A data acquisition method, device and equipment based on a trusted device

By storing data in trusted devices and using blockchain technology to build a trusted transfer service, combined with a trusted execution environment and smart contracts, the problems of leakage and tampering in privacy data transactions are solved, and the secure transmission and transaction of data are realized.

CN115033919BActive Publication Date: 2026-04-17ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
Filing Date
2020-09-04
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In existing technologies, there are risks of data leakage and tampering during the trading of personal privacy data. There is an urgent need for a reliable trading method to protect the security and integrity of privacy data.

Method used

By storing data in trusted devices and using blockchain technology to build trusted transfer services, combined with a trusted execution environment and smart contracts, secure data transmission and transactions can be achieved.

Benefits of technology

Effectively protect privacy data from theft, ensure the credibility and integrity of data sources, prevent data tampering, and maintain data privacy and security during transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115033919B_ABST
    Figure CN115033919B_ABST
Patent Text Reader

Abstract

Embodiments of the present specification disclose a data acquisition method and device based on a trusted device and equipment, and relate to the technical field of blockchains. The scheme comprises: publishing description information for first data, wherein the first data is stored in a trusted device; acquiring a data acquisition request for the first data issued by a data demand party in response to the description information, the data acquisition request being used to request reading of the first data based on a first resource; sending the data acquisition request to a data owner of the first data; acquiring first confirmation information of the data owner; acquiring the first data from the trusted device based on the first confirmation information; and sending the first data to the data demand party.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of blockchain technology, and in particular to a data acquisition method, apparatus and device based on a trusted device. Background Technology

[0002] Similar to goods, personal data, especially private data, can also be traded as a commodity. For example, a person's medication data during illness treatment, as well as their identity information during medication, can be used as a reference for developing new drugs. This creates a market for the supply and demand of personal privacy data. Given the privacy nature of personal data, and to prevent the leakage of personal data during transactions, there is an urgent need for a reliable method for the trading of personal privacy data. Summary of the Invention

[0003] To solve the above-mentioned technical problems, the embodiments in this specification are implemented as follows:

[0004] Firstly, the embodiments of this specification provide a data acquisition method based on a trusted device, comprising:

[0005] Publish descriptive information about the first data, wherein the first data is stored in a trusted device;

[0006] The data requester responds to the data acquisition request for the first data issued by the description information, and the data acquisition request is used to request to read the first data based on the first resource;

[0007] Send the data acquisition request to the data owner of the first data;

[0008] Obtain the first confirmation information from the data owner;

[0009] Based on the first confirmation information, the first data is obtained from the trusted device;

[0010] The first data is sent to the data requester.

[0011] Secondly, the embodiments of this specification provide a data acquisition method based on a trusted device, including:

[0012] The data requester's needs regarding the first data;

[0013] The data owner obtains data provision information in response to the requested information, the data provision information being used to prompt the data requester to provide a first resource to read the first data; the first data is stored in a trusted device.

[0014] The data provision information is sent to the data requester.

[0015] Obtain the first certain information of the data requester;

[0016] Based on the first confirmation information, the first data is obtained from the trusted device;

[0017] The first data is sent to the data requester.

[0018] Thirdly, the embodiments of this specification provide a data acquisition device based on a trusted device, comprising:

[0019] A description information publishing module is used to publish description information for the first data, wherein the first data is stored in a trusted device;

[0020] The data acquisition request acquisition module is used to acquire a data acquisition request for the first data issued by the data requester in response to the description information. The data acquisition request is used to request to read the first data based on the first resource.

[0021] A data acquisition request sending module is used to send the data acquisition request to the data owner of the first data;

[0022] The first confirmation information acquisition module is used to acquire the first confirmation information of the data owner.

[0023] The first data acquisition module is used to acquire the first data from the trusted device based on the first confirmation information;

[0024] The first data sending module is used to send the first data to the data requester.

[0025] Fourthly, the embodiments of this specification provide a data acquisition device based on a trusted device, comprising:

[0026] The demand information publishing module is used to publish the demand information of data demanders for the first data.

[0027] A data provision information acquisition module is used to acquire data provision information from the data owner in response to the requested information. The data provision information is used to prompt the data requester to provide a first resource to read the first data. The first data is stored in a trusted device.

[0028] A data provision information sending module is used to send the data provision information to the data requester;

[0029] The first confirmation information acquisition module is used to acquire the first confirmation information of the data requester.

[0030] The first data acquisition module is used to acquire the first data from the trusted device based on the first confirmation information;

[0031] The first data sending module is used to send the first data to the data requester.

[0032] Fifthly, the embodiments of this specification provide a data acquisition device based on a trusted device, comprising:

[0033] At least one processor; and,

[0034] A memory communicatively connected to the at least one processor; wherein,

[0035] The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to:

[0036] Publish descriptive information about the first data, wherein the first data is stored in a trusted device;

[0037] The data requester responds to the data acquisition request for the first data issued by the description information, and the data acquisition request is used to request to read the first data based on the first resource;

[0038] Send the data acquisition request to the data owner of the first data;

[0039] Obtain the first confirmation information from the data owner;

[0040] Based on the first confirmation information, the first data is obtained from the trusted device;

[0041] The first data is sent to the data requester.

[0042] Sixthly, the embodiments of this specification provide a data acquisition device based on a trusted device, comprising:

[0043] At least one processor; and,

[0044] A memory communicatively connected to the at least one processor; wherein,

[0045] The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to:

[0046] The data requester's needs regarding the first data;

[0047] The data owner obtains data provision information in response to the requested information, the data provision information being used to prompt the data requester to provide a first resource to read the first data; the first data is stored in a trusted device.

[0048] The data provision information is sent to the data requester.

[0049] Obtain the first certain information of the data requester;

[0050] Based on the first confirmation information, the first data is obtained from the trusted device;

[0051] The first data is sent to the data requester.

[0052] Seventhly, embodiments of this specification provide a computer-readable medium having stored computer-readable instructions thereon, which can be executed by a processor to implement a data acquisition method based on a trusted device.

[0053] One embodiment of this specification achieves the following beneficial effects: by storing the first data in a trusted device and only publishing the descriptive information of the first data on the supply and demand platform, the first data can be effectively protected from being stolen. Furthermore, storing the first data on a trusted device ensures the trustworthiness of the data source and prevents the first data from being tampered with. Attached Figure Description

[0054] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0055] Figure 1 A flowchart illustrating a data acquisition method based on a trusted device provided in an embodiment of this specification;

[0056] Figure 2 A flowchart illustrating another data acquisition method based on a trusted device provided in the embodiments of this specification;

[0057] Figure 3 The embodiments provided in this specification correspond to Figure 1 A schematic diagram of a data acquisition device based on a trusted device;

[0058] Figure 4 The embodiments provided in this specification correspond to Figure 2 A schematic diagram of a data acquisition device based on a trusted device;

[0059] Figure 5 This is a schematic diagram of the structure of a data acquisition device based on a trusted device, provided as an embodiment of this specification. Detailed Implementation

[0060] To make the objectives, technical solutions, and advantages of one or more embodiments of this specification clearer, the technical solutions of one or more embodiments of this specification will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, and not all of them. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort are within the protection scope of one or more embodiments of this specification.

[0061] The technical solutions provided in the various embodiments of this specification are described in detail below with reference to the accompanying drawings.

[0062] Data, as a resource, is fundamental to many data applications and industrial development due to its liquidity and accessibility. However, privacy protection during data exchange and sharing remains a significant challenge for industry development. Unlike the trading of goods, data transactions, especially involving private data, require a more secure environment. Current technologies typically encrypt data before transmission, but even encrypted data can be decrypted, leading to data leaks.

[0063] This solution stores transaction data in trusted devices, ensuring data privacy and preventing tampering. The trusted devices retrieve data from trusted data sources, thus guaranteeing the data source's trustworthiness. Specifically, localized trusted data collection software acquires personal information from the data source and is privately deployed within the network environment where the data source resides. The transfer network relies on blockchain technology to form a trusted transfer service within a public cloud. Transaction data can be output in three formats: plaintext, ciphertext, and feature vectors, and computation is performed using trusted applications.

[0064] This solution pushes data based on supply and demand information published in a trusted network. For example, it pushes descriptive information about the data to users who need it, or sends demand information to users who may have relevant data.

[0065] A transaction can be triggered by either the data owner or the data requester, and confirmed by the other party to reach a consensus and complete the transaction. This can be accomplished through smart contracts. Furthermore, the data traded can be complete data or a value or result calculated from the complete data, depending on the type of data being traded by both the supply and demand parties.

[0066] The data trading process takes place on a supply and demand platform, which can be a centralized platform or a decentralized platform, such as a blockchain network.

[0067] A blockchain can be understood as a data chain composed of multiple blocks stored sequentially. Each block's header contains a timestamp of the current block, the hash value of the previous block, and the hash value of the current block's information. This enables mutual verification between blocks, forming an immutable blockchain. Each block can be understood as a data unit (a unit for storing data). As a decentralized database, a blockchain is a chain of data blocks linked together using cryptographic methods. Each data block contains information about a network transaction, used to verify the validity of the information (anti-counterfeiting) and generate the next block. The chain formed by linking blocks end-to-end constitutes the blockchain. Modifying data within a block requires modifying the content of all subsequent blocks and updating the backup data of all nodes in the blockchain network. Therefore, blockchains are difficult to tamper with or delete, and once data is stored on the blockchain, it serves as a reliable method for maintaining content integrity.

[0068] Blockchain technology has the following four main characteristics:

[0069] (1) Decentralization: It enables peer-to-peer transactions, coordination, and collaboration without the need for third-party intervention. In a blockchain network, no single institution or individual can control the global data, and the cessation of any node will not affect the overall operation of the system. This decentralized network will greatly enhance data security.

[0070] (2) Immutability: Blockchain uses encryption technology to verify and store data, and uses distributed consensus algorithms to add and update data. Blockchain requires each node to participate in verifying transactions and producing blocks; modifying any data requires changing all subsequent records, and it is extremely difficult to modify data on a single node.

[0071] (3) Openness, transparency, and traceability: The written block content is backed up and replicated to each node, and each node has the latest complete database copy, with all record information being publicly available. Anyone can query block data through a public interface. Every transaction in the blockchain is stored in the block data through chained storage, and a superimposed hash digest is performed on all transaction records in all blocks using cryptographic algorithms, thus allowing traceability to any historical transaction data.

[0072] (4) Collective Maintenance: The decentralized nature of blockchain networks determines their collective maintenance. Traditional centralized institutions typically have to perform three roles: data storage provider, data manager, and data analyst. Blockchain networks, on the other hand, are maintained jointly by all participants in an equal manner. The rights and responsibilities of each party are clearly defined, and there is no need to relinquish rights to third-party institutions, thus achieving collaborative cooperation.

[0073] The core technologies of blockchain mainly involve the following aspects:

[0074] (1) Consensus mechanism: Since there is no central authority in the blockchain system, there needs to be a set of rules to guide all nodes to reach a consensus on data processing. All data interactions must be carried out in accordance with strict rules and consensus.

[0075] (2) Cryptographic technology: Cryptographic technology is one of the core technologies of blockchain. Many classic algorithms of modern cryptography are used in current blockchain applications, including hash algorithms, symmetric encryption, asymmetric encryption, digital signatures, etc.

[0076] (3) Distributed Storage: Blockchain is a distributed ledger on a peer-to-peer network, where each participating node independently and completely stores and writes block data information. The advantages of distributed storage over traditional centralized storage are mainly reflected in two aspects: First, each node backs up data information, avoiding data loss due to single-point failures. Second, the data on each node is stored independently, effectively preventing malicious tampering of historical data.

[0077] (4) Smart Contracts: Smart contracts allow for trusted transactions without a third party. Once one party achieves the pre-defined goal, the contract automatically executes the transaction. These transactions are traceable and irreversible. Smart contracts offer advantages such as transparency, trustworthiness, automatic execution, and mandatory fulfillment.

[0078] Next, a data acquisition method based on a trusted device, as provided in the embodiments of the specification, will be described in detail with reference to the accompanying drawings:

[0079] Figure 1 This is a flowchart illustrating a data acquisition method based on a trusted device, as provided in an embodiment of this specification. From a programming perspective, the entity executing the process can be a program hosted on an application server or an application client.

[0080] like Figure 1 As shown, the process may include the following steps:

[0081] Step 102: Publish description information for the first data, wherein the first data is stored in a trusted device.

[0082] The primary data can be text, images, videos, or other data that can be transmitted digitally. The primary data can be personal privacy data, or creative works such as text, images, and videos.

[0083] A trusted device can be understood as a device that possesses a trusted environment through software or hardware means. This can be a hardware device with a Trusted Execution Environment (TEE) deployed, or a hardware device configured with a trusted secure application (Trusted APP). A trusted device can be a mobile communication tool, a server, a tablet computer, or a non-erasable storage device, etc.

[0084] A trusted device can be the device of the data owner of the first data. If the provider of the first data is also the data owner, such as a literary work, video, or photograph, then the data owner can directly store the first data in the trusted device. If the provider of the first data is not the data owner, such as Zhang San's bank statements where the bank is the provider but Zhang San is the owner, then the first data can be defined as data obtained by the trusted device from a trusted data source. For example, Zhang San can apply for salary slips on a bank's website, and the bank will then send the salary slips to an email address provided by Zhang San. A program can be pre-embedded in the trusted device to retrieve the salary slips sent by the bank from that email address according to the program's defined interface. The TEE (Trusted Equipment Environment) acts as a hardware black box; the code and data executed in the TEE cannot be viewed even at the operating system level, and can only be manipulated through the pre-defined interfaces in the code. Therefore, the trusted device can obtain trusted data through the pre-defined interfaces in the TEE's code. Taking obtaining salary slips as an example, an interface corresponding to the email address can be pre-embedded in the TEE. Since the code in the TEE cannot be tampered with, it can be guaranteed that the salary slips obtained by the trusted device are obtained from the specified address, and therefore the obtained salary slips are trustworthy.

[0085] In a more convenient implementation, the trusted device is a pluggable device, and the pluggable device is deployed with a trusted execution environment. Optionally, the pluggable device is a USB flash drive. Furthermore, the USB flash drive obtains the first data from the data owner's terminal based on the trusted execution environment. Specifically, the trusted device obtains the first data from the data owner through a predefined interface in the code of the trusted execution environment.

[0086] To enhance the security of trusted USB drives, each drive has a unique serial number and is bound to the first hardware device it connects to. A trusted USB drive can only communicate with the bound device. Furthermore, data on a trusted USB drive can only be added and deleted, not modified.

[0087] To protect the primary data from leakage, only descriptive information about the primary data is published on the platform. This descriptive information can include the data type, overall structure, and so on.

[0088] The process of obtaining descriptive information from user data can be executed on a trusted USB drive or processed in a trusted environment within a trusted network built by the supply and demand platform, such as using TAPP for secure computation. Taking medical case information as an example, the descriptive information can include the disease name, the patient's age, the type of medication, or the duration of medication use.

[0089] One implementation: The description information is generated by processing the data using a secure application within the trusted device. Based on the ISV software embedded in the trusted USB drive, user personal information is obtained from a trusted data source. The user personal information is then processed using the TAPP function on the trusted USB drive to obtain description information of the user data, which is then published on the supply and demand network.

[0090] Another implementation: Receive first data from the data owner; process the first data using a secure application to obtain descriptive information about the first data. It should be noted that the supply and demand platform constructs a trusted network by deploying a trusted execution environment. Specifically, this solution can construct the supply and demand network as a trusted network through hardware or software methods, thereby protecting privacy data.

[0091] When the supply and demand network is a blockchain network, each blockchain node can create and invoke smart contracts through a virtual machine. Transactions containing smart contracts and their execution results are stored on the blockchain ledger, or in a way where each node in the blockchain stores the entire ledger. This presents a challenge for privacy protection. Privacy protection can be achieved through various technologies, such as cryptographic techniques (homomorphic encryption or zero-knowledge proof), hardware privacy technologies, and network isolation technologies. Typical hardware privacy protection technologies include Trusted Execution Environments (TEEs).

[0092] For example, blockchain nodes can all implement a secure execution environment for blockchain transactions through a TEE (Trusted Platform Module). A TEE is a secure extension of CPU hardware, a trusted execution environment completely isolated from the outside world. Currently, the industry is paying close attention to TEE solutions; almost all mainstream chip and software alliances have their own TEE solutions, such as TPM (Trusted Platform Module) on the software side and SGX (Software Guard Extensions), ARM Trustzone, and AMD PSP (Platform Security Processor) on the hardware side. A TEE acts as a hardware black box; the code and data executed within a TEE cannot be viewed even at the operating system level, and can only be manipulated through predefined interfaces in the code. In terms of efficiency, due to the black-box nature of the TEE, the computations performed within it are plaintext data, rather than the complex cryptographic operations of homomorphic encryption, resulting in almost no loss of computational efficiency. Therefore, by deploying a TEE environment on blockchain nodes, privacy requirements in blockchain scenarios can be largely met with relatively little performance loss.

[0093] Taking SGX technology as an example, blockchain nodes can create enclaves (enclaves or enclaves) based on SGX technology to serve as TEEs for executing blockchain transactions. Specifically, blockchain nodes utilize newly added processor instructions in the CPU to allocate a portion of memory as an EPC (Enclave Page Cache) to house the aforementioned enclaves. The memory area corresponding to the EPC is encrypted by the CPU's internal Memory Encryption Engine (MEE). The contents of this memory area (code and data within the enclave) can only be decrypted within the CPU core, and the encryption / decryption keys are generated and stored in the CPU only when the EPC is started. As can be seen, the security boundary of the enclave only includes itself and the CPU. Neither privileged nor non-privileged software can access the enclave. Even the operating system administrator and the VMM (Virtual Machine Monitor, or Hypervisor) cannot affect the code and data within the enclave, thus providing extremely high security. Furthermore, given this security guarantee, the CPU can process blockchain transactions in plaintext within the enclave, achieving extremely high computational efficiency, thereby balancing data security and computational efficiency. Data entering and leaving the TEE can be encrypted, thus ensuring data privacy.

[0094] A blockchain network is a novel distributed infrastructure and computing method that utilizes a block-chain data structure to verify and store data, a distributed node consensus algorithm to generate and update data, cryptography to ensure the security of data transmission and access, and smart contracts composed of automated script code to program and manipulate data. A blockchain network consists of multiple nodes. When each node broadcasts information or a block to the blockchain network, all nodes receive it and verify the received block. When the percentage of nodes that have successfully verified a block exceeds a preset threshold, the block is considered valid, and all nodes receive and store it in their local node space. A node can be understood as an electronic device with storage capabilities, such as a server or terminal. Blockchain networks are mainly divided into public blockchains, consortium blockchains, and private blockchains.

[0095] Step 104: The data requester responds to the data acquisition request for the first data issued by the description information. The data acquisition request is used to request to read the first data based on the first resource.

[0096] When a data requester sees the description information of the first data on the supply and demand platform, they will initiate a request to read the first data on the platform. The data requester can also be called the data user.

[0097] Furthermore, in order to access the first data, the data requester or the data owner can specify what resources must be exchanged. The first resource can be digital resources or monetary resources. The data owner can limit the type and quantity of the first resource. The data requester can also apply for other methods to obtain the data owner's consent.

[0098] When the first resource is defined by the data owner, the descriptive information for the first data may also include the first resource.

[0099] Step 106: Send the data acquisition request to the data owner of the first data.

[0100] Users of supply and demand platforms (networks) can be individual users or enterprise users. To enhance privacy protection, the description information published on supply and demand platforms may or may not include the data owner of the first data source, and the data requester may not be aware of the data owner's identity information. Therefore, the supply and demand platform needs to forward the data acquisition request to the data owner of the first data source.

[0101] The data owner can also be called the data holder, data owner, etc.

[0102] Step 108: Obtain the first confirmation information from the data owner.

[0103] If the data owner agrees to the data request from the data requester, they will reply with a confirmation message. To ensure the data owner understands the purpose of the data purchase, the basic data requested and the intended use of the data can be specified in the data request. For individual users, this basic data may include some or all of the individual's name, gender, nationality, type of identification document, identification document number, age, occupation, mobile phone number, and contact address. For enterprise users, this basic data may include some or all of the enterprise's name, business license number, business address, name of the legal representative, type of identification document, identification document number, and validity period.

[0104] The aforementioned basic information is not publicly available on the platform and is only disclosed to the data owner of First Data.

[0105] Step 110: Based on the first confirmation information, obtain the first data from the trusted device. Step 110 can be performed using a secure application. The trusted device can obtain the first data from the data owner through a predefined interface in the code of the trusted execution environment.

[0106] Step 112: Send the first data to the data requester.

[0107] When the data owner agrees to sell the initial data to the data demander, and certain conditions are met, such as receiving the initial resource from the data demander, the supply and demand platform can obtain the initial data from a trusted device and then send it to the data demander. This entire process can be accomplished using smart contracts.

[0108] To enhance security, the first data is sent to the data requester. Specifically, a secure application can be used to send the first data to the data requester, and the secure application is a program selected by the data owner.

[0109] The methods described above can prevent the initial data from being sent to other users or stolen. Furthermore, the supply and demand platform acts merely as an intermediary throughout the process, responsible for the reliable transmission of data, and does not store the initial data.

[0110] It should be understood that the order of some steps in the methods described in one or more embodiments of this specification may be interchanged according to actual needs, or some steps may be omitted or deleted.

[0111] Figure 1The method described above, which stores the first data in a trusted device and only publishes descriptive information of the first data on the supply and demand platform, can effectively protect the first data from being stolen. Furthermore, storing the first data on a trusted device ensures the trustworthiness of the data source and prevents the first data from being tampered with.

[0112] Furthermore, the first data can be encrypted during transmission. To ensure that the first data is only sent to the data requester, it can be encrypted using the data requester's public key; the encrypted first data is then sent to the data requester. In a blockchain network, the public keys of each blockchain node are public; therefore, the data requester's public key can be directly obtained to encrypt the first data. The data requester's private key is only kept by the data requester; therefore, only the data requester can decrypt and read the encrypted first data.

[0113] Alternatively, the first data can be encrypted using the public key of the data owner, and then the encrypted first data and the private key of the data owner can be sent to the data requester for decryption.

[0114] Specifically, before obtaining the first data from the trusted device, the method may further include:

[0115] Send the private key of the data owner to the data requester;

[0116] Sending the first data to the data requester may specifically include:

[0117] The first data is encrypted using the public key of the data owner;

[0118] The encrypted first data is sent to the data requester.

[0119] The step of "sending the private key of the data owner to the data requester" is equivalent to the process of authorizing read permissions for the first data. This process can only ensure that the first data can only be read by users with read permissions; other users without permissions cannot read it.

[0120] In addition, a data request from a data demander regarding the first data can be either to obtain the right to use the first data or to obtain ownership of the first data.

[0121] When the data requester's data acquisition request for the first data is to acquire ownership of the first data, after sending the first data to the data requester, the method may further include:

[0122] Obtain a second confirmation message from the data requester, the second confirmation message indicating that the data requester has received the first data;

[0123] The first data is deleted from the trusted device.

[0124] In this method, the data requester's request for the first data is to acquire ownership of the first data. Once the data requester has received the first data, the first data needs to be deleted from the trusted device. Alternatively, the step "retrieving the first data from the trusted device" can be implemented by performing a "cut" operation on the first data on the trusted device, i.e., deleting the first data from the trusted device, and storing the first data in the platform's cache. After the data requester receives the first data, it then deletes the first data from the platform's cache.

[0125] When a data requester's request for access to the first data is for the right to use the first data, after sending the first data to the data requester, the method may further include:

[0126] Obtain third confirmation information from the data requester, the third confirmation information indicating that the data requester has received the first data;

[0127] The first data and the correspondence between the data requesters are stored in the blockchain network;

[0128] Update the usage record of the first data.

[0129] This method stores transaction information for each piece of first-data in the blockchain network, recording who the buyer is and how many times they purchased. The usage records can include how many users read the first-data and which time periods saw the most users reading it. For example, if the first-data is a literary work or a video work, the reading data can be analyzed to determine which types of data are more popular with other users, allowing for the recommendation of similar data to other users.

[0130] In addition, the above-mentioned "correspondence between the first data and the data requester" and "usage record" can be sent to the data requester, and can be stored in a trusted device.

[0131] Optionally, the method may further include:

[0132] The correspondence between the first data and the data requester is sent to the trusted device for storage;

[0133] The usage record of the first data is sent to the trusted device for storage.

[0134] Data users can analyze the popularity of the primary data based on its usage records, identifying which data is popular and allowing for targeted updates.

[0135] Optionally, before obtaining the first data from the trusted device, the method further includes:

[0136] Determine whether the first resource from the data requester has been received, and obtain a first judgment result;

[0137] Obtaining the first data from the trusted device specifically includes:

[0138] If the first determination result is yes, the first data is obtained from the trusted device;

[0139] Determine whether the fourth confirmation message from the data requester has been received, wherein the fourth confirmation message indicates that the data requester has received the first data, and obtain the second determination result;

[0140] If the second determination result is yes, the first resource is forwarded to the data owner.

[0141] The above method provides a way to complete the transaction process of the first data based on the first resource.

[0142] When the primary resource is a monetary resource, let's say the primary data is a literary work. To acquire this work, a corresponding amount of currency, say 19 yuan, is required. First, the user pays 19 yuan, which is stored in the platform's account. Then, the platform sends the primary data to the user. After the user reads the primary data, the 19 yuan is transferred to the data owner's account.

[0143] When the primary resource is a digital resource, for example, if the primary data is medical case information, and the owner of the medical case information is a medical research institution, in order to obtain more medical case information, they can request that the primary resource used to exchange the primary data also be medical case information, thus achieving information sharing and a win-win situation. In this case, the handling method is basically the same as for monetary resources; the primary resource can be temporarily stored on the platform, and then sent to the data owner after the data requester receives the primary data. Alternatively, the primary resource can be encrypted using methods similar to encrypting the primary data, which will not be repeated here.

[0144] Figure 1 The approach was written from the perspective of data supply. Figure 2 This is a flowchart illustrating another data acquisition method based on a trusted device provided in an embodiment of this specification. Figure 2 It is described from the perspective of data requirements. For example... Figure 2As shown, the method may include the following steps:

[0145] Step 202: Publish the data requester's requirements for the first data.

[0146] The requirements here can be compared with Figure 1 Corresponding to the descriptive information, the demand information can specify the type of data required, such as the specific cases. The demand information can also indicate what resources are available in exchange for the first data.

[0147] Step 204: Obtain data provision information from the data owner in response to the requested information. The data provision information is used to prompt the data requester to provide a first resource to read the first data; the first data is stored in a trusted device.

[0148] Data provision information can include what data the data owner can provide, with a brief description to help the data requester determine if it is the data they need. Additionally, it can specify that the provided data is stored on a trusted device.

[0149] Step 206: Send the data provision information to the data requester.

[0150] Step 208: Obtain the first confirmation information of the data requester.

[0151] If the data requester agrees to provide the first data in the manner specified in the data provision information, then reply with an affirmative response.

[0152] Step 210: Based on the first confirmation information, obtain the first data from the trusted device.

[0153] Step 212: Send the first data to the data requester.

[0154] Optionally, the trusted device is the device of the data owner.

[0155] Optionally, the first data is data obtained by the trusted device from a trusted data source.

[0156] Optionally, the trusted device is a pluggable device, which is deployed with a trusted execution environment that is isolated from the operating system layer.

[0157] Optionally, the pluggable device is a USB flash drive.

[0158] Optionally, the trusted device obtains the first data from the terminal of the data owner based on the trusted execution environment.

[0159] Optionally, the trusted device obtains the first data from the data owner's terminal based on the trusted execution environment, which may specifically include:

[0160] The trusted device obtains the first data from the terminal of the data owner through a predefined interface in the code of the trusted execution environment.

[0161] Optionally, after sending the first data to the data requester, the method may further include:

[0162] Obtain a second confirmation message from the data requester, the second confirmation message indicating that the data requester has received the first data;

[0163] The first data is deleted from the trusted device.

[0164] Optionally, after sending the first data to the data requester, the method may further include:

[0165] Obtain third confirmation information from the data requester, the third confirmation information indicating that the data requester has received the first data;

[0166] The first data and the correspondence between the data requesters are stored in the blockchain network;

[0167] Update the usage record of the first data.

[0168] Optionally, the method may further include:

[0169] The correspondence between the first data and the data requester is sent to the trusted device for storage;

[0170] The usage record of the first data is sent to the trusted device for storage.

[0171] Optionally, sending the first data to the data requester may specifically include:

[0172] The first data is sent to the data requester using a secure application, which is a program selected by the data owner.

[0173] Optionally, the first resource may be a data resource or a monetary resource.

[0174] Optionally, before obtaining the first data from the trusted device, the method may further include:

[0175] Send the private key of the data owner to the data requester;

[0176] Sending the first data to the data requester specifically includes:

[0177] The first data is encrypted using the public key of the data owner;

[0178] The encrypted first data is sent to the data requester.

[0179] The above-mentioned extension scheme can be referred to Figure 1 The descriptions of the corresponding parts will not be repeated here.

[0180] Based on the same idea, embodiments of this specification also provide apparatus corresponding to the above methods. Figure 3 The embodiments provided in this specification correspond to Figure 1 A schematic diagram of a data acquisition device based on a trusted device. (See diagram below.) Figure 3 As shown, the device may include:

[0181] The description information publishing module 302 is used to publish description information for the first data, wherein the first data is stored in a trusted device;

[0182] The data acquisition request acquisition module 304 is used to acquire a data acquisition request for the first data issued by the data requester in response to the description information. The data acquisition request is used to request to read the first data based on the first resource.

[0183] The data acquisition request sending module 306 is used to send the data acquisition request to the data owner of the first data;

[0184] The first confirmation information acquisition module 308 is used to acquire the first confirmation information of the data owner.

[0185] The first data acquisition module 310 is used to acquire the first data from the trusted device based on the first confirmation information;

[0186] The first data sending module 312 is used to send the first data to the data requester.

[0187] based on Figure 3 The embodiments of this specification also provide some specific implementations of the device, which will be described below.

[0188] Optionally, the trusted device is the device of the data owner.

[0189] Optionally, the first data is data obtained by the trusted device from a trusted data source.

[0190] Optionally, the trusted device is a pluggable device, which is deployed with a trusted execution environment that is isolated from the operating system layer.

[0191] Optionally, the pluggable device is a USB flash drive.

[0192] Optionally, the trusted device obtains the first data from the terminal of the data owner based on the trusted execution environment.

[0193] Optionally, the trusted device obtains the first data from the data owner's terminal based on the trusted execution environment, which may specifically include:

[0194] The trusted device obtains the first data from the terminal of the data owner through a predefined interface in the code of the trusted execution environment.

[0195] Optionally, the device may further include:

[0196] The second confirmation information acquisition module is used to acquire the second confirmation information of the data requester, which indicates that the data requester has received the first data.

[0197] The first data deletion module is used to delete the first data from the trusted device.

[0198] Optionally, the device may further include:

[0199] The third confirmation information acquisition module is used to acquire the third confirmation information of the data requester, which indicates that the data requester has received the first data.

[0200] A correspondence storage module is used to store the correspondence between the first data and the data requester in the blockchain network;

[0201] The usage record update module is used to update the usage record of the first data.

[0202] Optionally, the device may further include:

[0203] The correspondence sending module is used to send the correspondence between the first data and the data requester to the trusted device for storage;

[0204] The record sending module is used to send the usage record of the first data to the trusted device for storage.

[0205] Optionally, the device may further include;

[0206] The first data receiving module is used to receive the first data from the data owner.

[0207] The first data processing module is used to process the first data using a security application to obtain descriptive information of the first data.

[0208] Optionally, the description information is generated by processing with a security application in the trusted device.

[0209] Optionally, the first data sending module 312 is specifically used to send the first data to the data requester using a secure application, wherein the secure application is a program selected by the data owner.

[0210] Optionally, the device may further include:

[0211] The first judgment module is used to determine whether the first resource from the data requester has been received, and to obtain a first judgment result.

[0212] The first data acquisition module 310 is specifically used to acquire the first data from the trusted device when the first determination result is yes.

[0213] Optionally, the device may further include:

[0214] The second judgment module is used to determine whether the fourth confirmation information of the data requester has been received, and to obtain a second judgment result. The fourth confirmation information indicates that the data requester has received the first data.

[0215] The first resource forwarding module is used to forward the first resource to the data owner when the second judgment result is yes.

[0216] Optionally, the first resource may be a data resource or a monetary resource.

[0217] Optionally, the device may further include:

[0218] The private key sending module is used to send the private key of the data owner to the data requester;

[0219] The first data sending module 312 may specifically include:

[0220] The first encryption unit is used to encrypt the first data using the public key of the data owner;

[0221] The first sending unit is used to send the encrypted first data to the data requester.

[0222] Optionally, the first data sending module 312 may specifically include:

[0223] The second encryption unit is used to encrypt the first data using the public key of the data requester;

[0224] The second sending unit is used to send the encrypted first data to the data requester.

[0225] Figure 4 The embodiments provided in this specification correspond to Figure 2 A schematic diagram of a data acquisition device based on a trusted device. (See diagram below.) Figure 4 As shown, the device may include:

[0226] The demand information publishing module 402 is used to publish the demand information of the data demander for the first data.

[0227] The data provision information acquisition module 404 is used to acquire data provision information from the data owner in response to the demand information. The data provision information is used to prompt the data demander to provide a first resource to read the first data. The first data is stored in a trusted device.

[0228] The data provision information sending module 406 is used to send the data provision information to the data requester;

[0229] The first confirmation information acquisition module 408 is used to acquire the first confirmation information of the data requester.

[0230] The first data acquisition module 410 is used to acquire the first data from the trusted device based on the first confirmation information;

[0231] The first data sending module 412 is used to send the first data to the data requester.

[0232] based on Figure 4 The embodiments of this specification also provide some specific implementations of the device, which will be described below.

[0233] Optionally, the trusted device is the device of the data owner.

[0234] Optionally, the first data is data obtained by the trusted device from a trusted data source.

[0235] Optionally, the trusted device is a pluggable device, which is deployed with a trusted execution environment that is isolated from the operating system layer.

[0236] Optionally, the pluggable device is a USB flash drive.

[0237] Optionally, the trusted device obtains the first data from the terminal of the data owner based on the trusted execution environment.

[0238] Optionally, the trusted device obtains the first data from the data owner's terminal based on the trusted execution environment, which may specifically include:

[0239] The trusted device obtains the first data from the terminal of the data owner through a predefined interface in the code of the trusted execution environment.

[0240] Optionally, the device may further include:

[0241] The second confirmation information acquisition module is used to acquire the second confirmation information of the data requester, which indicates that the data requester has received the first data.

[0242] The first data deletion module is used to delete the first data from the trusted device.

[0243] Optionally, the device may further include:

[0244] The third confirmation information acquisition module is used to acquire the third confirmation information of the data requester, which indicates that the data requester has received the first data.

[0245] A correspondence storage module is used to store the correspondence between the first data and the data requester in the blockchain network;

[0246] The usage record update module is used to update the usage record of the first data.

[0247] Optionally, the device may further include:

[0248] The correspondence sending module is used to send the correspondence between the first data and the data requester to the trusted device for storage;

[0249] The record sending module is used to send the usage record of the first data to the trusted device for storage.

[0250] Optionally, the first data sending module 412 is specifically used to send the first data to the data requester using a secure application, wherein the secure application is a program selected by the data owner.

[0251] Optionally, the first resource may be a data resource or a monetary resource.

[0252] Optionally, the device may further include:

[0253] The private key sending module is used to send the private key of the data owner to the data requester;

[0254] The first data sending module 412 specifically includes:

[0255] The first encryption unit is used to encrypt the first data using the public key of the data owner;

[0256] The first sending unit is used to send the encrypted first data to the data requester.

[0257] Based on the same idea, this specification also provides devices corresponding to the above methods in its embodiments.

[0258] Figure 5 This is a schematic diagram of the structure of a data acquisition device based on a trusted device, provided as an embodiment of this specification. Figure 5 As shown, device 500 may include:

[0259] At least one processor 510; and,

[0260] Memory 530 communicatively connected to the at least one processor; wherein,

[0261] The memory 530 stores instructions 520 that can be executed by the at least one processor 510, the instructions being executed by the at least one processor 510 to enable the at least one processor 510 to:

[0262] Publish descriptive information about the first data, wherein the first data is stored in a trusted device;

[0263] The data requester responds to the data acquisition request for the first data issued by the description information, and the data acquisition request is used to request to read the first data based on the first resource;

[0264] Send the data acquisition request to the data owner of the first data;

[0265] Obtain the first confirmation information from the data owner;

[0266] Based on the first confirmation information, the first data is obtained from the trusted device;

[0267] The first data is sent to the data requester.

[0268] Alternatively, to enable the at least one processor 510 to:

[0269] The data requester's needs regarding the first data;

[0270] The data owner obtains data provision information in response to the requested information, the data provision information being used to prompt the data requester to provide a first resource to read the first data; the first data is stored in a trusted device.

[0271] The data provision information is sent to the data requester.

[0272] Obtain the first certain information of the data requester;

[0273] Based on the first confirmation information, the first data is obtained from the trusted device;

[0274] The first data is sent to the data requester.

[0275] Following the same approach, embodiments of this specification also provide a computer-readable medium corresponding to the above-described methods. The computer-readable medium stores computer-readable instructions that can be executed by a processor to implement the following methods:

[0276] Publish descriptive information about the first data, wherein the first data is stored in a trusted device;

[0277] The data requester responds to the data acquisition request for the first data issued by the description information, and the data acquisition request is used to request to read the first data based on the first resource;

[0278] Send the data acquisition request to the data owner of the first data;

[0279] Obtain the first confirmation information from the data owner;

[0280] Based on the first confirmation information, the first data is obtained from the trusted device;

[0281] The first data is sent to the data requester.

[0282] Alternatively, the computer-readable instructions may be executed by a processor to implement the following method:

[0283] The data requester's needs regarding the first data;

[0284] The data owner obtains data provision information in response to the requested information, the data provision information being used to prompt the data requester to provide a first resource to read the first data; the first data is stored in a trusted device.

[0285] The data provision information is sent to the data requester.

[0286] Obtain the first certain information of the data requester;

[0287] Based on the first confirmation information, the first data is obtained from the trusted device;

[0288] The first data is sent to the data requester.

[0289] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on its differences from other embodiments. In particular, for... Figure 5 The data acquisition device based on a trusted device shown is basically similar to the method embodiment, so the description is relatively simple. For relevant details, please refer to the description of the method embodiment.

[0290] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program a digital system themselves to "integrate" it onto a PLD, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must also be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also understand that by simply performing some logic programming on the method flow using one of these hardware description languages ​​and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.

[0291] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.

[0292] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.

[0293] For ease of description, the above devices are described separately by function as various units. Of course, in implementing this application, the functions of each unit can be implemented in one or more software and / or hardware.

[0294] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0295] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0296] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0297] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0298] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0299] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0300] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital character versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0301] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0302] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0303] This application can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. This application can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0304] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A data acquisition method based on a trusted device, comprising: A data acquisition request issued by a data requester for first data, wherein the data acquisition request is used to request to read the first data based on a first resource; Send the data acquisition request to the data owner of the first data; Obtain the first confirmation information from the data owner; Based on the first confirmation information, the first data is obtained from a trusted device, wherein the trusted device is a pluggable device; the trusted device is the device of the data owner of the first data; the trusted device is a hardware device with a trusted execution environment for storing the first data; the trusted device obtains the first data from a trusted data source through a predefined interface in the code of the trusted execution environment. The first data is sent to the data requester via a secure application.

2. The method as described in claim 1, further comprising, before obtaining the data acquisition request for the first data issued by the data requester: Publish descriptive information about the first data, which is stored in the trusted device; The first data is data obtained by the trusted device from a trusted data source; The trusted data source is the data provider of the first data.

3. The method as described in claim 1, wherein the trusted device is a pluggable device, the pluggable device is deployed with a trusted execution environment, and the trusted execution environment is isolated from the operating system layer.

4. The method as described in claim 3, wherein the pluggable device is a USB flash drive.

5. The method of claim 3, wherein the trusted device obtains the first data from the terminal of the data owner based on the trusted execution environment.

6. The method of claim 5, wherein the trusted device obtains the first data from the terminal of the data owner based on the trusted execution environment, specifically including: The trusted device obtains the first data from the terminal of the data owner through a predefined interface in the code of the trusted execution environment.

7. The method of claim 1, further comprising, after sending the first data to the data requester: Obtain a second confirmation message from the data requester, the second confirmation message indicating that the data requester has received the first data; The first data is deleted from the trusted device.

8. The method of claim 1, further comprising, after sending the first data to the data requester: Obtain third confirmation information from the data requester, the third confirmation information indicating that the data requester has received the first data; The first data and the correspondence between the data requesters are stored in the blockchain network; Update the usage record of the first data.

9. The method of claim 8, further comprising: The correspondence between the first data and the data requester is sent to the trusted device for storage; The usage record of the first data is sent to the trusted device for storage.

10. The method of claim 2, further comprising, before publishing descriptive information for the first data; The first data received from the data owner; The first data is processed using a security application to obtain descriptive information about the first data.

11. The method of claim 10, wherein the description information is generated by processing with a security application in the trusted device.

12. The method according to claim 1, wherein sending the first data to the data requester specifically includes: The first data is sent to the data requester using a secure application, which is a program selected by the data owner.

13. The method of claim 1, further comprising, before obtaining the first data from the trusted device: Determine whether the first resource from the data requester has been received, and obtain a first judgment result; Obtaining the first data from the trusted device specifically includes: If the first determination result is yes, the first data is obtained from the trusted device.

14. The method of claim 13, further comprising: Determine whether the fourth confirmation message from the data requester has been received, and obtain a second determination result, wherein the fourth confirmation message indicates that the data requester has received the first data; If the second determination result is yes, the first resource is forwarded to the data owner.

15. The method of claim 1, wherein the first resource is a data resource or a monetary resource.

16. The method of claim 1, further comprising, before obtaining the first data from the trusted device: Send the private key of the data owner to the data requester; Sending the first data to the data requester specifically includes: The first data is encrypted using the public key of the data owner; The encrypted first data is sent to the data requester.

17. The method of claim 1, wherein sending the first data to the data requester specifically includes: The first data is encrypted using the public key of the data requester; The encrypted first data is sent to the data requester.

18. A data acquisition method based on a trusted device, comprising: The data requester's needs regarding the first data; The data owner obtains data provision information in response to the requested information, the data provision information being used to prompt the data requester to provide a first resource to read the first data; The first data is stored in a trusted device; The trusted device is a pluggable device, and the pluggable device is deployed with a trusted execution environment; the first data is personal privacy data; the trusted device is the device of the data owner of the first data; the first data is data obtained by the trusted device from a trusted data source through a predefined interface in the code of the trusted execution environment; The trusted data source is the data provider; The data provision information is sent to the data requester. Obtain the first confirmation information from the data requester; Based on the first confirmation information, the first data is obtained from the trusted device; The first data is sent to the data requester via a secure application.

19. The method of claim 18, wherein the trusted execution environment is isolated from the operating system layer.

20. The method of claim 18, wherein the pluggable device is a USB flash drive.

21. The method of claim 18, wherein the trusted device obtains the first data from the terminal of the data owner based on the trusted execution environment.

22. The method of claim 20, wherein the trusted device obtains the first data from the terminal of the data owner based on the trusted execution environment, specifically including: The trusted device obtains the first data from the terminal of the data owner through a predefined interface in the code of the trusted execution environment.

23. The method of claim 18, further comprising, after sending the first data to the data requester: Obtain a second confirmation message from the data requester, the second confirmation message indicating that the data requester has received the first data; The first data is deleted from the trusted device.

24. The method of claim 18, further comprising, after sending the first data to the data requester: Obtain third confirmation information from the data requester, the third confirmation information indicating that the data requester has received the first data; The first data and the correspondence between the data requesters are stored in the blockchain network; Update the usage record of the first data.

25. The method of claim 24, further comprising: The correspondence between the first data and the data requester is sent to the trusted device for storage; The usage record of the first data is sent to the trusted device for storage.

26. The method according to claim 18, wherein sending the first data to the data requester specifically includes: The first data is sent to the data requester using a secure application, which is a program selected by the data owner.

27. The method of claim 18, wherein the first resource is a data resource or a monetary resource.

28. The method of claim 18, further comprising, before obtaining the first data from the trusted device: Send the private key of the data owner to the data requester; Sending the first data to the data requester specifically includes: The first data is encrypted using the public key of the data owner; The encrypted first data is sent to the data requester.

29. A data acquisition apparatus based on a trusted device, comprising: The data acquisition request acquisition module is used to acquire a data acquisition request for the first data issued by the data requester, wherein the data acquisition request is used to request to read the first data based on the first resource. A data acquisition request sending module is used to send the data acquisition request to the data owner of the first data; The first confirmation information acquisition module is used to acquire the first confirmation information of the data owner. A first data acquisition module is configured to acquire the first data from a trusted device based on the first confirmation information. The trusted device is a pluggable device; the trusted device is the device of the data owner of the first data; the trusted device is a hardware device with a trusted execution environment for storing the first data; the trusted device acquires the first data from a trusted data source through a predefined interface in the code of the trusted execution environment. The first data sending module is used to send the first data to the data requester through a secure application.

30. The apparatus of claim 29, further comprising: The description information publishing module is used to publish description information for the first data, which is stored in the trusted device; The first data is data obtained by the trusted device from a trusted data source; The trusted data source is the data provider of the first data.

31. The apparatus of claim 29, wherein the trusted device is a pluggable device, the pluggable device is deployed with a trusted execution environment, and the trusted execution environment is isolated from the operating system layer.

32. The apparatus of claim 31, wherein the pluggable device is a USB flash drive.

33. The apparatus of claim 29, wherein the trusted device acquires the first data from the terminal of the data owner based on the trusted execution environment.

34. The apparatus of claim 33, wherein the trusted device acquires the first data from the terminal of the data owner based on the trusted execution environment, specifically comprising: The trusted device obtains the first data from the terminal of the data owner through a predefined interface in the code of the trusted execution environment.

35. The apparatus of claim 29, further comprising: The second confirmation information acquisition module is used to acquire the second confirmation information of the data requester, which indicates that the data requester has received the first data. The first data deletion module is used to delete the first data from the trusted device.

36. The apparatus of claim 29, further comprising: The third confirmation information acquisition module is used to acquire the third confirmation information of the data requester, which indicates that the data requester has received the first data. A correspondence storage module is used to store the correspondence between the first data and the data requester in the blockchain network; The usage record update module is used to update the usage record of the first data.

37. The apparatus of claim 36, further comprising: The correspondence sending module is used to send the correspondence between the first data and the data requester to the trusted device for storage; The record sending module is used to send the usage record of the first data to the trusted device for storage.

38. The apparatus of claim 29, further comprising: The first data receiving module is used to receive the first data from the data owner. The first data processing module is used to process the first data using a security application to obtain descriptive information of the first data.

39. The apparatus according to claim 29, wherein the first data sending module is specifically configured to send the first data to the data requester using a secure application, wherein the secure application is a program selected by the data owner.

40. The apparatus of claim 29, further comprising: The first judgment module is used to determine whether the first resource from the data requester has been received, and to obtain a first judgment result. The first data acquisition module is specifically used to acquire the first data from the trusted device when the first determination result is yes.

41. The apparatus of claim 40, further comprising: The second judgment module is used to determine whether the fourth confirmation information of the data requester has been received, and to obtain a second judgment result. The fourth confirmation information indicates that the data requester has received the first data. The first resource forwarding module is used to forward the first resource to the data owner when the second judgment result is yes.

42. The apparatus of claim 29, wherein the first resource is a data resource or a monetary resource.

43. The apparatus of claim 29, further comprising: The private key sending module is used to send the private key of the data owner to the data requester; The first data sending module specifically includes: The first encryption unit is used to encrypt the first data using the public key of the data owner; The first sending unit is used to send the encrypted first data to the data requester.

44. The apparatus of claim 29, wherein the first data transmission module specifically comprises: The second encryption unit is used to encrypt the first data using the public key of the data requester; The second sending unit is used to send the encrypted first data to the data requester.

45. A data acquisition apparatus based on a trusted device, comprising: The demand information publishing module is used to publish the demand information of data demanders for the first data. A data provision information acquisition module is used to acquire data provision information from the data owner in response to the requested information. The data provision information is used to prompt the data requester to provide a first resource to read the first data. The first data is stored in a trusted device. The trusted device is a pluggable device, and the pluggable device is deployed with a trusted execution environment; the first data is personal privacy data; the trusted device is the device of the data owner of the first data; the first data is data obtained by the trusted device from a trusted data source through a predefined interface in the code of the trusted execution environment; the trusted data source is a data provider; A data provision information sending module is used to send the data provision information to the data requester; The first confirmation information acquisition module is used to acquire the first confirmation information of the data requester. The first data acquisition module is used to acquire the first data from the trusted device based on the first confirmation information; The first data sending module is used to send the first data to the data requester through a secure application.

46. ​​The apparatus of claim 45, wherein the trusted execution environment is isolated from the operating system layer.

47. The apparatus of claim 46, wherein the pluggable device is a USB flash drive.

48. The apparatus of claim 46, wherein the trusted device acquires the first data from the terminal of the data owner based on the trusted execution environment.

49. The apparatus of claim 48, wherein the trusted device acquires the first data from the terminal of the data owner based on the trusted execution environment, specifically comprising: The trusted device obtains the first data from the terminal of the data owner through a predefined interface in the code of the trusted execution environment.

50. The apparatus of claim 45, further comprising: The second confirmation information acquisition module is used to acquire the second confirmation information of the data requester, which indicates that the data requester has received the first data. The first data deletion module is used to delete the first data from the trusted device.

51. The apparatus of claim 45, further comprising: The third confirmation information acquisition module is used to acquire the third confirmation information of the data requester, which indicates that the data requester has received the first data. A correspondence storage module is used to store the correspondence between the first data and the data requester in the blockchain network; The usage record update module is used to update the usage record of the first data.

52. The apparatus of claim 51, further comprising: The correspondence sending module is used to send the correspondence between the first data and the data requester to the trusted device for storage; The record sending module is used to send the usage record of the first data to the trusted device for storage.

53. The apparatus according to claim 45, wherein the first data sending module is specifically configured to send the first data to the data requester using a secure application, wherein the secure application is a program selected by the data owner.

54. The apparatus of claim 45, wherein the first resource is a data resource or a monetary resource.

55. The apparatus of claim 45, wherein before obtaining the first data from the trusted device, the apparatus further comprises: The private key sending module is used to send the private key of the data owner to the data requester; The first data sending module specifically includes: The first encryption unit is used to encrypt the first data using the public key of the data owner; The first sending unit is used to send the encrypted first data to the data requester.

56. A data acquisition device based on a trusted device, comprising: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to: A data acquisition request issued by a data requester for first data, wherein the data acquisition request is used to request to read the first data based on a first resource; The data acquisition request is sent to the data owner of the first data; Obtain the first confirmation information from the data owner; Based on the first confirmation information, the first data is obtained from a trusted device, wherein the trusted device is a pluggable device; the trusted device is the device of the data owner of the first data; the trusted device is a hardware device with a trusted execution environment for storing the first data; the trusted device obtains the first data from a trusted data source through a predefined interface in the code of the trusted execution environment. The first data is sent to the data requester via a secure application.

57. A data acquisition device based on a trusted device, comprising: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to: The data requester's needs regarding the first data; The system obtains data provision information from the data owner regarding the requested information. This data provision information prompts the data requester to provide a first resource to read the first data. The first data is stored in a trusted device. The trusted device is a pluggable device deployed with a trusted execution environment. The first data is personal privacy data. The trusted device is the device of the data owner of the first data. The first data is data obtained by the trusted device from a trusted data source through a predefined interface in the code of the trusted execution environment. The trusted data source is the data provider. The data provision information is sent to the data requester. Obtain the first confirmation information from the data requester; Based on the first confirmation information, the first data is obtained from the trusted device; The first data is sent to the data requester via a secure application.

58. A computer-readable medium having stored thereon computer-readable instructions that can be executed by a processor to implement the data acquisition method based on a trusted device according to any one of claims 1 to 28.

Citation Information

Patent Citations

  • Digital works issuing method based on block chain smart contract

    CN107622385A

  • Internet of Things data privacy protection method based on block chain and trusted hardware

    CN110086804A

  • Blockchain-based data authorization method and device

    CN110457875A