Data flow access control and automatic settlement method for separation of powers

CN122845293APending Publication Date: 2026-09-29NANJING BESTLINK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611311217.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-27
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0005]针对现有技术中将数据流通中的权利管理、访问控制和价值结算视为三个独立的技术模块分别设计和运行、导致数据流通中多方利益关系的技术保障缺失的技术问题,本发明目的在于提供一种基于权责分离的数据流通访问控制与自动结算方法,将数据流通中参与主体的权利分解为数据产权、数据运营权和数据使用权三个独立维度,基于产权-运营权-使用权权责分离模型构建数据资源流通主体的权利关系图,在每次数据访问行为发生时基于权利验证链的三阶段访问控制引擎进行访问安全控制,实现会话级计费计量与分账联动,实现对不同权利主体的差异化访问控制与实时化利益分配,降低多方协作的信任成本和交易摩擦

Benefits of technology

[0013]由以上本发明实施例的权责分离的数据流通访问控制与自动结算方法,与传统的单角色设定下的二元判定范式不同,将数据流通过程中的各个参与主体权利分解为数据产权、数据运营权、数据使用权三个正交维度,通过权利关系的有向图对三维权利进行统一建模,并在每次数据访问行为发生时,由权利验证链依次执行产权验证、运营权验证、使用权验证三个阶段,验证通过后以授权票据作为统一会话凭证同时驱动使用计量和分账计算,使产权方设定的产权费率、运营方设定的运营服务费率和使用方实际产生的使用量在同一个会话闭环中自动结算,实现权利验证与价值分配的实时协同,适用于面向多角色、细粒度、实时的数据资产流通的分账结算处理,提高数据资源流通的权限控制与分账结算的效率、安全性,并支持权利状态审计回溯,解决了数据流通中存在的权责模糊与分账摩擦难题。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845293A_ABST
    Figure CN122845293A_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of data element circulation and access control, and discloses a kind of data circulation access control and automatic settlement method of separation of powers, the method will be the right of the subject participating in data circulation be decomposed into three independent dimensions of data property right, data operation right and data use right, the right relation diagram of data resource circulation subject is constructed based on property right-operation right-use right separation of powers model, access security control is carried out based on three-stage access control engine of right verification chain when each data access behavior occurs, session-level billing measurement and account linkage are realized, differential access control and real-time benefit distribution to different right subjects are realized, reduce the trust cost and transaction friction of multi-party cooperation. At the same time, access permission authorization and authorized state, real-time state synchronization and interlocking of account can be realized, the data consistency of permission control and settlement is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data element circulation and access control technology, and more specifically to a data circulation access control and automatic settlement method with separation of rights and responsibilities. It is particularly applicable to platform applications involving multi-subject, multi-role, and multi-level data circulation and benefit distribution, such as cross-organizational data sharing, data asset operation, and cross-border trade data services. Background Technology

[0002] Currently, data assets are a core objective of the digital economy, realizing value through three major paths: data assetization, data industrialization, and digital finance. Digital assets are closely related to software and system platforms, involving multiple internal and external parties and cross-domain environments. This includes circulating internal data to external entities and introducing external data into internal systems, achieving cross-domain circulation and generating data asset value in the process. The core of data value lies in connection and integration, rather than isolated storage. Taking cross-border trade operation and service platforms as an example, cross-border trade involves multiple participants such as customs, logistics, finance, taxation, overseas warehouses, e-commerce platforms, and payment gateways. Data is distributed across different legal entities, cloud environments, and geographical regions, and involves frequent changes in roles such as external suppliers, overseas branches, and regulatory auditors, posing challenges to cross-domain data circulation, compliance authentication, and access control.

[0003] Traditional cross-domain data flow access control technologies primarily rely on Role-Based Access Control (RBAC), API call-based metering and billing models, and smart contract-based data transaction settlement models. Existing data platforms generally use RBAC or its extended models (such as ABAC attribute-based access control) for permission management. Administrators assign one or more roles to each user, and each role is associated with a set of operation permissions. When a user initiates a data access request, the permission engine makes a binary decision (allow or deny) based on the user-role-permission mapping relationship. API call-based metering and billing models use API publishing and subscription for access control and billing. Smart contract-based data transaction platforms automate transaction settlement by introducing blockchain smart contracts. Transaction terms are encoded into smart contracts and deployed on the blockchain. When agreed conditions are met (such as data delivery completion), the smart contract automatically executes the fund transfer. However, smart contract triggering conditions are typically discrete transaction events (such as "delivery completion"), rather than continuous usage behaviors (such as each query or model training call), which cannot support refined settlement based on actual usage and real-time revenue sharing. Smart contract code is difficult to modify once deployed, while the revenue sharing rules in data circulation need to be dynamically adjusted based on changes in participant contributions, version iterations, market fluctuations, etc. There is an inherent contradiction between the rigidity of contracts and the flexibility required by business rules. Moreover, existing solutions focus on automating the fund settlement process, while the front-end access control is still managed by the traditional off-chain permission system. There is a risk of inconsistency between the on-chain and off-chain systems, which may result in situations where off-chain permissions are granted but the on-chain contract is not triggered, or the on-chain contract is executed but the off-chain metering data is lost.

[0004] These traditional data circulation platforms employ a provider-user two-party rights model, conflating data ownership, processing rights, and consumption rights. This results in data providers being technically unable to maintain continuous ownership control and revenue tracking of derivative data products created after processing by the operator. Once data is delivered, they lose awareness of the downstream circulation chain. Furthermore, after data operators perform value-added processing such as cleaning, fusion, and modeling, they lack the technical means to confirm their legal operational rights and independent service revenue for the processed data products. In circulation processes involving multiple parties, real-time measurement and automatic revenue sharing mechanisms are unavailable. The distribution of profits in complex circulation scenarios relies entirely on online and offline contracts and software / spreadsheet reconciliation. The lack of technical safeguards for the interests of multiple parties in data circulation leads to low efficiency, poor transparency, and a high likelihood of disputes. Summary of the Invention

[0005] To address the technical problem in existing technologies that treat rights management, access control, and value settlement in data circulation as three independent technical modules, resulting in a lack of technical safeguards for the interests of multiple parties involved in data circulation, this invention aims to provide a data circulation access control and automatic settlement method based on the separation of rights and responsibilities. This method decomposes the rights of participating entities in data circulation into three independent dimensions: data ownership, data operation rights, and data usage rights. Based on a rights-responsibility separation model, a rights relationship diagram of the data resource circulation entities is constructed. At each data access event, a three-stage access control engine based on a rights verification chain performs access security control, achieving session-level billing and metering linkage with revenue sharing. This enables differentiated access control and real-time benefit allocation for different rights holders, reducing trust costs and transaction friction in multi-party collaboration. Simultaneously, it enables real-time synchronization and interlocking of access permission authorization and authorization status, and revenue sharing status, ensuring data consistency in access control and settlement.

[0006] According to a first aspect of the present invention, a data flow access control and automatic settlement method based on separation of rights and responsibilities is proposed, comprising the following steps:

[0007] S100: Construct a rights and responsibilities diagram of data resource circulation entities based on the separation of rights and responsibilities model of ownership, operation rights, and usage rights, and establish the rights granting relationship between the participating entities in data resource circulation, including: the ownership party grants the operation rights of designated data resources to the operator and agrees on the sharing ratio of subsequent operation revenue between the ownership party and the operator; the operator provides the data products processed by it to the user and agrees on the service fee standard; and the ownership party directly issues usage licenses to the user and agrees on the usage fee standard.

[0008] S200: In response to a user's request to access data resources, the access control engine performs a permission determination based on the rights relationship diagram, including ownership verification, operation rights verification, and usage rights verification, and generates an authorization ticket with a digital signature only when the rights verification chain is verified successfully.

[0009] S300: Upon receiving the authorization ticket, a session-level metering accumulator is created to perform session-level multi-dimensional usage metering for each authorized data access. When the session terminates, a metering record containing the session identifier and metering data is generated, and the characteristic hash value of the metering record is digitally signed using the operator's private key.

[0010] S400: Calculates the revenue sharing based on the measurement records and the set revenue sharing model, generates a revenue sharing settlement statement, and determines the revenue sharing fee amount for each circulation entity.

[0011] S500: Writes back the hash of the settlement statement. Each record contains the SHA-256 hash value of the previous record, forming a tamper-proof chain data structure, which improves the tamper-proof capability and data security of multi-node data flow in the system.

[0012] Specifically, the settlement statement is data-bound with the characteristic hash value of the corresponding signed metering record and the overall hash value is calculated. The overall hash value is then concatenated with the hash pointer of the previous record in the settlement ledger and written back to form a tamper-proof chain data structure that interlocks access authorization, session metering, and settlement status.

[0013] The data circulation access control and automatic settlement method based on the separation of rights and responsibilities in the above embodiments of the present invention differs from the traditional binary judgment paradigm under a single-role setting. It decomposes the rights of each participating entity in the data circulation process into three orthogonal dimensions: data ownership, data operation rights, and data usage rights. It uses a directed graph of rights relationships to uniformly model the three-dimensional rights. When a data access behavior occurs, the rights verification chain sequentially executes three stages: ownership verification, operation rights verification, and usage rights verification. After successful verification, the authorized ticket serves as a unified session credential to simultaneously drive usage measurement and revenue sharing calculation. This allows the ownership fee rate set by the owner, the operation service fee rate set by the operator, and the actual usage generated by the user to be automatically settled in the same session loop. This achieves real-time collaboration between rights verification and value distribution. It is suitable for revenue sharing and settlement processing of data asset circulation with multiple roles, fine granularity, and real-time characteristics. It improves the efficiency and security of access control and revenue sharing settlement of data resource circulation, and supports rights status audit and backtracking. It solves the problems of ambiguous rights and responsibilities and revenue sharing friction in data circulation.

[0014] Meanwhile, by binding a session-level meter accumulator with a token, the network verification overhead during high-frequency access is reduced, improving the system's processing efficiency and concurrency performance.

[0015] It should be understood that all combinations of the foregoing concepts and the additional concepts described in more detail below may be considered part of the inventive subject matter of this disclosure, provided that such concepts do not contradict each other. Furthermore, all combinations of the claimed subject matter are considered part of the inventive subject matter of this disclosure.

[0016] The foregoing and other aspects, embodiments, and features of the teachings of the present invention will be more fully understood from the following description in conjunction with the accompanying drawings. Other additional aspects of the invention, such as features and / or beneficial effects of exemplary embodiments, will become apparent from the following description or may be learned through practice of specific embodiments according to the teachings of the present invention. Attached Figure Description

[0017] The accompanying drawings are not intended to be drawn to scale. In the drawings, each identical or nearly identical component shown in the various figures may be denoted by the same reference numeral. For clarity, not every component is labeled in each figure. Embodiments of various aspects of the invention will now be described by way of example and with reference to the accompanying drawings.

[0018] Figure 1 This is a schematic diagram of the data flow access control and automatic settlement system with separation of rights and responsibilities according to an embodiment of the present invention.

[0019] Figure 2 This is a flowchart illustrating a data flow access control and automatic settlement method with separation of rights and responsibilities according to an embodiment of the present invention.

[0020] Figure 3 This is a specific example of the three-party data flow and automatic settlement process according to an embodiment of the present invention. Detailed Implementation

[0021] To better understand the technical content of the present invention, specific embodiments are described below in conjunction with the accompanying drawings.

[0022] Various aspects of the invention are described in this disclosure with reference to the accompanying drawings, which illustrate numerous illustrative embodiments. The embodiments of this disclosure are not necessarily intended to encompass all aspects of the invention. It should be understood that the various concepts and embodiments described above, as well as those described in more detail below, can be implemented in any of many ways, because the concepts and embodiments disclosed herein are not limited to any particular implementation. Furthermore, some aspects of the invention disclosed may be used alone or in any suitable combination with other aspects of the invention disclosed.

[0023] Combination Figure 1 As shown, the data circulation access control and automatic settlement system with separation of rights and responsibilities proposed in this invention aims to decompose the rights of each participating entity in the data circulation process into three orthogonal dimensions: data ownership, data operation rights, and data usage rights, based on the separation of rights and responsibilities among the various entities in the data resource circulation process. The three-dimensional rights are uniformly modeled through a directed graph of rights relationships, and access control and security verification are performed based on the rights verification chain each time a data access behavior occurs. After verification, the authorized ticket is used as a unified session credential to drive usage measurement and accounting calculation, thereby realizing real-time collaboration between rights verification and value distribution.

[0024] {Example 1}

[0025] Combination Figure 1 , Figure 2As shown, the data circulation access control and automatic settlement system according to an embodiment of the present invention includes a three-dimensional rights registration module, an access control engine, a data usage metering module, and an automatic revenue sharing and settlement module.

[0026] The 3D rights registration module is used to uniformly register all parties involved in data circulation according to three rights dimensions: property owner, operator, and user. It constructs and maintains a rights relationship graph (i.e., a directed graph) and provides external interfaces for rights registration, rights query, and rights status change. Simultaneously, the 3D rights registration module provides rights relationship graph query services to the access control engine and provides fee rate parameter configuration to the automatic revenue sharing and settlement module.

[0027] The access control engine is used to perform permission determination based on the rights verification chain according to the rights relationship graph when a data access request occurs, and provides an authorization verification interface to the outside world through the engine, returning an authorization ticket token with a digital signature.

[0028] The metering module is used to perform session-level multi-dimensional usage measurement for each authorized data access behavior. The metering module receives an authorization ticket token with a digital signature as the start credential for the metering session, generates a signed metering record at the end of the session, and reports it to the revenue sharing and settlement module.

[0029] The automatic revenue sharing and settlement module is responsible for calculating the amount due to each party based on the rate configuration in the rights registration module and the usage data obtained from the metering module, and generating tamper-proof revenue sharing records.

[0030] In the design of this invention, the automatic revenue sharing and settlement module has a built-in revenue sharing engine that supports three revenue sharing modes: fixed ratio, tiered ratio, and dynamic adjustment.

[0031] In the design of this invention, after the automatic revenue sharing and settlement module completes the calculation of the due fees of each participating entity, it writes the revenue sharing record hash back to the rights registration module for subsequent auditing and adjustment of the rights status.

[0032] In the specific implementation process, combined with Figure 2 The data flow access control and automatic settlement method with separation of rights and responsibilities shown in the example includes the following steps:

[0033] S100: Construct a rights and responsibilities diagram of data resource circulation entities based on the separation of rights and responsibilities model of ownership, operation rights, and usage rights, and establish the rights granting relationship between the participating entities in data resource circulation, including: the ownership party grants the operation rights of designated data resources to the operator and agrees on the sharing ratio of subsequent operation revenue between the ownership party and the operator; the operator provides the data products processed by it to the user and agrees on the service fee standard; and the ownership party directly issues usage licenses to the user and agrees on the usage fee standard.

[0034] S200: In response to a user's request to access data resources, it performs a permission determination based on a rights relationship diagram, including property rights verification, operation rights verification, and usage rights verification, and generates an authorization ticket with a digital signature only when the rights verification chain is verified successfully.

[0035] S300: Upon receiving an authorization ticket, a session-level metering accumulator is created to perform session-level multidimensional usage metering for each authorized data access, generating a metering record with the operator's signature.

[0036] S400: Calculates the revenue sharing based on the measurement records and the set revenue sharing model, generates a revenue sharing settlement statement, and determines the revenue sharing fee amount for each circulation entity.

[0037] S500: Writes back the hash of the settlement statement. Each record contains the SHA-256 hash value of the previous record, forming a tamper-proof chain data structure.

[0038] As an optional implementation, in step S100, the aforementioned rights relationship diagram is represented as follows:

[0039] G = (V, E);

[0040] Wherein, V is the set of participating entity nodes in the data resource circulation, and each node v in the set V has an attribute set: {Entity ID, Entity Name, Entity Type, Digital Certificate Public Key, Bank Settlement Account}.

[0041] The subject type is an enumeration value, which can be one of the following: owner, operator, user, or a composite type. The value range is {owner, operator, user, composite}. A composite type means that the same legal entity is registered as multiple rights roles. For example, a data technology company may act as both an operator of certain data resources and a user of other data services.

[0042] Edge set E contains three types of directed edges, each corresponding to one of three rights granting relationships: property rights authorization edge, operation entrustment edge, and usage license edge.

[0043] The aforementioned property rights authorization defines that the property rights holder grants the operating rights of the designated data resources to the operator and agrees on the sharing ratio of the subsequent operating revenue between the property rights holder and the operator.

[0044] The aforementioned operation entrustment defines the operator as providing the data products processed by it to the user and agreeing on the service fee standard.

[0045] The aforementioned licensing agreement defines that the copyright holder directly issues a licensing agreement to the user and stipulates the usage fee standard.

[0046] The key constraint rule in the rights relationship graph is set as follows: at any given time, for the same data resource, there can be at most one ownership authorization edge from a given ownership holder to a given operator. If the authorization conditions need to be adjusted, it must be executed through the rights status change interface. The change operation is recorded as an immutable rights change log, which includes a snapshot of the parameters before the change, a snapshot of the parameters after the change, the change time, and the signature of the change initiator.

[0047] As an optional implementation, the aforementioned ownership authorization edge is represented as e_ownership, which has an attribute set: (owner A, operator B, constraint parameter set P); where the constraint parameter set P contains the following fields: {data resource scope (a list of resource identifiers accurate to the field level), ownership fee rate r_o (the percentage that the owner extracts from the operator's revenue, expressed as a percentage), start and end time of authorization validity period, whether re-authorization is allowed (Boolean value), maximum number of times it can be circulated (integer, -1 indicates no limit)}.

[0048] The aforementioned operation delegation edge is represented as e_operation, which has an attribute set: (Operator B, User C, Constraint parameter set Q); where the constraint parameter set Q contains the following fields: {Operation service fee rate r_p (the proportion retained by the operator from the user's payment, expressed as a percentage), billing mode (enumerated values: per use / per volume / monthly subscription), unit price, Service Level Agreement (SLA) metrics (including data update frequency, availability percentage, response time limit, etc.), list of allowed operation types}.

[0049] The aforementioned usage permission edge is denoted as e_usage, which has an attribute set: (owner A, user C, constraint parameter set R). The constraint parameter set R contains the following fields: {use purpose restriction, maximum number of uses, whether caching is allowed, whether it can be used for AI model training}. The usage permission edge is suitable for scenarios where data can be delivered directly without processing. The owner directly issues usage licenses to the user, and in this case, there is no operator involved in the revenue sharing model.

[0050] As an optional implementation, the complete lifecycle state of the rights granting relationship (i.e., the rights authorization edge) includes:

[0051] Pending confirmation → Effective → Suspended → Revoked → Expired.

[0052] The entire lifecycle is managed by a state machine, which triggers event notifications during state transitions, including:

[0053] The active status triggers the metering module to initialize the corresponding metering counter;

[0054] The suspended state triggers the access control engine to return the error code "VFY_ERR_OP_RIGHT_SUSPENDED" during verification;

[0055] A revoked / expired status triggers the access control engine to permanently deny all subsequent access based on that rights-granting relationship.

[0056] The state machine adopts a two-phase confirmation protocol: after the owner initiates authorization, it enters a pending confirmation state; after the operator confirms, it becomes effective. Either party can initiate suspension or cancellation, but it must be confirmed by the other party to take effect, thus preventing unilateral operation from harming the other party's interests.

[0057] Thus, the technical problem of inconsistent states in cross-domain distributed systems is solved through state machine management and interlocking mechanisms.

[0058] Furthermore, in step S200, the access control engine adopts a rights verification chain approach to decompose a complete permission determination into three sequentially executed verification stages. The judgment logic of each stage is independent of each other, and passing the previous stage is a prerequisite for the execution of the next stage.

[0059] As an optional implementation, the intellectual property verification process as the first stage includes:

[0060] When user C initiates an access request to a certain data resource D, taking operation type op as an example, the access control engine first searches the rights relationship graph for all permission edges ending with user C:

[0061] If there is a direct usage permission edge e_usage with the attribute value of (owner A, user C, constraint R), and the current requested operation type op is included in the list of operation types allowed by constraint R, and the current cumulative number of uses does not exceed the upper limit set by constraint R, then the ownership verification passes and the process jumps to the usage right verification stage.

[0062] If no direct use permission edge exists, then the operation delegation edge ending at C is retrieved: if an operation delegation edge e_operation exists with the attribute value (an operator B, user C, constraint Q), then the source is traced upwards to find the ownership authorization edge e_ownership = (owner A, operator B, constraint P) ending at operator B; if a complete A→B→C authorization link can be found, and the constraints of P and Q are satisfied, then the ownership verification passes and the operation right verification stage begins; if there is neither a direct use permission edge nor a complete A→B→C authorization link can be constructed, then access is denied and error code 1001 is returned, indicating an unauthorized link.

[0063] As an optional implementation method, the first phase of the operating rights verification process includes:

[0064] The access control engine checks whether the current status of the property authorization edge A→B is effective and whether the cumulative number of transactions by operator B has not exceeded the maximum number of transactions set by constraint P. If the verification is successful, the right of use verification stage is entered; if the current status is suspended, error code 2001 is returned, indicating that the right of operation has been suspended; if the number of transactions exceeds the limit, error code 2002 is returned, indicating that the operating quota has been exhausted.

[0065] As an optional implementation, the third stage of the right-to-use verification process includes:

[0066] The access control engine checks whether the operation type of the current access request is included in the list of allowed operation types of constraints Q and R corresponding to the operation delegation edge or the usage license edge, and checks whether the current time is within the authorization validity period and whether the user C has exceeded the usage limit.

[0067] Once all the above checks pass verification, the access control engine generates an authorization ticket token with a digital signature, which is transmitted to the metering module as the initiation credential for the metering session and returned to the user C as a session token for subsequent interactions.

[0068] If any of the above conditions—operation type check, authorization validity period check, and usage limit check—are not met, the corresponding error code will be returned.

[0069] Error code 3001 indicates that the operation type is not allowed;

[0070] Error code 3002 indicates that the usage limit has been exceeded;

[0071] Error code 3003 indicates that the license has expired.

[0072] As an optional example, the structure of an authorization ticket token with a digital signature is as follows:

[0073] Token = {Ticket ID, Request ID, Subject A_ID, Subject B_ID (can be empty), Subject C_ID, Data Resource D_ID, Allowed Operation Type, Ticket Effective Time, Ticket Expiry Time, Digital Signature}.

[0074] The digital signature is calculated as follows: Sign = ECDSA_Sign(engine private key, SHA-256(ticket ID||C_ID||D_ID||A_ID||B_ID||operation type||effective time||expiration time)).

[0075] Furthermore, the authorization ticket token is passed to the metering module as the initiation credential for the metering session, and is also returned to user C as a session token for subsequent interactions.

[0076] In an embodiment of the present invention, when user C initiates a subsequent data request within the validity period of the Token, it only needs to carry the Token identifier. The access control engine can quickly retrieve the verified authorization information through the Token identifier without having to repeat the complete verification chain. Re-verification is only triggered when the Token is about to expire or the rights status changes.

[0077] Furthermore, in step S300, the lifecycle of the aforementioned metering accumulator is bound to an authorization ticket token with a digital signature, and session-level usage statistics are performed for each authorized data access during the ticket's validity period, including:

[0078] The access count N_access count represents the number of requests made by user C to data resource D within the validity period of the authorization ticket Token; each SQL query, API call, or file download operation is counted as one access.

[0079] Data transfer volume V_data represents the actual amount of data returned to the user for each access, in bytes. For query operations, V_data = number of rows in the result set × average number of bytes per row; for file downloads, V_data = actual file size.

[0080] The operation_list records the processing operations. If the access request involves the operator's processing of the raw data, then a tuple (operation type, number of executions) is recorded for each operation. For example, the operation types include: cleaning (missing value filling, outlier removal, format standardization), fusion (multi-source data association, deduplication, entity alignment), modeling (feature engineering, model training, evaluation and inference), and export (API encapsulation, report generation, data package export).

[0081] The number of derived data products generated, N_derived, is a count of the number of derivatives generated from the original data resource D after processing, each obtaining an independent data product identifier, DPID.

[0082] When the authorized ticket token expires or the session terminates, the meter accumulator freezes and generates metering records and hash values ​​for metering record fields. The aforementioned hash values ​​are ECDSA signed using operator B's private key, and the signature value is appended to the end of the record.

[0083] As an example, the meter accumulator freezes and generates a meter record (MeterRecord), with the following structure: {session_id, token_hash, A_ID, B_ID, C_ID, D_ID, N_access, V_data, operation_list, N_derived, session start time, session end time, record hash (H_record)}. The record hash (H_record) is SHA-256 (a concatenation of all fields in the MeterRecord above).

[0084] Simultaneously, the metering module uses operator B's private key to perform an ECDSA signature on the record hash H_record, with the signature value appended to the end of the record. This digital signature ensures the non-repudiation of the metering data. Since the operator is responsible for data processing and delivery, their signature on the metering data signifies that they have confirmed the authenticity and accuracy of the usage.

[0085] In embodiments of the present invention, the metering module and the access control engine maintain state synchronization through a heartbeat mechanism:

[0086] The metering module queries the access control engine every T seconds (default is 30 seconds) to check the status of the right authorization edge corresponding to the currently active authorization ticket token;

[0087] If the authorization edge corresponding to any authorization ticket token has been revoked or suspended, the metering module will immediately freeze the metering accumulator corresponding to that authorization ticket token, stop accepting new usage behavior, and retain the usage behavior that has already occurred as valid metering.

[0088] If the authorization edge fee rate parameter corresponding to any authorized ticket token has changed, the metering module records the change timestamp in the metering accumulator and calculates it in segments before and after the fee rate change during the settlement.

[0089] Furthermore, the automatic revenue sharing and settlement module has a built-in revenue sharing engine that supports three revenue sharing and billing modes: fixed-ratio revenue sharing, tiered-ratio revenue sharing, and revenue sharing with dynamic adjustment of ratio based on contribution.

[0090] At the end of each settlement period, all frozen metering records in this period are grouped and aggregated according to the data resource identifier D_ID and the operator identifier B_ID;

[0091] For each set of records, the revenue sharing fee amount for each circulation entity is calculated by combining the corresponding property authorization edge fee rate and operation entrustment edge fee rate with the set revenue sharing mode, and a revenue sharing settlement statement SettlementRecord is generated. Its attribute values ​​include: {settlement cycle identifier, A_ID, B_ID, D_ID, total usage summary, P_total, P_owner, P_operator, P_platform, revenue sharing mode type, calculation formula details, timestamp, hash pointer of the previous settlement record}.

[0092] In this context, A_ID, B_ID, and D_ID represent the identifiers of the property owner, the operator, and the data resource, respectively; P_total, P_owner, P_operator, and P_platform represent the total cost incurred by user C in a single session, the amount due to property owner A, the amount due to operator B, and the platform service fee, respectively.

[0093] Further, in step S500, the SettlementRecord is appended to the settlement ledger. The settlement ledger adopts a hash chain structure: each record contains the SHA-256 hash value of the previous record, forming a tamper-proof chain data structure.

[0094] Specifically, the split settlement statement is data-bound with the characteristic hash value of the corresponding signed metering record and the overall hash value is calculated. The overall hash value is then concatenated with the hash pointer of the previous record in the settlement ledger and written back to form a tamper-proof chain data structure that interlocks access authorization, session metering, and split settlement status.

[0095] It should be understood that in step S300, the metering module embeds the signature hash value of the authorization ticket token into the metering record. Further, when generating the tamper-proof chain data structure, the automatic settlement module performs two-level hash anchoring: on the one hand, it verifies whether the signature hash value of the authorization ticket token embedded in the metering record matches the signature generated by the access control engine, confirming the legitimate authorization source of the metering; on the other hand, it extracts the feature hash values ​​of all metering records that have passed the first-level verification within the current settlement period, constructs a Merkle tree, and uses the root hash value of the Merkle tree as the summary field of the settlement statement. Each block record in the underlying settlement ledger contains: the hash pointer of the previous block record, the settlement statement for the current settlement period, and the root hash value of the Merkle tree.

[0096] Existing data transfer platforms face a disconnect between high-frequency data access metering and low-frequency on-chain fund settlement when handling multi-party settlements. This disconnect can easily lead to data tampering and billing loss due to network latency or node failures. This invention addresses this by linking session metering with the underlying hash chain. It proposes using a digitally signed authorization token as the sole hash credential throughout the process. The token hash value generated during the access control phase is forcibly injected into the metering module, resolving the security vulnerability of maliciously forged metering data in offline states. Simultaneously, by embedding a Merkle root hash (two-level anchoring) composed of the characteristic hash values ​​of all relevant metering records into the settlement statement, the massive and fragmented high-frequency session-level usage data (such as the number of bytes in a large number of API calls) can be solidified into the underlying hash chain with extremely low space overhead. This achieves spatiotemporal decoupling and state interlocking in computational logic, ensuring non-repudiation and tamper-proof throughout the entire lifecycle. It also reduces the storage pressure and consensus latency of the hash ledger, improving data consistency and processing efficiency in cross-domain distributed data circulation systems.

[0097] Furthermore, the metering module can perform asynchronous hash synchronization with the access control engine through a state machine: when a state transition in the rights relationship graph in the three-dimensional rights registration module triggers a change in the rights authorization edge attribute, a rights change hash log with a timestamp is generated;

[0098] After the metering module detects the rights change hash log through the heartbeat mechanism, it forcibly interrupts the current metering session of the corresponding authorized ticket token, freezes and generates the first metering record, and then starts the second metering accumulator with the new hash identifier based on the updated rights relationship graph attributes. This enables the billing statement to use the timestamps of different hash logs to achieve accurate segmented calculations before and after the rate change.

[0099] As an optional implementation method, the fixed-ratio revenue sharing model can be applied to scenarios where a fixed rate is clearly agreed upon in the rights and obligations diagram. For example, if the property fee rate is r_o and the operating fee rate is r_p, the total cost incurred by user C in a single session is P_total = billing unit price × usage.

[0100] Furthermore, the formula for calculating revenue sharing is as follows:

[0101] 1) Calculate the amount due to operator B: P_operator = P_total × r_p;

[0102] 2) Calculate the amount due to property owner A: P_owner = P_total × r_o;

[0103] 3) Calculate the platform service fee: P_platform = P_total - P_operator - P_owner.

[0104] Wherein, when r_o+r_p>1, that is, the sum of the rates of the property right owner and the operator exceeds 100%, the revenue sharing engine executes the priority rule: the operation rate is guaranteed preferentially, and the property right rate is allocated within the remaining space. That is:

[0105] P_operator=min(P_total×r_p,P_total);

[0106] P_owner=min(P_total×r_o,P_total-P_operator).

[0107] This design is based on the reason that the operator bears the direct costs of data processing and performance delivery, and its service costs occur immediately, so it can be paid preferentially in profit distribution.

[0108] As an alternative embodiment, the stepped proportional revenue sharing mode can be applied to scenarios where the rate is linked to the usage amount.

[0109] In this mode, the property right authorization side and the operation entrustment side can each independently set a stepped rate table. For example, the stepped property right rate set by property right owner A is: when N_access≤1000, r_o=5%; when 1000<N_access≤10000, r_o=8%; when N_access>10000, r_o=10%.

[0110] At the end of each settlement cycle (default calendar month), the revenue sharing engine determines the applicable rate according to the stepped interval where the cumulative usage amount falls, and then calculates the amount receivable by each party according to the revenue sharing calculation formula corresponding to the aforementioned fixed proportional revenue sharing mode.

[0111] In the design of the present invention, the purpose of the stepped rate design is to incentivize the operator to expand the usage scale of the data product. The larger the usage amount, the higher the marginal rate of the property right owner, and the more revenue the property right owner obtains, thereby enhancing the motivation of the property right owner to continuously provide high-quality data.

[0112] As an alternative implementation, the dynamically adjusted proportional revenue sharing mode based on contribution can be applied to scenarios where multiple property right owners or multiple operators collaborate for the same data product.

[0113] In this mode, the contribution degree C of each participant i to the value of the data product i is dynamically calculated through the feedback of historical data usage. The initial value of the contribution degree is determined by the negotiation proportion of all parties when the right is registered, and after each settlement cycle, the system automatically adjusts it according to the following exponential smoothing formula:

[0114] C i (new)=α×C i (old)+(1-α)×(Ui / ΣU i ). Among them, U i This represents the percentage of actual data or services used by participant i by the user within the specified period. α is a smoothing coefficient (default 0.8) used to suppress short-term, drastic fluctuations in contribution. If a participant's contribution is below the threshold (default 5%) for three consecutive periods, the system automatically triggers a power relationship diagram adjustment suggestion, reminding the operator to assess whether to remove the low-contribution participant.

[0115] {Example 2}

[0116] In this embodiment, we further elaborate on the execution of a complete three-party data flow and automatic settlement process by combining the data flow access control and automatic settlement method with the separation of rights and responsibilities in the above embodiments and specific data examples.

[0117] Combination Figure 3 As shown, during the initialization phase, the property owner A (a customs data holding institution) registers as the subject type property owner in the three-dimensional rights registration module and submits the data resource D1 to be circulated (import and export customs declaration dataset, 5 million records, fields including: import and export enterprise name, HS code, declared amount, country of trade, etc.).

[0118] Operator B (a data technology company) is registered as the operator.

[0119] User C (a cross-border e-commerce platform) registered as a user.

[0120] Step S100: Establish a rights relationship chain.

[0121] Property owner A issues a property rights authorization edge e_ownership to operator B, e_ownership=(A,B,{Data resource scope: all fields of D1,Property fee rate r_o:10%,Validity period:2026-01-01 to 2026-12-31,Maximum number of circulations:unlimited}).

[0122] After receiving authorization from the property owner A, operator B performs cleaning and processing on D1 (filling in missing values, standardizing the format, and classifying it using HS encoding) to generate the derivative data product DP1, which is then registered in the system.

[0123] Operator B issues an operation entrustment edge e_operation to user C, e_operation=(B,C,{Operation service fee rate r_p:30%, billing mode: per use, unit price:0.50 yuan / use, SLA: data updated daily, availability 99.5%}), thus forming a complete A→B→C authorization link in the rights relationship diagram.

[0124] Step S200: User C initiates data access and permission verification.

[0125] User C requests to retrieve import and export customs declaration data for a specific company by calling "queryCustomsData(company name, HS code)" via the API. The request includes C's digital signature certificate.

[0126] The access control engine executes a rights verification chain.

[0127] Phase 1: The access control engine retrieves the complete link A→B→C and the corresponding constraint parameters P and Q from the established rights relationship diagram, and the ownership verification is successful;

[0128] Phase Two: Check that the property rights authorization side A→B is in effect, with no limit on the number of times it can be circulated, and that the operation rights verification is passed;

[0129] Phase 3: Check that the operation type query is within the allowed range, the current usage count counter is 0, the limit has not been exceeded, and the usage right verification has passed.

[0130] Engine generates authorization ticket token:

[0131] Token={token_id:"T20260515-001",A_ID:"A",B_ID:"B",C_ID:"C",D_ID:"D1",op_types:["Query"],Valid:"2026-05-15T10:00:00Z",Expire:"2026-05-15T11:00:00Z",SignatureSig}.

[0132] Step S300: The metering module starts metering.

[0133] After receiving the authorized ticket token, the metering module creates a session accumulator ACC_T20260515-001.

[0134] User C initiated 5 query requests within the validity period of the authorized ticket Token, and the metering module counted N_access=5 and V_data=256KB.

[0135] When the session terminates, the accumulator freezes, a metering record (MeterRecord) is generated, H_record = SHA-256 (concatenated fields) is calculated, and operator B signs the H_record.

[0136] Step S400: Settlement of accounts.

[0137] At the end of the month, the automatic billing and settlement module summarizes all usage of DP1 by user C:

[0138] N_total=1250 times.

[0139] The automatic revenue sharing and settlement module calculates the revenue sharing of each party's due fees based on the settlement strategy configured in the rights and interests diagram, selecting a fixed percentage revenue sharing, tiered percentage revenue sharing, dynamically adjusted revenue sharing based on contribution, or a combination of revenue sharing modes.

[0140] In the fixed-ratio revenue sharing example, P_total=1250×0.50=625.00 yuan; Property owner A receives 62.50 yuan according to r_o=10%, operator B receives 187.50 yuan according to r_p=30%, and the platform service fee is 375.00 yuan.

[0141] Under the tiered revenue sharing model, the system can automatically match the corresponding rate range based on the cumulative number of calls, data transmission volume, or number of derivative products within the settlement cycle.

[0142] Under the dynamic contribution revenue sharing model, the system can adjust the revenue sharing ratio of each participant based on the actual usage ratio of each data resource, processing service, or model component within the current period.

[0143] Step S500: Post-event tracing and dispute resolution.

[0144] After settlement is completed, the system generates a settlement statement and writes it into the hash chain ledger, while simultaneously sending settlement notifications to parties A, B, and C.

[0145] Any party can retrieve their own metering and billing records through the query interface. If user C has any objection to the fees, they can view the occurrence time and billing basis of each access record. If property owner A has any objection to the billing amount, they can query the rate configuration in the rights and interests diagram to confirm that the calculation used their own set r_o=10%. All records are digitally signed and hashed, making them impossible to unilaterally tamper with.

[0146] Therefore, through the tripartite data circulation and automatic settlement process illustrated above, by realizing the three-dimensional decomposition and collaborative execution of ownership, operation rights, and usage rights in the data circulation platform, the respective rights boundaries of the ownership party, operator, and user are precisely defined and independently executed at the technical level, resolving the issue of ambiguous rights and responsibilities in data circulation. Combined with using authorized tickets as unified session credentials, the authorization verification results are directly used as a prerequisite for metering initiation, and changes in rights status are synchronized to the metering module in real time. This ensures that every data access has a corresponding metering record, and every metering record has a corresponding authorization basis, eliminating the risk of inconsistency between authorization and settlement status. Furthermore, through the operator's signature in the metering record and the hash chain structure of the settlement record, independently verifiable technical evidence is provided for the confirmation of rights and interests and dispute arbitration among multiple parties. Any party can independently verify the authenticity and integrity of the record without relying on a centralized arbitration institution, strengthening the technical trust foundation among the participants in the data circulation ecosystem, reducing the trust costs and transaction frictions of mutual cooperation among multiple data circulation parties, and promoting the realization of the value of data circulation.

[0147] While the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the invention. Those skilled in the art can make various modifications and refinements without departing from the spirit and scope of the invention. Therefore, the scope of protection of the present invention shall be determined by the claims.

Claims

1. A data flow access control and automatic settlement method with separation of rights and responsibilities, characterized in that, Includes the following steps: S100: Construct a rights and responsibilities diagram of data resource circulation entities based on the separation of rights and responsibilities model of ownership, operation rights, and usage rights, and establish the rights granting relationship between the participating entities in data resource circulation, including: the ownership party grants the operation rights of designated data resources to the operator and agrees on the sharing ratio of subsequent operation revenue between the ownership party and the operator; the operator provides the data products processed by it to the user and agrees on the service fee standard; and the ownership party directly issues usage licenses to the user and agrees on the usage fee standard. S200: In response to a user's request to access data resources, the access control engine performs a permission determination based on the rights relationship diagram, including ownership verification, operation rights verification, and usage rights verification, and generates an authorization ticket with a digital signature only when the rights verification chain is verified successfully. S300: Upon receiving the authorization ticket, a session-level metering accumulator is created to perform session-level multi-dimensional usage metering for each authorized data access. When the session terminates, a metering record containing the session identifier and metering data is generated, and the characteristic hash value of the metering record is digitally signed using the operator's private key. S400: Calculates the revenue sharing based on the measurement records and the set revenue sharing model, generates a revenue sharing settlement statement, and determines the revenue sharing fee amount for each circulation entity. S500: Writes back the hash of the settlement statement. Each record contains the SHA-256 hash value of the previous record, forming a tamper-proof chain data structure.

2. The data flow access control and automatic settlement method with separation of rights and responsibilities according to claim 1, characterized in that, In step S100, the rights relationship diagram is represented as follows: G = (V, E); Wherein, V is the set of participating entity nodes in the data resource circulation. Each node v in the set V has an attribute set: {Entity ID, Entity Name, Entity Type, Digital Certificate Public Key, Bank Settlement Account}, where the entity type can be one of the following: property owner, operator, user, or a combination thereof; the edge set E contains three types of directed edges, corresponding to three types of right granting relationships: property authorization edge, operation entrustment edge, and usage license edge. The aforementioned property rights authorization defines the property rights holder granting the operating rights of designated data resources to the operator, and stipulates the revenue sharing ratio between the property rights holder and the operator in the subsequent operation. The operation entrustment side defines the operator as providing the data products processed by it to the user and agreeing on the service fee standard; The licensing agreement defines that the property owner directly issues a licensing agreement to the user and stipulates the usage fee standard. At any given time, for the same data resource, there is at most one ownership authorization edge from a given ownership holder to a given operator.

3. The data flow access control and automatic settlement method with separation of rights and responsibilities according to claim 2, characterized in that, The entire lifecycle of the right granting relationship is managed by a state machine, which triggers event notifications during state transitions, including: The active status triggers the metering module to initialize the corresponding metering counter; The paused state triggers the access control engine to return an error code during verification; A revoked / expired status triggers the access control engine to permanently deny all subsequent access based on that rights-granting relationship.

4. The data flow access control and automatic settlement method with separation of rights and responsibilities according to claim 2, characterized in that, The ownership authorization edge is represented as e_ownership, which has an attribute set: (owner A, operator B, constraint parameter set P); where the constraint parameter set P contains the following fields: {data resource scope, ownership fee rate r_o, authorization validity period start and end time, whether re-authorization is allowed, maximum number of circulations}; The operation delegation edge is represented as e_operation, which has an attribute set: (operator B, user C, constraint parameter set Q); where the constraint parameter set Q contains the following fields: {operation service rate r_p, billing mode, unit price, service level agreement SLA index, list of allowed operation types}; The usage permission edge is denoted as e_usage, which has an attribute set: (owner A, user C, constraint parameter set R), where the constraint parameter set R contains the following fields: {use purpose restriction, maximum number of uses, whether caching is allowed, whether it is allowed for AI model training}.

5. The data flow access control and automatic settlement method with separation of rights and responsibilities according to claim 4, characterized in that, In step S200, the process of verifying intellectual property rights includes: When user C initiates an access request to a certain data resource D, the access control engine first searches the rights graph for all permission edges ending with user C: If there is a direct usage permission edge e_usage with the attribute value of (owner A, user C, constraint R), and the current requested operation type is included in the list of operation types allowed by constraint R, and the current cumulative number of uses does not exceed the upper limit set by constraint R, then the ownership verification passes and the process jumps to the usage right verification stage. If no direct use permission edge exists, then the operation delegation edge ending at C is retrieved: if an operation delegation edge e_operation exists with the attribute value (an operator B, user C, constraint Q), then the source is traced upwards to find the ownership authorization edge e_ownership = (owner A, operator B, constraint P) ending at operator B; if a complete A→B→C authorization link can be found, and the constraints of P and Q are satisfied, then the ownership verification passes and the operation right verification stage begins; if there is neither a direct use permission edge nor a complete A→B→C authorization link can be constructed, then access is denied and error code 1001 is returned, indicating an unauthorized link.

6. The data flow access control and automatic settlement method with separation of rights and responsibilities according to claim 5, characterized in that, The process of verifying the operating rights includes: The access control engine checks whether the current status of the property authorization edge A→B is effective and whether the cumulative number of transactions by operator B has not exceeded the maximum number of transactions set by constraint P. If the verification is successful, the right of use verification stage is entered; if the current status is suspended, error code 2001 is returned, indicating that the right of operation has been suspended; if the number of transactions exceeds the limit, error code 2002 is returned, indicating that the operating quota has been exhausted.

7. The data flow access control and automatic settlement method with separation of rights and responsibilities according to claim 6, characterized in that, The process of verifying the right to use includes: The access control engine checks whether the operation type of the current access request is included in the list of allowed operation types of constraints Q and R corresponding to the operation delegation edge or the usage license edge, and checks whether the current time is within the authorization validity period and whether the user C has exceeded the usage limit. Once all the above checks pass verification, the access control engine generates an authorization ticket token with a digital signature, which is transmitted to the metering module as the initiation credential for the metering session and returned to the user C as a session token for subsequent interactions. If any of the above conditions—operation type check, authorization validity period check, and usage limit check—are not met, the corresponding error code will be returned. Error code 3001 indicates that the operation type is not allowed; Error code 3002 indicates that the usage limit has been exceeded; Error code 3003 indicates that the license has expired.

8. The data flow access control and automatic settlement method with separation of rights and responsibilities according to claim 7, characterized in that, In step S300, the lifecycle of the meter accumulator is bound to an authorization ticket token with a digital signature, and session-level usage statistics are performed for each authorized data access during the ticket's validity period, including: N_access count represents the number of requests made by user C to data resource D within the validity period of the authorized ticket Token. Data transfer volume V_data represents the actual amount of data returned to the user for each access, in bytes. The operation_list is a list of processing operations. If the access request involves the operator's processing of the raw data, then a tuple (operation type, number of executions) is recorded for each operation. The number of derived data products generated, N_derived, is a count of the number of derivatives generated from the original data resource D after processing, each obtaining an independent data product identifier, DPID. When the authorized ticket token expires or the session terminates, the meter accumulator freezes and generates a metering record and a hash value for the metering record field. The hash value is signed using the operator B's private key using ECDSA, and the signature value is appended to the end of the record.

9. The data flow access control and automatic settlement method with separation of rights and responsibilities according to claim 8, characterized in that, The metering module and the access control engine maintain state synchronization through a heartbeat mechanism: Every T seconds, the metering module queries the access control engine for the status of the right authorization edge corresponding to the currently active authorization ticket token. If the authorization edge corresponding to any authorization ticket token has been revoked or suspended, the metering module immediately freezes the metering accumulator corresponding to that authorization ticket token, stops accepting new usage behavior, and retains the usage behavior that has already occurred as valid metering. If the rate parameter of the authorization edge corresponding to any authorization ticket token has been changed, the metering module records the change timestamp in the metering accumulator and calculates it in segments before and after the rate change during the billing settlement.

10. The data flow access control and automatic settlement method with separation of rights and responsibilities according to claim 1, characterized in that, The automatic revenue sharing and settlement module has a built-in revenue sharing engine that supports three revenue sharing and billing modes: fixed ratio revenue sharing, tiered ratio revenue sharing, and dynamic adjustment ratio revenue sharing based on contribution. At the end of each settlement period, all frozen metering records in this period are grouped and aggregated according to the data resource identifier D_ID and the operator identifier B_ID; For each set of records, the revenue sharing fee amount for each circulation entity is calculated by combining the corresponding property authorization edge fee rate and operation entrustment edge fee rate with the set revenue sharing mode, and a revenue sharing settlement statement SettlementRecord is generated. Its attribute values ​​include: {settlement cycle identifier, A_ID, B_ID, D_ID, total usage summary, P_total, P_owner, P_operator, P_platform, revenue sharing mode type, calculation formula details, timestamp, hash pointer of the previous settlement record}; In this context, A_ID, B_ID, and D_ID represent the identifiers of the property owner, the operator, and the data resource, respectively; P_total, P_owner, P_operator, and P_platform represent the total cost incurred by user C in a single session, the amount due to property owner A, the amount due to operator B, and the platform service fee, respectively.