A method and device for government data resource management based on blockchain
Through blockchain technology, the unified integration and security authorization of government data resources has been solved, and the problem of unity and security in the management and sharing of government data resources has been achieved, efficient, secure sharing and circulation of government data has been achieved, and the digital transformation of government data has been supported.
Patent Information
- Application Number
- CN202211578332.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-06
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2042-12-06
AI Technical Summary
The existing government data resources lack uniformity and security in management, integration and sharing, resulting in serious data silos between different regions and departments, and there are security problems with cross-network data interoperability and interconnection.
Blockchain technology is used to integrate government data at all levels of government departments, fields and regions, create digital identity certificates, group and match data according to property rights and authorization attributes, and realize secure authorization and transaction of data through smart contracts, and use virtual channels to conduct privacy transactions.
It realizes unified management and secure sharing of government data resources, ensures the authenticity, credibility and traceability of data, improves the circulation efficiency and security of data resources, and supports the digital transformation of the government.
Smart Images

Figure CN116341018B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of blockchain technology, and in particular to a method and device for government data resource management based on blockchain. Background Art
[0002] Data resources are a type of metadata. The process of grouping data from external data sources, local databases, or data lakes into individual data resources is called data resourceization. The process of assessing the value, pricing, and determining ownership of resourced data is called data assetization. Assetized data can be traded for data usage rights. After purchasing the rights, data users can access the data through batch downloads or API calls. This process is called data commoditization. Data ownership can also be traded, though this is less common than usage rights.
[0003] Government data resources are also a type of data resource. Sharing government data resources, as a crucial component of digital government development, is fundamental to building a digital society. The integration and sharing of government data resources involves diverse topics across departments, regions, and levels, and is influenced by multiple factors, including concepts, technology, business, and management. The interplay of these factors has led to the current difficulties in integrating and sharing government data resources. The main technical difficulties include: a lack of a unified top-level design, resulting in "data silos" between regions and departments. Different units have different network environments for storing government data, and the interoperability of data across networks raises a series of security issues. Due to the varying types of business data, formats, and business requirements across departments, the underlying platforms used for data calculation, processing, and storage are inconsistent. The differing technical makeup of these underlying platforms directly impacts the integration and sharing of data resources. Summary of the Invention
[0004] The embodiments of the present application provide a blockchain-based government data resource management method and device for solving the following technical problems: existing government data resources lack uniformity and security in management, integration and sharing.
[0005] The embodiments of this application adopt the following technical solutions:
[0006] On the one hand, an embodiment of the present application provides a blockchain-based government data resource management method, the method comprising: integrating government data scattered across government departments at all levels, various fields, and various regions according to a unified data resource standard to obtain a government data resource library, and storing the library in a blockchain; wherein the government data resource library contains a number of government data resources; creating a digital identity for each data operator of the government data resource library; grouping the government data resources according to the property rights attributes of the government data resources; wherein the property rights attributes include operational property rights attributes and individual property rights attributes; according to the digital identity, matching the grouped government data resources to each data operator to obtain a government data resource list for each data operator; according to the authorization operation of the data operator, obtaining an authorization list; according to the government data resource list of the data operator and the authorization list, authorizing the corresponding government data to the data user.
[0007] In a feasible implementation, according to a unified data resource standard, the government data scattered in government departments at all levels, various fields, and various regions are integrated to obtain a government data resource library and save it in the blockchain, which specifically includes: classifying and integrating various government data into different types of government data resources, and setting a resource ID for each government data resource; determining the sharing type of the government data resource according to the sharing attribute of the government data resource; wherein the sharing type includes no sharing, unconditional sharing, and conditional sharing; if the government data resource has an operating property owner, setting the operating property owner attribute for the government data resource; wherein the operating property owner attribute includes at least the operating property owner ID and the data group ID; if the government data resource belongs to personal privacy data, setting the individual property owner attribute for the government data resource; wherein the individual property owner attribute includes at least the individual property owner ID and the data ID; the government data resource and its corresponding type, sharing type and property owner attribute are stored according to the resource ID to obtain the government data resource library.
[0008] In a feasible implementation, a digital identity is created for each data operator of the government data resource library, specifically including: issuing a digital identity certificate to each data operator, obtaining the digital identity certificate of each data operator, and writing the summary information of the digital identity certificate into the blockchain; verifying the digital identity certificate of each data operator; when any data operator initiates a request to revoke the digital identity certificate, multiplying the prime number associated with the digital identity certificate by the accumulator of the issuer to generate a new accumulator; and updating the new accumulator to the blockchain to complete the revocation of the digital identity certificate.
[0009] In a feasible implementation, digital identity certificates are issued to each data operator, digital identity certificates of each data operator are obtained, and summary information of the digital identity certificates is written into the blockchain, specifically including: obtaining the identity information of the data operator and sending it to the corresponding issuer so that the issuer can review the identity information; after the review is passed, a corresponding hash value is generated for each user attribute of the identity information; the hash value of each attribute is spliced together in a preset order to obtain a declaration hash; the declaration hash is spliced with the preset field to obtain the digital identity of the data operator. Credentials; wherein the preset fields include at least any one of the following: timestamp, issuer ID, random number; calculating the hash value of the digital identity credential to obtain a credential hash; issuing the digital identity credential through the issuer's private key; storing all information of the digital identity credential in a database fully controlled by the data operator; wherein all information includes at least: user attributes, issuer ID, issuance time, random number; wherein the user attributes are stored in encrypted form; writing the DID of the digital identity credential, the public key of the data operator, the credential hash, and the issuer's signature on the credential hash into the blockchain.
[0010] In a feasible implementation, the digital identity credentials of each data operator are verified, specifically including: extracting the disclosure field from the digital identity credential of the data operator and calculating the hash value of the disclosure field; concatenating the hash values of the disclosure field in a preset order to obtain the disclosure field hash; combining the disclosure field hash with the hash values of other fields in the digital identity credential to form a credential declaration structure; calculating the hash of the credential declaration structure to obtain the credential declaration structure hash; decrypting the signature of the digital identity credential through the public key of the issuer to obtain the signature calculation value; if the signature calculation value is equal to the credential declaration structure hash, the digital identity credential is legal.
[0011] In a feasible implementation, the government data resources are grouped according to the ownership attributes of the government data resources; the grouped government data resources are matched to each data operator according to the digital identity, and a government data resource list of each data operator is obtained, which specifically includes: matching the digital identity of each data operator with the ownership attributes of the government data resources, dividing the government data resources into different groups, and the government data resources contained in each group are all government data resources owned by each data operator; and organizing all government data resources owned by each data operator into the government data resource list.
[0012] In a feasible implementation, an authorization list is obtained according to the authorization operation of the data operator, specifically including: generating an authorization list according to the authorization operation of the data operator; wherein, the authorization list includes at least the following primary keys: data operator ID, resource ID, data group ID, data user ID; the authorization list includes an operation authorization list and an individual authorization list; wherein, the data group ID is the ID of the data group authorized to the user after the data operator groups the government data resources owned by the data operator according to preset rules; if the data group ID is the ID of each record in the government data resource, then the records in the government data resource are authorized one by one.
[0013] In a feasible implementation, the corresponding government data is authorized to the data user based on the data operator's government data resource list and the authorization list, specifically including: extracting the data that needs to be authorized from the data operator's government data resource list based on the primary key in the authorization list; writing the authorization rules into the smart contract, and automatically authorizing the data that needs to be authorized based on the smart contract; writing the authorization results into the blockchain; generating an authorization whitelist based on all authorization results stored in the blockchain; wherein the authorization whitelist describes the list of data resources that the data user is allowed to access.
[0014] In a feasible implementation, the method further includes: when multiple data operators conduct government data transactions, all supply chains involved in the multiple data operators are added to a data channel; multiple virtual channels are defined in the data channel, and the supply chain involved in each transaction business is added to the corresponding virtual channel to conduct private transactions in the virtual channel.
[0015] On the other hand, an embodiment of the present application also provides a blockchain-based government data resource management device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, so that the at least one processor can execute a blockchain-based government data resource management method described in any of the above embodiments.
[0016] The embodiment of the present application provides a method and device for managing government data resources based on blockchain. By building a digital identity based on blockchain to lock the data responsible party, relying on the tamper-proof nature of blockchain, it realizes the ability to store and trace data evidence; it realizes the authenticity and credibility of shared data, real-time circulation, clear ownership confirmation, and traceability, further consolidating the foundation of urban big data and assisting the digital transformation of the government. By using the blockchain technology platform as the construction foundation, connecting to the established government data sharing and exchange platform, data can be put on the chain, and ultimately the business data provider can output data efficiently and accurately under the premise of independent control of its own data. It provides basic support for promoting the efficient, convenient and safe use of data in more government services. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments described in the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work. In the drawings:
[0018] Figure 1 A flowchart of a blockchain-based government data resource management method provided in an embodiment of the present application;
[0019] Figure 2 A schematic structural diagram of a blockchain-based government data resource management device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0020] In order to enable those skilled in the art to better understand the technical solutions in this application, the following will clearly and completely describe the technical solutions in the embodiments of this application in conjunction with the drawings in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments of this specification, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.
[0021] The embodiment of the present application provides a method for managing government data resources based on blockchain, and the execution subject is a government data resource management device based on blockchain. Figure 1 As shown, the blockchain-based government data resource management method specifically includes steps S101-S106:
[0022] S101. Based on the unified data resource standards, the government data scattered across government departments at all levels, in various fields, and in various regions are integrated to obtain a government data resource library, which is then stored in the blockchain.
[0023] Specifically, according to unified standards and specifications, government information resources scattered across government departments at all levels, in various fields, and in various regions will be integrated and organized to form a government data resource library that is logically centralized, physically decentralized, and can be uniformly managed and serviced. The specific standards and specifications are as follows:
[0024] Government data is categorized and integrated into different types of government data resources, and a resource ID is assigned to each government data resource. The sharing type of the government data resource is then determined based on its sharing attributes. Sharing attributes correspond to sharing types, including no sharing, unconditional sharing, and conditional sharing. Conditional sharing means that only authorized whitelisted users can access the data. No sharing means that only the data operator's internal users can access the data. Unconditional sharing means that the government data resource can provide data services for external users to access.
[0025] Furthermore, if a government data resource has an operating owner, then the operating owner attributes are set for the government data resource. These operating owner attributes include at least the operating owner ID and the data group ID. If a government data resource is personal privacy data, then individual owner attributes are set for the government data resource. These individual owner attributes include at least the individual owner ID and the data ID.
[0026] Furthermore, the government data resources and their corresponding types, sharing types, and property rights are stored according to resource IDs to obtain a government data resource library.
[0027] S102. Create digital identities for each data operator of the government data resource library.
[0028] Specifically, digital identity certificates are issued to each data operator, and the digital identity certificates of each data operator are obtained, and the summary information of the digital identity certificates is written into the blockchain. The specific steps are as follows:
[0029] Obtain the identity information of the data operator and send it to the corresponding issuer so that the issuer can review the identity information. After the review is passed, generate a corresponding hash value for each user attribute of the identity information. Concatenate the hash values of each attribute in a preset order to obtain a declaration hash. Concatenate the declaration hash with the preset fields to obtain the digital identity certificate of the data operator; wherein the preset fields include at least any one of the following: timestamp, issuer ID, random number. Calculate the hash value of the digital identity certificate to obtain the certificate hash. Issue the digital identity certificate using the issuer's private key. Store all information of the digital identity certificate in a database that is fully controlled by the data operator. Among them, all information includes at least: user attributes, issuer ID, issuance time, and random number. Among them, user attributes are stored encrypted. Write the DID of the digital identity certificate, the public key of the data operator, the certificate hash, and the issuer's signature on the certificate hash into the blockchain.
[0030] As a feasible implementation method, the embodiment of the present application supports two digital identities: corporate identity and personal identity (or corporate account and personal account), both of which require real-name authentication. For corporate identity, it is necessary to submit identity information such as a photo of the industrial and commercial business license when registering, and use a unified credit code as the account ID. For personal identity, when registering, use a mobile phone verification code to prove the identity of the owner, verify the consistency of the mobile phone number and the ID number through the operator, and verify the consistency of the ID number, name and face through face recognition technology. Through the above three consistencies, a high degree of consistency is ensured between the mobile phone number, ID number and the user himself, thereby ensuring the objectivity and authenticity of the user's identity and preventing impersonation. Finally, the ID number is used as a unique identifier as the personal identity account identifier (ID).
[0031] Furthermore, the digital identity credentials of each data operator are verified. The specific steps are as follows:
[0032] Extract the disclosure fields from the data operator's digital identity certificate and calculate their hash values. Concatenate the hash values of the disclosure fields in a pre-set order to obtain the disclosure field hash. Combine the disclosure field hash with the hash values of other fields in the digital identity certificate to form a credential declaration structure. Calculate the hash of the credential declaration structure to obtain the credential declaration structure hash. Decrypt the signature of the digital identity certificate using the issuer's public key to obtain the calculated signature value. If the calculated signature value is equal to the credential declaration structure hash, the digital identity certificate is valid.
[0033] Furthermore, when any data operator initiates a request to revoke a digital identity certificate, the prime number associated with the digital identity certificate is multiplied by the issuer's accumulator to generate a new accumulator. The new accumulator is then updated on the blockchain, completing the revocation of the digital identity certificate.
[0034] As a feasible implementation, the issuer assigns a large prime number to each credential when issuing it, and this prime number's ID is recorded in the issued credential. If the issuer wishes to revoke a credential, they multiply the credential's associated prime number by the issuer's accumulator to generate a new accumulator, which is then updated on the blockchain to complete the credential revocation. The validator then divides the credential's associated prime number by the accumulator from the blockchain or the issuer's revocation blacklist. If the result is divisible, the credential has been revoked and is invalid.
[0035] S103. Group the government data resources according to their ownership attributes, and match the grouped government data resources to each data operator based on their digital identities to obtain a list of government data resources for each data operator.
[0036] Specifically, by matching each data operator's digital identity with the ownership attributes of the government data resources, the government data resources are divided into different groups. Each group contains all the government data resources owned by each data operator. All government data resources owned by each data operator are organized into a government data resource list.
[0037] S104. Obtain an authorization list based on the authorization operation of the data operator.
[0038] Specifically, an authorization list is generated based on the data operator's authorization operations. The authorization list includes at least the following primary keys: data operator ID, resource ID, data group ID, and data user ID. The authorization list includes both an operational authorization list and an individual authorization list. The data group ID is the ID of the data group that the data operator authorizes to the user after grouping the government data resources owned by the data operator according to preset rules.
[0039] As a feasible implementation method, if the data group ID is the ID of each record in the government data resource, the records in the government data resource are authorized one by one.
[0040] S105. Authorize the corresponding government data to the data user based on the data operator's government data resource list and authorization list.
[0041] Specifically, based on the primary key in the authorization list, the data requiring authorization is extracted from the data operator's list of government data resources. The authorization rules are written into a smart contract, and the data requiring authorization is automatically authorized based on the smart contract. The authorization results are written to the blockchain. Based on all authorization results stored in the blockchain, an authorization whitelist is generated. The authorization whitelist contains a list of authorized data users and a list of data resources that each data user is permitted to access.
[0042] S106. Conduct private transactions between data operators through virtual channels.
[0043] Specifically, when multiple data operators conduct government data transactions, all supply chains involved in these transactions are added to a single data channel. Multiple virtual channels are defined within the data channel, and each supply chain involved in the transaction is added to the corresponding virtual channel, allowing for private transactions within the virtual channel.
[0044] In one embodiment, multiple "virtual channels" are defined within a data channel. Data channel members are added to the virtual channels as needed. When conducting a private transaction, a virtual channel is selected, and a decryption whitelist is automatically generated for the private transaction based on the virtual channel members. Private transactions generated in this manner are automatically associated with the virtual channel for subsequent management and statistics. If the number of virtual channel members increases or decreases, it does not affect the existing associated virtual transactions. The visible scope of transaction data gradually decreases in the order of channel, virtual channel, and private transaction. In practice, transaction methods can be selected as needed to control the visible scope of transaction data and ensure transaction privacy.
[0045] In addition, the embodiment of the present application also provides a government data resource management device based on blockchain, such as Figure 2 As shown, the blockchain-based government data resource management device 200 specifically includes:
[0046] At least one processor 201; and a memory 202 in communication with the at least one processor 201; wherein the memory 202 stores instructions executable by the at least one processor 201, so as to enable the at least one processor 201 to perform:
[0047] According to the unified data resource standards, the government data scattered across government departments at all levels, in various fields, and in various regions are integrated to obtain a government data resource library and stored in the blockchain; the government data resource library contains a number of government data resources;
[0048] Create digital identities for each data operator in the government data resource repository;
[0049] Grouping government data resources according to their ownership attributes; ownership attributes include operational ownership attributes and individual ownership attributes;
[0050] According to digital identity, the grouped government data resources are matched to each data operator to obtain a list of government data resources for each data operator;
[0051] Obtain the authorization list based on the data operator's authorization operation;
[0052] Based on the data operator's government data resource list and authorization list, the corresponding government data will be authorized to the data user.
[0053] The various embodiments in this application are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences from other embodiments. In particular, the device embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the partial description of the method embodiments.
[0054] The foregoing description describes specific embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in an order different from that described in the embodiments and still achieve the desired results. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0055] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the embodiments of the present application may have various modifications and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included within the scope of the claims of the present application.
Claims
1. A blockchain-based government data resource management method, characterized in that: The method comprises: According to the unified data resource standards, the government data scattered across government departments at all levels, in various fields, and in various regions are integrated to obtain a government data resource library and stored in the blockchain; the government data resource library contains a number of government data resources; Creating digital identities for each data operator of the government data resource repository; Grouping the government data resources according to their ownership attributes; wherein the ownership attributes include operational ownership attributes and individual ownership attributes; Matching the grouped government data resources to each data operator based on the digital identity to obtain a list of government data resources for each data operator; According to the authorization operation of the data operator, the authorization list includes: Generate an authorization list based on the data operator's authorization operation; wherein the authorization list includes at least the following primary keys: data operator ID, resource ID, data group ID, and data user ID; the authorization list includes an operation authorization list and an individual authorization list; wherein the data group ID is the ID of the data group authorized to the user after the data operator groups the government data resources owned by the data operator according to preset rules; If the data group ID is the ID of each record in the government data resource, then authorizing each record in the government data resource one by one; According to the data operator's government data resource list and the authorization list, the corresponding government data is authorized to the data user, specifically including: According to the primary key in the authorization list, the data requiring authorization is extracted from the list of government data resources of the data operator; the authorization rules are written into the smart contract, and the data requiring authorization is automatically authorized according to the smart contract; the authorization results are written into the blockchain; and an authorization whitelist is generated based on all the authorization results stored in the blockchain; wherein the authorization whitelist describes a list of data resources that the data user is allowed to access.
2. A blockchain-based government data resource management method according to claim 1, characterized in that: According to the unified data resource standards, the government data scattered across government departments at all levels, in various fields, and in various regions are integrated to obtain a government data resource library and stored in the blockchain, including: Classify and integrate various government data into different types of government data resources, and set a resource ID for each government data resource; Determining a sharing type of the government data resource according to the sharing attribute of the government data resource; wherein the sharing type includes no sharing, unconditional sharing, and conditional sharing; If the government data resource has an operating owner, then set the operating owner attribute for the government data resource; wherein the operating owner attribute includes at least an operating owner ID and a data group ID; If the government data resource is personal privacy data, then set individual property owner attributes for the government data resource; wherein the individual property owner attributes include at least individual property owner ID and data ID; The government data resources and their corresponding types, sharing types, and property rights attributes are stored according to the resource ID to obtain the government data resource library.
3. A blockchain-based government data resource management method according to claim 1, characterized in that: Create digital identities for each data operator of the government data resource library, including: Issue digital identity certificates to each data operator, obtain the digital identity certificates of each data operator, and write summary information of the digital identity certificates into the blockchain; Verifying the digital identity credentials of each data operator; When any data operator initiates a request to revoke a digital identity certificate, the prime number associated with the digital identity certificate is multiplied by the issuer's accumulator to generate a new accumulator; The new accumulator is updated on the blockchain to complete the revocation of the digital identity certificate.
4. A blockchain-based government data resource management method according to claim 3, characterized in that: The digital identity certificate is issued to each data operator, the digital identity certificate of each data operator is obtained, and the summary information of the digital identity certificate is written into the blockchain, specifically including: Obtain the identity information of the data operator and send it to the corresponding issuer so that the issuer can review the identity information; After the review is passed, a corresponding hash value is generated for each user attribute of the identity information; Concatenate the hash values of each user attribute in a preset order to obtain a declaration hash; Concatenate the declaration hash with the preset fields to obtain the digital identity certificate of the data operator; wherein the preset fields include at least any one of the following: timestamp, issuer ID, random number; Calculating a hash value of the digital identity credential to obtain a credential hash; Issuing the digital identity certificate using the issuer's private key; Storing all information of the digital identity certificate in a database fully controlled by the data operator; wherein the all information includes at least: user attributes, issuer ID, issuance time, and random number; wherein the user attributes are stored in encrypted form; The DID of the digital identity certificate, the public key of the data operator, the certificate hash, and the issuer's signature on the certificate hash are written into the blockchain.
5. A blockchain-based government data resource management method according to claim 3, characterized in that: Verify the digital identity credentials of each data operator, including: Extracting a disclosure field from the digital identity credential of the data operator and calculating a hash value of the disclosure field; Concatenate the hash values of the disclosure fields in a preset order to obtain the disclosure field hash; Hash the disclosure field with the hash values of other fields in the digital identity credential to form a credential declaration structure; Calculating a hash on the credential declaration structure to obtain a credential declaration structure hash; Decrypt the signature of the digital identity certificate using the issuer's public key to obtain a calculated signature value; If the calculated signature value is equal to the hash of the credential declaration structure, the digital identity credential is valid.
6. A blockchain-based government data resource management method according to claim 1, characterized in that: The government data resources are grouped according to the property rights of the government data resources; and the grouped government data resources are matched to each data operator according to the digital identity to obtain a list of government data resources of each data operator, specifically including: According to the matching of the digital identity of each data operator with the property rights of the government data resources, the government data resources are divided into different groups. The government data resources contained in each group are all the government data resources owned by each data operator; All government data resources owned by each data operator are organized into the government data resource list.
7. A blockchain-based government data resource management method according to claim 1, characterized in that: The method further comprises: When multiple data operators conduct government data transactions, all supply chains involved in the multiple data operators are added to one data channel; A plurality of virtual channels are defined in the data channel, and a supply chain involved in each transaction business is added to a corresponding virtual channel to conduct private transactions in the virtual channel.
8. A blockchain-based government data resource management device, characterized in that: The device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, so that the at least one processor can execute a blockchain-based government data resource management method according to any one of claims 1-7.
Citation Information
Patent Citations
Government affair data government platform based on block chain
CN114553882A
Blockchain-based trusted sharing method for protection of privacy-related government data
WO2022121058A1