Privacy protection verification of user data
By employing a data aggregation and verification mechanism between user devices and external servers, concerns about privacy leaks and tampering in user data verification are addressed, achieving privacy protection and validity verification of user data.
Patent Information
- Application Number
- CN202180019994.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-03-17
- Filing Date
- 2021-03-04
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2041-03-04
AI Technical Summary
Existing technologies fail to effectively protect the privacy of user data, especially when verifying the validity of user data, which may lead to the leakage of sensitive information, and concerns of external entities about the tampering of user data remain unresolved.
By receiving user data from a tamper-proof second user device at the first user device, aggregating it according to the first logic, and sending the aggregated user data and user data to an external server for verification, the external server verifies whether the aggregated user data corresponds to the predefined second logic, thereby ensuring the privacy protection of user data.
This approach protects user privacy when verifying the validity of user data. External entities can only access the digital signature and verification results, while the user data itself is not disclosed, thus ensuring the security and privacy of user data.
Smart Images

Figure CN115244895B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present disclosure relate to a method, a first user device, a second user device and a data processing system for privacy preserving verification of user data. BACKGROUND
[0002] A customer or user can interact with an external entity through a smart contract specifying various conditions, services and / or interactions between the participating entities, e.g. the user and the external entity.
[0003] Some smart contracts can rely on user data. Such smart contracts can further provide verification of the validity of the user data to ensure that the user data has not been tampered by the user. In order to verify the validity of the user data, the user can need to disclose the user data to the external entity. As the user data can contain sensitive personal information, the privacy of the user can be infringed by disclosing the user data to the external entity.
[0004] Furthermore, the external entity can be concerned that the user data has been tampered.
[0005] A first document (US 2008 / 0147502 Al) proposes a concept for receiving or sending verification that a user has performed a sports training prescribed by an abnormal schedule.
[0006] However, the first document does not disclose a suitable concept for protecting the privacy of the user. The concept can require verification based on clear text user data indicating the sports training.
[0007] A second document (WO 2019 / 032643 Al) discloses a concept for processing performance-based healthcare payments. The concept provides receiving, by a processor, patient health data from a computing device, determining, by the processor, that the patient health data satisfies a condition of a contract term, and automatically executing, by the processor, the contract in response to determining that the patient health data satisfies the condition. This can require evaluating the patient health data in a deciphered form. Thus, the second document can not provide a concept for protecting the privacy of the patient / user.
[0008] A third document (US 2016 / 0142380 Al) proposes a concept for providing user privacy and security using dynamically generated tokens to anonymize the identity and actions of a user during the user’s activities, exchanges or communications on a computer network.
[0009] However, the concept proposed by the third document does not provide a solution to overcome the concerns of the external entity that the user data has been tampered.
[0010] A fourth document (US 10 176 529 B2) discloses an activity assessment system. The assessment system comprises an electronic assessment module configured to determine an activity safety level of a worker from activity data of the worker. Further, the activity assessment system comprises a communication module for providing the activity data and / or the activity safety level to a computer system operated by a second entity for adjusting parameters related to risks.
[0011] The fourth document can not provide a concept for protecting the privacy of a user.
[0012] A fifth document (US 2018 / 0082041 Al) proposes a concept for tracking and reporting health data of a cardholder associated with a payment card. The fitness payment card has a fitness tracking component and the ability to report health data to a payment network.
[0013] The concept proposed by the fifth document can not be suitable for protecting the privacy of a user / cardholder.
[0014] Therefore, there can be a need to provide a concept for privacy protection verification of user data. SUMMARY
[0015] This need can be met by a method according to the independent claims. Advantageous embodiments are addressed by the dependent claims.
[0016] According to a first aspect, the disclosure relates to a method. The method comprises receiving, at a first user device, user data from a second user device which is tamper-proof. Further, the method comprises aggregating, at the first user device, the user data according to a first logic and sending the aggregated user data and the user data to an external server. The method further comprises verifying, at the external server, whether the first logic which relates the aggregated user data and the user data to each other corresponds to a second logic which is predefined for verifying a validity of the aggregated user data.
[0017] The first user device is, for example, a personal computer (PC) or a mobile phone. Alternatively, the first user device can be any other programmable hardware. The first user device can be coupled with the second user device via a data link such as a Bluetooth, a near field communication (NFC) interface or a network path to obtain the user data.
[0018] The user data can comprise, for example, one or more records such as activity data (e.g. distance traveled and / or steps), health data (e.g. heart rate and / or blood pressure) or personal information (e.g. age). Further, the user data can comprise single or multiple records, for example, each record indicating daily steps for consecutive days.
[0019] The second user device is, for example, an activity tracker or a mobile device comprising a heart rate sensor, a blood pressure sensor, a global positioning system (GPS) sensor, a step counter and / or data processing circuitry to obtain user data by monitoring the user.
[0020] For example, the user data can be signed using a private key of the second user device. Thus, the second user device can be identified as the source of the user data.
[0021] The second user device is tamper-proof such that the user or a third party cannot manipulate the user data. Thus, the user can not be able to increase the number of steps included in the user data or fake activity, e.g. to generate activity data in an “illegal way”.
[0022] The first logic and / or the second logic can specify rules and / or arithmetic operations for aggregating the user data. For example, the first logic provides a sequential record of accumulating the user data, e.g. daily steps.
[0023] By comparing the user data with the aggregated user data, the external server can determine whether the aggregation of the digitally signed data according to the first logic is reconcilable with the second logic.
[0024] The second logic can be defined by an external entity. For example, the second logic can be defined in connection with a smart contract between the user and the external entity.
[0025] The external server can be configured to connect to the first user device via a network path or via the internet to transmit the aggregated user data and the user data.
[0026] Further, the external server can be operated by a trusted third party such that the external entity cannot access the user data. The external entity can (only) access the digital signature and / or the verification result of the aggregated user data. In some embodiments, the external entity cannot access the aggregated user data, too.
[0027] Thus, the privacy of the user can be maintained for the external entity. Further, the method can create a confidence of the external entity in the validity of the digitally signed and / or aggregated user data.
[0028] According to a second aspect, the disclosure relates to a first user device. The first user device is configured to receive user data from a tamper-proof second user device and to aggregate the user data according to a first logic. Further, the first user device is configured to transmit the aggregated user data and the user data to an external server to verify whether the first logic relating the aggregated user data and the user data to each other corresponds to a pre-defined second logic for verifying the validity of the aggregated user data.
[0029] According to a third aspect, the disclosure relates to an external server configured to receive user data and aggregated user data from a first user device. The user data is obtained from a tamper-proof second user device. Further, the external server is configured to verify whether a first logic relating the aggregated user data and the user data to each other corresponds to a pre-defined second logic for verifying validity of the aggregated user data.
[0030] For example, the first user device and the external server can be configured as described in connection with the aforementioned method.
[0031] According to a fourth aspect, the disclosure relates to a data processing system comprising an external server and a first user device. The first user device is configured to receive user data from a tamper-proof second user device and to determine aggregated user data from the user data. Further, the first user device is configured to send the aggregated user data and the user data to the external server. The external server is configured to verify whether a first logic relating the aggregated user data and the user data to each other corresponds to a pre-defined second logic for verifying validity of the aggregated user data.
[0032] For example, the aforementioned method can be performed using the data processing system.
[0033] According to a fifth aspect, the disclosure relates to a computer program comprising instructions which, when executed by at least one processor, cause the processor to perform the aforementioned method. BRIEF DESCRIPTION OF DRAWINGS
[0034] Some examples of devices and / or methods will hereinafter be described by way of example only, and with reference to the drawings, in which
[0035] Figure 1 A block diagram schematically illustrating a method for privacy preserving verification of user data is shown;
[0036] Figure 2 A first example of a data sharing system is shown;
[0037] Figure 3a Transmission of user data and digitally signed encrypted user data is shown;
[0038] Figure 3b Verification of aggregated user data is shown;
[0039] Figure 4 A block diagram schematically illustrating an example of a method for privacy preserving verification of user data is shown; and
[0040] Figure 5 A second example of a data sharing system is shown. DETAILED DESCRIPTION
[0041] Various examples will now be described, by way of example only, with reference to the accompanying drawings, in which various examples are shown. In the drawings, the thickness of lines, layers and / or regions can be exaggerated for clarity.
[0042] Accordingly, although the further examples are capable of various modifications and alternative forms, some particular examples thereof are shown in the drawings and will subsequently be described in detail. However, this detailed description does not limit the further examples to the particular form disclosed. Instead, the further examples cover all modifications, equivalents, and alternatives falling within the scope of the disclosure. Like or similar elements are denoted by like or similar reference numbers throughout the several figures, which can be implemented identically or in modified form, when compared to each other, while providing the same or similar functionality.
[0043] It will be understood that when an element is referred to as being “connected” or “coupled” to another element, it can be directly connected or coupled or connected or coupled via one or more intervening elements. If two elements A and B are used in “or” combinations, this will be understood as disclosing all combinations that include at least one of A or B, unless otherwise explicitly stated or otherwise evident from context. An alternative wording of the same combinations is “at least one of A or B” or “at least one of A and B”. Similar alternatives can exist for yet other elements.
[0044] The terminology used herein for the purpose of describing particular examples is not intended to be limiting for further examples. Whenever a singular form such as “a”, “an” and “the” is used, this is only intended to mean a single unit, unless otherwise explicitly stated or otherwise evident from context. Further examples can be implemented using a plurality of the same or like elements. Likewise, whenever a combination is disclosed, including combinations of elements, features, integers or steps, this is intended to mean any combination of one, more or all, particularly recommended or preferred combinations, unless otherwise explicitly stated or otherwise evident from context.
[0045] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this example belongs.
[0046] To verify the validity of the user data, for example in relation to a smart contract, the user can need to disclose the user data to an external entity participating in the smart contract. As the user data can contain sensitive personal information, the disclosure of the user data to the external entity can infringe the privacy of the user.
[0047] Furthermore, the external entity can be concerned that the user data has been tampered with.
[0048] Thus, there can be a need to provide a concept of privacy protection verification of user data.
[0049] Figure 1 A method 100 for privacy protection verification of user data is schematically illustrated.
[0050] The method comprises receiving 110, at a first user device, user data from a tamper-proof second user device and aggregating 120 the user data according to a first logic. Further, the method 100 comprises transmitting 130 the aggregated user data and the user data to an external server.
[0051] Further, the method 100 provides for verifying 140 whether the first logic relating the aggregated user data and the user data to each other corresponds to a pre-defined second logic for verifying the validity of the aggregated user data at the external server.
[0052] As Figure 2 illustrated, the external server can be implemented as a cloud storage 220 of a data processing system 200.
[0053] The data processing system 200 further comprises a mobile phone 210 of a user 240 as the first user device.
[0054] The mobile phone 210 can communicate with a second user device 230 to transmit the user data. In the illustrated example, the second user device 230 corresponds to an activity tracker.
[0055] As Figure 2 illustrated, the activity tracker 230 is designed as a wristband, for example.
[0056] As Figure 3a illustrated, the user data 310 can comprise a first group 312-1 and at least one second group 312-2 of user data 310. For example, the first group 312-1 and the second group 312-1 of user data 310 each represent a daily record. In some embodiments of the present disclosure, each of the first group 312-1 and the second group 312-2 of user data 310 can comprise a plurality of records.
[0057] The activity tracker 230 can communicate the digitally signed encrypted user data 320 to the mobile phone 210 of the user 240. To this end, the activity tracker 230 can encrypt and sign the user data 310. The activity tracker 230 homomorphically encrypts the daily records, for example, with a public key of the mobile phone 210.
[0058] The user data 310 or the encrypted user data can be signed with a private (signature) key of the activity tracker 230 to obtain the digitally signed encrypted user data 320.
[0059] The private (signature key) can be (physically) embedded by its manufacturer into the hardware of the activity tracker 230. Thus, the digitally signed encrypted user data 320 can guarantee their authenticity.
[0060] As shown in Figure 3b The mobile phone 210 can recover the user data 310 by decrypting the digitally signed encrypted user data 320 using the private key of the mobile phone 210.
[0061] Thus, the mobile phone 210 can aggregate the user data 310 according to a first logical aggregation (plaintext) to generate the aggregated user data 330-1 in order to compare it with a predefined second logic, as explained in more detail later.
[0062] For example, the predefined second logic prescribes to accumulate the first set 312-1 of user data 310 and at least a second set 312-2 of user data 310 to generate the aggregated user data 330-1.
[0063] Moreover, the first set 312-1 of user data 310 can indicate a first time period, while the second set 312-2 of user data 310 can indicate a second time period.
[0064] For example, the first and second sets 312-1, 312-2 of user data 310 indicate daily steps.
[0065] As shown in Figure 2 and Figure 3b The mobile phone 210 sends the digitally signed encrypted user data 320 and the aggregated user data 330-1 to the cloud storage 220, as indicated by the arrows in
[0066] For verification, the cloud storage 220 determines a first encrypted aggregated user data 330-3 by aggregating the digitally signed encrypted user data 320 received from the mobile phone 210 according to the predefined second logic.
[0067] Moreover, the cloud storage 220 determines a second encrypted aggregated user data 330-2 by homomorphically encrypting the aggregated user data 330-1 received from the mobile phone 210.
[0068] Thus, the cloud storage can verify the validity of the aggregated user data 330-1 data by checking the correspondence of the first and second encrypted aggregated user data 330-3, 330-2.
[0069] Due to the homomorphic encryption of the first and second encrypted aggregated user data 330-3, 330-2, they can correspond if they stem from the same user data 310 and if the first logic corresponds to the second logic. Moreover, the correspondence of the first and second encrypted aggregated user data 330-3, 330-2 can indicate that the signature of the user data 310 matches the private key of the activity tracker 230.
[0070] This can enable the external entity 250 to obtain certainty about the validity of the aggregated user data 330-1. At the same time, the user 240 does not need to disclose individual records of the user data 310 to the external entity 250 to verify the aggregated user data 330-1. Moreover, the records of the user data 310 are not publicly visible at any time.
[0071] The external entity 250 is, for example, a private person or a company.
[0072] Subsequently, the external entity 250 can access the (plaintext) aggregated user data 330-1 and the verification result to check the validity of the aggregated user data 330-1.
[0073] This concept described in connection with the preceding embodiments can further enable a non-interactive but privacy-preserving way for verifying the aggregated user data 330-1.
[0074] To prevent pre-computation attacks affecting the digitally signed encrypted user data 320, the encryption of the user data 310 can provide for adding some random noise to the records of the user data 310. The random noise can be of a magnitude lower than the values of the records 312-1 and 312-2 of the user data 310 such that the random noise has no effect on the first and second encrypted aggregated user data 330-3, 330-2 extracted from the digitally signed encrypted user data 320.
[0075] Thus, the digitally signed encrypted user data 320 cannot be pre-computed, while the aggregated user data 330-1 can not be affected by the random noise.
[0076] The preceding method can comprise a smart contract 260 between the user 240 and the external entity 250.
[0077] Relying on the validity of the aggregated user data 330-1, the method 100 can further comprise triggering an interaction between the user 240 and the external entity 250 according to the smart contract 260, like Figure 2 as shown.
[0078] The interaction, for example, means a refund and / or a discount of the user 240 on a product of the external entity 250.
[0079] For reasons of transparency and security, the cloud storage 220, which executes the verification and / or stores / manages the smart contract 260, can be implemented as a blockchain (system).
[0080] As shown in Figure 4 and Figure 5 The method 100 can further comprise providing the user data 310 and the aggregated user data 330-1 to a zero-knowledge proof (ZKP) proof function (as input) for generating a cryptographic proof 510, which represents whether the aggregated user data 330-1 is computed based on the user data 310 according to the second logic without containing or revealing the user data 310 and the aggregated user data 330-1. This is performed, for example, by the mobile phone 210 using the proof function described above for generating the cryptographic proof 510 running a (suitable) proof program or “ZKP prover”.
[0081] In other words, the user, for example, runs a “ZKP prover” program, which takes the user data 310 and the aggregated user data 330-1 as input to generate the cryptographic proof 510. For example, the cryptographic proof 510 is a zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK), which does not explicitly contain the user data 310 and / or the aggregated user data 330-1.
[0082] Furthermore, the mobile phone 210 can send the aggregated user data 330-1 and the cryptographic proof 510 to an external entity. Thus, for example, the mobile phone 210 does not send the user data 310 itself.
[0083] The cryptographic proof 510 allows to verify that the aggregated user data 330-1 is generated based on the second logic, for example, which provides the accumulated user data 310.
[0084] Thus, the cryptographic proof 510 can be understood as a proof of (agreed) computation.
[0085] Furthermore, the method 100 can comprise obtaining 160 a binary value from the cryptographic proof 510 using a ZKP verification function related to the ZKP proof function. In this context, the ZKP verification function can be understood as being “related to the ZKP proof function” such that the ZKP verification function is configured or specialized for verifying cryptographic proofs generated by the ZKP proof function.
[0086] The binary value indicates whether the aggregated first logic representing the user data 310 corresponds to the pre-defined second logic. Thus, the binary value represents a validity of the aggregated user data 330-1.
[0087] For example, the external entity 250 runs a “ZKP verifier” program that takes the cryptographic proof 510 and the aggregated user data 330-1 as input for verifying whether the aggregated user data 330-1 results from the aggregation of the user data 310 according to a pre-defined second logic.
[0088] In cryptography, a first party (prover) can use a zero-knowledge proof to convince another party (verifier) that they know a value x without revealing anything other than the fact that they know the value x.
[0089] Depending on the one of the multiple concepts (e.g. discrete logarithm based on values, Hamiltonian cycles of graphs, (non-)interactive zero-knowledge proofs) used for generating the cryptographic proof 510, various mathematical operations can be applied to the user data 310 and the aggregated user data 330-1 which can be understood as inputs to the ZKP proof function.
[0090] As can be seen in Figure 5 The mobile phone 210 can transmit the cryptographic proof 510 to the blockchain 220.
[0091] For example, the blockchain 220 is configured to obtain a binary value from the cryptographic proof 510 and the aggregated user data 330-1 using a ZKP verification function. For example, the binary value is a Boolean value.
[0092] Depending on its status (e.g. “correct” or “incorrect”), the Boolean value indicates whether the first logic corresponds to the pre-defined second logic (“correct”) or not (“incorrect”). Thus, the Boolean value can implicitly indicate the validity of the aggregated user data.
[0093] Subsequently, for example, the mobile phone 210 can send the aggregated user data 330-1 to the external entity 250, directly or via the blockchain 220, in order to trigger an interaction defined by the smart contract 260.
[0094] As with the aforementioned embodiments of the method 100, this concept in connection with the cryptographic proof 510 can enable a non-interactive, privacy-preserving verification of the aggregated user data 330-1, as the amount of information exposed to the external server can be reduced compared to known concepts.
[0095] The skilled person, having the benefit of the present disclosure, will recognize that the above concept of using a cryptographic proof 510 for verifying the validity of the aggregated user data 330-1 can be applied to the various use cases described in the present disclosure.
[0096] The aspects and features mentioned and described with regard to one of the examples and Figure 1 The aspects and features mentioned and described with regard to one of the examples and
[0097] Examples can also be or relate to a computer program encoding a program of instructions for executing on a computer or processor to cause the above-described methods to be implemented. Various steps, operations or processes of the above-described methods can be performed by programmed computers or processors. Examples can also include electronic storage devices, such as digital data storage media, which are machine-, processor- or computer-readable and encode machine- executable, processor-executable or computer-executable programs of instructions. The described instructions, when executed, perform or cause the performance of some or all of the acts detailed above. The program storage devices can be, or be included in, for example, digital memories, magnetic storage media such as magnetic disks and magnetic tapes, hard disk drives or optically readable digital data storage media. Further examples can also include computers, processors or control units programmed to perform the above-described methods, or (field) programmable logic arrays ((F)PLAs) or (field) programmable gate arrays ((F)PGAs), programmed to perform the above-described methods.
[0098] The description and drawings merely illustrate the principles of the disclosure. Furthermore, all examples recited herein are principally intended expressly to be only for pedagogical purposes to aid the reader in understanding the principles of the disclosure and the concepts contributed by the inventor(s) to furthering the art, and are to be construed as being without limitation to such specifically recited examples and conditions. Thus, the scope of the disclosure should be interpreted without limitation to the
[0099] A function block denoted as "means for performing a certain function" can refer to a circuit configured to perform a certain function. Thus, "means for s.th." can be implemented as "a device configured to or adapted for s.th.", e.g. a device or circuit designed or adapted for the respective task.
[0100] The functions of the various elements shown in the figures, including any functional blocks labeled as "means", "means for providing a signal", "means for generating a signal" etc., can be embodied in
[0101] The following examples relate to further embodiments:
[0102] (1) A method comprising:
[0103] At a first user device:
[0104] receiving user data from a tamper-resistant second user device;
[0105] aggregating the user data according to a first logic;
[0106] sending the aggregated user data and the user data to an external server;
[0107] At the external server:
[0108] verifying whether the first logic that relates the aggregated user data and the user data to each other corresponds to a pre-defined second logic for verifying the validity of the aggregated user data.
[0109] (2) The method according to (1), wherein the method further comprises:
[0110] generating encrypted user data by homomorphically encrypting the user data,
[0111] generating digitally signed encrypted user data by signing the encrypted user data,
[0112] wherein sending the user data comprises sending the digitally signed encrypted user data; and
[0113] wherein verifying whether the first logic corresponds to the pre-defined second logic comprises:
[0114] determining a first encrypted aggregated user data by aggregating the digitally signed encrypted user data received from the first user device according to the pre-defined second logic;
[0115] determining a second encrypted aggregated user data by homomorphically encrypting the aggregated user data received from the first user device; and
[0116] verifying the validity of the aggregated user data by checking the correspondence of the first encrypted aggregated user data and the second encrypted aggregated user data.
[0117] (3) The method according to (1), wherein the method further comprises:
[0118] providing the user data and the aggregated user data to a zero-knowledge proof protocol as a function based on metadata stored on the first user device for sending a cryptographic proof to the external server that the aggregated user data was computed based on the user data; and
[0119] A binary value is obtained from the zero-knowledge proof protocol using the cryptographic proof and the metadata stored on the external server, wherein the binary value indicates whether the first logic corresponds to a pre-defined second logic, to verify the validity of the aggregated user data.
[0120] (4) The method of any one of (1) to (3), wherein the method further comprises storing the aggregated user data in a blockchain implemented on the external server.
[0121] (5) The method of any one of (1) to (4), wherein the method comprises a smart contract between the user and the external entity, and wherein the method further comprises
[0122] triggering an interaction between the user and the external entity according to the smart contract, according to the validity of the aggregated user data.
[0123] (6) The method of any one of (1) to (5), wherein the pre-defined second logic prescribes accumulating the first set of user data and at least a second set of user data.
[0124] (7) The method of any one of (1) to (6), wherein the user data comprises a first set of user data indicative of a first time period and at least a second set of user data indicative of a second time period.
[0125] (8) The method of any one of (1) to (7), wherein the user data refers to steps.
[0126] (9) A first user device configured to:
[0127] receive user data from a tamper-proof second user device;
[0128] aggregate the user data according to a first logic;
[0129] send the aggregated user data and the user data to an external server for verification of whether the first logic that relates the aggregated user data and the user data to each other corresponds to a pre-defined second logic for verifying the validity of the aggregated user data.
[0130] (10) An external server configured to:
[0131] receive user data and aggregated user data from a first user device, wherein the user data is obtained from a tamper-proof second user device; and
[0132] verify whether a first logic that relates the aggregated user data and the user data to each other corresponds to a pre-defined second logic for verifying the validity of the aggregated user data.
[0133] (11) A data processing system comprising:
[0134] an external server; and
[0135] a first user device, the first user device being configured to:
[0136] receive user data from a second user device that is tamper-proof;
[0137] determine aggregated user data from the user data; and
[0138] send the aggregated user data and the user data to an external server, wherein the external server is configured to verify whether a first logic that correlates the aggregated user data and the user data to each other corresponds to a second pre-defined logic for verifying validity of the aggregated user data.
[0139] (12) A computer program comprising instructions which, when executed by at least one processor, cause the processor(s) to carry out the method of (1).
[0140] For example, a block diagram can illustrate a high-level circuit schematic that implements the principles of the disclosure. Similarly, flow diagrams, flow charts, state transition diagrams, pseudocode, and the like can represent various processes, operations, or steps, for example, that can be substantially represented in computer-readable medium and executed by a computer or processor, whether or not such computer or processor is explicitly shown. Methods disclosed in the specification or claims can be implemented by a device having means for performing each of the individual actions of these methods.
[0141] It should be understood that the disclosure of a number of actions, processes, operations, steps, or functions in the specification or claims can not be interpreted as a requirement to perform the acts in a particular order unless explicitly or implicitly stated otherwise, for example, for technical reasons. Thus, the disclosure of a number of acts or functions will not limit these acts or functions to a strict order unless such acts or functions are technically interdependent. Furthermore, in some examples, a single act, function, process, operation, or step can include or can be broken down into multiple sub-acts, sub-functions, sub-processes, sub-operations, or sub-steps. Unless explicitly excluded, these sub-acts can be included in the disclosure of the single act and become part of the disclosure.
[0142] Furthermore, the appended claims are hereby incorporated into the detailed description, where each claim can stand alone as a separate example. While each claim can stand alone as a separate example, it is to be noted that any combination of claims can be used in accordance with the disclosure. Such combinations can be expressly recited as in the specific combination of claims, or it can be understood based on the disclosure that the combination is implicit to achieve the subject matter of each dependent or independent claim. Such combinations are hereby expressly set forth regardless of whether specific combinations are recited otherwise in the detailed description. In addition, it is intended that each of the other independent claims can stand on its own as a separate example, even if the claim does not directly depend on an independent claim.
Claims
1. A method for processing data, the method comprising: At the tamper-proof second user equipment: By applying homomorphic encryption to user data, encrypted user data is generated. By signing the encrypted user data, digitally signed encrypted user data is generated. At the first user equipment: Receive the digitally signed encrypted user data from the tamper-proof second user equipment; User data can be recovered by decrypting the encrypted user data with the digital signature. The user data is aggregated according to the first logic; The aggregated user data and the digitally signed encrypted user data are sent to an external server; At the external server: Verifying whether the first logic that correlates the aggregated user data and the user data with each other corresponds to a predefined second logic for verifying the validity of the aggregated user data, wherein verifying whether the first logic corresponds to the predefined second logic includes: According to the predefined second logic, the first encrypted aggregated user data is determined by aggregating the digitally signed encrypted user data received from the first user equipment; The user data of the second encrypted aggregation is determined by homomorphically encrypting the aggregated user data received from the first user equipment; and The validity of the aggregated user data is verified by checking the correspondence between the user data of the first encrypted aggregate and the user data of the second encrypted aggregate.
2. The method according to claim 1, wherein, The method further includes storing the aggregated user data in a blockchain implemented on the external server.
3. The method according to claim 1, wherein, The method includes a smart contract between a user and an external entity, and the method further includes triggering an interaction between the user and the external entity based on the validity of the aggregated user data according to the smart contract.
4. The method according to claim 1, wherein, The predefined second logic specifies the summation of the first group of user data and at least the second group of user data.
5. The method according to claim 1, wherein, The user data includes a first set of user data indicating a first time period and at least a second set of user data indicating a second time period.
6. The method according to claim 1, wherein, The user data refers to the number of steps taken.
7. A data processing system, comprising: External server; The tamper-proof second user equipment is configured as follows: By applying homomorphic encryption to user data, encrypted user data is generated. By signing the encrypted user data, digitally signed encrypted user data is generated, and A first user equipment, the first user equipment being configured as follows: Receive the digitally signed encrypted user data from the tamper-proof second user equipment; User data can be recovered by decrypting the encrypted user data with the digital signature. The aggregated user data is determined from the user data; as well as The aggregated user data and the digitally signed encrypted user data are sent to the external server, wherein the external server is configured to verify whether a first logic that correlates the aggregated user data and the user data corresponds to a predefined second logic for verifying the validity of the aggregated user data, wherein verifying whether the first logic corresponds to the predefined second logic includes: According to the predefined second logic, the first encrypted aggregated user data is determined by aggregating the digitally signed encrypted user data received from the first user equipment; The user data of the second encrypted aggregation is determined by homomorphically encrypting the aggregated user data received from the first user equipment; and The validity of the aggregated user data is verified by checking the correspondence between the user data of the first encrypted aggregate and the user data of the second encrypted aggregate.
8. A computer-readable storage medium storing a computer program including instructions that, when executed by a processing system according to claim 7, cause the processing system to perform the method of claim 1.
Citation Information
Patent Citations
Workplace activity evaluator
US10176529B2
Self-executing agents for gathering health information between trusted parties
WO2019032643A1
Method, device and system for verifying user health data
US20190189254A1