A data compliance assurance method and system

CN122824490APending Publication Date: 2026-09-25BEIJING HUAIROU SCIENCE CITY INSTITUTE OF MASS SPECTROMETRY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611200869.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-10
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

[0005]为此,本发明所要解决的技术问题在于提供一种数据合规性保障方法及系统,克服了现有技术中数据合规性保障依赖不可信软件环境、无法从源头绑定时空信息、改造会破坏原厂软件兼容性等问题

Benefits of technology

1、从物理根源保障数据防篡改。通过在数据源仪器与终端之间部署独立的硬件或专用软件单元,对原始数据流在源头进行拦截、注入时空指纹并硬件加密,整个过程脱离不可信的主机操作系统环境,杜绝了通过软件方式事后篡改时间、替换数据文件的可能性。采用独立硬件安全网关时,数据加密和时空标记均在独立的硬件设备内完成,与电脑操作系统物理隔离,合规举证力强;采用软件抓包模块时,也能在第一时间捕获原始数据并加盖指纹,同时记录完整性校验值,一旦被篡改即可发现。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122824490A_ABST
    Figure CN122824490A_ABST
Patent Text Reader

Abstract

The application provides a data compliance guarantee method and system, and relates to the technical field of data security and compliance control. A data flow control unit is deployed between a data source instrument and a data processing terminal; a device-specific root key is generated and solidified based on the physical unique identification of a hardware encryption chip; original collected data flow is intercepted in real time, and time-space fingerprint information is generated by an independent time-space perception module and embedded into a data packet; the data with time-space fingerprints is transmitted and stored after hardware-level encryption packaging based on the root key; a bottom-layer driver is deployed at the terminal to read and decrypt in real time and restore to the original data format for direct reading by upper-layer application software. The application ensures the data non-tamperability and time-space traceability through data flow source interception, hardware root key binding and independent time-space fingerprint binding, and at the same time, the original factory software ecology is preserved through bottom-layer transparent restoration, so that non-invasive large-scale inventory equipment compliance modification is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of data security and compliance management technology, and in particular relates to a data compliance assurance method and system. Background Technology

[0002] In scenarios requiring the authenticity, integrity, and traceability of raw data collection, such as analytical instrument testing, industrial process monitoring, and environmental data acquisition, ensuring that raw data is not tampered with, replaced, or falsified throughout the entire process from generation by the data source instrument to reading by the terminal software is a core requirement of data compliance. Relevant regulations require that raw data must be tamper-proof and traceable, and that the context information at the time of its generation must be truthfully and non-repudiable.

[0003] Currently, most existing data compliance assurance measures rely on audit trails, file encryption, and timestamp signatures at the host computer operating system or application software level. These solutions have several key drawbacks: First, timestamps and other information are generated by the computer operating system, and can be easily forged by high-level personnel in the laboratory by modifying the system time, making the underlying trust chain unreliable. Second, encryption operations are mostly performed after the file is created, making it impossible to bind to the real environment at the initial source of data generation, and making it difficult to prevent intentional substitution before or during data generation. Third, many encryption or security solutions, after being introduced, will damage the original data format relied upon by the original software of the data source instruments, causing the original software to be unable to read the data properly and perform subsequent analysis, requiring the replacement of specialized software, which faces significant resistance to implementation. Fourth, for a large number of existing deployed instruments, traditional security upgrades require disassembly, firmware flashing, or driver replacement, resulting in high costs and potential compatibility issues, and even voiding the instrument manufacturer's warranty.

[0004] Therefore, there is an urgent need for a data compliance assurance solution that can guarantee data authenticity from the source, bind unforgeable spatiotemporal attributes, not change the original operating procedures and data formats, and is easy to modify for existing instruments. Summary of the Invention

[0005] Therefore, the technical problem to be solved by the present invention is to provide a data compliance assurance method and system, which overcomes the problems of existing technologies such as data compliance assurance relying on untrusted software environments, inability to bind spatiotemporal information from the source, and modification damaging the compatibility of original software.

[0006] In a first aspect, the present invention provides a data compliance assurance method, comprising: Deploy the data flow control unit in the communication link between the data source instrument and the data processing terminal; A device-specific root key is generated and embedded using a physical unique identifier based on a hardware encryption chip; The data flow control unit intercepts the raw data streams output by the data source instrument in real time. Spatiotemporal fingerprint information is generated by the independent spatiotemporal perception module built into the data flow control unit, and the spatiotemporal fingerprint information is embedded into the data packet of the original acquired data flow. Based on the device's proprietary root key, the original data stream containing the spatiotemporal fingerprint information is hardware-level encrypted and encapsulated, and then transmitted to the data processing terminal for encrypted storage. The data processing terminal is equipped with an underlying driver that is used to decrypt encrypted data files in real time when reading them and restore them to the original data format of the data source instrument, so that the upper-level application software of the data source instrument can read them directly.

[0007] Furthermore, the data flow control unit is an independent hardware security gateway, which is connected to the communication link in series or by bypass parallel connection. The independent hardware security gateway is configured with a general interface for connecting the data source instrument without changing the original operating conditions and communication protocol of the data source instrument.

[0008] Furthermore, the independent hardware security gateway directly forwards the original data stream without intervention, and automatically switches to the data stream interception and encryption mode when it detects that the data source instrument has issued a data collection start command.

[0009] Furthermore, the device-specific root key is generated by hashing the unique identifier of the hardware encryption chip, the physical address of the data flow control unit, and the organization's authorization code.

[0010] Furthermore, the spatiotemporal fingerprint information includes time information generated by an independent high-precision hardware real-time clock or by synchronizing with the world standard time using a global navigation satellite system, and location information generated by dual-mode positioning of BeiDou and the global navigation satellite system or by a preset network address.

[0011] Furthermore, according to the method of claim 1, when the deployment location of the independent hardware security gateway changes or does not match the preset authorization record, the device-specific root key is automatically determined to be invalid, and the step of generating and solidifying the device-specific root key is re-executed.

[0012] Furthermore, it also includes: the regulatory audit end reads the encrypted data file stored on the data processing terminal through the authorized interface, extracts the device unique identifier in the data file, and matches the corresponding device public key from the cloud key management ledger for batch decryption.

[0013] Furthermore, after decryption, multi-dimensional compliance verification is performed in parallel. The verification includes: verifying the consistency between the standard time in the spatiotemporal fingerprint information and the preset authorized working period; verifying the matching between the physical location information in the spatiotemporal fingerprint information and the preset electronic geofence; and verifying the binding between the unique identifier of the device and the preset registered instrument ledger. When any verification fails, the corresponding data file is automatically marked and locked, and an immutable traceability log is generated. When all verifications pass, an audit report containing a compliance score and a full-chain traceability evidence chain is generated.

[0014] Furthermore, the data flow control unit is a software packet capture module deployed on the data processing terminal. It captures the original collected data stream in real time through communication packet capture and completes the embedding and encryption encapsulation of the spatiotemporal fingerprint information in the software layer. The software packet capture module also records the integrity verification value of the original data packet for detecting tampering behavior.

[0015] On the other hand, the present invention provides a data compliance assurance system, comprising: The data flow control module is deployed in the communication link between the data source instrument and the data processing terminal to intercept the raw data stream output by the data source instrument in real time. The key generation and spatiotemporal awareness module includes a hardware encryption chip and an independent spatiotemporal awareness module; the hardware encryption chip has a physically unique identifier embedded in it, which is used to generate and embed the device-specific root key. The independent spatiotemporal sensing module is used to generate spatiotemporal fingerprint information; The data stream control module is also used to embed the spatiotemporal fingerprint information into the data packet of the original acquired data stream, and to perform hardware-level encryption and encapsulation of the original acquired data stream containing the spatiotemporal fingerprint information based on the device-specific root key, and transmit it to the data processing terminal for encrypted storage. The transparent parsing module, deployed on the data processing terminal, includes an underlying driver. The underlying driver is used to decrypt the encrypted data file in real time when the file is read and restore it to the original data format of the data source instrument, so that the upper-layer application software of the data source instrument can read it directly.

[0016] Beneficial effects: 1. Protect data from tampering at the physical source. By deploying independent hardware or dedicated software units between the data source instrument and the terminal, the raw data stream is intercepted at the source, injected with a spatiotemporal fingerprint, and encrypted using hardware. The entire process is separated from the untrusted host operating system environment, eliminating the possibility of subsequent tampering with time or replacing data files via software. When using an independent hardware security gateway, data encryption and spatiotemporal marking are both completed within an independent hardware device, physically isolated from the computer operating system, providing strong compliance and evidentiary support. When using a software packet capture module, the raw data can be captured and fingerprinted in real time, while recording the integrity check value, making tampering immediately detectable.

[0017] 2. A robust and reliable spatiotemporal binding is achieved. A high-precision hardware clock independent of the computer system and BeiDou / GNSS dual-mode positioning ensure that time and location information cannot be tampered with, accurately anchoring the actual physical scene where data collection occurred. This allows regulatory audits to not only verify that the data content has not been modified, but also to verify whether the data was generated during the expected legal time period and at the legal location, effectively preventing hidden fraudulent activities such as off-site subcontracting and illegal nighttime supplementary measurements.

[0018] 3. No intrusive modifications are required to existing equipment, and the original operating procedures remain unchanged. When using an independent hardware security gateway, it connects in series or side-by-side via a universal interface, eliminating the need to disassemble the instrument or modify its internal firmware or circuitry. This protects the investment in existing equipment and avoids compatibility risks. The underlying transparent driver deployed on the terminal can decrypt and restore the data to its original format in real time when the file is read, allowing upper-layer application software to read and analyze data normally without any modifications. Operators are unaware of this process, ensuring workflow continuity.

[0019] 4. Secure key system isolation, achieving one key per device. Based on the unique hardware identifier and the organization's authorization code, the root key is derived. Each device and each site has a unique key that is not interchangeable. The key is embedded in the hardware chip and cannot be exported or copied, completely eliminating the large-scale data risk caused by the leakage of the global key.

[0020] 5. Supports multi-dimensional compliance verification, including real-time on-site assessment and remote batch auditing. By combining multiple verification methods such as time compliance, location fence matching, and device identity binding, it can automatically mark non-compliant documents, generate traceability logs, and generate qualified audit reports, greatly improving the efficiency and credibility of compliance reviews. Attached Figure Description

[0021] To make the content of this invention easier to understand, the invention will be further described in detail below with reference to specific embodiments and accompanying drawings.

[0022] Figure 1 This is a topology diagram of an external, sensorless, serial deployment according to Embodiment 1 of the present invention; Figure 2 This is a schematic diagram of the interconnection structure of the internal core hardware units in Embodiment 1 of the present invention; Figure 3 This is a full-link timing flowchart of Embodiment 1 of the present invention; Figure 4 This is a logic block diagram of anchor point binding and compliance verification in Embodiment 1 of the present invention; Figure 5 This is a schematic diagram illustrating the interaction between compliance auditing and evidence archiving in Embodiment 1 of the present invention. Detailed Implementation

[0023] The present invention will now be described in detail with reference to the accompanying drawings and embodiments. The principles and features of the present invention are described below with reference to the accompanying drawings. It should be noted that, unless otherwise specified, the embodiments and features described in these embodiments can be combined with each other. The embodiments given are only for explaining the present invention and are not intended to limit the scope of the present invention.

[0024] Example 1 This embodiment provides a data compliance assurance method, including the following steps: Deploy the data flow control unit in the communication link between the data source instrument and the data processing terminal; A device-specific root key is generated and embedded using a physical unique identifier based on a hardware encryption chip; The raw data streams from the data source instruments are intercepted in real time by the data flow control unit. Spatiotemporal fingerprint information is generated by the independent spatiotemporal perception module built into the data flow control unit, and the spatiotemporal fingerprint information is embedded into the data packet of the original acquired data stream. Based on the device's proprietary root key, the raw data stream containing spatiotemporal fingerprint information is hardware-level encrypted and encapsulated, and then transmitted to the data processing terminal for encrypted storage. The data processing terminal is equipped with an underlying driver that decrypts encrypted data files in real time during file reading and restores them to the original data format of the data source instrument, so that the upper-level application software of the data source instrument can read them directly.

[0025] As one specific implementation method, an independent hardware security gateway can be used as the data flow control unit. For example... Figure 1 As shown, the independent hardware security gateway connects to the communication link between the data source instrument and the data processing terminal via serial connection. The gateway is equipped with various universal interfaces, such as USB, RS232 serial port, and RJ45 network port, which can directly connect to the instrument's native communication port without changing the instrument's original operating conditions and communication protocol; it is plug-and-play. Therefore, it can seamlessly adapt to various existing instruments, both domestic and imported, without requiring internal circuit modifications or firmware flashing.

[0026] like Figure 2 As shown, the key generation and spatiotemporal awareness unit is built into the gateway, mainly consisting of a hardware encryption chip and an independent spatiotemporal awareness module. The hardware encryption chip is a physically unclonable chip, with a unique physical identifier (UID) embedded within it. The independent spatiotemporal awareness module integrates an independent high-precision hardware real-time clock (RTC) and a positioning unit. The positioning unit can obtain latitude and longitude coordinates through dual-mode positioning using BeiDou and Global Navigation Satellite System (GNSS), or it can pre-store IP addresses or location identifiers representing fixed laboratory locations set by the administrator.

[0027] At work, such as Figure 3 As shown, an independent hardware security gateway is deployed into the communication link to establish a transparent data transmission channel. The gateway initializes its key upon first power-on or upon detecting a change in the deployment environment. The gateway's hardware encryption chip reads its unique UID and obtains the gateway's physical address (MAC) and an authorization code pre-assigned by the compliance management agency. Internally, a 256-bit device-specific root key is generated through hash calculation and permanently stored. This root key never leaves the chip and cannot be exported, copied, or migrated. Furthermore, if the gateway's deployment location physically changes—for example, if a location change is detected by the built-in positioning module or if it does not match the authorized records—the gateway automatically determines that the root key is invalid and forces a re-execution of the key initialization steps, thereby firmly binding the device to the deployment location and preventing unauthorized misuse.

[0028] During routine non-data acquisition phases, the independent hardware security gateway operates in transparent pass-through mode, forwarding the raw data stream in real time without any intervention. During this phase, operators can use the instrument for all routine operations such as standby, method configuration, and optical path self-test; the gateway's existence is transparent to them. When the gateway's internal message recognition engine detects that the instrument has issued a formal data acquisition start command, if it parses the start flag in a specific communication protocol, the gateway will automatically switch to data stream interception and encryption mode within microseconds.

[0029] During the formal data acquisition phase, the data stream processing unit within the gateway intercepts every frame of raw data packets from the instrument in real time. Simultaneously, an independent spatiotemporal sensing module acquires the current precise time and location information. The current precise time information is provided by the RTC and can be periodically synchronized with Coordinated Universal Time (UTC) via GNSS, unaffected by the terminal computer's operating system time. The current location information includes latitude and longitude or preset location information. Based on this information, a standardized spatiotemporal fingerprint data block is generated and embedded into the metadata area or reserved fields of the raw data packets.

[0030] Next, the gateway uses a hardware encryption chip as its computing core and a pre-embedded device-specific root key to perform hardware-level encryption on the entire data packet or payload portion embedded with the spatiotemporal fingerprint. To ensure that no data collection points are lost during encryption, the gateway has a built-in high-speed cache unit. All data parsing, fingerprint embedding, and encryption operations are completed in a pipelined manner within the hardware buffer, keeping data processing latency within the millisecond-level allowable threshold, thereby ensuring the continuity of the data collection sequence and the distortion-free signal waveform. The encrypted and compliant data packet is then sent to the data processing terminal for encrypted storage via the original communication link.

[0031] A lightweight, transparent underlying driver is pre-installed on the data processing terminal. This driver operates in the operating system kernel mode and can silently monitor file read and write operations. When compliant data packets are received by the terminal and written to disk as encrypted data files, the underlying driver ensures that the file fully retains the standard data format defined by the instrument manufacturer, including file extensions, internal data structures, metadata headers, etc. When operators open the data file using the instrument's accompanying upper-level application software, such as specific analysis software or workstations, the underlying driver automatically decrypts the data in real time during the system's file reading process and restores the decrypted data to its original format before feeding it to the application software. The entire process is completely unnoticed by the application software and operators, without any pop-ups or additional operations. The software continues to perform its original functions such as data chart display, quantitative analysis, and report generation, achieving a perfect balance between encryption protection and business continuity.

[0032] As an optional implementation, this embodiment also provides a method of using a software packet capture module as a data flow control unit. For example... Figure 4 As shown, the packet capture module is installed and runs on the data processing terminal. It captures the raw data stream transmitted to the terminal from the data source instrument in real time through the operating system's network packet capture or communication port monitoring interface, either in a bypass or adaptive manner.

[0033] In this embodiment, the hardware encryption chip and the independent spatiotemporal sensing module can exist in other forms, such as utilizing the hardware security module originally configured on the terminal or an external USB encryption key, and cooperating with an independent spatiotemporal server via a network to generate the root key and spatiotemporal fingerprint. The spatiotemporal server can be a server with satellite time synchronization and a preset positioning strategy. After capturing the raw data stream, the software packet capture module embeds the spatiotemporal fingerprint information within the software layer, encrypts and encapsulates it based on the obtained root key, and then saves the encrypted data as a file.

[0034] Compared to using a standalone hardware security gateway, the software approach, while lacking hardware-level physical isolation and potentially vulnerable to tampering with captured data packets after an operating system attack, simultaneously records the integrity checksum of the original data packets, such as hash values. Subsequent file readings or compliance audits can then compare these checksums to detect tampering, providing a low-cost and easily deployable compliance assurance method, particularly suitable for scenarios already equipped with high-performance servers where adding additional dedicated hardware is inconvenient.

[0035] The encrypted data files mentioned above can all be easily supported for remote compliance auditing. For example... Figure 5 As shown, during remote auditing, the supervisory auditing end reads encrypted data files on the data processing terminal through a secure authorized interface. The auditing process first extracts the embedded unique device identifier from the file metadata or extended information, and then searches for and obtains the matching device public key from the cloud key management ledger database based on this identifier (in the case of asymmetric encryption assistance or key derivation), or requests the key management service to assist in decryption using the device root key. After obtaining decryption capability, batch files are decrypted.

[0036] After decryption, the auditing end performs multi-dimensional automated compliance checks in parallel: 1) Time dimension: The standard time carried by the spatiotemporal fingerprint of each data file is compared with the authorized working period preset for the laboratory to check for abnormal collection during non-working hours.

[0037] 2) Location dimension: Match the physical location information in the fingerprint with the preset electronic geofence of the registered laboratory to confirm whether the data was generated at the registered location.

[0038] 3) Equipment dimension: The unique identifier of the equipment recorded in the file is bound and verified with the registered instrument management ledger to prevent unregistered equipment from participating in data collection or data affiliation.

[0039] The system assesses the verification results: if any verification fails, the data file is immediately and automatically marked as non-compliant, locked, and cannot be modified or deleted. An immutable traceability log containing the time, verification item, and reason for failure is generated. If all verifications pass, the entire process is deemed compliant, and the auditing department automatically generates a comprehensive audit report. This report may include a compliance quantification score based on multi-dimensional weights, a violation distribution heatmap, and a complete traceability evidence chain that can be used for admissibility. This entire process is traceable, significantly improving regulatory efficiency and enhancing the legal validity and scientific rigor of the audit report.

[0040] Example 2 This embodiment provides a data compliance assurance system, including: The data flow control module is deployed in the communication link between the data source instrument and the data processing terminal to intercept the raw data stream output by the data source instrument in real time. The key generation and spatiotemporal awareness module includes a hardware encryption chip and an independent spatiotemporal awareness module; the hardware encryption chip has a physically unique identifier embedded in it, which is used to generate and embed the device-specific root key. The independent spatiotemporal sensing module is used to generate spatiotemporal fingerprint information; The data stream control module is also used to embed the spatiotemporal fingerprint information into the data packet of the original acquired data stream, and to perform hardware-level encryption and encapsulation of the original acquired data stream containing the spatiotemporal fingerprint information based on the device-specific root key, and transmit it to the data processing terminal for encrypted storage. The transparent parsing module, deployed on the data processing terminal, includes an underlying driver. The underlying driver is used to decrypt the encrypted data file in real time when the file is read and restore it to the original data format of the data source instrument, so that the upper-layer application software of the data source instrument can read it directly.

[0041] It should be noted that in the above embodiments, the time information output by the independent spatiotemporal sensing module is the hardware RTC or GNSS synchronization time independent of the operating system, and the location information is Beidou / GNSS dual-mode positioning or preset fixed IP / location data. This information cannot be arbitrarily modified by end users and is the foundation of trust for the entire compliance chain.

[0042] Obviously, the above embodiments are merely illustrative examples for clear explanation and are not intended to limit the implementation. Those skilled in the art will recognize that other variations or modifications can be made based on the above description. It is neither necessary nor possible to exhaustively list all possible implementations here. However, obvious variations or modifications derived therefrom are still within the scope of protection of this invention.

Claims

1. A method for ensuring data compliance, characterized in that, include: Deploy the data flow control unit in the communication link between the data source instrument and the data processing terminal; A device-specific root key is generated and embedded using a physical unique identifier based on a hardware encryption chip; The data flow control unit intercepts the raw data stream output by the data source instrument in real time. Spatiotemporal fingerprint information is generated by the independent spatiotemporal perception module built into the data flow control unit, and the spatiotemporal fingerprint information is embedded into the data packet of the original acquired data flow. Based on the device's proprietary root key, the original data stream containing the spatiotemporal fingerprint information is hardware-level encrypted and encapsulated, and then transmitted to the data processing terminal for encrypted storage. The data processing terminal is equipped with an underlying driver that is used to decrypt encrypted data files in real time when reading them and restore them to the original data format of the data source instrument, so that the upper-level application software of the data source instrument can read them directly.

2. The method according to claim 1, characterized in that, The data flow control unit is an independent hardware security gateway, which is connected to the communication link in series or by bypass parallel connection. The independent hardware security gateway is configured with a general interface for connecting the data source instrument without changing the original operating conditions and communication protocol of the data source instrument.

3. The method according to claim 2, characterized in that, The independent hardware security gateway forwards the original data stream directly without intervention, and automatically switches to data stream interception and encryption mode when it detects that the data source instrument has issued a data collection start command.

4. The method according to claim 2, characterized in that, The device-specific root key is generated by hashing the unique identifier of the hardware encryption chip, the physical address of the data flow control unit, and the organization's authorization code.

5. The method according to claim 1, characterized in that, The spatiotemporal fingerprint information includes time information generated by an independent high-precision hardware real-time clock or by synchronizing with the world standard time using a global navigation satellite system, and location information generated by dual-mode positioning of BeiDou and the global navigation satellite system or by a preset network address.

6. The method according to claim 1, characterized in that, The method according to claim 1 is characterized in that, when the deployment location of the independent hardware security gateway changes or does not match the preset authorization record, the device-specific root key is automatically determined to be invalid, and the step of generating and solidifying the device-specific root key is re-executed.

7. The method according to claim 1, characterized in that, Also includes: The regulatory audit end reads the encrypted data files stored on the data processing terminal through the authorized interface, extracts the unique device identifier from the data files, and matches the corresponding device public key from the cloud key management ledger for batch decryption.

8. The method according to claim 7, characterized in that, After decryption, multi-dimensional compliance checks are performed in parallel. These checks include: verifying the consistency of the standard time in the spatiotemporal fingerprint information with the preset authorized working period; verifying the matching of the physical location information in the spatiotemporal fingerprint information with the preset electronic geofence; and verifying the binding of the device's unique identifier with the preset registered instrument ledger. If any check fails, the corresponding data file is automatically marked and locked, and an immutable traceability log is generated. If all checks pass, an audit report containing a compliance score and a full-chain traceability evidence chain is generated.

9. The method according to claim 1, characterized in that, The data flow control unit is a software packet capture module deployed on the data processing terminal. It captures the original collected data stream in real time through communication packet capture and completes the embedding and encryption encapsulation of the spatiotemporal fingerprint information in the software layer. The software packet capture module also records the integrity verification value of the original data packet for detecting tampering behavior.

10. A data compliance assurance system, characterized in that, include: The data flow control module is deployed in the communication link between the data source instrument and the data processing terminal to intercept the raw data stream output by the data source instrument in real time. The key generation and spatiotemporal awareness module includes a hardware encryption chip and an independent spatiotemporal awareness module; the hardware encryption chip has a physically unique identifier embedded in it, which is used to generate and embed the device-specific root key. The independent spatiotemporal sensing module is used to generate spatiotemporal fingerprint information; The data stream control module is also used to embed the spatiotemporal fingerprint information into the data packet of the original acquired data stream, and to perform hardware-level encryption and encapsulation of the original acquired data stream containing the spatiotemporal fingerprint information based on the device-specific root key, and transmit it to the data processing terminal for encrypted storage. The transparent parsing module, deployed on the data processing terminal, includes an underlying driver. The underlying driver is used to decrypt the encrypted data file in real time when the file is read and restore it to the original data format of the data source instrument, so that the upper-layer application software of the data source instrument can read it directly.