaturity of the satellite data ownership confirmation and traceability system has been solved, achieving efficient ownership confirmation and traceability of satellite data and improving the reliability of data market circulation and security management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHAANXI SILK ROAD TIANTU SATELLITE TECH CO LTD
- Filing Date
- 2025-12-08
- Publication Date
- 2026-05-08
AI Technical Summary
The existing satellite data ownership confirmation and traceability technology system is not yet mature and cannot meet the needs of market-oriented circulation and security management. It has problems such as inaccurate ownership confirmation, unreliable traceability, and poor coordination.
Multi-dimensional ownership tags are generated and embedded in satellite data. By combining consortium blockchains and private blockchains to store traceability information, key information is synchronized through cross-chain protocols to achieve efficient ownership confirmation and traceability of satellite data.
It improves the accuracy and reliability of satellite data ownership confirmation, solves the problems of single point of failure and low efficiency of blockchain, realizes efficient storage and tamper-proof traceability records, and improves query efficiency and data transparency.
Smart Images

Figure CN121998654A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of satellite remote sensing technology, and in particular to a method and related equipment for satellite data ownership confirmation and data traceability. Background Technology
[0002] Satellite data has a wide range of applications. With the development of high-resolution satellite technology, the amount of data generated by a single remote sensing satellite can reach tens of TB per day, and the frequency and scope of data circulation continue to expand. However, the existing satellite data ownership and traceability technology system is not yet mature and cannot meet the needs of market circulation and security management.
[0003] Currently, satellite data ownership confirmation primarily relies on a combination of legal contracts and simple technical identifiers. The legal contract-dominated model defines data ownership through electronic or written agreements, but it depends entirely on external legal oversight and cannot technically prevent unauthorized copying or resale of data. Data watermarking technology uses discrete wavelet transform or discrete cosine transform to embed ownership identifiers, but suffers from an imbalance between robustness and concealment. Metadata annotation technology adds ownership fields to metadata files attached to the data, but metadata and the data ontology are independent and easily tampered with. Regarding data traceability, there are single points of failure risks and data credibility issues. Blockchain traceability technology stores traceability information on the Ethereum consortium blockchain, but it suffers from low processing efficiency and privacy risks.
[0004] These existing technologies have significant drawbacks. Specifically, legal contract-based rights protection requires incurring high evidentiary costs; for example, in 2023, a surveying institute failed to protect its rights due to missing data transfer records. Data watermarking technology, when embedded too strongly, can cause image pixel deviations exceeding 0.5%, impacting precision-sensitive applications; with reduced strength, the watermark extraction success rate drops below 70% when data compression exceeds 20% or is subject to noise interference. Metadata annotation technology lacks an effective verification mechanism; in 2022, a satellite data trading platform saw multiple cases of malicious tampering with metadata ownership. In centralized database systems, when data volume exceeds 100TB, traceability query response time increases from 0.5 seconds to 8 seconds, and in 2021, a ground station lost 72 hours of traceability data due to hardware failure. When blockchain traceability technology uses the traditional PBFT consensus mechanism, each traceability record takes 5-8 seconds to be uploaded to the chain, unable to handle the high-frequency data operations of over 100,000 per day for a single satellite; furthermore, publicly stored data on the chain may leak sensitive information.
[0005] In summary, existing technologies have systemic defects in dimensions such as the accuracy of rights confirmation, the reliability of traceability, collaboration, and the balance between security and efficiency, which seriously restrict the compliant circulation and value release of satellite data. A new technical solution is urgently needed to solve these problems. Summary of the Invention
[0006] The technical problem to be solved by this invention is to address the shortcomings of existing technologies, specifically by providing a method and related equipment for satellite data ownership confirmation and data traceability, as detailed below: 1) In a first aspect, the present invention provides a method for satellite data ownership confirmation and data traceability, the specific technical solution of which is as follows: A multi-dimensional ownership tag is generated for satellite data. This tag includes at least ownership layer information and is embedded into the satellite data. The ownership layer information includes information about the owner. During operations on the satellite data with embedded multi-dimensional ownership tags, a traceability record is generated. Lightweight traceability information in the traceability record is stored on a consortium blockchain, while detailed traceability information is stored on a private blockchain. Key information corresponding to the detailed traceability information is synchronized to the consortium blockchain via a cross-chain protocol. Based on the traceability record, the ownership layer information in the multi-dimensional ownership tag is updated. In response to a traceability query request, a full-process traceability map of the satellite data is generated and output by querying the lightweight traceability information stored on the consortium blockchain and the detailed traceability information stored on the private blockchain.
[0007] The beneficial effects of the satellite data ownership confirmation and data traceability method provided by this invention are as follows: By generating multi-dimensional ownership tags containing ownership layer information and embedding them into satellite data, the accuracy and reliability of ownership confirmation are effectively improved. The ownership layer information clearly includes the ownership subject information, ensuring clear definition of rights boundaries and avoiding the difficulties in rights protection caused by reliance on external supervision in traditional legal contract models. When operating on satellite data embedded with multi-dimensional ownership tags, traceability records are generated, and lightweight traceability information is stored in the consortium blockchain, while detailed traceability information is stored in the private blockchain. Key information is synchronized through cross-chain protocols, solving the problems of single point of failure in centralized databases and low efficiency of blockchain, achieving efficient storage and immutability of traceability records. The ownership layer information in the multi-dimensional ownership tags is automatically updated based on the traceability records, ensuring real-time synchronization of ownership status and data flow, eliminating errors from human intervention. When responding to traceability query requests, a full-process traceability map is quickly generated by querying the lightweight traceability information in the consortium blockchain and the detailed traceability information in the private blockchain, significantly improving query efficiency and data transparency. Overall, the solution overcomes the shortcomings of existing technologies, such as imprecise rights confirmation, delayed traceability, high security risks, and poor coordination, providing reliable support for the market-oriented circulation and secure management of satellite data.
[0008] 2) Secondly, the present invention also provides a satellite data ownership confirmation and data traceability system, the specific technical solution of which includes a tag generation and embedding module, a storage module, an update module, and a traceability module; the tag generation and embedding module is used to generate multi-dimensional ownership tags for satellite data, the multi-dimensional ownership tags including at least ownership layer information, and embed the multi-dimensional ownership tags into the satellite data, the ownership layer information including information of the ownership subject; the storage module is used to generate traceability records during the operation of satellite data with embedded multi-dimensional ownership tags, store lightweight traceability information in the traceability records to the consortium blockchain, and store detailed traceability information in the traceability records to the private blockchain, wherein, through a cross-chain protocol, the key information corresponding to the detailed traceability information is synchronized to the consortium blockchain; the update module is used to update the ownership layer information in the multi-dimensional ownership tags based on the traceability records; the traceability module is used to respond to traceability query requests, generate and output a full-process traceability map of satellite data by querying the lightweight traceability information stored in the consortium blockchain and the detailed traceability information stored in the private blockchain.
[0009] 3) In a third aspect, the present invention also provides an electronic device, the electronic device including a processor coupled to a memory, the memory storing at least one computer program, the at least one computer program being loaded and executed by the processor, so that the electronic device implements any of the above-mentioned satellite data ownership confirmation and data traceability methods.
[0010] 4) In a fourth aspect, the present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements any of the above-mentioned satellite data ownership confirmation and data traceability methods.
[0011] It should be noted that the beneficial effects of the technical solutions of the second to fourth aspects of the present invention and their corresponding possible implementations can be found in the above description of the technical effects of the first aspect and its corresponding possible implementations, and will not be repeated here. Attached Figure Description
[0012] Figure 1 This is a flowchart illustrating a satellite data ownership confirmation and data traceability method according to an embodiment of the present invention; Figure 2 This is one of the structural schematic diagrams of a satellite data ownership confirmation and data traceability system according to an embodiment of the present invention; Figure 3 This is a second schematic diagram of the structure of a satellite data ownership confirmation and data traceability system according to an embodiment of the present invention; Figure 4 A schematic diagram illustrating the multi-dimensional ownership tag structure and its embedding; Figure 5 A timeline diagram illustrating the hybrid traceability process of consortium blockchain and private blockchain; Figure 6 This is a schematic diagram illustrating a visual representation of a source tracing and tracking system. Detailed Implementation
[0013] like Figure 1 As shown, an embodiment of the present invention provides a method for satellite data ownership confirmation and data traceability, comprising the following steps: S1. Generate multi-dimensional ownership labels for satellite data. These labels must include at least ownership layer information. The multi-dimensional ownership labels are then embedded into the satellite data. The ownership layer information includes details of the ownership entity. The specific implementation process is as follows: S10. Generate multi-dimensional ownership label content at each level. For the base layer, automatically collect metadata of satellite data, including satellite identifier, orbital parameters, receiving station identifier, reception time, data type, and data resolution. The satellite identifier is a string representing a unique satellite number. Orbital parameters include longitude, latitude, and altitude, accurate to 0.1 degrees, used to describe the satellite's position at the time of data acquisition. The receiving station identifier is a string identifying the ground station receiving the data. The reception time is a timestamp recording the moment the data was received with millisecond precision. The data type is an enumerated value, such as remote sensing or communication. The data resolution is a floating-point number representing the spatial or temporal resolution of the data. For the ownership layer, extract rights information from the rights management database, including the owner's identifier, the user's identifier, the start and end timestamps of the rights term, a description of the rights scope, and the revenue distribution ratio. The rights management database stores authorization records and contract terms for satellite data, which can be queried and updated in real time via an API interface. For the security layer, calculate the combined hash value of the ownership layer information and the base layer information, and digitally sign it using the owner's private key. The hash value is generated using the SHA-256 algorithm and is a 256-bit binary sequence. The digital signature is generated using RSA or elliptic curve cryptography to ensure the integrity and authenticity of the tag. The data security level identifier is an enumerated value, such as public, secret, or confidential, set according to the data security policy.
[0014] S11. Embed the generated multi-dimensional ownership labels into the satellite data. For remote sensing image data, an adaptive wavelet domain hierarchical embedding algorithm is used. This algorithm first performs a discrete wavelet transform on the satellite data, decomposing the data into low-frequency, mid-frequency, and high-frequency coefficients. Low-frequency coefficients correspond to the approximate part of the data and have little impact on data accuracy. Mid-frequency coefficients correspond to the detailed part of the data and are used for redundancy backup. The embedding process is performed in the low-frequency coefficient region, embedding label information by modifying the coefficient values. The modification range is controlled within the range that the data accuracy deviation does not exceed 0.1%. The specific embedding formula is: ,in, These are the original wavelet coefficients. These are the modified wavelet coefficients. It is an adaptive embedding strength factor that dynamically adjusts based on data characteristics. It is the binary representation of multi-dimensional ownership labels. Embedded strength factor. The calculation is based on local variance of the data and a model of the human visual system, ensuring that the embedding process is invisible. Simultaneously, redundancy is performed in the mid-frequency coefficient region, with the tag information copied three times and embedded in different sub-bands. This redundancy improves the robustness of the tags, allowing for successful extraction even under data compression or noise interference. For communication satellite data, the embedding process is performed in a fixed field reserved in the data frame header. An 8-byte field is reserved in the data frame header to store the hash digest of the multi-dimensional ownership tags. The hash digest is calculated using the SM3 algorithm and is a 256-bit compressed value. The embedding formula is: ,in, It is the raw frame header data. It is the modified frame header data. This represents the XOR operation. It is a binary representation of the tag hash digest. This embedding method has an impact of no more than 0.01% on the data transmission rate, ensuring communication efficiency.
[0015] S12. After embedding, the satellite data is reconstructed and verified. For remote sensing image data, an inverse discrete wavelet transform is performed to convert the modified wavelet coefficients back to the spatial domain, generating data with embedded labels. Then, the peak signal-to-noise ratio (PSNR) and structural similarity index of the embedded data are calculated to ensure that the data quality meets application requirements. The PSNR formula is: ,in, This is the maximum possible value of the data; for an 8-bit image, it is 255. It is the mean squared error, which calculates the difference between the original data and the embedded data. The formula for the structural similarity index is: ,in, and It is the mean of the original data and the embedded data. and It is the standard deviation. It is covariance. and It is a constant. A peak signal-to-noise ratio of at least 40 dB and a structural similarity index of at least 0.98 are required to ensure data availability. For communication satellite data, verify transmission rate variations to ensure rate loss is within acceptable limits.
[0016] The ownership layer information is a specific level within the multi-dimensional ownership label used to describe the rights status of satellite data. It employs an extensible field design, containing multiple fields to support multi-dimensional rights definition. These fields include the ownership entity identifier, the right-to-use entity identifier, the start and end timestamps of the right term, a description of the scope of rights, and a revenue distribution ratio. The ownership entity identifier is a unique string used to identify the entity that owns the satellite data. The right-to-use entity identifier is also a unique string used to identify the entity currently authorized to use the satellite data. The start and end timestamps of the right term are 64-bit integers, representing the effective time range of the rights, recorded with millisecond precision. The scope of rights description is an enumeration type or string defining the data's usage scenarios and limitations, such as commercial or non-commercial use. The revenue distribution ratio is a floating-point number representing the proportion of data revenue distributed among the parties. The ownership layer information is generated by automatically populating fields by parsing the data source contract or licensing agreement, ensuring consistency between the rights information and legal agreements.
[0017] The ownership entity information is a data field within the ownership layer used to identify the owner of the satellite data. This information is stored as an ownership entity identifier, a globally unique string, such as a UUID or organization code. The ownership entity information originates from the ownership registration system during the satellite data production or procurement process, and its validity is verified through interface calls. Within the ownership layer, the ownership entity information is associated with other fields, such as the ownership entity identifier and the term of rights, to form a complete description of the rights. The ownership entity information is encrypted during tag generation to prevent unauthorized access or tampering.
[0018] S2. During the operation of satellite data embedded with multi-dimensional ownership tags, a traceability record is generated. The lightweight traceability information in the traceability record is stored in the consortium blockchain, and the detailed traceability information in the traceability record is stored in the private blockchain. Among them, the key information corresponding to the detailed traceability information is synchronized to the consortium blockchain through a cross-chain protocol. The specific implementation process is as follows: S20. When an operation on satellite data embedded with multi-dimensional ownership tags is detected to have begun, the operation management module captures the operation event. The operation event includes the operation type, operation node identifier, and operation timestamp. The multi-dimensional ownership tags are extracted from the satellite data file header, and the ownership layer information is parsed to verify the current operation permissions. The verification process involves checking the validity of the user rights subject identifier and the rights period. If verification fails, the operation is terminated and an exception event is recorded. If verification succeeds, an empty traceability record structure is initialized, ready to be filled with lightweight traceability information and detailed traceability information.
[0019] S21. Lightweight traceability information is generated by processing operation metadata through a compression algorithm. The tag hash in the lightweight traceability information is directly derived from the security layer hash value of the multi-dimensional ownership tag. The operation type is copied from the operation event. The node identifier uses the digital certificate of the current operation node. The operation timestamp is obtained from the system clock and formatted as a Unix timestamp. The result hash is calculated after the operation is completed, using the following formula: ,in, Indicates the result hash. This indicates a hash function such as SHA-256. This represents the satellite data after the operation. Detailed source information is generated by collecting operation details through a logging module. Preprocessing algorithm parameters in the detailed source information are stored as key-value pairs, such as algorithm name and version number. The analysis log contains intermediate variables and error codes during data processing. A complete operation log includes operator input commands and system response time. Detailed source information is serialized in JSON-LD format to ensure structure and scalability.
[0020] S22. Lightweight traceability information is stored on the consortium blockchain. Specifically, the consortium blockchain application programming interface (API) is invoked to construct a transaction object containing lightweight traceability information. The transaction object is digitally signed using the private key of the operating node. After receiving the transaction object, the consortium blockchain node initiates a dynamic PBFT consensus mechanism. The dynamic PBFT consensus mechanism adjusts the number of consensus nodes according to the operation type; for high-frequency operations such as data distribution, the number of consensus nodes is set to 5; for critical operations such as ownership changes, the number of consensus nodes is set to 10. The consensus process involves multiple rounds of message exchange between nodes. After reaching a consensus, the lightweight traceability information is written into the consortium blockchain block. Block generation time is optimized through batch processing, packaging multiple records of the same type of operation into one block.
[0021] S23. Store detailed traceability information on the private blockchain. Specifically, the detailed traceability information is transmitted to the private blockchain nodes, where smart contracts verify the data format. The smart contracts check the integrity and consistency of the detailed traceability information, ensuring that necessary fields such as operation records and algorithm parameters exist. After successful verification, the detailed traceability information is stored in the private blockchain's distributed database. The private blockchain uses a Merkle tree structure to organize the data, providing fast querying and data integrity proof. The private blockchain storage process is independent of the consortium blockchain and does not affect the main business process.
[0022] S24. Key information corresponding to the detailed traceability information is synchronized to the consortium blockchain via a cross-chain protocol. The cross-chain protocol listens for new detailed traceability information events on the private blockchain. Once the detailed traceability information is stored, the cross-chain protocol triggers key information extraction. Key information extraction uses a mapping function to select specific fields from the detailed traceability information, such as the operation result hash and state change identifier. The extracted key information is encapsulated into a cross-chain transaction, which includes the source private blockchain identifier and the target consortium blockchain address. The cross-chain protocol uses relay chain technology to forward the transaction, and the relay chain verifies the transaction signature and hash value. After receiving the cross-chain transaction, the consortium blockchain associates the key information with the existing lightweight traceability information and updates the traceability record status. The synchronization process ensures data consistency and real-time performance, supporting subsequent traceability queries.
[0023] The operations performed on satellite data embedded with multi-dimensional ownership tags refer to a series of processing actions executed throughout the satellite data lifecycle. These operations include data preprocessing, data analysis, data distribution, and data usage. Data preprocessing involves the application of algorithms such as radiometric and geometric correction. Data analysis includes feature extraction and classification. Data distribution refers to the process of transmitting data to authorized users. Data usage covers application scenarios such as data querying and visualization. Each operation step triggers the generation of a traceability record to ensure that the data flow process is fully recorded.
[0024] The lightweight traceability information consists of compressed and simplified data from the traceability record. It includes fields such as tag hash, operation type, node identifier, operation timestamp, and result hash. The tag hash is the hash value of a multi-dimensional ownership tag calculated using the SHA-256 algorithm. The operation type is a string describing the nature of the operation, such as preprocessing or distribution. The node identifier is a unique identifier for the entity performing the operation. The operation timestamp is a 64-bit integer recording the time the operation occurred. The result hash is a hash digest of the data state after the operation. The lightweight traceability information is designed so that each record is no larger than 1KB to improve storage and query efficiency.
[0025] A consortium blockchain is a distributed ledger technology jointly maintained by multiple organizations. It consists of nodes such as satellite operators, receiving stations, regulatory agencies, and core data processors. The consortium blockchain uses a dynamic PBFT consensus mechanism to verify the validity of transactions. This dynamic PBFT consensus mechanism adjusts the number of nodes participating in the consensus based on the type of operation. The consortium blockchain stores lightweight traceability information and provides an immutable audit trail. It supports efficient querying and real-time monitoring of the data flow process.
[0026] The detailed traceability information consists of data within the traceability record that contains complete operational details. This detailed traceability information includes preprocessing algorithm parameters, analysis logs, complete operation records, and error reports. Preprocessing algorithm parameters describe the specific methods and versions used for data correction. Analysis logs record intermediate results and status changes during data processing. The complete operation record stores metadata such as operator identifiers and operation duration. Detailed traceability information is typically stored in JSON or XML format, with a single record reaching 10KB or more in size.
[0027] Private blockchains are distributed ledger technologies maintained independently by a single organization. They are deployed within data processing centers or application institutions. Private blockchains store detailed traceability information and provide fine-grained data management. They ensure data privacy by restricting access through access control. Private blockchains synchronize data with consortium blockchains via cross-chain protocols. They support high-frequency operation record storage and fast retrieval.
[0028] Cross-chain protocols are technical specifications for enabling data exchange between consortium blockchains and private blockchains. They define data synchronization rules and verification logic based on smart contracts. Cross-chain protocols ensure the accurate transmission of key information corresponding to detailed traceability information to the consortium blockchain. They employ digital signatures and hash verification to guarantee the security of data transmission. Cross-chain protocols handle tasks such as data format conversion and error recovery.
[0029] The key information corresponding to the detailed source information is the summary data extracted from it for synchronization. This key information includes operation result hashes and state change identifiers. The operation result hash is the hash value of the data after the operation, calculated using the SM3 algorithm. The state change identifier records the update status of the ownership layer information. This key information acts as a bridge connecting the detailed source information and the lightweight source information.
[0030] The consortium blockchain employs a dynamic PBFT consensus mechanism to achieve consensus on the on-chain operations of lightweight traceability information and key information synchronized from the private blockchain. The specific implementation process is as follows: 1) Identify operation types and determine node configuration for the dynamic PBFT consensus mechanism. When a consortium blockchain node receives a request to upload lightweight traceability information or critical information synchronized from a private blockchain, it first parses the operation type field. The operation type field comes from the operation type description in the lightweight traceability information or the operation category identifier in the critical information synchronized from the private blockchain. The operation type is matched to the number of consensus nodes according to predefined rules; for high-frequency operations such as data distribution, the number of consensus nodes is set to five; for critical operations such as ownership changes or raw data reception, the number of consensus nodes is set to ten. Node configuration information is stored in the consortium blockchain's configuration file and dynamically loaded through smart contracts. This identification process ensures that consensus resource allocation matches the importance of the operation, improving overall efficiency.
[0031] 2) Initialize the consensus process and broadcast transaction data. The consortium blockchain's master node encapsulates lightweight traceability information or key information synchronized from the private blockchain into transaction objects. These transaction objects contain metadata such as sequence numbers, timestamps, and digital signatures. The master node broadcasts the transaction objects to all participating nodes, using digital signatures to verify identity. The broadcast protocol employs peer-to-peer network communication to ensure reliable message transmission. The initialization phase also includes setting consensus timeout parameters, such as a two-second timeout for high-frequency operations and a five-second timeout for critical operations. These timeout parameters prevent the consensus process from waiting indefinitely, enhancing responsiveness.
[0032] 3) Message exchange phase of the dynamic PBFT consensus mechanism. Message exchange is divided into the request phase, pre-preparation phase, preparation phase, and commit phase. In the request phase, the client or private chain node initiates a request for on-chain operation, and the master node receives the request and assigns a sequence number. The sequence number ensures the consistency of transaction order. In the pre-preparation phase, the master node creates a pre-preparation message and broadcasts it to all replica nodes. The pre-preparation message contains the transaction object and sequence number. Replica nodes verify the legality and digital signature of the pre-preparation message. In the preparation phase, each replica node broadcasts a preparation message to other nodes, indicating the node's approval of the pre-preparation message. The broadcast of the preparation message uses the gossip protocol for propagation. In the commit phase, after a node collects a sufficient number of preparation messages, it broadcasts a commit message to confirm that the transaction can be committed. Message exchange uses a formula to verify consistency: ,in, Indicates the message content, This indicates a digital signature function using a private key. This represents the hash value of the message. A node must receive more than two-thirds of the same messages to proceed to the next phase. The dynamic PBFT consensus mechanism adjusts the message threshold based on the number of nodes; for five nodes, the threshold is four; for ten nodes, the threshold is seven.
[0033] 4) Verify transaction data and reach consensus. Nodes participating in the consensus process verify the lightweight traceability information or key information synchronized from the private chain. Verification includes checking the integrity of the tag hash, the validity of the operation timestamp, the authorization status of the node identifier, and the matching of the result hash. For key information synchronized from the private chain, the digital signature of the cross-chain protocol and the consistency of the hash chain are additionally verified. The verification process uses hash functions to compare data integrity. ,in, This represents the hash value currently being calculated. This refers to the SHA-256 hash algorithm. This represents input data such as lightweight traceability information or key information. If all verifications pass, nodes vote in favor of uploading the transaction to the blockchain; otherwise, they vote against. Consensus is reached when more than a threshold of votes are received, and the transaction is marked as valid.
[0034] 5) Complete the on-chain operation and update the blockchain state. Once consensus is reached, the masternode writes lightweight traceability information or key information synchronized from the private chain into a new block. The new block contains a block header, a transaction list, and a hash pointer to the previous block. The block header includes a version number, a timestamp, and a Merkle root. The Merkle root is calculated using a Merkle tree: ,in, This represents the list of transactions in a block. This represents the Merkle tree hash function. The new block is distributed to all consortium blockchain nodes, and each node updates its local ledger. After the on-chain operation is complete, the consortium blockchain returns a success response to the client or private blockchain node, recording a consensus log for auditing and monitoring.
[0035] The Dynamic PBFT consensus mechanism is an improved Practical Byzantine Fault Tolerance (PBFT) algorithm that dynamically adjusts the number of nodes participating in the consensus process based on the operation type. The Dynamic PBFT consensus mechanism automatically selects the number of consensus nodes through predefined rules to balance efficiency and security. For high-frequency operations such as data distribution, the number of participating nodes is reduced to five to shorten consensus time. For critical operations such as ownership changes or raw data reception, the number of participating nodes is increased to ten to enhance security. The Dynamic PBFT consensus mechanism employs a multi-phase messaging protocol, including a request phase, a pre-preparation phase, a preparation phase, and a commit phase, ensuring that all honest nodes agree on the transaction order and content. The Dynamic PBFT consensus mechanism also supports batch processing, packaging multiple operation records into a single block to improve throughput.
[0036] Consensus refers to the process by which multiple nodes in a distributed system reach an agreement on a certain piece of data or state. The consensus process ensures, through protocols and algorithms, that all participating nodes maintain a consistent view even in the event of failures or malicious activity. In a consortium blockchain environment, consensus verifies and confirms the on-chain operations of lightweight traceability information and critical information synchronized from a private blockchain. The consensus process involves the exchange of messages and voting between nodes to decide whether to add transaction records to the blockchain. The goal of consensus is to guarantee the immutability, consistency, and availability of data, preventing single points of failure or malicious attacks.
[0037] S3. Based on the source tracing record, update the ownership layer information in the multi-dimensional ownership tag. The specific implementation process is as follows: S30. Monitor and identify the types of traceability records that trigger updates to ownership layer information. Continuously monitor newly added lightweight traceability information on the consortium blockchain and detailed traceability information stored in the private blockchain, capturing specific types of operation records through event listeners. The types of traceability records that trigger updates include data distribution operation records, right-of-use change operation records, right-of-use expiration operation records, and revenue distribution adjustment operation records. Data distribution operation records are generated when data is transmitted from the processing center to the end user and contain new right-of-use entity identifier information. Right-of-use change operation records are generated when the right-of-use entity changes, such as from an agricultural monitoring agency to a meteorological research agency. Right-of-use expiration operation records are automatically generated by a system timer when the right-of-use end timestamp arrives. Revenue distribution adjustment operation records are created after the satellite data transaction contract is revised. By parsing the operation type field and node identifier field in the traceability record, determine whether the ownership layer information update process needs to be initiated.
[0038] S31. After identifying a traceability record that needs updating, initiate the authorization verification process. The verification process includes checking whether the node initiating the update has the corresponding permissions and confirming that the operation conforms to the scope of rights defined in the ownership layer information. Extract the current ownership entity identifier and usage right entity identifier from the ownership layer information of the multi-dimensional ownership tags and compare them with the operation node identifier in the traceability record. For updating the usage right entity identifier, the operation node must be the current ownership entity or a regulatory agency node with proxy authority. The verification process uses digital signature technology, requiring each update request to be signed with the operation node's private key. The validity of the digital signature is verified through public key infrastructure to ensure the legitimate origin of the update request. Only update requests that pass verification will continue to be processed; requests that fail verification will be logged in the exception log and the regulatory agency will be notified.
[0039] S32. Extract updated data and prepare the ownership layer information modification content. Extract the field data that needs to be updated from the verified traceability records. For data distribution operation records, extract the new right-of-use subject identifier field and right term field. For right term expiration operation records, extract the status change flag and set the right-of-use subject identifier to null. Construct an ownership layer information update object based on the extracted data. The update object adopts the same structure definition as the original ownership layer information. The update object contains a list of fields that need to be modified and their new values, while retaining fields that do not need to be modified. Record the metadata of the update operation, including the update timestamp, update node identifier, and corresponding traceability record hash value. The metadata is used for subsequent auditing and tracing the update history.
[0040] S33. Perform ownership layer information update operations and maintain data consistency. After preparing the update object, initiate a multi-stage update process. The first stage reads the current multi-dimensional ownership label from the satellite data file header and parses out the ownership layer information content. The second stage applies the update object to the ownership layer information to generate new ownership layer information. For updates using the right holder identifier, the original field values are directly replaced. For rights term updates, the right term start timestamp and right term end timestamp fields are updated simultaneously. The third stage recalculates the security layer information of the multi-dimensional ownership label, including calculating the hash value of the new label and generating a new digital signature. The hash calculation uses the SHA-256 algorithm, and the new digital signature is generated using the private key of the ownership holder to ensure the authenticity of the updated multi-dimensional ownership label.
[0041] S34. After successfully updating the multi-dimensional ownership tags, the updated tags are re-embedded into the satellite data file header, replacing the original tags. The embedding process uses the same technology as the initial embedding: an adaptive wavelet domain hierarchical embedding algorithm is used for remote sensing image data, and a frame header reserved field embedding method is used for communication satellite data. Ownership update records are submitted to the consortium blockchain, including a summary of ownership layer information before and after the update, the reason for the update, and the corresponding traceability record identifier. Simultaneously, all relevant nodes are notified to update their locally cached multi-dimensional ownership tag information to ensure data consistency. A complete update operation log is recorded, including the update start time, completion time, details of the field changes involved, and the operation status. The log information is stored in the private blockchain for subsequent querying and auditing.
[0042] S4. In response to the traceability query request, by querying the lightweight traceability information stored in the consortium blockchain and the detailed traceability information stored in the private blockchain, a full-process traceability map of the satellite data is generated and output. The specific implementation process is as follows: S40. Receive the source tracing query request through the application programming interface (API). First, check the completeness and standardization of the request format. The verification process includes confirming whether the data identifier conforms to the encoding rules, whether the query time range is within the retention period, and whether the request node identifier is registered in the authorized whitelist. Verify the digital signature of the source tracing query request using an asymmetric encryption algorithm to ensure the trustworthiness of the request source. The verification formula is: ,in, This indicates the verification function that uses the request node's public key. This indicates the signature function that uses the request node's private key. This represents the hash value of the source tracing query request. This indicates the content of the source tracing query request. Requests that fail verification will be rejected and logged in the security log. Requests that pass verification enter the permission check phase, where the access control list is queried based on the request node identifier to confirm that the node has the right to access the source tracing information of the target data.
[0043] S41. Based on the data identifier in the traceability query request, retrieve relevant lightweight traceability information in the consortium blockchain. The query process uses a three-level index structure: first, locate the corresponding tag hash set through the data identifier; then, find the relevant operation records through the tag hash; finally, arrange all lightweight traceability information in chronological order. The query statement uses a specific query language, including filtering conditions and sorting rules. Organize the retrieved lightweight traceability information chronologically to construct a basic traceability framework. The basic traceability framework includes key node information and main flow paths, forming the backbone structure of the full-process traceability map of satellite data. Each node contains core fields such as operation type, node identifier, and operation timestamp from the lightweight traceability information.
[0044] S42. Based on the node identifiers and operation timestamps in the basic traceability framework, initiate a detailed traceability information query request to the corresponding private chain. The query request includes operation record identifiers and authorization credentials, ensuring that only detailed traceability information within the authorized scope can be accessed. Query requests are sent to multiple private chain nodes in parallel to improve data acquisition efficiency. The detailed traceability information obtained from the private chain includes preprocessing algorithm parameters, analysis logs, and complete operation records. Associate the detailed traceability information with the corresponding nodes in the basic traceability framework, establishing a mapping relationship through the operation record identifiers. The associated traceability data contains complete technical details and business context, providing ample data support for generating a rich, full-process traceability map of satellite data.
[0045] S43. The lightweight traceability information from the consortium blockchain and the detailed traceability information from the private blockchain are fused. The fusion process aligns data based on two dimensions: time series and node relationships. Time series alignment ensures all operations are arranged in the correct chronological order, while node relationship alignment establishes a complete data flow path. A graph computing engine is used to construct the data model of the traceability graph. Node attributes include node type, node identifier, operation details, and ownership status; edge attributes include data transmission time, data volume, and transmission protocol. The graph generation algorithm uses force-directed layout to automatically calculate node positions, optimizing visualization effects. The generation process includes the following calculations: in, This represents a complete traceability map of satellite data. Represents a set of nodes. Denotes the set of edges. and Representing different nodes, Indicates data from node Transmit to node Timestamps are used. Redundancy elimination and conflict resolution are performed on the map data to ensure the consistency and accuracy of the information.
[0046] S44. Convert the generated full-process traceability map of satellite data into standardized data exchange formats, including structured formats such as JSON and XML. The level of detail in the output information is determined by the query depth level in the traceability query request. For basic-level queries, only key nodes and main flow paths are output; for complete-level queries, all technical details and the complete operation history are output. The full-process traceability map of satellite data is rendered into an interactive graphical interface using a visualization engine, supporting user zooming, panning, and node selection. Exporting the map data is also provided, supporting PNG image and PDF document formats. The output process records query logs, including query time, request node identifier, and returned data size, for subsequent auditing and performance optimization. Finally, a complete traceability query response is returned to the requesting node, containing the full-process traceability map of the satellite data and related metadata information.
[0047] A source tracing query request is a formal request initiated by a user or system to trace the historical flow of specific satellite data. A source tracing query request contains several necessary fields, including a data identifier, a query time range, a request node identifier, and a query depth level. The data identifier is a unique code for the satellite data, used to accurately locate the target data. The query time range defines the start and end times of the source tracing information. The request node identifier indicates the identity information of the query initiator. The query depth level defines the level of detail of the source tracing information required, divided into basic and complete levels. The source tracing query request uses a digital signature to ensure its authenticity and non-repudiation.
[0048] The satellite data end-to-end traceability map is a visual representation of the entire process of satellite data from generation to final use. It presents the data flow path in the form of nodes and edges. Nodes represent various entities in the data processing stages, including satellite receiving stations, data processing centers, and end users. Edges represent the transmission relationships between different nodes. The map labels the operation type, timestamp, and ownership status changes for each node. It supports interactive exploration and detailed drilling-in, providing a complete view of the data lifecycle.
[0049] Optionally, the above technical solution also includes: S020. Calculate the hash value of the multi-dimensional ownership tag, and digitally sign the hash value using the private key of the ownership entity. Upload the hash value and digital signature to the consortium blockchain. The specific implementation process is as follows: S0200. Prepare complete data content for multi-dimensional ownership tags for hash calculation. Read the three levels of data of the generated multi-dimensional ownership tags from memory or persistent storage, including non-hash fields from the basic layer information, ownership layer information, and security layer information. The basic layer information contains the raw values of fields such as satellite identifier, orbital parameters, receiving station identifier, receiving time, data type, and data resolution. The ownership layer information contains the complete content of fields such as ownership entity identifier, usage right entity identifier, right term start timestamp, right term end timestamp, right scope description, and revenue distribution ratio. Other fields in the security layer information besides hash value and digital signature, such as data security level identifier, also participate in hash calculation. Convert this data into a byte sequence according to predefined serialization rules to ensure that the data order and format are completely consistent in each calculation, providing standardized input data for hash calculation.
[0050] S0201. The SHA-256 hash algorithm is used to perform one-way hash calculation on the serialized multi-dimensional ownership tag data. The hash calculation process converts input data of arbitrary length into a fixed-length 256-bit output value. The specific calculation process is as follows: ,in, This represents the hash value of the calculated multi-dimensional ownership label. This represents the SHA-256 hash algorithm function. This represents the serialized multi-dimensional ownership tag data. The hash value of the calculated multi-dimensional ownership tag is stored in the corresponding field of the security layer information, and is also retained in memory for subsequent digital signature use. The hash calculation process includes standard steps such as data padding, message chunking, loop processing, and compression functions, ensuring that even slight changes in the input data will produce completely different hash values, meeting cryptographic security requirements.
[0051] S0202. Digitally sign the hash value of the multi-dimensional ownership tag using the owner's private key. The owner's private key is obtained from a secure storage module; this private key is typically stored in a hardware security module or a protected keystore. The digital signature algorithm uses RSA-2048 or elliptic curve digital signature algorithms, generating the digital signature by encrypting the hash value of the multi-dimensional ownership tag. The digital signature generation process is represented as follows: ,in, This represents the generated digital signature. This indicates a signature function using the owner's private key. This represents the hash value of the multi-dimensional ownership label. The digital signature generation process includes cryptographic operations such as padding the hash value, modular exponentiation, or elliptic curve multiplication. The generated digital signature is stored in the security layer information of the multi-dimensional ownership label and associated with the hash value of the multi-dimensional ownership label.
[0052] S0203. Construct the upload data packet and prepare for transmission to the consortium blockchain. Create a structured data object containing the hash values of multi-dimensional ownership tags, digital signatures, and related metadata. Metadata includes auxiliary information such as timestamps, data identifiers, and ownership entity identifiers. The data object is encoded using serialization formats such as JSON or Protocol Buffers to ensure data integrity and parsing consistency during transmission. Perform an integrity check on the data object to verify the correct correspondence between the hash values of the multi-dimensional ownership tags and the digital signatures. The verification process uses the public key of the ownership entity to perform a preliminary verification of the digital signature, ensuring that the digital signature is valid and matches the hash values of the multi-dimensional ownership tags. The preliminary verification formula is: ,in, This indicates a verification function that uses the public key of the ownership entity. Indicates digital signature, The hash value representing the multi-dimensional ownership label.
[0053] S0204. Upload the hash value and digital signature of the multi-dimensional ownership tag to the consortium blockchain. Initiate a transaction request through the application programming interface of the consortium blockchain node. The transaction content includes the hash value of the multi-dimensional ownership tag, the digital signature, and related metadata. The transaction request is authenticated using the node's identity credentials to ensure the legitimacy of the upload operation. Wait for the consortium blockchain network to perform consensus verification on the transaction. The consensus process adopts a dynamic PBFT consensus mechanism to ensure that the transaction is confirmed by a majority of nodes in the network. After the transaction is confirmed, the consortium blockchain generates a transaction receipt, which includes information such as the transaction hash and block height. Record the transaction receipt information to establish a mapping relationship between the multi-dimensional ownership tag and the consortium blockchain storage record. The upload process also includes error handling and retry mechanisms to deal with abnormal situations such as network interruption or node failure, ensuring that the hash value and digital signature of the multi-dimensional ownership tag are reliably stored on the consortium blockchain.
[0054] In this context, the ownership entity refers to the entity or individual that legally owns the satellite data. The ownership entity possesses the highest level of authority within the satellite data management system, including key rights such as defining data usage rules, granting data usage rights, and distributing data revenue. The ownership entity's information is recorded in the ownership layer information of the multi-dimensional ownership tag and stored as the ownership entity identifier field. The ownership entity holds the private key in the asymmetric encryption key pair, used to digitally sign the multi-dimensional ownership tag, thereby confirming its ownership status. During the circulation of satellite data, the ownership entity's identity information needs to undergo rigorous verification, and its authenticity and legality are guaranteed through a digital certificate mechanism.
[0055] S021. Before operating on satellite data embedded with multi-dimensional ownership tags, extract the multi-dimensional ownership tags from the satellite data, calculate the hash value of the extracted multi-dimensional ownership tags, compare it with the hash value obtained from the consortium blockchain, and verify the digital signature of the satellite data embedded with the multi-dimensional ownership tags using the public key corresponding to the private key of the ownership entity, so as to verify the integrity and authenticity of the extracted multi-dimensional ownership tags. The specific implementation process is as follows: S0210. Extract multi-dimensional ownership labels from satellite data embedded with multi-dimensional ownership labels. Different extraction methods are used depending on the satellite data type. For remote sensing image data, a discrete wavelet transform is performed to decompose the image data into low-frequency, mid-frequency, and high-frequency coefficients. The main multi-dimensional ownership label information is extracted from the low-frequency coefficient region, and redundant backup multi-dimensional ownership label information is extracted from the mid-frequency coefficient region. The extraction process uses an inverse transform corresponding to the embedding algorithm to convert the wavelet coefficients into the original multi-dimensional ownership label data. For communication satellite data, the reserved fixed fields in the data frame header are directly parsed to read the stored multi-dimensional ownership label hash digest and related information. After extraction, the three levels of multi-dimensional ownership label data are completely reconstructed, including basic layer information, ownership layer information, and security layer information.
[0056] S0211. Calculate the hash value of the extracted multi-dimensional ownership tags. Standardize and serialize the extracted multi-dimensional ownership tag data to ensure the data order and format are completely consistent with the initial generation. The serialized data is used as input to the hash algorithm, and the SHA-256 hash function is used for calculation. The hash calculation process is represented as follows: ,in, This represents the hash value of the extracted multi-dimensional ownership tags obtained through calculation. This represents the SHA-256 hash algorithm function. This represents the multi-dimensional ownership tag data extracted and serialized from satellite data. The calculated hash value is temporarily stored in memory for subsequent comparison and verification operations.
[0057] S0212. Obtain the hash value of the original multi-dimensional ownership tag from the consortium blockchain. Through the consortium blockchain's query interface, retrieve the corresponding transaction records based on the data identifier and ownership entity identifier. The query process uses a multi-level index structure, first locating the block range corresponding to the data identifier, and then searching for transactions containing the target multi-dimensional ownership tag hash value within that block. Parse the hash value field of the multi-dimensional ownership tag from the transaction data and verify the existence and confirmation status of this hash value in the consortium blockchain. The acquisition process ensures the use of the latest consortium blockchain state data to avoid data inconsistencies caused by blockchain reorganization.
[0058] S0213. Compare the hash values of the extracted multi-dimensional ownership tags with the hash values obtained from the consortium blockchain. Calculate the hash values of the extracted multi-dimensional ownership tags... The hash value of the original multi-dimensional ownership tag obtained from the consortium blockchain A bit-by-bit comparison is performed. The comparison operation uses a constant-time comparison algorithm to prevent timing attacks from leaking the comparison results. The comparison results are categorized into three cases: complete match, no match, and partial match. In the case of a complete match, subsequent verification steps continue; in the case of a no match, the operation is immediately terminated and a security event is recorded; in the case of a partial match, an attempt is made to restore the multi-dimensional ownership tags from redundant backups and re-verify. The comparison formula is expressed as: ,in, This indicates a bitwise XOR operation. This indicates the comparison result; all zeros indicate a perfect match.
[0059] S0214. Verify the digital signature of satellite data embedded with multi-dimensional ownership tags using the public key corresponding to the private key of the ownership entity. Obtain the ownership entity's public key from the digital certificate; this public key is verified for validity and authenticity through a public key infrastructure. The verification process uses an asymmetric encryption algorithm to decrypt and compare the hash value of the extracted multi-dimensional ownership tag with the digital signature. The digital signature verification formula is expressed as: ,in, This indicates the verification result. This indicates a verification function that uses the public key of the ownership entity. This refers to a digital signature extracted from satellite data embedded with multi-dimensional ownership tags. This represents the hash value of the extracted multi-dimensional ownership tags. Successful verification confirms the integrity and authenticity of the multi-dimensional ownership tags, allowing subsequent operations to proceed. Failure to verify results in the operation request being rejected, a security alert being generated, and the event being logged in the audit log.
[0060] Optionally, in the above technical solution, sensitive information in the multi-dimensional ownership tags is desensitized and encrypted. The specific implementation process includes: 1) Identify sensitive information fields requiring protection in multi-dimensional ownership labels. Scan the three-tiered structure of the multi-dimensional ownership labels and classify sensitive information types according to predefined security policies. The orbital parameters in the basic layer information, including longitude, latitude, and altitude coordinates, are marked as location-sensitive information. The ownership entity identifier and usage right entity identifier in the ownership layer information are marked as identity-sensitive information, involving the identification of commercial entities or government agencies. The data security level identifier in the security layer information is itself marked as metadata-sensitive information. Establish a sensitive information field mapping table, recording the sensitivity level, data processing rules, and authorized access roles for each field. The identification process employs pattern matching and metadata analysis techniques to ensure comprehensive coverage of all sensitive information fields in the multi-dimensional ownership labels.
[0061] 2) For the latitude and longitude coordinates in the orbital parameters, partial masking is used to reduce data precision. The longitude value is reduced from the original precision of 0.1 degrees to 1 degree, and the latitude value is similarly reduced from 0.1 degrees to 1 degree. The masking process is implemented using a mathematical rounding function, expressed by the following formula: ,in, This represents the desensitized latitude and longitude values. Represents the original latitude and longitude values. This represents a rounding function that rounds the numerical value x to the nearest integer. For the ownership entity identifier and the usage entity identifier, the first three characters are retained for visibility, and the subsequent characters are replaced with an asterisk mask. The confidentiality level information in the data security classification identifier is converted into a general level description, such as converting the specific security classification number into a text description like "public," "secret," or "confidential." The anonymized data is retained in the original position of the multi-dimensional ownership tags, ensuring that the integrity of the tag structure is not affected.
[0062] 3) Encrypt the original sensitive information using an encryption algorithm. The AES-256 symmetric encryption algorithm is used to encrypt the complete sensitive information before de-identification. The encryption process requires generating a random initialization vector and obtaining an encryption key. The encryption key comes from the session key of the key management system, and each encryption operation uses independent key material. The encryption formula is expressed as: ,in, This represents the encrypted sensitive information. This represents the AES-256 encryption function. Indicates the session key. Represents the initialization vector. This represents the original plaintext sensitive information. The encryption process uses a cipher block chaining model to ensure that the same plaintext produces different ciphertexts in different contexts. The initialization vector is concatenated with the ciphertext and stored to provide necessary parameters for subsequent decryption operations.
[0063] 4) Securely store encrypted sensitive information and establish an access index. The encrypted sensitive information ciphertext, along with the initialization vector, is stored in a specific data area of the private blockchain. The storage process generates a unique data storage identifier, which is associated with a multi-dimensional ownership tag. In the lightweight traceability information of the consortium blockchain, an index pointer pointing to the encrypted data on the private blockchain is stored, in the format of a hash reference value. The index structure is represented as follows: ,in, The hash value representing the index pointer. This represents the encrypted sensitive information. Represents the timestamp of the encryption operation, symbol This indicates a data concatenation operation. Complete metadata information is recorded, including the encryption algorithm version, key identifier, and data storage location, ensuring accurate retrieval and decryption of data during subsequent authorized access.
[0064] 5) Implement fine-grained access control and decryption authorization mechanisms. Control access to encrypted sensitive information based on a role-based access control model. When an authorized user, such as a regulatory agency, needs to access complete sensitive information, the user's digital certificate and access permissions are verified. Upon successful verification, the encrypted data is retrieved from the private blockchain, and the corresponding decryption key is obtained from the key management system. The decryption process uses the same AES-256 algorithm, expressed by the formula: ,in, This indicates the original sensitive information that has been decrypted and recovered. This represents the AES-256 decryption function. All decryption access operations are recorded, including the requesting user's identity, access timestamp, and decrypted data range, forming a complete audit trail. For unauthorized users, only anonymized sensitive information is displayed, ensuring that sensitive data is not leaked. Sensitive information in multi-dimensional ownership tags is effectively protected while maintaining functional availability, meeting both data security requirements and supporting necessary authorized access scenarios.
[0065] This invention adopts a four-layer technical solution that combines source tag solidification, a hybrid consortium blockchain-private blockchain architecture, a collaborative mechanism, and security optimization. The specific details are as follows: 1) Source Multi-Dimensional Ownership Tagging Technology: The tag structure design adopts a three-layer architecture: a basic layer, an ownership layer, and a security layer. It is bound to the satellite data ontology and embedded in the data file header, rather than being a separate file. The basic layer includes satellite identifiers, orbital parameters including longitude, latitude, and altitude with an accuracy of 0.1 degrees, receiver station identifiers, reception time accurate to milliseconds, data types including remote sensing and communication, and data resolution. The ownership layer uses an extensible field design. The security layer includes tag hash values calculated using the SHA-256 algorithm, digital signatures generated using the owner's private key, and data security classifications including public / private / confidential information. Tag embedding and extraction algorithms implement differentiated schemes for different types of satellite data. For remote sensing image data, an adaptive wavelet domain hierarchical embedding algorithm is used, embedding tags in the low-frequency coefficient region of the image with an impact on data accuracy of no more than 0.1%. Simultaneously, three redundant backups are set in the mid-frequency coefficient region to ensure a tag extraction success rate of no less than 98% when the data compression rate does not exceed 30% and the noise interference intensity does not exceed 15 dB. The communication satellite data reserves an eight-byte fixed field in the data frame header to store the tag hash digest. Tag storage is achieved through SM3 algorithm compression, ensuring the impact on data transmission rate does not exceed 0.01%. Tag tamper-proof verification includes both local and on-chain verification. Local verification stores the original tag hash value through the TPM trusted platform module at the receiving station and processing center. The tag hash value is recalculated and compared before each use; any inconsistency indicates tampering. On-chain verification synchronizes the hash value and digital signature to the consortium blockchain after tag generation. Subsequent steps can verify the tag's authenticity using the hash value stored on-chain.
[0066] 2) Hybrid Consortium Blockchain-Private Blockchain Traceability Architecture: The architecture comprises a dual design of a consortium blockchain layer and a private blockchain layer. The consortium blockchain layer consists of ten to fifteen consortium nodes, including satellite operators, receiving stations, regulatory agencies, and core data processors, employing a dynamic PBFT consensus mechanism for efficient consensus. For high-frequency operations such as data distribution, the number of participating nodes is reduced to five, with consensus time not exceeding two seconds per transaction. For critical operations such as ownership changes and raw data reception, ten nodes participate in consensus, with consensus time not exceeding five seconds per transaction. The consortium blockchain layer stores only lightweight traceability information, including fields such as tag hash, operation type, node identifier, operation timestamp, and result hash, with each record not exceeding one thousand bytes. The private blockchain layer is independently built by each data processing and application institution, storing detailed traceability information including preprocessing algorithm parameters, analysis logs, complete operation records, and other detailed data. It synchronizes key information with the consortium blockchain through a smart contract-based cross-chain protocol, such as synchronizing the result hash to the consortium blockchain after processing. Storage and query optimization employs a layered storage and three-level indexing scheme. Tiered storage stores lightweight information on-chain, while complete data and detailed logs are stored off-chain via a distributed file system, using on-chain hash values to locate off-chain data. A three-level index establishes a correlation index between data identifiers, tag hashes, and operation records on the consortium blockchain, supporting rapid tracing of the entire process by data identifier, with a query response time of no more than one second for data within a year.
[0067] 3) A collaborative mechanism for rights confirmation and traceability: An information association mechanism achieves deep binding between traceability records and ownership tags. Traceability records are forcibly associated with tag identifiers and right types. Each traceability operation, including preprocessing analysis and distribution, requires reading data tags and marking the current node's right type in the record, such as a non-commercial scenario for the right transferee, thus enabling reverse rights confirmation through traceability. Ownership status is automatically updated when the right expires, triggered by a timestamp. An automatic permission termination record is generated on the consortium blockchain, synchronously updating the right holder field in the tag to an invalid state, prohibiting subsequent operations on that node. A unified data flow standard is achieved through the formulation of a tag and traceability interaction protocol. The protocol uses JSON-LD format to define field meanings, data types, and interface specifications, ensuring that tags are automatically synchronized to the consortium blockchain and the corresponding private blockchain after generation. After a traceability operation is completed, the record is automatically associated with the tag and the ownership status is updated, all without manual intervention. A one-stop management platform is developed, integrating web and client platforms for tag generation, ownership query, traceability tracking, and permission application functions. The platform supports visual traceability maps to display the entire data process nodes and changes in rights, and provides an automatic early warning function to push notifications when rights expire or abnormal operations occur.
[0068] 4) Security and Efficiency Optimization Technologies: Sensitive information protection employs a combination of de-identification and encryption technologies. De-identification uses partial masking and symmetric encryption for sensitive fields in tags, such as track parameters and data receiving station identifiers. After masking, the parameter precision is reduced to one degree. The complete information is stored on a private blockchain using AES-256 encryption, decrypted only by authorized regulatory nodes. On-chain information encryption uses RSA-2048 asymmetric encryption for tag hashes in the consortium blockchain, with the decryption key held only by the ownership entity and authorized nodes. Efficiency optimization achieves performance improvements through hardware acceleration and batch processing. Hardware acceleration deploys SM4 encryption chips and blockchain acceleration cards on consortium blockchain nodes, improving encryption / decryption and consensus computation efficiency, increasing the number of traceability records processed per node from 100 to 300 per second. Batch on-chain processing distributes similar high-frequency operations as batches of data, packaging every 10 to 20 records into a block for on-chain processing, reducing the number of blocks and lowering network transmission pressure. Fine-grained access control is based on a role-based access control model, dividing users into four roles and assigning different permissions. Ownership holders can view all information and modify ownership status; users can view traceability and ownership information within the authorized scope and initiate permission requests; regulatory agencies can view all traceability records and anonymized ownership information; ordinary users can only view the operation nodes and time information of publicly available data.
[0069] The implementation steps include: In the data reception and tag generation stage, the satellite receiving station automatically generates multi-dimensional ownership tags after acquiring raw data, embeds them in the data file header, calculates the tag hash, and uploads it to the consortium blockchain, while simultaneously storing it in the local TPM module. In the data preprocessing and traceability on-chain stage, the processing center reads the data tags and performs preprocessing operations such as radiometric correction, generating traceability records associated with tag identifiers and rights types. Detailed records are stored on the private blockchain, and key information such as the result hash is synchronized to the consortium blockchain.
[0070] During the data distribution and ownership update phase, a distribution traceability record is generated when data is distributed to users. Simultaneously, the usage rights subject field in the tag is updated and uploaded to the consortium blockchain. During the data usage and verification phase, users verify the tag hash before using the data, comparing the value stored on the consortium blockchain with their local TPM storage, and viewing the traceability graph. When rights expire, the system automatically terminates permissions and records the termination. During the anomaly monitoring and auditing phase, regulatory agencies monitor the traceability records in real time through the consortium blockchain. Abnormal operations, such as unauthorized distribution, trigger an audit process, tracing the responsible party based on on-chain records.
[0071] Compared to existing technologies, the technical advantages of this invention include: In terms of accuracy and reliability in rights confirmation, the multi-dimensional ownership tags support precise division of rights such as ownership and usage rights, solving the problem that traditional contracts cannot cover subdivided rights scenarios, and improving the clarity of rights boundaries by 90%. The adaptive embedding algorithm ensures that the tag extraction success rate is no less than 98% when the data compression rate does not exceed 30% and the noise interference does not exceed 15 dB, with a data accuracy deviation of no more than 0.1%, meeting the high-precision application needs of agricultural monitoring, land surveying, and other fields. The combination of tag binding with the data ontology and on-chain hash verification completely solves the problem of easily tampered metadata, ensuring 100% authenticity of ownership information. In terms of traceability efficiency and reliability, the consortium blockchain-private blockchain hybrid architecture eliminates the risk of single-point failure in centralized systems, increasing system availability from 95% to 99.99%. The dynamic PBFT consensus mechanism and batch on-chain strategy increase the on-chain speed of traceability records to two to five seconds per record, with a single node processing capacity of 300 records per second, meeting the high-frequency demand of over 100,000 operations per day for a single satellite. The tiered storage and three-level index design ensures that the traceability query response time is less than one second, suitable for data stored within one year. Compared to the eight-second query time of a centralized system, this represents an 87.5% efficiency improvement. Regarding collaboration and ease of use, the automatic association between ownership confirmation and traceability ensures that ownership status is updated synchronously with traceability operations, avoiding manual synchronization errors. The operation steps are reduced from eight to ten steps in the previous technology to three to four steps, improving user efficiency by 60%. A unified data flow standard eliminates data silos, shortening the integration time between different institutional systems from fifteen days to one day, reducing cross-institutional collaboration costs. The one-stop management platform supports visualized traceability maps, allowing users to intuitively view the entire data flow and lowering the technical threshold. In terms of balancing security and efficiency, sensitive information desensitization and encryption ensure that information such as satellite orbital parameters and image features are not leaked, and data security compliance meets the requirements of the National Satellite Data Security Management Regulations. The combination of lightweight encryption algorithms and hardware acceleration improves encryption and decryption efficiency by 30% while ensuring security and reduces system CPU utilization by 25%. Fine-grained access control prevents excessive information exposure, ensuring ordinary users cannot access sensitive information and enabling regulatory agencies to conduct efficient audits, thus achieving a balance between security and openness. In terms of economic and social value, it reduces the dispute rate in satellite data transactions, projected to decrease from the current 20% to below 5%, reducing the cost of rights protection. It promotes the market-based circulation of satellite data, with data reuse rates expected to increase by 40%, unlocking the value of data assets. It provides technical support for national satellite data security management, contributing to the high-quality development of the aerospace information industry.
[0072] In the above embodiments, although the steps are numbered S1, S2, etc., they are only specific embodiments given by the present invention. Those skilled in the art can adjust the execution order of S1, S2, etc. according to the actual situation. The scheme after adjusting the order is also within the protection scope of the present invention. It can be understood that in some embodiments, some or all of the above embodiments may be included.
[0073] like Figure 2 As shown, an embodiment of the satellite data ownership confirmation and data traceability system 200 of the present invention includes: a tag generation and embedding module 201, a storage module 202, an update module 203, and a traceability module 204; the tag generation and embedding module 201 is used to: generate multi-dimensional ownership tags for satellite data, the multi-dimensional ownership tags including at least ownership layer information, and embed the multi-dimensional ownership tags into the satellite data, the ownership layer information including information of the ownership subject; the storage module 202 is used to: generate, during the operation of satellite data embedded with multi-dimensional ownership tags, generate, store, update, and traceability modules 204. The system establishes a traceability record, stores lightweight traceability information from the record on a consortium blockchain, and stores detailed traceability information from the record on a private blockchain. Key information corresponding to the detailed traceability information is synchronized to the consortium blockchain via a cross-chain protocol. The update module 203 updates the ownership layer information in the multi-dimensional ownership tags based on the traceability record. The traceability module 204 responds to traceability query requests by querying the lightweight traceability information stored on the consortium blockchain and the detailed traceability information stored on the private blockchain to generate and output a full-process traceability map of the satellite data.
[0074] Optionally, the above technical solution also includes a verification module, which is used to: calculate the hash value of the multi-dimensional ownership tag, digitally sign the hash value using the private key of the ownership entity, and upload the hash value and digital signature to the consortium blockchain; before operating on the satellite data embedded with the multi-dimensional ownership tag, extract the multi-dimensional ownership tag from the satellite data embedded with the multi-dimensional ownership tag, calculate the hash value of the extracted multi-dimensional ownership tag, compare it with the hash value obtained from the consortium blockchain, and verify the digital signature of the satellite data embedded with the multi-dimensional ownership tag using the public key corresponding to the private key of the ownership entity, so as to verify the integrity and authenticity of the extracted multi-dimensional ownership tag.
[0075] Optionally, in the above technical solution, the consortium blockchain uses a dynamic PBFT consensus mechanism to reach consensus on the on-chain operation of lightweight traceability information and key information synchronized by the private blockchain.
[0076] Optionally, the above technical solution also includes a desensitization and encryption processing module, which is used to desensitize and encrypt sensitive information in multi-dimensional ownership tags.
[0077] In another embodiment, such as Figure 3 As shown, Figure 3This design embodies a layered, decoupled, and collaborative approach. The user layer includes ownership entities (satellite operators) with the authority to modify ownership status; users (research institutions and enterprises) with the authority to apply for data access; regulatory agencies with auditing and monitoring authority; and ordinary users with the authority to view public information. These users initiate operation requests through a one-stop management platform in the application layer. This platform integrates a tag generation module for creating multi-dimensional ownership tags, an ownership query module for retrieving rights information, a source tracing module for tracking data flow paths, an access request module for processing access requests, and an anomaly warning module for monitoring system operation. After the user layer initiates an operation request through the application layer's one-stop platform, the four subsystems of the core technology layer collaboratively process the request. Specifically, the rights confirmation subsystem generates tags and then... The system synchronizes with the traceability subsystem. Specifically, the ownership confirmation subsystem uses multi-dimensional ownership tags and TPM verification technology to confirm data ownership. The traceability subsystem adopts a hybrid architecture of consortium blockchain and private blockchain to record lightweight traceability information and detailed traceability information. The collaboration subsystem uses a unified data flow interface based on JSON-LD format to synchronize the status of ownership confirmation and traceability. The security subsystem combines encryption technology and access control to ensure data processing security. The data layer provides secure storage support for the entire process, including consortium blockchain nodes storing lightweight traceability information, private blockchain nodes storing detailed traceability information, the distributed file system HDFS storing complete data files, and the TPM trusted module protecting tag hash values. This architecture solves the problems of system silos and scattered storage in existing technologies, and achieves deep collaboration between ownership confirmation and traceability.
[0078] Figure 4This display showcases the hierarchical structure and field details of multi-dimensional ownership tags. The security layer includes tag hashes calculated using the SHA256 algorithm, digital signatures generated from the owner's private key, and data security classification information. The ownership layer includes owner identifiers, user identifiers, rights duration timestamps, and rights scope description fields. The base layer includes satellite identifiers, orbital parameter coordinates, receiver identifiers, millisecond-level reception time stamps, data type classifications, and resolution values. This structured design addresses the issues of single metadata fields and ambiguous ownership classification in existing metadata. The right side compares the original image with the embedded image to demonstrate the embedding effect. The original image is 10,000 x 10,000 pixels with a pixel grayscale value range of 0 to 255 and has no embedding markers. The embedded image maintains the same size and grayscale range but clearly marks the embedding area. The low-frequency coefficient area accounts for 15%, and three redundant backups are set in the mid-frequency coefficient area. The enlarged part of the image shows the comparison between the original pixel values (128, 130, 129, 127, 126, 125, 124, 123, 122, 121) and the embedded pixel values (127, 129, 128, 126, 125, 124, 123, 122, 121, 120) in a 10x10 pixel area. The image clearly marks that the maximum grayscale deviation is 0.8 and does not exceed 1, and the accuracy impact is 0.08% and does not exceed 0.1%. These data intuitively demonstrate that the advantage of the adaptive wavelet domain hierarchical embedding algorithm is that it can solidify the label without affecting the data accuracy. Compared with the existing watermarking technology with a pixel deviation of 0.5%, the accuracy impact of this invention is reduced by 80%, and the redundant backup design improves the label extraction success rate.
[0079] Figure 5The invention demonstrates the operational mechanism of the hybrid traceability architecture, highlighting the efficiency advantages of the dynamic PBFT consensus mechanism and the batch on-chain strategy. The on-chain time for a single record is no more than 2 seconds, and the batch on-chain efficiency is improved by 50%. Compared with the processing speed of existing blockchain technologies of 5-8 seconds per record, the on-chain speed of this invention is improved by 60%-75%. At the same time, the layered design of storing lightweight information (0.8KB / record) on the consortium chain and storing detailed logs (10KB / record) on the private chain solves the problem of high storage pressure and slow query speed in existing centralized systems. The detailed operation process is as follows: At time T0 (second 0), the satellite receiving station acquires the raw data, namely the Gaofen-10 remote sensing image, automatically generates multi-dimensional ownership tags, and calculates the tag hash using the SHA256 algorithm; At time T1 (second 1), the satellite receiving station uploads the tag hash to consortium blockchain nodes C1 to C5, triggering the dynamic PBFT consensus mechanism; At time T2 (second 3), consortium blockchain nodes C1 to C5 complete consensus in 2 seconds and return a successful upload notification to the receiving station, with a record size of 0.8KB; At time T3 (second 4), the satellite receiving station transmits the data and tags to the preprocessing center; At time T4 (second 5), the preprocessing center reads the tags and performs radiometric correction using the ENVI5.6 algorithm, generating a traceability record associated with the tag identifier TAG-GF10-061001; Preprocessing... The center stores 15KB of detailed log data on the private blockchain node P1, calculates the result hash using the SM3 algorithm, and uploads it to the consortium blockchain. At time T5 (second 7), consortium blockchain nodes C1 to C5 complete the result hash consensus in 2 seconds, successfully uploading the data to the blockchain. At time T6 (second 8), the preprocessing center distributes data to agricultural monitoring agencies, with the distribution nodes generating 15 distribution records and batch packaging 10 records for uploading to the blockchain. At time T7 (second 11), consortium blockchain nodes C1 to C5 complete the batch uploading to the blockchain in 3 seconds, generating 2 blocks. At time T8 (second 12), the regulatory agency initiates a query request through the one-stop management platform. The system calls the lightweight information stored on the consortium blockchain and the detailed log data stored on the private blockchain. The system generates a visualized traceability map within 0.8 seconds and returns it to the regulatory agency, with a query response time of 0.8 seconds. The entire process demonstrates the efficient operation characteristics of the hybrid traceability architecture, optimizing system performance through dynamic node selection and batch processing, and achieving complete tracking of ownership information and traceability records.
[0080] Figure 6The invention showcases the traceability visualization function of a one-stop management platform, which enables reverse rights confirmation through node attribute annotation. For example, users can directly view the current user information by distributing node attributes. Compared with existing technologies that require manual association of rights confirmation and traceability systems, the visualization map of this invention improves operational efficiency by 60%. At the same time, the anomaly marking function can provide real-time warnings of violations, helping regulatory agencies to quickly trace the responsible parties. The graph clearly displays the entire process of satellite data flow, including satellite receiving station nodes labeled with reception time and coordinate information, preprocessing center nodes displaying the radiometric correction algorithm version, distribution nodes indicating the user rights entity identifier and scope of rights, and terminal user nodes recording data application scenarios. The timeline accurately displays the complete time sequence from data reception to final use. Connecting lines between nodes indicate the data transmission direction and data volume. Changes in ownership status are distinguished by color coding between the owner and user rights entities. Abnormal operation nodes are highlighted in red and display the violation type and occurrence time. The monitoring view provides multi-dimensional filtering functions, supporting filtering by time range, node type, and ownership status. The detailed information panel can be expanded to view the complete traceability record and ownership change history of any node. The system supports the export and sharing of the traceability graph for easy audit archiving. The entire visualization interface adopts a layered display design, presenting both macro-processes and micro-details. Users can drill down to the operation logs and ownership certificates of specific nodes through interactive operations.
[0081] Example 1: This example involves the application scenario of high-resolution remote sensing satellite data ownership confirmation and traceability. The background is as follows: The Gaofen-10 high-resolution remote sensing satellite has a resolution of 0.5 meters, generates 30TB of data daily, and performs an average of 120,000 data processing and distribution operations per day. A satellite operator needs to address the problems of easily tampered ownership and slow traceability response in existing technologies. This invention is used to construct an ownership confirmation and traceability system. The implementation steps include three main stages: system deployment, data ownership confirmation process, and data traceability process. The system deployment corresponds to the attached... Figure 1The system's overall architecture diagram shows three user layers: satellite operators as owners, agricultural monitoring institutions as users with limited non-commercial use, and the China National Space Administration as the regulatory body, all configured with role-based access control permissions. The application layer deploys a one-stop management platform integrating functional modules such as tag generation and ownership query, with platform interfaces adapted to the Gaofen-10 ground station data format. The core technology layer deploys a rights confirmation subsystem running an adaptive wavelet domain layered embedding algorithm server connected to the ground station's data receiving interface. The traceability subsystem establishes 10 consortium blockchain nodes, including 2 operator nodes, 3 ground station nodes, 3 core processor nodes, and 2 regulatory body nodes, while also deploying 3 private blockchain nodes, including 1 preprocessing center node and 2 distribution center nodes. The security subsystem deploys SM4 encryption chips on the consortium blockchain nodes, and the ground station is configured with a TPM2.0 module. The data layer deploys an HDFS cluster to store complete remote sensing data and interfaces with the private blockchain nodes via a network file system protocol. At time T0, the ground station receives raw remote sensing data from Gaofen-10, with an image size of 10000×10000 pixels and a grayscale range of 0-255. At time T1, the ownership confirmation subsystem automatically generates multi-dimensional ownership tags. The basic layer includes the satellite identifier: GF-10, orbital parameters: 118.5°E / 29.8°N, receiving station identifier: JS-01, receiving time: 2025-06-10 09:15:30.123, data type: remote sensing, resolution: 0.5 meters. The ownership layer includes the owner identifier: OP-001, the user identifier: AG-001 (corresponding to the agricultural monitoring agency), the right period: 2025-06-10 to 2025-12-10, and the scope of the right: non-commercial use (limited to agricultural disaster monitoring). The security layer includes the tag hash calculated using the SHA-256 algorithm to obtain a3b7c9..., and the digital signature generated using the owner's OP-001 private key, with a security level of... Identifier: Secret; At time T2, an adaptive wavelet domain hierarchical embedding algorithm is used to embed multi-dimensional ownership tags in the low-frequency coefficient region of the image, and three redundant backups are set in the mid-frequency coefficient region. After embedding, the maximum pixel deviation of the image is 0.8, specifically, the original pixel value of 128 becomes 127.2, with an accuracy impact of 0.08%; At time T3, the TPM module stores the original hash value of the tag and uploads the tag hash and digital signature to the consortium blockchain. The consortium blockchain uses a dynamic PBFT consensus mechanism with 5 nodes participating in consensus verification, completing the on-chain operation within 2 seconds. The corresponding data traceability process is attached. Figure 3The sequence diagram of the hybrid traceability process using a consortium blockchain and a private blockchain is as follows: At time T4, the preprocessing center applies for data usage rights through the one-stop management platform. The system verifies the tag hash by comparing the stored value on the consortium blockchain with the value stored in the TPM module. After successful verification, data download is authorized. At time T5, the preprocessing center performs radiation correction using the ENVI 5.6 algorithm, generating traceability records containing the tag identifier: TAG-GF10-061001. The operation type is preprocessing, the processor is USER-01, and the detailed log size is 15KB. The data is stored on the private blockchain. The result hash is calculated using the SM3 algorithm to obtain d2e5f8... and synchronized to the consortium blockchain, achieving consensus within 3 seconds. At time T6, the preprocessing center distributes the processed data to the agricultural monitoring agency, distributing 15 records at a time. A batch on-chain strategy is used, packaging 10 records at a time to generate 2 blocks, completing the on-chain process in 4 seconds. At time T7, when the agricultural monitoring agency uses the data, the one-stop management platform automatically verifies the tag validity and displays the corresponding traceability map. Figure 4 Example of a source tracing visualization graph, marking the current user AG-001 and the remaining 180 days of the right; at T8 time, the regulatory agency queried the data flow record on June 10 through the platform. The system retrieved lightweight information (0.8KB each) from the consortium blockchain and detailed logs from the private blockchain, generating a visualization graph within 1 second. No abnormal operations were found. The implementation effect is shown in Table 1.
[0082] Table 1: Example 2: Application scenario involving data ownership confirmation and traceability for communication satellites. Background: This example focuses on the Zhongxing-26 communication satellite, which transmits an average of 15TB of communication data daily, involving sensitive information. A certain aerospace company needs to address privacy leaks and slow processing during high-frequency operations, and applies this invention to optimize the system. Key differences in implementation are reflected in the comparison with Example 1. The tag embedding method uses a unique approach to communication satellite data, reserving fixed fields in the data frame header for embedding, corresponding to... Figure 2The variant design on the right reserves an 8-byte fixed field in the header of the 2048kbps E1 frame data frame. The stored tag hash digest is compressed using the SM3 algorithm, controlling the transmission rate loss to 0.008%, an optimization not yet achieved in existing technologies. Sensitive information protection for the orbital parameter 110.3°E / 0° employs a protection scheme combining partial masking and AES-256 encryption. After masking, the displayed value is 110°E / 0°, while the complete parameter is encrypted using AES-256 and stored on a private blockchain, with only regulatory agency nodes having decryption privileges. Consensus optimization addresses the high-frequency demand of 80,000 communication data operations per day by adopting a simplified dynamic PBFT consensus mechanism. Three consortium blockchain nodes participate in consensus verification, reducing the on-chain time to 1.5 seconds per transaction, meeting the timeliness requirements of real-time communication scenarios. These differentiated implementation schemes significantly improve system processing efficiency while ensuring the security of communication data, providing technical assurance for the trusted circulation of sensitive communication data. The implementation results are shown in Table 2.
[0083] Table 2: Comparative examples demonstrate the effectiveness of existing technologies and highlight the advantages of this invention. Comparative Example 1 employs a centralized database traceability system, corresponding to the centralized database solution in the background technology. The application scenario uses the same Gaofen-10 data and uses an Oracle centralized database to store traceability records. The system has several problems: on the seventh day, due to a hardware failure of the database server, approximately one thousand traceability records were lost for two hours, making it impossible to trace the data flow; when the data volume reaches 120TB, the traceability query response time is extended to 10.5 seconds, far exceeding the 0.9-second query speed achieved by this invention; an internal staff member tampered with five distribution records to forge the receiving time, and the system lacks a verification mechanism, with the anomaly only discovered through manual auditing three days later. Comparative Example 2 adopts a preliminary blockchain application scheme from the background technology corresponding to a traditional blockchain traceability system. The application scenario uses the same data from the ChinaSat 26 satellite and employs a ten-node Ethereum consortium blockchain architecture with the traditional PBFT consensus mechanism. The system has significant drawbacks: 120,000 operations per day cause transaction congestion, and the longest on-chain time is up to twelve seconds, failing to meet the real-time requirements of communication data; the on-chain publicly stored orbital parameters (118.5°E / 29.8°N) pose a risk of sensitive information leakage; and no collaborative mechanism has been established with the rights confirmation system, requiring manual data synchronization between the two systems, resulting in an average of three synchronization errors per day. The implementation conclusions show that this invention, through a combination of multi-dimensional ownership tags, a consortium blockchain-private blockchain hybrid architecture, and a rights confirmation and traceability collaborative mechanism, can effectively solve the shortcomings of existing technologies in application scenarios such as high-resolution remote sensing satellites and communication satellites. In terms of ownership accuracy, the invention achieves a tag extraction success rate of no less than 98%, reducing the risk of ownership tampering to zero and meeting the needs of high-precision data applications. Regarding traceability efficiency, the query response time is no more than 1 second, with a daily processing capacity of no less than 120,000 queries, adapting to high-frequency data operation needs. For security and compliance, the invention achieves 100% encryption of sensitive information, meeting the requirements of the National Satellite Data Security Management Regulations, balancing security and efficiency. In terms of usability, the invention reduces operation steps by 60% and shortens cross-institutional integration time by 93%, lowering the threshold for industrial application. These technical indicators fully demonstrate the comprehensive technological improvements provided by this invention in the field of satellite data ownership confirmation and traceability.
[0084] It should be noted that the beneficial effects of the satellite data ownership confirmation and data traceability system 200 provided in the above embodiments are the same as those of the satellite data ownership confirmation and data traceability method described above, and will not be repeated here. Furthermore, the system and method embodiments provided in the above embodiments belong to the same concept, and their specific implementation processes are detailed in the method embodiments, and will not be repeated here.
[0085] An electronic device according to an embodiment of the present invention includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements any of the aforementioned satellite data ownership confirmation and data traceability methods. A computer-readable storage medium according to an embodiment of the present invention stores a computer program, which, when executed by a processor, implements any of the aforementioned satellite data ownership confirmation and data traceability methods.
[0086] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.
Claims
1. A method for satellite data ownership confirmation and data traceability, characterized in that, include: Generate multi-dimensional ownership tags for satellite data, wherein the multi-dimensional ownership tags include at least ownership layer information, and embed the multi-dimensional ownership tags into the satellite data, wherein the ownership layer information includes information about the ownership subject; During the operation of satellite data embedded with multi-dimensional ownership tags, a traceability record is generated. The lightweight traceability information in the traceability record is stored in the consortium blockchain, and the detailed traceability information in the traceability record is stored in the private blockchain. The key information corresponding to the detailed traceability information is synchronized to the consortium blockchain through a cross-chain protocol. Based on the source tracing record, update the ownership layer information in the multi-dimensional ownership tag; In response to a traceability query request, the system generates and outputs a full-process traceability map of the satellite data by querying the lightweight traceability information stored in the consortium blockchain and the detailed traceability information stored in the private blockchain.
2. The method for satellite data ownership confirmation and data traceability according to claim 1, characterized in that, Also includes: Calculate the hash value of the multi-dimensional ownership tag, digitally sign the hash value using the private key of the ownership entity, and upload the hash value and the digital signature to the consortium blockchain; Before operating on satellite data embedded with multi-dimensional ownership tags, the multi-dimensional ownership tags are extracted from the satellite data, the hash value of the extracted multi-dimensional ownership tags is calculated, and compared with the hash value obtained from the consortium blockchain. The digital signature of the satellite data embedded with multi-dimensional ownership tags is verified using the public key corresponding to the private key of the ownership entity, so as to verify the integrity and authenticity of the extracted multi-dimensional ownership tags.
3. The method for satellite data ownership confirmation and data traceability according to claim 2, characterized in that, The consortium blockchain uses a dynamic PBFT consensus mechanism to reach consensus on the on-chain operations of the lightweight traceability information and key information synchronized by the private blockchain.
4. A method for satellite data ownership confirmation and data traceability according to any one of claims 1 to 3, characterized in that, Also includes: Sensitive information in the multi-dimensional ownership tags is desensitized and encrypted.
5. A satellite data ownership confirmation and data traceability system, characterized in that, include: The system includes a tag generation and embedding module, a storage module, an update module, and a tracing module. The tag generation and embedding module is used to: generate multi-dimensional ownership tags for satellite data, wherein the multi-dimensional ownership tags include at least ownership layer information, and embed the multi-dimensional ownership tags into the satellite data, wherein the ownership layer information includes information about the ownership subject; The storage module is used to: generate a traceability record during the operation of satellite data embedded with multi-dimensional ownership tags, store the lightweight traceability information in the traceability record to the consortium blockchain, and store the detailed traceability information in the traceability record to the private blockchain, wherein the key information corresponding to the detailed traceability information is synchronized to the consortium blockchain through a cross-chain protocol; The update module is used to: update the ownership layer information in the multi-dimensional ownership tag based on the source tracing record; The traceability module is used to: respond to a traceability query request, generate and output a full-process traceability map of the satellite data by querying the lightweight traceability information stored in the consortium blockchain and the detailed traceability information stored in the private blockchain.
6. A satellite data ownership confirmation and data traceability system according to claim 5, characterized in that, It also includes a verification module, which is used for: Calculate the hash value of the multi-dimensional ownership tag, digitally sign the hash value using the private key of the ownership entity, and upload the hash value and the digital signature to the consortium blockchain; Before operating on satellite data embedded with multi-dimensional ownership tags, the multi-dimensional ownership tags are extracted from the satellite data, the hash value of the extracted multi-dimensional ownership tags is calculated, and compared with the hash value obtained from the consortium blockchain. The digital signature of the satellite data embedded with multi-dimensional ownership tags is verified using the public key corresponding to the private key of the ownership entity, so as to verify the integrity and authenticity of the extracted multi-dimensional ownership tags.
7. A satellite data ownership confirmation and data traceability system according to claim 6, characterized in that, The consortium blockchain uses a dynamic PBFT consensus mechanism to reach consensus on the on-chain operations of the lightweight traceability information and key information synchronized by the private blockchain.
8. A satellite data ownership confirmation and data traceability system according to any one of claims 5 to 7, characterized in that, It also includes a desensitization and encryption processing module, which is used to desensitize and encrypt sensitive information in the multi-dimensional ownership tags.
9. An electronic device, characterized in that, The system includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the satellite data ownership confirmation and data traceability method according to any one of claims 1 to 4.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed by a processor, implements a satellite data ownership confirmation and data traceability method as described in any one of claims 1 to 4.