A data usage authorization method and device based on an authorization center

Through authorization center and blockchain technology, the problem of fake authorization by data users is solved, the accuracy and security of data authorization information are achieved, and the reliability of data transmission is ensured.

CN114491626BActive Publication Date: 2025-08-01SHANDONG DATA TRADING CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202210009909.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-05
Publication Date
2025-08-01
Estimated Expiration
2042-01-05

AI Technical Summary

Technical Problem

It is difficult for the prior art to verify the situation where data users fakely obtain personal authorization and maliciously invoke personal data.

Method used

Receive information from data providers and users through the authorization center, use the blockchain to perform identification query and comparison, ensure the accuracy of authorization information, and protect data transmission through encryption algorithms.

Benefits of technology

It reduces the situation where data users fake personal authorization and maliciously call personal data, and improves the accuracy and transmission security of authorized information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114491626B_ABST
    Figure CN114491626B_ABST
Patent Text Reader

Abstract

An embodiment of the present application discloses a data usage authorization method and device based on an authorization center. The authorization center receives data source information collected by a data provider and a data application sent by a data user; wherein, different data source information corresponds to different user information; the authorization center receives an authorization application sent by the data user and sends the authorization application to the corresponding user, and after receiving the user feedback information, sends the feedback information to the data user; when the feedback information is consent to authorize, the data user sends a data request to the data provider; the data provider performs authorization verification on the received data request, and after the authorization verification passes, sends the user information corresponding to the data request to the data user. Through the above method, it is possible to verify the situation where the data user obtains personal authorization by impersonation and maliciously calls personal data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of blockchain technology, and in particular, to a data usage authorization method and device based on an authorization center. Background Art

[0002] In the situation where data has become a new production factor, strengthening data circulation and promoting data development and utilization are important means to give full play to the value of data. Before a data provider provides user data, it usually needs to obtain the authorization and consent of the user.

[0003] However, in the current technical processing methods, whether it is signing an agreement offline or completing authorization with the assistance of a corresponding platform online, when the data is used, usually only the data user will come into contact with the user related to the data, and the data provider cannot contact the user. Therefore, it is the data user who directly obtains authorization from the user. In this case, it is difficult for the data provider to directly obtain authorization and difficult to verify authorization in real time. Therefore, it is difficult for the prior art to verify the situation where the data user fraudulently obtains personal authorization and maliciously calls personal data. Summary of the Invention

[0004] The embodiments of this application provide a data usage authorization method and device based on an authorization center, which are used to solve the following technical problems: It is difficult for the prior art to verify the situation where the data user fraudulently obtains personal authorization and maliciously calls personal data.

[0005] The embodiments of this application adopt the following technical solutions:

[0006] The embodiments of this application provide a data usage authorization method based on an authorization center. The method includes: receiving, through the authorization center, data source information collected by a data provider, and receiving a data application sent by a data user; wherein, different data source information corresponds to different user information; receiving, through the authorization center, an authorization application sent by the data user, and sending the authorization application to the corresponding user, and after receiving the user feedback information, sending the feedback information to the data user; when the feedback information is consent to authorize, sending a data request to the data provider through the data user; the data provider performs authorization verification on the received data request, and after the authorization verification passes, sending the user information corresponding to the data request to the data user.

[0007] In the embodiment of the present application, the authorization center receives the authorization application sent by the data user and sends the authorization application to the corresponding user, enabling the user to authorize the current authorization application to notify whether the data can be adopted. Secondly, by the data user sending a data request to the data provider, the data provider can obtain the authorization application information of the user and determine the accuracy of the current authorization information, thereby reducing the occurrence of the situation where the data user fraudulently obtains personal authorization and maliciously invokes personal data.

[0008] In an implementation manner of the present application, sending the authorization application to the corresponding user specifically includes: querying the registration information corresponding to the data source identifier on the blockchain according to the data source identifier in the received authorization application; and querying the registration information corresponding to the data application identifier on the blockchain according to the data application identifier in the received authorization application; and determining the user to be notified on the blockchain according to the user identity identifier in the received authorization application; when the registration information corresponding to the data source identifier, the registration information corresponding to the data application identifier, and the user to be notified are found, sending the authorization application to the user to be notified.

[0009] In the embodiment of the present application, the data source identifier, the data application identifier, and the user identity identifier in the current authorization application are queried through the pre-registered information. Only when all the registration information is found, the authorization application will be sent to the user to be notified. Thereby reducing the probability of false information and ensuring the accuracy of the sent information.

[0010] In an implementation manner of the present application, after receiving the user feedback information, sending the feedback information to the data user specifically includes: after the authorization center receives the feedback information, re-encoding the feedback information to obtain the feedback information in a preset format; digitally signing the feedback information in a preset format by the authorization center, saving the feedback information and the signed data to the current blockchain, and sending the signed data to the data user; wherein the signed data at least includes the data source identifier, the data application identifier, the user identity identifier, the authorization attribute information, and the digital signature.

[0011] In an implementation manner of the present application, the data provider performs authorization verification on the received data request, specifically including: the data provider obtains the application identifier corresponding to the data request; and obtains the data source identifier corresponding to the data request; and obtains the user identity identifier corresponding to the data request; comparing the application identifier corresponding to the data request, the data source identifier corresponding to the data request, and the user identity identifier corresponding to the data request with the identifiers in the authorization application respectively; when the comparison results are all the same, determining that the data request is correct and sending a verification success message to the data provider.

[0012] In an implementation manner of the present application, after comparing the application identifier corresponding to the data request, the data source identifier corresponding to the data request, and the user identity identifier corresponding to the data request with the identifiers in the authorization application respectively, the method further includes: when the comparison results are the same, sending the data request to the authorization center through the data provider; verifying the signature and the restriction attributes corresponding to the data request through the authorization center; where the restriction attributes include at least one of the expiration date and the usage limit; after the data provider receives the verification success information sent by the authorization center, determining that the data request is correct and sending the verification success information to the data provider.

[0013] In an implementation manner of the present application, after sending the authorization application to the corresponding user, the method further includes: through the user terminal, performing grayscale processing on the acquired user face image, and screening out the user facial image through the grayscale difference between the head and the background; extracting each facial feature point in the facial image through face recognition; placing the acquired facial image in a preset coordinate system, connecting the facial feature points pairwise to obtain a feature point vector; comparing the feature point vector with the feature point vector corresponding to the pre-stored facial image to determine the user's identity information.

[0014] In an implementation manner of the present application, after the authorization center receives the data source information collected by the data provider and the data application sent by the data user, the method further includes: when the authorization center is set to the two-dimensional code authorization state, generating an authorization information two-dimensional code for the authorization attributes set by the user through the authorization center and sending the authorization information two-dimensional code to the user terminal; sending the authorization information two-dimensional code to the data user through the user terminal so that the data user can obtain the authorization information corresponding to the authorization information two-dimensional code.

[0015] In the embodiment of the present application, the user terminal sends the authorization information two-dimensional code to the data user so that the data user can obtain the authorization information corresponding to the authorization information two-dimensional code. The data user does not interact with the authorization center and obtains the authorization information by scanning the two-dimensional code, thereby improving the efficiency of authorization information transmission and the speed at which the data user obtains data.

[0016] In an implementation manner of the present application, before the user terminal sends the authorization information two-dimensional code to the data user, the method further includes: encrypting the authorization information with the initial secret key through a symmetric encryption algorithm to obtain a first ciphertext; generating a public-private key pair through an asymmetric encryption algorithm, encrypting the initial secret key with the public key in the public-private key pair to obtain an encrypted ciphertext, and writing the encrypted ciphertext into the first ciphertext to obtain a second ciphertext; generating an authorization information two-dimensional code according to the first ciphertext and the second ciphertext to send the authorization information two-dimensional code to the data user.

[0017] In an implementation manner of the present application, the data user obtains the authorization information corresponding to the authorization information QR code, which specifically includes: the data user obtains the first ciphertext and the second ciphertext according to the received QR code; obtains the encrypted ciphertext through the second ciphertext; decrypts the encrypted ciphertext according to the private key corresponding to the data user to obtain the decrypted initial secret key; and decrypts the first ciphertext based on the corresponding symmetric decryption algorithm and the decrypted initial secret key to obtain the authorization information.

[0018] The embodiment of the present application provides a data usage authorization device based on an authorization center, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to: receive the data source information collected by the data provider through the authorization center, and receive the data application sent by the data user; wherein, different data source information corresponds to different user information; receive the authorization application sent by the data user through the authorization center, and send the authorization application to the corresponding user, and after receiving the user feedback information, send the feedback information to the data user; when the feedback information is consent to authorize, send a data request to the data provider through the data user; the data provider performs authorization verification on the received data request, and after the authorization verification passes, sends the user information corresponding to the data request to the data user.

[0019] The above at least one technical solution adopted by the embodiment of the present application can achieve the following beneficial effects: The embodiment of the present application receives the authorization application sent by the data user through the authorization center and sends the authorization application to the corresponding user, enabling the user to authorize the current authorization application to notify the user whether the data can be adopted. Secondly, by sending a data request from the data user to the data provider, the data provider can obtain the authorization application information of the user and determine the accuracy of the current authorization information, thereby reducing the occurrence of situations where the data user fraudulently obtains personal authorization and maliciously invokes personal data. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. In the drawings:

[0021] Figure 1 It is a flowchart of a data usage authorization method based on an authorization center provided by an embodiment of the present application;

[0022] Figure 2Schematic diagram of a data usage authorization method based on an authorization center provided by an embodiment of the present application;

[0023] Figure 3 Schematic diagram of the structure of a data usage authorization device based on an authorization center provided by an embodiment of the present application. Detailed implementation manners

[0024] An embodiment of the present application provides a data usage authorization method and device based on an authorization center.

[0025] In order to enable those skilled in the art to better understand the technical solutions in the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments of this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0026] In the situation where data has become a new production factor, strengthening data circulation and promoting data development and utilization are important means to give full play to the value of data. Before a data provider provides user data, it usually needs to obtain the authorization and consent of the user.

[0027] However, in the current technical processing methods, whether signing agreements offline or having corresponding platforms assist in completing authorization online, when the data is used, the following problems usually exist:

[0028] 1. Usually only the data users will come into contact with the users related to the data, and the data providers cannot access the users. Therefore, it is the data users who directly obtain authorization from the users. In this case, it is difficult for the data providers to directly obtain authorization and difficult to verify authorization in real time.

[0029] 2. The data provider cannot directly verify personal authorization before providing the data, which leaves loopholes for data users to fraudulently obtain personal authorization and maliciously call personal data.

[0030] 3. An individual authorizes for different data application scenarios with different data users, and it is not easy to clearly remember the authorizations made afterwards, nor is it easy to check one's own authorizations, which also leaves hidden dangers for the malicious use of personal data.

[0031] To solve the above problems, an embodiment of the present application provides a data usage authorization method and device based on an authorization center. By receiving an authorization application sent by a data user through the authorization center and sending the authorization application to the corresponding user, the user can be allowed to authorize the current authorization application to notify the user whether the data can be adopted. Secondly, by sending a data request from the data user to the data provider, the data provider can obtain the authorization application information of the user and determine the accuracy of the current authorization information, thereby reducing the occurrence of situations where the data user fraudulently obtains personal authorization and maliciously invokes personal data.

[0032] The technical solutions proposed in the embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0033] Figure 1 The following is a flowchart of a data usage authorization method based on an authorization center provided by an embodiment of the present application. As Figure 1 shown, the data usage authorization method based on the authorization center includes the following steps:

[0034] S101. Receive the data source information collected by the data provider through the authorization center, and receive the data application sent by the data user.

[0035] In an embodiment of the present application, the authorization center in the embodiments of the present application needs to implement functions such as registration of data sources and data applications, recording of users' authorization operations, sending of user authorization notifications, generation of authorization information, and verification of authorization information. The user terminal needs to implement functions such as user authentication, display of relevant information of data sources and data applications, allowing users to perform authorization operations, and querying and displaying authorization information. The authorization center needs to provide an external program call interface for the data user and the data provider to apply for and verify authorization. The user terminal can be an App on a mobile phone, or in the form of a small program, or in the form of a text message.

[0036] Specifically, the authorization center in the embodiments of the present application is an authorization center implemented based on a blockchain to uniformly generate, verify, store, and manage authorization information. When the data provider registers the data source and the data user registers the data application, the registration information of the data source and the registration information of the data application are both stored on the blockchain. The authorization center assigns a unique identifier to each registered data source and data application for authorization information.

[0037] Furthermore, the data source needs to register detailed description information such as the source, content, and update period of the data, and the data application needs to register detailed description information such as the application scenario, usage, and usage method of the data. The authorization center saves this registration information on the blockchain. The authorization center assigns a unique identifier to both the data source and the data application, and through this identifier, the detailed information of the corresponding data source or data application can be queried on the authorization center.

[0038] For example, assume that the data provider is a communication enterprise and the data user is a bank. The communication enterprise can obtain information about users such as their phone numbers, locations, and whether they are in arrears based on the call record information of the users. The communication enterprise can record the information of the data source on the blockchain. And the authorization center will assign a unique identifier to each user. The data user bank can record information such as the current application scenario and the purpose of data use on the blockchain. For example, when the bank conducts a credit investigation on a user, it needs to obtain the user's arrears information recorded by the communication enterprise. At this time, the bank needs to obtain data use authorization.

[0039] S102. Receive the authorization application sent by the data user through the authorization center, send the authorization application to the corresponding user, and after receiving the user feedback information, send the feedback information to the data user.

[0040] In an embodiment of the present application, the authorization center queries the registration information corresponding to the data source identifier on the blockchain according to the data source identifier in the received authorization application. And the authorization center queries the registration information corresponding to the data application identifier on the blockchain according to the data application identifier in the received authorization application. And the authorization center determines the user to be notified on the blockchain according to the user identity identifier in the received authorization application. When the authorization center queries the registration information corresponding to the data source identifier, the registration information corresponding to the data application identifier, and determines the user to be notified, the authorization center sends the authorization application to the user to be notified.

[0041] Specifically, when the data user initiates an authorization application to the authorization center, the application information includes a data application identifier, a data source identifier to be used, and user identity identification information. The authorization center records the authorization application information on the blockchain. When the authorization center sends a notice to the user through the user terminal, the authorization center queries its detailed description information from the blockchain based on the data source identifier and the data application identifier in the authorization application information, and displays it to the user through the user terminal. The authorization center searches for the user based on the user identity identification information in the authorization application information and sends an authorization application notice to the user's terminal.

[0042] Furthermore, the authorization center saves the authorization application information on the blockchain. The platform queries the registration information of the data source from the blockchain according to the data source identifier in the authorization application, queries the registration information of the data application from the blockchain according to the identifier of the data application in the authorization application, and determines the user to be notified according to the identity identifier of the user. If the authorization center cannot query the corresponding data source, data application, or user, it returns an authorization failure message to the data user. If all the information can be queried, the platform sends a notice of the authorization application to the user through the user terminal.

[0043] In one embodiment of the present application, through the user terminal, the acquired user face image is grayscale processed, and the user face image is screened out through the grayscale difference between the head and the background. Each facial feature point in the face image is extracted through face recognition. The acquired face image is placed in a preset coordinate system, and the facial feature points are connected pairwise to obtain a feature point vector. The feature point vector is compared with the feature point vector corresponding to the pre-stored face image to determine the user's identity information.

[0044] Further, when the user decides whether to authorize through the terminal, the user needs to perform identity recognition through the face image. After the user terminal grayscale processes the acquired image, the face image can be separated from the background, and then the head image can be obtained. The head image may include multiple facial feature points. For example, the starting points of the pupils, the tip of the nose, and the eyebrows in the face. Taking the straight line where the tip of the nose and the chin are located as the y-axis, the straight line passing through the tip of the nose and perpendicular to the y-axis as the x-axis, and the tip of the nose as the origin to establish a preset coordinate system, and the head image is placed in the preset coordinate system, where the position of the tip of the nose of the head image coincides with the coordinate origin. The coordinate positions of each facial feature point are obtained in this coordinate system, and the facial feature points are connected pairwise to obtain a feature point vector. The acquired feature point vector is compared with the pre-stored feature point vector to determine the identity information of the current face image information. After the identity information verification is successful, the user authorizes the current authorization application through the terminal.

[0045] In another embodiment of the present application, when the user decides whether to authorize through the terminal, the user can also verify the identity information through other different methods such as passwords, fingerprints, or ID numbers.

[0046] In one embodiment of the present application, the user can agree or reject the authorization application according to the authorization application information displayed on the terminal. When the user agrees to the authorization application, attributes such as the expiration date and the number of limited uses of the authorization can be set. The authorization center records the information after the user's authorization operation on the blockchain.

[0047] In one embodiment of the present application, after the authorization center receives the feedback information, the feedback information is re-encoded to obtain the feedback information in a preset format. The authorization center digitally signs the feedback information in the preset format, saves the feedback information and the signed data to the current blockchain, and sends the signed data to the data user. The signed data includes at least the data source identifier, the data application identifier, the user identity identifier, the authorization attribute information, and the digital signature.

[0048] Specifically, if the user agrees to grant authorization, the authorization center encodes the authorization information in a fixed format, digitally signs it to form complete authorization information, and sends it to the data user. If the user refuses to grant authorization, the authorization center returns an information indicating that the authorization application has failed to the data user. If the user refuses to grant authorization, the authorization center returns an information indicating that the authorization application has failed to the data user. Among them, the authorization information includes the data source identifier, the data application identifier, the user identity identifier, the authorization attribute information, and the digital signature of the authorization center for the foregoing identifiers and information.

[0049] In an embodiment of the present application, when the authorization center is set to the QR code authorization status, the authorization center generates a QR code of authorization information based on the authorization attributes set by the user, and sends the QR code of authorization information to the user terminal. The user terminal sends the QR code of authorization information to the data user so that the data user can obtain the authorization information corresponding to the QR code of authorization information.

[0050] Specifically, when the authorization center is set to the QR code authorization status, the data user may also not initiate an authorization application for using data to the authorization center. Instead, the user actively operates on the terminal by himself to generate authorization information. The user selects the data source and data application through the terminal, configures the authorization attributes, and submits them to the authorization center. The authorization center generates the authorization information and its QR code. The user shows the QR code of the authorization information to the data user, and the data user obtains the authorization information for using the data by scanning the QR code shown by the user.

[0051] In an embodiment of the present application, the authorization information is encrypted with an initial secret key through a symmetric encryption algorithm to obtain a first ciphertext. A public-private key pair is generated through an asymmetric encryption algorithm, and the initial secret key is encrypted with the public key in the public-private key pair to obtain an encrypted ciphertext, and the encrypted ciphertext is written into the first ciphertext to obtain a second ciphertext. A QR code of authorization information is generated based on the first ciphertext and the second ciphertext, and the QR code of authorization information is sent to the data user.

[0052] Specifically, when the QR code of authorization information is transmitted to the data user, in order to ensure data security, it is necessary to encrypt the QR code of authorization information to reduce the occurrence of data leakage or tampering. The authorization information is encrypted through the symmetric encryption algorithm AES, and a public-private key pair is generated through the asymmetric encryption algorithm RSA. The initial secret key is encrypted with the public key in the public-private key pair to obtain an encrypted ciphertext, and the encrypted ciphertext is written into the first ciphertext to obtain a second ciphertext. The private key in the public-private key pair is simply encrypted through a cyclic shift encryption algorithm to obtain the encrypted ciphertext of the private key. A corresponding QR code is constructed based on the obtained first ciphertext and second ciphertext, and the QR code is sent to the data user.

[0053] In one embodiment of the present application, a data user obtains a first ciphertext and a second ciphertext based on a received QR code. The encrypted ciphertext is obtained using the second ciphertext. The encrypted ciphertext is decrypted using the data user's corresponding private key to obtain an initial decrypted key. The first ciphertext is decrypted using the AES decryption algorithm and the decrypted initial key to obtain authorization information.

[0054] Specifically, after obtaining the authorization information QR code, the data user scans the code to obtain the first and second ciphertexts. The encrypted ciphertext is obtained by encrypting the initial secret key with the public key. Therefore, the encrypted ciphertext is first decrypted using the data user's corresponding private key to obtain the decrypted initial secret key. This decrypted initial key is then used to obtain the authorization information using the AES decryption algorithm.

[0055] The embodiment of the present application encrypts the authorization information QR code to prevent information leakage or tampering during the QR code transmission process, thereby ensuring that the information is transmitted securely and accurately.

[0056] S103: When the feedback information indicates authorization consent, a data request is sent to the data provider via the data user.

[0057] In one embodiment of the present application, after obtaining user authorization, a data user includes authorization information in the request message when initiating a data request from a data provider. The authorization information includes a data source identifier, a data application identifier, a user identity identifier, authorization attribute information, and a digital signature of the authorization center on the aforementioned identifiers and information.

[0058] S104: The data provider performs authorization verification on the received data request, and after the authorization verification passes, sends the user information corresponding to the data request to the data user.

[0059] In one embodiment of the present application, a data provider obtains an application identifier corresponding to a data request, a data source identifier corresponding to the data request, and a user identifier corresponding to the data request. The application identifier, data source identifier, and user identifier corresponding to the data request are compared with the identifiers in the authorization request. If the comparison results are identical, the data request is determined to be correct, and a verification success message is sent to the data provider.

[0060] In an embodiment of the present application, when the comparison results are the same, the data request is sent to the authorization center by the data provider. The authorization center verifies the signature corresponding to the data request and the restriction attributes; wherein, the restriction attributes include at least one of the expiration date and the number of permitted uses. After the data provider receives the verification success information sent by the authorization center, it determines that the data request is correct and sends the verification success information to the data provider.

[0061] Specifically, after the data provider receives the data request from the data user, it determines whether the application initiating the request is consistent with the data application identifier in the authorization information, whether the data source of the request is consistent with the data source identifier in the authorization information, and whether the subject of the requested data is consistent with the user identity identifier in the authorization information. If any of the above is inconsistent, it returns an information indicating that the request fails to the data user. Otherwise, the data provider requests the authorization center to verify the authenticity and validity of the authorization information. The authorization center verifies the signature validity, expiration date, number of permitted uses and other restriction attributes of the authorization information. If the authorization information is valid and can be used normally, it returns verification success to the data provider. Otherwise, it returns verification failure and explains the reason for the failure. The authorization center saves the operation and result of this authorization verification on the blockchain.

[0062] Further, after the data provider obtains the authorization verification result from the authorization center, if the authorization verification is successful, it performs normal business processing and returns the requested data to the data user. If the authorization verification fails, it directly rejects the request of the data user.

[0063] Figure 2 It is a schematic diagram of a data usage authorization method based on an authorization center provided by an embodiment of the present application. As Figure 2 shown, the data usage authorization method based on the authorization center is completed through the user terminal, the authorization center, the data user and the data provider. During processes such as data transmission records, all data needs to be saved to the blockchain for on-chain evidence preservation.

[0064] In one embodiment of the present application, the data provider registers the data source with the authorization center, and the data user registers the data application with the authorization center. Before using the data, the data user initiates an authorization application for the use of the data to the authorization center, and the authorization center sends an application notification to the user with data permission through the user terminal. The user decides whether to authorize through the terminal, and the authorization center records the authorized user's operation result information and returns it to the data user. After obtaining the result of the authorization application, if the user authorizes and agrees, the data user initiates a data request to the data provider. After receiving the data request from the data user, the data provider requests the authorization center to verify the authorization. If the authorization verification is successful, the data provider returns the requested data to the data user. If the authorization verification fails, the data will not be returned to the data user. In the entire process, the data is stored on the chain.

[0065] Specifically, let's take a bank as the data user and a telecommunications company as the data provider. The telecommunications company records the data source information it obtains in an authorization center. The authorization center also assigns a unique identifier to each user. The data user, the bank, can record information such as the current application scenario and data usage on the blockchain. For example, when conducting a credit check on a user, the bank may need to obtain information on the user's outstanding payments recorded by the telecommunications company. In this case, the bank needs to obtain authorization to use the data.

[0066] Furthermore, the bank initiates an authorization request to the authorization center. After receiving the authorization request from the bank, the authorization center determines the basic information of the user to be notified based on the user identifier recorded in the authorization request and sends the authorization request to the terminal corresponding to the user to be notified. The user performs the authorization operation through the terminal device and feeds the authorization information back to the authorization center. The authorization center feeds this authorization information back to the bank. If the current authorization information indicates that the authorization is approved, the bank initiates a data request to the telecommunications company. The telecommunications company verifies the request data and, if the verification is correct, sends the user data corresponding to the request data to the bank.

[0067] Figure 3 This is a schematic diagram of the structure of a data use authorization device based on an authorization center provided in an embodiment of the present application. Figure 3 As shown, the authorized device is used based on the data of the authorization center, including:

[0068] at least one processor; and,

[0069] a memory communicatively connected to the at least one processor; wherein,

[0070] The memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to:

[0071] Receive the data source information collected by the data provider through the authorization center, and receive the data application sent by the data user; among them, different data source information corresponds to different user information.

[0072] Receive the authorization application sent by the data user through the authorization center, and send the authorization application to the corresponding user. After receiving the user feedback information, send the feedback information to the data user.

[0073] When the feedback information is consent to authorize, send a data request to the data provider through the data user.

[0074] The data provider performs authorization verification on the received data request, and after the authorization verification passes, sends the user information corresponding to the data request to the data user.

[0075] Each embodiment in this application is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and the key point of each embodiment is to illustrate the differences from other embodiments. In particular, for the embodiments of the device, equipment, and non-volatile computer storage medium, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiments.

[0076] The above describes specific embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0077] The above are only the embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the embodiments of the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the embodiments of the present application shall be included within the scope of the claims of the present application.

Claims

1. A data usage authorization method based on an authorization center, characterized in that The method includes: Receiving, by an authorization center, data source information collected by a data provider and receiving a data application sent by a data user; wherein, different data source information corresponds to different user information; Receiving, by the authorization center, an authorization application sent by the data user, sending the authorization application to the corresponding user, and after receiving the user feedback information, sending the feedback information to the data user; When the feedback information is consent to authorize, sending, by the data user, a data request to the data provider; The data provider performs authorization verification on the received data request, and after the authorization verification passes, sends the user information corresponding to the data request to the data user; The sending the authorization application to the corresponding user specifically includes: Querying, according to the data source identifier in the received authorization application, the registration information corresponding to the data source identifier on the blockchain; and Querying, according to the data application identifier in the received authorization application, the registration information corresponding to the data application identifier on the blockchain; and Determining, according to the user identity identifier in the received authorization application, the user to be notified on the blockchain; When the registration information corresponding to the data source identifier, the registration information corresponding to the data application identifier, and the user to be notified are determined, sending the authorization application to the user to be notified; The sending the feedback information to the data user after receiving the user feedback information specifically includes: After the authorization center receives the feedback information, re-encoding the feedback information to obtain feedback information in a preset format; Digitally signing, by the authorization center, the feedback information in the preset format, saving the feedback information and the signed data to the current blockchain, and sending the signed data to the data user; wherein, the signed data at least includes a data source identifier, a data application identifier, a user identity identifier, authorization attribute information, and the digital signature; The data provider performing authorization verification on the received data request specifically includes: The data provider obtains the application identifier corresponding to the data request; and Obtaining the data source identifier corresponding to the data request; and Obtaining the user identity identifier corresponding to the data request; Comparing the application identifier corresponding to the data request, the data source identifier corresponding to the data request, and the user identity identifier corresponding to the data request with the identifiers in the authorization application respectively; When the comparison results are all the same, determining that the data request is correct and sending a verification success message to the data provider; After comparing the application identifier corresponding to the data request, the data source identifier corresponding to the data request, and the user identity identifier corresponding to the data request with the identifiers in the authorization application respectively, the method further includes: When the comparison results are the same, sending, by the data provider, the data request to the authorization center; Verify the signature corresponding to the data request and the restriction attributes through the authorization center; wherein, the restriction attributes include at least one of an expiration date and a limited usage times; After the data provider receives the verification success information sent by the authorization center, determine that the data request is correct, and send the verification success information to the data provider; After the authorization center receives the data source information collected by the data provider and the data application sent by the data user, the method further includes: When the authorization center is set to the QR code authorization status, generate an authorization information QR code for the authorization attributes set by the user through the authorization center, and send the authorization information QR code to the user terminal; Send the authorization information QR code to the data user through the user terminal, so that the data user can obtain the authorization information corresponding to the authorization information QR code.

2. The data usage authorization method based on an authorization center according to claim 1, wherein After the authorization application is sent to the corresponding user, the method further includes: Through the user terminal, perform gray processing on the acquired user face image, and filter out the user face image through the gray difference between the head and the background; Extract each facial feature point in the facial image through face recognition; Put the acquired facial image into a preset coordinate system, connect the facial feature points in pairs to obtain a feature point vector; Compare the feature point vector with the feature point vector corresponding to the pre-stored facial image to determine the user's identity information.

3. A data usage authorization method based on an authorization center according to claim 1, characterized in that, Before the authorization information QR code is sent to the data user through the user terminal, the method further includes: Encrypt the authorization information with the initial secret key through a symmetric encryption algorithm to obtain a first ciphertext; Generate a public-private key pair through an asymmetric encryption algorithm, encrypt the initial secret key with the public key in the public-private key pair to obtain an encrypted ciphertext, and write the encrypted ciphertext into the first ciphertext to obtain a second ciphertext; Generate the authorization information QR code according to the first ciphertext and the second ciphertext, so as to send the authorization information QR code to the data user.

4. The data usage authorization method based on an authorization center according to claim 3, characterized in that The data user obtains the authorization information corresponding to the authorization information QR code, specifically including: The data user obtains the first ciphertext and the second ciphertext according to the received QR code; Obtain the encrypted ciphertext through the second ciphertext; Decrypt the encrypted ciphertext according to the private key corresponding to the data user to obtain the decrypted initial secret key; Based on the corresponding symmetric decryption algorithm and the decrypted initial secret key, decrypt the first ciphertext to obtain the authorization information.

5. A data usage authorization device based on an authorization center, including: At least one processor; And, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can: Receive the data source information collected by the data provider through the authorization center, and receive the data application sent by the data user; wherein, different data source information corresponds to different user information; Receive the authorization application sent by the data user through the authorization center, and send the authorization application to the corresponding user. After receiving the user feedback information, send the feedback information to the data user; When the feedback information is consent to authorize, send a data request to the data provider through the data user; The data provider performs authorization verification on the received data request, and after the authorization verification passes, sends the user information corresponding to the data request to the data user; The sending the authorization application to the corresponding user specifically includes: According to the data source identifier in the received authorization application, query the registration information corresponding to the data source identifier on the blockchain; and According to the data application identifier in the received authorization application, query the registration information corresponding to the data application identifier on the blockchain; and According to the user identity identifier in the received authorization application, determine the user to be notified on the blockchain; When the registration information corresponding to the data source identifier, the registration information corresponding to the data application identifier, and the user to be notified are determined, send the authorization application to the user to be notified; The sending the feedback information to the data user after receiving the user feedback information specifically includes: After the authorization center receives the feedback information, re-encode the feedback information to obtain the feedback information in a preset format; Digitally sign the feedback information in the preset format through the authorization center, save the feedback information and the signed data to the current blockchain, and send the signed data to the data user; wherein, the signed data at least includes a data source identifier, a data application identifier, a user identity identifier, authorization attribute information, and the digital signature; The data provider performs authorization verification on the received data request, specifically including: The data provider obtains the application identifier corresponding to the data request; and Obtain the data source identifier corresponding to the data request; and Obtain the user identity identifier corresponding to the data request; Compare the application identifier corresponding to the data request, the data source identifier corresponding to the data request, and the user identity identifier corresponding to the data request with the identifiers in the authorization application respectively; When the comparison results are all the same, determine that the data request is correct, and send a verification success message to the data provider; After the comparing the application identifier corresponding to the data request, the data source identifier corresponding to the data request, and the user identity identifier corresponding to the data request with the identifiers in the authorization application respectively, further includes: When the comparison results are the same, send the data request to the authorization center through the data provider; Verify the signature and restriction attributes corresponding to the data request through the authorization center; wherein, the restriction attributes at least include one of an expiration date and a limited use times; After the data provider receives the verification success information sent by the authorization center, it determines that the data request is correct and sends the verification success information to the data provider; After receiving the data source information collected by the data provider and the data application sent by the data user through the authorization center, it further includes: When the authorization center is set to the QR code authorization status, the authorization center generates an authorization information QR code based on the authorization attributes set by the user and sends the authorization information QR code to the user terminal; The user terminal sends the authorization information QR code to the data user so that the data user can obtain the authorization information corresponding to the authorization information QR code.

Citation Information

Patent Citations

  • Private data processing method, device and equipment of block chain and storage medium

    CN111737366A

  • Medical data sharing method and device based on block chain, terminal and storage medium

    CN111986764A

  • Authorization information verification system and method

    CN112149080A

  • Data authorization method and device, computer readable storage medium and computer equipment

    CN113792318A