Data transaction and shared session construction method, system, device and storage medium

By conducting two-way verification between the permission machine and the trading terminal, a data trading session is constructed, which solves the complex problems of security risks and permission management in the data sharing and exchange process, and establishes trust and permission management between the trading terminals.

CN115378649BActive Publication Date: 2025-05-06ZHEJIANG ANCUN CLOUD CHAIN DATA TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210848163.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-19
Publication Date
2025-05-06
Estimated Expiration
2042-07-19

AI Technical Summary

Technical Problem

In the prior art, there are high security risks in the data sharing and exchange process, and the management of access rights is complex, which leads to concerns between the two parties in the data sharing process.

Method used

By conducting two-way verification between the authority machine and the trading terminal participating in the transaction, a trust relationship is established, and a verification token is issued between the trading terminals when the two-way verification is passed, a data trading session is constructed.

Benefits of technology

A trust mechanism between trading terminals that are not trusted by each other has been established. The authority machine can effectively manage the trading rights between trading terminals and reduce the security risks of data sharing and exchange.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115378649B_ABST
    Figure CN115378649B_ABST
Patent Text Reader

Abstract

The present invention relates to a method, system, device and storage medium for establishing a data transaction and a shared session, wherein the method comprises: performing two-way verification between a transaction terminal participating in a data transaction and an authority machine, wherein during the two-way verification process, the authority machine sends a verification token belonging to the transaction terminal on one side of the data interaction to the transaction terminal on the other side; when the two-way verification is passed, the transaction terminals constituting the data interaction mutually send their own verification tokens, and when all transaction terminals determine that the verification tokens belonging to the same transaction terminal received twice are the same, a data transaction session between the transaction terminals participating in the data transaction is established; a trust mechanism can be established between mutually distrustful transaction terminals through the authority machine, and then the authority machine can manage the transaction authority between the transaction terminals.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security and data transmission technology, and in particular to a method, system, device and storage medium for establishing data transaction and shared session. Background Art

[0002] The widespread application of big data is an inevitable trend in social and economic development. As the "socialization of data" takes shape, how to effectively exchange and manage data is also a key challenge currently faced by the government and most companies.

[0003] Since data owners and data acquirers do not trust each other, there are high security risks in the data sharing and exchange process, which leads to great concerns on both sides in the data sharing process. In addition, since the attributes of participants and data transaction rules will affect the rights of data transactions, the management of access rights is complicated. Summary of the invention

[0004] Embodiments of the present invention provide a data transaction and shared session construction method, system, device and storage medium to solve the problem mentioned in the prior art of how to enable computer applications in the real world to be used in the metaverse.

[0005] A first aspect of the present invention provides a method for establishing a data transaction and sharing session, the method comprising:

[0006] Performing two-way verification between the transaction terminal participating in the data transaction and the authority machine, wherein, during the two-way verification process, the authority machine sends a verification token belonging to the other transaction terminal to one of the transaction terminals constituting the data interaction;

[0007] When the two-way verification is passed, the transaction terminals constituting the data interaction mutually issue their own verification tokens, and when all the transaction terminals determine that the verification tokens belonging to the same transaction terminal received twice are the same, a data transaction session between the transaction terminals participating in the data transaction is established;

[0008] The number of the transaction terminals is set to at least two, and each of the transaction terminals is data-connected with at least one other transaction terminal, and the transaction terminal corresponds one-to-one to the verification token belonging to the transaction terminal.

[0009] Optionally, the two-way verification between the transaction terminal participating in the data transaction and the authority machine includes:

[0010] The transaction terminal participating in the data transaction and the authority machine mutually issue verification tokens belonging to themselves;

[0011] When both the transaction terminal and the authority machine verify the received verification token, the two-way authentication between the interactive terminal participating in the data transaction and the authority machine is completed, wherein the authority machine corresponds one-to-one with the verification token belonging to the authority machine.

[0012] Optionally, before the transaction terminal and the authority machine both verify the received verification token, the method further includes:

[0013] The authority machine sends a verification token belonging to the other transaction terminal to one of the transaction terminals constituting the data interaction.

[0014] Optionally, the two-way verification between the transaction terminal participating in the data transaction and the authority machine includes:

[0015] The transaction terminals participating in the data transaction send their respective verification tokens to the authority machine;

[0016] When the verification token belonging to the transaction terminal is successfully verified by the authority machine, the transaction terminal corresponding to the verified verification token is determined to be a trusted terminal to complete the one-way verification;

[0017] The authority machine sends relevant data information to the transaction terminal determined as a trusted terminal; wherein the relevant data information includes: a verification token of the authority machine and a verification token of the other transaction terminal that forms data interaction with the transaction terminal determined as a trusted terminal, wherein the authority machine corresponds to the verification token belonging to the authority machine one by one;

[0018] When the verification token belonging to the authority machine is successfully verified by the transaction terminal determined as a trusted terminal, the authority machine is determined to be a trusted authority machine to complete the two-way authentication between the interactive terminal participating in the data transaction and the authority machine.

[0019] Optionally, the transaction terminal sends a verification token belonging to the transaction terminal to the authority machine, including:

[0020] Any of the transaction terminals sends a data transaction request to the authority machine, wherein the transaction request includes: a verification token belonging to any of the transaction terminals, and terminal attribute information of the other transaction terminal that forms data interaction with any of the transaction terminals;

[0021] Based on the terminal attribute information of the other transaction terminal that forms data interaction with any transaction terminal, the authority machine forwards the data transaction request to the other transaction terminal that forms data interaction with any transaction terminal;

[0022] The verification token belonging to the other transaction terminal that forms data interaction with any one of the transaction terminals is received by the authority machine; wherein the verification token belonging to the other transaction terminal that forms data interaction with any one of the transaction terminals is fed back by the other transaction terminal that forms data interaction with any one of the transaction terminals in response to the data transaction request.

[0023] Optionally, after the transaction terminals constituting the data interaction mutually issue their own verification tokens and before establishing a data transaction session between the transaction terminals participating in the data transaction, the method further includes:

[0024] The transaction terminals constituting data interaction mutually issue verification tokens belonging to the authority machine;

[0025] Comparing whether the verification tokens belonging to the authority machine and the verification tokens belonging to the same transaction terminal received twice by each transaction terminal are the same;

[0026] If so, a data transaction session is established between the transaction terminals participating in the data transaction.

[0027] Optionally, comparing whether the verification tokens belonging to the authority machine and received twice by each of the transaction terminals and the verification tokens belonging to the same transaction terminal are the same includes:

[0028] The transaction terminal binds the verification token belonging to the authority machine and the verification token belonging to the other transaction terminal that performs data interaction with the transaction terminal.

[0029] Compare whether the two binding data belonging to the same trading terminal in each trading terminal are the same;

[0030] If so, a data transaction session is established between the transaction terminals participating in the data transaction.

[0031] Optionally, the data transaction request further includes: attribute information of the data to be traded, and terminal attribute information of any transaction terminal;

[0032] Before establishing the data transaction session between the transaction terminals participating in the data transaction, the method further includes:

[0033] Based on the attribute information of the data to be traded and the terminal attribute information of any transaction terminal, the authority machine generates a transaction decision;

[0034] When the transaction decision is passed, it is determined that the data transaction is valid.

[0035] Optionally, the transaction terminal and the authority machine are both provided with corresponding key pairs, and each of the key pairs includes: a private key and a public key;

[0036] The transaction terminal and the authority machine both encrypt the verification token issued by themselves through their own private keys; moreover, the transaction terminal and the authority machine that receive the verification token both decrypt the verification token through the corresponding public key. If the decryption is successful, it means that the verification token has been verified, wherein the corresponding public key is represented by the public key corresponding to the transaction terminal and / or the authority machine that issued the verification token.

[0037] According to a second aspect of the present invention, a data transaction and shared session establishment system is provided, the system comprising: an authority machine, which forms a data connection with transaction terminals participating in the data transaction, and is used to receive and verify verification tokens uploaded by each transaction terminal participating in the data transaction, and the authority machine also sends its own verification token to the transaction terminals participating in the data transaction; transaction terminals, the number of which is set to at least two and each transaction terminal participates in the data transaction, and each transaction terminal receives and verifies the verification token belonging to the authority machine and sent by the authority machine; and, when the two-way verification between the authority machine and each transaction terminal participating in the data transaction is passed, the transaction terminals that constitute the data interaction issue their own verification tokens to each other, and when all the transaction terminals determine that the verification tokens belonging to the same transaction terminal received twice are the same, a data transaction session between the transaction terminals participating in the data transaction is established.

[0038] According to a third aspect of the present invention, a computer device is provided, comprising: one or more processors; a memory; and one or more applications, wherein the one or more applications are stored in the memory and are configured to be executed by the one or more processors, and the one or more programs are configured to: execute the data transaction and shared session construction method described above.

[0039] A fourth aspect of the present invention provides a computer-readable storage medium, wherein the storage medium stores at least one instruction, at least one program, a code set or an instruction set, and the at least one instruction, the at least one program, the code set or the instruction set are loaded and executed by a processor to implement the data transaction and shared session construction method as described above.

[0040] The beneficial effects of the embodiments of the present invention are as follows: by performing two-way verification between the authority machine and the transaction terminals participating in the transaction, the authority machine and the transaction terminals participating in the transaction can verify each other, thereby establishing trust between the authority machine and each transaction terminal participating in the transaction; then, when the two-way verification is passed, the transaction terminals constituting the data interaction mutually issue their own verification tokens, and in combination with the verification token belonging to the transaction terminal on the other side sent by the authority machine to the transaction terminal on one side of the data interaction, when all the transaction terminals determine that the verification tokens belonging to the same transaction terminal received twice are the same, a data transaction session between the transaction terminals participating in the data transaction is established, thereby, a trust mechanism can be established between mutually distrustful transaction terminals through the authority machine, and then the authority machine can manage the transaction permissions between the transaction terminals. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:

[0042] Figure 1 A schematic diagram of a flow chart of a data transaction and sharing session establishment method according to a first embodiment of the present invention;

[0043] Figure 2 A schematic diagram of the structure of a data transaction and shared session building system involved in the first and third embodiments of the present invention;

[0044] Figure 3 A schematic diagram of the structure of a data transaction and shared session building system according to a second embodiment of the present invention;

[0045] Figure 4 A flowchart of a method for establishing a data transaction and a shared session according to a second embodiment of the present invention;

[0046] Figure 5 It is a schematic diagram of the structure of the authority machine involved in the second embodiment of the present invention. DETAILED DESCRIPTION

[0047] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.

[0048] Figure 1 A schematic diagram of a flow chart of a data transaction and sharing session establishment method according to a first embodiment of the present invention; Figure 2 A schematic diagram of the structure of a data transaction and shared session building system involved in the first and third embodiments of the present invention; Figure 3 A schematic diagram of the structure of a data transaction and shared session building system according to a second embodiment of the present invention; Figure 4 A flowchart of a method for establishing a data transaction and a shared session according to a second embodiment of the present invention; Figure 5 It is a schematic diagram of the structure of the authority machine involved in the second embodiment of the present invention.

[0049] According to a first embodiment of the present invention, a method for establishing a data transaction and a shared session is provided, the method comprising: performing two-way verification between a transaction terminal participating in a data transaction and an authority machine, wherein, during the two-way verification process, the authority machine sends a verification token belonging to the transaction terminal on one side of the data interaction to the transaction terminal on the other side; when the two-way verification is passed, the transaction terminals constituting the data interaction mutually send their own verification tokens, and when all the transaction terminals determine that the verification tokens belonging to the same transaction terminal received twice by themselves are the same, a data transaction session between the transaction terminals participating in the data transaction is established;

[0050] The number of the transaction terminals is set to at least two, and each of the transaction terminals is data-connected with at least one other transaction terminal, and the transaction terminal corresponds one-to-one to the verification token belonging to the transaction terminal.

[0051] In this regard, by performing two-way verification between the authority machine and the transaction terminals participating in the transaction, mutual verification is achieved between the authority machine and the transaction terminals participating in the transaction, and trust is established between the authority machine and each transaction terminal participating in the transaction; then, when the two-way verification is successful, the transaction terminals that constitute the data interaction issue their own verification tokens to each other, and in combination with the verification token belonging to the transaction terminal on the other side sent by the authority machine to the transaction terminal on one side of the data interaction, when all the transaction terminals determine that the verification tokens belonging to the same transaction terminal received twice are the same, a data transaction session is established between the transaction terminals participating in the data transaction. In this way, a trust mechanism can be established between mutually distrustful transaction terminals through the authority machine, and then the authority machine can manage the transaction authority between the transaction terminals.

[0052] Specifically, according to Figure 1 and 2As shown, the first embodiment of the present invention provides a method for establishing a data transaction and a shared session, wherein the method can also be understood as: before establishing a transaction terminal session, the transaction terminal participating in the data transaction is authenticated for authority. In addition, the data transaction and shared session construction method involved in this embodiment is not only applicable to data transmission between transaction terminals, but also to network data sharing or transactions between network terminals, information sharing or transactions between different networks, data sharing and transactions based on big data, and of course, the transmission and transaction of payment information in the electronic payment process. Specifically, the method includes:

[0053] Step S100: performing a two-way verification between the transaction terminal participating in the data transaction and the authority machine, wherein, during the two-way verification process, the authority machine sends a verification token belonging to the other transaction terminal to one of the transaction terminals constituting the data interaction;

[0054] In a typical data transaction scenario, there should be at least one transaction terminal as a data acquirer and one transaction terminal as a data owner. In this article, a two-way verification is first performed between the transaction terminal participating in the data transaction and the authority machine. In this way, the authority machine can be determined as a trustworthy or legal authority machine on the transaction terminal side, and the transaction terminal participating in the data transaction can also be determined as a trustworthy or legal terminal device on the authority machine side.

[0055] It is worth noting that during the two-way verification process, the authority machine sends the verification token belonging to the transaction terminal on the other side to the transaction terminal on one side of the data interaction; of course, in another embodiment, the authority machine may also send the verification token belonging to the transaction terminal on the other side to the transaction terminal on one side of the data interaction after the two-way verification is completed (after executing step S100 but before executing step S120).

[0056] In this embodiment, it involves a data transaction and a shared session construction system, which does not limit the number of the transaction terminals, and the number of the transaction terminals is set to at least two. For example, the number of the transaction terminals is set to two. Of course, in other embodiments, the transaction terminals can also be set to three or more, such as transaction terminal 1, transaction terminal 2, transaction terminal 3 and transaction terminal 4. Of course, there is at least one data acquirer and at least one data owner between the at least two transaction terminals. Therefore, when the number of transaction terminals is two, one of the two transaction terminals is the data owner and the other is the data acquirer; when the number of transaction terminals is three or more, the transaction terminal includes a data owner and a data acquirer, and the role of the remaining transaction terminals is not limited. These remaining transaction terminals play certain tasks and roles in the data transaction process, such as: analyzing, and / or verifying, and / or splitting and reorganizing the data to be traded.

[0057] In addition, in this embodiment, each transaction terminal is data-connected with the authority, such as a network communication connection between the transaction terminal and the authority.

[0058] The above-mentioned authority machine may be a security server, which is used to make an authority judgment on whether transaction terminals participating in data transactions can conduct transactions. The specific details are described in detail below.

[0059] Step S120: When the two-way verification is passed, the transaction terminals constituting the data exchange mutually issue their own verification tokens, and when all the transaction terminals determine that the verification tokens belonging to the same transaction terminal received twice are the same, a data transaction session between the transaction terminals participating in the data transaction is established;

[0060] There is a one-to-one correspondence between the transaction terminal and the verification token belonging to the transaction terminal.

[0061] In the case of two-way verification, the transaction terminals participating in the data transaction send their own verification tokens to each other in the transaction that constitutes data interaction. In addition, in combination with step S100, the authority sends the verification token belonging to the other transaction terminal to one of the transaction terminals constituting the data interaction, so each transaction terminal successively receives the verification token of the same transaction terminal that constitutes data interaction with it, and when all transaction terminals determine that the verification tokens belonging to the same transaction terminal received twice are the same, a data transaction session between the transaction terminals participating in the data transaction is established.

[0062] Specifically, for example, the number of transaction terminals is set to three: data acquirers, data owners, and data processors. In the normal data transaction and sharing process, the data owner has data to be traded and shared. Any of the data acquirers, data owners, and data processors can initiate a data transaction request, so that the data owner sends the data to be traded and shared to the data processor, and the data processor pre-processes the data to be traded and shared (the pre-processing content is not limited in this embodiment) and then sends it to the data acquirer, thereby completing the data transaction and sharing, that is, the data owner only interacts with the data processor, and the data acquirer also only interacts with the data processor, but the data processor interacts with the data acquirer and the data owner respectively. Therefore, in this embodiment, before the transmission of the data to be traded and shared is performed, the above-mentioned steps S100 to S120 need to be executed. Specifically, an authority machine is added on the basis of the data acquirer, the data owner and the data processor. The data acquirer, the data owner and the data processor all form a data connection with the authority machine. Therefore, the data acquirer, the data owner and the data processor all perform two-way verification with the authority machine. It is worth noting that in the two-way verification process, the authority machine sends a verification token belonging to the data processor to the data acquirer, the authority machine sends a verification token belonging to the data processor to the data owner, and the authority machine sends a verification token belonging to the data owner and a verification token belonging to the data acquirer to the data processor; if the two-way verification passes, the data acquirer sends a verification token belonging to the data acquirer to the data processor, and the data processor sends a verification token belonging to the data processor to the data acquirer and the data owner. The data processor sends a verification token belonging to the data owner to the data processor; therefore: the data owner receives two verification tokens belonging to the data processor, the data processor receives two verification tokens belonging to the data owner and two verification tokens belonging to the data acquirer, and the data acquirer receives two verification tokens belonging to the data processor; the data owner compares whether the two received verification tokens belonging to the data processor are the same; the data processor compares whether the two received verification tokens belonging to the data owner are the same, the data processor compares whether the two received verification tokens belonging to the data acquirer are the same, and the data acquirer compares whether the two received verification tokens belonging to the data processor are the same. If the comparison results of the data acquirer, the data processor and the data owner are the same, it can be determined that the authentication of the data acquirer, the data processor and the data owner is passed, that is, a data transaction, i.e. a shared data transaction session, can be established among the data acquirer, the data processor and the data owner.

[0063] For example, the number of transaction terminals is set to two: data acquirers and data owners. In the normal data transaction and sharing process, the data owner has data to be traded and shared. Either the data acquirer or the data owner can initiate a data transaction request. The data owner sends the data to be traded and shared to the data acquirer, thereby completing the data transaction and sharing, that is, the data owner only interacts with the data acquirer. Therefore, in this embodiment, before the data to be traded and shared is transmitted, the above steps S100-S120 need to be performed. Specifically, an authority machine is added on the basis of the data acquirer and the data owner. The data acquirer and the data owner both form a data connection with the authority machine. Therefore, the data acquirer and the data owner both perform two-way verification with the authority machine. It is worth noting that in the two-way verification process, the authority machine sends a verification token belonging to the data owner to the data acquirer, and the authority machine sends a verification token belonging to the data acquirer to the data owner; if the two-way verification is passed, the data acquirer sends a verification token belonging to the data acquirer to the data owner. The data owner sends the verification token belonging to the data owner to the data acquirer; therefore: the data owner receives two verification tokens belonging to the data acquirer, and the data acquirer receives two verification tokens belonging to the data owner; the data owner compares whether the two received verification tokens belonging to the data acquirer are the same; the data acquirer compares whether the two received verification tokens belonging to the data owner are the same. If the comparison results of the data acquirer and the data owner are the same, it can be determined that the authentication of the data acquirer and the data owner is passed, that is, a data transaction, i.e. a shared data transaction session, can be established among the data acquirer and the data owner.

[0064] In another embodiment, regarding the verification token and its verification process involved in this article, the following exemplary settings are made: the above-mentioned transaction terminals and authority machines are equipped with corresponding key pairs, and each of the key pairs includes: a private key and a public key; the public key is publicly published (such as broadcasting) by the transaction terminal and authority machine to which it belongs, and the transaction terminal and the authority machine encrypt the verification token issued by themselves with their own private keys; and the transaction terminal and the authority machine that receive the verification token decrypt the verification token with the corresponding public key. If the decryption is successful, it means that the verification token has been verified, wherein the corresponding public key is represented by the public key corresponding to the transaction terminal and / or the authority machine that issued the verification token.

[0065] That is, the above step S100 specifically includes: performing two-way verification between the transaction terminal participating in the data transaction and the authority machine, wherein, during the two-way verification process, the authority machine sends a token belonging to the other transaction terminal to one of the transaction terminals constituting the data interaction. Since the token is sent by the authority machine, the token is encrypted by the private key corresponding to the authority machine and then sent out by the authority machine. Of course, before performing the verification token comparison in step S120, each transaction terminal needs to use the public key corresponding to the authority machine to decrypt the token received in step S100 to obtain the token to be compared;

[0066] The above-mentioned step S120 specifically includes: when the two-way verification is passed, the transaction terminals that constitute the data interaction send their own tokens to each other, and the tokens sent by each transaction terminal are decrypted by their own private keys. The transaction terminal that receives the token will decrypt the token using the public key corresponding to the transaction terminal that sent the token to obtain the decrypted token. When all the transaction terminals determine that the decrypted tokens belonging to the same transaction terminal received twice are the same, a data transaction session between the transaction terminals participating in the data transaction is established.

[0067] In another embodiment, for the above step S100, one option is:

[0068] Step S101: The transaction terminal participating in the data transaction and the authority machine mutually issue verification tokens belonging to themselves;

[0069] That is, each transaction terminal participating in the data transaction sends its own verification token to the authority machine; and the authority machine also sends its own verification token to each transaction terminal participating in the data transaction. That is, each transaction terminal participating in the data transaction encrypts its own token with its corresponding private key and sends it to the authority machine; and the authority machine also encrypts its own token with its corresponding private key and sends it to each transaction terminal participating in the data transaction.

[0070] Therein, the authority machine corresponds one-to-one to the verification token belonging to the authority machine.

[0071] Step S102: When both the transaction terminal and the authority machine successfully verify the received verification token, a two-way authentication is completed between the interactive terminal participating in the data transaction and the authority machine.

[0072] After receiving the verification token belonging to the authority machine sent by the authority machine, each transaction terminal verifies the received verification token belonging to the authority machine; at the same time, after receiving the verification token belonging to each transaction terminal sent by the authority machine, the authority machine verifies the verification token belonging to each transaction terminal; if each transaction terminal and the authority machine pass the verification of the verification token received by each transaction terminal, it means that the two-way authentication between the interactive terminal participating in the data transaction and the authority machine is completed. That is: as long as any transaction terminal or authority machine fails to verify the received verification token, the two-way authentication fails.

[0073] Of course, before executing the above step S102, step S100 also includes: the authority machine sends the verification token belonging to the other transaction terminal to one of the transaction terminals constituting the data interaction.

[0074] Specifically, for example, the number of transaction terminals is set to two: data acquirers and data owners. Both data acquirers and data owners send their own verification tokens to the authority machine, and the authority machine also sends its own verification tokens to the data acquirers and data owners respectively. That is, both data acquirers and data owners encrypt their own tokens with their corresponding private keys and send them to the authority machine; and the authority machine also encrypts its own tokens with its corresponding private keys and sends them to the data acquirers and data owners.

[0075] After the data acquirer and the data owner receive the token belonging to the authority machine (the token encrypted by the authority machine with its own corresponding private key) sent by the authority machine, the data acquirer and the data owner both decrypt the token (the token encrypted by the authority machine with its own corresponding private key) through the public key corresponding to the authority machine; at the same time, after the authority machine receives the token belonging to the data acquirer (the token encrypted by the data acquirer with its own corresponding private key) sent by the data acquirer, the authority machine decrypts the token belonging to the data acquirer (the token encrypted by the data acquirer with its own corresponding private key); at the same time, after the authority machine receives the token belonging to the data owner (the token encrypted by the data owner) sent by the data owner After the data acquirer and the data owner receive the token encrypted by the corresponding private key of the data owner, the authority machine decrypts the token belonging to the data owner (the token encrypted by the data owner with the corresponding private key); if the data acquirer and the data owner both successfully decrypt the received token belonging to the authority machine (the token encrypted by the authority machine with the corresponding private key of the data owner), and the token belonging to the data owner (the token encrypted by the data owner with the corresponding private key of the data owner) and the token belonging to the data acquirer (the token encrypted by the data acquirer with the corresponding private key of the data acquirer) received by the authority machine are also successfully decrypted, it means that the two-way authentication between the interactive terminal participating in the data transaction and the authority machine is completed. However: as long as the data acquirer, the data owner, or the authority machine fails to successfully decrypt the received token, the two-way authentication fails.

[0076] Moreover, in the two-way verification process, the authority machine sends a token belonging to the transaction terminal on the other side to one of the transaction terminals constituting the data interaction. Since the token is sent by the authority machine, the token is encrypted by the private key corresponding to the authority machine and then sent out by the authority machine. Of course, before comparing the verification tokens in step S120, each transaction terminal needs to use the public key corresponding to the authority machine to decrypt the token received in step S100 to obtain the token to be compared.

[0077] In another embodiment, another option for the above step S100 is:

[0078] Step S111: The transaction terminals participating in the data transaction send their respective verification tokens to the authority machine;

[0079] Step S112: when the verification token belonging to the transaction terminal is successfully verified by the authority machine, the transaction terminal corresponding to the verified verification token is determined to be a trusted terminal to complete the one-way verification;

[0080] Step S113: the authority machine sends relevant data information to the transaction terminal determined as a trusted terminal; wherein the relevant data information includes: a verification token of the authority machine, and a verification token of the other transaction terminal that forms data interaction with the transaction terminal determined as a trusted terminal, wherein the authority machine has a one-to-one correspondence with the verification token belonging to the authority machine;

[0081] Step S114: When the verification token belonging to the authority machine is successfully verified by the transaction terminal determined as a trusted terminal, the authority machine is determined to be a trusted authority machine to complete the two-way authentication between the interactive terminal participating in the data transaction and the authority machine.

[0082] In this regard, through steps S111-S104, not only can the two-way verification between each transaction terminal participating in the data transaction and the authority machine be completed, but also, during the two-way verification process, the authority machine will send the verification token of the other side transaction terminal that constitutes data interaction with the transaction terminal determined as a trusted terminal to the transaction terminal determined after the two-way verification is passed.

[0083] In this solution, the selection of the above steps S101-S102 and steps S111-S104 is not limited. In the above steps S101-S102 and steps S111-S104, the authority machine makes an authority judgment on whether transactions can be conducted between transaction terminals. Therefore, the above steps S101-S102 or steps S111-S104 can be selectively executed according to actual conditions.

[0084] In addition, in another embodiment, when there are two or more transaction terminals participating in the data transaction, before establishing a data transaction session between the transaction terminals, one of the steps is to perform two-way authentication between each transaction terminal participating in the data transaction and the authority machine, and one of the steps of the two-way authentication is: the transaction terminal sends a verification token belonging to the transaction terminal to the authority machine, and the "transaction terminal sends a verification token belonging to the transaction terminal to the authority machine" specifically includes:

[0085] Step S1111: any of the transaction terminals sends a data transaction request to the authority machine, wherein the transaction request includes: a verification token belonging to any of the transaction terminals, and terminal attribute information of the other transaction terminal that forms data interaction with any of the transaction terminals;

[0086] Step S1112: Based on the terminal attribute information of the other transaction terminal that forms data interaction with any transaction terminal, the authority machine forwards the data transaction request to the other transaction terminal that forms data interaction with any transaction terminal;

[0087] Step S1113: The authority machine receives a verification token belonging to the other transaction terminal that forms data interaction with any one of the transaction terminals; wherein the verification token belonging to the other transaction terminal that forms data interaction with any one of the transaction terminals is feedback from the other transaction terminal that forms data interaction with any one of the transaction terminals in response to the data transaction request.

[0088] Therefore, among the transaction terminals participating in the data transaction, any transaction terminal may issue a data transaction request, so that each transaction terminal participating in the data transaction may send a verification token belonging to the transaction terminal to the authority machine.

[0089] In addition, in another embodiment, in the above step S120, after the transaction terminals constituting the data interaction send their own verification tokens to each other, and before all the transaction terminals determine that the verification tokens belonging to the same transaction terminal received twice are the same, the data transaction and sharing session establishment method further includes:

[0090] Step S121: the transaction terminals constituting data interaction mutually issue verification tokens belonging to the authority machine;

[0091] Step S122: Compare whether the verification tokens belonging to the authority machine and the verification tokens belonging to the same transaction terminal received twice by each transaction terminal are the same; if so, execute step S123; otherwise, execute step S124;

[0092] Step S123: Establishing a data transaction session between transaction terminals participating in the data transaction;

[0093] Step S124: Stop the process.

[0094] Therefore, in the present embodiment, after the two-way verification, the transaction terminals constituting the data interaction will also send each other the verification tokens belonging to the authority machine, and then each transaction terminal will receive the verification token belonging to the transaction terminal interacting with it and the verification token belonging to the authority machine during the two-way verification; in step S120 and step S121, each transaction terminal will also receive the verification token belonging to the transaction terminal interacting with it and the verification token belonging to the authority machine; therefore, it is only necessary to compare whether the verification tokens of the transaction terminal interacting with it and the verification tokens belonging to the authority machine received by each transaction terminal in these two times are the same. If they are the same, a data transaction session between the transaction terminals participating in the data transaction is established; otherwise, the process is stopped.

[0095] In addition, in another embodiment, another option of the above step S122 is:

[0096] Step S1221: The transaction terminal binds the verification token belonging to the authority machine and the verification token belonging to the other transaction terminal that performs data interaction with the transaction terminal.

[0097] Step S1222: Compare whether the two binding data belonging to the same transaction terminal in each transaction terminal are the same; if so, execute step S1223; otherwise, execute step S1224;

[0098] Step S1223: Establishing a data transaction session between transaction terminals participating in the data transaction;

[0099] Step S1224: Stop the process.

[0100] Therefore, in this embodiment, after the two-way verification, the transaction terminals that constitute the data interaction will also send verification tokens belonging to the authority machine to each other, and then each transaction terminal will receive the verification token belonging to the transaction terminal interacting with it and the verification token belonging to the authority machine during the two-way verification; in step S120 and step S121, each transaction terminal will also receive the verification token belonging to the transaction terminal interacting with it and the verification token belonging to the authority machine; each transaction terminal will bind the verification token belonging to the transaction terminal interacting with it and the verification token belonging to the authority machine received each time, and then each transaction terminal only needs to compare whether the two binding data belonging to the same transaction terminal it receives are the same. If they are the same, a data transaction session between the transaction terminals participating in the data transaction is established; otherwise, the process is stopped.

[0101] In addition, in another embodiment, the data transaction request further includes: attribute information of the data to be traded, and terminal attribute information of the other transaction terminal that forms data interaction with any of the transaction terminals;

[0102] Therefore, before step S113, or S120, or step S1223, the data transaction and shared session construction method also includes: based on the attribute information of the data to be traded and the terminal attribute information of the other side transaction terminal that constitutes data interaction with any of the transaction terminals, the authority machine generates a transaction decision; when the transaction decision is passed, it is determined that the data transaction is valid.

[0103] In this regard, the validity of the data transaction can be verified.

[0104] Specifically, a typical data transaction includes a data owner and a data acquirer, and the authority machine makes an authority judgment on whether the data transaction can be carried out. The data transaction can be initiated by the owner or the acquirer, and there is no restriction here. The authority machine receives a data transaction request, which includes: attribute information of the data to be traded and terminal attribute information of any of the transaction terminals. Among them, the terminal attribute information includes but is not limited to the region where the any transaction terminal is located, the data transaction history of the any transaction terminal, the credit rating of the any transaction terminal, etc. The attribute information of the data to be traded includes but is not limited to personal identity information (PII), sensitive information, data type, data restricted area, and user level allowed by the data. The authority machine analyzes the attribute information of the data to be traded and the terminal attribute information of any of the transaction terminals according to the rules stored in the rule base to determine whether the transaction can be carried out.

[0105] Specifically, the authority machine includes but is not limited to: a policy execution module, a rule judgment module, a rule base and an attribute acquisition module.

[0106] The strategy execution module is used to accept a data transaction request from any transaction terminal, communicate with the rule judgment module to obtain a transaction decision result, and send a transaction signature to any transaction terminal to establish a transaction session between the transaction terminals;

[0107] The rule judgment module is used to receive the data transaction request (the attribute information of the data to be traded, the terminal attribute information of any transaction terminal, and the terminal attribute information of the other transaction terminal that forms data interaction with any transaction terminal) transmitted by the strategy execution module, collect the applicable strategies and data required for making transaction authority decisions (from the attribute acquisition module and the rule base), formulate the rules and attributes to obtain the logical operation results, and return them to the strategy execution module;

[0108] The rule base stores data transaction compliance requirements and other rule sets that need to be managed. These rules can be combined using logical operations such as and, or, and not.

[0109] The attribute acquisition module collects relevant data about the transaction terminals involved in the data transaction, the data to be traded and the environment and provides it to the rule judgment module.

[0110] according to Figure 3-Figure 5 In a typical data transaction scenario, there are data owners and data acquirers, and the authority machine makes an authority judgment on whether data transactions can be carried out. Data transactions can be initiated by the owner or the acquirer, and there is no restriction here. The authority machine receives a data transaction request, which includes: attribute information of the data to be traded and terminal attribute information of any transaction terminal. Among them, the terminal attribute information includes but is not limited to the region where any transaction terminal is located, the data transaction history of any transaction terminal, the credit level of any transaction terminal, etc. The attribute information of the data to be traded includes but is not limited to personal identity information (PII), sensitive information, data type, data restricted area, and user level allowed by the data. The authority machine analyzes the attribute information of the data to be traded and the terminal attribute information of any transaction terminal according to the rules stored in the rule base to determine whether the transaction can be carried out.

[0111] Therefore, the second embodiment of the present invention provides a data transaction and sharing session construction system, in which a data transaction request can be initiated by a data owner or a data acquirer. Specifically, taking the data acquirer initiating a data transaction request as an example, the acquirer holds key pair 1 (private key 1 and public key 1), the owner holds key pair 2 (private key 2 and public key 2), and the authority holds key pair 3 (private key 3 and public key 3), wherein the private key is used for signature authorization to ensure that only the key generator owns it, and the public key can be publicly released:

[0112] 1. The data acquirer initiates a data transaction request to the authority machine. The data transaction request contains the data owner, attribute information of the data to be traded, and token1 encrypted by private key 1. The authority machine uses public key 1 to decrypt and obtain token1;

[0113] 2. The authority machine forwards the data transaction request to the data owner;

[0114] 3. The data owner returns token2 encrypted by private key 2 to the authority machine, and the authority machine decrypts it using public key 2 to obtain token2;

[0115] 4. The policy execution module of the authority machine communicates with the rule judgment module to obtain the transaction decision result. If it passes, steps 5 and 6 are executed; otherwise, the process is stopped;

[0116] 5. The authority machine sends token2+token3 encrypted by private key 3 to the data acquirer, who decrypts it using public key 3 to obtain token2+token3. Token2 indicates that the data owner has signed and approved it, and token3 indicates that the authority machine has signed and approved it.

[0117] 6. The authority machine sends token1+token3 encrypted by private key 3 to the data owner, who decrypts it using public key 3 to obtain token1+token3. Token1 indicates that the data acquirer has signed and approved the data, and token3 indicates that the authority machine has signed and approved the data.

[0118] In this embodiment, the execution timing of step 5 and step 6 is not prioritized;

[0119] 7. The data owner sends token2+token3 encrypted by private key 2 to the data acquirer, who decrypts it using public key 2 to obtain token2+token3. The decrypted token2+token3 obtained in this step is then compared with the token2+token3 obtained in step 5.

[0120] 8. The data acquirer sends token1+token3 encrypted by private key 1 to the data owner, and the data acquirer decrypts it using public key 1 to obtain token1+token3; then the decrypted token1+token3 obtained in this step is compared with the token1+token3 obtained in step 6;

[0121] In this embodiment, the execution timing of step 7 and step 8 is not prioritized;

[0122] When the comparison results of steps 7 and 8 are the same, the transaction session between the data acquirer and the data owner is successfully established.

[0123] The authority machine includes but is not limited to: a policy execution module, a rule judgment module, a rule base and an attribute acquisition module.

[0124] The strategy execution module is used to accept a data transaction request from any transaction terminal, communicate with the rule judgment module to obtain a transaction decision result, and send a transaction signature to any transaction terminal to establish a transaction session between the transaction terminals;

[0125] The rule judgment module is used to receive the data transaction request (the attribute information of the data to be traded, the terminal attribute information of any transaction terminal, and the terminal attribute information of the other transaction terminal that forms data interaction with any transaction terminal) transmitted by the strategy execution module, collect the applicable strategies and data required for making transaction authority decisions (from the attribute acquisition module and the rule base), formulate the rules and attributes to obtain the logical operation results, and return them to the strategy execution module;

[0126] The rule base stores data transaction compliance requirements and other rule sets that need to be managed. These rules can be combined using logical operations such as and, or, and not.

[0127] The attribute acquisition module collects relevant data about the transaction terminals involved in the data transaction, the data to be traded and the environment and provides it to the rule judgment module.

[0128] according to Figure 2 As shown, the third embodiment of the present invention provides a data transaction and sharing session construction system, the system comprising:

[0129] The authority machine forms a data connection with the transaction terminals participating in the data transaction, and is used to receive and verify the verification tokens uploaded by the transaction terminals participating in the data transaction, and the authority machine also sends its own verification tokens to the transaction terminals participating in the data transaction;

[0130] The number of transaction terminals is set to be at least two and each transaction terminal participates in the data transaction, and each transaction terminal receives and verifies the verification token belonging to the authority machine sent by the authority machine; and, when the two-way verification between the authority machine and each transaction terminal participating in the data transaction is passed, the transaction terminals constituting the data interaction mutually issue their own verification tokens, and when all the transaction terminals determine that the verification tokens belonging to the same transaction terminal received twice are the same, a data transaction session between the transaction terminals participating in the data transaction is established.

[0131] A fourth embodiment of the present invention provides a computer device, comprising: one or more processors; a memory; and one or more applications, wherein the one or more applications are stored in the memory and configured to be executed by the one or more processors, and the one or more programs are configured to: execute the data transaction and shared session construction method according to the above-mentioned method.

[0132] The specific implementation process of the above method steps can be found in the first, second and third embodiments, and this embodiment will not be repeated here.

[0133] The fifth embodiment of the present invention provides a computer-readable storage medium, which stores at least one instruction, at least one program, a code set or an instruction set, and the at least one instruction, the at least one program, the code set or the instruction set are loaded and executed by a processor to implement the data transaction and shared session construction method as described above.

[0134] The specific implementation process of the above method steps can be found in the first, second and third embodiments, and this embodiment will not be repeated here.

[0135] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of finger controls to enable a terminal (which can be a mobile phone, computer, server, air conditioner, or network equipment, etc.) to execute the methods described in each embodiment of the present invention.

[0136] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation modes, which are merely illustrative rather than restrictive. Under the guidance of the present invention, ordinary technicians in this field can also make many forms without departing from the scope of protection of the present invention and the claims, all of which are within the protection of the present invention.

Claims

1. A method for establishing a data transaction and sharing session, characterized in that: The method comprises: Performing two-way verification between the transaction terminal participating in the data transaction and the authority machine, wherein, during the two-way verification process, the authority machine sends a verification token belonging to the other transaction terminal to one of the transaction terminals constituting the data interaction; In the case where the two-way verification is passed, the transaction terminals constituting the data interaction mutually issue their own verification tokens, and the transaction terminals constituting the data interaction mutually issue the verification tokens belonging to the authority machine; compare whether the verification tokens belonging to the authority machine and the verification tokens belonging to the same transaction terminal received twice by each transaction terminal are the same; if all the transaction terminals determine that the verification tokens belonging to the same transaction terminal received twice are the same, establish a data transaction session between the transaction terminals participating in the data transaction; The number of the transaction terminals is set to at least two, and each of the transaction terminals is data-connected with at least one other transaction terminal, and the transaction terminal corresponds one-to-one to the verification token belonging to the transaction terminal; The comparing whether the verification tokens belonging to the authority machine and the verification tokens belonging to the same transaction terminal received twice by each transaction terminal are the same includes: The transaction terminal binds the verification token belonging to the authority machine and the verification token belonging to the other transaction terminal that performs data interaction with the transaction terminal. Compare whether the two binding data belonging to the same trading terminal in each trading terminal are the same; If so, a data transaction session is established between the transaction terminals participating in the data transaction.

2. The method according to claim 1, characterized in that The two-way verification between the transaction terminal participating in the data transaction and the authority machine includes: The transaction terminal participating in the data transaction and the authority machine mutually issue verification tokens belonging to themselves; When both the transaction terminal and the authority machine verify the received verification token, the two-way authentication between the interactive terminal participating in the data transaction and the authority machine is completed, wherein the authority machine corresponds one-to-one with the verification token belonging to the authority machine.

3. The method according to claim 2, characterized in that Before the transaction terminal and the authority machine both verify the received verification token, the method further includes: The authority machine sends a verification token belonging to the other transaction terminal to one of the transaction terminals constituting the data interaction.

4. The method according to claim 1, characterized in that The two-way verification between the transaction terminal participating in the data transaction and the authority machine includes: The transaction terminals participating in the data transaction send their respective verification tokens to the authority machine; When the verification token belonging to the transaction terminal is successfully verified by the authority machine, the transaction terminal corresponding to the verified verification token is determined to be a trusted terminal to complete the one-way verification; The authority machine sends relevant data information to the transaction terminal determined as a trusted terminal; wherein the relevant data information includes: a verification token of the authority machine and a verification token of the other transaction terminal that forms data interaction with the transaction terminal determined as a trusted terminal, wherein the authority machine corresponds to the verification token belonging to the authority machine one by one; When the verification token belonging to the authority machine is successfully verified by the transaction terminal determined as a trusted terminal, the authority machine is determined to be a trusted authority machine to complete the two-way authentication between the interactive terminal participating in the data transaction and the authority machine.

5. The method according to claim 2 or 4, characterized in that: The transaction terminal sends a verification token belonging to the transaction terminal to the authority machine, including: Any of the transaction terminals sends a data transaction request to the authority machine, wherein the transaction request includes: a verification token belonging to any of the transaction terminals, and terminal attribute information of the other transaction terminal that forms data interaction with any of the transaction terminals; Based on the terminal attribute information of the other transaction terminal that forms data interaction with any transaction terminal, the authority machine forwards the data transaction request to the other transaction terminal that forms data interaction with any transaction terminal; The verification token belonging to the other transaction terminal that forms data interaction with any one of the transaction terminals is received by the authority machine; wherein the verification token belonging to the other transaction terminal that forms data interaction with any one of the transaction terminals is fed back by the other transaction terminal that forms data interaction with any one of the transaction terminals in response to the data transaction request.

6. The method according to claim 5, characterized in that The data transaction request also includes: attribute information of the data to be traded and terminal attribute information of any transaction terminal; Before establishing the data transaction session between the transaction terminals participating in the data transaction, the method further includes: Based on the attribute information of the data to be traded and the terminal attribute information of any transaction terminal, the authority machine generates a transaction decision; When the transaction decision is passed, it is determined that the data transaction is valid.

7. The method according to claim 2, characterized in that: The transaction terminal and the authority machine are each provided with a corresponding key pair, each of the key pairs comprising: a private key and a public key; The transaction terminal and the authority machine both encrypt the verification token issued by themselves through their own private keys; moreover, the transaction terminal and the authority machine that receive the verification token both decrypt the verification token through the corresponding public key. If the decryption is successful, it means that the verification token has been verified, wherein the corresponding public key is represented by the public key corresponding to the transaction terminal and / or the authority machine that issued the verification token.

8. A data transaction and sharing session construction system, characterized in that: The system comprises: The authority machine forms a data connection with the transaction terminals participating in the data transaction, and is used to receive and verify the verification tokens uploaded by the transaction terminals participating in the data transaction, and the authority machine also sends its own verification tokens to the transaction terminals participating in the data transaction; and The transaction terminal, the number of which is set to at least two and each transaction terminal participates in the data transaction, each transaction terminal receives and verifies the verification token belonging to the authority machine sent by the authority machine; and, when the two-way verification between the authority machine and each transaction terminal participating in the data transaction is passed, the transaction terminals constituting the data interaction mutually issue their own verification tokens, and the transaction terminals constituting the data interaction mutually issue verification tokens belonging to the authority machine; compare whether the verification token belonging to the authority machine received twice by each of the transaction terminals and the verification token belonging to the same transaction terminal are the same; when all the transaction terminals determine that the verification tokens belonging to the same transaction terminal received twice are the same, establish a data transaction session between the transaction terminals participating in the data transaction; wherein, the comparison of whether the verification token belonging to the authority machine received twice by each of the transaction terminals and the verification token belonging to the same transaction terminal are the same includes: The transaction terminal binds the verification token belonging to the authority machine and the verification token belonging to the other transaction terminal that performs data interaction with the transaction terminal. Compare whether the two binding data belonging to the same trading terminal in each trading terminal are the same; If so, a data transaction session is established between the transaction terminals participating in the data transaction.

9. A computer device, characterized in that: include: one or more processors; Memory; One or more applications, wherein the one or more applications are stored in the memory and are configured to be executed by the one or more processors, and the one or more programs are configured to: execute the data transaction and sharing session establishment method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that the storage medium stores at least one instruction, at least one program, a code set or an instruction set, and the at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by a processor to implement the data transaction and shared session construction method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Identity authentication method for accessing SIP security video monitoring system

    CN104168267A

  • Method, terminal equipment, and server for carrying out identity authentication in electronic transaction

    CN105184569A