Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

467 results about "Access time" patented technology

Access time is the time delay or latency between a request to an electronic system, and the access being completed or the requested data returned...

Cloud storage dynamic optimization method and system

The invention relates to the technical field of cloud computing storage, in particular to a cloud storage dynamic optimization method and system, and the method comprises the following steps: based on a cloud storage data access record, recognizing an access time interval sequence, analyzing the variation amplitude of adjacent time intervals, and calculating the standard deviation of the access time intervals; and determining the access period stability according to the standard deviation and the change amplitude, and classifying the data objects to obtain a data access period stability classification value. According to the method, task scheduling is more accurate by identifying a data access time interval sequence and changes thereof and refining data classification and storage resource allocation, a high-throughput and low-delay storage path is matched, the health condition of a storage node is evaluated, a fault node is identified in advance, data stability is guaranteed, and data copy distribution is adjusted; the storage reliability and stability are improved, the storage path for accessing the intensive data is optimized, the dynamic load balance of the storage resources is realized, and the storage efficiency is improved.
Owner:ZHONGZHIYUN HLDG CO LTD

Mass data storage optimization method and device and storage medium

The invention relates to the technical field of big data processing, and provides a mass data storage optimization method which comprises the following steps: analyzing target data according to access frequency and / or access time of the data, and dividing the target data into hot data, warm data and cold data; aiming at the hot data, the temperature data and the cold data, performing compression processing by adopting corresponding compression algorithms; before the target data is stored, performing duplicate removal on the target data according to the fingerprint of the target data; monitoring the use condition of the memory, the access frequency of the target data and the performance of the compression algorithm in real time, and deploying system resources according to a monitoring result; and setting a multi-level cache, and caching different types of target data to the multi-level cache according to the divided types of the target data. According to the technical scheme, mass data can be efficiently stored and rapidly accessed, and the storage space utilization rate and the overall system performance are remarkably improved.
Owner:深圳市青云端信息科技有限公司

Frequency access data storage migration method and device for big data

The invention belongs to the field of data storage, and discloses a frequency access data storage migration method and device for big data, and the method comprises the steps: obtaining a data access log, carrying out the preprocessing of the data access log, and obtaining a time window statistical matrix; carrying out timeliness attenuation weighting calculation on a plurality of data access times in the time window statistical matrix to obtain a weighted access frequency vector; obtaining a multi-dimensional feature matrix based on the weighted access frequency vector; clustering the feature vector of each time window slice in the multi-dimensional feature matrix through a Gaussian mixture model to obtain a clustering tag vector; inputting the clustering label vector into an access frequency prediction model to obtain an access frequency prediction value of the data in a future preset time step; the migration decision matrix is determined based on the access frequency predicted value and the data storage cost parameter, data migration is carried out based on the migration decision matrix, the data migration complexity can be reduced, and the access speed and the storage cost are balanced.
Owner:XIAMEN MEIYA YIAN INFORMATION TECH CO LTD

Dynamic access control policy system based on behavior

The invention discloses a dynamic access control strategy system based on behaviors, comprising: A, a behavior acquisition module for acquiring user behavior data in real time, the behavior data comprising login information, operation records, access resources, access time, access frequency and equipment information; b, the behavior analysis module is used for carrying out preprocessing, behavior pattern recognition and anomaly detection on the collected behavior data to generate a behavior analysis result; c, an access decision module which dynamically generates an access control decision in combination with user identity information, a behavior analysis result and a resource authority requirement; and D, a strategy updating module which updates the access control strategy in real time according to the security audit result, the user feedback and the new threat information. Compared with the prior art, the method has the advantages that a dynamic access control strategy based on behaviors is provided, the access authority of the user is dynamically adjusted by collecting and analyzing the user behavior data in real time, and finer, more flexible and safer access control is achieved.
Owner:LIAONING DAYIN INFORMATION SERVICE CO LTD +1

High-speed distributed storage system and method

The invention relates to the technical field of distributed storage, in particular to a high-speed distributed storage system and method, and the system comprises a file index characterization module which carries out the statistics of the access frequency and the recent access timestamp of each data block in the system, and obtains the popularity magnitude of the file data blocks; according to the method, the popularity magnitude concept is introduced on the basis of linkage statistics of the data block access frequency and the recent access time, the data blocks with remarkable service influence in the current system can be recognized, the priority processing sequence of different data blocks in the repair process is divided, and the decision-making efficiency during fault recovery is improved. After the to-be-repaired data blocks are identified, the comprehensive weight values are formed through correlation calculation with the popularity magnitude, and all the weight values are arranged in a descending order, so that dynamic grading and sequential scheduling of repair tasks are realized, and important data blocks are guaranteed to preferentially obtain recovery resource support.
Owner:DEEP THINKING COMPUTER (QINGDAO) CO LTD

Method for eliminating and maintaining hotspot data in distributed cache system

A hotspot data elimination and maintenance method in a distributed cache system comprises the steps that the access frequency, the time locality score, the service weight and the real-time data popularity value of data are acquired, and the dynamic priority score of the data is generated; determining failure data based on the dynamic priority score; dividing the data into hot spot area data, temperature spot area data and cold spot area data, when the cache space is insufficient, preferentially eliminating the data with the lowest dynamic priority score and the retention benefit value lower than a preset threshold value in the cold spot area data, and if the cache space is still insufficient, performing data elimination on the temperature spot area data according to the latest access time of the temperature spot area data; packaging the cold point area elimination data, the warm point area elimination data and the failure data into a final transaction message; and broadcasting the final transaction message through a preset protocol, and performing distributed consistency maintenance operation on the final transaction message through the receiving node. According to the invention, intelligent and efficient cache data elimination and consistency maintenance management can be realized.
Owner:EAST CHINA JIAOTONG UNIVERSITY

Layered storage read cache management method and system, storage medium and product

The invention provides a hierarchical storage read cache management method and system, a storage medium and a product, and relates to the field of data storage, the method comprises the following steps: dividing all data blocks into three data hierarchies of hot data, warm data and cold data for respective storage according to access popularity, the data storage positions, the storage data proportions and the information recording precision of the three data levels are different; when the cold data is accessed, the accessed target cold data is upgraded to the temperature data, and the temperature data is updated; when the hot data is accessed, the complete metadata information of the accessed target hot data is cached in the memory, and the hot data is sorted and updated again; and when the temperature data is accessed, determining whether to replace the target hot data with the target temperature data or not according to the size relationship between the first historical access time of the accessed target temperature data and the second historical access time of the target hot data with the lowest access heat. By implementing the method, the occupation of memory resources can be reduced when the popularity of mass data is tracked.
Owner:北京志凌海纳科技股份有限公司

A method and device for implementing high-speed operation of an algorithm based on a multi-level field cache

The application discloses a method and device for realizing high-speed operation of an algorithm based on a multi-level field cache, which comprises the following steps: a configuration management CPU sends algorithm parameters to an FPGA chip and saves the algorithm parameters in a RAM; a service processing CPU creates a handle and sends the handle to the configuration management CPU; the configuration management CPU generates a key number according to the handle; the configuration management CPU sends a key library to the FPGA chip; the service processing CPU sends a to-be-operated message to the FPGA chip; an algorithm scheduling module performs fragmentation judgment, and performs subsequent processing according to a sequence judgment result; a password operation module takes the received key, an initialization vector or an intermediate chain variable and the to-be-operated message as input, performs password operation, and outputs a calculation result and an operated intermediate chain variable; whether the to-be-operated message is the last data fragment is judged according to a tail fragment identifier, and subsequent processing is performed according to a tail fragment judgment result. The application can reduce the communication interface and CPU access times, realize high-speed operation of a password algorithm, and improve the overall performance of a password service system.
Owner:JIANGSU NEW QUALITY INFORMATION TECH CO LTD

Display device and advertisement data playing method

The embodiment of the invention provides a display device and an advertisement data playing method. According to the method, storage positions are dynamically allocated according to advertisement data characteristics, memory occupation is reduced, and the access speed of key data is increased; a priority score is generated by calculating the access frequency, the resource type weight and the final access time of the advertisement data, and a low-score data block is preferentially removed when the storage space is insufficient, so that the cache hit rate of high-frequency / hot advertisements is ensured; by downloading recent advertisement data to the local in advance, real-time downloading delay during playing is avoided, large file advertisements are stored in blocks, cached parts are read preferentially during playing, meanwhile, remaining data blocks are downloaded in the background, and rapid playing of the advertisement data is achieved. In addition, cloud advertisement data change is monitored, local cache is dynamically synchronized, data timeliness is ensured, a local index table is quickly queried before the advertisement is played, direct playing or playing while playing is selected according to cache integrity, waiting time is shortened, and the problem that the advertisement playing speed is low is solved.
Owner:VIDAA (NETHERLANDS) INT HLDG LTD

Data maintenance management method and system based on artificial intelligence

The invention relates to the technical field of electronic data digital processing, and discloses a data maintenance management method and system based on artificial intelligence. The method comprises the following steps: acquiring multi-dimensional features such as an access time sequence, metadata, an association relationship and a service context of data; constructing a hybrid model fusing a long-short-term memory network and a graph attention network, and predicting a future value score of the data; dynamically generating a hierarchical storage, archiving or deleting strategy based on the score and storage cost-performance model; and through the access feedback after the execution of the monitoring strategy, the prediction model is optimized in a closed-loop manner by using a reinforcement learning mechanism. The system comprises a data feature acquisition module, a value prediction module, a strategy generation module and an execution feedback module. According to the method, self-adaptive, refined and intelligent management of the full life cycle of the data is realized, the utilization efficiency of storage resources is remarkably improved, and the operation and maintenance cost is reduced.
Owner:SHANGHAI ZHIENTROPY INFORMATION TECH CO LTD

Encrypted data storage and key management protection method based on blue-ray disc

The invention provides an encrypted data storage and key management protection method for a blue-ray disc, which relates to the technical field of data storage security and comprises the following steps of: performing multi-frequency data block division by extracting access time sequence characteristics of original data, calculating a multi-dimensional entropy value to determine an encryption algorithm parameter and a key; and extracting physical characteristic signals of the blue-ray disc to obtain sector defect distribution and evaluate reliability, thereby realizing optimal mapping storage of encrypted data and a multi-dimensional reliability sector group. According to the invention, the data storage security is effectively improved, the key management mechanism is optimized, and the physical characteristics of the blue-ray disc are fully utilized to enhance the data protection capability.
Owner:BEIJING XINXUN XINAN TECH CO LTD

Gateway port on-off control method, equipment and medium

The invention provides an on-off control method and device for a gateway port and a medium. The on-off control method comprises the steps of obtaining historical access log data and threat intelligence data of a target port in a gateway; based on the historical access log data and the threat intelligence data, performing time sequence analysis by using a pre-trained long-short-term memory network model to obtain a predicted security access time period of the target port in a future preset time period; generating a temporary port exposure preset rule of the target port according to the predicted security access time period; determining a traffic feature vector of the real-time traffic data packet of the target port; using a preset deep reinforcement learning agent to determine an on-off control instruction for the target port based on the traffic feature vector and a temporary port exposure preset rule; and executing the on-off control instruction to modify an access control list state of the gateway firewall to the target port. According to the method and the device, dynamic and refined gateway port on-off control can be realized, so that the service flexibility and security are considered.
Owner:LINGBO TECH (BEIJING) CO LTD

Polling arbitration method and system for dynamically updating weight based on EWMA algorithm

The invention discloses a polling arbitration method and a polling arbitration system for dynamically updating weight by an EWMA algorithm, and the method comprises the following steps: monitoring and receiving a request signal sent by each AHB bus channel on a matrix bus in real time; taking a preset arbitration period as a time window, collecting the current request access times of each AHB bus channel, reading the historical request times stored in the last period, calculating the request variation of each channel, and performing uniform quantization; and on the basis of the historical weight value and the quantized value, an exponentially weighted moving average value is calculated through an EWMA algorithm. When the method is used, the actual weight value of each AHB channel can be adaptively and dynamically adjusted every fixed arbitration period number, resource allocation and system fairness are improved, and it is ensured that an arbiter can more accurately reflect the actual demand of each AHB channel on a matrix bus.
Owner:ANHUI NORMAL UNIV

Adaptive compatible protocol and gateway system of multi-source heterogeneous parking system

The invention provides a self-adaptive compatible protocol of a multi-source heterogeneous parking system and a gateway system, and belongs to the technical field of Internet of Things communication. According to the scheme, manufacturer equipment protocols such as Bosch, Gifcian and Haikang are identified through a protocol fingerprint feature library, heterogeneous data are converted into a unified JSON Schema format by utilizing a self-adaptive field mapping rule, and a multi-source heterogeneous parking system is obtained. Seamless access of multi-source equipment data is realized by combining fault-tolerant mechanisms such as off-network storage and rule hot update, the system adopts a three-layer protocol conversion architecture, the protocol identification accuracy is greater than or equal to 99.2%, the new system access time is shortened to 2 hours from 15 people days, the integration cost is reduced by 92%, the problems of protocol fragmentation, data splitting and high docking cost in the prior art can be solved, and the system has a wide application prospect. And access to an intelligent wheel parking platform is supported, and zero loss of data conversion is ensured.
Owner:黄昌慧

I2C bus communication optimization method and device, equipment and storage medium

The invention provides an I2C bus communication optimization method and device, equipment and a storage medium, and relates to the technical field of communication, and the method comprises the steps: monitoring a signal quality parameter of an I2C bus to obtain a real-time transmission state; based on the monitored signal quality parameters, dynamically adjusting time sequence parameters by using an adaptive algorithm; when it is detected that devices with different rates exist on the I2C bus, clock domain synchronization is carried out based on the adjusted time sequence parameters, and reliable communication between the mixed rate devices is ensured; and when the plurality of main devices access the I2C bus, judging the bus state according to the monitoring result of the signal quality parameter, and adjusting the access time sequence of the I2C bus to optimize the multi-main competition efficiency. According to the technical scheme, the inherent defects that in a traditional I2C protocol, static time sequence parameter limitation, the multi-main-device competition problem, the mixing rate compatibility is poor and the like are effectively overcome, and the communication performance and efficiency of the I2C bus under the requirements of full-temperature-domain stability, multi-device hot plugging, ultra-low power consumption and high reliability are remarkably improved.
Owner:INSPUR (SHANDONG) COMPUTER TECH CO LTD

Mapping segment management method and device, electronic equipment and storage medium

The invention discloses a mapping segment management method and device, electronic equipment and a storage medium, and relates to the technical field of storage. The method comprises the following steps: acquiring the total access times of a plurality of mapping segments included in a mapping table corresponding to the solid state disk in a current period, the first access times of a first mapping segment, and a first mapping temperature corresponding to the first mapping segment in a previous period; determining a second mapping temperature of the first mapping section in the current period according to the first mapping temperature, the first access times and the total access times; according to the second mapping temperature, the preset mapping temperature and the cache region where the first mapping section is located currently, whether cache region migration operation is conducted on the first mapping section or not is determined, and the cache region migration operation comprises migration from the hot cache region to the cold cache region or migration from the cold cache region to the hot cache region. According to the embodiment of the invention, the problems of long time consumption and high delay of random writing and poor writing performance of the solid state disk caused by large capacity of a mapping table from a logic address to a physical address are solved.
Owner:SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD

Network security supervision system and method based on network technology

The invention relates to the technical field of network security, and discloses a network security supervision system and method based on a network technology, and the system comprises the following modules: a data collection module which is used for obtaining browsing information data of a collection target, and the browsing information data comprises an access time period, an information browsing duration, page stay data, and an access IP address; the data analysis module is used for analyzing and calculating an abnormal behavior value of the collection target according to the browsing information data of the collection target, and comparing the obtained abnormal behavior value with a safety threshold value; and the risk assessment module is used for calculating and acquiring a leakage risk value of the acquisition target and comparing the leakage risk value with a risk threshold value. A data acquisition module is constructed to comprehensively obtain access information, a behavior abnormal value and a leakage risk value are calculated respectively, a safety threshold and a risk threshold are combined to be compared with the obtained behavior abnormal value and the leakage risk value, obvious browsing abnormity is rapidly recognized, and potential information leakage risks can also be recognized.
Owner:SHANDONG XINJIEMAI INFORMATION TECH CO LTD

Time management method and device for half-duplex satellite terminal signal, and communication system

The invention discloses a half-duplex satellite terminal signal time management method and device and a communication system, and relates to the field of satellite communication, and the method comprises the steps: adding forbidden time period data generated by an allocated time slot into a plurality of conflict management data sets, the plurality of conflict management data sets at least comprise a forward distribution management data set corresponding to a forward frame, a reverse distribution management data set corresponding to a reverse frame, and a terminal conflict management data set corresponding to a target terminal; and a forward unicast time slot which does not conflict with the reverse sending time on the terminal side timeline is allocated to the target terminal, an available time period of the reverse allocation management data set is searched, and a reverse dedicated access time slot which does not conflict with the forward receiving time on the terminal side timeline is allocated to the target terminal. According to the invention, the technical problem that the resource efficiency is reduced due to the fact that extra protection time needs to be set when satellite communication is realized in a half-duplex mode in the prior art is solved.
Owner:PURPLE MOUNTAIN LAB

Traceable file watermark generation method and device, computer equipment and medium

The invention discloses a traceable file watermark generation method and device, computer equipment and a storage medium, and the method comprises the steps: obtaining an access request for a target file, the access request comprising target user information and access time information; calculating a traceability code based on the target user information, the access time information and the protection code; generating an anti-counterfeiting watermark based on the traceability code, the target user information and the current time information, and embedding the anti-counterfeiting watermark into the target file; and when a preset verification condition is met, recalculating the traceability code, and comparing the traceability code with the traceability code embedded in the current anti-counterfeiting watermark in the target file to determine whether the anti-counterfeiting watermark is tampered or not. The traceability code is calculated by introducing the protection code of enterprise confidential level storage, and the traceability code, the target user information and the time information are jointly embedded into the anti-counterfeiting watermark, so that the authority and the credibility of a traceability system are improved, and the problem that after an existing watermark is tampered, a behavior source (such as falsification of an access record) is difficult to trace is solved.
Owner:ASPIRE TECH (SHENZHEN) LTD

Time based file access

Time based file access credentials are disclosed herein. For instance authentication data representing a user identifier and a user password associated with the user identifier is received from user input associated with a user identity. In response to determining that the user identifier and the user password are valid and are associated with the user identity and based on first metadata associated the user identity, it is determined that the user identity is authorized to access storage server equipment associated with the authentication server. Furthermore, based on second metadata associated with data resources stored on the storage server equipment, it is determined that the user identity is permitted access to at least one data resource of the data resources.
Owner:DELL PROD LP

Distributed multi-level cache and storage method based on cold and hot data label identification

The invention relates to the technical field of data storage, in particular to a distributed multi-level caching and storage method based on cold and hot data label identification, which comprises the following steps of: acquiring access frequency and access time locality of data blocks in real time, generating dynamic cold and hot label values, and storing the dynamic cold and hot label values into a database; wherein the access time locality is a standard deviation reciprocal of an access interval in the current time window; the data blocks are distributed to different storage hierarchies according to the dynamic cold and hot label values H, meanwhile, a cross-hierarchy label mirror image queue is established, and the label mirror image queue records a pre-distributed address of a target hierarchy; and in a source level keeping service state, writing the data block copy into a target level address specified by the label mirror image queue, and switching an access path in an atomized manner after writing is completed. According to the method, delay jitter caused by burst migration is avoided, a continuous physical space alignment strategy is adopted for the pre-allocated address, the fragment rate is reduced, the SSD sequential write-in performance is improved, migration operation is achieved, and resource switching is rapidly completed.
Owner:WUHAN SPARK ZHONGDA INFORMATION TECH CO LTD

Signal detection method, device, equipment, medium and product

The invention relates to a signal detection method, device and equipment, a medium and a product. The method comprises the following steps: acquiring a target receiving signal to be detected and a Monte Carlo tree corresponding to a transmitting signal; under the condition that the current node in the Monte Carlo tree is completely expanded, for each child node of the current node, shifting processing is carried out based on the number of access times of the child node, the exploration value of the child node is determined, and the optimal child node of the current node is determined based on the reward value and the exploration value of the child node. Adding the optimal child node into a current search path corresponding to the current iterative search process, taking the optimal child node as a new current node until the current search path is searched, and determining a reward value corresponding to each node in the current search path; and determining a target transmitting signal corresponding to the target receiving signal based on the reward value of each node in the Monte Carlo tree when a preset iteration end condition is satisfied. By adopting the method, the hardware implementation complexity can be reduced.
Owner:PURPLE MOUNTAIN LAB

Information encryption management method and system

The invention belongs to the technical field of data security and passwords, and provides an information encryption management method and system. After the system receives the access request, calling user historical behaviors, and calculating behavior baseline stability; obtaining a time deviation degree based on the difference between the current access time and the historical time distribution, obtaining a geographic deviation degree based on the difference between the source address and the geographic attribution, combining the time deviation degree and the geographic deviation degree into a comprehensive deviation degree, and modulating according to the behavior baseline stability to obtain a context disturbance factor. Fusing the context disturbance factor with the static risk index of the target data to obtain a session risk calibration value; and mapping the key length to the step set according to the session risk calibration value to obtain a final key length, and performing encryption. According to the method, the encryption strength can be adaptively improved when abnormal access occurs, the performance is kept under normal access, and the method has real-time performance, context sensing and good generalization ability.
Owner:NINGBO NINGFAN INFORMATION TECH CO LTD +1

Memory device, semiconductor device, and electronic device

A memory device with shortened access time in data reading is provided. The memory device includes a first layer and a second layer positioned above the first layer, the first layer includes a reading circuit, and the second layer includes a first memory cell and a second memory cell. The reading circuit includes a Si transistor. The first memory cell and the second memory cell each include an OS transistor. The first memory cell is electrically connected to the reading circuit, and the second memory cell is electrically connected to the reading circuit. When a first current corresponding to first data retained in the first memory cell flows from the reading circuit to the first memory cell and a second current corresponding to second data retained in the second memory cell flows from the reading circuit to the second memory cell, the reading circuit compares the current amounts of the first current and the second current, and reads the first data.
Owner:SEMICON ENERGY LAB CO LTD

Object data processing method, system and program product

Disclosed are an object data processing method, system and program product, the method being applied to an object data management system, the method comprising: a forwarding node receiving a data operation request sent by a client, the data operation request comprising a first public network address; the forwarding node performs load balancing processing on a plurality of proxy nodes configured with the first public network address, determines a first proxy node for processing the data operation request, and forwards the data operation request to the first proxy node; the first agent node receives the data operation request and executes corresponding operation based on the local cache information; the local cache information comprises information of the object data, access times of the object data, creation time of the object data and a verification value. According to the method provided by the invention, the complexity and the use cost of operation and maintenance management can be reduced, and the first agent node can quickly respond to the data operation request, so that the query efficiency and the downloading efficiency of the object data are improved.
Owner:HANGZHOU YOUYUN TECH CO LTD

Energy efficiency control method and system for dormancy triggering of NPU computing unit

The invention discloses an energy efficiency control method and system for dormancy triggering of an NPU computing unit, relates to the technical field of computers, and aims to effectively reduce memory access times and reduce power consumption by optimizing a cache structure of the NPU computing unit and introducing a multi-level cache mechanism, design an intelligent prefetching mechanism and predict and load data possibly needed subsequently in advance. A task scheduling algorithm is optimized; a strategy based on priority and load awareness is adopted; the load of the calculation unit is reasonably distributed; the response speed and the resource utilization rate of the system are improved; load balancing is achieved, the overall performance of the system is further improved, an intelligent sleep triggering mechanism is designed, when the load of the calculation unit is lower than a preset threshold value, a sleep mode is automatically triggered, the static power consumption of the system is reduced, and a complete energy efficiency control strategy is formed.
Owner:XIAMEN YUNQUE ZHILIAN TECHNOLOGY CO LTD

Dynamic multi-file service storage access control method based on aging URL (Uniform Resource Locator)

The invention provides a dynamic multi-file service storage access control method based on an aging URL (Uniform Resource Locator), which relates to the technical field of file storage control, and comprises the following steps: receiving a URL access request, extracting a user access time point and a duration sequence, and inputting a long-short-term memory neural network to generate a behavior time sequence feature vector; and calculating a time sequence distance value by utilizing a dynamic time warping algorithm, determining an access permission level and a URL effective duration, constructing a temporary access token, and verifying by adopting a multi-level heterogeneous consensus mechanism. According to the method, illegal access can be effectively prevented, the data security is improved, and refined authority control is realized.
Owner:BEIJING LEYU ZHIXIN TECHNOLOGY SERVICE CO LTD

Data efficient circulation system based on data capsule and trusted controlled execution environment

The invention belongs to the technical field of data security, and particularly relates to an efficient data circulation system based on a data capsule and a trusted controlled execution environment. The invention aims to cooperatively construct an efficient data element safe circulation architecture based on software and hardware technologies such as attribute-based encryption, a distributed account book and a credible controlled execution environment depending on a data capsule, and innovatively realize management and control of a full life cycle of data; the data capsule is used as a core component, ciphertext packaging and strategy packaging modes are adopted, and a strategy covers five dimensions of an access main body, access time, a use position, access content and a use mode; the production component completes data encryption and capsule generation in a trusted controlled execution environment, and the consumption component can access data only when conditions are met through double-layer attribute encryption and decryption, identity verification and strategy check; besides, the system architecture has wide universality and is suitable for various data circulation scenes, and a safe and efficient circulation mode of data elements is provided.
Owner:NANKAI UNIV