A data transmission method, system, device and medium based on a trusted data space

By deploying secure chips and trusted execution environments in the cloud-edge-device architecture of the power supply chain, a trusted data space is constructed, solving the problems of forgery, tampering, and privacy leakage in power supply chain data transmission, and realizing secure and controllable data transmission and efficient business value transformation.

CN122137559APending Publication Date: 2026-06-02STATE GRID ZHEJIANG ELECTRIC POWER CO LTD +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
STATE GRID ZHEJIANG ELECTRIC POWER CO LTD
Filing Date
2026-05-06
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

The centralized data platform architecture of existing power supply chain data platforms is difficult to build a trusted data channel covering the entire chain from cloud to edge to terminal, resulting in problems such as source forgery, mid-transmission tampering, privacy leakage and insufficient trust protection during data transmission.

Method used

A data transmission method based on trusted data space is adopted. By deploying security chips in the cloud-edge-device architecture of the power supply chain for hardware encryption, digital signatures are generated, and signature verification and decryption are performed in a trusted execution environment. Combined with the encryption channel, a transmission channel is selected to build a complete trusted link and record the data lineage map for source tracing and abnormal data tracking.

Benefits of technology

It enables secure and controllable transmission of power supply chain data, prevents forgery and tampering at the source, protects privacy and security, provides transparent end-to-end trusted auditing and process traceability, and improves data processing efficiency and business value conversion efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137559A_ABST
    Figure CN122137559A_ABST
Patent Text Reader

Abstract

This invention discloses a data transmission processing method, system, device, and medium based on a trusted data space, belonging to the field of power supply chain data transmission. The trusted data space is constructed according to the cloud-edge-device architecture of the power supply chain and integrates a trusted execution environment and an encrypted channel. The method is as follows: based on the trusted data space, data transmission obtains encrypted data packets; wherein, the encrypted data packets are obtained by hardware encryption of the collected original multi-source heterogeneous data and generating a digital signature through an externally deployed security chip; the encrypted data packets are verified by signature verification through the trusted execution environment, and if the verification is successful, the encrypted data packets are decrypted and processed to obtain first multi-source heterogeneous data; according to different recipients, a corresponding transmission channel is selected from the encrypted channel to transmit the first multi-source heterogeneous data. Therefore, by implementing this invention, secure transmission of power supply chain data can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power supply chain data transmission, and in particular to a method, system, device and medium for data transmission based on a trusted data space. Background Technology

[0002] In the power industry chain and supply chain, data is a key element driving collaboration across the entire chain, including procurement, warehousing, logistics, and on-site installation. A secure, reliable, and efficient data environment is the foundation for achieving precise resource matching, dynamic process optimization, and proactive business services.

[0003] The current mainstream technology for power supply chain data platforms is the "centralized data platform" architecture. This architecture makes it difficult to build a trusted data channel and computing environment covering the entire "cloud-edge-device" chain. As a result, data faces multiple security risks during cross-system and cross-link transmission and flow, such as source forgery, mid-transmission tampering, privacy leaks, and difficulty in tracing operations. At the same time, its centralized and rigid data governance model also makes it difficult to ensure the credibility of data in the process of authorized sharing, collaborative computing, and value exchange inside and outside the industry chain. It is impossible to form a data foundation that supports the secure mutual trust and agile collaboration of multiple parties in the industry chain. Summary of the Invention

[0004] This invention provides a data transmission processing method, system, device, and medium based on a trusted data space. By implementing this invention, secure transmission of power supply chain data can be achieved.

[0005] This invention provides a data transmission method based on a trusted data space, wherein the trusted data space is constructed according to the cloud-edge-device architecture of the power supply chain and obtained by integrating a trusted execution environment and an encrypted channel. The data transmission method includes: Obtain encrypted data packets; wherein, the encrypted data packets are obtained by hardware encryption of the collected raw multi-source heterogeneous data and generating a digital signature through an externally deployed security chip; The encrypted data packet is signed and verified through the trusted execution environment. If the verification is successful, the encrypted data packet is decrypted and processed to obtain the first multi-source heterogeneous data. Depending on the recipient, a corresponding transmission channel is selected from the encrypted channel to transmit the first multi-source heterogeneous data.

[0006] This invention employs a deployed security chip to hardware encrypt the collected raw, multi-source heterogeneous data and generate a digital signature with a unique device identifier, obtaining encrypted data packets. By establishing a hardware-level trust anchor from the source of data generation, it ensures the authenticity and immutability of the data source, effectively preventing the risks of source forgery and tampering in the transmission of power supply chain data. The encrypted data packets are then signed, decrypted, and processed using a trusted execution environment within a trusted data space. This ensures that only signed and verified data can proceed to subsequent stages, and data processing is completed in a secure isolation environment, protecting the privacy and security of sensitive data. Furthermore, the encrypted channels within the trusted data space allow the transmission of the first multi-source heterogeneous data through corresponding transmission channels selected for different recipients, ensuring data integrity during transmission and preventing data leakage and theft. Compared to existing technologies that rely on centralized data platforms, which struggle to prevent source forgery and tampering, and lack privacy computing environments leading to the vulnerability of sensitive data to leakage, this application constructs a complete trusted link from data collection and trusted processing to secure transmission through a trusted data space. This achieves secure and controllable transmission of power supply chain data, guaranteeing the secure transmission of power supply chain data.

[0007] Furthermore, the process of transmitting the first multi-source heterogeneous data also includes: Record the entire process information of the first multi-source heterogeneous data and generate a data lineage map; the entire process information includes the source, flow path, processor and modification content; The transmission process of the first multi-source heterogeneous data is traced and queried through the data lineage map to complete compliance audit or data verification. Abnormal nodes are marked by the data lineage map, and the source and flow path of abnormal data within the abnormal nodes are obtained, thereby locking the abnormal data and pushing alarm information of the abnormal data to complete the abnormal data tracking.

[0008] In this way, by automatically recording the entire process information of the source, flow path, processor, and modification content of the first multi-source heterogeneous data during the transmission of the first multi-source heterogeneous data, and generating a structured data lineage map, a complete and verifiable record of the data flow trajectory is achieved, providing a transparent and trustworthy data foundation for end-to-end trusted auditing and process traceability. By tracing the transmission process of the first multi-source heterogeneous data and tracking abnormal data based on the data lineage map, the source node and flow path of any data can be quickly and accurately located, transforming the traditional post-audit that relies on manual verification into an efficient and reproducible systematic verification. When abnormal data is tracked, the system automatically marks the abnormal node through the data lineage and locks the abnormal data according to the recorded source and flow information, while pushing alarm information in real time, realizing immediate perception, accurate location, and proactive intervention of data risks.

[0009] Furthermore, the encrypted data packet is signed and verified using the trusted execution environment. If the verification passes, the encrypted data packet is decrypted and processed to obtain the first multi-source heterogeneous data, specifically as follows: The encrypted data packet is signed and verified by the trusted execution environment. If the verification is successful, the encrypted data packet is decrypted to obtain the decrypted data. The decrypted data is standardized to obtain standardized data assets; the standardization process includes structure transformation, quality auditing, and deduplication cleaning; wherein the signature verification, decryption, and data processing are all performed within the secure isolation zone of the trusted execution environment; Based on the data type of the data asset, a preset trusted microservice interface is invoked to process the data and obtain the first multi-source heterogeneous data; the trusted microservice interface includes a material demand forecasting interface, an intelligent production scheduling interface, and an inventory scheduling interface.

[0010] This approach utilizes a trusted execution environment to sign, verify, and decrypt encrypted data packets. Decryption ensures the authenticity and integrity of the data source, providing a reliable data foundation for subsequent processing. Standardized processing, including structure transformation, quality auditing, and deduplication cleaning, transforms the decrypted multi-source heterogeneous data into standardized data assets that conform to unified standards. This effectively addresses the data processing difficulties caused by diverse data sources and formats in the power supply chain. Furthermore, by invoking pre-defined trusted microservice interfaces for material demand forecasting, intelligent production scheduling, and inventory management, the standardized data assets are processed and calculated on demand, improving the efficiency of data transformation into business value.

[0011] Furthermore, after obtaining the first multi-source heterogeneous data, the process also includes: The first multi-source heterogeneous data is input into a preset multi-objective optimization model. The multi-objective optimization model is combined with the material supply strategy to conduct multi-scenario simulation and deduction, and output the supply bottleneck prediction and optimized scheduling scheme of power materials.

[0012] By inputting the first multi-source heterogeneous data into a preset multi-objective optimization model and combining it with material supply strategies for multi-scenario simulation and deduction, a leap from experience-driven to model-driven intelligent decision-making is achieved. Through the prediction results output by the multi-objective optimization model, potential future supply bottlenecks and resource conflicts can be accurately identified. Then, based on the prediction results, schemes such as material scheduling, inventory allocation, and logistics routes can be dynamically optimized, significantly improving the response speed, resource utilization efficiency, and overall operational resilience of the power supply chain, and realizing a value closed loop from reliable data to intelligent decision-making.

[0013] Furthermore, the material supply strategy includes a preset component library strategy and a business rule library strategy; The multi-scenario simulation and deduction using the multi-objective optimization model combined with material supply strategies includes: By using a preset component library strategy, algorithm components and preset functional models are invoked to process the first multi-source heterogeneous data to obtain real-time demand, inventory turnover, and logistics routes for electronic materials; the algorithm components include natural language processing components, computer vision components, and operations research and optimization components; the functional models are obtained by training based on power material consumption data and real-time project progress data. The business rule base strategy calls the preset business rule base to process the first multi-source heterogeneous data in order to verify the business compliance of the data and make constraint corrections; the business rule base contains various business logics and rules of the power material supply chain.

[0014] By combining the pre-defined component library strategy and the business rule library strategy, the first multi-source heterogeneous data is deeply mined, significantly improving the intelligence level and prediction accuracy of data analysis. By calling various business logics and rules encapsulated in the business rule library, clear industry standards and constraint frameworks are provided for data processing, ensuring that the output results conform to the actual business logic and requirements.

[0015] Furthermore, the encrypted data packet is obtained by hardware encryption of the collected raw multi-source heterogeneous data and generation of a digital signature through a deployed security chip, specifically as follows: By deploying a security chip in the power material terminal equipment, the collected raw multi-source heterogeneous data is hardware encrypted using the national cryptographic SM4 algorithm, and a digital signature with the unique identifier of the power material terminal equipment is generated using the national cryptographic SM2 algorithm to obtain an encrypted data packet.

[0016] By deploying a security chip in the power equipment terminal, the original multi-source heterogeneous data collected is hardware-encrypted using the national cryptographic SM4 algorithm. The chip's built-in dedicated encryption engine provides real-time protection for the data at the moment of generation, effectively preventing theft and spying risks during data collection. The national cryptographic SM2 algorithm generates a digital signature with the unique identifier of the power equipment terminal, strongly binding each data packet to the unique physical identity that generated it, effectively preventing the risk of impersonation and tampering during data transmission.

[0017] Furthermore, after generating the data lineage map, the method also includes performing adaptive optimization on the trusted data space, specifically: Through the data lineage graph, multi-dimensional operational indicators are continuously obtained from the data asset library, while real-time business events are obtained through the trusted execution environment as supplementary indicators. An evaluation result is generated based on the multi-dimensional operational metrics and the supplementary metrics. An optimization instruction is then generated based on the evaluation result, and adaptive optimization is performed on the trusted data space based on the optimization instruction.

[0018] This approach continuously acquires multi-dimensional operational metrics from the data asset repository through the data lineage graph, enabling long-term structured tracking and quantitative analysis of the trusted data space. The trusted execution environment acquires business events in real time as supplementary metrics, ensuring timely response to the latest supply chain dynamics and enhancing the ability to handle emergencies and business fluctuations. Evaluation results are generated based on the multi-dimensional and supplementary metrics, and optimization instructions are automatically generated. These instructions then adaptively adjust and continuously evolve the trusted data space, continuously improving its processing efficiency, resource utilization, business fit, and overall robustness, forming a closed-loop "monitoring-evaluation-optimization" process with self-awareness, self-assessment, and self-optimization capabilities.

[0019] Another embodiment of the present invention provides a data transmission system based on a trusted data space, comprising: a data encryption module, a data processing module, and a data transmission module; The data encryption module is used to acquire encrypted data packets; wherein, the encrypted data packets are obtained by hardware encryption of the collected raw multi-source heterogeneous data and generation of a digital signature through an externally deployed security chip; The data processing module is used to perform signature verification on the encrypted data packet through the trusted execution environment of the trusted data space. If the verification is successful, the encrypted data packet is decrypted and processed to obtain the first multi-source heterogeneous data. The data transmission module is used to select a corresponding transmission channel from the encrypted channel of the trusted data space to transmit the first multi-source heterogeneous data according to different recipients.

[0020] This invention employs a deployed security chip to hardware encrypt the collected raw multi-source heterogeneous data and generate a digital signature with a unique device identifier, obtaining an encrypted data packet. By establishing a hardware-level trust anchor from the source of data generation, the authenticity and immutability of the data source are ensured, effectively preventing the risk of source forgery and tampering in the transmission of power supply chain data. The encrypted data packet is then signed, decrypted, and processed using a trusted execution environment within a trusted data space, ensuring that only signed and verified data can proceed to subsequent stages. Data processing is completed in a secure isolation environment, protecting the privacy and security of sensitive data. Furthermore, the first multi-source heterogeneous data is transmitted through an encrypted channel within the trusted data space, selecting the appropriate transmission channel based on the different recipients, ensuring data integrity during transmission and preventing data leakage and theft. By constructing a complete trusted link from data collection and trusted processing to secure transmission through the trusted data space, the secure and controllable transmission of power supply chain data during transmission is achieved, guaranteeing the secure transmission of power supply chain data.

[0021] Another embodiment of the present invention provides a terminal device, including: a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, it implements the steps of the data transmission method based on trusted data space of the present invention.

[0022] Another embodiment of the present invention provides a computer-readable storage medium item, including: a stored computer program, which, when the computer program is running, controls the device where the computer-readable storage medium is located to perform the steps of the data transmission method based on trusted data space of the present invention. Attached Figure Description

[0023] To more clearly illustrate the technical solution of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0024] Figure 1 This is a flowchart illustrating an embodiment of the data transmission method based on a trusted data space provided by the present invention. Figure 2 This is a schematic diagram of a module of another embodiment of the data transmission system based on trusted data space provided by the present invention. Detailed Implementation

[0025] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0026] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the application; the terms “comprising” and “having”, and any variations thereof, in the specification, claims, and foregoing description of the drawings are intended to cover non-exclusive inclusion.

[0027] In the description of the embodiments of this application, technical terms such as "first" and "second" are used only to distinguish different objects and should not be construed as indicating or implying relative importance or implicitly specifying the number, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, "multiple" means two or more, unless otherwise explicitly defined.

[0028] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0029] In the description of this invention, the term "for example" is used to mean "used as an example, illustration, or description." Any embodiment described as "for example" in this invention is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is provided to enable any person skilled in the art to make and use the invention. Details are set forth in the following description for purposes of explanation. It should be understood that those skilled in the art will recognize that the invention can be made without using these specific details. In other instances, well-known structures and processes will not be described in detail to avoid obscuring the description of the invention with unnecessary detail. Therefore, the invention is not intended to be limited to the embodiments shown, but is consistent with the broadest scope of the principles and features disclosed herein.

[0030] In the description of the embodiments of this application, the term "multiple" refers to two or more (including two), similarly, "multiple sets" refers to two or more (including two sets), and "multiple pieces" refers to two or more (including two pieces).

[0031] See Figure 1 To address the data transmission problems in existing technologies, an embodiment of the present invention provides a data transmission method based on a trusted data space. The trusted data space is constructed according to the cloud-edge-device architecture of the power supply chain and integrates a trusted execution environment and an encrypted channel. The data transmission method includes steps S1 to S3, each step as follows: S1. Obtain the encrypted data packet; wherein, the encrypted data packet is obtained by hardware encryption of the collected raw multi-source heterogeneous data and generating a digital signature through an externally deployed security chip; Specifically, a security chip is deployed in the power material terminal equipment. The original multi-source heterogeneous data collected is hardware encrypted using the national cryptographic SM4 algorithm through the security chip, and a digital signature with the unique identifier of the power material terminal equipment is generated using the national cryptographic SM2 algorithm. The encrypted data and the digital signature are then encapsulated into an encrypted data packet.

[0032] S2. The encrypted data packet is signed and verified through the trusted execution environment. If the verification is successful, the encrypted data packet is decrypted and processed to obtain the first multi-source heterogeneous data. Specifically, the digital signature of the encrypted data packet is verified through the trusted execution environment. If the verification is successful, the encrypted data packet is decrypted and processed in the secure isolation zone of the trusted execution environment. The data processing includes structure transformation, quality audit, and deduplication cleaning to obtain the first multi-source heterogeneous data.

[0033] S3. Based on different recipients, select the corresponding transmission channel from the encrypted channel to transmit the first multi-source heterogeneous data.

[0034] The encrypted channel includes several transmission links with different security levels or transmission protocols. Based on the recipient's identity and permissions, data security classification, and service scheduling strategy, a corresponding transmission link is matched from the encrypted channel, and the first multi-source heterogeneous data is encrypted and transmitted to the corresponding recipient via the selected transmission link.

[0035] This invention employs a deployed security chip to hardware encrypt the collected raw, multi-source heterogeneous data and generate a digital signature with a unique device identifier, obtaining encrypted data packets. By establishing a hardware-level trust anchor from the source of data generation, it ensures the authenticity and immutability of the data source, effectively preventing the risks of source forgery and tampering in the transmission of power supply chain data. The encrypted data packets are then signed, decrypted, and processed using a trusted execution environment within a trusted data space. This ensures that only signed and verified data can proceed to subsequent stages, and data processing is completed in a secure isolation environment, protecting the privacy and security of sensitive data. Furthermore, the encrypted channels within the trusted data space allow the transmission of the first multi-source heterogeneous data through corresponding transmission channels selected for different recipients, ensuring data integrity during transmission and preventing data leakage and theft. Compared to existing technologies that rely on centralized data platforms, which struggle to prevent source forgery and tampering, and lack privacy computing environments leading to the vulnerability of sensitive data to leakage, this application constructs a complete trusted link from data collection and trusted processing to secure transmission through a trusted data space. This achieves secure and controllable transmission of power supply chain data, guaranteeing the secure transmission of power supply chain data.

[0036] In one embodiment, the process of transmitting the first multi-source heterogeneous data further includes steps S201 to S203, each of which is as follows: S201. Record the entire process information of the first multi-source heterogeneous data and generate a data lineage map; the entire process information includes the source, flow path, processor, and modification content; This involves deploying and initializing end-to-end lineage collection rules at each node, such as defining that "material procurement data" must record "collection terminal equipment - collection time - transmission node - processing personnel - modification record", while configuring unified power material data standards (such as material coding specifications and data format requirements) and security policies (such as encryption algorithms and access control rules). S202. Using the data lineage map, trace the transmission process of the first multi-source heterogeneous data to complete compliance audit or data verification. Specifically, the data lineage graph allows for the traceability and compliance auditing of the entire data chain for each batch of power materials, from procurement and project initiation, production and delivery, warehousing and storage, logistics and distribution to on-site installation. The data lineage graph also allows for the precise identification of the source and flow path of any data, such as querying which WMS terminal collected "a certain transformer inventory data," which node processed it, which microservice called it, whether it was modified, and who modified it, thus ensuring that responsibility is delineated, the process is verifiable, and risks are controllable. S203. Mark abnormal nodes through the data lineage map, obtain the source and flow path of abnormal data within the abnormal nodes, thereby locking the abnormal data and pushing alarm information of the abnormal data to complete the abnormal data tracking.

[0037] The data lineage graph automatically records information such as the source, flow path, processor, and modified content of data throughout the entire lifecycle of data collection, transmission, processing, storage, and use, forming a complete lineage graph for full-chain traceability and auditing. When abnormal data (such as material quantity tampering) is traced, the abnormal node is automatically marked and the operation audit of the TEE environment is triggered, the digital signature of the tampering device is locked, and an alarm is pushed to the risk control management module of the material management platform.

[0038] This invention, through its embodiments, automatically records the entire process information of the source, flow path, processor, and modified content of the first multi-source heterogeneous data during transmission, and generates a structured data lineage graph. This achieves a complete and verifiable record of the data flow trajectory, providing a transparent and reliable data foundation for end-to-end trusted auditing and process traceability. By tracing the transmission process of the first multi-source heterogeneous data and tracking abnormal data based on the data lineage graph, the system can quickly and accurately locate the source node and flow path of any data, transforming traditional post-audit relying on manual verification into efficient and reproducible systematic verification. When abnormal data is tracked, the system automatically marks the abnormal node through the data lineage graph and locks the abnormal data based on the recorded source and flow information, while simultaneously pushing alarm information in real time, achieving immediate perception, accurate location, and proactive intervention of data risks.

[0039] In one embodiment, the encrypted data packet is signed and verified using the trusted execution environment. If the verification passes, the encrypted data packet is decrypted and processed to obtain the first multi-source heterogeneous data, including steps S301 to S303, each step of which is as follows: S301. The encrypted data packet is signed and verified by the trusted execution environment. If the verification is successful, the encrypted data packet is decrypted to obtain the decrypted data. S302. Standardize the decrypted data to obtain standardized data assets; the standardization process includes structure transformation, quality audit, and deduplication cleaning; wherein the signature verification, decryption, and data processing processes are all performed within the secure isolation zone of the trusted execution environment; The TEE Trusted Execution Environment (TEE) is deployed on edge nodes and the cloud using the ARM TrustZone and Intel SGX architectures, respectively. The two architectures achieve mutual trust and compatibility through a power grid-specific trusted communication protocol, providing isolated secure computing areas for processing and computing sensitive data. In practical applications, ETL tools such as DataWorks (Alibaba Cloud, adapted for large-scale provincial data) or open-source Kettle (adapted for small and medium-sized warehouse nodes) are used in conjunction with semantic alignment algorithms to perform structured transformation, quality auditing (such as integrity and consistency verification), and deduplication and cleaning on the decrypted data. Based on the master data of power materials, a unified data model is built to form standardized data assets including material catalogs, inventory ledgers, procurement contracts, and logistics trajectories. S303. Based on the data type of the data asset, call the preset trusted microservice interface to process the data and obtain the first multi-source heterogeneous data; the trusted microservice interface includes a material demand forecasting interface, an intelligent production scheduling interface, and an inventory scheduling interface.

[0040] This invention utilizes a trusted execution environment to sign and decrypt encrypted data packets, ensuring the authenticity and integrity of the data source before decryption, thus providing a trusted data foundation for subsequent processing. By performing standardized processing such as structured transformation, quality auditing, and deduplication on the decrypted multi-source heterogeneous data, it transforms it into standardized data assets conforming to unified standards, effectively solving the data processing difficulties caused by diverse data sources and formats in the power supply chain. Furthermore, by invoking pre-defined trusted microservice interfaces for material demand forecasting, intelligent production scheduling, and inventory management, the standardized data assets are processed and calculated on demand, improving the efficiency of data transformation into business value.

[0041] In one embodiment, the material supply strategy includes a preset component library strategy and a business rule library strategy. The multi-objective optimization model, combined with the material supply strategy, is used to perform multi-scenario simulations, including steps S401 to S402, each of which is detailed below: S401. By using a preset component library strategy, the algorithm components and preset functional models are invoked to process the first multi-source heterogeneous data to obtain the real-time demand, inventory turnover, and logistics path of electronic materials; the algorithm components include natural language processing components, computer vision components, and operations research and optimization components; the functional model is obtained by training based on power material consumption data and real-time project progress data. The functional model is designed for the power material supply chain scenario. It uses power material consumption data from the past three years and real-time project progress data for pre-training and optimization to obtain functional models such as material demand prediction model, inventory optimization model, and path planning model. S402. Through the business rule base strategy, the preset business rule base is invoked to process the first multi-source heterogeneous data to verify the business compliance of the data and make constraint corrections; the business rule base contains various business logics and rules of the power material supply chain.

[0042] The business rules library contains various business logics and rules for the power material supply chain, such as inventory warning thresholds, supplier evaluation rules, and logistics scheduling strategies, which can be configured and managed in a visual manner.

[0043] This invention, through the collaborative application of preset component library strategies and business rule library strategies, performs in-depth mining of the first multi-source heterogeneous data, significantly improving the intelligence level and prediction accuracy of data analysis; by calling various business logics and rules encapsulated in the business rule library, it provides clear industry standards and constraint frameworks for data processing, ensuring that the output results conform to actual business logic and requirements.

[0044] In one embodiment, after generating the data lineage map, the method further includes performing adaptive optimization on the trusted data space, including steps S501 to S502, each step of which is as follows: S501. Through the data lineage graph, multi-dimensional operational indicators are continuously obtained from the data asset library, and real-time business events are obtained through the trusted execution environment as supplementary indicators. The system continuously acquires multi-dimensional operational indicators such as material turnover efficiency, supply response speed, and strategy execution deviation from the trusted data asset library through the data lineage graph. At the same time, it collects real-time business events (such as material delays and equipment failures) in the TEE environment of edge nodes as supplementary indicators. For example, when a "decline in supplier fulfillment rate" is detected, the system automatically triggers the optimization of supplier evaluation rules or the retraining of demand forecasting models. The optimization instructions are distributed to the corresponding nodes through a secure channel, driving the iterative updates of data standards, service components, and business rules. The execution status and effects are fed back in real time. After the optimized rules and models are verified on a small scale (the verification period is no less than 15 days, and the standard for compliance is "the deviation of optimized business indicators ≤ 5%)", they are gradually promoted to the entire system. At the same time, the data lineage records are updated to ensure that all changes are traceable, forming a "monitoring-optimization-feedback" closed loop. S502. Generate evaluation results based on the multi-dimensional operating indicators and the supplementary indicators, generate optimization instructions based on the evaluation results, and then perform adaptive optimization on the trusted data space based on the optimization instructions.

[0045] In this system, adaptive optimization is performed by combining cloud-edge collaboration and feedback operation mechanisms. Strategies such as inventory early warning and logistics scheduling are encapsulated into secure instructions through an encrypted channel and encrypted with a session key generated in the TEE environment, and then attached with a cloud-based digital signature before being sent to edge nodes. Edge nodes complete instruction verification and decryption within the TEE environment, perform local business processing such as inventory entry and exit checks and in-transit transportation monitoring, and transmit the processing results and status back to the cloud after encryption. By monitoring and evaluating the transmitted data, for example, when an edge node reports that "the actual logistics cost is higher than the projected value," the system automatically analyzes the reasons for the deviation (such as the failure to include special fees), triggers adjustments to the inventory scheduling strategy, and generates new instructions to be sent to relevant nodes, forming a trusted operational closed loop of "issuance-execution-feedback-optimization."

[0046] This invention continuously acquires multi-dimensional operational indicators from the data asset library through the data lineage graph, enabling long-term structured tracking and quantitative analysis of the trusted data space. It uses real-time business events obtained through the trusted execution environment as supplementary indicators to ensure timely response to the latest supply chain dynamics and enhance the ability to cope with emergencies and business fluctuations. Based on the multi-dimensional indicators and the supplementary indicators, it generates evaluation results and automatically generates optimization instructions. These instructions then adaptively adjust and continuously evolve the trusted data space, continuously improving its processing efficiency, resource utilization, business fit, and overall robustness, forming a closed-loop "monitoring-evaluation-optimization" process with self-awareness, self-evaluation, and self-optimization capabilities.

[0047] like Figure 2 Based on the data transmission in the trusted data space, a corresponding system implementation is provided, building upon the above method implementation. This invention provides a data transmission system based on a trusted data space, comprising: a data encryption module 601, a data processing module 602, and a data transmission module 603; The data encryption module 601 is used to acquire encrypted data packets; wherein, the encrypted data packets are obtained by hardware encryption of the collected raw multi-source heterogeneous data and generation of a digital signature through an externally deployed security chip; The data processing module 602 is used to perform signature verification on the encrypted data packet through the trusted execution environment of the trusted data space. If the verification is successful, the encrypted data packet is decrypted and processed to obtain the first multi-source heterogeneous data. The data transmission module 603 is used to select a corresponding transmission channel from the encrypted channel of the trusted data space to transmit the first multi-source heterogeneous data according to different recipients.

[0048] This invention employs a deployed security chip to hardware encrypt the collected raw multi-source heterogeneous data and generate a digital signature with a unique device identifier, obtaining an encrypted data packet. By establishing a hardware-level trust anchor from the source of data generation, the authenticity and immutability of the data source are ensured, effectively preventing the risk of source forgery and tampering in the transmission of power supply chain data. The encrypted data packet is then signed, decrypted, and processed using a trusted execution environment within a trusted data space, ensuring that only signed and verified data can proceed to subsequent stages. Data processing is completed in a secure isolation environment, protecting the privacy and security of sensitive data. Furthermore, the first multi-source heterogeneous data is transmitted through an encrypted channel within the trusted data space, selecting the appropriate transmission channel based on the different recipients, ensuring data integrity during transmission and preventing data leakage and theft. By constructing a complete trusted link from data collection and trusted processing to secure transmission through the trusted data space, the secure and controllable transmission of power supply chain data during transmission is achieved, guaranteeing the secure transmission of power supply chain data.

[0049] It is understood that the above system item embodiments correspond to the method item embodiments of the present invention, and can implement the data transmission method based on trusted data space provided by any of the above method item embodiments of the present invention.

[0050] It should be noted that the system embodiments described above are merely illustrative, and some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the system embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.

[0051] For ease of description and brevity, the system embodiments of the present invention include all the implementation methods described in the above embodiments of the data transmission method based on trusted data space, and will not be repeated here.

[0052] Based on the above embodiments of the data transmission method based on trusted data space, another embodiment of the present invention provides a terminal device, which includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the data transmission method based on trusted data space of any embodiment of the present invention.

[0053] For example, in this embodiment, the computer program can be divided into one or more modules, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the terminal device.

[0054] The terminal device may be a desktop computer, laptop, handheld computer, or cloud server, etc. The terminal device may include, but is not limited to, a processor and a memory.

[0055] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the terminal device, connecting all parts of the terminal device via various interfaces and lines.

[0056] Based on the above-described method embodiments, another embodiment of the present invention provides a computer-readable storage medium including a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to execute the data transmission method based on trusted data space described in any of the above-described method embodiments of the present invention.

[0057] The modules / units integrated in the device / terminal equipment, if implemented as software functional units and sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.

[0058] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.

Claims

1. A data transmission method based on a trusted data space, characterized in that, The trusted data space is constructed based on the cloud-edge-device architecture of the power supply chain and integrates a trusted execution environment and encrypted channels. The data transmission method includes: Obtain encrypted data packets; wherein, the encrypted data packets are obtained by hardware encryption of the collected raw multi-source heterogeneous data and generating a digital signature through an externally deployed security chip; The encrypted data packet is signed and verified through the trusted execution environment. If the verification is successful, the encrypted data packet is decrypted and processed to obtain the first multi-source heterogeneous data. Depending on the recipient, a corresponding transmission channel is selected from the encrypted channel to transmit the first multi-source heterogeneous data.

2. The data transmission method based on a trusted data space as described in claim 1, characterized in that, The process of transmitting the first multi-source heterogeneous data also includes: Record the entire process information of the first multi-source heterogeneous data and generate a data lineage map; the entire process information includes the source, flow path, processor and modification content; The transmission process of the first multi-source heterogeneous data is traced and queried through the data lineage map to complete compliance audit or data verification. Abnormal nodes are marked by the data lineage map, and the source and flow path of abnormal data within the abnormal nodes are obtained, thereby locking the abnormal data and pushing alarm information of the abnormal data to complete the abnormal data tracking.

3. The data transmission method based on a trusted data space as described in claim 1, characterized in that, The process involves verifying the signature of the encrypted data packet using the trusted execution environment. If the verification passes, the encrypted data packet is decrypted and processed to obtain the first multi-source heterogeneous data. Specifically: The encrypted data packet is signed and verified by the trusted execution environment. If the verification is successful, the encrypted data packet is decrypted to obtain the decrypted data. The decrypted data is standardized to obtain standardized data assets; the standardization process includes structure transformation, quality auditing, and deduplication cleaning; wherein the signature verification, decryption, and data processing are all performed within the secure isolation zone of the trusted execution environment; Based on the data type of the data asset, a preset trusted microservice interface is invoked to process the data and obtain the first multi-source heterogeneous data; the trusted microservice interface includes a material demand forecasting interface, an intelligent production scheduling interface, and an inventory scheduling interface.

4. The data transmission method based on a trusted data space as described in claim 3, characterized in that, After obtaining the first multi-source heterogeneous data, the process further includes: The first multi-source heterogeneous data is input into a preset multi-objective optimization model. The multi-objective optimization model is combined with the material supply strategy to conduct multi-scenario simulation and deduction, and output the supply bottleneck prediction and optimized scheduling scheme of power materials.

5. The data transmission method based on a trusted data space as described in claim 4, characterized in that, The material supply strategy includes a preset component library strategy and a business rule library strategy; The multi-scenario simulation and deduction using the multi-objective optimization model combined with material supply strategies includes: By using a preset component library strategy, algorithm components and preset functional models are invoked to process the first multi-source heterogeneous data to obtain real-time demand, inventory turnover and logistics path of electronic materials; the algorithm components include natural language processing components, computer vision components and operations research and optimization components. The functional model is obtained by training based on power material consumption data and real-time project progress data; The business rule base strategy calls the preset business rule base to process the first multi-source heterogeneous data in order to verify the business compliance of the data and make constraint corrections; the business rule base contains various business logics and rules of the power material supply chain.

6. The data transmission method based on a trusted data space as described in claim 1, characterized in that, The encrypted data packet is obtained by hardware encryption of the collected raw multi-source heterogeneous data and generation of a digital signature through a deployed security chip, specifically as follows: By deploying a security chip in the power material terminal equipment, the collected raw multi-source heterogeneous data is hardware encrypted using the national cryptographic SM4 algorithm, and a digital signature with the unique identifier of the power material terminal equipment is generated using the national cryptographic SM2 algorithm to obtain an encrypted data packet.

7. The data transmission method based on a trusted data space as described in claim 3, characterized in that, After generating the data lineage map, the process also includes performing adaptive optimization on the trusted data space, specifically: Through the data lineage graph, multi-dimensional operational indicators are continuously obtained from the data asset library, while real-time business events are obtained through the trusted execution environment as supplementary indicators. An evaluation result is generated based on the multi-dimensional operational metrics and the supplementary metrics. An optimization instruction is then generated based on the evaluation result, and adaptive optimization is performed on the trusted data space based on the optimization instruction.

8. A data transmission system based on a trusted data space, characterized in that, include: Data encryption module, data processing module, and data transmission module; The data encryption module is used to acquire encrypted data packets; wherein, the encrypted data packets are obtained by hardware encryption of the collected raw multi-source heterogeneous data and generation of a digital signature through an externally deployed security chip; The data processing module is used to perform signature verification on the encrypted data packet through the trusted execution environment of the trusted data space. If the verification is successful, the encrypted data packet is decrypted and processed to obtain the first multi-source heterogeneous data. The data transmission module is used to select a corresponding transmission channel from the encrypted channel of the trusted data space to transmit the first multi-source heterogeneous data according to different recipients.

9. A terminal device, characterized in that, It includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, it implements the data transmission method based on a trusted data space as described in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, include: A stored computer program, wherein, when the computer program is executed, it controls the device containing the computer-readable storage medium to perform the data transmission method based on a trusted data space as described in any one of claims 1-7.