A method and apparatus for sharing user data
By issuing verifiable credentials, the security risks and data duplication issues in interbank data sharing are resolved, enabling secure and efficient sharing and a unified view of user data, thus meeting the open sharing needs of users.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-19
- Publication Date
- 2026-03-13
AI Technical Summary
In existing technologies, interbank data sharing suffers from limitations in the scope of data sharing, data security risks, and difficulties in connecting with and reusing existing infrastructure. This is especially true when decentralized blockchains and centralized online banking systems are heterogeneous, leading to difficulties in data duplication and maintenance, and making it impossible to proactively initiate data sharing according to user needs.
By issuing verifiable credentials, the business system of the issuer holding user data receives the issuance request, generates and returns the verifiable credential to the target user. When the user requests services from the verifier through the digital identity application, the verifier verifies the credential and responds with authorization, thus achieving secure and efficient sharing of user data.
It enables secure sharing of user data, avoids the risk of data leakage, simplifies data storage construction, reduces data governance costs, and meets users' open sharing requirements.
Smart Images

Figure CN115664759B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to a user data sharing method, apparatus, and storage medium. Background Technology
[0002] Open banking, first proposed in the UK in 2015, refers to a model where banks, under the premise of legal and regulatory guarantees of data security, share data, algorithms, transactions, processes, and other business functions with authorized and trusted third-party service providers and other partners by opening up customer account information systems. Open banking is of great significance for promoting data sharing, encouraging financial innovation, and enhancing socio-economic development. The core of open banking is data sharing, and interbank data sharing is a crucial indicator for evaluating the effectiveness of open banking data sharing.
[0003] Current technologies generally rely on private permissioned blockchains to achieve interbank data sharing. While this enables secure data sharing within the consortium, it also presents challenges such as limitations on the scope of data sharing, data security vulnerabilities, and difficulties in integrating and reusing existing infrastructure. Firstly, current methods typically only grant data owners authorization to access the data, without providing the data directly to them. This prevents data sharing from being initiated proactively by users outside the consortium blockchain. Secondly, while data records are stored on the consortium blockchain with security and privacy protection measures in place, there is still a risk of data leakage after algorithmic breaches. The non-deletable nature of the ledger also poses data security risks. Furthermore, online banking systems, as the gateway to bank customer service, provide the primary functions of data management and service requests. However, their centralized architecture, heterogeneous with decentralized blockchains, means that centralized data cannot be directly used. Some data must be copied and migrated to decentralized storage, leading to redundant construction and wasted investment. Moreover, storing data in multiple locations creates maintenance difficulties and may result in inconsistencies.
[0004] Therefore, how to securely and efficiently achieve user data sharing between financial institutions and other institutions is a technical problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0005] In view of this, the purpose of this invention is to provide a user data sharing method, apparatus, and storage medium that can avoid the risk of user data leakage, meet data security requirements, and simultaneously enable open sharing of user data according to user needs. The specific solution is as follows:
[0006] The first aspect of this application provides a user data sharing method, including:
[0007] The business system of the issuer, which holds the user data of the target user and has the qualification to issue credentials, receives the issuance request for issuing a verifiable credential representing the digital identity of the target user initiated by the digital identity application of the target user assisted by the front end of the business system and prepares the data.
[0008] Upon receiving the issuance request, the business system issues the verifiable credential based on the obtained preparation data and returns the verifiable credential to the target user; wherein, the digital identity includes user data of the target user held by the issuer;
[0009] When the target user requests a service from the verification party through the digital identity application, the verification party obtains the corresponding verifiable credential from the target user based on the service request, and verifies the target user's digital identity by verifying the verifiable credential, and authorizes the service request based on the verification result.
[0010] Optionally, the issuer holding the target user's user data and possessing credential issuance qualifications generates a verifiable credential representing the target user's digital identity based on the target user's issuance request, including:
[0011] The target user logs into the issuer's business system and determines the preset type of the verifiable voucher to be generated through the preset selection interface of the visual interface of the voucher issuance service of the business system; wherein, there is a mapping relationship between the preset type of the verifiable voucher to be generated and the voucher template type in the verifiable data registry built based on distributed ledger technology.
[0012] The business system constructs a verifiable credential view based on the user data of the target user and the determined preset type, displays the verifiable credential view on the visualization interface, and obtains the manual confirmation result of the verifiable credential view returned by the visualization interface.
[0013] Upon receiving the manual confirmation result, the business system performs data preparation by creating a voucher ID for the verifiable voucher to be issued and pre-storing the verifiable voucher data to the voucher database.
[0014] Once the data preparation is complete, a DID connection is established between the target user and the issuer. The target user's digital identity application sends the issuance request to the issuer. The issuer's credential issuance service responds to the issuance request by retrieving the pre-stored user data corresponding to the credential ID from the credential database, generating the verifiable credential, and sending the generated verifiable credential to the target user's digital identity application through the DID connection.
[0015] Optionally, the issuer's certificate issuance service responds to the issuance request by including:
[0016] The credential issuance service retrieves the credential definition corresponding to the credential template consistent with the preset type from the verifiable data registry, generates the verifiable credential of the preset type using the credential definition and the user data of the target user, and updates the credential accumulator in the verifiable data registry.
[0017] Optionally, the user data sharing method further includes:
[0018] The business system obtains the target DID parameter corresponding to the target user from the issuer, and calls the digital identity application corresponding to the target user according to the target DID parameter to establish the DID connection between the target user and the issuer, so as to enable the target user to initiate the issuance request to the issuer;
[0019] After the target user's digital identity application completes mutual authentication and establishes a connection with the issuer's digital identity application based on the target DID parameter, the target user's digital identity application generates the issuance request for the credential ID and sends the issuance request for the credential ID to the issuer's digital identity application. The issuer's digital identity application then forwards the received issuance request to the issuer's credential issuance service.
[0020] Optionally, the step of invoking the digital identity application corresponding to the target user based on the target DID parameter to establish the DID connection between the target user and the issuer includes:
[0021] If the target user logs into the business system on a mobile device, the online banking system logged in on the mobile device will call the target user's digital identity application installed on the mobile device through the mobile device's operating system, based on the target DID parameter, to establish the DID connection between the target user and the issuer.
[0022] If the target user logs into the business system on a PC, the online banking system logged in on the PC will display the target DID parameter in the form of a scannable code on the visual interface, so that the target user can use the target user's digital identity application installed on the mobile device to scan the scannable code and then call the target user's digital identity application installed on the mobile device to establish the DID connection between the target user and the issuer.
[0023] Optionally, before the business system obtains the target DID parameter corresponding to the target user from the issuer, it further includes:
[0024] The business system determines whether the issuer's database stores the target DID parameter corresponding to the target user. If so, it executes the step of obtaining the target DID parameter.
[0025] If not, the target user creates a relationship DID using the corresponding digital identity application and sends the relationship DID to the issuer, so that the issuer can generate the target DID parameter based on the relationship DID and store it in the database.
[0026] Optionally, before the verifier obtains the corresponding verifiable credential from the target user based on the target user's service request, the method further includes:
[0027] The target user sends the service request to the verification party;
[0028] The verifier invokes the digital identity application corresponding to the target user according to the service request and establishes a DID connection between the two parties to send a credential verification request to the target user's digital identity application.
[0029] The digital identity application of the target user controls the target user to respond to the verification request according to preset rules. If the response result indicates that the target user confirms the verification, one or more different verifiable credentials are selected from the verifiable credentials of the target user stored in the application and the corresponding verifiable credentials are encrypted and reconstructed, so as to send the encrypted and reconstructed verifiable credentials to the verification party.
[0030] Optionally, the verifier invokes the digital identity application corresponding to the target user according to the service request and establishes a DID connection between the two parties to send a credential verification request to the target user's digital identity application, including:
[0031] If the verifier provides services on a mobile device, the verifier calls the target user's digital identity application installed on the mobile device through the mobile device's operating system and establishes a DID connection between the verifier and the target user's digital identity application to send a credential verification request to the target user's digital identity application through the DID connection.
[0032] If the verification party provides services on a PC, the verification party will call the digital identity application installed on the mobile device by providing the target user with a way to scan a code on the PC using the digital identity application installed on the mobile device, and establish a DID connection between the verification party and the target user's digital identity application, so as to send a credential verification request to the target user's digital identity application through the DID connection.
[0033] Optionally, the step of verifying the target user's digital identity by verifying verifiable credentials and responding to the service request based on the verification result includes:
[0034] The verifier obtains the public key, credential template, and credential accumulator of the issuing authority from the verifiable data registry built on distributed ledger technology to verify the verifiable credential proof. If the verification is successful and the service access authorization conditions are met, the verifier provides the service corresponding to the service request to the target user.
[0035] A second aspect of this application provides a user data sharing device, comprising:
[0036] The data preparation module is used by the business system of the issuer that holds the user data of the target user and has the qualification to issue credentials to receive the issuance request initiated by the digital identity application of the target user, which is assisted by the front end of the business system, regarding the issuance of a verifiable credential representing the digital identity of the target user, and to prepare the data.
[0037] The credential issuance module is used by the business system to issue the verifiable credential based on the obtained preparation data after receiving the issuance request, and to return the verifiable credential to the target user; wherein, the digital identity includes user data of the target user held by the issuer;
[0038] The credential verification module is used to verify the digital identity of a target user when the target user requests a service from the verification party through the digital identity application. The verification party obtains the corresponding verifiable credential certificate from the target user based on the service request and verifies the target user's digital identity by verifying the verifiable credential certificate, and authorizes the service request based on the verification result.
[0039] A third aspect of this application also provides a computer-readable storage medium storing computer-executable instructions, which, when loaded and executed by a processor, implement the aforementioned user data sharing method.
[0040] In this application, firstly, the business system of an issuer holding user data of the target user and possessing credential issuance qualifications receives an issuance request initiated by the target user's digital identity application, assisted by the business system's front end, regarding the issuance of a verifiable credential representing the target user's digital identity, and prepares the data. Then, upon receiving the issuance request, the business system issues the verifiable credential based on the prepared data and returns the verifiable credential to the target user; wherein, the digital identity includes the target user's user data held by the issuer. When the target user requests a service from a verification party through the digital identity application, the verification party obtains the corresponding verifiable credential certificate from the target user according to the service request, and verifies the target user's digital identity by verifying the verifiable credential certificate, and authorizes the service request based on the verification result. Therefore, the user data sharing method in this application issues user data held by financial institutions as verifiable credentials. Based on this, what flows between financial institutions and other financial institutions or non-financial institutions is the verifiable credential rather than the original data, avoiding the risk of user data leakage and meeting data security requirements. Meanwhile, the issuance and maintenance of verifiable credentials are user-centric, enabling open sharing of user data according to user needs. Attached Figure Description
[0041] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0042] Figure 1 A flowchart of a user data sharing method provided in this application;
[0043] Figure 2 A flowchart illustrating a specific method for issuing verifiable credentials provided in this application;
[0044] Figure 3 This application provides a schematic diagram of a specific verifiable credential issuance process;
[0045] Figure 4 This application provides a specific flowchart of the verifiable credential issuance process.
[0046] Figure 5 A flowchart of a specific verifiable credential verification method provided in this application;
[0047] Figure 6 This application provides a schematic diagram of a specific verifiable credential verification process;
[0048] Figure 7 This is a schematic diagram of a user data sharing device provided in this application. Detailed Implementation
[0049] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0050] Existing technologies generally rely on private permissioned blockchains to achieve interbank data sharing. While this enables secure data sharing within the consortium, it also presents challenges such as limitations on the scope of data sharing, data security risks, and difficulties in integrating and reusing existing infrastructure. Furthermore, it struggles to support privacy protection requirements for raw user data and original transaction data within banks during the development and sharing process. To address these shortcomings, this application provides a user data sharing solution that avoids the risk of user data leakage, meets data security requirements, and enables open sharing of user data according to user needs.
[0051] Figure 1 A flowchart illustrating a user data sharing method provided in an embodiment of this application. See also... Figure 1 As shown, the user data sharing method includes:
[0052] S11: The business system of the issuer, which holds the user data of the target user and has the qualification to issue credentials, receives the issuance request for issuing a verifiable credential representing the digital identity of the target user initiated by the digital identity application of the target user assisted by the front end of the business system, and prepares the data.
[0053] S12: After receiving the issuance request, the business system issues the verifiable credential based on the obtained preparation data and returns the verifiable credential to the target user; wherein, the digital identity includes the user data of the target user held by the issuer.
[0054] In this embodiment, the business system of the issuer, which holds the user data of the target user and has the qualification to issue credentials, first receives a request from the digital identity application of the target user, initiated by the front end of the business system, to issue a verifiable credential representing the digital identity of the target user, and prepares the data. Then, after receiving the issuance request, the business system issues the verifiable credential based on the prepared data and returns the verifiable credential to the target user. The digital identity includes the user data of the target user held by the issuer. In this embodiment, the issuer is a bank, and the bank, as the credential issuer, can have its business system as an online banking system (hereinafter referred to as the business system). The target user is a bank customer, and the user data of the target user is generally the customer's private data, such as KYC data. KYC (Know Your Customer) is a procedure that allows suppliers to verify the identity of participants (users) before a transaction. Accordingly, the verifiable credential is a KYC verifiable credential, and its data format and construction process are based on the W3C Verifiable Credentials Data Model 1.0 specification. This embodiment supports the effective integration of decentralized identity systems with centralized business system KYC processes, ensuring that users' existing business access and service experience remain unchanged while simplifying the issuance process of decentralized verifiable credentials. Furthermore, it eliminates the need for redundant centralized data storage construction; instead, shared data is distributed and stored in the data owner's identity wallet using encrypted credentials. This helps achieve a unified data view, reduces the overall data governance costs for society, and improves data security and privacy protection.
[0055] In one specific embodiment, see Figure 2 As shown, the issuance process of the verifiable credential includes the following steps:
[0056] S21: The target user logs into the issuer's business system and determines the preset type of the verifiable voucher to be generated through the preset selection interface of the visual interface of the voucher issuance service of the business system; wherein, there is a mapping relationship between the preset type of the verifiable voucher to be generated and the voucher template type in the verifiable data registry built based on distributed ledger technology.
[0057] S22: The business system constructs a verifiable credential view based on the user data of the target user and the determined preset type, displays the verifiable credential view on the visualization interface, and obtains the manual confirmation result of the verifiable credential view returned by the visualization interface.
[0058] S23: Upon receiving the manual confirmation result, the business system performs data preparation by creating a voucher ID for the verifiable voucher to be issued and pre-storing the verifiable voucher data to the voucher database.
[0059] S24: Once the data preparation is complete, a DID connection is established between the target user and the issuer. The target user's digital identity application sends the issuance request to the issuer. The issuer's credential issuance service responds to the issuance request by retrieving the pre-stored user data corresponding to the credential ID from the credential database, generating the verifiable credential, and sending the generated verifiable credential to the target user's digital identity application through the DID connection.
[0060] In this embodiment, the specific process is as follows: Figure 3 The target user logs into the issuer's online banking system and determines the preset type of verifiable voucher to be generated through the preset selection interface of the voucher issuance service's visual interface. The preset type of verifiable voucher to be generated has a mapping relationship with the voucher template type in the verifiable data registry built based on distributed ledger technology. The user logs into the online banking system and selects the type of verifiable voucher to be issued through the voucher issuance service interface. Then, the online banking system constructs a verifiable voucher view based on the target user's user data and the determined preset type, and displays the verifiable voucher view on the visual interface. In other words, the online banking system responds to the request, constructs a verifiable voucher view based on the background user data and the requested verifiable voucher type, and displays it to the user through the online banking client.
[0061] The user confirms this so that the online banking system receives the manual confirmation result returned by the visual interface for the verifiable credential view. It's important to note that after user confirmation, the issuing system only prepares the credential data for the credential to be issued. The actual credential issuance request needs to be initiated after the target user's digital identity agent is invoked and a DID connection is established, using relational DID signatures to request credential issuance for the confirmed credential ID. Specifically, upon receiving the manual confirmation result, the business system prepares the data by creating a credential ID for the verifiable credential to be issued and pre-storing the verifiable credential data in the credential database. After the issuance business system completes the preparation of the certificate issuance data, a DID connection needs to be established between the target user and the issuer. The target user's digital identity application submits a certificate issuance request to the issuer regarding the certificate ID to be issued. The issuer's certificate issuance service responds to the certificate issuance request sent by the target user's digital identity application by retrieving the user data corresponding to the requested certificate ID from the pre-stored certificate database to be issued, generating the verifiable certificate, and sending the generated verifiable certificate to the target user's digital identity application through the DID connection.
[0062] In this embodiment, more specifically, the issuing party's business system obtains the certificate specification corresponding to the certificate template consistent with the preset type from the verifiable data registry, and uses the certificate specification and the target user's user data to prepare the data for the verifiable certificate of the preset type, including: pre-storing the prepared data and generating a corresponding certificate ID for the certificate to be issued. When the issuing party's certificate issuance service receives a certificate issuance request from the target user for the certificate ID, the issuing party's certificate issuance service responds to the request to issue the specific certificate and updates the certificate accumulator in the verifiable data registry. That is, after the target user's digital identity application establishes a DID connection with the bank's certificate issuance server (which has deployed the bank's digital identity application), the certificate issuance service responds to the target user's certificate request for a specific certificate ID, and the certificate issuance server constructs the verifiable certificate with a bank signature based on the certificate preparation data associated with the certificate ID. To enable mobile devices to persistently receive messages online, it is common practice to encrypt and send the certificate to a cloud proxy service that acts as a user identity agent. For specific designs, please refer to relevant projects; this embodiment will not elaborate on this. Simultaneously, the voucher accumulator in the verifiable data registry needs to be updated. After issuing or revoking a voucher, the bank should promptly update the voucher accumulator in the ledger to ensure that the voucher-dependent party only needs to access the verifiable data registry ledger when verifying the validity of the voucher, without having to interface with the bank system.
[0063] In this embodiment, the process of establishing a DID connection is as follows: The business system obtains the target DID parameter corresponding to the target user from the issuer, and calls the digital identity application corresponding to the target user according to the target DID parameter to establish the DID connection between the target user and the issuer, enabling the target user to initiate the issuance request to the issuer. Based on this, after the target user's digital identity application and the issuer's digital identity application complete mutual authentication and establish a connection based on the target DID parameter, the target user's digital identity application generates the issuance request for the credential ID and sends the issuance request to the issuer's digital identity application. The issuer's digital identity application then forwards the received issuance request to the issuer's credential issuance service.
[0064] In this embodiment, in order to send the verifiable credential through the DID channel, before obtaining the target DID parameter, the business system also needs to determine whether the issuer's database stores the target DID parameter corresponding to the target user. The target DID parameter is a relation DID parameter. If yes, the step of obtaining the target DID parameter is executed. If no, the target user uses the digital identity application to create a relation DID and sends the relation DID to the issuer, so that the issuer can generate the target DID parameter based on the relation DID and store it in the database. That is, the issuer provides the target user with DID connection invitation information, receives the relation DID parameter created by the target user using the digital identity application and stores it in the database, and returns the relation DID parameter it created to the target user to complete the creation of the relation DID. Specifically, the online banking client requests the backend to provide relevant parameters for calling the digital identity wallet. The online banking backend service checks whether the current online banking user's userID has established a DID connection with the bank (whether there is a relation DID record corresponding to the userID in the database). If a connection has been established, the relation DID parameter is returned; otherwise, a DID connection invitation is returned to the bank. It is understood that when a bank responds to a request for credential issuance for a specific ID and issues the verifiable credential, it has already established a DID connection with its customer. If a DID connection has not been established, such as for the first connection, a relational DID should first be created through the digital identity application, and this DID should be sent to the invitation link address provided by the bank to establish the DID connection. The addressing of the user identity application is based on the entry point address in the previously received user DID data.
[0065] Furthermore, the method of invoking the digital identity application differs for different business systems. If the target user logs into the business system on a mobile device, the online banking system logged in on the mobile device invokes the target user's digital identity application installed on the mobile device through the mobile operating system based on the target DID parameter. If the target user logs into the business system on a PC, the online banking system logged in on the PC displays the target DID parameter in the form of a scannable code on the visual interface, so that the target user can scan the scannable code using the target user's digital identity application installed on the mobile device and then invoke the target user's digital identity application installed on the mobile device. For example, in mobile online banking, the online banking client invokes the local digital identity application App through the mobile device operating system based on the received parameters. If the digital identity application is not installed locally, the user should be prompted to download and install it. In PC online banking clients, the parameters are displayed as a QR code for the user's digital identity application App to scan and connect.
[0066] In this embodiment, the above-mentioned verifiable credential issuance process is implemented based on a distributed identity credential circulation model and peer-to-peer communication (DID communication) based on digital identity applications.
[0067] Therefore, Figure 4 To and Figure 3 The corresponding shared architecture diagram is provided, but verifying the identity of the credential requester as an existing genuine bank customer requires relying on the existing centralized bank customer management system. Users log in through their online banking to request specific credential issuance services, enabling the local loading of the user's digital identity application and its internal connection with the bank's issuing system. The bank accepts credential issuance requests through its online banking system, performs data preparation before credential issuance, and establishes the association between the existing bank customer's userID and their distributed digital identity (DID), providing a best practice path for banks to conduct decentralized digital services based on centralized user data. Furthermore, banks can also provide users with more value-added services based on personal data by requesting users to share credentials issued from other industries or financial institutions.
[0068] S13: When the target user requests a service from the verification party through the digital identity application, the verification party obtains the corresponding verifiable credential from the target user according to the target user's service request, and verifies the target user's digital identity by verifying the verifiable credential, and authorizes the service request based on the verification result.
[0069] Based on the above embodiments, see Figure 5 As shown, step S13 specifically includes:
[0070] S31: The target user sends the service request to the verification party.
[0071] S32: The verifier invokes the digital identity application corresponding to the target user according to the service request and establishes a DID connection between the two parties to send a credential verification request to the target user's digital identity application.
[0072] In this embodiment, the user browses the application service URL or App, selects the relevant application service, and requests access authorization, i.e., sends a service request to the verification party. Regarding the process of the verification party calling the digital identity application corresponding to the target user based on the service request, if the verification party provides the service on a mobile device, the verification party calls the target user's digital identity application installed on the mobile device through the mobile device's operating system and establishes a DID connection between the verification party and the target user's digital identity application to send a credential verification request to the target user's digital identity application through this DID connection. If the verification party provides the service on a PC, the verification party provides the target user with a method to call the digital identity application installed on the mobile device by scanning a QR code on the PC, and establishes a DID connection between the verification party and the target user's digital identity application to send a credential verification request to the target user's digital identity application through this DID connection. If service authorization is provided based on specific user attributes, the application server establishes a DID connection with the digital identity application that calls it and sends a verification request for the relevant attribute credentials.
[0073] S33: The digital identity application of the target user controls the target user to respond to the verification request according to preset rules. If the response result indicates that the target user confirms the verification, one or more different verifiable credentials are selected from the verifiable credentials of the target user stored in the application and the corresponding verifiable credentials are encrypted and reconstructed, so as to send the encrypted and reconstructed verifiable credentials to the verification party.
[0074] In this embodiment, the target user's digital identity application (agent) receives a request for verifiable credentials. The digital identity application controls the target user to respond to the verification request according to preset rules. For example, if the user agrees to provide verifiable credentials, they should provide a PIN or fingerprint to prove their consent. Then, the application selects one or more different verifiable credentials from the target user's stored verifiable credentials and encrypts and reconstructs them to send the encrypted and reconstructed verifiable credentials to the verifier. The digital identity application calls the digital identity wallet interface to construct the verifiable credentials. The verifiable credentials consist of one or more verifiable credentials in the wallet, with the holder's signature information attached. When privacy protection is required, the verifiable credentials can be constructed based on anonymous credentials. Finally, the encrypted and reconstructed verifiable credentials are sent to the verifier through the DID connection established between the two digital identity applications. To ensure information security, the verifiable credentials should consider data encryption based on the keys of both parties and envelope encryption based on the router key.
[0075] S34: The verifier obtains the public key, credential template, and credential accumulator of the issuing authority from the verifiable data registry built on distributed ledger technology to verify the verifiable credential certificate. If the verification is successful and the service access authorization conditions are met, the verifier provides the service corresponding to the service request to the target user.
[0076] In this embodiment, the verifier obtains the public key, credential template, and credential accumulator of the issuing authority from a verifiable data registry built on distributed ledger technology to verify the verifiable credential certificate. If the verification passes and the service access authorization conditions are met, the service corresponding to the service request is provided to the target user. That is, the application server receives the verifiable credential certificate, verifies it, and determines whether the service authorization conditions are met based on the verification result. If met, data preparation is performed, and the data is returned to the service frontend, supporting the corresponding service access redirection; if not met, a message "Conditions not met, service rejected" is displayed on the frontend page. For details of the above process, please refer to [reference needed]. Figure 6 As shown, customers hold verifiable credentials and share these credentials as needed in other business scenarios to achieve the goal of open banking KYC data sharing that meets data security and privacy protection requirements.
[0077] As can be seen, in this embodiment, the business system of an issuer holding user data of the target user and possessing credential issuance qualifications first receives an issuance request initiated by the digital identity application of the target user, assisted by the front end of the business system, regarding the issuance of a verifiable credential representing the target user's digital identity, and prepares the data. Then, upon receiving the issuance request, the business system issues the verifiable credential based on the prepared data and returns the verifiable credential to the target user; wherein, the digital identity includes the user data of the target user held by the issuer. When the target user requests a service from a verification party through the digital identity application, the verification party obtains the corresponding verifiable credential certificate from the target user according to the service request, and verifies the target user's digital identity by verifying the verifiable credential certificate, and authorizes the service request based on the verification result. The user data sharing method in this application issues user data held by financial institutions as verifiable credentials. Based on this, what flows between financial institutions and other financial institutions or non-financial institutions is the verifiable credential rather than the original data, avoiding the risk of user data leakage and meeting data security requirements. Meanwhile, the issuance and maintenance of verifiable credentials are user-centric, enabling open sharing of user data according to user needs.
[0078] See Figure 7 As shown in the figure, this application also discloses a user data sharing device, including:
[0079] The data preparation module 11 is used by the business system of the issuer that holds the user data of the target user and has the qualification to issue credentials to receive the issuance request initiated by the digital identity application of the target user by the front end of the business system to issue a verifiable credential representing the digital identity of the target user and to prepare the data.
[0080] The credential issuance module 12 is used by the business system to issue the verifiable credential based on the obtained preparation data after receiving the issuance request, and to return the verifiable credential to the target user; wherein, the digital identity includes user data of the target user held by the issuer;
[0081] The credential verification module 13 is used to, when the target user requests a service from the verification party providing the service through the digital identity application, obtain the corresponding verifiable credential certificate from the target user according to the target user's service request, and verify the target user's digital identity by verifying the verifiable credential certificate, so as to authorize the service request based on the verification result.
[0082] As can be seen, in this embodiment, the business system of an issuer holding user data of the target user and possessing credential issuance qualifications first receives an issuance request initiated by the digital identity application of the target user, assisted by the front end of the business system, regarding the issuance of a verifiable credential representing the target user's digital identity, and prepares the data. Then, upon receiving the issuance request, the business system issues the verifiable credential based on the prepared data and returns the verifiable credential to the target user; wherein, the digital identity includes the user data of the target user held by the issuer. When the target user requests a service from a verification party through the digital identity application, the verification party obtains the corresponding verifiable credential certificate from the target user according to the service request, and verifies the target user's digital identity by verifying the verifiable credential certificate, and authorizes the service request based on the verification result. The user data sharing method in this application issues user data held by financial institutions as verifiable credentials. Based on this, what flows between financial institutions and other financial institutions or non-financial institutions is the verifiable credential rather than the original data, avoiding the risk of user data leakage and meeting data security requirements. Meanwhile, the issuance and maintenance of verifiable credentials are user-centric, enabling open sharing of user data according to user needs.
[0083] In some specific embodiments, the user data sharing device further includes:
[0084] The login module is used for the target user to log in to the issuer's business system and determine the preset type of the verifiable voucher to be generated through the preset selection interface of the visual interface of the voucher issuance service of the business system; wherein, there is a mapping relationship between the preset type of the verifiable voucher to be generated and the voucher template type in the verifiable data registry built based on distributed ledger technology.
[0085] The view confirmation module is used by the business system to construct a verifiable credential view based on the user data of the target user and the determined preset type, to display the verifiable credential view on the visualization interface, and to obtain the manual confirmation result of the verifiable credential view returned by the visualization interface.
[0086] In some specific embodiments, the data preparation module 11 is specifically used to, when the manual confirmation result is obtained, the business system performs data preparation to create a voucher ID for the verifiable voucher to be issued and to pre-store the verifiable voucher data to be issued into the voucher database.
[0087] In some specific embodiments, the credential issuance module 12 is specifically used to establish a DID connection between the target user and the issuer after the data preparation is completed. The target user's digital identity application sends the issuance request to the issuer. The issuer's credential issuance service responds to the issuance request by retrieving the pre-stored user data corresponding to the credential ID from the credential database, generating the verifiable credential, and sending the generated verifiable credential to the target user's digital identity application through the DID connection.
[0088] In some specific embodiments, the credential issuance module specifically includes:
[0089] The credential definition acquisition unit is used by the credential issuance service to acquire the credential definition corresponding to the credential template that is consistent with the preset type from the verifiable data registry.
[0090] A credential generation unit is used by the credential issuance service to generate the verifiable credential of the preset type using the credential definition and the user data of the target user.
[0091] An update unit is used by the credential issuance service to update the credential accumulator in the verifiable data registry.
[0092] In some specific embodiments, the user data sharing device further includes:
[0093] The judgment module is used by the business system to determine whether the issuer's database stores the target DID parameter corresponding to the target user. If so, the step of obtaining the target DID parameter is executed.
[0094] A generation module is created, which, if not, allows the target user to create a relationship DID using the digital identity application and send the relationship DID to the issuer, so that the issuer can generate the target DID parameters based on the relationship DID and store them in the database;
[0095] The connection establishment module is used by the business system to obtain the target DID parameter corresponding to the target user from the issuer, and call the digital identity application corresponding to the target user according to the target DID parameter to establish the DID connection between the target user and the issuer, so as to enable the target user to initiate the issuance request to the issuer;
[0096] The credential issuance request generation module is used to generate an issuance request for the credential ID after the target user's digital identity application completes mutual authentication and establishes a connection with the issuer's digital identity application based on the target DID parameter, and sends the issuance request for the credential ID to the issuer's digital identity application. The issuer's digital identity application then forwards the received issuance request to the issuer's credential issuance service.
[0097] In some specific embodiments, the connection establishment module specifically includes:
[0098] The first calling unit is configured to, if the target user logs into the online banking system on a mobile device, call the digital identity application of the target user installed on the mobile device through the mobile device's operating system according to the target DID parameter, so as to establish the DID connection between the target user and the issuer.
[0099] The second calling unit is configured to, if the target user logs into the online banking system on a PC, display the target DID parameter in the form of a scannable code on the visual interface, so that the target user can scan the scannable code using the target user's digital identity application installed on the mobile device and then call the target user's digital identity application installed on the mobile device to establish the DID connection between the target user and the issuer.
[0100] In some specific embodiments, the user data sharing device further includes:
[0101] The service request module is used for the target user to send the service request to the verification party;
[0102] The verification request module is used by the verification party to call the digital identity application corresponding to the target user according to the service request and establish a DID connection between the two parties, so as to send a credential verification request to the digital identity application of the target user;
[0103] The credential reconstruction module is used to control the target user's digital identity application to respond to the verification request according to preset rules. If the response result indicates that the target user confirms the verification, it selects one or more different verifiable credentials from the verifiable credentials of the target user stored in its own database and performs encrypted reconstruction on the corresponding verifiable credential proof, so as to send the encrypted and reconstructed verifiable credential proof to the verification party.
[0104] In some specific embodiments, the verification request module specifically includes:
[0105] The first verification request unit is configured to, if the verification party provides services on a mobile device, call the digital identity application of the target user installed on the mobile device through the mobile device's operating system, and establish a DID connection between the verification party and the target user's digital identity application, so as to send a credential verification request to the target user's digital identity application through the DID connection.
[0106] The second verification request unit is configured to, if the verification party provides services on a PC, enable the target user to scan a QR code on the PC using the digital identity application installed on the mobile device, and establish a DID connection between the verification party and the target user's digital identity application to send a credential verification request to the target user's digital identity application through the DID connection.
[0107] In some specific embodiments, the credential verification module 12 is specifically used by the verifier to obtain the public key of the issuing authority of the verifiable credential, the credential template, and the credential accumulator from the verifiable data registry built based on distributed ledger technology to verify the verifiable credential proof. If the verification is successful and the service access authorization conditions are met, the verifier provides the target user with the service corresponding to the service request.
[0108] Furthermore, this application also discloses a storage medium storing a computer program, which, when loaded and executed by a processor, implements the user data sharing method steps disclosed in any of the foregoing embodiments.
[0109] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.
[0110] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0111] The user data sharing method, apparatus, and storage medium provided by the present invention have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A user data sharing method, characterized by, The application relates to a user data sharing method and system. A business system of an issuer holding user data of a target user and having a credential issuing qualification receives an issuing request for issuing a verifiable credential representing a digital identity of the target user initiated by a digital identity application of the target user assisted by a front end of the business system and performs data preparation; The business system issues the verifiable credential based on the obtained prepared data after receiving the issuing request, and returns the verifiable credential to the target user; wherein the digital identity contains the user data of the target user held by the issuer; the data format and construction process of the verifiable credential are based on the W3C verifiable credential data model specification; When the target user requests a service through the digital identity application to a verifying party providing the service, the verifying party obtains the corresponding verifiable credential proof of the target user according to the service request of the target user, and verifies the digital identity of the target user by verifying the verifiable credential proof to authorize the service request according to the verification result; The user data sharing method further comprises: The target user logs in the business system of the issuer, and determines a preset type of a verifiable credential to be generated through a preset selection interface of a visual interface of a credential issuing service of the business system; wherein the preset type of the verifiable credential to be generated has a mapping relationship with a credential template type in a verifiable data registry constructed based on a distributed ledger technology; The business system constructs a verifiable credential view according to the user data of the target user and the determined preset type, displays the verifiable credential view on the visual interface, and obtains an artificial confirmation result returned by the visual interface for the verifiable credential view; When the artificial confirmation result is obtained, the business system creates a credential ID for the verifiable credential to be issued and pre-stores verifiable credential data to be issued in a credential database for data preparation; When the data preparation is completed, a DID connection is established between the target user and the issuer, the digital identity application of the target user sends the issuing request to the issuer, and the credential issuing service of the issuer responds to the issuing request to generate the verifiable credential by extracting the pre-stored user data corresponding to the credential ID from the credential database, and sends the generated verifiable credential to the digital identity application of the target user through the DID connection.
2. The user data sharing method of claim 1, wherein, The credential issuing service of the issuer responds to the issuing request, comprising: The credential issuing service obtains a credential definition corresponding to a credential template consistent with the preset type from the verifiable data registry, generates the verifiable credential of the preset type by using the credential definition and the user data of the target user, and updates a credential accumulator in the verifiable data registry.
3. The user data sharing method of claim 1, wherein, Further comprising: The business system obtains a target DID parameter corresponding to the target user from the issuer, and calls the digital identity application corresponding to the target user according to the target DID parameter to establish the DID connection between the target user and the issuer, so that the target user initiates the issuance request to the issuer. After the digital identity application of the target user and the digital identity application of the issuer complete mutual authentication and establish a connection based on the target DID parameter, the digital identity application of the target user generates the issuance request of the credential ID, and sends the issuance request of the credential ID to the digital identity application of the issuer. The digital identity application of the issuer forwards the received issuance request to the credential issuance service of the issuer.
4. The user data sharing method of claim 3, wherein, The calling of the digital identity application corresponding to the target user according to the target DID parameter to establish the DID connection between the target user and the issuer comprises: If the target user logs in the business system on a mobile terminal, the business system logged in on the mobile terminal calls the digital identity application of the target user installed on the mobile terminal according to the target DID parameter through a mobile terminal operating system to establish the DID connection between the target user and the issuer. If the target user logs in the business system on a PC terminal, the business system logged in on the PC terminal displays the target DID parameter in the form of a scannable code on the visual interface, so that the target user calls the digital identity application of the target user installed on the mobile terminal after scanning the scannable code by using the digital identity application of the target user installed on the mobile terminal to establish the DID connection between the target user and the issuer.
5. The user data sharing method of claim 3, wherein, Before the business system obtains the target DID parameter corresponding to the target user from the issuer, the method further comprises: The business system judges whether the database of the issuer stores the target DID parameter corresponding to the target user. If yes, the step of obtaining the target DID parameter is performed; If no, the target user creates a relationship DID by using the corresponding digital identity application and sends the relationship DID to the issuer, so that the issuer generates the target DID parameter according to the relationship DID and stores it in the database.
6. The user data sharing method of claim 3, wherein, Before the verification party obtains the corresponding verifiable credential proof from the target user according to the service request of the target user, the method further comprises: The target user sends the service request to the verification party; The verification party calls the digital identity application corresponding to the target user according to the service request and establishes a DID connection between the two parties to send a credential proof verification request to the digital identity application of the target user; The digital identity application of the target user controls the target user to respond to the verification request according to a preset rule, and if the response result represents that the target user confirms the verification, one or more different verifiable credentials are selected from the verifiable credentials of the target user stored by itself, and the corresponding verifiable credential proof is encrypted and reconstructed to send the encrypted and reconstructed verifiable credential proof to the verification party.
7. The user data sharing method of claim 6, wherein, The verification party calls the digital identity application corresponding to the target user according to the service request and establishes DID connection between the two parties to send a credential proof verification request to the digital identity application of the target user, including: If the verification party provides services on a mobile terminal, the verification party calls the digital identity application of the target user installed on the mobile terminal through the mobile terminal operating system, and establishes DID connection between the verification party and the digital identity application of the target user to send a credential proof verification request to the digital identity application of the target user through the DID connection; If the verification party provides services on a PC terminal, the verification party calls the digital identity application installed on the mobile terminal by providing the target user with a code scanning method on the PC terminal using the digital identity application installed on the mobile terminal, and establishes DID connection between the verification party and the digital identity application of the target user to send a credential proof verification request to the digital identity application of the target user through the DID connection.
8. The user data sharing method according to any one of claims 1 to 7, characterized in that, The digital identity of the target user is verified by verifying the verifiable credential proof, and the service request is responded according to the verification result, including: The verification party obtains the public key of the verifiable credential issuing authority, the credential template and the credential accumulator from the verifiable data registry constructed based on distributed ledger technology, verifies the verifiable credential proof, and if the verification is passed and the service access authorization condition is met, provides the target user with a service corresponding to the service request.
9. A user data sharing apparatus, characterized by comprising: Including: A data preparation module, a business system of an issuing party having user data of a target user and having a credential issuing qualification receives a signing request initiated by a digital identity application of the target user assisted by a front end of the business system and performs data preparation; A credential signing module, the business system signs the verifiable credential based on the obtained prepared data after receiving the signing request, and returns the verifiable credential to the target user; wherein the digital identity contains user data of the target user held by the issuing party; the data format and construction process of the verifiable credential are based on the verifiable credential data model specification of W3C; The credential verification module is configured to, when the target user requests a service from a verification party providing the service through the digital identity application, acquire corresponding verifiable credential proofs from the target user according to a service request of the target user, and verify the digital identity of the target user by verifying the verifiable credential proofs to authorize the service request according to a verification result. The login module is configured to log in the target user to the business system of the issuing party, and determine a preset type of a verifiable credential to be generated through a preset selection interface of a visual interface of a credential issuing service of the business system. The preset type of the verifiable credential to be generated has a mapping relationship with a credential template type in a verifiable data registry constructed based on a distributed ledger technology. The view confirmation module is configured to construct a verifiable credential view according to the user data of the target user and the determined preset type, display the verifiable credential view on the visual interface, and acquire an artificial confirmation result returned by the visual interface for the verifiable credential view. The data preparation module is configured to, when the artificial confirmation result is acquired, create a credential ID for the verifiable credential to be issued, and pre-store verifiable credential data to be issued in a credential database. The credential issuing module is configured to, when the data preparation is completed, establish a DID connection between the target user and the issuing party, send the issuing request to the issuing party through the digital identity application of the target user, and respond to the issuing request through the credential issuing service of the issuing party to generate the verifiable credential by extracting the user data corresponding to the credential ID from the credential database, and send the generated verifiable credential to the digital identity application of the target user through the DID connection.
10. A computer-readable storage medium, characterized in that, A computer readable storage medium for storing computer executable instructions, which are loaded and executed by a processor to implement the user data sharing method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Data sharing method and system and computer readable storage medium
CN114491449A
Decentralized identity certificate verification method and device, and electronic equipment
CN114666168A