A data product trading method that supports privacy protection and trusted supervision

Through data blinding and encryption technology, combined with zero-knowledge proof algorithm, the problems of privacy protection and trusted supervision in data transactions are solved, and the privacy protection and trusted supervision of rights and interests of data products and derivative services are realized.

CN116188008BActive Publication Date: 2025-09-23UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310084106.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-09
Publication Date
2025-09-23
Estimated Expiration
2043-02-09

AI Technical Summary

Technical Problem

Existing technologies cannot effectively protect privacy in data transactions, and cannot support proof of authenticity of data sources during transactions of data-derived services, resulting in infringement of the interests of data owners and unreliable trading platforms.

Method used

Through data blinding and encryption technology, equity tags are generated and signed, and verified using the signature generated by the trading platform. Combined with the zero-knowledge proof algorithm, data privacy protection and trusted supervision of transactions are ensured.

Benefits of technology

It supports privacy protection of data products and derivative services without leaking original data, ensures credible supervision of rights and interests during the transaction process, and protects the interests of both parties to the transaction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116188008B_ABST
    Figure CN116188008B_ABST
Patent Text Reader

Abstract

The present invention discloses a data product trading method that supports privacy protection and trusted supervision. The method is applied to a data trading system, which includes a trading platform, a data product owner, a data product purchaser, and a derivative service purchaser. The method includes three stages: the first stage is a system initialization stage, the second stage is an original data trading stage, and the third stage is a derivative service data trading stage. This method is based on a zero-knowledge proof algorithm. The data product purchaser can prove the source of the derivative service data without leaking the original data of the data product, thereby enabling the data trading system to support the derivative service data transaction. In addition, the transaction data and the transaction process of the derivative service data both support privacy protection. Under the premise that the transaction data and the derivative service data are kept confidential to the third-party trading platform, the third-party trading platform can achieve trusted supervision of the rights and interests of both parties to the transaction.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of data transaction technology, and specifically relates to a data product transaction method that supports privacy protection and trusted supervision. Background Art

[0002] As the digital economy enters a new era driven by data resources, promoting data transactions is an inevitable requirement for innovative economic and social development. Because data transactions carry complex rights and rights holders, data transaction regulation is essential. In practice, the most widely deployed data transaction regulation model relies on data trading platforms.

[0003] Specifically, the two parties to a transaction negotiate their rights and interests and generate a rights and interests tag. The seller sends the data and rights and interests tag to the trading platform for transaction verification. The trading platform, as the supervisor, signs the transaction data and rights and interests tag to authorize the transaction. During the transaction, if the rights and interests of a participant are infringed, the participant can use the signature to prove the validity of the transaction to the trading platform and file a complaint, requesting the platform's assistance in protecting their rights and interests in the transaction.

[0004] However, the above method has the following problems. First, it fails to protect the privacy of transaction data. The trading platform has access to the plaintext of all transaction data. If the trading platform engages in malicious behavior, such as illegal use of transaction data, the interests of data owners will be harmed. Furthermore, it cannot support data derivative service transactions. When the purchaser of a data product needs to provide derivative services of the data product to others, it cannot prove the authenticity of the data product's source to the derivative service purchaser without disclosing the original data product.

[0005] It can be seen that there is an urgent need to propose solutions to support the privacy protection of the original data of data products and their derivative services during transactions, as well as to ensure the trustworthy supervision of data trading platforms. Summary of the Invention

[0006] The purpose of the present invention is to overcome one or more deficiencies of the prior art and to provide a data product trading method that supports privacy protection and trusted supervision.

[0007] The object of the present invention is achieved through the following technical solutions:

[0008] A data product trading method that supports privacy protection and trusted supervision is applied to a data trading system. The data trading system includes a trading platform, a data product owner, and a data product buyer. The trading platform is connected to the data product owner and the data product buyer respectively, and the data product owner is connected to the data product buyer.

[0009] The method comprises the following steps:

[0010] S100. Initialize the data transaction system;

[0011] S200. The data product owner and the data product buyer negotiate and determine the rights label of the transaction data, where the transaction data is the original data of the data product;

[0012] S300. The data product owner blinds the transaction data and sends a first parameter set for transaction authentication to the trading platform. The first parameter set includes the equity tag of the transaction data and the blinded transaction data. The trading platform then generates a first signature for the first parameter set and sends the first signature to the data product owner.

[0013] S400. The data product owner verifies whether the first signature is correct. If so, the first signature is deblinded to obtain a second signature. The second signature is a joint signature of the transaction data and the equity tag of the transaction data.

[0014] S500. The data product owner encrypts the transaction data based on the selected first secret parameter to generate ciphertext of the transaction data and discloses first transaction information, which includes the ciphertext of the transaction data, the equity tag of the transaction data, and the second signature.

[0015] S600. After the data product purchaser pays the data product owner the amount for purchasing the transaction data, the data product owner sends the transaction data and the first secret parameter to the data product purchaser. The data product purchaser verifies whether the received transaction data is correct based on the ciphertext of the obtained transaction data and the first secret parameter. If so, the transaction is completed, and the trading platform stores the first transaction information.

[0016] Preferably, the data trading system further includes a derivative service buyer, which is in communication with the data product buyer and the trading platform respectively, and further includes the following steps after S600:

[0017] S700. The data product buyer and the derivative service buyer negotiate to determine the equity tag of the derivative service data. The equity tag of the derivative service data includes the derivative service function of the transaction data, wherein the derivative service data is the derivative service data of the transaction data generated based on the derivative service function;

[0018] S800. The data product purchaser blinds the derivative service data and sends a second parameter set for transaction authentication to the trading platform. The second parameter set includes the equity tag of the derivative service data and the blinded derivative service data. The trading platform then generates a third signature for the second parameter set and sends the third signature to the data product purchaser.

[0019] S900. The data product purchaser verifies whether the third signature is correct. If so, the third signature is deblinded to obtain a fourth signature. The fourth signature is a joint signature of the derived service data and the equity tag of the derived service data.

[0020] S1000. The data product purchaser encrypts the derivative service data based on the selected second secret parameter to generate ciphertext of the derivative service data, and discloses second transaction information, which includes the ciphertext of the derivative service data, the equity tag of the transaction data, the equity tag of the derivative service data, and a fourth signature;

[0021] S1100. The data product buyer proves the authenticity of the transaction data source to the derivative service buyer based on a zero-knowledge proof algorithm;

[0022] S1200. If the data product purchaser proves successful to the derivative service purchaser, the derivative service purchaser accepts the transaction and pays the data product purchaser the amount for purchasing the derivative service data;

[0023] S1300. The data product purchaser sends the derivative service data and the second secret parameter to the derivative service purchaser. The derivative service purchaser verifies whether the received derivative service data is correct based on the ciphertext of the obtained derivative service data and the second secret parameter. If so, the transaction is completed and the second transaction information is stored by the trading platform.

[0024] Preferably, the step S100 is as follows:

[0025] The system is initialized according to the selected security parameter l, and the public parameter set PP = {p, g, G, G T , e, H1, H2, H3}, where p is the first prime number, G and G T are all cyclic groups of order p, g is a generator of G, e is a bilinear map, and e: G×G→G T , H1 is the first secure hash function, and H1: {0, 1} * →G, H2 is the second secure hash function, and H2: {0, 1} * →{0, 1} 2l , H3 is the third secure hash function, and H3: {0, 1} * →{0, 1} l ;

[0026] Trading Platform Randomly select the largest prime number and the second largest prime number And the first prime number and the second largest prime number satisfy And calculate and publish its own public key Head Then calculate your own private key based on the public key and

[0027] Data product owner Randomly select the third largest prime number and the fourth largest prime number And the third largest prime number and the fourth largest prime number satisfy And calculate and publish its own public key and

[0028] Data product buyers Randomly select the fifth largest prime number and the sixth largest prime number And the fifth largest prime number and the sixth largest prime number satisfy And calculate and publish its own public key and

[0029] Preferably, the S300 is specifically:

[0030] Data product owner Select the first random number r1, and r1∈Z p , where Z p is the residual group modulo p;

[0031] Data product owner Blind the transaction data m1 to generate blinded transaction data and

[0032] Data product owner Send the first parameter set for transaction authentication To the trading platform Where tag1 is the equity tag of transaction data m1;

[0033] Trading Platform Calculate the first parameter set First signature And the first signature Sent to the data product owner, where

[0034] Preferably, the step S400 is specifically as follows:

[0035] Data product owner Verify whether the first equation is true. If the first equation is true, then sign the first After deblinding, the second signature σ1 is obtained, where the first equation is established to indicate that the first signature Correct, the first equation is Second signature

[0036] Preferably, the S500 is specifically:

[0037] Data product owner Encrypt transaction data m1 and generate the ciphertext of transaction data m1 after encryption in is the selected first secret parameter, and Model The simplified residual group;

[0038] Data product owner Public first transaction information

[0039] Preferably, the step S600 specifically includes:

[0040] Data product buyers To data product owners After paying the amount to purchase transaction data m1, the data product owner The transaction data m1 and the first secret parameter Sent to data product buyers

[0041] Data product buyers Verify whether the second equation is true. If the second equation is true, the transaction is completed. If the second equation is true, it means that the transaction data m1 is correct. The second equation is

[0042] Trading Platform Store the first transaction information

[0043] Preferably, the derivative service function is a polynomial, and the polynomial is expressed as f(x)=a0+a1x+…+a n x n ; The derived service data m2 = f(m1);

[0044] The S800 specifically includes: the data product purchaser Select a second random number r2, and r2∈Z p ;Data product buyers Blind the derived service data m2 to generate blinded derived service data and Data product buyers Send the second parameter set for transaction authentication To the trading platform Among them, tag2 is the equity tag of the derivative service data m2; trading platform Calculate the second parameter set The third signature And the third signature Sent to data product buyers in

[0045] The S900 specifically includes: data product purchaser Verify whether the third equation is true. If the third equation is true, then sign the third After deblinding, the fourth signature σ2 is obtained, where the third equation is established to indicate the third signature Correct, the third equation is Fourth Signature

[0046] The S1000 specifically includes: data product purchaser Encrypt the derived service data m2 and generate the ciphertext of the derived service data m2 after encryption in is the third random number, and represents the selected second secret parameter, 2≤i≤n; the data product purchaser The second transaction information {c2, tag1, tag2, σ2} is made public.

[0047] Preferably, the S1100 specifically includes:

[0048] Data product buyers Select the relationship you want to prove

[0049] For each i∈[3,n], the data product buyer Select the first intermediate parameter m i,3 , the fourth random number and the fifth random number r i-1,3 ,in

[0050] Data product buyers Calculate the first intermediate parameter m i,3 Ciphertext and the first data product Ciphertext And the first intermediate parameter m i,3 The ciphertext c i,3 and the first data product Ciphertext Sent to the buyer of derivative services

[0051] Derivative service buyers Randomly select the second intermediate parameter a, and satisfy |a|=1, and send the second intermediate parameter a to the data product buyer

[0052] Data product buyers Calculate the third intermediate parameter Fourth intermediate parameter and the fifth intermediate parameter And send the third intermediate parameter, the fourth intermediate parameter and the fifth intermediate parameter to the derivative service buyer

[0053] Derivative service buyers Verify whether the fourth and fifth equations are both true. If so, the data product buyer To the purchaser of derivative services Successfully proved the relationship R that needs to be proved, and the derivative service buyer Accept the transaction, where the fourth equation is The fifth equation is Otherwise, the derivative service buyer No trade accepted.

[0054] Preferably, the step S1200 specifically includes: if the data product purchaser To the purchaser of derivative services If the relationship R that needs to be proved is successfully proved, the service buyer will be derived Accept the transaction and send it to the data product buyer The amount paid for purchasing the derivative service data m2;

[0055] The S1300 specifically includes: The derived service data m2 and the second secret parameter Sent to the buyer of derivative services Derivative service buyers Verify whether the sixth equation is true. If so, the transaction is completed. The sixth equation The sixth equation is true, indicating that the received derivative service data m2 is correct; the trading platform The second transaction information {c2, tag1, tag2, σ2} is stored.

[0056] The beneficial effects of the present invention are:

[0057] (1) The data product owner sends the equity tag and the blinded transaction data (the original data of the data product) to the trading platform to request transaction authentication. The trading platform signs the equity tag and the blinded transaction data. After verifying the validity of the signature sent by the trading platform, the data product owner deblinds the signature to obtain the transaction signature (second signature) of the transaction data and the equity tag in this transaction, and publicly discloses the first transaction information containing the ciphertext of the transaction data, the equity tag of the transaction data and the second signature. The trading platform stores the first transaction information for transaction evidence. The data product buyer completes the transaction after verifying the validity of the transaction data. Based on this, the transaction process of the transaction data supports privacy protection. On the premise that the transaction data is kept confidential to the third-party trading platform, the third-party trading platform realizes the trusted supervision of the rights and interests of both parties to the transaction.

[0058] (2) The data product purchaser sends the equity tag and the blinded derivative service data (the result data after the original data is analyzed) to the trading platform to request transaction authentication. The trading platform signs the equity tag and the blinded derivative service data. After verifying the validity of the signature sent by the trading platform, the data product purchaser deblinds the signature to obtain the transaction signature (the fourth signature) of the derivative service data and the equity tag in this transaction, and publicly discloses the second transaction information containing the ciphertext of the derivative service data, the equity tag of the transaction data, the equity tag of the derivative service data and the fourth signature. The trading platform stores the second transaction information for transaction evidence. In addition, based on the zero-knowledge proof algorithm, the data product purchaser realizes the proof of the source of the derivative service data without disclosing the original data of the data product. Based on this, the data trading system supports the transaction of derivative service data, and the derivative service data supports privacy protection during the transaction process. Under the premise that the derivative service data is kept confidential to the third-party trading platform, the third-party trading platform realizes the trusted supervision of the rights and interests of both parties to the transaction. BRIEF DESCRIPTION OF THE DRAWINGS

[0059] Figure 1 This is a flowchart of a data product trading method that supports privacy protection and trusted supervision, implemented in Example 1;

[0060] Figure 2 This is a flowchart of the data product trading method that supports privacy protection and trusted supervision implemented in Example 2. DETAILED DESCRIPTION

[0061] The following will clearly and completely describe the technical solutions of the present invention in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work shall fall within the scope of protection of the present invention.

[0062] Example 1

[0063] This embodiment provides a data product trading method that supports privacy protection and trusted oversight. The method is applied to a data trading system, which is used to trade data products. Generally, data products include raw data used for trading and derived service data derived from analysis and processing of the raw data. The data trading system includes data product owners, data product buyers, and a trading platform. The trading platform is in communication with the data product owners and buyers, respectively. The data product owners and buyers are in communication with each other.

[0064] like Figure 1 As shown, a data product transaction method that supports privacy protection and trusted supervision includes:

[0065] Phase 1: System initialization phase;

[0066] Phase 2: Raw data transaction phase.

[0067] Specifically, the first stage includes the following steps:

[0068] S100. Initialize the data transaction system.

[0069] A specific implementation step of step S100 is:

[0070] S101. Initialize the system according to the selected security parameter l, and generate a public parameter set PP = {p, g, G, G T , e, H1, H2, H3}, where p is the first prime number, G and G T are all cyclic groups of order p, g is a generator of G, e is a bilinear map, and e: G×G→G T , H1 is the first secure hash function, and H1: {0, 1} * →G, H2 is the second secure hash function, and H2: {0, 1} * →{0, 1} 2l , H3 is the third secure hash function, and H3: {0, 1} * →{0, 1} l .

[0071] S102. Trading Platform Randomly select the largest prime number and the second largest prime number And the first prime number and the second largest prime number satisfy And calculate and publish its own public key and Then calculate your own private key based on the public key and

[0072] S103.Data Product Owner Randomly select the third largest prime number and the fourth largest prime number And the third largest prime number and the fourth largest prime number satisfy And calculate and publish its own public key and

[0073] S104. Data product purchaser Randomly select the fifth largest prime number and the sixth largest prime number And the fifth largest prime number and the sixth largest prime number satisfy And calculate and publish its own public key and

[0074] Specifically, the second stage includes the following steps:

[0075] S200. The data product owner and the data product purchaser negotiate and determine the rights and interests tag for the transaction data, where the transaction data is the original data used for the transaction. The rights and interests tag for the transaction data is the same as that used in conventional embodiments, including rights and interests information and identity information of both parties to the transaction.

[0076] S300. The data product owner blinds the transaction data and sends a first parameter set for transaction authentication to the trading platform. The first parameter set includes the equity tag of the transaction data and the blinded transaction data. The trading platform then generates a first signature for the first parameter set and sends the first signature to the data product owner.

[0077] S400. The data product owner verifies whether the first signature is correct. If the first signature is correct, the first signature is deblinded to obtain a second signature. The second signature is a joint signature of both the transaction data and the equity tag of the transaction data.

[0078] S500. The data product owner encrypts the transaction data based on the selected first secret parameter, generates ciphertext of the transaction data, and publishes first transaction information. The first transaction information includes the ciphertext of the transaction data, the equity tag of the transaction data, and the second signature. By publishing the first transaction information, the data product purchaser and the trading platform can learn the content of the first transaction information.

[0079] S600. After the data product purchaser pays the data product owner the amount for the transaction data, the data product owner sends the transaction data and the first secret parameter to the data product purchaser. The data product purchaser verifies the correctness of the received transaction data based on the ciphertext of the transaction data and the first secret parameter. If the transaction data is correct, the transaction is completed, and the trading platform stores the first transaction information. After the trading platform stores the first transaction information, it subsequently uses the first transaction information as transaction evidence for this transaction and implements regulatory actions based on this transaction evidence, such as resolving rights and interests disputes between the data product owner and the data product purchaser.

[0080] In particular, a specific implementation step of step S300 is:

[0081] S301.Data product owner Select the first random number r1, and r1∈Z p , where Z p is the residual group modulo p;

[0082] S302.Data product owner Blind the transaction data m1 to generate blinded transaction data and

[0083] S303.Data product owner Send the first parameter set for transaction authentication To the trading platform Where tag1 is the equity tag of transaction data m1;

[0084] S304. Trading Platform Calculate the first parameter set First signature And the first signature Sent to data product owner in

[0085] In particular, a specific implementation step of step S400 is:

[0086] Data product owner Verify whether the first equation is true. If the first equation is true, then sign the first After deblinding, the second signature σ1 is obtained, where the first equation is established to indicate that the first signature Correct, the first equation is Second signature

[0087] In particular, a specific implementation step of step S500 is:

[0088] S501.Data product owner Encrypt transaction data m1 and generate the ciphertext of transaction data m1 after encryption in is the selected first secret parameter, and Model The simplified residual group, The superscript is used to indicate that the ciphertext is the ciphertext of transaction data m1 (the first power of transaction data m1). The superscript has no mathematical meaning.

[0089] S502.Data product owner Public first transaction information

[0090] In particular, a specific implementation step of step S600 is:

[0091] S601. Data product purchaser To data product owners After paying the amount to purchase transaction data m1, the data product owner The transaction data m1 and the first secret parameter Sent to data product buyers

[0092] S602. Data product purchaser Verify whether the second equation is true. If the second equation is true, the transaction is completed. If the second equation is true, it means that the transaction data m1 is correct. The second equation is

[0093] S603. Trading Platform Store the first transaction information

[0094] Example 2

[0095] This embodiment provides a data trading system for a data product trading method supporting privacy protection and trusted oversight, and further includes a derivative service purchaser, which is in communication with the trading platform and the data product purchaser. The data trading system also supports trading of derivative service data, with the derivative service purchaser and the data product purchaser being the two parties involved in the transaction.

[0096] like Figure 2 As shown, to support the transaction of derivative service data, after the transaction of original data is completed between the data product buyer and the data product owner, the data product transaction method further includes:

[0097] The third stage: derivative service data trading stage.

[0098] Specifically, the third stage includes the following steps:

[0099] S700. The data product purchaser and the derivative service purchaser negotiate to determine the rights and interests label of the derivative service data. The rights and interests label of the derivative service data includes the derivative service function of the transaction data, data usage rules, and identity information of the two parties to the transaction, etc. Among them, the derivative service data is the derivative service data of the transaction data generated based on the derivative service function. Specifically, the transaction data is used as the input value of the derivative service function, and the derivative service data is the output value of the derivative service function corresponding to the input value.

[0100] S800. The data product purchaser blinds the derivative service data and sends a second parameter set for transaction authentication to the trading platform. The second parameter set includes the equity tag of the derivative service data and the blinded derivative service data. The trading platform then generates a third signature for the second parameter set and sends the third signature to the data product purchaser.

[0101] S900. The data product purchaser verifies whether the third signature is correct. If the third signature is correct, the third signature is deblinded to obtain the fourth signature. The fourth signature is a joint signature of the derivative service data and the equity tag of the derivative service data.

[0102] S1000. The data product purchaser encrypts the derivative service data based on the selected second secret parameter, generates ciphertext of the derivative service data, and discloses second transaction information. The second transaction information includes the ciphertext of the derivative service data, the equity tag of the transaction data, the equity tag of the derivative service data, and a fourth signature. The disclosure of the second transaction information allows the derivative service purchaser and the trading platform to learn the contents of the second transaction information.

[0103] S1100. The data product purchaser proves the authenticity of the source of the transaction data to the derivative service purchaser based on the zero-knowledge proof algorithm.

[0104] S1200. If the data product purchaser successfully proves the authenticity of the derivative service purchaser, the derivative service purchaser accepts the transaction and pays the data product purchaser the amount for purchasing the derivative service data.

[0105] S1300. The data product purchaser sends the derivative service data and the second secret parameter to the derivative service purchaser. The derivative service purchaser verifies the received derivative service data based on the ciphertext of the derived service data and the second secret parameter. If the derived service data is correct, the transaction is completed, and the trading platform stores the second transaction information. After the trading platform stores the second transaction information, it subsequently uses the second transaction information as transaction evidence for this transaction and implements regulatory actions based on this transaction evidence, such as handling rights and interests disputes between the data product purchaser and the derivative service purchaser.

[0106] In particular, the derived service function in step S700 is a polynomial, which is expressed as f(x)=a0+a1x+…+a n x n , where a0 is the first constant of the polynomial, a1 is the second constant of the polynomial, and so on. n Denotes the nth constant of the polynomial. Therefore, based on the derived service function, the derived service data m2 corresponding to the transaction data m1 = f(m1).

[0107] In particular, the specific implementation steps of step S800 are:

[0108] S801. Data product purchaser Select a second random number r2, and r2∈Z p ;

[0109] S802. Data product purchaser Blind the derived service data m2 to generate blinded derived service data and

[0110] S803. Data product purchaser Send the second parameter set for transaction authentication To the trading platform Where tag2 is the equity tag of the derived service data m2;

[0111] S804. Trading Platform Calculate the second parameter set The third signature And the third signature Sent to data product buyers in

[0112] In particular, the specific implementation steps of step S900 are:

[0113] Data product buyers Verify whether the third equation is true. If the third equation is true, then sign the third After deblinding, the fourth signature σ2 is obtained, where the third equation is established to indicate the third signature Correct, the third equation is Fourth Signature

[0114] In particular, the specific implementation steps of step S1000 are:

[0115] S1001. Data product purchaser Encrypt the derived service data m2 and generate the ciphertext of the derived service data m2 after encryption in is the third random number, and is the ciphertext corresponding to the transaction data m1 to the power of i, The superscripts in have no mathematical meaning, and represents the selected second secret parameter, 2≤i≤n;

[0116] S1002. Data product purchaser The second transaction information {c2, tag1, tag2, σ2} is made public.

[0117] In particular, the specific implementation steps of step S1100 are:

[0118] S1101. Data product purchaser Select the relationship you want to prove Where | represents the universal symbol for zero-knowledge proof; the first part of the relation R before the universal symbol represents the parameters involved in the proof; the second part of the relation R after the universal symbol represents the relation satisfied by the parameters involved; Indicates the ciphertext corresponding to the nth power of transaction data m1; When i is 2, the corresponding The third random number selected; and so on, When i is n, the corresponding a third random number selected;

[0119] S1102. For each i∈[3,n], the data product buyer Select the first intermediate parameter m i,3, the fourth random number and the fifth random number r i-1,3 ,in

[0120] S1103. Data product purchaser Calculate the first intermediate parameter m i,3 Ciphertext and the first data product Ciphertext And the first intermediate parameter m i,3 The ciphertext c i,3 and the first data product Ciphertext Sent to the buyer of derivative services

[0121] S1104. Purchaser of derivative services Randomly select the second intermediate parameter a, and satisfy |a|=1, and send the second intermediate parameter a to the data product buyer

[0122] S1105. Data product purchaser Calculate the third intermediate parameter Fourth intermediate parameter and the fifth intermediate parameter And send the third intermediate parameter, the fourth intermediate parameter and the fifth intermediate parameter to the derivative service buyer

[0123] S1106. Purchaser of derivative services Verify whether the fourth and fifth equations are both true. If both are true, the data product buyer To the purchaser of derivative services Successfully proved the relationship R that needs to be proved, and the derivative service buyer Accept the transaction, where the fourth equation is The fifth equation is is the ciphertext corresponding to the transaction data m1 to the power of i-2, is the ciphertext corresponding to the transaction data m1 to the power of i-1; if the fourth equation and / or the fifth equation does not hold, then the derivative service buyer No trade accepted.

[0124] In particular, the specific implementation steps of step S1200 are:

[0125] If the data product buyer To the purchaser of derivative services If the relationship R that needs to be proved is successfully proved, the service buyer will be derived Accept the transaction and send it to the data product buyer The amount paid for purchasing the derivative service data m2.

[0126] In particular, the specific implementation steps of step S1300 are:

[0127] S1301. Data product purchaser The derived service data m2 and the second secret parameter Sent to the buyer of derivative services Derivative service buyers Verify whether the sixth equation is true. If the sixth equation is true, the transaction is completed. The sixth equation is true, indicating that the received derivative service data m2 is correct;

[0128] S1302. Trading Platform The second transaction information {c2, tag1, tag2, σ2} is stored.

[0129] The foregoing description is merely a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the form disclosed herein and should not be construed as excluding other embodiments. Rather, the present invention can be used in various other combinations, modifications, and environments and can be modified within the scope of the concept described herein through the above teachings or techniques or knowledge in the relevant field. Modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention are intended to be protected by the appended claims.

Claims

1. A data product trading method that supports privacy protection and trusted supervision is applied to a data trading system. The data trading system includes a trading platform, a data product owner, and a data product buyer. The trading platform is in communication with the data product owner and the data product buyer, respectively. The data product owner is in communication with the data product buyer, and the method is characterized by: The method comprises the following steps: S100. Initialize the data transaction system; S200. The data product owner and the data product buyer negotiate and determine the rights label of the transaction data, where the transaction data is the original data of the data product; S300. The data product owner blinds the transaction data and sends a first parameter set for transaction authentication to the trading platform. The first parameter set includes the equity tag of the transaction data and the blinded transaction data. The trading platform then generates a first signature for the first parameter set and sends the first signature to the data product owner. S400. The data product owner verifies whether the first signature is correct. If so, the first signature is deblinded to obtain a second signature. The second signature is a joint signature of the transaction data and the equity tag of the transaction data. S500. The data product owner encrypts the transaction data based on the selected first secret parameter to generate ciphertext of the transaction data and discloses first transaction information, which includes the ciphertext of the transaction data, the equity tag of the transaction data, and the second signature. S600. After the data product purchaser pays the data product owner the amount for purchasing the transaction data, the data product owner sends the transaction data and the first secret parameter to the data product purchaser. The data product purchaser verifies whether the received transaction data is correct based on the ciphertext of the acquired transaction data and the first secret parameter. If so, the transaction is completed, and the first transaction information is stored by the trading platform. The S300 is specifically as follows: Data product owner Select the first random number r1, and r1∈Z p , where Z p is the residual group modulo p; Data product owner Blind the transaction data m1 to generate blinded transaction data and Data product owner Send the first parameter set for transaction authentication To the trading platform Where tag1 is the equity tag of transaction data m1; Trading Platform Calculate the first parameter set First signature And the first signature Sent to the data product owner, where The S400 is specifically as follows: Data product owner Verify whether the first equation is true. If the first equation is true, then sign the first After deblinding, the second signature σ1 is obtained, where the first equation is established to indicate that the first signature Correct, the first equation is Second signature 2. A data product trading method supporting privacy protection and trusted supervision according to claim 1, characterized in that: The data trading system further includes a derivative service buyer, which is in communication with the data product buyer and the trading platform respectively. After S600, the following steps are further included: S700. The data product buyer and the derivative service buyer negotiate to determine the equity tag of the derivative service data. The equity tag of the derivative service data includes the derivative service function of the transaction data, wherein the derivative service data is the derivative service data of the transaction data generated based on the derivative service function; S800. The data product purchaser blinds the derivative service data and sends a second parameter set for transaction authentication to the trading platform. The second parameter set includes the equity tag of the derivative service data and the blinded derivative service data. The trading platform then generates a third signature for the second parameter set and sends the third signature to the data product purchaser. S900. The data product purchaser verifies whether the third signature is correct. If so, the third signature is deblinded to obtain a fourth signature. The fourth signature is a joint signature of the derived service data and the equity tag of the derived service data. S1000. The data product purchaser encrypts the derivative service data based on the selected second secret parameter to generate ciphertext of the derivative service data, and discloses second transaction information, which includes the ciphertext of the derivative service data, the equity tag of the transaction data, the equity tag of the derivative service data, and a fourth signature; S1100. The data product buyer proves the authenticity of the transaction data source to the derivative service buyer based on a zero-knowledge proof algorithm; S1200. If the data product purchaser proves successful to the derivative service purchaser, the derivative service purchaser accepts the transaction and pays the data product purchaser the amount for purchasing the derivative service data; S1300. The data product purchaser sends the derivative service data and the second secret parameter to the derivative service purchaser. The derivative service purchaser verifies whether the received derivative service data is correct based on the ciphertext of the obtained derivative service data and the second secret parameter. If so, the transaction is completed and the second transaction information is stored by the trading platform.

3. A data product transaction method supporting privacy protection and trusted supervision according to claim 2, characterized in that: The S100 is specifically as follows: The system is initialized according to the selected security parameter l, and the public parameter set PP = {p, g, G, G T ,e,H1,h2,H3}, where p is the first prime number, G and G T are all cyclic groups of order p, g is a generator of G, e is a bilinear map, and e:G×G→G T , H1 is the first secure hash function, and H1:{0,1} * →G, H2 is the second secure hash function, and H2: {0,1} * →{0,1} 2l , H3 is the third secure hash function, and H3:{0,1} * →{0,1} l ; Trading Platform Randomly select the largest prime number and the second largest prime number And the first prime number and the second largest prime number satisfy And calculate and publish its own public key and Then calculate your own private key based on the public key and Data product owner Randomly select the third largest prime number and the fourth largest prime number And the third largest prime number and the fourth largest prime number satisfy And calculate and publish its own public key and Data product buyers Randomly select the fifth largest prime number and the sixth largest prime number And the fifth largest prime number and the sixth largest prime number satisfy And calculate and publish its own public key and 4. A data product transaction method supporting privacy protection and trusted supervision according to claim 2, characterized in that: The S500 is specifically as follows: Data product owner Encrypt transaction data m1 and generate the ciphertext of transaction data m1 after encryption in is the selected first secret parameter, and Model The simplified residual group; Data product owner Public first transaction information 5. A data product transaction method supporting privacy protection and trusted supervision according to claim 4, characterized in that: The S600 is specifically as follows: Data product buyers To data product owners After paying the amount to purchase transaction data m1, the data product owner The transaction data m1 and the first secret parameter Sent to data product buyers Data product buyers Verify whether the second equation is true. If the second equation is true, the transaction is completed. If the second equation is true, it means that the transaction data m1 is correct. The second equation is Trading Platform Store the first transaction information 6. A data product transaction method supporting privacy protection and trusted supervision according to claim 5, characterized in that: The derivative service function is a polynomial, which is expressed as f(x)=a0+a1x+…+a n x n ; The derived service data m2 = f(m1); The S800 is specifically: Data product buyers Select a second random number r2, and r2∈Z p ; Data product buyers Blind the derived service data m2 to generate blinded derived service data and Data product buyers Send the second parameter set for transaction authentication To the trading platform Where tag2 is the equity tag of the derived service data m2; Trading Platform Calculate the second parameter set The third signature And the third signature Sent to data product buyers in The S900 is specifically: Data product buyers Verify whether the third equation is true. If the third equation is true, then sign the third After deblinding, the fourth signature σ2 is obtained, where the third equation is established to indicate the third signature Correct, the third equation is Fourth Signature The S1000 is specifically: Data product buyers Encrypt the derived service data m2 and generate the ciphertext of the derived service data m2 after encryption in is the third random number, and represents the selected second secret parameter, 1≤i≤n; Data product buyers The second transaction information {c2, tag1, tag2, σ2} is made public.

7. A data product transaction method supporting privacy protection and trusted supervision according to claim 6, characterized in that: The S1100 is specifically as follows: Data product buyers Select the relationship you want to prove For each i∈[3,n], the data product buyer Select the first intermediate parameter m i,3 , the fourth random number and the fifth random number r i-1,3 ,in Data product buyers Calculate the first intermediate parameter m i,3 Ciphertext and the first data product Ciphertext And the first intermediate parameter m i,3 The ciphertext c i,3 and the first data product Ciphertext Sent to the buyer of derivative services Derivative service buyers Randomly select the second intermediate parameter a, and satisfy |a|=1, and send the second intermediate parameter a to the data product buyer Data product buyers Calculate the third intermediate parameter Fourth intermediate parameter and the fifth intermediate parameter And send the third intermediate parameter, the fourth intermediate parameter and the fifth intermediate parameter to the derivative service buyer Derivative service buyers Verify whether the fourth and fifth equations are both true. If so, the data product buyer To the purchaser of derivative services Successfully proved the relationship R that needs to be proved, and the derivative service buyer Accept the transaction, where the fourth equation is The fifth equation is Otherwise, the derivative service buyer No trade accepted.

8. A data product transaction method supporting privacy protection and trusted supervision according to claim 7, characterized in that: The S1200 is specifically: If the data product buyer To the purchaser of derivative services If the relationship R that needs to be proved is successfully proved, the service buyer will be derived Accept the transaction and send it to the data product buyer The amount paid for purchasing the derivative service data m2; The S1300 is specifically as follows: Data product buyers The derived service data m2 and the second secret parameter Sent to the derivative service buyer Derivative service buyers Verify whether the sixth equation is true. If so, the transaction is completed. The sixth equation The sixth equation is true, indicating that the received derivative service data m2 is correct; Trading Platform The second transaction information {c2, tag1, tag2, σ2} is stored.

Citation Information

Patent Citations

  • Transaction method and apparatus based on blind signature

    US20210334809A1

  • Method and device for certificateless partially blind signature

    WO2018119670A1