A data sovereignty sharing method and system based on a trusted gateway for a zero-carbon park
Patent Information
- Application Number
- CN202610637977.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-11
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2046-05-11
AI Technical Summary
[0005]传统园区管理平台采用中心化数据汇聚模式,企业数据脱离自身管控范围,天然存在单点泄露、内部滥用及未经授权二次使用的风险;常规的数据访问控制、静态加密传输技术,仅能保障数据传输与存储环节的保密性,无法约束数据被平台接收后的使用行为,难以规避未授权分析、挖掘与共享问题
[0040]本发明的优点是:本发明提出的技术方案既通过数据分级加密、TEE可信执行环境实现企业敏感数据“可用不可见”,从底层保障数据主权、消除企业共享顾虑,又依托全链路区块链审计存证与可信计算,为园区碳核算提供技术级可信背书,满足监管与认证要求;同时创新“数据不动、算力移动”的价值共享范式,通过双连接器+数字碳合约的对等协同架构,在不泄露原始数据的前提下,为园区提供实时准确的碳排、能耗聚合数据,且基于成熟技术选型打造的方案兼具安全性、实时性与强落地性,构建了零碳园区数据安全协同的新生态。
Smart Images

Figure CN122293424B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security and green computing, specifically to a data sovereignty sharing method and system based on a trusted gateway for zero-carbon industrial parks. Background Technology
[0002] In existing technologies, the mainstream approach to addressing the data sharing and carbon accounting needs of industrial parks adopts a centralized data platform aggregation model. This involves the park building a unified data platform, where resident companies upload energy, production, and other relevant data. The platform then uses a built-in carbon accounting algorithm to calculate the park's overall carbon emissions and analyze energy consumption, providing data support for the park's dual-carbon management. This model protects data through account permissions and basic data encryption, attempting to reduce the risk of data leakage while sharing data.
[0003] Another similar technology is the IDS Connector data exchange mode, which relies on general-purpose data exchange components to achieve cross-entity data transmission. Data providers can define basic data usage strategies and complete the targeted transmission and access control of data through connectors, thus ensuring sovereignty during data transmission to a certain extent. This mode has been attempted to be applied to data interaction between multiple entities in the park in order to solve the trust problem of centralized platforms, but it has not been customized for the specific needs of carbon accounting in zero-carbon parks.
[0004] In the process of promoting the digital and intelligent management of zero-carbon parks, there is a clear conflict between the carbon accounting data needs of park operators and the demands of enterprises for the protection of trade secrets: in order to fulfill their emission reduction supervision responsibilities, parks urgently need to integrate carbon-related data from multiple parties to conduct macro-analysis and carbon footprint accounting, while enterprises generally refuse to submit raw plaintext data to the centralized park management platform for fear of leakage of core sensitive data such as production energy efficiency and process details.
[0005] Traditional park management platforms employ a centralized data aggregation model, leaving enterprise data outside their own control. This inherently presents risks of single-point leaks, internal misuse, and unauthorized secondary use. Conventional data access controls and static encryption transmission technologies can only ensure the confidentiality of data transmission and storage, failing to constrain data usage after it is received by the platform and making it difficult to prevent unauthorized analysis, mining, and sharing. Furthermore, these technologies lack the technical support for "usable but invisible." Park carbon accounting only requires aggregated indicators such as total energy consumption and average carbon intensity, without needing to obtain the original detailed data from enterprises. However, existing technologies cannot perform reliable calculations on encrypted or controlled data and output compliant aggregated results without accessing the original plaintext data. This ultimately creates a severe "data trust deficit" between parks and enterprises, hindering the release of the value of data elements within the park.
[0006] In recent years, advanced concepts, exemplified by the International Data Space, have proposed an architecture centered on data sovereignty and enabling controllable data exchange through standardized connectors. While IDS connectors have initially achieved policy-based data access control, providing a new approach to breaking down data silos, this type of architecture still has significant technical shortcomings when applied to complex scenarios involving the fusion and computation of sensitive data from multiple parties in zero-carbon industrial parks. First, its control policies remain at the basic level of "whether access is allowed," lacking refined definitions and execution capabilities for computational constraints, and failing to achieve permission control tailored to carbon accounting needs, such as "allowing only summation and prohibiting detailed queries." Second, it fails to build a trusted execution environment for the data usage stage, i.e., the computation process, making it impossible to ensure the "invisibility" of data during the computation process from a technical perspective, thus failing to fundamentally protect corporate data sovereignty. Third, the cross-organizational collaborative computation stage lacks a full-chain, verifiable audit mechanism, failing to meet the stringent requirements of carbon accounting for the credibility of results and regulatory compliance.
[0007] In summary, current technologies have not yet deeply integrated the concept of data sovereignty with trusted computing technology, and lack a dedicated solution for carbon data sharing scenarios in zero-carbon parks. There is an urgent need for an innovative technological solution that can effectively protect corporate data sovereignty at the technical level while securely and reliably releasing the value of data aggregation and resolving the core contradiction between green governance of parks and protection of corporate privacy. Summary of the Invention
[0008] To address the aforementioned issues, this invention discloses a data sovereignty sharing method and system based on a trusted gateway for zero-carbon industrial parks.
[0009] The specific technical solution is as follows:
[0010] A data sovereignty sharing method based on a trusted gateway for zero-carbon industrial parks includes the following steps:
[0011] S1 Data Classification and Data-Policy Binding: For carbon accounting scenarios in zero-carbon industrial parks, enterprises classify data based on the sensitivity of production and operation confidentiality of carbon-related raw data and the value of carbon accounting contribution. Customized structured data usage strategies are then bound to data of different levels, forming a sovereign and controllable data-policy binding system. The data usage strategies include at least encryption strength, allowed types of computational operations within a trusted execution environment, and restrictions on the output of computational results.
[0012] S2 Source Encryption and Data Encapsulation: The enterprise uses its own controlled key to perform end-to-end encryption on the graded original data according to the encryption strength agreed upon in the corresponding data usage policy. The data usage policy is associated with the encrypted data and encapsulated to generate a data object to be shared that is protected by the policy.
[0013] S3 Dual-End Authentication and Digital Carbon Contract Signing: The enterprise side and the park side complete two-way identity verification. Based on the aforementioned data policy binding system and the park's carbon accounting needs, the system automatically negotiates and signs a machine-readable programmable digital carbon contract, stipulating the execution rules for the entire carbon accounting process.
[0014] S4 Trusted Execution Environment Construction and Remote Verification: The park side creates a hardware-level isolated Trusted Execution Environment (TEE) for this carbon accounting task and issues a remote trusted verification report on the integrity of the environment to the enterprise side, thus completing the verification of the trustworthiness of the computing environment;
[0015] S5 Mobile Trusted Aggregated Computing: Within the trusted execution environment, a hash-verified carbon accounting algorithm agreed upon by the digital carbon contract is loaded. The session key is requested from the enterprise side to decrypt encrypted data, and aggregated computing is performed with "data remaining stationary and computing power moving". The original data and intermediate data during the computing process are isolated within the trusted execution environment. Only the park-level aggregated carbon index is generated according to the agreement of the digital carbon contract. The original data does not flow out of the trusted execution environment at all.
[0016] S6 Controlled Result Output and Secure Data Erasure: Outputs aggregated carbon index through a preset controlled API interface, while immediately destroying all raw and intermediate data in the trusted execution environment and releasing memory resources;
[0017] S7 Full-Link Hash Evidence Storage and Audit Chain Construction: Collect the hash values of evidence from key nodes in the entire carbon accounting process, process them in a standardized serialization manner, and store them in a tamper-proof distributed ledger to build a non-repudiable and verifiable carbon footprint audit chain;
[0018] S8 Authorization Verification and Data Sovereignty Traceability: Opens the audit chain query interface to authorized users. Enterprises can verify their own data contribution ratio and accounting process through the interface, verify the consistency of evidence throughout the process, and realize closed-loop governance with full-chain traceability of data sovereignty.
[0019] In step S1, the sensitivity classification is divided into at least a high sensitivity level and a low sensitivity level; for high sensitivity level data, the data usage strategy is as follows: time-aligned summation and weighted average calculation of data are only allowed within a trusted execution environment, and any export of raw data is prohibited;
[0020] For low-sensitivity data, the data usage strategy is to allow summation calculations and output the average power metric within the time window.
[0021] In step S3, the signed digital carbon contract shall at least specify the data type, carbon accounting algorithm hash, calculation result format and accuracy, and audit and evidence storage requirements; at the same time, it shall clearly define the identity of the data provider, the unique identifier of the bound data usage strategy, the identity of the data user, the unique code hash value of the authorized carbon accounting algorithm, and the output interface of the aggregated carbon index, so as to ensure that the governance rules for data sharing are consistent and tamper-proof on both ends.
[0022] In step S5, the carbon accounting aggregation calculation performed within the trusted execution environment includes at least the calculation of the green electricity ratio and the minute-level estimated carbon emissions calculation; in step S7, the key node evidence collected includes at least the data usage strategy, digital carbon contract, TEE remote trusted proof report, carbon accounting algorithm code, encrypted data sharding, and aggregated carbon index results; in step S8, enterprises can verify the contribution ratio of their own data to the total load of the park through the query interface, as well as verify the consistency of evidence at each stage of the entire process.
[0023] A data sovereignty sharing system based on a trusted gateway for zero-carbon industrial parks includes an enterprise-side data sovereignty connector, a park-side trusted computing gateway, a policy and contract center, and an audit and evidence storage system.
[0024] The enterprise-side data sovereignty connector is used to classify and bind the enterprise's carbon-related raw data based on sensitivity, complete the end-to-end encryption and data encapsulation of the raw data, complete identity authentication and digital carbon contract negotiation with the park-side trusted computing gateway, and initiate data sovereignty traceability verification requests.
[0025] The park-side trusted computing gateway is used to complete two-way identity verification with the enterprise side, create a hardware-level isolated trusted execution environment (TEE) and issue a remote trusted proof report, perform mobile trusted aggregate computing within the TEE, and complete the controlled output of aggregated carbon indicators and secure erasure of data within the computing environment.
[0026] The strategy and contract center is used to provide standardized digital carbon contract templates and two-way identity authentication services to support automated negotiation and signing of digital carbon contracts between enterprises and industrial parks.
[0027] The audit and evidence storage system is used to collect the hash values of evidence from key nodes throughout the entire process. After being processed by normalized serialization and cryptographic hashing, the data is stored in a tamper-proof distributed ledger to build a carbon footprint audit chain. The system also provides query and verification interfaces to authorized users, supporting full-chain traceability of data sovereignty.
[0028] The enterprise-side data sovereignty connector has a built-in hierarchical management and control module, an encryption and encapsulation module, and a contract negotiation module.
[0029] The hierarchical management module is used to classify the sensitivity of carbon accounting in zero-carbon parks based on the production and operation confidentiality sensitivity of carbon-related raw data and the contribution value of carbon accounting, and to bind customized structured data usage strategies to different levels of data.
[0030] The encryption and encapsulation module is used to perform end-to-end encryption on the graded original data using a key controlled by the enterprise, and to associate the data usage policy with the encrypted data for encapsulation.
[0031] The contract negotiation module is used to connect with the strategy and contract center, complete two-way identity authentication with the park-side trusted computing gateway, and initiate and complete the automated negotiation and signing of digital carbon contracts.
[0032] The campus-side trusted computing gateway has a built-in TEE management module, trusted computing module, and controlled output module.
[0033] The TEE management module is used to create a hardware-level isolated trusted execution environment for carbon accounting tasks, generate and issue a remote trusted proof report of environment integrity, and securely destroy and release the original data and intermediate data in the environment after the calculation is completed.
[0034] The trusted computing module is used to load a hash-verified carbon accounting algorithm within a trusted execution environment, request a session key to decrypt encrypted data, and perform aggregate computing with "data remaining stationary while computing power moves," thus isolating the original data from the intermediate data throughout the process.
[0035] The controlled output module is used to output aggregated carbon indicators in the format and precision agreed upon by the digital carbon contract through a preset controlled API interface, thereby blocking the outflow of raw data throughout the process.
[0036] The audit and evidence storage system has a built-in hash processing module, a distributed ledger module, and a verification and traceability module.
[0037] The hash processing module is used to perform standardized serialization processing on evidence at key nodes throughout the entire process, and generate corresponding evidence storage hash values through cryptographic hash functions;
[0038] The distributed ledger module is used to store the processed hash value and build a non-repudiable and verifiable carbon footprint audit chain.
[0039] The verification and traceability module is used to open a query interface to authorized users, supporting enterprises to complete the verification of their own data contribution ratio and the consistency verification of evidence throughout the entire process, so as to achieve full-chain traceability of data sovereignty.
[0040] The advantages of this invention are as follows: The technical solution proposed in this invention not only ensures data sovereignty and eliminates concerns about data sharing by achieving "usable but invisible" sensitive enterprise data through data hierarchical encryption and a TEE trusted execution environment, but also provides technical-level trusted endorsement for park carbon accounting by relying on end-to-end blockchain audit and evidence storage and trusted computing, meeting regulatory and certification requirements; at the same time, it innovates the value-sharing paradigm of "data does not move, computing power moves", and provides parks with real-time and accurate aggregated carbon emission and energy consumption data without leaking the original data through a peer-to-peer collaborative architecture of dual connectors and digital carbon contracts. Moreover, the solution, based on mature technology selection, combines security, real-time performance, and strong feasibility, building a new ecosystem of data security collaboration for zero-carbon parks. Attached Figure Description
[0041] Figure 1 This is a schematic diagram of the overall architecture of the data sovereignty sharing system based on a trusted gateway for zero-carbon industrial parks as described in this invention;
[0042] Figure 2 This is a schematic diagram of the internal functional modules and data processing flow of the enterprise-side data sovereignty connector of the present invention;
[0043] Figure 3 This is a schematic diagram of the digital carbon contract negotiation process between the enterprise-side data sovereignty connector and the park-side trusted computing gateway of the present invention;
[0044] Figure 4 This is a schematic diagram of the process of trusted aggregation computing of TEE within the trusted computing gateway on the campus side of the present invention;
[0045] Figure 5 This is a schematic diagram of the architecture and verification traceability process of the audit and evidence storage system of the present invention;
[0046] Figure 6 This is a schematic diagram of the interface of the present invention applied to the zero-carbon park monitoring platform;
[0047] Figure 7 This is a schematic diagram of the parameter configuration and execution control interface of the system of the present invention;
[0048] Figure 8 This is a schematic diagram of the interface for energy efficiency and carbon efficiency regulation of the present invention in zero-carbon industrial parks. Detailed Implementation
[0049] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0050] This invention integrates data sovereignty hierarchical management and trusted computing technology, and innovatively constructs a four-in-one collaborative architecture consisting of an enterprise-side data sovereignty connector, a park-side trusted computing gateway, a policy and contract center, and an audit and evidence storage system, so as to realize carbon data that is "usable but invisible, valuable and shareable, and auditable throughout the entire chain".
[0051] refer to Figures 1 to 5 The data sovereignty sharing method and system process based on trusted gateways of this invention includes the following steps:
[0052] Step 1: Zero-carbon scenario-specific data grading + strategy binding
[0053] For carbon accounting scenarios, the enterprise-side data sovereignty connector classifies raw carbon-related data into high / low sensitivity levels based on the data's production and operational confidentiality sensitivity and its contribution value to carbon accounting. It then binds customized structured usage strategies to different levels of data, clearly specifying encryption strength, the types of computational operations allowed within the TEE (e.g., only summation / weighted average is allowed for highly sensitive data), and result output restrictions, forming a sovereign and controllable data policy binding system.
[0054] (1) When the fluctuation range and cycle of a company’s data directly reflect the trade secret characteristics of the production schedule, and the data objects are judged to be of high sensitivity level and require key sovereign protection, the following policy is issued: only allow time-aligned summation and weighted average calculation of power data within the TEE, and prohibit any export of raw data.
[0055] The power after aligning the time to the park's timeline is:
[0056] ;
[0057] The total power of the park is:
[0058] ;
[0059] The group of participating enterprises within the park is defined as follows: , For the local power sampling time of the enterprise, For the first Companies at their local sampling time The power value, where t is the unified output timestamp on the park side, fixed at a 1-minute granularity. For time alignment algorithms, The total power of the park; within the window of timestamp t. Internal time alignment is performed to obtain the power aligned to the park's time axis. .
[0060] The formula for calculating the weighted average is:
[0061] ;
[0062] If an energy weight that is closer to carbon accounting is used:
[0063] ;
[0064] in The weighted average of the attributes of the park at timestamp t. For the i-th enterprise, the energy consumption is measured in minutes at timestamp t. Let be the attribute value to be statistically analyzed for the i-th company at timestamp t. The weight value of the i-th company at timestamp t.
[0065] (2) When the fluctuation of the enterprise's basic energy consumption load is smooth and the regularity is weak, it is difficult to reverse the production details from the detailed data. Therefore, it is judged to be of low sensitivity level and a more lenient sovereignty protection strategy is applied. The strategy is: allow summation calculation and allow output of average power.
[0066] If in The set of internal sampling points is The aligned discrete power is Then the average power of the window is:
[0067] ;
[0068] If calculated over continuous time, then:
[0069] ;
[0070] in For the park's time window Internal sampling point set, For set The timestamp of a single sampling point in the data. For set The number of sampling points in the sample. For the park at the sampling point Total power.
[0071] Step 2: Enterprise source encryption + data encapsulation
[0072] Enterprise-side connectors use self-controlled keys to perform end-to-end encryption on the graded raw data according to the encryption strength agreed upon in the policy. At the same time, the data is associated with the encrypted data and encapsulated using the policy to form a shared data object protected by the policy, thus ensuring data sovereignty from the source.
[0073] Step 3: Dual-end identity authentication + digital carbon contract negotiation and signing
[0074] The Strategy and Contract Center provides standardized contract templates and two-way authentication services. The enterprise-side connector and the park-side trusted computing gateway complete identity verification. Based on the data-policy binding system, both parties automatically negotiate digital carbon contract terms (clarifying data types, algorithm hashes, result formats, audit requirements, etc.), sign machine-readable programmable digital carbon contracts, and verify the integrity of the contracts and the validity of the signatures locally, achieving peer-to-peer collaborative governance.
[0075] Step 4: TEE Environment Construction + Remote Trusted Proof
[0076] The park-side trusted computing gateway creates a trusted execution environment (TEE) based on hardware-level isolation for carbon accounting tasks, and issues remote proof reports of environment integrity to the enterprise-side connector and audit and evidence storage system to ensure the trustworthiness of the computing environment and lay the foundation for subsequent trusted execution.
[0077] Step 5: Trusted Computing within a Mobile TEE
[0078] The TEE loads a specified carbon accounting algorithm that has been hash-verified, requests a session key from the enterprise to decrypt encrypted data, and performs aggregate calculations with "data remaining stationary while computing power moves". The calculation process, raw data and intermediate data are strictly isolated within the TEE and are completely invisible to the external operating system and administrators. Only park-level aggregated carbon indicators are generated according to the contract, achieving data that is "usable but invisible".
[0079] Trusted computation within a TEE includes:
[0080] (1) Green electricity ratio: When the aggregated data stream requires the output of the green electricity ratio, and the green electricity supplier provides "green electricity supply curve data", the calculation formula is as follows:
[0081] ;
[0082] in The aligned power of green electricity at timestamp t; The percentage of green electricity in the park at timestamp t. This represents the total power of the park.
[0083] (2) Estimated carbon emissions: The aggregated data stream requires the output to be included. The park management needs to "calculate the park's total carbon emissions," and the calculation formula is as follows:
[0084] First, convert the power consumption to energy consumption per minute:
[0085] , .
[0086] The estimated carbon emissions at the minute level are:
[0087]
[0088] .
[0089] in The total energy consumption of the park at the minute level at timestamp t. The park's green energy consumption is measured in minutes at timestamp t. The conversion factor for converting a time window to hours. ,when hour, ; Emission factors for electricity consumption by the power grid As an emission factor for green electricity, To estimate the carbon emissions of the park at the minute level of timestamp t, Let be the power grid energy consumption of the park at timestamp t, and let be the difference between total energy consumption and green energy consumption.
[0090] (3) The enterprise and the park shall calculate the carbon accounting algorithm as stipulated in the digital carbon contract.
[0091] Step 6: Controlled Result Output + Secure Data Erasure
[0092] After the calculation is completed, the aggregated carbon index in the TEE is output to the park application platform in the agreed format through the preset controlled API interface, blocking the outflow of raw data throughout the process; at the same time, all raw data and intermediate data in the TEE environment are immediately destroyed to release memory resources and prevent data leakage from the execution layer.
[0093] Step 7: Construction of the end-to-end hash-based evidence storage and audit chain
[0094] The audit evidence storage system collects hash values of key evidence throughout the entire process, including data strategies, digital carbon contracts, TEE proof reports, algorithm code, encrypted data fragments, and aggregation results. After standardized serialization and cryptographic hashing, the data is serialized and stored in a tamper-proof distributed ledger. This constructs a non-repudiable and regulatory-verifiable carbon footprint audit chain, providing legal evidence for enterprises' data rights.
[0095] The hash "formula" used for audit evidence storage has the following hash expression for various object types:
[0096] Strategy hashing: ;
[0097] Contract hash: ;
[0098] Remote proof report hash: ;
[0099] Algorithm code hash: ;
[0100] Data fragment cryptographic hash: ;
[0101] Carbon accounting result hash: ;
[0102] in For cryptographic hash functions, For normalized serialization functions; The hash value for evidence storage of the data strategy. Carbon data usage strategies defined for the enterprise side; The hash value for the notarization of the digital carbon contract. Digital carbon contracts signed between enterprises and the industrial park; This is the storage hash value of the TEE remote proof report. A remote verification report for the TEE environment on the park side; This is the notarized hash value of the carbon accounting algorithm code. This refers to the carbon accounting algorithm code executed within the TEE. The notarized hash value of the encrypted data fragment for the i-th enterprise. For the i-th enterprise, shard the encrypted data; This is the hash value for storing the carbon accounting results. This represents the final carbon accounting aggregation result from the park's perspective.
[0103] Audit reconciliation requires a company contribution rating, which is calculated using the following formula:
[0104] Enterprise energy consumption per minute:
[0105] ;
[0106] The percentage of each enterprise's contribution to the park's total load:
[0107] ;
[0108] in For the i-th enterprise, the energy consumption is measured in minutes at timestamp t. Let j represent the percentage of the total load of the park at timestamp t for the i-th enterprise, and j be the enterprise ID, belonging to the set. This is used to distinguish between different companies when summing.
[0109] Step 8: Authorization Verification + Data Sovereignty Tracing
[0110] The audit and evidence storage system opens a query interface to authorized users, allowing enterprises to verify their own data contribution ratio and accounting process through the interface, verify the consistency of evidence at each stage of the entire process, achieve full-chain traceability of data sovereignty, and complete closed-loop governance.
[0111] The following specific embodiments, in conjunction with the appendix, demonstrate this process. Figure 3 The present invention will now be described in further detail. Figure 3 This diagram illustrates the negotiation of a digital carbon contract between the enterprise-side data sovereignty connector and the park-side trusted computing gateway. The enterprise-side data sovereignty connector and the park-side trusted computing gateway negotiate and sign the digital carbon contract through a policy and contract center. The policy and contract center provides standardized contract templates and two-way authentication services. Both parties first authenticate their identities using this service, and then automatically negotiate the specific terms of the data usage policy. After reaching an agreement, both parties jointly sign a programmable digital carbon contract and verify the integrity of the contract content and the validity of both parties' signatures locally. This digital carbon contract specifically defines the identity of the data provider, the data type and format of the shared data, the unique identifier of the bound data usage policy; the identity of the data user, the unique code hash value of the carbon accounting algorithm authorized to run in the trusted execution environment; the format, accuracy, and output interface of the allowed aggregated carbon index results; and the specific requirements and evidence submission format for auditing and evidence preservation, thereby ensuring that the governance rules during the data sharing process are consistently and immutably executed at both ends.
[0112] The key points of this invention are as follows: After establishing the basic architecture of an enterprise-side data sovereignty connector, a park-side trusted computing gateway, a policy and contract center, and an audit and evidence storage system, this invention first adopts a grading standard specific to zero-carbon scenarios to classify the enterprise's carbon-related raw data according to its commercial confidentiality sensitivity and carbon accounting contribution value, and binds customized encryption and usage strategies to different levels of data to achieve refined management of data sovereignty; then, based on the results of two-way authentication of dual-end identities, and combined with the enterprise's data strategy and the park's carbon accounting needs, it executes automated negotiation and signing of programmable digital carbon contracts to build a peer-to-peer collaborative carbon data governance architecture; then, through a hardware-level isolated Trusted Execution Environment (TEE), it performs trusted aggregation calculations on encrypted data with "data not moving, computing power moving," outputting only park-level aggregated carbon indicators, achieving "usable but not visible" raw data; finally, it hashes and serializes all key evidence throughout the process and stores it in a tamper-proof distributed ledger to generate a non-repudiable and regulatory-verifiable carbon footprint audit chain, thereby achieving the dual goals of zero-carbon park data sovereignty protection and secure sharing and trusted accounting of carbon data.
Claims
1. A data sovereignty sharing method based on a trusted gateway for zero-carbon industrial parks, characterized in that, Includes the following steps: S1 Data Classification and Data-Policy Binding: For carbon accounting scenarios in zero-carbon industrial parks, enterprises classify data based on the sensitivity of production and operation confidentiality of carbon-related raw data and the value of carbon accounting contribution. Customized structured data usage strategies are then bound to data of different levels, forming a sovereign and controllable data-policy binding system. The data usage strategies include at least encryption strength, allowed types of computational operations within a trusted execution environment, and restrictions on the output of computational results. S2 Source Encryption and Data Encapsulation: The enterprise uses its own controlled key to perform end-to-end encryption on the graded original data according to the encryption strength agreed upon in the corresponding data usage policy. The data usage policy is associated with the encrypted data and encapsulated to generate a data object to be shared that is protected by the policy. S3 Dual-End Authentication and Digital Carbon Contract Signing: The enterprise side and the park side complete two-way identity verification. Based on the aforementioned data policy binding system and the park's carbon accounting needs, the system automatically negotiates and signs a machine-readable programmable digital carbon contract, stipulating the execution rules for the entire carbon accounting process. S4 Trusted Execution Environment Construction and Remote Verification: The park side creates a hardware-level isolated Trusted Execution Environment (TEE) for this carbon accounting task and issues a remote trusted verification report on the integrity of the environment to the enterprise side, thus completing the verification of the trustworthiness of the computing environment; S5 Mobile Trusted Aggregated Computing: Within the trusted execution environment, a hash-verified carbon accounting algorithm agreed upon by the digital carbon contract is loaded. The session key is requested from the enterprise side to decrypt encrypted data, and aggregated computing is performed with "data remaining stationary and computing power moving". The original data and intermediate data during the computing process are isolated within the trusted execution environment. Only the park-level aggregated carbon index is generated according to the agreement of the digital carbon contract. The original data does not flow out of the trusted execution environment at all. S6 Controlled Result Output and Secure Data Erasure: Outputs aggregated carbon index through a preset controlled API interface, while immediately destroying all raw and intermediate data in the trusted execution environment and releasing memory resources; S7 Full-Link Hash Evidence Storage and Audit Chain Construction: Collect the hash values of evidence from key nodes in the entire carbon accounting process, process them in a standardized serialization manner, and store them in a tamper-proof distributed ledger to build a non-repudiable and verifiable carbon footprint audit chain; S8 Authorization Verification and Data Sovereignty Traceability: Opens the audit chain query interface to authorized users. Enterprises can verify their own data contribution ratio and accounting process through the interface, verify the consistency of evidence throughout the process, and achieve closed-loop governance with full-chain traceability of data sovereignty.
2. The data sovereignty sharing method based on a trusted gateway for zero-carbon industrial parks according to claim 1, characterized in that: In step S1, the sensitivity classification is divided into at least a high sensitivity level and a low sensitivity level; for high sensitivity level data, the data usage strategy is as follows: time-aligned summation and weighted average calculation of data are only allowed within a trusted execution environment, and any export of raw data is prohibited; For low-sensitivity data, the data usage strategy is to allow summation calculations and output the average power metric within the time window.
3. The data sovereignty sharing method based on a trusted gateway for zero-carbon industrial parks according to claim 1, characterized in that: In step S3, the signed digital carbon contract shall at least specify the data type, carbon accounting algorithm hash, calculation result format and accuracy, and audit and evidence storage requirements; at the same time, it shall clearly define the identity of the data provider, the unique identifier of the bound data usage strategy, the identity of the data user, the unique code hash value of the authorized carbon accounting algorithm, and the output interface of the aggregated carbon index, so as to ensure that the governance rules for data sharing are consistent and tamper-proof on both ends.
4. The data sovereignty sharing method based on a trusted gateway for zero-carbon industrial parks according to claim 1, characterized in that: In step S5, the carbon accounting aggregation calculation performed within the trusted execution environment includes at least the calculation of the green electricity ratio and the minute-level estimated carbon emissions calculation; in step S7, the key node evidence collected includes at least the data usage strategy, digital carbon contract, TEE remote trusted proof report, carbon accounting algorithm code, encrypted data sharding, and aggregated carbon index results; in step S8, enterprises can verify the contribution ratio of their own data to the total load of the park through the query interface, as well as verify the consistency of evidence at each stage of the entire process.
5. A data sovereignty sharing system based on a trusted gateway for zero-carbon industrial parks, characterized in that, This includes an enterprise-side data sovereignty connector, a park-side trusted computing gateway, a policy and contract center, and an audit and evidence storage system; The enterprise-side data sovereignty connector is used to classify and bind the enterprise's carbon-related raw data based on sensitivity, complete the end-to-end encryption and data encapsulation of the raw data, complete identity authentication and digital carbon contract negotiation with the park-side trusted computing gateway, and initiate data sovereignty traceability verification requests. The park-side trusted computing gateway is used to complete two-way identity verification with the enterprise side, create a hardware-level isolated trusted execution environment (TEE) and issue a remote trusted proof report, perform mobile trusted aggregate computing within the TEE, and complete the controlled output of aggregated carbon indicators and secure erasure of data within the computing environment. The strategy and contract center is used to provide standardized digital carbon contract templates and two-way identity authentication services to support automated negotiation and signing of digital carbon contracts between enterprises and industrial parks. The audit and evidence storage system is used to collect the hash values of evidence from key nodes throughout the entire process. After being processed by normalized serialization and cryptographic hashing, the data is stored in a tamper-proof distributed ledger to build a carbon footprint audit chain. The system also provides query and verification interfaces to authorized users, supporting full-chain traceability of data sovereignty.
6. The data sovereignty sharing system based on a trusted gateway for zero-carbon industrial parks according to claim 5, characterized in that, The enterprise-side data sovereignty connector has a built-in hierarchical management and control module, an encryption and encapsulation module, and a contract negotiation module. The hierarchical management module is used to classify the sensitivity of carbon accounting in zero-carbon parks based on the production and operation confidentiality sensitivity of carbon-related raw data and the contribution value of carbon accounting, and to bind customized structured data usage strategies to different levels of data. The encryption and encapsulation module is used to perform end-to-end encryption on the graded original data using a key controlled by the enterprise, and to associate the data usage policy with the encrypted data for encapsulation. The contract negotiation module is used to connect with the strategy and contract center, complete two-way identity authentication with the park-side trusted computing gateway, and initiate and complete the automated negotiation and signing of digital carbon contracts.
7. The data sovereignty sharing system based on a trusted gateway for zero-carbon industrial parks according to claim 5, characterized in that, The campus-side trusted computing gateway has a built-in TEE management module, trusted computing module, and controlled output module. The TEE management module is used to create a hardware-level isolated trusted execution environment for carbon accounting tasks, generate and issue a remote trusted proof report of environment integrity, and securely destroy and release the original data and intermediate data in the environment after the calculation is completed. The trusted computing module is used to load a hash-verified carbon accounting algorithm within a trusted execution environment, request a session key to decrypt encrypted data, and perform aggregate computing with "data remaining stationary while computing power moves," thus isolating the original data from the intermediate data throughout the process. The controlled output module is used to output aggregated carbon indicators in the format and precision agreed upon by the digital carbon contract through a preset controlled API interface, thereby blocking the outflow of raw data throughout the process.
8. The data sovereignty sharing system based on a trusted gateway for zero-carbon industrial parks according to claim 5, characterized in that, The audit and evidence storage system has a built-in hash processing module, a distributed ledger module, and a verification and traceability module. The hash processing module is used to perform standardized serialization processing on evidence at key nodes throughout the entire process, and generate corresponding evidence storage hash values through cryptographic hash functions; The distributed ledger module is used to store the processed hash value and build a non-repudiable and verifiable carbon footprint audit chain. The verification and traceability module is used to open a query interface to authorized users, supporting enterprises to complete the verification of their own data contribution ratio and the consistency verification of evidence throughout the entire process, so as to achieve full-chain traceability of data sovereignty.
Citation Information
Patent Citations
Carbon emission checking system and method based on block chain
CN121119352A
Data sharing device and data sharing method
WO2025187037A1