The application discloses a kind of cross-organizational transmission and
verification method of security obligation in
data sharing scene.Sender obtains field obligation set through security
semantic knowledge base before
data sharing, forms obligation accompanying load with obligation set identification,
receiver identification and sharing batch identification, embeds in shared data in the form of digital
watermark, generates obligation transmission
voucher by signing obligation accompanying load and data hash value using SM2 private key, together with signed data is sent to
receiver.
Receiver extracts obligation accompanying load from received data by locally deployed lightweight semantic obligation
verification component, verifies the validity of SM2 signature, and confirms the integrity and compliance of obligation set content against
semantic knowledge base;obligation
verification log is returned after verification, to realize the closed-loop monitoring of sender to
receiver obligation fulfillment status.The application also supports the construction of obligation transmission chain in multi-level circulation scene, and each level of transmission
voucher contains a reference to the upper-level
voucher, so that the obligation transmission chain can be completely traced back.The application solves the fundamental problem that the cross-organizational
data sharing obligation constraints in the prior art can only rely on contractual constraints and lack technical
automation support, and realizes a cross-organizational obligation transmission mechanism that propagates with data, is not dependent on prior agreement and is cryptographically verifiable.