Identity recognition-based data security collaborative computing method and system

CN122548723APending Publication Date: 2026-08-11ANHUI CHENTU BIG DATA TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-04-29
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

但是在实际部署中仍存在问题,参与方身份可信与准入控制往往停留在静态账号认证或单次登录校验,难以实现与轮次、权限、密钥材料动态联动的会话级隔离与撤销控制,易出现越权参与、撤销不及时、密钥复用导致的横向风险扩散;协同计算过程中的提交物、轮次节奏与结果发布缺少统一的可验证链路,参与方可能通过提前获知他方提交物进行策略性调整,或在提交窗口内外实施投机行为,使协同流程的公平性、可控性与可追责性难以保证

Benefits of technology

本发明通过将身份认证得到的身份鉴别信息与权限状态矩阵、闭合相位编码生成的单次有效权限波形帧进行联动,实现了多方协同计算中的身份可信准入与授权边界的细粒度表达;进一步结合时间锁谜题处理中身份分段-密钥拼图的门限份额化拆分与单向微能量累积物理计时生成的轮次解锁因子,使权限、密钥与轮次时窗形成一致的受控解锁链路,从而实现会话隔离、动态联动与可撤销,降低越权参与、密钥复用与提前投机带来的风险,并确保协同计算流程在轮次级别的可控性与公平性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122548723A_ABST
    Figure CN122548723A_ABST
Patent Text Reader

Abstract

This invention discloses a data security collaborative computing method and system based on identity recognition, belonging to the field of data processing technology. The method includes: receiving a task request to complete identity authentication and obtain identity verification information; constructing a permission state matrix and generating a single valid permission waveform frame; performing time-lock puzzle processing to generate a controlled unlocking parameter set; triggering random phase modulation mapping to form a set of optical residual data blocks; constructing an improved ERFNet network and outputting the submission and corresponding digest; performing digest consistency verification and generating the computation result and result digest. This invention achieves controllable process and reliable, verifiable results in multi-party collaborative computing through threshold key puzzles, physical timing unlocking, and controlled inference submissions using an improved ERFNet network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, and in particular to a data security collaborative computing method and system based on identity recognition. Background Technology

[0002] Existing multi-party collaborative computing technologies are widely used in cross-institutional data joint analysis, joint modeling, and distributed inference scenarios. The core requirement is to complete computational tasks and obtain usable results without directly aggregating raw data. Existing solutions typically employ centralized or consortium-style task orchestration, where participating nodes complete feature extraction, model training, or inference locally and then submit intermediate results, which are then aggregated and computed by the coordinator. However, problems remain in actual deployment. The credibility of participant identities and access control often remain at the level of static account authentication or single login verification, making it difficult to achieve session-level isolation and revocation control that is dynamically linked to rounds, permissions, and key materials. This can easily lead to unauthorized participation, untimely revocation, and horizontal risk diffusion caused by key reuse. Furthermore, the collaborative computing process lacks a unified and verifiable link for submissions, round rhythms, and result publication. Participants may make strategic adjustments by knowing the submissions of others in advance, or engage in speculative behavior inside or outside the submission window, making it difficult to guarantee the fairness, controllability, and accountability of the collaborative process.

[0003] To reduce bandwidth and computing power overhead and improve real-time capabilities on the edge, lightweight semantic segmentation networks or efficient feature extraction networks are often used in engineering to generate submissions at edge nodes. However, existing lightweight networks are prone to output jitter in scenarios with unstable inputs, temporal noise, or boundary details. The output features often retain strong data reversibility characteristics, posing a risk of inferring the original data content from the submissions. Existing time delay control methods mostly rely on pure computational delays or single timing logic, which makes it difficult to ensure uniform non-preemptiveness in heterogeneous hardware environments. It is also difficult to bind the delay process with identity thresholds and key share reconstruction collaborative logic. Therefore, it is impossible to simultaneously meet the comprehensive requirements of identity-driven dynamic linkage of permissions and keys, secure and controllable collaborative computing process, reliable and verifiable results, and audit traceability and accountability capabilities.

[0004] Therefore, how to provide a data security collaborative computing method and system based on identity recognition is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0005] One objective of this invention is to propose a data security collaborative computing method and system based on identity recognition. This invention employs identity authentication to generate identity verification information and constructs a permission state matrix. It generates a single-use valid permission waveform frame through closed-phase encoding. A time-lock puzzle is executed, and session key material is generated based on the permission state matrix and permission waveform frame. A round unlocking factor is generated by combining threshold fractional splitting of the identity segmentation-key puzzle with unidirectional micro-energy accumulation physical timing, forming a controlled unlocking parameter set. Based on the controlled unlocking parameter set, the local original data undergoes controlled transformation to form a set of optical residual data blocks. An improved ERFNet network is constructed to complete event pulse coding, reversible spectral mixing, and sparse gated hash interconnection inference. The submitted items and digest are output, and after consistency verification within the submission window, collaborative computing is performed to generate the result and result digest. This achieves trusted access, dynamic linkage of permissions and keys, session isolation and revocability in multi-party collaborative computing, and ensures process controllability, result reliability, and audit traceability without exposing the original data.

[0006] A data security collaborative computing method based on identity recognition according to an embodiment of the present invention includes: Receive collaborative computing task requests, collect the identity credentials of participating nodes and complete identity authentication to obtain the identity authentication information of participating nodes; Based on the identity authentication information, an access status matrix is ​​constructed, and closed-phase encoding is used to perform time slot and phase offset to generate a single valid access waveform frame. The execution time lock puzzle is processed by generating session key material based on the permission state matrix and single valid permission waveform frame. The session key material is fractionally split and threshold parameters are set by using identity segmentation-key puzzle. Physical timing is performed by unidirectional micro-energy accumulation and round unlocking factors are generated to generate a controlled unlocking parameter set. A controlled transformation is performed on the local raw data based on the controlled unlocking parameter set, and a random phase modulation mapping is triggered by the round unlocking factor to form a set of optical residual data blocks. An improved ERFNet network is constructed to perform inference computation on the optical residual data block set. Temporal pulsed representation is performed based on the event pulse coding layer. Frequency domain reversible coupling and mixing are performed using the reversible spectral mixing layer. Hash bucket interconnection and gated sparse write-back are performed through the sparse gated hash interconnection layer. The output submissions and corresponding summaries are then provided. Upload the submission item, corresponding summary, round unlock factor, and identity authentication information in the submission window, perform summary consistency verification, and execute collaborative computing to generate calculation results and result summary.

[0007] Optionally, the identity authentication information includes a unique identity identifier, a set of identity attributes, a trust level marker, a revocation status marker, an identity authentication completion timestamp, and an identity credential content digest value.

[0008] Optionally, obtaining the identity authentication information of the participating nodes includes: Receive collaborative computing task requests and generate task identifiers; collect the original identity credential data uploaded by participating nodes, including participating node certificate chain data, participating node device identifier data, and participating node signature response data. Perform integrity and validity checks on the original identity credential data, verify the signatures of the participating nodes' signature response data, verify the chain of the participating nodes' certificate chains, and determine the revocation status flag of the participating nodes based on the revocation information. After the original identity credential data passes verification, identity authentication information is generated and stored in association with the task identifier.

[0009] Optionally, constructing the permission state matrix and generating a single valid permission waveform frame includes: Receive identity authentication information and extract the identity attribute set, map the identity attribute set according to the permission dimension set, and generate a permission status matrix. The matrix unit of the permission status matrix takes a binary value, which includes allowed value and denied value. The time slot sequence and phase offset sequence are generated based on the permission status matrix. The time slot sequence consists of multiple consecutive time slots with the same width. The phase offset sequence corresponds to the time slot sequence, and the phase offset of each phase in the phase offset sequence is determined by the value of the corresponding matrix unit. Closed-phase encoding is performed on the time slot sequence to generate a single valid permission waveform frame. The single valid permission waveform frame includes a frame identifier, time slot width, number of time slots, phase offset sequence, and effective time window length. The single valid permission waveform frame is associated with the identity authentication information and sent out.

[0010] Optionally, generating the controlled unlock parameter set includes: Receive the permission status matrix and a single valid permission waveform frame. Generate session key material based on the set of matrix unit values ​​of the permission status matrix and the phase offset sequence of the single valid permission waveform frame. The session key material includes a session key seed, a session identifier binding value, and a round identifier binding value. The session key material is processed by identity segmentation and key puzzle. The number of shares is determined according to the number of participating nodes and a threshold parameter is set. The session key seed is fractionally split according to the threshold parameter to generate a key share set. The key share set is bound according to the unique identity identifier in the identity authentication information, and a share identifier and share verification digest are generated for each key share to form a key puzzle parameter set. Perform unidirectional micro-energy accumulation physical timing processing on a single valid permission waveform frame to generate a round unlocking factor. The unidirectional micro-energy accumulation physical timing processing includes controlling the energy accumulation window according to the effective time window length, collecting the charge integration sequence of the energy accumulation process and determining the accumulation completion status with a preset threshold, and outputting the round unlocking factor and generating an unlock verification summary when the accumulation completion status is established. The key puzzle parameter set is associated and encapsulated with the round unlocking factor to generate a controlled unlocking parameter set. The controlled unlocking parameter set includes threshold parameters, key share set, share identifier set, share verification digest set, round unlocking factor and unlocking verification digest. The controlled unlocking parameter set is associated with the session identifier and round identifier, stored and distributed.

[0011] Optionally, forming the set of optical residual data blocks includes: Receive the controlled unlock parameter set and extract the round unlock factor and session key material. Generate a random phase modulation seed based on the round unlock factor and round identifier. The random phase modulation seed is obtained by concatenating the round unlock factor and round identifier and inputting it into a hash mapping. The local raw data is subjected to random phase modulation mapping and propagated through a scattering medium to generate a speckle map. The random phase modulation mapping includes converting the local raw data into an amplitude matrix and superimposing it with the random phase matrix in the complex field. The complex field superposition is the multiplication of the amplitude matrix with an exponential phase matrix. The exponential phase matrix is ​​an exponential matrix with the natural constant as the base and the exponent as the imaginary unit multiplied by the phase value. The phase value of the random phase matrix is ​​generated by a pseudo-random sequence driven by a random phase modulation seed. The speckle pattern is meshed and residual quantized to form a set of optical residual data blocks. The speckle pattern is divided into multiple grid cells according to a preset grid size. The residual energy value is calculated for each grid cell and a speckle energy residual vector is formed. The speckle energy residual vector is quantized according to the quantization threshold to generate a round hash string. The round hash string is combined with the residual energy value corresponding to each grid cell to generate a set of optical residual data blocks.

[0012] Optionally, the output submission and the corresponding summary include: An improved ERFNet network is constructed by setting an event pulse coding layer at the input of the original ERFNet network and connecting the output of the event pulse coding layer to the encoder input of the original ERFNet network. At the non-bottleneck block positions of the original encoder, a set of non-bottleneck blocks are replaced with a reversible spectral mixing layer while keeping the number of output channels and spatial resolution of the encoder unchanged. A sparse gated hash interconnection layer is set between the output of the original encoder and the decoder input, and the output of the sparse gated hash interconnection layer is connected to the decoder of the original ERFNet network. The optical residual data block set is subjected to temporal pulsed characterization based on the event pulse coding layer. The optical residual data block set is formed into a time series according to the sampling interval. The difference matrix is ​​calculated for adjacent time series elements. The difference matrix is ​​symbolically quantized according to a preset threshold to obtain the pulse sequence and output the pulse feature tensor. Based on the reversible spectral mixing layer, frequency domain reversible coupling mixing is performed on the pulse feature tensor. Discrete cosine transform is performed on the pulse feature tensor to obtain the frequency domain coefficient matrix. The frequency domain coefficient matrix is ​​divided into a first sub-matrix and a second sub-matrix according to the channel. A first mapping quantity is generated for the first sub-matrix and added element-wise to the second sub-matrix to obtain a second updated sub-matrix. A second mapping quantity is generated for the second updated sub-matrix and added element-wise to the first sub-matrix to obtain a first updated sub-matrix. The first updated sub-matrix and the second updated sub-matrix are concatenated to obtain an updated frequency domain coefficient matrix. Inverse discrete cosine transform is performed to obtain the frequency domain mixed features. Based on the sparse gated hash interconnection layer, hash bucket interconnection and gated sparse write-back are performed on the frequency domain hybrid features. A hash index is generated based on the session identifier and round identifier and the bucket set is divided. The feature representative vector within the bucket set is calculated and backfilled to form interconnection features. The gate value is calculated for the interconnection features and compared with the gate threshold. Channels with gate values ​​not less than the gate threshold are retained to obtain sparse interconnection features. Submissions and corresponding summaries are generated based on the sparse interconnection features. Training the improved ERFNet network involves constructing training sample pairs and performing iterative updates. The training sample pairs consist of a set of optical residual data blocks and corresponding task labels. The training samples are input into the improved ERFNet network to obtain the network output. The loss value is calculated based on the network output and the corresponding task labels, and backpropagation is used to obtain the parameter gradient. The parameters of the event pulse coding layer, the mapping parameters of the invertible spectral mixing layer, and the gating parameters of the sparse gated hash interconnection layer are updated based on the parameter gradient. When the stopping condition is met, the improved ERFNet network with training completed is output.

[0013] Optionally, the step of performing collaborative computation to generate computation results and result summaries includes: Participating nodes upload submissions, submission summaries, round unlock factors, and identity authentication information in the submission window, while coordinating nodes generate a reception record containing a session identifier, round identifier, reception timestamp, and uploaded data summary. The coordinating node sequentially verifies the validity of the identity authentication information, the validity period of the single valid permission waveform frame, the validity of the round unlocking factor, and the consistency of the submission digest. The participating nodes that pass the verification are counted into the valid submission set and the threshold count is recorded. When the number of valid submissions reaches the threshold parameter, the coordinating node reconstructs the session key material based on the key share and derives the session key for this round. It then performs controlled unsealing of the submissions, performs collaborative computation to generate computation results and result summaries, generates evidence packages, and writes them into the audit log.

[0014] According to an embodiment of the present invention, a data security collaborative computing system based on identity recognition includes the following modules: The task authentication module is used to receive collaborative computing task requests to complete identity authentication and generate identity authentication information for participating nodes. The permission waveform generation module is used to construct a permission status matrix based on identity authentication information and generate a single valid permission waveform frame. The time-lock key module is used to generate session key material based on the permission state matrix and a single valid permission waveform frame, and to generate round unlocking factors and controlled unlocking parameter sets. The controlled transformation module is used to perform controlled transformation on the local raw data based on the controlled unlocking parameter set and output a set of optical residual data blocks; An improved ERFNet inference module is used to perform event pulse coding, reversible spectral mixing and sparse gated hash interconnection processing on optical residual data block sets, and output submissions and corresponding summaries. The submission verification and collaboration module is used to perform digest consistency verification based on the submission and the corresponding digest, and generate the calculation results and result digest.

[0015] The beneficial effects of this invention are: This invention links identity authentication information obtained through identity verification with the permission state matrix and single-valid permission waveform frames generated by closed-phase encoding, thereby achieving fine-grained expression of trusted access and authorization boundaries in multi-party collaborative computing. Furthermore, by combining the threshold fractionalization of identity segmentation-key puzzle in time-lock puzzle processing with the round unlocking factor generated by unidirectional micro-energy accumulation physical timing, permissions, keys, and round time windows form a consistent and controlled unlocking link, thereby achieving session isolation, dynamic linkage, and revocability, reducing the risks of unauthorized participation, key reuse, and premature speculation, and ensuring the controllability and fairness of the collaborative computing process at the round level.

[0016] This invention performs controlled transformations on local raw data based on a controlled unlocking parameter set to form a set of optical residual data blocks. It then utilizes event pulse coding, reversible spectral mixing, and sparse gated hash interconnection of an improved ERFNet network to infer and output submissions and digests. This allows collaborative computing to maintain effective task information expression without exposing the original data. Simultaneously, digest consistency verification is performed within the submission window, and collaborative computing is executed to generate results and result digests, forming verifiable submission and result links. This facilitates audit record solidification and traceability, overcoming the problems of difficult process verification, difficult result traceability, and high risk of data leakage in existing technologies. This improves the engineering feasibility and security reliability of cross-organizational collaborative computing. Attached Figure Description

[0017] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is a flowchart of a data security collaborative computing method based on identity recognition proposed in this invention; Figure 2 This is a structural block diagram of the improved ERFNet network proposed in this invention for a data security collaborative computing method based on identity recognition; Figure 3 This is a functional diagram of a data security collaborative computing system based on identity recognition proposed in this invention. Detailed Implementation

[0018] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.

[0019] refer to Figure 1 and Figure 2 A data security collaborative computing method based on identity recognition, comprising: Receive collaborative computing task requests, collect the identity credentials of participating nodes and complete identity authentication to obtain the identity authentication information of participating nodes; Based on the identity authentication information, an access status matrix is ​​constructed, and closed-phase encoding is used to perform time slot and phase offset to generate a single valid access waveform frame. The execution time lock puzzle is processed by generating session key material based on the permission state matrix and single valid permission waveform frame. The session key material is fractionally split and threshold parameters are set by using identity segmentation-key puzzle. Physical timing is performed by unidirectional micro-energy accumulation and round unlocking factors are generated to generate a controlled unlocking parameter set. A controlled transformation is performed on the local raw data based on the controlled unlocking parameter set, and a random phase modulation mapping is triggered by the round unlocking factor to form a set of optical residual data blocks. An improved ERFNet network is constructed to perform inference computation on the optical residual data block set. Temporal pulsed representation is performed based on the event pulse coding layer. Frequency domain reversible coupling and mixing are performed using the reversible spectral mixing layer. Hash bucket interconnection and gated sparse write-back are performed through the sparse gated hash interconnection layer. The output submissions and corresponding summaries are then provided. Upload the submission item, corresponding summary, round unlock factor, and identity authentication information in the submission window, perform summary consistency verification, and execute collaborative computing to generate calculation results and result summary.

[0020] In this embodiment, the identity authentication information includes a unique identity identifier, a set of identity attributes, a trust level marker, a revocation status marker, an identity authentication completion timestamp, and an identity credential content digest value.

[0021] In this embodiment, obtaining the identity authentication information of the participating nodes includes: Receive collaborative computing task requests and generate task identifiers; collect the original identity credential data uploaded by participating nodes, including participating node certificate chain data, participating node device identifier data, and participating node signature response data. The integrity and validity checks are performed on the original identity credential data; signature verification is performed on the participating node's signature response data; and link verification is performed on the participating node's certificate chain data. The revocation status flag of the participating node is determined based on the revocation information. Specifically, the integrity and validity checks on the original identity credential data are performed as follows: The certificate chain data, device identification data, and signature response data are concatenated sequentially into a data string to be verified. The data string to be verified is input byte by byte and hashed to obtain a digest value. The public key is extracted from the leaf certificate. The digest value and the signature value in the signature response data are used as inputs for signature verification. If the signature verification output is unsuccessful, the integrity verification is deemed to have failed. The validity verification includes certificate chain verification and revocation determination. The certificates of two adjacent levels in the certificate chain are read sequentially. The public key of the upper level certificate is used to perform signature verification on the signature field of the lower level certificate. If consecutive signature verifications are successful, the chain verification is deemed to have passed. At the same time, it is checked that the start effective time of each level certificate is not later than the identity authentication completion timestamp and the expiration time is not earlier than the identity authentication completion timestamp. The serial number of each certificate is read and the revocation information source is queried. If the serial number matches the revocation entry, the revocation status is set to revocation; otherwise, it is set to non-revocation. The revocation information query has a timeout threshold of 300 seconds. If a valid response is not obtained after 300 seconds, the validity verification is deemed to have failed. After the original identity credential data passes verification, identity authentication information is generated and stored in association with the task identifier.

[0022] In this embodiment, constructing the permission state matrix and generating a single valid permission waveform frame includes: The system receives identity authentication information and extracts a set of identity attributes. It then maps this set of attributes to a set of permission dimensions to generate a permission status matrix. The matrix elements of the permission status matrix are binary values, including allowed and denied values. Specifically, the generation of the permission status matrix is ​​as follows: The system reads the set of identity attributes from the identity authentication information, defines the set of permission dimensions and their order. The set of permission dimensions includes three categories: the range of data available, the range of results that can be output, and the round participation permission. For each permission dimension, a judgment rule table is established to determine the relationship between attributes and permissions. The set of identity attributes is matched and calculated against the rule table one by one. For enumerated attributes, equal value matching is used, and for numerical attributes, range matching is used and thresholds are compared. The judgment threshold for the trust level mark is set to no less than level three. The revocation status mark must be not revoked. The threshold for the difference between the identity authentication completion timestamp and the current time is set to no more than 3600 seconds. When all the mandatory conditions of a dimension are met at the same time, the matrix cell corresponding to the dimension is assigned an allowed value; otherwise, it is assigned a rejected value. The row index of the matrix is ​​arranged according to the order of the permission dimension set, and the column index is arranged according to the round number corresponding to the round identifier. The time slot sequence and phase offset sequence are generated based on the permission status matrix. The time slot sequence consists of multiple consecutive time slots with the same width. The phase offset sequence corresponds to the time slot sequence, and the phase offset of each phase offset sequence is determined by the value of the corresponding matrix unit. Specifically, the generation of the time slot sequence and phase offset sequence based on the permission status matrix is ​​as follows: The time slot width is determined to be 1 millisecond. Matrix cells are read from the permission status matrix in row-major order to form a binary string. The reading order is from top to bottom by permission dimension rows and from left to right by round number columns within each row. The binary string is mapped sequentially to consecutive time slots, with each bit of the binary string corresponding to one time slot. The number of time slots is equal to the length of the binary string, resulting in a time slot sequence composed of multiple consecutive time slots with the same width. At the same time, a phase offset value is generated for each time slot. Allowed values ​​are mapped to a zero-degree phase offset, and rejected values ​​are mapped to a 180-degree phase offset. The phase offset values ​​are arranged in time slot order to obtain a phase offset sequence. A single valid authorization waveform frame is generated by performing closed-phase encoding on the time slot sequence. This single valid authorization waveform frame includes a frame identifier, time slot width, number of time slots, phase offset sequence, and effective time window length. The single valid authorization waveform frame is then associated with identity authentication information and distributed. Specifically, the process of generating the single valid authorization waveform frame by performing closed-phase encoding on the time slot sequence is as follows: The service waveform is generated by reading the phase offset sequence in the time slot order. The difference between the phase of the first time slot and the phase of the last time slot of the service waveform is calculated. If the difference is zero, the waveform is closed directly. If the difference is not zero, a closed time slot is appended at the end and the phase is set to the phase of the first time slot so that the phases of the first and last time slots are the same. After the closure is completed, a single valid permission waveform frame is generated.

[0023] In this embodiment, generating the controlled unlocking parameter set includes: Receive the permission status matrix and a single valid permission waveform frame. Generate session key material based on the set of matrix unit values ​​of the permission status matrix and the phase offset sequence of the single valid permission waveform frame. The session key material includes a session key seed, a session identifier binding value, and a round identifier binding value. The session key material undergoes identity segmentation and key mosaicking processing. The number of shares is determined based on the number of participating nodes, and a threshold parameter is set. The session key seed is then fractionally split according to the threshold parameter to generate a key share set. This key share set is bound to a unique identity identifier from the identity authentication information, and a share identifier and share verification digest are generated for each key share, forming a key mosaic parameter set. Specifically, the identity segmentation and key mosaicking processing of the session key material involves: The number of participating nodes that have passed identity authentication is used as the share quantity. The threshold parameter is set to the share quantity multiplied by 0.67 and rounded up. The session key seed is grouped into 32-byte groups and used as a constant term. A random polynomial with a frequency of 1 minus the threshold parameter is generated. The polynomial coefficients are generated by a secure random source and each coefficient is 32 bytes long. The first 8 bytes of the digest value of the unique identity of each participating node are taken as the x-coordinate input. The x-coordinate is substituted into the random polynomial and the polynomial output value is calculated term by term. The term-by-term calculation includes the power calculation of the x-coordinate, multiplying the power result by the corresponding coefficient, adding the results of each term and taking the modulus of the preset prime field. The resulting polynomial output value is used as the key share of the participating node. For each key share, a share identifier is generated. The share identifier is obtained by hashing the concatenation of the session identifier, round identifier, and unique identity identifier. The share verification digest is obtained by hashing the byte string concatenated with the share identifier and the key share. The key share, share identifier, and share verification digest are bound to the corresponding unique identity identifier to form a key puzzle parameter set. A one-way micro-energy accumulation physical timing process is performed on the single valid permission waveform frame to generate a round unlocking factor. The one-way micro-energy accumulation physical timing process includes controlling the energy accumulation window according to the effective time window length, acquiring the charge integration sequence of the energy accumulation process and determining the accumulation completion status with a preset threshold, and outputting the round unlocking factor and generating an unlock verification digest when the accumulation completion status is established. Specifically, the one-way micro-energy accumulation physical timing process is performed on the single valid permission waveform frame as follows: The effective time window length is read and the energy accumulation window is set to the effective time window length. The charging and discharging circuit is controlled to charge the capacitor with a constant charging current within the energy accumulation window. The voltage across the capacitor is sampled at a sampling interval of 0.5 milliseconds. The charge integration sequence is calculated using the trapezoidal integration method. The charge integration is calculated by multiplying the average of two adjacent sampled voltages by the capacitor value and then summing them to obtain the cumulative charge. The accumulation completion threshold is set to 0.95 times the cumulative charge corresponding to the nominal capacity of the capacitor. When the cumulative charge reaches or exceeds the accumulation completion threshold and 10 consecutive samples are not lower than the accumulation completion threshold, the accumulation completion state is determined to be established. When the accumulation completion state is established, the last cumulative charge, the last sampled voltage, the effective time window length and the round identifier of the charge integration sequence are concatenated and hashed to obtain the round unlocking factor. The round unlocking factor is hashed again to generate an unlock verification digest. The key puzzle parameter set is associated and encapsulated with the round unlocking factor to generate a controlled unlocking parameter set. The controlled unlocking parameter set includes threshold parameters, key share set, share identifier set, share verification digest set, round unlocking factor and unlocking verification digest. The controlled unlocking parameter set is associated with the session identifier and round identifier, stored and distributed.

[0024] In this embodiment, forming the optical residual data block set includes: Receive the controlled unlock parameter set and extract the round unlock factor and session key material. Generate a random phase modulation seed based on the round unlock factor and round identifier. The random phase modulation seed is obtained by concatenating the round unlock factor and round identifier and inputting it into a hash mapping. A speckle map is generated by performing random phase modulation mapping on the local raw data and propagating it through a scattering medium. The random phase modulation mapping involves converting the local raw data into an amplitude matrix and superimposing it in the complex domain with the random phase matrix. This complex domain superposition results in the amplitude matrix being multiplied by an exponential phase matrix. The exponential phase matrix is ​​an exponential matrix with the natural constant as the base and the imaginary unit as the exponent, multiplied by the phase values. The phase values ​​of the random phase matrix are generated by a pseudo-random sequence driven by a random phase modulation seed. Specifically, the random phase modulation mapping and speckle map generation process for the local raw data involves: The local raw data is normalized to the 0 to 1 range according to pixel grayscale as the amplitude matrix. A pseudo-random sequence generator is initialized with a random phase modulation seed. A phase matrix of the same size as the amplitude matrix is ​​generated. Each phase value is uniformly selected in the range of 0 to 360 degrees. An exponential phase matrix is ​​constructed. Each phase value is converted to radians and multiplied by the imaginary unit. The exponent is then taken to obtain a complex phase factor with a unit amplitude. The amplitude matrix and the complex phase factor are multiplied element by element to obtain the modulated complex optical field. The complex optical field is propagated through a scattering medium. The scattering medium is represented by a fixed scattering transfer function. The representation of the complex optical field in the frequency domain is calculated using a two-dimensional discrete Fourier transform. The representation is multiplied element by element with the scattering transfer function in the frequency domain and then subjected to a two-dimensional discrete Fourier inverse transform to obtain the output complex field. The square of the amplitude of the output complex field is taken to obtain the speckle intensity map and used as the speckle map. The speckle pattern is subjected to mesh partitioning and residual quantization to form a set of optical residual data blocks. The speckle pattern is divided into multiple mesh cells according to a preset mesh size. For each mesh cell, the residual energy value is calculated to form a speckle energy residual vector. The speckle energy residual vector is then quantized according to a quantization threshold to generate a round hash string. The round hash string is combined with the residual energy value corresponding to each mesh cell to generate the set of optical residual data blocks. Specifically, the mesh partitioning and residual quantization of the speckle pattern to form the set of optical residual data blocks involves: The speckle map is divided into blocks of 16x16 pixels to obtain multiple non-overlapping grid cells. For each grid cell, an energy residual value is calculated by summing the intensity of all pixels within the grid cell and dividing by the number of pixels in the grid cell to obtain the average energy. The maximum pixel intensity minus the minimum pixel intensity is used as the texture residual term. The average energy is added to the texture residual term to obtain the energy residual value of the grid cell. The energy residual values ​​are arranged sequentially according to the grid cell order to form a speckle energy residual vector. Residual quantization is performed on the speckle energy residual vector, with the quantization threshold set to the median of the speckle energy residual vector. Each energy residual value is compared with the median; values ​​greater than or equal to the median are recorded as 1, and values ​​less than the median are recorded as 0. The residual values ​​are concatenated in their original order to obtain a round hash string. An optical residual data block is formed by combining the index of each grid cell, the corresponding energy residual value, and the corresponding bit of the round hash string. The entire set of optical residual data blocks is output as an optical residual data block set.

[0025] In this embodiment, the output submissions and corresponding digests include: An improved ERFNet network is constructed by setting an event pulse coding layer at the input of the original ERFNet network and connecting the output of the event pulse coding layer to the encoder input of the original ERFNet network. At the non-bottleneck block positions of the original encoder, a set of non-bottleneck blocks are replaced with a reversible spectral mixing layer while keeping the number of output channels and spatial resolution of the encoder unchanged. A sparse gated hash interconnection layer is set between the output of the original encoder and the decoder input, and the output of the sparse gated hash interconnection layer is connected to the decoder of the original ERFNet network. The event pulse coding layer performs temporal pulsed representation on the optical residual data block set, forming a time series of the optical residual data block set according to the sampling interval. A difference matrix is ​​calculated for adjacent time series elements, and the difference matrix is ​​sign-quantized according to a preset threshold to obtain a pulse sequence. A pulse feature tensor is then output. Specifically, the temporal pulsed representation of the optical residual data block set based on the event pulse coding layer is as follows: Aligned sampling is performed on the continuously sampled optical residual data block set at a sampling interval of 10 milliseconds. The optical residual data block set obtained from each sampling is expanded into a matrix of the same size according to the grid index order and stacked in time order to form a time series. The difference matrix is ​​obtained by subtracting the matrix of adjacent two frames in the time series element by element. The element of the difference matrix represents the change in the energy residual value of the corresponding grid cell. Sign quantization is performed on the difference matrix. The sign quantization threshold is set to 0.02. The difference matrix element is quantized as a positive pulse if it is greater than or equal to 0.02, as a negative pulse if it is less than or equal to -0.02, and as a zero pulse if it is between -0.02 and 0.02. The quantization results of each time step are stacked in time order to obtain a pulse sequence. The positive pulse, negative pulse and zero pulse are encoded as 1, -1 and 0 respectively to form a pulse feature tensor. Based on the reversible spectral mixing layer, frequency domain reversible coupling mixing is performed on the pulse feature tensor. Discrete cosine transform is performed on the pulse feature tensor to obtain the frequency domain coefficient matrix. The frequency domain coefficient matrix is ​​divided into a first sub-matrix and a second sub-matrix according to the channel. A first mapping quantity is generated for the first sub-matrix and added element-wise to the second sub-matrix to obtain a second updated sub-matrix. A second mapping quantity is generated for the second updated sub-matrix and added element-wise to the first sub-matrix to obtain a first updated sub-matrix. The first updated sub-matrix and the second updated sub-matrix are concatenated to obtain an updated frequency domain coefficient matrix. Inverse discrete cosine transform is performed to obtain the frequency domain mixed features. Based on a sparsely gated hash interconnection layer, hash bucketing interconnection and gated sparse write-back are performed on the frequency domain hybrid features. A hash index is generated based on session identifiers and round identifiers, and bucket sets are created. Feature representative vectors within each bucket set are calculated and backfilled to form interconnection features. A gate value is calculated for the interconnection features and compared with a gate threshold. Channels with gate values ​​not less than the gate threshold are retained to obtain sparse interconnection features. Submissions and corresponding summaries are generated based on these sparse interconnection features. Specifically, the hash bucketing interconnection and gated sparse write-back are performed on the frequency domain hybrid features using the sparsely gated hash interconnection layer as follows: A hash index is generated for each spatial location of the frequency domain hybrid feature. The hash index is calculated by concatenating the session identifier and the round identifier to obtain the session round seed, concatenating the row number and column number of the spatial location with the session round seed, and performing a hash operation. The hash result is moduloed to obtain the bucket number. The number of buckets is set to 256. All spatial locations are divided into bucket sets according to the bucket number. The feature representative vector within each bucket set is calculated. The feature representative vector within the bucket is calculated by summing the channel features of all spatial locations within the bucket and dividing by the number of locations within the bucket to obtain the channel mean vector. The channel mean vector is then backfilled into each spatial location within the bucket to form interconnected features. The gating value is calculated for the interconnect features. The gating value is calculated by averaging the absolute value of each channel over the entire space to obtain the channel strength value. The channel strength value is normalized to the interval between 0 and 1. The gating threshold is set to 0.3. Channels with a gating value of not less than 0.3 are retained to obtain sparse interconnect features. Training the improved ERFNet network involves constructing training sample pairs and performing iterative updates. Each training sample pair consists of a set of optical residual data blocks and corresponding task labels. The training samples are input into the improved ERFNet network to obtain the network output. The loss value is calculated based on the network output and the corresponding task labels, and backpropagation is used to obtain the parameter gradients. Based on these gradients, the parameters of the event pulse coding layer, the mapping parameters of the invertible spectral mixing layer, and the gating parameters of the sparse gated hash interconnection layer are updated. When the stopping condition is met, the trained improved ERFNet network is output. Specifically, training the improved ERFNet network involves: Training samples are fed into the improved ERFNet network to obtain the network output probability map. For each labeled position, the output probability and the true class are used to form a cross-entropy loss, which is then averaged across all positions to obtain the loss value. A sparsity loss is introduced for the channel retention ratio of the sparse gated hash interconnection layer. The sparsity loss is defined as the absolute value of the difference between the actual channel retention ratio and the target ratio of 0.25. The final loss value is the sum of the cross-entropy loss and the sparsity loss. Backpropagation is performed on the final loss value to calculate the gradient of the parameters of each layer. The parameters of the event pulse coding layer, the mapping parameters of the reversible spectral mixing layer, and the gating parameters of the sparse gated hash interconnection layer are updated with a learning rate of 0.001. One iteration period is used as a stopping unit. Training is stopped when the loss value decreases by less than 0.001 for 10 consecutive iteration periods or when the iteration period reaches 200, and the improved ERFNet network that has been trained is output.

[0026] In this embodiment, the step of performing collaborative computing to generate computation results and result summaries includes: Participating nodes upload submissions, submission summaries, round unlock factors, and identity authentication information in the submission window, while coordinating nodes generate a reception record containing a session identifier, round identifier, reception timestamp, and uploaded data summary. The coordinating node sequentially verifies the validity of the identity authentication information, the validity period of the single valid permission waveform frame, the validity of the round unlocking factor, and the consistency of the submission digest. The participating nodes that pass the verification are counted into the valid submission set and the threshold count is recorded. When the number of valid submissions reaches the threshold parameter, the coordinating node reconstructs the session key material based on the key share and derives the session key for this round. It then performs controlled unsealing of the submissions, performs collaborative computation to generate computation results and result summaries, generates evidence packages, and writes them into the audit log.

[0027] refer to Figure 3 A data security collaborative computing system based on identity recognition includes the following modules: The task authentication module is used to receive collaborative computing task requests to complete identity authentication and generate identity authentication information for participating nodes. The permission waveform generation module is used to construct a permission status matrix based on identity authentication information and generate a single valid permission waveform frame. The time-lock key module is used to generate session key material based on the permission state matrix and a single valid permission waveform frame, and to generate round unlocking factors and controlled unlocking parameter sets. The controlled transformation module is used to perform controlled transformation on the local raw data based on the controlled unlocking parameter set and output a set of optical residual data blocks; An improved ERFNet inference module is used to perform event pulse coding, reversible spectral mixing and sparse gated hash interconnection processing on optical residual data block sets, and output submissions and corresponding summaries. The submission verification and collaboration module is used to perform digest consistency verification based on the submission and the corresponding digest, and generate the calculation results and result digest.

[0028] Example 1: To verify the feasibility of this invention in practice, it was applied to a cross-domain collaborative segmentation computation task. The platform simultaneously connected multiple participating nodes to perform joint segmentation inference and model iteration verification on images of similar scenes. The original data was collected locally from each node, totaling 5120 images with a resolution of 1024×512 pixels and 8 categories; low-light samples accounted for 31%, motion-blurred samples for 18%, and occluded samples for 22%. To ensure the persuasiveness of the comparison, the platform used the same batch of training and test samples for comparative experiments: 4000 training samples, 500 verification samples, and 620 test samples, all from the 5120 images and without overlap. Traditional methods use the original ERFNet + static token authentication + direct upload of intermediate feature summaries.

[0029] After the task begins, the identity authentication phase begins, with 12 nodes submitting their original identity credentials. The system concatenates the certificate chain data, device identification data, and signature response data to calculate a digest and verifies the signature. Nodes that fail signature verification, fail step-by-step certificate chain verification, or are revoked are directly rejected. In this batch, one node was rejected due to signature verification failure, and one node was rejected due to revocation. The remaining 10 nodes generated identity authentication information and entered the valid participant set. To reflect revocability, the system sets one node to a revoked state during the task. If the node fails to verify the revoked state in the next round of submission, it will be rejected. The interval between revocation taking effect and rejection is 1.7 seconds. Traditional methods only verify the token when the session is established, and revoked nodes still have one round of submissions accepted. The current comparison results are: the unauthorized interception rate is 83.3% for traditional methods and 100% for this invention; the number of submissions still accepted after revocation is 1 for traditional methods and 0 for this invention.

[0030] Upon entering the authorization phase, the system generates a permission status matrix based on identity authentication information. The permission dimensions include the data availability range, the output result range, and the round of participation permissions. Matrix cells take either allowed or rejected values. A 3x20 permission status matrix is ​​generated for 10 valid nodes. One node, due to insufficient trust level, is set to a rejected value within the output result range, allowing only digest submission. The system maps the permission status matrix to a single valid permission waveform frame with a time slot width of 1 millisecond. A row-first time slot sequence is generated, with phase offset mapping allowed values ​​to 0 degrees and rejected values ​​to 180 degrees. Closed-phase encoding ensures consistent phase at the beginning and end, and a transition time slot is inserted when the phase difference exceeds 90 degrees. This results in 86 time slots and an effective time window of 86 milliseconds. Traditional methods distribute static permission tables without single-valid time window constraints, allowing submissions exceeding the time window limit to be accepted. This invention directly rejects submissions exceeding the time window limit under waveform frame validity verification.

[0031] Entering the time-lock puzzle processing phase, the system generates session key material based on the permission state matrix and permission waveform frame, and performs identity segmentation and key puzzle fractionalization. The effective participant set consists of 10 nodes, with 10 shares and a threshold parameter of 7. After grouping the session key seed, the system generates a random polynomial, using the first 8 bytes of each node's unique identifier digest as input to calculate the key share, and generates a share identifier and share verification digest for each share. Simultaneously, unidirectional micro-energy accumulation physical timing is performed on the permission waveform frame, with an energy accumulation window of 86 milliseconds and a sampling interval of 0.5 milliseconds to obtain 172 sampling points. A trapezoidal integral is used to obtain the charge integration sequence; the completion threshold is 0.95 times the cumulative charge corresponding to the nominal capacity, and completion is determined only after 10 consecutive samples are not lower than the threshold. The average time for the current round completion determination is 88.6 milliseconds, with a standard deviation of 3.2 milliseconds; traditional methods use pure software timing, which can lead to premature triggering, with the shortest trigger time being 41 milliseconds. The round unlocking factor and key share are jointly encapsulated into a controlled unlocking parameter set and distributed.

[0032] In the controlled transformation phase, nodes do not upload the original image. Instead, a speckle map is generated by random phase modulation mapping triggered by the round unlocking factor. This speckle map is then formed into a set of optical residual data blocks through grid partitioning and residual quantization. The phase value is uniformly selected from 0 to 360 degrees. The scattering transfer function is obtained through offline calibration and is calculated in the frequency domain by dividing the output spectrum element-wise by the input spectrum, setting the denominator to 0 if it is less than 0.001. The speckle intensity map is normalized to 0 to 1, and intensities less than 0.01 are truncated to 0. The grid size is 16×16 pixels, resulting in 2048 grid cells per image. The residual energy of each grid cell is calculated to form a residual vector, and a round hash string is generated using the median as the quantization threshold. Traditional methods directly extract intermediate features from the original image and upload a summary, lacking the representation of the current class de-identified residual blocks.

[0033] In the inference phase, nodes construct an improved ERFNet network to process the optical residual data block set. The event pulse coding layer constructs a time series with a 10-millisecond sampling interval, differs adjacent residual matrices, quantizes them with a threshold of 0.02, and outputs a pulse feature tensor. The invertible spectral mixing layer performs discrete cosine transform, invertible coupled mixing, and inverse transform to obtain frequency domain mixed features. The sparse gated hash interconnection layer generates hash indexes based on session and round identifiers, with 256 buckets. It calculates the representative vectors within each bucket to backfill and form interconnection features. The channel gating value is taken as the absolute mean and normalized, with a gating threshold of 0.3. Channels are retained to obtain sparse interconnection features and generate submissions and summaries. Training uses training samples for iterative updates, adding cross-entropy loss and sparsity loss. The target channel retention ratio is 0.25, the learning rate is 0.001, and the process stops when the loss decreases by less than 0.001 for 10 consecutive iterations or when the number of iterations reaches 200. The test set comparison results are as follows: For pixel-level average intersection-over-union (IoU) ratios, the traditional method achieves 72.6%, while this invention achieves 78.9%; for small targets, the traditional method achieves 54.2%, while this invention achieves 63.5%; and for boundary f-scores, the traditional method achieves 0.71, while this invention achieves 0.79. In terms of efficiency, the single-node inference latency is 42.3 milliseconds for the traditional method and 39.1 milliseconds for this invention; the single-round uplink transmission volume is 5.8 megabytes for the traditional method and 2.1 megabytes for this invention.

[0034] In the submission and collaboration phase, nodes upload submissions, digests, round unlocking factors, and identity verification information within the submission window. Coordinating nodes verify identity validity, the validity period of the permission waveform frame, and the consistency of the round unlocking factor and digest before adding them to the valid submission set. When the number reaches the threshold of 7, the session key material is reconstructed and the current round key is derived. The submissions are then unsealed in a controlled manner, and collaborative computation is performed to generate results and a result digest, which are then written into the evidence package. In this batch, one node was rejected due to exceeding the window limit, and another node was rejected due to digest inconsistency. Ultimately, eight nodes met the threshold and completed collaboration. In the early speculation simulation, one node submitted before completing the physical timing. Traditional methods are accepted because software timing can be bypassed, while this invention was rejected due to the failure of round unlocking factor verification. Regarding dispute review, traditional methods resulted in two instances where the digests were identical but the content differed, with a reviewability rate of 40%. This invention, through controlled unsealing and evidence package solidification, increases the reviewability rate to 100%.

[0035] The comprehensive comparative experimental data are as follows: the unauthorized interception rate is 83.3% for the traditional method and 100% for this invention; the number of submissions still accepted after revocation is 1 for the traditional method and 0 for this invention; the average pixel-level intersection-union ratio (IU / R) on the test set is 72.6% for the traditional method and 78.9% for this invention; the average IU / R for small targets is 54.2% for the traditional method and 63.5% for this invention; the boundary f-score is 0.71 for the traditional method and 0.79 for this invention; the single-node inference latency is 42.3 milliseconds for the traditional method and 39.1 milliseconds for this invention; the single-round uplink transmission volume is 5.8 megabytes for the traditional method and 2.1 megabytes for this invention; the number of successful early speculations is 1 for the traditional method and 0 for this invention. As can be seen from the embodiments, this invention can provide observable data links and verifiable verification results for each step of the claims. It demonstrates advantages in trusted access control, dynamic linkage of permissions and keys, session isolation and revocation, and security and controllability, result reliability, and audit accountability without exposing the original data, verifying the feasibility and effectiveness of the project.

[0036] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. A data security collaborative computing method based on identity recognition, characterized in that, include: Receive collaborative computing task requests, collect the identity credentials of participating nodes and complete identity authentication to obtain the identity authentication information of participating nodes; Based on the identity authentication information, an access status matrix is ​​constructed, and closed-phase encoding is used to perform time slot and phase offset to generate a single valid access waveform frame. The execution time lock puzzle is processed by generating session key material based on the permission state matrix and single valid permission waveform frame. The session key material is fractionally split and threshold parameters are set by using identity segmentation-key puzzle. Physical timing is performed by unidirectional micro-energy accumulation and round unlocking factors are generated to generate a controlled unlocking parameter set. A controlled transformation is performed on the local raw data based on the controlled unlocking parameter set, and a random phase modulation mapping is triggered by the round unlocking factor to form a set of optical residual data blocks. An improved ERFNet network is constructed to perform inference computation on the optical residual data block set. Temporal pulsed representation is performed based on the event pulse coding layer. Frequency domain reversible coupling and mixing are performed using the reversible spectral mixing layer. Hash bucket interconnection and gated sparse write-back are performed through the sparse gated hash interconnection layer. The output submissions and corresponding summaries are then provided. Upload the submission item, corresponding summary, round unlock factor, and identity authentication information in the submission window, perform summary consistency verification, and execute collaborative computing to generate calculation results and result summary.

2. The data security collaborative computing method based on identity recognition according to claim 1, characterized in that, The identity authentication information includes a unique identity identifier, a set of identity attributes, a trust level marker, a revocation status marker, an identity authentication completion timestamp, and an identity credential content digest value.

3. The data security collaborative computing method based on identity recognition according to claim 1, characterized in that, The obtained identity authentication information of the participating nodes includes: Receive collaborative computing task requests and generate task identifiers; collect the original identity credential data uploaded by participating nodes, including participating node certificate chain data, participating node device identifier data, and participating node signature response data. Perform integrity and validity checks on the original identity credential data, verify the signatures of the participating nodes' signature response data, verify the chain of the participating nodes' certificate chains, and determine the revocation status flag of the participating nodes based on the revocation information. After the original identity credential data passes verification, identity authentication information is generated and stored in association with the task identifier.

4. The data security collaborative computing method based on identity recognition according to claim 1, characterized in that, The construction of the permission state matrix and the generation of a single valid permission waveform frame include: Receive identity authentication information and extract the identity attribute set, map the identity attribute set according to the permission dimension set, and generate a permission status matrix. The matrix unit of the permission status matrix takes a binary value, which includes allowed value and denied value. The time slot sequence and phase offset sequence are generated based on the permission status matrix. The time slot sequence consists of multiple consecutive time slots with the same width. The phase offset sequence corresponds to the time slot sequence, and the phase offset of each phase in the phase offset sequence is determined by the value of the corresponding matrix unit. Closed-phase encoding is performed on the time slot sequence to generate a single valid permission waveform frame. The single valid permission waveform frame includes a frame identifier, time slot width, number of time slots, phase offset sequence, and effective time window length. The single valid permission waveform frame is associated with the identity authentication information and sent out.

5. The data security collaborative computing method based on identity recognition according to claim 1, characterized in that, The generation of the controlled unlock parameter set includes: Receive the permission status matrix and a single valid permission waveform frame. Generate session key material based on the set of matrix unit values ​​of the permission status matrix and the phase offset sequence of the single valid permission waveform frame. The session key material includes a session key seed, a session identifier binding value, and a round identifier binding value. The session key material is processed by identity segmentation and key puzzle. The number of shares is determined according to the number of participating nodes and a threshold parameter is set. The session key seed is fractionally split according to the threshold parameter to generate a key share set. The key share set is bound according to the unique identity identifier in the identity authentication information, and a share identifier and share verification digest are generated for each key share to form a key puzzle parameter set. Perform unidirectional micro-energy accumulation physical timing processing on a single valid permission waveform frame to generate a round unlocking factor. The unidirectional micro-energy accumulation physical timing processing includes controlling the energy accumulation window according to the effective time window length, collecting the charge integration sequence of the energy accumulation process and determining the accumulation completion status with a preset threshold, and outputting the round unlocking factor and generating an unlock verification summary when the accumulation completion status is established. The key puzzle parameter set is associated and encapsulated with the round unlocking factor to generate a controlled unlocking parameter set. The controlled unlocking parameter set includes threshold parameters, key share set, share identifier set, share verification digest set, round unlocking factor and unlocking verification digest. The controlled unlocking parameter set is associated with the session identifier and round identifier, stored and distributed.

6. The data security collaborative computing method based on identity recognition according to claim 1, characterized in that, The formation of the optical residual data block set includes: Receive the controlled unlock parameter set and extract the round unlock factor and session key material. Generate a random phase modulation seed based on the round unlock factor and round identifier. The random phase modulation seed is obtained by concatenating the round unlock factor and round identifier and inputting it into a hash mapping. The local raw data is subjected to random phase modulation mapping and propagated through a scattering medium to generate a speckle map. The random phase modulation mapping includes converting the local raw data into an amplitude matrix and superimposing it with the random phase matrix in the complex field. The complex field superposition is the multiplication of the amplitude matrix with an exponential phase matrix. The exponential phase matrix is ​​an exponential matrix with the natural constant as the base and the exponent as the imaginary unit multiplied by the phase value. The phase value of the random phase matrix is ​​generated by a pseudo-random sequence driven by a random phase modulation seed. The speckle pattern is meshed and residual quantized to form a set of optical residual data blocks. The speckle pattern is divided into multiple grid cells according to a preset grid size. The residual energy value is calculated for each grid cell and a speckle energy residual vector is formed. The speckle energy residual vector is quantized according to the quantization threshold to generate a round hash string. The round hash string is combined with the residual energy value corresponding to each grid cell to generate a set of optical residual data blocks.

7. The data security collaborative computing method based on identity recognition according to claim 1, characterized in that, The output submissions and corresponding digests include: An improved ERFNet network is constructed by setting an event pulse coding layer at the input of the original ERFNet network and connecting the output of the event pulse coding layer to the encoder input of the original ERFNet network. At the non-bottleneck block positions of the original encoder, a set of non-bottleneck blocks are replaced with a reversible spectral mixing layer while keeping the number of output channels and spatial resolution of the encoder unchanged. A sparse gated hash interconnection layer is set between the output of the original encoder and the decoder input, and the output of the sparse gated hash interconnection layer is connected to the decoder of the original ERFNet network. The optical residual data block set is subjected to temporal pulsed characterization based on the event pulse coding layer. The optical residual data block set is formed into a time series according to the sampling interval. The difference matrix is ​​calculated for adjacent time series elements. The difference matrix is ​​symbolically quantized according to a preset threshold to obtain the pulse sequence and output the pulse feature tensor. Based on the reversible spectral mixing layer, frequency domain reversible coupling mixing is performed on the pulse feature tensor. Discrete cosine transform is performed on the pulse feature tensor to obtain the frequency domain coefficient matrix. The frequency domain coefficient matrix is ​​divided into a first sub-matrix and a second sub-matrix according to the channel. A first mapping quantity is generated for the first sub-matrix and added element-wise to the second sub-matrix to obtain a second updated sub-matrix. A second mapping quantity is generated for the second updated sub-matrix and added element-wise to the first sub-matrix to obtain a first updated sub-matrix. The first updated sub-matrix and the second updated sub-matrix are concatenated to obtain an updated frequency domain coefficient matrix. Inverse discrete cosine transform is performed to obtain the frequency domain mixed features. Based on the sparse gated hash interconnection layer, hash bucket interconnection and gated sparse write-back are performed on the frequency domain hybrid features. A hash index is generated based on the session identifier and round identifier and the bucket set is divided. The feature representative vector within the bucket set is calculated and backfilled to form interconnection features. The gate value is calculated for the interconnection features and compared with the gate threshold. Channels with gate values ​​not less than the gate threshold are retained to obtain sparse interconnection features. Submissions and corresponding summaries are generated based on the sparse interconnection features. Training the improved ERFNet network involves constructing training sample pairs and performing iterative updates. The training sample pairs consist of a set of optical residual data blocks and corresponding task labels. The training samples are input into the improved ERFNet network to obtain the network output. The loss value is calculated based on the network output and the corresponding task labels, and backpropagation is used to obtain the parameter gradient. The parameters of the event pulse coding layer, the mapping parameters of the invertible spectral mixing layer, and the gating parameters of the sparse gated hash interconnection layer are updated based on the parameter gradient. When the stopping condition is met, the improved ERFNet network with training completed is output.

8. The data security collaborative computing method based on identity recognition according to claim 1, characterized in that, The execution of collaborative computing to generate computation results and result summaries includes: Participating nodes upload submissions, submission summaries, round unlock factors, and identity authentication information in the submission window, while coordinating nodes generate a reception record containing a session identifier, round identifier, reception timestamp, and uploaded data summary. The coordinating node sequentially verifies the validity of the identity authentication information, the validity period of the single valid permission waveform frame, the validity of the round unlocking factor, and the consistency of the submission digest. The participating nodes that pass the verification are counted into the valid submission set and the threshold count is recorded. When the number of valid submissions reaches the threshold parameter, the coordinating node reconstructs the session key material based on the key share and derives the session key for this round. It then performs controlled unsealing of the submissions, performs collaborative computation to generate computation results and result summaries, generates evidence packages, and writes them into the audit log.

9. A data security collaborative computing system based on identity recognition, executing the data security collaborative computing method based on identity recognition as described in any one of claims 1 to 8, characterized in that, Includes the following modules: The task authentication module is used to receive collaborative computing task requests to complete identity authentication and generate identity authentication information for participating nodes. The permission waveform generation module is used to construct a permission status matrix based on identity authentication information and generate a single valid permission waveform frame. The time-lock key module is used to generate session key material based on the permission state matrix and a single valid permission waveform frame, and to generate round unlocking factors and controlled unlocking parameter sets. The controlled transformation module is used to perform controlled transformation on the local raw data based on the controlled unlocking parameter set and output a set of optical residual data blocks; An improved ERFNet inference module is used to perform event pulse coding, reversible spectral mixing and sparse gated hash interconnection processing on optical residual data block sets, and output submissions and corresponding summaries. The submission verification and collaboration module is used to perform digest consistency verification based on the submission and the corresponding digest, and generate the calculation results and result digest.