Method and apparatus for processing privacy data
By using the privacy computing platform and the encryption processing of the TEE unit, the issues of willingness and security in the flow of user privacy data are resolved, and the trusted flow and security of user privacy data are achieved.
Patent Information
- Application Number
- CN202211191853.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-28
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2042-09-28
AI Technical Summary
In existing technologies, the process of acquiring user privacy data usually skips the user's wishes, fails to effectively transfer the data while respecting the user's wishes, and lacks privacy and security guarantees for the data transfer process.
The privacy computing platform receives authorization requests, generates and transmits authorization statements, acquires and processes encrypted privacy data, generates encrypted result data, and ensures that data flows in an encrypted state, including using TEE units for data processing and encryption/decryption, and using blockchain to record data flow information.
It enables the effective transfer of user privacy data among multiple parties while respecting user wishes, and ensures the privacy and security of the data transfer process, guaranteeing the immutability and trustworthiness of the data.
Smart Images

Figure CN115664668B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present specification relate to the technical field of computer, and specifically, to a privacy data processing method and device. BACKGROUND
[0002] The privacy data of a user is usually distributed in the business systems of several institutions used by the user. Any of the business systems can be, for example, a shopping system, a financial management system, an insurance system or a payment system, etc. When other institutions need to use the privacy data of the user, they generally negotiate directly with an institution of the several institutions, and thus obtain the required data from the institution. SUMMARY
[0003] Embodiments of the present specification provide a privacy data processing method and device, which can help multiple parties to effectively circulate the privacy data of a user while respecting the user's will, and guarantee the privacy security of the circulation process of the privacy data of the user.
[0004] In a first aspect, embodiments of the present specification provide a privacy data processing method applied to a privacy computing platform, comprising: receiving an authorization application for privacy data of a target user submitted by a first institution; sending the authorization application to a user device of the target user; in response to receiving an authorization statement sent by the user device, obtaining ciphertext privacy data from a data storage end used by the target user based on the authorization statement; the authorization statement comprising information of the first institution; generating ciphertext result data based on the ciphertext privacy data; returning the ciphertext result data to the first institution.
[0005] In some embodiments, before receiving the authorization application for the privacy data of the target user submitted by the first institution, the method further comprises: receiving an information publishing request of the target user from the user device; the information publishing request comprising a user identifier of the target user and related information of the privacy data; and storing the user identifier and the related information in association.
[0006] In some embodiments, the authorization application comprises a data usage mode; and the authorization statement further comprises at least one of the following: a data category, a data range, and the data usage mode.
[0007] In some embodiments, the related information comprises the data category and data value information corresponding to the data category.
[0008] In some embodiments, the authorization application further comprises the data category, and data value information corresponding to the data category provided by the first institution.
[0009] In some embodiments, after returning the ciphertext result data to the first institution, further comprising: based on the data value information, performing value allocation for the target user.
[0010] In some embodiments, after returning the ciphertext result data to the first institution, further comprising: storing at least one of the following to a block chain: the authorization declaration, a hash value of the plaintext privacy data corresponding to the ciphertext privacy data, time information; the time information includes at least one of the following: issuance time of the authorization declaration, reception time of the authorization declaration, reception time of the ciphertext privacy data, sending time of the ciphertext result data.
[0011] In some embodiments, the privacy computing platform has a data storage end address provided by the target user; and the obtaining of the ciphertext privacy data from the data storage end used by the target user comprises: obtaining the ciphertext privacy data from the data storage end indicated by the data storage end address.
[0012] In some embodiments, the authorization declaration further includes a user identifier of the target user and is added with a first signature of the target user; and the obtaining of the ciphertext privacy data from the data storage end used by the target user based on the authorization declaration comprises: sending a data obtaining request to the data storage end; the data obtaining request includes the authorization declaration added with the first signature; and receiving the ciphertext privacy data returned by the data storage end after the first signature is verified.
[0013] In some embodiments, the information of the first institution includes an institution identifier, and the user identifier and the institution identifier are both decentralized identity identifiers.
[0014] In some embodiments, the privacy computing platform includes a trusted execution environment (TEE) unit; and the generating of the ciphertext result data based on the ciphertext privacy data comprises: the TEE unit generates the ciphertext result data based on the ciphertext privacy data.
[0015] In some embodiments, the authorization application includes a data usage manner; and the generating of the ciphertext result data based on the ciphertext privacy data comprises: decrypting the ciphertext privacy data to obtain plaintext privacy data; and processing the plaintext privacy data based on the data usage manner to generate the ciphertext result data.
[0016] In some embodiments, the method further comprises: obtaining a second signature generated by the data storage end for the ciphertext privacy data; the TEE unit verifies the second signature; and the decrypting of the ciphertext privacy data comprises: in response to the second signature passing the verification, decrypting the ciphertext privacy data.
[0017] In some embodiments, the data storage end stores a first public key of the TEE unit, the ciphertext privacy data is obtained by encrypting the plaintext privacy data using the first public key; and the decrypting the ciphertext privacy data comprises: the TEE unit decrypting the ciphertext privacy data using a first private key of the TEE unit.
[0018] In some embodiments, the data usage mode is to use the original text; and the processing the plaintext privacy data based on the data usage mode to generate ciphertext result data comprises: providing a second public key of the first institution pre-stored in the TEE unit; and the TEE unit encrypting the plaintext privacy data using the second public key to obtain the ciphertext result data.
[0019] In some embodiments, the data usage mode is to use a privacy computing result, and the privacy computing platform stores a privacy computing algorithm corresponding to the data usage mode provided by the first institution; and the processing the plaintext privacy data based on the data usage mode to generate ciphertext result data comprises: performing computing processing on the plaintext privacy data using the privacy computing algorithm to obtain a computing result; providing a second public key of the first institution pre-stored in the TEE unit; and the TEE unit encrypting the computing result using the second public key to obtain the ciphertext result data.
[0020] In some embodiments, the data storage end stores privacy data of a plurality of data categories hosted by the target user; the privacy data of the plurality of data categories is obtained from a plurality of business systems of institutions used by the target user, and is collected by the user equipment from the business systems in a trusted manner.
[0021] In some embodiments, the plurality of institutions includes a second institution, the business system of the second institution includes a data interface opened by the second institution to the outside, the data interface is used for downloading data and signing data by a user; and the privacy data of the plurality of data categories, which is obtained from the business system, is collected by the user equipment by calling the data interface and is associated with a signature.
[0022] In some embodiments, the plurality of institutions includes a third institution, and the privacy data of the plurality of data categories, which is obtained from the business system of the third institution, is collected by the user equipment from the business system using a trusted proof technology.
[0023] In a second aspect, the embodiments of the present specification provide a privacy data processing method, comprising: receiving, by a privacy computing platform, an authorization application for privacy data of a target user submitted by a first institution, and sending the authorization application to a user device of the target user; generating, by the user device, an authorization statement including information of the first institution after the target user agrees to the authorization application, and sending the authorization statement to the privacy computing platform; sending, by the privacy computing platform, a data acquisition request to a data storage end used by the target user; the data acquisition request including the authorization statement; processing, by the data storage end, privacy data of the target user locally saved based on the authorization statement, generating ciphertext privacy data, and sending the ciphertext privacy data to the privacy computing platform; generating, by the privacy computing platform, ciphertext result data based on the ciphertext privacy data, and returning the ciphertext result data to the first institution.
[0024] In a third aspect, the embodiments of the present specification provide a privacy data processing apparatus applied to a privacy computing platform, comprising: a receiving unit configured to receive an authorization application for privacy data of a target user submitted by a first institution; a sending unit configured to send the authorization application to a user device of the target user; an acquiring unit configured to acquire ciphertext privacy data from a data storage end used by the target user based on an authorization statement in response to receiving the authorization statement sent by the user device; the authorization statement including information of the first institution; a generating unit configured to generate ciphertext result data based on the ciphertext privacy data; and the sending unit is further configured to return the ciphertext result data to the first institution.
[0025] In a fourth aspect, the embodiments of the present specification provide a computer readable storage medium having a computer program stored thereon, wherein when the computer program is executed in a computer, the computer executes the method described in any implementation manner of the first aspect.
[0026] In a fifth aspect, the embodiments of the present specification provide a computing device comprising a memory and a processor, wherein the memory has executable code stored therein, and the processor executes the executable code to implement the method described in any implementation manner of the first aspect.
[0027] In a sixth aspect, the embodiments of the present specification provide a computer program, wherein when the computer program is executed in a computer, the computer executes the method described in any implementation manner of the first aspect.
[0028] The above-mentioned embodiments of the present specification provide a solution, which can make the privacy computing platform connect the institution equipment of the institution (such as the first institution in the foregoing) with the data use demand, the user equipment of the user (such as the target user in the foregoing) as the data owner, and the data storage end used by the user. In the solution, after receiving the authorization application of the first institution for the private data of the target user, the privacy computing platform can make the target user judge whether to authorize by sending the authorization application to the user equipment of the target user, so as to respect the will of the target user. After the target user agrees to the authorization application, the user equipment can generate an authorization statement including the information of the first institution, and send the authorization statement to the privacy computing platform, so that the privacy computing platform obtains the ciphertext private data from the data storage end used by the target user based on the authorization statement, generates the ciphertext result data based on the ciphertext private data, and returns the ciphertext result data to the first institution. Since the private data obtained by the privacy computing platform from the data storage end and the private data returned to the first institution are both ciphertext data, the privacy of the user private data flow process can be guaranteed. Therefore, the solution can help multiple parties to effectively flow the private data of the user while respecting the will of the user, and guarantee the privacy of the user private data flow process. BRIEF DESCRIPTION OF DRAWINGS
[0029] In order to more clearly illustrate the technical solutions of the multiple embodiments disclosed in the present specification, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present specification, and other drawings can be obtained by those skilled in the art without creative labor.
[0030] Figure 1 is an exemplary system architecture diagram in which some embodiments of the present specification can be applied;
[0031] Figure 2 is a schematic diagram of one embodiment of a private data processing method;
[0032] Figure 3 is a schematic diagram of one embodiment of a private data processing method;
[0033] Figure 4 is a structural schematic diagram of a private data processing device. DETAILED DESCRIPTION
[0034] The present specification will be further described in conjunction with the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related application, and not to limit the application. The described embodiments are only part of the embodiments of the present specification, not all. Based on the embodiments in the present specification, all other embodiments obtained by those of ordinary skill in the art without creative labor are within the scope of the present application.
[0035] It should be noted that, for the convenience of description, only the part related to the application is shown in the drawings. The embodiments in the present specification and the features in the embodiments can be combined with each other without conflict.
[0036] As mentioned before, the privacy data of a user is usually distributed in the business systems of several institutions used by the user. When other institutions need to use the privacy data of the user, they generally negotiate directly with an institution of the several institutions, and thus obtain the required data from the institution. Such a privacy data obtaining process skips the user and does not respect the user's will.
[0037] Based on this, some embodiments of the present specification provide a privacy data processing method, which can help multiple parties to effectively circulate the privacy data of a user while respecting the user's will, and guarantee the privacy security of the circulation process of the user's privacy data.
[0038] Referring to Figure 1 , which is an exemplary system architecture diagram applicable to some embodiments of the present specification. As Figure 1 indicated, the exemplary system architecture shown can include a user device 101 of a user User1 who is a data owner, business systems of several institutions used by User1 (such as a business system 102 of an institution A and a business system 103 of an institution B as shown in Figure 1 ), a data storage end used by User1 (such as a privacy data center 104 as shown in Figure 1 ), a privacy computing platform 105, and an institution device 106 of an institution C which has a data use demand.
[0039] Among them, any of the business systems may, for example, be a shopping system, a financial system, an insurance system or a payment system, etc. When the business systems used by User1 include a shopping system, User1 may, for the shopping system, be a merchant settled in the shopping system, or an ordinary user (such as a buyer) in the shopping system.
[0040] The private data hub (PDH) 104 is a repository that helps users store and manage private data, and can be implemented as a cloud service or a client application installed on a user device. The private data hub 104 can manage private data in a classified manner and has the ability to verify user authorization claims.
[0041] The private computing platform 105 can be referred to as a private data matchmaking platform. The private computing platform 105 can support data owners to publish information related to private data owned by the data owners on the platform, and support institutions with data usage needs to search for needed data on the platform and apply for authorization. In addition, the private computing platform 105 can pull encrypted data from the PDH of the data owner and provide private computing capabilities.
[0042] The institution C can be an institution of any category, for example, a bank institution or an institution for big data analysis, etc. Taking the bank institution as an example, after receiving a loan application from a user, the bank institution can use the private data of the user by applying for the use of the private data of the user, and use the private data to assess the loan amount of the user. The institution device 106 of the institution C can be a terminal device or a server, which is not specifically limited here.
[0043] It should be noted that, for ease of description, only one user as a data owner and one institution with data usage needs are shown in Figure 1 It should be noted that, for ease of description, only one user as a data owner and one institution with data usage needs are shown in
[0044] In the whole link from private data collection to private data usage, User 1 can use the user device 101 to collect the private data of User 1 from the business systems 102 and 103 in a trusted collection manner. The private data collected in the trusted collection manner can be verified by others to be downloaded from the corresponding business system, and the data owner cannot tamper with the data, which guarantees the trustworthiness of the private data.
[0045] Then, User 1 can use the user device 101 to store the private data of User 1 in the private data hub 104. After that, if User 1 wants to make the private data of User 1 available for use by others, for example, to be used by others for compensation, etc., User 1 can publish information related to the private data of User 1 through the user device 101 to the private computing platform 105, so that the private computing platform 105 stores the information. In the private computing platform 105, the information can be viewed by institutions with data usage needs.
[0046] When the institution C checks the relevant information and wants to obtain the authorization of the privacy data corresponding to the relevant information, the institution device 106 can send an authorization application for the privacy data of Userl to the privacy computing platform 105. Then, the privacy computing platform 105 can send the authorization application to the user device 101. After Userl agrees to the authorization application, the user device 101 can generate an authorization statement for the first institution and send the authorization statement to the privacy computing platform 105. Then, the privacy computing platform 105 can obtain the ciphertext privacy data from the privacy data center 104 based on the authorization statement, generate ciphertext result data based on the ciphertext privacy data, and return the ciphertext result data to the institution C.
[0047] By using the above-described privacy data processing process, the effective flow of user privacy data of multiple parties can be facilitated under the premise of respecting the will of Userl, and the privacy security of the user privacy data flow process is guaranteed.
[0048] The scheme provided by the embodiments of the present specification can be divided into a privacy data preparation phase and a privacy data use phase.
[0049] Next, the related content of the privacy data preparation phase will be introduced in combination with Figure 2 .
[0050] Referring to Figure 2 , a schematic diagram of one embodiment of a privacy data processing method is shown. The method comprises the following steps:
[0051] Step 202: The user device of the target user collects privacy data from the business systems of a plurality of institutions used by the target user through a trusted collection manner;
[0052] Step 204: The user device sends the collected privacy data to the data storage end used by the target user;
[0053] Step 206: The data storage end saves the received privacy data.
[0054] Step 208: The user device sends an information publishing request of the target user to the privacy computing platform; the information publishing request comprises a user identifier of the target user and related information of the privacy data;
[0055] Step 210: The privacy computing platform stores the user identifier and the above-mentioned related information in association.
[0056] Next, steps 202-210 will be further described.
[0057] In step 202, the user device can collect the privacy data from the service system of the target user's using several institutions by a trusted collection manner, for example, collect the privacy data of several data categories. Wherein, a single data category can be, for example, order data, payment data, financial data or insurance data, etc. It should be understood that the data categories can be divided according to actual needs, which is not limited here.
[0058] The privacy data collected by the trusted collection manner can be verified by others that it is downloaded from the corresponding service system, and the data owner cannot tamper with it, which guarantees the trustworthiness of the privacy data.
[0059] In one example, the service system of a certain institution (which can be referred to as a second institution) in the above several institutions can include a data interface opened by the institution to the outside. The data interface can be used for users to download data and sign the data. The user device can collect the privacy data of the target user from the service system of the second institution by calling the data interface of the service system. Wherein, the privacy data is associated with a signature. The signature can be the signature of the second institution.
[0060] In another example, the service system of a certain institution (which can be referred to as a third institution) in the above several institutions does not have a data interface as described above. The user device can collect the privacy data of the target user from the service system of the third institution by a trusted proof technology. Wherein, the trusted proof technology includes but is not limited to TLSNotoray proof technology. TLSNotary can introduce a third party as an auditing party by using the mechanism of TLS1.1 protocol, thereby improving the trustworthiness of the data. Since the TLSNotoray proof technology is a well-known technology, it will not be described here.
[0061] Then, in step 204, the user device can send the collected privacy data to the data storage end used by the target user. Specifically, the target user can collect the privacy data collected from the service system of the above several institutions by the user device, and then send the collected privacy data to the data storage end. Wherein, the data storage end can be the privacy data center described above.
[0062] Then, in step 206, the data storage end can save the received privacy data, for example, can store the received privacy data in a classified manner.
[0063] It should be noted that when the data storage end is not located locally on the user equipment, for example, the data storage end is a cloud service, in order to ensure the security of the privacy data in the transmission process, the user equipment can use the pre-stored public key of the data storage end to encrypt the collected privacy data, and then send the encryption result to the data storage end. Subsequently, the data storage end can use its private key to decrypt the encryption result to obtain the decrypted privacy data and save the privacy data.
[0064] Further, in order to ensure the integrity of the privacy data, after obtaining the encryption result, the user equipment can use the private key of the target user to generate a signature for the encryption result, and send the encryption result and the signature to the data storage end. Subsequently, the data storage end can use the pre-stored public key of the target user to verify the signature, and after the signature is verified, use its own private key to decrypt the encryption result to obtain the decrypted privacy data and save the privacy data.
[0065] After the privacy data is hosted to the data storage end, if the target user wants to make his own privacy data available to others, for example, to be used by others for a fee, etc., the user equipment can be used to perform step 208. In step 208, the user equipment can send an information publishing request of the target user to the privacy computing platform. The information publishing request can include the user identification of the target user and the related information of the privacy data. The related information may, for example, include data categories. Further, the related information can also include data value information corresponding to the data categories. The data value information may, for example, indicate the fee to be paid by others for using the privacy data of the data categories. Then, in step 210, the privacy computing platform can store the user identification of the target user and the related information in association.
[0066] Figure 2 The privacy data processing method provided by the corresponding embodiments can realize trusted collection of user privacy data and publishing of related information of the privacy data. The trusted collected privacy data can be verified by others as being downloaded from the corresponding business system and cannot be tampered with by the data owner, thereby ensuring the trustworthiness of the data.
[0067] In practice, the related information stored in the privacy computing platform can be viewed by institutions that have data usage needs. For any institution that has data usage needs (referred to as a first institution), when the institution views the related information and wants to obtain authorization for the privacy data corresponding to the related information, the privacy data usage phase can be entered.
[0068] Next, in combination with Figure 3 , the related content of the privacy data usage phase will be introduced.
[0069] Referring to Figure 3FIG. 1 shows a schematic diagram of an embodiment of a method for processing privacy data. The method comprises the following steps:
[0070] At step 302, the institution device of the first institution sends an authorization application for the privacy data of the target user to the privacy computing platform;
[0071] At step 304, the privacy computing platform sends the authorization application to the user device of the target user;
[0072] At step 306, the user device generates an authorization statement including the information of the first institution after the target user agrees to the authorization application;
[0073] At step 308, the user device sends the authorization statement to the privacy computing platform;
[0074] At step 310, the privacy computing platform sends a data acquisition request to the data storage end used by the target user; the data acquisition request includes the authorization statement;
[0075] At step 312, the data storage end processes the locally saved privacy data of the target user based on the authorization statement to generate ciphertext privacy data;
[0076] At step 314, the data storage end sends the ciphertext privacy data to the privacy computing platform;
[0077] At step 316, the privacy computing platform generates ciphertext result data based on the ciphertext privacy data;
[0078] At step 318, the privacy computing platform returns the ciphertext result data to the first institution.
[0079] Hereinafter, steps 302-318 are further described.
[0080] At step 302, the institution device of the first institution can send an authorization application for the privacy data of the target user to the privacy computing platform. Thus, the privacy computing platform can receive the authorization application submitted by the first institution.
[0081] The authorization application can include a data usage mode. The data usage mode can be, for example, using plaintext or using privacy computing result. Further, the authorization application can further include, but is not limited to, at least one of the following: user identification of the target user, information of the first institution, data category, data value information corresponding to the data category provided by the first institution. The information of the first institution can include, for example, the institution identification of the first institution. The data category is the data category to which the privacy data applied by the first institution belongs. The data value information can indicate the fee that the first institution is willing to pay for using the privacy data of the data category.
[0082] It should be noted that the user identifier of the target user and the institution identifier of the first institution can each be a decentralized identifier (DID). The decentralized identifier can also be referred to as a decentralized identifier or a distributed identifier.
[0083] In the embodiments of the present specification, a digital identity can be created for each institution and user, for example, by a DIS (Decentralized Identity Service) in combination with a blockchain. The blockchain can provide a decentralized (or weakly centralized), tamper-proof (or difficult to tamper), trusted distributed ledger, and can provide a secure, stable, transparent, auditable, and efficient way to record transactions and interact with data information. The blockchain network can include a plurality of nodes. Generally, one or more nodes of the blockchain belong to a participant. In general, the more participants in the blockchain network, the more authoritative the participants, and the more trustworthy the blockchain network. Here, the blockchain network formed by a plurality of participants is referred to as a blockchain platform. With the help of the blockchain platform, the identity of the institution and the user can be verified.
[0084] Taking an institution as an example, in order to use the distributed digital identity service provided by the blockchain platform, the institution can register its own identity in the blockchain platform. For example, institution C can create a pair of public key and private key, store the private key confidentially, and can create a decentralized identifier. The DID can be created by institution C itself, or can request the DIS system to create the DID. DIS is a blockchain-based identity management solution that can provide functions such as creation, verification, and management of digital identity, so as to realize standardized management and protection of entity data, while ensuring the authenticity and efficiency of information flow, and can solve the difficult problems of cross-institution identity authentication and data cooperation. The DIS system can be connected to the blockchain platform. Through the DIS system, a DID can be created for institution C, and the DID and the public key are sent to the blockchain platform for storage, and the created DID is returned to institution C. The public key can be included in the DIDdoc, and the DIDdoc can be stored in the blockchain platform. The DIS creates the DID for institution C, which can be created based on the public key sent by institution C, for example, by calculating the public key of institution C using a Hash function, or by creating it based on other information of institution C (which can include or not include the public key). The latter may require institution C to provide some information in addition to the public key. Thereafter, institution C can provide a verification function to prove to other parties that it is institution C.
[0085] Then, in step 304, the privacy computing platform can send the authorization application to the user device of the target user. Then, the user device can show the authorization application to the target user, for the target user to determine whether to authorize. After the target user agrees to the authorization application, i.e., after the authorization application, the user device can then perform step 306.
[0086] In step 306, the user device can generate an authorization statement including the information of the first institution. Further, the authorization statement can also include, but is not limited to, at least one of the following: user identification of the target user, data category, data range, data usage mode, issuance time of the authorization statement.
[0087] It should be understood that the data category in the authorization statement is the data category to which the private data allowed to be used by the first institution by the target user belongs. The data range in the authorization statement is the range of the private data allowed to be used by the first institution by the target user, which can include but is not limited to a time range. The data usage mode in the authorization statement is the usage mode of the private data allowed to be used by the first institution by the target user. It should be pointed out that when the authorization application of the first institution includes the data category and the data usage mode, the data category and the data usage mode in the authorization statement are usually consistent with those in the authorization application.
[0088] Then, in step 308, the user device can send the authorization statement to the privacy computing platform. Further, in order to ensure the integrity of the authorization statement, the user device can add a signature of the target user (which can be referred to as a first signature) to the authorization statement. Then, the user device can send the authorization statement with the first signature to the privacy computing platform.
[0089] Then, the privacy computing platform can obtain the ciphertext private data from the data storage used by the target user based on the authorization statement. As an example, the privacy computing platform can save the data storage address provided by the target user, and the privacy computing platform can obtain the ciphertext private data from the data storage indicated by the data storage address.
[0090] Specifically, the privacy computing platform can send a data obtaining request to the data storage used by the target user by performing step 310. The data obtaining request includes the authorization statement, for example, the authorization statement with the first signature. Then, the data storage can process the local private data of the target user based on the authorization statement to generate the ciphertext private data by performing step 312.
[0091] Wherein, in the case that the authorization statement is added with the first signature, the data storage can first verify the first signature. For example, the first signature is added by using the private key of the target user, and the data storage can verify the first signature by using the public key of the target user previously saved.
[0092] After the first signature is verified, the data storage end can process the locally saved privacy data of the target user based on the authorization statement to generate the ciphertext privacy data. For example, the data storage end can locally search for privacy data that meets the authorization statement, such as searching for privacy data of a data category when the authorization statement includes the data category. After the privacy data that meets the authorization statement is found, the data storage end can use the public key (which can be referred to as the first public key) of the TEE (Trusted Execution Environment) unit of the privacy computing platform previously saved to encrypt the privacy data to obtain the ciphertext privacy data.
[0093] The TEE is a secure extension based on CPU hardware and a trusted execution environment completely isolated from the outside. The industry is very concerned about the TEE solution, and almost all mainstream chips and software alliances have their own TEE solutions, such as TPM (Trusted Platform Module) in software and Intel SGX (Software Guard Extensions), ARM Trustzone, and AMD PSP (Platform Security Processor) in hardware. The TEE can function as a hardware black box, and the code and data executed in the TEE cannot be snooped even by the operating system layer, and can only be operated through the pre-defined interface in the code. In terms of efficiency, due to the black box nature of the TEE, the data operated in the TEE is plaintext data, not the complex cryptography operation in homomorphic encryption, and the computing process has almost no efficiency loss.
[0094] Taking Intel SGX (hereinafter referred to as SGX) technology as an example. The blockchain node can create an enclave (a circle or a flyover) as a TEE based on the SGX technology. Among them, the server can use the newly added processor instructions in the CPU to allocate a part of the EPC (Enclave Page Cache, enclave page cache or flyover page cache) in the memory for the enclave. The memory area corresponding to the above-mentioned EPC is encrypted by the internal memory encryption engine MEE (Memory Encryption Engine) of the CPU. The content (code and data in the enclave) in the memory area can only be decrypted in the CPU kernel, and the key for encryption and decryption is generated only when the EPC is started and stored in the CPU. It can be seen that the security boundary of the enclave only contains itself and the CPU, neither privileged nor non-privileged software can access the enclave, even the operating system administrator and VMM (Virtual Machine Monitor, or called Hypervisor) cannot affect the code and data in the enclave, so it has very high security, and under the premise of the above security guarantee, the CPU can process the data in plaintext form in the enclave, with very high operation efficiency, so as to balance the data security and computing efficiency. The data in and out of the TEE can be encrypted to protect the privacy of the data.
[0095] The TEE can prove itself to be trustworthy before being used. The process of proving itself to be trustworthy can involve a remote attestation report. The remote attestation report is generated in a remote attestation process of the TEE. The remote attestation report can be generated by an authoritative authentication server after verifying the self-recommendation information generated by the TEE. The remote attestation report can be used to show that the TEE is trustworthy.
[0096] For example, before encrypting the privacy data using the first public key of the TEE unit, the data storage end can first verify whether the TEE unit is trustworthy. Specifically, the data storage end can initiate a challenge to the TEE unit and receive a remote attestation report returned by the TEE unit. After obtaining the remote attestation report, the data storage end can verify the signature of the remote attestation report according to the public key of the authoritative authentication server, and if the verification is passed, it can confirm that the TEE unit is trustworthy. Specifically, after receiving the verification request, the TEE unit generates authentication information based on its internal mechanism, and sends the authentication information and the hardware public key of the TEE unit to the data storage end. The authentication information includes, for example, the signature information, hardware information and software information of the TEE unit. The signature information is generated, for example, by the hardware key of the TEE unit; the hardware information includes, for example, the indicators of various hardware, such as CPU frequency, memory capacity, etc.; and the software information includes the code hash value, code name, version, running log, etc. of each program. As known by those skilled in the art, the TEE unit can perform a "measurement" of the program running therein through the memory hardware, such as obtaining the code hash value of the program, the hash value of the memory occupancy of the program at a certain execution point, etc., and include the "measurement" information of the program in the authentication information. Since the "measurement" information is executed by the entity (memory hardware) of the TEE unit itself and does not involve any software or operating system, it is authentic and trustworthy. After receiving the authentication information, the data storage end can send the authentication information to the remote authentication server of the TEE unit, so as to receive a remote attestation report of the TEE unit from the server. The remote attestation report includes the identity verification of the TEE unit and the verification of the execution program in the TEE unit, etc. Thus, based on the remote attestation report, the data storage end can determine that the TEE unit is trustworthy, and the query result through the TEE unit is trustworthy. Meanwhile, the data storage end can locally save the hardware public key of the TEE unit for subsequent verification of the signature of the TEE unit. The TEE unit stores a pair of public and private keys, and the private key is properly kept in the TEE unit. The content transmitted by the TEE unit can be signed by the private key saved in the TEE unit, thereby proving that it is the result executed by the TEE unit.
[0097] Then, in step 314, the data storage end can send the ciphertext privacy data to the privacy computing platform. Further, in order to ensure the integrity of the ciphertext privacy data, the data storage end can generate a signature (which can be referred to as a second signature) for the ciphertext privacy data using its private key. After that, the data storage end can send the ciphertext privacy data and the second signature to the privacy computing platform.
[0098] Then, in step 316, the privacy computing platform can generate ciphertext result data based on the ciphertext privacy data. Specifically, the TEE unit in the privacy computing platform can generate the ciphertext result data based on the ciphertext privacy data.
[0099] It should be noted that if the privacy computing platform obtains the ciphertext privacy data and also obtains the second signature generated by the data storage end for the ciphertext privacy data, the TEE unit in the privacy computing platform can first verify the second signature. For example, the second signature is generated by using the private key of the data storage end, and the privacy computing platform can provide the public key of the data storage end pre-stored to the TEE unit, and then the TEE unit can verify the second signature by using the public key. After the second signature is verified, the TEE unit can generate the ciphertext result data based on the ciphertext privacy data.
[0100] In one example, the TEE unit can decrypt the ciphertext privacy data to obtain plaintext privacy data. For example, the ciphertext privacy data is obtained by encrypting the corresponding plaintext privacy data by using the first public key of the TEE unit, and the TEE unit can decrypt the ciphertext privacy data by using the private key (which can be referred to as the first private key) to obtain the plaintext privacy data. In addition, the privacy computing platform can provide the public key (which can be referred to as the second public key) of the first institution to the TEE unit, and the TEE unit can encrypt the plaintext privacy data by using the second public key to obtain the ciphertext result data.
[0101] In another example, the authorization application as described above includes a data usage mode. The TEE unit can decrypt the ciphertext privacy data to obtain plaintext privacy data, and then process the plaintext privacy data based on the data usage mode to generate the ciphertext result data.
[0102] For example, when the data usage mode is to use the original text, the privacy computing platform can provide the second public key of the first institution to the TEE unit, and the TEE unit can encrypt the plaintext privacy data by using the second public key to obtain the ciphertext result data.
[0103] For another example, when the data usage mode is to use the privacy computing result, the privacy computing platform can pre-store the privacy computing algorithm corresponding to the data usage mode provided by the first institution. The privacy computing platform can use the privacy computing algorithm to process the plaintext privacy data to obtain a computing result, and provide the second public key of the first institution pre-stored to the TEE unit, and the TEE unit can encrypt the computing result by using the second public key to obtain the ciphertext result data.
[0104] Then, in step 318, the privacy computing platform can return the ciphertext result data to the first institution, for example, send the ciphertext result data to the institution device of the first institution.
[0105] After that, the agency device can decrypt the ciphertext result data, for example, the ciphertext result data is obtained by encrypting the corresponding plaintext result data (the plaintext privacy data or the calculation result as described above) by using the second public key of the first agency, and the agency device can decrypt the ciphertext result data by using the private key (which can be referred to as the second private key) of the first agency to obtain the plaintext result data. Then, the agency device can perform corresponding business processing on the target user, such as loan limit assessment or credit enhancement, based on the plaintext result data, for example.
[0106] Figure 3 The privacy data processing method provided by the corresponding embodiments can help multiple parties to effectively circulate user privacy data while respecting the will of the user, and guarantee the privacy security of the circulation process of the user privacy data.
[0107] In one embodiment, if the above authorization application further includes a data category, and any of the following conditions is met: the privacy calculation platform further saves the data value information corresponding to the data category published by the target user, and the above authorization application further includes the data value information corresponding to the data category provided by the first agency, then after the step 318, the privacy calculation platform can further perform value distribution for the target user based on the data value information.
[0108] As an example, the privacy calculation platform can determine the due fee of the target user this time based on the data value information, and increase the balance of the target account of the target user by the due fee. The target account can be an account of the target user in the privacy calculation platform, or a third-party account. When the target account is a third-party account, the privacy calculation platform can interact with the service platform to which the target account belongs to increase the balance of the target account.
[0109] As another example, the privacy calculation platform can determine the due fee of the first agency this time and the due fee of the target user this time based on the data value information, wherein the due fee of the first agency is greater than or equal to the due fee of the target user. Then, the privacy calculation platform can first collect the due fee of the first agency, and then increase the balance of the target account of the target user by the due fee of the target user. It should be pointed out that when the due fee of the first agency is greater than the due fee of the target user, the difference between the due fee of the first agency and the due fee of the target user can be the service fee collected by the privacy calculation platform from the target user.
[0110] In practice, user privacy data has certain value, and in the process of being used by an institution, this part of value is often intercepted by the institution, and the individual cannot benefit from it. The scheme provided by the embodiments of the present specification can realize value allocation for the target user by supporting the target user to publish data value information corresponding to the data category and supporting the institution with data use demand to provide data value information corresponding to the data category in the authorization application, so that the target user can obtain benefits in the process of using the privacy data by the institution. Moreover, the scheme can make the value circulation of privacy data simple under the premise of security.
[0111] In one embodiment, in order to facilitate subsequent audit and traceability, after the above step 318, the privacy computing platform can also store at least one of the following to the block chain: authorization declaration, hash value of the plaintext privacy data corresponding to the ciphertext privacy data, time information. The time information can include at least one of the following: issuance time of the authorization declaration, receiving time of the authorization declaration, receiving time of the ciphertext privacy data, sending time of the ciphertext result data.
[0112] According to the foregoing description, it can be seen that the scheme provided by the above embodiments of the present specification can achieve the following beneficial effects: lightweight data collection, right establishment, authorization, and protection; authenticity verification of data without touching the data; providing a lightweight privacy data matching method in the personal dimension; promoting data owners to actively contribute data by reasonably allocating data value.
[0113] Further referring to Figure 4 , the present specification provides an embodiment of a privacy data processing device, which can be applied to a privacy computing platform 105 as shown in Figure 1 .
[0114] As shown in Figure 4 , the privacy data processing device 400 of the present embodiment comprises a receiving unit 401, a sending unit 402, an obtaining unit 403, and a generating unit 404. The receiving unit 401 is configured to receive an authorization application for the privacy data of a target user submitted by a first institution; the sending unit 402 is configured to send the authorization application to a user device of the target user; the obtaining unit 403 is configured to obtain ciphertext privacy data from a data storage end used by the target user based on an authorization declaration in response to receiving the authorization declaration sent by the user device; the authorization declaration includes information of the first institution; the generating unit 404 is configured to generate ciphertext result data based on the ciphertext privacy data; and the sending unit 402 is further configured to return the ciphertext result data to the first institution.
[0115] In some embodiments, the receiving unit 401 can be further configured to receive an information publishing request of the target user from the user device before receiving the authorization application of the target user's privacy data submitted by the first institution; the information publishing request comprises a user identification of the target user and related information of the privacy data; and the device 400 can further comprise a first storage unit (not shown in the figure) configured to store the user identification and the related information in association.
[0116] In some embodiments, the authorization application comprises a data usage manner; and the authorization statement further comprises at least one of the following: a data category, a data range, and the data usage manner.
[0117] In some embodiments, the related information comprises a data category and data value information corresponding to the data category.
[0118] In some embodiments, the authorization application further comprises a data category, and the data value information corresponding to the data category provided by the first institution.
[0119] In some embodiments, the device 400 can further comprise a value allocation unit (not shown in the figure) configured to perform value allocation for the target user based on the data value information after the sending unit 402 returns the ciphertext result data to the first institution.
[0120] In some embodiments, the device 400 can further comprise a second storage unit (not shown in the figure) configured to store at least one of the following to the blockchain after the sending unit 402 returns the ciphertext result data to the first institution: the authorization statement, the hash value of the plaintext privacy data corresponding to the ciphertext privacy data, and time information; the time information comprises at least one of the following: the issuance time of the authorization statement, the receiving time of the authorization statement, the receiving time of the ciphertext privacy data, and the sending time of the ciphertext result data.
[0121] In some embodiments, the privacy computing platform has a data storage end address provided by the target user; and the obtaining unit 403 can be further configured to obtain the ciphertext privacy data from the data storage end indicated by the data storage end address.
[0122] In some embodiments, the authorization statement further comprises a user identification of the target user and is added with a first signature of the target user; and the obtaining unit 403 can be further configured to send a data obtaining request to the data storage end; the data obtaining request comprises the authorization statement added with the first signature; and the ciphertext privacy data returned by the data storage end after the first signature is verified.
[0123] In some embodiments, the information of the first institution comprises an institution identification; and the user identification and the institution identification are both decentralized identifications.
[0124] In some embodiments, the privacy computing platform comprises a trusted execution environment (TEE) unit; and the generating unit 404 can be further configured to: generate the ciphertext result data based on the ciphertext privacy data by executing the TEE unit.
[0125] In some embodiments, the authorization application comprises a data usage manner; and the generating unit 404 can be further configured to: decrypt the ciphertext privacy data to obtain plaintext privacy data, and process the plaintext privacy data based on the data usage manner to generate the ciphertext result data by executing the TEE unit.
[0126] In some embodiments, the obtaining unit 403 can be further configured to: obtain, from the data storage end, a second signature generated by the data storage end for the ciphertext privacy data; and the generating unit 404 can be further configured to: verify the second signature by executing the TEE unit, and decrypt the ciphertext privacy data in response to the second signature passing the verification.
[0127] In some embodiments, the data storage end stores a first public key of the TEE unit, and the ciphertext privacy data is obtained by encrypting the plaintext privacy data by using the first public key; and the generating unit 404 can be further configured to: decrypt the ciphertext privacy data by using a first private key of the TEE unit by executing the TEE unit.
[0128] In some embodiments, the data usage manner is to use the original text; and the generating unit 404 can be further configured to: provide a second public key of the first institution, which is pre-stored, to the TEE unit; and encrypt the plaintext privacy data by using the second public key to obtain the ciphertext result data by executing the TEE unit.
[0129] In some embodiments, the data usage manner is to use a privacy computing result, and the privacy computing platform stores a privacy computing algorithm corresponding to the data usage manner provided by the first institution; and the generating unit 404 can be further configured to: perform computing processing on the plaintext privacy data by using the privacy computing algorithm to obtain a computing result; provide a second public key of the first institution, which is pre-stored, to the TEE unit; and encrypt the computing result by using the second public key to obtain the ciphertext result data by executing the TEE unit.
[0130] In some embodiments, the data storage end stores privacy data of a plurality of data categories hosted by the target user; and the privacy data of the plurality of data categories is collected by the user device from a plurality of business systems of institutions used by the target user in a trusted collection manner.
[0131] In some embodiments, the plurality of institutions includes a second institution, a business system of the second institution includes a data interface exposed by the second institution, the data interface is configured to allow a user to download data and sign the data; and the privacy data of the plurality of data categories includes privacy data from the business system of the second institution, the privacy data is collected by the user device by calling the data interface, and is associated with a signature.
[0132] In some embodiments, the plurality of institutions includes a third institution, and the privacy data of the plurality of data categories includes privacy data from a business system of the third institution, the privacy data is collected by the user device from the business system of the third institution by using a trusted attestation technology. The trusted attestation technology includes, but is not limited to, a TLS Notoray attestation technology.
[0133] In Figure 3 In the corresponding device embodiments, the specific processing of each unit and the technical effects brought by the specific processing can be referred to the related descriptions in the corresponding embodiments, and will not be described here. Figure 2 In the corresponding device embodiments, the specific processing of each unit and the technical effects brought by the specific processing can be referred to the related descriptions in the corresponding embodiments, and will not be described here.
[0134] The embodiments of the present specification also provide a computer readable storage medium having a computer program stored thereon, wherein when the computer program is executed in a computer, the computer program causes the computer to perform the privacy data processing method described in each of the method embodiments.
[0135] The embodiments of the present specification also provide a computer readable storage medium having a computer program stored thereon, wherein when the computer program is executed in a computer, the computer program causes the computer to perform the privacy data processing method described in each of the method embodiments.
[0136] The embodiments of the present specification also provide a computer readable storage medium having a computer program stored thereon, wherein when the computer program is executed in a computer, the computer program causes the computer to perform the privacy data processing method described in each of the method embodiments.
[0137] Those skilled in the art should be aware that the functions described in the above one or more examples can be implemented in hardware, software, firmware, or any combination thereof. When implemented in software, the functions can be stored in a computer readable medium or transmitted as one or more instructions or code on a computer readable medium.
[0138] In some cases, the actions or steps recited in the claims can be performed in a different order than the order described in the embodiments and still achieve the desired result. In addition, the processes depicted in the figures do not necessarily require the particular order shown or sequential order to achieve the desired results. In certain implementations, multitasking and parallel processing can be advantageous.
[0139] The above detailed description sets forth numerous specific details for the purpose of providing a thorough understanding of the various embodiments of the present disclosure. However, it will be understood that the various embodiments of the present disclosure can be practiced without these specific details. In other instances, well-known methods, procedures, components, and circuits have not been described in detail as not to unnecessarily obscure aspects of the various embodiments of the present disclosure. It can be understood that the various embodiments of the present disclosure while including numerous specific details are given by way of example and for purpose of illustration only. The various embodiments of the present disclosure can be practiced without these specific details. In other instances, specific instrumentation and details have not been described in detail since they would be apparent to those skilled in the art.
Claims
1. A privacy data processing method applied to a privacy computing platform, comprising: receiving an authorization application for privacy data of a target user submitted by a first institution; sending the authorization application to a user device of the target user; in response to receiving an authorization statement sent by the user device to the privacy computing platform, obtaining ciphertext privacy data from a data storage used by the target user based on the authorization statement; the authorization statement comprising information of the first institution; generating ciphertext result data based on the ciphertext privacy data; returning the ciphertext result data to the first institution.
2. The method of claim 1, wherein, Before receiving the authorization application for privacy data of a target user submitted by a first institution, further comprising: receiving an information publishing request of the target user from the user device; the information publishing request comprising a user identifier of the target user and related information of privacy data; storing the user identifier and the related information in association.
3. The method of claim 2, wherein, The authorization application comprises a data usage mode; the authorization statement further comprises at least one of the following: data category, data range, data usage mode.
4. The method of claim 3, wherein, The related information comprises the data category and data value information corresponding to the data category.
5. The method of claim 3, wherein, The authorization application further comprises the data category and data value information corresponding to the data category provided by the first institution.
6. The method of claim 4 or 5, wherein, After returning the ciphertext result data to the first institution, further comprising: based on the data value information, performing value allocation for the target user.
7. The method of claim 1, wherein, After returning the ciphertext result data to the first institution, further comprising: storing at least one of the following to a blockchain: the authorization statement, a hash value of plaintext privacy data corresponding to the ciphertext privacy data, time information; the time information comprises at least one of the following: issuance time of the authorization statement, reception time of the authorization statement, reception time of the ciphertext privacy data, sending time of the ciphertext result data.
8. The method of claim 1, wherein, The privacy computing platform has a data storage address provided by the target user; and The ciphertext privacy data obtained from the data storage used by the target user comprises: obtaining ciphertext privacy data from the data storage indicated by the data storage address. The authorization statement further comprises a user identifier of the target user and is added with a first signature of the target user; and 9. The method of claim 1, wherein, The ciphertext privacy data obtained from the data storage used by the target user comprises: sending a data acquisition request to the data storage; the data acquisition request comprises the authorization statement added with the first signature; receiving the ciphertext privacy data returned by the data storage after the first signature is verified. The information of the first institution comprises an institution identifier, and the user identifier and the institution identifier are both decentralized identifiers. The privacy computing platform comprises a trusted execution environment (TEE) unit; 10. The method of claim 2 or 9, wherein, The ciphertext result data generated based on the ciphertext privacy data comprises:
11. The method of claim 1, wherein, the TEE unit generates the ciphertext result data based on the ciphertext privacy data. The authorization application comprises a data usage mode; and 12. The method of claim 11, wherein, The ciphertext result data is generated based on the ciphertext privacy data, including: decrypting the ciphertext privacy data to obtain plaintext privacy data; processing the plaintext privacy data based on the data usage mode to generate ciphertext result data.
13. The method of claim 12, further comprising: obtaining, from the data storage end, a second signature generated for the ciphertext privacy data; verifying, by the TEE unit, the second signature; decrypting the ciphertext privacy data, including: decrypting the ciphertext privacy data in response to the second signature passing the verification.
14. The method of claim 12 or 13, wherein, The data storage end stores a first public key of the TEE unit, and the ciphertext privacy data is obtained by encrypting the plaintext privacy data using the first public key; and decrypting the ciphertext privacy data, including: decrypting the ciphertext privacy data by the TEE unit using its first private key.
15. The method of claim 12, wherein, The data usage mode is to use the original text; and processing the plaintext privacy data based on the data usage mode to generate ciphertext result data, including: providing a second public key of the first institution previously stored to the TEE unit; encrypting, by the TEE unit, the plaintext privacy data using the second public key to obtain ciphertext result data.
16. The method of claim 12, wherein, The data usage mode is to use a privacy computing result, and the privacy computing platform stores a privacy computing algorithm corresponding to the data usage mode provided by the first institution; and processing the plaintext privacy data based on the data usage mode to generate ciphertext result data, including: computing and processing the plaintext privacy data using the privacy computing algorithm to obtain a computing result; providing a second public key of the first institution previously stored to the TEE unit; encrypting, by the TEE unit, the computing result using the second public key to obtain ciphertext result data.
17. The method of claim 1, wherein, The data storage end stores privacy data of a plurality of data categories hosted by the target user; the privacy data of the plurality of data categories is sourced from business systems of a plurality of institutions used by the target user and is collected by the user device from the business systems through a trusted collection mode.
18. The method of claim 17, wherein, The plurality of institutions includes a second institution, and the business system of the second institution includes a data interface opened by the second institution to the outside, the data interface being used for users to download data and sign the data; the privacy data of the plurality of data categories that is sourced from the business system is collected by the user device by calling the data interface and is associated with a signature.
19. The method of claim 17, wherein, The plurality of institutions includes a third institution, and the privacy data of the plurality of data categories that is sourced from the business system of the third institution is collected by the user device from the business system through trusted certification technology.
20. A privacy data processing method, comprising: receiving, by a privacy computing platform, an authorization application for privacy data of a target user submitted by a first institution, and sending the authorization application to a user device of the target user; The user equipment generates an authorization statement including information of the first institution after the target user agrees to the authorization application, and sends the authorization statement to the privacy computing platform; The privacy computing platform sends a data acquisition request to a data storage end used by the target user; the data acquisition request includes the authorization statement; The data storage end processes locally saved privacy data of the target user based on the authorization statement, generates ciphertext privacy data, and sends the ciphertext privacy data to the privacy computing platform; The privacy computing platform generates ciphertext result data based on the ciphertext privacy data, and returns the ciphertext result data to the first institution. 21.A privacy data processing apparatus applied to a privacy computing platform, comprising: a receiving unit configured to receive an authorization application for privacy data of a target user submitted by a first institution; a sending unit configured to send the authorization application to a user equipment of the target user; an acquiring unit configured to acquire ciphertext privacy data from a data storage end used by the target user based on an authorization statement sent by the user equipment to the privacy computing platform in response to receiving the authorization statement; the authorization statement includes information of the first institution; a generating unit configured to generate ciphertext result data based on the ciphertext privacy data; the sending unit is further configured to return the ciphertext result data to the first institution.
22. A computer readable storage medium having stored thereon a computer program, wherein, When the computer program is executed in the computer, the computer executes the method in any one of claims 1-19.
23. A computing device comprising a memory and a processor, wherein, The memory stores executable code, and the processor executes the executable code to implement the method in any one of claims 1-19.
Citation Information
Patent Citations
Providing data authorization based on blockchain
US20200169388A1
Blockchain-based data authorization method and apparatus
US20200169407A1
Providing data authorization based on blockchain
US20200177604A1
Trusted hardware-based identity management methods, apparatuses, and devices
US20210397688A1