Data cross-platform secure exchange method and system fusing ai and privacy computing

By integrating artificial intelligence (AI) with privacy computing, deeply analyzing the sensitivity level of data metadata, and formulating reasonable protection strategies based on this information, the security and stability issues of cross-platform data transmission in existing technologies are solved, enabling efficient and secure data transmission in complex network environments.

CN122372260APending Publication Date: 2026-07-10BEIJING GUOXIN XINWANG COMM TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING GUOXIN XINWANG COMM TECH CO LTD
Filing Date
2026-04-08
Publication Date
2026-07-10

Smart Images

  • Figure CN122372260A_ABST
    Figure CN122372260A_ABST
Patent Text Reader

Abstract

This application relates to the field of data transmission security technology, and in particular to a method and system for secure cross-platform data exchange that integrates AI and privacy computing. The method includes: acquiring and deeply analyzing the metadata information of the data to be transmitted to determine its sensitivity level distribution; performing layered protection processing on the data according to the sensitivity level distribution to generate a protection priority sequence; identifying high-risk data in the protection priority sequence and evaluating the stability indicators of the transmission environment; performing adaptive protection processing on the data according to the stability indicators and calculating the protection requirement strength; performing a trust assessment on the receiving device based on the protection requirement strength to determine the final protection strength configuration; calculating the trust level of the receiving device based on the final configuration and formulating a path optimization scheme; simulating the transmission process according to the path optimization scheme, adjusting the distributed protection strategy, updating the path scheme, and outputting the final transmission configuration scheme. This application effectively improves the security and adaptability of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data transmission security technology, and in particular to a method and system for secure cross-platform data exchange that integrates AI and privacy computing. Background Technology

[0002] In today's rapidly developing information age, data transmission security has become a critical area of ​​research and application. As enterprises, governments, and individuals increasingly demand higher standards of information protection, ensuring the confidentiality, integrity, and availability of data during transmission has become paramount. This is especially true in multi-platform, multi-node, and complex network environments, where data protection is constantly becoming more challenging. Currently, traditional data protection solutions often overlook the differences in the sensitivity of data content and fail to provide precise security protection based on the actual needs of different data types, resulting in unsatisfactory protection effects. This problem becomes even more apparent in cross-platform or multi-node transmission environments, posing a severe challenge to data security.

[0003] Furthermore, existing protection methods often struggle to cope with the complexity and instability of network environments. With the continuous development of network technology, data transmission often needs to traverse different network environments, the stability of which is frequently affected by factors such as bandwidth fluctuations, latency, and node failures. Traditional static security protection strategies often neglect dynamic changes during transmission and fail to effectively adjust protection strategies in the face of real-time network fluctuations, easily leading to data leakage or loss during transmission. Especially in cross-regional or multi-node transmission scenarios, network uncertainty further increases the risk of data security breaches. Existing solutions fail to provide real-time assessment and flexible adjustment, significantly increasing the risk of data protection failure.

[0004] Therefore, achieving precise and secure protection for cross-platform data transmission in complex and ever-changing network environments has become a pressing technical challenge. To address this challenge, a secure exchange method integrating artificial intelligence (AI) and privacy computing has emerged. This method accurately identifies the sensitivity level of data through deep analysis of its metadata and formulates appropriate protection strategies based on this information. Simultaneously, by assessing the stability of the transmission environment and dynamic changes in the network, the method can adjust security measures in real time, ensuring efficient and secure data transmission in cross-platform, multi-node environments. This innovative technical solution not only effectively addresses the shortcomings of existing solutions but also improves the security and stability of data transmission, providing a more precise and flexible solution for protecting various types of sensitive data. Summary of the Invention

[0005] This application provides a method and system for secure cross-platform data exchange that integrates AI and privacy computing, to improve the security and adaptability of data transmission.

[0006] In a first aspect, this application provides a method for secure cross-platform data exchange that integrates AI and privacy computing, the method comprising: S1. Obtain the metadata information of the data to be transmitted, perform in-depth analysis of the metadata information, and determine the sensitivity level distribution of the data to be transmitted. S2. Based on the sensitivity level distribution, perform layered protection processing on the data to be transmitted to generate a protection priority sequence; S3. Identify high-risk data in the protection priority sequence and assess the stability indicators of the transmission environment; S4. Perform adaptation and protection processing on the data to be transmitted according to the stability index, and calculate the protection requirement intensity; S5. Based on the protection requirement strength, perform a trust assessment on the receiving device to determine the final protection strength configuration; S6. Calculate the trust level of the receiving device based on the final protection strength configuration, and formulate a path optimization scheme; S7. Simulate the transmission process according to the path optimization scheme, adjust the distributed protection strategy, update the path optimization scheme, and output the final transmission configuration scheme.

[0007] Secondly, this application provides a cross-platform secure data exchange system that integrates AI and privacy computing, the system comprising: The metadata decomposition module is used to obtain the metadata information of the data to be transmitted, perform in-depth decomposition of the metadata information, and determine the sensitivity level distribution of the data to be transmitted. The hierarchical protection processing module is used to perform hierarchical protection processing on the data to be transmitted according to the sensitivity level distribution, and generate a protection priority sequence; The transmission environment assessment module is used to identify high-risk data in the protection priority sequence and assess the stability indicators of the transmission environment. The adaptation protection calculation module is used to perform adaptation protection processing on the data to be transmitted based on the stability index and calculate the protection requirement strength. The trust assessment and matching module is used to perform a trust assessment on the receiving device based on the protection requirement strength, and determine the final protection strength configuration. The path optimization formulation module is used to calculate the trust level of the receiving device based on the final protection strength configuration and formulate a path optimization scheme. The simulation adjustment output module is used to simulate the transmission process according to the path optimization scheme, adjust the distributed protection strategy, update the path optimization scheme, and output the final transmission configuration scheme.

[0008] Thirdly, this application provides a computer device in which the memory stores machine-readable instructions executable by the processor. When the computer device is running, the processor communicates with the memory via a bus. When the machine-readable instructions are executed by the processor, the steps of the above-described method for secure cross-platform data exchange that integrates AI and privacy computing are performed.

[0009] Compared with the prior art, the beneficial effects of the present invention are at least as follows: The technical solution provided in this application achieves precise and dynamic data protection by integrating artificial intelligence (AI) and privacy computing technologies. Compared with existing technologies, this solution accurately identifies the sensitivity level of data by deeply analyzing data metadata and combining it with contextual semantic analysis technology, and then provides layered protection based on this information. This approach ensures that highly sensitive data receives stronger protection first, while less sensitive data is protected using a lighter protection strategy, thereby effectively improving the efficiency and accuracy of data protection. This invention also introduces a dynamic transmission environment assessment mechanism. By monitoring transmission environment parameters such as network fluctuations and latency in real time, the system can dynamically adjust the data protection strategy according to changes in the environment. Compared with the static protection strategies in existing technologies, this is more adaptable to complex and unstable network environments, ensuring that data maintains high security under different transmission conditions. This invention employs a trust assessment method based on behavioral intent inference to intelligently assess the trust level of the receiving device and dynamically adjust the protection strength based on the assessment results. This intelligent trust assessment mechanism is more flexible and accurate than traditional static judgment methods, and can provide personalized protection configurations based on the device's historical behavior and real-time status, significantly reducing security risks in data transmission. Attached Figure Description

[0010] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0011] Figure 1 This is a flowchart illustrating the cross-platform secure data exchange method integrating AI and privacy computing as described in this application; Figure 2 This is a flowchart illustrating the priority processing of encrypted sensitive data according to the classification in this application; Figure 3 This is a diagram showing the results of data anomaly score detection in this application; Figure 4 This is a schematic diagram of the cross-platform secure data exchange system that integrates AI and privacy computing as described in this application; Figure 5This is a schematic block diagram of the cross-platform secure data exchange device that integrates AI and privacy computing as described in this application. Detailed Implementation

[0012] This application provides a method and system for secure cross-platform data exchange that integrates AI and privacy computing. The terms "first," "second," "third," "fourth," etc. (if present) in the specification, claims, and accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in a sequence other than that illustrated or described herein. Furthermore, the terms "comprising" or "having" and any variations thereof are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or device that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.

[0013] For ease of understanding, the specific process of the embodiments of this application is described below. Please refer to [link / reference]. Figure 1 One embodiment of the cross-platform secure data exchange method integrating AI and privacy computing in this application includes: Step S1: Obtain the metadata information of the data to be transmitted, perform in-depth analysis of the metadata information, and determine the sensitivity level distribution of the data to be transmitted.

[0014] In one specific embodiment, the process of performing step S1 may specifically include the following steps: Retrieve the data to be transmitted from the data storage system and extract the metadata information of the data to be transmitted; Contextual semantic parsing technology is used to deeply decompose metadata information and extract sensitive features; Clustering algorithms are used to group sensitive features to obtain different risk patterns; Based on the frequency of different risk patterns, sensitivity levels are classified to determine the distribution of sensitivity levels of the data to be transmitted.

[0015] Specifically, the data to be transmitted is obtained from the Hadoop Distributed File System, and its metadata information is extracted. The metadata information includes the data table structure, field descriptions, data size, and data generation timestamps. Natural language processing techniques (such as Stanford CoreNLP) are used to perform dependency parsing on the field descriptions, construct a semantic relation tree, and identify and extract keywords containing personal identifiers (such as "name" and "ID number"), financial information (such as "account balance" and "transaction amount"), or health information (such as "diagnosis result" and "medical record number") as sensitive features.

[0016] The clustering process will generate feature vectors corresponding to sensitive features. Mapped to In the clusters, among which Representing the Sensitive feature vectors of each data unit Representing the Each feature dimension (such as keyword frequency, field type encoding) is used to iteratively minimize the intra-cluster sum of squares. To complete the grouping, among which Indicates the first Clusters, This represents the centroid of the cluster, thereby identifying data groups with similar sensitive attributes and forming different risk patterns.

[0017] Calculate the frequency of each risk pattern in the dataset. and set a threshold and (For example, , ).like If so, the data block corresponding to that mode is marked as "high sensitivity level"; if If so, it will be marked as "Medium Sensitivity Level"; if If a data block is not sensitive enough, it is marked as "low sensitivity level". Finally, the sensitivity level distribution, containing each data block and its corresponding sensitivity level, is determined and output.

[0018] For example, in a bank customer information transmission scenario, metadata is extracted from the customer information table. Using contextual semantic parsing technology, sensitive features "PII" (Personal Identification Information) and "financial data" are extracted from the fields "Customer Name," "ID Number," and "Annual Income." Clustering algorithms group these features, identifying feature combinations that simultaneously contain both "PII" and "financial data" as a risk pattern. Statistical analysis shows that this pattern occurs 15% of the dataset (i.e.,...). ), above the threshold Therefore, all customer records (approximately 3,000 records) under this model are classified as "high" in terms of sensitivity. This sensitivity level distribution will serve as direct input for subsequent tiered protection, ensuring that highly sensitive data is prioritized.

[0019] Step S2: Based on the sensitivity level distribution, perform layered protection processing on the data to be transmitted and generate a protection priority sequence.

[0020] In one specific embodiment, the process of performing step S2 may specifically include the following steps: Based on the distribution of sensitivity levels, the data to be transmitted is divided into different protection levels, namely, high-sensitivity data, medium-sensitivity data, and low-sensitivity data. For highly sensitive data, a layered encryption technology is used for priority protection. A distributed key management mechanism is used to restrict the initial access scope of processed highly sensitive data. Based on the protection level and initial access scope, a priority sequence for encryption protection is generated; Record the encryption processing time and method of data in the priority sequence; Develop a resource allocation strategy based on the encryption processing time and method; Map and bind priority sequences to resource allocation strategies, and output protection priority sequences.

[0021] Specifically, the data to be transmitted is clearly divided into three levels: high-sensitivity data, medium-sensitivity data, and low-sensitivity data. The classification can be directly based on the sensitivity level distribution, with data blocks marked as "high-sensitivity level" classified as high-sensitivity data, and data blocks marked as "medium-sensitivity level" and "low-sensitivity level" classified as medium-sensitivity data and low-sensitivity data, respectively.

[0022] For highly sensitive data, a layered encryption technique is employed for priority protection. Specifically, highly sensitive data is divided into two layers: a core content layer and an auxiliary metadata layer. The core content layer is encrypted using a high-strength encryption algorithm (such as AES-256-GCM), and the encryption key... Generated using a cryptographically secure random number generator; the auxiliary metadata layer is lightly encrypted (e.g., ChaCha20-Poly1305), and its key... and Different but related management. The encryption process follows the formula:

[0023]

[0024] in, and The plaintext is divided into the core layer and the metadata layer. and This corresponds to the encrypted text. This layered encryption technology ensures the highest level of protection for critical information while maintaining processing efficiency. A distributed key management mechanism is employed to restrict the initial access scope of highly sensitive processed data. Specifically, the complete data decryption key is used... (Depend on and (Synthesis) is split into the Shamir secret sharing scheme. Key fragmentation and distributed to A pre-authorized, geographically distributed key management node. Set access thresholds. (For example, The rule requires at least [number] pieces to be collected. Only by reconstructing a fragment can we obtain the desired result. This mechanism, through distributed control, strictly limits the initial access to data to a set of authorized nodes, preventing the risk of single point of leakage.

[0025] Based on the protection level and initial access scope, a priority sequence for encryption protection is generated. The sequence generation rules are as follows: (1) Place all highly sensitive data and their corresponding encrypted ciphertext blocks, along with the minimum authorized node list (i.e., the initial access range), at the very beginning of the sequence; (2) Secondly, for moderately sensitive data, standard encryption (such as AES-128) is used with a more lenient access policy; (3) Finally, there is low-sensitivity data, which can be checked for integrity or encrypted with low strength. This sequence constitutes a task list ordered by protection urgency, i.e., a priority sequence of encryption protection.

[0026] This sequence constitutes a list of tasks ordered by protection urgency, i.e., a priority sequence for cryptographic protection.

[0027] Record the encryption processing time for each data item in the priority sequence (record the moment the encryption operation is completed in Unix timestamp format). ) and encryption processing method (record the encryption algorithm used, key length, and hierarchical structure information, denoted as Based on the recorded encryption processing time and methods, a resource allocation strategy is formulated. For example, historical encryption tasks are analyzed to calculate the average processing time. For the current sequence, data layering encryption technology is used (i.e. (Identified as high-strength layered encryption) and the estimated processing time may exceed [time limit]. The data items are marked in their corresponding resource allocation tags as requiring priority allocation of high-performance computing cores and larger memory buffers. This strategy can be represented by a decision function:

[0028] The CPU, memory, and network bandwidth quotas are dynamically adjusted based on the input. The priority sequence is mapped and bound to the resource allocation strategy, outputting the final protection priority sequence. Specifically, a structured list is generated, where each entry contains: data block identifier, sensitivity level, encrypted ciphertext reference, a list of required key fragment holding node IDs (i.e., access scope), and allocated computing resource specifications. This list serves as the protection priority sequence to guide subsequent transmission preparation.

[0029] In a cross-domain medical image data exchange scenario, patient diagnostic report images are classified as highly sensitive data based on sensitivity level distribution. A layered encryption technique is applied to this data: pixel data of lesion areas in the images are encrypted using AES-256 as the core layer, while image acquisition parameters and other metadata are encrypted using lightweight encryption. A distributed key management mechanism is used to distribute decryption keys in fragments to three parties: the hospital's internal server, the regional data center, and a cloud audit node for safekeeping. Based on this, the generated encryption priority sequence places this batch of image data first, recording its encryption timestamp and algorithm identifier. The resource allocation strategy allocates dedicated GPU encryption acceleration resources based on its high-strength encryption processing history. The final output protection priority sequence explicitly guides the system to process this most sensitive data with priority and high resource guarantees, ensuring its security foundation in subsequent transmission. (Reference) Figure 2 The diagram illustrates the priority processing flow for tiered sensitive data encryption.

[0030] Step S3: Identify high-risk data in the protection priority sequence and assess the stability indicators of the transmission environment.

[0031] In one specific embodiment, the process of performing step S3 may specifically include the following steps: If high-risk data is identified from the protection priority sequence, the current status of the transmission environment is obtained through the real-time threat awareness function. High-risk data includes personal information, health information, and financial data. Based on the current status and assessment model, and combined with dynamic privacy masking technology, a comprehensive assessment of network fluctuations and latency is conducted. The stability index of the transmission environment is calculated based on the comprehensive evaluation results, and the specific parameters of network fluctuation and latency corresponding to the stability index are recorded. Generate a status report of the transmission environment based on specific parameters; Correlation analysis between status reports and stability indicators was conducted to identify the main factors affecting stability; The parameter weights of the evaluation model are adjusted based on the main factors, and the recalculated stability index is used as the final stability index.

[0032] Specifically, if high-risk data is identified from the protection priority sequence, the current state of the transmission environment is obtained through real-time threat awareness. If no high-risk data is identified, the evaluation of stability indicators and adaptation protection processing are skipped, and the preset basic security strategy is directly adopted for data transmission. The method for identifying high-risk data is as follows: based on the generated protection priority sequence, data blocks involving personal privacy, important financial information, or health records are further filtered out. If this data is leaked or tampered with, it will have a serious negative impact on individual rights or public interests, and is therefore identified as high-risk data. The preset basic security strategy refers to standardized security measures that do not rely on dynamic environment assessment and trust assessment, and includes at least: encrypting the data transmission channel using transport layer security protocols and using digital certificates to perform basic identity verification between the communicating parties. This strategy is suitable for low-risk scenarios and can reduce system overhead and improve transmission efficiency while ensuring basic communication security.

[0033] It's important to note that the "high-risk data" in this step is not the same concept as the "highly sensitive data" mentioned earlier. The specific difference lies in the classification: "highly sensitive data" is a static category based on the inherent attributes of the data content (such as whether it contains ID numbers, bank account numbers, etc.); while "high-risk data" is a subset dynamically identified based on these attributes, combined with the actual conditions of the transmission environment (such as network stability, the presence of threats, etc.). All high-risk data necessarily falls under the category of highly sensitive data, but not all highly sensitive data will be identified as high-risk data at any given moment. Only when the transmission environment of highly sensitive data is unstable or poses a potential threat will it be marked as high-risk data, triggering subsequent in-depth assessment and adaptation protection processes. This distinction ensures that protection resources can be focused on the most urgent scenarios, avoiding resource waste caused by applying the highest level of protection to all highly sensitive data.

[0034] Real-time threat awareness acquires the current state of the transmission environment. High-risk data includes, but is not limited to, personal information, health information, and financial data. Real-time threat awareness continuously collects data at the current moment through probes deployed at the network edge and core nodes. Network link state parameters, including but not limited to: end-to-end delay Network jitter Packet loss rate and available bandwidth These parameters together constitute the current state vector of the transmission environment:

[0035] Based on the current state vector Combined with a pre-defined evaluation model and dynamic privacy masking technology, a comprehensive assessment of network fluctuations and latency is performed. The initial evaluation model is a weighted evaluation function:

[0036] in, These are the normalized values ​​of the corresponding parameters (mapped to the [0, 1] interval), and the initial weights. The sum is 1. The role of dynamic privacy masking technology is to avoid directly using the raw measurements when calculating latency and jitter. and Instead, it adds noise that meets differential privacy requirements. The masked value is obtained as follows:

[0037] in, and These are end-to-end latency and network jitter after privacy masking. and From the Laplace distribution Medium sampling, scale parameter Configure based on data sensitivity. Use and By normalizing the data and substituting it into the evaluation function, a comprehensive stability assessment can be performed without exposing the precise network conditions, thus enhancing the privacy of the evaluation process.

[0038] Based on the comprehensive evaluation results, the stability index of the transmission environment is calculated. The calculation process is as follows: Substitute the normalized values ​​obtained using the masked parameters into the evaluation function to obtain a preliminary evaluation score. ; By using piecewise functions Mapped to a more interpretable stability metric ,like ,but For high stability, if ,but For the sake of stability, if ,but For low stability, the specific parameters of network fluctuations and latency corresponding to the calculation of this stability index are recorded.

[0039] Based on the recorded parameters, a status report of the transmission environment is generated. This report is a structured document that includes timestamps, measured values ​​of each parameter, parameter trends (such as comparisons with the previous period), and a basic stability score calculated based on the original parameters (without privacy masking).

[0040] Compare the status report with the calculated stability index Correlation analysis was conducted to identify the main factors affecting stability. Pearson correlation coefficient analysis was used to calculate the baseline scores of each original parameter in the status report before mapping to the stability indicators. For example, calculating the correlation coefficient between delay and baseline score. :

[0041] in, For the total number of sampled data, and It consists of the delay values ​​and corresponding scores from historical data or multiple samples taken within the same time period. and For the mean delay and the mean score, set a threshold. (e.g., 0.7), if If so, then this parameter is considered to be the main factor affecting stability.

[0042] Adjust the parameter weights of the evaluation model based on the identified key factors. For example, if the analysis shows network jitter... It is the main factor ( If so, its weight is increased in the evaluation model. At the same time, the weights of other non-primary factors are reduced accordingly, maintaining a total weight sum of 1. The adjusted weights are denoted as follows: Using the adjusted weights and the parameters masked at the current time step, the evaluation score is recalculated based on the weighted evaluation function. And mapped to a new stability index .Will This will be used as the final output of the transmission environment stability indicator for subsequent steps.

[0043] For example, when transmitting high-risk data containing patient genomic information, the real-time threat awareness function obtains the current state vector of the intercontinental link. By combining dynamic privacy masking technology, noise is added to the latency and jitter to calculate the preliminary evaluation score. , mapped to The system recorded an initial jitter of 25ms and a latency of 150ms. The generated status report showed a recent upward trend in latency. Correlation analysis revealed jitter... Correlation coefficient with baseline score This was identified as a primary factor. Therefore, the evaluation model was... The weight was increased from 0.25 to 0.4, while other weights were decreased. The result was obtained by recalculating using the new weights. The final stability metric was updated to This dynamic adjustment process more accurately reflects the dominant impact of current network fluctuations (jitter) on transmission stability, providing a precise basis for subsequent adaptation and protection decisions.

[0044] Step S4: Perform adaptation and protection processing on the data to be transmitted based on stability indicators, and calculate the protection requirement strength.

[0045] In one specific embodiment, the process of performing step S4 may specifically include the following steps: Based on stability indicators, cross-platform compatibility adaptation technology is used to perform additional protection processing on the data to be transmitted, resulting in processed data. Through a node collaborative verification mechanism, the processed data and the transmission node are securely verified through interactive communication. The results of secure interactive verification are quantified into scores, and these scores are used as the strength of protection requirements in heterogeneous environments.

[0046] Specifically, cross-platform compatibility and adaptation technologies are based on The level selection and application of different data encapsulation and hardening strategies: If For "low stability," forward error correction coding and fragmented redundant transmission strategies are applied to data (especially high-priority data blocks in the protection priority sequence). For example, Reed-Solomon encoding is used to encode data blocks into n data fragments, where any k fragments can recover the original data (n>k), adapting to high packet loss or high latency environments. Simultaneously, the data format is uniformly encapsulated into a platform-independent format (such as a JSON structure combined with Base64 encoding) to ensure parsing across heterogeneous operating systems such as Windows, Linux, Android, and iOS; if For "medium stability" or "high stability," only lightweight format normalization and integrity check codes (such as HMAC) may be applied. This process ensures that the data has stronger resistance to interference and cross-platform readability under the current estimated network stability conditions.

[0047] A node-based collaborative verification mechanism is used to securely verify the processed data against nodes along the transmission path. Before data transmission, the source node initiates a challenge-response verification process with m selected relay or target nodes (i.e., transmission nodes). The specific process is as follows: the source node generates a random number... And calculate its hash This, along with the unique identifier of the data block, is sent to each transmission node; each transmission node must use a pre-shared key or certificate. Perform the signature and return the signature result. The source node verifies all returned signatures. This collaborative verification mechanism ensures that critical nodes along the path are trustworthy and active before the data actually flows, and can collaboratively guarantee transmission security.

[0048] The results of secure interactive verification are quantified into a score, and this score is used as the strength of the protection requirements for data in heterogeneous environments. The quantification rules are as follows: The total number of nodes is set to... The number of nodes that successfully verified and returned valid signatures is ; Calculate the verification success rate: Combined with stability indicators The quantization values ​​(for example, mapping "high stability" to 1.0, "medium stability" to 0.7, and "low stability" to 0.4, denoted as ) Intensity of protection needs Calculated using a weighted formula: in, and To adjust the weights (e.g.) This reflects the contribution of node reliability and environmental instability to protection needs. This indicates that the more unstable the environment ( The lower the value, the stronger the need for protection. The final calculated... It is a value between 0 and 1, with higher values ​​indicating a stronger need for data protection in the current environment. The system will use this... The output value serves as a key decision variable, used in subsequent steps for trust assessment and protection strength configuration of the receiving device.

[0049] Step S5: Based on the protection requirement strength, perform a trust assessment on the receiving device to determine the final protection strength configuration.

[0050] In one specific embodiment, the process of performing step S5 may specifically include the following steps: Determine whether the protection demand intensity exceeds the preset intensity threshold. If so, use historical behavior tracking technology to conduct a trust assessment of the receiving device and obtain the trust score of the receiving device in the target scenario. Based on trust scoring, behavioral intent inference technology is used to predict the credibility of the receiving device in the target scenario; Based on trust scores and credibility, determine the initial protection strength configuration; For the initial protection strength configuration, the calculation process of trust score and credibility is traced back, and the trust assessment basis used to form the initial protection strength configuration is recorded. Based on the trust assessment criteria, generate a detailed trust assessment report; The detailed report is matched with the initial protection strength configuration for risk correlation, the protection strength configuration parameters are adjusted, and the final protection strength configuration is output.

[0051] Specifically, the intensity of protection demand Does it exceed the preset intensity threshold? ,like Then, a deep trust assessment process for the receiving device is initiated. Strength threshold. This is a configurable parameter, for example, set to 0.5, to trigger additional security checks in high-risk scenarios. Trust assessment of the receiving device is performed using historical behavior tracking technology to obtain a trust score for the receiving device in the target scenario. The historical behavior tracking technology analyzes the receiving device over a window of time. Historical interaction logs (e.g., within 30 days). Key behavioral features extracted include: data request success rate. Frequency of abnormal access attempts (Measures the randomness of access time distribution; the lower the entropy value, the more regular the pattern); Consumption pattern consistency index (Determined by comparing the similarity of historical request sequences). Trust Score Calculated by the following comprehensive evaluation function:

[0052] in, Positive weighting coefficients are used to adjust the contribution of each feature to trust. The calculated... Normalized to the interval [0, 100], the higher the score, the more reliable the historical behavior.

[0053] Based on the trust score Using behavioral intent inference technology, the credibility of the receiving device in the current transmission task target scenario is predicted. This technology analyzes the contextual features of the receiving device's current request, including: whether the data type and sensitivity level of the request match its historical patterns, whether the geographical location and network topology of the request source are abnormal, and whether the time of the request is within the operating mode. These features are then inferred using a pre-trained lightweight classification model (such as one based on logistic regression or a small neural network), outputting a confidence probability value between 0 and 1. This indicates the likelihood that the device's behavior is benign in the current scenario.

[0054] Based on trust rating and credibility This determines the initial protection strength configuration. Configuration decisions are made through a rule engine or decision function. For example, a comprehensive trust index can be defined:

[0055] in, This is a weight that balances historical and current intentions (e.g., 0.6). According to... The value determines the initial protection strength configuration: if (e.g., 0.8), then configure it as "low strength" (e.g., using only transport layer encryption TLS); if (e.g., 0.6), then configure it to "medium strength" (e.g., add application layer encryption and access frequency limits); if If it is 0.6, then it is configured as "high strength" (e.g., enabling homomorphic encrypted envelopes, strict session auditing and real-time behavior monitoring).

[0056] For the initial protection strength configuration, the system retrospectively examines the trust score and credibility calculation process upon which its decisions are based. Detailed records are kept of the trust assessment criteria used to form this configuration, including: the historical log time period used to calculate the trust score, the specific values ​​and weights of each behavioral feature, the context feature vector of the current request used to calculate credibility, and the version and inference results of the classification model. Based on the recorded trust assessment criteria, a structured, detailed trust assessment report is generated. This report includes the assessment timestamp, the receiver device identifier, and the calculated... and The analysis of values, contribution of each sub-item, and the derivation of the decision path for the preliminary protection strength configuration are explained.

[0057] The detailed report is matched against the initial protection strength configuration for risk correlation, the protection strength configuration parameters are adjusted, and the final protection strength configuration is output. This process involves a review step: the report content is verified by the risk policies set by the system or administrator. For example, if the report shows that although... The value is relatively high (corresponding to a "low intensity" initial configuration), but the credibility is low. The lower protection level is primarily due to the rarity of the requested geographical location, while the known network risk in that area is high. In such cases, the risk management strategy may require increased protection strength. Adjustments can be made manually or automatically fine-tuned via a policy function. Ultimately, the system outputs a definitive final protection strength configuration, specifying the encryption algorithms, key length, access control policies, audit levels, and monitoring frequency to be used. For example, in a scenario involving the transmission of confidential business data to an external partner's server, the required protection strength might be... This triggers an assessment. Historical behavior tracking technology calculates the partner server's performance over the past 30 days. Behavioral intent inference analysis revealed that the request time was normal, but the requested data range was slightly wider than historical patterns, leading to the conclusion that... Calculate the overall credibility index: The initial protection strength configuration is set to "medium strength" according to the rules. The system records all calculations and generates a report. After reviewing the report, the risk strategy module automatically adjusts the configuration from "medium strength" to "medium-high strength" based on the risk point of "expanded data scope." Specifically, this means that in addition to application-layer encryption, real-time watermarking and abnormal traffic detection are added to the data transmission process. This adjusted scheme is the final protection strength configuration, which strengthens the protection against specific identified risks while balancing efficiency.

[0058] Step S6: Calculate the trust level of the receiving device based on the final protection strength configuration, and formulate a path optimization scheme.

[0059] In one specific embodiment, the process of performing step S6 may specifically include the following steps: Based on the final protection strength configuration, a dynamic trust update mechanism is used to calculate the trust level of the receiving device. Based on trust levels and combined with abnormal behavior detection technology, the status of the transmission path is monitored; Obtain abnormal behavior data of the transmission path from the transmission path status; Develop a path optimization plan based on abnormal behavior data.

[0060] Specifically, a dynamic trust update mechanism is adopted to adjust the verification results of the receiving device in real time and calculate its dynamic trust level. This mechanism not only relies on historical assessments but also collects real-time data on the receiver's interactive behavior during the transmission preparation phase, based on the monitoring level required by the final protection strength configuration. For example, if configured for "high strength," the system monitors details of its connection handshake protocol, the stability of heartbeat intervals, and latency in responding to challenges. A short-term behavior window is defined. (e.g., the last 5 minutes), calculate the compliance score of the behavior within that window. Dynamic trust level Based on historical trust scores (From step S5) Determined together with the real-time compliance score:

[0061] in, It's the attenuation factor; the higher the configuration requirements, the better. The lower the value, the higher the weight given to real-time behavior. This dynamic trust update mechanism ensures that the device's trust level reflects its latest behavior.

[0062] Based on the calculated dynamic trust level This technology, combined with anomaly behavior detection technology, enables real-time monitoring of transmission path stability. It deploys lightweight agents at key nodes in the transmission path (such as ingress gateways, core switches, and egress proxies) to continuously collect path performance and behavioral metrics, including but not limited to throughput fluctuations, packet round-trip time variation rates, connection reconnection frequency, and the proportion of protocol-level abnormal packets. These metrics are correlated with trust levels: when... At lower levels, the system pays more attention to any minor fluctuations along the same path and marks them as potential anomalous behavior.

[0063] The system sets a series of thresholds (which can be dynamic, and...). We use negative correlation to determine what constitutes an anomaly. For example, when When the round-trip time of a data packet changes by more than 50ms, it is considered abnormal behavior data. This data is recorded, including the anomaly type, the timestamp of occurrence, the involved path nodes, and the associated metric values.

[0064] Based on the collected abnormal behavior data, a path optimization scheme is formulated. The optimization decision is based on a multi-objective cost function, aiming to maximize path stability (minimize anomaly risk) and transmission efficiency, while considering dynamic trust levels. The specific process includes: identifying whether the anomaly is an isolated event or concentrated in a specific path segment (e.g., from node A to B); identifying available alternative transmission paths based on the network topology; and predicting the stability of each candidate path. The prediction method references historical performance data and the current network state, and considers the trust level of the receiving device. If the value is low, the system tends to choose paths that pass through more trusted nodes (such as the corporate intranet) or nodes with stronger monitoring capabilities; and outputs optimized path solutions.

[0065] In a scenario where sensitive notifications are pushed to a mobile terminal, the final protection strength configuration requires "high-intensity" monitoring. The dynamic trust update mechanism detects irregular heartbeat packets from the terminal during the connection warm-up phase, leading to... The value dropped to 0.55. The anomaly detection technology then intensified monitoring and detected sudden, high-frequency, brief connection interruptions (anomaly data) on the current 4G transmission path. Analysis indicated that this path segment was unreliable under the current circumstances. The system then evaluated available Wi-Fi direct paths and another 4G carrier path. Combined with... In cases with lower bandwidth, the Wi-Fi path through the enterprise security gateway, although with slightly lower bandwidth, was prioritized as the optimized path, and it was recommended to perform more granular verification of data packets during transmission.

[0066] Step S7: Simulate the transmission process according to the path optimization scheme, adjust the distributed protection strategy, update the path optimization scheme, and output the final transmission configuration scheme.

[0067] In one specific embodiment, the process of performing step S7 may specifically include the following steps: Based on the path optimization scheme, risk scenario simulation technology is used to perform distributed protection processing on the layered data blocks, and then the simulated transmission process is entered. By using real-time anomaly detection technology, potential anomalies during the transmission process can be intercepted. Based on the risk interception results, a risk report is generated during the transmission process; For risk reports, record the specific types of potential anomalies and the handling methods; Adjust the distributed protection strategy based on the specific type and processing method; The path optimization scheme is updated based on the adjusted distributed protection strategy, and the final transmission configuration scheme is output.

[0068] Specifically, risk scenario simulation technology is used to perform distributed protection processing on the layered data blocks and then enter the simulated transmission process. Specifically, risk scenario simulation technology constructs a high-fidelity virtual transmission sandbox environment based on the path topology and node attributes specified in the optimized path scheme. In this sandbox, the system will "pre-transmit" the layered encrypted data blocks (core ciphertext blocks, metadata ciphertext blocks, etc.) defined in the protection priority sequence, according to the main path, backup path, or multiple parallel paths planned in the scheme. During the simulation, a series of preset or historically generated risk scenarios are injected, such as simulating sudden high latency or packet loss at a specific intermediate node, simulating sniffing attacks on a segment of the path, and simulating sudden deviations in the behavior of the receiving node from the expected pattern. The purpose of the simulation is to evaluate whether the distributed deployment of data blocks can effectively resist these risks under the current optimized path scheme, and to test the triggering conditions and efficiency of mechanisms such as data recovery and path switching.

[0069] Real-time anomaly detection technology (serving as a monitoring module in the simulated environment) is used to intercept potential anomalies during simulated transmission. This technology is a specific application and deepening of real-time threat perception functionality in a simulated environment. It continuously analyzes the simulated data stream and uses pattern recognition algorithms. These algorithms are trained using time-series data of various indicators from "normal" transmission during the risk-free injection phase to establish a baseline model of normal behavior (the isolated forest anomaly detection model). Specifically, the implementation of the isolated forest anomaly detection model is an unsupervised anomaly detection method based on ensemble learning. Its core idea is that anomalous data points, due to their scarcity and unique feature values, are more easily and quickly "isolated" in the feature space. The model's construction begins with collecting multi-dimensional time-series indicator data from the normal transmission process during the risk-free injection phase. These indicators constitute a feature vector, specifically including dimensions such as packet arrival interval, network jitter variance, CPU and memory utilization of key nodes, protocol handshake response latency, control signaling interaction frequency, and the proportion of encrypted data blocks in the total traffic. After standardizing these raw features, the model is trained by constructing multiple "isolated trees." Each tree is constructed using a random subsampling and random feature segmentation strategy: a subset of samples is randomly extracted from the training data; a feature dimension is randomly selected at each node of the tree, and a segmentation point is randomly determined within its value range; the sample space is recursively bisected until termination conditions such as uniqueness of samples in a node, complete consistency of sample features, or reaching a preset depth are met. This recursive segmentation ensures that anomalous samples, due to their feature values ​​deviating from the mainstream distribution, are often isolated to individual leaf nodes at a relatively shallow depth. To improve detection stability, the model integrates multiple isolated trees to form a "forest." For the data points to be detected, the average path length (the average number of edges from the root node to a leaf node) is calculated by traversing all trees. This average path length is then converted into an anomaly score between 0 and 1 using a normalization formula. The closer the score is to 1, the easier it is to isolate the point, and the higher the probability of an anomaly. In real-time monitoring, the model inputs the transmission indicator feature vector for each time window. If the output anomaly score exceeds a preset threshold (e.g., 0.65), it is identified as a potential anomaly. For example, an unencrypted fragment appearing in an encrypted stream will result in a high score due to its features deviating from the normal baseline. This process allows the model to learn the multidimensional joint distribution of normal behavior without relying on anomalous samples and to identify anomalous patterns that significantly deviate from the baseline in real time.

[0070] Based on the baseline model, the system detects potential anomalies in real time that deviate from the normal baseline or match known attack characteristics. Examples include unencrypted data fragments appearing outside a predefined secure channel, severe disruptions in the arrival order of data blocks that cannot be explained by network jitter, or the simulated "receiver" using an unauthorized key version in a decryption request. Once such potential anomalies are detected, the simulation system immediately triggers pre-defined risk interception rules, such as isolating the abnormal data stream, issuing an alarm to the simulation's control center, or forcibly initiating a switchover process to an alternative path. (Reference) Figure 3 The figure illustrates the effectiveness of data anomaly score detection.

[0071] Based on the results of risk interception, a risk report is generated during the transmission process. This report details how many interceptions were triggered during the simulation, the type of risk scenario corresponding to each interception, the interception actions (such as isolation, alarm, and handover), whether the interception was successful, and the impact of the interception on the overall latency and integrity of the simulated transmission task. The report also provides a quantitative score for the robustness of the optimized path scheme, such as calculating the "proportion of successfully mitigated risk scenarios" or "mean time to recover from failure."

[0072] Record the specific type of each potential anomaly that is intercepted (such as "path sniffing attempt", "data reassembly disorder", "key usage anomaly") and its corresponding handling method (such as "traffic redirection to encrypted tunnel", "initiating data retransmission request", "revoking and updating session key"). These records constitute a "risk-response" mapping knowledge base for subsequent policy optimization.

[0073] Analyzing the simulation results reveals that a certain type of anomaly occurs frequently and the existing handling methods are inefficient (e.g., excessively long recovery times), the strategy should be optimized. For example, if the simulation shows that data retransmission causes a surge in latency under specific network congestion scenarios, the strategy might be adjusted as follows: (1) Increase forward error correction redundancy for this type of high-risk data block; (2) Pre-set a fast switching path with lower latency in the path scheme.

[0074] The strategy adjustment process is iterative, aiming to make the distributed protection mechanism more intelligent and proactive in adapting to the vulnerabilities exposed in the simulation.

[0075] Based on the adjusted distributed protection strategy, the path optimization scheme is updated. For example, the newly added fast switching path node information, the adjusted data block distribution rules (such as which data blocks require higher redundancy), and the updated exception response protocol are integrated into the original optimized path scheme. The update process ensures that the strategy and the path are logically consistent.

[0076] Based on the updated path optimization scheme, which has been validated through simulation and enhanced with improved policies, and the associated adjusted distributed protection strategy, the system outputs a detailed and executable final transmission configuration scheme. This scheme is a structured instruction set, including at least: the mapping relationship between data blocks and target paths, the specific security protocols and encryption parameters to be enabled on each path segment, anomaly monitoring thresholds and response actions, key distribution and update plans, and preset failover procedures. This scheme signifies the completion of transmission preparation and can be directly loaded into the actual data transmission engine to perform secure and reliable cross-platform data exchange.

[0077] In a multinational data center synchronization scenario, the optimized path scheme planned a primary path via submarine fiber optic cable and a backup path via satellite link. Risk scenario simulation technology simulated scenarios of primary path fiber optic cable interruption and satellite link encountering strong interference. Real-time anomaly detection technology successfully intercepted data stream interruptions caused by the interruption in the simulation and triggered a switchover. The risk report indicated that after switching to the satellite link, due to bandwidth limitations, the transmission latency of large core encrypted data blocks exceeded the standard. Based on this, the system adjusted its distributed protection strategy, adding a more efficient data compression preprocessing step for core data blocks. The path optimization scheme was updated, adding an "Enable Compression" flag to the satellite link transmission command. The final output transmission configuration scheme clearly stipulates: full transmission when the primary path is normal; once an interruption is detected, automatic switch to the satellite link is initiated, and core data blocks are compressed before transmission, while adjusting end-to-end timeout parameters. This scheme achieves a simulation-verified balance between security and availability.

[0078] It is understood that the executing entity of this application can be a cross-platform secure data exchange system integrating AI and privacy computing, or it can be a terminal or a server; the specific implementation is not limited here. This application's embodiments use a server as an example for illustration.

[0079] The cross-platform secure data exchange method integrating AI and privacy computing in the embodiments of this application has been described above. The cross-platform secure data exchange system integrating AI and privacy computing in the embodiments of this application is described below. Please refer to... Figure 4 One embodiment of the cross-platform secure data exchange system integrating AI and privacy computing in this application includes: The metadata decomposition module is used to obtain the metadata information of the data to be transmitted, perform in-depth decomposition of the metadata information, and determine the sensitivity level distribution of the data to be transmitted. The hierarchical protection processing module is used to perform hierarchical protection processing on the data to be transmitted according to the distribution of sensitivity levels, and generate a protection priority sequence. The transmission environment assessment module is used to identify high-risk data in the protection priority sequence and assess the stability indicators of the transmission environment. The adaptation protection calculation module is used to perform adaptation protection processing on the data to be transmitted based on stability indicators and to calculate the protection requirement strength. The trust assessment and matching module is used to perform a trust assessment on the receiving device based on the strength of protection requirements, and to determine the final protection strength configuration. The path optimization module is used to calculate the trust level of the receiving device based on the final protection strength configuration and to formulate a path optimization scheme. The simulation adjustment output module is used to simulate the transmission process according to the path optimization scheme, adjust the distributed protection strategy, update the path optimization scheme, and output the final transmission configuration scheme.

[0080] Through the collaborative efforts of the aforementioned components, the system achieves closed-loop management of the entire process, from intelligent identification of data sensitivity, layered dynamic encryption, real-time assessment of the transmission environment, cross-platform adaptation protection, dynamic trust assessment of the receiver, and optimization of the transmission path to risk simulation verification. This forms a cross-platform secure exchange system that can adapt to complex network environments and ensure data privacy and integrity.

[0081] above Figure 4 The cross-platform secure data exchange system integrating AI and privacy computing in this embodiment of the invention is described in detail from the perspective of modular functional entities. The cross-platform secure data exchange device integrating AI and privacy computing in this embodiment of the invention is described in detail from the perspective of hardware processing.

[0082] Reference Figure 5 This invention also provides a cross-platform secure data exchange device that integrates AI and privacy computing. This device can be a server, and its internal structure can be as follows: Figure 5 As shown, this cross-platform secure data exchange device integrating AI and privacy computing includes a processor, memory, display screen, input device, network interface, and database connected via a system bus. The processor in this computer design provides computing and control capabilities. The memory of this cross-platform secure data exchange device integrating AI and privacy computing includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The database of this cross-platform secure data exchange device integrating AI and privacy computing is used to store the data corresponding to this embodiment. The network interface of this cross-platform secure data exchange device integrating AI and privacy computing is used for communication with external terminals via network connection. When the computer program is executed by the processor, it implements the above-described method.

[0083] Those skilled in the art will understand that Figure 5The structure shown is merely a block diagram of a portion of the structure related to the present invention and does not constitute a limitation on the cross-platform secure data exchange device that integrates AI and privacy computing applied to the present invention.

[0084] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A method for secure cross-platform data exchange integrating AI and privacy computing, characterized in that, The method includes: S1. Obtain the metadata information of the data to be transmitted, perform in-depth analysis of the metadata information, and determine the sensitivity level distribution of the data to be transmitted. S2. Based on the sensitivity level distribution, perform layered protection processing on the data to be transmitted to generate a protection priority sequence; S3. Identify high-risk data in the protection priority sequence and assess the stability indicators of the transmission environment; S4. Perform adaptation and protection processing on the data to be transmitted according to the stability index, and calculate the protection requirement intensity; S5. Based on the protection requirement strength, perform a trust assessment on the receiving device to determine the final protection strength configuration; S6. Calculate the trust level of the receiving device based on the final protection strength configuration, and formulate a path optimization scheme; S7. Simulate the transmission process according to the path optimization scheme, adjust the distributed protection strategy, update the path optimization scheme, and output the final transmission configuration scheme.

2. The cross-platform secure data exchange method integrating AI and privacy computing according to claim 1, characterized in that, S1 includes: The data to be transmitted is obtained from the data storage system, and the metadata information of the data to be transmitted is extracted. The metadata information is deeply decomposed using contextual semantic parsing technology to extract sensitive features; Clustering algorithms are used to group the sensitive features to obtain different risk patterns; Based on the frequency of the different risk patterns, sensitivity levels are classified, and the sensitivity level distribution of the data to be transmitted is determined.

3. The cross-platform secure data exchange method integrating AI and privacy computing according to claim 1, characterized in that, S2 includes: Based on the sensitivity level distribution, the data to be transmitted is divided into different protection levels, namely, high-sensitivity data, medium-sensitivity data, and low-sensitivity data. For the highly sensitive data, a layered data encryption technique is used for priority protection. A distributed key management mechanism is used to restrict the initial access scope of processed highly sensitive data. Based on the protection level and the initial access range, a priority sequence for encryption protection is generated; Record the encryption processing time and encryption method of the data in the priority sequence; Based on the encryption processing time and the encryption processing method, a resource allocation strategy is formulated; The priority sequence is mapped and bound to the resource allocation strategy, and a protection priority sequence is output.

4. The method according to claim 3, characterized in that, S3 includes: If high-risk data is identified from the protection priority sequence, the current state of the transmission environment is obtained through the real-time threat awareness function. The high-risk data includes personal information, health information, and financial data. Based on the current state and evaluation model, and combined with dynamic privacy masking technology, a comprehensive assessment of network fluctuations and latency is conducted. The stability index of the transmission environment is calculated based on the comprehensive evaluation results, and the specific parameters of network fluctuation and latency corresponding to the stability index are recorded. Based on the specific parameters, a status report of the transmission environment is generated; The status reports are correlated with stability indicators to identify the main factors affecting stability; The parameter weights of the evaluation model are adjusted based on the main factors mentioned above, and the recalculated stability index is used as the final stability index.

5. The method according to claim 1, characterized in that, S4 includes: Based on the stability index, cross-platform compatibility adaptation technology is used to perform additional protection processing on the data to be transmitted, resulting in processed data. The processed data and the transmission node are securely verified through a node collaborative verification mechanism. The results of secure interactive verification are quantified into scores, and these scores are used as the strength of protection requirements in heterogeneous environments.

6. The method according to claim 1, characterized in that, S5 includes: Determine whether the protection requirement intensity exceeds a preset intensity threshold. If so, perform a trust assessment on the receiving device using historical behavior tracking technology to obtain a trust score for the receiving device in the target scenario. Based on the trust score, behavioral intent inference technology is used to predict the credibility of the receiving device in the target scenario. Based on the trust score and the credibility, a preliminary protection strength configuration is determined; For the initial protection strength configuration, the calculation process of the trust score and the credibility is traced back, and the trust assessment basis used to form the initial protection strength configuration is recorded; Based on the aforementioned trust assessment criteria, a detailed trust assessment report is generated; The detailed report is matched with the initial protection strength configuration for risk correlation, the protection strength configuration parameters are adjusted, and the final protection strength configuration is output.

7. The method according to claim 6, characterized in that, S6 includes: Based on the final protection strength configuration, a dynamic trust update mechanism is used to calculate the trust level of the receiving device. Based on the aforementioned level of trust, and combined with abnormal behavior detection technology, the status of the transmission path is monitored; Obtain abnormal behavior data of the transmission path from the transmission path status; Based on the abnormal behavior data, a path optimization plan is formulated.

8. The method according to claim 1, characterized in that, S7 includes: According to the path optimization scheme, risk scenario simulation technology is used to perform distributed protection processing on the data blocks after layered processing, and then enters the simulated transmission process; By using real-time anomaly detection technology, potential anomalies in the transmission process can be intercepted. Based on the risk interception results, a risk report is generated during the transmission process; For the aforementioned risk report, record the specific types of potential anomalies and the handling methods; Based on the specific type and processing method, adjust the distributed protection strategy; The path optimization scheme is updated according to the adjusted distributed protection strategy, and the final transmission configuration scheme is output.

9. A cross-platform secure data exchange system integrating AI and privacy computing, used to implement the method as described in any one of claims 1-8, characterized in that, The cross-platform secure data exchange system that integrates AI and privacy computing includes: The metadata decomposition module is used to obtain the metadata information of the data to be transmitted, perform in-depth decomposition of the metadata information, and determine the sensitivity level distribution of the data to be transmitted. The hierarchical protection processing module is used to perform hierarchical protection processing on the data to be transmitted according to the sensitivity level distribution, and generate a protection priority sequence; The transmission environment assessment module is used to identify high-risk data in the protection priority sequence and assess the stability indicators of the transmission environment. The adaptation protection calculation module is used to perform adaptation protection processing on the data to be transmitted based on the stability index and calculate the protection requirement strength. The trust assessment and matching module is used to perform a trust assessment on the receiving device based on the protection requirement strength, and determine the final protection strength configuration. The path optimization formulation module is used to calculate the trust level of the receiving device based on the final protection strength configuration and formulate a path optimization scheme. The simulation adjustment output module is used to simulate the transmission process according to the path optimization scheme, adjust the distributed protection strategy, update the path optimization scheme, and output the final transmission configuration scheme.

10. A cross-platform secure data exchange device integrating AI and privacy computing, characterized in that: The device includes: a memory and at least one processor, wherein the memory stores instructions; The at least one processor invokes the instructions in the memory to cause the data cross-platform secure exchange device for integrating AI and privacy computing to perform the data cross-platform secure exchange method for integrating AI and privacy computing as described in any one of claims 1-8.