A Cross-Domain Trusted Certification Method and Storage Medium for the Right to Operate Data Products
By issuing business rights authorization certificates to dealers and verifying business rights using public key infrastructure and bilinear mapping algorithms, the problem of forgery business rights in data transactions is solved, and efficient and secure data circulation and sharing are achieved.
Patent Information
- Application Number
- CN202311386250.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-23
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2043-10-23
AI Technical Summary
The existing technology cannot effectively prevent malicious dealers from forging proof of business rights in data transactions, and it brings massive computing, communication and storage overhead when a large number of data products is authorized, and it is impossible to generate proof of business rights on demand.
The data product owner issues operating rights authorization certificates to the dealer, and the dealer generates operating rights certificates as needed. The user verifies the dealer's operating rights through interactive verification, and uses public key infrastructure and bilinear mapping algorithm to ensure the credibility of the verification.
It realizes credible proof of data product operating rights in cross-domain data transactions, prevents forgery of operating rights, reduces calculation and storage overhead, supports flexible proof generation on demand, and ensures safe circulation and sharing of data.
Smart Images

Figure CN117422467B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security transactions, and particularly to a cross-domain trusted certification method and storage medium for the right to operate data products. Background Art
[0002] The growing massive data has penetrated into every industry functional field. The compliant circulation of data is the basis and prerequisite for improving the data factor market. In actual data transactions, the right attributes of data products often show separation, that is, the data resource ownership, data processing and usage rights, and the right to operate data products of the same data product may belong to different entities. Specifically, in data transactions, the data product owner has the ownership of the data product and authorizes some of the held data products to a dealer for sale; the dealer has the data processing and usage rights and the right to operate the data product; users at the dealer can directly purchase data products through the dealer.
[0003] Data transactions are of great significance for promoting data circulation and bringing data value into play. In data transactions, data right confirmation is an important prerequisite for realizing the safe and orderly flow of data and the circulation of data factors. The separation of right attributes can relieve the data product owner from the burden of processing frequent data transaction requests, and at the same time, provide personalized services for users. However, in practical applications, malicious dealers may tamper with data content, resulting in users being unable to obtain the original data they need; they may pirate and sell unauthorized data, damaging the rights and interests of data product owners. Therefore, it is necessary to conduct right confirmation verification on the right to operate data, that is, to prove that the dealer actually has the right to operate the authorized data products.
[0004] To prove the right to operate data products, an intuitive method is for the data product owner to generate corresponding right-to-operate certificates for each authorized data product. However, the generation and verification overhead of such right-to-operate certificates is proportional to the number of authorizations. When the number of authorized data is large, it will bring massive computing, communication, and storage overhead.
[0005] The present invention proposes an efficient cross-domain trusted certification method for the right to operate data products. The data product owner issues corresponding right-to-operate authorization certificates according to the set of data products purchased by the dealer; the dealer generates corresponding right-to-operate proofs as needed according to the data products purchased by the user; the user verifies the dealer's right to operate through interaction with the dealer. The present invention realizes the trusted certification of the right to operate data products in cross-domain data transactions, supports the dealer to flexibly generate right-to-operate proofs of data products as needed, and supports the cross-domain secure circulation and sharing of data.
[0006] In the prior art, for example, CN115375505A discloses a method for generating a trustworthy certificate of electricity-carbon data based on blockchain. Source-side business data is obtained from an external business system, and power process information data is obtained through processing based on the source-side business data. The power full-process information data is uploaded to the blockchain through a data on-chain module. Based on the characteristic that the data on the blockchain is difficult to tamper with, the power process information data is protected, and a green electricity usage certificate, a carbon emission reduction certificate, and a green electricity consumption certificate are provided based on the on-chain data to achieve trustworthy data storage and evidence.
[0007] However, it cannot prevent the forgery of the business operation right certificate, and the data content may be tampered with, resulting in users being unable to obtain the original data they need. When the amount of data is large, it will bring a huge amount of computing, communication, and storage overhead and cannot generate certificates on demand. Summary of the Invention
[0008] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a method for cross-domain trustworthy certification of data product business operation rights.
[0009] The purpose of the present invention is achieved through the following technical solutions:
[0010] A method for cross-domain trustworthy certification of data product business operation rights, in which the data product owner issues corresponding business operation right authorization certificates according to the set of data products purchased by the dealer; the dealer generates corresponding business operation right certificates on demand according to the data products purchased by the user; the user verifies the dealer's business operation rights through interaction with the dealer, specifically including the following steps: S1: System initialization stage: The system is initialized according to security parameters to determine the system public parameter set pp; the data product owner generates its public and private keys (pk a , sk a ), and the dealer generates its public and private keys (dsk, dpk); S2: Data product business operation right authorization stage: The data product owner issues the business operation right authorization certificate σ to the dealer a ; S3: Data product business operation right verification stage: The user verifies the validity of the business operation right authorization certificate σ a '.
[0011] Preferably, the S2: Data product business operation right authorization stage further includes the following steps: S21: The dealer purchases data products from the data product owner and requests data product business operation right authorization from it; S22: Authenticates the authorization request of and the dealer identity of . If the authentication passes, the business operation right authorization certificate σ is issueda , otherwise, reject the authorization request.
[0012] Preferably, the S3: data product operation right verification stage further includes the following steps: S31: According to the user's purchase request, the dealer exports the operability certificate σ′ of the corresponding data product as needed based on the authorization certificate of the data product owner a ; S32: The user verifies the validity of σ′ a by interacting with the dealer, so as to confirm whether the dealer has obtained the authorization of the owner.
[0013] Preferably, the S1: system initialization stage further includes the following steps: Determine the system public parameter set according to the security parameters where p is a prime number, and are cyclic groups of order p, e: is a bilinear mapping, are the generators uniformly and randomly selected in and respectively; there are q mutually independent data product owners in this system, denoted as where the data product dimension is n a , and the data product set is Generate the corresponding public and private keys (sk a , pk a ) according to the following steps: S11: Uniformly and randomly select n a +2 numbers: S12: Calculate:
[0014]
[0015]
[0016]
[0017]
[0018] According to the above steps, take as the private key, and the corresponding public key is The dealer generates the corresponding public and private keys (dsk, dpk) according to the following steps: S13: Uniformly and randomly select S14: Calculate
[0019] Preferably, the specific steps of the S2 data product business operation right authorization stage are as follows: The data product owner and the dealer complete the authorization operation of the data product business operation right for the dealer according to the following steps: S211: The dealer uniformly and consistently selects calculate S212: Purchase the data product from the data product owner and send a data product business operation right authorization request Q = {dpk, A}; S213: After receiving Q, uniformly and consistently select and send e to S214: After receiving e, calculate z = a + e · dsk and send z to S215: Verify If the verification passes, it means passed the identity authentication and continue the authorization operation; otherwise, reject the authorization request; S216: According to the purchased data product, determine the authorized data product set and the corresponding index set S217: uniformly and consistently select S218: Calculate the following:
[0020] to obtain the business operation right authorization certificate S219: Send to
[0021] Preferably, the specific steps of the S3: data product business operation right verification stage are as follows: First, according to the user's purchase request, the dealer exports the business operation right certificate for the user's purchased data product as needed based on the authorization certificate of the data product owner. The specific steps are as follows: S311: The user sends a purchase data product request where is a subset of the data product index set with business operation rights, S312: According to the purchase data product request, obtain the distributed data product set {M a} 1≤a≤q , where the data product set is a subset of the authorized data product set from ; S313: Obtain according to Obtain according to Calculate S314: Uniformly and consistently select S315: According to the data product set M a , the index set and the business operation authorization certificate σ a calculate:
[0022] S316: According to the purchase data product request of obtain the business operation right certificate of the data product at the sales After the dealer generates the business operation right certificate as needed, the dealer and its user complete the verification operation of the dealer's data product business operation right according to the following steps: S317: Send to the user S318: The user Uniformly and consistently select and send c to S319: After receiving c, calculate s = k + c · dsk and send s to S320: Calculate
[0023]
[0024] S321: Judge whether the following equation holds:
[0025]
[0026]
[0027] If for the business operation right certificate σ a ′, the above equations all hold, the verification passes, and it is confirmed that the dealer has obtained the authorization from the data product owner , otherwise, the verification fails.
[0028] On the other hand, the present invention provides a computer-readable storage medium storing computer-executable instructions, which, when loaded and executed by a processor, implement the method for cross-domain trusted certification of data product management rights as described in any one of claims 1-6.
[0029] The beneficial effects of the present invention are as follows:
[0030] 1) It can prevent malicious dealers from forging management right certificates because the data product management right verification stage ensures that any dishonest operation by the dealer will result in the failure of verification.
[0031] 2) Compared with the intuitive management right confirmation method, it supports data dealers to flexibly generate management right certificates for data products as needed, supporting cross-domain secure circulation and sharing of data. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 It is a flowchart of the method for cross-domain trusted certification of data product management rights. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0033] Next, the technical solutions of the present invention will be clearly and completely described in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0034] The present invention provides a method for cross-domain trusted certification of data product management rights:
[0035] (I) System initialization stage
[0036] Determine the system public parameter set according to the security parameters where p is a prime number, and are cyclic groups of order p, e: is a bilinear mapping, are respectively randomly and uniformly selected generators in and .
[0037] In this system, there are q independent data product owners, denoted as where the data product dimension of a is n Generate the corresponding public and private keys (sk a , pk a ) according to the following steps:
[0038] 1) Uniformly and consistently select n a +2 numbers:
[0039] 2) Calculate:
[0040]
[0041]
[0042]
[0043]
[0044] According to the above steps, Take as the private key, and the corresponding public key is
[0045] The dealer Generates the corresponding private and public keys (dsk, dpk) according to the following steps:
[0046] 1) Uniformly and consistently select
[0047] 2) Calculate
[0048] (II) Authorization stage of the data product operation right
[0049] The data owner and the dealer complete the authorization operation of the data product operation right for the dealer according to the following steps:
[0050] 1) The dealer Uniformly and consistently select Calculate
[0051] 2) Purchase the data product from the data product owner and send a data product operation right authorization request Q = {dpk, A} to it;
[0052] 3) After receiving Q, uniformly and consistently select and send e to
[0053] 4) After receiving e, calculate z = a + e · dsk and send z to
[0054] 5) Verify If the verification is passed, it means that Passed the identity authentication, continue with the authorization operation, otherwise, reject the authorization request;
[0055] 6) According to the purchased data products, determine the authorized data product set and the corresponding index set
[0056] 7) Uniformly and consistently select
[0057] 8) Calculate the following:
[0058]
[0059]
[0060] Obtain the business operation right authorization certificate
[0061] 9) Send to
[0062] (3) Data Product Business Operation Right Verification Phase
[0063] First, according to the user's purchase request, the distributor exports the business operation right certificate for the data products requested by the user as needed from the authorization certificate of the data product owner. The specific steps are as follows:
[0064] 1) The user Sends a purchase data product request where is a subset of the index set of data products with business operation rights,
[0065] 2) According to the purchase data product request, obtain the distributed data product set {M a} 1≤a≤q . Among them, the data product set is a subset of the authorized data product set from
[0066] 3) According to Obtain According to obtain calculate
[0067] 4) uniformly and consistently select
[0068] 5) According to the data product set M a , the index set and the business operation right authorization certificate σ a calculate:
[0069]
[0070]
[0071]
[0072]
[0073]
[0074] 6) According to the purchase data product request, obtain the business operation right certificate of the data product at the sales location
[0075]
[0076] After the distributor generates the business operation right certificate as needed, the distributor and its users complete the verification operation of the distributor's data product business operation right according to the following steps:
[0077] 1) Send to the user
[0078] 2) The user uniformly and consistently selects and sends c to
[0079] 3) After receiving c, calculate s = k + c • dsk and send s to
[0080] 4) Calculate
[0081] 5) Judge whether the following equation holds:
[0082]
[0083]
[0084] If for the proof of the right to operate σ a ′, the above equations all hold, the verification passes, and it is confirmed that the dealer has obtained the authorization of the data product owner . Otherwise, the verification fails.
[0085] On the other hand, the present invention provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are loaded and executed by a processor, the cross-domain trusted proof method for the right to operate a data product according to any one of claims 1-6 is implemented.
[0086] The above are only the preferred embodiments of the present invention. It should be understood that the present invention is not limited to the forms disclosed herein, should not be regarded as excluding other embodiments, but can be used in various other combinations, modifications and environments, and can be changed within the scope of the concept described herein through the above teachings or the technology or knowledge in related fields. And any changes and modifications made by those skilled in the art without departing from the spirit and scope of the present invention shall fall within the protection scope of the appended claims of the present invention.
Claims
1. A cross-domain trusted certification method for the right to operate data products, characterized in that: The data product owner issues corresponding operation right authorization certificates according to the set of data products purchased by the distributor; the distributor generates corresponding operation right certificates as needed according to the data products purchased by the user; the user verifies the operation right of the distributor by interacting with the distributor, which specifically includes the following steps: S1: System initialization phase: Initialize the system according to security parameters to determine the system public parameter set pp; the data product owner generates its public and private keys (pk a , sk a ), and the dealer generates its public and private keys (dsk, dpk); S2: Data product operation right authorization stage: The data product owner issues the operation right authorization certificate σ to the distributor ; a ; S3: Data product operation right verification stage: According to the user's purchase request, the dealer exports the corresponding operation right certificate σ' as needed a , and the user can verify the validity of the operation right certificate σ' a . The S2 mentioned above: The data product operation right authorization stage further includes the following steps: S21: Dealer purchases a data product from the data product owner and requests authorization for the right to operate the data product from the data product owner; S22: Authenticate the identity of the dealer. If the authentication is successful, issue an operating right authorization certificate σ a , otherwise, reject the authorization request; The S3 mentioned above: The data product operation right verification stage further includes the following steps: S31: According to the user's request, the dealer exports the business operation right certificate σ' of the corresponding data product on demand based on the authorization certificate of the data product owner a ; S32: The user verifies the validity of σ′ a by interacting with the distributor, so as to confirm whether the distributor has obtained the authorization of the data product owner; The S1 mentioned above: The system initialization stage further includes the following steps: Determine the system public parameter set according to the security parameters where p is a prime number and is a cyclic group of order p is a bilinear mapping, g are respectively the generators uniformly and randomly selected from and There are q mutually independent data product owners in this system, denoted as Among them, the dimension of the data product is n a , and the data product set is Generate the corresponding public and private keys (pk a , sk a ) according to the following steps: S11: Uniformly and consistently select n a +2 numbers: S12: Calculate: According to the above steps, Take as the private key, and the corresponding public key is Dealer Generate the corresponding public and private keys (dsk, dpk) according to the following steps: S13: Select uniformly S14: Calculate The specific steps of the S2 data product operation right authorization stage are as follows: The data product owner and the distributor complete the authorization operation of the distributor's data product operation right according to the following steps: S211: Dealer Select uniformly Calculate S212: Purchase a data product from the data product owner and send a data product operation right authorization request Q = {dpk, A} to it; S213: After receiving Q, uniformly and consistently select and send e to S214: After receiving e, calculate z = a + e·dsk and send z to S215: Verify If the verification is passed, it means the passed identity authentication, continue with the authorization operation, otherwise, reject the authorization request; S216: Determine the authorized data product set and the corresponding index set based on the purchased data products S217: Select uniformly S218: Calculate the following: Obtain the business operation authorization certificate S219: Send to The S3 mentioned above: The specific steps of the data product operation right verification stage are as follows: First, according to the purchase request of the user, the distributor exports the operation right certificate for the data product requested by the user as needed based on the authorization certificate of the data product owner. The specific steps are as follows: S311: User Send A request to purchase a data product Wherein Is A subset of the set of data product indices with the right to operate S312: Obtain the distribution data product set {M } according to the purchase data product request, where the data product set a} 1≤a≤q is a subset of the authorized data product set from ; S313: According to obtain According to obtain Calculate S314: Select uniformly S315: Based on the data product set M a , the index set and the business operation authorization certificate σ a Calculate: S316: Obtain the right to operate the data product at the sales based on the purchase data product request certificate After the distributor generates the operation right certificate as needed, it and its user complete the verification operation of the distributor's data product operation right according to the following steps: S317: Send {{M a} 1≤a≤q , C, {σ a '} 1≤a≤q} to the user S318: User Select uniformly And send c to S319: After receiving c, calculate s = k + c·dsk and send s to S320: Calculate S321: Determine whether the following equation holds: If for the right-of-operation certificate σ a ′, the above equations all hold, the verification passes, and it is confirmed that the dealer has obtained the authorization of the data product owner . Otherwise, the verification fails.
2. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are loaded and executed by a processor, the cross-domain trusted proof method for data product operation rights described in claim 1 is implemented.
Citation Information
Patent Citations
Electricity and carbon data credible proof generation method based on block chain
CN115375505A
Data product transaction method supporting privacy protection and credible supervision
CN116188008A