Data exchange methods and apparatuses, and device and storage medium

By having the business party initiate a data exchange request and obtain a signature, combined with the reviewer's review, the compliance issues of cross-regional data exchange were resolved, achieving both compliance and efficiency in on-demand data transmission.

WO2025084989A9PCT designated stage expired Publication Date: 2025-11-27LEMON INC(GB)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/SG2024/050667
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-10-20
Filing Date
2024-10-18
Publication Date
2025-11-27

Smart Images

  • Figure SG2024050667_27112025_PF_FP_ABST
    Figure SG2024050667_27112025_PF_FP_ABST
Patent Text Reader

Abstract

In the embodiments of the present disclosure, provided are data exchange methods and apparatuses, and a device and a storage medium. A method described herein comprises: a service party initiating a first request for exchanging target data between different platforms; acquiring a signature for exchanging the target data; and controlling a target message for exchanging the target data to be generated on the basis of the signature, wherein the target message is provided to a reviewer, so that, on the basis of a review result from the reviewer, the target message is transmitted or prevented from being transmitted, the review result being determined by the reviewer at least on the basis of the signature comprised in the target message. In this way, the embodiments of the present disclosure can support on-demand exchange of specific types of data between different platforms.
Need to check novelty before this filing date? Find Prior Art

Description

[0001]Method, apparatus, device and storage medium for data exchange This application claims priority to the Chinese patent application for "Method, apparatus, device and storage medium for data exchange" filed on October 20, 2023, with application number 202311367924.0, the entire contents of which are incorporated herein by reference. TECHNICAL FIELD Implementations of the present disclosure relate to the field of computers, and more specifically, to methods, apparatuses, devices and computer storage media for data exchange. BACKGROUND Technical Field With the development of Internet technology, various Internet applications have become an important part of people's lives. Such applications will generate a large amount of data every day, which brings data security problems such as data sovereignty protection in various aspects. For example, some countries may prohibit certain types of user data from being sent to overseas servers. However, in business scenarios, the exchange of certain specific data in different regions is required for business operation without violating the corresponding laws and regulations. Therefore, how to effectively manage the exchange of data between different regions has become the focus of attention. SUMMARY In a first aspect of the present disclosure, a data exchange method is provided. The method comprises: initiating, by a business party, a first request for exchanging target data between different platforms; obtaining a signature for exchanging the target data; and controlling a target message for exchanging the target data to be generated based on the signature, wherein the target message is provided to an auditing party, so that the target message is transmitted or prevented from being transmitted based on an auditing result of the auditing party, wherein the auditing result is determined by the auditing party based on at least the signature included in the target message. In a second aspect of the present disclosure, a data exchange method is provided. The method comprises: obtaining, by an auditing party, a target message for exchanging target data between different platforms; verifying a signature included in the message using key information associated with the target data; determining whether the target data is allowed to be exchanged based on at least the verification result of the signature; and in the case where it is determined that the target data is allowed to be exchanged, causing the target message to be transmitted to a target platform. In a third aspect of the present disclosure, an apparatus for data exchange is provided. The apparatus comprises: a request module configured to initiate, by a business party, a first request for exchanging target data between different platforms; a signature obtaining module configured to obtain a signature for exchanging the target data; and a control module configured to control a target message for exchanging the target data to be generated based on the signature, wherein the target message is provided to an auditing party, so that the target message is transmitted or prevented from being transmitted based on an auditing result of the auditing party, wherein the auditing result is determined by the auditing party based on at least the signature included in the target message.In a fourth aspect of the disclosure, an apparatus for data exchange is provided. The apparatus includes: a message obtaining module configured to obtain, by an auditing party, a target message for exchanging target data between different platforms; a verification module configured to verify a signature included in the message by using key information associated with the target data; a determination module configured to determine whether the target data is allowed to be exchanged based at least on a verification result of the signature; and a transmission module configured to cause the target message to be transmitted to a target platform in a case where it is determined that the target data is allowed to be exchanged. In a fifth aspect of the disclosure, an electronic device is provided. The device includes: a memory and a processor; wherein the memory is configured to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement the method according to the first aspect or the second aspect of the disclosure. In a sixth aspect of the disclosure, a computer-readable storage medium is provided, and one or more computer instructions are stored thereon, wherein the one or more computer instructions are executed by a processor to implement the method according to the first aspect or the second aspect of the disclosure. The above and other features and advantages of embodiments of the disclosure will become more apparent by describing in detail some embodiments thereof with reference to the attached drawings, in which: FIG. 1 shows a schematic block diagram of a data exchange system according to embodiments of the disclosure; FIGS. 2A-2B show example interfaces of data registration according to embodiments of the disclosure; FIG. 3 shows an example auditing process according to some embodiments of the disclosure; FIGS. 4A and 4B show a flowchart of an example process for data exchange according to some embodiments of the disclosure; FIGS. 5A and 5B show example block diagrams of an apparatus for data exchange according to some embodiments of the disclosure; and FIG. 6 shows a block diagram of an example device that can be used to implement embodiments of the disclosure. Embodiments of the disclosure will be described in more detail by making reference to the drawings, below. While certain embodiments of the disclosure are shown in the drawings, it is understood that the disclosure can be embodied in various forms and should not be construed as being limited to the embodiments set forth herein, rather, these embodiments are provided so that the disclosure will be thorough and complete, and fully convey the scope of the disclosure to those skilled in the art. It should be understood that the drawings and embodiments of the disclosure are for illustrative purposes only and are not intended to limit the scope of the protection of the disclosure. In the description of embodiments of the disclosure, the term “comprising” and similar terms are understood to be open-ended, i.e., “including but not limited to”. The term “based on” is understood to mean “based, at least in part, on”. The term “one embodiment” or “the embodiment” is understood to mean “at least one embodiment”.The term "some embodiments" should be understood to mean "at least some embodiments". Further explicit and implicit definitions can be included below. In this document, unless explicitly stated, performing a step "in response to A" does not mean that the step is performed immediately after "A", but can include one or more intermediate steps. It can be understood that the data involved in the technical solutions of the present disclosure (including but not limited to the data itself, obtaining, using, storing or deleting the data) should comply with the requirements of the corresponding laws and regulations and relevant provisions. It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the type of information involved in the present disclosure, the scope of use, the use scenario, etc. should be notified to the relevant user and the authorization of the relevant user should be obtained in a proper manner according to the relevant laws and regulations, wherein the relevant user can include any type of right subject, such as an individual, an enterprise, or a group. It can be understood that the above notification and user authorization process is only illustrative, and does not limit the implementation manner of the present disclosure, and other manners meeting the relevant laws and regulations can also be applied to the implementation manner of the present disclosure. The basic principles and several example implementations of the present disclosure are described below with reference to the accompanying drawings. Overall architecture of data exchange system According to the embodiments of the present disclosure, a data exchange system is provided. FIG. 1 shows a schematic block diagram of a data exchange system 100 according to an embodiment of the present disclosure. As will be described in detail below, the data exchange system 100 is used for exchanging data in a target application from one platform to another platform. In some embodiments, different platforms may, for example, include target application platforms governed by different countries or regions. Different platforms may, for example, be used to provide services related to the target application for users in different countries or regions; or, different platforms may, for example, correspond to supporting different functions associated with the target application. In some scenarios, due to business implementation or data management needs, some data needs to be exchanged between different platforms. For example, it may be necessary to transmit certain data from a platform governed by a first region to a platform governed by another region. The process of transmitting target data associated with the target application by a business party 105 of the target application will be described below in combination with the data exchange system 100 shown in FIG. 1. As described above, user data in the target application is generally not allowed to be exchanged across regions. However, in some business scenarios, part of the user data of a certain type can be allowed to be exchanged across regions if it complies with the legal constraints of each region. Taking a content sharing application as an example of the target application, for creator-related data in the target application, such related data helps the creator to interact with more users in the target application.Such transfer of the creator-related data helps the promotion of the creator under the premise of compliance with the relevant regional compliance strategy. In addition, some target applications also have the need for testing, and therefore there can be a need to transfer the relevant data of the test users to another region to complete the testing. Such transfer of the data of the test users helps improve the stability of the application under the premise of compliance with the relevant regional compliance strategy. In addition, for the data generated in a specific region, some compliance strategies can be limited to managing the data of the users belonging to the specific region. However, the data of some users not belonging to the specific region can also be retained in the platform in the specific region. Therefore, there can be a need to transfer the data of the non-regional users under the premise of compliance with the relevant regional compliance strategy. Thus, in order to facilitate different business parties in the target application to apply for the on-demand transfer of specific data, as shown in FIG. 1, the business party 105 can first perform registration about the target data that needs to be exchanged, for example. As shown in FIG. 1, the business party 105 can register the data that needs to be exchanged to a registration center, such as the DECC (Data Exchange Control Center) 110, for example. Illustratively, the business party 105 can submit a registration request about the target data to be exchanged to the DECC 110, and the registration request is audited by the DECC 110. FIGS. 2A and 2B show example registration interfaces according to some embodiments of the present disclosure. As shown in FIG. 2A, the business party 105 can indicate the source of the data to be exchanged, such as Table 210, and the description 220 about the data to be exchanged through the registration interface 200A. Additionally, the business party 105 can also specify the scenario 215 of the data exchange through the registration interface 200A. Illustratively, such scenarios can include but are not limited to the scenarios mentioned above, namely the creator scenario, the test user scenario, and the non-regional user scenario. The business party 105 can select the scenario involved in the current registration of the data exchange from a group of preset scenarios, for example. Further, as shown in FIG. 2B, the business party 105 can further indicate the detailed information of the data to be transferred. Such detailed information can include the message structure of the data exchange, for example. The data to be exchanged can include a plurality of data items organized according to the order shown in FIG. 2B, namely data item "a", data item "b", data item "c", and data item "d". In addition, such detailed information can also indicate the data identifiers associated with the data to be exchanged. As shown in FIG. 2B, the data identifiers can include the field names 225 of the data items. Additionally, such detailed information can also include the description of each field.Additionally, such detailed information can also include type information of each data item. Such type information can indicate, for example, what type of data each data item is. Business party 105 can specify, for example, a corresponding type from a set of pre-set types corresponding to the scenario. Taking FIG. 2B as an example, a user can indicate, for example, that the type of data item “b” is a user identification of a test account. For example, the identification can be “Test account uid” to indicate that the field is an account ID of a test account. Further, business party 105 can submit, for example, a registration request such that the registration request can indicate various information discussed based on FIG. 2A and / or FIG. 2B. Further, the registration request from business party 105 can be approved, for example, offline such that a data exchange request approved can be added as a whitelist. Such offline approval can be based on, for example, data management policies within a corresponding region. In some embodiments, registration information from DECC 110 can be synchronized to DRS (Data Registry Service) 115 as shown in FIG. 1. It should be understood that DECC 110 and DRS 115 can be located, for example, in different VPCs (application virtual private data centers). For example, DECC 110 can be located in VPC1 185 and DRS 115 can be located in VPC2 190. Different VPCs can correspond to, for example, data centers managed by different parties. In some embodiments, VPC2 190 can be managed by, for example, a TTP (Trusted Technology Partner) which can include, for example, any individual, enterprise or organization that is technically trusted within a particular region (e.g., a particular country or jurisdiction). With reference to FIG. 1, after registration of data to be exchanged is completed, business party 105 can initiate a first request to exchange target data between different platforms. As shown in FIG. 1, business party 105 can request, for example, to exchange target data through different types of channels. In some embodiments, business party can utilize, for example, DES-RPC channel 125 to exchange target data. Specifically, business party 105 can send a data exchange request to service manager 130. The service manager can include, for example, a management service (also referred to as a source of truth service) maintained by a TTP. Further, business party 105 can execute process 120.Specifically, the service management party 130 can provide the business party 105 with a signature corresponding to the exchange of the target data, also known as a token (i.e., token), in a case where the business party 105 is determined to allow the use of the on-demand channel to exchange the target data. oAccordingly, after obtaining the corresponding signature, the business party can send a second request including the signature to the data management party. For example, the business party 105 can put the returned signature into the RPCHeader, and request the TTP to obtain the data. Further, the TTP can put the signature into the header of the response message for the request, and the response can also include the target data to be exchanged. Further, the business party 105 can transmit the response message to the auditing party via the DES-RPC 125. As shown in FIG. 1, the auditing party can include, for example, a gateway located in the VPC2 190, i.e., the DES-worker 150. The DES-worker 150 can further audit whether the data included in the message is allowed to be exchanged, and determine whether to allow or block the transmission of the message. In some embodiments, the business party 105 can also utilize other types of data channels, such as DES-MQ (Message Queue) or DES-HDFS (Hadoop Distributed File System) for data exchange. As an example, as shown in FIG. 1, the business party 105 can send the target message containing the signature to the DES-Worker 150 via the DES-MQ 135. In the case of using the DES-MQ 135, the business party 105 can be, for example, unaware of the obtaining of the signature. As another example, as shown in FIG. 1, the business party 105 can also perform the process 140. Specifically, the business party 105 can obtain the offline Hive table provided by the Source of truth service, i.e., the offline source data 160, which can include the meta information of the on-demand subject and the corresponding signature. Accordingly, the business party 105 can match the data it needs to transmit with the original information to screen the data that can be transmitted and the corresponding signature. Accordingly, the target message containing the signature can be transmitted to the DES-Worker 150 via the DES-Hive 145. The process of auditing whether the target message is allowed to be transmitted by the DES-Worker 150 will be described below. In some embodiments, the DES-Worker 150 can perform a real-time verification process on the target message. The specific process of real-time verification will be described below with reference to FIG. 3. FIG. 3 shows an example auditing process 300 according to some embodiments of the present disclosure. As shown in FIG. 3, at block 305, the DES-Worker 150 can determine whether the scenario of data exchange matches the preset scenario, i.e., determine whether the current data exchange is an on-demand channel.Further, upon determining that the data exchange is an on-demand channel, the DES-Worker 150 can determine whether a signature can be acquired, i.e., whether the signature is included in the target message. Accordingly, if the signature can be acquired, the process 300 can proceed to block 315, where the DES-Worker 150 can acquire registration information associated with the service party requesting to exchange target data and utilize the registration information to parse the traffic. Specifically, as introduced above, during the registration process of the service party 105, it can indicate a message structure of the data exchange, i.e., a data organization manner in the message for exchanging data. Taking FIG. 2B as an example, the message structure of the message can indicate that it includes four fields, and the field order thereof is field “a”, field “b”, field “c”, and field “d”. Such a message structure can also be stored by a json schema. Conversely, if the signature cannot be acquired in the message, the process 300 can proceed to block 340, where the DES-Worker 150 can block the transmission of the target message. Further, at block 320, the DES-Worker 150 can perform a basic check process and can remove the on-demand mark column. Specifically, the DES-Worker 150 can determine whether the target message to be transmitted matches the message structure indicated by the registration information. Such a match can indicate, for example, that the number of data items included in the target message is consistent with the number of data items indicated in the message structure. Conversely, if the target message does not match the message structure indicated by the registration information, the DES-Worker 150 can block the transmission of the target message. Further, at block 325, the DES-Worker 150 can verify the signature included in the message by utilizing the key information associated with the target data. Specifically, the DES-Worker 150 can determine a data exchange scenario (e.g., a test user scenario) corresponding to the exchange of the target data, and can acquire a public key associated with the data exchange scenario as the key information. Further, at block 330, the DES-Worker 150 can determine whether the public key can be used to parse the signature. If the public key cannot be used to parse the signature, the DES-Worker 150 can determine that the signature verification fails, and can block the transmission of the target message. Conversely, if the DES-Worker 150 can parse the signature by utilizing the public key, the parsed result of the signature can be acquired, which can indicate, for example, an identification of the data item for on-demand transmission.Further, at block 335, the DES-worker 150 can determine whether the resolution result matches the target message. Specifically, a correct resolution result of the signature can indicate a first identity of the data item allowed to be transmitted. The DES-worker 150 can determine whether the first identity indicated by the resolution result matches a second identity of the target data item in the target data, i.e., whether the entity value (i.e., the identity indicated in the signature) is consistent with the specially marked column (i.e., the second representation). In the case where the two match, the process 300 can proceed to block 345, i.e., the DES-worker 150 can allow the transmission of the target data, such that the target message is transmitted to the target platform. Taking FIG. 2B as an example, the first identity indicated by the signature is “b”. Thus, if the identity of the data item required to be transmitted in the target data is also “b”, the target data is allowed to be exchanged. Otherwise, the DES-worker 150 can block the transmission of the target data. In some embodiments, at block 350, for each occurrence of data transmission, the DES-worker 150 can also generate record information about the target data being exchanged, and can provide the record information for offline auditing of the exchanged target data. As shown in FIG. 1, the DES-worker 150 can backup the actual transmitted traffic to generate the record information 180. In some embodiments, such record information can indicate at least one of the following: an exchange scenario (e.g., a test user scenario, a creator scenario, a non-regional user scenario, etc.) for exchanging the target data, an identity of the data item in the target data (e.g., the field “b”), a type of the data item in the target data (e.g., Test account id), a time of exchanging the target data (e.g., a timestamp of the data transmission), description information about the data item meeting the exchange scenario (e.g., why this information belongs to Test account id), etc. In some embodiments, as shown in FIG. 1, such record information 180 can be provided for offline auditing of the data exchange performed by the TTP. Specifically, the record information 180 can be stored into the DES-Hive 170.Further, data in the service metadata 155 from the VPC1 185 can be periodically migrated to the service metadata 165 maintained by the VPC2 190, so that the TTP can determine whether the subject information of the transmission is consistent with the metadata maintained by the Source of truth service based on the service metadata 165 and the subject information stored in the DES-Hive 170 about the data of the actual transmission. Based on the data exchange system discussed above, embodiments of the present disclosure can support on-demand transmission of cross-regional data by the business party as needed under the premise of ensuring compliance of data transmission. Further, by performing on-demand transmission registration by the business party and performing signature (or token) based review by the gateway, embodiments of the present disclosure can further ensure compliance of data transmission. FIG. 4A illustrates a flowchart of an example process 400A for data exchange, according to some embodiments of the present disclosure. As shown in FIG. 4A, at block 402, a first request for exchanging target data between different platforms is initiated by a business party. At block 404, a signature for exchanging the target data is obtained. At block 406, a target message for exchanging the target data is generated based on the signature, wherein the target message is provided to a reviewer, so that the target message is transmitted or prevented from being transmitted based on a review result of the reviewer, wherein the review result is determined by the reviewer based on at least the signature included in the target message. In some embodiments, obtaining the signature for exchanging the target data comprises: registering, by the business party to a registration center, a target data type to be exchanged between different platforms; and obtaining a signature generated by the registration center based on a registration result of the target data type. In some embodiments, registering, by the business party to the registration center, the target data type to be exchanged between different platforms comprises: sending, by the business party to the registration center, a data registration request, the data registration request indicating at least one of: a target scenario of data exchange, a message structure of data exchange, an identification of at least one data item to be exchanged, description information of the data to be exchanged, a type of the at least one data item. In some embodiments, the target scenario is selected from a group of preset scenarios that allow data exchange; or the message structure indicates a data organization manner in a message for exchanging data; or the type of the at least one data item is selected from a group of preset types corresponding to the target scenario. In some embodiments, the process 400A further comprises: in a case where the data registration request is reviewed and passed, generating, by the registration center, registration information, wherein the registration information is provided for the reviewer to determine the review result of the target message. In some embodiments, the first request further indicates a type of a data channel for exchanging the target data.In some embodiments, the target message for exchanging the target data is generated based on the signature includes: sending, by the business direction data manager, a second request including the signature to generate the message for exchanging the target data, wherein the signature is included in a header of the message. In some embodiments, the different platforms include target application platforms governed by different countries or regions. FIG. 4B shows a flowchart of an example process 400B for data exchange according to some embodiments of the present disclosure. As shown in FIG. 4B, at block 412, the target message for exchanging the target data between the different platforms is obtained by the auditing party. At block 414, the signature included in the target message is verified using the key information associated with the target data. At block 416, it is determined whether the target data is allowed to be exchanged based at least on the verification result of the signature. At block 418, the target message is transmitted to the target platform in a case where it is determined that the target data is allowed to be exchanged. In some embodiments, verifying the signature included in the message using the key information associated with the target data includes: determining whether an exchange scenario of the target data matches a preset scenario; if the exchange scenario matches the preset scenario, determining whether the signature is included in the target message; and if the target message includes the signature, verifying the signature included in the target message using the key information associated with the target data. In some embodiments, verifying the signature included in the target message using the key information associated with the target data includes: obtaining registration information associated with the business party requesting to exchange the target data, the registration information indicating at least a message structure of the data exchange, the message structure indicating a data organization manner in the target message for exchanging the data; determining whether the target message matches the message structure indicated by the registration information; and if the target message matches the message structure, verifying the signature included in the target message using the key information associated with the target data. In some embodiments, the process 400B further includes: determining a data exchange scenario corresponding to the target data; and obtaining a public key associated with the data exchange scenario as the key information. In some embodiments, verifying the signature included in the message using the key information associated with the target data includes: determining whether the public key can be used to parse the signature; and if the public key cannot be used to parse the signature, determining that the signature verification fails. In some embodiments, determining whether the target data is allowed to be exchanged based at least on the verification result of the signature includes: if the signature verification succeeds, obtaining a parsing result of the signature; and based on a comparison between the parsing result and the target message, determining whether the target data is allowed to be exchanged.In some embodiments, the parsing result indicates a first data identifier of a data item allowed to be transmitted, and determining whether the target data is allowed to be exchanged based on a comparison of the parsing result and the target message of the message comprises: determining whether the first data identifier indicated by the parsing result matches a second data identifier of a target data item in the target data in the message; and in response to the first data identifier matching the second data identifier, determining that the target data is allowed to be exchanged. In some embodiments, the process 400B further comprises: generating record information about the target data being exchanged; and providing the record information for offline auditing of the target data being exchanged. In some embodiments, the record information indicates at least one of: an exchange scenario for exchanging the target data, an identifier of a data item in the target data, a type of the data item in the target data, a time of exchanging the target data, and description information about the data item meeting the exchange scenario. In some embodiments, registration information associated with the business party requesting to exchange the target data is also provided for offline auditing of the target data being exchanged. Example apparatus and devices Embodiments of the present disclosure also provide corresponding apparatuses for implementing the above-described methods or processes. FIG. 5A shows an example block diagram of an apparatus 500A for data exchange according to some embodiments of the present disclosure. As shown in FIG. 5A, the apparatus 500A comprises a request module 510 configured to initiate, by a business party, a first request for exchanging target data between different platforms; a signature obtaining module 520 configured to obtain a signature for exchanging the target data; and a control module 530 configured to control a target message for exchanging the target data to be generated based on the signature, wherein the target message is provided to an auditing party, such that the target message is transmitted or prevented from being transmitted based on an auditing result of the auditing party, wherein the auditing result is determined by the auditing party based on at least the signature included in the target message. In some embodiments, the signature obtaining module 520 is further configured to: register, by the business party, a target data type to be exchanged between different platforms to a registration center; and obtain a signature generated by the registration center based on a registration result of the target data type. In some embodiments, the signature obtaining module 520 is further configured to: send, by the business party, a data registration request to the registration center, the data registration request indicating at least one of: a target scenario of data exchange, a message structure of data exchange, an identifier of at least one data item to be exchanged, description information of the data to be exchanged, and a type of the at least one data item.In some embodiments, the target scenario is selected from a set of preset scenarios that allow data exchange; or the message structure indicates a data organization manner in the message for exchanging data; or the type of the at least one data item is selected from a set of preset types corresponding to the target scenario. In some embodiments, the apparatus 500A further includes a generation module configured to: in a case where the data registration request is approved, generate, by the registration center, registration information, wherein the registration information is provided for the auditing party to determine an auditing result of the target message. In some embodiments, the first request further indicates a type of a data channel for exchanging the target data. In some embodiments, the control module 530 is further configured to: send, by the business party to the data management party, a second request including a signature, to generate, by the data management party, a message for exchanging the target data, wherein the signature is included in a header of the message. In some embodiments, the different platforms include target application platforms governed by different countries or regions. FIG. 5B shows an example block diagram of an apparatus 500B for data exchange, according to some embodiments of the present disclosure. As shown in FIG. 5B, the apparatus 500 includes a message acquisition module 540 configured to acquire, by an auditing party, a target message for exchanging target data between different platforms; a verification module 550 configured to verify a signature included in the target message by using key information associated with the target data; a determination module 560 configured to determine whether the target data is allowed to be exchanged based at least on a verification result of the signature; and a transmission module 570 configured to cause the target message to be transmitted to a target platform in a case where it is determined that the target data is allowed to be exchanged. In some embodiments, the verification module 550 is further configured to: determine whether an exchange scenario of the target data matches a preset scenario; if the exchange scenario matches the preset scenario, determine whether the signature is included in the target message; and if the target message includes the signature, verify the signature included in the target message by using the key information associated with the target data. In some embodiments, the verification module 550 is further configured to: acquire registration information associated with a business party requesting to exchange the target data, the registration information at least indicating a message structure of data exchange, the message structure indicating a data organization manner in the message for exchanging data; determine whether the target message matches the message structure indicated by the registration information; and if the target message matches the message structure, verify the signature included in the target message by using the key information associated with the target data. In some embodiments, the apparatus 500 further includes a key acquisition module configured to: determine a data exchange scenario corresponding to the target data; and acquire a public key associated with the data exchange scenario as the key information.In some embodiments, the verification module 550 is further configured to: determine whether the public key can be used to resolve the signature; and if the public key cannot be used to resolve the signature, determine that the signature verification fails. In some embodiments, the determination module 560 is further configured to: if the signature verification succeeds, obtain a resolution result of the signature; and based on a comparison of the resolution result and the target message, determine whether the target data is allowed to be exchanged. In some embodiments, the resolution result indicates a first data identifier of a data item allowed to be transmitted, and the determination module 560 is further configured to: determine whether the first data identifier indicated by the resolution result matches a second data identifier of the target data item in the target data in the message; and in response to the first data identifier matching the second data identifier, determine that the target data is allowed to be exchanged. In some embodiments, the apparatus 500B further includes an offline audit module configured to: generate record information about the target data being exchanged; and provide the record information for offline audit of the target data being exchanged. In some embodiments, the record information indicates at least one of: an exchange scenario for exchanging the target data, an identifier of a data item in the target data, a type of the data item in the target data, a time of exchanging the target data, and description information about the data item meeting the exchange scenario. In some embodiments, registration information associated with a business party requesting to exchange the target data is also provided for offline audit of the target data being exchanged. FIG. 6 shows a schematic block diagram of an example device 600 that can be used to implement embodiments of the present disclosure. For example, the system 100 and / or the system 400 according to embodiments of the present disclosure can be implemented by the device 600. As shown, the device 600 includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to computer program instructions stored in a read-only memory (ROM) 602 or loaded into a random access memory (RAM) 603 from a storage unit 608. Various programs and data required for operation of the device 600 can also be stored in the RAM 603. The CPU 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604. Various components in the device 600 are connected to the I / O interface 605, including: an input unit 606, such as a keyboard, a mouse, etc.; an output unit 607, such as various types of displays, a speaker, etc.; the storage unit 608, such as a magnetic disk, an optical disk, etc.; and a communication unit 609, such as a network card, a modem, a wireless communication transceiver, etc.The communication unit 609 allows the device 600 to exchange information / data with other devices over a computer network, such as the Internet, and / or various telecommunication networks. The various processes and processes described above, such as the process 400A and / or the process 400B, can be performed by the processing unit 601. For example, in some embodiments, the process 400A and / or the process 400B can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed onto the device 600 via the ROM 602 and / or the communication unit 609. When the computer program is loaded onto the RAM 603 and executed by the CPU 601, one or more actions of the process 400A and / or the process 400B described above can be performed. The present disclosure can be a method, an apparatus, a system, and / or a computer program product. The computer program product can include a computer readable storage medium (or media) having computer readable program instructions thereon for implementing various aspects of the present disclosure. The computer readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer readable storage medium can be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer readable storage medium include the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device such as punch-cards or punched tape, a holographic storage medium, and any suitable combination of the foregoing. A computer readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable), or electrical signals transmitted through a wire. Computer readable program instructions described herein can be downloaded to respective computing / processing devices from a computer readable storage medium or to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network. The network can comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers.The network interface card or network connection in each computing / processing device receives computer readable program instructions from the network and forwards the computer readable program instructions for storage in the computer readable storage medium in the respective computing / processing device. Computer readable program instructions for carrying out operations of the present disclosure can be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, state-setting data, or source code or object code written in any combination of one or more programming languages, including an object oriented programming language such as Smalltalk, C++ or the like, and conventional procedural programming languages such as the "C" programming language or similar programming languages. The computer readable program instructions can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate array (FPGA), or programmable logic array (PLA) can execute the computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry, in order to perform aspects of the present disclosure. The aspects of the present disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the present disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer readable program instructions. These computer readable program instructions can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer readable program instructions can also be stored in a computer readable storage medium that can include a non-transitory computer readable storage medium that can be coupled to a computer system or other data processing apparatus to cause the computer readable program instructions to be executed by the computer or other data processing apparatus.Computer readable program instructions described herein can be downloaded to a computer, other programmable data processing apparatus, or other device from a computer readable storage medium to result in a machine, other programmable data processing apparatus, or other device implementing processes, programs, routines, storage structures, components, and / or objects that enable the computer readable program instructions to generate articles of manufacture embodying the methods and concepts described herein. The computer readable storage medium can be a transmission medium or a storage medium, including without limitation, volatile and non-volatile, removable and non-removable tangible media, and / or computer storage and data storage devices. Program code segments can be downloaded to and / or transmitted to the computer, other programmable data processing apparatus, or other device from a computer readable storage medium to cause functions to be performed by a computer, other programmable data processing apparatus, or other device. As used herein, the term "computer", "other programmable data processing apparatus", and "other device" each include one or more machines, components, and / or other devices for executing programs of instructions to perform tasks and / or implement user interfaces as described herein.

Claims

CLAIM 1. A data exchange method, comprising: initiating, by a business party, a first request for exchanging target data between different platforms; obtaining a signature for exchanging the target data; and controlling a target message for exchanging the target data to be generated based on the signature, wherein the target message is provided to an auditing party, so that the target message is transmitted or blocked based on an auditing result of the auditing party, wherein the auditing result is determined by the auditing party based on at least the signature included in the target message.

2. The method according to claim 1, wherein acquiring a signature for exchanging the target data includes: registering, by the business party, a target data type to be exchanged between different platforms to a registration center; and obtaining the signature generated by the registration center based on a registration result of the target data type. 3.The method of claim 2, wherein registering, by the service direction registry, target data types to be exchanged between different platforms comprises: sending, by the business party, a data registration request to the registration center, the data registration request indicating at least one of: a target scenario of data exchange, a message structure of data exchange, an identification of at least one data item to be exchanged, description information of data to be exchanged, a type of at least one data item.

4. The method of claim 3, wherein: the target scenario is selected from a group of preset scenarios allowing data exchange; or the message structure indicates a data organization manner in a message for exchanging data; or the type of the at least one data item is selected from a group of preset types corresponding to the target scenario.

5. The method of claim 3, further comprising: in a case where the data registration request is audited and passed, generating, by the registration center, registration information, wherein the registration information is provided for the auditing party to determine an auditing result of the target message.

6. The method of claim 1, wherein the first request further indicates a type of a data channel for exchanging the target data.

7. The method of claim 1, wherein controlling a target message for exchanging the target data is generated based on the signature includes: sending, by the business party, a second request including the signature to a data management party to generate the message for exchanging the target data, wherein the signature is included in a header of the message.

8. The method of claim 1, wherein different platforms include target application platforms governed by different countries or regions.

9. A data exchange method, comprising: obtaining, by an auditing party, a target message for exchanging target data between different platforms; verifying a signature included in the target message using key information associated with the target data; determining whether the target data is allowed to be exchanged based on at least a verification result of the signature; and in a case where it is determined that the target data is allowed to be exchanged, causing the target message to be transmitted to a target platform.

10. The method according to claim 9, wherein verifying the signature included in the target message with the key information associated with the target data includes: determining whether an exchange scenario of the target data matches a preset scenario; if the exchange scenario matches the preset scenario, determining whether a signature is included in the target message; if the target message includes the signature, verifying the signature included in the target message using key information associated with the target data.

11. The method according to claim 9, wherein verifying the signature included in the target message using the key information associated with the target data includes: obtaining registration information associated with a service party requesting exchange of the target data, the registration information indicating at least a message structure of data exchange, the message structure indicating a data organization manner in a message for exchanging data; determining whether the target message matches the message structure indicated by the registration information; and verifying the signature included in the target message by using the key information associated with the target data, if the target message matches the message structure.

12. The method of claim 9, further comprising: determining a data exchange scenario corresponding to exchange of the target data; and obtaining a public key associated with the data exchange scenario as the key information.

13. The method according to claim 12, wherein verifying the signature included in the target message with the key information associated with the target data comprises: determining whether the public key can be used to parse the signature; and determining that the signature verification fails, if the public key cannot be used to parse the signature.

14. The method of claim 13, wherein determining whether the target data is allowed to be exchanged based at least on a verification result of the signature includes: obtaining a parsing result of the signature, if the signature verification succeeds; and determining whether the target data is allowed to be exchanged based on a comparison between the parsing result and the target message.

15. The method according to claim 14, wherein the resolution result indicates a first identification of a data item allowed to be transmitted, and determining whether the target data is allowed to be exchanged based on a comparison of the resolution result with the target message comprises: determining whether a first identifier indicated by the parsing result matches a second identifier of a target data item in the target data; and determining that the target data is allowed to be exchanged, in response to the first identifier matching the second identifier.

16. The method of claim 9, further comprising: generating record information about the target data being exchanged; and providing the record information for offline auditing of exchange of the target data.

17. The method of claim 16, wherein the record information indicates at least one of: an exchange scenario for exchanging the target data, an identifier of a data item in the target data, a type of a data item in the target data, a time of exchanging the target data, description information about the data item complying with the exchange scenario.

18. The method of claim 16, wherein the registration information associated with the service party requesting exchange of the target data is also provided for the offline auditing of exchange of the target data.

19. An apparatus for data exchange, comprising: a request module configured to initiate, by a service party, a first request for exchanging target data between different platforms; a signature obtaining module configured to obtain a signature for exchanging the target data; and a control module configured to control a target message for exchanging the target data to be generated based on the signature, wherein the target message is provided to an auditor, so that the target message is transmitted or prevented from being transmitted based on an auditing result of the auditor, wherein the auditing result is determined by the auditor based on at least the signature included in the target message.

20. An apparatus for data exchange, comprising: a message obtaining module configured to obtain, by an auditor, a target message for exchanging target data between different platforms; a verification module configured to verify a signature included in the target message by using key information associated with the target data; A determination module configured to determine whether the target data is allowed to be exchanged based on at least a verification result of the signature; and a transmission module configured to cause the target message to be transmitted to a target platform in a case where it is determined that the target data is allowed to be exchanged.

21. An electronic device, comprising: A memory and a processor; wherein the memory is configured to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement the method according to any one of claims 1-8 or 9-18.

22. A computer-readable storage medium, having stored thereon one or more computer instructions, wherein the one or more computer instructions are executed by a processor to implement the method according to any one of claims 1-8 or 9-18. 16