Method for realizing personal information portability based on blockchain and private data set
By combining blockchain with private data sets, the security, privacy and controllability of personal data in the flow process are achieved, the verification difficulties and autonomous control problems in data flow are solved, and trusted data carrying across application systems is achieved.
Patent Information
- Application Number
- CN202211237855.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-10
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2042-10-10
AI Technical Summary
Personal data is difficult to store and verify reliably during its circulation process. There is data monopoly, individuals cannot independently control data sharing, third-party verification agencies may leak data, and there is a lack of the right to carry personal information across application systems.
By using blockchain and private data sets, and deploying smart contracts through blockchain node types including personal data user nodes, data provider nodes and data user nodes, and utilizing the tamper-proof and traceable characteristics of blockchain, combined with the access control characteristics of private data sets, controllable sharing and supervision of data can be achieved.
It realizes the security, privacy, authenticity, traceability and controllable flow of personal data, solves the problems of difficulty in verifying the authenticity of data from data provider nodes and third-party leakage, and gives individuals autonomous control over data sharing.
Smart Images

Figure CN115495525B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of personal data security, and in particular to a method for realizing the portability of personal information based on blockchain and private data sets. Background Art
[0002] According to the Personal Information Protection Law of the People's Republic of China, "if an individual requests the transfer of personal information to a designated personal information processor that meets the conditions specified by the national cyberspace administration, the personal information processor shall provide a means for the transfer." Currently, the release of the value of personal data is limited, personal data is difficult to transfer, and data monopolies are difficult to break. The right to portability of personal information grants individuals the right to actively transfer personal data between companies. However, in practice, the current platform-led or company-led models generally lack reliable storage and verification mechanisms and are difficult to avoid data monopolies. The use of third-party verification agencies may also lead to the theft of user privacy. Individuals lack independent control over the sharing of personal data, making it impossible to achieve widespread and cross-application portability of personal information. Summary of the Invention
[0003] In order to solve at least one of the above technical problems, the present invention proposes a method for realizing the portability of personal information based on blockchain and private data sets.
[0004] The purpose of the present invention is achieved through the following technical solutions:
[0005] The present invention provides a method for implementing the portability of personal information based on blockchain and private data sets. The method is characterized in that the blockchain node types include personal data user nodes, data provider nodes, and data user nodes. The specific steps of the method are as follows:
[0006] S1. The personal data user node sets the function attributes of providing private data sets and using private data sets, and deploys smart contracts containing the functions of providing private data sets and using private data sets;
[0007] S2. The personal data user node initiates a personal data transfer proposal and uploads it to the blockchain with a signature;
[0008] S3. After the data provider node endorses the personal data transfer proposal with the endorsement node and the functional attributes of the private data set provided, the consensus node reaches consensus and distributes the block to other nodes in the blockchain.
[0009] S4. The personal data user node receives the personal data and verifies the validity of the personal data based on the received block;
[0010] S5. The data user node initiates a data demand proposal and uploads it to the blockchain with a signature;
[0011] S6. After the personal data user node submits the data demand proposal and endorses it with the functional attributes of the private data set by the endorsement node, the consensus node reaches consensus and distributes the block to other nodes in the blockchain.
[0012] S7. The data user node receives personal data and verifies the validity of the personal data based on the block.
[0013] As a further improvement, the valid node types of the blockchain include regulator nodes, on which smart contracts are deployed. After steps S4 and S7 are completed, the regulator node supervises whether the endorsing nodes of the blockchain endorse the block, whether the nodes involved in the block sign the block, and verifies the legitimacy of the transaction after receiving the block.
[0014] As a further improvement, the supervisor node verifies the legitimacy of the transaction after receiving the block, including the following:
[0015] SI1. The data structure of the block is syntactically valid;
[0016] SI2, verify the effectiveness of workload;
[0017] SI3. The block timestamp is two hours before the verification time;
[0018] SI4. Verify that the block size is within the length limit;
[0019] SI5. Verify transactions within the block and ensure the validity of transactions.
[0020] As a further improvement, in step S1, providing a private data set and using a private data set respectively include mandatory functional attributes and optional functional attributes. The mandatory functional attributes are: the name of the private data set, the distribution strategy of the private data, the minimum number of endorsement nodes distributed to authorized nodes, the maximum number of endorsement nodes distributed to authorized nodes, the time when the private data is stored in the privacy status database, whether only authorized nodes can read the private data and whether only authorized nodes can write the private data set. The optional functional attribute is: the endorsement strategy of the private data set.
[0021] As a further improvement, in step S3, the data provider node endorses the personal data transfer proposal through the endorsement node in combination with the functional attributes of the private data set provided, including the following steps:
[0022] S31. The data provider node constructs a transfer proposal based on the personal data transfer proposal of the personal data user node, signs the transfer proposal, and uploads it to the endorsement node. The endorsement node distributes the personal data to the authorized nodes according to the private data distribution strategy that provides the functional attributes of the private dataset.
[0023] S32. The endorsement node returns the data hash value containing only personal data to the data provider, and the data provider node submits the transfer endorsement proposal to the consensus node.
[0024] As a further improvement, in step S6, the personal data user node endorses the data demand proposal through the endorsement node in combination with the functional attributes of the private data set, including the following steps:
[0025] S61. The personal data user node queries the local data for personal data that matches the data demand proposal based on the data user node's data demand proposal. If so, it constructs a transfer and use proposal, signs the transfer and use proposal, and uploads it to the endorsing node. The endorsing node distributes the personal data to the authorized nodes based on the private data distribution policy using the functional attributes of the private dataset.
[0026] S62. The endorsement node returns a data hash value containing only personal data or a transfer endorsement proposal indicating a failed transaction to the personal data user node, and the personal data user node submits the transfer endorsement proposal to the consensus node.
[0027] As a further improvement, in step S1, the personal data transfer proposal initiated by the personal data user node includes the personal data user node initiating a personal data preservation proposal to the data provider node or obtaining a personal data proposal from the data provider node.
[0028] As a further improvement, in step S61, it is checked whether there is personal data matching the data demand proposal in the local data, otherwise jump to step S2. The personal data transfer proposal initiated by the personal data user node is to obtain the personal data proposal from the data provider node, and execute steps S3, S4, S6 and S7 in sequence.
[0029] The present invention provides a method for implementing the right to portability of personal information based on blockchain and private data sets. The blockchain node types include personal data user nodes, data provider nodes and data user nodes, and include the following steps: S1. The personal data user node is set with functional attributes of providing private data sets and using private data sets, and a smart contract containing providing private data sets and using private data sets is deployed; S2. The personal data user node initiates a personal data transfer proposal and uploads it with a signature to the blockchain; S3. The data provider node endorses the personal data transfer proposal with the endorsement node in combination with the functional attribute of providing private data sets, and the consensus node completes the consensus and distributes the block to other nodes of the blockchain; S4. The personal data user node receives the personal data and verifies the validity of the personal data based on the received block; S5. The data user node initiates a data demand proposal and uploads it with a signature to the blockchain; S6. The personal data user node endorses the data demand proposal with the endorsement node in combination with the functional attribute of using private data sets, and the consensus node completes the consensus and distributes the block to other nodes of the blockchain; S7. The data user node receives the personal data and verifies the validity of the personal data based on the block. The present invention ensures the authenticity and verifiability of data by utilizing the tamper-proof and traceable characteristics of blockchain, adds data provider nodes to the blockchain network, realizes operational supervision of data provider nodes, and utilizes the access control characteristics of private data sets to realize controllable sharing of user privacy data. It solves the problems in current technology that the authenticity of data provided by data provider nodes is difficult to verify, the personal data of personal data user nodes may be leaked by third-party verification agencies, and the personal data user nodes cannot independently control the granularity of personal data sharing, and realizes the security, privacy, authenticity, traceability and controllable flow of personal data of personal data user nodes. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 It is a structural schematic diagram of the present invention;
[0031] Figure 2 It is a schematic diagram of the process of the present invention. DETAILED DESCRIPTION
[0032] Combine Figure 1 As shown, embodiment 1 of the present invention provides a method for realizing the portability of personal information based on blockchain and private data sets. The blockchain node types include endorsement nodes and consensus nodes in the blockchain network, as well as personal data user nodes, data provider nodes, and data user nodes involved in this embodiment.
[0033] Endorsing node: A node that undertakes the endorsement task in the blockchain. The endorsing node must prove its legitimacy by validly signing the expected information of a valid certificate.
[0034] Consensus nodes: In addition to completing the work of ordinary nodes, they will take turns participating in the generation, broadcasting and consensus of new blocks, and update the ledger after reaching consensus.
[0035] Personal data user node: possesses personal data information and actively initiates personal data transfer proposals in the blockchain network.
[0036] Data provider node: holds the personal data of the personal data user node and provides services to users. When the personal data user node initiates a data transfer proposal, it constructs a transfer proposal based on the personal data transfer proposal, signs it, and submits it to the endorsement node for endorsement. It stores the personal data of the personal data user node or provides personal data to the personal data user node according to regulations, and submits the returned results after endorsement by the endorsement node to the consensus node.
[0037] Data user node: The destination party of the personal data transfer of the personal data user node, who hopes to use the personal data of the personal data user node.
[0038] The specific steps of the method are as follows:
[0039] S1. The personal data user node is set with the functional attributes of providing private data sets and using private data sets, and a smart contract containing the providing private data sets and using private data sets is deployed. Providing private data sets and using private data sets are a controllable data sharing mechanism that protects user privacy. In this embodiment, the personal data of the personal data user node is stored only in the private database of the authorized network node in the form of transient data, and the hash value corresponding to the personal data is stored in the ledger of other nodes in the blockchain network. Unauthorized nodes have no right to access the personal data of the personal data user node and can only view the hash value corresponding to the personal data of the personal data user node.
[0040] Providing a private data set and using a private data set respectively include mandatory functional attributes and optional functional attributes. The mandatory functional attributes are: the name of the private data set name, the distribution policy of the private data, the minimum number of endorsement nodes distributed to authorized nodes requiredPeerCount, the maximum number of endorsement nodes distributed to authorized nodes maxPeerCount, the time blockToLive for private data to be stored in the privacy status database, whether only authorized nodes can read private data memberOnlyRead, and whether only authorized nodes can write private data sets memberOnlyWrite. The optional functional attribute is: the endorsement policy endorsementPolicy of the private data set.
[0041] In this embodiment, the functional attributes of providing a private data set are defined as follows:
[0042] "name": "Provide Private Dataset",
[0043] "policy": "OR('UserMSP.member', 'DataProviderMSP.member')",
[0044] "requiredPeerCount": 1,
[0045] "maxPeerCount": 2,
[0046] "blockToLive": 3,
[0047] "memberOnlyRead": true,
[0048] "memberOnlyWrite": true,
[0049] wherein UserMSP.member is a node type of personal data user node in the blockchain network, DataProviderMSP.member is a node type of data provider node in the blockchain network, and the blockToLive function attribute is in units of blocks, indicating that the personal data of the private data set will be saved in the privacy state database of the blockchain for 3 blocks, from the time the hash value of the personal data is stored on the blockchain, after the blockchain increases 3 blocks, the personal data of the private data set will be automatically cleared, if the private data needs to be permanently retained, the blockToLive attribute value is set to 0.
[0050] In this embodiment, the function attribute of using the private data set is defined as follows:
[0051] "name": "Use Private Dataset",
[0052] "policy": "OR('UserMSP.member', 'DataUserMSP.member')",
[0053] "requiredPeerCount": 1,
[0054] "maxPeerCount": 2,
[0055] "blockToLive": 3,
[0056] "memberOnlyRead": true,
[0057] "memberOnlyWrite": true,
[0058] "endorsementPolicy":{"signaturePolicy":"OR('UserMSP.member','DataUserMSP.member')"},
[0059] Among them, DataUserMSP.member indicates that the node type of the blockchain network is a data user node, and the signaturePolicy attribute is an optional attribute, indicating that the endorsement policy for using private datasets is OR('UserMSP.member', 'DataUserMSP.member'), which is used to override the endorsement policy at the chaincode level. The endorsement policy for using private datasets is included in its distribution policy.
[0060] S2. The personal data user node initiates a personal data transfer proposal and uploads it to the blockchain with a signature. The personal data transfer proposal includes the personal data user node initiating a personal data preservation proposal to the data provider node or obtaining a personal data proposal from the data provider node. In this embodiment, the personal data user node initiates a personal data preservation proposal, and the personal data preservation proposal contains personal data.
[0061] S3. The data provider node passes the personal data transfer proposal to the endorsement node in combination with the functional attributes of the private data set provided. The specific steps include the following:
[0062] S31. The data provider node constructs a transfer proposal containing personal data based on the personal data transfer proposal of the personal data user node, signs the transfer proposal, and uploads it to the endorsing node. The endorsing node distributes the personal data to authorized nodes according to the private data distribution strategy that provides the functional attributes of the private dataset. In this embodiment, the authorized nodes are the personal data user node and the data provider node on the blockchain.
[0063] S32. The endorsement node returns a data hash value containing only personal data, and the data provider node submits the transfer endorsement proposal to the consensus node.
[0064] The consensus nodes reach consensus and distribute blocks containing only the hash of the individual’s data to other nodes in the blockchain.
[0065] S4. The personal data user node receives the personal data and verifies the validity of the personal data based on the received block. Verifying the validity of the personal data here mainly involves verifying whether the nodes involved in the block are signed, whether the received personal data has been tampered with, and whether the data hash value stored locally is consistent with the data hash value of the block.
[0066] S5. The data user node initiates a data demand proposal and uploads it to the blockchain with a signature. The data demand proposal includes data query requirements and key query information.
[0067] S6. The personal data user node uses the endorsement node to endorse the data demand proposal using the functional attributes of the private dataset. The specific steps include:
[0068] S61. The personal data user node queries the local data for personal data that matches the data demand proposal based on the data user node's data demand proposal. If so, it constructs a transfer and use proposal containing the personal data related to the query key information, signs the transfer and use proposal, and uploads it to the endorsing node. The endorsing node distributes the personal data to authorized nodes based on a private data distribution strategy that uses the functional attributes of a private dataset. In this embodiment, the authorized nodes are personal data user nodes and data user nodes on the blockchain.
[0069] S62. The endorsement node returns a data hash value containing only personal data, and the personal data user node submits the transfer endorsement proposal to the consensus node.
[0070] The consensus node completes the consensus and distributes the block to other nodes in the blockchain;
[0071] S7. The data user node receives personal data and verifies the validity of the personal data based on the block. Verifying the validity of personal data here mainly involves verifying whether the nodes involved in the block are signed and whether the received personal data is relevant to the data demand proposal.
[0072] As a further preferred embodiment, the effective node type of the blockchain also includes a regulator node, on which a smart contract is deployed. After steps S4 and S7 are completed, the regulator node supervises whether the endorsing node of the blockchain endorses, whether the nodes involved in the block sign, and verifies the legitimacy of the transaction after receiving the block, thereby preventing the data provider node from leaking the personal data of the personal data user node, making the operations on the blockchain authentic and traceable, and protecting the personal data of the personal data user node while realizing the supervision of data circulation.
[0073] Supervisor node: supervises and audits the data flow process in the block.
[0074] After receiving the block, the regulator node verifies the legitimacy of the transaction, including the following:
[0075] SI1. The data structure of the block is syntactically valid;
[0076] SI2. Verify the proof of work. Specifically, the hash value of the block header is less than the target difficulty to confirm that the block contains sufficient proof of work.
[0077] SI3. The block timestamp is two hours ahead of the verification time. This is due to time differences between nodes on the blockchain and network transmission time. Blockchains usually allow a certain degree of error in timestamps.
[0078] SI4. Verify that the block size is within the length limit and check whether the block size is within the set range;
[0079] SI5. Verify transactions within the block and ensure their validity. Specifically, verify whether the Merkle root (MerkleRoot) is obtained from the transactions in the block body, that is, reconstruct the root of the block Merkle tree (MerkleTree) and confirm whether it is equal to the hash MerkleRoot value in the block header.
[0080] Embodiment 1 of the present invention ensures the authenticity and verifiability of data by utilizing the tamper-proof and traceable characteristics of blockchain, adds data provider nodes to the blockchain network, realizes operational supervision of data provider nodes, and utilizes the access control characteristics of private data sets to realize controllable sharing of user privacy data. It solves the problems in the current technology that the authenticity of data provided by data provider nodes is difficult to verify, the personal data of personal data user nodes may be leaked by third-party verification agencies, and the personal data user nodes cannot independently control the granularity of personal data sharing, thereby realizing the security, privacy, authenticity, traceability and controllable flow of personal data of personal data user nodes.
[0081] Embodiment 2 of the present invention:
[0082] It should be noted that, when Example 2 and Example 1 do not conflict, further preferred implementation methods can be combined with each other and produce the same or corresponding technical effects. The same implementation content will not be repeated. On the basis of Example 1, that is, after steps S1, S2, S3 and S4 of Example 1, the personal data of the personal data user node is endorsed by the endorsement node and stored on the personal data user node and the data provider node respectively, and the data user initiates a data demand proposal. The difference between Example 2 and Example 1 is that in step S61, a query is made as to whether there is personal data matching the data demand proposal in the local data. Otherwise, it indicates that the personal data user node does not store personal data matching the data demand proposal. This is because the personal data user node has deleted historical data or the storage environment has changed, resulting in data loss. The personal data user node can re-obtain personal data from the data provider node and distribute it to the data provider node. The specific method is that at this time, the method of the embodiment of the present invention jumps to step S2. The personal data transfer proposal initiated by the personal data user node is to obtain personal data from the data provider node. The content of the personal data transfer proposal at this time includes information related to obtaining personal data from the data provider node extracted by the personal data user node from the data demand proposal initiated by the data user node, such as query requirements and query key information, or the data hash value of the personal data obtained by the personal data user node from the local query, and steps S3, S4, S6 and S7 are executed in sequence. For specific content, please refer to Example 1 and will not be repeated here.
[0083] In the second embodiment, the data user node directly submits a data demand proposal to the personal data user node. When the personal data user node deletes local historical data or the storage environment changes, resulting in data loss, the personal data user node obtains personal data related to the data user node's data demand proposal from the data provider node. The personal data user node then directly provides the personal data to the data user node. The purpose is to prevent the data provider node from leaking the personal data of the personal data user node and to enable the personal data user node to independently control the granularity of data sharing.
[0084] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0085] The above-described embodiments merely illustrate several implementations of the present invention, and while their descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent. It should be noted that a person skilled in the art would be able to make numerous variations and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present invention. Therefore, the scope of protection of the patent for this invention shall be determined by the appended claims.
Claims
1. A method for implementing the portability of personal information based on blockchain and private data sets, characterized in that: Blockchain node types include personal data user nodes, data provider nodes, and data user nodes. The method includes the following steps: S1. The personal data user node sets the function attributes of providing a private dataset and using a private dataset, and deploys a smart contract containing the functions of providing a private dataset and using a private dataset. The functions of providing a private dataset and using a private dataset respectively include mandatory and optional function attributes. The mandatory function attributes are: the name of the private dataset, the distribution strategy of the private data, the minimum number of endorsement nodes distributed to authorized nodes, the maximum number of endorsement nodes distributed to authorized nodes, the time for private data to be stored in the privacy status database, whether only authorized nodes can read the private data, and whether only authorized nodes can write the private dataset. The optional function attribute is: the endorsement strategy of the private dataset. S2. The personal data user node initiates a personal data transfer proposal and uploads it to the blockchain with a signature; S3. After the data provider node endorses the personal data transfer proposal with the endorsement node and the functional attributes of the private data set provided, the consensus node reaches consensus and distributes the block to other nodes in the blockchain. S4. The personal data user node receives the personal data and verifies the validity of the personal data based on the received block; S5. The data user node initiates a data demand proposal and uploads it to the blockchain with a signature; S6. After the personal data user node submits the data demand proposal and endorses it with the functional attributes of the private data set by the endorsement node, the consensus node reaches consensus and distributes the block to other nodes in the blockchain. S7. The data user node receives personal data and verifies the validity of the personal data based on the block.
2. The method for implementing the right of portability of personal information based on blockchain and private data sets according to claim 1 is characterized in that: The valid node types of the blockchain include regulator nodes, on which smart contracts are deployed. After steps S4 and S7 are completed, the regulator node supervises whether the endorsing nodes of the blockchain endorse and whether the nodes involved in the block sign, and verifies the legitimacy of the transaction after receiving the block.
3. The method for implementing the right of portability of personal information based on blockchain and private data sets according to claim 2 is characterized in that: After receiving the block, the regulator node verifies the legitimacy of the transaction, including the following: SI1. The data structure of the block is syntactically valid; SI2, verify the effectiveness of workload; SI3. The block timestamp is two hours before the verification time; SI4. Verify that the block size is within the length limit; SI5. Verify transactions within the block and ensure the validity of transactions.
4. The method for implementing the right of portability of personal information based on blockchain and private data sets according to claim 1 is characterized in that: In step S3, the data provider node endorses the personal data transfer proposal with the endorsement node in combination with the functional attributes of the private data set provided, including the following steps: S31. The data provider node constructs a transfer proposal based on the personal data transfer proposal of the personal data user node, signs the transfer proposal, and uploads it to the endorsement node. The endorsement node distributes the personal data to the authorized nodes according to the private data distribution strategy that provides the functional attributes of the private dataset. S32. The endorsement node returns the data hash value and endorsement result containing only personal data to the data provider. The data provider node submits the transfer endorsement proposal containing the hash value and endorsement result to the consensus node.
5. The method for implementing the right of portability of personal information based on blockchain and private data sets according to claim 1 is characterized in that: In step S1, the personal data transfer proposal initiated by the personal data user node includes the personal data user node initiating a personal data preservation proposal to the data provider node or obtaining a personal data proposal from the data provider node.
6. The method for implementing the right of portability of personal information based on blockchain and private data sets according to any one of claims 1 to 5, characterized in that: In step S6, the personal data user node endorses the data demand proposal through the endorsement node in combination with the functional attributes of the private data set, including the following steps: S61. The personal data user node queries the local data for personal data that matches the data demand proposal based on the data user node's data demand proposal. If so, it constructs a transfer and use proposal, signs the transfer and use proposal, and uploads it to the endorsing node. The endorsing node distributes the personal data to the authorized nodes based on the private data distribution policy using the functional attributes of the private dataset. S62. The endorsement node returns a data hash value containing only personal data or a transfer endorsement proposal indicating a failed transaction to the personal data user node, and the personal data user node submits the transfer endorsement proposal to the consensus node.
7. The method for implementing the right of portability of personal information based on blockchain and private data sets according to claim 6 is characterized in that: In step S61, it is checked whether there is personal data matching the data demand proposal in the local data. Otherwise, it jumps to step S2. The personal data transfer proposal initiated by the personal data user node is to obtain the personal data proposal from the data provider node, and execute steps S3, S4, S6 and S7 in sequence.