A data center secure communication and training inference system and method based on QKD and TEE
By combining quantum key distribution with a trusted execution environment, the problems of identity authentication and data transmission security across data centers are solved, high-frequency dynamic key updates and data isolation are achieved, and the security and scalability of data center communication are improved.
Patent Information
- Application Number
- CN202610698456.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-20
- Publication Date
- 2026-08-25
AI Technical Summary
Data transmission across data centers presents challenges such as high computational overhead for authentication and key negotiation, limited key update frequency, difficulty in balancing security and real-time performance, and the vulnerability of raw training data to leakage.
A system architecture based on quantum key distribution (QKD) and trusted execution environment (TEE) is adopted. Symmetric encryption is achieved through quantum key negotiation, peer-to-peer authentication is established, and the isolation and one-way publication mechanism between the training domain and the inference domain are combined to ensure data transmission security and control data flow.
It increases the frequency of key updates, enhances the level of communication confidentiality, reduces the risk of data leakage, and achieves high security and real-time update capabilities, making it suitable for scalability and deployment in multiple data centers.
Smart Images

Figure CN122640109A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a data processing system and method, and more particularly to a data center secure communication and training inference system and method. Background Technology
[0002] As the digitalization of sectors such as government affairs, finance, energy, healthcare, and manufacturing continues to increase, numerous independent data centers have been built within these industries, creating fragmented data silos. To support emerging AI applications such as large-scale model training, industry-specific intelligent analysis, embodied intelligence, and world models, it is often necessary to centrally process and train multi-source heterogeneous data in higher-level data centers.
[0003] In existing technologies, data transmission across data centers typically employs traditional leased lines, VPNs, TLS / IPSec, or conventional symmetric cryptographic schemes. These schemes generally rely on traditional cryptographic systems for key generation, distribution, updating, and management. In particular, authentication and key negotiation often require asymmetric cryptographic mechanisms, resulting in significant computational overhead for authentication and key negotiation, difficulty adapting to high-frequency, low-latency data scheduling scenarios, a high risk of exposure for long-term static keys or infrequently updated keys, and a difficulty in simultaneously achieving high security, real-time update capabilities, and efficiency for large-scale data transmission.
[0004] On the other hand, while existing privacy computing, multi-party secure computing, or homomorphic encryption technologies can reduce plaintext exposure to some extent, they have high computational overhead and complex deployment in large-scale artificial intelligence training tasks, making it difficult to meet the requirements of high throughput, low latency, and engineering implementation.
[0005] Furthermore, even if data is securely transmitted to the centralized training side, if there is a lack of effective isolation between the training environment, the original data storage environment, and the model inference service environment, there may still be issues such as the original industry data on the training side being accessed laterally or indirectly by external inference interfaces, the lack of isolation between the model release link and the training link leading to the retention or leakage of sensitive data, and the lack of verifiable destruction and auditing mechanisms after data use, which is not conducive to the circulation of data elements and compliance management.
[0006] In light of the needs for building a trusted data space, the practical implementation is more likely to involve higher-level city, regional, or national data centers taking on a coordinating role, with industry data centers serving as edge data source nodes connected to a unified trusted network and training system. Therefore, a new system architecture is urgently needed to enable higher-level authentication and data transmission between industry data centers and central nodes, and to build a trusted execution environment on the centralized training side. This architecture, through isolation between the training and inference domains and a one-way publishing mechanism, will ensure the secure use of industry data and the controlled output of models. Summary of the Invention
[0007] Purpose of the invention: To address the aforementioned existing technologies, this invention proposes a secure communication and training inference system and method for data centers based on Quantum Key Distribution (QKD) and Trusted Execution Environment (TEE). This system solves the problems in existing technologies, such as cross-data center authentication relying on traditional asymmetric cryptography, limited authentication efficiency and update frequency, lack of highly secure and real-time key-updating encrypted networks for large-scale cross-data center data transmission, and the risk of leakage due to the mixing of raw industry data with model inference services after centralized training.
[0008] Technical solution: A data center secure communication and training inference system based on QKD and TEE, including: industry data center nodes, city-level data center nodes, quantum key transceiver terminals, quantum key management devices, quantum encryption and decryption application devices, trusted execution environment management module, training domain storage and computing module, inference domain storage and service module, training-to-inference one-way publishing module, and data lifecycle management and auditing module; The industry data center nodes are used to generate or store raw industry data; the city data center nodes are used to reliably load, train, analyze, and generate models from the received data. The quantum key transceiver terminal, quantum key management device, and quantum encryption / decryption application device work together to achieve quantum key negotiation, storage, and scheduling, using quantum keys as a unified key source for identity authentication and business encryption. Specifically, the quantum key transceiver terminal is used to complete quantum state transmission, reception, and quantum key negotiation on the quantum channel; the quantum key management device is used to complete key storage, key scheduling, key relay, key access control, and key output; and the quantum encryption / decryption application device is used to encrypt, decrypt, and transmit business data. The Trusted Execution Environment Management module is used to perform trusted measurement, remote verification, or integrity verification of training tasks, data loading processes, program images, and running status. The training domain is used for training on raw data, and the inference domain is used to provide inference services to the outside world. The two are completely isolated in terms of hardware, virtualization resource pool, network plane, and access control policies. The one-way publishing module is used to allow only the training products to be transmitted unidirectionally from the training domain to the inference domain, and prohibits the inference domain from reading the original data of the training domain in reverse through network access, interface calls, file system mounting, and shared storage. The data lifecycle management and auditing module is used for full-process data policy control, record keeping, destruction, and audit report generation.
[0009] A data center secure communication and training inference method based on QKD and TEE includes the following steps: (1) Industry data center nodes and city data center nodes generate shared quantum keys in quantum channels and classical channels through quantum key transceiver terminals; (2) Extract or derive authentication keys based on shared quantum keys, complete point-to-point dynamic identity authentication and establish secure business sessions, and continuously update the authentication key index for the next round. (3) Industry data is encrypted using quantum key or quantum key-driven symmetric encryption algorithms and then transmitted to city data center nodes via classical networks; (4) After the encrypted text is decrypted, it is loaded into the training domain under the control of the trusted execution environment management module to carry out model training, fine-tuning or evaluation; (5) After the training products are reviewed by the one-way release module, they are one-way released to the reasoning domain to provide reasoning services to the outside world; (6) Destroy the original training domain data according to the preset strategy, and generate full-process audit records and destruction reports.
[0010] Beneficial effects: 1. Quantum key distribution enables a unified source of authentication and encryption keys, increasing the key update frequency and reducing reliance on traditional asymmetric authentication.
[0011] 2. It can achieve one-time key communication in high-security scenarios, or high-frequency dynamic key-swapping communication based on quantum keys in engineering deployments, thereby improving the overall security level.
[0012] 3. Training tasks are carried out in a trusted execution environment within the city data center, enabling the industry's raw data to be effectively utilized within a controlled scope and reducing the risk of direct exposure.
[0013] 4. By isolating the training domain from the inference domain and implementing a one-way publishing mechanism, the risk of indirect access to raw industry data by the inference side, external network side, or operations and maintenance side is reduced.
[0014] 5. By regularly destroying data and leaving audit trails, the compliance and controllability of data elements in the circulation process can be enhanced, which is conducive to data hosting training and secure collaboration.
[0015] 6. Suitable for multiple industry data centers to access a unified city data center or regional computing center, with good scalability and practical value. Attached Figure Description
[0016] Figure 1 This is a diagram of the overall system architecture of the present invention.
[0017] Figure 2 This is a diagram illustrating the point-to-point quantum secure communication architecture between industry data centers and city data centers.
[0018] Figure 3 This is a timing diagram for dynamic identity authentication based on quantum keys. Detailed Implementation
[0019] The invention will now be further explained with reference to the accompanying drawings.
[0020] A data center secure communication and training inference system based on QKD and TEE, such as Figure 1 As shown, it includes industry data center nodes, city data center nodes, quantum key transceiver terminals, quantum key management devices, quantum encryption and decryption application devices, trusted execution environment management modules, training domain storage and computing modules, inference domain storage and service modules, training-to-inference one-way publishing modules, and data lifecycle management and auditing modules.
[0021] The system comprises the following components: Industry data center nodes for generating or storing raw industry data to be trained or analyzed; City data center nodes for trusted loading, training, analysis, and model generation of received data; Quantum key transceiver terminals for transmitting and receiving quantum states and negotiating quantum keys on quantum channels; Quantum key management devices for key storage, key scheduling, key relay, key access control, and key output; Quantum encryption / decryption application devices for encrypting, decrypting, and transmitting business data; Trusted execution environment management modules for trusted measurement, remote verification, or integrity checks of training tasks, data loading processes, program images, and runtime status; a training domain for training raw data and an inference domain for providing inference services, with complete isolation between the two in terms of hardware, virtualization resource pools, network plane, and access control policies; a one-way publishing module for allowing only trained models, parameters, or selected inference products to be transmitted unidirectionally from the training domain to the inference domain, while prohibiting the inference domain from accessing the raw data in the training domain in the reverse direction; and a data lifecycle management and auditing module for policy control and auditing of data reception, use, caching, archiving, and destruction processes.
[0022] In a more specific implementation, the city data center node serves as a high-level coordination node, providing unified access authentication, data aggregation, training scheduling, model deployment, and audit management functions to multiple industry data centers; multiple industry data center nodes connect to the high-level coordination node as edge nodes. The high-level coordination node can be a city-level center, a regional-level center, or a national-level coordination center.
[0023] In one embodiment of the present invention, instead of using a conventional certificate authentication mechanism based on asymmetric cryptography, the industry data center and the city data center implement peer-to-peer authentication based on a symmetric key generated by quantum key distribution. For example... Figure 2 , Figure 3 As shown, the authentication label can be generated and verified using a national cryptographic algorithm component based on SM4, SM3, or a combination thereof. The authentication process includes the following steps: S1. Industry data centers and city data centers generate a set of shared quantum keys through a quantum key distribution link.
[0024] S2. Both parties extract the first authentication key from the shared quantum key, or generate the first authentication key based on the shared quantum key through a preset derivation algorithm.
[0025] S3. The sending end sends an authentication request to the receiving end, which includes an identity identifier, a timestamp, a random number, and an authentication tag.
[0026] S4. The receiving end uses the corresponding local authentication key to verify the authentication tag, and generates a response random number and response authentication tag to return to the sending end.
[0027] S5. The sending end verifies the authentication tag in the response and establishes the current business session after successful verification.
[0028] S6. After each authentication is completed, both parties derive the next round of authentication keys based on the newly generated quantum key or based on the remaining quantum key, thereby realizing the rolling update of authentication keys.
[0029] After authentication, the industry data center and the city data center transmit encrypted data over a standard classical network, with the key required for encryption provided in real-time or near real-time by a quantum key management device. When the quantum key generation rate meets business requirements, a one-time pad method can be used to encrypt business data or fragmented business data. When business bandwidth is high or the quantum key rate needs to be optimized, the quantum key can be used as a session key, segment key, or master key for frequent key changes to symmetric encryption algorithms such as SM4 and AES. In a preferred embodiment, SM4 is used as the national standard block cipher for business data encryption and decryption; the key update conditions can be dynamically adjusted based on time periods, data volume thresholds, business sensitivity levels, or link status.
[0030] In one embodiment of the present invention, a trusted execution environment management module is set up inside the urban data center. This module can impose trusted constraints on the training task execution environment based on trusted hardware, trusted boot, remote authentication, execution mirroring measurement, memory protection, or controlled access mechanisms. It is used to verify the integrity of the training program, data access program, and model building program; check the identity of the entity initiating data reading, the task number, and the tenant identifier; restrict data within the training domain to be decrypted and used only within the controlled environment; and output trusted audit records to data providers, platform providers, or regulators.
[0031] This invention further establishes isolated training and inference domains. The training domain receives raw industry data, performs model training, fine-tuning, and evaluation; the inference domain hosts external service interfaces and provides only model inference capabilities. The raw industry data storage medium and the model service medium are separated in terms of hardware, virtualization resource pool, network plane, or access control policies. To prevent the inference domain from accessing the raw industry data in the training domain, this invention includes a one-way publishing module. The one-way publishing module can be implemented using a hardware one-way transmission device, a controlled export gateway, an offline audit export device, or a write-only publishing queue. It only allows trained model files, model parameters, weight summaries, anonymized evaluation results, or permitted inference materials to be output from the training domain to the inference domain. The inference domain is not allowed to read the raw data in the training domain from the training domain via network access, interface calls, file system mounting, or shared storage. Simultaneously, the output model undergoes version registration, hash verification, and publishing approval records, and the exported objects are type-checked to prevent objects carrying raw data samples or sensitive cached content from leaking out.
[0032] This invention also supports industry data centers in continuously transmitting incremental, revised, or batch data to city data centers via a quantum secure communication network according to a preset frequency or event-triggered mechanism. In one implementation, the platform treats each batch of data as an independent data asset unit and establishes for it a data source identifier, data ownership or usage right identifier, transmission batch identifier, permitted usage scope, retention period, destruction time point, and audit record. This enables industry data to participate in model training in a controlled manner through exchange, use, and destruction, forming a secure foundation suitable for data asset hosting training or the construction of a trusted data space.
[0033] After model training, analysis, or a specified business task is completed, the data lifecycle management and auditing module triggers one or more of the following actions according to the policy: deleting the original data copy in the training domain, deleting cache files and temporary decryption files, deleting or invalidating the corresponding data encryption key index, retaining irreversible digests and access logs, and generating a destruction report for data provider verification. Destruction triggering conditions can be task completion, authorization expiration, regulatory instructions, batch replacement, or storage period expiration.
[0034] In one embodiment of the present invention, the data access, training, publishing and destruction process is as follows: S1: Data access and identity authentication; S2: Quantum key protected transmission; S3: Trusted loading of training domain; S4: Model training / fine-tuning; S5: One-way publishing to inference domain; S6: Data destruction and audit output.
[0035] Depending on the number of data centers, this invention can employ different quantum encryption network topologies: when there are only two data centers, a point-to-point quantum secure communication link is used; when there are three data centers, a ring or triangular interconnection topology is used; when there are four or more data centers, a star topology is used, with key scheduling and relay management implemented through core city data centers or core quantum nodes. Therefore, this invention possesses the engineering implementation capability to gradually expand from small-scale pilot projects to multi-node networks.
[0036] This invention also provides a secure communication and training inference method for data centers based on QKD and TEE, including steps such as quantum key generation, dynamic identity authentication, encrypted transmission of business data, trusted loading of training domain, model training and one-way publication, and periodic destruction and auditing of original data; under authorized conditions, the new version of the model after training can also be transmitted back to the corresponding industry data center through an encrypted network for private deployment, edge inference or local business updates on the industry side, but the original industry data is not returned with the model backflow link.
[0037] Example 1: Secure training link between industry data centers and city data centers Step S101: The quantum key transmitting terminal on the industry data center side and the quantum key receiving terminal on the city data center side generate a shared quantum key through quantum channel and classical channel.
[0038] Step S102: The quantum key management devices of both parties store the corresponding shared quantum key and provide the authentication key and business encryption key to their respective quantum encryption and decryption application devices.
[0039] Step S103: The industry data center initiates an identity authentication request to the city data center based on the authentication key. The authentication message carries the node identifier, random number, timestamp and authentication tag. The authentication tag is preferably generated using a national cryptographic algorithm component based on SM4, SM3 or a combination thereof.
[0040] Step S104: After verifying the authentication tag, the city data center returns an authentication response. After completing the verification, the industry data center establishes a secure business session and updates the authentication key index for the next round.
[0041] Step S105: After the industry data center segments the data to be trained, it encrypts it directly with quantum keys or with a symmetric block cipher driven by quantum keys, and sends the ciphertext through a classical network; in the preferred embodiment, the symmetric block cipher is implemented using the SM4 algorithm.
[0042] Step S106: After receiving the ciphertext, the city data center reads the corresponding key from the local quantum key management device to complete the decryption, and loads the decrypted data into the training domain under the control of the trusted execution environment management module.
[0043] Step S107: The training domain completes model training, fine-tuning, or analysis tasks, generating model files, weight parameters, and evaluation results.
[0044] Step S108: After review by the one-way publishing module, only model files, weight parameters, or permitted output results are allowed to be published to the inference domain to provide inference services to external parties; raw industry data remains in the training domain for controlled use and is periodically destroyed according to the strategy.
[0045] Example 2: Star-shaped quantum secure network for multi-industry data center access In this embodiment, multiple industry data centers establish quantum key distribution links with a city data center. The city data center, as the core node, provides access authentication, key scheduling, task orchestration, and centralized audit management for each edge node.
[0046] When industry data center A and industry data center B need to share intermediate results or participate in joint tasks, they can first establish quantum key distribution with the city data center respectively. Then, the city data center can coordinate the use of keys by both parties or carry out controlled key forwarding according to the strategy, so as to complete collaborative communication without exposing the original key content.
[0047] Example 3: Destruction Mechanism for Data Asset Custody Training In this embodiment, data batches uploaded from the industry data center are assigned data asset numbers, authorization periods, and destruction policies before entering the training domain. After the training task is completed, the system automatically retrieves the associated data batches based on the task number and performs original file deletion, cache invalidation, intermediate file cleanup, and key index invalidation processing, while generating a destruction audit report with a timestamp.
[0048] Example 4: Centralized Aggregation Training for Trusted Data Space In this embodiment, multiple industry data centers correspond to data providers in government affairs, finance, healthcare, energy, manufacturing, or other industries. These industry data centers do not directly exchange data freely with each other; instead, they connect to a unified high-level central node through a quantum-secured communication network. This high-level central node can be a city-level data center, a regional data center, or a national-level coordination center.
[0049] Data centers across various industries establish trusted connections with high-level central nodes through a quantum key-based peer-to-peer dynamic authentication mechanism, and send the training data required to the central training domain under quantum key protection. The central side completes model training, fine-tuning, or world model training in a trusted execution environment, and publishes the trained model to the inference domain or back to authorized industry nodes through a one-way publishing module.
[0050] This implementation method is applicable to scenarios involving unified aggregation, unified training, unified auditing, and unified release in the construction of a trusted data space.
[0051] Example 5: Update mechanism for training model backflow to the industry side In this embodiment, the industry data center continuously uploads incremental data to the central training domain via a quantum secure communication network. The central training domain then retrains, incrementally trains, or fine-tunes the existing model based on the new data. After training, the new version of the model can be output to the inference domain via a one-way publishing module, or, under authorized conditions, transmitted back to the corresponding industry data center via an encrypted network for private deployment on the industry side, edge inference, or local business updates.
[0052] In this process, raw industry data flows unidirectionally into the central training domain; model versions, model parameters, or model encapsulation products can be returned to the industry side as controlled output objects; quantum key distribution continues to protect the transmission link during the return process; the industry side is not allowed to use the model return link to request raw sample data from the training domain in reverse.
[0053] Example 6: A Progressive Scaling Solution for Engineering Deployment In this embodiment, the system first forms a demonstration network with a small number of industry nodes and a central node, completing closed-loop verification of point-to-point quantum secure communication, dynamic identity authentication, trusted loading of training domains, and one-way model distribution. Subsequently, based on the number of access nodes, the system expands the quantum key distribution equipment, edge access devices, and central key management capabilities, gradually evolving into a multi-node star-shaped quantum secure network. This implementation demonstrates that the present invention is applicable not only to large-scale networking but also to a gradual deployment path from small-scale pilot projects to large-scale deployment.
[0054] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A secure data center communication and training inference system based on QKD and TEE, characterized in that, include: Industry data center nodes, city-level data center nodes, quantum key transceiver terminals, quantum key management devices, quantum encryption and decryption application devices, trusted execution environment management modules, training domain storage and computing modules, inference domain storage and service modules, training-to-inference one-way publishing modules, and data lifecycle management and auditing modules; The industry data center nodes are used to generate or store raw industry data; the city data center nodes are used to reliably load, train, analyze, and generate models from the received data. The quantum key transceiver terminal, quantum key management device, and quantum encryption / decryption application device work together to achieve quantum key negotiation, storage, and scheduling, using quantum keys as a unified key source for identity authentication and business encryption. Specifically, the quantum key transceiver terminal is used to complete quantum state transmission, reception, and quantum key negotiation on the quantum channel; the quantum key management device is used to complete key storage, key scheduling, key relay, key access control, and key output; and the quantum encryption / decryption application device is used to encrypt, decrypt, and transmit business data. The Trusted Execution Environment Management module is used to perform trusted measurement, remote verification, or integrity verification of training tasks, data loading processes, program images, and running status. The training domain is used for training on raw data, and the inference domain is used to provide inference services to the outside world. The two are completely isolated in terms of hardware, virtualization resource pool, network plane, and access control policies. The one-way publishing module is used to allow only the training products to be transmitted unidirectionally from the training domain to the inference domain, and prohibits the inference domain from reading the original data of the training domain in reverse through network access, interface calls, file system mounting, and shared storage. The data lifecycle management and auditing module is used for full-process data policy control, record keeping, destruction, and audit report generation.
2. The system according to claim 1, characterized in that, The city-level data center node serves as the core node, while multiple industry data center nodes connect as edge nodes. The core coordinating node provides unified access authentication, data aggregation, training scheduling, model release, and audit management functions. The system adopts a point-to-point, ring, or star quantum encryption network topology. Four or more data centers use a star topology with the core node implementing key scheduling and relay management.
3. The system according to claim 1, characterized in that, The industry data center nodes and city data center nodes implement point-to-point identity authentication based on symmetric keys generated by quantum key distribution. The authentication tags are generated and verified using national cryptographic algorithm components such as SM4, SM3, or combinations thereof. After authentication, the next round of authentication keys is derived based on the new quantum key or the remaining quantum key, thereby realizing the rolling update of authentication keys.
4. The system according to claim 3, characterized in that, When the quantum key generation rate meets the business requirements, one-time pad is used for business data encryption. In high-bandwidth scenarios, quantum keys are used as session keys, segment keys, or master keys to drive the SM4 symmetric encryption algorithm for high-frequency key switching. Key updates are dynamically adjusted according to time period, data volume threshold, business sensitivity level, or link status.
5. The system according to claim 1, characterized in that, The one-way publishing module is implemented using a hardware one-way transmission device, a controlled export gateway, an offline audit export device, or a write-only publishing queue. It performs version registration, hash verification, publishing approval, and type checking on the output model to prevent objects carrying original data samples or sensitive cached content from flowing out.
6. The system according to claim 1, characterized in that, The data lifecycle management and auditing module treats each batch of data as an independent data asset unit, assigning it a data source identifier, ownership or usage right identifier, transmission batch identifier, permitted usage scope, retention period, and destruction time point. Destruction is triggered by task completion, authorization expiration, regulatory instructions, batch replacement, or storage cycle expiration, executing the deletion of original data copies, cache files, temporary decryption files, and invalidation of key indexes, retaining irreversible digests and access logs, and generating a destruction report.
7. A data center secure communication and training inference method based on QKD and TEE, characterized in that, Includes the following steps: (1) Industry data center nodes and city data center nodes generate shared quantum keys in quantum channels and classical channels through quantum key transceiver terminals; (2) Extract or derive authentication keys based on shared quantum keys, complete point-to-point dynamic identity authentication and establish secure business sessions, and continuously update the authentication key index for the next round. (3) Industry data is encrypted using quantum key or quantum key-driven symmetric encryption algorithms and then transmitted to city data center nodes via classical networks; (4) After the encrypted text is decrypted, it is loaded into the training domain under the control of the trusted execution environment management module to carry out model training, fine-tuning or evaluation; (5) After the training products are reviewed by the one-way release module, they are one-way released to the reasoning domain to provide reasoning services to the outside world; (6) Destroy the original training domain data according to the preset strategy, and generate full-process audit records and destruction reports.
8. The method according to claim 7, characterized in that, The point-to-point dynamic identity authentication specifically involves the sending end sending an authentication request containing an identity identifier, timestamp, random number, and authentication tag; the receiving end verifying the authentication tag and returning a response random number and response authentication tag; and the session establishment is completed after the sending end's verification is successful.
9. The method according to claim 7, characterized in that, Industry data center nodes continuously transmit incremental, revised, or batch data to city data center nodes via a quantum secure communication network at a preset frequency or through an event-triggered mechanism, while raw industry data flows unidirectionally into the central training domain.
10. The method according to claim 7, characterized in that, Once trained, the new version of the model is transmitted back to the corresponding industry data center node via an encrypted network under authorized conditions. This data is used for private deployment on the industry side, edge inference, or local business updates. The original industry data is not returned along with the model transmission link.