NFT-based User Information Usage, Entrusted Authorization and Privacy Protection Method

Through NFT-based user information use, delegation authorization and privacy protection methods, smart contract technology is used to provide customized access control and conditional query, which solves the problems of user information privacy security and value on the chain in blockchain technology, and realizes the effective management of privacy NFTs and the secure delegation authorization use.

CN116032634BActive Publication Date: 2025-07-29SHANGHAI JIAOTONG UNIV
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202310017341.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-01-06
Publication Date
2025-07-29
Estimated Expiration
2043-01-06

AI Technical Summary

Technical Problem

When existing blockchain technology is on the link and shared with NFT, there are privacy and security issues and value linkage problems, which limits its further industrialization and popularization.

Method used

Through NFT-based user information use, delegation authorization and privacy protection methods, smart contract technology is used to provide customized access control and condition query functions, and realize the management of privacy NFTs and a variety of usage methods, including direct use, scope proof delegation authorization use and mean calculation delegation authorization use.

Benefits of technology

While ensuring the privacy and security of user information, it realizes the authorized use of user information, enhances privacy protection capabilities, reduces the risk of information leakage, and ensures the traceability of access through open and transparent call records.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116032634B_ABST
    Figure CN116032634B_ABST
Patent Text Reader

Abstract

A method for using, entrusting authorization, and privacy protection of user information based on NFT. Structured data is used to describe user privacy information. After calling a smart contract to mint privacy NFTs and storing them in the world state, the access control and conditional query of the privacy NFTs are managed through the smart contract, and different ways of using and entrusting the authorization to use corresponding to different types of privacy information are carried out through the classification of privacy NFTs. The present invention realizes the management of privacy NFTs and various ways of using privacy NFTs, and realizes the entrusted authorization to use user information while ensuring the privacy and security of user information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a technology in the field of information security, and specifically to a method for using, entrusting authorization, and privacy protection of user information based on non-fungible tokens (NFTs). Background Art

[0002] In recent years, with the development of blockchain technology, its inherent characteristics such as decentralization, immutability, anonymity, and openness and transparency have brought many applications. Although the open and transparent nature of blockchain brings many advantages in auditing and trust, problems in protecting user information privacy and security in aspects such as user information being uploaded to the chain and NFTs, and when sharing digital type information through NFTs, still directly sharing the information with users through cryptographic means, resulting in value upload problems, limit the further industrial popularization of blockchain and NFT technologies. Summary of the Invention

[0003] Aiming at the above deficiencies of the existing technology, the present invention proposes a method for using, entrusting authorization, and privacy protection of user information based on NFTs. Through the Turing-complete programmable control ability brought by NFT technology and smart contract technology, it provides a customized access control function for private NFTs based on the personal information of the caller to enhance the privacy protection ability. At the same time, it provides a customized conditional query function for private NFTs to enhance usability. Through the immutable characteristics of the blockchain, it is ensured that the private NFTs and the records of their access and calls are unchangeable, realizing the protection of privacy while realizing the use and entrusting authorization of user information. Through the classification of user information, methods of directly using private NFTs, using range-proof entrusting authorization, and using mean calculation entrusting authorization are proposed. The present invention realizes the management of private NFTs and various ways of using private NFTs, and realizes the entrusting authorization use of user information while ensuring the privacy and security of user information.

[0004] The present invention is realized through the following technical solutions:

[0005] The present invention relates to a method for using, entrusting authorization, and privacy protection of user information based on NFTs, including:

[0006] Step 1: Use structured data to describe user privacy information, create private NFTs by calling smart contracts, and store them in the world state.

[0007] Step 2: Manage the access control and conditional query of private NFTs through smart contracts.

[0008] Step 3: Through the classification of private NFTs, corresponding different ways of using and entrusting authorization for different types of privacy information are carried out.

[0009] The different ways of use and authorized use by entrustment include: for privacy NFTs that must be used by the user knowing the specific content, the direct use method is adopted; for privacy NFTs where the user can use them by confirming the scope of the digital information contained, the scope proof authorized use by entrustment method is adopted; for privacy NFTs where the user can use them by obtaining the average value of multiple users for the digital information contained, the average value calculation authorized use by entrustment method is adopted.

[0010] Technical effects

[0011] The present invention casts user information into privacy NFTs to solve the problems of user information use and authorized use by entrustment; through access control and conditional query management of privacy NFTs, the usability and privacy protection ability of privacy NFTs are enhanced; through the direct use of privacy NFTs, while not exposing user privacy information to third parties, the privacy NFTs are shared with users for use, reducing the risk of information leakage; through the scope proof authorized use by entrustment and average value calculation authorized use by entrustment of user privacy NFTs, while not exposing user privacy information, the authorized use of privacy NFTs and user information is realized, enhancing the privacy protection ability; the information is publicly transparent, and users can view the call records of the smart contract interface through a public interface, making the access to privacy NFTs traceable. Description of the drawings

[0012] Figure 1 It is a schematic diagram of the system of the present invention;

[0013] Figure 2 It is a schematic diagram of the privacy NFT casting process;

[0014] Figure 3 It is a schematic diagram of the direct use process of privacy NFTs;

[0015] Figure 4 It is a schematic diagram of the scope proof authorized use by entrustment process of privacy NFTs;

[0016] Figure 5 It is a schematic diagram of the average value calculation authorized use by entrustment process of privacy NFTs. Detailed implementation manners

[0017] Such as Figure 1As shown in the figure, this embodiment relates to a privacy protection system, including: a management unit, a usage unit, a proof unit, and a mean value calculation unit, where: the management unit creates privacy NFTs and processes user access and queries, and decides whether to return the information of the privacy NFT or the privacy NFT corresponding to the query result according to the user's permissions and the field information of the query; the usage unit proxy re-encrypts the information in the privacy NFT under the user's key, and while not exposing the user's privacy information to a third party, shares the privacy NFT with the user for direct use based on NFT leasing; the proof unit stores the cryptographic commitments and range proofs generated by the user on the privacy NFT, and entrusts and authorizes the privacy NFT to the user for use through a smart contract based on NFT leasing; the mean value calculation unit sums up the digital information confused by the users with random numbers to obtain a sum value, and entrusts and authorizes the privacy NFT and the sum value to the user for use based on NFT leasing.

[0018] This embodiment relates to an NFT-based user information usage, delegation authorization, and privacy protection method for the above system, including the following steps:

[0019] Step 1, as Figure 2 shown in the figure, the user calls the smart contract to create a privacy NFT, specifically including: calling the interface provided by the smart contract to generate a privacy NFT containing field information such as token ID (TokenId), owner (Owner), user (User), revocation date (RevocationDate), name (Name), description (Description), content (Content), data type (DataType), and suffix (Suffix), and storing it in the world state.

[0020] The so-called world state refers to: a relational database that stores specific information, and the execution results of the consensus smart contract will be submitted to the database by blockchain nodes.

[0021] Step 1.1, the user encrypts his own information as the Content field, and generates a description of the user information, including Name, Description, DataType, and Suffix.

[0022] Step 1.2, the user calls the smart contract interface and passes in the fields generated in Step 1.1.

[0023] Step 1.3, the smart contract generates a TokenId, and generates a corresponding privacy NFT according to the fields passed in by the user, and stores it in the world state.

[0024] Step 2, manage the access control and conditional query of the privacy NFT through the smart contract, specifically including:

[0025] Step 2.1: NFT access control means that when a user calls the interface provided by the smart contract, passes in the TokenId, and accesses the specific information of the corresponding private NFT, the smart contract checks the caller's permissions and decides whether to return the corresponding query information to ensure the user's information privacy and security.

[0026] Step 2.2: The NFT conditional query mentioned above refers to the process where a user calls the interface provided by the smart contract and enters the query parameters. The smart contract will then return all eligible private NFTs based on the query parameters and user permissions. If the user queries for their own private NFT, the smart contract will return the TokenIds of all private NFTs belonging to the caller.

[0027] Step 2.3: The above-mentioned smart contract calls, including minting privacy NFTs, accessing privacy NFTs, and querying privacy NFTs, will be recorded in the blockchain ledger to ensure the authenticity and traceability of the call records, so that access to private information can be traced.

[0028] Step 3: By classifying private NFTs, different types of private information can be used and authorized in different ways. Specifically, users can use private NFTs directly, through range proof authorization, and through mean calculation authorization, by calling the corresponding smart contract interface and combining it with NFT leasing technology.

[0029] The NFT leasing technology described above involves modifying the NFT's user and revocation date fields through smart contracts, guaranteeing access rights and availability through smart contracts. Specifically, when a user calls an interface to access a private NFT, the system checks whether their permissions are met and whether the revocation date has expired. If the permissions are not met, the access is denied. If the revocation date has expired, the access is denied and the private NFT's permissions are revoked.

[0030] Step 3.1, such as Figure 3 As shown, the direct use of the privacy NFT means: based on the privacy NFT and the user passed in by the user, the information in the privacy NFT is re-encrypted to the user's key, and the privacy NFT is shared with the user for direct use based on NFT leasing without exposing the user's privacy information to a third party.

[0031] Step 3.1.1. The user generates a re-encryption key based on the privacy NFT to be used and the user's public key.

[0032] Step 3.1.2: The user calls the privacy NFT directly using the smart contract, passing in the TokenId, User, and re-encryption key.

[0033] Step 3.1.3: The smart contract executes the re-encryption algorithm, saves the re-encrypted information in the privacy NFT, and grants the user access rights to the privacy NFT based on NFT leasing.

[0034] Step 3.1.4: The user calls the smart contract interface and accesses the privacy NFT and the corresponding re-encrypted information after access control.

[0035] Step 3.2: As shown in Figure 4 The entrusted authorization for the use of the privacy NFT range proof means: According to the privacy NFT and the user passed in by the user, the cryptographic commitment and range proof generated by the user are saved on the privacy NFT, and the privacy NFT is entrusted and authorized to the user for use through the smart contract based on NFT leasing.

[0036] Step 3.2.1: The user generates the corresponding cryptographic commitment and range proof according to the digital type privacy NFT to be used and the interval to be proved.

[0037] Step 3.2.2: The user calls the privacy NFT range proof smart contract and passes in the TokenId, User, and the information generated in Step 3.2.1.

[0038] Step 3.2.3: The smart contract saves the cryptographic commitment and range proof in the privacy NFT and grants the user access rights to the privacy NFT based on NFT leasing.

[0039] Step 3.2.4: The user calls the smart contract interface and accesses the privacy NFT and the cryptographic commitment and range proof information after access control.

[0040] Step 3.3: As shown in Figure 5 The entrusted authorization for the use of the privacy NFT mean calculation means: According to the privacy NFT and the user passed in by the users, the sum values of the digital information confused by the users using random numbers are obtained, and the privacy NFT and the sum value are entrusted and authorized to the user for use based on NFT leasing.

[0041] Step 3.3.1: The user confuses the user information represented by the privacy NFT using random numbers according to the digital type privacy NFT to be used.

[0042] Step 3.3.2: The user calls the privacy NFT mean calculation smart contract and passes in the TokenId, User, the digital information confused by random numbers, and the shared secret.

[0043] The shared secret refers to the relevant information shared with the user through the shared key algorithm. Only the user with the corresponding private key can restore the confused random number through this information.

[0044] Step 3.3.3: The smart contract sums up the digitally scrambled random numbers transmitted by the users, stores the sum value in the world state, stores the shared secret in the privacy NFT, and grants the corresponding privacy NFT access rights to the users based on NFT leasing.

[0045] Step 3.3.4: The user calls the smart contract interface, obtains the calculated sum value after access control, and accesses the corresponding privacy NFT. All the scrambled random numbers are restored from the shared secret, the sum of the scrambled random numbers is subtracted from the sum value to obtain the sum of all digital information, and then divided by the number of people to obtain the average value information.

[0046] After specific actual experiments, the above smart contract is implemented on the Hyperledger Fabric platform. User A casts his age information 23 into a privacy NFT with TokenId 01. User A, B, and C respectively cast their income information m i into privacy NFTs with TokenIds 02, 03, and 04 respectively. Without authorization, other users cannot access the specific content of the privacy NFT.

[0047] For the direct use of the privacy NFT, User A generates a proxy re-encryption key rk B based on the privacy NFT01 and the public key y of User B A→B . According to the foregoing steps, User A calls the smart contract for direct use of the privacy NFT, and passes in TokenId 01, User User B, and the re-encryption key rk A→B . The smart contract accepts the call and executes the code. After that, User B calls the smart contract to access the privacy NFT01, obtains the re-encrypted ciphertext, and thus learns that User A's age is 23.

[0048] For the delegated authorized use of the privacy NFT range proof, User A generates a cryptographic commitment Comm(m) and a range proof RP(m, 18, 200) based on the privacy NFT01. According to the foregoing steps, User A calls the smart contract for the privacy NFT range proof, and passes in TokenId 01, User User C, the cryptographic commitment Comm(m), and the range proof RP(m, 18, 200). The smart contract accepts the call and executes the code. After that, User C calls the smart contract to access the privacy NFT01, obtains the cryptographic commitment and the range proof, and verifies the commitment and the proof to learn that the age digital information corresponding to NFT01 is in the interval {18, 19, …, 200}, that is, learns that User A has reached adulthood.

[0049] For the delegated authorized use of the privacy NFT average value calculation, User A, B, and C respectively generate a random number r i , and according to this random number and the public key of User D Generate a shared secret With the obfuscated random number After that, according to the corresponding privacy NFTs 02, 03, and 04, calculate the obfuscated digital information m i +R i According to the foregoing steps, users A, B, and C respectively call the privacy NFT mean calculation smart contract, input their own privacy NFT TokenIds, User user D, and the obfuscated digital information m i +R i The smart contract accepts the call and executes the code. After that, user D calls the smart contract to access privacy NFTs 02, 03, and 04 to obtain the shared secret And the sum value ∑m i +R i User D can use his own private key x D Restore the obfuscated random number So as to obtain the sum value ∑m of the income digital information of users A, B, and C i And then calculate the income mean value of users A, B, and C

[0050] Through the above experiment, while being able to achieve the use and entrusted authorization use of user information, the privacy and security of user information can be fully guaranteed

[0051] Compared with the prior art, the present invention solves the functions of user information use and entrusted authorization use through privacy NFTs, which is more practical than traditional distributed databases; to a certain extent, solves the problem of NFT value on-chain through the inherent information value of user information represented by privacy NFTs; due to the decentralized and immutable characteristics of privacy NFTs, it ensures that user information is true and reliable and not forged; effectively enhances the usability and privacy protection ability of privacy NFTs through the management of privacy NFTs; through the direct use method of privacy NFTs, while not exposing user privacy information to third parties, realizes sharing privacy NFTs with users for use, avoids single-point failure problems compared with traditional user information use methods, and reduces the risk of information leakage; through the entrusted authorization use of user privacy NFT scope proof and the entrusted authorization use of mean value calculation, while not exposing user privacy information, realizes the entrusted authorization use of privacy NFTs and user information, and enhances the privacy protection ability; the information is open and transparent, and users can view the call records of the smart contract interface through the public interface, making the access to privacy NFTs traceable

[0052] The above specific implementation can be locally adjusted by those skilled in the art in different ways without departing from the principles and purposes of the present invention. The protection scope of the present invention is subject to the claims and is not limited by the above specific implementation, and all implementation solutions within its scope are subject to the present invention

Claims

1. A method for using user information, entrusting authorization, and privacy protection based on NFT, characterized in that, Using structured data to describe user privacy information, after calling a smart contract to mint privacy NFTs and storing them in the world state, the access control and conditional query of privacy NFTs are managed through the smart contract, and through the classification of privacy NFTs, different usage and entrusted authorization usage methods are carried out for different types of privacy information; The different usage and entrusted authorization usage methods include: for privacy NFTs that must be used by the user knowing the specific content, a direct usage method is adopted; for privacy NFTs where the user can use them by confirming the scope of the digital information contained, a scope proof entrusted authorization usage method is adopted; for privacy NFTs where the user can use them by obtaining the average value of multiple users for the digital information contained, a mean calculation entrusted authorization usage method is adopted.

2. The method for using, entrusting authorization, and privacy protection of user information based on NFT according to claim 1, characterized in that specifically Including: Step 1: The user calls the smart contract to mint privacy NFTs, specifically including: calling the interface provided by the smart contract to generate privacy NFTs containing field information such as token ID (TokenId), owner (Owner), user (User), revocation date (RevocationDate), name (Name), description (Description), content (Content), data type (DataType), and suffix (Suffix), and storing them in the world state; Step 2: Manage the access control and conditional query of privacy NFTs through the smart contract; The access control mentioned above means that when the user accesses the specific information of the corresponding privacy NFT by passing in the TokenId through the interface provided by the smart contract, the smart contract checks the permissions of the caller and decides whether to return the corresponding query information to ensure the privacy and security of the user's information; The conditional query mentioned above means that when the user passes in the query parameters through the interface provided by the smart contract, the smart contract will return all privacy NFTs that meet the conditions according to the query parameters and the user's permissions; for example, if the user queries the privacy NFTs with the owner (Owner) being himself, the smart contract will return the TokenIds of all privacy NFTs belonging to the caller; Step 3: Through the classification of privacy NFTs, different usage and entrusted authorization usage methods are carried out for different types of privacy information, specifically: the user calls the corresponding interface of the smart contract and combines NFT leasing technology to achieve direct usage of privacy NFTs, scope proof entrusted authorization usage, and mean calculation entrusted authorization usage.

3. The method for using, commissioning authorization and privacy protection of user information based on NFT according to claim 2, characterized in that, The specific content of Step 1 includes: Step 1.1: The user encrypts his own information as the Content field and generates a description of the user information, including Name, Description, DataType, and Suffix; Step 1.2: The user calls the smart contract interface and passes in the fields generated in Step 1.1; Step 1.3: The smart contract generates the TokenId and generates the corresponding privacy NFT according to the fields passed in by the user and stores it in the world state.

4. The method for using, commissioning authorization and privacy protection of user information based on NFT according to claim 2, characterized in that, The NFT leasing technology described above refers to: modifying the user and revocation date fields of the NFT through a smart contract, and ensuring the access rights and available time of the NFT through the smart contract. Specifically, it includes: when a user calls an interface to access a private NFT, checking whether their permissions are met and whether the expiration time has been exceeded; if the permissions are not met, rejecting the access; if the expiration time has been exceeded, rejecting the access and revoking the permissions of the private NFT.

5. The method for using, entrusting authorization, and privacy protection of user information based on NFT according to claim 1 or 2, characterized in that, The direct use of NFT described above refers to: proxy re-encrypting the information in the private NFT under the user's key according to the private NFT and user passed in by the user, and sharing the private NFT for direct use by the user based on NFT leasing without exposing the user's private information to a third party. Specifically, it includes: Step 1.1: The user generates a re-encryption key according to the private NFT to be used and the public key of the user. Step 1.2: The user calls the smart contract for the direct use of the private NFT and passes in the TokenId, User, and re-encryption key. Step 1.3: The smart contract executes the re-encryption algorithm, saves the re-encrypted information in the private NFT, and grants the user access rights to the private NFT based on NFT leasing. Step 1.4: The user calls the smart contract interface and accesses the private NFT and the corresponding re-encrypted information after access control.

6. The method for using, entrusting authorization, and privacy protection of user information based on NFT according to claim 1 or 2, characterized in that, The delegated authorization use of range proof described above refers to: saving the cryptographic commitment and range proof generated by the user on the private NFT according to the private NFT and user passed in by the user, and delegating and authorizing the private NFT to the user for use through a smart contract based on NFT leasing. Step 2.1: The user generates the corresponding cryptographic commitment and range proof according to the digital type private NFT to be used and the interval to be proved. Step 2.2: The user calls the smart contract for the range proof of the private NFT and passes in the TokenId, User, and the information generated in Step 2.

1. Step 2.3: The smart contract saves the cryptographic commitment and range proof in the private NFT and grants the user access rights to the private NFT based on NFT leasing. Step 2.4: The user calls the smart contract interface and accesses the private NFT and the cryptographic commitment and range proof information after access control.

7. The method for using, entrusting authorization and privacy protection of user information based on NFT according to claim 1 or 2, characterized in that The delegated authorization use of mean calculation described above refers to: summing up the digital information confused with random numbers by the users according to the private NFT and user passed in by the users, and delegating and authorizing the private NFT and the sum value to the user for use based on NFT leasing. Step 3.1: The user confuses the user information represented by the private NFT with random numbers according to the digital type private NFT to be used. Step 3.2: The user calls the smart contract for the mean calculation of the private NFT and passes in the TokenId, User, the digital information confused with random numbers, and the shared secret. The shared secret mentioned above refers to the relevant information shared with the user through a shared key algorithm, and only the user with the corresponding private key can restore the confused random number through this information. Step 3.3: The smart contract sums up the obfuscated digital information of the random numbers transmitted by the users, saves the sum value in the world state, saves the shared secret in the privacy NFT, and grants the corresponding privacy NFT access rights to the users based on NFT leasing; Step 3.4: The user calls the smart contract interface, obtains the calculated sum value through access control and accesses the corresponding privacy NFT; restores all the obfuscated random numbers from the shared secret, subtracts the sum of the obfuscated random numbers from the sum value to obtain the sum of all digital information, and divides by the number of people to obtain the mean information.

8. A privacy protection system for implementing the method according to any one of claims 1-7, characterized in that, Including: A management unit, a usage unit, a proof unit, and a mean calculation unit, where: The management unit mints privacy NFTs and processes user access and queries, and decides whether to return the information of the privacy NFT or the privacy NFT corresponding to the query result according to the user's permissions and the field information of the query; The usage unit proxy re-encrypts the information in the privacy NFT under the user's key, and while not exposing the user's privacy information to a third party, shares the privacy NFT directly with the user based on NFT leasing; The proof unit stores the cryptographic commitments and range proofs generated by the user on the privacy NFT, and entrusts and authorizes the privacy NFT to the user for use through the smart contract based on NFT leasing; The mean calculation unit sums up the digital information obfuscated by the users using random numbers to obtain a sum value, and entrusts and authorizes the privacy NFT and the sum value to the user for use based on NFT leasing.

Citation Information

Patent Citations

  • Blockchain data access authority control method based on proxy re-encryption

    CN111191288A

  • Data privacy protection method and system based on block chain and authority contract

    CN113420319A

  • NFT right confirmation and circulation method with privacy protection and supervision

    CN114567640A