Page 288 - 《软件学报》2026年第6期
P. 288

软件学报 ISSN 1000-9825, CODEN RUXUEW                                        E-mail: jos@iscas.ac.cn
                 2026,37(6):2607−2646 [doi: 10.13328/j.cnki.jos.007642] [CSTR: 32375.14.jos.007642]  http://www.jos.org.cn
                 ©中国科学院软件研究所版权所有.                                                          Tel: +86-10-62562563



                                                     *
                 安全可信的数据要素流通综述

                 陈毅飞  1 ,    李    萌  1 ,    乔    焰  1 ,    汪    青  1 ,    张子剑  2 ,    祝烈煌  2


                 1
                  (合肥工业大学 计算机与信息学院, 安徽 合肥 230601)
                 2
                  (北京理工大学 网络空间安全学院, 北京 100081)
                 通信作者: 李萌, E-mail: mengli@hfut.edu.cn; 张子剑, E-mail: zhangzijian@bit.edu.cn

                 摘 要: 随着数字经济的快速发展, 数据作为重要的生产要素, 在推动新质生产力和经济社会高效运转中发挥了核
                 心作用. 数据要素的高效利用及其在不同主体间的有序、安全、合规流通对于数据要素价值释放具有重要意义.
                 然而, 数据流通过程中面临显著的安全隐患与可信挑战, 如泄露、篡改以及不可用等问题, 同时数据真实性和流通
                 透明性要求也愈发重要. 为应对这些问题, 密码学、区块链、可信执行环境等技术被广泛应用, 但仍存在成本高、
                 灵活性不足等限制, 且当前研究多集中于特定阶段, 缺乏系统性视角. 为此, 以数据要素全生命周期为主线, 构建了
                 包含数据采集、传输、存储、处理、发布、溯源这                  6  大阶段的分析框架, 系统性分析其安全与可信挑战. 提炼出
                 安全技术“三线分化、协同融合”和可信技术“验证深度递进”两大演进模型. 旨在为该领域的关键问题提供体系化
                 的解决思路, 并对未来研究方向提出展望.
                 关键词: 数据要素; 数据流通; 数据真实性; 安全; 可信
                 中图法分类号: TP311

                 中文引用格式: 陈毅飞, 李萌, 乔焰, 汪青, 张子剑, 祝烈煌. 安全可信的数据要素流通综述. 软件学报, 2026, 37(6): 2607–2646. http://
                 www.jos.org.cn/1000-9825/7642.htm
                 英文引用格式: Chen YF, Li M, Qiao Y, Wang Q, Zhang ZJ, Zhu LH. Survey on Secure and Trustworthy Data Factor Circulation. Ruan
                 Jian Xue Bao/Journal of Software, 2026, 37(6): 2607–2646 (in Chinese). http://www.jos.org.cn/1000-9825/7642.htm

                 Survey on Secure and Trustworthy Data Factor Circulation
                                   1
                                            1
                           1
                                                                    2
                                                       1
                 CHEN Yi-Fei , LI Meng , QIAO Yan , WANG Qing , ZHANG Zi-Jian , ZHU Lie-Huang 2
                 1
                 (School of Computer Science and Information Engineering, Hefei University of Technology, Hefei 230601, China)
                 2
                 (School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing 100081, China)
                 Abstract:  With the rapid development of the digital economy, data, as an important productive factor, plays a central role in fostering new
                 forms  of  productive  forces  and  ensuring  the  efficient  functioning  of  the  economy  and  society.  The  efficient  utilization  of  data  as  a
                 production  factor,  along  with  its  orderly,  secure,  and  compliant  circulation  among  various  entities,  is  essential  to  realizing  its  full  value.
                 However,  data  circulation  is  confronted  with  significant  security  risks  and  trust-related  challenges,  including  leakage,  tampering,  and
                 unavailability.  At  the  same  time,  the  requirements  for  data  authenticity  and  circulation  transparency  are  becoming  increasingly  important.
                 To  address  these  issues,  technologies  such  as  cryptography,  blockchain,  and  trusted  execution  environments  are  widely  applied.  However,
                 these  technologies  still  face  limitations  such  as  high  costs  and  insufficient  flexibility,  and  current  research  often  focuses  on  specific  stages,
                 lacking a holistic perspective. Therefore, this study is structured around the full life cycle of data factors, develops an analytical framework
                 comprising  six  stages:  data  collection,  data  transmission,  data  storage,  data  processing,  data  publication,  and  data  traceability,  and
                 systematically  analyzes  the  security  and  trust-related  challenges  at  each  stage.  For  the  first  time,  this  study  explicitly  proposes  two
                 evolutionary models: the “three-line differentiation and collaborative integration” model for security technologies and the “verification-depth


                 *    基金项目: 国家自然科学基金区域创新发展联合基金       (U23A20303); 国家自然科学基金面上项目  (62372149, 62572168); 国家留学基金
                  委访问学者项目    (202406690030); 安徽省自然科学基金面上项目   (2508085MF151); 中文大数据知识工程教育部重点实验室开放课题
                  (BigKEOpen2025-04); 网络与交换技术全国重点实验室  (北京邮电大学) 开放课题    (SKLNST-2025-1-12)
                  收稿时间: 2025-08-26; 修改时间: 2025-11-25; 采用时间: 2026-01-25; jos 在线出版时间: 2026-04-01
                  CNKI 网络首发时间: 2026-04-02
   283   284   285   286   287   288   289   290   291   292   293