A distributed data sharing method, system and device
Patent Information
- Application Number
- CN202210821482.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-13
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2042-07-13
AI Technical Summary
[0003]但是,当前方案更多面向数据共享,对数据所有权的保护不足,对全流程的控制、监管不足
[0014]根据本发明上述实施例提供的方案,通过区块链上的位于第一自治域中的第一全量节点将数据资源请求方的数据资源请求交易发送至区块链,使得第二自治域中的第二全量节点同步所述区块链上的所述数据资源请求交易后,向数据资源所有方发送;所述数据资源请求方位于第一自治域,所述数据资源所有方位于第二自治域,所述第一自治域和所述第二自治域是区块链上的不同的自治域;所述第一全量节点接收所述数据资源所有方通过第二全量节点,反馈的数据资源许可交易,并将所述数据资源许可交易发送至数据资源请求方。这样,对链上的数据请求和响应过程匿名化,保障链上用户的隐私;并进一步在保障数据所有权的基础上进行数据资源共享,在数据资源发布、请求、许可、获取、审计的全流程对数据进行控制,减小数据滥用的风险,以全流程监管威慑潜在的数据滥用者,提高守法用户共享数据的便利。
Smart Images

Figure CN116955472B_ABST
Abstract
Claims
1. A distributed data sharing method, characterized in that, include: The first full node receives the data resource request transaction of the data resource requester forwarded by the first delegated access node of the data resource requester; The first full node sends the data resource request transaction from the data resource requester to the blockchain. This data resource request transaction includes: a random number, a timestamp, a first temporary public key calculated based on the random number, the address public key of the second delegated access node, and the timestamp, an encrypted address public key of the data resource owner obtained by encrypting the address public key of the data resource owner using the first temporary public key, an encrypted data resource requester ID, and an encrypted data resource ID. The first temporary public key serves as the identification value for the second delegated access node, enabling the second full node on the blockchain to synchronize the data resource request transaction and send it to the second delegated access node of the data resource owner in the second autonomous region. The second delegated access node then... The second delegated access node sends the data resource request transaction to the data resource owner. The second delegated access node parses the data resource request transaction to obtain a first parsing result, where a first temporary private key is used as the first parsing result. Based on the first parsing result, the address public key of the data resource owner is parsed. Based on the address public key of the data resource owner, the data resource owner is determined, and the requested data resource requires the data resource owner's permission. The data resource request transaction is then forwarded to the data resource owner in the second autonomous domain. The data resource requester is located in the first autonomous domain, and the data resource owner is located in the second autonomous domain. The first and second autonomous domains are different autonomous domains on the blockchain. The first full node receives the data resource license transaction fed back by the data resource owner through the second full node, and sends the data resource license transaction to the data resource requester. The data resource license transaction includes: a random number, a timestamp, a second temporary public key calculated based on the random number, the address public key of the first delegated access node, and the timestamp, an encrypted address public key of the data resource requester obtained by encrypting the address public key of the data resource requester based on the second temporary public key, and an encrypted file encryption key for the data resource. The second temporary public key serves as the identification value of the first delegated access node.
2. The distributed data sharing method according to claim 1, characterized in that, The data resource request transaction is generated by the data resource requester through the following process: Generate random numbers and obtain the public key of the address of the second delegated access node; Calculate the first temporary public key based on the random number, the address public key of the second delegated access node, and the timestamp, and use it as the identification value of the second delegated access node; The first temporary public key is used to encrypt the address public key of the data resource owner to obtain the encrypted address public key of the data resource owner; Based on the encrypted public key of the data resource owner, the encrypted data resource requester ID and the requested data resource ID are encrypted to obtain the encrypted data resource requester ID and the encrypted data resource ID. The data resource request transaction is generated based on the random number, the identification value of the second delegated access node, the encrypted public key of the address of the data resource owner, the encrypted ID of the data resource requester, the encrypted data resource ID, and the timestamp.
3. The distributed data sharing method according to claim 1, characterized in that, The data resource licensing transaction is generated through the following process: The data resource requester ID and data resource ID are decrypted using the data decryption private key; Generate a random number and obtain the public key of the address of the first delegated access node; Calculate the second temporary public key based on the random number, the address public key of the first delegated access node, and the timestamp, and use it as the identification value of the first delegated access node; The address public key of the data resource requester is encrypted using the second temporary public key to obtain the encrypted address public key of the data resource requester; Based on the public key of the data resource requester and the file encryption key of the encrypted data resource, the encrypted data resource encryption key is obtained. The data resource license transaction is generated based on the random number, the identification value of the first delegated access node, the encrypted public key of the data resource requester's address, and the encrypted data resource encryption key.
4. The distributed data sharing method according to claim 1, characterized in that, The first full node receives the data resource license transaction from the data resource owner through the second full node, and sends the data resource license transaction to the data resource requester, including: The first full node receives the data resource license transaction fed back by the second full node. The data resource license transaction is the data resource license transaction of the data resource owner forwarded by the second delegated access node located in the data resource owner, received by the second full node. The first full node sends the data resource license transaction to the first delegated access node of the data resource requester in the first autonomous domain, and the first delegated access node identifies the data resource license transaction and forwards the identification result to the data resource requester in the first autonomous domain.
5. The distributed data sharing method according to claim 4, characterized in that, The first delegated access node identifies the data resource license transaction, including: The first delegated access node parses the data resource license transaction to obtain the second parsing result; Based on the second parsing result, the public key of the data resource requester's address is parsed; The data resource requester is identified based on the public key of the data resource requester's address, and the requested data resource needs to be sent to the data resource requester.
6. The distributed data sharing method according to any one of claims 1 to 5, characterized in that, Also includes: The audit nodes in the second autonomous domain on the blockchain publish data resource audit record transactions in all directions; The data resource audit record transaction includes: random number, timestamp, audit node identification value, and encrypted audit record.
7. The distributed data sharing method according to claim 1, characterized in that, Also includes: The data resource requester publishes security parameters to the second delegated access node; The second delegated access node calculates based on the security parameters to determine the data resource owner of the data resource requested by the data resource requester; The second delegated access node sends the encrypted data resource requester ID and data resource ID to the data resource owner; the data resource owner then decrypts the data resource requester ID and data resource ID to obtain them.
8. A distributed data sharing system, characterized in that, include: At least one autonomous system, the autonomous system having full nodes; at least one delegated access node connected to the full nodes, wherein a first full node is connected to at least one first delegated access node, and a second full node is connected to at least one second delegated access node; The first full node in the first autonomous domain receives the data resource request transaction of the data resource requester forwarded by the first delegated access node of the data resource requester. The first full node in the first autonomous domain sends the data resource request transaction of the data resource requester to the blockchain. The data resource request transaction includes: a random number, a timestamp, a first temporary public key calculated based on the random number, the address public key of the second delegated access node, and the timestamp, an encrypted address public key of the data resource owner obtained by encrypting the address public key of the data resource owner using the first temporary public key, an encrypted data resource requester ID, and an encrypted data resource ID. The first temporary public key serves as the identification value of the second delegated access node, enabling the second full node on the blockchain to synchronize the data resource request transaction and send it to the second delegated access node of the data resource owner in the second autonomous domain. The first full node then sends the data resource request transaction to the second delegated access node of the data resource owner in the second autonomous domain. The second delegated access node sends the data resource request transaction to the data resource owner. The second delegated access node parses the data resource request transaction to obtain a first parsing result, where a first temporary private key is used as the first parsing result. Based on the first parsing result, it parses the public address key of the data resource owner. Based on the public address key of the data resource owner, it determines the data resource owner, and confirms that the requested data resource requires the data resource owner's permission. The node then forwards the data resource request transaction to the data resource owner in the second autonomous domain. The data resource requester is located in the first autonomous domain, and the data resource owner is located in the second autonomous domain. The first and second autonomous domains are located in different autonomous domains on the blockchain. The first full node receives the data resource license from the data resource owner through the second full node, and sends the data resource license to the data resource requester. The data resource license transaction includes: a random number, a timestamp, a second temporary public key calculated based on the random number, the address public key of the first delegated access node, and the timestamp, an encrypted address public key of the data resource requester obtained by encrypting the address public key of the data resource requester based on the second temporary public key, and an encrypted file encryption key for the data resource. The second temporary public key serves as the identification value of the first delegated access node.
9. A node device, comprising: The processor, memory, communication interface, and communication bus are provided, wherein the processor, memory, and communication interface communicate with each other via the communication bus. The memory is used to store at least one executable instruction, which causes the processor to perform the operation corresponding to the distributed data sharing method as described in any one of claims 1-7.
10. A computer storage medium storing at least one executable instruction that causes a processor to perform an operation corresponding to the distributed data sharing method as described in any one of claims 1-7.
Citation Information
Patent Citations
Information sharing method and device based on blockchain network and related equipment
CN111404950A
Data sharing method and system based on block chain
CN113111069A