A data authorization method and system for data element transaction

By collaborating with third-party CA institutions through a data ownership confirmation system, certificates and key pairs are generated, resolving the issue of inconsistent standards in data exchanges, enabling secure and legal data transactions and reasonable use, and improving the standardization and security of the data element market.

CN117614651BActive Publication Date: 2025-10-24AISINO CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311432799.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-10-31
Publication Date
2025-10-24
Estimated Expiration
2043-10-31

AI Technical Summary

Technical Problem

my country's data element market has not yet formed a unified basic system for data ownership, valuation and pricing, circulation and trading, and security governance. This has led to inconsistencies in the standards and business rules of data exchanges, which affect the circulation and value release of data elements.

Method used

By collaborating with third-party CA institutions through a data ownership confirmation system, we generate and issue certificates and public key certificates, establish a mapping table, and generate key pairs to implement data authorization policies and encrypted storage on the data operator's end, thereby ensuring data security.

Benefits of technology

It effectively ensures the security and legality of data, supports the reasonable use of data by data operators, prevents data leakage, and improves the standardization and security of data transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117614651B_ABST
    Figure CN117614651B_ABST
Patent Text Reader

Abstract

The application discloses a data authorization method and system for data element transaction, and belongs to the technical field of data processing. The method comprises the following steps: auditing the identity information of a user UserA according to a p10 request by a third-party CA institution; returning a certificate CertA for a data right system DS and a data operator end PlatformB by the third-party CA institution, and issuing a public key certificate CertB to the data operator end PlatformB by the third-party CA institution; generating a mapping relationship table MapC according to the certificate CertA and the public key certificate CertB by the data operator end PlatformB; authorizing the data of the user UserA to the data operator end PlatformB; and obtaining the data authorized by the user UserA to the data operator end PlatformB. The application can effectively guarantee the data security of the user side.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and more particularly, to a data authorization method and system for data element transaction. BACKGROUND

[0002] The strategic layout of China's data element market is constantly evolving and deepening. At present, data elements have been widely used in intelligent risk control, advertisement recommendation and other scenarios in the fields of finance, Internet, etc.

[0003] With the continuous maturity of data theory and technology, the continuous improvement of data circulation system, the continuous improvement of data fusion, and the accelerated assistance of new generation information technology, the value of data elements is constantly released, and the contribution of data elements to the economy will be higher and higher. In the institutional dimension, the basic system of data elements in China is still not perfect, and a clear and unified basic system of data ownership, evaluation and pricing, circulation and transaction, income distribution, and security governance has not yet been formed. It is still necessary to accelerate the construction of data basic system to better release the potential of data elements and promote the high-quality development of digital economy, and inject strong momentum into the construction of modern economic system and the construction of new national competitive advantage. China's data element circulation market is still in its infancy, with nearly 40 local and industry data exchanges, but there is no unified national data exchange, and the standards, guidelines and business rules developed by each data exchange for each link of data element circulation are not the same. SUMMARY

[0004] To solve the above problems, the present application provides a data authorization method for data element transaction, comprising:

[0005] After a user UserA logs in a data right system DS, the data right system DS creates a p10 request for the user UserA and sends the p10 request to a third-party CA institution, and the third-party CA institution audits the identity information of the user UserA according to the p10 request;

[0006] If the identity information of the user UserA passes the audit of the third-party CA institution, the third-party CA institution returns a signed certificate CertA for the data right system DS and a data operator end PlatformB, and the third-party CA institution issues a public key certificate CertB to the data operator end PlatformB;

[0007] According to the signed certificate CertA and the public key certificate CertB, the data operator end PlatformB generates a mapping relationship table MapC;

[0008] A data authorization policy for the data operator end PlatformB is generated by a data right system DS according to the signing certificate CertA, and a key KeyPA and a key KeyPB are generated according to the authorization policy, the key KeyPA and the key KeyPB are issued to the data operator end PlatformB, and the authorized data of the user UserA is authorized to the data operator end PlatformB;

[0009] In the data operator end PlatformB, the data authorized by the user UserA to the data operator end PlatformB is obtained based on the key KeyPA, the key KeyPB and the mapping relationship table MapC.

[0010] Optionally, after the user UserA logs in the data right system DS, the data right system DS creates a p10 request for the user UserA, including:

[0011] After the user UserA logs in the client DsClient of the data right system DS, the identity information input by the user UserA is obtained through the client DsClient, and a pair of public and private keys for identity authentication is generated based on the identity information and a trusted hardware medium, and the private key in the public and private keys is used to create a p10 request.

[0012] Optionally, the private key in the public and private keys is retained for the user UserA.

[0013] Optionally, the third-party CA institution issues the signing certificate CertA and the public key certificate CertB to the server DsServer of the data right system DS, and the server DsServer retains the signing certificate CertA and the public key certificate CertB;

[0014] The third-party CA institution issues the public key certificate CertB to the data operator end PlatformB, and the data operator end PlatformB obtains the signing certificate CertA generated by the third-party CA institution through the public key certificate CertB.

[0015] Optionally, the mapping relationship table MapC is generated by the data operator end PlatformB according to the signing certificate CertA and the public key certificate CertB, including:

[0016] In the data operator end PlatformB, the unique ID information of the data authorized by the user UserA is obtained, and the unique ID information is bound using the signing certificate CertA to generate the mapping relationship table MapC.

[0017] Optionally, the key KeyPA and the key KeyPB are sent to the data operator end PlatformB, and specifically include:

[0018] When the data authorization of the data operator end PlatformB is not opened, the key KeyPA and the key KeyPB are sent to a third-party CA institution, the key KeyPA is sent to the service end DsServer for storage via the third-party CA institution, the key KeyPB is sent to the data operator end PlatformB for storage, the key KeyPA is sent to the data operator end PlatformB by the service end DsServer, and the data operator end PlatformB stores the authorized data of the user UserA based on the key KeyPA, the key KeyPB and the mapping relationship table MapC.

[0019] Optionally, the data operator end PlatformB obtains the data authorized by the user UserA based on the key KeyPA, the key KeyPB and the mapping relationship table MapC, and specifically includes:

[0020] When the data authorization of the data operator end PlatformB is opened, the client DsClient sends the key KeyPA to the data operator end PlatformB in the form of a digital envelope, the data operator end PlatformB uses the stored key KeyPB and the key KeyPA sent by the client DsClient to form a key pair, and decrypts the encrypted authorized data of the user UserA according to the key pair and the mapping relationship table MapC to obtain the authorized data of the user UserA.

[0021] In still another aspect, the application further provides a data authorization system for data element transaction, which includes:

[0022] An identity authentication unit is configured to create a p10 request for the user UserA after the user UserA logs in the data authorization system DS, send the p10 request to a third-party CA institution, and audit the identity information of the user UserA according to the p10 request by the third-party CA institution.

[0023] a certificate issuing unit configured to, after the identity information of the user UserA is audited by the third-party CA institution, return a signed certificate CertA for the data right system DS and the data operator end PlatformB by the third-party CA institution, and issue a public key certificate CertB to the data operator end PlatformB by the third-party CA institution;

[0024] a mapping unit configured to, by the data operator end PlatformB, generate a mapping relationship table MapC according to the signed certificate CertA and the public key certificate CertB;

[0025] an authorization unit configured to, according to the signed certificate CertA, generate a data authorization policy for the data operator end PlatformB by the data right system DS, and according to the authorization policy, generate a key KeyPA and a key KeyPB, and issue the key KeyPA and the key KeyPB to the data operator end PlatformB, and authorize the data of the user UserA to the data operator end PlatformB;

[0026] a data acquisition unit configured to, based on the key KeyPA, the key KeyPB and the mapping relationship table MapC, obtain the data authorized by the user UserA to the data operator end PlatformB by the data operator end PlatformB.

[0027] Optionally, after the user UserA logs in the data right system DS, the data right system DS creates a p10 request for the user UserA, including:

[0028] After the user UserA logs in the client DsClient of the data right system DS, the identity information of the user UserA is obtained by the client DsClient, and a pair of public and private keys for identity authentication is generated based on the identity information and a trusted hardware medium, and the p10 request is created by using the private key in the public and private keys.

[0029] Optionally, the private key in the public and private keys is retained to the user UserA.

[0030] Optionally, the third-party CA institution issues the signed certificate CertA and the public key certificate CertB to the server DsServer of the data right system DS, and the server DsServer retains the signed certificate CertA and the public key certificate CertB;

[0031] The third-party CA institution issues a public key certificate CertB to the data operator end PlatformB, and the data operator end PlatformB obtains the issuing certificate CertA generated by the third-party CA institution through the public key certificate CertB.

[0032] Optionally, the data operator end PlatformB generates a mapping relationship table MapC according to the issuing certificate CertA and the public key certificate CertB, including:

[0033] The data operator end PlatformB obtains the unique ID information of the data authorized by the user UserA, and binds the unique ID information using the issuing certificate CertA to generate the mapping relationship table MapC.

[0034] Optionally, the key KeyPA and the key KeyPB are distributed to the data operator end PlatformB, specifically including:

[0035] When the data operator end PlatformB does not open data authorization, the key KeyPA and the key KeyPB are distributed to the third-party CA institution, the key KeyPA is distributed to the service end DsServer for retention via the third-party CA institution, the key KeyPB is distributed to the data operator end PlatformB for retention, the key KeyPA is distributed to the data operator end PlatformB by the service end DsServer, and the data authorized by the user UserA is encrypted and stored based on the key KeyPA, the key KeyPB, and the mapping relationship table MapC in the data operator end PlatformB.

[0036] Optionally, in the data operator end PlatformB, the data authorized by the user UserA to the data operator end PlatformB is obtained based on the key KeyPA, the key KeyPB, and the mapping relationship table MapC, specifically including:

[0037] When the data operator end PlatformB opens data authorization, the client DsClient sends the key KeyPA to the data operator end PlatformB in the form of a digital envelope, the data operator end PlatformB uses the retained key KeyPB and the key KeyPA sent by the client DsClient to the data operator end PlatformB to form a key pair, and decrypts the encrypted and stored data authorized by the user UserA according to the key pair and the mapping relationship table MapC to obtain the data authorized by the user UserA.

[0038] In still another aspect, the present application provides a computing device, comprising: one or more processors;

[0039] a processor for executing one or more programs;

[0040] when the one or more programs are executed by the one or more processors, the method as described above is implemented.

[0041] In still another aspect, the present application provides a computer readable storage medium, having a computer program stored thereon, when the computer program is executed, the method as described above is implemented.

[0042] Compared with the prior art, the present application has the following beneficial effects:

[0043] The present application provides a data authorization method for data element transaction, comprising: after a user User A logs in a data right system DS, the data right system DS creates a p10 request for the user User A, and sends the p10 request to a third-party CA institution, and the third-party CA institution audits the identity information of the user User A according to the p10 request; if the identity information of the user User A passes the audit of the third-party CA institution, the third-party CA institution returns a signed certificate Cert A for the data right system DS and a data operator end Platform B, and the third-party CA institution issues a public key certificate Cert B to the data operator end Platform B; the data operator end Platform B generates a mapping relationship table Map C according to the signed certificate Cert A and the public key certificate Cert B; the data right system DS generates a data authorization strategy for the data operator end Platform B according to the signed certificate Cert A, and generates a key Key PA and a key Key PB according to the authorization strategy, and the data right system DS issues the key Key PA and the key Key PB to the data operator end Platform B, and authorizes the data of the user User A to the data operator end Platform B; based on the key Key PA, the key Key PB and the mapping relationship table Map C, the data operator end Platform B obtains the data authorized by the user User A to the data operator end Platform B. The present application can effectively guarantee the data security of the user side. BRIEF DESCRIPTION OF DRAWINGS

[0044] Figure 1 The flowchart of the method of the present application;

[0045] Figure 2 The implementation principle diagram of the method of the present application;

[0046] Figure 3 for the method of the present application;

[0047] Figure 4 for the system of the present application. DETAILED DESCRIPTION

[0048] Reference will now be made to the drawings in describing the exemplary embodiments of the present application, however, the present application can be embodied in many different forms and should not be construed as limited to the embodiments set forth herein, provided as examples to thoroughly and completely disclose the present application and to convey the full scope of the present application to those skilled in the art. The terminology used herein is for the purpose of describing the exemplary embodiments and is not intended to limit the present application. In the drawings, the same elements / elements are denoted by the same reference numerals.

[0049] Unless otherwise defined, the terms (including technical terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art. In addition, it is to be understood that the terms defined by commonly used dictionaries are to be interpreted as having a meaning that is consistent with their meaning in the context of the relevant art, and should not be interpreted in an idealized or overly formal sense unless expressly so defined herein.

[0050] Example 1:

[0051] The present application provides a data authorization method for data element transaction, as shown in Figure 1 , comprising:

[0052] Step 1, after a user UserA logs in a data authorization system DS, the data authorization system DS creates a p10 request for the user UserA and sends the p10 request to a third-party CA institution, and the third-party CA institution audits the identity information of the user UserA according to the p10 request;

[0053] Step 2, if the identity information of the user UserA passes the audit of the third-party CA institution, the third-party CA institution returns a signed certificate CertA for the data authorization system DS and a data operator end PlatformB, and the third-party CA institution issues a public key certificate CertB to the data operator end PlatformB;

[0054] Step 3, according to the signed certificate CertA and the public key certificate CertB, the data operator end PlatformB generates a mapping relationship table MapC;

[0055] Step 4, the data rights system DS generates a data authorization policy for the data operator end PlatformB according to the signing certificate CertA, and generates a key KeyPA and a key KeyPB according to the authorization policy, and the key KeyPA and the key KeyPB are issued to the data operator end PlatformB, and the authorized data of the user UserA is authorized to the data operator end PlatformB;

[0056] Step 5, in the data operator end PlatformB, based on the key KeyPA, the key KeyPB and the mapping relationship table MapC, the data authorized by the user UserA to the data operator end PlatformB is obtained.

[0057] Wherein, after the user UserA logs in the data rights system DS, the data rights system DS creates a p10 request for the user UserA, including:

[0058] After the user UserA logs in the client DsClient of the data rights system DS, the identity information of the user UserA is obtained through the client DsClient, and a pair of public and private keys for identifying identity is generated based on the identity information based on the trusted hardware medium, and the private key in the public and private keys is used to create a p10 request.

[0059] Wherein, the private key in the public and private keys is retained to the user UserA.

[0060] Wherein, the third party CA institution issues the signing certificate CertA and the public key certificate CertB to the server DsServer of the data rights system DS, and the server DsServer retains the signing certificate CertA and the public key certificate CertB;

[0061] The third party CA institution issues the public key certificate CertB to the data operator end PlatformB, and the data operator end PlatformB obtains the signing certificate CertA generated by the third party CA institution through the public key certificate CertB.

[0062] Wherein, the mapping relationship table MapC is generated according to the signing certificate CertA and the public key certificate CertB through the data operator end PlatformB, including:

[0063] In the data operator end PlatformB, the unique ID information of the data authorized by the user UserA is obtained, and the unique ID information is bound by using the signing certificate CertA to generate the mapping relationship table MapC.

[0064] Wherein, the key KeyPA and the key KeyPB are issued to the data operator end PlatformB, and specifically include:

[0065] When the data authorization of the data operator end PlatformB is not opened, the key KeyPA and the key KeyPB are issued to a third-party CA institution, the key KeyPA is issued to the server end DsServer for storage via the third-party CA institution, the key KeyPB is issued to the data operator end PlatformB for storage, the key KeyPA is issued to the data operator end PlatformB by the server end DsServer, and the authorized data of the user UserA is encrypted and stored based on the key KeyPA, the key KeyPB and the mapping relationship table MapC in the data operator end PlatformB.

[0066] Wherein, in the data operator end PlatformB, the data authorized by the user UserA to the data operator end PlatformB is obtained based on the key KeyPA, the key KeyPB and the mapping relationship table MapC, and specifically includes:

[0067] When the data authorization of the data operator end PlatformB is opened, the key KeyPA is sent to the data operator end PlatformB in the form of a digital envelope by the client end DsClient, the key KeyPB stored in the data operator end PlatformB and the key KeyPA sent to the data operator end PlatformB in the form of a digital envelope by the client end DsClient are used to form a key pair, the encrypted and stored authorized data of the user UserA is decrypted according to the key pair and the mapping relationship table MapC, and the authorized data of the user UserA is obtained.

[0068] The application will be further described below in combination with the implementation principle of the application, as shown in Figure 2 , and the corresponding relationship of each port of the application, as shown in Figure 3 , and the application will be further described below in combination with the implementation principle of the application, as shown in

[0069] The user UserA registers an account in Ds, which is used for logging in the system.

[0070] The user UserA applies for a certificate based on a trusted hardware medium (such as a smart password key, a security chip, etc.) for identity authentication, and a pair of public and private keys will be generated in the calling process, the private key is stored in the smart password key, and the public key is used to create a p10 request and sent to the CA institution for signing.

[0071] After verifying the information of user UserA, the CA issues certificate CertA and returns it to UserA. It also returns the public key certificate of the data operator PlatformB, which will be used later. At the same time, the certificate public key is published to the public LDAP server.

[0072] After obtaining the certificate, user UserA sets the authorization policy on the system client DsClient and chooses whether to grant data access rights to the data operator. If data access rights are not granted, the CA interface is called, and the CA generates an encryption key. The key consists of two parts: KeyPA and KeyPB. KeyPA is stored by the DsServer, and KeyPB is stored by the data operator.

[0073] The data operator uses KeyPA and KeyPB to form a complete key based on the data mapping relationship saved in MapC, and encrypts all of UserA's data. The data operator cannot decrypt the encrypted data and use it alone. If UserA needs to use the data, he needs to provide authorization and send KeyPA to the data operator.

[0074] The present invention adopts a lightweight authorization method to ensure that users can openly authorize their own data at any time. The authorization supports mobile and PC terminals, which is convenient and fast.

[0075] The present invention can be easily integrated with other data operators and is easy to expand. If a data operator wants to collect and use user data, it only needs to register its identity with the CA organization. The data right confirmation system can connect to the CA organization and update the information of the data operator.

[0076] When the present invention is applied, if a data operator wants to use user data, the user needs to authorize the operator to provide a portion of the key that the user holds in a timely manner before the data operator can decrypt and use the data. If the user does not provide the key, the data operator cannot use the data, which greatly avoids the problem of data leakage.

[0077] On the other hand, the present invention also provides a data authorization system 200 for data element transactions, such as Figure 4 As shown, including:

[0078] Identity authentication unit 201, configured to generate a p10 request for user UserA after user UserA logs into the data rights confirmation system DS, and send the p10 request to a third-party CA institution, which then verifies the identity information of user UserA based on the p10 request;

[0079] The certificate issuing unit 202 is configured to, after the identity information of the user UserA is verified by the third-party CA organization, return the issuance certificate CertA to the data rights confirmation system DS and the data operator PlatformB through the third-party CA organization, and issue the public key certificate CertB to the data operator PlatformB through the third-party CA organization;

[0080] A mapping unit 203 is configured to generate a mapping relationship table MapC according to the issuance certificate CertA and the public key certificate CertB through the data operator side PlatformB;

[0081] Authorization unit 204 is used for the data right confirmation system DS to generate a data authorization policy for the data operator PlatformB based on the issuance certificate CertA, generate keys KeyPA and KeyPB based on the authorization policy, send the keys KeyPA and KeyPB to the data operator PlatformB, and authorize the authorizable data of user UserA to the data operator PlatformB;

[0082] The data acquisition unit 205 is configured to obtain, at the data operator side PlatformB, the data authorized by the user UserA to the data operator side PlatformB based on the key KeyPA, the key KeyPB and the mapping relationship table MapC.

[0083] After user UserA logs in to the data ownership confirmation system DS, the data ownership confirmation system DS creates a p10 request for user UserA, including:

[0084] After user UserA logs in to the client DsClient of the data rights confirmation system DS, the identity information entered by the user UserA is obtained through the client DsClient. Based on the identity information and the trusted hardware medium, a pair of public and private keys for identity authentication is generated, and the private key in the public and private keys is used to create a p10 request.

[0085] Among them, the private key in the public and private keys is retained by user UserA.

[0086] The third-party CA organization publishes the issuance certificate CertA and the public key certificate CertB to the server DsServer of the data rights confirmation system DS, and the server DsServer retains the issuance certificate CertA and the public key certificate CertB;

[0087] The third-party CA institution issues a public key certificate CertB to the data operator end PlatformB, and the data operator end PlatformB obtains the issuing certificate CertA generated by the third-party CA institution through the public key certificate CertB.

[0088] The mapping relationship table MapC is generated by the data operator end PlatformB according to the issuing certificate CertA and the public key certificate CertB, and includes:

[0089] In the data operator end PlatformB, the unique ID information of the data authorized by the user UserA is obtained, and the unique ID information is bound by using the issuing certificate CertA to generate the mapping relationship table MapC.

[0090] The key KeyPA and the key KeyPB are distributed to the data operator end PlatformB, and specifically include:

[0091] When the data authorization of the data operator end PlatformB is not opened, the key KeyPA and the key KeyPB are distributed to the third-party CA institution, the key KeyPA is distributed to the service end DsServer for storage through the third-party CA institution, the key KeyPB is distributed to the data operator end PlatformB for storage, the key KeyPA is distributed to the data operator end PlatformB through the service end DsServer, and the data authorized by the user UserA is encrypted and stored based on the key KeyPA, the key KeyPB and the mapping relationship table MapC in the data operator end PlatformB.

[0092] In the data operator end PlatformB, the data authorized by the user UserA to the data operator end PlatformB is obtained based on the key KeyPA, the key KeyPB and the mapping relationship table MapC, and specifically includes:

[0093] When the data authorization of the data operator end PlatformB is opened, the client DsClient sends the key KeyPA to the data operator end PlatformB in the form of a digital envelope, the key KeyPB stored in the data operator end PlatformB and the key KeyPA sent by the client DsClient to the data operator end PlatformB in the form of a digital envelope are used to form a key pair, and the encrypted and stored data authorized by the user UserA is decrypted according to the key pair and the mapping relationship table MapC to obtain the data authorized by the user UserA.

[0094] The application can effectively guarantee the data security of the user side.

[0095] Embodiment 3

[0096] Based on the same inventive concept, the application further provides a computer device, which comprises a processor and a memory, the memory is used for storing a computer program, the computer program comprises program instructions, and the processor is used for executing the program instructions stored in the computer storage medium. The processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc., which are the computing core and control core of the terminal, and are suitable for implementing one or more instructions, and are specifically suitable for loading and executing one or more instructions in the computer storage medium to implement a corresponding method flow or a corresponding function, so as to implement the steps of the method in the above embodiments.

[0097] Embodiment 4

[0098] Based on the same inventive concept, the application further provides a storage medium, specifically a computer readable storage medium (Memory), which is a memory device in the computer device, and is used for storing programs and data. It can be understood that the computer readable storage medium herein can include the built-in storage medium in the computer device, and of course can also include the expansion storage medium supported by the computer device. The computer readable storage medium provides a storage space, and the storage space stores the operating system of the terminal. Furthermore, one or more instructions suitable for being loaded and executed by the processor are also stored in the storage space, and the instructions can be one or more computer programs (including program codes). It should be noted that the computer readable storage medium herein can be a high-speed RAM memory, or a non-volatile memory such as at least one disk memory. One or more instructions stored in the computer readable storage medium can be loaded and executed by the processor to implement the steps of the method in the above embodiments.

[0099] Those skilled in the art will appreciate that embodiments of the present application can be readily used as software, hardware, or a combination of software and hardware. In a software embodiment, the methods can be tangibly embodied in a machine-readable storage medium having stored thereon instructions that can be used to program a computer to perform any of the methods. The software implementation can be initialized by loading and executing a set of instructions arranged to perform one of the methods into the computer's memory. Alternatively, hard-wired circuitry can be used in place of, or in combination with, software instructions. Thus, the

[0100] The present application is described in reference to the flowchart illustrations and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in one or more of the flowchart illustrations and / or block diagrams. Figure 1 means for performing each of the functions specified in the flowchart illustrations and / or block diagrams.

[0101] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in one or more of the flowchart illustrations and / or block diagrams. Figure 1 means for performing each of the functions specified in the flowchart illustrations and / or block diagrams.

[0102] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in one or more of the flowchart illustrations and / or block diagrams. Figure 1 means for performing each of the functions specified in the flowchart illustrations and / or block diagrams.

[0103] While preferred embodiments of the application have been described, modifications and variations can be apparent to those skilled in the art once aware of the general underlying concepts. Accordingly, the appended claims are intended to embrace all such modifications and variations as fall within the scope of the application.

[0104] It will be apparent to those skilled in the art that various modifications and variations can be made to the present application without departing from the spirit or scope of the application. Thus, it is intended that the present application cover modifications and variations of this application provided they come within the scope of the appended claims and their equivalents.

Claims

1. A data authorization method for data element transaction, characterized by, The data authorization method comprises: After a user User A logs in a data authorization system DS, the data authorization system DS creates a p10 request for the user User A and sends the p10 request to a third-party CA institution, and the third-party CA institution audits identity information of the user User A according to the p10 request; If the identity information of the user User A passes the audit of the third-party CA institution, the third-party CA institution returns an issued certificate Cert A to the data authorization system DS and a data operator end Platform B, and the third-party CA institution issues a public key certificate Cert B to the data operator end Platform B; The data operator end Platform B generates a mapping relationship table Map C according to the issued certificate Cert A and the public key certificate Cert B; The data authorization system DS generates a data authorization policy for the data operator end Platform B according to the issued certificate Cert A, generates a key Key PA and a key Key PB according to the authorization policy, and issues the key Key PA and the key Key PB to the data operator end Platform B, and authorizes the data of the user User A to the data operator end Platform B; The data operator end Platform B obtains the data authorized by the user User A to the data operator end Platform B based on the key Key PA, the key Key PB and the mapping relationship table Map C.

2. The data authorization method of claim 1, wherein, After the user User A logs in the data authorization system DS, the data authorization system DS creates a p10 request for the user User A, which comprises: After the user User A logs in the client DsClient of the data authorization system DS, the client DsClient obtains the identity information input by the user User A, generates a pair of public and private keys for identity authentication based on the identity information and a trusted hardware medium, and creates a p10 request by using the public key in the public and private keys.

3. The data authorization method of claim 2, wherein, The private key in the public and private keys is retained by the user User A.

4. The data authorization method of claim 1, wherein, The third-party CA institution issues the issued certificate Cert A and the public key certificate Cert B to the server DsServer of the data authorization system DS, and the server DsServer retains the issued certificate Cert A and the public key certificate Cert B; The third-party CA institution issues the public key certificate Cert B to the data operator end Platform B, and the data operator end Platform B obtains the issued certificate Cert A generated by the third-party CA institution by using the public key certificate Cert B.

5. The data authorization method of claim 1, wherein, The data operator end Platform B generates a mapping relationship table Map C according to the issued certificate Cert A and the public key certificate Cert B, which comprises: At the data operator end PlatformB, obtain the unique ID information of the data authorized by the user UserA, bind the unique ID information with the issuing certificate CertA to generate a mapping relationship table MapC.

6. The data authorization method of claim 1, wherein, The key KeyPA and the key KeyPB are delivered to the data operator end PlatformB, specifically including: When the data authorization of the data operator end PlatformB is not opened, the key KeyPA and the key KeyPB are delivered to the third-party CA institution, the key KeyPA is delivered to the service end DsServer of the data right system DS for storage through the third-party CA institution, the key KeyPB is delivered to the data operator end PlatformB for storage, the key KeyPA is delivered to the data operator end PlatformB through the service end DsServer, and the data authorized by the user UserA is encrypted and stored based on the key KeyPA, the key KeyPB and the mapping relationship table MapC in the data operator end PlatformB.

7. The data authorization method of claim 1, wherein, The data authorized by the user UserA to the data operator end PlatformB is obtained based on the key KeyPA, the key KeyPB and the mapping relationship table MapC in the data operator end PlatformB, specifically including: When the data authorization of the data operator end PlatformB is opened, the key KeyPA is sent to the data operator end PlatformB in the form of a digital envelope by the client DsClient of the data right system DS, the key KeyPA and the key KeyPB retained in the data operator end PlatformB are used to form a key pair, the encrypted and stored data authorized by the user UserA is decrypted according to the key pair and the mapping relationship table MapC to obtain the data authorized by the user UserA.

8. A data authorization system for data element transactions, characterized by The data authorization system includes: An identity authentication unit is configured to create a p10 request for the user UserA after the user UserA logs in the data right system DS, send the p10 request to the third-party CA institution, and audit the identity information of the user UserA according to the p10 request through the third-party CA institution; A certificate issuing unit is configured to return an issuing certificate CertA for the data right system DS and the data operator end PlatformB through the third-party CA institution after the identity information of the user UserA is audited by the third-party CA institution, and issue a public key certificate CertB to the data operator end PlatformB through the third-party CA institution. A mapping unit is configured to generate a mapping table MapC according to the issuing certificate CertA and the public key certificate CertB through the data operator end PlatformB. An authorization unit is configured to generate a data authorization policy for the data operator end PlatformB according to the issuing certificate CertA through the data rights system DS, and generate a key KeyPA and a key KeyPB according to the authorization policy, and then issue the key KeyPA and the key KeyPB to the data operator end PlatformB, and authorize the data of the user UserA to the data operator end PlatformB. A data acquisition unit is configured to obtain the data authorized by the user UserA to the data operator end PlatformB based on the key KeyPA, the key KeyPB and the mapping table MapC through the data operator end PlatformB.

9. The data authorization system of claim 8, wherein, After the user UserA logs in the data rights system DS, the data rights system DS creates a p10 request for the user UserA, which includes: After the user UserA logs in the client DsClient of the data rights system DS, the client DsClient obtains the identity information input by the user UserA, and generates a pair of public and private keys for identity authentication based on the identity information and the trusted hardware medium, and creates a p10 request by using the public key in the public and private keys.

10. The data licensing system of claim 9, wherein, The private key in the public and private keys is retained to the user UserA.

11. The data authorization system of claim 8, wherein, The third-party CA institution issues the issuing certificate CertA and the public key certificate CertB to the server DsServer of the data rights system DS, and the server DsServer retains the issuing certificate CertA and the public key certificate CertB. The third-party CA institution issues the public key certificate CertB to the data operator end PlatformB, and the data operator end PlatformB obtains the issuing certificate CertA generated by the third-party CA institution through the public key certificate CertB.

12. The data authorization system of claim 8, wherein, The data operator end PlatformB generates a mapping table MapC according to the issuing certificate CertA and the public key certificate CertB, which includes: The data operator end PlatformB obtains the unique ID information of the data authorized by the user UserA, and binds the unique ID information by using the issuing certificate CertA to generate a mapping table MapC.

13. The data authorization system of claim 8, wherein, The key KeyPA and the key KeyPB are issued to the data operator end PlatformB, which specifically includes: When the data operator end PlatformB does not open data authorization, the key KeyPA and the key KeyPB are issued to a third-party CA institution, the key KeyPA is issued to a service end DsServer of a data right system DS via the third-party CA institution for storage, the key KeyPB is issued to the data operator end PlatformB for storage, the key KeyPA is issued to the data operator end PlatformB through the service end DsServer, and the data operator end PlatformB stores the authorized data of the user UserA based on the key KeyPA, the key KeyPB and a mapping relationship table MapC.

14. The data authorization system of claim 8, wherein, The data operator end PlatformB obtains the data authorized by the user UserA based on the key KeyPA, the key KeyPB and the mapping relationship table MapC, and specifically includes: When the data operator end PlatformB opens data authorization, the data right system DS sends the key KeyPA to the data operator end PlatformB in the form of a digital envelope, the data operator end PlatformB uses the stored key KeyPB and the key KeyPA sent by the client DsClient to form a key pair, and decrypts the encrypted authorized data of the user UserA according to the key pair and the mapping relationship table MapC to obtain the authorized data of the user UserA.

15. A computer device, comprising: It includes: One or more processors; Processors for executing one or more programs; When the one or more programs are executed by the one or more processors, the method of any one of claims 1-7 is implemented.

16. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and when the computer program is executed, the method of any one of claims 1-7 is implemented.

Citation Information

Patent Citations

  • Data element transaction system

    CN115496416A

  • Smart television terminal and method for establishing a trust chain therefor

    US20200322172A1