Sign In |Help & Support
ALL SECTORS
  • ALL SECTORS
  • GB(National Standard)
  • CB(Shipping)
  • CECS(Engineering Construction)
  • CJ(Urban Construction)
  • CY(News and Publication)
  • DB(Provincial Standard)
  • DL(Electricity & Power)
  • DZ(Geology & Mineralogy)
  • FZ(Spinning & Textile)
  • GA(Public Security)
  • HB(Aviation)
  • HG(Chemical Industry)
  • HJ(Environmental Protection)
  • JB(Machinery)
  • JC(Building Materials)
  • JG(Building & Construction)
  • JJ(Metering)
  • JT(Highway & Transportation)
  • LY(Forestry)
  • MT(Coal)
  • NB(Energy)
  • NY(Agriculture)
  • QB(Light Industry)
  • QC(Automobile & Vehicle)
  • QJ(Aerospace)
  • SH(Petrochemical)
  • SJ(Electronics)
  • SL(Water Resources)
  • SN(Commodity Inspection)
  • SY(Oil & Gas)
  • TB(Railway & Train)
  • YB(Ferrous Metallurgy)
  • YC(Tobacco)
  • YD(Telecommunication)
  • YY(Medical Device)
Database: 365,228(8 Aug 2026)
information technology big data cross-domain data trusted sharing reference architecture trusted cross-domain data trusted cross-domain data sharing cross-domain data sharing cross-domain data thermal reinjection filtration devices strawberry production scopethis standard ketone musk
GB/T 45994-2025 in English

GB/T 45994-2025 in English

VALID

Information technology—Big data—Reference model for trusted cross-domain data sharing

  • Issued on:2025-08-01
  • Implemented on:2026-02-01
  • File Format:PDF
  • Delivery:Via email within 1~3 business days
Price(USD): $240.00
$233.00
Standard No: GB/T 45994-2025
Document status: VALID
Title in English: Information technology—Big data—Reference model for trusted cross-domain data sharing
Title in Chinese: 信息技术 大数据 跨域数据可信共享参考架构
Language: English
File Format: Electronic (PDF)
Delivery: Via email within 1~3 business days
Issued on: 2025-08-01
Implemented on: 2026-02-01
ICS Classification: 35.240-Applications of information technology
Chinese Classification: L70-Information processing technology in general
Professional Classification: GB-National Standard
Related Keywords: information technology big data cross-domain data trusted sharing reference architecture
trusted cross-domain data
trusted cross-domain data sharing
cross-domain data sharing
cross-domain data
Related Topics: Data reference data
Data composition ratio
General information technology big data system

《GB/T 45994-2025信息技术 大数据 跨域数据可信共享参考架构》由TC28(全国信息技术标准化技术委员会)归口,主管部门为国家标准委。


Introduction

Background and Significance of Standard Development

With the rapid development of the digital economy, the demand for cross-organizational and cross-domain data sharing is becoming increasingly urgent. However, issues such as data security, privacy protection, and ownership control have become key bottlenecks that hinder the unlocking of the value of data elements. The release of GB/T 45994-2025, "Information Technology Big Data Cross-Domain Data Trusted Sharing Reference Architecture," provides an important technical basis for my country to establish a standardized, secure, and trustworthy cross-domain data sharing system.

This standard, under the jurisdiction of the National Technical Committee for Information Technology Standardization (SAC/TC 28), was jointly drafted by over 30 organizations, including Renmin University of China, China Electronics Standardization Institute, and Ant Group. It brings together practical experience and technical consensus from industry, academia, research, and application sectors. The standard will be officially implemented in 2025, marking a new stage in the standardization and regularization of the market-based allocation of data elements in my country.


Core Architecture Framework Analysis

The standard establishes a reference architecture for collaboration among data providers, data users, and data intermediaries, clarifying the functional boundaries and responsibilities of each participant. The architecture design adheres to the principle of "data remains within the domain and data is available but not visible," achieving a balance between data value utilization and security protection through technical means.

Participants Core Responsibilities Key Technical Requirements Security Management and Control Focus
Data Provider Data resource management, service encapsulation, security protection Semantic representation and association, data objectification, service generation Data classification and grading, encryption and desensitization, permission management
Data User Data service call, compliance use, internal audit Identity authentication, service call, usage control Access control, operation audit, risk prevention
Data Intermediary Cross-domain coordination, trusted management and control, service intermediary Cross-domain alignment, trusted traceability, confidential computing Identity identification, permission management, audit traceability

Detailed explanation of data provider functional requirements

Layered architecture design

The data provider adopts a four-layer architecture design, from the bottom layer to the service layer:

Data resource layer: Manages structured, semi-structured, and unstructured data resources to ensure the legal and compliance of shared data. Supports multiple data types such as tables, text, audio, images, video, log files, and JSON/XML documents.

Semantic representation and association layer: Through metadata alignment, management, and navigation technologies, standardized semantic representation and association construction of data resources are achieved. Key functions include:

  • Metadata alignment: Automatically or manually aligns metadata within a domain to a unified data catalog.
  • Metadata management: Provides add, delete, modify, and query functions and indexing technology support.
  • Data objectification: Aggregates records across data sources based on unique identifiers.

Data sharing directory layer: Inherits the existing data directory functions and supports directory updates and searches. When updating, the correctness and completeness of the record format must be verified. Searches support multiple methods such as keywords, fuzzy search, and search with paths, and the results can be displayed in a hierarchical manner.

Data sharing service layer: Shares data resources as services, built using the REST framework, and encapsulates messages in XML or JSON. It includes service generation and service management functions, and requires monitoring of service performance and availability, fault repair, and quality control.

Security and privacy protection mechanism

Data providers must implement five core security measures before data is exported:

Security measures Technical requirements Standard basis Implementation points
Identity authentication Multi-factor authentication, single sign-on, policy configuration GB/T 25069-2022 Support username and password, dynamic token, biometrics, etc.
Permission management Role definition, permission allocation, policy configuration Industry best practices Attribute- or role-based access control, support permission audit
Data classification and grading Standard definition, label management, classification implementation GB/T 43697-2024 Set classification and grading labels and circulation permissions according to national standards
Data encryption Algorithm selection, policy configuration, key management National Cryptography Specification Support record-level, field-level, table-level encryption, and confidential computing processing
Data desensitization Sensitive information identification, rule configuration, desensitization processing GB/T 35273-2020 Desensitization methods such as replacement, deletion, hiding, generalization, and mapping

Compliance Requirements for Data Users

As the data value realization end-user, data users bear the key responsibility for data compliance and risk prevention.

Data Service Interconnection Specifications

Identity Authentication: Identity certificates and proof of authority must be presented to data providers and data intermediaries, and credentials must be properly stored to prevent misuse.

Service Invocation: Specific network protocols and command formats must be used as required by the protocol, controlling access frequency and transmission rates to avoid excessive pressure on the service provider.

Secure Usage Control Mechanism

Data Usage Control: Based on data usage authorization rules, data access is controlled within the domain through methods such as discretionary and mandatory permission controls to prevent unauthorized operations.

Internal Audit: Data operation logs are recorded and reported to data intermediaries to support audit verification and tracking of unauthorized use. Audit logs should include key information such as operation time, user, operation type, and operation object.


Data intermediary cross-domain coordination function

As the "trust anchor" for cross-domain data sharing, the data intermediary provides five core functions: cross-domain service, cross-domain alignment, cross-domain management and control, cross-domain computing and cross-domain search.

Cross-domain service management

Provide unified service registration, discovery, composition and deregistration functions:

  • Service registration: Receive service metadata and reliably store it, including service name, address, protocol, usage method and other information
  • Health detection: Monitor service status and filter invalid services to avoid computing load
  • Service discovery: Provide query interface to support data users to find required services
  • Service composition: Combine multiple services into composite services according to logical relationships

Cross-domain alignment technology

Realize data fusion at the directory level and object level:

  • Directory alignment: Collect data directories and match them, supporting automatic and manual alignment
  • Object alignment: Obtain information about objects in different domains based on unique identification codes, and aggregate and align them into complete information

Cross-domain management and control system

Build a four-in-one trusted management and control mechanism:

Control and management dimensions Technical means Security objectives Implementation requirements
Trusted traceability Electronic signature, trusted hardware Traceable operations, verifiable results Record complete traceability information, support query and verification
Trusted audit Logging, event tracing Auditable behavior, traceable events Real-time collection of shared transactions, regular backup of audit records
Trusted identity TEE, cryptography mechanism Trusted identity, trusted environment Unique identification management, remote authentication and verification
Trusted permission management Authorization management, chain verification Controllable usage, secure distribution Complete authorization chain, monitoring and early warning mechanism

Cross-domain computing support

Supports multi-party secure computing, homomorphic encryption, anonymization and other confidential computing technologies:

  • Data joint analysis: Multi-party joint statistical analysis to prevent information leakage
  • Data joint modeling: Joint machine learning training and prediction to ensure data security

Cross-domain search function

Provides two methods: plaintext query and confidential query, and supports data weaving:

  • Plaintext query: Query and obtain data according to authorization rules
  • Confidential query: Use searchable encryption and other technologies to protect query privacy
  • Data Weaving: Enables multi-source data model conversion and associated views

Technological Evolution and Innovation Highlights

GB/T 45994-2025 embodies multiple innovations in its technical architecture:

Object-based Data Governance: Unique identifiers enable the aggregation of records across data sources, laying the foundation for the ownership and circulation of data elements. This governance approach effectively resolves data silos and improves data utilization efficiency.

Secret Computing Integration: Privacy-focused computing technologies such as multi-party secure computing, homomorphic encryption, and trusted execution environments are deeply integrated into the architectural design to achieve a secure sharing model where "data is available but invisible." The standard specifically references JR/T 0196-2020 Technical Specification for Multi-party Secure Computing in Financial Applications to ensure the standardization of its technical implementation.

Semantic Alignment Innovation: Metadata knowledge graphs and automatic alignment technologies are used to address the semantic heterogeneity of cross-domain data and improve the accuracy of data discovery and usage. This technology draws on the advanced concepts of the knowledge graph technology framework in GB/T 42131-2022.


Implementation Recommendations and Best Practices

Organizational Structure Development

It is recommended to establish a cross-departmental data sharing governance committee, clarify the division of responsibilities among all participants, and develop detailed data sharing management standards and operational procedures. In particular, it is important to clarify the boundaries of rights and responsibilities and the collaboration mechanisms between data providers, users, and intermediaries.

Technology Platform Selection

Select a technology platform that supports RESTful architecture and has comprehensive security management and control capabilities, focusing on the following functions:

  • Metadata management capabilities: support automated metadata collection, alignment, and management
  • Security technology support: integrated encryption, desensitization, access control and other security components
  • Performance monitoring guarantee: with service performance monitoring and fault recovery capabilities
  • Standard compatibility: support GB/T 36344 data quality standard and GB/T 43697 classification and grading standard

Phase-based implementation strategy

A phased implementation strategy is recommended:

  1. Pilot phase: select low-risk data and application scenarios for technical verification
  2. Promotion phase: expand the data scope and application scenarios, and improve the management mechanism
  3. Mature phase: establish a full life cycle data sharing governance system

Risk Assessment and Response

During implementation, the following risks require special attention:

  • Technical Risks: Encryption algorithm security, system performance bottlenecks, etc.
  • Management Risks: Abuse of authority, operational violations, audit deficiencies, etc.
  • Compliance Risks: Incorrect data classification and grading, insufficient privacy protection, etc.

It is recommended to establish a comprehensive risk identification, assessment, and response mechanism, and conduct regular security audits and compliance inspections to ensure the security and controllability of cross-domain data sharing.


Summary and Outlook

GB/T 45994-2025, "Reference Architecture for Trusted Cross-Domain Data Sharing of Information Technology Big Data," provides important technical standards and practical guidance for the market-oriented allocation of national data elements. By establishing a standardized tripartite collaboration framework and a comprehensive security management and control system, it provides an effective path to address data sharing challenges and unlock the value of data elements.

With the continuous development of technology and the continuous enrichment of application scenarios, the cross-domain data sharing standard system will be further improved. In the future, new technological breakthroughs and application innovations may emerge in areas such as blockchain evidence storage, artificial intelligence empowerment, and cross-border data flow. All relevant organizations should closely monitor the development of standards and promptly adjust and optimize their own data governance systems to better adapt to the development requirements of the digital economy era.

Sample only — not a preview of GB/T 45994-2025
Page: 1 / 0
100%

Loading PDF document...

Error loading PDF. Please make sure the file is valid and try again.

We also recommend