Data authorization method, apparatus and electronic device
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA MOBILE GRP GUANGDONG CO LTD
- Filing Date
- 2022-10-26
- Publication Date
- 2026-08-07
AI Technical Summary
[0004]本申请实施例提供一种数据授权方法、装置和电子设备,用以解决现有方案无法满足针对用户数据进行批量授权的技术问题
[0028] The data authorization method, apparatus, and electronic device provided in this application embodiment determine a target dataset from the dataset based on at least two user authorization information pieces by a business terminal; generate a business terminal authorization credential based on the user authorization information and determine the addresses of at least two user authorization information pieces on the blockchain by the business terminal; send the target dataset to the data processing terminal by the business terminal and upload the business terminal authorization credential to the blockchain. This facilitates the data processing terminal in obtaining the target dataset, acquiring the business terminal authorization credential based on the data digest information of the target dataset, and tracing the user authorization information of at least two users on the blockchain based on at least two addresses of the business terminal authorization credential. Thus, this application embodiment combines the business terminal with the blockchain, enabling batch authorization of user data when the business terminal sends batches of user data (i.e., datasets) to the data processing terminal.
Smart Images

Figure CN116992410B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of blockchain technology, specifically to a data authorization method, apparatus, and electronic device. Background Technology
[0002] During data sharing, users' personal privacy data is scattered across enterprise-level business data. Users may be unaware of how the enterprise uses this data, or the enterprise may expose or even seriously infringe upon users' privacy data when processing or providing it for other purposes.
[0003] Existing technologies can protect user privacy data by collecting it after authorization and then authorizing it to other parties through authentication and evidence preservation schemes. However, this approach is mainly applicable to single data entries and is only feasible when one party provides the data and the other party obtains authorization on the blockchain. In the telecommunications industry, the data involved are often datasets containing a large number of users. During the flow of large amounts of data, such as voice and call detail records, users need to authorize data use and have the right to know about data usage. Existing technology systems use point-to-point authorization, which cannot meet the needs of batch authorization of user data. Summary of the Invention
[0004] This application provides a data authorization method, apparatus, and electronic device to solve the technical problem that existing solutions cannot meet the requirements for batch authorization of user data.
[0005] In a first aspect, embodiments of this application provide a data authorization method, including:
[0006] The business side determines the dataset to be sent to the data processing side;
[0007] Based on the business type of the dataset, the business terminal determines at least two user authorization information entries located on the blockchain; the user authorization information represents the authorization relationship between the user and the business type of the business terminal.
[0008] The business unit determines the target dataset from the dataset based on at least two pieces of user authorization information;
[0009] The business terminal generates a business terminal authorization certificate based on the data digest information of the target dataset. The business terminal authorization certificate represents the authorization relationship between the business terminal and the data processing terminal. The business terminal authorization certificate includes at least two addresses of the user authorization information on the blockchain and the data digest information.
[0010] The business terminal sends the target dataset to the data processing terminal and uploads the business terminal authorization certificate to the blockchain.
[0011] Secondly, embodiments of this application provide a data authorization method, including:
[0012] The data processing terminal receives the target dataset sent by the business terminal and determines the business terminal authorization credential that matches the data digest information of the target dataset on the blockchain;
[0013] The data processing terminal queries at least two user authorization information on the blockchain based on at least two addresses of the business terminal authorization credential;
[0014] Wherein, the user authorization information represents the authorization relationship between the user and the business type of the business terminal; the business terminal authorization credential represents the authorization relationship between the business terminal and the data processing terminal; the business terminal authorization credential includes at least two addresses of the user authorization information on the blockchain and the data digest information.
[0015] Thirdly, embodiments of this application provide a data authorization device, including:
[0016] The dataset determination module is used to enable the business side to determine the dataset to be sent to the data processing side;
[0017] The user authorization information determination module is used to enable the business terminal to determine at least two user authorization information pieces located on the blockchain based on the business type of the dataset; the user authorization information represents the authorization relationship between the user and the business type of the business terminal.
[0018] The target dataset determination module is used to enable the business terminal to determine the target dataset from the dataset based on at least two pieces of user authorization information;
[0019] A business-side authorization credential and address determination module is used to enable the business end to generate a business-side authorization credential based on the data digest information of the target dataset. The business-side authorization credential represents the authorization relationship between the business end and the data processing end. The business-side authorization credential includes at least two addresses of the user authorization information on the blockchain and the data digest information.
[0020] The data sending module is used to enable the business terminal to send the target dataset to the data processing terminal and upload the business terminal authorization certificate to the blockchain.
[0021] Fourthly, embodiments of this application provide a data authorization device, including:
[0022] The data receiving module is used to enable the data processing terminal to receive the target dataset sent by the business terminal, and to determine the business terminal authorization credential that matches the data digest information of the target dataset on the blockchain;
[0023] The query module is used to enable the data processing terminal to query at least two user authorization information of the user on the blockchain based on at least two addresses of the authorization credentials of the business terminal;
[0024] Wherein, the user authorization information represents the authorization relationship between the user and the business type of the business terminal; the business terminal authorization credential represents the authorization relationship between the business terminal and the data processing terminal; the business terminal authorization credential includes at least two addresses of the user authorization information on the blockchain and the data digest information.
[0025] Fifthly, embodiments of this application provide an electronic device, including a processor and a memory storing a computer program, wherein the processor executes the program to implement the steps of the data authorization method described in the first or second aspect.
[0026] In a sixth aspect, embodiments of this application provide a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the data authorization method described in the first or second aspect.
[0027] In a seventh aspect, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the steps of the data authorization method described in the first or second aspect.
[0028] The data authorization method, apparatus, and electronic device provided in this application embodiment determine a target dataset from the dataset based on at least two user authorization information pieces by a business terminal; generate a business terminal authorization credential based on the user authorization information and determine the addresses of at least two user authorization information pieces on the blockchain by the business terminal; send the target dataset to the data processing terminal by the business terminal and upload the business terminal authorization credential to the blockchain. This facilitates the data processing terminal in obtaining the target dataset, acquiring the business terminal authorization credential based on the data digest information of the target dataset, and tracing the user authorization information of at least two users on the blockchain based on at least two addresses of the business terminal authorization credential. Thus, this application embodiment combines the business terminal with the blockchain, enabling batch authorization of user data when the business terminal sends batches of user data (i.e., datasets) to the data processing terminal. Attached Figure Description
[0029] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0030] Figure 1 This is one of the flowcharts illustrating the data authorization method provided in the embodiments of this application;
[0031] Figure 2 This is a second schematic flowchart of the data authorization method provided in the embodiments of this application;
[0032] Figure 3 This is the third flowchart illustrating the data authorization method provided in the embodiments of this application;
[0033] Figure 4 This is the fourth flowchart illustrating the data authorization method provided in the embodiments of this application;
[0034] Figure 5 This is the fifth flowchart illustrating the data authorization method provided in the embodiments of this application;
[0035] Figure 6 This is the sixth flowchart illustrating the data authorization method provided in the embodiments of this application;
[0036] Figure 7 This is the seventh flowchart illustrating the data authorization method provided in the embodiments of this application;
[0037] Figure 8 This is one of the structural schematic diagrams of the data authorization device provided in the embodiments of this application;
[0038] Figure 9 This is a second schematic diagram of the structure of the data authorization device provided in the embodiments of this application;
[0039] Figure 10 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0040] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0041] Figure 1 This is a flowchart illustrating the data authorization method provided in an embodiment of this application. Please refer to... Figure 1 and Figure 2 This application provides a data authorization method, which may include:
[0042] Step 400a: The business side determines the dataset to be sent to the data processing side.
[0043] In this context, the "business end" refers to the terminal or server that generates various types of data (such as voice, call detail records, SMS volume, location information, etc.) during actual business operations. This business data is related to each user. A dataset refers to a collection of user data for a specific business type. For example, the business end determines the dataset of voice data to be sent to the data processing end.
[0044] Step 500a: The business terminal determines at least two user authorization information on the blockchain based on the business type of the dataset; the user authorization information represents the authorization relationship between the user and the business type of the business terminal.
[0045] Specifically, in this embodiment, the blockchain includes at least two user authorization information entries. By storing this user authorization information on the blockchain, the information is immutable, user-controllable, traceable, and auditable. The user authorization information represents the authorization relationship between the user and the business type of the business terminal.
[0046] Therefore, based on the business type of the dataset, this application embodiment can determine user authorization information related to the business type of the dataset on the blockchain. Through this user authorization information, this application embodiment can determine which business terminal's data the user authorized. For example, in one embodiment, when the business type of the dataset is business 1, the user authorization information related to business 1 on the blockchain indicates that user 1 and user 2 have authorization relationships with business terminal A for business 1. That is, user 1 and user 2 respectively authorized business terminal A to use the data of user 1 and user 2 related to business 1.
[0047] For example, when User 1 orders a food recommendation service in the application and clicks to agree to the authorization terms, the food recommendation service is provided by the application and will record User 1's location information in the application. When User 1 clicks the confirmation authorization pop-up on the page, it means that User 1 authorizes the application to use User 1's location information.
[0048] Step 600a: The business terminal determines the target dataset from the dataset based on at least two user authorization information.
[0049] Based on the determination of at least two user authorization information, the business side can determine the target dataset composed of data authorized by at least two users from the dataset.
[0050] Step 700a: The business terminal generates a business terminal authorization certificate based on the data digest information of the target dataset. The business terminal authorization certificate represents the authorization relationship between the business terminal and the data processing terminal. The business terminal authorization certificate includes at least two addresses of the user authorization information on the blockchain and the data digest information.
[0051] When the business side needs to provide user-related business-type data to the data processing side for data analysis, the data processing side requires authorization from the business side and also wants to obtain authorization information for each user in the data. The business side generates a business side authorization credential based on the data summary information of the target dataset. This credential represents the authorization relationship between the business side and the data processing side. For example, when user authorization information shows that user 1 and user 2 have authorization relationships with business side A's business 1, the business side authorization credential is a business A-data processing side B authorization credential, meaning that business side A authorizes sending the data of user 1 and user 2 to data processing side B for data analysis.
[0052] The business authorization credential includes at least the addresses of the two user authorization information on the blockchain and the data digest information. In one embodiment, the business authorization credential also includes the authorized business type, the authorized business terminal, and the data processing terminal.
[0053] It should be noted that the data digest information can be a hash digest, and the address of the user authorization information on the blockchain can be a hash address on the blockchain.
[0054] Step 800a: The business terminal sends the target dataset to the data processing terminal and uploads the business terminal authorization certificate to the blockchain.
[0055] The business end sends the target dataset to the data processing end and uploads the business end authorization credential to the blockchain. This facilitates the data processing end in obtaining the target dataset and, based on the data digest information of the target dataset, in obtaining the business end authorization credential. It also allows the data processing end to obtain authorization from the business end through the business end authorization credential and to trace at least two user authorization information based on at least two addresses of the business end authorization credential, thereby obtaining the authorization credential for the user-authorized business type of data. This improves the compliance of user data usage.
[0056] For example, in one embodiment, the target dataset includes voice data from user 1 and user 2. Two user authorization information sets are: user 1 authorization information (the voice service authorization relationship between user 1 and service provider A), and user 2 authorization information (the voice service authorization relationship between user 2 and service provider A). The service provider sends the voice data of user 1 and user 2 to the data processing terminal. The service provider authorization credential, user 1 authorization information, and user 2 authorization information are uploaded to the blockchain. The data processing terminal obtains authorization from service provider A through the service provider authorization credential, compares the data digest information of the service provider authorization credential on the blockchain with the data digest information of the target dataset, obtains a matching service provider authorization credential, and traces the voice service authorization relationship between user 1 and service provider A, and user 2 and service provider A, through the addresses of user 1 authorization information and user 2 authorization information on the blockchain. This obtains the authorization credential for the user-authorized service type data.
[0057] In one specific embodiment, the application on the business side provides user-generated location information and food selection data to the data processing end. The data processing end analyzes the user's food preferences based on this information to provide more accurate food recommendations within the application on the business side. Therefore, the application on the business side extracts and packages this data to form a food recommendation business dataset. This dataset contains multiple data entries, each with a user identifier (anonymized), location coordinates, and food click-through rate. Users are unaware that their data is being provided to the data processing end for data mining by the application on the business side, and the data processing end is unaware whether the application on the business side has obtained user authorization for the dataset. By traversing the user authorization information on the blockchain during dataset generation, records of unauthorized food recommendation services are deleted. The remaining target dataset is then packaged and sent to the data processing end, and a data summary of the target dataset is recorded and uploaded to the blockchain.
[0058] By uploading a dataset summary to the blockchain and linking it to the business identifier of the food recommendation service and user authorization information, users can query whether their data related to the food recommendation service has been authorized to the data processing end for analysis. Simultaneously, the data processing end acquires the target dataset, obtains the business authorization credential based on the dataset's summary information, and traces the user authorization information of at least two users on the blockchain using at least two addresses from the business authorization credential. By querying the user authorization information for the food recommendation service on the blockchain, the address of the on-chain user authorization information can be found. This address allows for the retrieval of the recorded user authorization information within the food recommendation service dataset, thus tracing its contents on the blockchain.
[0059] The business terminal determines a target dataset from the dataset based on at least two user authorization information entries; the business terminal generates a business terminal authorization credential based on the user authorization information and determines the addresses of at least two user authorization information entries on the blockchain; the business terminal sends the target dataset to the data processing terminal and uploads the business terminal authorization credential to the blockchain. This facilitates the data processing terminal in obtaining the target dataset, acquiring the business terminal authorization credential based on the data digest information of the target dataset, and tracing the user authorization information of at least two users on the blockchain based on at least two addresses of the business terminal authorization credential. Therefore, this embodiment combines the business terminal with the blockchain, enabling batch authorization of user data when the business terminal sends batches of user data (i.e., datasets) to the data processing terminal.
[0060] For other aspects of the embodiments of this application, please refer to Figure 3 Before step 400a, where the business terminal determines the dataset to be sent to the data processing terminal, the process further includes:
[0061] Step 100a: The business terminal obtains the authorization contract between the user and the business type of the business terminal.
[0062] Specifically, when a user subscribes to a service type with the service provider, an authorization process occurs, and the authorization record between the user and the service provider for that service type is recorded through an authorization contract.
[0063] Step 200a: The business terminal generates the user authorization information based on the authorization contract; wherein, the user authorization information includes at least the user authorization credential of the business type between the user and the business terminal, and the data authorization period of the user authorization credential.
[0064] The service provider generates the user authorization information based on the authorization contract. Specifically, in one embodiment, the user authorization information includes user authorization credentials for the service type between the user and the service provider, user information, service information, data digest information, data authorization period, processing method, and service provider information. User information includes user name, mobile phone number, ID card number, user nickname, etc. Service information includes service type, such as voice, call detail records, SMS volume, location information, etc. User authorization credentials for the service type between the user and the service provider may include, for example, user 1-service provider A authorization credentials, user 2-service provider A authorization credentials, indicating that user 1 and user 2 have authorization relationships with service provider A for service type 1, respectively. Data authorization period indicates the authorization period between the user and the service type of the service provider. For example, the authorization between user 1 and service provider A for service type 1 is one month, from July 1st to August 1st. Processing method includes online processing and offline processing. Service provider information refers to the name or identifier of the service provider, such as service provider A. Data digest information represents the data digest information of the target dataset.
[0065] Specifically, in one embodiment, the user authorization information includes: Xiaoming, food recommendation service, location data, data storage for 1 month, real-time processing, mobile company (business end), authorization period 20220810-20220910.
[0066] Step 300a: The business terminal uploads at least two sets of user authorization information to the blockchain.
[0067] The business unit uploads at least two sets of user authorization information to the blockchain. Specifically, the business unit uploads authorization information for multiple users with authorization relationships to the business types in the dataset to the blockchain. For example, the business unit links the user authorization information acquired daily to the blockchain. By using the blockchain to share the business unit's dataset and simultaneously managing the user data within the shared dataset for authorization, user authorization records are made immutable, user-controllable, traceable, and auditable.
[0068] In other aspects of the embodiments of this application, step 600a, in which the service terminal determines the target dataset from the dataset based on at least two pieces of user authorization information, specifically includes:
[0069] The business unit, based on at least two sets of user authorization information, deletes data from the dataset that does not include the user authorization credentials and / or whose data authorization period has expired, to obtain the target dataset.
[0070] Specifically, since each user authorization information includes at least a user authorization credential and a data authorization period for that credential, the business side can perform validity checks on the data in the dataset based on the user authorization credential and calculate the authorization period for the data in the dataset based on the data authorization period, thereby obtaining the target dataset.
[0071] Specifically, the business side can delete data of unauthorized users in the dataset based on user authorization credentials; for example, only users 1 and 2 have user authorization credentials. However, the dataset includes data for user 3, so user 3's data needs to be deleted. And / or, the business side can delete business data whose data authorization period has expired. For example, user 1's user authorization credential has a data authorization period from July 1st to August 1st, and it is currently August 5th, at which point user 1's data authorization period expires, so user 1's data in the dataset is deleted. After deleting data from the dataset that does not include the aforementioned user authorization credentials and / or whose data authorization periods have expired, the target dataset is obtained.
[0072] For other aspects of the embodiments of this application, please refer to Figure 4 The data authorization method further includes:
[0073] Step 910a: The service terminal receives a user's query request; the query request includes a user identifier.
[0074] Specifically, user identifiers include user name, mobile phone number, ID card number, and user nickname.
[0075] Step 920a: The business terminal queries the blockchain for the user authorization credential and the business terminal authorization credential that match the user identifier based on the user identifier.
[0076] Specifically, in this embodiment of the application, user authorization information is stored on the blockchain, and the user's corresponding user credentials and business authorization credentials can be retrieved through the user identifier.
[0077] For example, please refer to Figure 5The blockchain includes initial digest information for authorization of Service 1, initial digest information for authorization of Service 2, and initial digest information for authorization of Service 3. The initial digest information for authorization of Service 1 includes the authorization credential between User 1 and Service A, the authorization credential between Service A and Data Processing Terminal B, and the authorization credential between User 1 and Service B (expired). The initial digest information for authorization of Service 2 includes the authorization credential between User 1 and Service A, the authorization credential between Service A and Data Processing Terminal B, the authorization credential between User 1 and Service B, and the authorization credential between Service B and Data Processing Terminal B. The initial digest information for authorization of Service 3 includes the authorization credential between User 1 and Service B, and the authorization credential between Service B and Data Processing Terminal B. Service 1 can be a voice service type; Service 2 can be a call detail record (CDR) service type; and Service 3 can be an SMS service type.
[0078] Because each user has a unique identifier on the blockchain, the user is bound to a business based on their unique position on the chain. This is achieved using a user identifier + business type design, allowing the chain to iterate through all authorization credentials for businesses authorized by that user. When a user cancels a subscription or the authorization expires, an invalidation record for that business is inserted into the chain. When a user queries, they can iterate through the expired authorization credentials for that user and that business during that time period.
[0079] For example, if a user authorizes a food recommendation service, any subsequent authorizations granted by the service provider to other data processing terminals for the data related to the food recommendation service, as recorded on the blockchain, can be traced and retrieved on-chain. Users can use the food recommendation service identifier in the authorization to query related authorization information from various service providers, such as previous authorization certificates from the service provider to data processing terminals. When a user's agreement with the food recommendation service expires, a record of this expiration is created on the blockchain. When a user encounters this expired block record during a search, the search stops, and any subsequent authorizations from the same user related to this service are considered invalid.
[0080] Therefore, in this embodiment, the business terminal queries the blockchain for the user authorization credential and the business terminal authorization credential that match the user identifier, thereby obtaining the corresponding business terminal authorization credential for the user and the types of business data authorized. In other words, the user can query who used their data, ensuring the user's right to know, and achieving user control, traceability, and auditability.
[0081] Please refer to Figure 6 This application also proposes a data authorization method, including:
[0082] Step 100b: The data processing terminal receives the target dataset sent by the business terminal and determines the business terminal authorization credential that matches the data digest information of the target dataset on the blockchain;
[0083] Step 200b: The data processing terminal queries at least two user authorization information on the blockchain based on at least two addresses of the business terminal authorization credential;
[0084] Wherein, the user authorization information represents the authorization relationship between the user and the business type of the business terminal; the business terminal authorization credential represents the authorization relationship between the business terminal and the data processing terminal; the business terminal authorization credential includes at least two addresses of the user authorization information on the blockchain and the data digest information.
[0085] Please refer to Figure 7 For example, the data processing end receives a dataset of user location data and food selection data provided by the business end, and queries the blockchain to find the user authorization information for this data. By comparing the data digest information of the user location data and food selection data dataset with the data digest information of the business end's authorization certificate on the blockchain, it can be determined that the data obtained by the data processing end is consistent with the authorized data. The data processing end can then query the business end's authorization certificate on the blockchain, proving that the data obtained was authorized by the business party. The business end's authorization certificate includes: the data digest information of the target dataset, business information, and the blockchain address of the user authorization information. Through the blockchain address of the user authorization information and the business information, the information of the user-authorized business type on the blockchain can be traced backwards, thus proving that this data is authorized by the user.
[0086] The data processing terminal is used to analyze and process data sent by the business terminal. It receives authorization credentials from the business terminal to obtain authorization and can receive target datasets from the business terminal for data analysis and processing. Based on at least two addresses, the data processing terminal queries the blockchain for at least two user authorization information entries. This allows it to obtain user authorization credentials for the business type. Based on these authorization credentials, the data processing terminal ensures compliance with regulations regarding user data processing within the target dataset, enabling batch traceability of user authorization information on the blockchain and thus achieving batch authorization of user data.
[0087] In this embodiment of the application, the data processing terminal obtains the business terminal authorization certificate while acquiring the target dataset, and traces the user authorization information of at least two users on the blockchain based on the address. Thus, this embodiment of the application combines the business terminal with the blockchain, and realizes batch authorization of user data when the business terminal sends batch user data (i.e., dataset) to the data processing terminal.
[0088] Furthermore, this application embodiment, by storing and tracing user authorization information on the blockchain, protects the association between authorization credentials and users when the business end extracts data offline and sends it to the data processing end for processing. The data processing end can verify the authorization status of the data on the blockchain based on the authorization record information and has the right to use it. Users can query who has used their data and have the right to know. Personal data stored on the business end can be provided to the data processing end for further data exploration with user authorization, providing richer functions while improving the security of user data.
[0089] The data authorization apparatus provided in the embodiments of this application is described below. The data authorization apparatus described below and the data authorization method described above can be referred to in correspondence.
[0090] Please refer to Figure 8 A data authorization device, comprising:
[0091] The dataset determination module 201 is used to enable the business side to determine the dataset to be sent to the data processing end;
[0092] User authorization information determination module 202 is used to enable the business terminal to determine at least two user authorization information pieces located on the blockchain based on the business type of the dataset; the user authorization information represents the authorization relationship between the user and the business type of the business terminal.
[0093] The target dataset determination module 203 is used to enable the business terminal to determine the target dataset from the dataset based on at least two pieces of user authorization information;
[0094] The business-side authorization credential and address determination module 204 is used to enable the business end to generate a business-side authorization credential based on the data digest information of the target dataset. The business-side authorization credential represents the authorization relationship between the business end and the data processing end. The business-side authorization credential includes at least two addresses of the user authorization information on the blockchain and the data digest information.
[0095] The data sending module 205 is used to enable the business terminal to send the target dataset to the data processing terminal and upload the business terminal authorization certificate to the blockchain.
[0096] The data authorization device in this embodiment determines a target dataset from the dataset based on at least two user authorization information pieces by the business terminal; generates a business terminal authorization credential based on the user authorization information and determines the addresses of at least two user authorization information pieces on the blockchain; sends the target dataset to the data processing terminal by the business terminal and uploads the business terminal authorization credential to the blockchain. This facilitates the data processing terminal in obtaining the target dataset, acquiring the business terminal authorization credential based on the data digest information of the target dataset, and tracing the user authorization information of at least two users on the blockchain based on at least two addresses of the business terminal authorization credential. Thus, this embodiment combines the business terminal with the blockchain, enabling batch authorization of user data when the business terminal sends batches of user data (i.e., datasets) to the data processing terminal.
[0097] In one embodiment, the data authorization device further includes:
[0098] The authorization contract acquisition module is used to enable the business terminal to acquire the authorization contract between the user and the business type of the business terminal.
[0099] The user authorization information generation module is used to enable the business terminal to generate the user authorization information based on the authorization contract.
[0100] The on-chain module is used to enable the business terminal to upload at least two sets of user authorization information to the blockchain;
[0101] The user authorization information includes at least the user authorization credentials for the business type of the user and the business terminal, as well as the data authorization period of the user authorization credentials.
[0102] In one embodiment, the target dataset determination module is specifically used by the business side to delete data of users in the dataset that do not include the user authorization credentials and / or whose data authorization period has expired, based on at least two user authorization information, to obtain the target dataset.
[0103] In one embodiment, the data authorization device further includes:
[0104] A query request receiving module is used to enable the business terminal to receive user query requests; the query request includes a user identifier.
[0105] The query module is used to enable the business terminal to query the user authorization credential and the business terminal authorization credential that match the user identifier on the blockchain based on the user identifier.
[0106] Please refer to Figure 9 This application also provides a data authorization device, including:
[0107] Data receiving module 206 is used to enable the data processing terminal to receive the target dataset sent by the business terminal, and to determine the business terminal authorization credential that matches the data digest information of the target dataset on the blockchain;
[0108] Query module 207 is used to enable the data processing terminal to query at least two user authorization information of the user on the blockchain based on at least two addresses of the business terminal authorization credential;
[0109] Wherein, the user authorization information represents the authorization relationship between the user and the business type of the business terminal; the business terminal authorization credential represents the authorization relationship between the business terminal and the data processing terminal; the business terminal authorization credential includes at least two addresses of the user authorization information on the blockchain and the data digest information.
[0110] In this embodiment of the application, the data processing terminal obtains the business terminal authorization certificate while acquiring the target dataset, and traces the user authorization information of at least two users on the blockchain based on the address. Thus, this embodiment of the application combines the business terminal with the blockchain, and realizes batch authorization of user data when the business terminal sends batch user data (i.e., dataset) to the data processing terminal.
[0111] Figure 10 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 10 As shown, the electronic device may include a processor 1010, a communication interface 1020, a memory 1030, and a communication bus 1040, wherein the processor 1010, the communication interface 1020, and the memory 1030 communicate with each other via the communication bus 1040. The processor 1010 may call a computer program in the memory 1030 to execute steps of a data authorization method, such as: the service terminal determining the dataset to be sent to the data processing terminal;
[0112] The business terminal determines at least two user authorization information entries located on the blockchain based on the business type of the dataset; the user authorization information represents the authorization relationship between the user and the business type of the business terminal; the business terminal determines a target dataset from the dataset based on the at least two user authorization information entries; the business terminal generates a business terminal authorization credential based on the data digest information of the target dataset, the business terminal authorization credential represents the authorization relationship between the business terminal and the data processing terminal; the business terminal authorization credential includes at least the addresses of the two user authorization information entries on the blockchain and the data digest information; the business terminal sends the target dataset to the data processing terminal and uploads the business terminal authorization credential to the blockchain. Alternatively, the data processing terminal receives a target dataset sent by the business terminal and determines a business terminal authorization credential that matches the data digest information of the target dataset on the blockchain; the data processing terminal queries at least two user authorization information on the blockchain based on at least two addresses of the business terminal authorization credential; wherein, the user authorization information represents the authorization relationship between the user and the business type of the business terminal; the business terminal authorization credential represents the authorization relationship between the business terminal and the data processing terminal; the business terminal authorization credential includes at least two addresses of the user authorization information on the blockchain and the data digest information.
[0113] Furthermore, the logical instructions in the aforementioned memory 1030 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0114] On the other hand, this application also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can perform the steps of the data authorization method provided in the above embodiments, such as: the business end determines a dataset to be sent to the data processing end; the business end determines at least two user authorization information located on the blockchain based on the business type of the dataset; the user authorization information represents the authorization relationship between the user and the business type of the business end; the business end determines a target dataset from the dataset based on the at least two user authorization information; the business end generates a business end authorization certificate based on the data digest information of the target dataset, the business end authorization certificate representing the authorization relationship between the business end and the data processing end; the business end authorization certificate includes at least the addresses of the two user authorization information on the blockchain and the data digest information; the business end sends the target dataset to the data processing end and uploads the business end authorization certificate to the blockchain. Alternatively, the data processing terminal receives a target dataset sent by the business terminal and determines a business terminal authorization credential that matches the data digest information of the target dataset on the blockchain; the data processing terminal queries at least two user authorization information on the blockchain based on at least two addresses of the business terminal authorization credential; wherein, the user authorization information represents the authorization relationship between the user and the business type of the business terminal; the business terminal authorization credential represents the authorization relationship between the business terminal and the data processing terminal; the business terminal authorization credential includes at least two addresses of the user authorization information on the blockchain and the data digest information.
[0115] On the other hand, embodiments of this application also provide a processor-readable storage medium storing a computer program for causing a processor to execute the steps of the data authorization method provided in the above embodiments, such as: a business terminal determining a dataset to be sent to a data processing terminal; the business terminal determining at least two user authorization information located on a blockchain based on the business type of the dataset; the user authorization information representing the authorization relationship between the user and the business type of the business terminal; the business terminal determining a target dataset from the dataset based on the at least two user authorization information; the business terminal generating a business terminal authorization credential based on the data digest information of the target dataset, the business terminal authorization credential representing the authorization relationship between the business terminal and the data processing terminal; the business terminal authorization credential including at least the addresses of the two user authorization information on the blockchain and the data digest information; the business terminal sending the target dataset to the data processing terminal and uploading the business terminal authorization credential to the blockchain. Alternatively, the data processing terminal receives a target dataset sent by the business terminal and determines a business terminal authorization credential that matches the data digest information of the target dataset on the blockchain; the data processing terminal queries at least two user authorization information on the blockchain based on at least two addresses of the business terminal authorization credential; wherein, the user authorization information represents the authorization relationship between the user and the business type of the business terminal; the business terminal authorization credential represents the authorization relationship between the business terminal and the data processing terminal; the business terminal authorization credential includes at least two addresses of the user authorization information on the blockchain and the data digest information.
[0116] The processor-readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to magnetic memory (e.g., floppy disk, hard disk, magnetic tape, magneto-optical disk (MO)), optical memory (e.g., CD, DVD, BD, HVD), and semiconductor memory (e.g., ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state drive (SSD)).
[0117] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0118] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the embodiments or some parts of the embodiments.
[0119] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A data authorization method, characterized in that, include: The business side obtains the authorization contract between the user and the business type of the business side; The business terminal generates user authorization information based on the authorization contract. The user authorization information represents the authorization relationship between the user and the business type. The user authorization information includes at least the user authorization credential between the user and the business type, and the data authorization period of the user authorization credential. The business unit will upload at least two sets of user authorization information to the blockchain; The business unit determines the dataset to be sent to the data processing unit; Based on the business type of the dataset, the business terminal determines at least two user authorization information located on the blockchain; The business unit determines the target dataset from the dataset based on at least two pieces of user authorization information; The business terminal generates a business terminal authorization certificate based on the data summary information of the target dataset, and the business terminal authorization certificate represents the authorization relationship between the business terminal and the data processing terminal; The business authorization credential includes at least two addresses of the user authorization information on the blockchain and the data digest information; The business terminal sends the target dataset to the data processing terminal and uploads the business terminal authorization certificate to the blockchain.
2. The data authorization method according to claim 1, characterized in that, The business unit determines the target dataset from the dataset based on at least two pieces of user authorization information, including: The business unit, based on at least two sets of user authorization information, deletes data from the dataset that does not include the user authorization credentials and / or whose data authorization period has expired, to obtain the target dataset.
3. The data authorization method according to claim 1, characterized in that, The data authorization method further includes: The service terminal receives a user's query request; the query request includes a user identifier. The business terminal queries the blockchain for the user authorization credential and the business terminal authorization credential that match the user identifier based on the user identifier.
4. A data authorization method, characterized in that, include: The data processing terminal receives a target dataset sent by the business terminal and determines a business terminal authorization credential that matches the data digest information of the target dataset on the blockchain. The target dataset is obtained by the business terminal through the following steps: the business terminal obtains an authorization contract between a user and the business type of the business terminal, and generates user authorization information based on the authorization contract. The user authorization information represents the authorization relationship between the user and the business type, and includes at least a user authorization credential between the user and the business type, and the data authorization period of the user authorization credential; the business terminal uploads at least two pieces of the user authorization information to the blockchain; when a dataset to be sent to the data processing terminal is determined, at least two pieces of user authorization information located on the blockchain are determined based on the business type of the dataset; the target dataset is determined from the dataset based on the at least two pieces of user authorization information. The data processing terminal queries at least two user authorization information on the blockchain based on at least two addresses of the business terminal authorization credential; Wherein, the user authorization information represents the authorization relationship between the user and the business type of the business terminal; the business terminal authorization credential represents the authorization relationship between the business terminal and the data processing terminal; the business terminal authorization credential includes at least two addresses of the user authorization information on the blockchain and the data digest information.
5. A data authorization device, characterized in that, include: The authorization contract acquisition module is used to enable the business terminal to acquire the authorization contract between the user and the business type of the business terminal; The user authorization information generation module is used to enable the business terminal to generate user authorization information based on the authorization contract. The user authorization information represents the authorization relationship between the user and the business type. The user authorization information includes at least the user authorization credential of the user and the business type, and the data authorization period of the user authorization credential. The on-chain module is used to enable the business terminal to upload at least two sets of user authorization information to the blockchain; The dataset determination module is used to enable the business terminal to determine the dataset to be sent to the data processing terminal; The user authorization information determination module is used to enable the business terminal to determine at least two user authorization information located on the blockchain based on the business type of the dataset. The user authorization information represents the authorization relationship between the user and the business type of the business terminal; The target dataset determination module is used to enable the business terminal to determine the target dataset from the dataset based on at least two pieces of user authorization information; The business-side authorization credential and address determination module is used to enable the business-side to generate a business-side authorization credential based on the data digest information of the target dataset, wherein the business-side authorization credential represents the authorization relationship between the business-side and the data processing end; The business authorization credential includes at least two addresses of the user authorization information on the blockchain and the data digest information; The data sending module is used to enable the business terminal to send the target dataset to the data processing terminal and upload the business terminal authorization certificate to the blockchain.
6. A data authorization device, characterized in that, include: A data receiving module is used to enable a data processing terminal to receive a target dataset sent by a business terminal, and to determine a business terminal authorization credential that matches the data digest information of the target dataset on the blockchain. The target dataset is obtained by the business terminal through the following steps: the business terminal obtains an authorization contract between a user and a business type, and generates user authorization information based on the authorization contract. The user authorization information represents the authorization relationship between the user and the business type, and includes at least a user authorization credential between the user and the business type, and the data authorization period of the user authorization credential; the business terminal uploads at least two pieces of the user authorization information to the blockchain; when a dataset to be sent to the data processing terminal is determined, at least two pieces of user authorization information located on the blockchain are determined based on the business type of the dataset; and the target dataset is determined from the dataset based on the at least two pieces of user authorization information. The query module is used to enable the data processing terminal to query at least two user authorization information of the user on the blockchain based on at least two addresses of the authorization credentials of the business terminal; Wherein, the user authorization information represents the authorization relationship between the user and the business type of the business terminal; the business terminal authorization credential represents the authorization relationship between the business terminal and the data processing terminal; the business terminal authorization credential includes at least two addresses of the user authorization information on the blockchain and the data digest information.
7. An electronic device comprising a processor and a memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the data authorization method according to any one of claims 1 to 3 or claim 4.
8. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the data authorization method as described in any one of claims 1 to 3 or 4.
9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the data authorization method according to any one of claims 1 to 3 or claim 4.
Citation Information
Patent Citations
Private data processing method, device and equipment of block chain and storage medium
CN111737366A
File evidence storage method and system based on block chain and server
CN112383611A