A data security sharing method for a data element circulation system

CN122614801APending Publication Date: 2026-08-21NANJING UNIV OF INFORMATION SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611098155.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-23
Publication Date
2026-08-21

AI Technical Summary

Technical Problem

[0005]为了解决证书有效期无法实时调整导致数据泄露的技术问题,本申请提供了一种用于数据要素流通系统的数据安全共享方法,所采用的技术方案具体如下:

Benefits of technology

本申请通过滑动窗口标准差以及快速傅里叶变换算法分别对电流数据以及振动数据进行分析,从而对系统的功耗波动以及系统硬件的振动进行量化,从而对用户行为的危险性进行表征;并引入基于时间衰减的加权移动平均法突出用户近期操作的变化情况,同时结合基于Beta分布的信任概率密度函数对用户后续访问的信任值进行评估,从而对用户的长期信誉和短期波动进行综合评价;在此基础上,本申请对传统静态属性证书管理机制进行改进,对证书有效期T进行动态调整,使有效期随用户信任度自适应变化;当用户行为风险升高时B值下降,有效期自动缩短,迫使系统频繁重新评估用户属性,及时阻断潜在威胁,提高了数据共享的安全性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122614801A_ABST
    Figure CN122614801A_ABST
Patent Text Reader

Abstract

The application relates to the technical field of data security sharing, in particular to a data security sharing method for a data element circulation system. The method comprises the following steps: acquiring a current sequence and a vibration sequence, and acquiring a time sequence database; performing local analysis on the current sequence window to determine the current instability degree and the maximum instantaneous power consumption impact; performing global analysis on the vibration sequence to acquire a main frequency energy ratio; combining the local features of the current as a whole to determine an operation risk coefficient; integrating all the operation risk coefficients to acquire a weighted average risk coefficient, and then combining the trust probability expectation value obtained by screening the trusted access times to acquire a dynamic trust probability; and based on the dynamic trust probability, adjusting the validity period of a user attribute certificate to complete data security sharing. The application improves the data security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security sharing technology, specifically to a data security sharing method for a data element circulation system. Background Technology

[0002] Against the backdrop of rapid development in the digital economy, financial data, as a core asset of enterprises and a key carrier of regulatory compliance, has become a priority in the data flow system. Therefore, a more secure auditing system for financial data is needed to ensure the normal operation of modern financial systems.

[0003] The circulation methods of the data element circulation system mainly include important channels such as data openness, data sharing, and data trading. For financial data, in the secure sharing of data in the data element circulation system, the single-user local physical access terminal in the data element circulation system has gradually evolved from early encrypted transmission and identity authentication to a comprehensive solution combining attribute encryption and blockchain, realizing the usable but invisible attributes of data management. The development in this field has not only broken down the data ratio between different departments and ensured the privacy of data in the sharing process, but also fully explored the deep value of data elements, promoting cross-institutional business cooperation and collaboration.

[0004] In the secure sharing of financial data within a data element circulation system, attribute-based encryption achieves fine-grained access control through attribute matching. However, due to the continuous and dynamic changes in user behavior, operating environment, and trust levels, the validity period of attribute certificates cannot be adjusted in real time once issued. This means that when users engage in abnormal operations, the system cannot promptly revoke or shorten the validity period of their permissions, increasing the potential risk of data leakage. Existing static attribute encryption mechanisms lack the ability to respond to dynamic changes in user behavior and struggle to automatically tighten permissions when user trust decreases, easily leading to an imbalance between security protection and ease of use. Summary of the Invention

[0005] To address the technical problem of data leakage caused by the inability to adjust certificate validity periods in real time, this application provides a data security sharing method for data element circulation systems, the specific technical solution of which is as follows: This application proposes a method for secure data sharing in a data element circulation system, the method comprising the following steps: Obtain the current and vibration sequences at each data acquisition moment from the user, and acquire the time series database; For the current sequence, a time window is set; for the vibration sequence, a Fourier transform is performed, and the main frequency energy ratio is determined by the difference between its main frequency energy value and the total energy value. The operational risk coefficient of the user at each acquisition moment is determined by combining the maximum power consumption instability of the current within all time windows and the intensity of the maximum instantaneous power consumption impact. The operational risk coefficients at all collection times are sorted into a risk coefficient sequence according to time sequence, and their weighted average risk coefficient is obtained; the total number of user accesses is extracted from the time series database, and the number of trustworthy accesses is filtered based on the operational risk coefficients. The number of trustworthy accesses is used as the input of the probability density function to obtain the expected value of the trust probability; the dynamic trust probability is determined based on the weighted average risk coefficient and the expected value of the trust probability. The validity period of positive user attribute numbers is adjusted based on dynamic trust probability to achieve secure data sharing.

[0006] In the aforementioned scheme, this application analyzes current and vibration data using a sliding window standard deviation and a fast Fourier transform algorithm, respectively, to quantify the power consumption fluctuations and vibrations of the system hardware, thereby characterizing the risk of user behavior. It also introduces a time-decay-based weighted moving average method to highlight changes in recent user operations, and combines a trust probability density function based on a Beta distribution to evaluate the trust value of subsequent user visits, thus comprehensively evaluating the user's long-term reputation and short-term fluctuations. Furthermore, this application improves the traditional static attribute certificate management mechanism by dynamically adjusting the certificate validity period T, making the validity period adaptively change with the user's trust level. When the risk of user behavior increases, the B value decreases, and the validity period automatically shortens, forcing the system to frequently reassess user attributes, promptly blocking potential threats, and improving the security of data sharing.

[0007] In one embodiment, the current sequence is a normalized sequence of all currents acquired before each acquisition time; the vibration sequence is a normalized sequence of all vibration signals acquired before each acquisition time.

[0008] In one embodiment, the main frequency energy ratio is the ratio of the main frequency energy value to the total energy value.

[0009] In one embodiment, the operational risk coefficient is positively correlated with the maximum power consumption instability and the intensity of the maximum instantaneous power consumption surge, respectively, and negatively correlated with the main frequency energy value.

[0010] In one embodiment, the power consumption instability is the standard deviation of all currents within a time window.

[0011] In one embodiment, the intensity of the maximum instantaneous power consumption surge is the peak-to-average power ratio of the current value within the time window.

[0012] In one embodiment, the weighted average risk coefficient is the value output by taking the risk coefficient sequence as input and using a time-decay-based weighted moving average method.

[0013] In one embodiment, the dynamic trust probability is positively correlated with the expected value of the trust probability and negatively correlated with the weighted average risk coefficient.

[0014] In one embodiment, the expression for the dynamic trust probability is: , Indicates the weighting coefficient. This represents the weighted average risk coefficient. This represents the sigmoid function. This represents the expected value of the trust probability. This represents the dynamic trust probability.

[0015] In one embodiment, the method for adjusting the validity period of user attribute certificates based on dynamic trust probability is as follows: , This indicates the minimum validity period of the data element circulation system. This indicates the maximum validity period of the data element circulation system. This represents the user's dynamic trust probability. This indicates the adjusted validity period.

[0016] The beneficial effects of this application are as follows: This application analyzes current and vibration data using sliding window standard deviation and fast Fourier transform algorithms, respectively, to quantify system power consumption fluctuations and hardware vibrations, thereby characterizing the risk of user behavior. It also introduces a time-decay-based weighted moving average method to highlight changes in recent user operations, and combines a trust probability density function based on Beta distribution to evaluate the trust value of subsequent user visits, thus providing a comprehensive evaluation of the user's long-term reputation and short-term fluctuations. Furthermore, this application improves the traditional static attribute certificate management mechanism by dynamically adjusting the certificate validity period T, making it adaptively change with user trust levels. When the risk of user behavior increases, the B value decreases, and the validity period automatically shortens, forcing the system to frequently reassess user attributes, promptly blocking potential threats, and improving the security of data sharing. Attached Figure Description

[0017] Figure 1 This is a flowchart illustrating a data security sharing method for a data element circulation system, provided as an embodiment of this application. Detailed Implementation

[0018] An embodiment of a data security sharing method for a data element circulation system: The following description, in conjunction with the accompanying drawings, details a specific scheme for a data security sharing method for a data element circulation system provided in this application.

[0019] Please see Figure 1 The diagram illustrates a flowchart of a data security sharing method for a data element circulation system according to an embodiment of this application. The method includes the following steps: Step S001: Obtain the current sequence and vibration sequence of the user at each acquisition time, and obtain the time series database.

[0020] A high-precision current sensor is installed on the power supply line of the single-user local physical access terminal in the data element circulation system to record the current changes during each user access process; at the same time, a MEMS accelerometer is installed inside the equipment chassis to record the hardware vibration characteristics during each user access process.

[0021] In this embodiment, the acquisition frequency of both current data and vibration data is set to 1kHz, and real-time Min-Max normalization is performed on each type of data to eliminate the influence of dimensions.

[0022] For each data acquisition moment, all current and vibration data acquired before each acquisition moment are sorted in chronological order to obtain the current sequence and vibration sequence for each acquisition moment.

[0023] In addition, the system access logs are used to statistically analyze and record the cumulative number of accesses for each user in real time. A time-series database (such as InfluxDB) is used to store power consumption and vibration time-series data, indexed by user ID and session ID. A relational database (such as PostgreSQL) is used to store user statistical data, with user ID as the primary key. The two types of databases are linked through user ID to ensure that features can be extracted by user dimension in subsequent steps.

[0024] At this point, the current sequence and vibration sequence at each moment have been obtained, and the time series database has been acquired.

[0025] Step S002: For local analysis of the current sequence window, determine the degree of current instability and the maximum instantaneous power consumption impact; for global analysis of the vibration sequence, obtain the dominant frequency energy ratio, and determine the operational risk coefficient by combining the overall local characteristics of the current.

[0026] Traditional data element circulation systems rely solely on pre-defined user policies for data sharing, making it difficult to detect real-time physical states and behavioral anomalies in the user's operating environment. This results in an inability to dynamically respond to user actions, increasing the risk of privilege abuse and data leakage. For example, for local physical access terminals (such as industrial control computers used for classified queries), malicious user access (e.g., devices implanted with spyware, subjected to remote control, or hardware-level attacks) can indeed cause abnormal changes in monitoring data. Malware (such as spyware and remote control Trojans) running continuously in the background consumes CPU, network, and sensor resources, leading to increased overall device power consumption. Even in standby mode, battery consumption accelerates significantly.

[0027] Based on the above analysis, using the current sequence at each acquisition moment during user operation as input, a sliding window-based feature extraction algorithm is employed to ensure that the time window covers the device power consumption changes caused by most access requests. The standard deviation of all data within each time window is then calculated. The peak-to-average power ratio (PAPR) R of the current data within each time window is calculated. In this embodiment, the length of the sliding time window is set to 5 seconds, and the step size of the sliding time window is 1 second. The standard deviation of all data within each time window is calculated. It reflects the degree of power consumption instability of the data element circulation system during the encryption and decryption load operations when the user operates, while the peak-to-average power ratio R of the current data in each time window indicates the intensity of the instantaneous power consumption impact of the data element circulation system during the encryption and decryption load operations when the user operates.

[0028] The above analysis examines the changes in device power consumption during user operations in the data element circulation system. However, it is difficult to distinguish between normal user operations and malicious user access based solely on changes in device power consumption, and it is also difficult to detect and analyze hardware disturbances based on changes in device power consumption.

[0029] To address the aforementioned issues, since abnormal encryption during user operations or tampering with hardware can alter the vibration spectrum distribution of the vibration source, causing the vibration energy value to deviate from the normal baseline, this paper uses the vibration sequence at each acquisition moment during user operations as input to a Fast Fourier Transform algorithm. The algorithm outputs the dominant frequency energy value and calculates the ratio E between the dominant frequency energy value and the total energy value, thereby quantitatively analyzing the vibration characteristics of the device during the access request process. The analysis frequency band needs to cover the operating frequency bands of vibration sources such as computer fans and hard drives. In this embodiment, the analysis frequency band is set to 0~200Hz.

[0030] The operational risk coefficient is calculated based on the maximum power consumption instability within the time window, the intensity of the maximum instantaneous power consumption impact, and the main frequency energy value.

[0031] The operational risk coefficient is positively correlated with the degree of instability of maximum power consumption and the intensity of the maximum instantaneous power consumption impact, respectively; and negatively correlated with the main frequency energy value.

[0032] Preferably, in this embodiment, the expression for the operational risk coefficient is: , This indicates the degree of instability in maximum power consumption across all time windows. This represents the intensity of the maximum instantaneous power consumption surge across all time windows. Indicates the power ratio of the main frequency. It is a very small positive number, and its function is to prevent the denominator from being 0. This represents the operational risk coefficient at each data acquisition moment.

[0033] Standard deviation is used to measure the dispersion of data, describing the fluctuation range of data in the time domain. The larger the standard deviation, the more uneven the distribution of data size. Peak-to-average power ratio (PAPR) is used to characterize whether there are sudden events in the signal. The larger the value, the stronger the instantaneous impact experienced by the data. Fast Fourier transform is used to convert the time domain signal to the frequency domain. The dominant frequency energy value is used to obtain the concentration of the signal in the main frequency band through frequency domain analysis. The larger the value, the more concentrated the signal energy is in the main frequency band.

[0034] By analyzing the power consumption fluctuations and instantaneous power consumption impacts of the data element circulation system in the time domain to express the intensity of user access, and combining the intensity of vibration energy concentration of the hardware in the frequency domain to provide feedback on the intensity of risky access during the user's access process, the risk quantification and assessment of user operation behavior can be achieved.

[0035] At this point, the operational risk coefficient of the user at each data collection moment has been obtained.

[0036] Step S003: Integrate all operational risk coefficients to obtain their weighted average risk coefficient, and then combine them with the expected value of the trust probability obtained from the number of trusted accesses to obtain the dynamic trust probability.

[0037] The analysis of the above steps demonstrates the possibility of momentary behavioral anomalies in the data element circulation system during user access. However, it is difficult to reflect the risks of long-term historical behavioral patterns in the historical user access process. This leads to the misjudgment of occasional misoperations as risky operations in the data security sharing of the data element circulation system, causing users' legitimate and reasonable access to be misjudged and blocked.

[0038] Based on the above analysis, the operational risk coefficients A calculated from all past operations of each user are sorted in chronological order of access time to obtain the user's risk coefficient sequence. Using each user's risk coefficient sequence as input, a time-decay-based weighted moving average method is applied to output the weighted average risk coefficient for each user. The output weighted average risk coefficient This represents the risk level of a user during their historical visits; the higher the value, the higher the risk of abnormal access in the user's recent visits. In this embodiment, the decay factor of the algorithm is set to 0.2.

[0039] The weighted average algorithm described above can reflect the risk level of a user's historical operations by combining time trends, but it is difficult to characterize the credibility of a user's operations throughout the entire operation cycle. For new users or users with low frequency of access, the insufficient sample size can easily lead to evaluation distortion.

[0040] Therefore, a judgment threshold is set, and user access with an operation risk coefficient A less than or equal to the judgment threshold is considered trusted access; in this embodiment, the judgment threshold is 1.

[0041] Using the total number of user visits and the number of visits deemed trustworthy during the user's visits as input, a trust probability density function based on a Beta distribution is used to output the expected trust probability value for each user. The output expected trust probability value represents the probability of the user's next visit being trustworthy, calculated by the density function based on the user's historical visits. A higher value indicates a better user reputation in the past and higher security for the next visit. In this embodiment, the shape parameter of the trust probability density function is set to... , , where r is the number of trusted accesses and n is the total number of user accesses.

[0042] The dynamic trust probability of each user is determined based on the weighted average risk coefficient and the expected value of the trust probability.

[0043] The dynamic trust probability is positively correlated with the expected value of the trust probability and negatively correlated with the weighted average risk coefficient.

[0044] Preferably, in this embodiment, the expression for the dynamic trust probability is: , Indicates the weighting coefficient. This represents the weighted average risk coefficient. This refers to the sigmoid function, which performs normalization. This represents the expected value of the trust probability. This represents the dynamic trust probability.

[0045] The time-decay-based weighted moving average method is used for time series analysis. By setting a decay factor, different weights are assigned to data at different time points, thereby highlighting the influence of recent data on future trends. The confidence probability density function based on the Beta distribution is the conjugate prior distribution used in Bayesian statistics to estimate the probability of a binomial distribution. Its expected value can estimate the probability of future events based on historical data, thereby avoiding extreme probabilities caused by insufficient samples.

[0046] Based on the above principles and understanding, this application introduces the weighted moving average method to extract the recent behavioral change trend from the user's historical access risk; however, since the weighted moving average method is affected by short-term fluctuations, it is difficult to reflect the changes in the user's entire operation behavior process. Therefore, the Beta distribution trust probability is further introduced to take into account both long-term and short-term credible probability of user operation behavior, which is suitable for the evaluation of new users or low-frequency users.

[0047] At this point, the dynamic trust probability for each user has been obtained.

[0048] Step S004: Adjust the validity period of the user attribute certificate based on the dynamic trust probability to complete secure data sharing.

[0049] Through the analysis of the above steps, the dynamic trust probability B of each user after each access is obtained. In the existing technology, although attribute-based encryption (CP-ABE) can achieve fine-grained access control, its access policy is usually static. In the static policy, the validity period of the attribute certificate is fixed, which makes the revocation of permissions untimely and easily leads to data leakage.

[0050] Therefore, this application proposes a dynamic attribute certificate management strategy based on dynamic trust probability, which achieves real-time closed-loop control of user permissions by dynamically adjusting the validity period of attribute certificates.

[0051] The validity period of a user attribute certificate is adjusted based on the user's dynamic trust probability, and the expression is as follows: , This indicates the minimum validity period of the data element circulation system. This indicates the maximum validity period of the data element circulation system. This represents the user's dynamic trust probability. This indicates the adjusted validity period. In this embodiment, the minimum and maximum validity periods of the data element circulation system are system preset values, which are 10 days and 30 days respectively.

[0052] Based on the above analysis, the validity period is dynamically adjusted by the user's dynamic trust probability, achieving refined dynamic management of user permissions. When the risk of user behavior increases, the dynamic trust probability decreases and the validity period shortens, forcing the system to reassess user attributes more frequently and promptly block potential risks; when user behavior is stable and trustworthy, the dynamic trust probability increases and the validity period extends, improving user experience and reducing management burden.

[0053] This completes the secure sharing of data element circulation systems.

Claims

1. A method for secure data sharing in a data element circulation system, characterized in that, The method includes the following steps: Obtain the current and vibration sequences at each data acquisition moment from the user, and acquire the time series database; For the current sequence, a time window is set; for the vibration sequence, a Fourier transform is performed, and the main frequency energy ratio is determined by the difference between its main frequency energy value and the total energy value. The operational risk coefficient of the user at each acquisition moment is determined by combining the maximum power consumption instability of the current within all time windows and the intensity of the maximum instantaneous power consumption impact. The operational risk coefficients at all collection times are sorted into a risk coefficient sequence according to time sequence, and their weighted average risk coefficient is obtained; the total number of user accesses is extracted from the time sequence database, and the number of trustworthy accesses is filtered based on the operational risk coefficients. The number of trustworthy accesses is used as the input of the probability density function to obtain the expected value of the trust probability; the dynamic trust probability is determined based on the weighted average risk coefficient and the expected value of the trust probability. The validity period of user attribute certificates is adjusted based on dynamic trust probability to achieve secure data sharing.

2. The data security sharing method for a data element circulation system as described in claim 1, characterized in that, The current sequence is a normalized sequence of all currents acquired before each acquisition time; the vibration sequence is a normalized sequence of all vibration signals acquired before each acquisition time.

3. The data security sharing method for a data element circulation system as described in claim 1, characterized in that, The main frequency energy ratio is the ratio of the main frequency energy value to the total energy value.

4. A data security sharing method for a data element circulation system as described in claim 1, characterized in that, The operational risk coefficient is positively correlated with the degree of instability of maximum power consumption and the intensity of the maximum instantaneous power consumption impact, respectively; and negatively correlated with the main frequency energy value.

5. A data security sharing method for a data element circulation system as described in claim 1, characterized in that, The power consumption instability is defined as the standard deviation of all currents within a time window.

6. A data security sharing method for a data element circulation system as described in claim 1, characterized in that, The intensity of the maximum instantaneous power consumption surge is the peak-to-average power ratio of the current value within the time window.

7. A data security sharing method for a data element circulation system as described in claim 1, characterized in that, The weighted average risk coefficient is the value output by taking the risk coefficient sequence as input and using a time-decay-based weighted moving average method.

8. A data security sharing method for a data element circulation system as described in claim 1, characterized in that, The dynamic trust probability is positively correlated with the expected value of the trust probability and negatively correlated with the weighted average risk coefficient.

9. A data security sharing method for a data element circulation system as described in claim 1, characterized in that, The expression for the dynamic trust probability is: , Indicates the weighting coefficient. This represents the weighted average risk coefficient. This represents the sigmoid function. This represents the expected value of the trust probability. This represents the dynamic trust probability.

10. A data security sharing method for a data element circulation system as described in claim 1, characterized in that, The method for adjusting the validity period of user attribute certificates based on dynamic trust probability is as follows: , This indicates the minimum validity period of the data element circulation system. This indicates the maximum validity period of the data element circulation system. This represents the user's dynamic trust probability. This indicates the adjusted validity period.