A distributed private data control method and device

The distributed system formed by blockchain nodes utilizes consensus mechanism and private key control to solve the problem of user data out of control and realize decentralized management and security control of users' private data.

CN113919002BActive Publication Date: 2025-09-16BEIJING BAIXIN DIGITAL TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111101323.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-18
Publication Date
2025-09-16
Estimated Expiration
2041-09-18

AI Technical Summary

Technical Problem

User data is out of control, and they are unable to effectively control their own private data. There is a risk that the data may be used for free by the operating server or illegally resold.

Method used

Through the distributed system formed by blockchain nodes, private data at the collection end is labeled and packaged by the consensus mechanism, and stored and controlled using private keys. Users can obtain private keys to control the storage and evaluation of data, and the evaluation results are transmitted and stored through the blockchain system.

Benefits of technology

It enables decentralized management and control of users’ own data, improves data security, and ensures users’ autonomy and security over their private data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113919002B_ABST
    Figure CN113919002B_ABST
Patent Text Reader

Abstract

The present invention provides a distributed private data control method and device, which obtains the private information of the collection end that is labeled, and the label uniquely corresponds to the offline entity identity. The private information is packaged by the collection end according to the consensus mechanism, and is read by the private key. The private information is linked and stored, the private key of the evaluation end is received, the private information is sent to the evaluation end for reading, the online evaluation result of the evaluation end is received and stored, the download request of the user end is responded to, and the online evaluation result is sent to the user end. The technical solution connects multiple collection ends together to form a blockchain system that communicates with each other, which is used to store the data collected by the collection end, thereby realizing decentralized management and storage of user data, so that users can control their own private data without being controlled by the management of other commercial servers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to data processing technology, and in particular to a distributed private data control method and device. Background Art

[0002] With the development of Internet of Things technology, more and more user data is being collected, and the collected user data is often used for commercial processing, which leads to the data originally belonging to the user being out of control, used for free by the operating server, or even illegally resold.

[0003] Therefore, in the prior art, users cannot control their own user data. Summary of the Invention

[0004] The embodiments of the present invention provide a distributed private data control method and device, which can allow users to control their own user data and improve the security of user data.

[0005] According to a first aspect of an embodiment of the present invention, a distributed private data control method is provided, comprising:

[0006] Obtain the labeled private information of the collection end. The label uniquely corresponds to the offline entity identity. The private information is obtained by each node by packaging the private data of the collection end according to the consensus mechanism and read by the private key;

[0007] Linking and storing the private information;

[0008] Receive the private key of the evaluation terminal and send the private information to the evaluation terminal for reading;

[0009] Receiving and storing the online evaluation results of the evaluation terminal;

[0010] In response to a download request from the user terminal, the online evaluation result is sent to the user terminal;

[0011] Among them, the consensus mechanism includes:

[0012] Randomly select a trusted institution from multiple nodes to authenticate the block signature, and randomly generate multiple candidate nodes;

[0013] Perform signature authentication on the blocks generated by the candidate nodes based on the public trust institution, and use the block with the largest number of signature authentications as the consensus block;

[0014] Packaging the product data of the acquisition end according to the consensus block to obtain the current block of the product information;

[0015] The current block is broadcasted through the consensus block, and all nodes store the current block in conjunction with the previous block.

[0016] Optionally, in a possible implementation of the first aspect, the method further includes:

[0017] Receive tokens paid by the user terminal to the candidate node that generates the consensus block, and open a channel for obtaining the private key to the user terminal;

[0018] The user terminal obtains the private key controlling the private information based on the acquisition channel.

[0019] Optionally, in a possible implementation of the first aspect, before obtaining the private key for controlling the private information, the method further includes:

[0020] Generate a random dynamic password and the validity period of the random dynamic code;

[0021] The private key is generated based on the random dynamic password and the validity time.

[0022] Optionally, in a possible implementation of the first aspect, before receiving the private key of the evaluation terminal, the method further includes:

[0023] In response to the user end agreeing to the control request of the evaluation end, the private key of the user end is sent to the evaluation end.

[0024] Optionally, in a possible implementation of the first aspect, the private data includes multiple types;

[0025] The responding user terminal agrees to the control request of the evaluation terminal and sends the private key of the user terminal to the evaluation terminal, including:

[0026] In response to the user end agreeing to the control request of the evaluation end, the private key of the user end corresponding to the type is sent to the evaluation end.

[0027] Optionally, in a possible implementation of the first aspect, the method further includes:

[0028] Receive a first comparison result uploaded by the user terminal based on the online evaluation result and the offline evaluation result, link and store the first comparison result, and publish it to the entire network.

[0029] Optionally, in a possible implementation of the first aspect, the method further includes:

[0030] Receive a second comparison result of the online evaluation result and the offline evaluation result uploaded by the entity side, link and store the second comparison result, and publish it to the entire network.

[0031] A second aspect of an embodiment of the present invention provides a distributed private data control device, including:

[0032] The information module is used to obtain the labeled private information of each node. The label uniquely corresponds to the offline entity identity. The private information is obtained by the collection end by packaging the private data of the collection end according to the consensus mechanism and read by the private key;

[0033] A storage module, configured to link and store the private information;

[0034] An evaluation module, configured to receive a private key from an evaluation terminal and send the private information to the evaluation terminal for reading;

[0035] A result module, configured to receive and store the online evaluation results of the evaluation terminal;

[0036] A download module, configured to respond to a download request from the user terminal and send the online evaluation result to the user terminal;

[0037] Among them, the consensus mechanism includes:

[0038] Randomly select a trusted institution from multiple nodes to authenticate the block signature, and randomly generate multiple candidate nodes;

[0039] Perform signature authentication on the blocks generated by the candidate nodes based on the public trust institution, and use the block with the largest number of signature authentications as the consensus block;

[0040] Packaging the product data of the acquisition end according to the consensus block to obtain the current block of the product information;

[0041] The current block is broadcasted through the consensus block, and all nodes store the current block in conjunction with the previous block.

[0042] According to a third aspect of an embodiment of the present invention, a distributed private data control device is provided, comprising: a memory, a processor, and a computer program, wherein the computer program is stored in the memory, and the processor runs the computer program to execute the first aspect of the present invention and various methods that may be involved in the first aspect.

[0043] According to a fourth aspect of an embodiment of the present invention, a readable storage medium is provided, in which a computer program is stored. When the computer program is executed by a processor, it is used to implement the first aspect of the present invention and various methods that may be involved in the first aspect.

[0044] The present invention provides a distributed private data control method and device, which utilizes blockchain nodes to connect multiple collection terminals together to form a blockchain system that communicates with each other and is used to store data collected by the collection terminals, thereby realizing decentralized management and storage of user data. This allows users to control their own private data without being controlled by the management of other commercial servers, thereby allowing users to control their own user data while improving the security of user data. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 1 is a flow chart of a distributed private data control method provided by an embodiment of the present invention;

[0046] Figure 2 This is a schematic diagram of the structure of a blockchain system provided by an embodiment of the present invention;

[0047] Figure 3 1 is a schematic structural diagram of a distributed private data control device provided by an embodiment of the present invention;

[0048] Figure 4 This is a schematic diagram of the hardware structure of a distributed private data control device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0049] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0050] The terms "first," "second," "third," "fourth," and so forth (if any) in the description and claims of the present invention and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequential sequence. It should be understood that the terms used in this manner are interchangeable where appropriate, such that the embodiments of the present invention described herein can be practiced in sequences other than those illustrated or described herein.

[0051] It should be understood that in various embodiments of the present invention, the size of the sequence number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0052] It should be understood that in the present invention, "include" and "have" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or apparatus that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to these processes, methods, products or apparatuses.

[0053] It should be understood that in the present invention, "multiple" refers to two or more. "And / or" is only a description of the association relationship of associated objects, indicating that three relationships can exist. For example, and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "Contains A, B and C", "Contains A, B, C" means that A, B, and C are all included, "Contains A, B or C" means that one of A, B, and C is included, and "Contains A, B and / or C" means that any one, any two, or any three of A, B, and C are included.

[0054] It should be understood that, in the present invention, "B corresponding to A," "B corresponding to A," "A corresponds to B," or "B corresponds to A" means that B is associated with A and B can be determined based on A. Determining B based on A does not mean determining B based solely on A; B can also be determined based on A and / or other information. A and B match when the similarity between A and B is greater than or equal to a preset threshold.

[0055] Depending on the context, "if" as used herein may be interpreted as "when" or "when" or "in response to determining" or "in response to detecting."

[0056] The following specific embodiments are used to describe the technical solution of the present invention in detail. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.

[0057] See also Figure 1 , is a flow chart of a distributed private data control method provided by an embodiment of the present invention, Figure 1The execution subject of the method shown may be a software and / or hardware device. The execution subject of the present application may include but is not limited to at least one of the following: user equipment, network equipment, etc. Among them, the user equipment may include but is not limited to computers, smart phones, personal digital assistants (PDAs) and the electronic devices mentioned above. Network equipment may include but is not limited to a single network server, a server group consisting of multiple network servers, or a cloud based on cloud computing consisting of a large number of computers or network servers, wherein cloud computing is a type of distributed computing, a super virtual computer composed of a group of loosely coupled computers. This embodiment does not limit this. It includes steps S101 to S105, as follows:

[0058] S101, the blockchain system obtains the labeled private information of the collection end, the label uniquely corresponds to the offline entity identity, the private information is obtained by the collection end by packaging the private data of the collection end according to the consensus mechanism, and is read by the private key.

[0059] Specifically, see Figure 2 This embodiment uses blockchain nodes to connect multiple collection terminals together to form a blockchain system that communicates with each other and is used to store the data collected by the collection terminals, thereby realizing decentralized management and storage of user data, allowing users to control their own private data without being controlled by the management of other commercial servers.

[0060] Among them, each offline entity identity can be equipped with a collection terminal to collect user data to form private data, and then package the private data to form private information, which is uploaded to the blockchain system for storage. Subsequent users can use the obtained private key to read it.

[0061] Among them, the consensus mechanism includes:

[0062] Randomly extracting a trusted institution for block signature authentication from the plurality of collection terminals, and randomly generating a plurality of candidate nodes;

[0063] Perform signature authentication on the blocks generated by the candidate nodes based on the public trust institution, and use the block with the largest number of signature authentications as the consensus block;

[0064] Packaging the product data of the acquisition end according to the consensus block to obtain the current block of the product information;

[0065] The current block is broadcasted through the consensus block, and all nodes store the current block in conjunction with the previous block.

[0066] It can be understood that the blockchain system of this solution is composed of various nodes, and the public trust agency used to sign and authenticate the blocks will sign and authenticate the generated blocks. The block with the largest number of authentications will be selected as the consensus block, and then the private data will be packaged to form the current block for linked storage, which can realize data on the chain and users can use private keys to control their own data.

[0067] S102, the blockchain system links and stores the private information.

[0068] It can be understood that the blockchain system of this solution will link and store the current block formed, which can realize the storage of data on the chain.

[0069] S103, the blockchain system receives the private key of the evaluation end and sends the private information to the evaluation end for reading.

[0070] It is understandable that steps S101 and S102 can store user private data and allow the user to control the stored data using a private key.

[0071] This step allows users to use their own private information to allow the evaluation end to perform online evaluation operations. In order for the evaluation end to evaluate the private information, the user can send his or her own private key to the evaluation end. The evaluation end reads the private information based on the private key sent by the user to perform the evaluation operation.

[0072] For example, the collection end can be a smart wearable device, such as a smart bracelet, and the acquired data can be private data such as the user's heart rate, blood pressure, and exercise status. The evaluation end can be an online doctor, who evaluates the private data and uploads the evaluation results to the blockchain system.

[0073] It is understandable that before the evaluation end uses the private key to view private information, the user needs to obtain the private key first. The steps to obtain the private key can be:

[0074] Receive the token paid by the user terminal to the candidate node that generates the consensus block, and open a private key acquisition channel to the user terminal; the user terminal obtains the private key that controls the private information based on the acquisition channel.

[0075] It is understandable that after obtaining the private key, the user can forward it to the evaluation end, and the evaluation end can use the private key to view the corresponding private information.

[0076] Specifically, before receiving the private key of the evaluation terminal, the following may be further included:

[0077] In response to the user end agreeing to the control request of the evaluation end, the private key of the user end is sent to the evaluation end.

[0078] In some embodiments, private data may include multiple types;

[0079] The above-mentioned response to the user end agreeing to the control request of the evaluation end and sending the private key of the user end to the evaluation end may include:

[0080] In response to the user end agreeing to the control request of the evaluation end, the private key of the user end corresponding to the type is sent to the evaluation end.

[0081] It is understandable that if the user only wants the evaluation end to obtain one type of private information, then they only need to send the corresponding type of private key to the evaluation end. For example, the heart rate data in the user's private data can correspond to the first private key, and the exercise data can correspond to the second private key. If the user only wants the evaluation end to obtain the heart rate data, then they only need to send the first private key to the evaluation end.

[0082] In practical applications, before obtaining the private key for controlling the private information, the method further includes:

[0083] Generate a random dynamic password and the validity period of the random dynamic code, and generate the private key based on the random dynamic password and the validity period.

[0084] It can be understood that the private key in this embodiment is a random dynamic password, which improves the security of the private key. It also comes with a validity period. For example, if the user triggers the generation of a private key at 9:00 am, the validity period can be 1 hour, then the private key will expire at 10:00 am. After 10:00, any user who uses this key to access private information will not be able to access it, thereby improving the security of private information.

[0085] S104, the blockchain system receives and stores the online evaluation results of the evaluation terminal.

[0086] It is understandable that the evaluation end reads private information based on the private key sent by the user to perform evaluation operations, and uploads the online evaluation results to the blockchain system for storage, which is convenient for subsequent users to download and view.

[0087] S105, the blockchain system responds to the download request of the user terminal and sends the online evaluation result to the user terminal.

[0088] It is understandable that when the user wants to know the results of its own evaluation, it needs to download it from the blockchain system. After receiving the user's download request, the blockchain system sends the corresponding online evaluation results to the user.

[0089] The above embodiment not only enables users to securely store their own private data, but also allows users to control the stored data for online evaluation and obtain evaluation results related to their own private data.

[0090] Based on the above embodiment, in order to verify the online evaluation results and evaluate the evaluation capabilities of the evaluation end, the following two methods can be used for evaluation:

[0091] Method 1:

[0092] Receive a first comparison result uploaded by the user terminal based on the online evaluation result and the offline evaluation result, link and store the first comparison result, and publish it to the entire network.

[0093] It is understandable that users can go to the physical end offline to obtain offline evaluation results based on private data, and then compare them with the online evaluation results, upload them to the blockchain through the user end, check whether the results are consistent, and publish them to the entire network.

[0094] Method 2:

[0095] Receive a second comparison result of the online evaluation result and the offline evaluation result uploaded by the entity side, link and store the second comparison result, and publish it to the entire network.

[0096] Among them, the physical end can be, for example, a physical hospital, that is, the physical hospital can access the blockchain system, directly compare the online evaluation results, obtain the second comparison result, upload it to the blockchain system for storage, and publish it to the entire network.

[0097] See also Figure 3 , is a schematic structural diagram of a distributed private data control device provided by an embodiment of the present invention, the distributed private data control device comprising:

[0098] The information module is used to obtain the labeled private information of the collection end. The label uniquely corresponds to the offline entity identity. The private information is obtained by each node by packaging the private data of the collection end according to the consensus mechanism and read by the private key;

[0099] A storage module, configured to link and store the private information;

[0100] An evaluation module, configured to receive a private key from an evaluation terminal and send the private information to the evaluation terminal for reading;

[0101] A result module, configured to receive and store the online evaluation results of the evaluation terminal;

[0102] A download module, configured to respond to a download request from the user terminal and send the online evaluation result to the user terminal;

[0103] Among them, the consensus mechanism includes:

[0104] Randomly selecting a trusted institution for block signature authentication from the plurality of nodes, and randomly generating a plurality of candidate nodes;

[0105] Perform signature authentication on the blocks generated by the candidate nodes based on the public trust institution, and use the block with the largest number of signature authentications as the consensus block;

[0106] Packaging the product data of the acquisition end according to the consensus block to obtain the current block of the product information;

[0107] The current block is broadcasted through the consensus block, and all nodes store the current block in conjunction with the previous block.

[0108] Figure 3 The apparatus of the embodiment shown can be used to perform Figure 1 The implementation principles and technical effects of the steps in the method embodiment shown are similar and will not be repeated here.

[0109] See also Figure 4 , is a schematic diagram of the hardware structure of a distributed private data control device provided by an embodiment of the present invention, the distributed private data control device 40 includes: a processor 41, a memory 42 and a computer program; wherein

[0110] The memory 42 is used to store the computer program, which may also be a flash memory. The computer program is, for example, an application program or a functional module for implementing the above method.

[0111] The processor 41 is configured to execute the computer program stored in the memory to implement the various steps performed by the device in the above method. For details, please refer to the relevant description in the above method embodiment.

[0112] Optionally, the memory 42 may be independent or integrated with the processor 41 .

[0113] When the memory 42 is a device independent of the processor 41, the device may further include:

[0114] The bus 43 is used to connect the memory 42 and the processor 41 .

[0115] The present invention also provides a readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, it is used to implement the methods provided in the various embodiments described above.

[0116] Among them, the readable storage medium can be a computer storage medium or a communication medium. Communication media include any medium that facilitates the transmission of computer programs from one place to another. Computer storage media can be any available medium that can be accessed by a general-purpose or special-purpose computer. For example, a readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application-specific integrated circuit (ASIC). In addition, the ASIC can be located in a user device. Of course, the processor and the readable storage medium can also exist in a communication device as discrete components. The readable storage medium can be a read-only memory (ROM), a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.

[0117] The present invention also provides a program product, which includes execution instructions stored in a readable storage medium. At least one processor of a device can read the execution instructions from the readable storage medium, and at least one processor executes the execution instructions so that the device implements the methods provided in the various embodiments described above.

[0118] In the embodiments of the above-mentioned devices, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly implemented by a hardware processor or implemented by a combination of hardware and software modules in the processor.

[0119] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A distributed private data control method, characterized in that: include: Obtain the labeled private information of the collection end. The label uniquely corresponds to the offline entity identity. The private information is obtained by each node by packaging the private data of the collection end according to the consensus mechanism and read by the private key; Linking and storing the private information; Receive the private key of the evaluation terminal and send the private information to the evaluation terminal for reading; Receiving and storing the online evaluation results of the evaluation terminal; Responding to a download request from a user terminal, sending the online evaluation result to the user terminal; Among them, the consensus mechanism includes: Randomly select a trusted institution from multiple nodes to authenticate the block signature, and randomly generate multiple candidate nodes; Perform signature authentication on the blocks generated by the candidate nodes based on the public trust institution, and use the block with the largest number of signature authentications as the consensus block; Packaging the product data of the acquisition end according to the consensus block to obtain the current block of product information; The current block is broadcasted through the consensus node, and all nodes store the current block in conjunction with the previous block.

2. The method according to claim 1, characterized in that Also includes: Receive tokens paid by the user terminal to the candidate node that generates the consensus block, and open a channel for obtaining the private key to the user terminal; The user terminal obtains the private key controlling the private information based on the acquisition channel.

3. The method according to claim 2, characterized in that Before obtaining the private key that controls the private information, the method further includes: Generate a random dynamic password and the validity period of the random dynamic password; The private key is generated based on the random dynamic password and the validity time.

4. The method according to claim 1, wherein Before receiving the private key of the evaluation terminal, the method further includes: In response to the user end agreeing to the control request of the evaluation end, the private key of the user end is sent to the evaluation end.

5. The method according to claim 4, characterized in that The private data includes multiple types; The responding user terminal agrees to the control request of the evaluation terminal and sends the private key of the user terminal to the evaluation terminal, including: In response to the user end agreeing to the control request of the evaluation end, the private key of the user end corresponding to the type is sent to the evaluation end.

6. The method according to claim 1, characterized in that Also includes: Receive a first comparison result uploaded by the user terminal based on the online evaluation result and the offline evaluation result, link and store the first comparison result, and publish it to the entire network.

7. The method according to claim 1, characterized in that Also includes: Receive a second comparison result of the online evaluation result and the offline evaluation result uploaded by the entity side, link and store the second comparison result, and publish it to the entire network.

8. A distributed private data control device, characterized in that: include: The information module is used to obtain the labeled private information of the collection end. The label uniquely corresponds to the offline entity identity. The private information is obtained by each node by packaging the private data of the collection end according to the consensus mechanism and read by the private key; A storage module, configured to link and store the private information; An evaluation module, configured to receive a private key from an evaluation terminal and send the private information to the evaluation terminal for reading; A result module, configured to receive and store the online evaluation results of the evaluation terminal; A download module, configured to respond to a download request from a user terminal and send the online evaluation result to the user terminal; Among them, the consensus mechanism includes: Randomly select a trusted institution from multiple nodes to authenticate the block signature, and randomly generate multiple candidate nodes; Perform signature authentication on the blocks generated by the candidate nodes based on the public trust institution, and use the block with the largest number of signature authentications as the consensus block; Packaging the product data of the acquisition end according to the consensus block to obtain the current block of product information; The current block is broadcasted through the consensus node, and all nodes store the current block in conjunction with the previous block.

9. A distributed private data control device, characterized in that: include: A memory, a processor, and a computer program, wherein the computer program is stored in the memory, and the processor runs the computer program to execute the method according to any one of claims 1 to 7.

10. A readable storage medium, characterized in that: The readable storage medium stores a computer program, and when the computer program is executed by a processor, it is used to implement the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Generation method for consensus blocks in block chain and computing device

    CN107124403A

  • Big data system based on blockchain technology, storage method and use method

    CN112307501A